FortiGate Firewall Security Policy Administration Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-047
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

FortiGate administrators are expected to turn network access requirements into firewall rules that protect services without interrupting business operations. Poorly structured policies, unmanaged address objects, broad service definitions and missing logging create avoidable exposure and make troubleshooting slow. This five-day course equips IT and security professionals to administer FortiGate security policies with the discipline needed for production environments, including policy lifecycle control, traffic inspection, rule validation and change traceability.

Participants work through the FortiGate policy framework in FortiOS: interfaces, zones, address objects, service objects, firewall policies, central NAT, virtual IPs, schedules and policy routes. They configure IPv4 and IPv6 policies, apply web filtering, application control, IPS and SSL/TLS inspection profiles, and use session diagnostics and logs to investigate policy decisions. The course also covers policy ordering, implicit deny behaviour, least-privilege rule design, administrative access control, FortiManager policy packages and FortiAnalyzer reporting.

Instructor demonstrations are followed by guided configuration tasks in a FortiGate lab environment. Participants build and test a segmented policy set for a realistic organisation, document rule purpose and ownership, investigate blocked and permitted traffic, and refine policies from evidence in logs. They leave with a completed FortiGate security policy administration workbook, a reusable policy review checklist, and a documented implementation plan for improving policies in their own environment. A certificate of completion is awarded.

The course is suited to professionals who already support networks or security platforms and need practical responsibility for FortiGate policy administration, whether managing a single appliance, a branch estate or policies governed through FortiManager.

Course objectives

By the end of this course, participants will be able to:

  • Design least-privilege FortiGate IPv4 and IPv6 firewall policies using zones, address objects, service objects and schedules
  • Configure source NAT, central NAT and virtual IP policies for controlled inbound and outbound connectivity
  • Apply FortiGuard web filtering, application control and intrusion prevention profiles to security policy rules
  • Implement SSL/TLS inspection policies and identify certificate, privacy and application-compatibility considerations
  • Diagnose policy matches, denied sessions and routing outcomes using FortiGate logs, flow debugging and session tables
  • Structure policy order, naming conventions, comments and object groups for auditable rule lifecycle management
  • Deploy and review policy packages, installations and revision history through FortiManager
  • Produce a documented FortiGate policy review checklist and remediation plan for a production firewall estate

Benefits of attending

For you

  • Build the practical judgement to translate application access requests into controlled FortiGate policy changes
  • Gain evidence-based troubleshooting skills for explaining why a FortiGate session was allowed, denied or inspected
  • Strengthen credibility for FortiGate administration, firewall operations and network security engineering roles
  • Create reusable rule documentation and review artefacts that demonstrate disciplined change-management practice
  • Develop hands-on experience with FortiManager and FortiAnalyzer workflows used in managed Fortinet environments

For your organisation

  • Reduce exposure from overly broad, duplicated or poorly ordered firewall policies through structured rule reviews
  • Improve change quality by giving administrators a consistent method for policy design, testing and rollback planning
  • Shorten incident investigation time through stronger use of FortiGate session data, logs and traffic diagnostics
  • Increase audit readiness with clearer rule ownership, policy comments, logging settings and revision evidence
  • Support consistent security policy deployment across multiple FortiGate devices through FortiManager governance

Target competencies

FortiGate policy designNAT rule administrationTraffic flow diagnosisSecurity profile tuningPolicy lifecycle governanceFortiManager deployment

Who should attend

  • Network Security Administrators — who configure and maintain FortiGate firewall rules for enterprise traffic
  • Firewall Administrators — who need a repeatable method for reviewing, testing and documenting policy changes
  • Network Engineers — who support routing, NAT and segmentation across FortiGate-protected networks
  • Security Operations Analysts — who investigate firewall events and need to interpret policy and inspection logs
  • Infrastructure Engineers — who manage branch, data-centre or cloud connectivity protected by FortiGate appliances
  • IT Managers — who oversee firewall change control and need staff able to reduce policy risk and operational delays

Requirements and prerequisites

Participants should have practical experience administering IP networks and be comfortable with IPv4 addressing, subnetting, TCP/UDP ports, DNS, routing and NAT concepts. Familiarity with command-line and web-based network administration is useful. Attendees should understand the purpose of firewalls and basic security controls such as segmentation, least privilege and logging. Prior FortiGate experience is helpful but not essential; the course introduces the FortiOS interface and command-line workflow before advanced policy work. Fortinet certification, scripting skills, penetration-testing experience and prior FortiManager or FortiAnalyzer use are not required.

Training methodology

The course combines instructor-led technical briefings with individual FortiGate lab configuration, guided troubleshooting and policy-review workshops. Each concept is demonstrated first in FortiOS, then applied to a segmented organisation scenario involving user networks, servers, guest access, remote services and internet egress. Participants inspect live traffic and FortiAnalyzer logs, compare policy alternatives in small groups, and justify their rule designs against access requirements. On day five, each participant completes an application plan that maps course methods to a policy improvement in their own environment.

