Capstone: Enterprise FortiGate Build

FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)

مقصدObjectiveObjective

اس کیپ اسٹون میں آپ مکمل انٹرپرائز FortiGate ڈیپلائے کریں گے: ہارڈنڈ مینجمنٹ، انٹرفیسز اور زونز، روٹنگ، پالیسیز، NAT، آتھینٹیکیشن، IPsec VPN، سیکیورٹی پروفائلز، لاگنگ، سینٹرل مینجمنٹ اور بیک اپ۔Is capstone mein aap mukammal enterprise FortiGate deploy karenge: hardened management, interfaces aur zones, routing, policies, NAT, authentication, IPsec VPN, security profiles, logging, central management aur backup.In this capstone you will deploy a complete enterprise FortiGate: hardened management, interfaces and zones, routing, policies, NAT, authentication, IPsec VPN, security profiles, logging, central management, and backup.

آسان مثالSimple AnalogySimple Analogy

کیپ اسٹون ایسے ہے جیسے فائنل ڈرائیونگ ٹیسٹ: آپ نے پارکنگ، ریورس اور ہائی وے الگ الگ پریکٹس کیے — اب پورا روٹ ایک ساتھ چلا کر ثابت کرتے ہیں کہ آپ تیار ہیں۔Capstone aise hai jaise final driving test: aap ne parking, reverse aur highway alag alag practice kiye — ab poora route aik saath chala kar sabit karte hain ke aap tayyar hain.A capstone is like the final driving test: you have practiced parking, reversing, and highway driving separately — now you drive the whole route at once to prove you are ready.

سیٹ اپLab SetupLab Setup

EVE-NG میں تازہ FortiGate VM۔ ٹوپولوجی: port1 WAN 203.0.113.2/24 (gw 203.0.113.1)، port2 LAN 192.168.10.1/24، port3 DMZ 10.10.10.1/24۔ ہر چیک لسٹ قدم ترتیب سے مکمل کریں۔EVE-NG mein taaza FortiGate VM. Topology: port1 WAN 203.0.113.2/24 (gw 203.0.113.1), port2 LAN 192.168.10.1/24, port3 DMZ 10.10.10.1/24. Har checklist qadam tarteeb se mukammal karen.Fresh FortiGate VM in EVE-NG. Topology: port1 WAN 203.0.113.2/24 (gw 203.0.113.1), port2 LAN 192.168.10.1/24, port3 DMZ 10.10.10.1/24. Work through every checklist step in order.

اقداماتStepsSteps

Step 1

مینجمنٹ رسائی ہارڈن کریں: مضبوط admin پاس ورڈ، hostname، اور allowaccess صرف https اور ssh تک محدود کریں۔ http اور telnet ہر جگہ سے ہٹائیں۔Management rasai harden karen: mazboot admin password, hostname, aur allowaccess sirf https aur ssh tak mehdood karen. http aur telnet har jagah se hatayen.Harden management access: strong admin password, hostname, and restrict allowaccess to only https and ssh. Remove http and telnet everywhere.

config system admin
    edit admin
        set password HardenedPass123!
    next
end
config system global
    set hostname FG-ENTERPRISE
end

🖱️ System > Settings میں Host name سیٹ کریں؛ System > Administrators میں admin پاس ورڈ تبدیل کریں۔System > Settings mein Host name set karen; System > Administrators mein admin password tabdeel karen.Set Host name under System > Settings; change the admin password under System > Administrators.

Step 2

نیٹ ورک کی بنیاد بنائیں: انٹرفیس IPs اور رولز، port2+port3 کے لیے INTERNAL زون، اور WAN گیٹ وے تک ڈیفالٹ روٹ۔Network ki bunyad banayen: interface IPs aur roles, port2+port3 ke liye INTERNAL zone, aur WAN gateway tak default route.Build the network foundation: interface IPs and roles, an INTERNAL zone for port2+port3, and the default route to the WAN gateway.

config system interface
    edit port1
        set ip 203.0.113.2/24
        set allowaccess ping
        set role wan
    next
    edit port2
        set ip 192.168.10.1/24
        set allowaccess ping
        set role lan
    next
    edit port3
        set ip 10.10.10.1/24
        set allowaccess ping
        set role dmz
    next
end
config system zone
    edit INTERNAL
        set interface port2 port3
    next
end
config router static
    edit 1
        set dst 0.0.0.0/0
        set gateway 203.0.113.1
        set device port1
    next
end

🖱️ Network > Interfaces، Network > Zones، Network > Static Routes میں بنائیں۔Network > Interfaces, Network > Zones, Network > Static Routes mein banayen.Build under Network > Interfaces, Network > Zones, Network > Static Routes.

Step 3

ایڈریس آبجیکٹس اور مین آؤٹ باؤنڈ پالیسی بنائیں — NAT، مکمل لاگنگ اور چاروں سیکیورٹی پروفائلز کے ساتھ۔Address objects aur main outbound policy banayen — NAT, mukammal logging aur chaaron security profiles ke saath.Create address objects and the main outbound policy with NAT, full logging, and all four security profiles attached.

config firewall address
    edit LAN_NET
        set subnet 192.168.10.0 255.255.255.0
    next
    edit DMZ_NET
        set subnet 10.10.10.0 255.255.255.0
    next
end
config firewall policy
    edit 1
        set name INTERNAL-to-WAN
        set srcintf INTERNAL
        set dstintf port1
        set srcaddr LAN_NET DMZ_NET
        set dstaddr all
        set service HTTP HTTPS DNS
        set schedule always
        set action accept
        set logtraffic all
        set nat enable
        set utm-status enable
        set av-profile default
        set ips-sensor default
        set webfilter-profile default
        set application-list default
    next
end

🖱️ Policy & Objects > Addresses اور Policy & Objects > Firewall Policy میں بنائیں۔Policy & Objects > Addresses aur Policy & Objects > Firewall Policy mein banayen.Build under Policy & Objects > Addresses and Policy & Objects > Firewall Policy.

Step 4

DMZ ویب سرور کو VIP (DNAT) سے پبلش کریں اور میچنگ WAN-to-DMZ پالیسی بنائیں۔ یاد رکھیں: VIP کو اپنی الاؤ پالیسی چاہیے۔DMZ web server ko VIP (DNAT) se publish karen aur matching WAN-to-DMZ policy banayen. Yaad rakhen: VIP ko apni allow policy chahiye.Publish the DMZ web server with a VIP (DNAT) and a matching WAN-to-DMZ policy. Remember: VIP needs its own allow policy.

config firewall vip
    edit WEB_VIP
        set extintf port1
        set extip 203.0.113.10
        set mappedip 10.10.10.10
        set portforward enable
        set extport 443
        set mappedport 443
    next
end
config firewall policy
    edit 2
        set name WAN-to-Web
        set srcintf port1
        set dstintf port3
        set srcaddr all
        set dstaddr WEB_VIP
        set service HTTPS
        set schedule always
        set action accept
        set logtraffic all
    next
end

🖱️ Policy & Objects > Virtual IPs میں بنائیں، پھر پالیسی سے الاؤ کریں۔Policy & Objects > Virtual IPs mein banayen, phir policy se allow karen.Create under Policy & Objects > Virtual IPs, then allow it with a policy.

Step 5

یوزر آتھینٹیکیشن سیٹ کریں: لوکل یوزر، گروپ، اور گروپ کو IPsec/SSL VPN پالیسی سے جوڑیں تاکہ صرف آتھینٹی کیٹڈ یوزرز کو ریموٹ رسائی ملے۔User authentication set karen: local user, group, aur group ko IPsec/SSL VPN policy se joren taake sirf authenticated users ko remote rasai mile.Set up user authentication: local user, group, and attach the group to an IPsec/SSL VPN policy so only authenticated users get remote access.

config user local
    edit vpnuser
        set type password
        set passwd VpnUser123!
    next
end
config user group
    edit VPN_USERS
        set member vpnuser
    next
end

🖱️ User & Authentication > User Definition اور User Groups میں بنائیں۔User & Authentication > User Definition aur User Groups mein banayen.Create under User & Authentication > User Definition and User Groups.

Step 6

برانچ تک سائٹ ٹو سائٹ IPsec VPN بنائیں (برانچ سائیڈ پر مِرر کنفگ) اور ٹنل کی دونوں ڈائریکشنز کے لیے فائر وال پالیسیز شامل کریں۔Branch tak site-to-site IPsec VPN banayen (branch side par mirror config) aur tunnel ki dono directions ke liye firewall policies shamil karen.Build the site-to-site IPsec VPN to the branch (mirror config on the branch side) and add firewall policies for both tunnel directions.

config vpn ipsec phase1-interface
    edit HQ-to-Branch
        set interface port1
        set ike-version 2
        set peertype any
        set proposal aes256-sha256
        set dhgrp 14
        set remote-gw 198.51.100.2
        set psksecret CapstonePsk123!
    next
end
config vpn ipsec phase2-interface
    edit HQ-to-Branch-P2
        set phase1name HQ-to-Branch
        set proposal aes256-sha256
        set dhgrp 14
        set src-subnet 192.168.10.0 255.255.255.0
        set dst-subnet 192.168.20.0 255.255.255.0
    next
end

🖱️ VPN > IPsec Tunnels میں وزرڈ استعمال کریں۔VPN > IPsec Tunnels mein wizard istemal karen.Use the wizard under VPN > IPsec Tunnels.

Step 7

FortiAnalyzer پر سینٹرلائزڈ لاگنگ آن کریں اور FortiManager سے رجسٹر کریں۔ ٹیسٹ لاگ سے تصدیق کریں کہ لاگز بہہ رہے ہیں۔FortiAnalyzer par centralized logging on karen aur FortiManager se register karen. Test log se tasdeeq karen ke logs beh rahe hain.Enable centralized logging to FortiAnalyzer and register with FortiManager. Confirm logs flow with a test log.

config log fortianalyzer setting
    set status enable
    set server 192.168.20.10
end
config system central-management
    set mode normal
    set type fortimanager
    set fmg 192.168.20.12
end
diagnose log test

🖱️ Log & Report > Log Settings اور Security Fabric > Settings میں کنفیگر کریں۔Log & Report > Log Settings aur Security Fabric > Settings mein configure karen.Configure under Log & Report > Log Settings and Security Fabric > Settings.

Step 8

آخری قدم: ڈیوائس سے باہر مکمل کنفیگریشن بیک اپ لیں اور بلڈ ڈاکیومنٹ کریں — IPs، پالیسیز، VPN PSKs (والٹ میں) اور ورژنز۔ ڈاکیومنٹیشن اور بیک اپ کے بغیر ڈیپلائمنٹ مکمل نہیں۔Aakhri qadam: device se bahar mukammal configuration backup len aur build document karen — IPs, policies, VPN PSKs (vault mein) aur versions. Documentation aur backup ke baghair deployment mukammal nahi.Final step: take a full configuration backup off-device and document the build — IPs, policies, VPN PSKs (in a vault), and versions. A deployment without documentation and backup is not finished.

execute backup config tftp FG-ENTERPRISE-final.conf 192.168.1.10
get system status

تصدیقVerifyVerify

سب چیک لسٹ آئٹمز پاس: LAN سے انٹرنیٹ براؤز ہوتا ہے، VIP سے DMZ سائٹ کھلتی ہے، VPN ٹنل اپ ہے، لاگز FortiAnalyzer تک پہنچتے ہیں، ڈیوائس FortiManager میں مینیجڈ ہے، اور بیک اپ ڈیوائس سے باہر موجود ہے۔Sab checklist items pass: LAN se internet browse hota hai, VIP se DMZ site khulti hai, VPN tunnel up hai, logs FortiAnalyzer tak pohanchtay hain, device FortiManager mein managed hai, aur backup device se bahar mojood hai.All checklist items pass: LAN browses the internet, the DMZ site loads via the VIP, the VPN tunnel is up, logs reach FortiAnalyzer, the device is managed in FortiManager, and a backup exists off-device.

get system status
diagnose vpn tunnel list
get log fortianalyzer setting status

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ گو لائیو کے بعد ایک سروس چل رہی ہے مگر دوسری فیل ہو رہی ہے۔Go-live ke baad aik service chal rahi hai magar doosri fail ho rahi hai.One service works but another fails after go-live.

✅ چیک لسٹ کو الٹا چیک کریں: پالیسیز (آرڈر، انٹرفیسز، آبجیکٹس)، NAT/VIP، روٹس، پھر لاگز۔ فیل ہونے والے IP پر فلٹر کر کے Log & Report > Forward Traffic میں دیکھیں کہ کون سی پالیسی لگی یا مس ہوئی۔Checklist ko ulta check karen: policies (order, interfaces, objects), NAT/VIP, routes, phir logs. Fail hone wale IP par filter kar ke Log & Report > Forward Traffic mein dekhen ke kaun si policy lagi ya miss hui.Work the checklist backwards: policies (order, interfaces, objects), NAT/VIP, routes, then logs. Use Log & Report > Forward Traffic filtered by the failing IP to see which policy hit or missed.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ چھوٹی انٹرپرائز کے لیے FortiGate ڈیپلائے کرنے کا عمل بتائیں۔Choti enterprise ke liye FortiGate deploy karne ka amal batayen.Walk me through deploying a FortiGate for a small enterprise.

میں چیک لسٹ سے گزرتا ہوں: مینجمنٹ ہارڈننگ، انٹرفیسز اور زونز، روٹنگ، آبجیکٹس کے ساتھ پالیسیز، NAT، آتھینٹیکیشن، VPN، سیکیورٹی پروفائلز، FortiAnalyzer پر لاگنگ، FortiManager رجسٹریشن، پھر بیک اپ اور ڈاکیومنٹیشن۔Main checklist se guzarta hoon: management hardening, interfaces aur zones, routing, objects ke saath policies, NAT, authentication, VPN, security profiles, FortiAnalyzer par logging, FortiManager registration, phir backup aur documentation.I walk through the checklist: management hardening, interfaces and zones, routing, policies with objects, NAT, authentication, VPN, security profiles, logging to FortiAnalyzer, FortiManager registration, then backup and documentation.

❓ FortiGate کے گو لائیو ہارڈننگ کی آپ کی چیک لسٹ کیا ہے؟FortiGate ke go-live hardening ki aap ki checklist kya hai?What is your go-live hardening checklist for a FortiGate?

میں allowaccess (صرف ضروری پروٹوکولز)، مضبوط admin پاس ورڈز، فرم ویئر اپ ڈیٹڈ، ڈیفالٹ پالیسیز ریویوڈ، FortiAnalyzer پر لاگز کا بہاؤ، اور ڈیوائس سے باہر رکھا ہوا تازہ کنفگ بیک اپ چیک کرتا ہوں۔Main allowaccess (sirf zaroori protocols), mazboot admin passwords, firmware updated, default policies reviewed, FortiAnalyzer par logs ka bahao, aur device se bahar rakha hua taaza config backup check karta hoon.I check allowaccess (only needed protocols), strong admin passwords, firmware updated, default policies reviewed, logs flowing to FortiAnalyzer, and a fresh config backup stored off-device.