Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Fortinet FortiWeb WAF Administrator Training
Rating: 4.5 out of 5(94 ratings)
677 students

Fortinet FortiWeb WAF Administrator Training

Hands-on FortiWeb WAF Administration with EVE‑NG Labs for Web Security and Threat Protection with Workbook
Created byAhmad Ali
Last updated 2/2026
English
English [Auto],

What you'll learn

  • Introduction to Web Application Security
  • FortiWeb Configuration and Administration
  • Configuring SSL offloading and inspection
  • Performance Optimization
  • Configure server pools, policies, and protected host names
  • Build and configure a lab environment for FortiWeb step by step.
  • Understand the fundamental concepts of Web Application Firewalls (WAF).
  • Configure Content Routing
  • Protect against DoS/DDoS attacks.
  • Control traffic flow with Redirects & Rewrites.
  • Control traffic flow with Redirects & Rewrites.
  • Enable Bot Protection to stop malicious automated activities.
  • Deploy FortiWeb in EVE‑NG and configure it for real web apps.
  • Implement SSL offloading, load balancing, persistence, and health checks.
  • Protect against common web vulnerabilities
  • Configure Signatures — built‑in and custom signatures
  • Configure Virtual Server, VIPs, and Server Pool
  • Web App Vulnerabilities & Protection

Course content

15 sections78 lectures9h 22m total length
  • Course Introduction & Resources3:00

    Master Fortinet FortiWeb WAF administration through hands-on labs, building a lab, and applying protection to detect and block SQL injection, cross-site scripting, CSR, file upload abuse, and DoS bot attacks.

  • Overview of Web Applications8:36

    Explain what a web application is, how it runs in a browser with a database, and vulnerabilities like sql injection and cross-site scripting, with a web application firewall.

  • Web Application Firewall Concepts10:41

    A web application firewall sits between the user and web servers, inspecting and blocking unsafe HTTP/HTTPS traffic, including forms, cookies, and URLs, to protect web apps.

  • Overview of FortiWeb7:44

    FortiWeb, a Fortinet web application firewall, protects websites and web apps with multi-layer detection and machine learning to block SQL injection, XSS, bot threats, API abuse, and DDoS.

  • Key Features of FortiWeb12:06

    FortiWeb provides web vulnerability scanning with scheduling, IP reputation filtering, ML-based anomaly detection, OWASP top ten protection, API protection, bot mitigation, and flexible deployment across hardware, virtual, container, or cloud.

  • NGFW vs WAF vs IPS12:09

    Compare the roles of next generation firewall, web application firewall, and intrusion prevention system to show why traditional firewalls fall short for web apps.

  • FortiWeb Operation Modes11:03

    Explore FortiWeb operation modes, including reverse proxy, transparent, offline protection, true transparent proxy, and the WCCP/CCP mode, and learn how each fits different network deployments and security needs.

Requirements

  • Basic understanding of networking
  • No prior FortiWeb experience required
  • Access to a PC or virtual environment to build the lab
  • Web Application Fundamentals
  • Virtualization Lab Environment
  • Basic knowledge of EVE‑NG
  • Prior experience with Fortinet products FortiGate
  • Basic Linux or Windows server administration knowledge

Description

Course Description:

Master Fortinet FortiWeb WAF administration with hands-on labs in EVE‑NG and learn how to secure web applications and APIs against real-world threats. This course takes you step by step through deployment, configuration, tuning, and advanced web protection techniques.

You’ll start by setting up FortiWeb in EVE‑NG, adding virtual images, configuring servers and clients, and importing labs. From there, you’ll dive into core WAF concepts, including server policies, virtual servers, VIPs, server pools, and web protection profiles.

Learn how to protect web applications from vulnerabilities such as SQL injection, XSS, CSRF, command injection, file uploads, and web shells. You’ll also configure SSL offloading, load balancing, persistence, content routing, and HTTP rewriting to optimize traffic and improve security.

Advanced sections cover DoS/BOT protection, API gateway security, JSON schema validation, and access control, giving you the practical skills to defend any web application or API. Each module includes realistic labs, testing, verification, and troubleshooting exercises.

By the end of this course, you will be able to confidently deploy, configure, and manage FortiWeb WAFs to protect web applications, detect attacks, and ensure high availability and performance.

Who this course is for:

  • Network and security engineers seeking hands-on WAF experience.

  • Penetration testers and ethical hackers wanting to understand WAF deployment and tuning.

  • DevOps and application security professionals securing web apps and APIs.

  • IT professionals and system administrators enhancing web traffic monitoring and threat protection skills.

Requirements:

  • Basic networking knowledge (IP, routing, VLANs).

  • Understanding of web servers, HTTP/HTTPS, and web application basics.

  • A PC capable of running virtual labs (EVE‑NG, VMware, or VirtualBox).

  • Familiarity with Fortinet products, Linux/Windows server administration, or security tools like OWASP ZAP or Burp Suite.

What You Will Learn

  • Deploy FortiWeb in Reverse Proxy, Transparent, and WCCP modes

  • Configure Web Protection, API Security, and Advanced Threat Defense

  • Implement Signature-based, Behavior-based, and Machine Learning security models

  • Protect applications against OWASP Top 10, SQLi, XSS, CSRF, RCE, and more

  • Configure DoS protection, Bot mitigation, and Geo‑IP controls

  • Build and tune Custom Rules, URL Access Policies, and Parameter Validation

  • Analyze logs, investigate attacks, and perform real‑world troubleshooting

  • Apply best practices for production‑grade WAF deployments

Why This Course Stands Out

  • Hands‑on labs for every major FortiWeb feature

  • Real configurations, not theory or slides

  • Clear, simple explanations — ideal for beginners and professionals

  • Professional, concise delivery aligned with your teaching style

  • Downloadable configs, diagrams, and cheat sheets

  • Lifetime access + regular updates based on new FortiWeb releases

Who this course is for:

  • Network and Security Engineers
  • Penetration Testers & Ethical Hackers
  • DevOps and Application Security Professionals
  • IT Professionals & System Administrators
  • Students and Learners of Cybersecurity
  • Cybersecurity students
  • Individuals looking to enhance their expertise with FortiWeb
  • IT Administrators
  • Network and security professionals preparing for the FCP – FortiWeb 7.4 Administrator exam