FortiGate Firewall Security Policy Administration Training Course
| Course code | SD-CS-047 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
FortiGate administrators are expected to turn network access requirements into firewall rules that protect services without interrupting business operations. Poorly structured policies, unmanaged address objects, broad service definitions and missing logging create avoidable exposure and make troubleshooting slow. This five-day course equips IT and security professionals to administer FortiGate security policies with the discipline needed for production environments, including policy lifecycle control, traffic inspection, rule validation and change traceability.
Participants work through the FortiGate policy framework in FortiOS: interfaces, zones, address objects, service objects, firewall policies, central NAT, virtual IPs, schedules and policy routes. They configure IPv4 and IPv6 policies, apply web filtering, application control, IPS and SSL/TLS inspection profiles, and use session diagnostics and logs to investigate policy decisions. The course also covers policy ordering, implicit deny behaviour, least-privilege rule design, administrative access control, FortiManager policy packages and FortiAnalyzer reporting.
Instructor demonstrations are followed by guided configuration tasks in a FortiGate lab environment. Participants build and test a segmented policy set for a realistic organisation, document rule purpose and ownership, investigate blocked and permitted traffic, and refine policies from evidence in logs. They leave with a completed FortiGate security policy administration workbook, a reusable policy review checklist, and a documented implementation plan for improving policies in their own environment. A certificate of completion is awarded.
The course is suited to professionals who already support networks or security platforms and need practical responsibility for FortiGate policy administration, whether managing a single appliance, a branch estate or policies governed through FortiManager.
Course objectives
By the end of this course, participants will be able to:
- Design least-privilege FortiGate IPv4 and IPv6 firewall policies using zones, address objects, service objects and schedules
- Configure source NAT, central NAT and virtual IP policies for controlled inbound and outbound connectivity
- Apply FortiGuard web filtering, application control and intrusion prevention profiles to security policy rules
- Implement SSL/TLS inspection policies and identify certificate, privacy and application-compatibility considerations
- Diagnose policy matches, denied sessions and routing outcomes using FortiGate logs, flow debugging and session tables
- Structure policy order, naming conventions, comments and object groups for auditable rule lifecycle management
- Deploy and review policy packages, installations and revision history through FortiManager
- Produce a documented FortiGate policy review checklist and remediation plan for a production firewall estate
Benefits of attending
For you
- Build the practical judgement to translate application access requests into controlled FortiGate policy changes
- Gain evidence-based troubleshooting skills for explaining why a FortiGate session was allowed, denied or inspected
- Strengthen credibility for FortiGate administration, firewall operations and network security engineering roles
- Create reusable rule documentation and review artefacts that demonstrate disciplined change-management practice
- Develop hands-on experience with FortiManager and FortiAnalyzer workflows used in managed Fortinet environments
For your organisation
- Reduce exposure from overly broad, duplicated or poorly ordered firewall policies through structured rule reviews
- Improve change quality by giving administrators a consistent method for policy design, testing and rollback planning
- Shorten incident investigation time through stronger use of FortiGate session data, logs and traffic diagnostics
- Increase audit readiness with clearer rule ownership, policy comments, logging settings and revision evidence
- Support consistent security policy deployment across multiple FortiGate devices through FortiManager governance
Target competencies
Who should attend
- Network Security Administrators — who configure and maintain FortiGate firewall rules for enterprise traffic
- Firewall Administrators — who need a repeatable method for reviewing, testing and documenting policy changes
- Network Engineers — who support routing, NAT and segmentation across FortiGate-protected networks
- Security Operations Analysts — who investigate firewall events and need to interpret policy and inspection logs
- Infrastructure Engineers — who manage branch, data-centre or cloud connectivity protected by FortiGate appliances
- IT Managers — who oversee firewall change control and need staff able to reduce policy risk and operational delays
Requirements and prerequisites
Participants should have practical experience administering IP networks and be comfortable with IPv4 addressing, subnetting, TCP/UDP ports, DNS, routing and NAT concepts. Familiarity with command-line and web-based network administration is useful. Attendees should understand the purpose of firewalls and basic security controls such as segmentation, least privilege and logging. Prior FortiGate experience is helpful but not essential; the course introduces the FortiOS interface and command-line workflow before advanced policy work. Fortinet certification, scripting skills, penetration-testing experience and prior FortiManager or FortiAnalyzer use are not required.
