Course menu

FortiGate Administrator

Configure and run a FortiGate firewall the way administrators do day to day: from the first login to firewall policies, NAT, routing, VPNs, security profiles and high availability, following the FortiGate Administrator exam topics.

Intermediate · 18 lessons

What you will learn

  • FortiOS GUI and CLI
  • Interfaces and zones
  • Firewall policies
  • NAT and VIPs
  • Troubleshooting with debug flow

A FortiGate is a firewall, a router and a VPN gateway in one box. This course builds one, step by step, on a small lab: FGT1 connects a LAN and a DMZ web server to the Internet. Each module ends with a lab where you configure it yourself and then fix a broken version. You need IP addressing and basic routing; a FortiGate VM or any FortiGate model is enough to follow along.

port1203.0.113.0/30port210.0.1.0/24port310.0.2.0/24InternetISP gateway 203.0.113.1FGT1FortiGatePC1LAN · 10.0.1.10WEB1DMZ · 10.0.2.10
  1. 1. LAN to Internet: PC1 browses the web; FGT1 checks its policies and translates the source address to 203.0.113.2.
  2. 2. Internet to DMZ: Later modules publish WEB1 to the Internet with a virtual IP.

RouteLearn is independent and is not affiliated with or endorsed by Fortinet. Fortinet, FortiGate, FortiOS and FortiGuard are trademarks of Fortinet, Inc. Commands and menus follow FortiOS 7.4 and 7.6; other releases can differ slightly.

What's in this course

4 modules · 18 lessons · about 4 hours of reading

Module 1: Getting Started

What a FortiGate is, first login, the CLI, interfaces and keeping the device safe to run.

Module 2: Firewall Policies

How a FortiGate decides what to allow, the objects policies use, and how to find which policy a session hit.

Module 3: NAT

Source NAT with the interface address or IP pools, publishing servers with virtual IPs, and central NAT.

Module 4: Routing and SD-WAN

How a FortiGate chooses a path: the routing table, static and policy routes, and SD-WAN across two Internet links.

Start the first lesson →