Summary of the content on the page No. 1
INSTALL GUIDE
FortiGate-3600A
FortiOS 3.0 MR6
www.fortinet.com
Summary of the content on the page No. 2
FortiGate-3600A Install Guide FortiOS 3.0 MR6 18 March 2008 01-30006-0457-20080318 © Copyright 2008 Fortinet, Inc. All rights reserved. No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet, Inc. Trademarks Fortinet, FortiGate and FortiGuard are registered trademarks and Dynami
Summary of the content on the page No. 3
Contents Contents Introduction ........................................................................................ 7 Register your FortiGate unit............................................................................. 7 About the FortiGate-3600A ............................................................................... 8 About this document......................................................................................... 8 Document conventions..............................
Summary of the content on the page No. 4
Contents Adding a default route and gateway..................................................... 26 Adding firewall policies ......................................................................... 27 Configuring Transparent mode...................................................................... 27 Using the web-based manager ................................................................... 28 Switching to Transparent mode............................................................ 28 Conf
Summary of the content on the page No. 5
Contents FortiGate Firmware .......................................................................... 47 Downloading firmware .................................................................................... 47 Using the web-based manager....................................................................... 47 Upgrading the firmware............................................................................... 47 Reverting to a previous version..............................................
Summary of the content on the page No. 6
Contents FortiGate-3600A FortiOS 3.0 MR6 Install Guide 6 01-30006-0457-20080318
Summary of the content on the page No. 7
Introduction Register your FortiGate unit Introduction Welcome and thank you for selecting Fortinet products for your real-time network protection. The FortiGate Unified Threat Management System improves network security, reduces network misuse and abuse, and helps you use communications resources more efficiently without compromising the performance of your network. The FortiGate Unified Threat Management System are ICSA-certified for firewall, IPSec, and antivirus services. The FortiGate
Summary of the content on the page No. 8
About the FortiGate-3600A Introduction About the FortiGate-3600A The FortiGate-3600A multi-threat security appliance establishes a new level of price-performance and flexibility for multi-gigabit capacity network security systems. With ten gigabit Ethernet interfaces and up tosix Gbps throughput, the FortiGate-3600A enables a new generation of high performance protection against blended threats. The FortiGate-3600A includes • Multi-Gigabit performance for large enterprises and Managed Securi
Summary of the content on the page No. 9
Introduction Further Reading Document conventions The following document conventions are used in this guide: • In the examples, private IP addresses are used for both private and public IP addresses. • Notes and Cautions are used to provide important information: Note: Highlights useful additional information. Caution: Warns you about commands or procedures that could have unexpected or ! undesirable results including loss of data or damage to equipment. Typographic conventions FortiGate docu
Summary of the content on the page No. 10
Further Reading Introduction • FortiGate online help Provides a context-sensitive and searchable version of the Administration Guide in HTML format. You can access online help from the web-based manager as you work. • FortiGate CLI Reference Describes how to use the FortiGate CLI and contains a reference to all FortiGate CLI commands. • FortiGate Log Message Reference Available exclusively from the Fortinet Knowledge Center, the FortiGate Log Message Reference describes the structure of Fort
Summary of the content on the page No. 11
Introduction Customer service and technical support Customer service and technical support Fortinet Technical Support provides services designed to make sure that your Fortinet systems install quickly, configure easily, and operate reliably in your network. Please visit the Fortinet Technical Support web site at http://support.fortinet.com to learn about the technical support services that Fortinet provides. FortiGate-3600A FortiOS 3.0 MR6 Install Guide 01-30006-0457-20080318 11
Summary of the content on the page No. 12
Customer service and technical support Introduction FortiGate-3600A FortiOS 3.0 MR6 Install Guide 12 01-30006-0457-20080318
Summary of the content on the page No. 13
Installing Environmental specifications Installing This chapter describes installing your FortiGate unit in your server room, environmental specifications and how to mount the FortiGate in a rack if applicable. This chapter contains the following topics: • Environmental specifications • Cautions and warnings • Plugging in the FortiGate • Plugging in the FortiGate • Turning off the FortiGate unit Environmental specifications • Operating temperature: 32 to 104°F (0 to 40°C) If you install the Fo
Summary of the content on the page No. 14
Cautions and warnings Installing • Connect the equipment into an outlet on a circuit different from that to which the receiver is connected. • Consult the dealer or an experienced radio/TV technician for help. The equipment compliance with FCC radiation exposure limit set forth for uncontrolled Environment. Cautions and warnings Review the following cautions before installing your FortiGate unit. Grounding • Ensure the FortiGate unit is connected and properly grounded to a lightning and surge
Summary of the content on the page No. 15
Installing Cautions and warnings When placing the FortiGate unit on any flat, stable surface, ensure the unit has at least 1.5 inches (3.75 cm) of clearance on each side to ensure adequate airflow for cooling. For rack mounting, use the mounting brackets and screws included with the FortiGate unit. Note: Fortinet recommends purchasing side rail mounts or similar rack mount aids separately to ensure the FortiGate unit is attached safely to the rack. Caution: Depending on the size of your Fort
Summary of the content on the page No. 16
Plugging in the FortiGate Installing The following photos illustrate how the mounting brackets and FortiGate unit should be attached to the rack. Figure 2: Mounting in a rack Plugging in the FortiGate The FortiGate unit does not have an on/off switch. To power on the FortiGate unit 1 Connect the power cables to the power connections on the back of the FortiGate unit. 2 Connect the power cables to power outlets. Each power cable should be connected to a different power source. If one power
Summary of the content on the page No. 17
Installing Turning off the FortiGate unit Connecting to the network Using the supplied Ethernet cable, connect one end of the cable to your router or modem, whatever the connection is to the Internet. Connect the other end to the FortiGate unit. Connect to either the External, WAN port, or port 1. Connect additional cable to the Internal port or port 2 and your internal hub or switch. Turning off the FortiGate unit Always shut down the FortiGate operating system properly before turning off th
Summary of the content on the page No. 18
Turning off the FortiGate unit Installing FortiGate-3600A FortiOS 3.0 MR6 Install Guide 18 01-30006-0457-20080318
Summary of the content on the page No. 19
Configuring NAT vs. Transparent mode Configuring This section provides an overview of the operating modes of the FortiGate unit, NAT/Route and Transparent, and how to configure the FortiGate unit for each mode. There are two ways you can configure the FortiGate unit, using the web-based manager or the command line interface (CLI). This section will step through using both methods. Use whichever you are most comfortable with. This section includes the following topics: • NAT vs. Transparent
Summary of the content on the page No. 20
Connecting to the FortiGate unit Configuring Transparent mode In Transparent mode, the FortiGate unit is invisible to the network. Similar to a network bridge, all FortiGate interfaces must be on the same subnet. You only have to configure a management IP address to make configuration changes. The management IP address is also used for antivirus and attack definition updates. Figure 2: FortiGate unit in Transparent mode 10.10.10.1 Management IP Internal Network Gateway to public network 204.2