FGT1 01 Introduction
FGT1 01 Introduction
2
Traditional Network Security
VPN
Intrusion Prevention
Application Control
Web Filtering
WAN Optimization
Antispam
Antivirus
Firewall
3
FortiGate Capabilities
VPN
Intrusion Prevention
Application Control
Web Filtering
WAN Optimization
Antispam
Antivirus
FortiGate Firewall
and more…
4
Platform Design
Web
Firewall Antivirus
Filter
IPS …
FortiOS
5
FortiGuard Subscription Services
6
Modes of Operation
NAT Transparent
7
Operation Modes & the OSI Model
N
A
T
N
A
T
Transp.
8
Factory Default Settings
9
Resetting a Lost “admin” Password
User: maintainer
Password: bcpb<serial-number>
All letters in <serial-number> must be upper case: “FGT60…” etc.
10
Console Port
11
Administration Methods
GUI
FortiExplorer, Web Browser (HTTP, HTTPS)
CLI
Console, SSH, Telnet, GUI Widget
12
FortiExplorer
13
FortiExplorer
14
Administrator Profiles
15
Administrator Profiles: Permissions
16
Administrator Profiles: Hierarchy
17
Two-Factor Authentication
18
Other Two-Factor Authentication
19
Administrative Access: Trusted Sources
20
Administrative Access: Ports
21
Administrative Access: Protocols
• Each interface’s
management
protocols
enabled separately
o Separate IPv4 & IPv6
o IPv6 options hidden
by default
22
Features Hidden by Default
23
Features Hidden by Default: Security Features
• NGFW
o Next Generation Firewall
o Line Speed Inspection
• ATP
o Advanced Threat Protection
o Focuses on protecting PCs
• WF
o Web Filtering
• Full UTM
o All inspection profiles
24
Interface IPs
25
FortiGate as a DHCP Server
26
DHCP Server: IP Reservation
27
DHCP Logs
28
FortiGate as a DNS Server
29
DNS Forwarding
30
DNS Database: Configuration
31
Static Gateway
32
Configuration Files
33
Configuration File Format
Model
Firmware Major Version
34
Per VDOM Configuration Files
35
Upgrade
36
Downgrade
37
Upgrade via FortiExplorer
38
Review
39