Capstone: Enterprise FortiGate Build
FortiGate — FCP track EVE-NG — FortiGate VM (GUI + CLI)
مقصدObjectiveObjective
اس کیپ اسٹون میں آپ مکمل انٹرپرائز FortiGate ڈیپلائے کریں گے: ہارڈنڈ مینجمنٹ، انٹرفیسز اور زونز، روٹنگ، پالیسیز، NAT، آتھینٹیکیشن، IPsec VPN، سیکیورٹی پروفائلز، لاگنگ، سینٹرل مینجمنٹ اور بیک اپ۔Is capstone mein aap mukammal enterprise FortiGate deploy karenge: hardened management, interfaces aur zones, routing, policies, NAT, authentication, IPsec VPN, security profiles, logging, central management aur backup.In this capstone you will deploy a complete enterprise FortiGate: hardened management, interfaces and zones, routing, policies, NAT, authentication, IPsec VPN, security profiles, logging, central management, and backup.
آسان مثالSimple AnalogySimple Analogy
کیپ اسٹون ایسے ہے جیسے فائنل ڈرائیونگ ٹیسٹ: آپ نے پارکنگ، ریورس اور ہائی وے الگ الگ پریکٹس کیے — اب پورا روٹ ایک ساتھ چلا کر ثابت کرتے ہیں کہ آپ تیار ہیں۔Capstone aise hai jaise final driving test: aap ne parking, reverse aur highway alag alag practice kiye — ab poora route aik saath chala kar sabit karte hain ke aap tayyar hain.A capstone is like the final driving test: you have practiced parking, reversing, and highway driving separately — now you drive the whole route at once to prove you are ready.
سیٹ اپLab SetupLab Setup
EVE-NG میں تازہ FortiGate VM۔ ٹوپولوجی: port1 WAN 203.0.113.2/24 (gw 203.0.113.1)، port2 LAN 192.168.10.1/24، port3 DMZ 10.10.10.1/24۔ ہر چیک لسٹ قدم ترتیب سے مکمل کریں۔EVE-NG mein taaza FortiGate VM. Topology: port1 WAN 203.0.113.2/24 (gw 203.0.113.1), port2 LAN 192.168.10.1/24, port3 DMZ 10.10.10.1/24. Har checklist qadam tarteeb se mukammal karen.Fresh FortiGate VM in EVE-NG. Topology: port1 WAN 203.0.113.2/24 (gw 203.0.113.1), port2 LAN 192.168.10.1/24, port3 DMZ 10.10.10.1/24. Work through every checklist step in order.
اقداماتStepsSteps
Step 1
مینجمنٹ رسائی ہارڈن کریں: مضبوط admin پاس ورڈ، hostname، اور allowaccess صرف https اور ssh تک محدود کریں۔ http اور telnet ہر جگہ سے ہٹائیں۔Management rasai harden karen: mazboot admin password, hostname, aur allowaccess sirf https aur ssh tak mehdood karen. http aur telnet har jagah se hatayen.Harden management access: strong admin password, hostname, and restrict allowaccess to only https and ssh. Remove http and telnet everywhere.
config system admin
edit admin
set password HardenedPass123!
next
end
config system global
set hostname FG-ENTERPRISE
end🖱️ System > Settings میں Host name سیٹ کریں؛ System > Administrators میں admin پاس ورڈ تبدیل کریں۔System > Settings mein Host name set karen; System > Administrators mein admin password tabdeel karen.Set Host name under System > Settings; change the admin password under System > Administrators.
Step 2
نیٹ ورک کی بنیاد بنائیں: انٹرفیس IPs اور رولز، port2+port3 کے لیے INTERNAL زون، اور WAN گیٹ وے تک ڈیفالٹ روٹ۔Network ki bunyad banayen: interface IPs aur roles, port2+port3 ke liye INTERNAL zone, aur WAN gateway tak default route.Build the network foundation: interface IPs and roles, an INTERNAL zone for port2+port3, and the default route to the WAN gateway.
config system interface
edit port1
set ip 203.0.113.2/24
set allowaccess ping
set role wan
next
edit port2
set ip 192.168.10.1/24
set allowaccess ping
set role lan
next
edit port3
set ip 10.10.10.1/24
set allowaccess ping
set role dmz
next
end
config system zone
edit INTERNAL
set interface port2 port3
next
end
config router static
edit 1
set dst 0.0.0.0/0
set gateway 203.0.113.1
set device port1
next
end🖱️ Network > Interfaces، Network > Zones، Network > Static Routes میں بنائیں۔Network > Interfaces, Network > Zones, Network > Static Routes mein banayen.Build under Network > Interfaces, Network > Zones, Network > Static Routes.
