Page 2 - Trademarks
FortiWiFi-60A/AM Install Guide FortiOS 3.0 MR415 February 200701-30004-0283-20070215 © Copyright 2006 Fortinet, Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electro...
Page 3 - Contents
Contents FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 3 Contents Contents.............................................................................................. 3 Introduction ........................................................................................ 7 Ab...
Page 7 - Introduction; About the FortiWiFi unit
Introduction About the FortiWiFi unit FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 7 Introduction Welcome and thank you for selecting Fortinet products for your real-time network protection. The FortiGate™ Unified Threat Management System improves network security, reduces ne...
Page 8 - Register your FortiWiFi unit; Fortinet Family Products; FortiGuard Subscription Services; FortiClient
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 8 01-30004-0283-20070215 Fortinet Family Products Introduction Register your FortiWiFi unit Register your FortiWiFi unit by visiting http://support.fortinet.com and select Product Registration. To register, enter your contact information and the serial ...
Page 9 - FortiMail
Introduction Fortinet Family Products FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 9 FortiMail FortiMail™ Secure Messaging Platform provides powerful, flexible heuristic scanning and reporting capabilities to incoming and outgoing email traffic. The FortiMail unit has reliabl...
Page 10 - About this document; Document conventions
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 10 01-30004-0283-20070215 About this document Introduction About this document This document explains how to install and configure your FortiWiFi unit onto your network. This document also includes how to install and upgrade new firmware versions on you...
Page 11 - Typographic conventions
Introduction About this document FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 11 Typographic conventions FortiWiFi documentation uses the following typographical conventions: Convention Example Keyboard input In the Gateway Name field, type a name for the remote VPN peer or c...
Page 12 - Fortinet documentation
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 12 01-30004-0283-20070215 Fortinet documentation Introduction Fortinet documentation The most up-to-date publications and previous releases of Fortinet product documentation are available from the Fortinet Technical Documentation web site at http://docs...
Page 13 - Fortinet Knowledge Center; Customer service and technical support
Introduction Customer service and technical support FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 13 • FortiGate Certificate Management User Guide Contains procedures for managing digital certificates including generating certificate requests, installing signed certificates, i...
Page 15 - Installing the FortiWiFi unit; Package Contents
Installing the FortiWiFi unit Package Contents FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 15 Installing the FortiWiFi unit This section provides information on installing and setting up the FortiWiFi unit on your network. This section includes the following topics: • Packag...
Page 16 - Mounting; Powering on the FortiWiFi unit; To power on the FortiWiFi unit
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 16 01-30004-0283-20070215 Powering on the FortiWiFi unit Installing the FortiWiFi unit Figure 1: FortiWiFi-60A/AM package contents Table 1: Technical Specifications Mounting Install the FortiWiFi unit on any stable, flat surface. Make sure the unit has ...
Page 17 - Powering off the FortiWiFi unit; To power off the FortiWiFi unit; Connecting to the FortiWiFi unit; Command line interface
Installing the FortiWiFi unit Connecting to the FortiWiFi unit FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 17 Table 2: LED indicators Powering off the FortiWiFi unit Always shut down the FortiWiFi operating system properly before turning off the power switch to avoid potenti...
Page 18 - Connecting to the web-based manager; To connect to the web-based manager
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 18 01-30004-0283-20070215 Connecting to the FortiWiFi unit Installing the FortiWiFi unit Connecting to the web-based manager Use the following procedure to connect to the web-based manager for the first time. Configuration changes made with the web-base...
Page 19 - System Dashboard; Connecting to the CLI
Installing the FortiWiFi unit Connecting to the FortiWiFi unit FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 19 Figure 2: FortiWiFi login 4 Type admin in the Name field and select Login. System Dashboard After logging into the web-based manager, the web browser displays the sy...
Page 20 - To connect to the CLI; Quick installation using factory defaults
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 20 01-30004-0283-20070215 Quick installation using factory defaults Installing the FortiWiFi unit To connect to the CLI 1 Connect the RJ-45 to DB-9 serial cable/console port. 2 Start HyperTerminal, enter a name for the connection and select OK. 3 Config...
Page 23 - Factory defaults
Factory defaults FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 23 Factory defaults The FortiWiFi unit ships with a factory default configuration. The default configuration allows you to connect to and use the FortiWiFi web-based manager to configure the FortiWiFi unit onto the...
Page 24 - Factory default DHCP server configuration; Factory default NAT/Route mode network configuration
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 24 01-30004-0283-20070215 Factory default DHCP server configuration Factory defaults Factory default DHCP server configuration Using the factory default DHCP server settings, you can quickly configure the internal network and the FortiWiFi unit. See “Qu...
Page 25 - Factory default Transparent mode network configuration; Factory default firewall configuration; WLAN
Factory defaults Factory default Transparent mode network configuration FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 25 Factory default Transparent mode network configuration In Transparent mode, the FortiWiFi unit has the default network configuration listed in Table 5 . Fac...
Page 26 - Factory default protection profiles
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 26 01-30004-0283-20070215 Factory default firewall configuration Factory defaults Table 6: Factory default firewall configuration The factory default firewall configuration is the same in NAT/Route and Transparent mode. Factory default protection profil...
Page 27 - Restoring the default settings; Restoring the default settings using the web-based manager; To reset the default settings; Restoring the default settings using the CLI; To reset the default settings enter the following command:
Factory defaults Restoring the default settings FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 27 Restoring the default settings You can revert to the factory default settings if you change a network setting and are unable to recover from it. Restoring the default settings usin...
Page 29 - Configuring the FortiWiFi; Planning the FortiWiFi configuration
Configuring the FortiWiFi Planning the FortiWiFi configuration FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 29 Configuring the FortiWiFi This section provides an overview of the operating modes of the FortiWiFi unit. Before beginning to configure the FortiWiFi unit, you need ...
Page 30 - NAT/Route mode with multiple external network connections
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 30 01-30004-0283-20070215 Planning the FortiWiFi configuration Configuring the FortiWiFi You typically use NAT/Route mode when the FortiWiFi unit is operating as a gateway between private and public networks. In this configuration, you would create NAT ...
Page 31 - Transparent mode
Configuring the FortiWiFi Planning the FortiWiFi configuration FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 31 Figure 5: Example NAT/Route multiple internet connection Transparent mode In Transparent mode, the FortiWiFi unit is invisible to the network. Similar to a network b...
Page 32 - NAT/Route mode installation; Preparing to configure the FortiWiFi unit in NAT/Route mode
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 32 01-30004-0283-20070215 NAT/Route mode installation Configuring the FortiWiFi Figure 6: Example Transparent mode network configuration. NAT/Route mode installation This section describes how to install the FortiWiFi unit in NAT/Route mode. This sectio...
Page 33 - DHCP or PPPoE configuration; Using the web-based manager
Configuring the FortiWiFi NAT/Route mode installation FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 33 Table 9: NAT/Route mode settings DHCP or PPPoE configuration You can configure any FortiWiFi interface to acquire its IP address from a DHCP or PPPoE server. Your Internet Se...
Page 34 - Configuring basic settings; To add/change the administrator password; To configure DNS server settings
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 34 01-30004-0283-20070215 NAT/Route mode installation Configuring the FortiWiFi Configuring basic settings After connecting to the web-based manager, you can use the following procedures to complete the basic configuration of the FortiWiFi unit. To add/...
Page 35 - Adding a default route; To add a default route; Verifying the web-based manager configuration; Configuring the FortiWiFi unit to operate in NAT/Route mode
Configuring the FortiWiFi NAT/Route mode installation FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 35 Adding a default route Add a default route to configure where the FortiWiFi unit sends traffic destined for an external network (usually the Internet). Adding the default rou...
