Fortinet FortiGate FortiGate-5005-DIST Скачать руководство пользователя страница 2

FortiGate-5005-DIST Security System Getting Started

01-30000-0414-20070615

Warnings and cautions

Only trained and qualified personnel should be allowed to install or maintain FortiGate-5000 series 
equipment. Read and comply with all warnings, cautions and notices in this document. 

Turning off all power switches may not turn off all power to the FortiGate-5000 series equipment. 
Except where noted, disconnect the FortiGate-5000 series equipment from all power sources, 
telecommunications links and networks before installing, or removing FortiGate-5000 series 
components, or performing other maintenance tasks. Failure to do this can result in personal injury or 
equipment damage. Some circuitry in the FortiGate-5000 series equipment may continue to operate 
even though all power switches are off.

An easily accessible disconnect device, such as a circuit breaker, should be incorporated into the data 
center wiring that connects power to the FortiGate-5000 series equipment.

Install FortiGate-5000 series chassis at the lower positions of a rack to avoid making the rack top-heavy 
and unstable.

Do not insert metal objects or tools into open chassis slots.

Electrostatic discharge (ESD) can damage FortiGate-5000 series equipment. Only perform the 
procedures described in this document from an ESD workstation. If no such station is available, you 
can provide some ESD protection by wearing an anti-static wrist or ankle strap and attaching it to an 
ESD connector or to a metal part of a FortiGate chassis.

Some FortiGate-5000 series components may overload your supply circuit and impact your overcurrent 
protection and supply wiring. Refer to nameplate ratings to address this concern. 

Make sure all FortiGate-5000 series components have reliable grounding. Fortinet recommends direct 
connections to the branch circuit.

If you install a FortiGate-5000 series component in a closed or multi-unit rack assembly, the operating 
ambient temperature of the rack environment may be greater than room ambient. Make sure the 
operating ambient temperature does not exceed the manufacturer's maximum rated ambient 
temperature.

Installing FortiGate-5000 series equipment in a rack should be such that the amount of airflow required 
for safe operation of the equipment is not compromised.

This equipment is for installation only in a Restricted Access Location (dedicated equipment room, 
service closet or the like), in accordance with the National Electrical Code.

Per the National Electrical Code, sizing of a Listed circuit breaker or branch circuit fuse and the supply 
conductors to the equipment is based on the marked input current rating. A product with a marked input 
current rating of 25 A is required to be placed on a 40 A branch circuit. The supply conductors will also 
be sized according to the input current rating and also derated for the maximum rated operating 
ambient temperature, Tma, of the equipment.

FortiGate-5000 series equipment shall be installed and connected to an electrical supply source in 
accordance with the applicable codes and regulations for the location in which it is installed. Particular 
attention shall be paid to use of correct wire type and size to comply with the applicable codes and 
regulations for the installation / location. Connection of the supply wiring to the terminal block on the 
equipment may be accomplished using Listed wire compression lugs, for example, Pressure Terminal 
Connector made by Ideal Industries Inc. or equivalent which is suitable for AWG 10. Particular attention 
shall be given to use of the appropriate compression tool specified by the compression lug 
manufacturer, if one is specified.

!

CAUTION: 

Risk of Explosion if Battery is replaced by an Incorrect Type. Dispose of Used Batteries According 

to the Instructions.

!

Caution: 

You should be aware of the following cautions and warnings before installing FortiGate-5000 series 

hardware

Содержание FortiGate FortiGate-5005-DIST

Страница 1: ...IC BASE USB USB 3 4 1 2 5 6 7 8 OOS ACC STATUS IPM CONSOLE ACT ACT LINK LINK FABRIC BASE USB USB 3 4 1 2 5 6 7 8 OOS ACC STATUS IPM CONSOLE ACT ACT LINK LINK FABRIC BASE USB USB 3 4 1 2 5 6 7 8 OOS AC...

Страница 2: ...ate 5000 series component in a closed or multi unit rack assembly the operating ambient temperature of the rack environment may be greater than room ambient Make sure the operating ambient temperature...

Страница 3: ...CLI or web based manager 13 Configuring the primary I O module 14 Installing FortiGate 5005FA2 worker modules 15 Installing FortiGate 5005FA2 modules 16 Verifying that FortiGate 5005FA2 modules can c...

Страница 4: ...urrently installed firmware versions 34 Upgrading I O module firmware 34 Upgrading worker module firmware installed on the primary I O module 36 Upgrading FortiController 5208 NPU firmware 37 For more...

Страница 5: ...ic to the worker modules The worker modules provide FortiGate security system functions including firewall VPN IPS antivirus antispam and so on The following topics are included in this section Basic...

Страница 6: ...100 link Act ETH0 Service RESET STATUS Hot Swap link Act ETH0 ETH1 10 100 5000SM 10 100 link Act ETH0 Service RESET STATUS Hot Swap link Act ETH0 ETH1 10 100 5000SM PAYLOAD OPERATION STATUS IPM X 1 X...

Страница 7: ...led in slot 2 The worker modules apply all of the FortiGate security system functionality to traffic passing through the FortiGate 5005 DIST security system Traffic is distributed to the worker module...

Страница 8: ...5140 CRITICAL RESET MAJO R MINOR USER1 USER2 USER3 5140SAP SERIAL 1 SERIAL 2 ALARM FILTER 1 2 0 1 2 10 100 link Act ETH0 Service RESET STATUS Hot Swap link Act ETH0 ETH1 10 100 5000SM 10 100 link Act...

Страница 9: ...for the interfaces of the primary I O module installed in chassis slot 1 and 2 for the interfaces of the secondary I O module installed in chassis slot 2 The interfaces for the secondary I O module o...

Страница 10: ...ntroller 5208 location FortiController 5208 front panel interface names Web based manager and CLI interface names Primary FortiController 5208 module installed in chassis slot 1 X1 port1_X1 X2 port1_X...

Страница 11: ...ary I O module will connect with all components and after a few minutes the system will be operational However the first time you install a FortiGate 5005 DIST system you should follow the procedures...

Страница 12: ...Verify that the chassis is operating normally Installing FortiController 5208 modules If your FortiGate 5005 DIST security system includes one FortiController 5208 module it must be installed in slot...

Страница 13: ...3 Install SFP and XFP transceivers in the front panel interfaces of your FortiController 5208 I O module as required Connecting to the FortiController 5208 CLI or web based manager The following proce...

Страница 14: ...he management computer to 192 168 1 2 and the netmask to 255 255 255 0 3 To access the web based manager start Internet Explorer on the management computer and browse to https 192 168 1 99 remember to...

Страница 15: ...primary I O module If you have installed a FortiController 5208 module in slot 2 the module in slot 2 recognizes that the FortiController 5208 module in slot 1 is the primary I O module The FortiContr...

Страница 16: ...ware on a FortiGate 5005FA2 module Installing FortiGate 5005FA2 modules This procedure describes how to install FortiGate 5005FA2 modules in a FortiGate 5005 DIST chassis This procedure also describes...

Страница 17: ...ng in a FortiGate 5140 chassis with worker modules installed in chassis slots 6 and 10 The message indicates that both worker modules are operating in DIST mode and have successfully connected to the...

Страница 18: ...appear in the list use the procedure To view the status of FortiGate 5005FA2 modules from the FortiGate 5005FA2 CLI on page 18 to verify the status of each module and determine a course of action for...

Страница 19: ...and configured correctly In particular confirm the I O module in slot 1 is configured as the primary For details see To configure the primary I O module on page 15 If this does not solve the problem...

Страница 20: ...ult firmware H Display this list of options Enter G F B I Q or H 5 Enter B The FortiGate 5005FA2 module exchanges the backup and default firmware and then restarts If the DIST firmware was installed i...

Страница 21: ...system has two I O modules installed or slot 2 and above if one I O module is installed The FortiController 5208 module s should also have the appropriate XFP and SFP transceivers installed The module...

Страница 22: ...erforms network address translation before IP packets are sent to the destination network In Route mode no translation takes place Figure 7 Example FortiGate 5005 DIST system operating in NAT Route mo...

Страница 23: ...e the FortiGate module Web based manager The FortiGate web based manager is an easy to use management tool Use the web based manager to configure the FortiGate administrator password the interface add...

Страница 24: ...re the FortiGate security system for your network add an administrator password change the network interface IP addresses add DNS server IP addresses and if required configure basic routing Note Conne...

Страница 25: ..._____ _____ Netmask _____ _____ _____ _____ Management mng IP _____ _____ _____ _____ Netmask _____ _____ _____ _____ Secondary I O module interfaces X1 port2_X1 IP _____ _____ _____ _____ Netmask ___...

Страница 26: ...le web based manager go to System Network Interface 2 Select the edit icon for the mng interface 3 Enter the IP address and netmask for the interface To configure interfaces 1 Go to Worker Blade Syste...

Страница 27: ...t 6 Configure the port1_X1 interface execute worker manage config system interface edit port1_X1 set ip intf_ip netmask_ip end exit 7 Repeat to configure each interface as required for example to conf...

Страница 28: ...Worker Blade System Status and select the Change link beside Operation Mode NAT 2 Set Operation Mode to Transparent 3 Set the Management IP Netmask to 192 168 1 99 24 4 Set the default Gateway to 192...

Страница 29: ...sparent mode 1 Use the serial cable supplied with your FortiController 5208 module to connect the FortiController 5208 Com 2 port to the management computer serial port 2 Start a terminal emulation pr...

Страница 30: ...rtiGate 5005 DIST system 1 Connect to the primary I O module and shut down the worker modules execute worker shutdown 2 If present shut down the secondary I O module execute secondary io execute shutd...

Страница 31: ...O blade During this startup time the FortiGate 5005 DIST system cannot process traffic To start a configured FortiGate 5005 DIST system 1 Connect and turn on power to the chassis 2 Fully insert all mo...

Страница 32: ...ary I O module from the primary I O module CLI or web based manager Viewing the currently installed firmware versions Upgrading I O module firmware Upgrading worker module firmware installed on the pr...

Страница 33: ...he CLI 4 Make sure the I O module can connect to the TFTP server You can use the following command to ping the computer running the TFTP server For example if the IP address of the TFTP server is 192...

Страница 34: ...og into the web based manager 8 Go to System Status and check the Firmware Version to confirm that the firmware upgrade is successfully installed Update antivirus and attack definitions To upgrade the...

Страница 35: ...n recommended by Fortinet Customer Support you can use the following information to upgrade the firmware operating on FortiController 5208 module You must perform this procedure separately for each Fo...

Страница 36: ...ntroller 5208 copies the firmware image from the TFTP server and installs the image on the FortiController 5208 NPU 5 Once the firmware has been installed you must restart the FortiController 5208 If...

Страница 37: ...vailable from the Fortinet Knowledge Center The knowledge center contains troubleshooting and how to articles FAQs technical notes and more Visit the Fortinet Knowledge Center at http kc forticare com...

Страница 38: ...rks Dynamic Threat Prevention System DTPS APSecure FortiASIC FortiBIOS FortiBridge FortiClient FortiGate FortiGate Unified Threat Management System FortiGuard FortiGuard Antispam FortiGuard Antivirus...

Отзывы: