Media is too big
VIEW IN TELEGRAM
protocol decoder
بعد از باز شدن هر بسته (#dpi ) داخل #fortigate ما باید با یه مکانیزم خاصی شروع کنیم به تحلیل داده های داخل اون بسته که اینجا ابزاریی مثل #pcre و #aho_corasick میان تو دل ماجرا و نحوه تحلیل هر #protocol به بهترین شکل عملی میکنن.
#pcre #fgt #fortinet #fortigate #nse7 #inspection #ips #decoder #sheynshield
بعد از باز شدن هر بسته (#dpi ) داخل #fortigate ما باید با یه مکانیزم خاصی شروع کنیم به تحلیل داده های داخل اون بسته که اینجا ابزاریی مثل #pcre و #aho_corasick میان تو دل ماجرا و نحوه تحلیل هر #protocol به بهترین شکل عملی میکنن.
#pcre #fgt #fortinet #fortigate #nse7 #inspection #ips #decoder #sheynshield
SheynShield pinned «Youtube channel https://youtube.com/@sheynshield?si=0-slAn9SQyiLqMv4»
از الان به بعد ویدیو های اموزشی کوتاه میره تو کانال یوتوب
این ویدیو هم که لینکشو گذاشتم درباره tcp connection هست و برای تانلینگ ترافیک از سرور به کلاینت هم ویدیو جدا داریم که بعدا اشتراک میزارم.
https://youtu.be/pbBPZmj5fnw
#sheynshield
این ویدیو هم که لینکشو گذاشتم درباره tcp connection هست و برای تانلینگ ترافیک از سرور به کلاینت هم ویدیو جدا داریم که بعدا اشتراک میزارم.
https://youtu.be/pbBPZmj5fnw
#sheynshield
YouTube
TCP & TLS Handshake conecpt
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
#RSA
کلمه نام آشناییه، شاید تصور ما از انتقال ایمن و ارتباط دنیای اینترنتو ساخته ولی ماجرا عمیق تر ازین چیزاست.
با من همراه باشید این قسمت شاید به کارتون بیاد.
به قول یه بنده خدای باید ببینیم چه خواهد شد.
#tls #https #server #web #tcp #prf #cipher #cyber #client #cache #encryption
https://lnkd.in/ePjzCHSG
https://youtu.be/xPTDRzbL2V0
کلمه نام آشناییه، شاید تصور ما از انتقال ایمن و ارتباط دنیای اینترنتو ساخته ولی ماجرا عمیق تر ازین چیزاست.
با من همراه باشید این قسمت شاید به کارتون بیاد.
به قول یه بنده خدای باید ببینیم چه خواهد شد.
#tls #https #server #web #tcp #prf #cipher #cyber #client #cache #encryption
https://lnkd.in/ePjzCHSG
https://youtu.be/xPTDRzbL2V0
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
خیلی پیش میاد توی سازمان هدف ما بستن یک نرم افزار خاص و مشخص باشه ولی درست پیاده سازی کردن این فیلتر یا محدود سازی مهمتر از هر چیز دیگه ای هست . این ویدیو به ما نشون میده چجوری جلوی اجرای VPN داخل سازمان بگیریم.
#FortiGate #Fortinet #VPN #Firewall #Cybersecurity #NSE4 #NSE7 #DPI #SSLInspection #ApplicationControl #WebFiltering #InfoSec #SheynShield
https://youtu.be/38FlleQ7kac
https://www.instagram.com/sheynshield?igsh=MW5wYXB5dHdndjFxZw==
#FortiGate #Fortinet #VPN #Firewall #Cybersecurity #NSE4 #NSE7 #DPI #SSLInspection #ApplicationControl #WebFiltering #InfoSec #SheynShield
https://youtu.be/38FlleQ7kac
https://www.instagram.com/sheynshield?igsh=MW5wYXB5dHdndjFxZw==
YouTube
How Fortigate Block VPN in your Company
Welcome to the Sheyn Shield advanced firewall training series! VPNs are a common tool for bypassing security, but FortiGate gives you the granular control to stop them. This NSE 4 and NSE 7-level tutorial covers the comprehensive strategies FortiGate uses…
#ja3 #ja4 #ja4plus
شاید تحلیل بسته های شبکه سخت باشه ولی وقتی عمیق تر بهشون نگاه میکنیم متوجه تمام ابعاد تعامل اصولی سطح #network بشیم. اینجا قرار ببینیم این دوتا عنوان چه کمکی میکنن به ما و چجوری میتونن نرم افزارهای مارو ایمن نگه دارن.
