
Introduce Fortigate firewall concepts, demonstrate deploying and configuring the device, and guide you through downloading images, registering on Fortigate support, and lab setup.
Explore FortiGate firewall topics, from syllabus and lab setup to interface, ip addressing, default route, and policies; cover vlan, virtual wire, dhcp, dns, vpn, ha, Active Directory integration, and troubleshooting.
Install VMware Workstation using the setup file by double-clicking and following prompts, then choose the installation location and license to enable Cisco routers, switches, and firewall.
learn to install eve-ng community edition in vmware workstation by downloading the iso, creating an ubuntu 64-bit vm, and completing the setup to access labs.
Learn how to load Cisco router and switch, Windows images, and Palo Alto firewall into eve-ng, using WinSCP, and apply the permission command and client pack for CLI access.
Learn to download FortiGate firewall images from the official site and upload them to EVE-NG for hands-on labs, using versions like 7.4.7 and 7.0.9 with a Fortinet evaluation license.
Learn how to upload Fortigate firewall images in evnt, including folder and image naming, using the qemu folder, and applying the permission fix command for lab setups.
Explore Fortinet Fortigate concepts, from basic firewall definitions and barriers to next generation features like stateful inspection, app awareness, Content ID, User ID, and cloud firewall options.
Explore the FortiGate firewall dashboard, accessing via GUI or CLI. Review models, ports, and the management port setup for labs.
Perform an initial working lab on FortiGate firewall, configuring IP interfaces, DNS, static routes, and nat, then building a lan to wan policy with nat and logging.
Explore FortiGate firewall interfaces, including physical and virtual VLANs, subinterfaces, loopback, redundancy, aggregate links, 802.1Q trunking, and zone-based policy concepts.
Demonstrates a basic two-switch VLAN lab, creating VLAN 10 and VLAN 20, configuring access ports and a trunk, and illustrating broadcast isolation and MAC learning.
Build a multi vlan fortigate lab topology with a FortiGate firewall, a switch, and three vlans (ten, twenty, thirty), configuring 802.1q subinterfaces, dns, default routes, and zone policies.
Learn to configure a one-arm sniffer on a FortiGate firewall to capture traffic via a span port, generating logs for Wireshark and FortiGate analyzer 40.
Explore redundancy interface concepts on FortiGate firewall, configuring dual interfaces for failover, with GUI and CLI steps, and distinguishing redundancy from aggregation in network design.
Discover how to configure FortiGate aggregation via etherchannel using LACP, combining two or more physical interfaces into a single logical link for higher bandwidth and redundancy.
deploy the fortigate as a virtual wire, a transparent or bump-in-wire deployment that preserves the IP schema, and configure a virtual wire pair with a bidirectional policy and no NAT.
Learn how to enable and manage administrative access on Fortigate firewall interfaces, configuring protocols such as http, https, ssh, telnet, and ping, with temporary access and port-based control.
Learn how FortiGate uses DNS to translate domain names to IPs, configure primary and secondary DNS (Google DNS and 1.1.1), and apply DNS on interfaces for lab networks.
Explore routing fundamentals on a Fortigate firewall, including static and default routes, and implement dynamic routing protocols such as RIP, OSPF, and BGP with hands-on labs.
Explore static routing and static policy routing on a FortiGate firewall, compare administrative distance, configure two ISPs, and implement policy-based routing for port 80 traffic.
Perform a hands-on FortiGate firewall lab to configure static routes and policy-based routing, assign interfaces, enable http/https and telnet/ssh tests, and verify traffic between routers and a PC.
FortiGate firewall training: explore the theory of routing information protocol (RIP), compare version 1 and version 2, and contrast classful versus classless routing with multicast and broadcast updates.
Perform a hands-on rip lab in FortiGate using evnt, building a small topology with two routers and a management cloud, configuring rip version 2 and verifying routes.
Master ospf theory and FortiGate configuration, including link-state routing, area zero backbone, lsa updates, equal-cost load balancing, and ipv4/ipv6 support with vlsm and cidr.
Explore an OSPF lab on FortiGate and routers, enabling OSPF via interface method, configuring router IDs and area zero, and performing redistribution between RIP and OSPF with practical lab steps.
Explore border gateway protocol theory, including as numbers, ibgp and ebgp, and manual neighbor configuration, and learn how to apply these concepts to configuring bgp on fortigate firewalls.
Configure a BGP lab on a FortiGate firewall by removing OSPF and RIP, setting up two neighbors (192.168.2.1 and 192.168.2.2), advertising networks 3.0.0.0/8 and 4.0.0.0/8, and verifying routes.