Step 3
ایڈریس آبجیکٹس اور مین آؤٹ باؤنڈ پالیسی بنائیں — NAT، مکمل لاگنگ اور چاروں سیکیورٹی پروفائلز کے ساتھ۔Address objects aur main outbound policy banayen — NAT, mukammal logging aur chaaron security profiles ke saath.Create address objects and the main outbound policy with NAT, full logging, and all four security profiles attached.
config firewall address
edit LAN_NET
set subnet 192.168.10.0 255.255.255.0
next
edit DMZ_NET
set subnet 10.10.10.0 255.255.255.0
next
end
config firewall policy
edit 1
set name INTERNAL-to-WAN
set srcintf INTERNAL
set dstintf port1
set srcaddr LAN_NET DMZ_NET
set dstaddr all
set service HTTP HTTPS DNS
set schedule always
set action accept
set logtraffic all
set nat enable
set utm-status enable
set av-profile default
set ips-sensor default
set webfilter-profile default
set application-list default
next
end🖱️ Policy & Objects > Addresses اور Policy & Objects > Firewall Policy میں بنائیں۔Policy & Objects > Addresses aur Policy & Objects > Firewall Policy mein banayen.Build under Policy & Objects > Addresses and Policy & Objects > Firewall Policy.
Step 4
DMZ ویب سرور کو VIP (DNAT) سے پبلش کریں اور میچنگ WAN-to-DMZ پالیسی بنائیں۔ یاد رکھیں: VIP کو اپنی الاؤ پالیسی چاہیے۔DMZ web server ko VIP (DNAT) se publish karen aur matching WAN-to-DMZ policy banayen. Yaad rakhen: VIP ko apni allow policy chahiye.Publish the DMZ web server with a VIP (DNAT) and a matching WAN-to-DMZ policy. Remember: VIP needs its own allow policy.
config firewall vip
edit WEB_VIP
set extintf port1
set extip 203.0.113.10
set mappedip 10.10.10.10
set portforward enable
set extport 443
set mappedport 443
next
end
config firewall policy
edit 2
set name WAN-to-Web
set srcintf port1
set dstintf port3
set srcaddr all
set dstaddr WEB_VIP
set service HTTPS
set schedule always
set action accept
set logtraffic all
next
end🖱️ Policy & Objects > Virtual IPs میں بنائیں، پھر پالیسی سے الاؤ کریں۔Policy & Objects > Virtual IPs mein banayen, phir policy se allow karen.Create under Policy & Objects > Virtual IPs, then allow it with a policy.
Step 5
یوزر آتھینٹیکیشن سیٹ کریں: لوکل یوزر، گروپ، اور گروپ کو IPsec/SSL VPN پالیسی سے جوڑیں تاکہ صرف آتھینٹی کیٹڈ یوزرز کو ریموٹ رسائی ملے۔User authentication set karen: local user, group, aur group ko IPsec/SSL VPN policy se joren taake sirf authenticated users ko remote rasai mile.Set up user authentication: local user, group, and attach the group to an IPsec/SSL VPN policy so only authenticated users get remote access.
config user local
edit vpnuser
set type password
set passwd VpnUser123!
next
end
config user group
edit VPN_USERS
set member vpnuser
next
end🖱️ User & Authentication > User Definition اور User Groups میں بنائیں۔User & Authentication > User Definition aur User Groups mein banayen.Create under User & Authentication > User Definition and User Groups.
Step 6
برانچ تک سائٹ ٹو سائٹ IPsec VPN بنائیں (برانچ سائیڈ پر مِرر کنفگ) اور ٹنل کی دونوں ڈائریکشنز کے لیے فائر وال پالیسیز شامل کریں۔Branch tak site-to-site IPsec VPN banayen (branch side par mirror config) aur tunnel ki dono directions ke liye firewall policies shamil karen.Build the site-to-site IPsec VPN to the branch (mirror config on the branch side) and add firewall policies for both tunnel directions.
config vpn ipsec phase1-interface
edit HQ-to-Branch
set interface port1
set ike-version 2
set peertype any
set proposal aes256-sha256
set dhgrp 14
set remote-gw 198.51.100.2
set psksecret CapstonePsk123!
next
end
config vpn ipsec phase2-interface
edit HQ-to-Branch-P2
set phase1name HQ-to-Branch
set proposal aes256-sha256
set dhgrp 14
set src-subnet 192.168.10.0 255.255.255.0
set dst-subnet 192.168.20.0 255.255.255.0
next
end🖱️ VPN > IPsec Tunnels میں وزرڈ استعمال کریں۔VPN > IPsec Tunnels mein wizard istemal karen.Use the wizard under VPN > IPsec Tunnels.
Step 7
FortiAnalyzer پر سینٹرلائزڈ لاگنگ آن کریں اور FortiManager سے رجسٹر کریں۔ ٹیسٹ لاگ سے تصدیق کریں کہ لاگز بہہ رہے ہیں۔FortiAnalyzer par centralized logging on karen aur FortiManager se register karen. Test log se tasdeeq karen ke logs beh rahe hain.Enable centralized logging to FortiAnalyzer and register with FortiManager. Confirm logs flow with a test log.
config log fortianalyzer setting
set status enable
set server 192.168.20.10
end
config system central-management
set mode normal
set type fortimanager
set fmg 192.168.20.12
end
diagnose log test🖱️ Log & Report > Log Settings اور Security Fabric > Settings میں کنفیگر کریں۔Log & Report > Log Settings aur Security Fabric > Settings mein configure karen.Configure under Log & Report > Log Settings and Security Fabric > Settings.
