Gebruiksaanwijzing /service van het product FortiGuard Analysis 1.2.0 van de fabrikant Fortinet
Ga naar pagina of 76
www.fortinet.com F or tiG ua rd An alys is an d Management Ser vice V ersion 1 .2.0 ADMINISTRA TION GUIDE.
FortiGuard Analysis and Management Service Admini stration Guide V ersion 1.2. 0 31 October 2008 13-12000-40 6-20081031 © Copyright 2008 Fortine t, Inc.
Contents FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 3 Contents Introduction ............... ................................. .............................. .......... 7 About this document .
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 4 13-12000-406-200810 31 Contents Management ......... .................................................................. .......... 35 Device .............. ............
Contents FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 5 Index ............... ..............
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 6 13-12000-406-200810 31 Contents.
Introduction About this document FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081002 7 Introduction The FortiGuard Analysis an d Management Service is a subscription-based service that provides remo te management and logging and reporting capabilities for all FortiGate units.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 8 13-12000-406-200810 02 Fortinet documentation Introduction Typographic conventions Fortinet documenta tion uses the f.
Introduction Customer service a nd technical suppo rt FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 02 9 Customer service and technical support F.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 10 13-12000-406-200810 02 Customer service and technical support Introduction.
Setup About the portal web site FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081031 11 Setup This section explains how to: • log in to the portal web site • navigate within the porta l web site • properly set up the service • connect a device to the service.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 12 13-12000-406-200810 31 About the portal web site Setup Figure 1: The port al web site When you ente r the email address and password for logging in, the Service Account ID appears.
Setup About the portal web site FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 13 Figure 2: Port al web site layout, Ma nagement vie w Dashboard main menu The Dashboard main menu provides all features that are rela ted to it, such as customizing and addi ng pages.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 14 13-12000-406-200810 31 Obtaining a trial contract Setup Obt aining a trial contract When you first access the port al web site , you can immediately sign up for a trial contract.
Setup Obta ining a tria l contract FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 15 T o obtain a trial contract 1 Go to https://fams.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 16 13-12000-406-200810 31 Configuri ng a device to use the service Setup 4 Select Submit.
Setup Configuring a device to use the service FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 17 2 Select the Expand Arrow be side Analysis & Management Service Options to reveal the availa ble options.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 18 13-12000-406-200810 31 Configuri ng a device to use the service Setup T o configure remote logging to the service 1 In the FortiGate web-based man ager , go to Log&Report > Log Config > Log Setting .
Setup Expanding or renewing service FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 19 Figure 6: Central Manag ement options 2 Select the check box beside Enable Central Manage ment. 3 From T ype, select FortiGua rd Manageme nt Service.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 20 13-12000-406-200810 31 Expanding or renewing service Setup Renewing contracts If you want to extend the serv ice period, you can add a r enewal contract to the previous contract.
Setup Expanding or renewing service FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 21 Figure 8: Contract Number 6 Select Renew . The terms of the contr act appear . 7 If you agree, select Agree.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 22 13-12000-406-200810 31 Expanding or renewing service Setup Figure 9: Locating the Serv ice Account ID Near the bottom of the p age, a Product/Contract Maintenance area appears.
Setup Required port numbers FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 23 7 If your contract details appear to be correct, select Complete Registration.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 24 13-12000-406-200810 31 Required port numbers Setup.
Dashboard The Dashboard main menu FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081031 25 Dashboard The Dashboard main menu allows users to cu stomize what system information they want to monitor , such as virus ac tivity and system resources, which are displayed as widget s.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 26 13-12000-406-200810 31 Widgets Dashboard Figure 1 1: C ustomized Dashboard page Widget s The Dashboard widge ts provide valu able information about what is happ ening on your network.
Dashboard Adding and customizing pages FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 27 Adding and customizing p ages Y ou can add up to nine p ages within the Dashboard main menu, and you can customize the widgets that you apply to th ose pages.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 28 13-12000-406-200810 31 Configuring widgets Dashboard Figure 12: Resource Monitor • • Configuring the Network Monitor The Network Monitor provides inform ation about what is happening on the network fo r which the device is curr ently configure d.
