Day 0: Introduction to FortiGate and Network Security
Day 1: Initial Setup & Management Plane
FortiGate Introduction and Prerequisites Factory Reset of FortiGate devices Accessing the CLI (Console, SSH) and GUI (HTTPS) Initial Configuration Wizard Management Interface Configuration (IP address, administrative access: PING, SSH, HTTPS) Default Route for Management Access Feature Visibility for GUI Customization Lab 1.1: FortiGate Factory Reset and Management Access Day 1 β Quiz 1: Initial Setup & Management Plane Day 1: Initial Setup & Management Plane | Class Recording π΄π₯ Day 2: Data Plane Fundamentals & Zones
Data Plane Concepts: User traffic forwarding through the firewall Configuring Physical and VLAN Interfaces Zone-Based Security: Creating and assigning interfaces to zones (LAN, WAN, DMZ). FortiGate as a DHCP Server: Configuration of DHCP services, IP ranges, default gateway, DNS servers, and options. Monitoring DHCP clients and leases. LAB 02.1Β - Configure Data Plane Interfaces, Zones, and DHCP ServerΒ Day 2 Quiz 1: Data Plane and Zones Day 2 Quiz 2: DHCP Services Day 2: Data Plane Fundamentals & Zones | Class Recording π΄π₯ Day 3: Network Address Translation (NAT)
NAT Fundamentals: Understanding Network Address Translation (NAT) and Port Address Translation (PAT) Centralized Source NAT Policy: Using the outbound interface IP address (PAT). Dynamic IP Pools: Configuring a range of public IP addresses for one-to-one mapping. Virtual IPs (VIPs): Mapping external IP addresses/ports to internal servers Port Forwarding: Translating specific ports to different internal ports (e.g., external 8080 to internal 80) NAT with and without Zones. LAB 03.1 - Source NAT (SNAT) with PAT and Dynamic IP Pools LAB 03.2: Destination NAT (DNAT) with Virtual IPs (VIPs) Day 3 Quiz 1: NAT Fundamentals Day 3 Quiz 2: Advanced NAT Configuration Day 3: Network Address Translation (NAT) | Class Recording π΄π₯ Day 4: Firewall Policies Basics
Firewall Policy Fundamentals: Core component of FortiGate, controlling traffic flow. Incoming and Outgoing Interfaces/Zones Source and Destination Address Objects (IP addresses, subnets, FQDN, geographic-based ISDB) Service Definitions (HTTP, HTTPS, ICMP, ALL) Schedules for time-based policy enforcement Policy Processing Order: Top-to-bottom evaluation, implicit deny Action Types: Accept (Permit) vs. Deny (Drop) Logging: Logging all sessions vs. security events. LAB 04.1 - Basic Firewall Policy Configuration & Logging LAB 04.2 - Blocking ICMP Traffic to a Specific Destination Day 4 Quiz 1: Firewall Policy Fundamentals Day 4 Quiz 2: Advanced Firewall Policy Concepts Day 4: Firewall Policies Basics | Class Recording π΄π₯ Day 5: Static Routing, Failover, ECMP & Policy Routes
What is IP Routing? FortiGate as an IP router, forwarding packets, local-out traffic Routing Table (RIB & FIB): Components (Network, Gateway IP, Interface, Distance, Metric, Priority) Route Lookup Process Static Routes: Configuring default routes (0.0.0.0/0), next-hop, and outgoing interface Administrative Distance: Tie-breaker for different route sources, preference (lower is better) Static Route Failover: Using administrative distance and priority to create primary and backup routes Equal Cost Multi-Path (ECMP): Load balancing traffic across multiple equal-cost paths (same destination, distance, metric, priority). ECMP Load Balancing Algorithms (Source IP, Source-Destination IP, Weighted) Understanding and Configuring Policy Routes in FortiGate LAB 05.1 - Static Routing Between Networks β Initial Build LAB 05.2 - Floating Static Routes (Default Route Failover) LAB 05.3 - Equal Cost Multi-Path (ECMP) Load Balancing LAB 05.4 - Policy Based Routing (PBR) Day 5 Quiz 1: Static Routing Fundamentals Day 5 Quiz 2: Advanced Static Routing & Failover Day 5: Static Routing, Failover, ECMP & Policy Routes | Class Recording π΄π₯ Day 6: Dynamic Routing Protocols (RIP, OSPF, BGP)
