
Explore modern fortigate security, including zero-day protection, sandboxing, and email security, while designing networks with byod, dmzs, and iot behind the firewall.
Configure FortiGate to design a distributed network with access, collapsed core, and internal segmentation firewall, including DMZ and IPsec VPN. Troubleshoot with granular policies, DNS, and DHCP on FortiGate.
Explain FortiGate subscription services and licenses, including validity, and contrast layer four with layer seven inspection, while highlighting antivirus, web filter, IPS, sandbox, and FortiOS deployments in VMware.
Discover how Fortigate uses a network processor, security processor, and content processor to inspect layer seven content, offload sessions from the cpu, and handle ipsec encryption.
Explore FortiGate sandbox antivirus features and how packets are processed by network, security, and content processors. Learn about parallel processing concepts and hands-on lab setup with Ovf and VMware.
Configure Fortigate by designing port1 as the management interface and applying a static IP scheme aligned with the topology, then troubleshoot using GUI and CLI commands, noting licensing caveats.
Explore FortiGate firewall management with GUI, zones, and zone-based policies. Learn to create zones (inside, outside, DMZ), group interfaces, simplify policies, and troubleshoot via routing and ISP scenarios.
Configure FortiGate zones and interfaces, assign wan and dmz roles, set up routes, DHCP, and DNS, follow naming conventions, and implement security practices like using VPN and avoiding HTTP ping.
Configure FortiGate policies using feature visibility to allow unnamed policies, and create multi-interface policies with unique IDs for scalable rule management.
Explore the FortiGate dashboard and widget customization to monitor bandwidth with ISP interfaces. Learn the differences between NAT and transparent modes and compare flow-based versus proxy-based inspection.
Explore FortiGate dashboards, license status, and device health, including backup and restore configurations. Configure administrators, two-factor authentication, trusted hosts, and read-only monitors while reviewing time settings and security ports.
Master FortiGate password recovery and security practices, including maintainer resets and two-factor authentication, while configuring static IP, interface aggregation, policy sequencing, and robust logging with network packet capture.
Configure FortiGate objects, FQDNs, and ISDB entries, and define services and schedules for secure access. Implement policy-based routing (PBF) and session management to optimize firewall traffic.
Explain netting as network address translation, translating private IPs and ports to public ones, distinguishing source and destination nat, and noting auto versus manual nat and security benefits.
Compare FortiGate central netting and policy netting, learn policy-based nat with source net (ip pool) and destination net (virtual ip), plus static net, port forwarding, overload, and troubleshooting.
Day 4.3 walks through FortiGate troubleshooting using diagnose debug flow to trace packets, sessions, and routes, and to verify policy hits and confirm gateway and interface correctness.
Learn to configure FortiGate debug flow filters, diagnose sessions, and interpret fast path versus routing, including how policy, NAT, and port translation affect traffic.
Explore FortiGate NAT concepts with IP pools and 1-to-1, fixed port range, and port block allocation, including use of outgoing interface for LAN to WAN and diagnosis of NAT exhaustion.
Configure a destination NAT with a virtual IP to map a public IP to a DMZ server on Fortigate, and set firewall policies with port forwarding.
Explore FortiGate packet flow, destination NAT, and port translation through practical troubleshooting. Filter diagnosis sessions by IP, map external to internal addresses, and review policy IDs.
Explore FortiGate policy design, port handling (8080 to 80), and IPsec VPN basics, including phase one and two, to troubleshoot public IP traffic and rule formatting.
Enable Fortigate central net. Define source nets and destination nets, and align firewall policies with central NAT and IP pools.
Master FortiGate troubleshooting by focusing on routing and policy, using GUI over CLI, checking sessions, policy IDs, NAT pools, and route lookup to diagnose internet access.
Master FortiGate user authentication and user-based policy design, including LDAP group integration, while diagnosing NAT reachability and public IP scenarios to ensure secure access.
Configure local and remote server authentication on FortiGate, including LDAP, RADIUS, TACACS, and two-factor authentication, plus captive portal setup and a local user test.
Learn to implement two-factor authentication on FortiGate using FortiToken and mobile apps, configure local or LDAP users, and review log privacy settings for anonymity in Europe.
Learn to configure FortiGate LDAP authentication for remote and local users, implement active and passive authentication concepts, create LDAP users and groups, test connectivity, and enable two factor authentication.
Explore two-factor authentication on FortiGate using radius and ldap, including authentication flows with access request, access accept/reject, access challenge, and otp, plus fallback policies and admin security considerations.
Learn how certificate inspection and SSL inspection work in FortiGate, including outbound versus inbound flows, profile customization, and implementing full SSL inspection with client certificate installation.
Apply ssl deep inspection with security profiles; note web filtering works without ssl inspection, and learn tls handshake, client hello, server hello, cipher suites, and sni.
Explore how FortiGate performs certificate inspection and deep inspection to detect man-in-the-middle threats, explain certificate authorities and trusted roots, and discuss deployment of self-signed certificates across networks.
Explore how certificates issued by a firewall establish trust, verify revocation via CRL and serial numbers, and how public key pinning protects against man-in-the-middle attacks.
Explain how FortiGate exempts reputable websites, handles SSL inspection, and manages certificates (CSR, PKCS#12, self-signed) to enable end-to-end deep inspection with security profiles.
Explore logging and monitoring in FortiGate, enabling logs in policies, local vs remote logging, and navigating log basics, search, monitor, and protect logs for effective troubleshooting.
Learn how Fortigate logs distinguish traffic logs (forwarding, local, sniffer) and event logs, then use policy IDs and allow/deny actions to troubleshoot DNS and IP connection errors.
Analyze Fortigate event logs for IPsec, SSL, and user activity, and learn to read log headers and bodies. Build a practical log management plan with FortiAnalyzer options and best practices.
Explore FortiGate logging management: monitor disk usage, configure seven-day log retention, enable real-time remote logging to FortiAnalyzer or FortiCloud, and filter traffic and event logs.
Explore Forticloud free tier with seven days of log storage, compare 40 analyzer and 40 manager with FortiSIEM for storage and management, and learn central versus policy-based netting and forwarders.
Learn how FortiGate logs and FortiAnalyzer work together, including log buffering, queueing, and dropping policies, and how to configure syslog and analyzer settings via cli.
Enable reliable logging to switch from UDP to TCP and encrypt logs with TLS 1.2 for FortiAnalyzer, then test and filter logs to verify delivery.
Master FortiGate log management with diagnose log display and log filter, view traffic logs and live 40 view sessions, and configure log age and file size.
Master IPS intrusion prevention by detecting threats, blocking them, and logging events, while Fortigate uses signature and anomaly defenses within a multi-layer security approach.
Learn how intrusion prevention signatures identify and block threats targeting servers—configuring filters, selecting signatures, and applying policies for web, mail, and network traffic.
Understand how botnets use a command-and-control center to coordinate infected PCs for DDoS attacks, phishing, seo-driven sites, and credential theft, and why multi-layer security is essential.
Configure a Fortigate ddos policy for a DMZ server, defining source and destination zones, address and service, then apply layer three and four anomaly thresholds to block or monitor traffic.
Welcome to the ultimate course for mastering Fortinet network security solutions! This course provides a comprehensive and in-depth exploration of FortiGate devices, FortiOS, and all the essential concepts needed to secure and manage modern networks. Whether you're new to network security or looking to advance your skills, this course covers everything you need to know, from the basics to the most advanced configurations.
You’ll start by learning how to configure and manage FORTIGATE DEVICES, implementing basic security features, and optimizing network performance. As the course progresses, you'll dive into more complex topics such as FIREWALL POLICIES, VPN CONFIGURATION, ADVANCED THREAT PROTECTION, INTRUSION PREVENTION SYSTEMS (IPS), and SECURITY FABRIC INTEGRATION. We’ll also cover advanced features like , HIGH AVAILABILITY, and TRAFFIC SHAPING to ensure your networks are not only secure but also efficient.
Additionally, you’ll gain an in-depth understanding of USER AUTHENTICATION, SECURITY LOGGING AND MONITORING, and WEB FILTERING. You'll also be introduced to VIRTUAL LANs (VLANs) and ADVANCED ROUTING to manage traffic flow across multiple devices and networks. ADVANCED Troubleshooting, CONTENT INSPECTION and ANTI-BOTNET TECHNOLOGIES will also be covered, ensuring your network is protected from the latest cyber threats.
This course goes beyond just theory – you'll gain hands-on experience through practical labs and troubleshooting exercises. You’ll learn how to diagnose and resolve network issues effectively, from basic to advanced troubleshooting scenarios. By the end of the course, you’ll be equipped to manage and secure enterprise networks, deploy complex security solutions, and handle real-world security challenges with confidence.
Join this course today to become a skilled network security professional, ready to take on the challenges of securing today’s dynamic digital environments.