Professional Documents
Culture Documents
System Guide
FG 4.0 MR2
Contents
Contents
Overview of FortiGate-VM
Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Architecture of the FortiGate-VM . . . . . . . . . . . . . . . . . . . . . . . 4
Licensing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Registering your Fortinet product . . . . . . . . . . . . . . . . . . . . . . . 4
Customer service & technical support . . . . . . . . . . . . . . . . . . . . 5
Training . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Documentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Comments on Fortinet technical documentation . . . . . . . . . . . . . 5
Installing FortiGate-VM
Installation Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Installing FortiGate-VM . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Getting the FortiGate-VM software . . . . . . . . . . . . . . . . . 8
Deploying the FortiGate-VM software . . . . . . . . . . . . . . . . 8
Logging in . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Configuring Virtual Networks . . . . . . . . . . . . . . . . . . . . . . . . 12
Configuring Network Adapters . . . . . . . . . . . . . . . . . . . . . 12
Configuring the number of CPUs . . . . . . . . . . . . . . . . . . . . . . 13
Powering on FortiGate-VM . . . . . . . . . . . . . . . . . . . . . . . . . 14
Uploading the License . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Contents
Overview of FortiGate-VM
Prerequisites
Overview of FortiGate-VM
Fortinet is the leading provider of ASIC-accelerated unified threat management (UTM)
solutions that provide a comprehensive suite of security services at the highest levels of
network protection and performance.
This chapter provides an overview of the FortiGate-VM and the prerequisites to installing
the FortiGate-VM.
Prerequisites
This guide assumes that the reader has a thorough understanding of VMware concepts,
procedures, and terminology. VMware vSphere Hypervisor (ESX/ESXi) software MUST
be installed prior to installing FortiGate-VM.
See Table 1 for requirements.
Table 1: FortiGate-VM requirements.
Requirement
Value
Memory
CPU
10/100/1000 Interfaces
10 GB E Interface
Supported
Storage
A minimum of 30GB
Overview of FortiGate-VM
VLAN1
Internet
VM1
VLAN2
Virtual switch
VM2
VLAN3
VM3
FortiGate-VM
FortiGuard Services
Management Computer
Physical NIC
Licensing
When you placed an order for FortiGate-VM, a registration number is sent to the email
address used on the order form. Use the registration number to register with FortiCare
(www. support.fortinet.com) and to obtain a license file, which is used to activate the
FortiGate-VM.
For a new installations, the CLI and Web Config are locked until you enter a license. Once
a license is entered and validated by FortiGuard services, the CLI and Web Config are
unlocked and fully functional.
If FortiGuard discovers that the license is expired, pirated, or cloned, FortiGuard returns
an invalid status back to the FortiGate-VM and the device remains in locked state.
Overview of FortiGate-VM
Training
Fortinet Training Services provides classes that orient you quickly to your new equipment,
and certifications to verify your knowledge level. Fortinet provides a variety of training
programs to serve the needs of our customers and partners world-wide.
To learn about the training services that Fortinet provides, visit the Fortinet Training
Services web site at http://campus.training.fortinet.com, or email them at
training@fortinet.com.
Documentation
The Fortinet Technical Documentation web site, http://docs.fortinet.com, provides the
most up-to-date versions of Fortinet publications, as well as additional technical
documentation such as technical notes.
Fortinet Knowledge Base
The Fortinet Knowledge Base provides additional Fortinet technical documentation, such
as troubleshooting and how-to-articles, examples, FAQs, technical notes, and more. Visit
the Fortinet Knowledge Base at http://kb.fortinet.com.
Documentation
Overview of FortiGate-VM
Installing FortiGate-VM
Installation Overview
Installing FortiGate-VM
FortiGate-VM software must be installed on the VMware vSphere Hypervisor
(ESX/ESXi) server that is used to host the FortiGate-VM device. The installation
instructions for FortiGate-VM assume you are familiar with VMware ESXi server and
terminology. Refer to http://www.vmware.com/products/vsphere-hypervisor/index.html for
information.