Introduction to Dynamic Routing: Automating routing table updates for large networks Routing Information Protocol (RIP): Simple distance-vector protocol, configuration on FortiGate Open Shortest Path First (OSPF): Link-state protocol, concept of areas (Area 0 Backbone), router ID, configuring interfaces in areas Border Gateway Protocol (BGP): Inter-Autonomous System routing, local AS, neighbors, network advertisements Administrative distance values for RIP (120), OSPF (110), BGP (200 for external, 20 for internal). LAB 06.1 - Routing Information Protocol (RIP) LAB 06.2 - Open Shortest Path First (OSPF) LAB 06.3 - Border Gateway Protocol (BGP) LAB 06.4 - Border Gateway Protocol (iBGP) Day 6 Quiz 1: Dynamic Routing Protocols (RIP, OSPF, BGP) Day 6 Quiz 2: Dynamic Routing Protocols (RIP, OSPF, BGP) Day 6: Dynamic Routing Protocols (RIP, OSPF, BGP) | Class Recording π΄π₯ Day 7: Digital Certificates & SSL/TLS Inspection Fundamentals
Digital Certificates: Public Key Infrastructure (PKI), Certificate Authorities (CAs), X.509 standard, Public/Private Key pairs, self-signed certificates Encryption Basics: Symmetric vs. Asymmetric encryption, hashing, digital signatures Certificate Management on FortiGate: Importing trusted CAs, generating CSRs, importing signed certificates, generating local certificates SSL/TLS Inspection Fundamentals: Why inspect encrypted traffic, concepts of Full SSL Inspection (Deep Packet Inspection, Application Layer Visibility), Certificate Inspection Role of certificates in SSL/TLS inspection (FortiGate acts as a transparent proxy). LAB 07.1 - Digital Certificates β Importing CA Certificate into FortiGate LAB 07.2 - Digital Certificates β Generating CSR and Installing Signed Certificate LAB 07.3 - Digital Certificates β SCEP (NDES) Configuration on FortiGate LAB 07.4 - Digital Certificates β Self-Signed Certificate Generation LAB 07.5 - CRL (Certificate Revocation List) β Using Online Server (DTKCA-LAB-DC01) Day 7 Quiz 01: Digital Certificates & SSL/TLS Inspection Fundamentals Day 7 Quiz 02: Digital Certificates & SSL/TLS Inspection Fundamentals Day 7: Digital Certificates & SSL/TLS Inspection Fundamentals | Class Recording π΄π₯ Day 8: Outbound SSL/TLS Inspection Configuration
Outbound SSL Inspection Profile Creation: Deep Inspection profile, choosing a signing certificate (FortiGate's own CA or an imported one) Attaching the SSL Inspection Profile to a Firewall Policy Client Trust Requirements: Endpoints must trust the FortiGate's signing CA SSL Exemptions: Exempting specific web categories (e.g., Finance, Health) or FQDNs from inspection Troubleshooting outbound SSL inspection (missing security profiles, untrusted CA) LAB 08.1 - Outbound SSL/TLS Inspection Configuration β Profile Creation Day 8 Quiz 01: Outbound SSL Inspection Basics Day 8 Quiz 02: SSL Inspection Configuration & Troubleshooting Day 8: Outbound SSL/TLS Inspection Configuration | Class Recording π΄π₯ Day 8: Outbound SSL/TLS Inspection Configuration | Class Recording π΄π₯ (B1 Recording) Day 9: Inbound SSL/TLS Inspection Configuration
Inbound SSL Inspection Concept: Protecting internal servers from encrypted threats Exporting Web Server Certificates with Private Keys: Process for IIS servers (PFX format) Importing Certificate and Private Key to FortiGate Configuring Inbound SSL Inspection Profile: Using the web server's certificate Attaching to a firewall policy for traffic to the DMZ server Troubleshooting inbound SSL inspection (file filtering issues, inspection not enabled) LAB 09.1 - Inbound SSL/TLS Inspection β Configuration for DMZ Web Server Day 9 Quiz 01: Inbound SSL/TLS Inspection Basics Day 9 Quiz 02: Inbound SSL Inspection Configuration & Troubleshooting Day 9: Inbound SSL/TLS Inspection Configuration | Class Recording π΄π₯ Day 10: Antivirus Configuration
