Loading...

Khóa học Quản trị FortiGate Online (FortiOS 7.0) — Từ cơ bản đến nâng cao

Khóa học Quản trị FortiGate Firewall

Giới thiệu khóa học

FortiGate là dòng thiết bị Next-Generation Firewall (NGFW) được sử dụng phổ biến tại các doanh nghiệp Việt Nam, từ văn phòng chi nhánh nhỏ đến trung tâm dữ liệu. Là đối tác ủy quyền của Fortinet, VNExperts xây dựng khóa học này nhằm cung cấp kiến thức quản trị FortiGate một cách có hệ thống, đi từ nguyên lý nền tảng đến các tình huống triển khai thực tế mà đội ngũ kỹ thuật VNExperts đã gặp trong quá trình tư vấn và triển khai cho khách hàng.

Khóa học sử dụng FortiOS 7.0 làm phiên bản tham chiếu cho các ví dụ GUI và CLI. Những khác biệt quan trọng trên FortiOS 7.2 và 7.4 sẽ được ghi chú trong từng bài khi cần.

Đối tượng phù hợp học FortiGate

  • Kỹ thuật viên IT / Network Admin muốn triển khai và vận hành FortiGate trong môi trường doanh nghiệp
  • Người đã có nền tảng networking cơ bản (khuyến khích tham khảo trước khóa học CCNA online nếu chưa vững kiến thức routing/switching)
  • Người chuẩn bị học hoặc ôn luyện các chứng chỉ Fortinet (xem thêm lộ trình chứng chỉ Fortinet ở cuối khóa)
  • Đội ngũ kỹ thuật đối tác/khách hàng của VNExperts cần chuẩn hóa quy trình cấu hình FortiGate

Mục Lục Khóa Học FortiGate (84 Bài)

Nhóm 1: Nền tảng & Kiến trúc FortiGate

  1. Tổng quan Fortinet & vị trí FortiGate trong hệ sinh thái Security Fabric
  2. FortiASIC: chip NP (Network Processor) và CP (Content Processor) — vai trò tăng tốc hiệu năng
  3. Kiến trúc FortiOS: Profile-based vs Policy-based NGFW & luồng xử lý gói tin (Packet Flow)
  4. Các dòng thiết bị FortiGate & cách chọn model theo nhu cầu
  5. Cài đặt ban đầu: đấu nối, truy cập GUI/CLI, đăng ký FortiCare & FortiGuard
  6. Giao diện quản trị: cấu trúc lệnh CLI config/edit/set/end, 4 nhóm lệnh show/get/diagnose/execute
  7. Quản lý Admin: Admin Profile, quyền hạn, Trusted Hosts, Admin Lockout, Password Policy & 2FA
  8. Backup/Restore cấu hình, Firmware Upgrade Path & Configuration Revision
  9. VDOM (Virtual Domain): khi nào cần, No VDOM vs Split-task vs Multi VDOM

Nhóm 2: Networking cơ bản trên FortiGate

  1. Interface FortiGate: Physical, VLAN, Aggregate (LACP), Software Switch, Loopback
  2. Zone trên FortiGate: cách nhóm interface để đơn giản hóa Firewall Policy
  3. ARP, Neighbor table, MAC table trên FortiGate — xử lý Layer 2 và troubleshooting
  4. Routing tĩnh FortiGate: Administrative Distance, Priority, Blackhole Route, Policy Route
  5. ECMP, Link Monitor & Dead Gateway Detection trên FortiGate
  6. DHCP Server và Relay trên FortiGate — cấu hình và khi nào dùng chế độ nào
  7. NAT trên FortiGate: Policy NAT với SNAT Overload, One-to-one, Fixed Port Range
  8. NAT trên FortiGate: Central NAT, Virtual IP (VIP), Port Forwarding, VIP Hairpin NAT
  9. DNS trên FortiGate: DNS Server, DNS Relay, DNS Database và DNS Filter sơ lược
  10. IPv6 cơ bản trên FortiGate: cấu hình Interface, Firewall Policy, Routing tĩnh
  11. Routing động OSPF cơ bản trên FortiGate
  12. Routing động BGP cơ bản trên FortiGate
  13. SD-WAN trên FortiGate: khái niệm, Performance SLA, rule-based load balancing
  14. Virtual Wire Pair (Transparent inline mode) trên FortiGate