Define FortiGate firewall policy as a top-to-bottom set of rules to allow or deny traffic, with parameters like incoming and outgoing interfaces, source, destination, schedule, services, and NAT.
Explore a FortiGate firewall policy lab that uses MAC addresses to grant or restrict internet access, building policy objects, selecting sources, and applying policies across LAN and WAN.
Create and manage local users on the Fortigate firewall to control internet access. Define groups, assign policies, and use authentication prompts and logs to monitor activity.
Configure the FortiGate firewall as a DHCP client, server, or relay agent, and explore the Dora process, UDP ports 67 and 68, and the flow of DHCP messages.
Configure Fortigate as a dhcp server and test dhcp with multiple devices, setting interfaces, IP ranges, default gateway, DNS, and optional ntp for a realistic lab scenario.
FortiGate DHCP relay forwards client requests across subnets, converting broadcasts to unicast for the DHCP server. In a lab with lan, dmz, and wan, configure relay, pools, and policies.
Learn to configure FortiGate as a DHCP server for multiple VLANs, creating VLAN interfaces, assigning DHCP ranges, and enabling inter-VLAN and internet access through firewall policies and zones.
Learn how to customize replacement messages on a Fortigate firewall, including editing HTML and CSS, updating logos, and replacing blocked page banners for working hours, URL blocks, and login failures.
explain Fortigate inspection mode, comparing flow base and buffering base (proxy) modes; flow base inspects packets on the fly, while buffering base scans all data before allowing traffic.
Explore how enabling a FortiGate security profile enhances a policy with deep packet inspection, antivirus, web filtering, DNS filtering, application control, IPS, and file filtering to create a next-generation firewall.
Explore Fortigate firewall modes: nat mode and transparent mode (layer two). Switch from nat to transparent via cli, and configure management ip, gateway, dns, and lan-to-wan policies.
Explore Fortigate's next generation firewall modes, including profile base and policy base, and understand how central nat streamlines policy-based deployments.
Explore how a FortiGate dos policy defends a lab network against icmp, tcp, and udp floods using a threshold rule, with Kali Linux attack simulations and basic nat/lan setup.
Perform a dos policy lab in eve-ng to simulate icmp floods against a FortiGate firewall, configure nat, dhcp, and a web server, and observe blocking and logging.
Learn how to create and use address objects in FortiGate policies, defining single IPs, ranges, domains, countries, and Mac addresses, and grouping them for reusable policies.
Explore how to create and manage Fortigate service objects and service groups, defining telnet and web service entries with protocols and ports, and applying them in policies.
Master network address translation (NAT) on FortiGate, translating private IPs to public IPs, and explore source NAT, destination NAT, PAT, static and dynamic IPs, and central NAT.
Learn fortigate snat lab concepts in eve-ng, applying static nat overload with port translation to map many private ips to a single public ip, using a hands-on topology.
Configure dynamic nat overload on FortiGate by using an external ip pool to multiply available sessions; learn to define ip ranges, port preservation, and policy integration in a lab scenario.
Demonstrate dynamic NAT overload and dedicated one-to-one mappings, using IP pools and firewall policies to let only two internal servers share two external IPs.
Configure fixed port ranges on FortiGate by mapping external and internal IPs to allocated ports per IP, and explore port block allocation to enforce per-user limits.
Configure the central net to centrally apply NAT across policies, replacing per-policy nets with a single central nat setup that supports static and dynamic NAT via GUI or CLI.
Master destination NAT on FortiGate by configuring virtual IPs and policies to map a public IP and port (http 80, telnet 23) to internal servers, with central NAT options.
Explore high availability concepts for FortiGate devices, including power and ISP redundancy, etherchannel, failover testing, and active-passive vs active-active configurations with heartbeat and session synchronization.
Configure FortiGate ha active passive lab with two FortiGate firewalls, heartbeat links, and identical configurations to achieve seamless failover and session synchronization.
Explore a FortiGate HA active-active lab configuring two firewalls for TCP load balancing with session pickup and heartbeat monitoring, including interface setup, DHCP, DNS, and policy basics.
VDOM theory shows dividing a Fortigate firewall into multiple virtual domains that act as firewalls for HR, IT, and sales, enabled by license, with VDOM policies and GUI or CLI.
Learn VPN theory and FortiGate configurations for site-to-site and remote access, covering IPsec types, phase one and phase two, encryption, authentication, integrity, and route-based and policy-based setups.
