Fortinet FortiGate 4000 Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Akcesoria komputerowe Fortinet FortiGate 4000. Fortinet FortiGate 4000 User Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 332
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 0
FortiGate – 4000
User Manual
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
POWER ON/OFF
LAN 1 LAN 2
PWR/KVMSTATUS
KVM/ACCESS
KVM
ALARM
FortiGate User Manual Volume 1
Version 2.50
February 5 2004
Przeglądanie stron 0
1 2 3 4 5 6 ... 331 332

Podsumowanie treści

Strona 1 - User Manual

FortiGate – 4000User ManualPOWER ON/OFFLAN 1 LAN 2PWR/KVMSTATUSKVM/ACCESSPOWER ON/OFFLAN 1 LAN 2PWR/KVMSTATUSKVM/ACCESSPOWER ON/OFFLAN 1 LAN 2PWR/KVMS

Strona 2

Contents10 Fortinet Inc.Addresses ...

Strona 3 - Table of Contents

100 Fortinet Inc.Active-Active cluster packet flow High availability

Strona 4 - 4 Fortinet Inc

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 101System statusYou can connect t

Strona 5

102 Fortinet Inc.Changing the FortiGate host name System statusChanging the FortiGate host nameThe FortiGate host name appears on the Status page and

Strona 6 - 6 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 103Upgrading to a new firmware versionUse the follo

Strona 7

104 Fortinet Inc.Changing the FortiGate firmware System status4 Make sure the FortiGate unit can connect to the TFTP server.You can use the following

Strona 8 - 8 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 105If you are reverting to a previous FortiOS versi

Strona 9

106 Fortinet Inc.Changing the FortiGate firmware System statusIf you are reverting to a previous FortiOS version (for example, reverting from FortiOS

Strona 10 - 10 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 10711 Update antivirus and attack definitions. For

Strona 11 - Contents

108 Fortinet Inc.Changing the FortiGate firmware System status5 To confirm that the FortiGate unit can connect to the TFTP server, use the following c

Strona 12 - 12 Fortinet Inc

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 10911 Enter the firmware image filename and press E

Strona 13

ContentsFortiGate-4000 Installation and Configuration Guide 11Configuring LDAP support ...

Strona 14 - 14 Fortinet Inc

110 Fortinet Inc.Changing the FortiGate firmware System statusTo run this procedure you:• access the CLI by connecting to the FortiGate console port u

Strona 15 - Introduction

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 1119 Type the address of the TFTP server and press

Strona 16 - Web content filtering

112 Fortinet Inc.Changing the FortiGate firmware System statusTo install a backup firmware image1 Connect to the CLI using the null-modem cable and Fo

Strona 17 - Firewall

System status Changing the FortiGate firmwareFortiGate-4000 Installation and Configuration Guide 113Switching to the backup firmware imageUse this p

Strona 18 - Network intrusion detection

114 Fortinet Inc.Manual virus definition updates System statusTo switch back to the default firmware image1 Connect to the CLI using the null-modem ca

Strona 19 - High availability

System status Manual attack definition updatesFortiGate-4000 Installation and Configuration Guide 115Manual attack definition updatesThe Status page

Strona 20 - Web-based manager

116 Fortinet Inc.Restoring system settings System statusTo back up system settings1 Go to System > Status.2 Select System Settings Backup.3 Select

Strona 21 - Document conventions

System status Changing to Transparent modeFortiGate-4000 Installation and Configuration Guide 117For information about restoring system settings, se

Strona 22 - Fortinet documentation

118 Fortinet Inc.Restarting the FortiGate unit System status4 Select OK.The FortiGate unit changes operation mode.5 To reconnect to the web-based mana

Strona 23

System status System statusFortiGate-4000 Installation and Configuration Guide 119Viewing CPU and memory statusCurrent CPU and memory status indicat

Strona 24 - 24 Fortinet Inc

Contents12 Fortinet Inc.Network Intrusion Detection System (NIDS) ... 271Detecting attacks ...

Strona 25 - Getting started

120 Fortinet Inc.System status System statusViewing sessions and network statusUse the session and network status display to track how many network se

Strona 26 - Package contents

System status System statusFortiGate-4000 Installation and Configuration Guide 121Viewing virus and intrusions statusUse the virus and intrusions st

Strona 27 - Physical description

122 Fortinet Inc.Session list System statusSession listThe session list displays information about the communications sessions currently being process

Strona 28 - Front panel features

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 123Virus and attack definitions u

Strona 29 - FortiBlade-4010 module

124 Fortinet Inc.Updating antivirus and attack definitions Virus and attack definitions updates and registrationThe Update page on the web-based manag

Strona 30 - KVM switch module

Virus and attack definitions updates and registration Updating antivirus and attack definitionsFortiGate-4000 Installation and Configuration Guide 1

Strona 31 - Rear panel features

126 Fortinet Inc.Scheduling updates Virus and attack definitions updates and registrationConfiguring update loggingUse the following procedure to conf

Strona 32 - 32 Fortinet Inc

Virus and attack definitions updates and registration Scheduling updatesFortiGate-4000 Installation and Configuration Guide 1274 Select Apply.The Fo

Strona 33 - Management module

128 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationEnabling scheduled updates through a proxy serverIf your F

Strona 34 - Mounting Knot Mounting Knot

Virus and attack definitions updates and registration Enabling push updatesFortiGate-4000 Installation and Configuration Guide 129When the network c

Strona 35 - Switched interface module

ContentsFortiGate-4000 Installation and Configuration Guide 13Script filtering ...

Strona 36 - 36 Fortinet Inc

130 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationExample: push updates through a NAT deviceThis example des

Strona 37 - Installing hardware

Virus and attack definitions updates and registration Enabling push updatesFortiGate-4000 Installation and Configuration Guide 131General procedureU

Strona 38 - 38 Fortinet Inc

132 Fortinet Inc.Enabling push updates Virus and attack definitions updates and registrationFigure 38: Push update port forwarding virtual IPAdding a

Strona 39

Virus and attack definitions updates and registration Registering FortiGate unitsFortiGate-4000 Installation and Configuration Guide 1334 Set IP to t

Strona 40 - 40 Fortinet Inc

134 Fortinet Inc.Registering FortiGate units Virus and attack definitions updates and registrationAll registration information is stored in the Fortin

Strona 41 - Hot swapping modules

Virus and attack definitions updates and registration Registering FortiGate unitsFortiGate-4000 Installation and Configuration Guide 135• The product

Strona 42 - Hot swapping power supplies

136 Fortinet Inc.Updating registration information Virus and attack definitions updates and registration7 Select Finish.If you have not entered a Fort

Strona 43

Virus and attack definitions updates and registration Updating registration informationFortiGate-4000 Installation and Configuration Guide 1377 Sele

Strona 44 - 44 Fortinet Inc

138 Fortinet Inc.Updating registration information Virus and attack definitions updates and registration7 Enter the serial number of the FortiGate uni

Strona 45

Virus and attack definitions updates and registration Updating registration informationFortiGate-4000 Installation and Configuration Guide 1393 Ente

Strona 46 - 46 Fortinet Inc

Contents14 Fortinet Inc.

Strona 47

140 Fortinet Inc.Registering a FortiGate unit after an RMA Virus and attack definitions updates and registrationFor information about how to install t

Strona 48 - Factory default configuration

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 141Network configurationYou can u

Strona 49

142 Fortinet Inc.Configuring interfaces Network configurationAdding zonesThe new zone does not appear in the policy grid until you add an interface to

Strona 50 - 50 Fortinet Inc

Network configuration Configuring interfacesFortiGate-4000 Installation and Configuration Guide 143Viewing the interface listTo view the interface l

Strona 51 - Scan content profile

144 Fortinet Inc.Configuring interfaces Network configurationTo add an interface to a zone1 Go to System > Network > Interface.2 Choose the inte

Strona 52 - Web content profile

Network configuration Configuring interfacesFortiGate-4000 Installation and Configuration Guide 1454 Clear the Retrieve default gateway and DNS from

Strona 53 - Unfiltered content profile

146 Fortinet Inc.Configuring interfaces Network configuration7 Select Apply. The FortiGate unit attempts to contact the PPPoE server from the interfac

Strona 54 - 54 Fortinet Inc

Network configuration Configuring interfacesFortiGate-4000 Installation and Configuration Guide 147Controlling administrative access to an interface

Strona 55 - FortiGate-4000 unit

148 Fortinet Inc.Configuring interfaces Network configurationChanging the MTU size to improve network performanceTo improve network performance, you c

Strona 56 - 56 Fortinet Inc

Network configuration Out of band managementFortiGate-4000 Installation and Configuration Guide 149• Enable secure administrative access to this int

Strona 57 - External

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 15IntroductionFortiGate Antivirus

Strona 58 - Load balancer

150 Fortinet Inc.VLAN overview Network configuration5 Select Log for the interface if you want to record log messages whenever and administrator conne

Strona 59

Network configuration VLANs in NAT/Route modeFortiGate-4000 Installation and Configuration Guide 151A VLAN segregates devices logically instead of p

Strona 60 - Next steps

152 Fortinet Inc.VLANs in NAT/Route mode Network configurationRules for VLAN IP addressesIP addresses of all FortiGate interfaces cannot overlap. That

Strona 61 - NAT/Route mode installation

Network configuration Virtual domains in Transparent modeFortiGate-4000 Installation and Configuration Guide 153Virtual domains in Transparent modeI

Strona 62 - 62 Fortinet Inc

154 Fortinet Inc.Virtual domains in Transparent mode Network configurationFigure 44: FortiGate unit with two virtual domainsVirtual domain propertiesA

Strona 63 - Using the setup wizard

Network configuration Virtual domains in Transparent modeFortiGate-4000 Installation and Configuration Guide 155Adding a virtual domainUse the follo

Strona 64 - 64 Fortinet Inc

156 Fortinet Inc.Virtual domains in Transparent mode Network configurationAdding zones to virtual domainsAdd zones to a virtual domain to group togeth

Strona 65

Network configuration Virtual domains in Transparent modeFortiGate-4000 Installation and Configuration Guide 1576 Select OK to save your changes.You

Strona 66 - Completing the configuration

158 Fortinet Inc.Adding DNS server IP addresses Network configurationDeleting virtual domains You must remove all VLAN subinterfaces and zones that ha

Strona 67

Network configuration Configuring routingFortiGate-4000 Installation and Configuration Guide 159Adding a default routeYou can add a default route fo

Strona 68 - 68 Fortinet Inc

16 Fortinet Inc.Antivirus protection IntroductionAntivirus protectionFortiGate ICSA-certified antivirus protection scans web (HTTP), file transfer (FT

Strona 69 - Transparent mode installation

160 Fortinet Inc.Configuring routing Network configuration6 Set Device #1 to the FortiGate interface or VLAN subinterface through which to route traff

Strona 70

Network configuration Configuring routingFortiGate-4000 Installation and Configuration Guide 1615 Select OK to save the new route.6 Repeat steps 1 t

Strona 71

162 Fortinet Inc.Configuring DHCP services Network configurationUsing policy routing you can build a routing policy database (RPDB) that selects the a

Strona 72

Network configuration Configuring DHCP servicesFortiGate-4000 Installation and Configuration Guide 163Configuring a DHCP relay agentIn a DHCP relay

Strona 73

164 Fortinet Inc.Configuring DHCP services Network configurationYou can add multiple scopes to an interface so that the DHCP server added to that inte

Strona 74 - 74 Fortinet Inc

Network configuration Configuring DHCP servicesFortiGate-4000 Installation and Configuration Guide 165Adding a reserve IP to a DHCP serverIf you hav

Strona 75 - General configuration steps

166 Fortinet Inc.Configuring DHCP services Network configuration

Strona 76 - CLI configuration steps

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 167RIP configurationThe FortiGate

Strona 77

168 Fortinet Inc.RIP settings RIP configuration5 Change the following RIP timer settings, as required.RIP timer defaults are effective in most configu

Strona 78 - 78 Fortinet Inc

RIP configuration Configuring RIP for FortiGate interfacesFortiGate-4000 Installation and Configuration Guide 169Figure 47: Configuring RIP settings

Strona 79

Introduction Email filteringFortiGate-4000 Installation and Configuration Guide 17Email filteringFortiGate email filtering can scan all IMAP and POP

Strona 80 - 80 Fortinet Inc

170 Fortinet Inc.Configuring RIP for FortiGate interfaces RIP configuration4 Select OK to save the RIP configuration for the selected interface.Figure

Strona 81

RIP configuration Adding RIP filtersFortiGate-4000 Installation and Configuration Guide 171Adding RIP filtersUse the Filter page to create RIP filte

Strona 82 - Configuring an HA cluster

172 Fortinet Inc.Adding RIP filters RIP configuration3 For Filter Name, type a name for the RIP filter list.The name can be 15 characters long and can

Strona 83

RIP configuration Adding RIP filtersFortiGate-4000 Installation and Configuration Guide 173Assigning a RIP filter list to the outgoing filterThe out

Strona 84 - Connecting the cluster

174 Fortinet Inc.Adding RIP filters RIP configuration

Strona 85 - Internal Network

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 175System configurationUse the Sy

Strona 86 - FortiGate-4000P rear panel

176 Fortinet Inc.Changing system options System configuration9 Select Apply.Figure 49: Example date and time settingChanging system optionsOn the Syst

Strona 87 - Managing an HA cluster

System configuration Changing system optionsFortiGate-4000 Installation and Configuration Guide 1773 Select Apply.Auth Timeout controls the amount o

Strona 88 - 88 Fortinet Inc

178 Fortinet Inc.Adding and editing administrator accounts System configurationAdding and editing administrator accountsWhen the FortiGate unit is ini

Strona 89 - Monitoring cluster members

System configuration Adding and editing administrator accountsFortiGate-4000 Installation and Configuration Guide 179Editing administrator accountsT

