Fortinet FortiGate-800 manual Getting started

Page 25

FortiGate-800 Installation and Configuration Guide Version 2.50

Getting started

This chapter describes unpacking, setting up, and powering on a FortiGate Antivirus Firewall unit. When you have completed the procedures in this chapter, you can proceed to one of the following:

If you are going to operate the FortiGate unit in NAT/Route mode, go to “NAT/Route mode installation” on page 41.

If you are going to operate the FortiGate unit in Transparent mode, go to “Transparent mode installation” on page 59.

If you are going to operate two or more FortiGate units in HA mode, go to “High availability” on page 73.

This chapter describes:

Package contents

Mounting

Powering on

Connecting to the web-based manager

Connecting to the command line interface (CLI)

Factory default FortiGate configuration settings

Planning the FortiGate configuration

FortiGate model maximum values matrix

Next steps

FortiGate-800 Installation and Configuration Guide

25

Image 25
Contents January 15 Installation and Configuration GuideRegulatory Compliance TrademarksTable of Contents NAT/Route mode installation High availability Virus and attack definitions updates and registration 117 Network configuration 137 System configuration 169 Users and authentication 223 IPSec VPN 231 Network Intrusion Detection System Nids 269 Email filter 303 Glossary 323 Index 327 Contents Flexibility demanded by large enterprises IntroductionAntivirus protection Web content filteringFirewall Email filteringTransparent mode NAT/Route modeVLANs and virtual domains Network intrusion detectionHigh availability VPNWeb-based manager Secure installation, configuration, and managementLogging and reporting Command line interfaceFortinet documentation Document conventionsComments on Fortinet technical documentation Customer service and technical supportCustomer service and technical support Getting started Mounting Package contentsPower requirements Powering onEnvironmental specifications To power on the FortiGate-800 unitTo connect to the web-based manager Connecting to the web-based managerTo connect to the CLI Connecting to the command line interface CLIBits per second 9600 Data bits Parity Stop bits Flow controlFactory default NAT/Route mode network configuration Factory default FortiGate configuration settingsAccount Internal interfaceFactory default Transparent mode network configuration Factory default firewall configuration Strict content profile Factory default content profilesStrict content profile Options Scan content profileScan content profile Options Unfiltered content profile Web content profileWeb content profile Options Unfiltered content profile OptionsExample NAT/Route mode network configuration Planning the FortiGate configurationExample NAT/Route multiple internet connection configuration NAT/Route mode with multiple external network connectionsSetup wizard Configuration optionsFront keypad and LCD FortiGate model maximum values matrixSignatures Antivirus file Block patterns Web filter Next stepsPreparing to configure NAT/Route mode NAT/Route mode installationAdvanced FortiGate NAT/Route mode settings Advanced NAT/Route mode settingsDhcp server Starting the setup wizard Using the setup wizardReconnecting to the web-based manager DMZ and user-defined interfacesUsing the command line interface Using the front control buttons and LCDConfiguring the FortiGate unit to operate in NAT/Route mode Configuring NAT/Route mode IP addressesSet system interface external mode static ip 204.23.1.5 To connect the FortiGate unit running in NAT/Route mode Connecting the FortiGate unit to your networksTo connect to FortiGate-800 user-defined interfaces FortiGate-800 ExternalExample FortiGate-800 user-defined interface connections Configuring your networksConfiguring the DMZ interface Completing the configurationConfiguring interfaces 1 to Setting the date and timeConfiguring virus and attack definition updates Configuration example Multiple connections to the InternetRegistering your FortiGate unit Internal Configuring ping serversPrimary and backup links to the Internet Using the CLIDestination-based routing examples Go to System Network Routing TableLoad sharing and primary and secondary connections Load sharingRouting table should have routes arranged as shown in Table To add the routes using the CLIPolicy routing examples Routing a service to an external networkDestination DMZAll Schedule Always Service Adding a redundant default policyFirewall policy example Adding more firewall policiesRestricting access to a single Internet connection Configuration example Multiple connections to the Internet Preparing to configure Transparent mode Transparent mode installationTransparent mode settings Administrator Password DNS SettingsGo to System Status Changing to Transparent mode using the web-based managerOperation mode Transparent Changing to Transparent mode using the CLIConfigure the Transparent mode default gateway Configuring the Transparent mode management IP addressEnabling antivirus protection Connecting the FortiGate unit to your networks FortiGate-800 Transparent mode configuration examplesExample default route to an external network Default routes and static routesDefault route to an external network General configuration stepsCLI configuration steps Web-based manager example configuration stepsExample static route to an external destination Go to System Network ManagementDMZ Example static route to an internal destination FortiGate-800 Set system route number 1 dst 172.16.1.11 255.255.255.0 gw1 Transparent mode configuration examples High availability Configuring FortiGate units for HA operation Configuring an HA clusterTo configure a FortiGate unit for HA operation Go to System Config HANone Weighted Round RobinHub Least ConnectionExample Active-Active HA configuration Connecting the clusterTo connect the cluster HA network configurationAdding a new FortiGate unit to a functioning cluster Managing an HA clusterTo add a new unit to the cluster Configuring cluster interface monitoring Monitoring cluster members Viewing the status of cluster membersExample cluster CPU, memory, and hard disk display To set the update frequencyViewing and managing cluster log messages Viewing cluster sessionsViewing cluster communication sessions Monitoring cluster units for failoverManaging individual cluster units To manage a cluster unit Changing cluster unit host namesTo set the host name of each cluster member Keyword Description Synchronizing the cluster configurationUpgrading firmware Replacing a FortiGate unit after failover Advanced HA optionsSelecting a FortiGate unit as a permanent primary unit To select a permanent primary unitTo set the priority of each FortiGate unit in a cluster Configuring weighted-round-robin weightsActive-active HA packet flow Active-Active cluster packet flowNAT/Route mode packet flow Transparent mode packet flow Active-Active cluster packet flow System status System statusChanging the FortiGate host name Firmware upgrade procedures Procedure DescriptionChanging the FortiGate firmware To change the FortiGate host name Go to System StatusUpgrading the firmware using the CLI Upgrading the firmware using the web-based managerTo upgrade the firmware using the web-based manager To upgrade the firmware using the CLIExecute ping Reverting to a previous firmware versionReverting to a previous firmware version using the CLI To revert to a previous firmware version using the CLI To install firmware from a system reboot 100 Press any key to enter configuration menuTesting a new firmware image before installing it Restoring the previous configuration101 To test a new firmware image 102Installing a backup firmware image Installing and using a backup firmware image103 104 To install a backup firmware imageTo switch to the backup firmware image Switching to the backup firmware image105 Switching back to the default firmware image Manual virus definition updatesTo switch back to the default firmware image To update the antivirus definitions manuallyTo update the attack definitions manually Manual attack definition updatesDisplaying the FortiGate serial number 107Restoring system settings Backing up system settingsDisplaying the FortiGate up time Displaying log hard disk statusChanging to Transparent mode Restoring system settings to factory defaultsTo change to Transparent mode Go to System Status 109To change to NAT/Route mode Go to System Status Changing to NAT/Route modeRestarting the FortiGate unit Shutting down the FortiGate unitViewing CPU and memory status System status111 To view CPU and memory status Go to System Status MonitorCPU and memory status monitor Viewing sessions and network status113 Viewing virus and intrusions statusTo view the session list Go to System Status Session Session listProtocol 115116 Updating antivirus and attack definitions Virus and attack definitions updates and registration117 Go to System Update Connecting to the FortiResponse Distribution NetworkVersion Expiry date Last update attempt Last update status To make sure