Nhóm 3: Security Policy & Inspection

  1. Firewall Policy FortiGate: cấu trúc, thứ tự xử lý, Implicit Deny, Policy Lookup
  2. Address Object, Address Group, Internet Service Database (ISDB) trên FortiGate
  3. Service Object & Schedule trên FortiGate
  4. Local-In Policy — kiểm soát traffic đến chính FortiGate
  5. DoS Policy trên FortiGate — chống tấn công từ chối dịch vụ cơ bản
  6. Identity Policy & Authentication Rule trên FortiGate
  7. Certificate trên FortiGate: Local Cert, CA, Import
  8. SSL Inspection trên FortiGate: Certificate Inspection vs Deep Inspection
  9. Antivirus Profile trên FortiGate: Flow-based vs Proxy-based
  10. Web Filter trên FortiGate: FortiGuard Category, URL Filter, Override
  11. Application Control trên FortiGate: Sensor, Category, Override
  12. IPS trên FortiGate: Sensor, Signature, Severity
  13. DNS Filter & File Filter trên FortiGate
  14. Traffic Shaping & QoS trên FortiGate
  15. Explicit Proxy & Transparent Proxy trên FortiGate
  16. Logging & Reporting cơ bản trên FortiGate

Nhóm 4: VPN trên FortiGate

  1. Khái niệm VPN & IPSec Phase 1/Phase 2 trên FortiGate
  2. Site-to-Site IPsec VPN (Route-based) trên FortiGate — có Lab thực hành
  3. Route-based vs Policy-based IPSec VPN: so sánh và khi nào dùng
  4. IKEv2 trên FortiGate
  5. IPsec VPN qua Dynamic IP (Dialup) trên FortiGate — có Lab thực hành
  6. IPsec Hardware Offload — vai trò của NP trong tăng tốc VPN
  7. SSL-VPN trên FortiGate: Tunnel Mode vs Web Mode
  8. SSL-VPN Split Tunnel & Portal Customization — có Lab thực hành
  9. Troubleshooting VPN trên FortiGate: diagnose vpn ike log, diagnose vpn tunnel list
  10. ADVPN (Auto-Discovery VPN) — khái niệm cho SD-WAN hub-spoke
  11. VPN High Availability & Failover trên FortiGate
  12. FortiClient Integration cơ bản (Remote Access) với FortiGate

Nhóm 5: High Availability & Quản lý tập trung

  1. FGCP HA trên FortiGate: Active-Passive, Active-Active — nguyên lý bầu chọn Master
  2. Cấu hình HA Cluster, Heartbeat Interface trên FortiGate — có Lab thực hành
  3. HA Failover Testing & Troubleshooting trên FortiGate
  4. FortiSwitch — quản trị qua Security Fabric
  5. FortiAP — quản trị qua Security Fabric
  6. Giới thiệu FortiManager (quản lý tập trung nhiều FortiGate)
  7. Giới thiệu FortiAnalyzer (log & report tập trung)
  8. Fabric Connector: kết nối AWS, Azure, VMware với FortiGate
  9. Automation Stitch (Trigger–Action) cơ bản trên FortiGate
  10. REST API FortiGate — hướng đi tự động hóa

Nhóm 6: Authentication & User Management

  1. Local User & User Group trên FortiGate
  2. LDAP/AD Integration với FortiGate
  3. RADIUS Integration với FortiGate
  4. SAML / Azure AD (Entra ID) Integration với FortiGate
  5. Captive Portal (Guest Access) trên FortiGate
  6. Two-Factor Authentication (FortiToken) trên FortiGate
  7. Single Sign-On (FSSO) khái niệm trên FortiGate

Nhóm 7: Monitoring, Troubleshooting & Diagnostics

  1. FortiView — phân tích traffic real-time trên FortiGate
  2. Log & Report: cấu hình gửi log (local, FortiAnalyzer, syslog)
  3. CLI Diagnostic nâng cao trên FortiGate: diagnose sys, get system performance
  4. Packet Capture trên FortiGate (diagnose sniffer packet)
  5. Debug Flow & Flow Trace — công cụ troubleshooting quan trọng nhất trên FortiGate
  6. Session Table & Session TTL trên FortiGate (diagnose sys session list)
  7. Troubleshooting NAT/Routing thường gặp trên FortiGate
  8. Performance Tuning cơ bản trên FortiGate (CPU/Memory, Conserve Mode)

Nhóm 8: Chủ đề nâng cao / Thực chiến doanh nghiệp

  1. Zero Trust Network Access (ZTNA) trên FortiGate
  2. SD-WAN nâng cao trên FortiGate: multiple internet, failover thực tế
  3. Multi-tenant / MSSP Scenario với VDOM trên FortiGate
  4. Case Study: thiết kế firewall FortiGate cho SMB
  5. Case Study: thiết kế firewall FortiGate cho Enterprise/Datacenter
  6. Best Practice Hardening FortiGate
  7. Tổng hợp Policy Lookup & Debug Flow — quy trình chẩn đoán sự cố chuẩn
  8. Chứng chỉ Fortinet hiện nay & Roadmap học tiếp sau khóa FortiGate