Documente Academic
Documente Profesional
Documente Cultură
5 Build 1079
User Guide
FortiExplorer v2.5 Build 1079 User Guide
October 21, 2014
01-521-202417-20141021
Copyright 2014 Fortinet, Inc. All rights reserved. Fortinet, FortiGate, FortiCare and
FortiGuard, and certain other marks are registered trademarks of Fortinet, Inc., and other
Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All
other product or company names may be trademarks of their respective owners. Performance
and other metrics contained herein were attained in internal lab tests under ideal conditions,
and actual performance and other results may vary. Network variables, different network
environments and other conditions may affect performance results. Nothing herein represents
any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or
implied, except to the extent Fortinet enters a binding written contract, signed by Fortinets
General Counsel, with a purchaser that expressly warrants that the identified product will
perform according to certain expressly-identified performance metrics and, in such event, only
the specific performance metrics expressly identified in such binding written contract shall be
binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the
same ideal conditions as in Fortinets internal lab tests. Fortinet disclaims in full any covenants,
representations,and guarantees pursuant hereto, whether express or implied. Fortinet reserves
the right to change, modify, transfer, or otherwise revise this publication without notice, and the
most current version of the publication shall be applicable.
Change Log....................................................................................................... 5
Introduction....................................................................................................... 6
Supported models ................................................................................................... 6
FortiExplorer v2.5 Build 1079 support ..................................................................... 7
Download FortiExplorer ........................................................................................... 7
Firmware image checksums .................................................................................... 8
Installing FortiExplorer..................................................................................... 9
Installing FortiExplorer ............................................................................................. 9
Microsoft Windows install .................................................................................. 9
Mac OS X install............................................................................................... 10
Configuration options ............................................................................................ 10
Updating FortiExplorer and firmware..................................................................... 10
Register your device from FortiExplorer ................................................................ 11
Setup Wizard................................................................................................... 13
System settings ..................................................................................................... 13
Admin password .............................................................................................. 13
Time zone......................................................................................................... 13
Network.................................................................................................................. 13
Internet WAN connection................................................................................. 14
LAN settings..................................................................................................... 14
Security .................................................................................................................. 14
Schedule .......................................................................................................... 14
Internet access policy ...................................................................................... 14
Remote VPN .................................................................................................... 15
Configuration ......................................................................................................... 15
Summary.......................................................................................................... 15
FortiCloud ........................................................................................................ 15
Device Management Options ........................................................................ 16
Connecting to the Web-based Manager ............................................................... 16
Connecting to the CLI console .............................................................................. 17
Firmware ......................................................................................................... 18
Add model ............................................................................................................. 18
Download firmware images ................................................................................... 18
Uploaded firmware ................................................................................................ 19
DLP Watermark Tool ...................................................................................... 20
Using the DLP watermark tool............................................................................... 20
Apply watermark output message ................................................................... 21
Page 3
FortiExplorer command line Watermark tool ......................................................... 21
Create a filter in FortiOS ........................................................................................ 22
USB Serial Console ........................................................................................ 23
Supported models ................................................................................................. 23
Accessing the USB serial console menu ............................................................... 23
FortiGate BIOS menu............................................................................................. 23
Get firmware image from TFTP server ............................................................. 24
Format boot device.......................................................................................... 24
Configuration and information menu ............................................................... 25
Boot with backup firmware and set as default ................................................ 26
Quit menu and continue to boot ...................................................................... 26
Display this list of options ................................................................................ 26
FortiAP BIOS menu................................................................................................ 26
Get OS image from TFTP server...................................................................... 26
Quit this menu and continue to boot with default OS...................................... 27
Display this list of options ................................................................................ 27
FortiSwitch BIOS menu ......................................................................................... 27
Get firmware image from TFTP server. ............................................................ 28
Format boot device.......................................................................................... 28
Configuration and information menu ............................................................... 28
Boot with backup firmware and set as default ................................................ 30
Quit menu and continue to boot ...................................................................... 30
Display this list of options ................................................................................ 30
Fortinet Hardware Quick Inspection (HQIP)........................................................... 30
FortiCamera Configuration............................................................................ 32
Supported models ................................................................................................. 32
Detect FortiCamera................................................................................................ 32
Page 5
Introduction
FortiExplorer is a standalone software solution that allows you to connect to your Fortinet
device using the USB interface of your management computer. FortiExplorer provides direct
access to the FortiOS setup wizard, Web-based Manager, and CLI console. FortiExplorer also
provides useful tools to allow you to manage firmware versions for various managed devices
and a watermark tool which can be used to apply a watermark signature to confidential files.
