Fortinet FortiAnalyzer 3.0 MR7 Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Hardware Fortinet FortiAnalyzer 3.0 MR7 herunter. Fortinet FortiAnalyzer 3.0 MR7 User Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 234
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - ADMINISTRATION GUIDE

www.fortinet.comFortiAnalyzerVersion 3.0 MR7ADMINISTRATION GUIDE

Seite 2

FortiAnalyzer Version 3.0 MR7 Administration Guide10 05-30007-0082-20080908Fortinet documentation Introduction• Reports describes how to configure rep

Seite 3 - Contents

FortiAnalyzer Version 3.0 MR7 Administration Guide100 05-30007-0082-20080908Customizing the log view LogFigure 6: Filter iconsTo filter log messages b

Seite 4 - 4 05-30007-0082-20080908

Log Searching the logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 101• 1.1.1.1 or 2.2.2.1-2.2.2.10Most column filters re

Seite 5 - 05-30007-0082-20080908 5

FortiAnalyzer Version 3.0 MR7 Administration Guide102 05-30007-0082-20080908Searching the logs LogDevice/Group Select to search logs from the FortiAna

Seite 6 - 6 05-30007-0082-20080908

Log Searching the logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 103To search the logs1 Go to Log > Search.2 From De

Seite 7 - 05-30007-0082-20080908 7

FortiAnalyzer Version 3.0 MR7 Administration Guide104 05-30007-0082-20080908Searching the logs Log• Some keywords will not match unless you include bo

Seite 8 - 8 05-30007-0082-20080908

Log Rolling and uploading logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 105To download log search results1 Go to Log &

Seite 9 - Introduction

FortiAnalyzer Version 3.0 MR7 Administration Guide106 05-30007-0082-20080908Rolling and uploading logs LogFigure 8: Device Log SettingsLog file should

Seite 10 - Fortinet documentation

Log Rolling and uploading logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 107Upload rolled files in gzipped formatSelect

Seite 11 - Fortinet Knowledge Center

FortiAnalyzer Version 3.0 MR7 Administration Guide108 05-30007-0082-20080908Rolling and uploading logs Log

Seite 12 - 12 05-30007-0082-20080908

Content Archive Viewing content archivesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 107Content ArchiveContent archiving

Seite 13 - What’s new for 3.0 MR7

Introduction Customer service and technical supportFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 11Fortinet Tools and Docu

Seite 14 - 14 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide108 05-30007-0082-20080908Viewing content archives Content Archive• whether the FortiAnalyzer unit h

Seite 15 - Dashboard enhancements

Content Archive Customizing the content archive viewFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 109Customizing the conte

Seite 16

FortiAnalyzer Version 3.0 MR7 Administration Guide110 05-30007-0082-20080908Customizing the content archive view Content Archive3 Select which columns

Seite 17 - VoIP reports

Content Archive Customizing the content archive viewFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1114 Enter the text that

Seite 18 - 18 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide112 05-30007-0082-20080908Searching full email content archives Content ArchiveSearching full email

Seite 19

Content Archive Searching full email content archivesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 113To The recipient’s e

Seite 20

FortiAnalyzer Version 3.0 MR7 Administration Guide114 05-30007-0082-20080908Searching full email content archives Content Archive

Seite 21

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 113ReportsFortiAnalyzer units can collate informa

Seite 22 - Configuring ADOMs

FortiAnalyzer Version 3.0 MR7 Administration Guide114 05-30007-0082-20080908Configuring reports ReportsConfiguring report layoutThe Layout tab enables

Seite 23

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 115Figure 2: LayoutThere are also default report

Seite 24

FortiAnalyzer Version 3.0 MR7 Administration Guide12 05-30007-0082-20080908Customer service and technical support Introduction

Seite 25 - Dashboard

FortiAnalyzer Version 3.0 MR7 Administration Guide116 05-30007-0082-20080908Configuring reports Reports4 Select [Add Chart(s)]. 5 Enter the appropriat

Seite 26 - 26 05-30007-0082-20080908

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 117Editing charts in a report layoutYou can edit

Seite 27 - 05-30007-0082-20080908 27

FortiAnalyzer Version 3.0 MR7 Administration Guide118 05-30007-0082-20080908Configuring reports ReportsTo edit a chart 1 Select Edit beside the chart

Seite 28 - RAID Monitor

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1193 Select OK. If you want to rearrange the char

Seite 29 - System Information

FortiAnalyzer Version 3.0 MR7 Administration Guide120 05-30007-0082-20080908Configuring reports ReportsTo configure a report schedule1 Go to Report &g

Seite 30 - Setting the time

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1214 Select OK. Monthly Select to generate the re

Seite 31 - License Information

FortiAnalyzer Version 3.0 MR7 Administration Guide122 05-30007-0082-20080908Configuring reports ReportsConfiguring data filter templates You can confi

Seite 32 - Viewing operational history

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 123Figure 5: Configuring a data filter templateTo

Seite 33 - Formatting the log disks

FortiAnalyzer Version 3.0 MR7 Administration Guide124 05-30007-0082-20080908Configuring reports ReportsAlias Select the appropriate alias from the dro

Seite 34 - Alert Message Console

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1254 Select OK. Configuring report output templat

Seite 35 - Viewing session information

What’s new for 3.0 MR7 FortiAnalyzerVersion 3.0 MR7 Administration Guide05-30007-0082-20080908 13What’s new for 3.0 MR7This section lists and describe

Seite 36 - Report Engine

FortiAnalyzer Version 3.0 MR7 Administration Guide126 05-30007-0082-20080908Configuring reports ReportsWhen configuring the FortiAnalyzer unit to emai

Seite 37 - Log Receive Monitor

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 127Send Report by Mail Verify this check box is s

Seite 38 - Virus Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide128 05-30007-0082-20080908Configuring reports Reports4 Select OK. Configuring languageWhen creating

Seite 39 - Top FTP Traffic

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 129Keys are required and must not be removed or c

Seite 40 - Top Email Traffic

FortiAnalyzer Version 3.0 MR7 Administration Guide130 05-30007-0082-20080908Configuring reports ReportsFigure 8: LanguagesTo create a report language

Seite 41 - Top IM/P2P Traffic

Reports Configuring reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1316 If you changed the encoding of the string fi

Seite 42 - Top Traffic

FortiAnalyzer Version 3.0 MR7 Administration Guide132 05-30007-0082-20080908Browsing reports ReportsTo change a report language customization1 Go to R

Seite 43 - Top Web Traffic

Reports Browsing reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 133Figure 9: Viewing reports in Report > BrowseRe

Seite 44 - Interface

FortiAnalyzer Version 3.0 MR7 Administration Guide134 05-30007-0082-20080908Browsing reports Reports

Seite 45 - Changing interface settings

Quarantine Viewing quarantined filesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 131QuarantineFortiAnalyzer units can act

Seite 46

FortiAnalyzerVersion 3.0 MR7 Administration Guide14 05-30007-0082-20080908What’s new for 3.0 MR7• Network Summary menu removed – The Network Summary m

Seite 47 - Adding a route

FortiAnalyzer Version 3.0 MR7 Administration Guide132 05-30007-0082-20080908Viewing quarantined files QuarantineDate & Time The date and time the

Seite 48

Alert Alert EventsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 133AlertAlerts provide a method of informing you of issues

Seite 49 - Access Profile

FortiAnalyzer Version 3.0 MR7 Administration Guide134 05-30007-0082-20080908Alert Events AlertAdding an alert eventAdding an alert event enables you t

Seite 50 - Auth Group

Alert OutputFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1354 Select OK.OutputWhen the FortiAnalyzer unit receives a log

Seite 51 - Administrator Settings

FortiAnalyzer Version 3.0 MR7 Administration Guide136 05-30007-0082-20080908Output AlertTo add a mail server for alerts1 Go to Alert > Output >

Seite 52 - Network Sharing

Alert OutputFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 137Figure 3: SNMP Access ListSNMP Agent Select to enable the SNM

Seite 53 - Configuring Windows shares

FortiAnalyzer Version 3.0 MR7 Administration Guide138 05-30007-0082-20080908Output AlertAdding an SNMP serverYou can add an SNMP server to define a de

Seite 54 - Assigning user permissions

Alert OutputFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 139Fortinet MIB System Traps• fnTrapCpuHigh• fnTrapMemLow• fnTra

Seite 55 - Configuring NFS shares

FortiAnalyzer Version 3.0 MR7 Administration Guide140 05-30007-0082-20080908Output AlertRFC-1213 (MIB II)• mib-2.system• mib-2.interface•mib-2.at•mib-

Seite 56

Alert OutputFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1413 Configure the following options, and select OK.Name Enter a

Seite 57

What’s new for 3.0 MR7 3.0 MR7 new features and changesFortiAnalyzerVersion 3.0 MR7 Administration Guide05-30007-0082-20080908 153.0 MR7 new features

Seite 58 - Configuring log aggregation

FortiAnalyzer Version 3.0 MR7 Administration Guide142 05-30007-0082-20080908Output Alert

Seite 59

Network Analyzer Connecting the FortiAnalyzer unit to analyze network trafficFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908

Seite 60 - Configuring log forwarding

FortiAnalyzer Version 3.0 MR7 Administration Guide142 05-30007-0082-20080908Connecting the FortiAnalyzer unit to analyze network traffic Network Analy

Seite 61 - Configuring IP aliases

Network Analyzer Viewing Network Analyzer log messagesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 143Viewing Network Ana

Seite 62 - RAID levels

FortiAnalyzer Version 3.0 MR7 Administration Guide144 05-30007-0082-20080908Viewing Network Analyzer log messages Network AnalyzerViewing historical N

Seite 63

Network Analyzer Browsing Network Analyzer log filesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 145Browsing Network Anal

Seite 64 - Hot swapping hard disks

FortiAnalyzer Version 3.0 MR7 Administration Guide146 05-30007-0082-20080908Browsing Network Analyzer log files Network AnalyzerFigure 5: Viewing Netw

Seite 65

Network Analyzer Browsing Network Analyzer log filesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 147Downloading a Network

Seite 66 - FortiAnalyzer-4000/4000A

FortiAnalyzer Version 3.0 MR7 Administration Guide148 05-30007-0082-20080908Customizing the Network Analyzer log view Network AnalyzerCustomizing the

Seite 67 - FortiAnalyzer-800/800B

Network Analyzer Customizing the Network Analyzer log viewFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1493 Select which

Seite 68 - Configuring LDAP connections

FortiAnalyzerVersion 3.0 MR7 Administration Guide16 05-30007-0082-200809083.0 MR7 new features and changes What’s new for 3.0 MR7For the Log Receive M

Seite 69

FortiAnalyzer Version 3.0 MR7 Administration Guide150 05-30007-0082-20080908Customizing the Network Analyzer log view Network Analyzer3 If you want to

Seite 70 - Maintenance

Network Analyzer Searching the Network Analyzer logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 151Searching the Network

Seite 71 - FortiGuard Center

FortiAnalyzer Version 3.0 MR7 Administration Guide152 05-30007-0082-20080908Searching the Network Analyzer logs Network AnalyzerTo search the logs1 Go

Seite 72

Network Analyzer Searching the Network Analyzer logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 153• You can search for

Seite 73

FortiAnalyzer Version 3.0 MR7 Administration Guide154 05-30007-0082-20080908Rolling and uploading Network Analyzer logs Network Analyzer4 Select the d

Seite 74 - Maintenance System

Network Analyzer Rolling and uploading Network Analyzer logsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 155Figure 9: Tra

Seite 75 - Viewing the device list

FortiAnalyzer Version 3.0 MR7 Administration Guide156 05-30007-0082-20080908Rolling and uploading Network Analyzer logs Network AnalyzerEnable log upl

Seite 76

Tools Preparing for the vulnerability scan jobFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 157ToolsThe Tools menu provide

Seite 77

FortiAnalyzer Version 3.0 MR7 Administration Guide158 05-30007-0082-20080908Preparing for the vulnerability scan job Toolsauthenticating without root

Seite 78 - Maximum number of devices

Tools Preparing for the vulnerability scan jobFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 159Some vulnerability scan mod

Seite 79

What’s new for 3.0 MR7 3.0 MR7 new features and changesFortiAnalyzerVersion 3.0 MR7 Administration Guide05-30007-0082-20080908 17Fortinet recommends

Seite 80

FortiAnalyzer Version 3.0 MR7 Administration Guide160 05-30007-0082-20080908Preparing for the vulnerability scan job ToolsFigure 1: Configuring the se

Seite 81

Tools Viewing vulnerability scan modulesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1619 Select OK.10 Select OK.11 Selec

Seite 82 - Manually adding a device

FortiAnalyzer Version 3.0 MR7 Administration Guide162 05-30007-0082-20080908Viewing vulnerability scan modules ToolsWhen configuring a full vulnerabil

Seite 83

Tools Configuring vulnerability scan jobsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 163To filter the module view by vul

Seite 84

FortiAnalyzer Version 3.0 MR7 Administration Guide164 05-30007-0082-20080908Configuring vulnerability scan jobs ToolsConfiguring a custom scan allows

Seite 85

Tools Configuring vulnerability scan jobsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 165To configure a vulnerability sca

Seite 86

FortiAnalyzer Version 3.0 MR7 Administration Guide166 05-30007-0082-20080908Configuring vulnerability scan jobs Tools6 Select the blue arrow to expand

Seite 87 - 05-30007-0082-20080908 85

Tools Viewing vulnerability scan reportsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 16710 Select OK.Viewing vulnerabilit

Seite 88

FortiAnalyzer Version 3.0 MR7 Administration Guide168 05-30007-0082-20080908File Explorer ToolsTo view a vulnerability scan report1 Go to Tools > V

Seite 89 - Configuring device groups

Tools File ExplorerFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 169Figure 5: File ExplorerFigure 6: File Explorer with St

Seite 90

FortiAnalyzerVersion 3.0 MR7 Administration Guide18 05-30007-0082-200809083.0 MR7 new features and changes What’s new for 3.0 MR7Alert email configura

Seite 91 - Viewing log messages

FortiAnalyzer Version 3.0 MR7 Administration Guide170 05-30007-0082-20080908File Explorer Tools

Seite 92 - Reference

Managing firmware versions Backing up your configurationFortiAnalyzer Version 3.0 MR7 Administration Guide 05-30007-0082-20080908 169Managing firmwar

Seite 93 - Settings

FortiAnalyzer Version 3.0 MR7 Administration Guide170 05-30007-0082-20080908Backing up your configuration Managing firmware versionsBacking up your co

Seite 94 - Browsing log files

Managing firmware versions Backing up your configurationFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1715 Select OK.6 Sel

Seite 95 - Viewing log file contents

FortiAnalyzer Version 3.0 MR7 Administration Guide172 05-30007-0082-20080908Testing firmware before upgrading Managing firmware versionsTesting firmwa

Seite 96 - Importing a log file

Managing firmware versions Testing firmware before upgradingFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1738 Type G to g

Seite 97 - Downloading a log file

FortiAnalyzer Version 3.0 MR7 Administration Guide174 05-30007-0082-20080908Upgrading your FortiAnalyzer unit Managing firmware versionsUpgrading your

Seite 98 - Customizing the log view

Managing firmware versions Upgrading your FortiAnalyzer unitFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 175To upgrade to

Seite 99

FortiAnalyzer Version 3.0 MR7 Administration Guide176 05-30007-0082-20080908Upgrading your FortiAnalyzer unit Managing firmware versionsThis operation

Seite 100 - Filtering tips

Managing firmware versions Reverting to a previous firmware versionFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 177Revert

Seite 101 - Searching the logs

Administrative Domains (ADOMs) About administrative domains (ADOMs)FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 19Adminis

Seite 102

FortiAnalyzer Version 3.0 MR7 Administration Guide178 05-30007-0082-20080908Reverting to a previous firmware version Managing firmware versionsVerifyi

Seite 103 - Search tips

Managing firmware versions Reverting to a previous firmware versionFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1798 Reco

Seite 104 - Printing the search results

FortiAnalyzer Version 3.0 MR7 Administration Guide180 05-30007-0082-20080908Restoring your configuration Managing firmware versionsRestoring your conf

Seite 105 - Rolling and uploading logs

Managing firmware versions Restoring your configurationFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1816 When this messag

Seite 106

FortiAnalyzer Version 3.0 MR7 Administration Guide182 05-30007-0082-20080908Restoring your configuration Managing firmware versionsRestoring your conf

Seite 107

Managing firmware versions Restoring your configurationFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 1836 Type y.The Forti

Seite 108 - 108 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide184 05-30007-0082-20080908Restoring your configuration Managing firmware versions

Seite 109 - Content Archive

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reportsFortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 185Appendix: Fo

Seite 110

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Intrusion Activ

Seite 111

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 187Top Infecte

Seite 112 - Filtering logs

FortiAnalyzer Administration GuideVersion 3.0 MR708 September 200805-30007-0082-20080908© Copyright 2008 Fortinet, Inc. All rights reserved. No part o

Seite 113

FortiAnalyzer Version 3.0 MR7 Administration Guide20 05-30007-0082-20080908About administrative domains (ADOMs) Administrative Domains (ADOMs)• If ADO

Seite 114

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Top Virus Desti

Seite 115

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 189The followi

Seite 116 - 114 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Antispam Activi

Seite 117 - Configuring reports

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 191The followi

Seite 118 - Configuring report layout

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7VoIP reportsThe

Seite 119

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 193Content Act

Seite 120

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Network Activit

Seite 121 - Text and Section in Layout

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 195The followi

Seite 122 - To edit a chart

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7The following r

Seite 123 - Configuring report schedules

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 197Terminal Ac

Seite 124 - 2 Select Create New

Administrative Domains (ADOMs) About administrative domains (ADOMs)FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 21• If AD

Seite 125 - 4 Select OK

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Event ActivityT

Seite 126

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiGate reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 199The report,

Seite 127

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiGate reports Appendix: FortiAnalyzer reports in 3.0 MR7Audit ActivityT

Seite 128

Appendix: FortiAnalyzer reports in 3.0 MR7 Summary Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 201Summary Repor

Seite 129

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908Forensic Reports Appendix: FortiAnalyzer reports in 3.0 MR7• Top Spam Desti

Seite 130

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiMail Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 203SummaryThe

Seite 131

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiMail Reports Appendix: FortiAnalyzer reports in 3.0 MR7Top Client IP b

Seite 132 - Configuring language

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiMail Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 205Mail Sender

Seite 133 - 05-30007-0082-20080908 129

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiMail Reports Appendix: FortiAnalyzer reports in 3.0 MR7Mail Recipient

Seite 134

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiMail Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 207Spam Sender

Seite 135

FortiAnalyzer Version 3.0 MR7 Administration Guide22 05-30007-0082-20080908Configuring ADOMs Administrative Domains (ADOMs)Configuring ADOMsAdministra

Seite 136 - Browsing reports

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiMail Reports Appendix: FortiAnalyzer reports in 3.0 MR7Spam RecipientT

Seite 137

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiMail Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 209Spam Destin

Seite 138 - Browsing reports Reports

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiMail Reports Appendix: FortiAnalyzer reports in 3.0 MR7Table 36: Virus

Seite 139 - Quarantine

Appendix: FortiAnalyzer reports in 3.0 MR7 FortiMail Reports FortiAnalyzer Version 3.0 MR7 Administration Guide005-30007-0082-20080908 211Virus Recip

Seite 140

FortiAnalyzer Version 3.0 MR7 Administration Guide 005-30007-0082-20080908FortiClient Reports Appendix: FortiAnalyzer reports in 3.0 MR7Virus Destina

Seite 141 - Alert Events

Index FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 213IndexAaccessadministrative ports 46profile, administrator 48, 50acce

Seite 142 - Adding an alert event

FortiAnalyzer Version 3.0 MR7 Administration Guide214 05-30007-0082-20080908Indexdeleting tabs 27denial of service (DoS) 158deviceadd 80alerts 133bloc

Seite 143

Index FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 215Fortinet MIB 138Fortinet Technical Support 11, 138FTPcontent archive

Seite 144

FortiAnalyzer Version 3.0 MR7 Administration Guide216 05-30007-0082-20080908IndexMmail server 135Main Menu 20managing firmwarebacking up configuration

Seite 145

Index FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 217SFTP 105, 155SNMP 73SOAP 46SSH 46, 58, 160telnet 46TFTP 180UDP 47, 8

Seite 146 - FortiAnalyzer SNMP support

Administrative Domains (ADOMs) Configuring ADOMsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 23To add or edit an ADOM1 Lo

Seite 147 - 05-30007-0082-20080908 139

FortiAnalyzer Version 3.0 MR7 Administration Guide218 05-30007-0082-20080908Indexsniffer 141, 144See also network analyzerSNMP 73manager 138MIB 138se

Seite 148 - Adding a Syslog server

Index FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 219registered device’s hard limits 15report configuration enhancements

Seite 149

FortiAnalyzer Version 3.0 MR7 Administration Guide220 05-30007-0082-20080908Index

Seite 152

FortiAnalyzer Version 3.0 MR7 Administration Guide24 05-30007-0082-20080908Accessing ADOMs as the admin administrator Administrative Domains (ADOMs)Ac

Seite 153

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 25SystemThe System menu contains basic FortiAnalyzer unit sy

Seite 154

FortiAnalyzer Version 3.0 MR7 Administration Guide26 05-30007-0082-20080908Dashboard SystemFigure 1: Dashboard of a FortiAnalyzer-100A unit displaying

Seite 155

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 273 Select Show or Hide.The widget toggles between showing t

Seite 156

FortiAnalyzer Version 3.0 MR7 Administration Guide28 05-30007-0082-20080908Dashboard System3 Enter a new name and press Enter. To delete a tab1 Go to

Seite 157

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 29Figure 4: RAID Monitor displaying a disk that is being reb

Seite 158 - 148 05-30007-0082-20080908

Contents FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 3ContentsIntroduction ...

Seite 159

FortiAnalyzer Version 3.0 MR7 Administration Guide30 05-30007-0082-20080908Dashboard SystemFigure 5: System InformationSetting the timeSet the system

Seite 160

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 31Changing the host nameChange the FortiAnalyzer host name t

Seite 161

FortiAnalyzer Version 3.0 MR7 Administration Guide32 05-30007-0082-20080908Dashboard SystemSystem ResourcesThe System Resources area of the Dashboard

Seite 162

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 33To view the FortiAnalyzer operational history1 Go to Syste

Seite 163

FortiAnalyzer Version 3.0 MR7 Administration Guide34 05-30007-0082-20080908Dashboard SystemResetting to the default configurationYou can reset the For

Seite 164

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 35Figure 10: Alert messagesStatisticsThe Statistics area of

Seite 165

FortiAnalyzer Version 3.0 MR7 Administration Guide36 05-30007-0082-20080908Dashboard SystemTo view the session information1 Go to System > Dashboar

Seite 166

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 37Log Receive MonitorThe Log Receive Monitor displays histor

Seite 167 - 05-30007-0082-20080908 157

FortiAnalyzer Version 3.0 MR7 Administration Guide38 05-30007-0082-20080908Dashboard SystemIntrusion ActivityIntrusion Activity displays the top attac

Seite 168 - 158 05-30007-0082-20080908

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 39Figure 15: Virus Activity widgetTo edit the information fo

Seite 169

FortiAnalyzer Version 3.0 MR7 Administration Guide4 05-30007-0082-20080908ContentsViewing session information ...

Seite 170 - 160 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide40 05-30007-0082-20080908Dashboard SystemTo edit the information for Top FTP Traffic1 Go to System &

Seite 171 - Preparing Unix target hosts

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 413 Enter the appropriate information for the following: 4 S

Seite 172

FortiAnalyzer Version 3.0 MR7 Administration Guide42 05-30007-0082-20080908Dashboard System3 Enter the appropriate information for the following: 4 Se

Seite 173

System DashboardFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 433 Enter the appropriate information for the following: 4 S

Seite 174

FortiAnalyzer Version 3.0 MR7 Administration Guide44 05-30007-0082-20080908Network System3 Enter the appropriate information for the following: 4 Sele

Seite 175

System NetworkFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 45Changing interface settingsTo change the interface settings1

Seite 176

FortiAnalyzer Version 3.0 MR7 Administration Guide46 05-30007-0082-20080908Network SystemAbout Fortinet Discovery ProtocolFortiGate units running Fort

Seite 177

System AdminFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 47Adding a routeStatic routes provide the FortiAnalyzer unit wit

Seite 178 - File Explorer

FortiAnalyzer Version 3.0 MR7 Administration Guide48 05-30007-0082-20080908Admin SystemAdding or editing an administrator accountYou can add, edit or

Seite 179 - Figure 5: File Explorer

System AdminFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 49Changing an administrator’s passwordThe admin administrator an

Seite 180 - File Explorer Tools

Contents FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 5Hot swapping the FortiAnalyzer-2000/2000A and FortiAnalyz-er-4000/4

Seite 181 - Managing firmware versions

FortiAnalyzer Version 3.0 MR7 Administration Guide50 05-30007-0082-20080908Admin SystemFigure 24: Access ProfileTo create an access profile1 Go to Sys

Seite 182 - Backing up your log files

System AdminFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 51RADIUS ServerRADIUS servers authenticate administrators. The f

Seite 183 - 05-30007-0082-20080908 171

FortiAnalyzer Version 3.0 MR7 Administration Guide52 05-30007-0082-20080908Network Sharing SystemMonitorThe Monitor page enables the admin administrat

Seite 184

System Network SharingFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 533 Enter the following information for the user accou

Seite 185 - 05-30007-0082-20080908 173

FortiAnalyzer Version 3.0 MR7 Administration Guide54 05-30007-0082-20080908Network Sharing SystemTo enable Windows shares1 Go to System > Network S

Seite 186

System Network SharingFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 557 Select the type of access rights the users and gro

Seite 187 - Upgrading using the CLI

FortiAnalyzer Version 3.0 MR7 Administration Guide56 05-30007-0082-20080908Config System5 Select OK.6 In Remote Clients, enter the IP address or domai

Seite 188 - Verifying the upgrade

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 57Figure 30: FortiAnalyzer unit log settingsLog Locally Select

Seite 189 - Downgrading to FortiLog 1.6

FortiAnalyzer Version 3.0 MR7 Administration Guide58 05-30007-0082-20080908Config SystemConfiguring log aggregationLog aggregation is a method of coll

Seite 190 - Verifying the downgrade

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 59For example, a company may have a headquarters and a number o

Seite 191 - 8 Reconnect to the CLI

FortiAnalyzer Version 3.0 MR7 Administration Guide6 05-30007-0082-20080908ContentsCustomizing the content archive view ...

Seite 192 - Restoring your configuration

FortiAnalyzer Version 3.0 MR7 Administration Guide60 05-30007-0082-20080908Config SystemConfiguring an aggregation clientAn aggregation client is a Fo

Seite 193 - 05-30007-0082-20080908 181

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 613 Enter the IP address of the external syslog server in Remot

Seite 194 - 182 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide62 05-30007-0082-20080908Config System3 Enter the path and file name or select Browse to locate the

Seite 195 - 05-30007-0082-20080908 183

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 63LinearA linear RAID level combines all hard disks into one la

Seite 196 - 184 05-30007-0082-20080908

FortiAnalyzer Version 3.0 MR7 Administration Guide64 05-30007-0082-20080908Config SystemRAID 10RAID 10 (or 1+0), includes nested RAID levels 1 and 0,

Seite 197 - FortiGate reports

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 65You can use any brand of hard disk to replace a failed hard d

Seite 198 - Antivirus Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide66 05-30007-0082-20080908Config SystemHot swapping the FortiAnalyzer-2000/2000A and FortiAnalyzer-40

Seite 199

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 67The options available here will depend on the RAID level sele

Seite 200

FortiAnalyzer Version 3.0 MR7 Administration Guide68 05-30007-0082-20080908Config SystemRAID settings can be configured from the Dashboard, in the RAI

Seite 201 - Webfilter Activity

System ConfigFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 69Figure 34: LDAP settingsTo define an LDAP server query1 Go to

Seite 202 - Antispam Activity

Contents FortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 7Searching the Network Analyzer logs ...

Seite 203 - IM Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide70 05-30007-0082-20080908Maintenance System3 Select OK.The LDAP query becomes an available option wh

Seite 204

System MaintenanceFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 71FortiGuard CenterYou can update the engine and vulnerabi

Seite 205 - Content Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide72 05-30007-0082-20080908Maintenance SystemFigure 36: FortiGuard CenterFortiGuard Subscription Servi

Seite 206 - Network Activity

System MaintenanceFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 73Port Enter the port number of the web proxy.This is usua

Seite 207 - Web Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide74 05-30007-0082-20080908Maintenance System

Seite 208 - FTP Activity

Device Viewing the device listFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 73DeviceThe Device menu controls connection at

Seite 209 - VPN Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide74 05-30007-0082-20080908Viewing the device list DeviceDevices may automatically appear on the devic

Seite 210 - Event Activity

Device Viewing the device listFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 75• Tx indicates logging access for all device

Seite 211 - P2P Activity

FortiAnalyzer Version 3.0 MR7 Administration Guide76 05-30007-0082-20080908Viewing the device list DeviceTo delete a device1 Go to Device > All >

Seite 212 - Audit Activity

Device Viewing the device listFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 77For networks with more demanding logging sce

Seite 213 - Summary Reports

FortiAnalyzer Version 3.0 MR7 Administration Guide8 05-30007-0082-20080908ContentsAppendix: FortiAnalyzer reports in 3.0 MR7 ...

Seite 214 - Forensic Reports

FortiAnalyzer Version 3.0 MR7 Administration Guide78 05-30007-0082-20080908Configuring unregistered device connection attempt handling DeviceConfiguri

Seite 215 - FortiMail Reports

Device Configuring unregistered device connection attempt handlingFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 79Figure 2

Seite 216

FortiAnalyzer Version 3.0 MR7 Administration Guide80 05-30007-0082-20080908Manually adding a device DeviceManually adding a deviceYou can add devices

Seite 217 - Mail Sender

Device Manually adding a deviceFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 81Figure 3: Configuring a deviceDevice Type S

Seite 218 - Mail Destination IP

FortiAnalyzer Version 3.0 MR7 Administration Guide82 05-30007-0082-20080908Manually adding a device DeviceTo manually add a device or HA cluster1 Go t

Seite 219 - Spam Sender

Device Manually adding a deviceFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 8313 Select the blue arrow to expand Group Me

Seite 220 - Spam Recipient

FortiAnalyzer Version 3.0 MR7 Administration Guide84 05-30007-0082-20080908Manually adding a device DeviceTo classify network interfaces and VLAN subi

Seite 221 - Virus Sender

Device Manually adding a deviceFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 85To enable the FortiAnalyzer unit to reply t

Seite 222

FortiAnalyzer Version 3.0 MR7 Administration Guide86 05-30007-0082-20080908Blocking device connection attempts DeviceTest Connectivity does not verify

Seite 223 - Virus Recipient

Device Configuring device groupsFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 87To block a device1 Go to Device > All &

Seite 224 - FortiClient Reports

Introduction About this documentFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 9IntroductionFortiAnalyzer units are network

Seite 225

FortiAnalyzer Version 3.0 MR7 Administration Guide88 05-30007-0082-20080908Configuring device groups DeviceFigure 5: List of device groupsTo configure

Seite 226

Log Viewing log messagesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 91LogFortiAnalyzer units collect logs from network h

Seite 227

FortiAnalyzer Version 3.0 MR7 Administration Guide92 05-30007-0082-20080908Viewing log messages LogFigure 1: Viewing current logsViewing historical lo

Seite 228

Log Viewing log messagesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 93Figure 2: Viewing historical logsDevices Select th

Seite 229

FortiAnalyzer Version 3.0 MR7 Administration Guide94 05-30007-0082-20080908Browsing log files LogTo view historical logs1 Go to Log > Log Viewer &g

Seite 230

Log Browsing log filesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 95Viewing log file contentsThe Log Browser tab enables

Seite 231

FortiAnalyzer Version 3.0 MR7 Administration Guide96 05-30007-0082-20080908Browsing log files LogImporting a log fileYou can import devices’ log files

Seite 232 - 220 05-30007-0082-20080908

Log Browsing log filesFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 975 In Filename, enter the path and file name of the l

Seite 233

FortiAnalyzer Version 3.0 MR7 Administration Guide98 05-30007-0082-20080908Customizing the log view Log5 Select Download Current View.6 Configure the

Seite 234

Log Customizing the log viewFortiAnalyzer Version 3.0 MR7 Administration Guide05-30007-0082-20080908 99Figure 5: Displaying and arranging log columns

Kommentare zu diesen Handbüchern

Keine Kommentare