FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall User Guide

June 10, 2024
FORTINET

FORTINET-logo

FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall

FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
product

Product Information

The FortiGate 1000F Series includes two models: FG-1000F and FG-1001F. The package contents include a FortiGate device, Quick Start Guide, two power cables, one Ethernet cable, one console cable, four rubber feet, two SFP transceivers, two rack-mount brackets, eight bracket screws, two grounding lugs (DC models only), and six terminal rings (DC models only). The device can be set up using Forti Explorer, GUI, or CLI. The device also comes with default logins, including the management IP address of 192.168.1.99 and the username “admin” with a blank password. Customers can access the Admin Guide on https://docs.fortinet.com/ for detailed setup and configuration information. Self-service resources, such as knowledge base, forums, videos, and technical experts, are also available at https://www.fortinet.com/support /support-services/forticare-support.
For contracts, licensing, product registration, and account management, customers can contact Forti Care Support at https://www.fortinet.com/support/contact.

Product Usage Instructions

Before setting up the device, customers should register their device to access Forti Guard updates, cloud management, firmware upgrades, technical support, and warranty coverage at https://support.fortinet.com. Customers can set up the device using Forti Explorer, GUI, or CLI. For Forti Explorer setup, customers can scan the QR code or visit https://links.fortinet.com/fortiexplorer/downloads to download the app for free. For GUI setup, customers should connect the Ethernet cable from the device to a management computer configured with IP 192.168.1.x and subnet 255.255.255.0. For CLI setup, customers should connect the USB console cable from the device to a management computer and follow the detailed guide on docs.fortinet.com. For SFP module installation, customers should insert the module into the cage socket and ensure that the Tx and Rx are aligned. For removal, customers should release the lock and pull out the module from the cage socket. For desktop installation, customers should place the device on a flat, clean, and stable surface with 1.5 inches of clearance above and below the device. For rack installation, it is recommended that two or more people mount the device on a rack with 1.5 inches of clearance above and below the device.

Quick Start Guide

FortiGate 1000F Series
FG-1000F and FG-1001F
This guide covers: FG-1000F and FG-1001F
February 14, 2023
Copyright© 2023 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, Forti Care® and Forti Guard®, and certain other marks are registered trademarks of Fortinet, Inc., in the U.S. and other jurisdictions, and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. In no event does Fortinet make any commitment related to future deliverables, features or development, and circumstances may change such that any forward-looking statements herein are not accurate. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.
For Product License Agreement / EULA and Warranty Terms, visit https://www.fortinet.com/content/dam/fortinet/assets/legal/EULA.pdf

Before you begin

Register your device to access Forti Guard updates, cloud management, firmware upgrades, technical support and warranty coverage. https://support.fortinet.com

Forti Explorer App
Rapidly provision, deploy, and monitor Security Fabric components including FortiGate and Forti WiFi devices from your mobile. Download now for free.

Scan the QR Code or visit:
https://links.fortinet.com/fortiexplorer/downloads

The Essentials

Default Logins
https://192.168.1.99 Username: admin Password: leave blank

Admin Guide
For a detailed Getting Started guide, setup and configuration information, refer to the Admin Guide on https://docs.fortinet.com/

Customer Service
For contracts, licensing, product registration and account management, contact Forti Care Support at https://www.fortinet.com/support/contact

Self-service Resources
Access our knowledge base, forums, videos and technical experts at https://www.fortinet.com/support/support-services/forticare-support

Package Contents

FortiGate 1000F Series
FG-1000F and FG-1001F
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
02
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
03
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
04

Setup

Unpack the box, power the device and choose one of the following options:

Forti Explorer
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
05 Note: Enable Bluetooth on your mobile device for BLE or connect your mobile’s USB cable into the device

GUI
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
06 Note: Configure the management computer with IP 192.168.1.x and subnet 255.255.255.0

CLI
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
07 Note: For a detailed CLI guide, visit docs.fortinet.com

SFP Modules

Installation
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
08 Removal
FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
09 Desktop Installation
Note: Place the device on a flat, clean and stable surface.

