
Upload Fortinet FTV7 folder to the event server, rename the image to qcow2, fix permissions, boot the Fortigate VM, configure port one IP, and verify access via the web GUI.
Upload a Windows Server 2016 image, create a 60 GB disk, and complete the initial Windows setup in a lab using FileZilla or WinSCP.
Add a Windows 10 Pro VM to the lab by uploading folder, creating a 60 GB disk, installing Windows 10 home x64, and saving the image with firefox, putty, wireshark.
add a mikrotik router os to the fortinet lab by uploading the image, renaming to hdr.qcow2, configuring the network, booting, and verifying the web gui with admin and empty password.
FortiAnalyzer delivers parallel IT and OT visibility, turning raw data into actionable intelligence and real-time analytics within Fortinet's security fabric. Supports HIPAA and PCI compliance reporting and threat prevention.
Configure FortiAnalyzer to operate in analyzer mode to aggregate logs from multiple collectors for analysis and reporting, or switch to collector mode to forward and archive raw logs.
Describe how FortiAnalyzer fabric centralizes viewing of devices, incidents, and events across a supervisor and member architecture with API-synced data and integrated logs.
Learn to create and configure fabric connectors for ITSM (ServiceNow, Slack, generic) and security fabric, plus storage connectors for S3, Azure Blob, and Google Cloud.
Configure the Fortinet FortiAnalyzer lab by setting up a Windows 10 host, enabling LAN DHCP on port two, and creating DNS and internet access firewall policies, then test connectivity.
Configure the FortiAnalyzer with minimum hardware, connect port one to the 192.168.1.99 network for web GUI access, then set the default route and activate the Forticloud trial license.
Configure network interfaces on Fortinet devices to separate admin and log traffic, assign ports and IP addresses, enable https and ssh for admin, and disable unnecessary services.
Learn to disable and enable analyzer ports, test connectivity with ping, and configure administrative access using https, http, ssh, snmp, web service, and body manager, separating admin and log interfaces.
Learn to create and edit static routes in the FortiAnalyzer routing table, use the CLI, and perform packet capture on configured interfaces with filters, then download the pcap for Wireshark.
Review the task monitor to track user actions in the FortiAnalyzer, view task details, progress reports, and status, and adjust the task list size in advanced settings.
Configure the FortiAnalyzer to support TLS 1.3 by enabling SSL low encryption, then align FortiGate TLS settings to TLS 1.0 for trial connectivity.
Configure fw2 by setting port 1 to 10.10.20.1/24 and port 3 to 192.168.2.254/24, enable dns 1.1.1.1 and 8.8.8.8, and add static routes to reach connected networks, then verify connectivity.
Add firewall two to FortiAnalyzer by configuring log settings, testing connectivity, and authorizing the device in FortiAnalyzer. Two devices appear, fw1 and fw2, with fw2 encryption enabled for log transmission.
Configure a Fortigate high-availability pair for firewall two (fw2ha2) in an active-passive setup, including management interface, port assignments, and synchronization to ensure seamless failover.
Add an ha cluster to FortiAnalyzer to synchronize logs across up to four FortiGate devices, ensuring same 48 series, then add via credentials or serial numbers and verify.
Change the host name of the Fourier analyzer unit via GUI (system settings dashboard) or CLI (config global); it appears in system information widget, CLI prompt, and SNMP system name.
Configure the Fourier analyzer time by syncing with an NTP server or setting the date and time manually, and enable daylight saving to ensure accurate scheduling, login, and SSL features.
Update the FortiAnalyzer firmware from system settings, choosing Fortiguard or local upload to apply a newer version quickly, while backing up configuration and database first.
Configure the FortiAnalyzer in operation mode, set interfaces and IPs, enable remote access, adjust DNS and routes, and enable the aggregation service while preparing log storage and forwarding.
Configure log forwarding on the collector in phase one to the analyzer at 172.16.1.3 using port two, enabling real-time delivery from all devices with optional masking.
Configure log forwarding and authorize devices in FortiAnalyzer, enabling the collector to send logs to the analyzer and begin log synchronization in the log view.
Learn to view logs by device or log group, inspect log view columns, and open message details with a double-click to analyze data pairs, IPs, ports, and filters.
Customize the FortiAnalyzer log message list view using column settings to add or remove fields, rearrange columns (source/destination MAC, IP, application, event action), and reset to default.
Customize the default columns in FortiAnalyzer to display traffic, events, and firewall action, save as a default for all users, and tailor views by firewall and time.
Monitor all FortiGate event logs by using the log view, filtering by device and time frame, and viewing event types and levels on a focused dashboard.
Learn how to download historical log messages from the log view, choosing traffic logs, selecting pages, and exporting as text or CSV for Excel, with gzip options.
Configure trusted hosts to restrict administrator access to a single IP or allowed subnets, applying to GUI and CLI for highest security.
Monitor administrators via the admin session list in system information, view current sessions with IP and start time, and disconnect or delete a session as needed.
Master managing administrator accounts on FortiAnalyzer: create, edit, delete users, assign admin types (local, radius, ldap), set themes and access levels, and monitor and disconnect active sessions.
Learn to manage administrator profiles by reviewing permissions for restricted, standard, super, and no permission users, and to create, clone, edit, and delete profiles and assign them to users.
Configure active directory on Windows Server and enable ldap authentication for the analyzer by installing AD DS, promoting a domain controller, and creating lab users and groups.
Configure FortiAnalyzer to authenticate via LDAP against a Windows Active Directory, set up remote authentication servers, map LDAP users to administrator accounts, and verify logins from analyzer devices.
Configure admin settings to manage global administrator access on the 4D analyzer, including http and https ports. Set idle timeouts, language, themes, and local users password policy with expiry.
Configure FortiAnalyzer high availability to provide real-time redundancy and secure log synchronization across up to four units, including synchronized configuration and a cluster virtual IP.
Configure FortiAnalyzer HA by assigning a non-used virtual IP, syncing FortiAnalyzer units, adjusting the heartbeat, and verifying logs and port connections to ensure continuous synchronization.
Fortinet Certified Professional (FCP) FortiAnalyzer Lab Course is an immersive and hands-on training program designed to provide participants with practical experience in configuring, managing, and optimizing the FortiAnalyzer platform within a cybersecurity environment. This lab-intensive course complements theoretical knowledge with real-world scenarios, ensuring that participants develop the skills needed to proficiently administer FortiAnalyzer and extract actionable insights from log data.
Key Practical Learning Objectives:
Basic Setup and Configuration:
Set up a FortiAnalyzer environment from scratch.
Configure initial settings, including network interfaces and system parameters.
Log Management and Analysis Labs:
Practice configuring log settings for various Fortinet devices.
Analyze and interpret logs generated by FortiGate, FortiManager, and other supported devices.
Explore different log processing techniques for efficient data analysis.
User and Role Management Labs:
Create and manage user accounts with varying roles and permissions.
Implement access controls to restrict user access based on organizational requirements.
Event Handling and Notification Labs:
Configure event handling policies to automate responses to specific events.
Set up notifications and alerts for critical security incidents.
Integration Labs:
Integrate FortiAnalyzer with FortiGate.
Practice leveraging the integrated approach for a unified security management experience.
Backup and Restore Labs:
Perform backup and restore procedures for FortiAnalyzer configurations and data.
Simulate disaster recovery scenarios and practice restoring the system.
Troubleshooting and Optimization Labs:
Identify and resolve common issues related to FortiAnalyzer operation.
Optimize FortiAnalyzer performance based on best practices.
The FortiAnalyzer Administrator Lab Course emphasizes practical application through hands-on labs, simulations, and real-world scenarios. Participants will have the opportunity to work with live FortiAnalyzer instances, reinforcing theoretical concepts and gaining confidence in their ability to administer FortiAnalyzer effectively. Upon completion, attendees will be equipped with the hands-on skills necessary to navigate and manage FortiAnalyzer in diverse cybersecurity environments.