Gebruiksaanwijzing /service van het product Version 3.0 van de fabrikant Fortinet
Ga naar pagina of 88
www.fortinet.com FortiB ri dge V ersion 3.0 Administration Guide.
FortiBridge Administration Guide V ersion 3.0 9 November 200 6 09-30000-01 63-20061 109 © Copyright 2006 Fortine t, Inc. All rights reserved. No part of this publication including te xt, examp les, d.
Contents FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 3 Contents Introduction ............... ................................. .............................. .......... 7 About FortiBridge ....................... ............
FortiBridge Version 3.0 Administration Guide 4 09-30000-0163-20061 109 Contents Completing the basic FortiBridge confi guration ................ ................ .......... 26 Adding an administrator password .......... ................ ..............
Contents FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 5 system console ..................... ................ ................... ................ .................... .... 61 system dns ............ ................ .........
FortiBridge Version 3.0 Administration Guide 6 09-30000-0163-20061 109 Contents.
Introduction About FortiBridge FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 7 Introduction This chapter introduces yo u to the FortiBridge-1000 an d FortiBridge-1000F products that pr ovide fail open protection for FortiGat e Antivirus Fir ewalls operating in transp ar ent mode.
FortiBridge Version 3.0 Administration Guide 8 09-30000-0163-20061 109 Fortinet documentation Introduction • Using th e CLI describes how to use the FortiBridge CLI. • config CLI commands is the FortiBridge config CLI command r eference. • execute CLI commands is the FortiBridge execute CLI command reference.
FortiBridge operating principles Example FortiBridge ap plica tion FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 9 FortiBridge operating principles This chapter descri bes a typical transp arent mode FortiGate network and how to add a FortiBridge unit to this network to provide fail open protection.
FortiBridge Version 3.0 Administration Guide 10 09-30000-0163-20061 109 Example FortiBridge applicati on FortiBridge operating principle s The FortiGate unit acts as an extra layer of protec tion for your in ternal netw ork. While it is operating, the FortiGate un it protects the interna l network from threats originating on the Intern et.
FortiBridge operating princip les Normal mode operation FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 11 1 Connect the FortiBridge-100 0 INT 2 interface to the FortiGate intern al inter face. 2 Connect the FortiGate external interface to the Fort iBridge-1000 EXT 2 interface.
FortiBridge Version 3.0 Administration Guide 12 09-30000-0163-20061 109 Normal mode operation FortiBridge operating principle s Figure 5: FortiBridge unit operating i n normal mode sendin g probe p ac.
FortiBridge operating princip les Normal mode operation FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 13 Enabling probes to detect For tiGate hardware failure A FortiGate unit .
FortiBridge Version 3.0 Administration Guide 14 09-30000-0163-20061 109 Bypass mode operation FortiBridge operating principle s Byp ass mode operation When the FortiBri dge unit operates in bypass mode, the FortiBridge INT 1 and EXT 1 interfaces are directly connected.
FortiBridge operating princip les Example Fo rtiGate HA clu ster FortiBridge ap plication FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 15 Example FortiGate HA cluster FortiBri.
FortiBridge Version 3.0 Administration Guide 16 09-30000-0163-20061 109 Example conf i gu ra tion with other Fo rti G ate interfaces FortiBridge operating principle s 1 Connect the For tiBr idg e- 1 00 0 INT 2 inte rf ac e to th e switc h co nn ec te d to the HA cluster internal interface.
FortiBridge operating princip l es Example configuration wit h other FortiG ate interfaces FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 17 3 Connect the internal network to the FortiBridg e-1000 INT 1 interface. 4 Connect the FortiBridge-1000 EXT 1 inter fa ce to the router .
FortiBridge Version 3.0 Administration Guide 18 09-30000-0163-20061 109 Example conf i gu ra tion with other Fo rti G ate interfaces FortiBridge operating principle s.
Setting up FortiBridge units FortiBridge unit ba si c information FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 19 Setting up FortiBridge unit s This chapter cont ains the info .
FortiBridge Version 3.0 Administration Guide 20 09-30000-0163-20061 109 FortiBridge unit basic info rmation Setting up FortiBridge units Figure 9: FortiBridge- 1000 package contents FortiBridge-1000F .
Setting up FortiBridge units FortiBridge unit ba si c information FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 21 Technical specifications LED indicators T able 2: Fo rtiB ridge-1000 and 1000F tech nical sp ecifications Dimensions 8.