Installation
Caution: To avoid personal injury or damage to the device, it is recommended that two or more people mount the device on a rack.
Note: The recommended clearance is 1.5 inches above and below the device.
Optional: For desktop installation, place the device on a flat, clean and stable surface with 1.5 inches of clearance.

FG-1000F Series Front Panel

  1. FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall 12 STATUS
    Green: Normal operation
    Flashing Green: Booting up
    Red: Major Alarm
    Off: Device is Off
    HA
    Green: Operating in an HA cluster
    Red: HA failure
    Off: HA disabled
    ALARM
    Red: Major alarm detected
    Amber: Minor alarm detected
    Off: No errors detected
    POWER
    Green: Device is on Off: Device is off

  2. BLE Button Press to enable BLE
    Blue: BLE connected
    Flashing Blue: BLE in discovery
    Off: BLE not connected

  3. USB (USB A) x2:
    USB 3.0 server port

  4. Console (RJ45)
    CLI interface

  5. HA (RJ45)
    LINK/ACT
    Green: On, Link up
    Flashing Green: Data activity
    Off: No link established
    Green: Linked at 2.5 Gbps
    SPEED
    Amber: Linked at 1G / 100 Mbps
    Off: Linked at 10 Mbps or no link established.

  6. MGMT (RJ45)
    Green: On, Link up
    LINK/ACT
    Flashing Green: Data activity
    Off: No link established
    Green: Linked at 1 Gbps
    SPEED
    Amber: Linked at 100 Mbps
    Off: Linked at 10 Mbps or no link establishedFORTINET FG-1000F FortiGate
1000F Series Network Security Firewall 21

  7. Ports 1 to 8 (RJ45)
    LINK/ACT
    Green: On, Link up
    Flashing Green: Data activity
    Off: No link established
    Green: Connected at 10 Gbps
    SPEED
    Amber: Connected at 5 Gbps/ 2.5 Gbps/ 1 Gbps
    Off: Linked at 100 Mbps or no link established

  8. Ports 9 to 24 (SFP+)
    Green: Connected at 10 Gbps/ 1 Gbps
    Flashing Green: Data activity
    Off: No link establishedFORTINET FG-1000F FortiGate 1000F Series Network
Security Firewall 23

  9. Ports 25 to 32 (SFP28)
    Green: Connected at 25 Gbps/ 10 Gbps/ 1 Gbps
    Flashing Green: Data activity
    Off: No link establishedFORTINET FG-1000F FortiGate 1000F Series Network
Security Firewall 24

  10. Ports 33 and 34 (QSFP28)
    Green: Connected at 100 Gbps/ 40 Gbps
    Flashing Green: Data activity
    Off: No link established

FG-1000F Series Rear Panel -AC Model

FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
26

  1. Power Supply
    100-240VAC, 50/60Hz, 6A Max (2x PSU)
    1+1 Redundant, hot-swappable power supplies

  2. Input LED Indicators
    Green: Input voltage within normal range
    Flashing Green: Over or under voltage warning
    Off: No input power
    FG-1000F Series Rear Panel -DC Model
    FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
27 DC Models Only (FG- 1000F-DC and FG-1001F-DC)
    This product is only intended for installation and use in a Restricted Access Location. The DC power cables are intended to be used only for in-rack wiring, must be routed away from sharp edges, and must be adequately fixed to prevent excessive strain on the wires and terminals. DC cables must be a minimum of 12 AWG. For DC Cables Installation, ensure the terminal rings are securely and safely fastened to the PSU terminals.
    FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
28

  3. Output LED Indicators
    Green: Output voltage normal
    Flashing Green: Standby mode
    Flashing Amber: Warning
    Amber: Critical error
    Off: No output
    FORTINET FG-1000F FortiGate 1000F Series Network Security Firewall
29