# Legacy JA3 Format (Unsorted parameters - MD5 Hash)
Parameters: 771,4865-4866-4867-49195-49199,0-23-65281-10-11-35-16,29-23-24,0
JA3 Hash : 66918128f1b9b00714861676d123d244
# Modern JA4 Format (Human-Readable + Sorted Hash)
Format : [Protocol][TLS Ver][SNI][Ciphers][Extensions][ALPN]_[Cipher Hash]_[Extension Hash]
JA4 String: t13d151600_8daaf6152771_e8a159930c27
https://youtu.be/a8q8hFDOS38
#Cybersecurity #TLS #SSL #JA3 #JA4 #JA4Plus #TLSFingerprinting #NetworkSecurity #ThreatHunting #InfoSec #MalwareAnalysis #Wireshark #Zeek #Suricata #SOCAnalyst #BlueTeam #NetworkTrafficAnalysis #EncryptedTraffic #Cryptography #CobaltStrike #C2Detection #WAF #NGFW #Fortinet #PaloAlto #NetworkEngineering #CompTIA #NetworkPlus #N10009 #SecurityPlus #SY0701 #CCNA #CISSP #SheynShield
شاید تحلیل بسته های شبکه سخت باشه ولی وقتی عمیق تر بهشون نگاه میکنیم متوجه تمام ابعاد تعامل اصولی سطح #network بشیم. اینجا قرار ببینیم این دوتا عنوان چه کمکی میکنن به ما و چجوری میتونن نرم افزارهای مارو ایمن نگه دارن.
# Legacy JA3 Format (Unsorted parameters - MD5 Hash)
Parameters: 771,4865-4866-4867-49195-49199,0-23-65281-10-11-35-16,29-23-24,0
JA3 Hash : 66918128f1b9b00714861676d123d244
# Modern JA4 Format (Human-Readable + Sorted Hash)
Format : [Protocol][TLS Ver][SNI][Ciphers][Extensions][ALPN]_[Cipher Hash]_[Extension Hash]
JA4 String: t13d151600_8daaf6152771_e8a159930c27
https://youtu.be/a8q8hFDOS38
#Cybersecurity #TLS #SSL #JA3 #JA4 #JA4Plus #TLSFingerprinting #NetworkSecurity #ThreatHunting #InfoSec #MalwareAnalysis #Wireshark #Zeek #Suricata #SOCAnalyst #BlueTeam #NetworkTrafficAnalysis #EncryptedTraffic #Cryptography #CobaltStrike #C2Detection #WAF #NGFW #Fortinet #PaloAlto #NetworkEngineering #CompTIA #NetworkPlus #N10009 #SecurityPlus #SY0701 #CCNA #CISSP #SheynShield
YouTube
What is the JA3/4/4+ on TLS?
Welcome to another advanced network security masterclass by Sheyn Shield! In this video, we dive deep into the world of encrypted traffic analysis and TLS Fingerprinting. Even when traffic is fully encrypted via SSL/TLS, client software leaves behind distinct…
🛡 SheynShield Quick Tech Notes: Fortinet Security Fabric & OT Integration (NSE 7)
📌 AUTOMATION & DIAGNOSTICS
• Best Practice: Use sequential mode for restoring .pkg signature files & offline license tasks.
• Max Stitches Tuning:
config system automation setting
set max-concurrent-stitches 128
end
• CLI Diagnostics:
diagnose test application autod
diagnose debug application autod -1
diagnose debug enable
----------------------------------------
📌 DYNAMIC THREAT FEEDS (STIX/TAXII)
• Max File Size: 10 MB (FGT-100F) up to 500 MB (FGT-200F)
• Max Entries: 131,072 entries
• Limits: 512 Global / 256 per VDOM (Verify: print tablesize)
• Syntax Rules:
- Wildcards: *.google.com
- IPv4/IPv6 Ranges: CIDR notation (No brackets for IPs)
- IPv6 URLs: Must use brackets -> http://[2001:db8::1]/ip.txt
• CLI Check:
diagnose firewall dynamic list
----------------------------------------
📌 PURDUE OT MODEL (IEC 62443)
• Level 0: Physical Processes (Sensors/Actuators)
• Level 1: Basic Control (PLCs/RTUs)
• Level 2: Supervisory Control (SCADA/HMIs) -> FortiGate & FortiSwitch
• Level 3: Manufacturing Operations (MES/Historians)
• DMZ & Level 4: Enterprise Network (NGFW / IPS / SIEM)
• Change Purdue Level Memory Settings:
diagnose user-device-store device memory ot-prudue-set max ip level <level>
----------------------------------------
🔗 Full Video Tutorials & Labs on YouTube:
youtube.com/@sheynshield
#Fortinet #NSE7 #SecurityFabric #OTSecurity #CyberSecurity #SheynShield
📌 AUTOMATION & DIAGNOSTICS
• Best Practice: Use sequential mode for restoring .pkg signature files & offline license tasks.