Strona 90 - Viewing cluster sessions

18 Fortinet Inc.VLANs and virtual domains IntroductionNAT/Route modeIn NAT/Route mode, you can create NAT mode policies and Route mode policies.• NAT

Strona 91

180 Fortinet Inc.Configuring SNMP System configurationConfiguring SNMPYou can configure the FortiGate SNMP agent to report system information and send

Strona 92 - 92 Fortinet Inc

System configuration Configuring SNMPFortiGate-4000 Installation and Configuration Guide 181To configure SNMP access to an interface in Transparent

Strona 93

182 Fortinet Inc.Configuring SNMP System configurationFigure 50: Sample SNMP configurationFortiGate MIBsThe FortiGate SNMP agent supports FortiGate pr

Strona 94 - Upgrading firmware

System configuration Configuring SNMPFortiGate-4000 Installation and Configuration Guide 183FortiGate trapsThe FortiGate agent can send traps to up

Strona 95 - Advanced HA options

184 Fortinet Inc.Configuring SNMP System configurationVPN trapsNIDS trapsAntivirus trapsLogging trapsTable 31: FortiGate VPN trapsTrap message Descrip

Strona 96 - 96 Fortinet Inc

System configuration Configuring SNMPFortiGate-4000 Installation and Configuration Guide 185Fortinet MIB fieldsThe Fortinet MIB contains fields for

Strona 97 - NAT/Route mode packet flow

186 Fortinet Inc.Configuring SNMP System configurationUsers and authentication configurationVPN configuration and statusNIDS configurationAntivirus co

Strona 98 - 98 Fortinet Inc

System configuration Replacement messagesFortiGate-4000 Installation and Configuration Guide 187Logging and reporting configurationReplacement messa

Strona 99 - Transparent mode packet flow

188 Fortinet Inc.Replacement messages System configurationCustomizing replacement messagesEach of the replacement messages in the replacement message

Strona 100 - 100 Fortinet Inc

System configuration Replacement messagesFortiGate-4000 Installation and Configuration Guide 189Customizing alert emailsCustomize alert emails to co

Strona 101 - System status

Introduction VPNFortiGate-4000 Installation and Configuration Guide 19VPNUsing FortiGate virtual private networking (VPN), you can provide a secure

Strona 102 - 102 Fortinet Inc

190 Fortinet Inc.Replacement messages System configuration%%SOURCE_IP%% The IP address from which the block file was received. For email this is the I

Strona 103

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 191Firewall configurationFirewall

Strona 104 - 104 Fortinet Inc

192 Fortinet Inc.Default firewall configuration Firewall configuration• IP/MAC binding• Content profilesDefault firewall configurationBy default, the

Strona 105

Firewall configuration Default firewall configurationFortiGate-4000 Installation and Configuration Guide 193VLAN subinterfacesYou can also add VLAN

Strona 106 - 106 Fortinet Inc

194 Fortinet Inc.Adding firewall policies Firewall configurationYou can also add firewall policies that perform network address translation (NAT). To

Strona 107

Firewall configuration Adding firewall policiesFortiGate-4000 Installation and Configuration Guide 1953 Select New to add a new policy.You can also

Strona 108 - 108 Fortinet Inc

196 Fortinet Inc.Adding firewall policies Firewall configurationFirewall policy optionsThis section describes the options that you can add to firewall

Strona 109

Firewall configuration Adding firewall policiesFortiGate-4000 Installation and Configuration Guide 197NATConfigure the policy for NAT. NAT translate

Strona 110 - 110 Fortinet Inc

198 Fortinet Inc.Adding firewall policies Firewall configurationAuthenticationSelect Authentication and select a user group to require users to enter

Strona 111

Firewall configuration Adding firewall policiesFortiGate-4000 Installation and Configuration Guide 199Figure 54: Adding a Transparent mode policyLog

Strona 112 - 112 Fortinet Inc

© Copyright 2004 Fortinet Inc. All rights reserved.No part of this publication including text, examples, diagrams or illustrations may be reproduced,t

Strona 113

20 Fortinet Inc.Secure installation, configuration, and management IntroductionSecure installation, configuration, and managementThe first time you po

Strona 114 - 114 Fortinet Inc

200 Fortinet Inc.Configuring policy lists Firewall configurationConfiguring policy listsThe firewall matches policies by searching for a match startin

Strona 115 - Backing up system settings

Firewall configuration Configuring policy listsFortiGate-4000 Installation and Configuration Guide 201Changing the order of policies in a policy lis

Strona 116 - Restoring system settings

202 Fortinet Inc.Addresses Firewall configurationAddressesAll policies require source and destination addresses. To add addresses to a policy, you mus

Strona 117 - Changing to NAT/Route mode

Firewall configuration AddressesFortiGate-4000 Installation and Configuration Guide 2036 Enter the Netmask.The netmask corresponds to the type of ad

Strona 118 - Restarting the FortiGate unit

204 Fortinet Inc.Addresses Firewall configurationDeleting addressesDeleting an address removes it from an address list. To delete an address that has

Strona 119 - Viewing CPU and memory status

Firewall configuration ServicesFortiGate-4000 Installation and Configuration Guide 205Figure 56: Adding an internal address groupServicesUse service

Strona 120 - 120 Fortinet Inc

206 Fortinet Inc.Services Firewall configurationGRE Generic Routing Encapsulation. A protocol that allows an arbitrary network protocol to be transmit

Strona 121 - System status System status

Firewall configuration ServicesFortiGate-4000 Installation and Configuration Guide 207LDAP Lightweight Directory Access Protocol is a set of protoco

Strona 122 - Session list

208 Fortinet Inc.Services Firewall configurationAdding custom TCP and UDP servicesAdd a custom TCP or UDP service if you need to create a policy for a

Strona 123

Firewall configuration ServicesFortiGate-4000 Installation and Configuration Guide 209Adding custom ICMP servicesAdd a custom ICMP service if you ne

Strona 124 - 124 Fortinet Inc

Introduction Document conventionsFortiGate-4000 Installation and Configuration Guide 21Command line interfaceYou can access the FortiGate command li

Strona 125

210 Fortinet Inc.Schedules Firewall configuration3 Type a Group Name to identify the group. This name appears in the service list when you add a polic

Strona 126 - Scheduling updates

Firewall configuration SchedulesFortiGate-4000 Installation and Configuration Guide 211Creating one-time schedulesYou can create a one-time schedule

Strona 127 - Adding an override server

212 Fortinet Inc.Schedules Firewall configurationCreating recurring schedulesYou can create a recurring schedule that activates or deactivates policie

Strona 128 - Enabling push updates

Firewall configuration Virtual IPsFortiGate-4000 Installation and Configuration Guide 213Adding schedules to policiesAfter you create schedules, you

Strona 129

214 Fortinet Inc.Virtual IPs Firewall configurationThis section describes:• Adding static NAT virtual IPs• Adding port forwarding virtual IPs• Adding

Strona 130 - 130 Fortinet Inc

Firewall configuration Virtual IPsFortiGate-4000 Installation and Configuration Guide 2157 In Map to IP, type the real IP address on the destination

Strona 131

216 Fortinet Inc.Virtual IPs Firewall configuration6 Enter the External IP Address that you want to map to an address on the destination zone.You can

Strona 132 - 132 Fortinet Inc

Firewall configuration Virtual IPsFortiGate-4000 Installation and Configuration Guide 217Figure 61: Adding a port forwarding virtual IPAdding polici

Strona 133 - Registering FortiGate units

218 Fortinet Inc.IP pools Firewall configuration4 Select OK to save the policy.IP poolsAn IP pool (also called a dynamic IP pool) is a range of IP add

Strona 134 - FortiCare Service Contracts

Firewall configuration IP poolsFortiGate-4000 Installation and Configuration Guide 219Figure 62: Adding an IP PoolIP Pools for firewall policies tha

Strona 135

22 Fortinet Inc.Fortinet documentation Introductionexecute restore config <filename_str>You enter restore config myfile.bak<xxx_str> indic

Strona 136 - 136 Fortinet Inc

220 Fortinet Inc.IP/MAC binding Firewall configurationIP/MAC bindingIP/MAC binding protects the FortiGate unit and your network from IP spoofing attac

Strona 137

Firewall configuration IP/MAC bindingFortiGate-4000 Installation and Configuration Guide 221For example, if the IP/MAC pair IP 1.1.1.1 and 12:34:56:

Strona 138 - 138 Fortinet Inc

222 Fortinet Inc.IP/MAC binding Firewall configuration3 Enter the IP Address and the MAC Address.You can bind multiple IP addresses to the same MAC ad

Strona 139

Firewall configuration Content profilesFortiGate-4000 Installation and Configuration Guide 223Figure 63: IP/MAC settingsContent profilesUse content

Strona 140 - 140 Fortinet Inc

224 Fortinet Inc.Content profiles Firewall configurationDefault content profilesThe FortiGate unit has the following four default content profiles tha

Strona 141 - Network configuration

Firewall configuration Content profilesFortiGate-4000 Installation and Configuration Guide 2256 Enable the email filter protection options that you

Strona 142 - Configuring interfaces

226 Fortinet Inc.Content profiles Firewall configurationAdding content profiles to policiesYou can add content profiles to policies with action set to

Strona 143 - Adding an interface to a zone

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 227Users and authenticationFortiG

Strona 144 - 144 Fortinet Inc

228 Fortinet Inc.Setting authentication timeout Users and authenticationThis chapter describes:• Setting authentication timeout• Adding user names and

Strona 145

Users and authentication Adding user names and configuring authenticationFortiGate-4000 Installation and Configuration Guide 2295 Select the Try oth

Strona 146 - 146 Fortinet Inc

Introduction Customer service and technical supportFortiGate-4000 Installation and Configuration Guide 23• Volume 4: FortiGate NIDS GuideDescribes h

Strona 147

230 Fortinet Inc.Configuring RADIUS support Users and authenticationConfiguring RADIUS supportIf you have configured RADIUS support and a user is requ

Strona 148 - 148 Fortinet Inc

Users and authentication Configuring LDAP supportFortiGate-4000 Installation and Configuration Guide 231Configuring LDAP supportIf you have configur

Strona 149 - Out of band management

232 Fortinet Inc.Configuring user groups Users and authentication7 Enter the distinguished name used to look up entries on the LDAP server.Enter the b

Strona 150 - VLAN overview

Users and authentication Configuring user groupsFortiGate-4000 Installation and Configuration Guide 233• IPSec VPN Phase 1 configurations for dialup

Strona 151 - VLANs in NAT/Route mode

234 Fortinet Inc.Configuring user groups Users and authentication3 Enter a Group Name to identify the user group.The name can contain numbers (0-9), u

Strona 152 - Adding VLAN subinterfaces

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 235IPSec VPNA Virtual Private Net

Strona 153

236 Fortinet Inc.Key management IPSec VPNKey managementThere are three basic elements in any encryption system:• an algorithm that changes information

Strona 154 - Configuring a virtual domain

IPSec VPN Manual key IPSec VPNsFortiGate-4000 Installation and Configuration Guide 237In some respects, certificates are simpler to manage than manu

Strona 155 - Adding a virtual domain

238 Fortinet Inc.Manual key IPSec VPNs IPSec VPN5 Enter the Remote SPI. The Remote Security Parameter Index is a hexadecimal number of up to eight dig

Strona 156 - 156 Fortinet Inc

IPSec VPN AutoIKE IPSec VPNsFortiGate-4000 Installation and Configuration Guide 239AutoIKE IPSec VPNsFortiGate units support two methods of Automati

Strona 157

24 Fortinet Inc.Customer service and technical support Introduction

Strona 158 - Configuring routing

240 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPN3 Type a Gateway Name for the remote VPN peer.The remote VPN peer can be either a gateway to another netw

Strona 159 - Adding a default route

IPSec VPN AutoIKE IPSec VPNsFortiGate-4000 Installation and Configuration Guide 24110 Configure the Local ID the that the FortiGate unit sends to th

Strona 160 - 160 Fortinet Inc

242 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPN4 Optionally, configure NAT Traversal.5 Optionally, configure Dead Peer Detection.Use these settings to m

Strona 161 - Policy routing

IPSec VPN AutoIKE IPSec VPNsFortiGate-4000 Installation and Configuration Guide 243Figure 69: Adding a phase 1 configuration (Standard options)Figur

Strona 162 - Configuring DHCP services

244 Fortinet Inc.AutoIKE IPSec VPNs IPSec VPNAdding a phase 2 configuration for an AutoIKE VPNAdd a phase 2 configuration to specify the parameters us

Strona 163 - Configuring a DHCP server

IPSec VPN AutoIKE IPSec VPNsFortiGate-4000 Installation and Configuration Guide 24510 Enable Autokey Keep Alive if you want to keep the VPN tunnel r

Strona 164 - 164 Fortinet Inc

246 Fortinet Inc.Managing digital certificates IPSec VPNManaging digital certificatesUse digital certificates to make sure that both participants in a

Strona 165

IPSec VPN Managing digital certificatesFortiGate-4000 Installation and Configuration Guide 2476 Configure the key.7 Select OK to generate the privat

Strona 166 - 166 Fortinet Inc

248 Fortinet Inc.Managing digital certificates IPSec VPNDownloading the certificate requestUse the following procedure to download a certificate reque

Strona 167 - RIP configuration

IPSec VPN Configuring encrypt policiesFortiGate-4000 Installation and Configuration Guide 249Obtaining CA certificatesFor the VPN peers to authentic

Strona 168 - 168 Fortinet Inc

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 25Getting startedThis chapter des

Strona 169

250 Fortinet Inc.Configuring encrypt policies IPSec VPNIn addition to defining membership in the VPN by address, you can configure the encrypt policy

