Fortinet FortiGate FortiGate-5001FA2 Introductions Manual

Fortigate-5000 series
Hide thumbs Also See for FortiGate FortiGate-5001FA2:
Table of Contents

Advertisement

5140
13
11
9
7
5
3
1
MANAGEMENT
E
T
H
O
SYSTEM
CONSOLE
R
S
2
3
2
Z
R
E
0
Z
R
E
1
Z
R
E
2
E2
E1
14
15
12
13
10
11
8
9
6
7
4
5
2
3
0
1
ZRE
CLK
OK
EXT
INT
FLT
FLT
HOT SWAP
RESET
LED MODE
FILTER
0
1
FA N T R AY
FA N TR AY
5140SAP
SERIAL 1
SERIAL 2
ALARM
2
4
6
8
10
12
14
MANAGEMENT
E
T
H
O
SYSTEM
CONSOLE
R
S
2
3
2
Z
R
E
0
Z
R
E
1
Z
R
E
2
E2
E1
14
15
12
13
10
11
8
9
6
7
4
5
2
3
0
1
ZRE
CLK
OK
EXT
INT
FLT
FLT
HOT SWAP
RESET
LED MODE
2
FA N T RAY
www.fortinet.com
Introduction
FortiGate-5000 Series
USB
CONSOLE
5
PWR
ACC
USB
CONSOLE
4
PWR
ACC
USB
CONSOLE
3
PWR
ACC
2
ETH0 ETH1
1
ETH0
Service
RESET
STATUS
5000SM
SMC
10/100
Hot Swap
link/Act
10/100
2
link/Act
1 2
ETH0 ETH1
ETH0
Service
RESET
STATUS
Hot Swap
USB
CONSOLE
RESET
STATUS
USB
CONSOLE
RESET
STATUS
1
2
3
4
5
6
7
8
STA IPM
1
2
3
4
5
6
7
8
STA IPM
1
2
3
4
5
6
7
8
STA IPM
5050SAP
5000SM
10/100
SERIAL
SERIAL
link/Act
10/100
1
2
link/Act
1
2
6
5
3
4
5
6
ALT
ON/OFF
IPM
PWR
1
2
6
3
5
4
5
6
ALT
ON/OFF
IPM
PWR
POWER
SMC
1
PSU A
PSU B

Advertisement

Table of Contents
loading

Summary of Contents for Fortinet FortiGate FortiGate-5001FA2

  • Page 1 5000SM 10/100 Hot Swap link/Act 10/100 link/Act ETH0 ETH1 ETH0 Service RESET STATUS Hot Swap RESET RESET FA N T RAY www.fortinet.com FortiGate-5000 Series CONSOLE STA IPM CONSOLE STA IPM CONSOLE STA IPM 5050SAP 5000SM 10/100 SERIAL SERIAL link/Act 10/100...
  • Page 2 FortiGate-5000 Series Introduction 7 December 2006 01-30003-0378-20061207 © Copyright 2006 Fortinet, Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet, Inc.
  • Page 3: Table Of Contents

    Warnings and cautions ... 7 About Data Center DC power ... 9 Fortinet documentation... 9 Fortinet Tools and Documentation CD ... 9 Fortinet Knowledge Center ... 9 Comments on Fortinet technical documentation ... 9 Customer service and technical support ... 9 FortiGate-5140 chassis...
  • Page 4 FortiGate-5005FA2 security system ... 21 FortiGate-5001SX security system ... 25 FortiGate-5001FA2 security system ... 29 FortiSwitch-5003 module ... 33 Front panel LEDs and connectors ... 22 LEDs ... 22 Connectors... 23 Accelerated packet forwarding and policy enforcement... 23 Base backplane gigabit communication ... 24 FortiGate-5005-DIST security system...
  • Page 5: Introduction

    Revision history • About the FortiGate-5000 series chassis • About the FortiGate-5000 series modules • Warnings and cautions • Fortinet documentation • Customer service and technical support Revision history Table 1: Revision History Version 01-30003-0378-20061207 About the FortiGate-5000 series chassis...
  • Page 6: Fortigate-5140 Chassis

