Fortinet FortiGate 4000 Betriebsanweisung

Seite von 390
Introduction 
About FortiGate Antivirus Firewalls
FortiGate-4000 Administration Guide
01-28006-0012-20041105
 19
An active-passive (A-P) HA cluster, also referred to as hot standby HA, consists of a 
primary FortiGate unit that processes traffic, and one or more subordinate FortiGate 
units. The subordinate FortiGate units are connected to the network and to the 
primary FortiGate unit but do not process traffic.
Active-active (A-A) HA load balances virus scanning among all the FortiGate units in 
the cluster. An active-active HA cluster consists of a primary FortiGate unit that 
processes traffic and one or more secondary units that also process traffic. The 
primary FortiGate unit uses a load balancing algorithm to distribute virus scanning to 
all the FortiGate units in the HA cluster.
Secure installation, configuration, and management
The first time you power on the FortiGate unit, it is already configured with default IP 
addresses and security policies. Connect to the web-based manager, set the 
operating mode, and use the Setup wizard to customize FortiGate IP addresses for 
your network, and the FortiGate unit is ready to protect your network. You can then 
use the web-based manager to customize advanced FortiGate features.
Web-based manager
Using HTTP or a secure HTTPS connection from any computer running Internet 
Explorer, you can configure and manage the FortiGate unit. The web-based manager 
supports multiple languages. You can configure the FortiGate unit for HTTP and 
HTTPS administration from any FortiGate interface.
You can use the web-based manager to configure most FortiGate settings. You can 
also use the web-based manager to monitor the status of the FortiGate unit. 
Configuration changes made using the web-based manager are effective immediately 
without resetting the firewall or interrupting service. Once you are satisfied with a 
configuration, you can download and save it. The saved configuration can be restored 
at any time.
Command line interface
You can access the FortiGate command line interface (CLI) by connecting a 
management computer serial port to the FortiGate RS-232 serial console connector. 
You can also use Telnet or a secure SSH connection to connect to the CLI from any 
network that is connected to the FortiGate unit, including the Internet.
The CLI supports the same configuration and monitoring functionality as the 
web-based manager. In addition, you can use the CLI for advanced configuration 
options that are not available from the web-based manager. 
This Administration Guide contains information about basic and advanced CLI 
commands. For a more complete description about connecting to and using the 
FortiGate CLI, see the FortiGate CLI Reference Guide.