Strona 170 - 170 Fortinet Inc

IPSec VPN Configuring encrypt policiesFortiGate-4000 Installation and Configuration Guide 251Adding a destination addressThe destination address can

Strona 171 - Adding RIP filters

252 Fortinet Inc.Configuring encrypt policies IPSec VPNFor information about configuring the remaining policy settings, see “Adding firewall policies”

Strona 172 - 172 Fortinet Inc

IPSec VPN IPSec VPN concentratorsFortiGate-4000 Installation and Configuration Guide 253Figure 73: Adding an encrypt policyIPSec VPN concentrators I

Strona 173

254 Fortinet Inc.IPSec VPN concentrators IPSec VPNIf the VPN peer is one of the spokes, it requires a tunnel connecting it to the hub (but not to the

Strona 174 - 174 Fortinet Inc

IPSec VPN IPSec VPN concentratorsFortiGate-4000 Installation and Configuration Guide 255See “Adding an encrypt policy” on page 251.5 Arrange the pol

Strona 175 - System configuration

256 Fortinet Inc.IPSec VPN concentrators IPSec VPNVPN spoke general configuration stepsA remote VPN peer that functions as a spoke requires the follow

Strona 176 - Changing system options

IPSec VPN Monitoring and Troubleshooting VPNsFortiGate-4000 Installation and Configuration Guide 257See “Adding an encrypt policy” on page 251.6 Arr

Strona 177

258 Fortinet Inc.Monitoring and Troubleshooting VPNs IPSec VPNViewing dialup VPN connection statusYou can use the dialup monitor to view the status of

Strona 178 - 178 Fortinet Inc

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 259PPTP and L2TP VPNYou can use P

Strona 179

26 Fortinet Inc.Warnings and cautions Getting startedWarnings and cautionsYou should be aware of the following cautions and warnings before operating

Strona 180 - Configuring SNMP

260 Fortinet Inc.Configuring PPTP PPTP and L2TP VPNConfiguring the FortiGate unit as a PPTP gatewayUse the following procedures to configure the Forti

Strona 181

PPTP and L2TP VPN Configuring PPTPFortiGate-4000 Installation and Configuration Guide 2613 Select New to add an address.4 Enter the Address Name, IP

Strona 182 - FortiGate MIBs

262 Fortinet Inc.Configuring PPTP PPTP and L2TP VPN6 Set Service to match the traffic type inside the PPTP VPN tunnel. For example, if PPTP users can

Strona 183 - System traps

PPTP and L2TP VPN Configuring PPTPFortiGate-4000 Installation and Configuration Guide 263To connect to the PPTP VPN1 Start the dialup connection tha

Strona 184 - Logging traps

264 Fortinet Inc.Configuring PPTP PPTP and L2TP VPN5 Name the connection and select Next. 6 If the Public Network dialog box appears, choose the appro

Strona 185 - Firewall configuration

PPTP and L2TP VPN Configuring L2TPFortiGate-4000 Installation and Configuration Guide 265Configuring L2TPSome implementations of L2TP support elemen

Strona 186

266 Fortinet Inc.Configuring L2TP PPTP and L2TP VPNTo add source addressesAdd a source address for every address in the L2TP address range.1 Go to Fir

Strona 187 - Replacement messages

PPTP and L2TP VPN Configuring L2TPFortiGate-4000 Installation and Configuration Guide 2672 Select the policy list that you want to add the policy to

Strona 188 - 188 Fortinet Inc

268 Fortinet Inc.Configuring L2TP PPTP and L2TP VPN4 Go to the Options tab and select IP security properties.5 Make sure that Do not use IPSEC is sele

Strona 189 - Customizing alert emails

PPTP and L2TP VPN Configuring L2TPFortiGate-4000 Installation and Configuration Guide 2697 In the VPN Server Selection dialog, enter the IP address

Strona 190 - 190 Fortinet Inc

Getting started Physical descriptionFortiGate-4000 Installation and Configuration Guide 27Figure 2: FortiGate-4000 package contentsPhysical descript

Strona 191

270 Fortinet Inc.Configuring L2TP PPTP and L2TP VPN8 Add the following registry value to this key:Value Name: ProhibitIpSecData Type: REG_DWORDValue:

Strona 192 - Interfaces

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 271Network Intrusion Detection Sy

Strona 193 - VLAN subinterfaces

272 Fortinet Inc.Detecting attacks Network Intrusion Detection System (NIDS)Selecting the interfaces to monitorTo select the interfaces to monitor for

Strona 194 - Adding firewall policies

Network Intrusion Detection System (NIDS) Detecting attacksFortiGate-4000 Installation and Configuration Guide 273Viewing the signature listYou can

Strona 195

274 Fortinet Inc.Detecting attacks Network Intrusion Detection System (NIDS)Figure 80: Example signature group members listDisabling NIDS attack signa

Strona 196

Network Intrusion Detection System (NIDS) Detecting attacksFortiGate-4000 Installation and Configuration Guide 275To add user-defined signatures1 Go

Strona 197 - Traffic Shaping

276 Fortinet Inc.Preventing attacks Network Intrusion Detection System (NIDS)Preventing attacksNIDS attack prevention protects the FortiGate unit and

Strona 198 - Anti-Virus & Web filter

Network Intrusion Detection System (NIDS) Preventing attacksFortiGate-4000 Installation and Configuration Guide 277Setting signature threshold value

Strona 199 - Comments

278 Fortinet Inc.Logging attacks Network Intrusion Detection System (NIDS)To set Prevention signature threshold values1 Go to NIDS > Prevention.2 S

Strona 200 - Configuring policy lists

Network Intrusion Detection System (NIDS) Logging attacksFortiGate-4000 Installation and Configuration Guide 279The FortiGate unit uses an alert ema

Strona 201 - Enabling policies

28 Fortinet Inc.Front panel features Getting startedFront panel featuresFigure 3 shows the location of the FortiGate-4000 chassis front panel componen

Strona 202

280 Fortinet Inc.Logging attacks Network Intrusion Detection System (NIDS)

Strona 203 - Editing addresses

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 281Antivirus protectionYou can en

Strona 204 - Deleting addresses

282 Fortinet Inc.Antivirus scanning Antivirus protectionAntivirus scanningVirus scanning intercepts most files (including files compressed with up to

Strona 205 - Services

Antivirus protection File blockingFortiGate-4000 Installation and Configuration Guide 283Figure 82: Example content profile for virus scanningFile b

Strona 206 - 206 Fortinet Inc

284 Fortinet Inc.File blocking Antivirus protectionBy default, when blocking is enabled, the FortiGate unit blocks the following file patterns:• execu

Strona 207

Antivirus protection Blocking oversized files and emailsFortiGate-4000 Installation and Configuration Guide 285Blocking oversized files and emailsYo

Strona 208 - 208 Fortinet Inc

286 Fortinet Inc.Viewing the virus list Antivirus protectionViewing the virus listYou can view the names of the viruses and worms in the current virus

Strona 209 - Grouping services

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 287Web filteringWhen you enable A

