Course menu

Module 1: Getting StartedLesson 1.1 (1 of 5 in this module)1 of 18 in the FortiGate Administrator course

What a FortiGate is

Next-generation firewalls, FortiOS, FortiGuard and the Security Fabric, and how a packet passes through a FortiGate.

Beginner · 10 min read

What you will learn

After this lesson, you can describe what a FortiGate does, name the parts of the Fortinet platform you meet as an administrator, and list the order in which a FortiGate handles a new connection.

  • NGFW
  • FortiOS
  • FortiGuard
  • NAT and transparent mode

A FortiGate is Fortinet's next-generation firewall (NGFW). Running the FortiOS operating system, it routes traffic between its interfaces, allows or denies each new connection with firewall policies, translates addresses (NAT), terminates VPNs, and inspects allowed traffic with security profiles such as antivirus, web filtering, application control and intrusion prevention.

In simple terms: A FortiGate sits between your network and the outside world. It decides what may pass, hides your internal addresses, and checks what does pass for anything harmful.

A real-life situation

A small company has a LAN for staff, a web server that customers reach from the Internet, and one Internet connection. It needs to let staff browse, let customers reach only the web server, keep everyone else out, and block malware on the way in. One FortiGate does all of that: it is the default gateway for the LAN, the firewall at the edge, and the inspection engine for allowed traffic.

port1203.0.113.0/30port210.0.1.0/24port310.0.2.0/24InternetISP gateway 203.0.113.1FGT1FortiGatePC1LAN · 10.0.1.10WEB1DMZ · 10.0.2.10
  1. 1. Allowed: PC1 browsing the web matches a LAN-to-Internet policy.
  2. 2. Denied: An unsolicited connection from the Internet to PC1 matches no policy and is dropped.

What a FortiGate does

  • Firewall: stateful inspection. A policy decides whether a new connection is allowed; replies belonging to that session are then allowed automatically.
  • Router: interfaces, a routing table, static routes, dynamic routing and SD-WAN.
  • NAT device: source NAT so the LAN shares one public address, and virtual IPs to publish servers.
  • VPN gateway: IPsec tunnels between sites and for remote users.
  • Security inspection: security profiles (antivirus, web filter, application control, IPS, DNS filter) applied per policy.
  • User identity: policies can match users and groups from local accounts, LDAP, RADIUS or Active Directory, not just IP addresses.

The Fortinet pieces you will meet

NameWhat it is
FortiOSThe operating system on every FortiGate, from small desktop models to chassis and VMs. Same GUI and CLI everywhere.
FortiGuardSubscription services that keep signatures and ratings current: antivirus, IPS, web and DNS categories, application signatures.
Security processorsHardware models include Fortinet ASICs: NP processors accelerate (offload) established sessions; CP processors speed up encryption and inspection. VMs do the same in software.
FortiAnalyzerCentral logging and reporting for many FortiGates.
FortiManagerCentral configuration management for many FortiGates.
FortiClientEndpoint software: VPN client, and endpoint security in the Security Fabric.
FortiSwitch / FortiAPSwitches and access points that a FortiGate can manage directly.

Operation modes and VDOMs

In NAT mode (the default and by far the most common) every interface has its own IP subnet and the FortiGate routes between them, like a router with a firewall built in. In transparent mode it behaves like a bridge: the interfaces have no addresses of their own, so it can be dropped into an existing network without readdressing, and still apply policies.

VDOMs split one FortiGate into separate virtual firewalls, each with its own interfaces, routing table, policies and administrators. A service provider might give each customer a VDOM. This course uses a single VDOM, called root, which is what a new FortiGate has.

How a FortiGate handles a new connection

When the first packet of a connection arrives, the FortiGate runs it through a fixed sequence of checks. Knowing the order explains many surprises: for example, why a policy for a published server must use the server's internal address.

1. Packet arrives on an interface
Basic sanity checks on the IP header; DoS policies if configured.
2. Destination NAT
If the destination matches a virtual IP, it is rewritten to the real server address.
3. Routing lookup
The routing table decides the outgoing interface. No route: dropped.
4. Firewall policy lookup
Top-down, first match on incoming and outgoing interface, source, destination, service and schedule (and user). No match: the implicit deny drops it.
5. Security inspection
Security profiles on the matching policy inspect the content.
6. Source NAT
If the policy (or central NAT) says so, the source address is translated.
7. Packet leaves
Encrypted first if it enters an IPsec tunnel. A session entry now exists for the replies.
A simplified view of the first packet of a new session. Later packets of the same session match the session table and skip most of these steps (and can be offloaded to hardware).

Why it works this way

Checking every packet against every policy would be slow. A stateful firewall checks only the first packet of a connection, records the result in a session table, and lets the rest of the conversation through by matching that entry. That is also why a FortiGate needs no rule for reply traffic: the session already allows it.

Common mistakes

  • Expecting traffic to flow because a route exists. Routing chooses the interface; a policy must still allow it.
  • Writing a separate policy for return traffic. Replies are handled by the session table.
  • Confusing FortiGuard (the cloud services) with FortiGate (the firewall).

Key takeaways

✅ Key takeaways
  • A FortiGate is a stateful NGFW that also routes, does NAT, terminates VPNs and inspects content.
  • FortiOS runs every model; FortiGuard keeps its signatures and ratings current.
  • NAT mode routes between subnets; transparent mode bridges. VDOMs make several virtual firewalls.
  • For a new session: destination NAT, routing, policy, inspection, source NAT, then out.

Check yourself

Predict · scenario 1

PC1 opens a web page. Does FGT1 need a policy to allow the web server's replies back to PC1?

Predict · scenario 2

Which step comes first for a new connection to a published server?

Predict · scenario 3

A company wants to add a FortiGate between existing routers without changing any IP addresses. Which mode fits?

FAQ

Do I need a physical FortiGate to learn?
No. A FortiGate VM runs in VMware, KVM, Hyper-V or a lab emulator such as EVE-NG or GNS3, and Fortinet offers a permanent trial licence for the VM with limited features. Everything in this course works on a VM.
Is a FortiGate a router?
Yes, in its normal NAT mode. It has a routing table, supports static routes and dynamic routing protocols (OSPF, BGP, RIP), and forwards between its interfaces. The difference from a router is that nothing passes between interfaces unless a firewall policy allows it.