Fortinet FortiGate-800 Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Software Fortinet FortiGate-800 herunter. Fortinet FortiGate-800 User's Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 336
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen

Inhaltsverzeichnis

Seite 1 - Configuration Guide

FortiGate 800Installation andConfiguration GuideEsc EnterCONSOLEINTERNAL EXTERNAL DMZ HA 1234 USB8PWRFortiGate User Manual Volume 1Version 2.50January

Seite 2

Contents10 Fortinet Inc.IPSec VPN... 231Key

Seite 3 - Table of Contents

100 Fortinet Inc.Changing the FortiGate firmware System status5 To confirm that the FortiGate unit can connect to the TFTP server, use the following c

Seite 4 - 4 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 10111 Enter the firmware image filename and press En

Seite 5

102 Fortinet Inc.Changing the FortiGate firmware System statusTo run this procedure you:• access the CLI by connecting to the FortiGate console port u

Seite 6 - 6 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 1039 Type the address of the TFTP server and press E

Seite 7

104 Fortinet Inc.Changing the FortiGate firmware System statusTo install a backup firmware image1 Connect to the CLI using the null-modem cable and Fo

Seite 8 - 8 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 105Switching to the backup firmware imageUse this pr

Seite 9

106 Fortinet Inc.Manual virus definition updates System statusSwitching back to the default firmware imageUse this procedure to switch the FortiGate u

Seite 10 - 10 Fortinet Inc

System status Manual attack definition updatesFortiGate-800 Installation and Configuration Guide 1074 Type the path and filename for the antivirus d

Seite 11 - Contents

108 Fortinet Inc.Displaying the FortiGate up time System statusDisplaying the FortiGate up time1 Go to System > Status.The FortiGate up time displa

Seite 12 - 12 Fortinet Inc

System status Restoring system settings to factory defaultsFortiGate-800 Installation and Configuration Guide 109Restoring system settings to factor

Seite 13

ContentsFortiGate-800 Installation and Configuration Guide 11Network Intrusion Detection System (NIDS) ...

Seite 14 - 14 Fortinet Inc

110 Fortinet Inc.Changing to NAT/Route mode System statusChanging to NAT/Route modeUse the following procedure to change the FortiGate unit from Trans

Seite 15 - Introduction

System status System statusFortiGate-800 Installation and Configuration Guide 111System statusYou can use the system status monitor to display Forti

Seite 16 - Web content filtering

112 Fortinet Inc.System status System statusFigure 19: CPU and memory status monitorViewing sessions and network statusUse the session and network sta

Seite 17 - Firewall

System status System statusFortiGate-800 Installation and Configuration Guide 1134 Select Refresh to manually update the information displayed.Figur

Seite 18 - Network intrusion detection

114 Fortinet Inc.Session list System statusFigure 21: Sessions and network status monitorSession listThe session list displays information about the c

Seite 19 - High availability

System status Session listFortiGate-800 Installation and Configuration Guide 115Each line of the session list displays the following information.Fig

Seite 20 - Web-based manager

116 Fortinet Inc.Session list System status

Seite 21 - Logging and reporting

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 117Virus and attack definitions upd

Seite 22 - Fortinet documentation

118 Fortinet Inc.Updating antivirus and attack definitions Virus and attack definitions updates and registrationThe Update page on the web-based manag

Seite 23

Virus and attack definitions updates and registration Updating antivirus and attack definitionsFortiGate-800 Installation and Configuration Guide 11

Seite 24 - 24 Fortinet Inc

Contents12 Fortinet Inc.URL blocking...

Seite 25 - Getting started

120 Fortinet Inc.Scheduling updates Virus and attack definitions updates and registrationConfiguring update loggingUse the following procedure to conf

Seite 26 - Mounting

Virus and attack definitions updates and registration Scheduling updatesFortiGate-800 Installation and Configuration Guide 1214 Select Apply.The For

Seite 27 - Powering on

122 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationEnabling scheduled updates through a proxy serverIf your F

Seite 28 - 28 Fortinet Inc

Virus and attack definitions updates and registration Enabling push updatesFortiGate-800 Installation and Configuration Guide 123When the network co

Seite 29

124 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationEnabling push updates through a NAT deviceIf the FDN can c

Seite 30 - 30 Fortinet Inc

Virus and attack definitions updates and registration Enabling push updatesFortiGate-800 Installation and Configuration Guide 125Figure 24: Example

Seite 31

126 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationAdding a port forwarding virtual IP to the FortiGate NAT d

Seite 32 - 32 Fortinet Inc

Virus and attack definitions updates and registration Enabling push updatesFortiGate-800 Installation and Configuration Guide 127Figure 25: Push upd

Seite 33 - Strict content profile

128 Fortinet Inc.Registering FortiGate units Virus and attack definitions updates and registration4 Set IP to the external IP address added to the vir

Seite 34 - Scan content profile

Virus and attack definitions updates and registration Registering FortiGate unitsFortiGate-800 Installation and Configuration Guide 129All registrati

Seite 35 - Unfiltered content profile

ContentsFortiGate-800 Installation and Configuration Guide 13Viewing logs saved to memory ...

Seite 36 - NAT/Route mode

130 Fortinet Inc.Registering FortiGate units Virus and attack definitions updates and registrationRegistering the FortiGate unitBefore registering a F

Seite 37 - Transparent mode

Virus and attack definitions updates and registration Updating registration informationFortiGate-800 Installation and Configuration Guide 1314 Selec

Seite 38 - Setup wizard

132 Fortinet Inc.Updating registration information Virus and attack definitions updates and registrationRecovering a lost Fortinet support passwordIf

Seite 39 - Front keypad and LCD

Virus and attack definitions updates and registration Updating registration informationFortiGate-800 Installation and Configuration Guide 133Figure

Seite 40 - Next steps

134 Fortinet Inc.Updating registration information Virus and attack definitions updates and registration6 Select the Serial Number of the FortiGate un

Seite 41 - NAT/Route mode installation

Virus and attack definitions updates and registration Updating registration informationFortiGate-800 Installation and Configuration Guide 135Downloa

Seite 42 - 42 Fortinet Inc

136 Fortinet Inc.Registering a FortiGate unit after an RMA Virus and attack definitions updates and registrationRegistering a FortiGate unit after an

Seite 43 - Using the setup wizard

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 137Network configurationYou can use

Seite 44 - 44 Fortinet Inc

138 Fortinet Inc.Configuring interfaces Network configurationAdding zonesThe new zone does not appear in the policy grid until you add an interface to

Seite 45

Network configuration Configuring interfacesFortiGate-800 Installation and Configuration Guide 139Viewing the interface listTo view the interface li

Seite 46 - 46 Fortinet Inc

Contents14 Fortinet Inc.

Seite 47

140 Fortinet Inc.Configuring interfaces Network configurationTo add an interface to a zone1 Go to System > Network > Interface.2 Choose the inte

Seite 48 - Configuring your networks

Network configuration Configuring interfacesFortiGate-800 Installation and Configuration Guide 1414 Clear the Retrieve default gateway and DNS from

Seite 49 - Completing the configuration

142 Fortinet Inc.Configuring interfaces Network configuration7 Select Apply. The FortiGate unit attempts to contact the PPPoE server from the interfac

Seite 50 - 50 Fortinet Inc

Network configuration Configuring interfacesFortiGate-800 Installation and Configuration Guide 143Controlling administrative access to an interfaceF

Seite 51

144 Fortinet Inc.Configuring interfaces Network configurationChanging the MTU size to improve network performanceTo improve network performance, you c

Seite 52 - Using the CLI

Network configuration VLAN overviewFortiGate-800 Installation and Configuration Guide 145• Enable secure administrative access to this interface usi

Seite 53 - Load sharing

146 Fortinet Inc.VLANs in NAT/Route mode Network configurationIn a typical VLAN configuration, 802.1Q-compliant VLAN layer-2 switches or layer-3 route

Seite 54 - 54 Fortinet Inc

Network configuration Virtual domains in Transparent modeFortiGate-800 Installation and Configuration Guide 147Adding VLAN subinterfacesThe VLAN ID

Seite 55 - Policy routing examples

148 Fortinet Inc.Virtual domains in Transparent mode Network configurationTo support VLANs in Transparent mode, you add virtual domains to the FortiGa

Seite 56 - Adding more firewall policies

Network configuration Virtual domains in Transparent modeFortiGate-800 Installation and Configuration Guide 149Virtual domain propertiesA virtual do

Seite 57

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 15IntroductionFortiGate Antivirus F

Seite 58 - 58 Fortinet Inc

150 Fortinet Inc.Virtual domains in Transparent mode Network configurationAdding VLAN subinterfaces to a virtual domainUse the following procedure to

Seite 59 - Transparent mode installation

Network configuration Virtual domains in Transparent modeFortiGate-800 Installation and Configuration Guide 151Figure 32: FortiGate unit containing

Seite 60

152 Fortinet Inc.Virtual domains in Transparent mode Network configurationAdding firewall policies for virtual domainsOnce the network configuration f

Seite 61

Network configuration Adding DNS server IP addressesFortiGate-800 Installation and Configuration Guide 153Deleting virtual domains You must remove a

Seite 62

154 Fortinet Inc.Configuring routing Network configurationAdding a default routeYou can add a default route for network traffic leaving the external i

Seite 63

Network configuration Configuring routingFortiGate-800 Installation and Configuration Guide 1556 Set Device #1 to the FortiGate interface or VLAN su

Seite 64

156 Fortinet Inc.Configuring routing Network configuration5 Select OK to save the new route.6 Repeat steps 1 to 5 to add more routes as required.Confi

Seite 65

Network configuration Configuring DHCP servicesFortiGate-800 Installation and Configuration Guide 157Using policy routing you can build a routing po

Seite 66 - General configuration steps

158 Fortinet Inc.Configuring DHCP services Network configurationConfiguring a DHCP relay agentIn a DHCP relay configuration, the FortiGate unit forwar

Seite 67 - CLI configuration steps

Network configuration Configuring DHCP servicesFortiGate-800 Installation and Configuration Guide 159You can add multiple scopes to an interface so

Seite 68 - 68 Fortinet Inc

16 Fortinet Inc.Antivirus protection IntroductionAntivirus protectionFortiGate ICSA-certified antivirus protection scans web (HTTP), file transfer (FT

Seite 69

160 Fortinet Inc.Configuring DHCP services Network configurationAdding a reserve IP to a DHCP serverIf you have configured an interface as a DHCP serv

Seite 70 - 70 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 161RIP configurationThe FortiGate i

Seite 71

162 Fortinet Inc.RIP settings RIP configuration5 Change the following RIP timer settings, as required.RIP timer defaults are effective in most configu

Seite 72 - 72 Fortinet Inc

RIP configuration Configuring RIP for FortiGate interfacesFortiGate-800 Installation and Configuration Guide 163Figure 34: Configuring RIP settingsC

Seite 73

164 Fortinet Inc.Configuring RIP for FortiGate interfaces RIP configuration4 Select OK to save the RIP configuration for the selected interface.Figure

Seite 74 - Configuring an HA cluster

RIP configuration Adding RIP filtersFortiGate-800 Installation and Configuration Guide 165Adding RIP filtersUse the Filter page to create RIP filter

Seite 75

166 Fortinet Inc.Adding RIP filters RIP configuration3 For Filter Name, type a name for the RIP filter list.The name can be 15 characters long and can

Seite 76 - Connecting the cluster

RIP configuration Adding RIP filtersFortiGate-800 Installation and Configuration Guide 167Assigning a RIP filter list to the outgoing filterThe outg

Seite 77

168 Fortinet Inc.Adding RIP filters RIP configuration

Seite 78 - Managing an HA cluster

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 169System configurationUse the Syst

Seite 79

Introduction Email filteringFortiGate-800 Installation and Configuration Guide 17Email filteringFortiGate email filtering can scan all IMAP and POP3

Seite 80 - Monitoring cluster members

170 Fortinet Inc.Changing system options System configuration9 Select Apply.Figure 36: Example date and time settingChanging system optionsOn the Syst

Seite 81

System configuration Changing system optionsFortiGate-800 Installation and Configuration Guide 1713 Select Apply.Auth Timeout controls the amount of

Seite 82 - Viewing cluster sessions

172 Fortinet Inc.Adding and editing administrator accounts System configurationAdding and editing administrator accountsWhen the FortiGate unit is ini

Seite 83

System configuration Configuring SNMPFortiGate-800 Installation and Configuration Guide 173Editing administrator accountsThe admin account user can

Seite 84 - 84 Fortinet Inc

174 Fortinet Inc.Configuring SNMP System configurationRFC support includes support for most of RFC 2665 (Ethernet-like MIB) and most of RFC 1213 (MIB

Seite 85

System configuration Configuring SNMPFortiGate-800 Installation and Configuration Guide 175To configure SNMP community settings1 Go to System > C

Seite 86 - Upgrading firmware

176 Fortinet Inc.Configuring SNMP System configurationFigure 37: Sample SNMP configurationFortiGate MIBsThe FortiGate SNMP agent supports FortiGate pr

Seite 87 - Advanced HA options

System configuration Configuring SNMPFortiGate-800 Installation and Configuration Guide 177FortiGate trapsThe FortiGate agent can send traps to up t

Seite 88 - 88 Fortinet Inc

178 Fortinet Inc.Configuring SNMP System configurationVPN trapsNIDS trapsAntivirus trapsLogging trapsTable 23: FortiGate VPN trapsTrap message Descrip

Seite 89

System configuration Configuring SNMPFortiGate-800 Installation and Configuration Guide 179Fortinet MIB fieldsThe Fortinet MIB contains fields for c

Seite 90 - NAT/Route mode packet flow

18 Fortinet Inc.VLANs and virtual domains IntroductionNAT/Route modeIn NAT/Route mode, you can create NAT mode policies and Route mode policies.• NAT

Seite 91 - Transparent mode packet flow

180 Fortinet Inc.Configuring SNMP System configurationUsers and authentication configurationVPN configuration and statusNIDS configurationAntivirus co

Seite 92 - 92 Fortinet Inc

System configuration Replacement messagesFortiGate-800 Installation and Configuration Guide 181Logging and reporting configurationReplacement messag

Seite 93

182 Fortinet Inc.Replacement messages System configurationCustomizing replacement messagesEach of the replacement messages in the replacement message

Seite 94 - 94 Fortinet Inc

System configuration Replacement messagesFortiGate-800 Installation and Configuration Guide 183Customizing alert emailsCustomize alert emails to con

Seite 95

184 Fortinet Inc.Replacement messages System configuration%%SOURCE_IP%% The IP address from which the block file was received. For email this is the I

Seite 96 - 96 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 185Firewall configurationFirewall p

Seite 97

186 Fortinet Inc.Default firewall configuration Firewall configurationThis chapter describes:• Default firewall configuration• Adding firewall policie

Seite 98 - 98 Fortinet Inc

Firewall configuration Default firewall configurationFortiGate-800 Installation and Configuration Guide 187InterfacesAdd policies to control connect

Seite 99

188 Fortinet Inc.Default firewall configuration Firewall configurationAddressesTo add policies between interfaces, VLAN subinterfaces, and zones, the

Seite 100 - 100 Fortinet Inc

Firewall configuration Adding firewall policiesFortiGate-800 Installation and Configuration Guide 189Content profilesAdd content profiles to policie

Seite 101

Introduction VPNFortiGate-800 Installation and Configuration Guide 19VPNUsing FortiGate virtual private networking (VPN), you can provide a secure c

Seite 102 - 102 Fortinet Inc

190 Fortinet Inc.Adding firewall policies Firewall configurationFigure 40: Adding a NAT/Route policyFirewall policy optionsThis section describes the

Seite 103

Firewall configuration Adding firewall policiesFortiGate-800 Installation and Configuration Guide 191DestinationSelect an address or address group t

Seite 104 - 104 Fortinet Inc

192 Fortinet Inc.Adding firewall policies Firewall configurationNATConfigure the policy for NAT. NAT translates the source address and the source port

Seite 105

Firewall configuration Adding firewall policiesFortiGate-800 Installation and Configuration Guide 193AuthenticationSelect Authentication and select

Seite 106 - 106 Fortinet Inc

194 Fortinet Inc.Adding firewall policies Firewall configurationFigure 41: Adding a Transparent mode policyLog TrafficSelect Log Traffic to write mess

Seite 107

Firewall configuration Configuring policy listsFortiGate-800 Installation and Configuration Guide 195Configuring policy listsThe firewall matches po

Seite 108 - Restoring system settings

196 Fortinet Inc.Configuring policy lists Firewall configurationChanging the order of policies in a policy listTo change the order of a policy in a po

Seite 109 - Changing to Transparent mode

Firewall configuration AddressesFortiGate-800 Installation and Configuration Guide 197AddressesAll policies require source and destination addresses

Seite 110 - Restarting the FortiGate unit

198 Fortinet Inc.Addresses Firewall configuration6 Enter the Netmask.The netmask corresponds to the type of address that you are adding. For example:•

Seite 111 - System status

Firewall configuration AddressesFortiGate-800 Installation and Configuration Guide 199Deleting addressesDeleting an address removes it from an addre

Seite 112 - 112 Fortinet Inc

© Copyright 2004 Fortinet Inc. All rights reserved.No part of this publication including text, examples, diagrams or illustrations may be reproduced,t

Seite 113 - System status System status

20 Fortinet Inc.Secure installation, configuration, and management IntroductionSecure installation, configuration, and managementThe first time you po

Seite 114 - Session list

200 Fortinet Inc.Services Firewall configurationFigure 43: Adding an internal address groupServicesUse services to determine the types of communicatio

Seite 115

Firewall configuration ServicesFortiGate-800 Installation and Configuration Guide 201GRE Generic Routing Encapsulation. A protocol that allows an ar

Seite 116 - 116 Fortinet Inc

202 Fortinet Inc.Services Firewall configurationLDAP Lightweight Directory Access Protocol is a set of protocols used to access information directorie

Seite 117

Firewall configuration ServicesFortiGate-800 Installation and Configuration Guide 203Adding custom TCP and UDP servicesAdd a custom TCP or UDP servi

Seite 118 - 118 Fortinet Inc

204 Fortinet Inc.Services Firewall configurationAdding custom ICMP servicesAdd a custom ICMP service if you need to create a policy for a service that

Seite 119

Firewall configuration SchedulesFortiGate-800 Installation and Configuration Guide 2053 Type a Group Name to identify the group. This name appears i

Seite 120 - Scheduling updates

206 Fortinet Inc.Schedules Firewall configurationCreating one-time schedulesYou can create a one-time schedule that activates or deactivates a policy

Seite 121 - Adding an override server

Firewall configuration SchedulesFortiGate-800 Installation and Configuration Guide 207Creating recurring schedulesYou can create a recurring schedul

Seite 122 - Enabling push updates

208 Fortinet Inc.Virtual IPs Firewall configurationAdding schedules to policiesAfter you create schedules, you can add them to policies to schedule wh

Seite 123

Firewall configuration Virtual IPsFortiGate-800 Installation and Configuration Guide 209This section describes:• Adding static NAT virtual IPs• Addi

Seite 124 - 124 Fortinet Inc

Introduction Secure installation, configuration, and managementFortiGate-800 Installation and Configuration Guide 21Command line interfaceYou can acc

Seite 125 - NAT Device

210 Fortinet Inc.Virtual IPs Firewall configuration7 In Map to IP, type the real IP address on the destination network, for example, the IP address of

Seite 126 - 126 Fortinet Inc

Firewall configuration Virtual IPsFortiGate-800 Installation and Configuration Guide 2116 Enter the External IP Address that you want to map to an a

Seite 127

212 Fortinet Inc.Virtual IPs Firewall configurationFigure 48: Adding a port forwarding virtual IPAdding policies with virtual IPsUse the following pro

Seite 128 - Registering FortiGate units

Firewall configuration IP poolsFortiGate-800 Installation and Configuration Guide 2134 Select OK to save the policy.IP poolsAn IP pool (also called

Seite 129 - FortiCare Service Contracts

214 Fortinet Inc.IP/MAC binding Firewall configurationFigure 49: Adding an IP PoolIP Pools for firewall policies that use fixed portsSome network conf

Seite 130 - 130 Fortinet Inc

Firewall configuration IP/MAC bindingFortiGate-800 Installation and Configuration Guide 215You can enter the static IP addresses and corresponding M

Seite 131

216 Fortinet Inc.IP/MAC binding Firewall configurationFor example, if the IP/MAC pair IP 1.1.1.1 and 12:34:56:78:90:ab:cd is added to the IP/MAC bindi

Seite 132 - 132 Fortinet Inc

Firewall configuration IP/MAC bindingFortiGate-800 Installation and Configuration Guide 2173 Enter the IP Address and the MAC Address.You can bind m

Seite 133

218 Fortinet Inc.Content profiles Firewall configurationFigure 50: IP/MAC settingsContent profilesUse content profiles to apply different protection s

Seite 134 - 134 Fortinet Inc

Firewall configuration Content profilesFortiGate-800 Installation and Configuration Guide 219Default content profilesThe FortiGate unit has the foll

Seite 135

22 Fortinet Inc.Document conventions IntroductionDocument conventionsThis guide uses the following conventions to describe CLI command syntax.• angle

Seite 136 - 136 Fortinet Inc

220 Fortinet Inc.Content profiles Firewall configuration6 Enable the email filter protection options that you want.7 Enable the fragmented email and o

Seite 137 - Network configuration

Firewall configuration Content profilesFortiGate-800 Installation and Configuration Guide 221Adding content profiles to policiesYou can add content

Seite 138 - Configuring interfaces

222 Fortinet Inc.Content profiles Firewall configuration

Seite 139 - Adding an interface to a zone

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 223Users and authenticationFortiGat

Seite 140 - 140 Fortinet Inc

224 Fortinet Inc.Setting authentication timeout Users and authenticationThis chapter describes:• Setting authentication timeout• Adding user names and

Seite 141

Users and authentication Adding user names and configuring authenticationFortiGate-800 Installation and Configuration Guide 2255 Select the Try othe

Seite 142 - 142 Fortinet Inc

226 Fortinet Inc.Configuring RADIUS support Users and authenticationConfiguring RADIUS supportIf you have configured RADIUS support and a user is requ

Seite 143

Users and authentication Configuring LDAP supportFortiGate-800 Installation and Configuration Guide 227Configuring LDAP supportIf you have configure

Seite 144 - 144 Fortinet Inc

228 Fortinet Inc.Configuring LDAP support Users and authentication7 Enter the distinguished name used to look up entries on the LDAP server.Enter the

Seite 145 - VLAN overview

Users and authentication Configuring user groupsFortiGate-800 Installation and Configuration Guide 229Configuring user groupsTo enable authenticatio

Seite 146 - VLANs in NAT/Route mode

Introduction Customer service and technical supportFortiGate-800 Installation and Configuration Guide 23• Volume 4: FortiGate NIDS GuideDescribes ho

Seite 147 - Adding VLAN subinterfaces

230 Fortinet Inc.Configuring user groups Users and authenticationFigure 55: Adding a user group3 Enter a Group Name to identify the user group.The nam

Seite 148 - 148 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 231IPSec VPNA Virtual Private Netwo

Seite 149 - Adding a virtual domain

232 Fortinet Inc.Key management IPSec VPNKey managementThere are three basic elements in any encryption system:• an algorithm that changes information

Seite 150 - 150 Fortinet Inc

IPSec VPN Manual key IPSec VPNsFortiGate-800 Installation and Configuration Guide 233In some respects, certificates are simpler to manage than manua

Seite 151

234 Fortinet Inc.Manual key IPSec VPNs IPSec VPN5 Enter the Remote SPI. The Remote Security Parameter Index is a hexadecimal number of up to eight dig

Seite 152 - 152 Fortinet Inc

IPSec VPN AutoIKE IPSec VPNsFortiGate-800 Installation and Configuration Guide 235AutoIKE IPSec VPNsFortiGate units support two methods of Automatic

Seite 153 - Configuring routing

236 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPN3 Type a Gateway Name for the remote VPN peer.The remote VPN peer can be either a gateway to another netw

Seite 154 - Adding a default route

IPSec VPN AutoIKE IPSec VPNsFortiGate-800 Installation and Configuration Guide 23710 Configure the Local ID the that the FortiGate unit sends to the

Seite 155

238 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPN4 Optionally, configure NAT Traversal.5 Optionally, configure Dead Peer Detection.Use these settings to m

Seite 156 - Policy routing

IPSec VPN AutoIKE IPSec VPNsFortiGate-800 Installation and Configuration Guide 239Figure 56: Adding a phase 1 configuration (Standard options)Figure

Seite 157 - Configuring DHCP services

24 Fortinet Inc.Customer service and technical support Introduction

Seite 158 - Configuring a DHCP server

240 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPNAdding a phase 2 configuration for an AutoIKE VPNAdd a phase 2 configuration to specify the parameters us

Seite 159

IPSec VPN AutoIKE IPSec VPNsFortiGate-800 Installation and Configuration Guide 24110 Enable Autokey Keep Alive if you want to keep the VPN tunnel ru

Seite 160 - 160 Fortinet Inc

242 Fortinet Inc.Managing digital certificates IPSec VPNManaging digital certificatesUse digital certificates to make sure that both participants in a

Seite 161 - RIP configuration

IPSec VPN Managing digital certificatesFortiGate-800 Installation and Configuration Guide 2436 Configure the key.7 Select OK to generate the private

Seite 162 - 162 Fortinet Inc

244 Fortinet Inc.Managing digital certificates IPSec VPNDownloading the certificate requestUse the following procedure to download a certificate reque

Seite 163

IPSec VPN Configuring encrypt policiesFortiGate-800 Installation and Configuration Guide 245Obtaining CA certificatesFor the VPN peers to authentica

Seite 164 - 164 Fortinet Inc

246 Fortinet Inc.Configuring encrypt policies IPSec VPNIn addition to defining membership in the VPN by address, you can configure the encrypt policy

Seite 165 - Adding RIP filters

IPSec VPN Configuring encrypt policiesFortiGate-800 Installation and Configuration Guide 247Adding a destination addressThe destination address can

Seite 166 - 166 Fortinet Inc

248 Fortinet Inc.Configuring encrypt policies IPSec VPNFor information about configuring the remaining policy settings, see “Adding firewall policies”

Seite 167

IPSec VPN IPSec VPN concentratorsFortiGate-800 Installation and Configuration Guide 249Figure 60: Adding an encrypt policyIPSec VPN concentrators In

Seite 168 - 168 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 25Getting startedThis chapter descr

Seite 169 - System configuration

250 Fortinet Inc.IPSec VPN concentrators IPSec VPNIf the VPN peer is one of the spokes, it requires a tunnel connecting it to the hub (but not to the

Seite 170 - Changing system options

IPSec VPN IPSec VPN concentratorsFortiGate-800 Installation and Configuration Guide 251See “Adding an encrypt policy” on page 247.5 Arrange the poli

Seite 171

252 Fortinet Inc.IPSec VPN concentrators IPSec VPNVPN spoke general configuration stepsA remote VPN peer that functions as a spoke requires the follow

Seite 172 - 172 Fortinet Inc

IPSec VPN Redundant IPSec VPNsFortiGate-800 Installation and Configuration Guide 253See “Adding an encrypt policy” on page 247.6 Arrange the policie

Seite 173 - Configuring SNMP

254 Fortinet Inc.Redundant IPSec VPNs IPSec VPNConfiguring redundant IPSec VPNsPrior to configuring the VPN, make sure that both FortiGate units have

Seite 174 - 174 Fortinet Inc

IPSec VPN Monitoring and Troubleshooting VPNsFortiGate-800 Installation and Configuration Guide 255Monitoring and Troubleshooting VPNs• Viewing VPN

Seite 175 - 4 Select Apply

256 Fortinet Inc.Monitoring and Troubleshooting VPNs IPSec VPNFigure 63: Dialup MonitorTesting a VPNTo confirm that a VPN between two networks has bee

Seite 176 - FortiGate MIBs

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 257PPTP and L2TP VPNYou can use PPT

Seite 177 - System traps

258 Fortinet Inc.Configuring PPTP PPTP and L2TP VPNConfiguring the FortiGate unit as a PPTP gatewayUse the following procedures to configure the Forti

Seite 178 - Logging traps

PPTP and L2TP VPN Configuring PPTPFortiGate-800 Installation and Configuration Guide 2593 Select New to add an address.4 Enter the Address Name, IP

Seite 179 - Firewall configuration

26 Fortinet Inc.Package contents Getting startedPackage contentsThe FortiGate-800 package contains the following items:• FortiGate-800 Antivirus Firew

Seite 180

260 Fortinet Inc.Configuring PPTP PPTP and L2TP VPN6 Set Service to match the traffic type inside the PPTP VPN tunnel. For example, if PPTP users can

Seite 181 - Replacement messages

PPTP and L2TP VPN Configuring PPTPFortiGate-800 Installation and Configuration Guide 261To connect to the PPTP VPN1 Start the dialup connection that

Seite 182 - 182 Fortinet Inc

262 Fortinet Inc.Configuring PPTP PPTP and L2TP VPN5 Name the connection and select Next. 6 If the Public Network dialog box appears, choose the appro

Seite 183 - Customizing alert emails

PPTP and L2TP VPN Configuring L2TPFortiGate-800 Installation and Configuration Guide 263Configuring L2TPSome implementations of L2TP support element

Seite 184 - 184 Fortinet Inc

264 Fortinet Inc.Configuring L2TP PPTP and L2TP VPNFigure 65: Sample L2TP address range configurationTo add source addressesAdd a source address for e

Seite 185

PPTP and L2TP VPN Configuring L2TPFortiGate-800 Installation and Configuration Guide 2656 Select OK to add the address group.To add a destination ad

Seite 186 - 186 Fortinet Inc

266 Fortinet Inc.Configuring L2TP PPTP and L2TP VPN7 In the Connect window, select Properties.8 Select the Security tab.9 Make sure that Require data

Seite 187 - VLAN subinterfaces

PPTP and L2TP VPN Configuring L2TPFortiGate-800 Installation and Configuration Guide 2674 In the connect window, enter the User Name and Password th

Seite 188 - Schedules

268 Fortinet Inc.Configuring L2TP PPTP and L2TP VPNTo disable IPSec1 Select the Networking tab.2 Select Internet Protocol (TCP/IP) properties.3 Double

Seite 189 - Adding firewall policies

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 269Network Intrusion Detection Syst

Seite 190 - Firewall policy options

Getting started Powering onFortiGate-800 Installation and Configuration Guide 27Power requirements• Power dissipation: 300 W (max)• AC input voltage

Seite 191 - Schedule

270 Fortinet Inc.Detecting attacks Network Intrusion Detection System (NIDS)Selecting the interfaces to monitorTo select the interfaces to monitor for

Seite 192 - Traffic Shaping

Network Intrusion Detection System (NIDS) Detecting attacksFortiGate-800 Installation and Configuration Guide 271Viewing the signature listYou can d

Seite 193 - Anti-Virus & Web filter

272 Fortinet Inc.Detecting attacks Network Intrusion Detection System (NIDS)Figure 67: Example signature group members listDisabling NIDS attack signa

Seite 194 - Comments

Network Intrusion Detection System (NIDS) Detecting attacksFortiGate-800 Installation and Configuration Guide 273To add user-defined signatures1 Go

Seite 195 - Configuring policy lists

274 Fortinet Inc.Preventing attacks Network Intrusion Detection System (NIDS)Preventing attacksNIDS attack prevention protects the FortiGate unit and

Seite 196 - Enabling policies

Network Intrusion Detection System (NIDS) Preventing attacksFortiGate-800 Installation and Configuration Guide 275Setting signature threshold values

Seite 197

276 Fortinet Inc.Logging attacks Network Intrusion Detection System (NIDS)To set Prevention signature threshold values1 Go to NIDS > Prevention.2 S

Seite 198 - Editing addresses

Network Intrusion Detection System (NIDS) Logging attacksFortiGate-800 Installation and Configuration Guide 277The FortiGate unit uses an alert emai

Seite 199 - Deleting addresses

278 Fortinet Inc.Logging attacks Network Intrusion Detection System (NIDS)

Seite 200

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 279Antivirus protectionYou can enab

Seite 201

28 Fortinet Inc.Connecting to the web-based manager Getting startedConnecting to the web-based managerUse the following procedure to connect to the we

Seite 202 - 202 Fortinet Inc

280 Fortinet Inc.Antivirus scanning Antivirus protection6 Configure the FortiGate unit to send an alert email when it blocks or deletes an infected fi

Seite 203

Antivirus protection File blockingFortiGate-800 Installation and Configuration Guide 281Figure 69: Example content profile for virus scanningFile bl

Seite 204 - Grouping services

282 Fortinet Inc.File blocking Antivirus protectionBy default, when blocking is enabled, the FortiGate unit blocks the following file patterns:• execu

Seite 205

Antivirus protection QuarantineFortiGate-800 Installation and Configuration Guide 283QuarantineFortiGate units with a hard disk can quarantine block

Seite 206 - Creating one-time schedules

284 Fortinet Inc.Quarantine Antivirus protection5 Add this content profile to firewall policies.See “Adding content profiles to policies” on page 221.

Seite 207 - Creating recurring schedules

Antivirus protection QuarantineFortiGate-800 Installation and Configuration Guide 285Filtering the quarantine listYou can filter the quarantine list

Seite 208 - Virtual IPs

286 Fortinet Inc.Blocking oversized files and emails Antivirus protection3 Type the Age Limit (TTL) in hours to specify how long files are left in qua

Seite 209 - Adding static NAT virtual IPs

Antivirus protection Exempting fragmented email from blockingFortiGate-800 Installation and Configuration Guide 287Exempting fragmented email from b

Seite 210 - 210 Fortinet Inc

288 Fortinet Inc.Viewing the virus list Antivirus protection

Seite 211

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 289Web filteringWhen you enable Ant

Seite 212 - 212 Fortinet Inc

Getting started Connecting to the command line interface (CLI)FortiGate-800 Installation and Configuration Guide 29Connecting to the command line in

Seite 213 - IP pools

290 Fortinet Inc.Content blocking Web filtering3 Configure web filtering settings to control how the FortiGate unit applies web filtering to the HTTP

Seite 214 - IP/MAC binding

Web filtering Content blockingFortiGate-800 Installation and Configuration Guide 2914 Type a banned word or phrase.If you type a single word (for ex

Seite 215

292 Fortinet Inc.Content blocking Web filteringBacking up the Banned Word listYou can back up the banned word list by downloading it to a text file on

Seite 216 - Adding IP/MAC addresses

Web filtering URL blockingFortiGate-800 Installation and Configuration Guide 2935 Select Return to display the updated Banned Word List.6 You can co

Seite 217 - Enabling IP/MAC binding

294 Fortinet Inc.URL blocking Web filtering4 Ensure that the Enable checkbox has been selected and then select OK.5 Select OK to add the URL to the We

Seite 218 - Content profiles

Web filtering URL blockingFortiGate-800 Installation and Configuration Guide 295Downloading the Web URL block listYou can back up the Web URL block

Seite 219 - Adding content profiles

296 Fortinet Inc.Configuring Cerberian URL filtering Web filtering8 You can continue to maintain the Web URL block list by making changes to the text

Seite 220 - 220 Fortinet Inc

Web filtering Configuring Cerberian URL filteringFortiGate-800 Installation and Configuration Guide 297Installing a Cerberian license keyBefore you

Seite 221

298 Fortinet Inc.Configuring Cerberian URL filtering Web filteringYou can add users to the default group and apply any policies to the group.Use the d

Seite 222 - 222 Fortinet Inc

Web filtering Script filteringFortiGate-800 Installation and Configuration Guide 299Script filteringYou can configure the FortiGate unit to remove J

Seite 223 - Users and authentication

ContentsFortiGate-800 Installation and Configuration Guide 3Table of ContentsIntroduction ...

Seite 224 - 224 Fortinet Inc

30 Fortinet Inc.Factory default FortiGate configuration settings Getting startedFactory default FortiGate configuration settingsThe FortiGate unit is

Seite 225

300 Fortinet Inc.Exempt URL list Web filteringExempt URL listAdd URLs to the exempt URL list to allow legitimate traffic that might otherwise be block

Seite 226 - Configuring RADIUS support

Web filtering Exempt URL listFortiGate-800 Installation and Configuration Guide 301Figure 75: Example URL Exempt listDownloading the URL Exempt List

Seite 227 - Configuring LDAP support

302 Fortinet Inc.Exempt URL list Web filtering3 Select Upload URL Exempt List .4 Type the path and filename of your URL Exempt List text file, or sel

Seite 228 - Deleting LDAP servers

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 303Email filterEmail filtering is e

Seite 229 - Configuring user groups

304 Fortinet Inc.Email banned word list Email filterEmail banned word listWhen the FortiGate unit detects an email that contains a word or phrase in t

Seite 230 - Deleting user groups

Email filter Email banned word listFortiGate-800 Installation and Configuration Guide 305Downloading the email banned word listYou can back up the b

Seite 231 - IPSec VPN

306 Fortinet Inc.Email block list Email filterEmail block listYou can configure the FortiGate unit to tag all IMAP and POP3 protocol traffic sent from

Seite 232 - Key management

Email filter Email exempt listFortiGate-800 Installation and Configuration Guide 307Uploading an email block listYou can create a email block list i

Seite 233 - Manual key IPSec VPNs

308 Fortinet Inc.Adding a subject tag Email filterAdding address patterns to the email exempt listTo add an address pattern to the email exempt list1

Seite 234 - 234 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 309Logging and reportingYou can con

Seite 235 - AutoIKE IPSec VPNs

Getting started Factory default FortiGate configuration settingsFortiGate-800 Installation and Configuration Guide 31Factory default Transparent mod

Seite 236 - 236 Fortinet Inc

310 Fortinet Inc.Recording logs Logging and reportingRecording logs on a remote computerYou can configure the FortiGate unit to record log messages on

Seite 237 - Configuring advanced options

Logging and reporting Recording logsFortiGate-800 Installation and Configuration Guide 3115 Select Config Policy.To configure the FortiGate unit to

Seite 238 - 238 Fortinet Inc

312 Fortinet Inc.Recording logs Logging and reportingRecording logs in system memoryIf your FortiGate unit does not contain a hard disk, you can confi

Seite 239 - IPSec VPN AutoIKE IPSec VPNs

Logging and reporting Filtering log messagesFortiGate-800 Installation and Configuration Guide 313Filtering log messagesYou can configure the logs t

Seite 240 - 240 Fortinet Inc

314 Fortinet Inc.Configuring traffic logging Logging and reportingFigure 79: Example log filter configurationConfiguring traffic loggingYou can config

Seite 241

Logging and reporting Configuring traffic loggingFortiGate-800 Installation and Configuration Guide 315Enabling traffic loggingYou can enable loggin

Seite 242 - Managing digital certificates

316 Fortinet Inc.Configuring traffic logging Logging and reportingConfiguring traffic filter settingsYou can configure the information recorded in all

Seite 243 - 6 Configure the key

Logging and reporting Viewing logs saved to memoryFortiGate-800 Installation and Configuration Guide 3174 Select OK.The traffic filter list displays

Seite 244 - 244 Fortinet Inc

318 Fortinet Inc.Viewing and managing logs saved to the hard disk Logging and reporting4 To view a specific line in the log, type a line number in the

Seite 245 - Configuring encrypt policies

Logging and reporting Viewing and managing logs saved to the hard diskFortiGate-800 Installation and Configuration Guide 319Viewing logsLog messages

Seite 246 - Adding a source address

32 Fortinet Inc.Factory default FortiGate configuration settings Getting startedFactory default firewall configurationThe factory default firewall con

Seite 247 - Adding an encrypt policy

320 Fortinet Inc.Viewing and managing logs saved to the hard disk Logging and reportingDownloading a log file to the management computerYou can downlo

Seite 248 - 248 Fortinet Inc

Logging and reporting Configuring alert emailFortiGate-800 Installation and Configuration Guide 321Configuring alert emailYou can configure the Fort

Seite 249 - IPSec VPN concentrators

322 Fortinet Inc.Configuring alert email Logging and reportingEnabling alert emailYou can configure the FortiGate unit to send alert email in response

Seite 250 - 250 Fortinet Inc

FortiGate-800 Installation and Configuration Guide 323FortiGate-800 Installation and Configuration Guide Version 2.50GlossaryConnection: A link betwe

Seite 251 - Adding a VPN concentrator

324 Fortinet Inc.GlossaryLAN, Local Area Network: A computer network that spans a relatively small area. Most LANs connect workstations and personal c

Seite 252 - 252 Fortinet Inc

GlossaryFortiGate-800 Installation and Configuration Guide 325SSH, Secure shell: A secure Telnet replacement that you can use to log into another c

Seite 253 - Redundant IPSec VPNs

326 Fortinet Inc.Glossary

Seite 254 - 254 Fortinet Inc

FortiGate-800 Installation and Configuration Guide 327FortiGate-800 Installation and Configuration Guide Version 2.50IndexAacceptpolicy 191actionpoli

Seite 255 - Viewing VPN tunnel status

328 Fortinet Inc.Indexattack updatesconfiguring 121scheduling 120through a proxy server 122authentication 193, 223configuring 224enabling 229LDAP serv

Seite 256 - Testing a VPN

IndexFortiGate-800 Installation and Configuration Guide 329DHCPadding a DHCP server to an interface 158adding a reserved IP to a DHCP server 160add

Seite 257 - PPTP and L2TP VPN

Getting started Factory default FortiGate configuration settingsFortiGate-800 Installation and Configuration Guide 33Factory default content profile

Seite 258 - 258 Fortinet Inc

330 Fortinet Inc.IndexFortiResponse Distribution Network 118connecting to 118FortiResponse Distribution Server 118from IPsystem status 115from portsys

Seite 259

IndexFortiGate-800 Installation and Configuration Guide 331IPSec VPNauthentication for user group 229AutoIKE 232certificates 232disabling 266, 268m

Seite 260 - 260 Fortinet Inc

332 Fortinet Inc.IndexmodeTransparent 18monitorsystem status 114monitored interfaces 270monitoringsystem status 111MTU size 144changing 144definition

Seite 261

IndexFortiGate-800 Installation and Configuration Guide 333PPTP dialup connectionconfiguring Windows 2000 client 261configuring Windows 98 client 2

Seite 262 - 262 Fortinet Inc

334 Fortinet Inc.Indexschedule 205applying to policy 208automatic antivirus and attack definition updates 120creating one-time 206creating recurring 2

Seite 263 - Configuring L2TP

IndexFortiGate-800 Installation and Configuration Guide 335system settingsbacking up 108restoring 108restoring to factory default 109system status

Seite 264 - 264 Fortinet Inc

336 Fortinet Inc.Indexviewingdialup connection status 255logs 318, 319logs saved to memory 317VPN tunnel status 255virtual domainadding 149adding a VL

Seite 265

34 Fortinet Inc.Factory default FortiGate configuration settings Getting startedScan content profileUse the scan content profile to apply antivirus sc

Seite 266 - 266 Fortinet Inc

Getting started Factory default FortiGate configuration settingsFortiGate-800 Installation and Configuration Guide 35Web content profileUse the web

Seite 267

36 Fortinet Inc.Planning the FortiGate configuration Getting startedPlanning the FortiGate configurationBefore you configure the FortiGate unit, you n

Seite 268 - 268 Fortinet Inc

Getting started Planning the FortiGate configurationFortiGate-800 Installation and Configuration Guide 37NAT/Route mode with multiple external netwo

Seite 269 - Detecting attacks

38 Fortinet Inc.Planning the FortiGate configuration Getting startedFigure 6: Example Transparent mode network configurationYou can connect up to 8 ne

Seite 270 - 270 Fortinet Inc

Getting started FortiGate model maximum values matrixFortiGate-800 Installation and Configuration Guide 39Front keypad and LCDIf you are configuring

Seite 271 - Viewing attack descriptions

Contents4 Fortinet Inc.NAT/Route mode installation... 41Preparing to conf

Seite 272 - 272 Fortinet Inc

40 Fortinet Inc.Next steps Getting startedNext stepsNow that your FortiGate unit is operating, you can proceed to configure it to connect to networks:

Seite 273

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 41NAT/Route mode installationThis c

Seite 274 - Preventing attacks

42 Fortinet Inc.Preparing to configure NAT/Route mode NAT/Route mode installationAdvanced NAT/Route mode settingsUse Tab le 11 to gather the informat

Seite 275

NAT/Route mode installation Using the setup wizardFortiGate-800 Installation and Configuration Guide 43DMZ and user-defined interfacesUse Tab le 12

Seite 276 - Logging attacks

44 Fortinet Inc.Using the front control buttons and LCD NAT/Route mode installationUsing the front control buttons and LCDAs an alternative to the set

Seite 277 - Manual message reduction

NAT/Route mode installation Using the command line interfaceFortiGate-800 Installation and Configuration Guide 453 Set the IP address and netmask of

Seite 278 - 278 Fortinet Inc

46 Fortinet Inc.Connecting the FortiGate unit to your networks NAT/Route mode installation9 Set the default route to the Default Gateway IP address (n

Seite 279

NAT/Route mode installation Connecting the FortiGate unit to your networksFortiGate-800 Installation and Configuration Guide 47Figure 7: FortiGate-8

Seite 280 - Antivirus scanning

48 Fortinet Inc.Configuring your networks NAT/Route mode installationFigure 8: Example FortiGate-800 user-defined interface connectionsConfiguring you

Seite 281 - File blocking

NAT/Route mode installation Completing the configurationFortiGate-800 Installation and Configuration Guide 49Completing the configurationUse the inf

Seite 282 - Adding file patterns to block

ContentsFortiGate-800 Installation and Configuration Guide 5Transparent mode configuration examples...

Seite 283 - Quarantine

50 Fortinet Inc.Configuration example: Multiple connections to the Internet NAT/Route mode installationRegistering your FortiGate unitAfter purchasing

Seite 284 - Sorting the quarantine list

NAT/Route mode installation Configuration example: Multiple connections to the InternetFortiGate-800 Installation and Configuration Guide 51Figure 9

Seite 285 - Downloading quarantined files

52 Fortinet Inc.Configuration example: Multiple connections to the Internet NAT/Route mode installationUsing the CLI1 Add a ping server to the externa

Seite 286 - 286 Fortinet Inc

NAT/Route mode installation Configuration example: Multiple connections to the InternetFortiGate-800 Installation and Configuration Guide 53Load sha

Seite 287 - Viewing the virus list

54 Fortinet Inc.Configuration example: Multiple connections to the Internet NAT/Route mode installation3 Select New to add a route for connections to

Seite 288 - 288 Fortinet Inc

NAT/Route mode installation Configuration example: Multiple connections to the InternetFortiGate-800 Installation and Configuration Guide 55Policy r

Seite 289 - Web filtering

56 Fortinet Inc.Configuration example: Multiple connections to the Internet NAT/Route mode installationFirewall policy exampleFirewall policies contro

Seite 290 - Content blocking

NAT/Route mode installation Configuration example: Multiple connections to the InternetFortiGate-800 Installation and Configuration Guide 57Restrict

Seite 291 - Clearing the Banned Word list

58 Fortinet Inc.Configuration example: Multiple connections to the Internet NAT/Route mode installation

Seite 292 - 292 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 59Transparent mode installationThis

Seite 293 - URL blocking

Contents6 Fortinet Inc.Displaying the FortiGate up time... 108Disp

Seite 294 - 294 Fortinet Inc

60 Fortinet Inc.Using the setup wizard Transparent mode installationUsing the setup wizardFrom the web-based manager, you can use the setup wizard to

Seite 295 - Uploading a URL block list

Transparent mode installation Using the front control buttons and LCDFortiGate-800 Installation and Configuration Guide 61Using the front control bu

Seite 296 - 296 Fortinet Inc

62 Fortinet Inc.Completing the configuration Transparent mode installationConfiguring the Transparent mode management IP address1 Make sure that you a

Seite 297 - Adding a Cerberian user

Transparent mode installation Connecting the FortiGate unit to your networksFortiGate-800 Installation and Configuration Guide 63Registering your Fo

Seite 298 - 298 Fortinet Inc

64 Fortinet Inc.Transparent mode configuration examples Transparent mode installationFigure 10: FortiGate-800 Transparent mode connectionsTransparent

Seite 299 - Script filtering

Transparent mode installation Transparent mode configuration examplesFortiGate-800 Installation and Configuration Guide 65This section describes:• D

Seite 300 - Exempt URL list

66 Fortinet Inc.Transparent mode configuration examples Transparent mode installationFigure 11: Default route to an external networkGeneral configura

Seite 301 - 1 Enabled

Transparent mode installation Transparent mode configuration examplesFortiGate-800 Installation and Configuration Guide 67Web-based manager example

Seite 302 - 302 Fortinet Inc

68 Fortinet Inc.Transparent mode configuration examples Transparent mode installationFigure 12: Static route to an external destinationGeneral configu

Seite 303 - Email filter

Transparent mode installation Transparent mode configuration examplesFortiGate-800 Installation and Configuration Guide 692 Go to System > Networ

Seite 304 - Email banned word list

ContentsFortiGate-800 Installation and Configuration Guide 7Network configuration...

Seite 305

70 Fortinet Inc.Transparent mode configuration examples Transparent mode installationFigure 13: Static route to an internal destinationGeneral configu

Seite 306 - Email block list

Transparent mode installation Transparent mode configuration examplesFortiGate-800 Installation and Configuration Guide 71Web-based manager example

Seite 307 - Email exempt list

72 Fortinet Inc.Transparent mode configuration examples Transparent mode installation

Seite 308 - Adding a subject tag

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 73High availabilityFortinet achieve

Seite 309

74 Fortinet Inc.Configuring an HA cluster High availabilityAn active-passive (A-P) HA cluster, also referred to as hot standby HA, consists of a prima

Seite 310 - 310 Fortinet Inc

High availability Configuring an HA clusterFortiGate-800 Installation and Configuration Guide 756 Select the HA mode.Select Active-Active mode to cr

Seite 311

76 Fortinet Inc.Configuring an HA cluster High availabilityFigure 14: Example Active-Active HA configuration11 If you are configuring a NAT/Route mode

Seite 312 - Log message levels

High availability Configuring an HA clusterFortiGate-800 Installation and Configuration Guide 77Inserting an HA cluster into your network temporaril

Seite 313 - Filtering log messages

78 Fortinet Inc.Managing an HA cluster High availability2 Power on all the FortiGate units in the cluster.As the units power on they negotiate to choo

Seite 314 - Configuring traffic logging

High availability Managing an HA clusterFortiGate-800 Installation and Configuration Guide 79You can also use SNMP to manage the cluster by configur

Seite 315 - Enabling traffic logging

Contents8 Fortinet Inc.Adding RIP filters ...

Seite 316 - Adding traffic filter entries

80 Fortinet Inc.Managing an HA cluster High availabilityTo monitor cluster interfaces1 Connect to the cluster and log into the web-based manager.2 Go

Seite 317 - Viewing logs saved to memory

High availability Managing an HA clusterFortiGate-800 Installation and Configuration Guide 813 Select Sessions & Network.The cluster displays se

Seite 318 - Searching logs

82 Fortinet Inc.Managing an HA cluster High availabilityViewing cluster sessionsTo view the cluster communication sessions1 Connect to the cluster and

Seite 319 - Viewing logs

High availability Managing an HA clusterFortiGate-800 Installation and Configuration Guide 83Monitoring cluster units for failoverIf the primary uni

Seite 320 - Deleting a saved log file

84 Fortinet Inc.Managing an HA cluster High availabilityTo manage a cluster unit1 Use SSH to connect to the cluster and log into the CLI.Connect to an

Seite 321 - Configuring alert email

High availability Managing an HA clusterFortiGate-800 Installation and Configuration Guide 85Synchronizing the cluster configurationCluster synchron

Seite 322 - Enabling alert email

86 Fortinet Inc.Managing an HA cluster High availability4 Repeat steps 2 and 3 for all the subordinate units in the HA cluster.Upgrading firmwareTo up

Seite 323 - Glossary

High availability Advanced HA optionsFortiGate-800 Installation and Configuration Guide 87Replacing a FortiGate unit after failoverA failover can oc

Seite 324 - 324 Fortinet Inc

88 Fortinet Inc.Advanced HA options High availabilityset system ha override enableEnable override so that the permanent primary unit overrides any oth

Seite 325 - Glossary

High availability Active-Active cluster packet flowFortiGate-800 Installation and Configuration Guide 89Weight values are entered in order according

Seite 326 - 326 Fortinet Inc

ContentsFortiGate-800 Installation and Configuration Guide 9Services ...

Seite 327

90 Fortinet Inc.Active-Active cluster packet flow High availabilityNAT/Route mode packet flowIn NAT/Route mode, five MAC addresses are involved in act

Seite 328 - 328 Fortinet Inc

High availability Active-Active cluster packet flowFortiGate-800 Installation and Configuration Guide 91The following are examples of switches that

Seite 329

92 Fortinet Inc.Active-Active cluster packet flow High availability

Seite 330 - 330 Fortinet Inc

FortiGate-800 Installation and Configuration Guide Version 2.50FortiGate-800 Installation and Configuration Guide 93System statusYou can connect to t

Seite 331

94 Fortinet Inc.Changing the FortiGate host name System statusChanging the FortiGate host nameThe FortiGate host name appears on the Status page and i

Seite 332 - 332 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 95Upgrading to a new firmware versionUse the followi

Seite 333

96 Fortinet Inc.Changing the FortiGate firmware System status4 Make sure the FortiGate unit can connect to the TFTP server.You can use the following c

Seite 334 - 334 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 97If you are reverting to a previous FortiOS version

Seite 335

98 Fortinet Inc.Changing the FortiGate firmware System statusIf you are reverting to a previous FortiOS version (for example, reverting from FortiOS v

Seite 336 - 336 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-800 Installation and Configuration Guide 9911 Update antivirus and attack definitions. For in

Kommentare zu diesen Handbüchern

Keine Kommentare