Fortiweb 5.0 Patch 3 Administration Guide December 1, 2013 3Rd Edition Copyright© 2013 Fortinet, Inc
Total Page:16
File Type:pdf, Size:1020Kb
WEB APPLICATION FIREWALL FortiWeb™ 5.0 Patch 3 Administration Guide Courtney Schwartz Contributors: George Csaba Martin Duijm Patricia Siertsema Idan Soen Shiji Li Qin Lu Atsunobu Shiiya Hao Xu Shiqiang Xu Forrest Zhang FortiWeb 5.0 Patch 3 Administration Guide December 1, 2013 3rd Edition Copyright© 2013 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, and FortiGuard® are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance metrics contained herein were attained in internal lab tests under ideal conditions, and performance may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to the performance metrics herein. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any guarantees. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable. Technical Documentation http://help.fortinet.com Knowledge Base http://kb.fortinet.com Forums https://support.fortinet.com/forum Customer Service & Support https://support.fortinet.com Training http://training.fortinet.com FortiGuard Threat Research & Response http://www.fortiguard.com License http://www.fortinet.com/doc/legal/EULA.pdf Document Feedback Email: [email protected] Table of contents Introduction..................................................................................................... 13 Benefits.................................................................................................................. 13 Architecture ........................................................................................................... 14 Scope..................................................................................................................... 14 What’s new...................................................................................................... 16 Documentation enhancements.............................................................................. 20 Key concepts .................................................................................................. 21 Workflow................................................................................................................ 21 Sequence of scans ................................................................................................ 22 Solutions for specific web attacks......................................................................... 26 HTTP/HTTPS threats ....................................................................................... 26 DoS attacks ..................................................................................................... 31 HTTP sessions & security ...................................................................................... 33 FortiWeb sessions vs. web application sessions ............................................ 36 Sessions & FortiWeb HA.................................................................................. 38 Example: Magento & FortiWeb sessions during failover ........................... 38 HA heartbeat & synchronization ............................................................................ 39 Data that is not synchronized by HA ............................................................... 40 Configuration settings that are not synchronized by HA ................................. 41 How HA chooses the active appliance ............................................................ 43 How to use the web UI .......................................................................................... 44 System requirements....................................................................................... 44 URL for access ................................................................................................ 44 Workflow .......................................................................................................... 45 Permissions...................................................................................................... 46 Trusted hosts ............................................................................................. 50 Maximum concurrent administrator sessions.................................................. 50 Global web UI & CLI settings........................................................................... 50 Buttons, menus, & the displays ....................................................................... 54 Deleting entries .......................................................................................... 56 Renaming entries ....................................................................................... 57 Shutdown............................................................................................................... 57 How to set up your FortiWeb......................................................................... 59 Appliance vs. VMware ........................................................................................... 59 Registering your FortiWeb ..................................................................................... 59 Fortinet 3 FortiWeb 5.0 Patch 3 Administration Guide Planning the network topology.............................................................................. 60 How to choose the operation mode ................................................................ 60 Supported features in each operation mode ............................................. 61 Matching topology with operation mode & HA mode................................ 62 Topology for reverse proxy mode.................................................................... 62 Topology for either of the transparent modes ................................................. 64 Topology for offline protection mode .............................................................. 65 Topologies for high availability (HA) clustering ................................................ 67 Connecting to the web UI or CLI ........................................................................... 69 Connecting to the web UI ................................................................................ 70 Connecting to the CLI...................................................................................... 72 Updating the firmware ........................................................................................... 75 Testing new firmware before installing it ......................................................... 75 Installing firmware............................................................................................ 77 Updating firmware on an HA pair............................................................... 81 Installing alternate firmware............................................................................. 82 Booting from the alternate partition ........................................................... 85 Changing the “admin” account password............................................................. 88 Setting the system time & date.............................................................................. 89 Setting the operation mode ................................................................................... 92 Configuring a high availability (HA) FortiWeb cluster............................................. 95 Replicating the configuration without FortiWeb HA (external HA) ................. 105 Configuring the network settings......................................................................... 109 Network interface or bridge? ......................................................................... 109 Configuring the network interfaces.......................................................... 111 Adding VLAN subinterfaces ............................................................... 115 Link aggregation ...................................................................................... 118 Configuring a bridge (V-zone) .................................................................. 120 Adding a gateway .......................................................................................... 123 Configuring DNS settings .............................................................................. 128 Connecting to FortiGuard services...................................................................... 132 Choosing the virus signature database & decompression buffer.................. 136 Accessing FortiGuard via a web proxy.......................................................... 138 How often does Fortinet provide FortiGuard updates for FortiWeb?............ 138 Scheduling automatic signature updates ...................................................... 139 Manually initiating update requests ............................................................... 142 Uploading signature & geography-to-IP updates.........................................