
Master FortiGate firewall administration with GUI and CLI, configure interfaces, zones, routes, and policies, deploy in network and transparent operation modes, and set up SSL VPN and IPsec tunnels.
Learn FortiGate factory settings, configure port one for DHCP, connect to the device, and secure it by changing the default admin credentials.
Download a FortiGate virtual image from the Fortinet support site, import it into VMware, and configure port seven as the management interface with IP 10.0.3.16, subnet 255.255.255.0, and http access.
Compare super admin and professional admin roles, login as different profiles, and configure local versus remote credentials and trusted hosts within the FortiGate dashboard.
Configure trusted hosts for Fortigate admin accounts by restricting the professional admin to a specific IP, verify access by logging in and out, and update trusted hosts via the cli.
Configure FortiGate system settings, including host name, data center naming, system time, ports 80/81/8080, ssh and telnet, and idle timeout, plus inspection mode and next-generation firewall mode for traffic policies.
Back up the FortiGate configuration using plain text or encrypted backups. Restore from the admin menu with the encrypted key; transfers require the same model and firmware.
Configure FortiGate management interface via CLI, assign the admin interface a static IP with a 24 subnet mask, enforce https and redirect http to https, and disable dhcp and dns.
Master the FortiGate command line interface, learning basic syntax and core commands: get, config, and show, to inspect hardware, configure interfaces, and display full configurations.
Learn to create a local FortiGate user, assign credentials and an email, then place the user into a test users group, setting up for later IPv4 policy use.
Create a new local user via the cli, set a password, and add it to the test users group, confirming the group now has two members.
Learn to use FortiGate system status commands to view version and build, virus and IPS updates, hostname, logging options, high availability, interfaces, sessions, and process diagnostics.
Fortigate system status commands include get system performance status with cpu usage, uptime, network activity, dns and dhcp details, and show full configuration with grab and grep.
Master FortiGate cli commands to view the system and firewall policies, then review log disk settings, including space thresholds and options to override or keep logs.
Learn FortiGate feature visibility by enabling needed security features, such as antivirus, DNS filter, and web filter, then activate IPS and application control to monitor and control applications.
Use the execute ping to troubleshoot connectivity by sending ICMP echo requests to websites or local hosts, with options to adjust repeat count and source.
Set up email alerts for FortiGate firewall by configuring a Gmail smtp server, using smtp.gmail.com port 587 with starttls, and enabling alerts for admin actions, logins, configuration changes, and threats.
Explore FortiGate firewall policies as rules that match traffic across interfaces, sources, destinations, users or devices, apply security profiles, enable net and logs, and build a simple full access policy.
Compare nat mode and transparent mode on fortigate: nat mode is layer 3 routing with ip addresses on interfaces; transparent mode is layer 2 switching using mac-based forwarding.
Switch FortiGate to transparent mode to see how it switches traffic; examine the mac address table and port associations while noting virtual wire pairing and forward domains.
In transparent mode, FortiGate broadcasts every packet to the internal interfaces. Create a forward domain for three internal VLANs to keep broadcasts within those interfaces.
Link two ports in transparent mode with a virtual wire pair to connect the internal network to an ISP router, then create a two-way policy.
Clarify how traffic flows in two directions on FortiGate by differentiating ingress and egress interfaces. Destined traffic uses the ingress interface, while exiting traffic uses the egress interface.
Configure the FortiGate marketing LAN with 10.0.2.1/24, set DHCP range 10.0.2.2–10.0.2.254, and deny http/https admin access; connect the switch to the interface and WAN.
Create and use zones to group unreferenced interfaces into a unified land zone, combining marketing and finance LANs for a single policy, with IP 10.0.4.1/24, ping, SNMP, and DHCP settings.
Configure a DHCP server on a LAN interface, define a 40-host pool from 10.10.9.2 to 10.10.9.42 with a 24 subnet and gateway, and enable MAC reservations and relay options.
Configure the Fortigate dhcp server to manage mac reservations and unknown macs, view and edit the pool and dns settings via cli or gui, and save changes.
Configure dhcp options to apply client settings when they obtain an IP address. Create option 252 to redirect clients to a proxy server on port 8080 for a pac file.
Configure virtual local area networks (VLANs) to split a single physical port into multiple broadcast domains, creating secure, efficient networks with trunk ports and native versus tagged traffic on FortiGate.
Configure VLAN-based policies for marketing employees and managers, restricting marketing employees to FTP with logging and security profiles, while implementing an unrestricted policy for managers on VLAN 110.
Configure a hardware virtual switch on the FortiGate by grouping ports into a marketing switch with its own subnet and dhcp server, and observe traffic forwarding via the Mac table.
Configure NAT on the FortiGate to connect a large local network to a single public IP, translating private addresses and distinguishing source NAT from destination NAT, including PAT overload.
FortiGate NAT overloading uses IP pools to map many private addresses to a public IP, assigning sessions by source ports and offering overload, one-to-one port range, and port block allocation.
Compare static and dynamic nets and implement a virtual ip addressing to map a public ip to an internal web server, using port forwarding, firewall address, vp, and no-nat policy.
Enable policy based ngfw mode on FortiGate, then create central nat rules that specify incoming and outgoing interfaces, source and destination addresses, ports, and dynamic ip pools, evaluated top-down.
Explore how FortiGate in nat mode acts as an osi layer 3 router, using a routing table and two session lookups, with static, dynamic (ospf), and policy routes.
Explore static routes and default routes in FortiGate, including administrative distance and priority, with scenarios using multiple gateways and firewall address objects to steer traffic.
Understand how administrative distance selects the FortiGate route, comparing connected (0), static (10), OSPF (110), and RIP (120). When routes exist, the lowest administrative distance wins the active route.
Explore how distance and priority select the best static route, compare two routes, and apply equal cost multipath and metric-based load balancing with dynamic routing protocols.
Explore equal cost multipath routing on FortiGate and how metrics influence load balancing. Configure weight and spillover thresholds for methods: source IP, weighted IP, usage IP, and source-destination IP.
Learn how vpn creates a secure tunnel over the public internet with encryption and authentication, enabling access to private networks, and compare IPsec and SSL VPN and use cases.
Configure ssl vpn in web and tunnel modes, create a user and group, set a high cipher suite, and use the full access portal with traffic routing and split tunneling.
Configure FortiGate ssl vpn web mode with credentials, a customizable portal, bookmarks to admin pages, and protocols like ftp, rdp, ssh, telnet, and vnc; adjust ports to avoid conflicts.
Create an ssl vpn with tunnel and web modes, define the 10.0.3.0/24 local network object, and configure a policy for access via the portal bookmarks to FortiGate admin.
Learn how ipsec differs from ssl vpn and set up ipsec with FortiGate templates and wizards, covering phase 1, phase 2, and security policies for site-to-site and remote user connections.
Configure a remote ipsec lan object and a site-to-site tunnel using main mode, pre-shared key, diffie-hellman groups, phase two networks, replay detection, and perfect forward secrecy.
Configure FortiGate IPsec by finishing phase one and two, creating remote and local address objects, adding a static route on the two branch tunnel interface, and establishing bidirectional IPsec policies.
Fortigate Firewall training - Admin Crash Course is the First course in Udemy , that teaches you to administrate your fortigate FW , from the very start.
In this course , you will learn how to set up:
Different admin profiles
Operate your fortigate in NAT and Transparent mode
Virtual WirePair
Forward Domains
Mac Table
Create Vlan's
Create firewall policies
Understand relevant Network Topologies to your FW
Configure VPN's ( ipsec and ssl VPN )
Understand Network address translation techniques
Nat Overload
Virtual IP
Ip Pools
Central NAT
Understand Routing
Create static routes
Set Up Interfaces in different Modes and Services
Check System Status
Back up your configuration
Master the CLI syntax
Understand policy routes
AND Much Much More ...
this course is all hands-on, no fancy slides, only admin page and many CLI commands
This Course is being instructed by A fortinet Certified Trainer ( FCT )