Fortiwan Administration Guide
Total Page:16
File Type:pdf, Size:1020Kb
FortiWAN - Handbook VERSION 4.2.4 FORTINET DOCUMENT LIBRARY http://docs.fortinet.com FORTINET VIDEO GUIDE http://video.fortinet.com FORTINET BLOG https://blog.fortinet.com CUSTOMER SERVICE & SUPPORT https://support.fortinet.com FORTIGATE COOKBOOK http://cookbook.fortinet.com FORTINET TRAINING SERVICES http://www.fortinet.com/training FORTIGUARD CENTER http://www.fortiguard.com END USER LICENSE AGREEMENT http://www.fortinet.com/doc/legal/EULA.pdf FEEDBACK Email: [email protected] August 1, 2016 FortiWAN 4.2.4 Handbook Revision 1 38-424-382158-20160801 TABLE OF CONTENTS Introduction 8 Product Benefits 8 Key Concepts and Product Features 10 Scope 11 What's new 13 Document enhancements 19 How to set up your FortiWAN 23 Registering your FortiWAN 23 Planning the network topology 23 WAN, LAN and DMZ 23 Default port mappings 24 WAN link and WAN port 25 WAN types: Routing mode and Bridge mode 25 Near WAN 27 Public IP pass through (DMZ Transparent Mode) 28 Scenarios to deploy subnets 29 VLAN and port mapping 29 IPv6/IPv4 Dual Stack 30 FortiWAN in HA (High Availability) Mode 30 Web UI and CLI Overview 34 Connecting to the Web UI and the CLI 34 Using the Web UI 37 Console Mode Commands 41 Configuring Network Interface (Network Setting) 52 Set DNS server to FortiWAN 52 Configurations for VLAN and Port Mapping 54 MIB fields for WAN links and VLANs 64 System Configurations 68 Summary 68 Optimum Route Detection 71 Port Speed/Duplex Settings 76 Backup Line Settings 76 IP Grouping 77 Service Grouping 78 Busyhour Settings 78 Diagnostic Tools 79 Setting the system time & date 82 Remote Assistance 82 Administration 83 Administrator and Monitor Password 83 RADIUS Authentication 84 Firmware Update 85 Configuration File 86 Maintenance 88 Web UI Port 88 License Control 90 Load Balancing & Fault Tolerance 91 Load Balancing Algorithms 91 Round Robin (weighted) 92 By Connection 92 By Downstream Traffic 94 By Upstream Traffic 94 By Total Traffic 95 By Optimum Route 96 By Response Time 96 By Static 96 By Fixed 96 Hash 97 Outbound Load Balancing and Failover (Auto Routing) 97 Auto Routing Mechanism 97 Fault Tolerance Mechanism 98 Configurations 99 Inbound Load Balancing and Failover (Multihoming) 106 Multihoming 106 Introduction to DNS 106 SwiftDNS 107 How does SwiftDNS work? 107 Prerequisites for Multihoming 108 DNSSEC Support 108 Relay Mode 109 Enable Backup 109 Configurations 109 Scenarios 124 Tunnel Routing 127 How the Tunnel Routing Works 128 Tunnel Routing - Setting 134 How to set up routing rules for Tunnel Routing 138 Tunnel Routing - Benchmark 144 Scenarios 146 Virtual Server & Server Load Balancing 156 WAN Link Health Detection 161 IPSec 164 IPSec VPN Concepts 164 IPSec VPN overview 165 IPSec key exchange 166 How IPSec VPN Works 170 IPSec set up 171 About FortiWAN IPSec VPN 171 173 Limitation in the IPSec deployment 173 Planning your VPN 176 IPSec VPN in the Web UI 177 Define routing policies for an IPSec VPN 191 Establish IPSec VPN with FortiGate 200 Optional Services 208 Firewall 208 NAT 211 Persistent Routing 216 Bandwidth Management 219 Inbound BM and Outbound BM 220 Managing Bandwidth for Tunnel Routing and IPsec 222 Scenarios 223 Connection Limit 228 Cache Redirect 229 Internal DNS 231 DNS Proxy 233 SNMP 236 IP MAC Mapping 237 Statistics 239 Traffic 239 Bandwidth 239 Persistent Routing 240 WAN Link Health Detection 241 Dynamic IP WAN Link 241 DHCP Lease Information 242 RIP & OSPF Status 242 Connection Limit 243 Virtual Server Status 243 FQDN 244 Tunnel Status 244 Tunnel Traffic 245 IPSec 245 Traffic Statistics for Tunnel Routing and IPSec 247 Log 250 View 250 Log format 250 Log Control 258 Notification 259 Enable Reports 262 Reports 263 Create a Report 264 Export and Email 265 Device Status 265 Dashboard 265 Bandwidth 268 CPU 269 Session 270 WAN Traffic 270 WAN Reliability 271 WAN Status 271 TR Reliability 271 TR Status 272 Bandwidth Usage 272 Inclass 273 Outclass 274 WAN 275 Services 276 Internal IP 277 Traffic Rate 278 Function Status 279 Connection Limit 279 Firewall 279 Virtual Server 280 Multihoming 280 Advanced Functions of Reports 281 Drill In 281 Custom Filter 285 Export 288 Report Email 288 Reports Database Tool 290 Reports Settings 297 Reports 298 IP Annotation 298 Dashboard Page Refresh Time 299 Email Server 299 Disk Space Control 299 Appendix A: Default Values 302 Introduction Enterprises are increasingly relying on the internet for delivery of critical components for everyday business operations. Any delays or interruptions in connectivity can easily result in reduced productivity, lost business opportunities and a damaged reputation. Maintaining a reliable and efficient internet connection to ensure the operation of critical applications is therefore key to the success of the