FortiGate Antivirus Capabilities: Stopping viruses and malware Antivirus Components: Signature databases (FortiGuard AV service), AI scan, Grayware scan Antivirus Scanning Modes: Flow-based inspection (optimizes performance) Antivirus Scanning Modes: Proxy-based inspection (more features, thorough, requires >2GB RAM) Advanced AV Features: Virus outbreak prevention (VOS), External Malware Blocklist, EMS Threat Feed, Content Disarm and Reconstruction (CDR) Configuring Protocol Options for AV inspection. LAB 10.1 - Antivirus Configuration β New Antivirus Profile Setup Day 10 Quiz 01: Antivirus Protection & Components Day 10 Quiz 02: Antivirus Features & Configuration Day 10: Antivirus Configuration | Class Recording π΄π₯ Day 11: Web Filtering Configuration
Web Filtering Overview: Controlling web traffic (URL filtering, web content filtering, FortiGuard Web Filtering service) FortiGuard Categories: Websites categorized, actions (Allow, Block, Warn, Authenticate, Quotas) Creating Web Filter Profiles: Flow-based vs. Proxy-based URL Filtering: Blocking/exempting specific URLs (static URL filters, wildcards, regular expressions) Safe Search enforcement Troubleshooting web filtering (FortiGuard connection status, log analysis). LAB 11.1 - Web Filtering Configuration β FortiGuard Category-Based Filtering LAB 11.2 - Web Filtering β Custom URL Filtering (Static URL Block List) Day 11 Quiz 01: Web Filtering Basics & Components Day 11 Quiz 02: Web Filtering Profiles & Troubleshooting Day 11: Web Filtering Configuration | Class Recording π΄π₯ Day 12: DNS Filtering
DNS Filtering for Security: Protecting against malicious domains, botnet, and command & control (C2) servers FortiGuard Category-Based DNS Filtering: Blocking domains based on FortiGuard categories Static Domain Filters: Blocking or redirecting specific domain names (wildcards, regular expressions, exact strings) External IP Blocklists: Importing lists of known malicious IP addresses for DNS filtering Monitoring DNS filter logs and botnet activity widgets Troubleshooting DNS filtering issues. LAB 12.1 - DNS Filtering Configuration β Security Profile Setup Day 12 Quiz 01: DNS Filtering Basics & Components Day 12 Quiz 02: DNS Filtering Configuration & Troubleshooting Day 12: DNS Filtering | Class Recording π΄π₯ Day 13: Application Control
Application Control Overview: Identifying and controlling applications beyond ports and protocols Uses the IPS Engine: Flow-based scanning for application detection Application Categories: FortiGuard-defined application categories Application Signatures: Detection based on application-specific patterns Vendor-based Control: Matching applications based on their vendor (e.g., Meta/Facebook) Action Types: Monitor, Block, Allow, Quarantine LAB 13.1 - Application Control Configuration β Application Filtering Profile Day 13 Quiz 01: Application Control Basics & Categories Day 13 Quiz 02: Application Control Features & Configuration Day 13: Application Control | Class Recording π΄π₯ Day 14: Intrusion Prevention System (IPS)
IPS Overview: Detecting and preventing network attacks, protecting against exploits IPS Components: IPS signature databases, protocol decoders, IPS engine IPS Sensors: Collections of IPS signatures and filters, severity levels Action Types: Block, Reset, Monitor, Quarantine for specific signatures Blocking Malicious URLs/Command and Control (C2) traffic Vulnerability Types: SQL Injection, Cross-Site Scripting (XSS), Buffer Overflows, Path Traversal, Code Injection Monitoring IPS logs and security dashboard LAB 14.1 - Intrusion Prevention System (IPS) β Profile Configuration and Deployment Day 14 Quiz 01: IPS Overview & Components Day 14 Quiz 02: IPS Action Types & Vulnerabilities Day 14: Intrusion Prevention System (IPS) | Class Recording π΄π₯ Day 14: Intrusion Prevention System (IPS) Part II (Practical) | Class Recording π΄π₯ Day 15: DoS Prevention
Denial of Service (DoS) Prevention Overview: Protecting network resources from flood attacks DoS Policy Configuration: Defining source/destination, service, and anomaly thresholds ICMP Flood Protection: Detecting and blocking excessive ICMP packets to a destination TCP SYN Flood Protection: Mitigating SYN flood attacks by setting thresholds for TCP SYN requests ICMP Sweep Detection: Identifying attackers scanning multiple IPs with ICMP TCP Port Scan Detection: Blocking clients attempting to scan ports on internal servers Quarantine Action for Attackers (CLI): Blocking source IP for a period (e.g., 5 minutes) Monitoring DoS anomaly logs LAB 15.1 - Denial of Service (DoS) Prevention β Policy Configuration Day 15 Quiz 01: DoS Prevention Overview & Policy Configuration Day 15 Quiz 02: DoS Protection Techniques & Troubleshooting Day 15: DoS Prevention | Class Recording π΄π₯ Day 16: Site-to-Site IPsec VPN
IPsec VPN Basics: Benefits (secure remote access), encapsulation (tunnel mode), negotiation, authentication IKE Phase 1 & Phase 2: Understanding the two phases of tunnel establishment, proposals (encryption, hashing, DH groups), selectors (encryption domain) IPsec Wizard: Simplifying configuration for site-to-site VPNs Manual IPsec Configuration: Configuring Phase 1 (Network, Authentication, Proposals, XAUTH) and Phase 2 (Selectors, Proposals) settings Route-Based IPsec VPNs: Using virtual tunnel interfaces Firewall Policies for IPsec Traffic: Allowing traffic through the VPN tunnel Troubleshooting IPsec VPNs (Phase 1/2 mismatches, routing, permissions) LAB 16.1 - Site-to-Site IPsec VPN β Wizard and Custom Configuration LAB 16.2 - Site-to-Site IPsec VPN β Certificate-Based Authentication Day 16 Quiz 01: IPsec VPN Overview & Configuration Day 16 Quiz 02: IPSec Configuration & Troubleshooting Day 16: Site-to-Site IPsec VPN | Class Recording π΄π₯ Day 17: SSL VPN (Remote Access)
SSL VPN Overview: Providing remote users secure access to the internal network SSL VPN Deployment Modes: Focusing on Tunnel Mode using FortiClient (virtual adapter) SSL VPN Portals: Configuring portal settings, split tunneling (policy-based destination), enabling/disabling web mode IP Pools: Defining IP address ranges for SSL VPN clients SSL VPN Settings: Defining listeners (interface, port), authentication realms Firewall Policies for SSL VPN: Allowing access from SSL VPN interface to internal resources FortiClient Usage: Connecting to SSL VPN Troubleshooting SSL VPN (routing, permissions, portal settings) LAB 17.1 - SSL VPN (Remote Access) β FortiGate Server Configuration LAB 17.2 - IPsec VPN (Remote Access) β FortiClient Configuration Day 17 Quiz 01: SSL VPN Overview & Configuration Day 17 Quiz 02: SSL VPN Portal & Troubleshooting Day 17: SSL VPN (Remote Access) | Class Recording π΄π₯ Day 18: User Authentication & Two-Factor Authentication
User Authentication: Why User Authentication is Needed Local Accounts: Creating and managing local user accounts Remote Server Accounts: Integrating with external authentication servers (LDAP, RADIUS) for user and administrator authentication Authentication Policies: Enforcing authentication for traffic flows (Active/Passive) Two-Factor Authentication (2FA): Enhancing security for admin and user access FortiToken: Generating One-Time Passwords (OTPs), time-based, FortiToken Mobile, Push Notifications NTP server importance for 2FA synchronization LAB 18.1 - User Authentication β Local & LDAP Integration LAB 18.2 - Two-Factor Authentication (2FA) β Email-Based OTP Day 18 Quiz 01: Administrator Access Control & Authentication Day 18 Quiz 02: Two-Factor Authentication & FortiToken Day 18: User Authentication & 2FA | Class Recording π΄π₯ Day 19: FortiGate Administrator Authentication & 2FA
Administrator Accounts on FortiGate Admin Access Profiles Securing Admin Login with Trusted Hosts Local-In Policies (Management Traffic Control) Administrator Two-Factor Authentication (2FA) LAB 19.1 - FortiGate Administrator Authentication & Two-Factor Authentication LAB 19.2 - FortiGate Administrator Authentication using LDAP (AD Integration) Day 19: FortiGate Administrator Authentication & 2FA | Class Recording π΄π₯ Day 20: High Availability (HA)
