Fortinet 800/800F manual Connecting to the FortiGate unit, Transparent mode

Page 16

Connecting to the FortiGate unit

Configuring

Transparent mode

In Transparent mode, the FortiGate unit is invisible to the network. Similar to a network bridge, all FortiGate interfaces must be on the same subnet. You only have to configure a management IP address to make configuration changes. The management IP address is also used for antivirus and attack definition updates.

Figure 2: FortiGate unit in Transparent mode

 

 

 

 

10.10.10.1

 

 

 

 

Management IP

 

Gateway to public network

 

Internal Network

 

 

 

Internet

204.23.1.2

10.10.10.2

External

Internal

 

 

Router

 

10.10.10.3

 

 

 

Transparent mode policies

 

 

 

controlling traffic between

 

 

 

internal and external networks.

You typically use the FortiGate unit in Transparent mode on a private network behind an existing firewall or behind a router. The FortiGate unit performs firewall functions, IPSec VPN, virus scanning, IPS web filtering, and Spam filtering.

Connecting to the FortiGate unit

To configure, maintain and administer the FortiGate unit, you need to connect to it. There are two methods for these tasks:

using the web-based manger, a GUI interface using a current web browser such as FireFox or Internet Explorer.

using the command line interface (CLI), a command line interface similar to DOS or UNIX commands using an SSH terminal or Telnet terminal.

Connecting to the web-based manager

To connect to the web-based manager, you require:

a computer with an Ethernet connection

Microsoft Internet Explorer version 6.0 or higher or any recent version of the most popular web browser

an Ethernet cable.

To connect to the web-based manager

1Set the IP address of the management computer to the static IP address 192.168.1.2 with a netmask of 255.255.255.0.

2Using the Ethernet cable, connect the internal interface of the FortiGate unit to the computer Ethernet connection.

3Start your browser and enter the address https://192.168.1.99. (remember to include the “s” in https://).

 

FortiGate-800 and FortiGate-800F FortiOS 3.0 MR6 Install Guide

16

01-30006-0455-20080910

Image 16
Contents Install G U I D E Trademarks Regulatory complianceContents Advanced configuration FortiGate FirmwareTesting new firmware before installing Installing firmware from a system reboot using the CLIIndex Page Introduction Register your FortiGate unitAbout this document About the FortiGate-800/800FDocument conventions Further Reading Typographic conventionsFortinet Knowledge Center Customer service and technical supportComments on Fortinet technical documentation Installing Environmental specificationsGrounding Rack mount instructions To install the FortiGate unit into a rack MountingConnecting to the network To power on the FortiGate unitTo power off the FortiGate unit Plugging in the FortiGateNAT vs. Transparent mode NAT modeConnecting to the FortiGate unit Transparent modeConnecting to the web-based manager To connect to the web-based managerConnecting to the CLI To connect to the CLIConfiguring NAT mode Using the web-based managerConfigure the interfaces To configure interfaces Go to System Network InterfaceConfigure a DNS server Adding a default route and gatewayTo modify the default gateway Go to Router Static Adding firewall policiesTo set an interface to use a static address Using the CLITo set an interface to use Dhcp addressing To configure DNS server settings To set an interface to use PPPoE addressingTo modify the default gateway To add an outgoing traffic firewall policySwitching to Transparent mode Configuring Transparent modeTo switch to Transparent mode Go to System Status Source Address All Destination Interface To switch to Transparent mode Verify the configuration Backing up the configurationRestoring a configuration Additional configurationSet the Administrator password Set the time and dateConfigure FortiGuard Updating antivirus and IPS signaturesAdditional configuration Advanced configuration Protection profilesFirewall policies Firewall policiesConfiguring firewall policies Antivirus optionsAntiSpam options Web filtering Logging FortiGate Firmware Downloading firmwareUpgrading the firmware Using the web-based managerReverting to a previous version Using the USB Auto-Install Backup and Restore from a USB keyTo revert to a previous firmware version Using the CLI To upgrade the firmware using the CLIExecute restore image namestr tftpip4 To revert to a previous firmware version using the CLIInstalling firmware from a system reboot using the CLI Execute restore image namestr tftpipv4To install firmware from a system reboot Press any key to display configuration menuRestoring the previous configuration To backup configuration using the CLITo restore configuration using the CLI Additional CLI Commands for a USB keyTo configure the USB Auto-Install using the CLI Testing new firmware before installing To test the new firmware imageTesting new firmware before installing Testing new firmware before installing Index Web filtering 35 web-based manager Page Page