Home Cloud & Networking Getting Started with FortiGate

Getting Started with FortiGate

By Fabrizio Volpe , Rosato Fabbri
books-svg-icon Book
Subscription FREE
eBook + Subscription $15.99
eBook $19.99
Print + eBook $32.99
READ FOR FREE Free Trial for 7 days. $15.99 p/m after trial. Cancel Anytime! BUY NOW BUY NOW BUY NOW
What do you get with a Packt Subscription?
This book & 7000+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with a Packt Subscription?
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with eBook + Subscription?
Download this book in EPUB and PDF formats
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with a Packt Subscription?
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with eBook?
Download this book in EPUB and PDF formats
Access this title in our online reader
DRM FREE - Read whenever, wherever and however you want
Online reader with customised display settings for better reading experience
What do you get with video?
Download this video in MP4 format
Access this title in our online reader
DRM FREE - Watch whenever, wherever and however you want
Online reader with customised display settings for better learning experience
What do you get with Audiobook?
Download a zip folder consisting of audio files (in MP3 Format) along with supplementary PDF
READ FOR FREE Free Trial for 7 days. $15.99 p/m after trial. Cancel Anytime! BUY NOW BUY NOW BUY NOW
Subscription FREE
eBook + Subscription $15.99
eBook $19.99
Print + eBook $32.99
What do you get with a Packt Subscription?
This book & 7000+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with a Packt Subscription?
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with eBook + Subscription?
Download this book in EPUB and PDF formats
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with a Packt Subscription?
This book & 6500+ ebooks & video courses on 1000+ technologies
60+ curated reading lists for various learning paths
50+ new titles added every month on new and emerging tech
Early Access to eBooks as they are being written
Personalised content suggestions
Customised display settings for better reading experience
50+ new titles added every month on new and emerging tech
Playlists, Notes and Bookmarks to easily manage your learning
Mobile App with offline access
What do you get with eBook?
Download this book in EPUB and PDF formats
Access this title in our online reader
DRM FREE - Read whenever, wherever and however you want
Online reader with customised display settings for better reading experience
What do you get with video?
Download this video in MP4 format
Access this title in our online reader
DRM FREE - Watch whenever, wherever and however you want
Online reader with customised display settings for better learning experience
What do you get with Audiobook?
Download a zip folder consisting of audio files (in MP3 Format) along with supplementary PDF
About this book
FortiGate from Fortinet is a highly successful family of appliances enabled to manage routing and security on different layers, supporting dynamic protocols, IPSEC and VPN with SSL, application and user control, web contents and mail scanning, endpoint checks, and more, all in a single platform. The heart of the appliance is the FortiOS (FortiOS 5 is the latest release) which is able to unify a friendly web interface with a powerful command line to deliver high performance. FortiGate is able to give users the results they usually achieve at a fraction of the cost of what they would have to invest with other vendors.This practical, hands-on guide addresses all the tasks required to configure and manage a FortiGate unit in a logical order. The book starts with topics related to VLAN and routing (static and advanced) and then discusses in full the UTM features integrated in the appliance. The text explains SSL VPN and IPSEC VPN with all the required steps you need to deploy the aforementioned solutions. High availability and troubleshooting techniques are also explained in the last two chapters of the book.This concise, example-oriented book explores all the concepts you need to administer a FortiGate unit. You will begin by covering the basic tools required to administer a FortiGate unit, including NAT, routing, and VLANs. You will then be guided through the concepts of firewalling, UTM inside the appliance, tunnelling using SSL, and IPSEC and dial-up configurations. Next, you will get acquainted with important topics like high availability and Vdoms. Finally, you will end the book with an overview of troubleshooting tools and techniques.
Publication date:
November 2013
Publisher
Packt
Pages
126
ISBN
9781782178200

 

Chapter 1. First Steps

Fortinet FortiGate is a line of products that includes a series of network appliances. An appliance is defined as a discrete hardware device with integrated software, optimized to give specific features. The single device integrates networking and security features to achieve what is called a Unified Threat Management (UTM) approach to security.

The main advantages of the UTM viewpoint are:

  • Consolidation of security functions on a single device. We are not required to reiterate several times the same filters on different devices.

  • Consolidated administrative interface based on a single management console.

  • Consistent updates across all the devices involved in UTM.

Based on the aforementioned approach to security, a FortiGate is able to grant:

  • Networking services at layer 2 and layer 3 (switching and routing, both static and dynamic)

  • Network security services (firewalling, secure VPN connection, intrusion detection, and endpoint security)

  • Application security services (spam and virus controls, web filtering, application control, and data leak prevention)

Note

Fortinet uses proprietary chipsets and a processor known as a Content Processor (CP) ASIC. The main advantage of this architecture is to address the performance issues that could be associated with the UTM approach. For more details see the FortiGate Hardware Guide: http://docs.fortinet.com/fgt/handbook/40mr3/fortigate-hardware-40-mr3.pdf.

 

Administering a FortiGate


We are able to manage one or all the aforementioned security features from one of the administrative tools of the device, a graphical interface (the web-based manager), and a command line (CLI). In the following screenshot, we can see the dashboard of the web-based manager and the CLI paired in the same screen:

Access to the web-based manager requires a browser and an Ethernet connection between the FortiGate unit and the administrator's workstation.

The CLI can be used inside the graphical dashboard or we can detach it to use the command line in a separate window. The CLI is also the only administrative access we have when we access a FortiGate from a Telnet (or SSH) connection.

Note

A Telnet session uses clear text in all transmissions. Everything we type during a Telnet session, including passwords, is basically readable on the network. SSH encrypts information and makes it unreadable. If we have the option to select a connection type, SSH is to be preferred over Telnet.

We are able to open the CLI from the browser as a part of the web-based manager or using a terminal connection that requires an RJ-45 to DB-9 serial cable and a terminal emulation client like PuTTY.

While the graphical interface is easier to manage and does not require knowledge of specific commands, the command line has some advantages:

  • To troubleshoot problems with the operation of a FortiGate as we are able to use the diagnose debug command in the CLI console. This is something we will see in more detail in Chapter 5, Troubleshooting.

  • To script and automatize operations.

  • For accessing configuration items that are only available using the CLI. An example is the FortiGate Session Life Support Protocol (FGSP) explained in Chapter 4, High Availability.

  • To apply modifications and changes on multiple devices in a reliable and less error prone manner.

Note

To allow SSH access to the CLI, we have to enable this kind of administrative access on at least one interface. The operation is performed as shown in the section, Selecting the operation mode and configuring the internal and external interfaces.

 

Unboxing the FortiGate and license options


Usually the package we receive contains at least the device, a quick start guide, a power cord, a CD-ROM containing software, and an RJ-45 to DB-9 serial cable.

Note

The software included in the box is usually older than the one we are able to download from the Internet. After the registration procedure described in this section, we can download the updated release of all the required firmware and software.

Depending on the kind of license we have purchased, the device will have some or all of the available features:

  • FortiCare: It is the less costly option and includes hardware support and software upgrades. This license enables the use of the FortiGate as a networking device with the capability to configure intranets (also using VPNs).

  • Bundle: This license adds updates for the UTM features like antivirus, web filtering, IPS, and anti-spam.

  • A third option: Buying one or more single UTM features instead of the full bundle is available for medium and high end devices.

Features can be enabled or disabled based on our needs. We can also buy some features as an additional option to our license later on and activate them as soon as the new options are available. This is done using the Features option in the Config widget. The related pane is shown in the following screenshot:

             
About the Authors
  • Fabrizio Volpe

    Fabrizio Volpe is a Lync MVP and an experienced IT professional, with more than 15 years of experience working in the IT department of large-scale banking and financial companies. He has been working as a network and systems administrator in various firms of the Iccrea Banking Group (one of the top banking groups in Italy) since 2000. From 2011 to 2013, before moving his focus to Unified Communications, Fabrizio received the MVP award for Directory Services. Over the past few years, Fabrizio has participated as a speaker at many events and conferences (both Italian and international). He creates IT-focused content on different platforms that have received good feedback. His works are available on YouTube (http://www.youtube.com/user/lync2013), on his personal blog (http://www.absoluteuc.org), and on SlideShare (http://www.slideshare.net/fabriziov). Fabrizio has published three books with Packt Publishing: Getting Started with FortiGate,Getting Started with Microsoft Lync Server 2013, and Instant Microsoft Forefront UAG Mobile Configuration Starter. He has also authored a successful free e-book, Microsoft Lync Server 2013: Basic Administration, available in the TechNet Office gallery (http://bit.ly/1jbzpfo), which has been downloaded more than 25,000 times.

    Browse publications by this author
  • Rosato Fabbri

    Rosato Fabbri, 50 years old, has been the IT Manager for Need s.r.l. for the last 10 years. The company has more than a thousand users spread across eight sites (a national headquarters in Italy and a network of remote offices abroad). Need's network is entirely based on FortiGate appliances and on secure VPNs over the Internet. Rosato used his first FortiGate in 2003 and for him it was "love at first sight". He fully used the competitive advantage of Fortinet technology, both in functionalities and in features and that advantage made Need a use case, enabling the company to gain the trust of its customers and adding a lead over competitors.

    Browse publications by this author
Getting Started with FortiGate
Unlock this book and the full library FREE for 7 days
Start now