FortiBridge Version 3.0 Administration Guide 22 09-30000-0163-20061 109 FortiBridge unit basic info rmation Setting up FortiBridge units Connectors Factory default configuration T able 5: FortiBridge-.
Setting up FortiBridge units Connecting and turning on the FortiBridge uni t FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 23 Connecting and turning on the FortiBridge unit In most cases, you can connect the For tiBridge unit without making any configuration changes to your network or your FortiGate unit.
FortiBridge Version 3.0 Administration Guide 24 09-30000-0163-20061 109 Connecting and tu rning on the FortiBridge unit Setting up FortiBridge u nits T o connect and turn on the FortiBridge-1000 unit 1 Connect the FortiBridge-1000 INT 2 interface to the FortiGate unit internal interface.
Setting up FortiBridge units Connecting to the command line inte rface (CLI) FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 25 3 Connect the internal network to the FortiBridg e-1000F INT 1 interface. 4 Connect the FortiBridge-1000F EXT 1 inter face to the router .
FortiBridge Version 3.0 Administration Guide 26 09-30000-0163-20061 109 Completing the basic FortiBri dge configuration Setting up FortiBridge units 9 T ype the password for t his administra tor and pre ss Enter . The defa ult admin acco unt does n ot require a password.
Setting up FortiBridge units Completing the basic FortiBridge configu ration FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 27 • Adding an administrator p assword • Changing.
FortiBridge Version 3.0 Administration Guide 28 09-30000-0163-20061 109 Completing the basic FortiBri dge configuration Setting up FortiBridge units Changing DNS ser ver IP addresses Change the FortiBridge DNS server IP ad dresses to the IP addresses of your DNS servers.
Setting up FortiBridge units Completing the basic FortiBridge configu ration FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 29 Allowing management access to the EXT 1 interface By default no m anagement access is conf igu red for the EXT 1 interface.
FortiBridge Version 3.0 Administration Guide 30 09-30000-0163-20061 109 Resetting to the factory default conf iguration Setting up FortiBridge units config system admin edit <admin_name_str> set.
Setting up FortiBridge units Installing FortiBridge unit firmware FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 31 Upgrading to a new firmware version Y ou cannot use this procedure to re-inst all the current firmware or to revert to an older versio n of the firmw are.
FortiBridge Version 3.0 Administration Guide 32 09-30000-0163-20061 109 Installing FortiBridge unit firmware Setting up FortiBridge units Reverting to a previous firmware version This procedure revert s the FortiBridge unit to a previous firmware version and rests th e un it to its factory default co nfiguration.
Setting up FortiBridge units Installing FortiBridge unit firmware FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 33 Installing firmware from a system reboot This procedure inst alls a specified firmware image and re se t s the FortiBridge unit to default settings.
FortiBridge Version 3.0 Administration Guide 34 09-30000-0163-20061 109 Installing FortiBridge unit firmware Setting up FortiBridge units The following message appears: Enter firmware image file [image.out]: 10 T ype the firmware image file na m e an d pr es s Ente r .
Configuration and operating proc edu res Example network settings FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 35 Configuration and operating procedures This chapter describes ho w to configure a FortiBridge un it to provide fail open protection for a FortiGate unit operating in transp arent mode.
FortiBridge Version 3.0 Administration Guide 36 09-30000-0163-20061 109 Configuring FortiBridge probe s Confi guration and operating procedure s Figure 13: Example FortiBridge application Ta b l e 9 lists the internal network configuration . Ta b l e 1 0 lists the basic For tiBridge unit configuration settings.
Configuration and operating procedu res Configuring FortiBridge probes FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 37 This section describes: • Probe settings • Enabling .
FortiBridge Version 3.0 Administration Guide 38 09-30000-0163-20061 109 Configuring FortiBridge probe s Confi guration and operating procedure s 2 Configure probe settings. Enter: config probe setting set action_on_failure alertmail failopen snmp syslog set dynamic_ip_pattern 2.
Configuration and operating procedu res Configuring FortiBridge probes FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 39 3 Display ping probe settings, enter: get probe probe_list ping name : ping failure_threshold : 3 probe_interval : 1 status : enable 4 Enable the FTP prob e .
FortiBridge Version 3.0 Administration Guide 40 09-30000-0163-20061 109 Configuring FortiBridge alerts Conf igurati on and operating pr ocedures Figure 15: FortiGate Session li st showing Forti Bridge probe s This session list shows the following: • The FortiBridge dynamic prob e IP ad dresses are 2.