Page 36 - To configure interfaces
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 36 01-30004-0283-20070215 NAT/Route mode installation Configuring the FortiWiFi To add/change the administrator password 1 Log in to the CLI. 2 Change the admin administrator password. Enter: config system admin edit admin set password <psswrd> en...
Page 37 - To set the WAN1 interface to use PPPoE, enter:; Example
Configuring the FortiWiFi NAT/Route mode installation FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 37 To set the WAN1 interface to use PPPoE, enter: config system interface edit WAN1 set mode pppoeset connection enableset username <name_str>set password <psswrd> e...
Page 38 - Verify the connection; Connecting the FortiWiFi unit to the network(s); To connect the FortiWiFi unit
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 38 01-30004-0283-20070215 NAT/Route mode installation Configuring the FortiWiFi Example If the default gateway IP is 204.23.1.2 and this gateway is connected to WAN1: config router static edit 1set dst 0.0.0.0 0.0.0.0set gateway 204.23.1.2set device wan...
Page 39 - Configuring the networks
Configuring the FortiWiFi NAT/Route mode installation FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 39 Figure 7: NAT/Route mode connections Configuring the networks If you are running the FortiWiFi unit in NAT/Route mode, your networks must be configured to route all Internet ...
Page 40 - Transparent mode installation; Preparing to configure Transparent mode; To switch to Transparent mode using the web-based manager
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 40 01-30004-0283-20070215 Transparent mode installation Configuring the FortiWiFi Transparent mode installation This section describes how to install the FortiWiFi unit in Transparent mode. This section includes the following topics: • Preparing to conf...
Page 41 - Using the Command line interface; To change to Transparent mode using the CLI
Configuring the FortiWiFi Transparent mode installation FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 41 You do not have to reconnect to the web-based manager at this time. Once you select Apply, the changes are immediate, and you can go to the system dashboard to verify the F...
Page 42 - Reconnecting to the web-based manager; To connect the FortiWiFi unit running in Transparent mode:
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 42 01-30004-0283-20070215 Transparent mode installation Configuring the FortiWiFi The above CLI command should give you the following DNS server setting information: config system dns set primary 293.44.75.21set secondary 293.44.75.22set fwdintf interna...
Page 43 - Next steps; Set the date and time; To set the date and time
Configuring the FortiWiFi Next steps FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 43 If you cannot browse to the web site or retrieve/send email from your account, review the previous steps to ensure all information was entered correctly and try again. Figure 8: Transparent m...
Page 44 - To use NTP to set the FortiWiFi date and time; System Information > System Time; Updating antivirus and IPS signatures
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 44 01-30004-0283-20070215 Next steps Configuring the FortiWiFi 7 Set the hour, minute, second, month, day, and year as required. 8 Select OK. To use NTP to set the FortiWiFi date and time 1 Go to System > Status . 2 Under System Information > Syst...
Page 45 - To update antivirus definitions and IPS signatures; Updating the IPS signatures from the CLI; To update IPS signatures using the CLI; Scheduling antivirus and IPS updates; To enable schedule updates from the web-based manager
Configuring the FortiWiFi Next steps FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 45 To update antivirus definitions and IPS signatures 1 Go to System > Maintenance > FortiGuard Center . 2 Select the blue arrow for AntiVirus and IPS Downloads to expand the options. 3 Se...
Page 46 - To enable schedule updates from the CLI; Adding an override server; To add an override server from the web-based manager
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 46 01-30004-0283-20070215 Next steps Configuring the FortiWiFi 5 Select Apply. The FortiWiFi unit starts the next scheduled update according to the new update schedule. Whenever the FortiWiFi unit runs a scheduled update, the event is recorded in the Fo...
Page 47 - To add an override server using the CLI
Configuring the FortiWiFi Next steps FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 47 To add an override server using the CLI 1 Log into the CLI. 2 Enter the following command: config system autoupdate override set addressset status end
Page 49 - Configuring the modem interface
Configuring the modem interface FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 49 Configuring the modem interface This section describes how to configure the FortiWiFi-60AM internal modem using the web-based manager and the FortiWiFi-60A with an external modem using the Command...
Page 50 - Selecting a modem mode; Redundant mode configuration; To configure a redundant modem connection for the FortiWiFi-60AM; To configure the FortiWiFi-60A using the CLI; Stand alone mode configuration
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 50 01-30004-0283-20070215 Selecting a modem mode Configuring the modem interface Selecting a modem mode The modem interface can work in one of two modes: • redundant mode• stand alone mode Redundant mode configuration The redundant modem interface serve...
Page 51 - To operate in stand alone mode for the FortiWiFi-60AM; To operate in stand alone mode for the FortiWiFi-60A on the CLI
Configuring the modem interface Selecting a modem mode FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 51 If the connection to the dial-up account fails, the FortiWiFi unit modem automatically redials the number. The modem redials the ISP number based on the amount of times spec...
Page 52 - Configuring modem settings
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 52 01-30004-0283-20070215 Configuring modem settings Configuring the modem interface Configuring modem settings Configure modem settings so that the FortiWiFi unit uses the modem to connect to your ISP dial-up accounts. You can configure the modem to co...
Page 53 - To configure modem settings; Connecting and disconnecting the modem in Stand alone mode; To connect to a dial-up account
Configuring the modem interface Connecting and disconnecting the modem in Stand alone mode FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 53 You can configure and use the modem in NAT/Route mode only. To configure modem settings 1 Go to System > Network > Modem . 2 Select...
Page 54 - Configuring the modem using the CLI
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 54 01-30004-0283-20070215 Configuring the modem using the CLI Configuring the modem interface Configuring the modem using the CLI Configure the modem settings for the FortiWiFi-60A/AM through the CLI. The following table of CLI commands are specifically...
Page 56 - Adding a Ping Server; To add a ping server to an interface; Dead gateway detection; To modify the dead gateway detection settings; Adding firewall policies for modem connections
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 56 01-30004-0283-20070215 Adding a Ping Server Configuring the modem interface Adding a Ping Server Adding a ping server is required for routing failover for the modem in redundant mode. A ping server confirms the connectivity to an Ethernet interface. ...
Page 57 - Using a wireless network; Setting up a wireless network
Using a wireless network Setting up a wireless network FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 57 Using a wireless network In a wired network, computers are connected through a series of cables that transfer information. In a wireless network, information is transferred ...
Page 58 - Positioning an Access Point
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 58 01-30004-0283-20070215 Setting up a wireless network Using a wireless network Positioning an Access Point When placing the FortiWiFi AP, your main concern is providing a strong signal to all users. A strong signal ensures a fast connection and the ef...
Page 59 - Wireless Security; Elevator
Using a wireless network Wireless Security FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 59 Figure 11: Using multiple APs to provide a constant strong signal. This sample office has washrooms, a stairwell and an elevator shaft in the center of the building, making it impossibl...
Page 60 - Additional security measures
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 60 01-30004-0283-20070215 Wireless Security Using a wireless network There has been criticism of WEP security. WEP keys are static. They must be changed manually and frequently on both the wireless device and the APs. On a small company or network with ...
Page 61 - Service Set Identifier; To disable SSID; FortiWiFi operation modes; Access Point mode
Using a wireless network FortiWiFi operation modes FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 61 Service Set Identifier The Service Set Identifier (SSID) is the network name shared by all users on a wireless network. Wireless users should configure their computers to connec...
Page 62 - Client mode; Changing the operating mode; To change the wireless operating mode; Setting up the FortiWiFi unit as an Access Point
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 62 01-30004-0283-20070215 Setting up the FortiWiFi unit as an Access Point Using a wireless network Client mode When using the FortiWiFi unit in Client mode, the device is set to receive transmissions from another access point. This enables you to conne...
Page 63 - Set the DHCP settings; To configure the FortiWiFi unit to be a DHCP server; Set the security options; To set the data security
Using a wireless network Setting up the FortiWiFi unit as an Access Point FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 63 This section contains the following steps: • Set the DHCP settings • Set the security options • Configure the firewall policies Set the DHCP settings Conf...
