A real-life situation
A small company has a LAN for staff, a web server that customers reach from the Internet, and one Internet connection. It needs to let staff browse, let customers reach only the web server, keep everyone else out, and block malware on the way in. One FortiGate does all of that: it is the default gateway for the LAN, the firewall at the edge, and the inspection engine for allowed traffic.
- 1. Allowed: PC1 browsing the web matches a LAN-to-Internet policy.
- 2. Denied: An unsolicited connection from the Internet to PC1 matches no policy and is dropped.
What a FortiGate does
- Firewall: stateful inspection. A policy decides whether a new connection is allowed; replies belonging to that session are then allowed automatically.
- Router: interfaces, a routing table, static routes, dynamic routing and SD-WAN.
- NAT device: source NAT so the LAN shares one public address, and virtual IPs to publish servers.
- VPN gateway: IPsec tunnels between sites and for remote users.
- Security inspection: security profiles (antivirus, web filter, application control, IPS, DNS filter) applied per policy.
- User identity: policies can match users and groups from local accounts, LDAP, RADIUS or Active Directory, not just IP addresses.
The Fortinet pieces you will meet
| Name | What it is |
|---|---|
| FortiOS | The operating system on every FortiGate, from small desktop models to chassis and VMs. Same GUI and CLI everywhere. |
| FortiGuard | Subscription services that keep signatures and ratings current: antivirus, IPS, web and DNS categories, application signatures. |
| Security processors | Hardware models include Fortinet ASICs: NP processors accelerate (offload) established sessions; CP processors speed up encryption and inspection. VMs do the same in software. |
| FortiAnalyzer | Central logging and reporting for many FortiGates. |
| FortiManager | Central configuration management for many FortiGates. |
| FortiClient | Endpoint software: VPN client, and endpoint security in the Security Fabric. |
| FortiSwitch / FortiAP | Switches and access points that a FortiGate can manage directly. |
Operation modes and VDOMs
In NAT mode (the default and by far the most common) every interface has its own IP subnet and the FortiGate routes between them, like a router with a firewall built in. In transparent mode it behaves like a bridge: the interfaces have no addresses of their own, so it can be dropped into an existing network without readdressing, and still apply policies.
VDOMs split one FortiGate into separate virtual firewalls, each with its own interfaces, routing table, policies and administrators. A service provider might give each customer a VDOM. This course uses a single VDOM, called root, which is what a new FortiGate has.
How a FortiGate handles a new connection
When the first packet of a connection arrives, the FortiGate runs it through a fixed sequence of checks. Knowing the order explains many surprises: for example, why a policy for a published server must use the server's internal address.
Why it works this way
Checking every packet against every policy would be slow. A stateful firewall checks only the first packet of a connection, records the result in a session table, and lets the rest of the conversation through by matching that entry. That is also why a FortiGate needs no rule for reply traffic: the session already allows it.
Common mistakes
- Expecting traffic to flow because a route exists. Routing chooses the interface; a policy must still allow it.
- Writing a separate policy for return traffic. Replies are handled by the session table.
- Confusing FortiGuard (the cloud services) with FortiGate (the firewall).
Key takeaways
- A FortiGate is a stateful NGFW that also routes, does NAT, terminates VPNs and inspects content.
- FortiOS runs every model; FortiGuard keeps its signatures and ratings current.
- NAT mode routes between subnets; transparent mode bridges. VDOMs make several virtual firewalls.
- For a new session: destination NAT, routing, policy, inspection, source NAT, then out.
Check yourself
PC1 opens a web page. Does FGT1 need a policy to allow the web server's replies back to PC1?
Which step comes first for a new connection to a published server?
A company wants to add a FortiGate between existing routers without changing any IP addresses. Which mode fits?