Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

FortiGate I

Instructor Guide
for FortiGate 5.4.1
 Product Version

Product Version
This training covers FortiGate 5.4.1.
The FortiGate I course is the first part of the two-part NSE 4 curriculum. It can be delivered as an
instructor-led course, or it can be taken online. This course includes a facilitated lab. This course may
be delivered as part of a custom, private training engagement.
See the course descriptions for the lessons, and the course goals and objectives.

What’s new
This section highlights some of the key changes you will see in this update of the FortiGate I course.

General Changes
 16X9 layout for slides, which is better displayed in modern screens.
 Quizzes have been added to FLC using Quizmaker. This provides direct feedback with references
to source slides.
 The Firewall Policies lesson has been divided into two lessons:
o Firewall Policies
o Network Address Translation (NAT)
 FortiGate inspection mode is chosen at the VDOM level – proxy-based or flow-based.
 The student guide includes labs that are divided into exercises, and the exercises are divided into
procedures.
o Each procedure contains a short list of steps, and a description that explains what the student
will do and why.
 The GUI settings are now shown in bold.

Hatsize Environment Changes


 CA certificates for admin access and SSL inspection are pre-installed on a Firefox browser so that
SSL inspection can be used in the security profile lessons without a certificate warning.
 The resource folder has new structure. It contains the FortiGate-I and FortiGate-II course folders.
Each course folder contains subfolders for each of the lessons. The lesson folders contain the
initial configuration backups and other files needed for the associated labs. The lesson subfolders
now include a solutions folder, which contains the backup of the final configuration.
 Some VMs were renamed. The FortiGates are now called Local-FortiGate and Remote-FortiGate.
The Windows VMs are now called Local-Windows and Remote-Windows.
 Product Version

Changes in Lessons
This section provides details about changes and new feature information added to specific lessons.

Lesson 1 - Introduction
 The Link Aggregation slide was moved from the Routing lesson to the Introduction lesson.

New Features
 The ability to assign roles to interfaces. This defines the configuration settings that are available
on an interface, based on the role that is selected.

Lesson 3 - Firewall Policies


 The following topics have been moved from the Firewall Policies lesson to these lessons:
o NAT lesson
 NAT (SNAT, DNAT, Central NAT)
 Session table
 Session helper
o Antivirus lesson
 Flow-based vs. proxy-based inspection
 SSL/SSH inspection
o Diagnostics lesson
 Debug flow, packet capture (CLI and GUI)
 Selecting multiple Interfaces or any Interface is disabled by default for GUI and can be enabled
from Feature Select.

New Features
 The requirement for mandatory policy names when configuring firewall policies in the GUI.
 Learning mode:
o Applies hidden security profiles with monitor action and fully enabled logging capabilities.
o Provides cyber threat assessment report under Log & Reports > Learning Reports.
 Right-click menu contains various options to add/modify policies.
 Policy lookupx:
o Highlights matching policy based on input criteria.

Lesson 4 - Network Address Translation


 The Firewall Policy NAT section includes SNAT using IP Pool and DNAT using virtual IPs.
 Central NAT supports both SNAT and DNAT.
o SNAT and DNAT configurations are per virtual domain – applies to multiple firewall policies
based on SNAT and DNAT rules.
 Product Version

Lesson 6 - SSL VPN


 The tunnel mode widget has been removed from the browser (web-only mode) in the 5.4.1
firmware.
o Tunnel mode now requires FortiClient.

Lesson 9 - Antivirus
 Proxy/System conserve mode should be called only system conserve mode as proxy conserve
mode has different meaning for developers.
New Features
 Flow-based: Quick Scan uses the IPS engine and embedded compact antivirus database.
o Quick scan is faster because the file is not cached in memory but it has a lower catching rate
compared to proxy-based or full flow-based scanning.

Lesson 10- Web Filtering


New Features
 There is a separate security profile for the DNS filter.

