fortinet
文章平均质量分 72
gotonet
这个作者很懒,什么都没留下…
展开
-
DNS translation feature configuration example
DNS translation translates IP addresses in packets sent by a DNS server from the internal network to the external network. Use DNS translation if you have a DNS server on your internal network that原创 2006-10-29 17:20:00 · 659 阅读 · 0 评论 -
FortiNet v2.8 FCSE培训笔记!
1. 全球技术论坛:http://support.fortinet.com/forumFortiNet2. 中国技术论坛:http://bbs.fortinet.com.cnFortiNet3. 技术资料网站:http://kc.forticare.comFortiNet4. 最新版本:FortiOS V2.80 buil原创 2006-10-29 17:43:00 · 1606 阅读 · 0 评论 -
Disabling Microsoft L2TP for IPSec
FortiGate units support L2TP with Microsoft Point-to-Point Encryption (MPPE) encryption only. Later implementations of Microsoft L2TP for Windows use IPSec and require certificates for authentication原创 2006-10-29 17:41:00 · 999 阅读 · 0 评论 -
configure secondary IPs to overlap the primary ip
Fortigate-800 # config sys global (global)# set modify value unset set to default value get get configuration show retrieve value abort end and discard last config原创 2006-10-29 17:39:00 · 1522 阅读 · 0 评论 -
Configuring Fortinet Dual Internet Links
Design ConsiderationsThere are two separate considerations when using two Internet uplinks: Link Redundancy and Load Sharing. These two features can be combined or implemented separately.转载 2006-10-29 17:37:00 · 1076 阅读 · 0 评论 -
FortiClient_DHCP-Over-IPSec_to_Fortigate
IntroductionThis configuration demonstrates how to connect a Forticlient to a Fortigate usingDHCP-Over-IPSec feature. PrerequisitesComponents Usedu Forticlient V1.0-build207u Fo原创 2006-10-29 17:34:00 · 1080 阅读 · 0 评论 -
Fortigate firewall LDAP config
Case ScenarioYou have to two groups of users attempting to access the Internet through the FortiGate. Most users need to be restricted in their access to the Internet. A few select users are permitt原创 2006-10-29 17:32:00 · 1375 阅读 · 0 评论 -
Fortinet Certified Network Security Professional
Fortinet Certified Network Security Professional Taining NotesImplmenting FortiGate Security and Content InspectionCourse 925-201b Authorized TainingInstructor: Florence Lau Fortinet Malaysia Sd原创 2006-10-29 17:31:00 · 1945 阅读 · 1 评论 -
FortiGate has reached connection limit..message
This above message may be displayed on the Alert Message Console GUI. It is similar to the “The system has entered conserve mode” Event log message.Explanation:The antivirus engine was low on memo原创 2006-10-29 17:21:00 · 2330 阅读 · 0 评论 -
FortiOS 3.0 部分网站及MSN无法登陆解决方法
转载请保留作者信息及出处。测试环境:fortios 3.0 MR2.防火墙策略没有做任何防病毒过滤及保护内容表动作。现象:MSN无法登陆,部分网站同样也无法访问。 一开始我使用的版本为FortiOS 2.8 MR11 build 489,MSN和部分网站可以访问,没有问题,升级到3.0版本后,配置没变,但MSN和部分网站无法登陆,首先,给我的第一印象可能是版本BUG问题,与厂商原创 2006-10-29 17:23:00 · 721 阅读 · 0 评论 -
如何利用FG防火墙实现IP/MAC地址binding?
1、在防火墙上定义对应的IP-mac对应表config firewall ipmacbinding table edit 1 set ip 192.167.1.111 set mac 00:0a:eb:7c:16:05 set name "robbie" set status enable next原创 2006-10-29 17:42:00 · 1535 阅读 · 0 评论 -
Can I block IM by FortiGate firewalls
You can use the CLI command config imp2p old-version to block older IM versions than the following at Fortios 3.0: MSN 6.0 ICQ 4.0 AIM 5.0 Yahoo 6.0For details see the For原创 2006-10-29 17:41:00 · 1410 阅读 · 0 评论 -
如何使用CLI通过TFTP升级Fortigate防火墙系统文件
1,通过超级终端或其他工具,连接CONSOLE口,参数设置为默认即可,特别的例外,例如,Fortigate-300(A),速率为115200.其他相同。2,使用交叉线连接防火墙的internal口,A系列产品的接口为自适应。3,重新启动防火墙,出现如下提示: Ver:03000300Serial number:FGT-602103243758RAM activation原创 2006-10-29 17:37:00 · 2129 阅读 · 0 评论 -
Fortigate防火墙忘记密码时恢复
如果用户忘记默认的"admin" password (or any other admin access), 如下为恢复密码的过程,仅供参考:1. Connect a PC serial (com port) to FG console.2. Bring up Hyper Terminal using proper setting.3. At the console login prompt, t原创 2006-10-29 17:36:00 · 2717 阅读 · 0 评论 -
Fortinet and huawei 6502 DHCP configure
FORTINET DHCP CONFIGURE:config system dhcp server edit "DHCP" set default-router 192.168.3.254 set end-ip 192.168.3.253 set interface "internal" set lease-time 17280原创 2006-10-29 17:35:00 · 841 阅读 · 0 评论 -
Reformat and_recover hard disk procedure
PROCEDURE TO FORMAT AND RECOVER THE HARD DISK---------------------------------------------------------Needed tools for this procedure :- a terminal client (windows hyperterminal, linux minicom...)原创 2006-10-29 17:34:00 · 715 阅读 · 0 评论 -
Link Aggregation how tos
How do I configure an interface to use link aggregation using CLI commands?If port 2 and port 3 are available, the following CLI commands create an aggregate called "link_agg" with an IP/netmask of原创 2006-10-29 17:28:00 · 807 阅读 · 0 评论 -
Cannot view some web sites when using PPPoE
Problem: Certain web sites are not viewable. The Fortigate is configured to use PPPoE to connect to the ISP.Solution: Use the "tcp-mss" interface option.Topology:HTTP Client----(internal)FGT(ppp原创 2006-10-29 17:30:00 · 550 阅读 · 0 评论 -
Making FortiGate completely invisible to probes
FortiGate units by default do not accept TCP or UDP connections on any port (except TCP port 443 HTTPS connections on the default internal interface for administration). This reduces the possibility o原创 2006-10-29 17:27:00 · 980 阅读 · 0 评论 -
Basic FortiOS 2.80 OSPF configuration
FortiGate Configuration1. Area configuration:Fortigate-500 # config router ospf(ospf)# config area(area)# edit 0.0.0.1new entry 0.0.0.1 added(0.0.0.1)# end2. Network configuration:(ospf)# co原创 2006-10-29 17:38:00 · 713 阅读 · 0 评论 -
How to Using the FortiUSB key
The FortiUSB key enables you to backup and restore configuration files and auto install firmware images.Note: The FortiGate unit can only use a FortiUSB key.Inserting and removing the FortiUSB key原创 2006-10-29 17:31:00 · 750 阅读 · 0 评论 -
Traffic Types and TCP/UDP Ports used by Fortinet
Network traffic originating from FortiGate units (not passing through FortiGate units) is used for sending log messages to remote log servers, sending SNMP traps, resolving network names using DNS,原创 2006-10-29 17:29:00 · 809 阅读 · 0 评论 -
configure the logging of Denied Traffic to a FG
All FortiGate models with v2.80Session or connection attempts that are established to a FortiGate interface, are by default not logged if they are denied. The following can be configured, so that t原创 2006-10-29 17:28:00 · 796 阅读 · 0 评论 -
802.3ad Link Aggregation FAQ
What is link aggregation?Link aggregation, otherwise known as IEEE 802.3ad standard, allows the grouping of interfaces into a larger bandwidth trunk. It also allows for high availability (HA) by a原创 2006-10-29 17:28:00 · 1941 阅读 · 0 评论 -
FortiOS v3.0 HA Cluster virtual MAC addresses
When a FortiOS v3.0 cluster is operating, the FGCP assigns virtual MAC addresses to each primary unit interface. The FGCP uses virtual MAC addresses so that if a failover occurs, the new primary uni原创 2006-10-29 17:26:00 · 938 阅读 · 0 评论 -
Limiting YouTube bandwidth for fortios 3.0
Limiting bandwidth requires two steps Create an address name for youtube.com Create a traffic shaping firewall policy This policy will only affect traffic between users and YouTube,原创 2006-10-29 17:23:00 · 533 阅读 · 0 评论 -
Configure virtual domains for an 802.1q VLAN trunk
IntroductionThis document describes how to configure virtual domains in Transparent mode to provide AV/IPS protection in an 802.1q VLAN trunk environment. In a typical 802.1q VLAN trunk environmen原创 2006-10-29 17:39:00 · 1731 阅读 · 0 评论 -
Manual RBL ORDBL DNSBL SPAM troubleshooting
This article describes how to manually test an IP address connecting to your SMTP server to verify whether it is considered a Spam source by various RBL/ORDBL/DNSBL services.This example uses a Micr原创 2006-10-29 17:40:00 · 1305 阅读 · 0 评论 -
How do I configure a Virtual IP
About virtual IPsVirtual IP (VIP) addresses enable users from outside a private network to access services inside that network. Under normal circumstances, this is not possible because Internet rout原创 2006-10-29 17:27:00 · 773 阅读 · 0 评论 -
Creating redundant network interfaces with os 2.8
About redundant interfacesYou can combine two or more physical interfaces to provide link redundancy, to ensure that Internet services remain active if one physical interface fails.You can set u原创 2006-10-29 17:24:00 · 474 阅读 · 0 评论 -
Using the FortiOS built-in packet sniffer
IntroductionAll FortiGate units have a powerful packet sniffer on board. If you know tcpdump you should feel comfortable using the FortiGate Sniffer.Additional sniffer tips can be found in the F原创 2006-10-29 17:26:00 · 804 阅读 · 0 评论 -
Creating redundant network interfaces with os 3.0
About redundant interfacesYou can combine two or more physical interfaces to provide link redundancy, to ensure that Internet services remain active if one physical interface fails. You can set原创 2006-10-29 17:24:00 · 556 阅读 · 0 评论 -
Loading FortiGate firmware using TFTP
Unless you are doing this to resolve an outage, plan this firmware installation because there will be an outage from when you reboot the FortiGate unit until it restarts with the new firmware. Co原创 2006-10-29 17:22:00 · 1094 阅读 · 0 评论 -
Runtime-only config mode
Runtime-only config mode is a temporary mode where the commands you enter do not automatically become part of the saved FortiGate configuration. This enables you to make changes with the knowledge tha原创 2006-10-29 17:21:00 · 943 阅读 · 0 评论 -
cisco and fortigate OSPF configure
cisco 3745 router config:Router#sh runBuilding configuration...Current configuration : 3002 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service p原创 2006-10-29 12:26:00 · 1407 阅读 · 0 评论