Manuals
/
Fortinet
/
Computer Equipment
/
Network Card
Fortinet
manual
FortiLog-100 FortiLog-400 FortiLog-800, January 15, 2004
Models:
FortiLog-100
FortiLog-400
FortiLog-800
1
1
124
124
Download
124 pages
26.49 Kb
1
2
3
4
5
6
7
8
<
>
Specs
Password
Factory defaults Administrator
Login
Admin
Connecting the FortiLog unit
Config Network
Assigning access to folders
CLI commands
FortiGate 2.8 log settings
Page 1
Image 1
FortiLog
Administration Guide
FortiLog-100
1
FortiLog-400
4
FortiLog-800
8
FortiLog Administration Guide
Version 1.6
January 15, 2004
05-16000-0082-20050115
Page 2
Page 1
Image 1
Page 2
Contents
January 15, 2004
FortiLog-100 FortiLog-400 FortiLog-800
Trademarks
Version 1.6 January 15 05-16000-0082-20050115
Regulatory Compliance
Table of Contents
Managing the FortiLog unit
Config Network
Reports
103
Setting folder and file properties
104
110
FortiLog-400 FortiLog-100 FortiLog-800
Introduction
Operational Modes
Active Mode
Introduction
Passive Mode
About this guide
Explains how to install and set up the FortiLog unit
FortiLog documentation
Related documentation
Explains how to configure VPNs using the web-based manager
FortiGate documentation
FortiClient documentation
FortiManager documentation
FortiMail documentation
Fortinet Knowledge Center
Customer service and technical support
Customer service and technical support
Checking the package contents
Setting up the FortiLog unit
Weight
Hardware specifications Dimensions
FortiLog-100 2.5 kg FortiLog-400 11 kg FortiLog-80014 kg
Power requirements
Planning the installation
Environmental specifications
Air flow
Connecting the FortiLog unit
Connecting the FortiLog unit
FortiLog unit Management PC
To connect the FortiLog unit to the network
Using the web-based manager
Configuring the FortiLog unit
Factory defaults Administrator
To connect to the web-based manager
To configure the FortiLog unit using the web-based manager
Using the command line interface
To configure the FortiLog unit using the CLI
Set system interface port1 mode static ip IPaddress netmask
Set the primary DNS server IP address
Using the front panel buttons and LCD
Set system dns primary IPaddress
Configuring the FortiLog unit
Configuring FortiGate unit running FortiOS
Connecting to the FortiLog Unit
Go to Log&Report Log Config
Sending device logs to the FortiLog unit
FortiGate 2.8 log settings
Configuring FortiGate devices running FortiOS
FortiGate 2.5 Log settings
Configuring FortiMail devices
To add a device
Adding a device
Groups from this tab
Unregistered
Defining device port interfaces
To create a device group Go to System Devices Groups
Creating Device Groups
Status
Managing the FortiLog unit
Status
Interval
Operating Mode
Refresh
Alerts
Changing the FortiLog host name
To change the operating mode in the CLI
Changing operating modes
Set system opmode activepassive
Viewing system resources information
To change the firmware using the web-based manager
Changing the firmware
To change the firmware using the CLI
Installing firmware from a system reboot
Execute restore image namestr tftpip
Execute restore image FortiLog400-v120.out
Press any key to enter configuration menu
To install firmware from a system reboot
Immediately press any key to interrupt the system startup
Enter Local Address
To test a new firmware image before installing it
Testing a new firmware image
Following message appears
Enter File Name image.out
Save as Default firmware/Run image without savingD/R
Installing a backup firmware image
Get system status
You can test the new firmware image as required
Type B
To install a backup firmware image
Switching to the default firmware image
Switching to a backup firmware image
To switch to the backup firmware image
To switch back to the default firmware image
Backing up system settings
Execute reboot
To backup up system settings Go to System Status Status
Restore factory default system settings
Restoring system settings
To restore system settings Go to System Status Status
Restoring a FortiLog unit
Press any key to begin download
To upload the firmware image to the FortiLog unit
Network
Config
Config RAID
Config Policy
Log settings
Log to Host
Port
Log policy
Config Policy
CSV format
Levels Description Generated by
Time
Admin
Options
Language
Configure Administrator access
Administrator options
Administrator account levels
Changing the Administrator password
Devices Active mode
To add an administrator account Go to System Config Admin
Adding and registering a device
Device list
Editing device information
Server
Alert Email
To edit a device Go to System Devices
Local
Device Active mode
Creating a new device alert
Attack Type Entry and listing Level of wait interval
Attack Type
To add a device alert Go to System Alert Email Device
Alerts
Virus Type
Defining IP aliases
Network Sharing
Window
IP aliases
To set host alias names Go to Reports IP Aliases
Reports
To create a report Go to Reports Config
Creating and generating a report
Select New and enter a name for the report
To define report parameters Go to Reports Config
Configuring report parameters
Set the following
Select Run now
To set the report queries Go to Reports Config
Configuring a report query
Resolve Service Names Ranked Reports show top
Select a report from the list Select Queries
Creating a query profile
To select the devices Go to Reports Config
Selecting the devices for the report
To create a query profile
Creating a device profile
To set the filtering on a log report Go to Reports Config
Select filtering options
To create a device profile
To create a scheduled report Go to Reports Config
Setting a report schedule
Creating a filter profile
To create a report filter profile
Choosing the report destination and format
Creating a report schedule profile
Select Schedule Select a day from the following
To create a report schedule profile
Creating a report destination and format profile
To generate a report on demand Go to Reports Config
Reports on demand
To create a pre-defined output selection
To view a generated report Go to File Browse Reports
Viewing reports
Individual reports
Roll up report
Vulnerability reports
To create a report Go to Reports Config Vulnerability
Creating and generating a report
Selecting report result parameters
Per device Resolve Host Names Resolve Service Names
Selecting plug-ins
Creating a plug-in profile
To select the plug-ins Go to Reports Config Vulnerabilities
Selecting the scan targets for the report
To create a plug-in profile
To add additional devices
Creating a scan target profile
To create a scan target profile
Browse/Reports hard disk
File
Email list
As an email attachment
Select the report name from the list of completed reports
Viewing the vulnerability report
Using Logs
Viewing logs
Log view interface
To view the device log files Go to File Browse Logs
Finding log information
Select the column header to change the sort order between
Ascending and descending order
Basic log filter
Alert level
Importing log files
To import a log file Go to File Browse Logs
Match Up and Down arrows
Log Search
Log watch Active mode
To set log watching Go to File Browse Logs
Show Up and Down arrows
Sort list
Event correlation Active mode
Event correlation Active mode
Connecting to the FortiLog file system
Using the FortiLog unit as a NAS
Select Enable for a file sharing protocol
Providing access to the FortiLog hard disk
Selecting a file sharing protocol
Adding and modifying user accounts
Adding and modifying group accounts
Assigning access to folders
To add a user group Go to Network Sharing Groups
Select Create New
Windows sharing configuration
NFS share configuration
Modifying the user or group folder access
To set file and folder permissions Go to File Browse Files
Setting folder and file properties
Owner
CLI documentation conventions
FortiLog CLI reference
Connecting to the FortiLog-800 console
Connecting to the CLI
FortiLog-800 login
To connect to the FortiLog-800 console
To use the CLI to configure SSH or Telnet access
Setting administrative access for SSH or Telnet
Welcome
Connecting to the FortiLog CLI using Telnet
Connecting to the FortiLog CLI using SSH
To connect to the CLI using SSH
To connect to the CLI using Telnet
FortiLog CLI commands include
CLI commands
Execute branch
Get command architecture
Use get to display settings, logs, or system information
Get branch
Get system admin
Get log logsetting
Get report resolve
Get report aliases
Use set alertemail to configure alert mails
Use set to configure settings, logs, or system information
Set alertemail command architecture
Set branch
Namestr is the user name
String is the password
Below
Set alertmail local time 0.5 1.0 3.0 6.0
Set alertmail device enable add leveltime
CLI commands
Settings originate from a singe source IP
Set console
Use set console to set console configuration
Set log command architecture
Use set log to configure log settings
Set log
YY-MM-DD
100
101
102
103
Set NAS
Set report
Set report command architecture
Set system
104
105
106
107
0.0
108
Trusthoststr is trusted host IP address
Netmaskstr is the netmask
109
Unset branch
111
112
Network Activity
Appendix a Log Report Types
Web Activity
113
FTP Activity
Mail Activity
Terminal Activity
115
Mail activity reports record Email traffic and connections
Antivirus Activity
Intrusion Activity
Web Filter Activity
117
Mail Filter Activity
VPN Activity
Content Activity
119
120
121
Index
Index
122
123
124
Top
Page
Image
Contents