Not all FortiExplorer features mentioned in this document are available for all Fortinet device
models.
Supported models
FortiGateVoice FGV-70D4
See the FortiExplorer v2.5 Build 1079 Release Notes for additional information on FortiExplorer.
Page 6
FortiExplorer v2.5 Build 1079 support
The following table lists FortiExplorer v2.5 Build 1079 product integration and support
information.
Table 2: FortiExplorer v2.5 Build 1079 support
Download FortiExplorer
FortiExplorer is available for download from the Customer Service & Support web site
ihttps://support.fortinet.com in firmware images and from the Fortinet Resource Center
http://www.fortinet.com/resource_center/product_downloads.html. FortiExplorer is available for
both Microsoft Windows and Mac OS X computers.
The Watermark Tool is available for FortiExplorer v2.5 Build 1079 for Microsoft Windows only.
You can download the following FortiExplorer software from the Customer Service & Support
portal.
The MD5 checksums for all Fortinet software and firmware releases are available at the
Customer Service & Support portal, https://support.fortinet.com. After logging in select
Download > Firmware Image Checksums, enter the image file name including the extension,
and select Get Checksum Code
FortiExplorer provides a user-friendly tool that you can use to configure a FortiGate unit over a
standard USB connection, rather than using a console cable or Ethernet connection.
When using the FortiExplorer setup wizard for the first time, ensure the FortiGate unit is using its
factory default settings.
Do not connect the USB cable until after FortiExplorer has been installed.
Installing FortiExplorer
FortiExplorer v2.5 Build 1079 is available for Microsoft Windows XP, Vista, 7, 8, and 8.1.
FortiExplorer v2.5 Build 1079 is available for Mac OS X v10.6 Snow Leopard, v10.7 Lion, v10.8
Mountain Lion, v10.9 Mavericks, and v10.10 Yosemite.
Page 9
3. The FortiExplorer Fortinet Device Easy Configuration Utility opens when the USB cable is
connected. Select Install the hardware automatically and select Next.
4. After a moment, FortiExplorer will launch.
Mac OS X install
To install FortiExplorer on a Mac OS X workstation:
1. Double-click the .dmg file and drag the FortiExplorer program file into the Applications
folder.
2. Connect the USB cable to the FortiGate unit and then to the management computer.
3. Double-click the FortiExplorer icon to launch the application.
Configuration options
With FortiExplorer, you are provided a number of options on how to configure the FortiGate unit,
depending on your level of comfort with various interfaces.
The below image shows the FortiExplorer tool connected to a FortiGate 60C device.
FortiExplorer may be automatically updated from time to time. Select the checkbox at the
bottom of the page to remember the device and check for updates with FDS automatically.
You can use FortiExplorer to register your Fortinet device. By registering your device, you can
download firmware images, receive FortiGuard service updates including virus and attack
definitions, VCM updates, and access Fortinet Customer Service & Support.
You can select to register the device to an existing FortiCare account, see Figure 3, or you can
create a new FortiCare account, see Figure 4.
To register the device to an existing FortiCare account, select Existing FortiCare User - FortiCare
Login, enter your FortiCare username and password, select the country in the drop-down menu,
select the reseller in the drop-down menu, and select Register.
Once registration is complete, the device will reflect a Registered status on the FortiExplorer
home page.
FortiExplorer allows you to configure your FortiGate unit using the setup wizard in FortiOS from
the FortiExplorer shell.
The setup wizard is intended for initial configuration of your device and includes basic settings.
This feature is not available on all device types. Options in the setup wizard will vary based on
the firmware version, device type, and features the device supports. This chapter provides an
overview of the options for a FortiGate 60C running FortiOS v5.2.0.
Select Setup Wizard in the left-hand devices menu and log in to your device. The default login
credentials are admin/no password.
System settings
Device system settings include setting the admin password, and setting time zone information.
Admin password
Select the checkbox to change the admin password. The default password is no password,
leave the Old Password field blank and enter the new password. Changing the password will
require re-authentication when the setup wizard is complete.
Time zone
Select the appropriate time zone for your location in the drop-down menu.
Network
Network settings include the Internet WAN connection and LAN settings.
The network menu is determined by the WAN topology selection. Menu items that are not
applicable to the topology selected will not be available.
Page 13
Internet WAN connection
Select the connection type for your Internet connection. Select one of the following:
DHCP, if your ISP automatically assigns you a dynamic IP address
Static IP, if your ISP assigns you a specific IP address or a group of addresses
Enter the IP address, netmask, default gateway IP address, and DNS server IP address for
WAN1.
PPPoE, if your ISP provided you with client software, a username, and a password
Enter the PPPoE username and password.
Contact your Internet service provider (ISP) if you are unsure which Internet connection type to
select for your primary WAN connection.
LAN settings
One this page you can configure LAN settings. Enter the IP address and netmask for the internal
interface or leave the default values. Select the checkbox to enable DHCP and enter the start
and end IP address.
Security
Security settings include schedule, Internet access policy, and remote VPN settings.
Schedule
On the you can configure the Internet access schedule. You can select to enable Internet
access to a specified schedule or set to allow access always.
The FortiGate setup wizard deletes all security policies and adds a single security policy
configured by the wizard to allow Internet access from the Internal network.
Configuration
Summary
The summary page allows you to verify the settings configured in the setup wizard before
committing the changes. In this page you can also select to print FortiClient VPN setup
instructions. Select Configure to save the settings to the device.
FortiCloud
In the FortiCloud page you can configure the device to send logs to your FortiCloud account.
Once the setup wizard in finished, you will be prompted to log back into the device.
After installing and setting up the basic settings for your device, you can use FortiExplorer to
connect to the devices Web-based Manager and CLI console for ongoing administration.
The following topics are discussed in this section:
Connecting to the Web-based Manager
Connecting to the CLI console
To connect to the device Web-based Manager, go to Devices > Web-based Manager, and enter
your username and password. Optionally, select Tools > Web-based Manager to launch a web
browser session with the device on 127.0.0.1:12180.
When accessing the Web-based Manager from within the FortiExplorer shell, you can access
detailed content-sensitive online help that displays for the current Web-based Manager page.
Configuration changes made in the Web-based Manager take effect immediately, without
resetting the device of interrupting service.
For more information on configuring your FortiOS device see the FortiOS Handbook 5.0.
Page 16
Connecting to the CLI console
The command line interface (CLI) is an alternative method of configuring the FortiGate unit. The
CLI complements the web-based manager in that it not only has the same configuration
options, but additional settings not available through the web-based manager.
The CLI contains commands and sub-commands that are used to configure a features settings,
and you can upload batches of commands from a text file.
To connect to the device command line interface, go to Devices > Command-line Interface, and
enter your username and password. Optionally, select Tools > Command-line Interface to
launch a Telnet session window on 127.0.0.1.
For more information on using the CLI console see the CLI Reference for FortiOS 5.0.
Device Management Options Page 17 FortiExplorer v2.5 Build 1079 User Guide
Firmware
You can use FortiExplorer to store and monitor firmware versions for managed Fortinet devices.
FortiExplorer will display the three most recent builds for the device. You can select Download,
enter your FortiCare username and password, and download the firmware image to
FortiExplorer. Optionally, you can download specific firmware images from the Customer
Service & Support website and upload the image to FortiExplorer.