the FortiGate unit can connect to the FDN119 Manually initiating antivirus and attack definitions updatesConfiguring update logging Scheduling updatesEnabling scheduled updates 120Adding an override server To add an override server Go to System Update121 Enabling scheduled updates through a proxy server Enabling push updates122 Push updates when FortiGate IP addresses change Enabling push updatesTo enable push updates Go to System Update 123Example push updates through a NAT device Enabling push updates through a NAT device124 125 General procedure126 Schedule Always Service ANY Action Accept To configure the FortiGate NAT deviceAdding a firewall policy for the port forwarding virtual IP 127128 Registering FortiGate units129 FortiCare Service Contracts130 Registering the FortiGate unit131 Updating registration informationViewing the list of registered FortiGate units Recovering a lost Fortinet support password132 Adding or changing a FortiCare Support Contract number Registering a new FortiGate unit133 Changing your contact information or security question Changing your Fortinet support password134 135 Downloading virus and attack definitions updates136 Registering a FortiGate unit after an RMAConfiguring zones Network configuration137 Adding zones Configuring interfacesDeleting zones 138Viewing the interface list Changing the administrative status of an interfaceAdding an interface to a zone 139Configuring an interface for Dhcp Configuring an interface with a manual IP address140 141 Configuring an interface for PPPoEAdding a ping server to an interface Adding a secondary IP address to an interface142 143 Controlling administrative access to an interfaceConfiguring the management interface in Transparent mode Configuring traffic logging for connections to an interfaceChanging the MTU size to improve network performance 144145 Vlan overviewRules for Vlan IDs VLANs in NAT/Route modeRules for Vlan IP addresses 146Adding Vlan subinterfaces Virtual domains in Transparent mode147 To add Vlan subinterfaces Go to System Network InterfaceFortiGate unit with two virtual domains 148Virtual domain properties Configuring a virtual domainAdding a virtual domain 149Adding zones to virtual domains Adding Vlan subinterfaces to a virtual domain150 To add a zone to a virtual domain Go to System Network Zone 151Adding addresses for virtual domains Adding firewall policies for virtual domains152 Go to Firewall AddressAdding DNS server IP addresses Configuring routingDeleting virtual domains 153To add a default route Go to System Network Routing Table Adding a default routeAdding destination-based routes to the routing table 154155 Adding routes in Transparent modePolicy routing Configuring the routing table156 Policy routing command syntax Configuring Dhcp services157 Configuring a Dhcp server Configuring a Dhcp relay agentAdding a Dhcp server to an interface Adding scopes to a Dhcp serverTo add a scope to a Dhcp server Go to System Network Dhcp 159Viewing a Dhcp server dynamic IP list Adding a reserve IP to a Dhcp server160 Selected scopeRIP settings RIP configuration161 Invalid 162Holddown Flush163 Configuring RIP for FortiGate interfaces164 Example RIP configuration for an internal interfaceAdding a RIP filter list Adding RIP filters165 To add a RIP filter list Go to System RIP FilterAssigning a RIP filter list to the incoming filter Assigning a RIP filter list to the neighbors filter166 167 Assigning a RIP filter list to the outgoing filter168 Setting system date and time System configurationTo set the date and time Go to System Config Time 169To set the Auth timeout Go to System Config Options To set the system idle timeout Go to System Config OptionsChanging system options 170171 Modifying the Dead Gateway Detection settingsAdding new administrator accounts Adding and editing administrator accountsTo add an administrator account Go to System Config Admin 172Editing administrator accounts Configuring SnmpTo edit an administrator account Go to System Config Admin 173Configuring FortiGate Snmp support Configuring the FortiGate unit for Snmp monitoringConfiguring Snmp access to an interface Configuring Snmp community settingsSystem Name 175System Location 176 FortiGate MIBsGeneral FortiGate traps FortiGate trapsSystem traps 177Nids traps VPN trapsAntivirus traps Logging trapsFirewall configuration System configuration and statusFortinet MIB fields 179180 Logging and reporting configuration Replacement messages181 182 Customizing replacement messages183 Customizing alert emailsAlert email message sections Alert email message sections 184185 Firewall configuration186 Default firewall configurationVlan subinterfaces InterfacesZones 187Default addresses Interface Address Description ServicesAddresses SchedulesAdding firewall policies Content profiles189 To add a firewall policy Go to Firewall PolicySource Firewall policy options190 Destination ServiceSchedule ActionTraffic Shaping VPN Tunnel192 Dynamic IP Pool Fixed PortAnti-Virus & Web filter Authentication193 Maximum Bandwidth Traffic PriorityComments Log Traffic194 Policy matching in detail Configuring policy lists195 Enabling and disabling policies Changing the order of policies in a policy listDisabling policies Enabling policiesAdding addresses Addresses197 To add an address Go to Firewall Address198 Editing addressesTo edit an address Go to Firewall Address Organizing addresses into address groups Deleting addresses199 To delete an address Go to Firewall AddressPredefined services Services200 GRE 201Ldap 202203 Adding custom TCP and UDP servicesAdding custom IP services Adding custom Icmp servicesGrouping services 204205 Schedules206 Creating one-time schedules207 Creating recurring schedulesAdding schedules to policies Virtual IPs208 To add a schedule to a policy Go to Firewall Policy209 Adding static NAT virtual IPsTo add a static NAT virtual IP Go to Firewall Virtual IP Virtual IP External Interface examples Description Internal210 Adding port forwarding virtual IPs211 212 Adding policies with virtual IPsTo add a policy with a virtual IP Go to Firewall Policy Adding an IP pool IP pools213 To add an IP pool Go to Firewall IP PoolIP Pools for firewall policies that use fixed ports IP/MAC bindingIP pools and dynamic NAT 214Go to Firewall IP/MAC Binding Static IP/MAC 215216 Adding IP/MAC addressesEnabling IP/MAC binding Viewing the dynamic IP/MAC list217 218 Content profilesAdding content profiles Default content profilesTo add a content profile Go to Firewall Content Profile 219Oversized File/Email Pass Fragmented Email 220To add a content profile to a policy Go to Firewall Policy Adding content profiles to policies221 222 223 Users and authenticationAdding user names and configuring authentication Setting authentication timeoutAdding user names and configuring authentication To set authentication timeout Go to System Config Options225 Deleting user names from the internal databaseAdding Radius servers Configuring Radius supportDeleting Radius servers 226Adding Ldap servers Configuring Ldap support227 To add an Ldap server Go to User Ldap228 Deleting Ldap serversTo delete an Ldap server Go to User Ldap Adding user groups Configuring user groups229 To add a user group Go to User User Group230 Deleting user groupsTo delete a user group Go to User User Group 231 IPSec VPNManual Keys Key managementAutoIKE with pre-shared keys AutoIKE with certificatesManual key IPSec VPNs General configuration steps for a manual key VPNAdding a manual key VPN tunnel 233AES128 234AES192 AES256Adding a phase 1 configuration for an AutoIKE VPN General configuration steps for an AutoIKE VPNAutoIKE IPSec VPNs 235Remote Gateway Static IP Address 236Remote Gateway Dialup User To configure phase 1 advanced options Configuring advanced options237 238 239 Adding a phase 1 configuration Standard optionsTo add a phase 2 configuration Go to VPN Ipsec Phase Adding a phase 2 configuration for an AutoIKE VPN240 Use selectors from policy 241Use wildcard selectors Obtaining a signed local certificate Managing digital certificatesGenerating the certificate request 242Key Type 243Key Size Importing the signed local certificate Downloading the certificate request244 Obtaining CA certificates Configuring encrypt policiesImporting CA certificates 245246 Adding a source addressTo add a source address Go to Firewall Address Adding an encrypt policy Adding a destination address247 To add a destination address Go to Firewall Address248 249 IPSec VPN concentratorsTo create a VPN concentrator configuration VPN concentrator hub general configuration steps250 251 Adding a VPN concentratorTo create a VPN spoke configuration VPN spoke general configuration steps252 253 Redundant IPSec VPNsTo configure a redundant IPSec VPN Configuring redundant IPSec VPNs254 To view VPN tunnel status Go to VPN Ipsec Phase Monitoring and Troubleshooting VPNsViewing VPN tunnel status Viewing dialup VPN connection status256 Testing a VPNPptp and L2TP VPN Configuring Pptp257 258 Configuring the FortiGate unit as a Pptp gatewayTo add users and user groups To add a source addressTo add a source address group 259To add a destination address To add a firewall policy260 Configuring a Windows 98 client for PptpConfiguring a Windows XP client for Pptp Configuring a Windows 2000 client for Pptp261 To connect to the Pptp VPN262 To configure the VPN connectionSelect Properties Security Configuring the FortiGate unit as an L2TP gateway Configuring L2TP263 To add source addresses 264265 Configuring a Windows 2000 client for L2TP266 To disable IPSecTo connect to the L2TP VPN 267 Configuring a Windows XP client for L2TP268 Detecting attacks Network Intrusion Detection System Nids269 Selecting the interfaces to monitor Configuring checksum verificationDisabling monitoring interfaces 270Viewing attack descriptions Viewing the signature list271 Adding user-defined signatures Disabling Nids attack signatures272 273 Downloading the user-defined signature listPreventing attacks To enable Nids attack prevention Go to Nids PreventionEnabling Nids attack prevention Enabling Nids attack prevention signatures275 Setting signature threshold valuesLogging attack messages to the attack log Logging attacksReducing the number of Nids attack log and email messages Automatic message reduction277 Manual message reduction278 Antivirus protection General configuration steps279 280 Antivirus scanningTo scan FortiGate firewall traffic for viruses 281 File blockingAdding file patterns to block Blocking files in firewall traffic282 To block files in firewall trafficQuarantining infected files QuarantineQuarantining blocked files 283Sorting the quarantine list Viewing the quarantine list284 To view the quarantine list Go to Anti-Virus QuarantineFiltering the quarantine list Configuring quarantine optionsDeleting files from the quarantine list Downloading quarantined filesBlocking oversized files and emails Configuring limits for oversized files and email286 Exempting fragmented email from blocking To view the virus list Go to Anti-Virus Config Virus ListViewing the virus list 287288 289 Web filteringGo to Web Filter Content Block Content blockingAdding words and phrases to the Banned Word list 290291 Clearing the Banned Word listRestoring the Banned Word list Backing up the Banned Word list292 URL blocking Configuring FortiGate Web URL blockingAdding URLs to the Web URL block list 293294 Clearing the Web URL block listUploading a URL block list Downloading the Web URL block list295 To upload a URL block listConfiguring FortiGate Web pattern blocking Configuring Cerberian URL filtering296 Configuring Cerberian web filter Installing a Cerberian license keyAbout the default group and policy Adding a Cerberian userEnabling Cerberian URL filtering To configure Cerberian web filtering298 Enabling script filtering Script filteringSelecting script filter options 299Adding URLs to the URL Exempt list Exempt URL list300 Go to Web Filter URLExemptUploading a URL Exempt List Downloading the URL Exempt List301 Go to Web Filter URL Exempt302 303 Email filterAdding words and phrases to the email banned word list Email banned word list304 Uploading the email banned word list Downloading the email banned word list305 Adding address patterns to the email block list Email block listDownloading the email block list 306Uploading an email block list Email exempt list307 To upload the email block listAdding a subject tag To add a subject tag Go to Email Filter ConfigAdding address patterns to the email exempt list 308Recording logs Logging and reporting309 Recording logs on a NetIQ WebTrends server Recording logs on a remote computer310 311 Recording logs on the FortiGate hard diskOverwrite OptionLog message levels Recording logs in system memory312 Filtering log messages To filter log entries Go to Log&Report Log Setting313 314 Configuring traffic loggingEnabling traffic logging for an interface Enabling traffic loggingEnabling traffic logging for a Vlan subinterface Enabling traffic logging for a firewall policyAdding traffic filter entries Configuring traffic filter settings316 Resolve IPViewing logs saved to memory Destination IP Address Destination Netmask ServiceViewing logs 317Searching logs Viewing and managing logs saved to the hard disk318 KeywordTo view the active or saved logs Go to Log&Report Logging 319Deleting all messages from an active log Downloading a log file to the management computerDeleting a saved log file 320Testing alert email Configuring alert emailAdding alert email addresses 321322 Enabling alert email323 Glossary324 325 326 327 IndexIndex 328Dialup Pptp 329Http 330Ldap 331332 Pptp dialup connection 333334 TCP 335Vlan 336