• Max Stitches Tuning:
config system automation setting
set max-concurrent-stitches 128
end
• CLI Diagnostics:
diagnose test application autod
diagnose debug application autod -1
diagnose debug enable
----------------------------------------
📌 DYNAMIC THREAT FEEDS (STIX/TAXII)
• Max File Size: 10 MB (FGT-100F) up to 500 MB (FGT-200F)
• Max Entries: 131,072 entries
• Limits: 512 Global / 256 per VDOM (Verify: print tablesize)
• Syntax Rules:
- Wildcards: *.google.com
- IPv4/IPv6 Ranges: CIDR notation (No brackets for IPs)
- IPv6 URLs: Must use brackets -> http://[2001:db8::1]/ip.txt
• CLI Check:
diagnose firewall dynamic list
----------------------------------------
📌 PURDUE OT MODEL (IEC 62443)
• Level 0: Physical Processes (Sensors/Actuators)
• Level 1: Basic Control (PLCs/RTUs)
• Level 2: Supervisory Control (SCADA/HMIs) -> FortiGate & FortiSwitch
• Level 3: Manufacturing Operations (MES/Historians)
• DMZ & Level 4: Enterprise Network (NGFW / IPS / SIEM)
• Change Purdue Level Memory Settings:
diagnose user-device-store device memory ot-prudue-set max ip level <level>
----------------------------------------
🔗 Full Video Tutorials & Labs on YouTube:
youtube.com/@sheynshield
#Fortinet #NSE7 #SecurityFabric #OTSecurity #CyberSecurity #SheynShield
👍1
🔥 FortiGate HA: What You MUST Know Before Hitting Production
Setting up a FortiGate High Availability (HA) cluster is easy, but running it reliably in production requires understanding the underlying mechanics.
Here is a breakdown of the critical architecture rules every network engineer needs to master:
⚡️ 1. Decouple the Core HA Concepts
Don't treat HA as a single monolithic process. Always separate these four distinct stages during design and troubleshooting:
Heartbeat: Continuous health checks between peer units.
Failure Detection: Deciding when a peer or monitored interface is actually down.
Election: The logic engine determining which unit becomes Primary.
Session Synchronization: Keeping active stateful connections alive across role shifts.
👑 2. The Primary Selection & Override Trap
Consider this standard configuration:
Enabling Override forces
⚠️ The Critical Gotcha:
HA Override and Device Priority are NOT synchronized between cluster members.
Fortinet explicitly places these under non-synchronized configurations.
If you enable
💓 3. Heartbeat Timers: Faster Isn't Always Better
Configuring heartbeat parameters in FortiOS:
Plaintext
💡 Pro Tip: Aggressive detection timers reduce failover time, but they dramatically increase the risk of false positives caused by temporary CPU spikes or transient switchport delays. Balance speed with cluster stability.
🛠 4. Independent Management (Reserved Management Interfaces)
Managing cluster members via a shared Virtual MAC can lead to routing headaches during troubleshooting.
Always design with Reserved Management Interfaces (
Assigns a dedicated, static IP and gateway to each individual FortiGate unit.
Allows out-of-band access for SSH, HTTPS, SNMP, Syslog, and FortiAnalyzer logging.
Ensures reachability even during failover events (especially when tuning
💬 Discussion:
Do you run
#Fortinet #FortiGate #NetworkSecurity #HighAvailability #NetworkEngineering #CyberSecurity
Setting up a FortiGate High Availability (HA) cluster is easy, but running it reliably in production requires understanding the underlying mechanics.
Here is a breakdown of the critical architecture rules every network engineer needs to master:
⚡️ 1. Decouple the Core HA Concepts
Don't treat HA as a single monolithic process. Always separate these four distinct stages during design and troubleshooting:
Heartbeat: Continuous health checks between peer units.
Failure Detection: Deciding when a peer or monitored interface is actually down.
Election: The logic engine determining which unit becomes Primary.
Session Synchronization: Keeping active stateful connections alive across role shifts.
👑 2. The Primary Selection & Override Trap
Consider this standard configuration:
FGT-1 $\rightarrow$ Priority 200FGT-2 $\rightarrow$ Priority 100Enabling Override forces
Priority to rank above Uptime during master election.⚠️ The Critical Gotcha:
HA Override and Device Priority are NOT synchronized between cluster members.
Fortinet explicitly places these under non-synchronized configurations.
If you enable
override on one unit, you must manually set it on the peer. Failing to do so creates severe, unpredictable election behavior after a failover.💓 3. Heartbeat Timers: Faster Isn't Always Better
Configuring heartbeat parameters in FortiOS:
Plaintext
config system ha
set hb-interval 2
set hb-interval-in-milliseconds 100ms
set hb-lost-threshold 20
end
💡 Pro Tip: Aggressive detection timers reduce failover time, but they dramatically increase the risk of false positives caused by temporary CPU spikes or transient switchport delays. Balance speed with cluster stability.
🛠 4. Independent Management (Reserved Management Interfaces)
Managing cluster members via a shared Virtual MAC can lead to routing headaches during troubleshooting.
Always design with Reserved Management Interfaces (
ha-mgmt-interfaces):Assigns a dedicated, static IP and gateway to each individual FortiGate unit.
Allows out-of-band access for SSH, HTTPS, SNMP, Syslog, and FortiAnalyzer logging.
Ensures reachability even during failover events (especially when tuning
ha-direct).💬 Discussion:
Do you run
override enable in your enterprise clusters, or do you keep it disabled to avoid preemption flapping? Drop your thoughts below! 👇#Fortinet #FortiGate #NetworkSecurity #HighAvailability #NetworkEngineering #CyberSecurity
🔥2
🔐 SheynShield | FortiGate Cheat Sheets
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه میداشتم.
بعضیهاشون از Documentation میومدن،
بعضیهاشون از Lab،
و خیلیهاشون هم نتیجهی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا اینها فقط برای خودم بمونن؟
از همینجا ایدهی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet
داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی میخونی:
خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟
چرا Failover اتفاق افتاده؟
چرا Session عبور نمیکنه؟
از کجا Troubleshooting رو شروع کنم؟
کدوم Command واقعاً الان به دردم میخوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.
Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."
📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA
🔹 IPSec VPN
🔹 SD-WAN
🔹 Network
🔹 Policy & Objects
🔹 Security Profiles
🔹 Security Fabric
🔹 System
🔹 Troubleshooting
🔹 User Authentication
🔹 FortiGate VM
🔹 Hardware Acceleration
🔹 Logs & Reports
🔹 and more...
و این لیست قرار نیست همینجا تموم بشه.
🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو بهعنوان یک Knowledge Base برای Network & Security Engineering میسازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub
Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube
آموزشهای عمیقتر، Lab و Technical Videos
📸 Instagram
نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram
Notes، منابع، Cheat Sheetها و محتوای تکمیلی
🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
میخوام بهمرور این Knowledge Base رو در حوزههای مختلف گسترش بدم:
Network Engineering
→ Network Security
→ Firewall
→ WAF
→ Load Balancing
→ Network Design
→ Troubleshooting
و Vendorهای مختلف.
من این پروژه رو بیشتر شبیه یک Engineering Notebook میبینم که کمکم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار میکنید، خوشحال میشم این Repository به کارتون بیاد.
⭐ GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield
Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه میداشتم.
بعضیهاشون از Documentation میومدن،
بعضیهاشون از Lab،
و خیلیهاشون هم نتیجهی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا اینها فقط برای خودم بمونن؟
از همینجا ایدهی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet
داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی میخونی:
Configure HA
خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟
چرا Failover اتفاق افتاده؟
چرا Session عبور نمیکنه؟
از کجا Troubleshooting رو شروع کنم؟
کدوم Command واقعاً الان به دردم میخوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.
Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."
📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA
🔹 IPSec VPN
🔹 SD-WAN
🔹 Network
🔹 Policy & Objects
🔹 Security Profiles
🔹 Security Fabric
🔹 System
🔹 Troubleshooting
🔹 User Authentication
🔹 FortiGate VM
🔹 Hardware Acceleration
🔹 Logs & Reports
🔹 and more...
و این لیست قرار نیست همینجا تموم بشه.
🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو بهعنوان یک Knowledge Base برای Network & Security Engineering میسازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub
Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube
آموزشهای عمیقتر، Lab و Technical Videos
نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram
Notes، منابع، Cheat Sheetها و محتوای تکمیلی
🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
میخوام بهمرور این Knowledge Base رو در حوزههای مختلف گسترش بدم:
Network Engineering
→ Network Security
→ Firewall
→ WAF
→ Load Balancing
→ Network Design
→ Troubleshooting
و Vendorهای مختلف.
من این پروژه رو بیشتر شبیه یک Engineering Notebook میبینم که کمکم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار میکنید، خوشحال میشم این Repository به کارتون بیاد.
⭐ GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield
Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
GitHub
sheynshield/Fortinet/FortiGate/CheatSheet at main · Shayan-heydarikhah/sheynshield
A repository for all network and security guys. Contribute to Shayan-heydarikhah/sheynshield development by creating an account on GitHub.
🛡 FortiGate Backup, Restore & Factory Reset
اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
⚠️
🔹 3. YAML Configuration
Backup:
Restore:
⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
🔹 4. Configuration Revision
ایجاد Revision روی Flash:
Restore یک Revision:
Diff vs Revert
💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
Memory:
🔹 7. Custom IPS Signatures
FTP:
TFTP:
اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
🔥 Factory Reset Commands
Reset + Reboot
Reset + Shutdown
Selective / Specific Reset Behavior
⚠️
🧠 NSE Exam Traps
1️⃣ Backup
2️⃣ YAML
3️⃣ Revision
4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
5️⃣ Factory Reset
⚡️ One-Minute CLI Recall
🔥 Golden Rule
FortiOS CLI Quick Reference
Backup • Restore • Configuration Revision • YAML • Logs • IPS Signatures • Certificates • Factory Reset
اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
execute backup config
برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
execute backup full-config
⚠️
config و full-config را یکی در نظر نگیرید.execute backup config
↓
Standard Configuration Backup
execute backup full-config
↓
More Complete Configuration / Recovery Data
🔹 3. YAML Configuration
Backup:
execute backup yaml-config tftp fgt.yml 192.168.254.254
Restore:
execute restore yaml-config tftp fgt.yml 192.168.254.254
⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
#config-version=...
#conf_file_ver=...
#buildno=...
#global_vdom=...
🔹 4. Configuration Revision
ایجاد Revision روی Flash:
execute backup config flash test
Restore یک Revision:
execute restore config flash 2
Diff vs Revert
Diff
↓
Compare Configurations
Revert
↓
Rollback to Previous Configuration
💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
execute backup config management-station
برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
Memory:
execute backup memory alllogs
execute backup memory log
🔹 7. Custom IPS Signatures
FTP:
execute backup ipsuserdefsig ftp
TFTP:
execute backup ipsuserdefsig tftp
اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
execute vpn certificate local export tftp \
fortinet_ca_ssl cer cassl.cer 192.168.254.254
قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
☑️ Configuration Backup
☑️ Full Backup if required
☑️ Certificates
☑️ Custom IPS Signatures
☑️ Required Logs
☑️ FortiOS Version
☑️ Console / OOB Access
☑️ Post-Reset Access Plan
🔥 Factory Reset Commands
Reset + Reboot
execute factoryreset
Reset + Shutdown
execute factoryresetshutdown
Selective / Specific Reset Behavior
execute factoryreset2
⚠️
factoryreset2 را صرفاً بهعنوان یک نام دیگر برای factoryreset حفظ نکنید؛ رفتار و Configuration Areas تحت تأثیر آن متفاوت است و باید با Release موردنظر بررسی شود.🧠 NSE Exam Traps
1️⃣ Backup
config ≠ full-config
2️⃣ YAML
Metadata Headers
↓
DO NOT DELETE
3️⃣ Revision
Diff → Compare
Revert → Rollback
4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
MODEL
+
FORTIOS VERSION
+
VDOM / OPERATION MODE
+
CONFIGURATION COMPATIBILITY
5️⃣ Factory Reset
factoryreset
↓
Reset + Reboot
factoryresetshutdown
↓
Reset + Shutdown
factoryreset2
↓
Different / Selective Reset Behavior
⚡️ One-Minute CLI Recall
# Backup
execute backup config
execute backup full-config
# YAML
execute backup yaml-config tftp fgt.yml 192.168.254.254
execute restore yaml-config tftp fgt.yml 192.168.254.254
# Revision
execute backup config flash test
execute restore config flash 2
# Management
execute backup config management-station
# Logs
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
execute backup memory alllogs
execute backup memory log
# IPS
execute backup ipsuserdefsig ftp
execute backup ipsuserdefsig tftp
# Factory Reset
execute factoryreset
execute factoryresetshutdown
execute factoryreset2
🔥 Golden Rule
Backup Before Change
Revision Before Risk
Verify Before Restore
Diff Before Revert
Factory Reset = Destructive Operation
📚 SheynShield Resources
🎥 YouTube
https://youtube.com/@sheynshield
📚 Telegram
https://t.me/sheynshield
https://linkedin.com/in/shayan-heydarikhah
🐙 GitHub — Technical Knowledge Base
https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #Fortinet #NSE4 #NSE7 #Backup #Restore #Configuration #YAML #FactoryReset #NetworkSecurity #CyberSecurity👍1