The following topics are discussed in this section:
Add model
Download firmware images
Uploaded firmware
Add model
Select Add Model in the toolbar to add device models to the Monitored Firmware page. In
FortiExplorer v2.5 Build 1079 you can add the following devices:
Table 3: Supported models
FortiGateVoice FGV-70D4
When selecting to download a firmware image, you will be prompted to enter your FortiCare
account credentials. The firmware image will be saved to FortiExplorer. Only the three most
current firmware versions are displayed in Online Updates.
When connected to the FortiGate device you can select to Install the firmware image.
Before upgrading or downgrading the device, always read and review the applicable Firmware
Release Notes. The Firmware Release Notes are available on the Customer Service & Support
site in the file folder that contains firmware images. The Release Notes include support
information, special notices, supported upgrade and downgrade paths, resolved and known
issues for the firmware release.
Page 18
Uploaded firmware
Optionally, you can upload firmware image .out files that you have downloaded from the
Customer Service & Support site into the FortiExplorer shell. You can upload firmware image
files for any monitored device.
When connected to the FortiGate device you can select to Install the firmware image.
Before upgrading or downgrading the device, always read and review the applicable Firmware
Release Notes. The Firmware Release Notes are available on the Customer Service & Support
site in the file folder that contains firmware images. The Release Notes include support
information, special notices, supported upgrade and downgrade paths, resolved and known
issues for the firmware release.
Watermarking is essentially marking files with a digital pattern to mark the file as being
proprietary to a specific company. The Watermark tool will apply a digital watermark to the file.
You can also select to add the watermark to an entire directory. The tool adds a small
(approximately 178 bytes) pattern to the file that is recognized by the DLP watermark filter
configured on your FortiOS device.
The following file types are supported: .txt, .pdf, .doc, .xls, .ppt, .docx, .pptx, and .xlsx.
The Watermark Tool is available for FortiExplorer v2.5 Build 1079 for Microsoft Windows only.
Watermarks can only be removed using the command line Watermark tool.
You can use the FortiExplorer DLP watermark tool to apply a corporate identifier to a specific
file or directory.
Page 20
6. Select Apply Watermark to apply the watermark to the selected file or directory.
-->
'C:\Users\username\Desktop\FEXP\FortiExplorer_25_RN_253431\Outp
ut\fortiexplorer-v2.5-release-notes.pdf'
--------------------------------------------------------
1 file(s) processed. (success = 1, failure = 0)
FortiExplorer v2.5 Build 1079 installer includes a command line Watermark tool,
fortinet-watermark-win.exe. This file is located in the C: > Program Files >
Fortinet > FortiExplorer directory. This tool can be launched from the
Administrator Command Prompt and can be used to add or delete Watermarks.
The following syntax lists usage and options available in this tool:
C:\>fortinet-watermark-win.exe
USAGE: fortinet-watermark-win.exe <options> -f <file name> -i
<identifier> -l <sensitivity level>
fortinet-watermark-win.exe <options> -d <directory> -i
<identifier> -l <sensitivity level>
Options:
-h print help
-v verbose information
-I inplace watermarking (don't copy file)
-o output directory
-e encode <to non-readable>
-a add additional watermark (by default replaces watermarks
existing watermarks)
-D delete all watermarks
DLP Watermark Tool Page 21 FortiExplorer v2.5 Build 1079 User Guide
Create a filter in FortiOS
You need to create a filter in FortiOS to recognize the watermark that you added using the
FortiExplorer watermark tool.
DLP Watermark Tool Page 22 FortiExplorer v2.5 Build 1079 User Guide
USB Serial Console
In FortiExplorer v2.2 build 1046 or later, you can access the BIOS configuration menu from
within the FortiExplorer shell. The USB serial console is available for devices which do not have
a hardware console port.
Supported models
FortiGateVoice FGV-70D4
FortiSwitch FS-28C
You can access the USB serial console menu from within the FortiExplorer shell. On device boot
you will be prompted to press any key to interrupt the boot sequence and enter the BIOS menu.
To enter the BIOS menu, press any key at the Press any key to display
configuration menu ..... screen.
If you do not press a key, the device will continue to boot. The time required to complete the
boot is dependent on the system BIOS.
Page 23
The following options are available in the FortiGate BIOS menu:
[G]: Get firmware image from TFTP server.
[F]: Format boot device.
[I]: Configuration and information.
[B]: Boot with backup firmware and set as default.
[Q]: Quit menu and continue to boot.
[H]: Display this list of options.
Windows Firewall may block the TFTP connection. If you experience issues when attempting to
TFTP the firmware image, either disable Windows Firewall on your management computer or
configure to allow these connections.
USB Serial Console Page 24 FortiExplorer v2.5 Build 1079 User Guide
4. Once complete, the configuration menu is displayed.
USB Serial Console Page 25 FortiExplorer v2.5 Build 1079 User Guide
Quit the configuration and information menu
Select Q to quit the configuration and information menu and return to the main BIOS menu.
To enter the BIOS menu, press any key at the Hit any key to stop autoboot screen.
If you do not press a key, the device will continue to boot. The time required to complete the
boot is dependent on the system BIOS.
USB Serial Console Page 26 FortiExplorer v2.5 Build 1079 User Guide
To load a firmware image from a TFTP server:
1. Select G in the BIOS menu to start firmware download.
The console displays:
Please connect TFTP server to Ethernet port WAN1.
Enter TFTP server address [192.168.1.145]:
2. Enter the IP address of the management computer running the TFTP server and select
Enter.
The console displays:
Enter Local Address [192.168.1.188]:
3. Enter an unused IP address that is on the same subnet as the TFTP server and select Enter.
The console displays:
Enter firmware image file name [image.out]:
4. Enter the firmware image file name and select Enter.
5. The FortiAP unit installs the new firmware image and restarts, The installation may take a few
minutes to complete.
Windows Firewall may block the TFTP connection. If you experience issues when attempting to
TFTP the firmware image, either disable Windows Firewall on your management computer or
configure to allow these connections.
To enter the BIOS menu, press any key at the Press any key to display
configuration menu ..... screen.
If you do not press a key, the device will continue to boot. The time required to complete the
boot is dependent on the system BIOS.
USB Serial Console Page 27 FortiExplorer v2.5 Build 1079 User Guide
Get firmware image from TFTP server.
You can upload a new firmware image to your FortiSwitch device in the BIOS menu. Download
the firmware image from the Customer Service & Support FTP portal. In the portal you can verify
the MD5 checksum of firmware image you downloaded. Place the firmware image in the root
directory of your TFTP server and configure a static IP address on the network adapter of the
management computer.
Windows Firewall may block the TFTP connection. If you experience issues when attempting to
TFTP the firmware image, either disable Windows Firewall on your management computer or
configure to allow these connections.
USB Serial Console Page 28 FortiExplorer v2.5 Build 1079 User Guide
The following options are available in this menu:
[S]: Set serial port baudrate (will take effect on next boot).
[T]: Set image download port (will take effect now and on next boot).
[C]: Set DHCP enable (will take effect now and on next boot).
[I]: Display hardware information.
[Q]: Quit this menu.
[H]: Display this list of options.
USB Serial Console Page 29 FortiExplorer v2.5 Build 1079 User Guide
Boot with backup firmware and set as default
For devices with two partitions, you can select B to boot with the firmware image on the backup
partition.
[B]: Boot with backup firmware and set as default.
Loading backup firmware from boot device...
Reinitializing...
You can run the Fortinet Hardware Quick Inspection (HQIP) test from the USB Serial Console in
FortiExplorer. You can obtain the HQIP image from Technical Support.
USB Serial Console Page 30 FortiExplorer v2.5 Build 1079 User Guide
Reset Button Test
8. When complete, the HQIP report is displayed. Save the full output and submit to Technical
Support with your support ticket.
9. Reboot the system using the execute reboot CLI command. The device will reboot and
load the regular FortiOS firmware image.
USB Serial Console Page 31 FortiExplorer v2.5 Build 1079 User Guide
FortiCamera Configuration
Supported models
Detect FortiCamera
In FortiExplorer v2.4 build 1075 or later, you can view and configure FortiCamera from within the
FortiExplorer shell.
Page 32