EasyManua.ls Logo

Fortinet FortiWAN User Manual

Fortinet FortiWAN
311 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
FortiWANHandbook
VERSION 4.2.1

Table of Contents

Other manuals for Fortinet FortiWAN

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiWAN and is the answer not in the manual?

Fortinet FortiWAN Specifications

General IconGeneral
Firewall ThroughputVaries by model
Concurrent SessionsVaries by model
IPsec VPN ThroughputVaries by model
SSL VPN ThroughputVaries by model
High AvailabilityYes
Load BalancingYes
Traffic ShapingYes
ThroughputVaries by model
IPSec VPN TunnelsVaries by model
SSL VPN UsersVaries by model
WAN InterfaceMultiple (varies by model)
LAN InterfaceMultiple (varies by model)
Routing ProtocolsBGP, OSPF, RIP
ManagementCLI
Power SupplyVaries by model

Summary

Introduction

Product Benefits

Details the advantages of FortiWAN, focusing on performance, cost, reliability, and application support.

Key Concepts and Product Features

WAN load balancing (WLB)

Explains the mechanisms for managing and distributing workload across multiple WAN links for optimal performance.

Installation

Provides initial setup instructions for the FortiWAN appliance, covering network topology and interface configuration.

Bidirectional load balancing

Explains how FortiWAN handles network data transmission bidirectionally, covering both inbound and outbound sessions.

Auto Routing (Outbound Load Balancing)

Describes how FortiWAN distributes traffic across multiple WAN links using load balancing algorithms for outbound traffic.

Multihoming (Inbound Load Balancing)

Explains how FortiWAN balances incoming requests across multiple WAN links to improve user response and network reliability.

Fall-back or Fail-over

Details how FortiWAN detects and handles WAN link failures, allowing automatic switch-over to redundant links.

What's new

FortiWAN 4.2.1

Lists bug fixes and new features introduced in FortiWAN version 4.2.1.

FortiWAN 4.2.0

Details new features and enhancements in FortiWAN version 4.2.0, including IPSec VPN and Tunnel Routing.

Document enhancements

FortiWAN 4.2.1

Details enhancements and changes made to the documentation for FortiWAN 4.2.1.

FortiWAN 4.2.0

Lists document enhancements and changes for FortiWAN 4.2.0, including new pages and updated content.

How to set up your FortiWAN

Registering your FortiWAN

Instructions for registering your Fortinet product to access customer services like firmware updates and technical support.

Planning the network topology

Guides on planning the network topology for load balancing and fault tolerance between different networks.

WAN, LAN and DMZ

Defines Wide Area Network (WAN), Local Area Network (LAN), and Demilitarized Zone (DMZ) concepts in networking.

Default port mappings

Describes the default mapping of physical ports on FortiWAN appliances to WAN, LAN, or DMZ network types.

WAN link and WAN port

Explains WAN links for Internet access and WAN ports as physical network interfaces on FortiWAN.

WAN types: Routing mode and Bridge mode

Details the five types of network connections FortiWAN supports for WAN ports: Routing and Bridge modes.

Near WAN

Defines the 'near WAN' area and how it differs between routing and bridge modes for traffic management.

Public IP pass through (DMZ Transparent Mode)

Explains Public IP Pass-through functionality, allowing two segments to act as one IP subnetwork without NAT or routing.

Scenarios to deploy subnets

Presents four deployment scenarios for subnets in WAN, DMZ, WAN and DMZ, or on localhost.

VLAN and port mapping

Describes how to assign physical ports as WAN, LAN, or DMZ, supporting VLAN tagging for network segmentation.

IPv6/IPv4 Dual Stack

Details the support for IPv6/IPv4 Dual Stack deployment in various modes and configuration aspects.

FortiWAN in HA (High Availability) Mode

Explains how to set up FortiWAN in HA mode for double-device backup, ensuring network fault tolerance and non-stop service.

Web UI and CLI Overview

Connecting to the Web UI and the CLI

Provides instructions on how to connect to FortiWAN's Web UI and CLI for initial setup and management.

