
Explore FortiGate installation, labs, and core configurations—from routing and policies to security profiles and VPNs. Apply hands-on skills in SD-WAN, NAT, authentication, VPN, and virtual domain management across chapters.
Explore a lab topology for Fortinet FortiGate firewall training, detailing head and branch offices, dual internet connections, two firewalls, high availability, sd-wan zone rules, and vlan and subnet planning.
Prepare FortiGate by configuring VLAN groups and subnets on ESXi, including DMZ, management, and ISP networks, and test with Active Directory and a web server across vlans 11 and 12.
Deploy fortigate vm on ESXi using the fortigate 64 OVF, configure ports and VLANs across management, ISP, DMZ, and HA, import multiple devices, and access the GUI via http.
Build a FortiGate home lab with workstation pro, configuring multiple vmnet adapters and subnets (192.168.10.0, 192.168.1.0, 192.168.2.0, 172.16.0.0, 10.1.0.0) and NAT/bridge settings, install FortiVMs, and troubleshoot licenses via factory reset.
Explore the Fortinet FortiGate firewall dashboard: configure monitoring widgets, view CPU, memory, and session stats, adjust system time, NTP, DNS, and theme, and customize network and security pages.
Configure interface and zone settings on the Fortinet FortiGate firewall by assigning IPs to ports, creating WAN, LAN, DMZ, and VLAN interfaces, and forming Inside and Server zones.
Configure the FortiGate DHCP server for VLAN 11 and VLAN 12, assign IP ranges, gateway, and DNS, with optional option 66 for call manager, then verify IPs via ipconfig.
Learn to create a default static route on Fortinet FortiGate, configuring destination 0.0.0.0/0 with the ISP gateway 44.34.0.254 on WAN-1. Verify routing table entries to confirm internet access.
Explore the fundamentals of OSPF, including interior and exterior routing, administrative distance, and neighborhood concepts, and learn about areas, DR/BDR, LSA types, and SPF-based routing.
Configure OSPF between a FortiGate firewall and a router by setting router IDs and area 0, advertising subnets 172.16.0.0/24, 172.16.11.0, 12.0, and 192.168.10.0, and verify neighbors and routes.
Configure BGP between the firewall and the ISP to share the public subnet 74.34.54.0 using AS 65536, verify with show ip route bgp and show run.
Bridge your modem, set WAN 1 to PPPoE, and automatically obtain IP, DNS, and default gateway, then apply a firewall policy to enable internet access.
Configure layer 2 etherchannel with 802.3ad lacp on FortiGate ports 5 and 6 to enable redundancy and DHCP-enabled VLANs 11 and 12.
Learn to create address and service objects for hosts and subnets in policy and objects, configure server and dmz interfaces, and add an sftp service object with port 22.
Configure firewall policies to let VLAN 11 and VLAN 12 access the DNS server and enable the DNS server to reach the internet, with proper NAT.
Create and apply time-based policies in FortiGate by defining a working hours schedule, selecting days and times, and attaching it to rules while verifying firewall time and NTP settings.
Learn to configure an IPv4 DoS policy on FortiGate to monitor and block ICMP flood and port-scan attacks, using logs and monitoring to validate effectiveness.
Configure virtual IPs to forward external ports 80 and 443 from 44.34.0.100 to internal web server 10.1.0.100, and apply a WAN-1 to DMZ policy with NAT.
Configure a NAT rule using an IP pool to give the web server in the DMZ a fixed internet address 44.34.0.100, validate with logs and traffic from DMZ to WAN-1.
Discover the fundamentals of SD-WAN in Fortinet FortiGate firewall training, including its definition, purpose, and how to manage multiple internet connections with an SD-WAN zone.
Create an SD-WAN zone, add WAN interfaces with gateway IPs, configure static routes, and set up firewall policies and DNS rules to control internet access.
Learn to create and monitor sd-wan performance slas to track wan-1 and wan-2, including bandwidth, latency, jitter, and packet loss, and use these slas to shape rules and traffic flow.
Configure SD-WAN rules to steer traffic between WAN-1 and WAN-2 using volume and best quality, guided by performance SLAs, then validate via logs.
Enable ssl inspection to decrypt and inspect https traffic via TLS connections, allowing the Fortinet firewall to mediate between the client and the web server and log activity.
Create an antivirus profile under the security profile tab, select protocols like http, smtp, pop3, imap, and ftp, and set block for detected threats. Apply to a firewall policy rule.
Create and customize a web filter profile, clone the default profile, apply it to rules, and block categories or specific URLs with url filter and wildcard rules.
