SheynShield
23 subscribers
10 photos
4 videos
94 files
20 links
Secure your systems. Integrate smarter.
Multi-vendor engineering expert since 2017.
Download Telegram
SheynShield pinned «Youtube channel https://youtube.com/@sheynshield?si=0-slAn9SQyiLqMv4»
از الان به بعد ویدیو های اموزشی کوتاه میره تو کانال یوتوب

این ویدیو هم که لینکشو گذاشتم درباره tcp connection هست و برای تانلینگ ترافیک از سرور به کلاینت هم ویدیو جدا داریم که بعدا اشتراک میزارم.

https://youtu.be/pbBPZmj5fnw

#sheynshield
#RSA

کلمه نام آشناییه، شاید تصور ما از انتقال ایمن و ارتباط دنیای اینترنتو ساخته ولی ماجرا عمیق تر ازین چیزاست.
با من همراه باشید این قسمت شاید به کارتون بیاد.
به قول یه بنده خدای باید ببینیم چه خواهد شد.

#tls #https #server #web #tcp #prf #cipher #cyber #client #cache #encryption


https://lnkd.in/ePjzCHSG

https://youtu.be/xPTDRzbL2V0
خیلی پیش میاد توی سازمان هدف ما بستن یک نرم افزار خاص و مشخص باشه ولی درست پیاده سازی کردن این فیلتر یا محدود سازی مهمتر از هر چیز دیگه ای هست . این ویدیو به ما نشون میده چجوری جلوی اجرای VPN داخل سازمان بگیریم.

#FortiGate #Fortinet #VPN #Firewall #Cybersecurity #NSE4 #NSE7 #DPI #SSLInspection #ApplicationControl #WebFiltering #InfoSec #SheynShield

https://youtu.be/38FlleQ7kac

https://www.instagram.com/sheynshield?igsh=MW5wYXB5dHdndjFxZw==
#ja3 #ja4 #ja4plus

شاید تحلیل بسته های شبکه سخت باشه ولی وقتی عمیق تر بهشون نگاه میکنیم متوجه تمام ابعاد تعامل اصولی سطح #network بشیم. اینجا قرار ببینیم این دوتا عنوان چه کمکی میکنن به ما و چجوری میتونن نرم افزارهای مارو ایمن نگه دارن.
# Legacy JA3 Format (Unsorted parameters - MD5 Hash)
Parameters: 771,4865-4866-4867-49195-49199,0-23-65281-10-11-35-16,29-23-24,0
JA3 Hash : 66918128f1b9b00714861676d123d244

# Modern JA4 Format (Human-Readable + Sorted Hash)
Format : [Protocol][TLS Ver][SNI][Ciphers][Extensions][ALPN]_[Cipher Hash]_[Extension Hash]
JA4 String: t13d151600_8daaf6152771_e8a159930c27

https://youtu.be/a8q8hFDOS38

#Cybersecurity #TLS #SSL #JA3 #JA4 #JA4Plus #TLSFingerprinting #NetworkSecurity #ThreatHunting #InfoSec #MalwareAnalysis #Wireshark #Zeek #Suricata #SOCAnalyst #BlueTeam #NetworkTrafficAnalysis #EncryptedTraffic #Cryptography #CobaltStrike #C2Detection #WAF #NGFW #Fortinet #PaloAlto #NetworkEngineering #CompTIA #NetworkPlus #N10009 #SecurityPlus #SY0701 #CCNA #CISSP #SheynShield
🛡 SheynShield Quick Tech Notes: Fortinet Security Fabric & OT Integration (NSE 7)

📌 AUTOMATION & DIAGNOSTICS
• Best Practice: Use sequential mode for restoring .pkg signature files & offline license tasks.
• Max Stitches Tuning:
config system automation setting
set max-concurrent-stitches 128
end

• CLI Diagnostics:
diagnose test application autod
diagnose debug application autod -1
diagnose debug enable

----------------------------------------

📌 DYNAMIC THREAT FEEDS (STIX/TAXII)
• Max File Size: 10 MB (FGT-100F) up to 500 MB (FGT-200F)

• Max Entries: 131,072 entries

• Limits: 512 Global / 256 per VDOM (Verify: print tablesize)

• Syntax Rules:
- Wildcards: *.google.com
- IPv4/IPv6 Ranges: CIDR notation (No brackets for IPs)
- IPv6 URLs: Must use brackets -> http://[2001:db8::1]/ip.txt

• CLI Check:
diagnose firewall dynamic list

----------------------------------------

📌 PURDUE OT MODEL (IEC 62443)
• Level 0: Physical Processes (Sensors/Actuators)

• Level 1: Basic Control (PLCs/RTUs)

• Level 2: Supervisory Control (SCADA/HMIs) -> FortiGate & FortiSwitch

• Level 3: Manufacturing Operations (MES/Historians)

• DMZ & Level 4: Enterprise Network (NGFW / IPS / SIEM)

• Change Purdue Level Memory Settings:
diagnose user-device-store device memory ot-prudue-set max ip level <level>

----------------------------------------

🔗 Full Video Tutorials & Labs on YouTube:
youtube.com/@sheynshield

#Fortinet #NSE7 #SecurityFabric #OTSecurity #CyberSecurity #SheynShield
👍1
🔥 FortiGate HA: What You MUST Know Before Hitting Production
Setting up a FortiGate High Availability (HA) cluster is easy, but running it reliably in production requires understanding the underlying mechanics.

Here is a breakdown of the critical architecture rules every network engineer needs to master:
⚡️ 1. Decouple the Core HA Concepts
Don't treat HA as a single monolithic process. Always separate these four distinct stages during design and troubleshooting:
Heartbeat: Continuous health checks between peer units.
Failure Detection: Deciding when a peer or monitored interface is actually down.

Election: The logic engine determining which unit becomes Primary.
Session Synchronization: Keeping active stateful connections alive across role shifts.

👑 2. The Primary Selection & Override Trap
Consider this standard configuration:
FGT-1 $\rightarrow$ Priority 200
FGT-2 $\rightarrow$ Priority 100
Enabling Override forces Priority to rank above Uptime during master election.

⚠️ The Critical Gotcha:
HA Override and Device Priority are NOT synchronized between cluster members.
Fortinet explicitly places these under non-synchronized configurations.

If you enable override on one unit, you must manually set it on the peer. Failing to do so creates severe, unpredictable election behavior after a failover.

💓 3. Heartbeat Timers: Faster Isn't Always Better
Configuring heartbeat parameters in FortiOS:
Plaintext
config system ha
set hb-interval 2
set hb-interval-in-milliseconds 100ms
set hb-lost-threshold 20
end

💡 Pro Tip: Aggressive detection timers reduce failover time, but they dramatically increase the risk of false positives caused by temporary CPU spikes or transient switchport delays. Balance speed with cluster stability.

🛠 4. Independent Management (Reserved Management Interfaces)
Managing cluster members via a shared Virtual MAC can lead to routing headaches during troubleshooting.

Always design with Reserved Management Interfaces (ha-mgmt-interfaces):
Assigns a dedicated, static IP and gateway to each individual FortiGate unit.

Allows out-of-band access for SSH, HTTPS, SNMP, Syslog, and FortiAnalyzer logging.

Ensures reachability even during failover events (especially when tuning ha-direct).



💬 Discussion:
Do you run override enable in your enterprise clusters, or do you keep it disabled to avoid preemption flapping? Drop your thoughts below! 👇

#Fortinet #FortiGate #NetworkSecurity #HighAvailability #NetworkEngineering #CyberSecurity
🔥2
🔐 SheynShield | FortiGate Cheat Sheets
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه می‌داشتم.
بعضی‌هاشون از Documentation میومدن،

بعضی‌هاشون از Lab،

و خیلی‌هاشون هم نتیجه‌ی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا این‌ها فقط برای خودم بمونن؟
از همین‌جا ایده‌ی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet

داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی می‌خونی:
Configure HA

خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟

چرا Failover اتفاق افتاده؟

چرا Session عبور نمی‌کنه؟

از کجا Troubleshooting رو شروع کنم؟

کدوم Command واقعاً الان به دردم می‌خوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.

Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."

📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA

🔹 IPSec VPN

🔹 SD-WAN

🔹 Network

🔹 Policy & Objects

🔹 Security Profiles

🔹 Security Fabric

🔹 System

🔹 Troubleshooting

🔹 User Authentication

🔹 FortiGate VM

🔹 Hardware Acceleration

🔹 Logs & Reports

🔹 and more...
و این لیست قرار نیست همین‌جا تموم بشه.

🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو به‌عنوان یک Knowledge Base برای Network & Security Engineering می‌سازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub

Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube

آموزش‌های عمیق‌تر، Lab و Technical Videos
📸 Instagram

نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram

Notes، منابع، Cheat Sheetها و محتوای تکمیلی

🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
می‌خوام به‌مرور این Knowledge Base رو در حوزه‌های مختلف گسترش بدم:
Network Engineering

Network Security

Firewall

WAF

Load Balancing

Network Design

Troubleshooting
و Vendorهای مختلف.

من این پروژه رو بیشتر شبیه یک Engineering Notebook می‌بینم که کم‌کم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار می‌کنید، خوشحال میشم این Repository به کارتون بیاد.
GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield

Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
🛡 FortiGate Backup, Restore & Factory Reset
FortiOS CLI Quick Reference
Backup • Restore • Configuration Revision • YAML • Logs • IPS Signatures • Certificates • Factory Reset

اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
execute backup config

برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
execute backup full-config

⚠️ config و full-config را یکی در نظر نگیرید.
execute backup config

Standard Configuration Backup

execute backup full-config

More Complete Configuration / Recovery Data

🔹 3. YAML Configuration
Backup:
execute backup yaml-config tftp fgt.yml 192.168.254.254

Restore:
execute restore yaml-config tftp fgt.yml 192.168.254.254

⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
#config-version=...
#conf_file_ver=...
#buildno=...
#global_vdom=...

🔹 4. Configuration Revision
ایجاد Revision روی Flash:
execute backup config flash test

Restore یک Revision:
execute restore config flash 2

Diff vs Revert
Diff

Compare Configurations

Revert

Rollback to Previous Configuration

💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
execute backup config management-station

برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log

Memory:
execute backup memory alllogs
execute backup memory log

🔹 7. Custom IPS Signatures
FTP:
execute backup ipsuserdefsig ftp

TFTP:
execute backup ipsuserdefsig tftp

اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
execute vpn certificate local export tftp \
fortinet_ca_ssl cer cassl.cer 192.168.254.254

قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
☑️ Configuration Backup
☑️ Full Backup if required
☑️ Certificates
☑️ Custom IPS Signatures
☑️ Required Logs
☑️ FortiOS Version
☑️ Console / OOB Access
☑️ Post-Reset Access Plan

🔥 Factory Reset Commands
Reset + Reboot
execute factoryreset

Reset + Shutdown
execute factoryresetshutdown

Selective / Specific Reset Behavior
execute factoryreset2

⚠️ factoryreset2 را صرفاً به‌عنوان یک نام دیگر برای factoryreset حفظ نکنید؛ رفتار و Configuration Areas تحت تأثیر آن متفاوت است و باید با Release موردنظر بررسی شود.
🧠 NSE Exam Traps
1️⃣ Backup
config ≠ full-config

2️⃣ YAML
Metadata Headers

DO NOT DELETE

3️⃣ Revision
Diff   → Compare
Revert → Rollback

4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
MODEL
+
FORTIOS VERSION
+
VDOM / OPERATION MODE
+
CONFIGURATION COMPATIBILITY

5️⃣ Factory Reset
factoryreset

Reset + Reboot

factoryresetshutdown

Reset + Shutdown

factoryreset2

Different / Selective Reset Behavior

⚡️ One-Minute CLI Recall
# Backup
execute backup config
execute backup full-config

# YAML
execute backup yaml-config tftp fgt.yml 192.168.254.254
execute restore yaml-config tftp fgt.yml 192.168.254.254

# Revision
execute backup config flash test
execute restore config flash 2

# Management
execute backup config management-station

# Logs
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
execute backup memory alllogs
execute backup memory log

# IPS
execute backup ipsuserdefsig ftp
execute backup ipsuserdefsig tftp

# Factory Reset
execute factoryreset
execute factoryresetshutdown
execute factoryreset2

🔥 Golden Rule
Backup Before Change
Revision Before Risk
Verify Before Restore
Diff Before Revert
Factory Reset = Destructive Operation

📚 SheynShield Resources
🎥 YouTube
https://youtube.com/@sheynshield
📚 Telegram
https://t.me/sheynshield
💼 LinkedIn
https://linkedin.com/in/shayan-heydarikhah
🐙 GitHub — Technical Knowledge Base
https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #Fortinet #NSE4 #NSE7 #Backup #Restore #Configuration #YAML #FactoryReset #NetworkSecurity #CyberSecurity
👍1