ABACAS, APSecure, FortiASIC, FortiBIOS, FortiBridge, FortiClient,
FortiGate, FortiGuard, FortiGuard-Antispam, FortiGuard-Antivirus,
FortiGuard-Intrusion, FortiGuard-Web, FortiLog, FortiAnalyzer,
FortiManager, Fortinet, FortiOS, FortiPartner, FortiProtect, FortiReporter,
FortiResponse, FortiShield, FortiVoIP, and FortiWiFi are trademarks of
Fortinet, Inc. in the United States and/or other countries. The names of
actual companies and products mentioned herein may be the trademarks
of their respective owners.
Regulatory compliance
FCC Class A Part 15 CSA/CUS
Caution: If you install a battery that is not the correct type, it could
explode. Dispose of used batteries according to local regulations.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-200609259
Contents
FortiAnalyzer Version 3.0 MR3 Administration Guide
1005-30003-0082-20060925
Introduction The FortiAnalyzer Unit
Introduction
FortiAnalyzer units are network appliances that provides robust reporting, data
analysis and integrated log collection tools. Detailed log reports provide historical
as well as current analysis of network traffic, such as email, FTP and web
browsing activity, to help identify security issues and reduce network misuse and
abuse.
The FortiAnalyzer unit provides a robust selection of reporting tools from detailed
reports that can be scheduled or generated on demand, to basic traffic sniffing
and real-time network monitoring.
This section introduces you to the FortiAnalyzer appliance and includes the
following topics:
•The FortiAnalyzer Unit
•About this guide
•FortiAnalyzer documentation
•Customer service and technical support
The FortiAnalyzer Unit
The FortiAnalyzer family includes the following models:
FortiAnalyzer-100A/100B
Ports4 10/100 Ethernet ports
Memory256 MB
Disk Drives1
Disk Drive Capacity120 GB
FortiGate Devices Supported10 FortiGate devices or VDOM licenses.
FortiClient installations SupportedNone
AC Input Voltage100-240V 0.8Amp Max
4321
POWER
STATUS
10/100
LINK / ACT
Supports FortiGate-50A to FortiGate-100A
only.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092511
The FortiAnalyzer UnitIntroduction
FortiAnalyzer-400
Ports3 10/100 Ethernet ports
Memory256 MB
Disk Drives4 x 120MB hot-swappable (3.0 MR1)
Disk Drive Capacity480 GB
FortiGate Devices Supported200 FortiGate units or VDOM licenses.
Supports FortiGate-50A to FortiGate-800 only.
FortiClient installations Supported 2000
AC Input Voltage100-240V 4Amp Max
FortiAnalyzer-800
Ports2 10/100 Ethernet ports
Memory512 MB
Disk Drives4 x 120MB hot-swappable (3.0 MR1)
Disk Drive Capacity480 GB
FortiGate Devices Supported250 FortiGate units or VDOM licenses.
FortiClient installations Supported 2500
AC Input Voltage100-240V 04Amp Max
Supports FortiGate-50A to FortiGate-800 only.
FortiAnalyzer Version 3.0 MR3 Administration Guide
1205-30003-0082-20060925
Introduction The FortiAnalyzer Unit
FortiAnalyzer-2000
Ports4 gigabit Ethernet ports
Memory2 GB
Disk Drives6 x 400GB hot-swappable
Disk Drive Capacity2.4 TB
FortiGate Devices Supported500 FortiGate units or VDOM licenses.
Supports all FortiGate models.
FortiClient installations Supported5000
AC Input Voltage100-240V 9Amp Max
FortiAnalyzer-4000
FortiAnalyzer-4000A
1
2
Ports2 gigabit ethernet ports
Memory1 GB
Disk Drives12 x 250GB - hot-swappable
Disk Drive Capacity3 TB
FortiGate Devices Supported500 FortiGate units or VDOM licenses.
FortiClient installations Supported5
AC Input Voltage100-240V 9Amp Max
Ports2 gigabit ethernet ports
Memory1 GB
Disk Drives12 x 250GB - hot-swappable
Disk Drive Capacity3 TB
A
Supports all FortiGate models.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092513
FortiAnalyzer featuresIntroduction
FortiGate Devices Supported500 FortiGate units or VDOM licenses.
Supports all FortiGate models.