Course outline

Day 1: FortiGate policy architecture and access control foundations

  • FortiGate interfaces, zones, VDOMs and policy processing paths
  • FortiOS GUI and CLI navigation for policy administration
  • IPv4 and IPv6 address objects, address groups and dynamic objects
  • Service objects, service groups and port-based access definitions
  • Firewall policy anatomy: source, destination, service, action and logging
  • Policy order, first-match processing and implicit deny behaviour
  • Administrative profiles, trusted hosts and configuration backup procedures

Workshop: Build a baseline segmented firewall configuration and produce a documented rule matrix for users, servers, management and guest networks.

Day 2: NAT, publishing and policy-based traffic control

  • Source NAT methods and outbound internet access policies
  • Central NAT architecture and central SNAT policy configuration
  • Virtual IPs, port forwarding and inbound service publishing
  • Destination NAT policy matching and security considerations
  • IP pools, fixed-port NAT and address translation troubleshooting
  • Policy routes, static routes and route selection impacts on firewall rules
  • Schedules, internet service database objects and geography-based controls

Workshop: Publish a web application through a virtual IP, configure controlled outbound NAT and validate each traffic path with policy lookup tools.

Day 3: Security profiles and encrypted traffic inspection

  • Security profile attachment and profile groups in firewall policies
  • FortiGuard web filtering categories, overrides and monitoring
  • Application control signatures, application groups and enforcement actions
  • Intrusion prevention profiles, signature selection and exception handling
  • Antivirus scanning and file-filter policy controls
  • Certificate inspection versus deep SSL/TLS inspection
  • Certificate deployment, inspection exemptions and user-impact testing

Workshop: Create an internet access policy with web filtering, application control, IPS and SSL/TLS inspection, then document tested exceptions and risks.

Day 4: Troubleshooting, logging and policy assurance

  • Forward traffic logs, local logs and FortiAnalyzer log fields
  • Session tables, policy IDs and traffic-flow correlation
  • Diagnose debug flow commands and packet capture methods
  • Policy lookup, route lookup and interface-level troubleshooting
  • Denied traffic investigation and implicit deny analysis
  • Log settings, security event visibility and alerting considerations
  • Policy review methods for shadowed, unused, duplicate and high-risk rules

Workshop: Investigate a set of failed and suspicious connections using FortiGate diagnostics and FortiAnalyzer, then produce a corrective action report.

Day 5: Central management and production policy governance

  • FortiManager architecture, ADOMs and device management fundamentals
  • Policy packages, shared objects and installation targets
  • Workspace mode, locking and controlled policy change workflows
  • Revision history, install previews and rollback planning
  • Policy package validation and object consistency checks
  • Firewall rule naming, ownership, expiry dates and recertification evidence
  • Production policy review cadence and incident-driven rule improvement

Workshop: Use a FortiManager policy package to prepare a controlled rule change, review the installation preview and complete a production policy improvement plan.

Tools & standards covered

FortiGate, FortiOS, FortiManager, FortiAnalyzer

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior FortiGate administration is required, but participants should understand IP networking, subnetting, ports, routing and NAT. The course starts with FortiOS navigation before moving into policy design, inspection and central management.

A laptop is recommended for classroom delivery so you can access the lab environment and retain your notes. FortiGate, FortiManager and FortiAnalyzer lab systems are provided; you do not need to bring an appliance or hold Fortinet licences.

It is designed for network security administrators, firewall administrators, network engineers and security analysts who will configure, review or troubleshoot FortiGate policies. It is also useful for infrastructure staff moving into operational responsibility for Fortinet firewalls.

This course concentrates on the daily administration of security policies: objects, NAT, inspection profiles, rule order, logs, diagnostics and controlled deployment. It does not attempt to cover every FortiGate feature equally, such as full SD-WAN design or advanced VPN architecture.

Yes. The policy review checklist, rule documentation approach and troubleshooting workflow can be applied to existing policies after the course. Participants also practise FortiManager concepts relevant to estates where policy packages are centrally managed.

You leave with completed lab configurations, a policy rule matrix, a security-profile and inspection exercise record, and a documented policy improvement plan. These artefacts provide a practical starting point for reviewing and improving your own FortiGate environment.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Wireshark Network Packet Analysis Training Course

Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …

10 Days Certificate

Cloud Security Architecture for Solutions Architects Training Course

Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…

5 Days Certificate

Microsoft Sentinel Threat Detection Training Course

Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, inci…

5 Days Certificate

COBIT 2019 Cyber Risk Governance Training Course

Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …