Manuel d’utilisation Fortinet 800

60 pages 1.35 mb
Télécharger

Aller à la page of 60

Summary
  • Fortinet 800 - page 1

    FortiGate 800/800F Installation Guide Esc Enter CONSOLE INTERNAL EXTERNAL DMZ H A 1 2 3 4 USB 800F PWR Esc Enter CONSOLE INTERNAL EXTERNAL DMZ HA 123 4 USB 8 PWR F or tiGate-800F F or tiGate-800 Ve r s i o n 2 . 8 0 M R 6 26 October 2004 01-28006-00 24-20041026 ...

  • Fortinet 800 - page 2

    © Copyright 2004 Fortine t Inc. All rights reserved. No part of this publication incl uding text, examples , diagrams or illustrations may be reproduced, transmitted, or translated in any form or by an y means, electro nic, mechanical, manual, optical or otherwise, for any purpose, without prio r written permiss ion of Fortinet Inc. FortiGate-800/ ...

  • Fortinet 800 - page 3

    Contents FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 3 Table of Contents Introduction ............. .............................. ........................................................ ......... 5 Secure installation, configurat ion, and management ................ ................... ................... .... 5 Web-based manag ...

  • Fortinet 800 - page 4

    Contents 4 01-28006-0024-2004102 6 Fortinet Inc. Using the setup wizard............. ................... .................... ................ ................... ............... 34 Starting the setup wizard .................. ................... .................... ................... .................. 35 Connecting the FortiGate unit to the net ...

  • Fortinet 800 - page 5

    FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 5 Introduction FortiGate A ntivirus Firewalls improve netwo rk security , reduc e network misu se and abuse, and help you use communication s resources more efficiently without compromising the performance of yo ur netw ork. Fort ...

  • Fortinet 800 - page 6

    6 01-28006-0024-2004102 6 Fortinet Inc. Web-based manage r Introduction The CLI or the web-based manager can then be used to complete configuration and to perform maintenance and administration. Web-based manager Using HTTP or a secure HTTPS connection from any co mputer running Internet Explorer , you can configure and manage th e FortiGate unit. ...

  • Fortinet 800 - page 7

    Introduction Setup wizard FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 7 Setup wizard The FortiGate setup wizard p rovides an easy way to configure the b asic initial settings for the FortiGate unit. Th e wizard walks through the con figuration of a new administrato r password, FortiGat e interfaces, D HCP server se ttings, intern ...

  • Fortinet 800 - page 8

    8 01-28006-0024-2004102 6 Fortinet Inc. Setup wizard Introduction set allowaccess {ping https ssh snmp http telnet} Y ou can enter an y of the following: set allowaccess ping set allowaccess ping https ssh set allowaccess https ping ssh set allowaccess snmp In most ca ses to make cha n ges to lists that contain options se parated by sp aces, you ne ...

  • Fortinet 800 - page 9

    Introduction FortiManager documentation FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 9 Related document ation Additional info rmation about Fortinet produc t s is available from the following related documentation . FortiManager documentation • FortiManager QuickS tart Guide Explains how to inst all the FortiManager Console , se ...

  • Fortinet 800 - page 10

    10 01-28006-0024-2004102 6 Fortinet Inc. FortiLog documentation Introduction FortiLog documentation • FortiLog Administration Guide Describes how to install and configure a FortiLog unit to collect FortiGa te and FortiMail log files. It also describes how to view FortiGate and FortiMail log files, generate and view log report s, and use the Forti ...

  • Fortinet 800 - page 11

    Introduction Comments on Fortine t technical documenta tion FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 11 Customer service and technical support For antiviru s and attack defi nition up dates, firmware updates, updated product documentation , technical support informatio n, and other r esources, please visit the Fortinet technic ...

  • Fortinet 800 - page 12

    12 01-28006-0024-2004102 6 Fortinet Inc. Comments on Fortinet technica l docume ntation Introduction ...

  • Fortinet 800 - page 13

    FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 13 Getting st arted This section describes unp acking, setting up, and powering on a For tiGate Antivirus Firewall unit. This section includes: • Package content s • Mounting • T u rning the F ortiGate unit power on and off ...

  • Fortinet 800 - page 14

    14 01-28006-0024-2004102 6 Fortinet Inc. Getting started Package content s The FortiGate-800 an d FortiGate-800F packa ge contains the following items: • FortiGate-800 or FortiGate-80 0F Antivirus Firewall • one orange crossover ethernet cable (F ortinet part number CC300248) • one grey regular ethernet cable (Fortin et part number CC300249) ...

  • Fortinet 800 - page 15

    Getting started FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 15 Mounting The FortiGate-800/8 00F unit can be mounte d in a standa rd 19-inch rack. It requires 1 U of vertical space in the rack. The FortiGate-800/8 00F unit can also be inst alled as a free-standing a ppliance on any stable surface. Dimensions • 16.75 x 12 x 1.75 ...

  • Fortinet 800 - page 16

    16 01-28006-0024-2004102 6 Fortinet Inc. Getting started T urning the FortiGate unit power on and off T a ble 2: FortiGate- 800F LED in dicators T o power off the FortiGate unit Always shut down the FortiGate operatin g system properly bef ore turning off the power switch. 1 From the web-ba sed manager , go to System > Maintenance > ShutDown ...

  • Fortinet 800 - page 17

    Getting started FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 17 T o connect to the web-based manager, you need: • a computer with an ethernet connection, • Internet Explorer version 6.0 or higher , • a crossover cable or an etherne t hub and two ethernet cable s. T o connect to the web-based manager 1 Set the IP address of t ...

  • Fortinet 800 - page 18

    18 01-28006-0024-2004102 6 Fortinet Inc. Getting started T o connect to the CLI 1 Connect the serial cable to the communication s port of your computer and to the FortiGate Console port. Use the RJ-45 to DB-9 conver tor if your PC communications port re quires a DB-9 connector . 2 Make sure that the FortiGa te unit is powered on. 3 S tart HyperT er ...

  • Fortinet 800 - page 19

    Getting started Factory default NAT/Route mod e network configuration FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 19 Factory default FortiGate configuration settings The FortiGate unit is shipped with a fa ct ory default co nfiguration. T he default configuration allows you to connect to and use the FortiGa te web-based manager t ...

  • Fortinet 800 - page 20

    20 01-28006-0024-2004102 6 Fortinet Inc. Factory default Transpar ent mode network configuration Getting started Factory default Transparent mode network configuration In T ransparent mode, th e FortiGate unit has the default network configurat ion listed in Ta b l e 4 . HA interface IP: 0.0.0.0 Netmask: 0.0.0.0 Administrative Access: Ping Port 1 I ...

  • Fortinet 800 - page 21

    Getting started Factory default firewall configurati on FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 21 Factory default firewall configuration FortiGate firewall policies cont rol how all traf fic is processed by the FortiGate unit. Until firewall p olicies are added , no traffic can be ac cepted by or pass th rough the FortiGate ...

  • Fortinet 800 - page 22

    22 01-28006-0024-2004102 6 Fortinet Inc. Factory default protection profiles Getting started Using protection profiles, you can build pr ot ection configurations that can be applied to different types of firewall policies. This allows you to customize types and levels of protection for dif ferent firewall policies. For example, while traf fic betwe ...

  • Fortinet 800 - page 23

    Getting started NAT/Route mode FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 23 Planning the FortiGate configuration Before you configure the F ortiGate unit, you need to plan how to integrate the unit into the network. Amo ng other things, yo u must decide whethe r you want the unit to be visible to the network, which firewall fun ...

  • Fortinet 800 - page 24

    24 01-28006-0024-2004102 6 Fortinet Inc. NAT/Route mode with multiple external network connecti ons Getting started NAT/Route mode with multiple external network connections In NA T/Route mode, you can configure th e FortiGate u nit with multiple redundant connections to the external networ k (usually the Intern et). For example, you could create t ...

  • Fortinet 800 - page 25

    Getting started Configuration options FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 25 Figure 8: Example T ra nsp arent mode networ k configuration Y ou can connect up to 8 network segment s to the FortiGate unit to control traffic between these network segment s. • External can connect to the external firewall or router . • In ...

  • Fortinet 800 - page 26

    26 01-28006-0024-2004102 6 Fortinet Inc. Configuration opti ons Getting started If you are configuring the FortiGate unit to operate in Tr ansparent mode, you can use the front k eypad and LCD to s witch to Transparent mode. Then you can add t he management IP addr ess and default gateway . If you are configuring the FortiGate unit to operate in Tr ...

  • Fortinet 800 - page 27

    FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 27 NA T/Route mode inst allation This chapter describes how to install the FortiGate un it in NA T/Route mode. For information about installing a FortiGate unit in T ransparent mode, see “T ransp arent mode inst allation” on ...

  • Fortinet 800 - page 28

    28 01-28006-0024-2004102 6 Fortinet Inc. DHCP or PPPoE confi guration NAT/Route mode installati on DHCP or PPPoE configuration Y ou can configure any FortiGate interface to acquire it s IP address from a DHCP or PPPoE server . Y our ISP may provide IP add resses using one of these protocols. T o use the FortiGate DHCP server , you need to configure ...

  • Fortinet 800 - page 29

    NAT/Route mode installation Configuring basic settings FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 29 PPPoE requires you to supp ly a user name and pass word. In addition, PPPoE unnumbered configu rations require you to supply an IP address. Use T able 7 to record the information you requi re for your PPPo E configuration. Using ...

  • Fortinet 800 - page 30

    30 01-28006-0024-2004102 6 Fortinet Inc. Configuring basic settin gs NAT/Route mode installati on T o configure DNS server settin gs 1 Go to System > Network > DNS . 2 Enter the IP address of the primary DNS se rver . 3 Enter the IP address of the secondary DNS server . 4 Select OK. T o add a default route Add a default route to configure wh ...

  • Fortinet 800 - page 31

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 31 2 Use the up and down arrows to hi ghlight the name of the interface to change and press Enter . 3 Press Enter for IP address. 4 Use the up and down arrow keys to increase or decrea se the value ...

  • Fortinet 800 - page 32

    32 01-28006-0024-2004102 6 Fortinet Inc. Configur ing the FortiGat e unit to operate in NAT /Route mode NAT/Rout e mode installat ion config system admin edit admin set password <psswrd> end T o configure interfaces 1 Log in to the CLI. 2 Set the IP address and netmask of the internal interface to the internal IP address and netmask that you ...

  • Fortinet 800 - page 33

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 33 config system external edit external set mode static set ip <address_ip> <netmask> end Example config system external edit external set mode static set ip <204.23.1.5> <255. ...

  • Fortinet 800 - page 34

    34 01-28006-0024-2004102 6 Fortinet Inc. Configur ing the FortiGat e unit to operate in NAT /Route mode NAT/Rout e mode installat ion T o add a default route Add a default route to configure wh ere the FortiGate unit sends traf fic that should be sent to an external netwo r k (usually the Internet). A dding the default route also defines which inte ...

  • Fortinet 800 - page 35

    NAT/Route mode installati on Starting the setup wizard FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 35 Starting the setup wizard 1 In the web-based manager, sele ct Easy Setup Wizard. Figure 9: Select the Easy Setup W izard 2 Follow the instructions on th e wizard pages and use the in formation that you gathered in T a ble 6 on pa ...

  • Fortinet 800 - page 36

    36 01-28006-0024-2004102 6 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on Y ou are now finished the initial c onfiguration of the FortiGate unit. Connecting the FortiGate unit to the network(s) After you co mplete the initial configu ration, you can connect the FortiGate unit between the internal networ k and the Internet. Y o ...

  • Fortinet 800 - page 37

    NAT/Route mode installati on Starting the setup wizard FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 37 T o connect the FortiGate unit running in NA T/Route mode 1 Connect the Internal interfac e to the hub or switch connected to the internal network. 2 Connect the External interface to your public switch or ro uter . 3 Optionally ...

  • Fortinet 800 - page 38

    38 01-28006-0024-2004102 6 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on 2 Repeat for all user-defined inter faces that you have configured. The example in Figure 1 1 shows an intern al network connected to user-defined interface 1 and an externa l network c onnected to user-defined interfa ce 4. Figure 1 1: Example FortiGate ...

  • Fortinet 800 - page 39

    NAT/Route mode installati on Starting the setup wizard FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 39 In standalone m ode, the mo dem interf ace is the c onnection fro m the FortiG ate unit to the Internet. When connect ing to the IS P , in either conf iguration, the F ortiGate unit m odem can automatica lly dial up to thr ee dia ...

  • Fortinet 800 - page 40

    40 01-28006-0024-2004102 6 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on T o register , enter your contact informatio n and the serial numbers of the FortiGate units that you or your or ganization have purchased. Y ou can register multiple FortiGate units in a single session without re-entering your contact inform ation. T o ...

  • Fortinet 800 - page 41

    FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 41 T r ansp arent mode inst allation This chapter de scribes how to insta ll a FortiGate unit in T ransparent mode . If you want to install the FortiGate un it in NA T/Ro ute m ode, see “NA T/Route mode installa tion” on pag ...

  • Fortinet 800 - page 42

    42 01-28006-0024-2004102 6 Fortinet Inc. Transparen t mode installatio n Using the web-based manager Y ou can use the web-based manager to complete the initial configuration of the FortiGate unit. Y ou can continue to use the web-based mana ger for all FortiGate unit settings. For information about co nnecting to the web-based man ager, see “Conn ...

  • Fortinet 800 - page 43

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 43 2 Enter the IP address of the primary DNS se rver . 3 Enter the IP address of the secondary DNS server . 4 Select OK. T o configure the default gateway 1 Go to System > Network > Management . 2 Set Default Ga ...

  • Fortinet 800 - page 44

    44 01-28006-0024-2004102 6 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation T o add a default gateway 1 Press Enter to display the option list. 2 Use the down arrow to highl ight Default Gateway . 3 Press Enter and set the default gatewa y . 4 After you set the last digit of the default gateway , press Enter . 5 Pre ...

  • Fortinet 800 - page 45

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 45 config system manageip set ip 10.10.10.2 255.255.255.0 end 3 Confirm that the addre ss is correct. Enter: get system manageip The CLI lists the managemen t IP address and netmask. T o configure DNS server settin gs ...

  • Fortinet 800 - page 46

    46 01-28006-0024-2004102 6 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation The first tim e you connec t to the Fort iGate un it, it is configured to run in NA T/Route mode. T o switch to T ranspare nt mode using the web-based manag er 1 Go to System > S t atus . 2 Select Change beside the Operation Mode. 3 Selec ...

  • Fortinet 800 - page 47

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 47 There are 4 10/1 00 Base-TX connectors on the FortiGate-8 00: • user-defined interfaces 1 to 4 for connecti ng up to four additional networks to the FortiGate un it. FortiGate-800F There are 4 LC-SFP 1000 Base-SX ...

  • Fortinet 800 - page 48

    48 01-28006-0024-2004102 6 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation Figure 12: FortiGate-800/800F T r ansp arent mode connectio ns Next step s Y ou can use the following information to co nfigure FortiGat e system time, to register the FortiGate unit, and to configure ant ivirus and att ack definition update ...

  • Fortinet 800 - page 49

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 49 5 Select Set T ime and set the FortiGate system date and time. 6 Set the hour , minute, second, month, day , and year as required. 7 Select Apply . T o use NTP to set the FortiGate date and time 1 Go to System > ...

  • Fortinet 800 - page 50

    50 01-28006-0024-2004102 6 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation ...

  • Fortinet 800 - page 51

    FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 51 High availability inst allation This chapter describes how to install two or more FortiGate units in an HA cluster . HA installation involves three basic steps: • Configuring FortiGate un its for HA operation • Connecting ...

  • Fortinet 800 - page 52

    52 01-28006-0024-2004102 6 Fortinet Inc. High availability configuration se ttings High availability installation T a ble 10: High availability settings Mode Active-Active Load balancing and failo ve r HA. Each FortiGate unit in the HA cluster actively processes co nnections and monitors the statu s of the other FortiGat e units in the clu ster . T ...

  • Fortinet 800 - page 53

    High availability installation Configuring Fort iGate units for HA usi ng the web-based manager FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 53 Configuring FortiGate units for HA using the web-based manager Use the followin g procedure to configure e ach FortiGat e unit for HA op eration. T o change the FortiGate unit host name Ch ...

  • Fortinet 800 - page 54

    54 01-28006-0024-2004102 6 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on T o configure a FortiGate unit for HA operation 1 Go to System > Config > HA . 2 Select High Availability . 3 Select the mode. 4 Select a Group ID for the HA cluster . 5 If required, change the Unit Priority . 6 If requir ...

  • Fortinet 800 - page 55

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 55 T o configure the FortiGate unit for HA operation 1 Configure HA settings. Use the following command to: • Set the HA mode • Set the Group ID • Change the unit priority • Enab le override mast er ...

  • Fortinet 800 - page 56

    56 01-28006-0024-2004102 6 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on Inserting an HA cluster into your networ k temporarily interrupt s communications on the network because new ph ysical connectio ns are being made to ro ute traffic throug h the cluster . Also, starting th e cluster in terrupts ...

  • Fortinet 800 - page 57

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 57 Figure 13: HA network confi guration 2 Power on all the FortiGat e units in the cluster . As the units st art, they negotiate to choose the primary cluster un it and the subordinat e units. This negotiati ...

  • Fortinet 800 - page 58

    58 01-28006-0024-2004102 6 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on The configurations of all of the FortiGate uni ts in the cluster are synchronized so that the FortiGate units can functi on as a cluster . Because of th is synchron ization, you configure and m anage the HA cluste r instead of ...

  • Fortinet 800 - page 59

    FortiGate-800/800F Installati on Guide 01-28006-0024-2004102 6 59 FortiGate-800/800F Inst allati on Guide V ersion 2.80 MR6 Index C CLI 6 configuring IP addresses 44 configuring NAT/Route mode 31 connecting to 17 cluster connecting 55, 57 command line interface 6 connect cluster 55, 57 connecting to network 36 , 46 web-based manager 16 customer ser ...

  • Fortinet 800 - page 60

    60 01-28006-0024-2004102 6 Fortinet Inc. Index ...

Fabricant Fortinet Catégorie Switch

Les documents que nous recevons du fabricant de l'appareilFortinet 800 peuvent être divisés en plusieurs groupes. Ceux-ci sont, entre autres:
- dessins techniques Fortinet
- manuels d’utilisations 800
- fiches produit Fortinet
- dépliants
- ou étiquettes-énergie Fortinet 800
Tous sont importants, mais les informations les plus importantes du point de vue de l'utilisation de l'appareil se trouvent dans le manuel d’utilisation Fortinet 800.

Un groupe de documents appelé manuels d’utilisation est également divisé en types plus spécifiques, tels que: Manuels d’installation Fortinet 800, manuels d’entretien, brefs manuels ou manuels de l’utilisateur Fortinet 800. Selon vos besoins, vous devriez chercher le document dont vous avez besoin. Sur notre site, vous pouvez voir le manuel le plus populaire d’utilisation du produit Fortinet 800.

Manuels d’utilsiation similaires

Manuel d’utilisation complet de l’appareil Fortinet 800, quelle devrait-elle être?
Le manuel d’utilisation, également appelé le mode d’emploi, ou tout simplement le manuel, est un document technique destiné à aider à utiliser Fortinet 800 par les utilisateurs. Des manuels sont généralement écrits par un rédacteur technique, mais dans un langage accessible à tous les utilisateurs Fortinet 800.

Le manuel d’utilisation complet Fortinet, devrait inclure plusieurs éléments de base. Certains d'entre eux sont moins importants, tels que: la couverture / page de titre ou pages d'auteur. Cependant, la partie restante, devrait nous fournir des informations importantes du point de vue de l'utilisateur.

1. Introduction et des conseils sur la façon d'utiliser le manuel Fortinet 800 - Au début de chaque manuel, nous devrions trouver des indices sur la façon d'utiliser le document. Il doit contenir des informations sur l'emplacement de la table des matières Fortinet 800, FAQ ou des problèmes les plus fréquents - les points qui sont les plus souvent recherchés par les utilisateurs de chaque manuel
2. Table des matières - index de tous les conseils pour lFortinet 800 qui peuvent être trouvés dans le document courant
3. Conseils sur la façon d'utiliser les fonctions de base de l’appareil Fortinet 800 - qui devraient nous aider dans les premières étapes lors de l'utilisation Fortinet 800
4. Troubleshooting - séquence systématique des activités qui nous aideront à diagnostiquer et ensuite résoudre les principaux problèmes de Fortinet 800
5. FAQ - questions fréquemment posées
6. Détails du contact Informations sur l'endroit où chercher le contact avec le fabricant / service Fortinet 800 dans un pays donné, si le problème ne peut être résolu par nous-mêmes.

Avez-vous une question à propos de Fortinet 800?

Utiliser le formulaire ci-dessous

Si vous n’avez pas résolu votre problème avec Fortinet 800, avec l'aide du manuel que vous avez trouvé, posez une question en utilisant le formulaire ci-dessous. Si un utilisateur a eu un problème similaire avec Fortinet 800 il est probable qu’il a envie de partager la façon de le résoudre.

Réécrire le texte de l'image

Commentaires (0)