Course Code: fo_foritgateinfra_sec
Duration: 35 hours
Prerequisites:

• Knowledge of OSI layers
• Knowledge of firewall concepts in an IPv4 network
• Knowledge of the fundamentals of FortiGate, as presented in the FortiGate Security
course

Knowledge of network protocols
• Basic understanding of firewall concepts

Overview:

Fortigate Infrastracture (2 Days)

In this two-day course, you will learn how to use advanced FortiGate networking and security.
Topics include features commonly applied in complex or larger enterprise or MSSP networks, such as advanced routing, transparent mode, redundant infrastructure, site-to-site IPsec VPN, SSO, web proxy, and diagnostics.

FortiGate Security ( 3 Days) (n this three-day course, you will learn how to use basic FortiGate features, including security profiles.
In interactive labs, you will explore firewall policies, user authentication, SSL VPN, dial-up IPsec VPN, and how to protect your network using security profiles such as IPS, antivirus, web filtering, application control, and more. These administration fundamentals will provide you with a solid understanding of how to implement basic network security.

Course Outline:

FortiGate Infrastructure (2 Days)

After completing this course, you should be able to:
• Analyze a FortiGate's route table.
• Route packets using policy-based and static routes for multi-path and load balanced
deployments.
• Configure SD-WAN to load balance traffic between multiple WAN links effectively.
• Inspect traffic transparently, forwarding as a Layer 2 device.
• Divide FortiGate into two or more virtual devices, each operating as an independent
FortiGate, by configuring virtual domains (VDOMs).
• Establish an IPsec VPN tunnel between two FortiGate appliances.
• Compare policy-based to route-based IPsec VPN.
• Implement a meshed or partially redundant VPN.
• Diagnose failed IKE exchanges.
• Offer Fortinet Single Sign On (FSSO) access to network services, integrated with
Microsoft Active Directory.
• Deploy FortiGate devices as an HA cluster for fault tolerance and high performance.
• Deploy implicit and explicit proxy with firewall policies, authentication, and caching.
• Diagnose and correct common problems.

COURSE OUTLINE

1. Routing
2. Software-Defined WAN (SD-WAN)
3. Virtual Domains
4. Layer 2 Switching
5. Site-to-Site IPsec VPN
6. Fortinet Single Sign-On (FSSO)
7. High Availability (HA)
8. Web Proxy
9. Diagnostics
WHO SHOULD ATTEND

Anyone who is responsible for day-to-day management of a FortiDDoS appliance.

FortiGate Security (3 Days)

COURSE OUTLINE

1. Introduction to FortiGate and the Security Fabric
2. Firewall Policies
3. Network Address Translation (NAT)
4. Firewall Authentication
5. Logging and Monitoring
6. Certificate Operations
7. Web Filtering
8. Application Control
9. Antivirus
10. Intrusion Prevention and Denial of Service
11. SSL VPN
12. Dialup IPsec VPN
13. Data Leak Prevention (DLP)
WHO SHOULD ATTEND

Networking and security professionals involved in the management, configuration,
administration, and monitoring of FortiGate devices used to secure their organizations'
networks.
Participants should have a thorough understanding of all the topics covered in