Learn to create and apply a DNS filter profile in Fortinet FortiGate firewall, including selecting blocked categories and applying the profile to a policy rule.
Create an application control profile, name it Application Block, and block social media and specific apps like Skype and WhatsApp, then apply it to a rule to block matching traffic.
Create and apply an IPS profile on FortiGate to block high, orange, and yellow severity signatures from FortiGuard, use the trial signature package, monitor lower severities, then apply under policy.
Create and apply a file filter profile to block or monitor specific file formats, such as exe, zip, and gzip, across protocols like SMTP, POP3, IMAP, HTTP, and FTP.
integrate an ldap server with a fortigate firewall using active directory to manage users and create user-based rules through security fabric and active directory groups.
Learn how to create user-based firewall rules by integrating Active Directory, selecting IT group users, and enforcing access by VLANs 11 and 12 with real-time testing and log verification.
Configure captive portal authentication on VLAN 12 to grant internet access for users not joined to Active Directory, using an LDAP group and local authentication, with testing and logs.
Configure guest management by creating a guest group, using email IDs, and enforcing a four-hour validity with after first login; deploy vlan 13 with captive portal and test access.
Configure IPsec site-to-site VPN between central and branch Fortigate firewalls using the wizard, defining 172.16.11.0 and 192.168.20.0 subnets, and verify connectivity with cross-site pings.
Configure a site-to-site ipsec vpn between FortiGate and Cisco routers using the firewall wizard, phase 1 and phase 2 settings, pre-shared key, then verify with pings and traceroutes.
Compare IPsec remote access split tunnel and full tunnel, where split tunnel flows VPN traffic through the tunnel while internet uses the user’s modem.
Configure a full tunnel IPsec VPN on FortiGate with phase 1 and 2 crypto, user range 172.16.99.1–100, and a nat-enabled firewall policy for internet and RDP.
Create admin profiles under the system tab, including prof admin and super admin, then add admin users under the administrator tab and assign profiles with specific read or read-write permissions.
Set up high availability on two FortiGate devices in an active-passive configuration, assign primary and secondary via priority, and configure monitor and heartbeat interfaces for automatic failover.
Explore feature visibility on Fortinet FortiGate firewalls, adjusting core, security, and additional properties under system tab, and enable or disable routing, VPN, and DoS policy across versions 6 and 7.
Master FortiGate log settings: enable local logs on disk-enabled devices, configure remote logs via Forti Analyzer/Manager or syslog, and optionally send to Forti Cloud; customize event and traffic logs.
Learn how to back up and restore your FortiGate firewall by saving encrypted backups to local or cloud storage, then restoring by uploading the backup file.
Explore the virtual domain concept (VDOM) on FortiGate, creating a root domain with multiple VDOMs to separate traffic and assign per-company admins.
Configure virtual domains on a FortiGate 60E by activating vdom service, creating two vdoms for company A and company B, assign WAN and VLAN interfaces, and define admins and routes.
YOU CAN GET DISCOUNT CODES FOR ALL MY TRAININGS FROM MY WEBSITE
In this course, you can learn the Fortinet FotiGate firewall installation and management through the sample topology. Fortinet is one of the leading Network Security products manufacturer in the world, and you can always be one step ahead in the sector by learning the installation and management of Fortinet products.
During the course, we will do our lab work using VmWare ESXi, Workstation Pro and FortiGate 60E physical device. First, we will prepare the vLAN on VmWare ESXi, then we will install the FortiGate Virtual Firewall, after the installation, we will start to manage our device by making our basic settings and interface settings. I will also show you an example of installation on VmWare Workstation so that you can do home lab.
Throughout our course; Static Nat , EtherChannel, OSPF Configuration, BGP Configuration, Wan Interface PPPoE Settings, SSL Decryption, URL Filtering, Application Control, File Filter, DNS Filter, Captive Portal Authentication, Guest Management, IPS Inspection, IPsec Site to Site VPN, Remote Access VPN We will cover many more topics such as High Availability (HA), Feature Visibility, Back Up and Restore, VDOM (Virtual Domain).
To attend the course, you must have basic system, network and firewall knowledge. I also recommend that you have received Cisco CCNA training. This training will also help you prepare for the Fortinet NSE certification exam.
This course is suitable for anyone who wants to improve themselves in Network and Cyber Security.
I tried to convey this course to you in the best way with my 24 years of experience in the sector. While I was preparing this course, I prepared it with great pleasure, I have no doubt that you will enjoy watching it too.