enterprise. FortiWAN intelligently balances internet and intranet traffic across multiple WAN connections, providing additional low-cost incoming and outgoing bandwidth for the enterprise and substantially increased connection reliability. FortiWAN is supported by a user-friendly UI and a flexible policy-based performance management system. FortiWAN provides a unique solution that offers comprehensive multi-WAN management that keeps costs down as well as keeping customers and users connected. Product Benefits FortiWAN is the most robust, cost-effective way to: l Increase the performance of your: l Internet access l Public-to-Enterprise access l Site-to-site private intranet l Lower Operating Costs l Increase your network reliability l Enable Cloud / Web 2.0 Applications l Monitor Network Performance Increase Network Performance FortiWAN increases network performance in three key areas: l Access to Internet resources from the Enterprise l Access to Enterprise resources from the Internet l Creation of Enterprise Intranet connections between sites FortiWAN intelligently aggregates multiple broadband and/or leased access lines to significantly increase Internet access performance. FortiWAN makes reacting to network demands fast, flexible and inexpensive. FortiWAN transforms underperforming networks into responsive, cost-effective and easy-to-manage business assets. FortiWAN load balances Internet service requests from Enterprise users, optimally distributing traffic across all available access links. FortiWAN’s 7 different Load Balancing algorithms provide the flexibility to maximize productivity from any network scenario. FortiWAN gives you high-performance inter-site connectivity without the need to lease expensive links such as T1 and T3. FortiWAN aggregates multiple low-cost Internet access links to create site-to-site Virtual Private Line 8 FortiWAN Handbook Fortinet Technologies Inc. Product Benefits Introduction (VPL) Tunnels for LAN-like performance between company locations. By using multiple carriers and media, reliability of these VPL Tunnels can exceed that of traditional engineered carrier links. Substantially Lower Operating Costs Once bandwidth requirements exceed traditional asymmetrical Internet access services (like ADSL) there is a very high jump in bandwidth cost to engineered, dedicated access facilities like DS-1/DS-3. Even Metro Ethernet is a large cost increment where it is available. Adding shared Internet access links is substantially less expensive and delivery is substantially faster. Traditional point-to-point private lines for company intranets are still priced by distance and capacity. Replacing or augmenting dedicated point-to-point services with Virtual Private Line Tunnels reduces costs substantially while increasing available bandwidth and reliability. FortiWAN makes low-cost network access links behave and perform like specially-engineered carrier services at a fraction of the cost. l Deploy DSL services and get DS-3/STM-1-like speed and reliability while waiting for the carrier to pull fiber. l Add and remove bandwidth for seasonal requirements quickly and easily. l Increase bandwidth to web servers and use multiple ISPs without BGP4 management issues. Increase Network Reliability Businesses can no longer afford Internet downtime. FortiWAN provides fault tolerance for both inbound and outbound IP traffic to ensure a stable and dependable network. Even multiple link failures, while reducing available bandwidth, will not stop traffic. By using diverse media (fiber, copper, wireless) and multiple ISPs (Telco, Cableco, 4G), FortiWAN can deliver better than carrier-class “5-9’s” reliability. FortiWAN can be deployed in High Availability mode with fully redundant hardware for increased reliability. Larger FortiWAN models also feature redundant power supplies for further protection from hardware failures. Enable Cloud / Web 2.0 Applications Traditional WAN Optimization products expect that all users connect only to Headquarters servers and Internet gateways over dedicated, symmetric leased lines, but that is already “yesterday’s” architecture. Today users want to mix HQ connectivity with direct Cloud access to Web 2.0 applications like email, collaborative documentation, ERP, CRM and online backup. FortiWAN gives you the flexibility to customize your network, giving you complete control. Direct cloud-based applications to links optimized for them and reduce the bandwidth demand on expensive dedicated circuits. Combine access links and/or dedicated circuits into Virtual Private Line Tunnels that will support the fastest video streaming or video conferencing servers that Headquarters can offer. FortiWAN is designed for easy deployment and rapid integration into any existing network topology. Monitor Network Performance