FortiGate NGFW — Multi-Zone Firewall with VPN & IIS Server
A hands-on FortiGate NGFW lab built in EVE-NG (FortiGate VM64-KVM v7.0.3), simulating a real enterprise security architecture with segmented zones, deep traffic inspection, site-to-site VPN connectivity, and a DMZ-hosted IIS web server.
Key Features
3-zone architecture with full firewall policies and layered Security Profiles: Web Filter, IPS, Application Control, and SSL Inspection. Site-to-Site IPsec VPN tunnel verified passing traffic. Web Filtering tested live with blocked access and policy-level logging. Application Control blocking unauthorized traffic. DMZ-hosted Windows Server IIS site exposed via Virtual IP for controlled WAN-to-DMZ access. FortiView monitoring real-time bytes, sessions, and bandwidth per host.
Challenges & Skills
Configured a full enterprise security stack from scratch on FortiGate — zones, policies, UTM profiles, VPN, and VIP. Verified each security control with live traffic testing. Gained deep hands-on experience with FortiOS that goes beyond certification study.