Page 64 - Configure the firewall policies; To create a new wall policy for a secure Internet connection
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 64 01-30004-0283-20070215 Setting up the FortiWiFi unit as an Access Point Using a wireless network 9 Enter the MAC addresses and select to Allow or Deny them from the wireless network. Configure the firewall policies The FortiWiFi unit provides WAN int...
Page 65 - FortiWiFi Firmware; Upgrading to a new firmware version; Upgrading the firmware using the web-based manager; To upgrade the firmware using the web-based manager; System Information > Firmware Version
FortiWiFi Firmware Upgrading to a new firmware version FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 65 FortiWiFi Firmware Fortinet periodically updates the FortiWiFi firmware to include enhancements and address issues. After you have registered your FortiWiFi unit, FortiWiFi ...
Page 66 - Upgrading the firmware using the CLI; To upgrade the firmware using the CLI
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 66 01-30004-0283-20070215 Upgrading to a new firmware version FortiWiFi Firmware 6 Select OK. The FortiWiFi unit uploads the firmware image file, upgrades to the new firmware version, restarts, and displays the FortiWiFi login. This process takes a few ...
Page 67 - Reverting to a previous firmware version
FortiWiFi Firmware Reverting to a previous firmware version FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 67 8 To confirm the new firmware image is successfully installed, enter: get system status 9 Update antivirus and attack definitions (see the FortiGate Administration Guid...
Page 68 - Reverting to a previous firmware version using the CLI; To revert to a previous firmware version using the CLI
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 68 01-30004-0283-20070215 Reverting to a previous firmware version FortiWiFi Firmware 6 Select OK. The FortiWiFi unit uploads the firmware image file, reverts to the old firmware version, resets the configuration, restarts, and displays the FortiWiFi lo...
Page 70 - Installing firmware images from a system reboot using the CLI; To install firmware from a system reboot
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 70 01-30004-0283-20070215 Installing firmware images from a system reboot using the CLI FortiWiFi Firmware Installing firmware images from a system reboot using the CLI This procedure installs a specified firmware image and resets the FortiWiFi unit to ...
Page 72 - Restoring the previous configuration; The FortiUSB key
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 72 01-30004-0283-20070215 The FortiUSB key FortiWiFi Firmware 11 Enter the firmware image filename and press Enter. The TFTP server uploads the firmware image file to the FortiWiFi unit and messages similar to the following are displayed:• FortiWiFi uni...
Page 73 - Backup and Restore from the FortiUSB key
FortiWiFi Firmware The FortiUSB key FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 73 Backup and Restore from the FortiUSB key You can use the FortiUSB key to either backup a configuration file or restore a configuration file. You should always make sure the FortiUSB key is pro...
Page 74 - Using the USB Auto-Install feature; To configure the USB Auto-Install using the web-based manager; System > Maintenance > Backup and Restore; To configure the USB Auto-Install using the CLI
FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide 74 01-30004-0283-20070215 The FortiUSB key FortiWiFi Firmware Using the USB Auto-Install feature The USB Auto-Install feature automatically updates the FortiWiFi configuration file and image file on a system reboot. Also, this feature provides you with ...
Page 75 - Additional CLI Commands for the FortiUSB key; Testing a new firmware image before installing it; To test a new firmware image
FortiWiFi Firmware Testing a new firmware image before installing it FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 75 Additional CLI Commands for the FortiUSB key Use the following CLI commands when you want to delete a file from the FortiUSB key, list what files are on the ke...
Page 79 - Index; Numerics
Index FortiWiFi-60A/AM FortiOS 3.0 MR4 Install Guide01-30004-0283-20070215 79 Index Numerics 802.11 standard 58 A access point 57adding a default route 35, 37auto-dial 52 C certificate, security 18CLI additional commands for FortiUSB key 75 configuring NAT/Route mode 35 connecting 19 upgrading the f...