Learn to configure a site-to-site IPsec route-based VPN using a FortiGate template lab with two FortiGate firewalls, an ISP router, and testing of IP schema, interfaces, and routing.
Learn to configure site-to-site ipsec route-based vpn on Fortigate using a custom, manual setup: interface, ip schemes, nat traversal, pre-shared key, phase 1/2, policies, routes, and testing.
Enable policy-based VPN on the FortiGate. Create the IPsec site-to-site tunnel, define local subnets 192.168.1.0/24 and 192.168.2.0/24, configure MD5, a pre-shared key, and apply a single firewall policy.
Learn how to integrate FortiGate with Active Directory, enabling active and passive authentication, group-based access via LDAP, and policy-based control of internet access using Active Directory groups.
Learn to implement passive authentication with Fortinet single sign on, installing the AD agent, configuring fabric connection on the Fortigate firewall, and mapping groups and policies.
Configure syslog on FortiGate to centralize firewall logs by sending all events to a syslog server, using timestamps, severity levels 0–7, and customizable log types via log settings.
Configure SNMP on a FortiGate firewall to monitor devices via a manager, using SNMP agents and MIBs with get, set, get next, get bulk, and trap in versions 1–3.
Explore quality of service on FortiGate with traffic shaper and per IP shaper to prioritize traffic and allocate or limit bandwidth for specific IPs.
Learn to back up and restore FortiGate configurations using gui, cli, and ftp/tftp methods, including usb options, encryption, passwords, and revision features.
Explore top-down and bottom-up troubleshooting approaches for FortiGate, using tools like ping, traceroute, telnet, and packet sniffing to diagnose and resolve access issues.
The Network Security Professional designation recognizes your ability to install and manage the day-to-day configuration, monitoring, and operation of a FortiGate device to support specific corporate network security policies.
We recommend this course for network and security professionals who are involved in the day-to-day management, implementation, and administration of a security infrastructure using FortiGate devices.
In this course, you will learn how to use FortiGate Firewall features, including security profiles. You will explore firewall policies, the Fortinet Security Fabric, user authentication, SSL VPN, and how to protect your network using security profiles, such as IPS, antivirus, web filtering, application control, and advanced routing, transparent mode, redundant infrastructure, site-to-site IPsec VPN, and diagnostics and more.
Course Topics:
1. Introduction to Firewall
2. Installing FortiGate in GNS3
3. Installing FortiGate in EVE
4. FortiGate Dashboard
5. Initial Working Lab
6. Interfaces
7. VLAN and Zone Lab
8. One Armed Sniffer
9. Redundant Interfaces
10. Aggregate Interfaces
11. Virtual Wire Pair
12. Administrative Access
13. DNS Server
14. Static Policy Route
15. Static and Default Route Lab
16. Policy Routing LAB
17. RIP
18. OSPF
19. Routing Protocols Redistribution
20. BGP Border Gateway Protocol
21. Policies
22. Policy Labs MAC
23. Policy Labs LocalUser
24. DHCP
25. DHCP Relay Lab
26. Security Profile Intro
27. Replacement Messages
28. AV-Security Profiles
29. Web Filter
30. DNS Filter
31. Application+Control
32. Intrusion Prevention System
33. File Filter Profile
34. Inspection Mode
35. NGFW Modes
36. Policy Based Mode to Block Facebook
37. Policy Based Mode Default Service
38. FortiGate Firewall Modes
39. IPv4 DoS Policy
40. Network Address Translation
41. Policy Source Interface Overload NATLab
42. Policy Source Overload NAT Lab
43. Policy Source One To One NAT Lab
44. Policy Source Fixed Port Range NAT Lab
45. Policy Source Port Block Allocation NAT Lab
46. SNAT Lab
47. DNAT Lab
48. Destination NAT, Virtual IP with Central SNAT
49. Services+Objects
50. HA
51. Active Passive Lab
52. Active Active Lab
53. FortiGate AD
54. Active Authentication AD
55. Passive Authentication AD
56. VDOMS
57. Cryptography Concepts
58. Diffie Hellman(DH)
59. IPSec Protocols
60. VPN Concept
61. Site2SiteVPN+Theory
62. Site2Site Policy Based VPN
63. Backup and Restore
64. SNMP Access Lab
65. Syslog Server
66. Traffic Shaper
67. Remote Access VPN1
68. Command Line Interface
69. Troubleshooting FortiGate
70. Packet Sniffing
71. Fundamental CLI Commands
72. Packet Capture