FortiClient installations Supported5
AC Input Voltage100-240V 9Amp Max
FortiAnalyzer features
The FortiAnalyzer unit receives log files from multiple FortiGate and syslog
devices. Using the FortiAnalyzer unit’s robust reporting capabilities, you can
monitor the traffic, attacks, and misuses from network users. The FortiAnalyzer
unit includes the following features:
Reporting
The FortiAnalyzer reporting includes:
•Log analysis and reporting
Analyze logs submitted from multiple devices and generate a variety of reports
that enables you to proactively secure networks as threats arise, avoid network
abuses, manage bandwidth requirements, monitor Web site visits, and ensure
appropriate usage of the network. Analysis includes by firewall and by user or
group of users.
•Vulnerability reports
Vulnerability reports show potential weaknesses to attacks that may exist for a
selected device. The FortiAnalyzer unit queries for open ports, and where
possible, gathers information about the running services. Known vulnerabilities
that exist for a service or version of the service is included in the report.
Note: Vulnerability reports are not available on the FortiAnalyzer-100.
Data mining
The FortiAnalyzer unit provides data mining features that enables you to easily
access simple reports to obtain information on the intrusion attempts on your
network as well as the types of traffic occurring on your network. Security event
summaries provide a snapshot of what unwanted traffic is attempting to breach
the firewall and the top traffic producers on the network, while traffic summaries
provide a snapshot of the traffic passing through the firewall on your network.
These reports can help you identify the high volume users, or attack events that
may be slowing down overall network traffic.
Network analyzer
The FortiAnalyzer network analyzer enables you to reach areas of the network
where FortiGate firewalls are not employed, or if you do not have a FortiGate unit
as a firewall. The FortiAnalyzer network analyzer functions as a sniffer to capture
traffic data, save it to the FortiAnalyzer hard disk, and display it or generate
reports using the data.
Note: The network analyzer is not available on the FortiAnalyzer-100.
FortiAnalyzer Version 3.0 MR3 Administration Guide
1405-30003-0082-20060925
Introduction About this guide
Log viewer
The log browser, enables you to view the log messages sent to the FortiAnalyzer
unit from registered devices. With the log viewer you can view any log file and
messages saved on the FortiAnalyzer hard disk. All log files and messages are
searchable and can be filtered to drill down and locate specific information.
Real-time log viewing
The FortiAnalyzer unit provides real-time logging of web, FTP and email traffic
through content logs.The content viewer provides a real-time display of
meta-information from registered devices. Meta-information includes where the
information is coming from and going to. For example, HTTP content includes the
source IP address and the destination URL to allow you to follow real-time trends
in network usage.
Log Aggregation
Log aggregation is a method of collating log data from remote FortiAnalyzer units
or other third party network devices that support the syslog format to a central
FortiAnalyzer unit. For example, a company may have a headquarters and a
number of branch offices. Each branch office has a FortiGate unit and a
FortiAnalyzer-100A/100B to collect local log information. The headquarters has a
FortiAnalyzer-2000 as the central log aggregator.
Quarantine
Network Attached Storage
About this guide
For FortiGate units that do not have a hard disk, the FortiAnalyzer unit offers the
ability to quarantine infected or suspicious files entering your network
environment. Use the quarantine browser on the FortiAnalyzer unit to view the
files to determine whether they are dangerous or not. Set the option on the
FortiGate unit to send the quarantined files to the FortiAnalyzer unit.
The FortiAnalyzer unit also acts as a Network Attached Storage (NAS) device.
Use the FortiAnalyzer unit as a means of backing up or storing important
information or using the extra hard disk space as a file server or repository. Any
computer using NFS or Windows sharing can mount the FortiAnalyzer hard drive
to save and retrieve files.
This guide describes how to set up, configure and use the FortiAnalyzer unit to
collect logs and generate reports on network use.
This guide has the following sections:
•Installing the FortiAnalyzer unit describes how to set up and install the
FortiAnalyzer unit in your network environment.
•Configure the FortiAnalyzer unit describes how to configure the FortiAnalyzer
system settings, such as system time, session information, and user
management.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092515
FortiAnalyzer documentationIntroduction
•Devices describes how to add and configure FortiGate, FortiManager units and
Syslog servers so that the FortiAnalyzer unit can maintain a connection with
the device.
•Alerts describes how to set up alert messages and configure the FortiAnalyzer
unit to send messages via email through a mail server, to a syslog server or
using SNMP traps. This chapter also lists the SNMP traps supported by the
FortiAnalyzer unit.
•Traffic summary and security events describes how to configure and view
reports on intrusion attempts against your network as well as viewing the types
of traffic occurring on your network.
•Content archive describes how to monitor metadata content for all users using
email, FTP, Instant Messages and web browsing.
•Logs describes how to select and view device and FortiAnalyzer log files. It
also describes customizing the log views using filters and columns settings to
find information in the logs easier, as well as watch logs in real time.
•Quarantine describes how to configure the FortiAnalyzer unit to receive
quarantined files from a FortiGate unit and view them on the FortiAnalyzer
hard disk.
•Vulnerability scan describes how to set up vulnerability scans and view the
generated reports.
•Reports describes how to create report profiles for running regular reports on
the log information collected by the FortiAnalyzer unit. It also describes how to
view the generated reports.
•Network Analyzer describes how to connect the FortiAnalyzer unit to a SPAN
or mirror port on a network switch to analyze, or sniff, the network traffic
passing through it.
•Forensic Analysis describes how to view and report on an individuals network
habits and activities and generate reports for analysis.
FortiAnalyzer documentation
•FortiAnalyzer Administration Guide
Describes how to install and configure a FortiAnalyzer unit to collect FortiGate,
and Syslog log files, and connect to a FortiManager device for management
purposes. It also describes how to view log files, generate and view reports on
various network activities, and use the FortiAnalyzer unit as a NAS server.
•FortiAnalyzer CLI Reference
Describes how to use the command line interface of the FortiAnalyzer unit, and
describes all the commands available.
•FortiAnalyzer online help
Provides a searchable version of the Administration Guide in HTML format.
You can access online help from the web-based manager as you work.
•FortiAnalyzer QuickStart Guides
Explains how to install and set up the FortiAnalyzer unit.
FortiAnalyzer Version 3.0 MR3 Administration Guide
1605-30003-0082-20060925
Introduction Customer service and technical support
Fortinet Tools and Documentation CD
All Fortinet documentation is available from the Fortinet Tools and Documentation
CD shipped with your Fortinet product. The documents on this CD are current at
shipping time. For up-to-date versions of Fortinet documentation see the Fortinet
Technical Documentation web site at http://docs.forticare.com.
Fortinet Knowledge Center
The knowledge center contains short how-to articles, FAQs, technical notes,
product and feature guides, and much more. Visit the Fortinet Knowledge Center
at http://kc.forticare.com.
Comments on Fortinet technical documentation
Please send information about any errors or omissions in this document, or any
Fortinet technical documentation, to techdoc@fortinet.com.
Customer service and technical support
Fortinet Technical Support provides services designed to make sure that your
Fortinet systems install quickly, configure easily, and operate reliably in your
network.
Please visit the Fortinet Technical Support web site at http://support.fortinet.com
to learn about the technical support services that Fortinet provides.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092517
Customer service and technical supportIntroduction
FortiAnalyzer Version 3.0 MR3 Administration Guide
1805-30003-0082-20060925
Installing the FortiAnalyzer unit Planning the installation
Installing the FortiAnalyzer unit
This section describes the FortiAnalyzer hardware and how to connect the
FortiAnalyzer unit to the network. This section includes the following topics:
•Planning the installation
•Connecting the FortiAnalyzer unit
•Configuring the FortiAnalyzer unit
•Upgrading the FortiAnalyzer firmware
•Backing up the FortiAnalyzer hard disk
•Shutting down the FortiAnalyzer unit
Planning the installation
You can add the FortiAnalyzer unit to your local network to receive log message
packets from FortiGate and Syslog devices.
You can connect the FortiAnalyzer unit locally or remotely through the Internet. To
connect the FortiAnalyzer unit to devices remotely, you must configure the DNS
server and the default gateway. To manage the FortiAnalyzer unit, you can use a
computer within the local network or over the Internet.
