FortiGate Basics: Architecture & Initial Setup
FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)
مقصدObjectiveObjective
اس لیب میں آپ FortiOS کے بنیادی آرکیٹیکچر (Security Fabric اور FortiGuard) کو سمجھیں گے، مینجمنٹ تک رسائی حاصل کریں گے اور FortiGate کی ابتدائی کنفیگریشن مکمل کریں گے۔Is lab mein aap FortiOS ke bunyadi architecture (Security Fabric aur FortiGuard) ko samjhenge, management tak rasai hasil karenge aur FortiGate ki ibtedai configuration mukammal karenge.In this lab you will understand the FortiOS architecture (Security Fabric and FortiGuard), gain management access, and complete the initial FortiGate configuration.
آسان مثالSimple AnalogySimple Analogy
FortiGate کو ایک سوسائٹی کا مین گیٹ سمجھیں — ہر آنے جانے والی گاڑی (پیکٹ) کو گیٹ پر چیک کیا جاتا ہے، اور FortiGuard وہ اپ ڈیٹ لسٹ ہے جو بتاتی ہے کہ کون مشکوک ہے۔FortiGate ko aik society ke main gate samjhen — har aane jaane wali gari (packet) ko gate par check kiya jata hai, aur FortiGuard woh update list hai jo batati hai ke kaun mashkook hai.Think of FortiGate as a housing society's main gate — every vehicle (packet) is checked at the gate, and FortiGuard is the updated list that says who is suspicious.
سیٹ اپLab SetupLab Setup
EVE-NG میں ایک FortiGate VM چلائیں۔ port1 مینجمنٹ/وین کے لیے اور port2 اندرونی نیٹ ورک کے لیے استعمال ہوگا۔ کنسول یا SSH سے CLI اور براؤزر سے GUI تک رسائی رکھیں۔EVE-NG mein aik FortiGate VM chalayen. port1 management/WAN ke liye aur port2 androoni network ke liye istemal hoga. Console ya SSH se CLI aur browser se GUI tak rasai rakhen.Run one FortiGate VM in EVE-NG. port1 is for management/WAN and port2 for the internal network. Keep CLI access via console or SSH and GUI access via a browser.
اقداماتStepsSteps
Step 1
نئے FortiGate پر پہلی رسائی چیک کریں۔ فیکٹری ڈیفالٹ پر port1 کا IP 192.168.1.99 ہوتا ہے، یوزر admin اور پاس ورڈ خالی ہوتا ہے۔ براؤزر میں https://192.168.1.99 کھولیں۔Naye FortiGate par pehli rasai check karen. Factory default par port1 ka IP 192.168.1.99 hota hai, user admin aur password khaali hota hai. Browser mein https://192.168.1.99 kholen.Check first access on a new FortiGate. On factory defaults port1 is 192.168.1.99, user admin with a blank password. Open https://192.168.1.99 in a browser.
🖱️ براؤزر میں https://192.168.1.99 کھولیں اور admin / خالی پاس ورڈ سے لاگ اِن کریں۔Browser mein https://192.168.1.99 kholen aur admin / khaali password se log in karen.Open https://192.168.1.99 in a browser and log in as admin with a blank password.
Step 2
سب سے پہلے admin کا پاس ورڈ تبدیل کریں — خالی پاس ورڈ سیکیورٹی کا سب سے بڑا خطرہ ہے۔ مضبوط پاس ورڈ لگائیں۔Sab se pehle admin ka password tabdeel karen — khaali password security ka sab se bara khatra hai. Mazboot password lagayen.Change the admin password first — a blank password is the biggest security risk. Set a strong password.
config system admin
edit admin
set password NewStr0ngPass!
next
end🖱️ System > Administrators میں admin کو ایڈٹ کر کے پاس ورڈ بدلیں۔System > Administrators mein admin ko edit kar ke password badlen.Change the password under System > Administrators by editing admin.
Step 3
ڈیوائس کو پہچاننے کے لیے hostname سیٹ کریں اور DNS سرورز کنفیگر کریں تاکہ FortiGuard اپ ڈیٹس کام کریں۔Device ko pehchanne ke liye hostname set karen aur DNS servers configure karen taake FortiGuard updates kaam karen.Set a hostname to identify the device and configure DNS servers so FortiGuard updates work.
config system global
set hostname FG-LAB-01
end
config system dns
set primary 8.8.8.8
set secondary 1.1.1.1
end🖱️ System > Settings میں Host name بدلیں؛ Network > DNS میں DNS سرورز سیٹ کریں۔System > Settings mein Host name badlen; Network > DNS mein DNS servers set karen.Change the Host name under System > Settings; set DNS servers under Network > DNS.
Step 4
port1 پر مینجمنٹ IP کنفیگر کریں اور allowaccess میں صرف ضروری پروٹوکول (https, ssh, ping) رکھیں۔ غیر ضروری رسائی بند رکھنا بہترین پریکٹس ہے۔port1 par management IP configure karen aur allowaccess mein sirf zaroori protocol (https, ssh, ping) rakhen. Ghair zaroori rasai band rakhna behtareen practice hai.Configure the management IP on port1 and keep only needed protocols (https, ssh, ping) in allowaccess. Leaving unneeded access off is best practice.
config system interface
edit port1
set ip 192.168.1.99/24
set allowaccess ping https ssh
set role lan
next
end🖱️ Network > Interfaces میں port1 ایڈٹ کریں — IP اور Administrative Access سیٹ کریں۔Network > Interfaces mein port1 edit karen — IP aur Administrative Access set karen.Edit port1 under Network > Interfaces — set the IP and Administrative Access.
Step 5
FortiGuard کنکٹیویٹی چیک کریں۔ FortiGuard وہ کلاؤڈ سروس ہے جو اینٹی وائرس، IPS اور ویب فلٹر کی تازہ ترین ڈیفینیشنز دیتی ہے۔FortiGuard connectivity check karen. FortiGuard woh cloud service hai jo antivirus, IPS aur web filter ki taaza tareen definitions deti hai.Check FortiGuard connectivity. FortiGuard is the cloud service that delivers the latest antivirus, IPS, and web filter definitions.
execute ping service.fortiguard.net diagnose autoupdate versions
🖱️ System > FortiGuard میں کنکٹیویٹی اور لائسنس اسٹیٹس دیکھیں۔System > FortiGuard mein connectivity aur license status dekhen.View connectivity and license status under System > FortiGuard.
Step 6
کنفیگریشن کا بیک اپ لیں۔ ہر بڑی تبدیلی سے پہلے بیک اپ لینا اچھی عادت ہے تاکہ غلطی پر واپس جایا جا سکے۔Configuration ka backup len. Har bari tabdeeli se pehle backup lena achi aadat hai taake ghalti par wapas jaya ja sake.Take a configuration backup. Backing up before every major change is a good habit so you can roll back on mistakes.
execute backup config tftp FG-LAB-01-initial.conf 192.168.1.10
🖱️ اوپر دائیں کونے میں admin مینیو > Configuration > Backup سے بیک اپ ڈاؤن لوڈ کریں۔Oopar daayen kone mein admin menu > Configuration > Backup se backup download karen.Download a backup via the admin menu (top right) > Configuration > Backup.
تصدیقVerifyVerify
سسٹم اسٹیٹس چیک کریں — hostname، FortiOS ورژن اور اپ ٹائم نظر آنا چاہیے۔ انٹرفیس لسٹ میں port1 کا IP اور allowaccess درست ہونا چاہیے۔System status check karen — hostname, FortiOS version aur uptime nazar aana chahiye. Interface list mein port1 ka IP aur allowaccess durust hona chahiye.Check system status — you should see the hostname, FortiOS version, and uptime. The interface list should show port1's IP and correct allowaccess.
get system status get system interface
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ GUI نہیں کھل رہی — براؤزر میں https://192.168.1.99 ٹائم آؤٹ ہو رہا ہے۔GUI nahi khul rahi — browser mein https://192.168.1.99 time out ho raha hai.GUI won't open — https://192.168.1.99 times out in the browser.
✅ چیک کریں کہ آپ کا PC اسی سب نیٹ میں ہے، انٹرفیس پر allowaccess میں https شامل ہے، اور کیبل/لنک اپ ہے۔ کنسول سے get system interface چلائیں۔Check karen ke aap ka PC usi subnet mein hai, interface par allowaccess mein https shamil hai, aur cable/link up hai. Console se get system interface chalayen.Check that your PC is in the same subnet, that https is in the interface's allowaccess, and that the link is up. Run get system interface from the console.
⚠️ IP تبدیل کرنے کے بعد FortiGate تک رسائی ختم ہو گئی۔IP tabdeel karne ke baad FortiGate tak rasai khatam ho gayi.Lost access to the FortiGate after changing the IP.
✅ EVE-NG کنسول سے لاگ اِن کریں اور پرانا/صحیح IP دوبارہ سیٹ کریں۔ مستقبل میں تبدیلی سے پہلے بیک اپ ضرور لیں۔EVE-NG console se log in karen aur purana/sahih IP dobara set karen. Mustaqbil mein tabdeeli se pehle backup zaroor len.Log in via the EVE-NG console and re-set the old/correct IP. Always take a backup before changes in future.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ FortiOS کیا ہے اور Security Fabric سے کیا مراد ہے؟FortiOS kya hai aur Security Fabric se kya muraad hai?What is FortiOS and what does Security Fabric mean?
FortiOS وہ آپریٹنگ سسٹم ہے جو FortiGate پر چلتا ہے۔ Security Fabric کا مطلب ہے کہ FortiGate، FortiAnalyzer، FortiManager اور FortiSandbox جیسی ڈیوائسز مل کر ایک مربوط سیکیورٹی سسٹم بناتی ہیں اور آپس میں تھریٹ انٹیلی جنس شیئر کرتی ہیں۔FortiOS woh operating system hai jo FortiGate par chalta hai. Security Fabric ka matlab hai ke FortiGate, FortiAnalyzer, FortiManager aur FortiSandbox jaisi devices mil kar aik marboot security system banati hain aur aapas mein threat intelligence share karti hain.FortiOS is the operating system that runs on FortiGate. Security Fabric means devices like FortiGate, FortiAnalyzer, FortiManager, and FortiSandbox work as one integrated security system and share threat intelligence with each other.
❓ نئے FortiGate پر ڈیفالٹ مینجمنٹ رسائی کیا ہوتی ہے؟Naye FortiGate par default management rasai kya hoti hai?What is the default management access on a new FortiGate?
port1 پر https://192.168.1.99، یوزر admin اور پاس ورڈ خالی۔ پہلا کام پاس ورڈ تبدیل کرنا ہے۔port1 par https://192.168.1.99, user admin aur password khaali. Pehla kaam password tabdeel karna hai.https://192.168.1.99 on port1, user admin with a blank password. The first job is to change the password.