DC Power Input for FG-1000F-DC and FG-1001F-DC
-48VDC to -60VDC, 8.5A, hot swappable, redundant (1+1) power supplies

Cautions and Warnings

Environmental specifications

  • Ambient operating temperature: 0°C to 40°C
  • Rack Mount Instructions – The following or similar rack-mount instructions are included with the installation instructions:
  • Elevated Operating Ambient – If installed in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient. Therefore, consideration should be given to installing the equipment in an environment compatible with the maximum ambient temperature (Tma) specified by the manufacturer.
  • Reduced Air Flow – Installation of the equipment in a rack should be such that the amount of air flow required for safe operation of the equipment is not compromised.
  • Mechanical Loading – Mounting of the equipment in the rack should be such that a hazardous condition is not achieved due to uneven mechanical loading.
  • Circuit Overloading – Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of the circuits might have on overcurrent protection and supply wiring. Appropriate consideration of equipment nameplate ratings should be used when addressing this concern.
  • Reliable Earthing – Reliable earthing of rack-mounted equipment should be maintained. Particular attention should be given to supply connections other than direct connections to the branch circuit (e.g. use of power strips).

Refer to specific Product Model Data Sheet for Environmental Specifications (Operating Temperature, Storage Temperature, Humidity, and Altitude)

Safety

Moving parts — Hazardous moving parts. Keep away from moving fan blades.
Warning: Equipment intended for installation in Restricted Access Location.

  • A readily accessible disconnect device shall be incorporated in the building installation wiring.
  •  A UL Listed external disconnect device, i.e. circuit breaker or other, with over current protection suitable for local code(rated 6A recommended) shall be installed with this equipment
  • Battery – Risk of explosion if the battery is replaced by an incorrect type. Do not dispose of batteries in a fire. They may explode. Dispose of used batteries according to your local regulations. IMPORTANT: Switzerland: Annex 4.10 of SR814.013 applies to batteries.

CAUTION: Shock Hazard. Disconnect all power sources.
ATTENTION:

  • Grounding — To prevent damage to your equipment, connections that enter from outside the building should pass through a lightning / surge protector, and be properly grounded. Use an electrostatic discharge workstation (ESD) and/or wear an anti-static wrist strap while you work. In addition to the grounding terminal of the plug, on the back panel, there is another, separate terminal for earthing.

Caution: Slide/rail mounted equipment is not to be used as a shelf or a work space.
Attention:
Warning: Stability hazard.
The rack may tip over causing serious personal injury.
Before extending the rack to the installation position, read the installation instructions. Do not put any load on the slide-rail mounted equipment in the installation position. Do not put any load on the slide-rail mounted equipment in the installation position. Do not leave the slide-rail mounted equipment in the installation position. Laser Class 1 optical transceiver shall be used only IEC 60825-1:2014 transfer to FDA/CDRH Complies with FDA performance standards for laser products except for conformance with IEC 60825-1 Ed.3., as described in Laser Notice No. 56, dated May 8, 2019. The SFP ports should use UL Listed Optional Transceiver product, Rated 3.3Vdc, Laser Class 1. Fiber optic transceiver must be rated 3.3V, 22mA max, Laser Class 1, UL certified component.
Warning: Class I Equipment. This equipment must be earthed. The power plug must be connected to a properly wired earth ground socket outlet. An improperly wired socket outlet could place hazardous voltage on accessible metal parts.

  • All Ethernet cables are designed for intra-building connection to other equipment. Do not connect these ports directly to communication wiring or other wiring that exits the building where the appliance is located.

Regulatory Notices
Federal Communication Commission (FCC) – USA
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions:

  1.  this device may not cause harmful interference, and
  2. this device must accept any interference received; including interference that may cause undesired operation.

This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency energy, and if it is not installed and used in accordance with the instruction manual, it may cause harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which case the user will be required to correct the interference at his own expense.
WARNING: Any changes or modifications to this product not expressly approved by the party responsible for compliance could void the user’s authority to operate the equipment
This equipment complies with FCC radiation exposure limits set forth for an uncontrolled environment. This equipment should be installed and
operated with minimum distance 20cm between the radiator and your body. This transmitter must not be co-located or operating in conjunction with any other antenna or transmitter.
Industry Canada Equipment Standard for Digital Equipment (ICES) – Canada
CAN ICES-003 (A) / NMB-003 (A)
This digital apparatus does not exceed the Class A limits for radio noise emissions from digital apparatus set out in the Radio Interference Regulations of the Canadian Department of Communications.
Innovation, Science and Economic Development (ISED) – Canada
This device contains licence-exempt transmitter(s)/receiver(s) that comply with Innovation, Science and Economic Development Canada’s licence
ex-empt RSS(s). Operation is subject to the following two conditions:

  1. This device may not cause interference.
  2. This device must accept any interference, including interference that may cause undesired operation of the device.

This equipment complies with ISED radiation exposure limits set forth for an uncontrolled environment. This equipment should be installed and operated with minimum distance 20cm between the radiator & your body. This radio transmitter (Contains IC:7280B-111T15G) has been approved by ISED to operate with the antenna types listed below with the maximum permissible gain and required antenna impedance for each antenna type indicated. Antenna types not included in this list, having a gain greater than the maximum gain indicated for that type, are strictly prohibited for use with this device. This device and it’s antennas(s) must not be co-located or operating in conjunction with any other antenna or transmitter except in accordance with IC multi-transmitter product procedures.

Ant.| Brand Holder| Model Name| Antenna Type| Connector| Antenna Gain (dBi)
---|---|---|---|---|---
1| Wieson| ARY196-0346-003-00| PIFA| Ipex I| 1.84
2| INPAQ| WA-F-LA-02-119| PIFA| Ipex I| 1.64

European Conformity (CE) – EU
This is a Class A product. In a domestic environment, this product may cause radio interference, in which case the user may be required to take adequate measures.
The product transmits within the frequency ranges and less than or equal to the power listed below: 2402-2480MHz less than 20dBm

Simplified EU Declaration of Conformity

This declaration is only valid for Fortinet products (including combinations of software, firmware and hardware) provided by Fortinet or Fortinet’s
authorized partners to the end-customer directly for use within the EU or countries that have implemented the EU Directives and/or spectrum regulation. Any Fortinet products not obtained directly from Fortinet or Fortinet’s authorized partners may not comply with EU Directives and Fortinet makes no assurances for such products.
This product is in compliance with Directive 2014/53/EU.
Note: The full Declaration of Conformity for this product is available in the link below: https://site.fortinet.com/ProductRegulatory/EU
Compliance with 2014/53/EU Radio Equipment Directive (RED) In accordance with Article 10.8(a) and 10.8(b) of the RED, the following table provides information on the frequency bands used and the maximum e.i.r.p. of the product for sale in the EU:

Frequency Range (MHz) Maximum e.i.r.p. (dBm)
Bluetooth 2.4GHz 4.84

UK Conformity Assessed (UKCA) – United Kingdom
The product transmits within the frequency ranges and less than or equal to the power listed below: 2402-2480MHz less than 20dBm This equipment should be installed and operated with minimum distance 20cm between the radiator & your body.  This product is in compliance with Statutory Instrument 1206 Radio Equipment Regulations 2017 The full Declaration of Conformity for this product is available in the link below:
https://site.fortinet.com/ProductRegulatory/UK

  • Voluntary Control Council for Interference (VCCI) – Japan
  • Product Safety Electrical Appliance & Material (PSE) – Japan
  • Bureau of Standards Metrology and Inspection (BSMI) – Taiwan

The presence conditions of the restricted substance (BSMI RoHS table) are available at the link below: https://www.fortinet.com/bsmi

  • National Telecommunications Commission (NCC) – Taiwan

China
Fortinet.com

References

Read User Manual Online (PDF format)

Loading......

Download This Manual (PDF format)

Download this manual  >>

Related Manuals