Table Of ContentFortiPortal Administration Guide
Version4.0.0
FORTINETDOCUMENT LIBRARY
http://docs.fortinet.com
FORTINET VIDEO GUIDE
http://video.fortinet.com
FORTINET BLOG
https://blog.fortinet.com
CUSTOMER SERVICE & SUPPORT
https://support.fortinet.com
FORTIGATE COOKBOOK
http://cookbook.fortinet.com
FORTINET TRAINING SERVICES
http://www.fortinet.com/training
FORTIGUARD CENTER
http://www.fortiguard.com
END USER LICENSE AGREEMENT
http://www.fortinet.com/doc/legal/EULA.pdf
FEEDBACK
Email:[email protected]
Wednesday,April26,2017
FortiPortalAdministrationGuide
TABLE OF CONTENTS
Change Log 7
FortiPortalOverview 8
KeyFeatures 8
SpecialCharacters 8
Components 8
End-CustomerDevices 10
FortiPortalConcepts 10
DeploymentArchitecture 11
Installation Using OpenStack 13
Prerequisites 13
DownloadingFortiPortalImageFiles 13
OpenStackHorizonDashboard 13
CreateImagesforthePortalandCollectors 13
CreateVolumesforthePortalandCollector 14
LaunchtheInstances 14
AssignaFloatingIP Address 15
AssociateVolumetotheInstances 15
ReboottheInstances 15
DeterminetheIP AddressandPortNumber 15
ConfigurePortalParameters 16
ConfigureCollectorParameters 17
UpdatingSSL CertificateFile 18
UpdateCertificateusingAdminPortal 18
InstallingMySQL forFortiPortalDatabases 19
ReconfiguringMySQL PasswordonFortiPortal 19
Installation using VMware 21
Prerequisites 21
InstallationAlternatives 21
DownloadingOVF files 21
InstallingFortiPortalVMs 22
CreateaVMinstance 22
CreateaVMvApp 22
DefaultCredentials 23
ConfigureVM HardwareSettings 24
StarttheVMorvApp 24
ConfiguringFortiPortal 24
ConfigureMySQL forFortiPortalDatabases 24
ConfigurePortalParameters 24
ConfigureFortiPortalCollectorParameters 25
UpdatingSSL CertificateFile 27
UpdateCertificateusingAdminPortal 27
InstallingMySQL forFortiPortalDatabases 27
ReconfiguringMySQL PasswordonFortiPortal 28
FortiPortalConfiguration 29
LicenseExpiry 29
PageBanner 29
ConfigurationMajorSteps 30
Administrative Users 31
PageActions 31
Per-UserActions 31
CreateaUser 31
TrustedHosts 32
AdminUserRoles 33
Dashboard 34
InitialData-AggregationDelay 35
AbilitytosetTopNEntries 35
Customers 37
PageActions 37
Per-CustomerInformation 37
Per-CustomerActions 38
Add orEditCustomer 39
CustomerSites 45
PageActions 45
Per-SiteActions 45
Wireless Networks 48
PageActions 48
Per-NetworkActions 48
CustomerUsers 50
PageActions 50
Per-UserActions 50
AddorEditUser 50
AddTrustedHostforaUser 51
CustomerUserRoles 52
Reports 54
FortiPortalReports 54
PageActions 54
Per-ReportActions 54
FortiAnalyzerReports 55
PageActions 55
FortiManagerDevices 57
PageActions 57
Per-FortiManagerActions 57
FortiManagerHighAvailability(HA) 57
AddaFortiManager 58
EditaFortiManager 59
ManageFortiGateDevices 60
AP ControllerDevices 61
PageActions 61
Per-ControllerActions 61
EditaController 62
FortiAnalyzerDevices 63
Prerequisites 63
PageActions 63
Per-FortiAnalyzerActions 63
EditaFortiAnalyzer 64
ViewFortiAnalyzerReports 65
FortiPortalCollectors 66
PageActions 66
CollectorHighAvailability(HA) 66
AddFortiPortalCollector 66
Per-CollectorActions 67
EditaCollector 67
Admin Settings 69
RemoteAuthentication-FortiAuthenticator 71
RADIUSServerConfiguration 72
RemoteAuthentication-SSO 73
RADIUS Roles 75
PageActions 75
Per-RoleActions 76
Roles 78
PageActions 78
Per-RoleActions 78
SystemLog 80
PageActions 80
InitialLog-AggregationDelay 80
Theme 81
CustomThemeOptions 81
SelectaPredefinedColorScheme 81
CreateaCustomColorScheme 81
UsingtheColorPicker 82
UsingCustomCSS File 84
CustomURLsandText 84
CustomImages 85
ResizingImages 86
DetailsoftheThemeConfigurationFields 87
SystemInfo 90
LicenseInformation 90
UploadLicense 91
VersionInformation 91
CertificateInformation 91
Trusted Hosts 92
PageActions 92
Per-RoleActions 92
AdditionalResources 94
PageActions 94
Per-RoleActions 95
Audit 96
PageActions 96
Per-AuditActions 96
Upgrading FortiPortalsoftware 98
AlertMessages 99
Service-ProviderLevelMessages: 99
Customer-LevelMessages: 100
ChangeLog
Change Log
Date ChangeDescription
2017-03-31 FortiPortal4.0.0initialrelease.
7 FortiPortalAdminGuide
FortinetInc.