Strona 210 - Schedules

288 Fortinet Inc.Content blocking Web filtering3 Configure web filtering settings to control how the FortiGate unit applies web filtering to the HTTP

Strona 211 - Creating one-time schedules

Web filtering Content blockingFortiGate-4000 Installation and Configuration Guide 2894 Type a banned word or phrase.If you type a single word (for e

Strona 212 - Creating recurring schedules

Getting started Front panel featuresFortiGate-4000 Installation and Configuration Guide 29FortiBlade-4010 moduleEach FortiBlade-4010 module is an in

Strona 213 - Virtual IPs

290 Fortinet Inc.Content blocking Web filteringBacking up the Banned Word listYou can back up the banned word list by downloading it to a text file on

Strona 214 - Adding static NAT virtual IPs

Web filtering URL blockingFortiGate-4000 Installation and Configuration Guide 2915 Select Return to display the updated Banned Word List.6 You can c

Strona 215

292 Fortinet Inc.URL blocking Web filtering4 Ensure that the Enable checkbox has been selected and then select OK.5 Select OK to add the URL to the We

Strona 216 - 216 Fortinet Inc

Web filtering URL blockingFortiGate-4000 Installation and Configuration Guide 293Downloading the Web URL block listYou can back up the Web URL block

Strona 217

294 Fortinet Inc.Configuring Cerberian URL filtering Web filtering8 You can continue to maintain the Web URL block list by making changes to the text

Strona 218 - IP pools

Web filtering Configuring Cerberian URL filteringFortiGate-4000 Installation and Configuration Guide 295Installing a Cerberian license keyBefore you

Strona 219 - IP pools and dynamic NAT

296 Fortinet Inc.Configuring Cerberian URL filtering Web filteringYou can add users to the default group and apply any policies to the group.Use the d

Strona 220 - IP/MAC binding

Web filtering Script filteringFortiGate-4000 Installation and Configuration Guide 297Script filteringYou can configure the FortiGate unit to remove

Strona 221 - Adding IP/MAC addresses

298 Fortinet Inc.Exempt URL list Web filteringExempt URL listAdd URLs to the exempt URL list to allow legitimate traffic that might otherwise be block

Strona 222 - Enabling IP/MAC binding

Web filtering Exempt URL listFortiGate-4000 Installation and Configuration Guide 299Figure 88: Example URL Exempt listDownloading the URL Exempt Lis

Strona 223 - Content profiles

ContentsFortiGate-4000 Installation and Configuration Guide 3Table of ContentsIntroduction ...

Strona 224 - Adding content profiles

30 Fortinet Inc.Front panel features Getting startedKVM switch moduleUse the KVM switch module to switch serial connections to the CLI of each FortiBl

Strona 225 - 8 Select OK

300 Fortinet Inc.Exempt URL list Web filtering3 Select Upload URL Exempt List .4 Type the path and filename of your URL Exempt List text file, or sel

Strona 226 - 226 Fortinet Inc

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 301Email filterEmail filtering is

Strona 227 - Users and authentication

302 Fortinet Inc.Email banned word list Email filterEmail banned word listWhen the FortiGate unit detects an email that contains a word or phrase in t

Strona 228 - 228 Fortinet Inc

Email filter Email banned word listFortiGate-4000 Installation and Configuration Guide 303Downloading the email banned word listYou can back up the

Strona 229

304 Fortinet Inc.Email block list Email filterEmail block listYou can configure the FortiGate unit to tag all IMAP and POP3 protocol traffic sent from

Strona 230 - Configuring RADIUS support

Email filter Email exempt listFortiGate-4000 Installation and Configuration Guide 305Uploading an email block listYou can create a email block list

Strona 231 - Configuring LDAP support

306 Fortinet Inc.Adding a subject tag Email filterAdding address patterns to the email exempt listTo add an address pattern to the email exempt list1

Strona 232 - Configuring user groups

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 307Logging and reportingYou can c

Strona 233 - Adding user groups

308 Fortinet Inc.Recording logs Logging and reportingRecording logs on a remote computerYou can configure the FortiGate unit to record log messages on

Strona 234 - Deleting user groups

Logging and reporting Recording logsFortiGate-4000 Installation and Configuration Guide 3095 Select Config Policy.To configure the FortiGate unit to

Strona 235 - IPSec VPN

Getting started Rear panel featuresFortiGate-4000 Installation and Configuration Guide 31Rear panel featuresThe FortiGate-4000 chassis rear panel co

Strona 236 - Key management

310 Fortinet Inc.Filtering log messages Logging and reportingFiltering log messagesYou can configure the logs that you want to record and the message

Strona 237 - Manual key IPSec VPNs

Logging and reporting Configuring traffic loggingFortiGate-4000 Installation and Configuration Guide 3114 Select the message categories that you wan

Strona 238 - 238 Fortinet Inc

312 Fortinet Inc.Configuring traffic logging Logging and reportingThis section describes:• Enabling traffic logging• Configuring traffic filter settin

Strona 239 - AutoIKE IPSec VPNs

Logging and reporting Configuring traffic loggingFortiGate-4000 Installation and Configuration Guide 313Configuring traffic filter settingsYou can c

Strona 240 - 240 Fortinet Inc

314 Fortinet Inc.Viewing logs saved to memory Logging and reporting4 Select OK.The traffic filter list displays the new traffic address entry with the

Strona 241 - Configuring advanced options

Logging and reporting Configuring alert emailFortiGate-4000 Installation and Configuration Guide 3154 To view a specific line in the log, type a lin

Strona 242 - 242 Fortinet Inc

316 Fortinet Inc.Configuring alert email Logging and reportingAdding alert email addressesBecause the FortiGate unit uses the SMTP server name to conn

Strona 243 - IPSec VPN AutoIKE IPSec VPNs

Logging and reporting Configuring alert emailFortiGate-4000 Installation and Configuration Guide 317Enabling alert emailYou can configure the FortiG

Strona 244 - 244 Fortinet Inc

318 Fortinet Inc.Configuring alert email Logging and reporting

Strona 245

FortiGate-4000 Installation and Configuration Guide 319FortiGate-4000 Installation and Configuration Guide Version 2.50GlossaryConnection: A link bet

Strona 246 - Managing digital certificates

32 Fortinet Inc.Rear panel features Getting startedFigure 7: FortiGate-4000S rear panelPower supplies and power connectionsThe FortiGate-4000 chassis

Strona 247 - 6 Configure the key

320 Fortinet Inc.GlossaryLAN, Local Area Network: A computer network that spans a relatively small area. Most LANs connect workstations and personal c

Strona 248 - 248 Fortinet Inc

GlossaryFortiGate-4000 Installation and Configuration Guide 321SSH, Secure shell: A secure Telnet replacement that you can use to log into another

Strona 250 - Adding a source address

FortiGate-4000 Installation and Configuration Guide 323FortiGate-4000 Installation and Configuration Guide Version 2.50IndexAacceptpolicy 196actionpo

Strona 251 - Adding an encrypt policy

324 Fortinet Inc.Indexattack updatesconfiguring 127scheduling 126through a proxy server 128authentication 198, 227configuring 228enabling 232LDAP serv