Default LAN port

Describes the default LAN port configuration and access method for the FortiWAN Web UI.

Access via a computer that matches the default LAN IP address

Steps to access the Web UI using a computer configured within the default LAN subnet.

Access via a computer that does not match the default LAN IP address

Procedure to access Web UI via CLI when the computer's subnet does not match the default LAN IP.

To connect to the CLI

Instructions for connecting to the Command Line Interface (CLI) using a terminal emulator.

Using the Web UI

Web UI Overview

Describes the layout of the FortiWAN Web UI, including header, navigation menu, and content pane.

Multi-user Login

Explains FortiWAN's Web UI support for multiple concurrent logins and its limitations.

Basic concept to configure via Web UI

The common operation buttons

Explains common operation buttons used for managing rules, filters, and policies within the FortiWAN Web UI.

Configuration on When

Details how to filter traffic based on different time periods, utilizing predefined busyhour settings.

Configuration on Source and Destination

Describes filtering traffic based on specified source or destination IP addresses, ranges, or subnets.

Console Mode Commands

help: Displays the help menu

Shows how to display the help menu and a list of available console commands.

arp: Manipulate (add and delete entries) or display the IPv4 network neighbor cache

Explains ARP command for managing IPv4 network neighbor cache entries.

arping: Discover and prob hosts on a network by sending ARP requests

Describes how to use arping to discover network hosts by sending ARP requests.

diagnose: Get diagnostic information of FortiWAN hardware

Provides commands to retrieve diagnostic information about FortiWAN hardware components like CPU, disk, and NICs.

disablefw: Disable all the firewall rules

Command to disable all configured firewall rules, useful for rescuing Web UI access.

enforcearp: Force FortiWAN's surrounding machines to update their ARP tables

Command to force update ARP tables on surrounding machines using gratuitous ARP packets.

export: Display configurations of NAT, Multihoming and Virtual Server

Command to export configurations for NAT, Multihoming, and Virtual Server.

get: Get the version and serial number information of a FortiWAN apparatus

Command to retrieve system status, including firmware version and serial number.

httpctl: Control the web server that Web UI is running on

Commands to control the FortiWAN Web UI web server, such as restart, showport, and setport.

import: Import the configurations of NAT, Multihoming and Virtual Server

Command to import NAT, Multihoming, and Virtual Server configurations.

init_reports_db: Set Reports database to factory default

Command to reset the FortiWAN Reports database to factory default, deleting all report data.

jframe: Enable jumbo frames to support specified MTU size for FortiWAN's LAN ports

Enables jumbo frames on LAN ports by specifying MTU size, supporting larger packet sizes.

logout: Exit Console mode

Command to exit the console mode, with a confirmation prompt.

ping: Test network connectivity

Tests network connectivity by pinging a host, specifying WAN, LAN, or DMZ link.

reactivate: Reactivate the FortiWAN apparatus

Command to reset system configurations to factory default and revert to base bandwidth.

reboot: Restart FortiWAN

Command to restart the FortiWAN appliance immediately or after a specified delay.

resetconfig: Reset system configurations to factory defaults

Resets system configurations to factory defaults, including network settings and port mappings.

resetpasswd: Reset FortiWAN's Administrator and Monitor passwords to factory default

Resets Administrator and Monitor passwords to their factory default values.

setupport: Configure the transmission mode for all the FortiWAN port(s)

Configures port transmission mode, speed, and duplex settings.

shownetwork: Show the current status of all the WAN links available

Displays the current status of all available WAN links, including type, bandwidth, and IP information.

showtrstat: Display tunnel status

Displays the status of specified tunnel groups within Tunnel Routing.

shutdown: Shut the FortiWAN system down

Command to shut down the FortiWAN system, terminating all processes and services.

sslcert: Set or unset SSL certificate for FortiWAN WebUI

Manages SSL certificates for FortiWAN Web UI, including setting, showing, and resetting certificates.

sysctl: Controls the system parameters - [sip-helper] and [h323-helper]

Controls system parameters for SIP and H.323 application gateway modules.

sysinfo: Display usage FortiWAN's CPU, memory and disk

Displays the usage statistics for FortiWAN's CPU, memory, and disk space.

Configuring Network Interface (Network Setting)

tcpdump: Dump network traffic

Captures and analyzes network traffic packets for debugging purposes.

traceroute: Shows the packet routes between FortiWAN's port to a specified destination

Traces packet routes from FortiWAN ports to a specified destination host.

Set DNS server to FortiWAN

Configures DNS servers for FortiWAN to resolve domain names for service access.

Configurations for VLAN and Port Mapping

Details how to map physical ports to WAN, LAN, or DMZ, supporting VLAN tagging for network segmentation.

Redundant LAN/DMZ Port and Aggregated LAN/DMZ Port

Explains the necessity of redundant and aggregated ports for HA mode and increased bandwidth.

Configuring your WAN

Guides on configuring WAN settings, including basic settings, subnet, and static routing for various WAN link types.

Basic Setting & Basic Subnet & Static Routing Subnet

Covers essential settings for WAN links, including basic subnet and static routing configurations.

Automatic addressing within a basic subnet

Explains mechanisms for automatic IP address allocation for hosts in DMZ and LAN subnets.

DHCP Relay

Describes the DHCP Relay function for forwarding DHCP requests and responses between subnets.

IPv6 Automatic Addressing

Details stateless (SLAAC) and stateful (DHCPv6) mechanisms for IPv6 address allocation.

Configurations for a WAN link in Routing Mode

Provides detailed steps for configuring a WAN link in Routing Mode, including basic settings and subnets.

Examples of Basic Subnets

Illustrates configurations for basic subnets in WAN, DMZ, and WAN/DMZ scenarios.

Examples of Static Routing Subnets

Provides examples of configuring static routing subnets in WAN and DMZ.

Configurations for a WAN link in Bridge Mode: Multiple Static IP

Guides on configuring WAN links in Bridge Mode with multiple static IP addresses.

Configurations for a WAN link in Bridge Mode: One Static IP

Details configuring WAN links in Bridge Mode with a single static IPv4 address.

Configurations for a WAN link in Bridge Mode: DHCP

Explains configuring WAN links in Bridge Mode using DHCP client for dynamic IP address assignment.

LAN Private Subnet

Details the configuration of private subnets for LAN ports, essential for internal network deployment.

RIP

Describes FortiWAN's support for Routing Information Protocol (RIP) v1 and v2 for network routing.

OSPF

Explains FortiWAN's support for Open Shortest Path First (OSPF) for assigning LAN port router preferences.

VRRP

Details FortiWAN's implementation of VRRP for virtual router redundancy and failover.

WAN/DMZ Private Subnet

Provides topology structures for private subnets in WAN and DMZ, detailing configuration options.

Deployment Scenarios for Various WAN Types

Presents network scenarios for different WAN types and explains FortiWAN integration into existing networks.

WAN Type: Bridge Mode with a Single Static IP

Details a common WAN scenario using a single static IP address with a bridge-mode ISP connection.

WAN Type: Routing Mode Example 1

Illustrates a typical scenario where ISP provides a network segment, with servers deployed in DMZ or between ATU-R and FortiWAN.

WAN Type: Routing Mode Example 2

Shows a scenario with a private subnet between WAN router and FortiWAN, requiring a router for the DMZ public IP subnet.

WAN Type: Routing Mode Example 3

Illustrates a scenario with WAN links connected to routers via private IPs, and a public IP subnet behind a core switch.

System Configurations

Summary

Provides an overview of system information, peer information, and WAN link states, crucial for monitoring and HA status.

System Information / Peer Information

Details system information like firmware version, model, serial number, and peer information in HA mode.

WAN Link State

Shows the status of enabled WAN links, color-coded for active, backup, failed, or disabled states.

Optimum Route Detection

Explains how FortiWAN resolves inefficient transmission due to ISP peering issues using route detection.