Figure 1: FortiAnalyzer connection option
Internet
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092519
Connecting the FortiAnalyzer unitInstalling the FortiAnalyzer unit
Connecting the FortiAnalyzer unit
You can install the FortiAnalyzer unit as a free-standing appliance on any stable
surface. You can also mount the FortiAnalyzer-800, FortiAnalyzer-2000 and
FortiAnalyzer-4000/4000A onto a rack unit.
Environmental specifications
•Operating temperature: 41 to 95°F (5 to 35°C)
If you install the FortiAnalyzer unit in a closed or multi-unit rack assembly, the
operating ambient temperature of the rack environment may be greater than
room ambient temperature. Therefore, make sure to install the equipment in an
environment compatible with the manufacturer's maximum rated ambient
temperature.
•Storage temperature: -4 to 176°F (-20 to 80°C)
•Humidity: 10 to 90% non-condensing
Note: The FortiAnalyzer unit may overload your supply circuit and impact your surge
protection and supply wiring. Use appropriate equipment nameplate ratings to address this
concern.
Make sure that the FortiAnalyzer unit has reliable grounding. Fortinet recommends direct
connections to the branch circuit.
Air flow
•For rack installation, make sure that the amount of air flow required for safe
operation of the equipment is not compromised.
•For free-standing installation, make sure that the appliance has at least 1.5 in.
(3.75 cm) of clearance on each side to allow for adequate air flow and cooling.
Mechanical loading
You can mount the FortiAnalyzer-800, FortiAnalyzer-2000 and
FortiAnalyzer-4000/4000A units in a standard 19-inch rack. The FortiAnalyzer-800
requires 1U of vertical space and the FortiAnalyzer-2000 and
FortiAnalyzer-4000/4000A requires 2U of vertical space in the rack.
For rack installation, ensure an even mechanical loading of the FortiAnalyzer-800,
FortiAnalyzer-2000 and FortiAnalyzer-4000/4000A to avoid a hazardous
condition.
Connecting to the network
To connect the FortiAnalyzer unit to the network
1Place the unit on a stable surface, or in a 19-inch rack unit.
2Make sure the power of the unit is turned off.
3Connect the network cable to the LAN or Port 1 interface.
4Connect the power cable to a power outlet.
5Turn on the power switch.
FortiAnalyzer Version 3.0 MR3 Administration Guide
2005-30003-0082-20060925
Installing the FortiAnalyzer unit Configuring the FortiAnalyzer unit
Configuring the FortiAnalyzer unit
Use the web-based manager or the Command Line Interface (CLI) to configure the
FortiAnalyzer unit IP address, netmask, DNS server IP address, and default gateway IP
address.
Table 1: FortiAnalyzer-100A and FortiAnalyzer-100B factory defaults
FortiAnalyzer Version 3.0 MR3 Administration Guide
Installing the FortiAnalyzer unit Configuring the FortiAnalyzer unit
Using the web-based manager
The web-based manager provides a GUI interface to configure and administer the
FortiAnalyzer unit.
Use the web-based manager to:
•configure most FortiAnalyzer settings
•monitor the status of the FortiAnalyzer unit
•configure and view reports
•view log files and messages
•administer users, groups and set access rights.
You can configure and manage the FortiAnalyzer unit using a secure HTTPS
connection from any computer running Internet Explorer 6.0 or other current
browser.
Configuration changes made using the web-based manager are effective
immediately without resetting the firewall or interrupting service.For all
FortiAnalyzer models, use the following procedure to connect to the web-based
manager for the first time.
To connect to the web-based manager, you need:
•An Ethernet connection between the FortiAnalyzer unit and management
computer.
•Internet Explorer version 6.0 or higher or other current popular web browser on
the management computer.
To connect to the web-based manager
1Connect the Port1 interface of the FortiAnalyzer unit to the Ethernet port of the
management computer.
2Use a cross-over Ethernet cable to connect the devices directly. Use
straight-through Ethernet cables to connect the devices through a hub or switch.
3Configure the management computer to be on the same subnet as the
FortiAnalyzer LAN interface.
4To do this, change the IP address of the management computer to 192.168.1.2
and the netmask to 255.255.255.0.
5To access the FortiAnalyzer web-based manager, start your browser and browse
to https://192.168.1.99 (remember to include the “s” in https://).
6Type admin in the Name field and select Login.
After connecting to the Web-based manager, you can configure the FortiAnalyzer
unit IP address, DNS server IP address, and default gateway to connect the
FortiAnalyzer unit to the network.
To configure the FortiAnalyzer unit using the web-based manager
1In the web-based manager, go to System > Network > Interface.
2Select Edit for Port1.
3Enter the IP address and netmask and select OK.
If the FortiAnalyzer unit will be connected to the internet:
4Go to System > Network > DNS.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092523
Configuring the FortiAnalyzer unitInstalling the FortiAnalyzer unit
5Enter the, primary DNS server IP address, secondary DNS server IP address
(optional).
6Select Apply.
7Got to System > Network > Routing.
8Select Create New and add the default gateway IP address and any other routes
as required.
9Select OK.
Using the command line interface
You can also use terminal emulation software to connect to the command line
interface (CLI) from any network that is connected to the FortiAnalyzer unit,
including the Internet. This applies to all FortiAnalyzer models.
You can also access the FortiAnalyzer-100A/100B, FortiAnalyzer-800 and
FortiAnalyzer-4000/4000A CLI by using the null-modem cable provided to connect
to the unit’s console port.
The CLI supports the same configuration and monitoring functionality as the
web-based manager.
To connect to the FortiAnalyzer unit through the console
1Use a null-modem cable to connect the serial port on the
FortiAnalyzer-100A/100B, FortiAnalyzer-800 and FortiAnalyzer-4000/4000A to
the management computer serial port.
2Start a terminal emulation program (such as HyperTerminal) on the management
computer. Use these settings:
•Baud Rate (bps) 9600
•Data bits 8
•Parity None
•Stop bits 1
•Flow Control None.
3At the login: prompt, type admin and press Enter twice.
4(The
login
prompt is preceded by the server IP address.)
After connecting to the CLI, you can configure the unit IP address, DNS server IP
address, and default gateway to connect the FortiAnalyzer unit to the network.
To configure the FortiAnalyzer unit using the CLI
1Set the IP address and netmask of the LAN interface:
config system interface
edit port1
set ip <ip_address><netmask>
end
2Confirm that the address is correct:
get system interface
FortiAnalyzer Version 3.0 MR3 Administration Guide
2405-30003-0082-20060925
Installing the FortiAnalyzer unit Upgrading the FortiAnalyzer firmware
3Set the primary and optionally the secondary DNS server IP address:
config system dns
set primary <dns-server_ip>
set secondary <dns-server_ip>
end
4Set the default gateway:
config system route
edit 1
set device port1
set dst <destination_ip><netmask>
set gateway <gateway_ip>
end
Using the front panel buttons and LCD
You can use the front panel buttons on the FortiAnalyzer-400 and
FortiAnalyzer-800 to set up the unit’s IP address, netmask, and default gateway.
Press the cycle button to cycle through options and select the IP
address information.
Press the enter button to select a menu option or number in the IP
address.
On the FortiAnalyzer-2000, use the up and down arrow buttons to cycle through
the options and enter the IP address information, and select Enter to select a
menu option or number in the IP address.
Upgrading the FortiAnalyzer firmware
Upgrade the FortiAnalyzer firmware using the instructions in the topic “Changing
the firmware” on page 35. Ensure you backup all configuration settings and log
files before upgrading the firmware.
Note: If you are upgrading from FortiAnalyzer firmware version 0.8, the file system has
changed. After upgrading the firmware, all log data will be destroyed. Ensure you backup all
log information before proceeding with the upgrade. When upgrading from FortiLog 0.8 to
FortiAnalyzer
To format the hard disk, go to System > Dashboard. Select Format Log Disks for the
System Operation.
3.0, the FortiAnalyzer hard disks must be reformatted.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092525
Backing up the FortiAnalyzer hard diskInstalling the FortiAnalyzer unit
Backing up the FortiAnalyzer hard disk
Before upgrading the FortiAnalyzer firmware, formatting the log disk or changing
the RAID configuration (on a FortiAnalyzer-400, FortiAnalyzer-800,
FortiAnalyzer-2000 and FortiAnalyzer-4000/4000A), it is extremely important that
you back up the log data first. Using the CLI, you can perform a global backup of
all log information to an FTP server.
Note: In the case of changing RAID configurations and formatting log disks, this command
is designed to backup and restore all logs from the FTP server.