Strona 252 - 252 Fortinet Inc

IndexFortiGate-4000 Installation and Configuration Guide 325dialup PPTPconfiguring Windows 2000 client 263configuring Windows 98 client 262configur

Strona 253 - IPSec VPN concentrators

326 Fortinet Inc.IndexHHA 81connecting a NAT/Route mode cluster 84introduction 19managing HA group 87NAT/Route mode 82replacing FortiGate unit after f

Strona 254 - 254 Fortinet Inc

IndexFortiGate-4000 Installation and Configuration Guide 327log settingfiltering log entries 126, 310traffic filter 313log to memoryconfiguring 309

Strona 255 - Adding a VPN concentrator

328 Fortinet Inc.Indexoversized files and emailblocking 285Ppasswordadding 228changing administrator account 179Fortinet support 138recovering a lost

Strona 256 - 256 Fortinet Inc

IndexFortiGate-4000 Installation and Configuration Guide 329reserved IPadding to a DHCP server 165resolve IP 313traffic filter 313restarting 118res

Strona 257 - Viewing VPN tunnel status

Getting started Rear panel featuresFortiGate-4000 Installation and Configuration Guide 33Cooling fan traysThe FortiGate-4000 chassis is cooled using

Strona 258 - Testing a VPN

330 Fortinet Inc.Indexstatic NAT virtual IP 213adding 214static routeadding 159statusCPU 119interface 143intrusions 121IPSec VPN tunnel 257memory 119n

Strona 259 - PPTP and L2TP VPN

IndexFortiGate-4000 Installation and Configuration Guide 331URL block listadding URL 294, 304clearing 292downloading 290, 293, 299, 304uploading 29

Strona 260 - 260 Fortinet Inc

332 Fortinet Inc.Indexworm listdisplaying 286worm protection 286Zzoneadding 142adding to a virtual domain 156configuring 141

Strona 261

34 Fortinet Inc.Rear panel features Getting started10/100 out of band management moduleThe 10/100 out of band management module provides dedicated eth

Strona 262 - 262 Fortinet Inc

Getting started Rear panel featuresFortiGate-4000 Installation and Configuration Guide 35Pass-through interface moduleTwo pass-through interface mod

Strona 263

36 Fortinet Inc.Rear panel features Getting startedThe internal switched interface module provides two gigabit connections to the internal interfaces

Strona 264 - 264 Fortinet Inc

Getting started Installing hardwareFortiGate-4000 Installation and Configuration Guide 37Installing hardwareThis section describes how to install Fo

Strona 265 - Configuring L2TP

38 Fortinet Inc.Installing hardware Getting startedFigure 14: Rail mounting locationsInstalling FortiBlade-4010 modulesInstall a FortiBlade-4010 modul

Strona 266 - 266 Fortinet Inc

Getting started Installing hardwareFortiGate-4000 Installation and Configuration Guide 39FortiGate-4000P network connectionsUse the following steps

Strona 267

Contents4 Fortinet Inc.Installing hardware...

Strona 268 - 268 Fortinet Inc

40 Fortinet Inc.Turning FortiGate-4000 chassis power on and off Getting startedOut of band management connectionsYou can manage the FortiBlade-4010 mo

Strona 269

Getting started Hot swapping modulesFortiGate-4000 Installation and Configuration Guide 412 Connect the three power cables to the power connection m

Strona 270 - 270 Fortinet Inc

42 Fortinet Inc.Hot swapping modules Getting startedHot swapping FortiBlade-4010 modulesFollow this procedure to hot swap the FortiBlade-4010 modules.

Strona 271 - Detecting attacks

Getting started Hot swapping modulesFortiGate-4000 Installation and Configuration Guide 437 Slide the power supply module into the slot until the lo

Strona 272 - 272 Fortinet Inc

44 Fortinet Inc.Connecting to the web-based manager Getting started2 Unscrew the two locking screws to remove the module’s locking strip.3 Loosen its

Strona 273 - Viewing attack descriptions

Getting started Connecting to the web-based managerFortiGate-4000 Installation and Configuration Guide 45Connecting to the FortiGate-4000 internal i

Strona 274 - 274 Fortinet Inc

46 Fortinet Inc.Connecting to the web-based manager Getting startedFigure 16: FortiGate loginConnecting to the FortiGate-4000 10/100 out of band manag

Strona 275

Getting started Connecting to the Command Line Interface (CLI)FortiGate-4000 Installation and Configuration Guide 47To change the out of band manage

Strona 276 - Preventing attacks

48 Fortinet Inc.Factory default configuration Getting started8 Press Enter to connect to the CLI of the FortiGate-4000 unit.The following prompt is di

Strona 277

Getting started Factory default configurationFortiGate-4000 Installation and Configuration Guide 49Factory default Transparent mode network configur

Strona 278 - Logging attacks

ContentsFortiGate-4000 Installation and Configuration Guide 5Using the command line interface...

Strona 279 - Manual message reduction

50 Fortinet Inc.Factory default configuration Getting startedTable 14: Factory default firewall configuration Internal AddressInternal_AllIP: 0.0.0.0

Strona 280 - 280 Fortinet Inc

Getting started Factory default configurationFortiGate-4000 Installation and Configuration Guide 51Factory default content profilesYou can use conte

Strona 281

52 Fortinet Inc.Factory default configuration Getting startedWeb content profileUse the web content profile to apply antivirus scanning and web conten

Strona 282 - Antivirus scanning

Getting started Planning the FortiGate configurationFortiGate-4000 Installation and Configuration Guide 53Unfiltered content profileUse the unfilter

Strona 283 - File blocking

54 Fortinet Inc.Planning the FortiGate configuration Getting startedFor each FortiGate-4000 unit, the following interfaces are available for processin

Strona 284 - Adding file patterns to block

Getting started Planning the FortiGate configurationFortiGate-4000 Installation and Configuration Guide 55You typically use a FortiGate-4000 unit in

Strona 285

56 Fortinet Inc.Planning the FortiGate configuration Getting startedFigure 19: HA network configuration in NAT/Route modeFigure 20: HA network configu

Strona 286 - Viewing the virus list

Getting started Planning the FortiGate configurationFortiGate-4000 Installation and Configuration Guide 57Figure 21: FortiGate-4000P HA configuratio

Strona 287 - Web filtering

58 Fortinet Inc.Planning the FortiGate configuration Getting startedFigure 22: FortiGate-4000P configuration with load balancersFortiGate-4000 UnitInt

Strona 288 - Content blocking

Getting started FortiGate model maximum values matrixFortiGate-4000 Installation and Configuration Guide 59FortiGate model maximum values matrixTabl

Strona 289 - Clearing the Banned Word list

Contents6 Fortinet Inc.Managing an HA cluster... 87

Strona 290 - 290 Fortinet Inc

60 Fortinet Inc.Next steps Getting startedNext stepsNow that your FortiGate unit is operating, you can proceed to configure it to connect to networks:

Strona 291 - URL blocking

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 61NAT/Route mode installationThis

Strona 292 - 292 Fortinet Inc

62 Fortinet Inc.Preparing to configure NAT/Route mode NAT/Route mode installationAdvanced NAT/Route mode settingsUse Tab le 21 to gather the informat

Strona 293 - Uploading a URL block list

NAT/Route mode installation Using the setup wizardFortiGate-4000 Installation and Configuration Guide 63Out of band management interfaceUse Tab le 2

Strona 294 - 294 Fortinet Inc

64 Fortinet Inc.Using the command line interface NAT/Route mode installationUsing the command line interfaceAs an alternative to using the setup wizar

Strona 295 - Adding a Cerberian user

NAT/Route mode installation Connecting the FortiGate unit to your networksFortiGate-4000 Installation and Configuration Guide 656 Optionally, set th

Strona 296 - 296 Fortinet Inc

66 Fortinet Inc.Configuring your networks NAT/Route mode installationConfiguring your networksIf you are running the FortiGate unit in NAT/Route mode,

Strona 297 - Script filtering

NAT/Route mode installation Completing the configurationFortiGate-4000 Installation and Configuration Guide 67Registering your FortiGate unitAfter p

Strona 298 - Exempt URL list

68 Fortinet Inc.Completing the configuration NAT/Route mode installation

Strona 299 - Uploading a URL Exempt List

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 69Transparent mode installationTh

Strona 300 - 300 Fortinet Inc

ContentsFortiGate-4000 Installation and Configuration Guide 7System status ...

Strona 301 - Email filter

70 Fortinet Inc.Using the setup wizard Transparent mode installationOut of band management interfaceUse Tab le 24 to record the IP address, netmask,

Strona 302 - Email banned word list

Transparent mode installation Using the command line interfaceFortiGate-4000 Installation and Configuration Guide 71Reconnecting to the web-based ma

Strona 303

72 Fortinet Inc.Completing the configuration Transparent mode installationConfigure the Transparent mode default gateway1 Make sure that you are logge

Strona 304 - Email block list

Transparent mode installation Connecting the FortiGate unit to your networksFortiGate-4000 Installation and Configuration Guide 733 Select Anti-Viru

Strona 305 - Email exempt list

74 Fortinet Inc.Transparent mode configuration examples Transparent mode installationTransparent mode configuration examplesA FortiGate unit operating

Strona 306 - Adding a subject tag

Transparent mode installation Transparent mode configuration examplesFortiGate-4000 Installation and Configuration Guide 75Example default route to

Strona 307 - Logging and reporting

76 Fortinet Inc.Transparent mode configuration examples Transparent mode installationWeb-based manager example configuration stepsTo configure basic T

Strona 308 - 308 Fortinet Inc

Transparent mode installation Transparent mode configuration examplesFortiGate-4000 Installation and Configuration Guide 77Figure 24: Static route t

Strona 309 - Log message levels

78 Fortinet Inc.Transparent mode configuration examples Transparent mode installation2 Go to System > Network > Management.• Change the Manageme

Strona 310 - Filtering log messages

Transparent mode installation Transparent mode configuration examplesFortiGate-4000 Installation and Configuration Guide 79Figure 25: Static route t

Strona 311 - Configuring traffic logging

Contents8 Fortinet Inc.Network configuration... 141Configuring z

Strona 312 - Enabling traffic logging

80 Fortinet Inc.Transparent mode configuration examples Transparent mode installationWeb-based manager example configuration stepsTo configure the For

Strona 313 - Adding traffic filter entries

FortiGate-4000 Installation and Configuration Guide Version 2.50FortiGate-4000 Installation and Configuration Guide 81High availabilityFortinet achie

Strona 314 - Viewing logs saved to memory

82 Fortinet Inc.Configuring an HA cluster High availabilityAn active-passive (A-P) HA cluster, also referred to as hot standby HA, consists of a prima

Strona 315 - Configuring alert email

High availability Configuring an HA clusterFortiGate-4000 Installation and Configuration Guide 836 Select the HA mode.Select Active-Active mode to c

Strona 316 - Testing alert email

84 Fortinet Inc.Configuring an HA cluster High availabilityFigure 26: Example Active-Active HA configuration11 If you are configuring a NAT/Route mode

Strona 317 - Enabling alert email

High availability Configuring an HA clusterFortiGate-4000 Installation and Configuration Guide 85To connect the cluster1 Connect the cluster units:F

Strona 318 - 318 Fortinet Inc

86 Fortinet Inc.Configuring an HA cluster High availabilityFigure 28: FortiGate-4000P HA network configurationAdding a new FortiGate unit to a functio

Strona 319 - Glossary

High availability Managing an HA clusterFortiGate-4000 Installation and Configuration Guide 87Managing an HA clusterThe configurations of all of the

Strona 320 - 320 Fortinet Inc

88 Fortinet Inc.Managing an HA cluster High availabilityThis section describes:• Configuring cluster interface monitoring• Viewing the status of clust

Strona 321 - Glossary

High availability Managing an HA clusterFortiGate-4000 Installation and Configuration Guide 89Figure 29: Example cluster members listMonitoring clus

Strona 322 - 322 Fortinet Inc

ContentsFortiGate-4000 Installation and Configuration Guide 9RIP configuration ...

Strona 323

90 Fortinet Inc.Managing an HA cluster High availability4 Select Virus & Intrusions.The cluster displays virus and intrusions status for each clus

Strona 324 - 324 Fortinet Inc

High availability Managing an HA clusterFortiGate-4000 Installation and Configuration Guide 913 Select the serial number of one of the units in the

Strona 325

92 Fortinet Inc.Managing an HA cluster High availabilityManaging individual cluster unitsYou can connect to the CLI of each unit in the cluster. This

Strona 326

High availability Managing an HA clusterFortiGate-4000 Installation and Configuration Guide 93Synchronizing the cluster configurationCluster synchro

Strona 327

94 Fortinet Inc.Managing an HA cluster High availabilityUpgrading firmwareTo upgrade the firmware of the FortiGate units in a cluster, you must upgrad

Strona 328 - 328 Fortinet Inc

High availability Advanced HA optionsFortiGate-4000 Installation and Configuration Guide 95Replacing a FortiGate unit after failoverA failover can o

Strona 329

96 Fortinet Inc.Advanced HA options High availabilityConfiguring the priority of each FortiGate unit in the clusterIn addition to selecting a permanen

Strona 330 - 330 Fortinet Inc

High availability Active-Active cluster packet flowFortiGate-4000 Installation and Configuration Guide 97This command has the following results:• Th

Strona 331

98 Fortinet Inc.Active-Active cluster packet flow High availabilityIn NAT/Route mode, the HA cluster works as a gateway when it responds to ARP reques

Strona 332 - 332 Fortinet Inc

High availability Active-Active cluster packet flowFortiGate-4000 Installation and Configuration Guide 99Transparent mode packet flowIn transparent

Komentarze do niniejszej Instrukcji

Brak uwag