Port Speed/Duplex Settings

Enables configuration of port speed and duplex transfer modes, with options for auto-detection or manual settings.

Backup Line Settings

Details settings for backup lines, including threshold parameters, rules, and algorithms for activation.

IP Grouping

Explains how to create and manage IP groups for efficient use in various service submenus.

Service Grouping

Describes creating and managing service groups for ICMP, TCP/UDP ports, applications, and server ports.

Busyhour Settings

Crucial for bandwidth management, defining busy and idle hours for traffic shaping.

Diagnostic Tools

Provides tools for diagnosing network issues, including IPv4 and IPv6 ARP, IP conflict tests, and session cleanup.

Load Balancing & Fault Tolerance

WAN Link Fault Tolerance

Details how multiple WAN links increase reliability and prevent service interruptions during link failures.

Load Balancing Algorithms

Explains seven auto-routing algorithms for distributing traffic among multiple WAN links based on various criteria.

Outbound Load Balancing and Failover (Auto Routing)

Describes how Auto Routing balances outbound traffic across WAN links and handles failures.

Inbound Load Balancing and Failover (Multihoming)

Explains Multihoming technique for DNS fault tolerance and load balancing of inbound traffic across multiple ISP links.

Tunnel Routing

Explains tunneling techniques for data transmission, link aggregation, and fault tolerance over multiple WAN links.

How the Tunnel Routing Works

Explains the process of how Tunnel Routing delivers packets to remote private networks via the internet using GRE tunnels.

Tunnel Routing - Setting

Details the steps to set up Tunnel Routing, including basic settings, tunnel groups, and routing rules.

Tunnel Routing - Benchmark

Provides tools to evaluate the quality of tunnels by measuring run trip time, packet loss, and bandwidth.

Scenarios

Presents various scenarios for Tunnel Routing deployment, illustrating configurations for different network setups.

Virtual Server & Server Load Balancing

Describes Virtual Server functionality for acting as multiple servers and providing load balancing for inbound traffic.

WAN Link Health Detection

Details how to set up specific health detection criteria for WAN links to monitor their reliability.

IPSec VPN Concepts

IPSec VPN overview

Introduces the fundamental concepts of IPSec VPN, including tunnels, security associations, and key exchange.

IPSec set up

Provides configurations for setting up FortiWAN IPSec VPN, covering Tunnel mode and Transport mode.

About FortiWAN IPSec VPN

Lists the specifications of FortiWAN's IPSec VPN, highlighting supported features and limitations.

Limitation in the IPSec deployment

Explains the limitation of establishing ISAKMP SAs due to IP address mapping restrictions between devices.

Planning your VPN

Guides on planning VPN topology, considering site locations, networks, VPN devices, and interface communication.

IPSec VPN in the Web UI

Details configurations for IPSec VPNs between FortiWAN units using Web UI.

Configurations of IKE Phase 1

Defines parameters for IKE Phase 1 negotiation to establish ISAKMP Security Associations.

Configurations of IKE Phase 2

Defines parameters for IKE Phase 2 negotiation to establish IPSec Security Associations.

Define routing policies for an IPSec VPN

Explains how to define Auto Routing and Tunnel Routing policies for IPSec VPN traffic.

Define Auto Routing and NAT policies for an IPSec Tunnel-mode VPN

Details Auto Routing and NAT policies for IPSec Tunnel-mode VPN traffic.

Define NAT policies for IKE negotiation and IPSec communication packets

Explains NAT policies for IKE negotiation and IPSec communication packets to ensure proper VPN functionality.

Define IPSec parameters

Sets up Phase 1 and Phase 2 configurations for IPSec tunnel mode VPNs.

Define Tunnel Routing policies for IPSec communications

Configures Tunnel Routing policies for IPSec Transport mode VPNs, enabling secure communication.

Optional Services

Firewall

Details how to set up the firewall with unlimited rules, prioritizing rules for higher precedence.

Example 1

Provides an example of firewall rules for filtering packets from WAN, DMZ, and LAN.

Example 2

Illustrates firewall rules for filtering packets based on various source, destination, and service criteria.