Configuration and operating procedu res Configuring FortiBridge al erts FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 41 FortiBridge alert email If you set the probe action on .
FortiBridge Version 3.0 Administration Guide 42 09-30000-0163-20061 109 Configuring FortiBridge alerts Conf igurati on and operating pr ocedures 02-01-2005 8:21:27 Local7.
Configuration and o perating procedures Recovering from a FortiGa te failure FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 43 T o add and enable an SNMP community 1 Log into the CLI. 2 Add the first SNMP community and name it snmp1 .
FortiBridge Version 3.0 Administration Guide 44 09-30000-0163-20061 109 Manually switching between F ortiBridge operatin g modes Configuration and operating procedures 2 Make the required changes to fix the pr oblem.
Configuration and o perating procedures Backing up and restoring the FortiBridg e co nfiguration FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 45 3 Restore the system configuration from a text file on the TFT P serv er .
FortiBridge Version 3.0 Administration Guide 46 09-30000-0163-20061 109 Backing up and restoring the FortiBridge conf i guration Configuration and operating procedures.
Using the CLI CLI basics FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 47 Using the CLI This chapter explains how to connect to the command line inter face (CLI) and contains some ba sic information about using the CLI. Y ou us e CLI comma nds to view all system information and to change all system configuration settings.
FortiBridge Version 3.0 Administration Guide 48 09-30000-0163-20061 109 Connecting to the FortiBridge CLI using SSH or T elnet Using the CLI For example, to configure the inter nal in terface to accep.
Using the CLI Connecting to the FortiBridge CLI using SSH or T elnet FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 49 T o connect to the CLI using SSH 1 Install and st art an SSH client. 2 Connect to a FortiBridge in terface that is configured for SSH connections.
FortiBridge Version 3.0 Administration Guide 50 09-30000-0163-20061 109 Connecting to the FortiBridge CLI using SSH or T elnet Using the CLI.
config CLI commands FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 51 config CLI commands alertemail setting log syslogd setting probe probe_list {ping | h ttp | ft p | pop3 | sm.
FortiBridge Version 3.0 Administration Guide 52 09-30000-0163-20061 109 alertemail setting config CLI commands alertemail setting Use this command to configure the FortiBridg e unit to send alert email to up to three recipient s when action on failure is set to send a alert email message.
config CLI commands alertemail setti ng FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 53 Related Commands • probe setting.
FortiBridge Version 3.0 Administration Guide 54 09-30000-0163-20061 109 log syslogd setting config CLI commands log syslogd setting Use this command to configure the FortiBridg e unit to send a syslog message to a remote syslog server when action on failure is set to send a syslog message.
config CLI commands probe probe_list {ping | http | ftp | pop3 | smtp | imap} FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 55 probe probe_list {ping | http | f tp | pop3 | smtp | imap} Use this command to configur e probes for ping, HTTP , FTP , POP3, SMTP , and IMAP traffic.
FortiBridge Version 3.0 Administration Guide 56 09-30000-0163-20061 109 probe setting config CLI commands probe setting Use this command to configure how the For tiBridge unit responds when a p robe determines that the FortiGate unit has failed.
config CLI commands system accprofile FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 57 system accprofile Use this command to add access pr ofiles that control ad ministra tor access to FortiBridge features. Each administra to r ac co un t mu st inc lud e an acc ess profile.
FortiBridge Version 3.0 Administration Guide 58 09-30000-0163-20061 109 system accprofile config CLI commands Example Use the following commands to add a new access profile named policy_profile that allows read and write access system shut down. An administrator account with this access profile can shut down the system and upgrade firm ware.
config CLI commands system admin FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 59 system admin Use this command to add, edit, and delete administrator account s. Use the admin account or an account with system configuration read and write privileges to add new administrato r accounts and co ntrol their per mission levels.
FortiBridge Version 3.0 Administration Guide 60 09-30000-0163-20061 109 system admin config CLI commands Example Use the following commands to add a new ad ministrator account named new_admin with the password set to p8ssw0rd and that includes an access profile named policy_profile .
config CLI commands system console FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 61 system console Use this command to set the cons o le command mode and outp ut setting.
FortiBridge Version 3.0 Administration Guide 62 09-30000-0163-20061 109 system dns config CLI commands system dns Use this command to set th e DNS ser ve r addr e sse s. Sev eral FortiBridge fu nct ion s, includ in g sen d ing email alerts and URL blocking, use DNS.
config CLI commands get system status FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 63 get system st atus Use this command to display syste m status information.
FortiBridge Version 3.0 Administration Guide 64 09-30000-0163-20061 109 system fail_close config CLI commands system fail_close Use this com mand to con figure the fail close feature.
config CLI commands system fail_close FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 65 Example This example shows how to enable the Fort iBridge fail_ close feature, and set the threshold time to five seconds.
FortiBridge Version 3.0 Administration Guide 66 09-30000-0163-20061 109 system global config CLI commands system global Use this command to configure global se ttings that affect various FortiBridge systems and configurat ions.
config CLI commands system global FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 67 Example This examp le shows how to set the Fort iBridge system t imezone, ad d the IP addr ess of an NTP server , and enable synchronization with the NTP server .
FortiBridge Version 3.0 Administration Guide 68 09-30000-0163-20061 109 system interface {internal | external} config CLI commands system interface {internal | external} Use this command to configure managemen t access to the FortiBridge internal or external interface.
config CLI commands system manageip FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 69 system manageip Configure the FortiBridge management IP addr es s. Use the ma nagement IP address fo r management access to the FortiBridge unit.
FortiBridge Version 3.0 Administration Guide 70 09-30000-0163-20061 109 system route config CLI commands system route Use this command to add or edit FortiBridge static routes.
config CLI commands system snmp community FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 71 system snmp community Use this command to configur e SNMP communities. Add SNMP communities so that the FortiBridge unit can send SNMP v1 and v2c trap s to SNMP manage rs when action on failur e is set to send SNMP traps.
FortiBridge Version 3.0 Administration Guide 72 09-30000-0163-20061 109 system snmp community config CLI commands Command syntax pattern config hosts edit <id_integer> set <keyword> <va.
execute CLI commands FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 73 execute CLI commands backup date factoryr eset ping reboot restore switch-mode time.
FortiBridge Version 3.0 Administration Guide 74 09-30000-0163-20061 109 backup execute CLI commands backup Backup the FortiBridge configurat ion to a file on a TFTP server .
execute CLI commands date FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 75 date Get or set the system date. Command syntax execute date [<date_str>] date_str has th e for.
FortiBridge Version 3.0 Administration Guide 76 09-30000-0163-20061 109 factoryreset execute CLI commands factoryreset Reset the FortiBr idge configuratio n to factory de fault settings.
execute CLI commands ping FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 77 ping Send five ICMP ec ho requests (pings) to test the network connectio n between the For tiBridge unit and another network device.
FortiBridge Version 3.0 Administration Guide 78 09-30000-0163-20061 109 reboot execute CLI commands reboot Rest art the FortiBridge unit. Command syntax execute reboot.
execute CLI commands restore FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 79 restore Use this command to restore a backup confi guration and to change the FortiBridge firmware.
FortiBridge Version 3.0 Administration Guide 80 09-30000-0163-20061 109 switch-mode execute CLI commands switch-mode Use this command to switch between byp ass and normal mode.
execute CLI commands time FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 81 time Get or set the system time. Command syntax execute time [<time_str>] time_str has the form.
FortiBridge Version 3.0 Administration Guide 82 09-30000-0163-20061 109 time execute CLI commands.
Index FortiBridge Version 3.0 Administration Guide 09-30000-0163-20061 109 83 Index A accprofile 59 action on failure fail open 37 probe 37 send alertmail 37 SNMP trap 37 syslog 37 action_on_failure 5.
FortiBridge Version 3.0 Administration Guide 84 09-30000-0163-20061 109 Index HA cluster 15 other FortiGate interfaces 16 execute CLI commands 73 switch-mode 44 execute switch-mode 14 EXT 1 management.
Index FortiBridge V ersion 3.0 Administration Guide 09-30000-0163-20061 109 85 monitor FortiGate unit 11 mounting instructions 20 N name 71 new version FortiBridge firmware 31 normal mode 10, 11 monit.
FortiBridge Version 3.0 Administration Guide 86 09-30000-0163-20061 109 Index v2c 42 snmp action_on_failure 56 SSH access to CLI 47 standalon e FortiGate unit 9 static ro ute adding 28 status 5 4 stat.
www.fortinet.com.
www.fortinet.com.
Een belangrijk punt na aankoop van elk apparaat Fortinet Version 3.0 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen Fortinet Version 3.0 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens Fortinet Version 3.0 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding Fortinet Version 3.0 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over Fortinet Version 3.0 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van Fortinet Version 3.0 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de Fortinet Version 3.0 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met Fortinet Version 3.0 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.