Skip to main content
Training Institute
  • Library
  • Schedule
  • Certifications
  • ATC
  • Academic Partner Program
  • Fast Track Workshops
  • More
Log in
Contents
Library Schedule Certifications ATC Academic Partner Program Fast Track Workshops

FortiGate Advanced IPS

Training / Library
Download Brochure

Blocks

Course Description

In this course, students will learn how to configure, monitor, tune, and troubleshoot advanced intrusion prevention features on FortiGate.

This four-day workshop combines selected FortiOS Administrator, Network Security Support Engineer, and FortiAnalyzer Analyst content with custom advanced IPS modules. Students will begin with the core FortiGate administration skills required to support IPS deployments, including system and network settings, logging and monitoring, firewall policies, NAT, routing, and certificate operations. Students will then examine intrusion prevention, application control, traffic flow, security profiles, network defense, DoS protection, custom IPS signatures, Snort rule conversion, and IPS architecture and performance.

In interactive labs, students will configure a FortiGate device under test, generate traffic, monitor FortiGate dashboards and logs, create DoS policies, detect and block TCP SYN flood anomalies, enable application control, analyze application traffic, capture packets, and create and apply custom signatures. The lab environment also includes FortiAnalyzer for log analysis and security event review.

Who Should Attend

Anyone who is responsible for deploying, operating, monitoring, or troubleshooting FortiGate IPS features.

This workshop is suitable for network security administrators, firewall engineers, security operations teams, support engineers, and advanced FortiGate users who need deeper practical knowledge of intrusion prevention, DoS protection, custom signatures, application control, and IPS performance behavior.

Prerequisites

Students should have:

  • Knowledge of network protocols
  • Knowledge of firewall concepts in an IPv4 network
  • Experience with FortiGate firewall policy configuration
  • Basic understanding of routing and NAT
  • Basic understanding of security profiles
  • Familiarity with FortiGate GUI and CLI administration
Agenda Summary

The workshop agenda includes selected modules from FortiOS Administrator 7.6, Network Security Support Engineer 7.6, FortiAnalyzer Analyst 7.6, and custom IPS content, covering the following topic areas: system and network settings, logging and monitoring, firewall policies and NAT, routing, certificate operations, intrusion prevention and application control, sessions and traffic flow, security profiles, network defense and DoS protection, custom signatures, Snort rules and conversion, IPS architecture and performance, and FortiAnalyzer logging and FortiSoC events and incidents.

Objectives

After completing this course, students will be able to:

  • Use the FortiGate GUI and CLI for IPS-related administration
  • Configure FortiGate system and network settings required for inspection
  • Configure firewall policies, NAT, routing, and certificate operations to support security inspection
  • Explain how FortiGate processes sessions, traffic flow, and security profiles
  • Configure and monitor intrusion prevention and application control
  • Understand how application control uses the same underlying inspection processes and rules as IPS
  • Configure FortiGate logging and monitoring for IPS and application events
  • Use FortiAnalyzer to review logs, security events, and incidents
  • Configure a FortiGate device under test for traffic inspection
  • Use FortiTester to generate HTTP, mixed application, and high connection-rate traffic
  • Monitor FortiGate dashboard widgets such as CPU, sessions, session rate, and bandwidth during traffic tests
  • Create DoS policies to monitor network anomalies
  • Tune DoS thresholds and block TCP SYN flood traffic
  • Analyze FortiGate and FortiAnalyzer logs for anomaly and security events
  • Capture traffic and analyze packet details
  • Create and apply custom IPS signatures
  • Understand Snort rules and signature conversion considerations
  • Describe IPS architecture and performance considerations
  • Troubleshoot common IPS, application control, and traffic inspection issues
Labs

The workshop includes hands-on labs covering:

  • FortiGate device-under-test initial configuration
  • FortiTester configuration and traffic generation
  • High connection-per-second traffic testing
  • FortiGate dashboard and CLI monitoring
  • DoS policy creation, monitoring, and blocking
  • Anomaly detection and security event review
  • Application control configuration
  • Mixed application traffic generation
  • FortiView and log analysis
  • Packet capture and custom signature creation
  • Custom signature enforcement and validation
System Requirements

If you take an online format of this class, you must use a computer that has the following:

  • A high-speed Internet connection
  • An up-to-date web browser
  • A PDF viewer
  • Speakers or headphones
  • One of the following:
    • HTML5 support
    • An Up-to-date Java runtime environment (JRE) with Java plugin enabled in your web browser

You should use a wired Ethernet connection, not a Wi-Fi connection. Firewalls, including Windows Firewall or FortiClient, must allow connections to the online labs.

Purchasing Process

More information on how to purchase instructor-led courses, on-demand labs, exam vouchers, and study material.

Product Versions
  • FortiGate 7.6
  • FortiAnalyzer 7.6
Course Duration
  • Total course duration (estimated):
    • 4 full days
Formats
  • Private instructor-led (classroom and online)
ISC2
  • CPE training hours: 28
  • CISSP domains: Security Operations
Part Number (SKU)

See Purchasing Process for more information

Certification

There is no certification exam associated with this workshop. For certification information, refer to the appropriate Fortinet Training Institute certification courses and exams.

Data retention summary