NAT

Explains NAT functionality for translating private IP addresses to public IPs for internal to external communication.

Default Rules

Explains the automatically generated NAT rules based on WAN link network settings for traffic translation.

1-to-1 NAT Rules

Details 1-to-1 NAT rules for fixed mapping between internal and external IP addresses for IPv4.

Persistent Routing

Secures subsequent connections by maintaining source and destination pairs for specific applications.

IPv4/IPv6 Web Service Rules

Sets persistent routing rules for HTTP and HTTPS connections based on source IP to destination ports.

IPv4/IPv6 IP Pair Rules

Sets persistent routing rules for IPv4/IPv6 addresses, matching source and destination pairs.

Bandwidth Management

Allocates bandwidth to applications, securing critical applications and managing traffic flow.

Inbound BM and Outbound BM

Divides Bandwidth Management into inbound and outbound classes for traffic control on WAN ports.

Managing Bandwidth for Tunnel Routing and IPsec

Controls traffic for Tunnel Routing and IPSec VPN by managing bandwidth before encapsulation.

Example 1 Inbound BM

Illustrates inbound bandwidth management scenarios for email, LAN zone, and FTP server traffic.

Example 2 Inbound BM

Provides inbound bandwidth management examples for LAN zone downloads and remote subnet uploads.

Example 3 Outbound BM

Illustrates outbound bandwidth management scenarios for email, FTP server, and remote subnet uploads.

Connection Limit

Restricts the number of connections from a source IP to prevent network congestion and detect attacks.

Cache Redirect

Redirects web requests to external cache servers to save data retrieval time.

Internal DNS

Provides a built-in DNS server for managing internal domain names and resolving external domains.

DNS Proxy

Dynamically assigns DNS servers based on WAN link loading to resolve traffic congestion issues.

SNMP

Manages network devices by providing system information and sending event notifications to an SNMP manager.

IP MAC Mapping

Specifies IP-MAC table entries to classify traffic based on peak hours and idle hours.

Statistics

Traffic

Displays real-time traffic statistics sorted by WAN link and traffic direction (inbound/outbound).

Persistent Routing

Shows details of persistent routing status, allowing viewing and manual reset of connections.

WAN Link Health Detection

Provides insight into WAN link health, allowing setup of specific detection criteria for reliability.

Dynamic IP WAN Link

Shows details of dynamic IP WAN links, including IP address obtained via PPPoE or DHCP.

DHCP Lease Information

Displays DHCP lease assignments, including IP, MAC address, client-hostname, and expiration time.

RIP & OSPF Status

Shows RIP and OSPF routing status based on network settings.

Connection Limit

Inspects connection numbers in real-time to manage limits and avoid network congestion.

Virtual Server Status

Displays status and statistics regarding virtual servers defined in the system.

FQDN

Displays IPv4 and IPv6 addresses of FQDNs connected via FortiWAN.

Tunnel Status

Monitors tunnel routing status, viewing statistics like 3-Second and 1-Minute data.

Tunnel Traffic

Collects inbound/outbound traffic statistics for tunnel routing over various time periods.

IPSec

Reports usages and states of configured IPSec Security Associations.

Traffic Statistics for Tunnel Routing and IPSec

Analyzes traffic transferred through Tunnel Routing or IPSec, comparing BM logs and reports.

Log

View

Allows viewing system events by selecting log types like System, Firewall, NAT, and IPSec logs.

Log format

Describes the format of log entries, including timestamp, log type, and log content.

Log Control

Configures control sets to forward logs via FTP, E-mail, and Syslog for archiving and analysis.

Notification

Sets up methods for sending system event notifications via E-mail and SNMP trap.

Enable Reports

Embedded Reports

Enables embedded reports by processing logs directly to the built-in hard disk database.

Stand-alone Reports

Enables pushing logs to a specified stand-alone reports server via UDP.

Events

Selects log types for FortiWAN to send to Reports for analysis.

Reports

Provides monitoring and traffic pattern analysis tools for WAN connections and traffic statistics.