Lesson 11- Application Control


New Features
 There is a new category in the application control profile: Filter Overrides.
o The categorization of applications is based on behavior, popularity, protocol, risk, vendor,
and/or the technology.
 Traffic shaping for applications is now configured under Policy & Objects > Traffic Shaping
Policy.
 There is a separate security profile for cloud access security inspection (CASI). Previously, it was
found the in application control profile as the option, Deep Inspection of Cloud Applications.
o Allows granular control over popular cloud applications.
o Requires full SSL/SSH inspection in firewall policy.
 Materials and System Requirements

Materials and System Requirements


Prior to teaching this lesson, gather the materials.
This course has both on-location (classroom) and online versions.
When delivering the on-location version, you probably will be teaching most or all of the lessons.
(Each lesson is subject-specific.)
If you teach the online version of this class, you may be teaching one or all of the lessons. To access
online content, students must have a computer with:
 a high-speed Internet connection
 an up-to-date web browser that supports HTML 5
 a PDF viewer
 speakers or headphones
 a Java runtime environment (JRE) (optional)

Wi-Fi is not recommended due to packet loss. Firewalls (including FortiClient and Windows Firewall)
must allow connections with the virtual lab.
Students must be able to reach both the virtual lab hosted by Microtek/Hatsize (connectivity details are
in the Student Guide) and the Learning Management System (LMS).
(https://gm1.geolearning.com/geonext/fortinet/myhome.geo). From the LMS, students can download a
copy of the Student Guide for labs and exam study/preparation. They may also be able to view an
alternative video of the presentation.

Item Amount

Instructor Guide 1 per class


(this document)

Presentation Slides 1 per lesson

Virtual Lab Environment 1 per student

Student Guide 1 per student


(lab instructions and presentation notes)

Lab Setup
FortiGate VMs in the virtual lab are running FortiGate 5.4.1.
The lab topology is described in the Virtual Lab Setup Guide for FortiOS 5.4.1, and the FortiGate I
Student Guide for FortiGate 5.4.1.
 Materials and System Requirements

Class Size
The recommended class size for this course is 12 participants; however, smaller or larger class sizes
numbers are permitted.
 Time to Complete

Time to Complete
Schedules may vary by region and customer, but, assuming a 9am to 5pm day with one hour for
breaks, there is a seven-hour study day. There are 11 lessons to deliver in this two-day course.
Try to avoid lectures longer than 30 minutes. Break lessons into two segments, if necessary.

Lesson Estimated Time

Lesson 1 Introduction to FortiGate Lecture: 35 minutes


Lab (if purchased): 25 minutes
Total: 60 minutes

Lesson 2 Logging and Monitoring Lecture: 50 minutes


Lab (if purchased): 15 minutes
Total: 65 minutes

Lesson 3 Firewall Policies Lecture: 35 minutes


Lab (if purchased): 35 minutes
Total: 70 minutes

Lesson 4 Network Address Translation Lecture: 35 minutes


Lab (if purchased): 50 minutes
Total: 85 minutes

Lesson 5 Firewall Authentication Lecture: 50 minutes


Lab (if purchased): 20 minutes
Total: 70 minutes

Lesson 6 SSL VPN Lecture: 45 minutes


Lab (if purchased): 25 minutes
Total:70 minutes

Lesson 7 Basic IPsec VPN Lecture: 30 minutes


Lab (if purchased): 30 minutes
Total: 60 minutes

Lesson 8 Explicit Proxy Lecture: 35 minutes


Lab (if purchased): 30 minutes
Total: 65 minutes

Lesson 9 Antivirus Lecture: 45 minutes


 Time to Complete

Lab (if purchased): 20 minutes


Total: 65 minutes

Lesson 10 Web Filtering Lecture: 45 minutes


Lab (if purchased): 25 minutes
Total: 70 minutes

Lesson 11 Application Control Lecture: 25 minutes


Lab (if purchased): 25 minutes
Total: 50 minutes

Total Total: Approximately 12 hours and 10 minutes

You might also like