FortiGate 100 Installation Guide POWER INTERNAL EXTERNAL STATUS Version 2.80 MR4 30 August 2004 01-28004-0019-20040830...
Page 2
Products mentioned in this document are trademarks or registered trademarks of their respective holders. Regulatory Compliance FCC Class A Part 15 CSA/CUS For technical support, please visit http://www.fortinet.com. Send information about errors or omissions in this document or any Fortinet technical documentation to techdoc@fortinet.com.
Command line interface ... 6 Setup wizard ... 7 Document conventions ... 7 Fortinet documentation ... 8 Comments on Fortinet technical documentation... 9 Customer service and technical support... 10 Getting started ... 11 Package contents ... 12 Mounting ... 12 Turning the FortiGate unit power on and off ...
Page 4
High availability configuration settings ... 45 Configuring FortiGate units for HA using the web-based manager ... 47 Configuring FortiGate units for HA using the CLI... 48 Connecting the cluster to your networks... 49 Installing and configuring the cluster... 51 Index ... 53 01-28004-0019-20040830 Fortinet Inc.
• • The FortiGate Antivirus Firewall uses Fortinet’s Accelerated Behavior and Content Analysis System (ABACAS™) technology, which leverages breakthroughs in chip design, networking, security, and content analysis. The unique ASIC-based architecture analyzes content and behavior in real-time, enabling key applications to be deployed right at the network edge where they are most effective at protecting your networks.
This Installation Guide contains information about basic and advanced CLI commands. For a more complete description about connecting to and using the FortiGate CLI, see the FortiGate CLI Reference Guide. 01-28004-0019-20040830 Introduction Fortinet Inc.
Introduction Setup wizard The FortiGate setup wizard provides an easy way to configure the basic initial settings for the FortiGate unit. The wizard walks through the configuration of a new administrator password, FortiGate interfaces, DHCP server settings, internal servers (web, FTP, etc.), and basic antivirus settings. Document conventions This guide uses the following conventions to describe command syntax.
Setup wizard • Fortinet documentation Information about FortiGate products is available from the following FortiGate User Manual volumes: • • • • • • A space to separate options that can be entered in any combination and must be separated by spaces.
FortiGate unit. For a complete list of FortiGate documentation visit Fortinet Technical Support at http://support.fortinet.com. Comments on Fortinet technical documentation You can send information about errors or omissions in this document, or any Fortinet technical documentation, to techdoc@fortinet.com. FortiGate-100 Installation Guide...
Fortinet technical support web site at http://support.fortinet.com. You can also register FortiGate Antivirus Firewalls from http://support.fortinet.com and change your registration information at any time. Fortinet email support is available from the following addresses: amer_support@fortinet.com For customers in the United States, Canada, Mexico, Latin...
Getting started This section describes unpacking, setting up, and powering on a FortiGate Antivirus Firewall unit. This section includes: • • • • • • • • FortiGate-100 Installation Guide FortiGate-100 Installation Guide Version 2.80 MR4 Package contents Mounting Turning the FortiGate unit power on and off Connecting to the web-based manager Connecting to the command line interface (CLI) Factory default FortiGate configuration settings...
Power requirements • • FortiGate-100 Antivirus Firewall one orange crossover ethernet cable (Fortinet part number CC300248) one gray regular ethernet cable (Fortinet part number CC300249) one null modem cable (Fortinet part number CC300247) FortiGate-100 Quick Start Guide CD containing the FortiGate user documentation...
Getting started Environmental specifications • • • Turning the FortiGate unit power on and off To power on the FortiGate unit Connect the AC adapter to the power connection at the back of the FortiGate-100 unit. Connect the AC adapter to the power cable. Connect the power cable to a power outlet.
FortiGate unit using the CLI. Configuration changes made with the CLI are effective immediately without resetting the firewall or interrupting service. a computer with an ethernet connection, Internet Explorer version 4.0 or higher, a crossover cable or an ethernet hub and two ethernet cables. 01-28004-0019-20040830 Getting started Fortinet Inc.
Page 15
Getting started To connect to the FortiGate CLI, you need: • • • Note: The following procedure describes how to connect to the CLI using Windows HyperTerminal software. You can use any terminal emulation program. To connect to the CLI Connect the null modem cable to the communications port of your computer and to the FortiGate Console port.
Select from any of the 50 pre-defined services to control traffic through the FortiGate unit that uses that service. The recurring schedule is valid at any time. Control how the FortiGate unit applies virus scanning, web content filtering, spam filtering, and IPS. Fortinet Inc.
Getting started The FortiGate unit comes preconfigured with four protection profiles. Strict Scan Unfiltered Figure 4: Web protection profile settings Planning the FortiGate configuration Before you configure the FortiGate unit, you need to plan how to integrate the unit into the network.
NAT/Route mode NAT/Route mode In NAT/Route mode, the FortiGate unit is visible to the network. Like a router, all its interfaces are on different subnets. The following interfaces are available in NAT/Route mode: • • • You can add firewall policies to control whether communications through the FortiGate unit operate in NAT or Route mode.
The management IP address is also used for antivirus and attack definition updates. You typically use the FortiGate unit in Transparent mode on a private network behind an existing firewall or behind a router. The FortiGate unit performs firewall functions, IPSec VPN, virus scanning, IPS, web content filtering, and Spam filtering.
DNS server IP addresses add the DHCP server settings and IP addresses add various internal server IP addresses including web, IMAP, POP3, SMTP, and FTP servers set the antivirus protection to high, medium, or none 01-28004-0019-20040830 Getting started Fortinet Inc.
Getting started Next steps Now that your FortiGate unit is operating, you can proceed to configure it to connect to networks: • • • FortiGate-100 Installation Guide If you are going to operate the FortiGate unit in NAT/Route mode, go to “NAT/Route mode installation”...
Page 24
Configuration options Getting started 01-28004-0019-20040830 Fortinet Inc.
NAT/Route mode installation This chapter describes how to install the FortiGate unit in NAT/Route mode. For information about installing a FortiGate unit in Transparent mode, see mode installation” on page units in HA mode, see about installing the FortiGate unit in NAT/Route mode, see configuration”...
The default gateway directs all non-local traffic to this interface and to the external network. Primary DNS Server: Secondary DNS Server: 01-28004-0019-20040830 NAT/Route mode installation _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ Table 6 “Connecting to the Fortinet Inc.
NAT/Route mode installation Configuring basic settings After connecting to the web-based manager you can use the following procedures to complete the basic configuration of the FortiGate unit. To add/change the administrator password Go to System > Admin > Administrators. Select the Change Password icon for the admin administrator. Enter the new password and enter it again to confirm.
The default route is not required if the interface connected to the external network is configured using DHCP or PPPoE. Go to System > Router > Static. If the Static Route table contains a default route (IP and Mask set to 0.0.0.0), select the Delete icon to delete this route.
Page 29
NAT/Route mode installation To configure interfaces Log in to the CLI. Set the IP address and netmask of the internal interface to the internal IP address and netmask that you recorded in Example Set the IP address and netmask of the external interface to the external IP address and netmask that you recorded in Example To set the external interface to use DHCP, enter:...
Page 30
Set the default route to the Default Gateway IP address. Enter: config router static edit 1 set dst 0.0.0.0 0.0.0.0 set gateway <gateway_IP> set device <interface> config router static edit 1 set dst 0.0.0.0 0.0.0.0 set gateway 204.23.1.2 set device external 01-28004-0019-20040830 NAT/Route mode installation Fortinet Inc.
NAT/Route mode installation Using the setup wizard From the web-based manager, you can use the setup wizard to complete the initial configuration of the FortiGate unit. For information about connecting to the web-based manager, see If you are configuring the FortiGate unit to operate in NAT/Route mode (the default), you can use the setup wizard to: •...
Create a protection profile that enables virus scanning, for HTTP, FTP, IMAP, POP3, and SMTP (recommended). Add this protection profile to a default firewall policy. Do not configure antivirus protection. to fill in the wizard fields. Fortinet Inc.
Page 33
Connect the Internal interface to the hub or switch connected to your internal network. Connect the External interface to the Internet. Connect to the public switch or router provided by your Internet Service Provider. If you are a DSL or cable subscriber, connect the External interface to the internal or LAN connection of your DSL or cable modem.
For the DMZ network, change the default gateway address of all computers and routers connected directly to your DMZ network to the IP address of the FortiGate DMZ interface. For the external network, route all packets to the FortiGate external interface. 01-28004-0019-20040830 NAT/Route mode installation Fortinet Inc.
Page 35
After purchasing and installing a new FortiGate unit, you can register the unit by going to the System Update Support page, or using a web browser to connect to http://support.fortinet.com and selecting Product Registration. To register, enter your contact information and the serial numbers of the FortiGate units that you or your organization have purchased.
Page 36
Reconnecting to the web-based manager NAT/Route mode installation 01-28004-0019-20040830 Fortinet Inc.
Transparent mode installation This chapter describes how to install a FortiGate unit in Transparent mode. If you want to install the FortiGate unit in NAT/Route mode, see page availability installation” on page FortiGate unit in Transparent mode, see page This chapter describes: •...
The management IP address and netmask must be valid for the network from which you will manage the FortiGate unit. Add a default gateway if the FortiGate unit must connect to a router to reach the management computer. Primary DNS Server: Secondary DNS Server: _____._____._____._____...
Otherwise, you can reconnect to the web-based manager by browsing to https://10.10.10.1. If you connect to the management interface through a router, make sure that you have added a default gateway for that router to the management IP default gateway field.
Page 40
<address_ip> set secondary <address_ip> config system dns set primary 293.44.75.21 set secondary 293.44.75.22 config router static edit 1 set dst 0.0.0.0 0.0.0.0 set gateway <address_gateway> set device <interface> 01-28004-0019-20040830 Transparent mode installation Table 8 on page Fortinet Inc.
Otherwise, you can reconnect to the web-based manager by browsing to https://10.10.10.1. If you connect to the management interface through a router, make sure that you have added a default gateway for that router to the management IP default gateway field.
Connect the External interface to network segment connected to the external firewall or router. Connect to the public switch or router provided by your Internet Service Provider. Connect the DMZ interface to another network. Figure 10: FortiGate-100 Transparent mode connections...
After purchasing and installing a new FortiGate unit, you can register the unit by going to the System Update Support page, or using a web browser to connect to http://support.fortinet.com and selecting Product Registration. To register, enter your contact information and the serial numbers of the FortiGate units that you or your organization have purchased.
Page 44
FDN. Select Scheduled Update and configure a schedule for receiving antivirus and attack definition updates. Select Apply. You can also select Update Now to receive the latest virus and attack definition updates. 01-28004-0019-20040830 Transparent mode installation Fortinet Inc.
High availability installation This chapter describes how to install two or more FortiGate units in an HA cluster. HA installation involves three basic steps: • • • For information about HA, see the FortiGate Administration Guide and the FortiOS High Availability technical note. Priorities of heartbeat device and monitor priorities The procedures in this chapter do not include steps for changing the priorities of heartbeat devices or for configuring monitor priorities settings.
Page 46
FortiGate unit with the highest serial number becomes the primary cluster unit. You can configure a FortiGate unit to always become the primary unit in the cluster by giving it a high priority and by selecting Override master. 01-28004-0019-20040830 High availability installation Fortinet Inc.
High availability installation Table 9: High availability settings (Continued) Schedule Configuring FortiGate units for HA using the web-based manager Use the following procedure to configure each FortiGate unit for HA operation. To change the FortiGate unit host name Changing the host name is optional, but you can use host names to identify individual cluster units.
Connect to the CLI. Change the host name. “Connecting the cluster to your networks” on page “Connecting to the command line interface (CLI)” on page config system global set hostname <name_str> 01-28004-0019-20040830 High availability installation “Connecting the cluster to your networks” Fortinet Inc.
You must connect all matching interfaces in the cluster to the same hub or switch. Then you must connect these interfaces to their networks using the same hub or switch. Fortinet recommends using switches for all cluster connections for the best performance. FortiGate-100 Installation Guide...
Page 50
LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 Hub or Switch INTERNAL STATUS WAN1 WAN2 LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 LINK 100 Internal WAN1 Internet Router Fortinet Inc.
High availability installation Power on all the FortiGate units in the cluster. As the units start, they negotiate to choose the primary cluster unit and the subordinate units. This negotiation occurs with no user intervention and normally just takes a few seconds. Installing and configuring the cluster When negotiation is complete the you can configure the cluster as if it was a single FortiGate unit.
Page 52
Configuring FortiGate units for HA using the CLI High availability installation 01-28004-0019-20040830 Fortinet Inc.
Need help?
Do you have a question about the FortiGate FortiGate-100 and is the answer not in the manual?
Questions and answers