A FortiGate is a firewall, a router and a VPN gateway in one box. This course builds one, step by step, on a small lab: FGT1 connects a LAN and a DMZ web server to the Internet. Each module ends with a lab where you configure it yourself and then fix a broken version. You need IP addressing and basic routing; a FortiGate VM or any FortiGate model is enough to follow along.
- 1. LAN to Internet: PC1 browses the web; FGT1 checks its policies and translates the source address to 203.0.113.2.
- 2. Internet to DMZ: Later modules publish WEB1 to the Internet with a virtual IP.
RouteLearn is independent and is not affiliated with or endorsed by Fortinet. Fortinet, FortiGate, FortiOS and FortiGuard are trademarks of Fortinet, Inc. Commands and menus follow FortiOS 7.4 and 7.6; other releases can differ slightly.
What's in this course
4 modules · 18 lessons · about 4 hours of reading
Module 1: Getting Started
What a FortiGate is, first login, the CLI, interfaces and keeping the device safe to run.
- 1.1What a FortiGate is10 min · Beginner10 min · Beginner
- 1.2First login and basic setup11 min · Beginner11 min · Beginner
- 1.3The FortiOS CLI10 min · Beginner10 min · Beginner
- 1.4Interfaces, VLANs and zones13 min · Intermediate13 min · Intermediate
- 1.5Administrators, backups and firmware10 min · Intermediate10 min · Intermediate
Module 2: Firewall Policies
How a FortiGate decides what to allow, the objects policies use, and how to find which policy a session hit.
- 2.1How firewall policies work11 min · Beginner11 min · Beginner
- 2.2Addresses, services and schedules11 min · Intermediate11 min · Intermediate
- 2.3Configuring firewall policies12 min · Intermediate12 min · Intermediate
- 2.4Which policy did it hit?12 min · Intermediate12 min · Intermediate
- 2.5Lab: LAN, DMZ and Internet policiesLab25 min · Intermediate25 min · Intermediate
Module 3: NAT
Source NAT with the interface address or IP pools, publishing servers with virtual IPs, and central NAT.
Module 4: Routing and SD-WAN
How a FortiGate chooses a path: the routing table, static and policy routes, and SD-WAN across two Internet links.