12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Network Options<br />

System Network<br />

Enable DNS forwarding from This option applies only to <strong>FortiGate</strong> models 100 and<br />

lower operating in NAT/Route mode.<br />

Select the interfaces that forward DNS requests they<br />

receive to the DNS servers that you configured.<br />

Dead Gateway Detection<br />

Detection Interval<br />

Fail-over Detection<br />

Dead gateway detection confirms connectivity using a<br />

ping server added to an interface configuration. For<br />

information about adding a ping server to an interface, see<br />

“Dead gateway detection” on page 100.<br />

Enter a number in seconds to specify how often the<br />

<strong>FortiGate</strong> unit pings the target.<br />

Enter the number of times that the ping test fails before<br />

the <strong>FortiGate</strong> unit assumes that the gateway is no longer<br />

functioning.<br />

DNS Servers<br />

Several <strong>FortiGate</strong> functions use DNS, including alert email and URL blocking. You<br />

can specify the IP addresses of the DNS servers to which your <strong>FortiGate</strong> unit<br />

connects. DNS server IP addresses are usually supplied by your ISP.<br />

You can configure <strong>FortiGate</strong> models numbered 100 and lower to obtain DNS<br />

server addresses automatically. To obtain these addresses automatically, at least<br />

one <strong>FortiGate</strong> unit interface must use the DHCP or PPPoE addressing mode. See<br />

“Configuring DHCP on an interface” on page 88 or “Configuring an interface for<br />

PPPoE or PPPoA” on page 90.<br />

<strong>FortiGate</strong> models 100 and lower can provide DNS Forwarding on their interfaces.<br />

Hosts on the attached network use the interface IP address as their DNS server.<br />

DNS requests sent to the interface are forwarded to the DNS server addresses<br />

that you configured or that the <strong>FortiGate</strong> unit obtained automatically.<br />

Dead gateway detection<br />

Dead gateway detection periodically pings a ping server to confirm network<br />

connectivity. Typically, the ping server is the next-hop router that leads to an<br />

external network or the Internet. The ping period (Detection Interval) and the<br />

number of failed pings that is considered to indicate a loss of connectivity (Failover<br />

Detection) are set in System > Network > Options.<br />

To apply dead gateway detection to an interface, you must configure a ping server<br />

on it.<br />

To add a ping server to an interface<br />

1 Go to System > Network > Interface.<br />

2 Choose an interface and select Edit.<br />

3 Set Ping Server to the IP address of the next hop router on the network connected<br />

to the interface.<br />

4 Select the Enable check box.<br />

5 Select OK to save the changes.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

100 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!