FortiGate 5000 Series MANAGEMENT MANAGEMENT SYSTEM SYSTEM CONSOLE CONSOLE HOT SWAP HOT SWAP RESET RESET LED MODE LED MODE Installation Guide 5140 CONSOLE PWR ACC Crit. CONSOLE Maj. Min. PWR ACC CONSOLE PWR ACC Link ShMC ETH 0 Prim. ShMC Stat.
Page 2
CAUTION: RISK OF EXPLOSION IF BATTERY IS REPLACED BY AN INCORRECT TYPE. DISPOSE OF USED BATTERIES ACCORDING TO THE INSTRUCTIONS. For technical support, please visit http://www.fortinet.com. Send information about errors or omissions in this document or any Fortinet technical documentation to techdoc@fortinet.com.
FortiGate-5000 series Installation Guide Version 2.80 MR11 Introduction Welcome and thank you for selecting Fortinet products for your real-time network protection. FortiGate Antivirus Firewalls improve network security, reduce network misuse and abuse, and help you use communications resources more efficiently without compromising the performance of your network.
AC to DC power supplies that connect to AC power. The FortiGate-5020 chassis also includes an internal cooling fan tray. For details about the FortiGate-5020 chassis, see the Guide, which is a detailed guide to all three Guide. FortiGate-5000 series Hardware 01-28011-0259-20060210 Introduction FortiGate-5000 series Hardware Guide. Fortinet Inc.
Gigabit ethernet interfaces. The FortiGate-5001FA2 module is similar to the FortiGate-5001SX module except that two of the FortiGate-5001FA2 interfaces include Fortinet technology to accelerate small packet performance. For details about the FortiGate-5001FA2 module, see the Hardware...
Page 8
In most cases to make changes to lists that contain options separated by spaces, you need to retype the whole list including all the options you want to apply and excluding all the options you want to remove. 01-28011-0259-20060210 Introduction Fortinet Inc.
Fortinet technical documentation, to techdoc@fortinet.com. Customer service and technical support Fortinet Technical Support provides services designed to make sure that your Fortinet systems install quickly, configure easily, and operate reliably in your network. Please visit the Fortinet Technical Support web site at learn about the technical support services that Fortinet provides.
Page 10
Customer service and technical support Introduction 01-28011-0259-20060210 Fortinet Inc.
FortiGate-5000 series Installation Guide Version 2.80 MR11 Configuring the FortiGate for the Network This chapter provides an overview of the operating modes of the FortiGate unit. Before beginning to configure the FortiGate-5000 security system module, you need to plan how to integrate the unit into your network. Your configuration plan is dependent upon the operating mode that you select: NAT/Route mode or Transparent mode.
You typically use a FortiGate-5000 antivirus firewall module in Transparent mode on a private network behind an existing firewall or behind a router. The FortiGate-5000 module performs most of the same firewall functions in Transparent mode as in NAT/Route mode.
Page 13
FortiGate-5001SX HA Cluster in Transparent mode in a FortiGate-5020 chassis Gateway to public network 204.23.1.5 192.168.1.1 CONSOLE Internet PWR ACC CONSOLE (firewall, router) Port1 PWR ACC 01-28011-0259-20060210 Internal network Port1 192.168.1.99 PSU A PSU B CONSOLE PWR ACC...
Internet Explorer version 6.0 or higher an optical fiber patch or copper ethernet cable required to connect port 1 of the FortiGate-5000 module to your network 01-28011-0259-20060210 Configuring the FortiGate for the Network Fortinet Inc.
Page 15
Configuring the FortiGate for the Network By default, you can connect to the web-based manager using the FortiGate-5000 module port 1. If you cannot connect port 1 to your network, you can use the FortiGate CLI to add an IP address to one of the other FortiGate module ports. Note: You may not be able to connect port 1 to your network if port 1 is an optical interface and you do not have access to an optical network) you can change.
Select the following port settings and select OK. a computer with an available communications port the serial cable included in your FortiGate package terminal emulation software such as HyperTerminal for Windows 01-28011-0259-20060210 Configuring the FortiGate for the Network Fortinet Inc.
Configuring the FortiGate for the Network Bits per second 9600 Data bits Parity Stop bits Flow control Press Enter to connect to the FortiGate CLI. A prompt similar to the following is displayed: FortiGate-5001 login: Type admin and press Enter twice. The following prompt is displayed: Welcome ! Type ? to list available commands.
Page 18
Primary DNS Server: Secondary DNS Server: 01-28011-0259-20060210 Configuring the FortiGate for the Network _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ _____._____._____._____ Fortinet Inc.
Configuring the FortiGate for the Network DHCP or PPPoE configuration You can configure any FortiGate interface to acquire its IP address from a DHCP or PPPoE server. Your ISP may provide IP addresses using one of these protocols. To use the FortiGate DHCP server, you need to configure an IP address range and default route for the server.
DHCP or PPPoE. Go to System > Router > Static. If the Static Route table contains a default route (IP and Mask set to 0.0.0.0), select the Delete icon to delete this route.
Page 21
Configuring the FortiGate for the Network Configuring the FortiGate module to operate in NAT/Route mode Use the information that you gathered in procedures. To add/change the administrator password Log in to the CLI. Change the admin administrator password. Enter: To configure interfaces Log in to the CLI.
Page 22
Set the primary and secondary DNS server IP addresses. Enter config system dns set primary <address_ip> set secondary <address_ip> config system dns set primary 293.44.75.21 set secondary 293.44.75.22 01-28011-0259-20060210 Configuring the FortiGate for the Network Fortinet Inc.
Table 3: Setup wizard settings Password Internal Interface External Interface FortiGate-5000 series Installation Guide Set the default route to the Default Gateway IP address. Enter: config router static edit 1 set dst 0.0.0.0 0.0.0.0 set gateway <gateway_IP> set device <interface> config router static edit 1 set dst 0.0.0.0 0.0.0.0...
Create a protection profile that enables virus scanning, for HTTP, FTP, IMAP, POP3, and SMTP (recommended). Add this protection profile to a default firewall policy. Do not configure antivirus protection. to fill in the wizard fields. Fortinet Inc.
Figure 7: FortiGate-5001SX example NAT/Route mode connections FortiGate-5000 series Installation Guide Internal Network Hub or Switch Port 1 CONSOLE PWR ACC Port 2 Public Switch or Router Internet 01-28011-0259-20060210 NAT/Route mode installation Network Port 6 STA IPM FortiGate-5001SX Web Server...
Connecting the FortiGate unit to the network(s) Table 4 to gather the information that you need to customize Transparent mode the web-based manager GUI command line interface (CLI) setup wizard 01-28011-0259-20060210 Configuring the FortiGate for the Network “NAT/Route 32. For more Fortinet Inc.
The management IP address and netmask must be valid for the network from which you will manage the FortiGate unit. Add a default gateway if the FortiGate unit must connect to a router to reach the management computer. Primary DNS Server: Secondary DNS Server: _____._____._____._____...
Otherwise, you can reconnect to the web-based manager by browsing to https://10.10.10.1. If you connect to the management interface through a router, make sure that you have added a default gateway for that router to the management IP default gateway field.
Page 29
<address_ip> set secondary <address_ip> config system dns set primary 293.44.75.21 set secondary 293.44.75.22 config router static edit 1 set dst 0.0.0.0 0.0.0.0 set gateway <address_gateway> set device <interface> 01-28011-0259-20060210 Transparent mode installation...
Otherwise, you can reconnect to the web-based manager by browsing to https://10.10.10.1. If you connect to the management interface through a router, make sure that you have added a default gateway for that router to the management IP default gateway field.
Figure 8: FortiGate-5001SX example Transparent mode connections FortiGate-5001SX FortiGate-5000 series Installation Guide Internal Network Hub or Switch Por t 5 Port 1 CONSOLE PWR ACC Port 2 Public Switch or Router Internet 01-28011-0259-20060210 Transparent mode installation Other Network STA IPM Port 6 Other Network...
Connecting the cluster to your networks Installing and configuring the cluster High availability configuration settings Configuring FortiGate-5000 modules for HA using the web-based manager Configuring FortiGate-5000 modules for HA using the CLI 01-28011-0259-20060210 Configuring the FortiGate for the Network Fortinet Inc.
Page 33
Configuring the FortiGate for the Network Table 5: High availability settings Mode Group ID Unit priority Override Master FortiGate-5000 series Installation Guide Active-Active Load balancing and failover HA. Each FortiGate-5000 module in the HA cluster actively processes connections and monitors the status of the other FortiGate-5000 modules in the cluster.
Page 34
IP Port to distribute traffic to units in a cluster based on the Source IP, Source Port, Destination IP, and Destination port of the packet. “Connecting to the web-based manager” on page 01-28011-0259-20060210 Configuring the FortiGate for the Network Fortinet Inc.
Page 35
Configuring the FortiGate for the Network Go to System > Status. In the Host Name field of the Unit Information section, select Change. Type a new host name and select OK. To configure a FortiGate-5000 module for HA operation Go to System > Config > HA. Select High Availability.
Page 36
<password_str> set schedule {hub | ip | ipport | leastconnection | none | random | round-robin | weight-round-robin} 01-28011-0259-20060210 Configuring the FortiGate for the Network “Connecting the cluster to your networks” “Connecting the cluster to your networks” Fortinet Inc.
Configuring the FortiGate for the Network Allow the FortiGate-5000 module to restart in Transparent mode. Repeat this procedure for all of the FortiGate-5000 modules in the cluster then continue with Using the FortiSwitch-5003 in an HA cluster The FortiSwitch-5003 module is an HA component designed for use in the FortiGate-5050 and FortiGate-5140 chassis to provide full HA clustering capabilities between FortiGate-5000 modules.
Page 38
PSU B STA IPM STA IPM Port 3 Internet Port 3 STA IPM Port 3 STA IPM Port 3 STA IPM POWER CRITICAL MAJOR HOT SWAP ShMC STATUS ALARM MINOR ALARMS RESET Hub or Switch Router Internet Router Fortinet Inc.
Configuring the FortiGate for the Network Installing and configuring the cluster When negotiation is complete the you can configure the cluster as if it was a single FortiGate-5000 module. • • The configurations of all of the FortiGate-5000 in the cluster are synchronized so that the FortiGate-5000 modules can function as a cluster.
FortiGate unit. 01-28011-0259-20060210 Configuring the FortiGate for the Network CONSOLE PWR ACC CONSOLE PWR ACC CONSOLE PWR ACC POWER ShMC STA IPM STA IPM STA IPM POWER CRITICAL MAJOR HOT SWAP ShMC STATUS MINOR ALARM ALARMS RESET Fortinet Inc.
After purchasing and installing a new FortiGate appliances, you can register them by going to the System Update Support page, or using a web browser to connect to http://support.fortinet.com and selecting Product Registration. To register, enter your contact information and the serial numbers of the FortiGate chassis and modules that you or your organization has purchased.
Page 42
Next steps Configuring the FortiGate for the Network 01-28011-0259-20060210 Fortinet Inc.
FortiGate administrators whose access profiles contain system configuration read and write privileges and the FortiGate admin user can change the FortiGate firmware. After you download a FortiGate firmware image from Fortinet, you can use the procedures listed in module.
To upgrade the firmware using the CLI Make sure that the TFTP server is running. Copy the new firmware image file to the root directory of the TFTP server. the FortiGate Administration Guide. execute update_now 01-28011-0259-20060210 FortiGate Firmware to update the antivirus and attack Fortinet Inc.
Where <name_str> is the name of the firmware image file and <tftp_ip> is the IP address of the TFTP server. For example, if the firmware image file name is FGT_300-v280-build183-FORTINET.out and the IP address of the TFTP server is 192.168.1.168, enter: execute restore image FGT_300-v280-build183-FORTINET.out...
IPS custom signatures, web content lists, email filtering lists, and changes to replacement messages. Back up the FortiGate-5000 module configuration. Back up the IPS custom signatures. Back up web content and email filtering lists. the FortiGate Administration Guide 01-28011-0259-20060210 FortiGate Firmware the FortiGate Administration the FortiGate Administration Fortinet Inc.
Page 47
Where <name_str> is the name of the firmware image file and <tftp_ip> is the IP address of the TFTP server. For example, if the firmware image file name is FGT_300-v280-build158-FORTINET.out and the IP address of the TFTP server is 192.168.1.168, enter: execute restore image FGT_300-v280-build158-FORTINET.out...
FortiGate Administration Guide Back up the IPS custom signatures. For information, see the FortiGate Administration Guide Back up web content and email filtering lists. For information, see the FortiGate Administration Guide. 01-28011-0259-20060210 FortiGate Firmware , or from the CLI, enter: Fortinet Inc.
Page 49
FortiGate Firmware If you are reverting to a previous FortiOS version (for example, reverting from FortiOS v2.80 to FortiOS v2.50), you might not be able to restore your previous configuration from the backup configuration file. Note: Installing firmware replaces the current antivirus and attack definitions with the definitions included with the firmware release that you are installing.
Page 50
FortiGate-5000 module running v2.x BIOS Do You Want To Save The Image? [Y/n] Type Y. FortiGate-5000 module running v3.x BIOS Save as Default firmware/Run image without saving:[D/R] Save as Default firmware/Backup firmware/Run image without saving:[D/B/R] 01-28011-0259-20060210 FortiGate Firmware Fortinet Inc.
FortiGate Firmware The FortiGate-5000 module installs the new firmware image and restarts. The installation might take a few minutes to complete. Restoring the previous configuration Change the internal interface address if required. You can do this from the CLI using the command: config system interface After changing the interface address, you can access the FortiGate-5000 module from...
Page 52
FortiGate-5000 module running v3.x BIOS [G]: Get firmware image from TFTP server. [F]: Format boot device. [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter G,F,Q,or H: 01-28011-0259-20060210 FortiGate Firmware execute reboot Fortinet Inc.
FortiGate Firmware Type the number of the interface that connects to the same network as the TFTP server. The default interface is port8. To accept the default interface, press Enter. The following message appears: Enter TFTP server address [192.168.1.168]: Type the address of the TFTP server and press Enter. The following message appears: Enter Local Address [192.168.1.188]: Type an IP address that can be used by the FortiGate-5000 module to connect to the...
“Installing firmware images from a system reboot using the CLI” on page Get firmware image from TFTP server. Format boot device. Boot with backup firmware and set as default. Quit menu and continue to boot with default firmware. Display this list of options. 01-28011-0259-20060210 FortiGate Firmware execute reboot Fortinet Inc.
Page 55
FortiGate Firmware Type an IP address that can be used by the FortiGate-5000 module to connect to the FTP server. The IP address can be any IP address that is valid for the network that the interface is connected to. Make sure you do not enter the IP address of another device on this network.
Page 56
Get firmware image from TFTP server. Format boot device. Boot with backup firmware and set as default. Quit menu and continue to boot with default firmware. Display this list of options. 01-28011-0259-20060210 FortiGate Firmware Fortinet Inc.
FortiGate-5000 series Installation Guide Version 2.80 MR11 Factory defaults The FortiGate-5000 module ships with a factory default configuration. The default configuration allows you to connect to and use the FortiGate web-based manager to configure the FortiGate-5000 module onto the network. To configure the FortiGate- 5000 module onto the network you add an administrator password, change network interface IP addresses, add DNS server IP addresses, and configure basic routing, if required.
Page 58
Primary DNS Server Secondary DNS Server 01-28011-0259-20060210 Factory defaults 192.168.100.99 255.255.255.0 Ping 0.0.0.0 0.0.0.0 Ping 0.0.0.0 0.0.0.0 Ping 0.0.0.0 0.0.0.0 Ping 0.0.0.0 0.0.0.0 Ping 0.0.0.0 0.0.0.0 Ping 0.0.0.0 0.0.0.0 Ping 192.168.100.1 port2 207.192.200.1 207.192.200.129 Fortinet Inc.
Factory defaults Transparent mode network configuration In Transparent mode, the FortiGate-5000 module has the default network configuration listed in Table 8: Factory default Transparent mode network configuration Administrator account Management IP Administrative access Firewall configuration FortiGate firewall policies control how all traffic is processed by the FortiGate-5000 module.
To apply no scanning, blocking or IPS. Use if you do not want to apply content protection to content traffic. You can add this protection profile to firewall policies for connections between highly trusted or highly secure networks where content does not need to be protected. 01-28011-0259-20060210 Factory defaults Fortinet Inc.
Factory defaults Figure 13: Web protection profile settings Restoring the default settings Should you mistakenly change a network setting and cannot connect to the FortiGate- 5000 module, you can revert to the factory default settings and start over again. Restoring the default settings using the web-based manager To reset the default settings Go to System >...
Page 62
The FortiGate-5000 module loads the default firmware image and restarts. Get firmware image from TFTP server. Format boot device. Boot with backup firmware and set as default. Quit menu and continue to boot with default firmware. Display this list of options. 01-28011-0259-20060210 Factory defaults Fortinet Inc.
FortiGate-5000 series Installation Guide FortiGate-5020 chassis 6 FortiGate-5050 chassis 6 FortiGate-5140 chassis 6 Fortinet Knowledge Center 9 FortiSwitch-5003 introduction 7 configuring FortiGate units for HA operation 32 connecting an HA cluster 37, 39 High availability 32 internal network configuring 26...
Page 64
IP address 29 upgrading firmware 44 firmware using the CLI 44, 46 firmware using the web-based manager 44, 45, 61 web-based manager connecting to 17 wizard setting up firewall 19, 23, 27, 30 starting 19, 24, 27, 30 01-28011-0259-20060210 Fortinet Inc.
Need help?
Do you have a question about the FortiGate FortiGate-5001FA2 and is the answer not in the manual?
Questions and answers