This video goes over some of the steps and explains how to import policy into the FortiManager from a FortiGate that has already been unleashed into the wild.
This video goes over some of the steps and explains how to import policy into the FortiManager from a FortiGate that has already been unleashed into the wild.
There are a lot of folks out there spending a lot of money on SSL VPN solutions when they have the feature built into the FortiGate already. Watch this video discussing this.
The FortiAnalyzer unit has two operation modes: Analyzer and Collector. For more information, see Two operation modes on page 19.
When FortiAnalyzer is operating in Collector mode, the SQL database is disabled by default so logs that require the SQL database are not available in Collector mode unless the SQL database is enabled.
To change the operation mode:
You can back up the system of one FortiAnalyzer model, and then use the CLI and the FTP, SCP, or SFTP protocol to migrate the settings to another FortiAnalyzer model.
If you encrypted the FortiAnalyzer configuration file when you created it, you need the password to decrypt the configuration file when you migrate the file to another FortiAnalyzer model.
To migrate the FortiAnalyzer configuration:
execute migrate all-settings <ftp | scp | sftp> <server> <filepath> <user> <password> [cryptpasswd]
You can use the following procedure to restore your FortiAnalyzer configuration from a backup file on your management computer.
To restore the FortiAnalyzer configuration:
Choose Backup File | Select Browse to find the configuration backup file you want to restore, or drag and drop the file onto the dialog box. |
Password | Type the encryption password, if applicable. |
Overwrite current IP and routing settings | Select the checkbox to overwrite the current IP and routing settings. |
Fortinet recommends that you back up your FortiAnalyzer configuration to your management computer on a regular basis to ensure that, should the system fail, you can quickly get the system back to its original state with minimal affect to the network. You should also perform a back up after making any changes to the FortiAnalyzer configuration or settings that affect the connected devices.
Fortinet recommends backing up all configuration settings from your FortiAnalyzer unit before upgrading the FortiAnalyzer firmware.
To back up the FortiAnalyzer configuration:
To take advantage of the latest features and fixes, the FortiAnalyzer firmware can be updated. For information about upgrading your FortiAnalyzer device, see the FortiAnalyzerUpgrade Guide or contact Fortinet Customer Service & Support.
Backup the configuration and database before changing the firmware of your FortiAnalyzer unit. Changing the firmware to an older or incompatible version may reset the configuration and database to the default values for that firmware version, resulting in data loss. For information on backing up the configuration, see Backing up the system on page 160.
Before you can download firmware updates for your FortiAnalyzer unit, you must first register your FortiAnalyzer unit with Customer Service & Support. For details, go to https://support.fortinet.com/ or contact Customer Service & Support.
To update the FortiAnalyzer firmware:
Optionally, you can upgrade firmware stored on an FTP or TFTP server using the following CLI command:
execute restore image {ftp | tftp} <file path to server> <IP of server> <username on server> <password>
For more information, see the FortiAnalyzerCLI Reference.
You can either manually set the FortiAnalyzer system time or configure the FortiAnalyzer unit to automatically keep its system time correct by synchronizing with a Network Time Protocol (NTP) server.
To configure the date and time:
System Time | The date and time according to the FortiAnalyzer unit’s clock at the time that this pane was loaded or when you last clicked the Refresh button. | ||||
Time Zone | Select the time zone in which the FortiAnalyzer unit is located and whether or not the system automatically adjusts for daylight savings time. | ||||
Update Time By | Select Set time to manually set the time, or Synchronize with NTP Server to automatically synchronize the time. | ||||
Set Time | Manually set the data and time. | ||||
Select Date | Set the date from the calendar or by manually entering it in the format: YYYY/MM/DD. | ||||
Select Time | Select the time. | ||||
Synchronize with NTP Server | Automatically synchronize the date and time. | ||||
Sync Interval | Enter how often, in minutes, the device should synchronize its time with the NTP server. For example, entering 1440 causes the Fortinet unit to synchronize its time once a day. | ||||
Server | Enter the IP address or domain name of an NTP server. Click the plus icon to add more servers. To find an NTP server that you can use, go to http://www.ntp.org. | ||||