
Learn to administer Fortinet Fortigate firewalls via web interface and command line. Configure firewall policies, NAT, and static routes, and explore antivirus, web filtering, application control, backups, and automation.
Follow the course in order to learn topics from the beginning, practice with a firewall lab, and use the DNS and graphical network simulator section for setup and exercises.
Explore the graphical network simulator (DNS) to set up a Fortinet test environment with virtual Fortigate appliances, analyzer, and manager, by installing DNS in a Linux distribution for nested virtualization.
Install the graphical network simulator on Ubuntu using an apt repository, install Docker, and run Fortigate appliances inside Docker to test web filtering policies.
Create your first network project in DNS, set up a switch and two virtual PCs, connect them, assign IPs, and test with ping, while exploring Fortigate devices in NSS marketplace.
Set up a Fortigate appliance on Linux by importing qcow2 and Fortigate firmware via qemu kvm, then log in with admin and configure NAT for web interface and CLI.
Activate a FortiGate evaluation license by logging into the web interface, selecting a trial with limits or uploading a full license, then reboot and explore dashboards and basic administration.
Launch a web browser inside NSS by importing a web term appliance from the marketplace, then use Firefox with network utilities to access device web interfaces and simulate traffic.
Access FortiGate help via official Fortinet support, the Netcom portal, and tickets, web chat, or phone support, plus the D'oxford Netcom knowledge base and community forums.
Configure FortiGate interfaces via the web interface by setting static or dhcp ip addresses, assigning friendly names and roles, then adjust admin access and enable dhcp on internal networks.
Back up Fortigate configurations via the web interface to local PC or USB, using Fortios or YAML formats, with optional password masking or encryption, then restore by upload and reboot.
Learn how Fortinet firewall policies manage traffic using the web interface, including creating rules, configuring sources and destinations, and understanding the implicit deny and top-down rule processing.
Demonstrates how to store multiple FortiGate configuration revisions directly on the device, compare changes with a diff, and restore or delete revisions through the web interface.
Create a new firewall rule to allow a test client to access websites via https, adjust policies, enable dns, and save a new revision in the FortiGate web interface.
Use the policy match tool in the FortiGate web interface to simulate traffic and reveal the matching policy, its name, its id, and whether it allows or blocks the traffic.
Explore Fortigate system settings in the web interface, including hostname, time zone, NTP synchronization, admin ports (HTTPS and SSH), certificates, single sign-on, password policy, and startup and disk options.
Upgrade firmware to patch vulnerabilities and gain new features, following the recommended upgrade path and reviewing release notes, known issues, and CVE numbers.
Explore how to configure NGFW mode (profile-based or policy-based), enable central SNAT for source NAT, and use VDOMs to create separate firewall units in FortiGate.
Master FortiGate NAT concepts by configuring destination and source nets, virtual IP mappings, and port forwarding, plus dynamic IP pools for flexible policy-based translation.
Master advanced firewall policies by enabling security profiles such as antivirus and web filtering, exploring interface pair, sequence, and sequence grouping views, and configuring DNS, application control, and SSL/SSH inspection.
Configure the antivirus security profile on Fortigate and test malware blocking with the eicar test file. Enable ssl inspection to analyze encrypted traffic and observe end-user block messages.
Create a new TCP port 102 service object and assign it to a firewall policy to enable PLC communication on FortiGate.
Learn how to add static routes in the FortiGate web interface, configure destinations like 0.0.0.0/0, set gateways and interfaces, and adjust administrative distance and route priority.
FortiGate administrative accounts and profiles in the web interface, configure local, rest API, and SSO admins, assign profiles, enable two-factor authentication, restrict logins with trusted hosts, and apply least-privilege access.
Explore the FortiGate command line via ssh or the integrated web interface console, review current configuration details, and practice making command line interface changes through hands-on exercises.
Access the Fortigate command line via the web interface console, the NSS tool, or a direct cable, and securely via SSH from Linux, Windows, or macOS.
Explore the FortiGate CLI's execute command family, use ex and tab completion to view commands, and learn to run reboot, shutdown, ping, backup, and factory reset with execute.
Learn to configure FortiGate from the CLI using config commands, including DNS, interface, and FortiGuard settings, with show and show full configuration for verification.
Master FortiGate cli diagnose commands, including diag shortcuts, top, session, and grep, and use flow debug to analyze and troubleshoot traffic with filters in real time.
Learn how to use show and show full configuration in the FortiGate CLI to display current settings, including non-default and default values, with filtering and scripting to automate tasks.
Learn to use get commands to display applied FortiGate settings directly in the command-line interface, compare get with show, and view default values with get full configuration.
Use the FortiGate command line interface to view firmware and serial numbers, ping targets via execute ping, create firewall policies, and analyze traffic with diag debug flow and show configuration.
Capture and analyze traffic on FortiGate via web interface or CLI, apply basic or advanced filters, save or download pcap files, and inspect packet headers with Wireshark.
Configure FortiGate email notifications using SMTP settings, Gmail app passwords, and CLI commands to test delivery, troubleshoot issues, and enable automation stitches with event-driven emails.
Automation stitches trigger actions after defined events across the security fabric. Create triggers and actions, such as email notifications, script execution, or IP bans.
Explore how FortiGate traffic shaping enforces maximum bandwidth and quality of service by using per IP, shared, and reverse shapers with configurable priority and guaranteed bandwidth.
Configure vlan 100 on the switch and fortigate to enable network segmentation, with port 1 as an access port and port 0 as a 802.1Q trunk.
Explore Fortinet FortiGate vpn configurations, including remote access client-to-site vpn with ipsec and ssl vpn, and site-to-site ipsec tunnels between firewalls.
Configure an ipsec remote access vpn on Fortigate using the wizard, create a vpn user and group, test with Forticlient to access internal resources.
Configure ssl vpn on FortiGate via cli and web interface, enable web mode, set portals, and define authentication, certificates, and firewall policies.
Test the ssl vpn connection using forticlient and the web portal, verify tunnel mode and web mode, and confirm reachability and access to internal systems via icmp, rdp, and ssh.
Demonstrates configuring an IPsec site-to-site VPN between FortiGate firewalls. Set up tunnels, static routes, firewall policies, and address groups to enable inter-network access.
Install and integrate 4d manager to centrally manage Fortinet products, then deploy changes from 4d manager to 4d gate with history, diffs, and traceable change notes.
Install and configure the 4D manager appliance from the NSE marketplace, import the image, and access its web interface for centralized FortiGate management.
Set up FortiManager by assigning a static IP, activating the license, and connecting a FortiGate for centralized management, completing the basic FortiManager configuration.
Import and synchronize Fortigate firewall policies and objects into Fortimanager and 4D manager, mapping interfaces, handling conflicts, and deploying changes to Fortigate devices.
Edit firewall policies and objects in Fortimanager, adding snmp and adjusting policy details; install changes to Fortigate via the install wizard, review diffs, logs, and change nodes for traceability.
Apply and install FortiManager changes to FortiGate device settings—such as interface, VPN, and system settings—using the install wizard, then verify the deployment via the FortiGate web interface or CLI.
Demonstrates accessing a Fortigate via the 4D manager's ssh cli, enabling command interaction, clearing output, and recording history. Shows scripts to apply settings to multiple gates with a few clicks.
Learn to add and run scripts on FortiManager to automate CLI tasks on FortiGate devices, with TLS 1.2 HTTPS, comments, and execution history.
Configure firmware templates to schedule and automate upgrades across Fortigate devices and clusters, set install windows, choose upgrade paths, and verify compatibility with FortiManager and 4D manager.
Explore 4D Manager features for FortiGate devices, including system templates, per-device mapping, and a VPN Manager; manage device groups, licenses, and Adams for role-based access across large environments.
Connect and install FortiAnalyzer, integrate it with FortiGate via NSS, and explore the Fraud Analyzer web interface to centralize log analysis across multiple devices in a corporate environment.
Set up FortiAnalyzer as the central logging and reporting tool by importing the appliance in NSS, deploying version 7.4.3, and connecting to the web interface.
Configure FortiAnalyzer with a static IP, activate the trial license via Forticloud, and connect a FortiGate; authorize the device and start log collection.
Use the log view in the 4D analyzer to monitor Fortigate traffic, filter by time, source IP, and log level, and inspect system and event logs from a central interface.
Simulate blocked traffic with Fortigate, view and analyze the logs in the analyzer log view, and filter for IP or policy violation to study SSH block events.
Create custom views in the analyzer to display logs by criteria with one click, then generate charts and reports from filtered SSH traffic over the last seven days.
Create a chart from a custom view with the chart builder in the 4D analyzer, selecting device ID, destination IP, and service, grouped by destination IP and ordered by service.
Monitor real-time logs and traffic with 4D analyzer, view VPN connections and thread details, and map devices by location while auditing admin events and resource usage.
Learn how to harden Fortigate security via the web interface by restricting administrative access, using trusted hosts, enabling two-factor authentication, and changing default admin credentials and ports.
Strengthen FortiGate security with cli-based hardening: enable strong crypto, disable steady keys for tls sessions, and enforce tls 1.3 for https admin access.
Configure local-in policies to govern access to FortiGate services on the interface, such as web and SSH, using the command line to allow or deny.
Complete the Fortinet FortiGate firewalling masterclass by covering administration, firewall policies, interfaces, routing, upgrades, backups, and security hardening, plus FortiManager, FortiAnalyzer, VPN, automation, VLAN, and traffic shaping.
Welcome to "Fortinet FortiGate - Firewalling Masterclass"!
Do you want to learn how to administrate Fortinet FortiGate firewalls via the web interface and command line? And learn a lot about firewalling in general? Then this course is just right for you!
This course is all about the Fortinet firewall solution. We will teach you how to manage FortiGate firewalls from the ground up in an understandable and practical way. No dry theory, no endless presentations - we concentrate on the essentials and demonstrate the topics live on the system.
Our agenda includes topics such as:
Learn How to Administrate Fortinet FortiGate Firewalls
Manage and Understand Firewall Policies
Configuring Network Address Translation (NAT), Static Routes and Service Objects
Using the Command Line: Display and Change the Configuration
Introduction to FortiManager and FortiAnalyzer
Performing Security Hardening
Advices for Performing Firmware Upgrades
VPN Configuration: Remote Access (IPSec & SSL VPN) and Site-to-Site VPN
Get to Know Security Profiles (AntiVirus, Web Filtering, IPs etc.)
Advanced Topics: e.g. Automation Stitches, Notifications, Traffic Shaping
Managing Administrative Users and Profiles
Setting up a Lab Environment Using GNS3 (Graphical Network Simulator-3)
Backup & Restore the Configuration
Practical Exercises Related to the Presented Topics
Our practice-oriented exercises will help you to apply what you have learned in practice. You will understand how to manage Fortinet firewalls efficiently and how to carry out individual tasks via the command line.
Take this time to master the administration of FortiGate firewalls from the ground up. Get started with our course today and expand your skills in the world of firewalling.
Upon completion, you will be able to mange ForitGates confidently and effectively, whether for your own home lab or for more complex IT projects in a corporate environment.
Are you ready to conquer the world of firewalling? Then enroll now and learn how to manage Fortinet firewalls in an easy-to-understand and practical way!