← all cheatsheets
FortiGate

FortiGate

Fortinet NGFW

1. What FortiGate Does2. Security Capabilities3. Networking4. Connectivity5. Deployment Modes6. Traffic Flow

1. What FortiGate Does

Traffic Control, Threat Prevention, VPN, SD-WAN, Segmentation & Visibility on a single platform.

Remote User ──┐
              ├── Internet ── ISP/Edge Router ── WAN1 (Primary)
Branch Office ─┘                                    WAN2 (Secondary)
                                                        │
                                              FortiGate NGFW HA Cluster
                                              FG-1 (Active) ←→ FG-2 (Passive)
                                                        │
                                              Core Switch / Distribution Layer
                                              ├── Users VLAN
                                              ├── Servers VLAN
                                              ├── DMZ

2. Security Capabilities

CapabilityDescription
Stateful FirewallTracks connections and sessions
IPSIntrusion Prevention System
AntivirusMalware prevention
Web FilteringControls web access
Application ControlIdentifies and controls apps (L7)
SSL/TLS InspectionDecrypts and inspects encrypted traffic
DNS FilteringBlocks malicious DNS queries
Threat IntelligenceReal-time threat feeds

3. Networking

Routing & Switching

Static & dynamic routing, NAT, VLANs, SD-WAN

High Availability

HA clustering, Policy-Based Routing, Traffic Shaping, Multi-WAN

4. Connectivity

  • SSL VPN — Secure remote access via browser
  • IPsec VPN — Site-to-site VPN
  • Site-to-Site VPN — Branch connectivity
  • Remote Access VPN — User remote access
  • SD-WAN — Secure branch links

5. Deployment Modes

ModeDescription
L2 TransparentInline bridge deployment (Layer 2)
L3 RoutedDefault enterprise deployment (Layer 3)
L4 StatefulTracks connections (TCP/UDP/ICMP)
L7 ApplicationIdentifies and controls apps

6. Traffic Flow

Decision Pipeline
Identify → Inspect → Apply Policy → Allow/Block → Route → Log

Internet-bound

User Traffic → Identify → Inspect → Policy → NAT/IPS

Inbound Services

Internet → DNAT/VIP → IPS → Security Profiles → Allowed

Remote Access VPN

Remote User → SSL/IPsec → Auth → Internal Resources

Internal Segmentation

VLAN → Inter-VLAN Policy → East-West Inspection