KeyFeatures FortiPortalOverview
FortiPortal Overview
FortiPortalenablesaManagedSecurityServiceProvider(MSSP)tooperateacloud-basedhostedsecurity
managementandlogretentionservice.TheserviceprovidestheMSSP end-customerswithcentralizedreporting,
trafficanalysis,configurationmanagement,andlogretentionwithouttheneedfortheendcustomertoinvestin
additionalhardwareandsoftware.
Key Features
FortiPortalprovidesthefollowingfeatures:
dashboardwidgetsforsystemandlogstatus
l
logviewerwithfilters
l
drill-downanalysisofuserandnetworkactivity
l
reportgenerator(withcustomizationoptions)
l
wirelessnetworkstatus
l
devicemanagement
l
policymanagement
l
RemoteauthenticationusingFortiAuthenticator
l
FortiPortalsupportsthefollowinglanguages: Romanian,French,Portuguese,SpanishandEnglish.
Special Characters
Inreleasespriorto2.40,youcouldincludesomespecialcharacters(quoteandbackslash)incontrollernames.
Forexample,thefollowingnamewouldbevalid:
Name'1/3
However,Inrelease2.4.0andlater,youmustnotusethesecharacters.Priortoupgradingtorelease2.4.0,you
mustremovethesespecialcharactersfromexistingnames.
Inrelease2.4.0,ifanentryhasanamecontainingaspecialcharacter,youwillnotbeabletoedittheentry(but
youcandeleteit).
Components
Theend-customer'sFortiGatedevicesaremanagedbyoneormoreFortiManagers.Optionally,logsfromthe
FortiGatedevicescanbegatheredbyoneormoreFortiAnalyzers.
IntheFortiPortal,theCollectorscollectlogsfromtheFortiAnalyzer(ortheFortiGatedevicesdirectly)andstore
thelogsinCollectordatabases.ThePortalaggregatesthelogsintoacentraldatabase,andperformssecurity
analyticsonthelogs.ThePortalprovidesanadministrativewebinterface(fortheserviceprovideradministrative
staff)andacustomerwebinterface(fortheMSSP'scustomers).
FortiPortalAdminGuide 8
FortinetInc.
FortiPortalOverview Components
ThefollowingfigureillustratestheFortiPortalcomponentsandatypicalcustomernetwork.
TheFortiPortalsolutionincludesthefollowingcomponents:
1. Collector: virtualappliance:
ManageslogssentfromtheFortiGatedevices
l
TheFortiPortalmayincludemorethanoneCollector
l
2. CollectorDB: MySQLdatabase:
PhysicalorvirtualserverprovidedbytheServiceProvider
l
Collectorstoresthelogsinthisdatabase
l
TheFortiPortalmayincludemorethanoneCollectorDB
l
3. Portal: virtualappliance:
Providestheserviceproviderwebinterfaceandthecustomerwebinterface.
l
UsestheFortiManagerAPItomanageDevices,ObjectsandPolicies
l
TheFortiPortalincludesonlyonePortal(however,theportalmayconsistofmultipleVMinstancesfor
l
redundancyand/orscalability)
4. PortalDB: MySQLdatabase:
PhysicalorvirtualserverprovidedbytheServiceProvider
l
Portalaggregatesthelogsintothisdatabase
l
TheFortiPortalincludesonlyonePortalDatabase
l
Thecustomerwebinterfaceenableseachendcustomertoaccess/analyzetheirdataandadministertheir
service.Foradditionalinformationaboutthecustomerwebinterface,seetheFortiPortalUserHelp(whichisalso
availablebyclickingthehelpbuttoninthecustomerwebinterface).
Theadministrativewebserviceallowstheserviceprovidertoconfiguretheservicesforeachendcustomer,andto
managetheoverallcloudservice.
9 FortiPortalAdminGuide
FortinetInc.
End-CustomerDevices FortiPortalOverview
End-Customer Devices
TheFortiPortalrequiresthatthecustomerFortiGatedevicesmustbemanagedbyFortiManager.FortiManagers
mayresideinthecustomernetworkorintheMSSPcloud.
1. FortiGate: securitydevicesinthecustomerenvironment:
generatesthesecuritylogs
l
passeslogstothecollector
l
alsofulfillstheAP WirelessControllerrole
l
2. FortiManager: managesasetofFortiGatedevices:
AllFortiGatedevicesintheFortiPortalmustbemanagedbyFortiManager
l
FortiManagerprovidesdeviceinformationtotheFortiPortal
l
MayresideinthecustomernetworkorintheMSSPcloud
l
3. (Optional)FortiAnalyzer:receiveslogsfromthedevices:
passesthelogsontothecollector
l
MayresideinthecustomernetworkorintheMSSPcloud
l
FortiPortal Concepts
FortiPortalintroducesthefollowingconcepts:
CustomerSites
Anend-customercanhavemultiplesites.
l
Asiteisalogicalgroupingofdevices(independentofwhichFortiManagermanagesthedevice).
l
DevicesareFortiGatedevicesorAPWirelessDevices.
l
StorageLimits
Eachend-customerhasastoragecapacitymaximumamount,whichisexpressedasanumberofGBofdatabase
l
storage.
FortiPortalAdminGuide 10
FortinetInc.
Description:Installing MySQL for FortiPortal Databases. 19. Reconfiguring . The FortiPortal requires that the customer FortiGate devices must be managed by FortiManager Configure system IP address and default gateway for the Portal VM:.