FortiGate NGFW — Multi-Zone Firewall + VPN

Project 02 — Firewall & Security

FortiGate NGFW — Multi-Zone Firewall with VPN & IIS Server

A hands-on FortiGate NGFW lab built in EVE-NG (FortiGate VM64-KVM v7.0.3), simulating a real enterprise security architecture with segmented zones, deep traffic inspection, site-to-site VPN connectivity, and a DMZ-hosted IIS web server.

FortiGate Lab Interface

Platform ► EVE-NG · FortiGate VM64-KVM (FortiOS 7.0.3)

Zones ► LAN (port1) · DMZ (port2) · WAN (port3)

VPN ► Site-to-Site IPsec VPN (VPN-to-Cisco) — Up and passing traffic

DMZ ► Windows Server IIS — exposed via Virtual IP (VIP)


Key Features

3-zone architecture with full firewall policies and layered Security Profiles: Web Filter, IPS, Application Control, and SSL Inspection. Site-to-Site IPsec VPN tunnel verified passing traffic. Web Filtering tested live with blocked access and policy-level logging. Application Control blocking unauthorized traffic. DMZ-hosted Windows Server IIS site exposed via Virtual IP for controlled WAN-to-DMZ access. FortiView monitoring real-time bytes, sessions, and bandwidth per host.

Interface Configuration Firewall Policy IPsec VPN Web Filter Block Traffic Logs IIS Windows Server DMZ FortiView Sources

Technologies ► EVE-NG · FortiGate VM64-KVM (FortiOS 7.0.3) · IPsec VPN · Web Filtering · IPS · Application Control · SSL Inspection · Virtual IP · Windows Server IIS · FortiView


Challenges & Skills

Configured a full enterprise security stack from scratch on FortiGate — zones, policies, UTM profiles, VPN, and VIP. Verified each security control with live traffic testing. Gained deep hands-on experience with FortiOS that goes beyond certification study.

← Back to projects