Training methodology
The course combines instructor-led technical briefings with individual FortiGate lab configuration, guided troubleshooting and policy-review workshops. Each concept is demonstrated first in FortiOS, then applied to a segmented organisation scenario involving user networks, servers, guest access, remote services and internet egress. Participants inspect live traffic and FortiAnalyzer logs, compare policy alternatives in small groups, and justify their rule designs against access requirements. On day five, each participant completes an application plan that maps course methods to a policy improvement in their own environment.
Course outline
Day 1: FortiGate policy architecture and access control foundations
- FortiGate interfaces, zones, VDOMs and policy processing paths
- FortiOS GUI and CLI navigation for policy administration
- IPv4 and IPv6 address objects, address groups and dynamic objects
- Service objects, service groups and port-based access definitions
- Firewall policy anatomy: source, destination, service, action and logging
- Policy order, first-match processing and implicit deny behaviour
- Administrative profiles, trusted hosts and configuration backup procedures
Workshop: Build a baseline segmented firewall configuration and produce a documented rule matrix for users, servers, management and guest networks.
Day 2: NAT, publishing and policy-based traffic control
- Source NAT methods and outbound internet access policies
- Central NAT architecture and central SNAT policy configuration
- Virtual IPs, port forwarding and inbound service publishing
- Destination NAT policy matching and security considerations
- IP pools, fixed-port NAT and address translation troubleshooting
- Policy routes, static routes and route selection impacts on firewall rules
- Schedules, internet service database objects and geography-based controls
Workshop: Publish a web application through a virtual IP, configure controlled outbound NAT and validate each traffic path with policy lookup tools.
Day 3: Security profiles and encrypted traffic inspection
- Security profile attachment and profile groups in firewall policies
- FortiGuard web filtering categories, overrides and monitoring
- Application control signatures, application groups and enforcement actions
- Intrusion prevention profiles, signature selection and exception handling
- Antivirus scanning and file-filter policy controls
- Certificate inspection versus deep SSL/TLS inspection
- Certificate deployment, inspection exemptions and user-impact testing
Workshop: Create an internet access policy with web filtering, application control, IPS and SSL/TLS inspection, then document tested exceptions and risks.
Day 4: Troubleshooting, logging and policy assurance
- Forward traffic logs, local logs and FortiAnalyzer log fields
- Session tables, policy IDs and traffic-flow correlation
- Diagnose debug flow commands and packet capture methods
- Policy lookup, route lookup and interface-level troubleshooting
- Denied traffic investigation and implicit deny analysis
- Log settings, security event visibility and alerting considerations
- Policy review methods for shadowed, unused, duplicate and high-risk rules
Workshop: Investigate a set of failed and suspicious connections using FortiGate diagnostics and FortiAnalyzer, then produce a corrective action report.
Day 5: Central management and production policy governance
- FortiManager architecture, ADOMs and device management fundamentals
- Policy packages, shared objects and installation targets
- Workspace mode, locking and controlled policy change workflows
- Revision history, install previews and rollback planning
- Policy package validation and object consistency checks
- Firewall rule naming, ownership, expiry dates and recertification evidence
- Production policy review cadence and incident-driven rule improvement
Workshop: Use a FortiManager policy package to prepare a controlled rule change, review the installation preview and complete a production policy improvement plan.
Tools & standards covered
FortiGate, FortiOS, FortiManager, FortiAnalyzer
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Wireshark Network Packet Analysis Training Course
Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …
Cloud Security Architecture for Solutions Architects Training Course
Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…
Microsoft Sentinel Threat Detection Training Course
Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, inci…
COBIT 2019 Cyber Risk Governance Training Course
Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …