FortinetメーカーFortiGate 224Bの使用説明書/サービス説明書
ページ先へ移動 of 54
www.fortinet.com For tiGate-224B FortiO S 3 . 0 MR 6 INST ALL GUIDE.
FortiGate-224B Install Guide FortiOS 3.0 MR6 15 August 2008 01-30006-04 51-20080815 © Copyright 2008 Fortine t, Inc. All rights reserved. No part of this publication including text, examples , diagra.
Contents FortiGate-224B FortiOS 3.0 MR6 Install Guide 01-30006-0451-2008081 5 3 Content s Contents...................................................................... .............. .......... 3 Introduction ............... .........................
FortiGate-224B FortiOS 3.0 MR6 Install Guide 4 01-30006-0451-200808 15 Contents Configure a DNS server ................ ................... ................ ................... . 22 Adding a default route and gateway . ......... ................. ....
Contents FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 5 Installing firmware from a system reboot using the CLI...... ................ ........ 42 Restoring the previous configuration ............................. .............
FortiGate-224B FortiOS 3.0 MR6 Install Guide 6 01-30006-0451-200808 15 Contents.
Introduction Register your FortiGate unit FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 7 Introduction Welcome an d thank you for selecting Fortinet product s for your real-time network protection.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 8 01-30006-0451-200808 15 About the FortiGate-224B Introduction About the FortiGate-224B The FortiGa te-224B conv erges network and security products th at uniquely integrate multiple layers of threat protection with granular network access controls.
Introduction Further Reading FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 9 Typographic conventions FortiGate document ation uses the fo llowing typographical co nventions: Fu.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 10 01-30006-0451-200808 15 Customer service and technical support Introduction • FortiGate Log Message Refe rence Available exclusively from the Fortinet.
Installing Environmental specifications FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 11 Inst alling This chapter describes in stalling your FortiGate unit in your server room, environmental specifications and how to mount the FortiGate in a rack if applicable.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 12 01-30006-0451-200808 15 Cautions and warnings Installing • Connect the equipment into an outlet on a circuit differen t from that to which the receiver is connecte d. • Consult the dealer or an experien ced radio/TV technician for help.
Installing Cautions and warni ngs FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 13 When placing the For tiGate unit on an y flat , st able surface, ensure the unit has at least 1.5 inches (3.75 cm) of clearance on each side to ensure adequate airflow for cooling.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 14 01-30006-0451-200808 15 Plugging in the FortiGa te Installing Figure 3: Mounting in a rack Plugging in the FortiGate Use the following steps to conne ct the power supply to the FortiGate unit.
Configuring NA T vs. T ransparent mode FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 15 Configuring This section provides an overview of t he operating modes of the FortiGate unit, NA T/Route and T ransp arent, and how to configure the FortiGate unit for e ach mode.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 16 01-30006-0451-200808 15 Connecting to the FortiGate unit Configuring Transparent mode In T ransparent m ode, the Fo rtiGate unit is invisible to the network . Similar to a network bridge, all FortiGate interfaces must be on the same subnet.
Configuring Connecting to the FortiGate unit FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 17 T o support a secure HTTPS authentication method, the For tiGate unit ships with a self-signed security certific ate, which is offered to remote clients whenever they initiate a HTTPS connecti on to the FortiGate unit.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 18 01-30006-0451-200808 15 Configuring NA T mode Configuring Configuring NA T mode Configuring NA T mode involves defining interface addresses and defa ult routes, and simple firewall policies. Y ou can use the web-based m anager or the CLI to configure the FortiGate unit in NA T/Route mode.
Configuring Configuring NA T mode FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 19 4 Select OK. 5 Repeat this procedure for each interf ace as required. Configure a DNS server A DNS server is a service that conver ts symbolic node names to IP addresses.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 20 01-30006-0451-200808 15 Configuring NA T mode Configuring For an initial configuration, you must edit the factor y configured static d efault route to specify a different defau lt gateway for the FortiGat e unit.
Configuring Configuring NA T mode FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 21 3 Set the following and select OK. Firewall policy configurati on is the same in NA T/Route mode and T ransp arent mode. Note that these policies allo w all traffic throug h.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 22 01-30006-0451-200808 15 Configuring NA T mode Configuring T o set an interface to use PPPo E addressing config system interface edit external set mode p.
Configuring Configuring NA T mode FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 23 In the factory default configuration, entr y number 1 in the S tatic Route list is associated with a destination address of 0.0.0.0/0.0.0.0, which means any/all destinations.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 24 01-30006-0451-200808 15 Configuring T ransparent mod e Configuring Configuring T ra nsp arent mode Configuring T ransparent mode in volves switchin g to T ransparent mode, configurin g the management IP ad dress, default routes, and simple firewa ll policies.
Configuring Configuring T r ansparent mode FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 25 For the initial installation, a single firewa ll policy that enables all traffic through will enable you to verify your configur ation is working.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 26 01-30006-0451-200808 15 Configuring T ransparent mod e Configuring T o switch to T ransparent mode config system settings set opmode transparent set man.
Configuring V erify the conf iguration FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 27 Note that these policies allo w all traffic throug h. No protection profiles have been applied. Ensure you create additio nal firewall policies to accommodate you r network requirement s.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 28 01-30006-0451-200808 15 Restoring a configuration Configuring Restoring a configuration Should you need to restore the config uration file, use the following steps. T o restore the FortiGat e configuration 1 Go to System > Maintenance > Backup & Restore .
Configuring Addition al configurat ion FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 29 T o change the administrator p assword 1 Go to System > Admin > Administrators . 2 Select Change Password and enter a new p assword. 3 Select OK.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 30 01-30006-0451-200808 15 Additional confi guration Configuring.
Advanced configuration Protection profiles FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 31 Advanced configuration The FortiGate unit and the FortiOS o perating system provide a wide range of features that enable you to control netwo rk and internet traffic and pr otect your network.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 32 01-30006-0451-200808 15 Firewall p olicies Advanced configuration The best way to begin creating your own protection pr ofile is to open a predefined profile. This way you can see how a profile is set up, an d then modify it suit your requirement s.
Advanced configuration Antivirus options FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 33 Configuring firewall policies T o add or edit a firewall policy go to Firewall > Policy and select Edit on an existing policy , or select Create New to add a policy .
FortiGate-224B FortiOS 3.0 MR6 Install Guide 34 01-30006-0451-200808 15 AntiSpam options Advanced configuration • Graywar e - These are unsolicited commercial software programs that are installed on computer s, often without the user's consent or knowledge.
Advanced configuration Web fi ltering FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 35 Banned word lists are specific wor ds that may be typically found in email. The FortiGate u nit searches f or words or patter ns in email me ssages.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 36 01-30006-0451-200808 15 Logging Advanced configuration T o configure content blocking, go to W eb Filter > Content Block . URL filter enables you to control additional web sites that you can block or allow .
FortiGate Firmware Downloading firmware FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 37 FortiGate Firmware Fortinet periodically updates the For tiGat e firmware to include new featur es and address issues.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 38 01-30006-0451-200808 15 Using the web-based manage r FortiGate Firmware T o download firmware 1 Log into the site using your user n ame and password. 2 Go to Firmware Images > FortiGate . 3 Select the most recent FortiOS version, and MR release and p atch release.
FortiGate Firmware Using the web-based manager FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 39 T o revert to a previous firmwar e version 1 Copy the firmware image file to the managem ent computer . 2 Log into the FortiGate web- based manager .
FortiGate-224B FortiOS 3.0 MR6 Install Guide 40 01-30006-0451-200808 15 Using the CLI FortiGate Firmware T o configure the USB Au to-Inst all 1 Go to System > Maintenance > Backup and Restore . 2 Select the blue arrow to expa nd the Advanced options.
FortiGate Firmware Using the CLI FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 41 5 Enter the fo llowing command to copy the firmwar e image from the TFTP se rver to the FortiG.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 42 01-30006-0451-200808 15 Installing firmware from a system reboot using the CLI FortiGate Firmware 4 Make sure the FortiGate unit can connect to th e TFTP server . Y ou can use the following comm and to pin g the comput er running th e TFTP server .
FortiGate Firmware Installing firmware from a system reboot using the CLI FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 43 If you are revert ing to a previou s FortiOS version, you might not be able to restore the previous configuration from the backup configuration file .
FortiGate-224B FortiOS 3.0 MR6 Install Guide 44 01-30006-0451-200808 15 Installing firmware from a system reboot using the CLI FortiGate Firmware 9 T ype the address of the TFTP server and press Enter : The following message appears: Enter Local Address [192.
FortiGate Firmware Installing firmware from a system reboot using the CLI FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 45 T o restore configuration us ing the CLI 1 Log into the CLI.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 46 01-30006-0451-200808 15 T esting new firmware before installing FortiGate Firmware T esting new firmware before inst alling Y ou can test a new fi rmware image by installing the firmware image from a system reboot and saving it to system memory .
FortiGate Firmware T esting new firmware before installing FortiGate-224B Forti OS 3.0 MR6 Install Guide 01-30006-0451-20080 815 47 8 T ype G to get t he new firm ware image from the TF TP server . The following m essage appears: Enter TFTP server address [192.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 48 01-30006-0451-200808 15 T esting new firmware before installing FortiGate Firmware.
Index FortiGate-224B FortiOS 3.0 MR6 Install Guide 01-30006-0451-2008081 5 49 Index A adding a defa ult route 19, 22 additional resources 9 admin password 28 air flow 11 ambient te mperature 11 antisp.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 50 01-30006-0451-200808 15 Index P PADT timeout 19 password, changing 28 power off 14 PPPoE 22 protection profiles 31 R registering 7 restore 28 restoring .
FortiGate-224B FortiOS 3.0 MR6 Install Guide 51 01-30006-0451-200808 15 Index.
FortiGate-224B FortiOS 3.0 MR6 Install Guide 52 01-30006-0451-200808 15 Index.
www.fortinet.com.
www.fortinet.com.
デバイスFortinet FortiGate 224Bの購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Fortinet FortiGate 224Bをまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはFortinet FortiGate 224Bの技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Fortinet FortiGate 224Bの取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Fortinet FortiGate 224Bで得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Fortinet FortiGate 224Bを既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はFortinet FortiGate 224Bの不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Fortinet FortiGate 224Bに関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちFortinet FortiGate 224Bデバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。