    About the FortiGate-5000 series modules FortiGate-5140 chassis FortiGate-5050 chassis FortiGate-5020 chassis About the FortiGate-5000 series modules You can install up to 14 FortiGate-5000 series modules in the 14 slots of the FortiGate-5140 ATCA chassis. The FortiGate-5140 is a 12U chassis that contains two redundant hot swappable DC power entry modules that connect to -48 VDC Data Center DC power.
  • Page 7: Fortigate-5005Fa2 Module

    FortiGate security system with eight Gigabit ethernet interfaces. The FortiGate-5001FA2 module is similar to the FortiGate-5001SX module except that two of the FortiGate-5001FA2 interfaces include Fortinet technology to accelerate small packet performance. For details about the FortiGate-5001FA2 module, see on page...
  • Page 8 Refer to nameplate ratings to address this concern. • Make sure all FortiGate components have reliable grounding. Fortinet recommends direct connections to the branch circuit. • If you install a FortiGate component in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient.
  • Page 9: About Data Center Dc Power

    Fortinet Tools and Documentation CD All Fortinet documentation is available from the Fortinet Tools and Documentation CD shipped with your Fortinet product. The documents on this CD are current at shipping time. For up-to-date versions of Fortinet documentation see the Fortinet Technical Documentation web site at http://docs.forticare.com.
  • Page 10 Customer service and technical support Introduction FortiGate-5000 Series Introduction 01-30003-0378-20061207...
  • Page 11: Fortigate-5140 Chassis

    FortiGate-5140 chassis FortiGate-5140 chassis You can install up to 14 FortiGate-5000 series modules in the 14 front panel slots of the FortiGate-5140 ATCA chassis. The FortiGate-5140 is a 12U chassis that contains two redundant hot swappable DC power entry modules that connect to -48 VDC Data Center DC power.
  • Page 12 FortiGate-5140 chassis front panel Figure 1: FortiGate-5140 chassis front panel with FortiGate-5001SX, FortiGate-5001FA2, and FortiSwitch-5003 modules installed FortiGate-5001SX modules FortiSwitch-5003 slots 3, 5, 7, 9, modules 11, and 13 slots 1 and 2 5140 MANAGEMENT MANAGEMENT SYSTEM SYSTEM CONSOLE CONSOLE HOT SWAP HOT SWAP RESET...
  • Page 13: Fortigate-5140 Chassis Back Panel

    Figure 2 on page 13 back panel includes two hot-swappable redundant -48V/-60 VDC power entry modules (PEMs) labelled A and B. Fortinet ships the FortiGate-5140 chassis with PEM A and B installed. The PEMs provide redundant DC power connections for the FortiGate-5140 chassis and distribute DC power to the chassis slots and to the fan trays.
  • Page 14: Physical Description Of The Fortigate-5140 Chassis

    Physical description of the FortiGate-5140 chassis Physical description of the FortiGate-5140 chassis The back panel also includes the back cable tray, an ESD socket and the chassis ground connector. The ground connector must be connected to Data Center ground. Use the back cable tray for securing and managing DC power, RTN, and ground wires.
  • Page 15: Fortigate-5050 Chassis

    FortiGate-5050 chassis FortiGate-5050 chassis You can install up to five FortiGate-5000 series modules in the five slots of the FortiGate-5050 ATCA chassis. The FortiGate-5050 is a 5U 19-inch rackmount ATCA chassis that contains two redundant DC power connections that connect to -48 VDC Data Center DC power.
  • Page 16: Fortigate-5050 Back Panel

    FortiGate-5050 back panel FortiGate-5050 back panel Also visible on the front of the FortiGate-5050: • The location of the hot swappable FortiGate-5050 cooling fan tray behind panel. • Power LED. • ESD socket, used for connecting an ESD wrist or ankle band when working with the chassis.
  • Page 17: Physical Description Of The Fortigate-5050 Chassis

