EasyManua.ls Logo

Fortinet FortiAnalyzer-100A User Manual

Fortinet FortiAnalyzer-100A
162 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
www.fortinet.com
FortiAnalyzer
Version 3.0 MR3
ADMINISTRATION GUIDE

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiAnalyzer-100A and is the answer not in the manual?

Fortinet FortiAnalyzer-100A Specifications

General IconGeneral
BrandFortinet
ModelFortiAnalyzer-100A
CategoryMeasuring Instruments
LanguageEnglish

Summary

Introduction

The FortiAnalyzer Unit

Introduces the FortiAnalyzer appliance and lists its various models.

About this guide

Describes the setup, configuration, and use of the FortiAnalyzer unit.

FortiAnalyzer documentation

Lists available documentation resources for FortiAnalyzer.

Fortinet Tools and Documentation CD

Information on accessing Fortinet documentation resources via CD.

Fortinet Knowledge Center

Access to articles, FAQs, and technical notes for Fortinet products.

Customer service and technical support

Information on obtaining technical support services from Fortinet.

FortiAnalyzer features

Reporting

Details log analysis and vulnerability reporting capabilities.

Data mining

Enables data mining for network intrusion and traffic analysis.

Network analyzer

Analyzes network traffic where FortiGate firewalls are not employed.

Installing the FortiAnalyzer unit

Planning the installation

Prepares for the installation of the FortiAnalyzer unit.

Connecting the FortiAnalyzer unit

Details hardware installation and physical connection procedures.

Configuring the FortiAnalyzer unit

Outlines initial IP address, netmask, and gateway configuration.

Using the web-based manager

Describes GUI interface for configuration and administration.

Using the command line interface

Explains CLI for configuration and monitoring functionality.

Upgrading the FortiAnalyzer firmware

Instructions for updating the FortiAnalyzer firmware.

Backing up the FortiAnalyzer hard disk

Procedures for backing up log data before firmware upgrades or changes.

Shutting down the FortiAnalyzer unit

Safe procedures for powering off the FortiAnalyzer unit.

Configure the FortiAnalyzer unit

Dashboard

Provides a view of the current operating status of the FortiAnalyzer unit.

System Information

Displays current state including serial number, uptime, and firmware.

System Resources

Monitors CPU, memory, and hard disk usage.

License Information

Shows support contract, RVS engine, and device license details.

Alert Message Console

Displays alerts for FortiAnalyzer and connected FortiGate units.

Statistics

Shows connection and log/report activity statistics.

Report Engine

Displays FortiAnalyzer report generation activity status.

Automatic Refresh Interval

Configures how often the Status page automatically updates.

System Operation

Options for rebooting or shutting down the FortiAnalyzer unit.

Viewing operational history

Displays graphs of system resources and network utilization history.

Viewing Session information

Shows information about current communication sessions.

Setting the time

Manually sets or synchronizes FortiAnalyzer system time with NTP.

Restore factory default system settings

Resets FortiAnalyzer configuration to its original factory state.

Format the log disks

Formats the FortiAnalyzer hard disk, deleting all logs and reports.

Restoring a FortiAnalyzer unit

Procedure to restore firmware image if unit is unresponsive.

Restoring a FortiAnalyzer-100A/100B, 800, 2000 and 4000/4000A

Detailed steps for restoring firmware via CLI using TFTP.

Changing the firmware

Instructions for upgrading or reverting FortiAnalyzer firmware version.

Network settings

Changing the host name

Differentiates FortiAnalyzer units by assigning a unique host name.

Interface

Configures ports, IP address, administrator access, and MTU settings.

About FortiDiscovery

Explains the FortiDiscovery protocol for automatic device discovery.

DNS

Configures primary and secondary DNS server settings.

Routing

Displays route list and allows adding static routes for packet forwarding.

Administrator settings

Adding a new administrator

Describes how to add, edit, and manage administrator accounts.

Changing the administrator password

Procedures for changing administrator account passwords.

Access Profile

Defines access rights and privileges for administrator accounts.

Auth Groups

Groups RADIUS servers for logical arrangements and authorization.

RADIUS Server

Adds RADIUS servers for administrator authorization.

Administrator Settings

Configures idle timeout, language, and administrative domains.

Monitor

Views currently logged-in administrators and disconnects them.

Administrative domains

Enabling administrative domains

Enables multiple ADOM operation for managing access for multiple domains.

Disabling administrative domains

Procedures to turn off the ADOM setting by removing created ADOMs.

Configuring ADOM settings

Covers creating ADOMs, access profiles, and assigning administrators.

Creating a new ADOM

Creates a new ADOM to configure access privileges for groups.

Adding a device to an ADOM

Assigns devices to an ADOM for access control and management.

Network sharing

Adding users

Creates user accounts for access to logs, reports, and disk storage.

Adding groups

Creates user groups to manage directory access for multiple users.

Configuring Windows shares

Provides folder and file sharing using Windows sharing protocols.

Assigning user access

Configures file and folder access privileges for users and groups.

Configuring NFS shares

Configures folder and file sharing using NFS protocols.

Setting folder and file privileges

Manages access rights for folders and files on the FortiAnalyzer hard disk.

Configuring the FortiAnalyzer unit

Log Settings

Configures system log messages, log levels, and disk space allocation.

Log Aggregation

Collates log data from remote units to a central FortiAnalyzer unit.

Configuring an aggregation client

Sets up a FortiAnalyzer unit to send logs to an aggregation server.

Configuring an aggregation server

Configures a FortiAnalyzer unit to receive logs from aggregation clients.

IP Aliases

Assigns meaningful names to IP addresses for reports and logs.

Importing an IP alias list file

Imports IP address and name lists for easier updating.

RAID

Configuring RAID on the FortiAnalyzer-400 and FortiAnalyzer-800

Details RAID configuration for specific mid-range FortiAnalyzer models.

Configuring RAID on the FortiAnalyzer-2000 and FortiAnalyzer-4000/4000A

Details RAID configuration for specific high-end FortiAnalyzer models.

RAID levels

Describes various RAID levels supported by FortiAnalyzer units.

Linear

Combines all hard disks into a single large virtual disk.

RAID 0

Stripes information across disks for better performance with no redundancy.

RAID 1

Mirrors information to provide redundant storage with no single point of failure.

RAID 5

Uses striping with parity for data protection and performance.

RAID 10

Combines mirroring and striping for performance and redundancy.

RAID 50

Combines striping with parity and striping for performance and data recovery.

RAID 5 and RAID 10 with hot spare

Enables hot spare for drives, automatically rebuilding data upon failure.

Hot swapping hard disks

Allows removal and replacement of failed hard disks without system interruption.

Maintenance

Backup & Restore

Backs up and restores configuration files and manages firmware.

Update center

Connects to FortiProtect Distribution Network for definition updates.

Devices

Devices List

Displays a list of devices configured to send log packets to FortiAnalyzer.

Device interaction with a FortiAnalyzer unit

Explains how FortiGate, FortiManager, and Syslog devices send logs.

Maximum allowed devices

Details the maximum number of devices supported by each FortiAnalyzer model.

Unregistered device options

Configures how FortiAnalyzer handles connection requests from unknown devices.

FortiGate units connecting with FortiDiscovery

Describes FortiDiscovery for automatic device discovery and configuration.

Adding a FortiGate unit

Steps to add a FortiGate unit for log message collection.

Defining FortiGate port interfaces

Assigns FortiGate interface types for accurate traffic report representation.

Adding an HA cluster

Enables HA cluster to send log packets as a cluster rather than individual units.

Adding FortiClient installations

Stores FortiClient log messages for reporting purposes.

Adding a FortiManager unit

Configures FortiManager to connect to FortiAnalyzer for management.

Adding a Syslog server

Adds a syslog server to send log packets to FortiAnalyzer.

Device Groups

Creates groups to organize and monitor devices for easier management.

Blocked Devices

Blocks devices that exceed license limits to free up spots.

Viewing blocked devices

Displays a list of blocked devices on the FortiAnalyzer unit.

Logs

Log Viewer

Views logs from registered devices with real-time or historical options.

Real-time log viewer

Displays real-time log information and updates continually.

Historical log viewer

Views network traffic logs to identify trends and network issues.

Browse

Views all stored log files for devices and FortiAnalyzer logs.

Browsing log files

Views log information for a selected device's log file and filters specific events.

Importing a log file

Imports older log files for generating reports or RAID configuration.

Downloading a log file

Downloads log files for backup or use outside the FortiAnalyzer unit.

Customizing the log view

Customizes log display by adding, removing, or repositioning columns.

Filtering logs

Filters log contents in real-time and historical data for specific content.

Basic search

Performs a simple search of all log files for keywords.

Advanced search

Provides more options to narrow search criteria for log files.

Search tips

Provides tips for effective searching within log files.

Printing the search results

Produces hard copies of search results for email, saving, or printing.

Log rolling

Controls log file size and manages FortiAnalyzer disk space.

Log rolling settings

Configures log file size limits, rolling frequency, and FTP uploading.

Content archive

Content viewer

Displays metadata from devices connected to FortiAnalyzer for email, FTP, IM.

Customizing the content log view

Customizes content log display by adding, removing, or repositioning columns.

Filtering content logs

Filters content logs in real-time and historical data for specific information.

Log rolling

Controls content log file size and space used on the FortiAnalyzer hard disk.

Log rolling settings

Configures content log file size limits, rolling frequency, and FTP uploading.

Quarantine

Configuring quarantine settings

Defines hard disk space allocation for suspicious files from FortiGate units.

Viewing the quarantined files list

Displays a list of quarantined files and related information.

Forensic Analysis

Users and groups

Views network/internet usage habits of individual users or groups.

Creating groups

Creates user groups to obtain analysis information for a selection of users.

Lookup

Finds additional user information for forensic analysis reports.

Where does FortiAnalyzer get this information?

Outlines which logs FortiAnalyzer refers to for retrieving user information.

Searching user data

Performs quick searches on selected user activity like email, IM, FTP.

To save the results

Saves search results to the FortiAnalyzer hard disk for future reference.

Local archive

Provides easy access to forensic analysis searches saved on the unit.

Configuring reports

Configuring a report profile

Creates report profiles defining information, devices, and time frames.

Customizing the report properties

Customizes reports with company info, logos, headers, and footers.

Configuring the report criteria

Selects the type of results to include in the report, such as user or device analysis.

Configuring the time period

Selects a time span or specific frame for the report generation.

Configuring the report types

Selects the type of information to include in the report.

Configuring the report output

Selects report destination and format for saving or emailing.

File output

Selects file format for reports saved to the FortiAnalyzer hard disk.

Email output

Selects file formats for reports sent as email attachments.

Viewing Forensic Reports

Views a list of generated forensic analysis reports.

Traffic summary and security events

Traffic Summaries

Provides reports on traffic passing through the firewall to identify users.

Viewing Web traffic

Summarizes HTTP and HTTPS usage per user on the network.

Viewing Email traffic

Provides a summary of email usage per user on the network.

Viewing FTP traffic

Summarizes FTP usage per user on the network.

Viewing Instant Messaging and P2P traffic

Summarizes IM and P2P usage per user on the network.

Filtering traffic summaries

Filters user traffic summaries to find specific information.

Device Summary

Provides a graphical analysis of network traffic by FortiGate unit.

Traffic Report

Generates reports to aggregate all traffic summary information.

Security event summaries

Reports on unwanted traffic attempting to breach the firewall.

Viewing virus activity

Correlates virus logs and reports overall virus activity on the network.

Viewing Intrusion activity

Correlates intrusion logs and reports overall intrusion activity on the network.

Viewing Suspicious activity

Displays activity considered suspicious or unusual network traffic.

Viewing administrative activities

Correlates administration log entries to report overall administrative activity.

Reports

Configuring reports

Creates report profiles defining information, devices, and time frames.

Configuring a report profile

Configures report profile options to define the focus and settings of a report.

Customizing the report properties

Customizes reports with company info, logos, headers, and footers.

Configuring the report criteria

Selects the type of results to include in the report, such as user or device analysis.

Configuring the report devices

Selects device or device groups to include in the reports.

Configuring the report scope

Selects time span and filter information for data inclusion in reports.

Filter logs

Filters logs by matching criteria to customize report content.

Configuring the report types

Selects the type of information to include in the report.

Configuring the report Format

Selects the type of results to include in the report.

Configuring the report schedule

Sets a schedule for generating reports, such as weekly mail traffic reports.

Configuring the report output

Selects report destination and format for saving or emailing.

File output

Selects file format for reports saved to the FortiAnalyzer hard disk.

Email output

Selects file formats for reports sent as email attachments.

Browsing reports

Views a list of generated reports via the web-based manager.

Viewing reports

Views generated reports, including roll-up and individual report formats.

Default reports

Automatically created default report profiles for registered FortiGate units.

Report types

Browse and view roll-up reports and individual reports.

Alerts

Alert Events

Defines alert events that FortiAnalyzer monitors and actions to take.

Output

Configures where alert messages are sent (email, syslog, SNMP trap).

Mail server

Configures DNS and SMTP server settings for sending email alerts.

SNMP access

Configures SNMP servers for sending alerts via SNMP traps.

Syslog Servers

Configures syslog servers to receive log messages and send alerts.

FortiAnalyzer SNMP support

Details FortiAnalyzer's SNMP implementation and supported MIBs.

FortiAnalyzer traps

Lists MIBs and traps supported by FortiAnalyzer for SNMP communication.

Network Analyzer

Connecting the FortiAnalyzer for analyzing network traffic

Connects FortiAnalyzer to a switch's SPAN or mirroring port for traffic sniffing.

Traffic viewer

Provides real-time and historical display of network activity.

Historical traffic viewer

Views network traffic logs to identify trends and network issues.

Changing the historical view criteria

Defines time range to review historical network traffic logs.

Browsing network traffic logs

Views and downloads network traffic log files.

Browsing network traffic log files

Views network traffic information not logged by FortiGate units.

Downloading a network traffic log file

Downloads network traffic log files for backup or external use.

Customizing the traffic analyzer log view

Customizes log display by adding, removing, or repositioning columns.

Search the network traffic logs

Locates specific information within stored network traffic log files.

Search tips

Provides tips for effective searching within network traffic logs.

Log rolling

Controls network traffic log file size and space used on the FortiAnalyzer hard disk.

Log rolling settings

Configures network traffic log file size limits, rolling frequency, and FTP uploading.

Vulnerability scan

Modules

References types of vulnerability scans the unit can perform.

Jobs

Creates vulnerability scan report jobs, specifying scan types and devices.

Adding a new vulnerability scan job

Configures a report job for vulnerability scanning.

Reports

Views generated vulnerability scan reports.