HA Overview: Enhanced reliability and increased performance using multiple FortiGate devices HA Requirements: Same model, firmware, licensing, hard drive configuration, operating mode HA Operation Modes: Active-Passive (Primary/Secondary tasks), Active-Active (session distribution) HA Cluster Synchronization: Configuration, FIB entries, DHCP leases, ARP table, FortiGuard definitions, IPSec tunnel SAs HA Failover Types: Detecting failures, virtual MAC addresses Monitoring HA Status (GUI widget, CLI commands) LAB 20.1 - High Availability (HA) β Active-Passive Configuration LAB 20.2 - High Availability (HA) β Active-Active Configuration Day 20 Quiz 01: High Availability (HA) Overview & Configuration Day 20 Quiz 02: HA Operation Modes & Troubleshooting Day 20: High Availability (HA) | Class Recording π΄π₯ Day 21: SD-WAN Configuration
SD-WAN Overview: Software-defined approach to steer WAN traffic, use cases (DIA, site-to-site) SD-WAN Components: Members (physical/logical interfaces), Zones (logical grouping of members) SD-WAN Rules: Defining traffic steering policies based on criteria (source/destination, internet service, application) Traffic Steering Strategies: Manual (interface preference), Best Quality (based on SLA measurements like latency, jitter, packet loss), Lowest Cost Monitoring SD-WAN (traffic logs, link usage, quality status) LAB 21.1 - SD-WAN Configuration β Traffic Steering through DTKCA-FGT-2 Day 21 Quiz 01: SD-WAN Overview & Core Components Day 21 Quiz 02 : SD-WAN Rules & Monitoring Day 21: SD-WAN Configuration | Class Recording π΄π₯ Day 22: Fortinet Security Fabric
Fortinet Security Fabric Definition: Holistic network security solution, centralized management, automated defense Participating Devices: FortiGate (root/downstream), FortiAnalyzer, FortiSandbox, FortiManager, FortiClient, etc Benefits: Consistent objects, centralized logging (FortiAnalyzer/Cloud), automated actions, improved security posture Deploying the Security Fabric: Adding FortiGates as downstream devices Global Address Objects: Synchronizing address objects across fabric members Automation Stitches: Triggers (e.g., virus logs), Actions (e.g., email notification, quarantine) Security Rating: Identifying security gaps and prioritizing tasks LAB 22.1 - Connecting FortiGate to FortiAnalyzer LAB 22.2 - Connecting FortiGate to FortiManager Day 22 Quiz 01: Security Fabric Overview & Components Day 22 Quiz 02: Security Fabric Configuration & Monitoring Day 22: Fortinet Security Fabric | Class Recording π΄π₯ Day 23: Diagnostics & Troubleshooting
Troubleshooting Methodology: The RAP acronym (Routing, Address Translation, Permissions) as a guiding principle General Diagnosis: Monitoring abnormal behavior, traffic spikes, physical/network layer issues Packet Sniffer: Capturing traffic on interfaces, filtering options, saving as PCAP Debug Flow: Real-time analysis of packet processing through FortiGate kernel diagnose sys session list: Viewing active sessions, filtering by source/destination execute ping, execute traceroute: Basic connectivity and path analysis Log Analysis: Forward traffic logs, security event logs (AV, Web Filter, IPS, App Control) CPU and Memory Diagnosis: diagnose sys top, process monitor, conserve mode, high CPU/memory troubleshooting Day 23: Diagnostics & Troubleshooting | Class Recording π΄π₯ Day 24: Course Review & Exam Preparation
Comprehensive Review: Revisit key concepts from all modules (Fundamentals, Policies, Security Profiles, VPNs, HA, SD-WAN, Security Fabric, Troubleshooting) Key Configuration Steps: Summarize essential configurations for each feature Common Troubleshooting Scenarios: Review previous troubleshooting assignments and discuss best practices FortiGuard Services: Recap their role and importance across different security features FortiGate Study Guide Navigation: How to use the official documentation for further study Exam Tips and Strategies: Approach to different question types, time management Day 24: Course Review & Exam Preparation | Class Recording π΄π₯
No comments yet.