    FortiGate-5050 chassis The back panel also contains 5 backplane slots, which are numbered to correspond to the front panel slots. The backplane slots are used by some FortiGate-5000 series modules for various functions. When the FortiGate-5050 chassis is shipped, these slots are covered by backplane slot filler panels. Physical description of the FortiGate-5050 chassis The FortiGate-5050 chassis is a 5U chassis that can be installed in a standard 19-inch rack.
  • Page 18 Physical description of the FortiGate-5050 chassis FortiGate-5050 chassis FortiGate-5000 Series Introduction 01-30003-0378-20061207...
  • Page 19: Fortigate-5020 Chassis

    FortiGate-5020 chassis FortiGate-5020 chassis You can install one or two FortiGate-5000 series modules in the two slots of the FortiGate-5020 ATCA chassis. The FortiGate-5020 is a 4U chassis that contains two redundant AC to DC power supplies that connect to AC power. The FortiGate-5020 chassis also includes an internal cooling fan tray.
  • Page 20: Fortigate-5020 Back Panel

    FortiGate-5020 back panel FortiGate-5020 back panel Physical description of the FortiGate-5020 chassis Figure 6 shows the back of a FortiGate-5020 chassis. The chassis back panel includes two redundant AC power connectors and provides access to the hot swappable cooling fan tray. Each AC power connector includes a 25 Amp circuit breaker that also functions as the on/off switch for the AC power connector.
  • Page 21: Fortigate-5005Fa2 Security System

    FortiGate-5005FA2 security system FortiGate-5005FA2 security system The FortiGate-5005FA2 security system is a high-performance FortiGate security system with a total of 8 front panel Gigabit ethernet interfaces, two base backplane interfaces, and two fabric backplane interfaces. Use the front panel interfaces for connections to your networks and the backplane interfaces for communication between FortiGate-5000 series modules over the FortiGate-5000 chassis backplane.
  • Page 22: Front Panel Leds And Connectors

    The front panel also includes the RJ-45 console port for connecting to the FortiOS CLI and two USB ports. The USB ports can be used with a Fortinet USB key. For information about using the FortiUSB key, see the Series Firmware and FortiUSB Guide.
  • Page 23: Connectors

    FortiGate-5005FA2 security system Table 5: FortiGate-5005FA2 module LEDs (Continued) 1, 2, 3, 4, 5, 6, 7, 8 Connectors Table 6 Table 6: FortiGate-5005FA2 connectors Connector Type 1, 2, 3, 4, 5, 6 7, 8 CONSOLE RJ-45 Accelerated packet forwarding and policy enforcement FortiGate-5005FA2 Accelerated packet forwarding and policy enforcement results in accelerated small packet performance required for voice, video, and other multimedia streaming applications.
  • Page 24: Base Backplane Gigabit Communication

    Base backplane gigabit communication Base backplane gigabit communication FortiGate-5005-DIST security system • Firewall and intrusion protection (IPS), when there is a reasonable percentage of P2P packets. • Firewall, intrusion protection (IPS), and antivirus, when there is a reasonable percentage of P2P packets. •...
  • Page 25: Fortigate-5001Sx Security System

    FortiGate-5001SX security system FortiGate-5001SX security system The FortiGate-5001SX security system is a high-performance FortiGate security system with a total of 8 front panel Gigabit ethernet interfaces and two base backplane interfaces. Use the front panel interfaces for connections to your networks and the backplane interfaces for communication between FortiGate-5000 series modules over the FortiGate-5000 chassis backplane.
  • Page 26: Front Panel Leds And Connectors

    The front panel also includes the RS-232 console port for connecting to the FortiOS CLI and a USB port. The USB port can be used with a Fortinet USB key. For information about using the FortiUSB key, see the Firmware and FortiUSB Guide.
  • Page 27: Connectors

    FortiGate-5001SX security system Connectors Table 8 Table 8: FortiGate-5001SX connectors Connector Type 1, 2, 3, 4 5, 6, 7, 8 CONSOLE DB-9 Base backplane gigabit interfaces The FortiGate-5001SX port9 and port10 base backplane gigabit interfaces can be used for HA heartbeat communication between FortiGate-5001SX modules installed in the same or in different FortiGate-5000 chassis.
  • Page 28 Base backplane gigabit interfaces FortiGate-5001SX security system FortiGate-5000 Series Introduction 01-30003-0378-20061207...
  • Page 29: Fortigate-5001Fa2 Security System

    FortiGate-5001FA2 security system FortiGate-5001FA2 security system The FortiGate-5001FA2 security system is a high-performance FortiGate security system with a total of 8 front panel Gigabit ethernet interfaces and two base backplane interfaces. Use the front panel interfaces for connections to your networks and the backplane interfaces for communication between FortiGate-5000 series modules over the FortiGate-5000 chassis backplane.
  • Page 30: Front Panel Leds And Connectors

    The front panel also includes the RS-232 console port for connecting to the FortiOS CLI and a USB port. The USB port can be used with a Fortinet USB key. For information about using the FortiUSB key, see the Firmware and FortiUSB Guide.
  • Page 31: Connectors

    FortiGate-5001FA2 security system Connectors Table 10 Table 10: FortiGate-5001FA2 connectors Connector Type 1 and 2 3 and 4 5, 6, 7, 8 CONSOLE DB-9 Accelerated packet forwarding and policy enforcement FortiGate-5001FA2 Accelerated packet forwarding and policy enforcement results in accelerated small packet performance required for voice, video, and other multimedia streaming applications.
  • Page 32: Base Backplane Gigabit Communication

    Base backplane gigabit communication Base backplane gigabit communication • Firewall and antivirus only applications. Traffic will not be off-loaded to the FortiGate-5001FA2 accelerator module. The result will be high CPU usage because of the high CPU requirement for antivirus scanning. The FortiGate-5001FA2 port9 and port10 base backplane gigabit interfaces can be used for HA heartbeat communication between FortiGate-5001FA2 modules installed in the same or in different FortiGate-5000 chassis.
  • Page 33: Fortiswitch-5003 Module

    FortiSwitch-5003 module FortiSwitch-5003 module The FortiSwitch-5003 module provides base backplane interface switching for the FortiGate-5140 chassis and the FortiGate-5050 chassis. You can use this switching for data communication or HA heartbeat communication between the base backplane interfaces of FortiGate-5000 series modules installed in slots 3 and up in these chassis.
  • Page 34: Leds

    Front panel LEDs and connectors LEDs Figure 10: FortiSwitch-5003 front panel Power LED Management CONSOLE 100Base-TX RJ-45 Ethernet Serial Extraction ZRE0 ZRE1 ZRE2 Out of Lever base backplane interfaces Service LED Mounting 10/100/1000Base-T Knot Ethernet Table 11 lists and describes the FortiSwitch-5003 module front panel LEDs. Table 11: FortiSwitch-5003 module front panel LEDs and switches State Description...
  • Page 35: About The Zre Network Activity Leds

    FortiSwitch-5003 module Table 11: FortiSwitch-5003 module front panel LEDs and switches (Continued) EXT FLT INT FLT Hot Swap Reset switch About the ZRE network activity LEDs The ZRE network activity LEDs show links and network activity for the interfaces and connections listed in Figure 11: FortiSwitch-5003 ZRE network activity LEDs Table 12: ZRE network activity LEDs FortiSwitch-5003 interfaces and connections ZRE network...
  • Page 36: Connectors

    Base backplane communications Connectors Base backplane communications Table 13 lists and describes the FortiSwitch-5003 front panel connectors. Table 13: FortiSwitch-5003 connectors Connector Type Speed Protocol ETH0 RJ-45 100Base-T Ethernet CONSOLE RJ-45 9600 bps RS-232 serial ZRE0, RJ-45 10/100/1000 Ethernet Base-T ZRE1, ZRE2 This section provides a brief introduction to using FortiSwitch-5003 modules for...
  • Page 37 FortiSwitch-5003 module In a single chassis, more than one cluster can use the same base backplane interface for HA heartbeat communication. To separate heartbeat communication for multiple clusters on the same base backplane interface, configure a different HA group name and password for each cluster. In a single chassis, you can also use the same base backplane interface for data and HA heartbeat communication.
  • Page 38 Base backplane communications FortiSwitch-5003 module FortiGate-5000 Series Introduction 01-30003-0378-20061207...
  • Page 39 www.fortinet.com...

Table of Contents