To backup the log information on the FortiAnalyzer hard disk, use the CLI to enter
the following command:
Once the firmware upgrade or the RAID configuration is complete, you can restore
the log information to the FortiAnalyzer hard disk.
Note: Before using the restore CLI command, ensure you add the devices for the logs first.
The command will not function without the devices to associate with the logs. For details on
adding devices, see the chapter “Devices” on page 65.
When powering off the FortiAnalyzer unit, always shut down the unit using the
following procedures before disconnecting the power supply. By not following this
procedure you risk damaging the FortiAnalyzer hard disk.
To power off the FortiAnalyzer unit
1From the web-based manager, go to System > Dashboard.
2In the System Operation list, select Shut Down and select Go.
OR
from the CLI, enter:
execute shutdown
3Disconnect the power supply.
FortiAnalyzer Version 3.0 MR3 Administration Guide
2605-30003-0082-20060925
Configure the FortiAnalyzer unit Dashboard
Configure the FortiAnalyzer unit
The FortiAnalyzer unit provides a number of configuration options to customize
the FortiAnalyzer unit using the System settings.
This section describes the configuration settings you can apply to use the
FortiAnalyzer in your network environment.
This section includes the following topics:
•Dashboard
•Network settings
•Administrator settings
•Network sharing
•Configuring the FortiAnalyzer unit
•Maintenance
•RAID levels
Dashboard
The system dashboard provides a view of the current operating status of the
FortiAnalyzer unit. All FortiAnalyzer administrators with read access to system
configuration can view system status information.
Figure 2: FortiAnalyzer-400 dashboard
Connect to the web-based manager to view the current system status of the
FortiAnalyzer unit, and modify the system information. The status information that
appears includes the system information, alert messages, system resources,
license information and session statistics.
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092527
DashboardConfigure the FortiAnalyzer unit
System Information
The System Information area of the Dashboard displays the current state of the
FortiAnalyzer unit. The System Status area includes the following information:
Serial NumberThe serial number of the FortiAnalyzer unit. The serial number is
UptimeThe time in days, hours and minutes since the FortiAnalyzer was
System TimeThe current time according to the FortiAnalyzer internal clock.
Host NameThe name of the FortiAnalyzer unit. For details on changing the
Firmware VersionThe version of the firmware installed on the FortiAnalyzer unit.
System Resources
The system resources displays how the FortiAnalyzer unit’s resources are being
used. You can monitor the CPU, memory and hard disk use and quickly see at
what capacity the FortiAnalyzer unit is running. System resources includes the
following information:
CPU UsageThe current CPU status. The web-based manager displays CPU
Memory UsageThe current memory status. The web-based manager displays
Hard Disk Usage /
RAID status
History iconSelect History to view a graphical representation of the last minute
unique to the FortiAnalyzer unit and does not change with
firmware updates. Use this number when registering your
FortiAnalyzer unit with Fortinet.
started or last rebooted.
Select Change to change the time or configure the FortiAnalyzer
unit to obtain the time from an NTP server. For details see “Setting
the time” on page 32.
name see “Changing the host name” on page 36.
Select Update to upload a new version of the firmware. For details
on updating the firmware see “Changing the firmware” on
page 35.
usage for core processes only. CPU usage for management
processes (for example, for HTTPS connections to the web-based
manager) is excluded.
memory usage for core processes only. Memory usage for
management processes (for example, for HTTPS connections to
the web-based manager) is excluded.
For the FortiAnalyzer-100 and FortiAnalyzer-100A/100B, the
current status of the hard disk. The web-based manager displays
the amount of hard disk space used.
For the FortiAnalyzer-400, FortiAnalyzer-800, FortiAnalyzer-2000
and FortiAnalyzer-4000/4000A, the current RAID status of the
hard disks. Each circle indicates the status of a hard disk. Green
indicates the hard disk is functioning normally. If the disk is
flashing red and yellow, there is a problem with the hard disk.
The hard disks on the FortiAnalyzer-2000 and
FortiAnalyzer-4000/4000A are hot swappable. For details see “Hot
swapping the FortiAnalyzer-2000 and FortiAnalyzer-4000/4000A”
on page 62.
of CPU, memory, sessions, and network usage. For more
information see “Viewing operational history” on page 30.
FortiAnalyzer Version 3.0 MR3 Administration Guide
2805-30003-0082-20060925
Configure the FortiAnalyzer unit Dashboard
License Information
Support ContractThe support contract number and expiry date.
RVS EngineThe version of the RVS engine. Select Update to upload a new
RVS Plug-insThe version of the RVS plug-in.
Device LicenseA listing of the number of devices connected to the FortiAnalyzer
version of the engine.
This feature is not available on the FortiAnalyzer-100.
This feature is not available on the FortiAnalyzer-100.
unit.
Registered is the number of devices added to the FortiAnalyzer
unit.
Unregistered is the number of devices attempting to connect to
the FortiAnalyzer unit that need configuring. To configure the
FortiAnalyzer unit to accept logs from a device see “Devices List”
on page 65.
Alert Message Console
The Alert display shows alert messages for the FortiAnalyzer and connected
FortiGate units. The Alerts display shows hard disk failure messages, virus
outbreak, or suspicious event warnings. To view all the alert messages recorded
by the FortiAnalyzer unit, select More Alerts. For details on viewing alert
messages see “Viewing Alert messages” on page 31.
Statistics
SinceThe date and time when the statistics were last reset.
ConnectionsThe number of communication sessions occurring on the
Logs & ReportsA display of the log file activity and volume delivered to the
Report Engine
The Report Engine display shows the FortiAnalyzer report generation activity. The
report engine activity information includes whether the report engine is active or
inactive, what reports are running when active and the percentage completed.
Select the Generate report button to create a new report profile.
Automatic Refresh Interval
Select how often the Status page automatically updates. Select Refresh Now to
update the status page immediately.
System Operation
Perform the following operations from the Status page. These options are not
available if your access privileges include write permissions.
FortiAnalyzer unit. Select Details for more information on the
connections. For details on the session information, see “Viewing
Session information” on page 30.
FortiAnalyzer unit.
RebootRestart the FortiAnalyzer unit.
ShutDownShut down the FortiAnalyzer unit. You can only restart the
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-2006092529
FortiAnalyzer unit by turning the power off and then on again.
DashboardConfigure the FortiAnalyzer unit
Format log disksFormat the FortiAnalyzer hard disk. Selecting this option will
Reset to factory
default
Viewing operational history
The System resource history page displays four graphs representing system
resources and network utilization history, updated every three seconds.
To view the FortiAnalyzer operational history
1Go to System > Dashboard.
2Select History in the upper right corner of the System Resources area.
CPU UsageThe CPU usages for the previous minute.
Memory UsageThe memory usages for the previous minute.
SessionThe session history for the previous minute.
Network utilizationThe network use for the last minute.
delete all log files and reports from the hard disk. Ensure that you
back up all information before selecting this option. Formatting the
hard disk will also interrupt FortiAnalyzer operations for several
minutes.
Restart the FortiAnalyzer unit with its original configuration when it
was initially powered on. This will delete all configuration changes
you have made, but does not changes the firmware version. This
also includes resetting the IP address and netmask. You will need
to reconnect to the FortiAnalyzer device using the default IP
address of 192.168.1.99.
Viewing Session information
Session information displays information about the current communication
sessions on the FortiAnalyzer unit.
To view the session information
1Go to System > Dashboard.
2In the Statistics area, select Details for the Connection information.
Resolve Host NameSelect to display host names by a recognizable name rather than
Resolve ServiceSelect to display network service names rather than port numbers.
Refresh TimeSelect the frequency of the refresh of the Connections page to
Stop RefreshSelect to stop the refreshing of the connections page. To start the
View per pageSelect the number of rows to display per page.
Page n of nEnter a page number to jump to and press Enter.
SearchEnter a keyword to perform a simple search on the session
ProtocolThe service protocol of the connection. For example, udp and tcp.
From IPThe source IP address of the connection.
From PortThe source port of the connection.
To IPThe destination IP address of the connection.
IP addresses. For details on configuring IP address host names
see “IP Aliases” on page 53.
For example, HTTP rather than port 80.
view the connection activity.
refresh, select a refresh time.
information available. Select Go to begin the search. The number
of matches appears above the Search field.
FortiAnalyzer Version 3.0 MR3 Administration Guide
3005-30003-0082-20060925
Loading...
+ 132 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.