Step 8
آخری قدم: ڈیوائس سے باہر مکمل کنفیگریشن بیک اپ لیں اور بلڈ ڈاکیومنٹ کریں — IPs، پالیسیز، VPN PSKs (والٹ میں) اور ورژنز۔ ڈاکیومنٹیشن اور بیک اپ کے بغیر ڈیپلائمنٹ مکمل نہیں۔Aakhri qadam: device se bahar mukammal configuration backup len aur build document karen — IPs, policies, VPN PSKs (vault mein) aur versions. Documentation aur backup ke baghair deployment mukammal nahi.Final step: take a full configuration backup off-device and document the build — IPs, policies, VPN PSKs (in a vault), and versions. A deployment without documentation and backup is not finished.
execute backup config tftp FG-ENTERPRISE-final.conf 192.168.1.10 get system status
تصدیقVerifyVerify
سب چیک لسٹ آئٹمز پاس: LAN سے انٹرنیٹ براؤز ہوتا ہے، VIP سے DMZ سائٹ کھلتی ہے، VPN ٹنل اپ ہے، لاگز FortiAnalyzer تک پہنچتے ہیں، ڈیوائس FortiManager میں مینیجڈ ہے، اور بیک اپ ڈیوائس سے باہر موجود ہے۔Sab checklist items pass: LAN se internet browse hota hai, VIP se DMZ site khulti hai, VPN tunnel up hai, logs FortiAnalyzer tak pohanchtay hain, device FortiManager mein managed hai, aur backup device se bahar mojood hai.All checklist items pass: LAN browses the internet, the DMZ site loads via the VIP, the VPN tunnel is up, logs reach FortiAnalyzer, the device is managed in FortiManager, and a backup exists off-device.
get system status diagnose vpn tunnel list get log fortianalyzer setting status
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ گو لائیو کے بعد ایک سروس چل رہی ہے مگر دوسری فیل ہو رہی ہے۔Go-live ke baad aik service chal rahi hai magar doosri fail ho rahi hai.One service works but another fails after go-live.
✅ چیک لسٹ کو الٹا چیک کریں: پالیسیز (آرڈر، انٹرفیسز، آبجیکٹس)، NAT/VIP، روٹس، پھر لاگز۔ فیل ہونے والے IP پر فلٹر کر کے Log & Report > Forward Traffic میں دیکھیں کہ کون سی پالیسی لگی یا مس ہوئی۔Checklist ko ulta check karen: policies (order, interfaces, objects), NAT/VIP, routes, phir logs. Fail hone wale IP par filter kar ke Log & Report > Forward Traffic mein dekhen ke kaun si policy lagi ya miss hui.Work the checklist backwards: policies (order, interfaces, objects), NAT/VIP, routes, then logs. Use Log & Report > Forward Traffic filtered by the failing IP to see which policy hit or missed.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ چھوٹی انٹرپرائز کے لیے FortiGate ڈیپلائے کرنے کا عمل بتائیں۔Choti enterprise ke liye FortiGate deploy karne ka amal batayen.Walk me through deploying a FortiGate for a small enterprise.
میں چیک لسٹ سے گزرتا ہوں: مینجمنٹ ہارڈننگ، انٹرفیسز اور زونز، روٹنگ، آبجیکٹس کے ساتھ پالیسیز، NAT، آتھینٹیکیشن، VPN، سیکیورٹی پروفائلز، FortiAnalyzer پر لاگنگ، FortiManager رجسٹریشن، پھر بیک اپ اور ڈاکیومنٹیشن۔Main checklist se guzarta hoon: management hardening, interfaces aur zones, routing, objects ke saath policies, NAT, authentication, VPN, security profiles, FortiAnalyzer par logging, FortiManager registration, phir backup aur documentation.I walk through the checklist: management hardening, interfaces and zones, routing, policies with objects, NAT, authentication, VPN, security profiles, logging to FortiAnalyzer, FortiManager registration, then backup and documentation.
❓ FortiGate کے گو لائیو ہارڈننگ کی آپ کی چیک لسٹ کیا ہے؟FortiGate ke go-live hardening ki aap ki checklist kya hai?What is your go-live hardening checklist for a FortiGate?
میں allowaccess (صرف ضروری پروٹوکولز)، مضبوط admin پاس ورڈز، فرم ویئر اپ ڈیٹڈ، ڈیفالٹ پالیسیز ریویوڈ، FortiAnalyzer پر لاگز کا بہاؤ، اور ڈیوائس سے باہر رکھا ہوا تازہ کنفگ بیک اپ چیک کرتا ہوں۔Main allowaccess (sirf zaroori protocols), mazboot admin passwords, firmware updated, default policies reviewed, FortiAnalyzer par logs ka bahao, aur device se bahar rakha hua taaza config backup check karta hoon.I check allowaccess (only needed protocols), strong admin passwords, firmware updated, default policies reviewed, logs flowing to FortiAnalyzer, and a fresh config backup stored off-device.