Fortinet FortiGate 310B Install Manual

Fortinet FortiGate 310B Install Manual

Fortios 3.0 mr6
Hide thumbs Also See for FortiGate 310B:
Table of Contents

Advertisement

Quick Links

I N S T A L L G U I D E
FortiGate-310B
FortiOS 3.0 MR6
www.fortinet.com

Advertisement

Table of Contents
loading

Summary of Contents for Fortinet FortiGate 310B

  • Page 1 I N S T A L L G U I D E FortiGate-310B FortiOS 3.0 MR6 www.fortinet.com...
  • Page 2 FortiOS 3.0 MR6 15 August 2008 01-30006-0472-20080815 © Copyright 2008 Fortinet, Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet, Inc.
  • Page 3: Table Of Contents

    Document conventions... 9 Typographic conventions ... 9 Further Reading ... 9 Fortinet Knowledge Center ... 10 Comments on Fortinet technical documentation ... 11 Customer service and technical support ... 11 Environmental specifications... 13 Cautions and warnings ... 14 Grounding ... 14 Rack mount instructions ...
  • Page 4 Configuring Transparent mode... 26 Using the web-based manager ... 26 Switching to Transparent mode... 26 Configure a DNS server ... 26 Adding firewall policies ... 26 Using the CLI ... 27 Switching to Transparent mode... 27 Configure a DNS server ... 28 Adding firewall policies ...
  • Page 5 Contents Using the web-based manager... 46 Upgrading the firmware ... 46 Reverting to a previous version... 46 Backup and Restore from a USB key ... 47 Using the USB Auto-Install... 47 Using the CLI... 48 Reverting to a previous version... 49 Installing firmware from a system reboot using the CLI...
  • Page 6 Contents FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 7: Register Your Fortigate Unit

    Introduction Introduction Welcome and thank you for selecting Fortinet products for your real-time network protection. The FortiGate Unified Threat Management System improves network security, reduces network misuse and abuse, and helps you use communications resources more efficiently without compromising the performance of your network.
  • Page 8: About The Fortigate-310B

    About the FortiGate-310B About the FortiGate-310B LACP configuration About this document The FortiGate-310B is designed to raise the expectations of mid-range security devices. Incorporating FortiASIC network processors for firewall/VPN acceleration and the FortiASIC Content Processor for content inspection acceleration, the FortiGate-310B yields unmatched multi-threat performance metrics.
  • Page 9: Document Conventions

    CLI command syntax Document names Menu commands Program output Variables Further Reading The most up-to-date publications and previous releases of Fortinet product documentation are available from the Fortinet Technical Documentation web site at http://docs.forticare.com. The following FortiGate • FortiGate QuickStart Guide Provides basic information about connecting and installing a FortiGate unit.
  • Page 10: Fortinet Knowledge Center

    Describes how to configure VLANs and VDOMS in both NAT/Route and Transparent mode. Includes detailed examples. The Knowledge Center contains troubleshooting and how-to articles, FAQs, technical notes, and more. Visit the Fortinet Knowledge Center at http://kc.forticare.com. Introduction Center, the FortiGate Log FortiGate-310B FortiOS 3.0 MR6 Install Guide...
  • Page 11: Comments On Fortinet Technical Documentation

    Please send information about any errors or omissions in this document, or any Fortinet technical documentation, to techdoc@fortinet.com. Customer service and technical support Fortinet Technical Support provides services designed to make sure that your Fortinet systems install quickly, configure easily, and operate reliably in your network.
  • Page 12 Customer service and technical support Introduction FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 13: Environmental Specifications

    Installing Installing This chapter describes installing your FortiGate unit in your server room, environmental specifications and how to mount the FortiGate in a rack if applicable. This chapter contains the following topics: • Environmental specifications • Cautions and warnings • Plugging in the FortiGate •...
  • Page 14: Cautions And Warnings

    Cautions and warnings Cautions and warnings Grounding Rack mount instructions Mounting • Connect the equipment into an outlet on a circuit different from that to which the receiver is connected. • Consult the dealer or an experienced radio/TV technician for help. The equipment compliance with FCC radiation exposure limit set forth for uncontrolled Environment.
  • Page 15 Installing When placing the FortiGate unit on any flat, stable surface, ensure the unit has at least 1.5 inches (3.75 cm) of clearance on each side to ensure adequate airflow for cooling. For rack mounting, use the mounting brackets and screws included with the FortiGate unit.
  • Page 16: Plugging In The Fortigate

    Plugging in the FortiGate Plugging in the FortiGate Connecting to the network Turning off the FortiGate unit Figure 3: Mounting in a rack Use the following steps to connect the power supply to the FortiGate unit. To power on the FortiGate unit Ensure the power switch, located at the back of the FortiGate unit is in the off position, indicated by the “O”.
  • Page 17: Nat Vs. Transparent Mode

    Configuring Configuring This section provides an overview of the operating modes of the FortiGate unit, NAT/Route and Transparent, and how to configure the FortiGate unit for each mode. There are two ways you can configure the FortiGate unit, using the web-based manager or the command line interface (CLI).
  • Page 18: Transparent Mode

    Connecting to the FortiGate unit Transparent mode Connecting to the FortiGate unit Connecting to the web-based manager In Transparent mode, the FortiGate unit is invisible to the network. Similar to a network bridge, all FortiGate interfaces must be on the same subnet. You only have to configure a management IP address to make configuration changes.
  • Page 19: Connecting To The Cli

    Configuring To support a secure HTTPS authentication method, the FortiGate unit ships with a self-signed security certificate, which is offered to remote clients whenever they initiate a HTTPS connection to the FortiGate unit. When you connect, the FortiGate unit displays two security warnings in a browser. The first warning prompts you to accept and optionally install the FortiGate unit’s self-signed security certificate.
  • Page 20: Configuring Nat Mode

    Configuring NAT mode Configuring NAT mode Using the web-based manager Configuring NAT mode involves defining interface addresses and default routes, and simple firewall policies. You can use the web-based manager or the CLI to configure the FortiGate unit in NAT/Route mode. After connecting to the web-based manager, you can use the following procedures to complete the basic configuration of the FortiGate unit.
  • Page 21: Configure A Dns Server

    Internet. A DNS server matches domain names with the computer IP address. This enables you to use readable locations, such as fortinet.com when browsing the Internet. DNS server IP addresses are typically provided by your internet service provider.
  • Page 22: Adding Firewall Policies

    Configuring NAT mode For an initial configuration, you must edit the factory configured static default route to specify a different default gateway for the FortiGate unit. This will enable the flow of data through the FortiGate unit. For details on adding additional static routes, see the FortiGate Administration Guide.
  • Page 23: Using The Cli

    Configuring Set the following and select OK. Source Interface Source Address Destination Interface Select the port connected to the network. Destination Address All Schedule Service Action Firewall policy configuration is the same in NAT/Route mode and Transparent mode. Note that these policies allow all traffic through. No protection profiles have been applied.
  • Page 24: Configure A Dns Server

    Internet. A DNS server matches domain names with the computer IP address. This enables you to use readable locations, such as fortinet.com when browsing the Internet. DNS server IP addresses are typically provided by your internet service provider.
  • Page 25: Adding Firewall Policies

    Configuring In the factory default configuration, entry number 1 in the Static Route list is associated with a destination address of 0.0.0.0/0.0.0.0, which means any/all destinations. This route is called the "static default route". If no other routes are present in the routing table and a packet needs to be forwarded beyond the FortiGate unit, the factory configured static default route causes the FortiGate unit to forward the packet to the default gateway.
  • Page 26: Configuring Transparent Mode

    Internet. A DNS server matches domain names with the computer IP address. This enables you to use readable locations, such as fortinet.com when browsing the Internet. DNS server IP addresses are typically provided by your internet service provider.
  • Page 27: Using The Cli

    Configuring For the initial installation, a single firewall policy that enables all traffic through will enable you to verify your configuration is working. On lower-end units such a default firewall policy is already in place. For the higher end FortiGate units, you will need to add a firewall policy.
  • Page 28: Configure A Dns Server

    Internet. A DNS server matches domain names with the computer IP address. This enables you to use readable locations, such as fortinet.com when browsing the Internet. DNS server IP addresses are typically provided by your internet service provider.
  • Page 29: Verify The Configuration

    Configuring Note that these policies allow all traffic through. No protection profiles have been applied. Ensure you create additional firewall policies to accommodate your network requirements. Verify the configuration Your FortiGate unit is now configured and connected to the network. To verify the FortiGate unit is connected and configured correctly, use your web browser to browse a web site, or use your email client to send and receive email.
  • Page 30: Restoring A Configuration

    Restoring a configuration Restoring a configuration Additional configuration Set the time and date Set the Administrator password Should you need to restore the configuration file, use the following steps. To restore the FortiGate configuration Go to System > Maintenance > Backup & Restore. Select to upload the restore file from your PC or a USB key.
  • Page 31: Configure Fortiguard

    FortiGate unit. Before you can begin receiving updates, you must register your FortiGate unit from the Fortinet web page. For information about registering your FortiGate unit, “Register your FortiGate unit” on page...
  • Page 32 Additional configuration Configuring FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 33: Protection Profiles

    Advanced configuration Advanced configuration The FortiGate unit and the FortiOS operating system provide a wide range of features that enable you to control network and internet traffic and protect your network. This chapter describes some of these options and how to configure them.
  • Page 34: Firewall Policies

    Firewall policies Firewall policies Apply virus scanning and web content blocking to HTTP traffic. Unfiltered Apply no scanning, blocking or IPS. Use the unfiltered content profile if no content protection for content traffic is required. Add this protection profile to firewall policies for connections between highly trusted or highly secure networks where content does not need to be protected.
  • Page 35: Configuring Firewall Policies

    • Virus scan - The virus definitions are kept up to date through the FortiNet Distribution Network. The list is updated on a regular basis so you do not have to wait for a firmware upgrade. Note that you must register the FortiGate unit to and purchase FortiGuard services to use virus scanning through the FDN.
  • Page 36: Antispam Options

    FortiGuard is an antispam system from Fortinet that includes an IP address black list, a URL black list, and spam filtering tools. The FortiGuard Center accepts submission of spam email messages as well as well as reports of false positives.
  • Page 37: Web Filtering

    Advanced configuration Banned word lists are specific words that may be typically found in email. The FortiGate unit searches for words or patterns in email messages. If matches are found, values assigned to the words are totalled. If the defined threshold value is exceeded, the message is marked as spam.
  • Page 38: Logging

    To configure URL filters, go to Web Filter > URL Filter. FortiGuard web filtering is a managed web filtering solution provided by Fortinet. FortiGuard web filtering sorts hundreds of millions of web pages into a wide range of categories users can allow, block, or monitor.
  • Page 39: Installing Amc Filler Units

    AMC modules AMC modules FortiGate AMC modules enable you to expand your FortiGate unit and network environment. These modules enable you to provide small packet performance though optical or copper transceivers. A hard disk module enables you to quarantine files and store log information. Modules are available in single-width and double-width components.
  • Page 40: Removing Modules

    Remove the panel block on the FortiGate unit using the hot swap latch. Pull the latch on the module to the extended position. Insert the FortiGate module into the empty slot in the chassis. Ensure the Fortinet logo is right-side up. It should be on the upper-right corner of the module.
  • Page 41: Formatting The Hard Disk

    AMC modules Note: The FortiGate-3810A supports only one FortiGate-ASM-S08 hard disk module. Formatting the hard disk When you first install the ASM-S08 in the FortiGate unit, the hard disk may not be formatted. This will result in an error in the console when starting up the FortiGate unit, indicating that the hard drive could not be mounted.
  • Page 42: Log Configuration Using The Cli

    Using the AMC modules ASM-FB4 and ADM-XB2 modules Upload rolled files in Select to compress the log files before uploading. gzipped format Delete files after Select to remove the log files once the FTP upoad has completed. uploading Log configuration using the CLI Configure the FortiGate unit to log to the ASM-S08 using the CLI within the FortiAnalyzer command config log disk setting enable.
  • Page 43: Configure The Speed

    You must also ensure the speed for the interface is correct for the installed transceiver. Forcing the speed could result in link failure and disrupted service. Fortinet recommends enabling link speed auto negotiation by setting speed to auto. Use the following command to configure the auto speed setting: config system interface FortiGate-310B FortiOS 3.0 MR6 Install Guide...
  • Page 44 Using the AMC modules AMC modules FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 45: Downloading Firmware

    • Testing new firmware before installing Downloading firmware Firmware images for all FortiGate units is available on the Fortinet Customer Support web site. You must register your FortiGate unit to access firmware images. Register the FortiGate unit by visiting select Product Registration.
  • Page 46: Using The Web-Based Manager

    Using the web-based manager Using the web-based manager Upgrading the firmware Reverting to a previous version To download firmware Log into the site using your user name and password. Go to Firmware Images > FortiGate. Select the most recent FortiOS version, and MR release and patch release. Locate the firmware for your FortiGate unit, right-click the link and select the Download option for your browser.
  • Page 47: Backup And Restore From A Usb Key

    FortiGate Firmware Note: To use this procedure, you must log in using the admin administrator account, or an administrator account that has system configuration read and write privileges. To revert to a previous firmware version Copy the firmware image file to the management computer. Log into the FortiGate web-based manager.
  • Page 48: Using The Cli

    Using the CLI Using the CLI Note: You need an unencrypted configuration file for this feature. Also the default files, image.out and system.conf, must be in the root directory of the USB key. Note: Make sure at least FortiOS v3.0MR1 is installed on the FortiGate unit before installing.
  • Page 49: Reverting To A Previous Version

    FortiGate Firmware Enter the following command to copy the firmware image from the TFTP server to the FortiGate unit: execute restore image <name_str> <tftp_ip4> Where <name_str> is the name of the firmware image file and <tftp_ip4> is the IP address of the TFTP server. For example, if the firmware image file name is image.out and the IP address of the TFTP server is 192.168.1.168, enter: execute restore image image.out 192.168.1.168 The FortiGate unit responds with the message:...
  • Page 50: Installing Firmware From A System Reboot Using The Cli

    Installing firmware from a system reboot using the CLI Installing firmware from a system reboot using the CLI Make sure the FortiGate unit can connect to the TFTP server. You can use the following command to ping the computer running the TFTP server.
  • Page 51 FortiGate Firmware If you are reverting to a previous FortiOS version, you might not be able to restore the previous configuration from the backup configuration file. Note: Installing firmware replaces your current antivirus and attack definitions, along with the definitions included with the firmware release you are installing. After you install new firmware, make sure that antivirus and attack definitions are up to date.
  • Page 52: Restoring The Previous Configuration

    Installing firmware from a system reboot using the CLI Restoring the previous configuration Backup and Restore from a USB key Type the address of the TFTP server and press Enter: The following message appears: Enter Local Address [192.168.1.188]: Type an IP address the FortiGate unit can use to connect to the TFTP server. The IP address can be any IP address that is valid for the network the interface is connected to.
  • Page 53: Using The Usb Auto-Install

    FortiGate Firmware To restore configuration using the CLI Log into the CLI. Enter the following command to restore the configuration files: exec restore image usb <filename> The FortiGate unit responds with the following message: This operation will replace the current firmware version! Do you want to continue? (y/n) Type y.
  • Page 54: Testing New Firmware Before Installing

    Testing new firmware before installing Testing new firmware before installing You can test a new firmware image by installing the firmware image from a system reboot and saving it to system memory. After completing this procedure, the FortiGate unit operates using the new firmware image with the current configuration.
  • Page 55 FortiGate Firmware Type G to get the new firmware image from the TFTP server. The following message appears: Enter TFTP server address [192.168.1.168]: Type the address of the TFTP server and press Enter: The following message appears: Enter Local Address [192.168.1.188]: Type an IP address of the FortiGate unit to connect to the TFTP server.
  • Page 56 Testing new firmware before installing FortiGate Firmware FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 57 54 testing new firmware 54 upgrade from CLI 48 upgrade with web-based manager 46 upgrading using the CLI 48 FortiGuard 31 Fortinet Knowledge Center 10 further reading 9 gateway 21, 24 grounding 14 humidity 13 Initial Disc Timeout 20...
  • Page 58 PADT timeout 21 password, changing 30 power off 16 PPPoE 24 protection profiles 33 registering 7 restore 30 restoring previous firmware configuration 52 reverting firmware 46 security certificate 19 shielded twisted pair 14 shut down 16 signatures, update 31 static route 21, 25 system reboot, installing 50 technical support 11 TFTP server 50...
  • Page 59 Index FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 60 Index FortiGate-310B FortiOS 3.0 MR6 Install Guide 01-30006-0472-20080815...
  • Page 61 www.fortinet.com...
  • Page 62 www.fortinet.com...

This manual is also suitable for:

Fortigate-310bFortios 3.0 mr6

Table of Contents