Create a Report

Guides users on how to generate custom reports for analyzing traffic patterns and network statistics.

Export and Email

Allows exporting reports in PDF or CSV format and sending them via email as attachments.

Device Status

Shows a top-level view of traffic analysis, including categories like Bandwidth, CPU, Session, and WAN links.

Dashboard

Provides a chart-based summary of FortiWAN's system information and hardware states.

Session

Reports the distribution of sessions (connections) by date range, helping to determine the correct FortiWAN model.

CPU

Shows the distribution of CPU usage by date range, indicating traffic management load.

Memory

Displays FortiWAN's memory usage distribution by date range.

WAN Link State

Displays the state of every FortiWAN's WAN link, color-coded for status indication.

Peer Information

Provides information about the state of the slave unit for HA deployment.

WAN Reliability

Shows statistics on failures occurred on FortiWAN WAN links.

WAN Status

Displays the status of every FortiWAN's WAN link, defining states like OK, Fail, and Disabled.

TR Reliability

Shows statistics on failures occurred on FortiWAN's TR links, referencing the FortiWAN User Manual.

Bandwidth Usage

Analyzes traffic distribution by date range, providing insights into bandwidth usage for policy management.

Inclass

Shows statistics of inbound classes defined in FortiWAN's Bandwidth Management function.

Outclass

Displays statistics of outbound classes defined in FortiWAN's Bandwidth Management function.

WAN

Shows statistics of traffic passed through FortiWAN via WAN Links.

Services

Displays statistics of traffic passed through FortiWAN by various services.

Internal IP

Shows statistics of traffic passed through FortiWAN by Internal IP addresses.

Traffic Rate

Displays statistics of traffic passed through FortiWAN by Traffic Rate.

Function Status

Monitors the status of major FortiWAN functions like Connection Limit, Firewall, Virtual Server, and Multihoming.

Connection Limit

Limits the number of connections from each source IP to prevent network congestion and detect attacks.

Firewall

Controls network access and denies illegal access by limiting network access by service, source IP, or destination IP.

Virtual Server

Links multiple internal servers to external network public IP addresses for server load balancing.

Multihoming

Performs load balancing and fault tolerance for inbound traffic using multiple WAN links.

Advanced Functions of Reports

Provides advanced functions like Drill In and Custom Filter for querying reports with complex conditions.

Drill In

Allows drilling down into traffic data statistics by selecting query conditions like Service, Internal IP, etc.

Custom Filter

Allows users to apply custom filters for querying bandwidth usage reports based on specific requirements.

Export

Allows exporting reports in PDF or CSV format.

Report Email

Configures email server settings for sending reports and system alerts via email.

Reports Database Tool

Manages FortiWAN Reports database, including installation, backup, restore, and delete operations.

Setting

Specifies the database location and port number for managing the Reports database.

Backup

Provides functionality to back up Reports data from the database for a specified date range.

Restore

Allows restoring Reports data to the database from backup files.

Delete

Deletes data from the Reports database for a specified date range.

Reports Settings

Manages Reports database, disk space, and SMTP server settings for email reports.

IP Annotation

Allows users to add notes to IP addresses shown in Reports for easier recognition.

Dashboard Page Refresh Time

Sets the refresh interval for the dashboard to sync with the latest data.

Email Server

Configures email server settings for sending reports and system alerts via email.

Disk Space Control

Monitors disk space usage, triggering alerts or purging data when low.

Disk Space Status

Displays current disk space usage via a pie chart and statistics.

Appendix A: Default Values

FortiWAN Log-ins

Lists the default accounts and passwords for accessing FortiWAN via Web UI, CLI, and SSH.

WAN Link Health Detection Default Values

Provides default values for WAN link health detection, including fixed server IPs and port settings.

Network default Values (FortiWAN 200B)

Shows default network settings for FortiWAN 200B, including WAN and LAN port configurations.

Service Category Default Values

Lists default values for various service categories like Firewall, Persistent Routing, and Auto Routing.

Related product manuals