Page 2 - Trademarks
© Copyright 2005 Fortinet Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced,transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical orotherwise, for any purpose, without prior written pe...
Page 3 - Table of Contents
Contents FortiGate-60 Installation Guide 01-28008-0018-20050128 3 Table of Contents Introduction ............................................................................................................ 5 Secure installation, configuration, and management ............................................
Page 5 - FortiGate-60 Installation Guide Version 2.80 MR8; Introduction; Secure installation, configuration, and management
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 5 Introduction FortiGate Antivirus Firewalls improve network security, reduce network misuse and abuse, and help you use communications resources more efficiently without compromising the performa...
Page 6 - Command line interface
6 01-28008-0018-20050128 Fortinet Inc. Secure installation, configuration, and management Introduction The CLI or the web-based manager can then be used to complete configuration and to perform maintenance and administration. Web-based manager Using HTTP or a secure HTTPS connection from any compute...
Page 7 - Setup wizard; Document conventions
Introduction Document conventions FortiGate-60 Installation Guide 01-28008-0018-20050128 7 Setup wizard The FortiGate setup wizard provides an easy way to configure the basic initial settings for the FortiGate unit. The wizard walks through the configuration of a new administrator password, FortiGat...
Page 8 - FortiGate documentation
8 01-28008-0018-20050128 Fortinet Inc. FortiGate documentation Introduction For example: set allowaccess {ping https ssh snmp http telnet} You can enter any of the following: set allowaccess ping set allowaccess ping https ssh set allowaccess https ping ssh set allowaccess snmp In most cases to make...
Page 9 - Fortinet Knowledge Center; Related documentation; FortiManager documentation; FortiClient documentation
Introduction Related documentation FortiGate-60 Installation Guide 01-28008-0018-20050128 9 • FortiGate IPS Guide Describes how to configure the FortiGate Intrusion Prevention System settings and how the FortiGate IPS deals with some common attacks. • FortiGate VPN Guide Explains how to configure VP...
Page 10 - FortiMail documentation; Customer service and technical support
10 01-28008-0018-20050128 Fortinet Inc. Customer service and technical support Introduction FortiMail documentation • FortiMail Administration Guide Describes how to install, configure, and manage a FortiMail unit in gateway mode and server mode, including how to configure the unit; create profiles ...
Page 13 - Getting started
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 13 Getting started This section describes unpacking, setting up, and powering on a FortiGate Antivirus Firewall unit. This section includes: • Package contents • Mounting • Turning the FortiGate u...
Page 14 - Package contents; Mounting; Dimensions
14 01-28008-0018-20050128 Fortinet Inc. Package contents Getting started Package contents The FortiGate-60 package contains the following items: • FortiGate-60 Antivirus Firewall• one orange crossover ethernet cable (Fortinet part number CC300248)• one gray regular ethernet cable (Fortinet part numb...
Page 15 - Power requirements; Turning the FortiGate unit power on and off; To power on the FortiGate unit; To power off the FortiGate unit
Getting started Turning the FortiGate unit power on and off FortiGate-60 Installation Guide 01-28008-0018-20050128 15 Power requirements • DC input voltage: 12 V• DC input current: 3 A Environmental specifications • Operating temperature: 32 to 104°F (0 to 40°C)• Storage temperature: -13 to 158°F (-...
Page 16 - Connecting to the web-based manager; To connect to the web-based manager
16 01-28008-0018-20050128 Fortinet Inc. Connecting to the web-based manager Getting started Connecting to the web-based manager Use the following procedure to connect to the web-based manager for the first time. Configuration changes made with the web-based manager are effective immediately without ...
Page 17 - Connecting to the command line interface (CLI); To connect to the CLI
Getting started Connecting to the command line interface (CLI) FortiGate-60 Installation Guide 01-28008-0018-20050128 17 Connecting to the command line interface (CLI) As an alternative to the web-based manager, you can install and configure the FortiGate unit using the CLI. Configuration changes ma...
Page 18 - Quick installation using factory defaults
18 01-28008-0018-20050128 Fortinet Inc. Quick installation using factory defaults Getting started Quick installation using factory defaults You can quickly set up your FortiGate unit for a home or small office using the web-based manager and the factory default FortiGate configuration. All you need ...
Page 19 - Factory default FortiGate configuration settings; Factory default DHCP server configuration
Getting started Factory default FortiGate configuration settings FortiGate-60 Installation Guide 01-28008-0018-20050128 19 7 Select one of the following DNS settings• Obtain DNS server address automatically: select to get the DNS addresses from the ISP, select Apply • Use the following DNS server ad...
Page 20 - Factory default NAT/Route mode network configuration
20 01-28008-0018-20050128 Fortinet Inc. Factory default FortiGate configuration settings Getting started Factory default NAT/Route mode network configuration When the FortiGate unit is first powered on, it is running in NAT/Route mode and has the basic network configuration listed in Table 3 on page...
Page 21 - Factory default Transparent mode network configuration; Factory default firewall configuration
Getting started Factory default FortiGate configuration settings FortiGate-60 Installation Guide 01-28008-0018-20050128 21 Factory default Transparent mode network configuration In Transparent mode, the FortiGate unit has the default network configuration listed in Table 4 . Factory default firewall...
Page 22 - Factory default protection profiles
22 01-28008-0018-20050128 Fortinet Inc. Factory default FortiGate configuration settings Getting started The factory default firewall configuration is the same in NAT/Route and Transparent mode. Factory default protection profiles Use protection profiles to apply different protection settings for tr...
Page 23 - Planning the FortiGate configuration
Getting started Planning the FortiGate configuration FortiGate-60 Installation Guide 01-28008-0018-20050128 23 Figure 5: Web protection profile settings Planning the FortiGate configuration Before you configure the FortiGate unit, you need to plan how to integrate the unit into the network. Among ot...
Page 24 - NAT/Route mode with multiple external network connections
24 01-28008-0018-20050128 Fortinet Inc. Planning the FortiGate configuration Getting started You must configure routing to support the redundant WAN1 and WAN2 internet connections. Routing can be used to automatically redirect connections from an interface if its connection to the external network f...
Page 25 - Transparent mode
Getting started Planning the FortiGate configuration FortiGate-60 Installation Guide 01-28008-0018-20050128 25 Otherwise, security policy configuration is similar to a NAT/Route mode configuration with a single Internet connection. You would create NAT mode firewall policies to control traffic flowi...
Page 26 - Configuration options; CLI; Next steps
26 01-28008-0018-20050128 Fortinet Inc. Next steps Getting started Configuration options Once you have selected Transparent or NAT/Route mode operation, you can complete the configuration plan and begin to configure the FortiGate unit. Choose among three different tools to configure the FortiGate un...
Page 27 - NAT/Route mode installation; Preparing to configure the FortiGate unit in NAT/Route mode
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 27 NAT/Route mode installation This chapter describes how to install the FortiGate unit in NAT/Route mode. For information about installing a FortiGate unit in Transparent mode, see “Transparent m...
Page 28 - DHCP or PPPoE configuration; Using the web-based manager
28 01-28008-0018-20050128 Fortinet Inc. Using the web-based manager NAT/Route mode installation DHCP or PPPoE configuration You can configure any FortiGate interface to acquire its IP address from a DHCP or PPPoE server. Your ISP may provide IP addresses using one of these protocols. To use the Fort...
Page 29 - Configuring basic settings; To add/change the administrator password; To configure DNS server settings
NAT/Route mode installation Using the web-based manager FortiGate-60 Installation Guide 01-28008-0018-20050128 29 Configuring basic settings After connecting to the web-based manager you can use the following procedures to complete the basic configuration of the FortiGate unit. To add/change the adm...
Page 30 - Using the command line interface; Configuring the FortiGate unit to operate in NAT/Route mode
30 01-28008-0018-20050128 Fortinet Inc. Using the command line interface NAT/Route mode installation 1 Go to System > Router > Static . 2 If the Static Route table contains a default route (IP and Mask set to 0.0.0.0), select the Delete icon to delete this route. 3 Select Create New. 4 Set Des...
Page 31 - Example
NAT/Route mode installation Using the command line interface FortiGate-60 Installation Guide 01-28008-0018-20050128 31 Example config system interface edit internal set mode staticset ip <192.168.120.99> <255.255.255.0> end 3 Set the IP address and netmask of the WAN1 interface to the IP...
Page 32 - Using the setup wizard
32 01-28008-0018-20050128 Fortinet Inc. Using the setup wizard NAT/Route mode installation To configure DNS server settings • Set the primary and secondary DNS server IP addresses. Enter config system dns set primary <address_ip>set secondary <address_ip> end Example config system dns se...
Page 34 - Starting the setup wizard; Connecting the FortiGate unit to the network(s)
34 01-28008-0018-20050128 Fortinet Inc. Connecting the FortiGate unit to the network(s) NAT/Route mode installation Starting the setup wizard 1 In the web-based manager, select Easy Setup Wizard. Figure 9: Select the Easy Setup Wizard 2 Follow the instructions on the wizard pages and use the informa...
Page 36 - Configuring the networks
36 01-28008-0018-20050128 Fortinet Inc. Configuring the networks NAT/Route mode installation Configuring the networks If you are running the FortiGate unit in NAT/Route mode, your networks must be configured to route all Internet traffic to the IP address of the FortiGate interface to which they are...
Page 37 - To set the date and time; To use NTP to set the FortiGate date and time; To register the FortiGate unit
NAT/Route mode installation Next steps FortiGate-60 Installation Guide 01-28008-0018-20050128 37 To set the date and time For effective scheduling and logging, the FortiGate system date and time must be accurate. You can either manually set the system date and time or configure the FortiGate unit to...
Page 39 - Transparent mode installation; Preparing to configure Transparent mode
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 39 Transparent mode installation This chapter describes how to install a FortiGate unit in Transparent mode. If you want to install the FortiGate unit in NAT/Route mode, see “NAT/Route mode instal...
Page 40 - To switch to Transparent mode using the web-based manager
40 01-28008-0018-20050128 Fortinet Inc. Using the web-based manager Transparent mode installation Using the web-based manager You can use the web-based manager to complete the initial configuration of the FortiGate unit. You can continue to use the web-based manager for all FortiGate unit settings. ...
Page 41 - Reconnecting to the web-based manager; To change to Transparent mode using the CLI
Transparent mode installation Using the command line interface FortiGate-60 Installation Guide 01-28008-0018-20050128 41 To configure DNS server settings 1 Go to System > Network > DNS . 2 Enter the IP address of the primary DNS server. 3 Enter the IP address of the secondary DNS server. 4 Sel...
Page 42 - To configure the management IP address
42 01-28008-0018-20050128 Fortinet Inc. Using the command line interface Transparent mode installation The CLI displays the status of the FortiGate unit including the following line of text: Operation mode: Transparent To configure the management IP address 1 Make sure that you are logged into the C...
Page 44 - Connecting the FortiGate unit to your network
44 01-28008-0018-20050128 Fortinet Inc. Connecting the FortiGate unit to your network Transparent mode installation Connecting the FortiGate unit to your network When you have completed the initial configuration, you can connect the FortiGate unit between your internal network and the Internet using...
Page 47 - High availability installation; Priorities of heartbeat device and monitor priorities; Configuring FortiGate units for HA operation; High availability configuration settings
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 47 High availability installation This chapter describes how to install two or more FortiGate units in an HA cluster. HA installation involves three basic steps: • Configuring FortiGate units for ...
Page 49 - Configuring FortiGate units for HA using the web-based manager; To change the FortiGate unit host name
High availability installation Configuring FortiGate units for HA operation FortiGate-60 Installation Guide 01-28008-0018-20050128 49 Configuring FortiGate units for HA using the web-based manager Use the following procedure to configure each FortiGate unit for HA operation. To change the FortiGate ...
Page 50 - To configure a FortiGate unit for HA operation; Configuring FortiGate units for HA using the CLI
50 01-28008-0018-20050128 Fortinet Inc. Configuring FortiGate units for HA operation High availability installation To configure a FortiGate unit for HA operation 1 Go to System > Config > HA . 2 Select High Availability. 3 Select the mode. 4 Select a Group ID for the HA cluster. 5 If required...
Page 51 - To configure the FortiGate unit for HA operation; Connecting the cluster to your networks
High availability installation Connecting the cluster to your networks FortiGate-60 Installation Guide 01-28008-0018-20050128 51 To configure the FortiGate unit for HA operation 1 Configure HA settings.Use the following command to:• Set the HA mode• Set the Group ID• Change the unit priority• Enable...
Page 52 - To connect the cluster
52 01-28008-0018-20050128 Fortinet Inc. Connecting the cluster to your networks High availability installation Inserting an HA cluster into your network temporarily interrupts communications on the network because new physical connections are being made to route traffic through the cluster. Also, st...
Page 53 - Installing and configuring the cluster
High availability installation Installing and configuring the cluster FortiGate-60 Installation Guide 01-28008-0018-20050128 53 2 Power on all the FortiGate units in the cluster.As the units start, they negotiate to choose the primary cluster unit and the subordinate units. This negotiation occurs w...
Page 55 - Configuring the modem interface; Selecting a modem mode; Redundant mode configuration
FortiGate-60 Installation Guide Version 2.80 MR8 FortiGate-60 Installation Guide 01-28008-0018-20050128 55 Configuring the modem interface The FortiGate-60 includes the option of an external modem for use as either a redundant interface or a standalone interface in NAT/Route mode. • In redundant mod...
Page 56 - Standalone mode configuration; To operate in standalone mode
56 01-28008-0018-20050128 Fortinet Inc. Selecting a modem mode Configuring the modem interface For the FortiGate unit to switch from an ethernet interface to the modem you must select the name of the interface in the modem configuration and configure a ping server for that interface. You must also c...
Page 57 - Configuring modem settings
Configuring the modem interface Configuring modem settings FortiGate-60 Installation Guide 01-28008-0018-20050128 57 3 Configure other modem settings as required.See “Configuring modem settings” on page 57 . Make sure there is correct information in one or more Dialup Accounts. 4 Configure firewall ...
Page 58 - To configure modem settings; Connecting and disconnecting the modem in Standalone mode; To connect to a dialup account
58 01-28008-0018-20050128 Fortinet Inc. Connecting and disconnecting the modem in Standalone mode Configuring the modem interface You can configure and use the modem in NAT/Route mode only. To configure modem settings 1 Go to System > Network > Modem . 2 Select Enable Modem. 3 Change any of th...
Page 59 - To disconnect the modem; Defining a Ping Server; To add a ping server to an interface; Dead gateway detection; To modify the dead gateway detection settings
Configuring the modem interface Defining a Ping Server FortiGate-60 Installation Guide 01-28008-0018-20050128 59 5 Select Dial Now.The FortiGate unit initiates dialing into each dialup account in turn until the modem connects to an ISP.Modem status is one of the following: A green check mark indicat...
Page 60 - Adding firewall policies for modem connections
60 01-28008-0018-20050128 Fortinet Inc. Adding firewall policies for modem connections Configuring the modem interface 3 For Fail-over Detection, type a number of times that the connection test fails before the FortiGate unit assumes that the gateway is no longer functioning. 4 Select Apply. Adding ...
Page 61 - Index
FortiGate-60 Installation Guide 01-28008-0018-20050128 61 FortiGate-60 Installation Guide Version 2.80 MR8 Index A auto-dial 57 C CLI 6 configuring IP addresses 41configuring NAT/Route mode 30connecting to 17 cluster connecting 51, 53 command line interface 6configuring redundant mode 55configuring ...