Dashboard Configuring widge ts FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 29 Figure 13: Network Monitor • Configuring the Trap Console The T rap Console provides information about SNMP trap s.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 30 13-12000-406-200810 31 Configuring widgets Dashboard T o configure a T rap Console widget, select Add T rap Console in Add Widget s, follow the instructions in the table below , and select OK.
Dashboard Configuring widge ts FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 31 • Event Report – provides informatio n about event a ctivity th at is based on event logs, such as an admin istrator logg ing in to that de vice’s web-based manager .
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 32 13-12000-406-200810 31 Configuring widgets Dashboard • Figure 16: T raffic Report pie chart displ aying the top tr.
Dashboard Customizing the Dashboard page FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 33 Figure 18: W eb Report bar chart displaying th e web.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 34 13-12000-406-200810 31 Customizing the Dashboard page Dashboard.
Management Device FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081031 35 Management The Mana gement men u provides re mote manage ment featur es, allowing yo u to upload script s, schedule when to upgra de firmware on a device, and view account information.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 36 13-12000-406-200810 31 Device Management The Device Detail tab displays the Ba sic Information section, which shows information such as the internal IP a ddress of the device and the cu rrent firmware version ru nning on the device.
Management Device FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 37 Adding and editing devices Y ou can add devices to the contract or edit th e daily volume and quot a for a device. Adding devices to a contr act is av ailable only if your contract allows it.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 38 13-12000-406-200810 31 Device Management T o edit a device 1 Go to Management > Device . 2 In the Device section, select Edit. 3 Enter the appro priate information fo r the following: 4 Select Submit.
Management Device FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 39 Sending manual or automati c configuration revisions The service can receive manual and au tomatic configuration ba ckups when you change a licensed device’ s configuration.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 40 13-12000-406-200810 31 Device Management Searching configuration revisions Y ou can search configuration revisions to fin d a configuration change tha t occurred on a device.
Management Device FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 41 Comparing configuration revisions As you accrue conf iguration revisions, yo u may want to determine what changed between two revisions.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 42 13-12000-406-200810 31 Device Management T o compare co nfiguration revision s from within the FortiGate web-b ased manager 1 In the FortiGate web-based man ager , go to System > Maintenance > Revision Control .
Management Device FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 43 Running scripts Y ou can run script s or schedule when a scri pt runs from the T asks section of the Device menu. Scripts allow you to deploy identical configuration item s to many devices.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 44 13-12000-406-200810 31 Device Management Changing firmware from the portal web site The Device De tail tab displays each device’s curren t firmware vers ion and any scheduled firmware changes.
Management Scripts FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 45 Changing firmware from the device In addition to immediately changing a de.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 46 13-12000-406-200810 31 Scripts Management Creating scripts With a plain text edito r , you can create scr ipts fro m backed up configuration files, and then upload them as a script.
Management Scripts FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 47 7 Select Submit. The script is added to the list of available scr ipts.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 48 13-12000-406-200810 31 T opology T ool Management T opology T ool The T opology T ool tab, similar to the T o pology tab found on mo st devices, allows you to create and save a dia gram of your specific network.
Management T opology T ool FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 49 Figure 25: Network diagram in Edit mode Within the T o pology T o ol section, additi onal menus allow you to access network diagrams and custo mize the view .
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 50 13-12000-406-200810 31 T opology T ool Management In Edit mode, many dif ferent icons (or drawing tools) an d shapes help you create a network diagram.
Management Settings FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 51 4 Select Save to save the network diagram to the service’ s server . Y ou can save the network diag ram to either the Private or Share d folders.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 52 13-12000-406-200810 31 Settings Management Figure 26: Settings menu Delete Edit Account Information This section provide s information s pecific to your account, such a s the service account ID, the time zo ne, and other details about your contract.
Management Settings FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 53 Adding, editing and re moving administrators If multiple users will be accessing the serv ice portal, you can add those users to the accoun t from the User Information area.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 54 13-12000-406-200810 31 Settings Management T o add or edit account users 1 Go to Management > Settings . 2 In User Information, select eith er Add User to create a new user , or select the Edit icon in the row of the us er you want to change.
Management Settings FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 55 4 Select Submit. Changing your service account ID The Account In formation area includes th e Service Account ID an d time zone, and is displayed the same way for all users and devic es connecting to the ac count.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 56 13-12000-406-200810 31 Settings Management 4 Select OK. Name Enter a name for the alert profile.
Analysis FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081031 59 Analysis In the Analysis menu, you can view , search and browse through log files of each registered device. Y ou can also view and generate report s.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 60 13-12000-406-200810 31 Log Viewer Analysis Log V iewer From the Log V iewer tab, you can view re cen t and specific logs on the registered devices.
Analysis Log Viewer FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 61 Figure 27: V iewin g recent event log messages Device The device that you are currently viewing log messages from. Ty p e T he type of log messages you are cu rrently viewing.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 62 13-12000-406-200810 31 Customizing the log view Analysis Figure 28: Viewing historical event log messages Customizin.
Analysis Customizing the log view FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 63 Figure 29: Column Display Settings wi ndow for Even t log T o show or hide columns 1 Select Column Settings. A list of columns available for that log typ e appears.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 64 13-12000-406-200810 31 Customizing the log view Analysis Figure 30: Filter icons for logs When filtering by sour ce or destination IP , you can use the followi ng in the filtering criteria: • a single address ( 2.
Analysis Log File Browser FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 65 Log File Browser Y ou can down load all log files stored on each device. By downloading the log files, you can view all log messag es that were rec orded in that lo g file outside of the portal web site.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 66 13-12000-406-200810 31 Deleting log file s from the Fort iGate web-ba sed manager Analysis T o download a log fi le 1 Go to Analysis > Log File Browser . 2 In the row contai ning the file you want to download, select Download.
Analysis Reports FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 67 Y ou can access reports on the portal web s ite either from t he Dashboard m enu or from Analysis > Report .
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 68 13-12000-406-200810 31 Reports Analysis Figure 33: Generated daily report fo r the period of Septemb er 22, 2008 to Sept ember 23, 2008 T o view a generated report 1 Go to Analysis > Report .
Analysis e-Discovery FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 69 4 Select the dates using the calendars in Delete Repo rts. When selecting dates, remem ber that reports within th e time period will be deleted as well.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 70 13-12000-406-200810 31 e-Discovery Analysis Figure 34: An e-Discovery task in the e-Discovery menu Copy Ta s k Delete Ta s k Edit Ta s k Reschedule T asks <T ask name> D etails of the <T ask Name> T ask List This section displays the current t asks.
Analysis e-Discovery FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 71 Figure 35: Search Result s t ab with email messages found during the search View er s The users who have p ermission to view the task.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 72 13-12000-406-200810 31 e-Discovery Analysis Creating tasks for e-Discovery Y ou can create det ailed tasks for both users and th ird-par ty administrators to vie w . Y ou can also copy an existing task to form the basis of a new t ask.
Analysis e-Discovery FortiGuard Analysis and Ma nagement Serv ice Version 1.2.0 Administration Gu ide 13-12000-406-200810 31 73 T o create t asks for e-Discovery 1 Go to Analysis > e-Discove ry . 2 In T asks, select New T as k. 3 Enter the appropriate infor mation in the available fields.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 74 13-12000-406-200810 31 e-Discovery Analysis.
Index FortiGuard Analysis and Management Servic e Version 1.2.0 Administration Guide 13-12000-406-20081031 75 Index A adding purchased contracts 21 adding, configuring, or defining administrators 55 c.
FortiGuard Analysis and Manageme nt Service V ersion 1.2.0 Administratio n Guide 76 13-12000-406-200810 31 Index topology tool 49 O obtaining a trial con tract 14 P port numbers required for the servi.
www.fortinet.com.
www.fortinet.com.
Een belangrijk punt na aankoop van elk apparaat Fortinet FortiGuard Analysis 1.2.0 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen Fortinet FortiGuard Analysis 1.2.0 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens Fortinet FortiGuard Analysis 1.2.0 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding Fortinet FortiGuard Analysis 1.2.0 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over Fortinet FortiGuard Analysis 1.2.0 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van Fortinet FortiGuard Analysis 1.2.0 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de Fortinet FortiGuard Analysis 1.2.0 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met Fortinet FortiGuard Analysis 1.2.0 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.