background image

Layer 3 Network - Additional Routes

Layer 3 Network - Additional Routes

When a client connects on eth1 from a remote network, the return packet uses the eth0 Default
Gateway unless a network route is added. It is recommended that you configure your network so
that outbound and inbound routing uses the same interface, such as eth1. The routes you
created in Layer 3 Network - Configure Route Scopes on page 30 route back to the clients via
eth0.

Note:

In a High Availability environment you must enter additional routes on both the primary

and secondary servers.

When you re-run the Configuration Wizard, the routes that you entered previously appear in the
view. You may have routes in your system routes file that were not entered in the Configuration
Wizard. Be aware of the following issues:

If you import the system routes file, they overwrite any existing routes in the Additional
Routes view.

If you enter routes in the Additional Routes view and save, these routes overwrite
previous routes.

If there are no routes in the Additional Routes view and you save, all routes are erased
from the system routes file except for the Default Gateway.

To import system routes, click the

Read File

button on the Additional Routes window in the

Configuration Wizard. The number of routes in the system routes file is listed next to the button.

For each route you are configuring:

1.

On the

Additional Routes

screen click

Add

.

2.

Enter the Network IP Address, Mask, and Gateway, then click

Add

.

Example:

When eth1 IP is 192.168.10.2 and the eth1 gateway is 192.168.10.1 for DHCP Lease
Pool 192.168.110.100-192.168.110.200 add the following route:

Route Setup Field Example

Definition

Network 192.168.110.0

Identifies the network from which packets are coming.

Mask 255.255.255.0

Subnet mask for the network.

Gateway 192.168.10.1

Identifies the gateway for eth1. Do not use the gateway for the network.

3.

Repeat step 2 to add additional routes.

Important:

The routes you enter into the list on this view are written to the system

routes file when you click Apply on the Summary view.

If the list is blank, ALL routes

in the system routes file with the exception of the Default Gateway are removed from
the system routes file.

4.

Click

Next

.

40

Содержание FortiNac BFN320

Страница 1: ...Appliance Installation Guide Version 8 3 Date 8 24 2018...

Страница 2: ...om how to work with fortinet support FORTINET COOKBOOK http cookbook fortinet com FORTINET TRAINING AND CERTIFICATION PROGRAM https www fortinet com support and training training html NSE INSTITUTE ht...

Страница 3: ...To Configuration Wizard Software 15 Password Setup 17 Network Type 20 Layer 2 Network VLANs 21 Layer 2 Network Configure VLANS 22 Layer 2 Network Additional Routes 27 Layer 2 Network Summary 27 Layer...

Страница 4: ...ted contact Customer Support You can download electronic versions of the Appliance Installation Guides through the Configuration Wizard See Login To Configuration Wizard Software on page 15 Note The C...

Страница 5: ...ame Appliance Label Product Descriptor Appliance Identifier NS3200 Network Control Server NS3200 FortiNac Control Server SYS G BFN620XL NS3200 NS10200 Network Application Server NS10200 FortiNac Appli...

Страница 6: ...ance Product Port Port Used During Initial Basic Network Configuration BFN320 BFN330 BFN620 BFN630 All Products eth1 Used temporarily during configuration until the IP address mask default gateway and...

Страница 7: ...4...

Страница 8: ...asic networking information such as mask DNS or hostname IP address for this appliance Disconnect laptop from eth1 and connect appliance to network on eth0 None Software Configuration Return to Config...

Страница 9: ...x range The appliance itself has an IP address of 192 168 1 1 Be certain to connect the RJ45 cable to the correct Ethernet port LED 1 on the front of the appliance lights to indicate when eth0 has est...

Страница 10: ...Login To Configuration Wizard Hardware Setup 1 If you have not done so already bring up a web browser and navigate to http 192 168 1 1 8080 configWizard 2 Enter the User Name and Password credentials...

Страница 11: ...Hardware Setup Note You will be required to change the Configuration Wizard password during the setup process 8...

Страница 12: ...identification have the MAC Address of the appliance ready when you call for assistance The MAC Address is located on the shipping label the Appliance Identification Details document and on the back...

Страница 13: ...resent the current configuration of the appliance When you make edits in the Configuration Wizard your modifications are stored in a temporary file This allows you to exit the Configuration Wizard bef...

Страница 14: ...his is used in the basic IP network configuration for the appliance Domain Enter your domain name such as megatech com or megatech edu Forwarding DNS for all Isolation Networks Use Primary and Seconda...

Страница 15: ...CLI SSH and Configuration Wizard passwords must be eight characters or longer and contain a lowercase letter an uppercase letter a number and one of the following symbols Required Symbols exclamation...

Страница 16: ...pliance Must be at least 8 characters and no more than 64 characters root CLI SSH password Customer Support uses to log into the appliance Must be at least 8 characters and no more than 64 characters...

Страница 17: ...e type and corresponding ports WARNING DO NOT use a firewall between any FortiNac appliances because the firewall interferes with the connection between those appliances There should never be a firewa...

Страница 18: ...ss and apply those settings Login To Configuration Wizard Software 1 Bring up a web browser and point it to the IP Address of the FortiNac Server FortiNac Control Server or FortiNac Management Server...

Страница 19: ...Software Configuration Figure 7 Download Documentation Window 16...

Страница 20: ...Password Setup Figure 8 Change Passwords Figure 9 Configuration Wizard Password Setup Password Setup 17...

Страница 21: ...characters You are required to change this password New Configuration Wizard Password Retype Configuration Wizard Password The Password used to access the Configuration Wizard You are required to chan...

Страница 22: ...7 Close the window or tab 8 Click Next to continue Password Setup 19...

Страница 23: ...IP address you must select the Layer 3 network option L3 High Availability configurations are not supported with Layer 2 Isolation settings Select the Layer 2 network option to specify VLAN isolation...

Страница 24: ...clients connecting to the network and redirects them to the appropriate isolation web pages In the Isolation VLAN the state of the client such as known vs unknown or out of compliance determines the a...

Страница 25: ...lick the Add button in the Isolation DNS Subnets section 4 Click Next Table 12 VLAN Isolation Network Field Definitions Field Definition VLAN Type Interface eth1 Interface IPv4 Address IP4 address for...

Страница 26: ...hat an IP address in this domain is available for use When this time has elapsed the user is served a new IP address The recommended lease time for Isolation Registration Remediation Authentication De...

Страница 27: ...Layer 2 Network Configure VLANS Figure 11 Layer 2 Isolation Figure 12 Add Subnet 24...

Страница 28: ...Pool Start End Starting and ending IP addresses that delineate the range of IP addresses available on this VLAN Domain Domain Identifies the domain for this range of IP addresses To help identify the...

Страница 29: ...for the isolation VLAN use megatech iso com or for the registration VLAN use megatech reg com Note Note If you use agents for OS X iOS and some Linux systems using a local suffix in Domain fields may...

Страница 30: ...a on the Summary View to confirm the configured settings Important Confirm that you have selected the check boxes for the VLANs you are configuring If they have not been selected click the Back button...

Страница 31: ...ents rather than the clients connecting on the local Isolation VLANs Multiple scopes are allowed for each of the routes Registration Remediation Dead End VPN Authentication Isolation and Access Point...

Страница 32: ...on presented to the client via the web browser or persistent agent If you use these scopes configuring the other scopes Registration Remediation Dead End VPN Authentication or Access Point Management...

Страница 33: ...ask 5 In the Lease Pools section click Add to add the lease pool information for the scope 6 Enter the IP Addresses for Start and End of the lease pool range then click Add 7 Repeat steps 3 through 6...

Страница 34: ...art of the name in the domain For example for the isolation VLAN use megatech iso com or for the registration VLAN use megatech reg com Note Note If you use agents for OS X iOS and some Linux systems...

Страница 35: ...Layer 3 Network Configure Route Scopes Figure 15 Layer 3 Network Configuration Isolation Scopes 32...

Страница 36: ...ment Field Definitions Field Definition Access Point Management Interface eth1 Interface IP Address IP address for the VLAN interface on eth1 This VLAN is used when more than one MAC address is detect...

Страница 37: ...ields may cause communications issues Example Incorrect dns suffix for reg tech reg megatech local Correct dns suffix for reg tech megatech reg edu Production Lease Pools Starting and ending IP addres...

Страница 38: ...Production DNS Primary IP address of the Primary DNS Server Production DNS Secondary IP address of the Secondary DNS Server Access Point Management Isolation Network Scopes Lease Time In Seconds Time...

Страница 39: ...Layer 3 Network Configure Route Scopes Figure 18 Layer 3 Access Point Management 36...

Страница 40: ...Figure 19 Layer 3 Add Access Point Management Scopes Layer 3 Network Configure Route Scopes 37...

Страница 41: ...ue for each route scope that you import If it is not unique the record with the first instance of the ScopeLabel field is duplicated for each subsequent instance of the identical ScopeLabel Note When...

Страница 42: ...Figure 20 Layer 3 Routes Import Route Scopes Window Layer 3 Network Configure Route Scopes 39...

Страница 43: ...routes in the Additional Routes view and you save all routes are erased from the system routes file except for the Default Gateway To import system routes click the Read File button on the Additional...

Страница 44: ...Figure 21 Additional Routes Window Figure 22 Add Route Window Layer 3 Network Additional Routes 41...

Страница 45: ...apply them until a successful configuration is written 3 Click Reboot to continue with the installation and begin network modeling and policy creation OR Click Shutdown to turn off the appliance 4 If...

Страница 46: ...Figure 23 Results Window Results Layer 2 Layer3 Networks Or Control Manager 43...

Страница 47: ...port https IP Address 8443 or https Host Name of the appliance 8443 2 Enter the login credentials User Name root Password YAMS Note User Name and Password fields are case sensitive 3 Once you have log...

Страница 48: ...les to be overwritten if you use the Next button to scroll through all of the pages If no manual changes have been made this does not cause a problem However it is recommended that you go directly to...

Страница 49: ...Change Passwords After Configuration 46...

Страница 50: ...inet enters a binding written contract signed by Fortinet s General Counsel with a purchaser that expressly warrants that the identified product will perform according to certain expressly identified...

Отзывы: