Fortinet 500A manuel d'utilisation

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54

Aller à la page of

Un bon manuel d’utilisation

Les règles imposent au revendeur l'obligation de fournir à l'acheteur, avec des marchandises, le manuel d’utilisation Fortinet 500A. Le manque du manuel d’utilisation ou les informations incorrectes fournies au consommateur sont à la base d'une plainte pour non-conformité du dispositif avec le contrat. Conformément à la loi, l’inclusion du manuel d’utilisation sous une forme autre que le papier est autorisée, ce qui est souvent utilisé récemment, en incluant la forme graphique ou électronique du manuel Fortinet 500A ou les vidéos d'instruction pour les utilisateurs. La condition est son caractère lisible et compréhensible.

Qu'est ce que le manuel d’utilisation?

Le mot vient du latin "Instructio", à savoir organiser. Ainsi, le manuel d’utilisation Fortinet 500A décrit les étapes de la procédure. Le but du manuel d’utilisation est d’instruire, de faciliter le démarrage, l'utilisation de l'équipement ou l'exécution des actions spécifiques. Le manuel d’utilisation est une collection d'informations sur l'objet/service, une indice.

Malheureusement, peu d'utilisateurs prennent le temps de lire le manuel d’utilisation, et un bon manuel permet non seulement d’apprendre à connaître un certain nombre de fonctionnalités supplémentaires du dispositif acheté, mais aussi éviter la majorité des défaillances.

Donc, ce qui devrait contenir le manuel parfait?

Tout d'abord, le manuel d’utilisation Fortinet 500A devrait contenir:
- informations sur les caractéristiques techniques du dispositif Fortinet 500A
- nom du fabricant et année de fabrication Fortinet 500A
- instructions d'utilisation, de réglage et d’entretien de l'équipement Fortinet 500A
- signes de sécurité et attestations confirmant la conformité avec les normes pertinentes

Pourquoi nous ne lisons pas les manuels d’utilisation?

Habituellement, cela est dû au manque de temps et de certitude quant à la fonctionnalité spécifique de l'équipement acheté. Malheureusement, la connexion et le démarrage Fortinet 500A ne suffisent pas. Le manuel d’utilisation contient un certain nombre de lignes directrices concernant les fonctionnalités spécifiques, la sécurité, les méthodes d'entretien (même les moyens qui doivent être utilisés), les défauts possibles Fortinet 500A et les moyens de résoudre des problèmes communs lors de l'utilisation. Enfin, le manuel contient les coordonnées du service Fortinet en l'absence de l'efficacité des solutions proposées. Actuellement, les manuels d’utilisation sous la forme d'animations intéressantes et de vidéos pédagogiques qui sont meilleurs que la brochure, sont très populaires. Ce type de manuel permet à l'utilisateur de voir toute la vidéo d'instruction sans sauter les spécifications et les descriptions techniques compliquées Fortinet 500A, comme c’est le cas pour la version papier.

Pourquoi lire le manuel d’utilisation?

Tout d'abord, il contient la réponse sur la structure, les possibilités du dispositif Fortinet 500A, l'utilisation de divers accessoires et une gamme d'informations pour profiter pleinement de toutes les fonctionnalités et commodités.

Après un achat réussi de l’équipement/dispositif, prenez un moment pour vous familiariser avec toutes les parties du manuel d'utilisation Fortinet 500A. À l'heure actuelle, ils sont soigneusement préparés et traduits pour qu'ils soient non seulement compréhensibles pour les utilisateurs, mais pour qu’ils remplissent leur fonction de base de l'information et d’aide.

Table des matières du manuel d’utilisation

  • Page 1

    FortiGate 500A Installation Guide Esc Ent er A CON SOLE 56 USB LAN 12 3 4 L1 L2 L3 L4 10/ 100 10/ 100/1 000 Ve r s i o n 2 . 8 0 M R 5 15 October 2004 01-28005-01 01-20041015[...]

  • Page 2

    © Copyright 2004 Fortine t Inc. All rights reserved . No part of this publication incl uding text, examples, di agrams or illustration s may be reproduced, transmitted, or translated in any form or by any means, electronic, m echanical, m anual, optical or otherwise, for any purpose, without prio r written pe rmission of F ortinet I nc. FortiGate-[...]

  • Page 3

    Contents FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 3 Table of Contents Introduction ............. .............................. ........................................................ ......... 5 Secure installation, configurat ion, and management ................ ................ ................... ....... 6 Web-based manager .[...]

  • Page 4

    Contents 4 01-28005-0101-2004101 5 Fortinet Inc. Transparent mode installation .... ............................................................... ......... 37 Preparing to configure Transparent mode ............ ................ .................... ................ ........ 37 Using the web-based manager ....................... ................ [...]

  • Page 5

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 5 Introduction FortiGate A ntivirus Firew alls improve n etwork securit y , red uce networ k misuse and abuse, and help you use communication s resources more efficiently without compromising the performance of yo ur netw ork. FortiGate A[...]

  • Page 6

    6 01-28005-0101-2004101 5 Fortinet Inc. Web-based manage r Introduction Secure inst allation, configuration, and management The FortiGate unit default conf iguration includes default interface IP addr esses and is only a few steps away from protecting your netwo rk. There are several ways to configure basic FortiGate settings: • the web-based man[...]

  • Page 7

    Introduction Command line interface FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 7 Command line interface Y ou can access the FortiGate command lin e interface (CLI) by connecting a management compute r serial port to the Fo rtiGate RS-232 serial console connector . Y ou can also use T elnet or a secure SSH co nnection to connect to t[...]

  • Page 8

    8 01-28005-0101-2004101 5 Fortinet Inc. Setup wizard Introduction set opmode {nat | transparent} Y ou can en ter set opmode nat or set opmode transparent . • Square bracke ts [ ] to indica te that a keyword or variable is optional. For example: show system interface [<name_str>] T o show the settings for all interfaces, you can enter show s[...]

  • Page 9

    Introduction Comments on Fortine t technical documenta tion FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 9 Fortinet document ation Information about FortiGate produ cts is av ailable from the following FortiGate Gu ides: • FortiGate QuickS tart Guide Each QuickS tart Guide provides the basic information r equired to connect and inst[...]

  • Page 10

    10 01-28005-0101-2004101 5 Fortinet Inc. Comments on Fortinet technica l docume ntation Introduction Customer service and technical support For antiviru s and attack def inition up dates, firmware updates, updated product documentation , technical support informatio n , and other resources, please visit the Fortinet technical support we b site at h[...]

  • Page 11

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 11 Getting st arted This section describes unp acking, setting up, and powering on a FortiGate Antivirus Firewall unit. This section includes: • Package content s • Mounting • T urning the FortiGate unit po wer on and o ff • Conne[...]

  • Page 12

    12 01-28005-0101-2004101 5 Fortinet Inc. Getting started Package content s The FortiGate-500A p ackage cont ains the following items: • FortiGate-500A Antivirus Firewall • one orange crossover ethe rnet cable (Fortinet p art number CC300248) • one gray regular ethern et cable (Fortinet part number CC300249) • one RJ-45 serial cable (Fortine[...]

  • Page 13

    Getting started FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 13 Power requirements • Power dissipation: 50 W (max) • AC input volt age: 100 to 2 40 V AC • AC input current: 1.6 A • Frequency: 50 to 60 H Environmental specifications • Operating temperature: 32 to 10 4°F (0 to 40°C) • S torage temperature: -13 to 158°F (-[...]

  • Page 14

    14 01-28005-0101-2004101 5 Fortinet Inc. Getting started T o power off the FortiGate unit Always shut down the FortiGate operatin g system properly bef ore turning off the power switch. 1 From the web-ba sed manage r , go to System > Maintenance > ShutDown , select Shut Down and select Apply , or from the CLI, enter: execute shutdown 2 T urn [...]

  • Page 15

    Getting started FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 15 3 S tart Internet Explorer and browse to the address http s://192.168.1.99. (r emember to include the “s” in https://). The FortiGate login is displayed. Figure 3: FortiG ate login 4 T ype admin in the Name field and select Login. Connecting to the command line interf[...]

  • Page 16

    16 01-28005-0101-2004101 5 Fortinet Inc. Getting started 5 Press Enter to connect to the FortiGate CLI. The following prompt is displayed: FortiGate-500A login: 6 Ty p e admin and press Enter twice. The following prompt is displayed: Welcome ! T ype ? to list available commands. For information about how to use the CLI, see the FortiGate C LI Refer[...]

  • Page 17

    Getting started Factory default NAT/Route mod e network configuration FortiGate-500A Installati on Guide 01-28005-0101-200 41015 17 Factory default NAT/Route m ode network configuration When the FortiGate unit is first p owered on , it is running in NA T/Rout e mode and has the basic ne twork config uration listed in Ta b l e 2 . This configura tio[...]

  • Page 18

    18 01-28005-0101-2004101 5 Fortinet Inc. Factory default Transpar ent mode network configuration Getting started Factory default Transparent mode network configuration In T ransparent mode, the FortiGate unit has the d efault network configuration listed in Ta b l e 3 . Factory default firewall configuration FortiGate firewall policies cont rol how[...]

  • Page 19

    Getting started Factory default protection profiles FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 19 Factory default protection profiles Use protection profiles to apply dif ferent protection settings for traf fic that is controlled by firewall po licies. Y ou can us e protection profiles to : • Configure antivirus protection for HT [...]

  • Page 20

    20 01-28005-0101-2004101 5 Fortinet Inc. NAT/Rout e mode Getting started Figure 4: We b protection profile settings Planning the FortiGate configuration Before you configure the FortiGate unit, you need to plan how to integrate the unit into the network. Amo ng other thing s, you must decide whet her you want th e unit to be visible to the network,[...]

  • Page 21

    Getting started NAT/Route mode with multiple external network conn ections FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 21 Y ou can add firewall policies to control w hether communications through the FortiGate unit operate in NA T or Route mode. Firewall policies control the flow of traf fic based on the sou rce addres s, destinatio [...]

  • Page 22

    22 01-28005-0101-2004101 5 Fortinet Inc. Transparent mode Getting started Figure 6: Example NA T/Route multipl e internet connection configu ration Transparent mode In T ransparent mode, the Fo rtiGate unit is invisible to the network. Similar to a network bridge, all FortiGate inte rfaces must be on the same subnet. Y ou only have to configure a m[...]

  • Page 23

    Getting started Configuration options FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 23 Web-based manager and setup wizard The FortiGate web-based ma nager is a full featured management to ol. Y ou can use the web-based manager to confi gure most FortiGate settings. The web-based manage r Setup Wizard guides you through the initia l con[...]

  • Page 24

    24 01-28005-0101-2004101 5 Fortinet Inc. Configuration opti ons Getting started[...]

  • Page 25

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 25 NA T/Route mode inst allation This chapter describes ho w to install the FortiGate un it in NA T/Route mode. For information about installing a FortiGate unit in T r ansparent mode, see “T ransparent mode inst allation” on p age 37[...]

  • Page 26

    26 01-28005-0101-2004101 5 Fortinet Inc. DHCP or PPPoE confi guration NAT/Route mode installati on DHCP or PPPoE configuration Y ou can configure any FortiGate interface to acquire it s IP address from a DHCP or PPPoE server . Y our ISP may provide IP add resses using one of these protocols. T o use the FortiGate DHCP server , you need to configure[...]

  • Page 27

    NAT/Route mode installation Configuring basic settings FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 27 Using the web-based manager Y ou can use the web-based manager for the in itial configuration of the FortiGate unit. Y ou can also continue to use the web-based mana ger for all FortiGate unit settings. For information about co nnect[...]

  • Page 28

    28 01-28005-0101-2004101 5 Fortinet Inc. Configuring basic settin gs NAT/Route mode installati on T o add a default route Add a default route to configure wh ere the FortiGate unit sends traf fic destined for an external ne twork (usua lly the Interne t). A dding the default route also defines which interface is connected to an external ne twor k. [...]

  • Page 29

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-500A Installati on Guide 01-28005-0101-200 41015 29 T o add a default gateway to an interface The default gateway is usually configured for the interface connecte d to the Internet. Y ou can use the procedur e below to confi gure a de fault gateway f[...]

  • Page 30

    30 01-28005-0101-2004101 5 Fortinet Inc. Configur ing the FortiG ate unit to opera te in NAT/Ro ute mode NAT/Rout e mode instal lation Example T o set the IP address of the LAN interface to 192.16 8.2.99 and netmask to 255.255.255.0, enter: config system interface edit lan set ip 192.168.2.99 255.255.255.0 end 3 T o set the IP address and ne tmask [...]

  • Page 31

    NAT/Route mode installation Configuring the Fo rtiGate unit to oper ate in NAT/Route mode FortiGate-500A Installati on Guide 01-28005-0101-200 41015 31 6 Confirm that the addre sses are correct. Ente r: get system interface The CLI lists the IP address, netma sk, and other set tings for ea ch of the F ortiGate interfaces. T o configure DNS server s[...]

  • Page 32

    32 01-28005-0101-2004101 5 Fortinet Inc. Configur ing the FortiG ate unit to opera te in NAT/Ro ute mode NAT/Rout e mode instal lation Using the setup wizard From the web-based ma nager, you can use the setup wizard to complete the initial configuration of the FortiGate unit. For in formation about connecting to the web -based manager, see “C onn[...]

  • Page 33

    NAT/Route mode installati on Starting the setup wizard FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 33 Starting the setup wizard 1 In the web-based manager, sele ct Easy Setup Wizard. Figure 8: Select the Easy Setup W izard 2 Follow the instructions on th e wizard pages and use the in formation that you gathere d in T able 5 on page 2[...]

  • Page 34

    34 01-28005-0101-2004101 5 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on Connecting the FortiGate unit to the network(s) After you co mplete the initial configuration, you ca n connect the Fo rtiGate unit between the internal ne twork and the Internet. There are 5 10/1 00 Base-T conn ectors on the FortiGate-500A: • LAN, a 4[...]

  • Page 35

    NAT/Route mode installati on Starting the setup wizard FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 35 3 Optionally connect Ports 3, 4, 5, and 6 to other networks. For example, you could conne ct port 3 to a DMZ network to provide access from the Internet to a web server or other server wit hout installing the serv ers on the internal[...]

  • Page 36

    36 01-28005-0101-2004101 5 Fortinet Inc. Starting the setup wizard NAT/Route mode installati on T o register the FortiGate unit After pur chasing and inst alling a new FortiGat e unit, you can register th e unit by goin g to the System Update Support page, or usin g a web browser to connect to http://support.fortinet .com and selecting Pr oduct Reg[...]

  • Page 37

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 37 T ransp arent mode inst allation This chapter de scribes how to inst all a FortiGate unit in T ransp arent mode. If you want to install the FortiGate un it in NA T/Ro ute mode, see “NA T/Route mode installation” on pag e 25 . If yo[...]

  • Page 38

    38 01-28005-0101-2004101 5 Fortinet Inc. Transparen t mode install ation Using the web-based manager Y ou can use the web-based manager to complete the initial configuration of the FortiGate unit. Y ou can continue to use the web-based manager for all FortiGate unit settings. For information about co nnecting to the web-based manager, see “Connec[...]

  • Page 39

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 39 T o configure the default gateway 1 Go to System > Network > Management . 2 Set Default Gateway to the default gatewa y IP address that you recorded in T able 8 on page 38 . 3 Select Apply . Reconnecting to the w[...]

  • Page 40

    40 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation 4 After you set the last digit of the default gateway , press Enter . 5 Press Esc to return to the Main Menu. Y ou have now co mpleted the in itial configuration o f the FortiGate unit and you can proceed to “Next steps” on page 43 . Usi[...]

  • Page 41

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 41 Example config system manageip set ip 10.10.10.2 255.255.255.0 end 3 Confirm that the addre ss is correct. Enter: get system manageip The CLI lists the managemen t IP address and netmask. T o configure DNS server se tt[...]

  • Page 42

    42 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation Using the setup wizard From the web-based manager, you can use th e setup wizard to begin the initial configuration of the FortiGate unit. For in formation about connecting to the web -based manager, see “C onnecting to the web-based man a[...]

  • Page 43

    Transparent mode installatio n Reco nnecting to the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 43 For example, you can connect the Fort iGate-500A using the following ste ps: 1 Connect port 1 to the hub or switch connected to your internal network. 2 Connect port 2 to the network segment connected to the external f[...]

  • Page 44

    44 01-28005-0101-2004101 5 Fortinet Inc. Reconnecting to the web-based manager Transparent mode installation T o set the date and time For effective scheduling and logging, the FortiGate syst em date and time must be accurate. Y ou can either manually set the system date and time or configure the FortiGate unit to automatically keep its ti me corre[...]

  • Page 45

    FortiGate-500A Inst allation Guide V ersion 2.80 MR5 FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 45 High availability inst allation This chapter describes how to install two or more FortiGate units in an HA cluster . HA installation involves three basic steps: • Configuring FortiGate un its for HA operation • Connecting the clust[...]

  • Page 46

    46 01-28005-0101-2004101 5 Fortinet Inc. High availability configuration se ttings High availability installation T able 9: Hig h availability settings Mode Active-Active Load balancing and failo ve r HA. Each FortiGate unit in the HA cluster actively processes co nnections and monitors the statu s of the other Forti Gate unit s in the cluster . Th[...]

  • Page 47

    High availability installation Configuring Fort iGate units for HA usi ng the web-based manager FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 47 Configuring FortiGate units for HA using the web-based manager Use the followin g procedur e to configu re each For tiGate unit f or HA opera tion. T o change the FortiGate unit host name Chan[...]

  • Page 48

    48 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on T o configure a FortiGate unit for HA operation 1 Go to System > Config > HA . 2 Select High Availability . 3 Select the mode. 4 Select a Group ID for the HA cluster . 5 If required, change the Unit Priority . 6 If requir[...]

  • Page 49

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-500A Installati on Guide 01-28005-0101-200 41015 49 T o configure the FortiGate unit for HA operation 1 Configure HA settings. Use the following command to: • Set the HA mode • Set the Group ID • Change the unit priority • Enable ov erride master • E[...]

  • Page 50

    50 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on Inserting an HA cluster into your networ k temporarily interrupt s communications on the network because ne w physical conn ections are being made to route traf fic through the cluster . Also, starting th e cluster inte rrupts [...]

  • Page 51

    High availability installation Configuring FortiGate units for HA using the CLI FortiGate-500A Installati on Guide 01-28005-0101-200 41015 51 2 Power on all the FortiGat e units in the cluster . As the units st art, they negotiate to choose the primary cluste r unit and the subordinat e units. This negotiation occurs with no user interventio n and [...]

  • Page 52

    52 01-28005-0101-2004101 5 Fortinet Inc. Configuring FortiGate units for HA usin g the CLI High availability installati on[...]

  • Page 53

    FortiGate-500A Installati on Guide 01-28005-0101-2004101 5 53 FortiGate-500A Inst allation Guide V ersion 2.80 MR5 Index C CLI 7 configuring IP addresses 40 configuring NAT/Route mode 29 connecting to 15 cluster connecting 49, 51 command line interface 7 connect cluster 49, 51 connecting to network 34 , 42 web-based manager 14 customer service 10 D[...]

  • Page 54

    54 01-28005-0101-2004101 5 Fortinet Inc. Index[...]