This chapter provides the details of installing the FortiGate-VM.
Installation Overview
Figure 2 outlines the basic steps of installing the FortiGate-VM.
Figure 2: Overview of Installing FortiGate-VM
Set up VMware vSphere
Hypervisor (ESXi) server
No
Yes
Installing FortiGate-VM
Installing FortiGate-VM
Installing FortiGate-VM
Ensure the following prerequisites are met before installing FortiGate-VM:
The VMware vSphere Client is installed on the Management Computer. This could
be a desktop or a laptop that will be used to manage the devices.
A valid internet connection between the FortiGuard and the FortiGate is necessary in
order to validate the FortiGate-VM license. If you do not have a valid license, your
device will not be functional.
Description
datadrive.vmdk
Virtual disk.
FortiGate-VM.hw04.ovf
FortiGate-VM.ovf
fgt.vmdk
Virtual disk.
Installing FortiGate-VM
Installing FortiGate-VM
Installing FortiGate-VM
Installing FortiGate-VM
7 Select the format you want to store the virtual disks and click Next.
10
Installing FortiGate-VM
Logging in
8 Map the networks used in the FortiGate-VM to the networks in your inventory. For each
Source Network, select a Destination Network from the drop-down list.
Figure 6: Map networks.
Logging in
After installing the FortiGate-VM, log in and configure the FortiGate-VM.
To log in to the FortiGate-VM:
1 Open the Client.
2 Enter the IP address, user name, and password and click Login.
11
Installing FortiGate-VM
3 When you login, the first screen shows the Getting Started tab. From here you can do
the following:
In the left pane, click the + (plus) sign and you will see the FortiGate-VM you added
during deployment.
Click Edit virtual machine settings to edit details of the CPUs, interfaces, video
cards and other hardware information.
Do not power on the FortiGate-VM if you want to configure the ports on the ESXi
server.
Network Mapping:
ESXi Server vNetwork VM Port
Group
FortiGate-VM
Settings Network
Adapter
FortiGate-VM OS Port
eth0
VM Network 1
Network Adapter 1
Port 1
eth1
VM Network 2
Network Adapter 2
Port 2
12
Installing FortiGate-VM
13
Powering on FortiGate-VM
Installing FortiGate-VM
3 Click OK.
Powering on FortiGate-VM
Once FortiGate-VM has been deployed, you can power on the virtual machine and log in
using the Console.
In the Console, you are extremely limited to the type of commands you can enter until a
valid license is entered through the Web Config. You can configure the internal interface,
system DNS, and the static router.
To power on FortiGate-VM
1 Open the vSphere Client and enter the IP address, user name, and password. Click
Login.
2 Select the FortiGate-VM from the tree.
3 In the Getting Started tab, click Power on the virtual machine.
4 Select the Console tab. It may take a few minutes for the FortiGate-VM software to
format.
5 At the FortiGate-VM login prompt, type admin. There is no password.
6 Configure the FortiGate internal interface. Type:
config system interface
edit port1
set ip <intf_ip>/<netmask_ip>
end
7 Configure the primary and secondary DNS server IP addresses. Type:
config system dns
set primary <dns-server_ip>
set secondary <dns-server_ip>
end
8 Configure the default gateway. Type:
config router static
edit 1
set device port1
set gateway <gateway_ip>
end
Note: To access Web Config in the web browser, only https is allowed; http is not allowed.
14
Installing FortiGate-VM
15
Installing FortiGate-VM
CAUTION: You will need to set up firewall policies in FortiGate-VM. There are no firewall
policies by default; therefore no traffic will flow until firewall policies are created.
For more information on how to set up and use the FortiGate-VM features, see the
FortiGate Administration Guide or visit http://docs.fortinet.com/fgt.html for all FortiOS
documentation.
16