SheynShield
55 subscribers
11 photos
4 videos
94 files
24 links
Secure your systems. Integrate smarter.
Multi-vendor engineering expert since 2017.
Download Telegram
🔐 SheynShield | FortiGate Cheat Sheets
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه می‌داشتم.
بعضی‌هاشون از Documentation میومدن،

بعضی‌هاشون از Lab،

و خیلی‌هاشون هم نتیجه‌ی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا این‌ها فقط برای خودم بمونن؟
از همین‌جا ایده‌ی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet

داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی می‌خونی:
Configure HA

خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟

چرا Failover اتفاق افتاده؟

چرا Session عبور نمی‌کنه؟

از کجا Troubleshooting رو شروع کنم؟

کدوم Command واقعاً الان به دردم می‌خوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.

Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."

📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA

🔹 IPSec VPN

🔹 SD-WAN

🔹 Network

🔹 Policy & Objects

🔹 Security Profiles

🔹 Security Fabric

🔹 System

🔹 Troubleshooting

🔹 User Authentication

🔹 FortiGate VM

🔹 Hardware Acceleration

🔹 Logs & Reports

🔹 and more...
و این لیست قرار نیست همین‌جا تموم بشه.

🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو به‌عنوان یک Knowledge Base برای Network & Security Engineering می‌سازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub

Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube

آموزش‌های عمیق‌تر، Lab و Technical Videos
📸 Instagram

نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram

Notes، منابع، Cheat Sheetها و محتوای تکمیلی

🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
می‌خوام به‌مرور این Knowledge Base رو در حوزه‌های مختلف گسترش بدم:
Network Engineering

→ Network Security

→ Firewall

→ WAF

→ Load Balancing

→ Network Design

→ Troubleshooting
و Vendorهای مختلف.

من این پروژه رو بیشتر شبیه یک Engineering Notebook می‌بینم که کم‌کم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار می‌کنید، خوشحال میشم این Repository به کارتون بیاد.
⭐ GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield

Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
❤1
🛡 FortiGate Backup, Restore & Factory Reset
FortiOS CLI Quick Reference
Backup • Restore • Configuration Revision • YAML • Logs • IPS Signatures • Certificates • Factory Reset

اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
execute backup config

برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
execute backup full-config

⚠️ config و full-config را یکی در نظر نگیرید.
execute backup config
↓
Standard Configuration Backup

execute backup full-config
↓
More Complete Configuration / Recovery Data

🔹 3. YAML Configuration
Backup:
execute backup yaml-config tftp fgt.yml 192.168.254.254

Restore:
execute restore yaml-config tftp fgt.yml 192.168.254.254

⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
#config-version=...
#conf_file_ver=...
#buildno=...
#global_vdom=...

🔹 4. Configuration Revision
ایجاد Revision روی Flash:
execute backup config flash test

Restore یک Revision:
execute restore config flash 2

Diff vs Revert
Diff
↓
Compare Configurations

Revert
↓
Rollback to Previous Configuration

💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
execute backup config management-station

برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log

Memory:
execute backup memory alllogs
execute backup memory log

🔹 7. Custom IPS Signatures
FTP:
execute backup ipsuserdefsig ftp

TFTP:
execute backup ipsuserdefsig tftp

اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
execute vpn certificate local export tftp \
fortinet_ca_ssl cer cassl.cer 192.168.254.254

قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
☑️ Configuration Backup
☑️ Full Backup if required
☑️ Certificates
☑️ Custom IPS Signatures
☑️ Required Logs
☑️ FortiOS Version
☑️ Console / OOB Access
☑️ Post-Reset Access Plan

🔥 Factory Reset Commands
Reset + Reboot
execute factoryreset

Reset + Shutdown
execute factoryresetshutdown

Selective / Specific Reset Behavior
execute factoryreset2

⚠️ factoryreset2 را صرفاً به‌عنوان یک نام دیگر برای factoryreset حفظ نکنید؛ رفتار و Configuration Areas تحت تأثیر آن متفاوت است و باید با Release موردنظر بررسی شود.
🧠 NSE Exam Traps
1️⃣ Backup
config ≠ full-config

2️⃣ YAML
Metadata Headers
↓
DO NOT DELETE

3️⃣ Revision
Diff   → Compare
Revert → Rollback

4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
MODEL
+
FORTIOS VERSION
+
VDOM / OPERATION MODE
+
CONFIGURATION COMPATIBILITY

5️⃣ Factory Reset
factoryreset
↓
Reset + Reboot

factoryresetshutdown
↓
Reset + Shutdown

factoryreset2
↓
Different / Selective Reset Behavior

⚡️ One-Minute CLI Recall
# Backup
execute backup config
execute backup full-config

# YAML
execute backup yaml-config tftp fgt.yml 192.168.254.254
execute restore yaml-config tftp fgt.yml 192.168.254.254

# Revision
execute backup config flash test
execute restore config flash 2

# Management
execute backup config management-station

# Logs
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
execute backup memory alllogs
execute backup memory log

# IPS
execute backup ipsuserdefsig ftp
execute backup ipsuserdefsig tftp

# Factory Reset
execute factoryreset
execute factoryresetshutdown
execute factoryreset2

🔥 Golden Rule
Backup Before Change
Revision Before Risk
Verify Before Restore
Diff Before Revert
Factory Reset = Destructive Operation

📚 SheynShield Resources
🎥 YouTube
https://youtube.com/@sheynshield
📚 Telegram
https://t.me/sheynshield
💼 LinkedIn
https://linkedin.com/in/shayan-heydarikhah
🐙 GitHub — Technical Knowledge Base
https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #Fortinet #NSE4 #NSE7 #Backup #Restore #Configuration #YAML #FactoryReset #NetworkSecurity #CyberSecurity
👍1
جلسه رفع اشکال دوره های فورتینت
Anonymous Poll
6%
چهارشنبه ساعت ۶ عصر
94%
پنجشنبه ساعت ۱۱ ظهر
🛡️ SheynShield | Engineering Secure Networks

اگر در حوزه Network، Network Security، Cybersecurity یا Enterprise Infrastructure فعالیت می‌کنید، SheynShield را برای همین ساخته‌ام:

یک Knowledge Base فنی و عملی برای یادگیری، طراحی، پیاده‌سازی، Troubleshooting و Security در محیط‌های واقعی Enterprise.

🔐 موضوعات اصلی:
• Fortinet / FortiGate / FortiOS / FortiWeb
• Cisco / Firepower / FTD / ISE
• F5 BIG-IP / LTM
• Palo Alto / Juniper
• Firewall & NGFW
• WAF / Web Security
• Routing & Switching
• BGP / OSPF / MPLS
• SD-WAN / VXLAN / EVPN
• Network Automation & Infrastructure

📚 در GitHub، مطالب به شکل Cheat Sheet، Checklist، Configuration Guide، Technical Notes و Reference منتشر می‌شوند.

🎥 در YouTube، همین مفاهیم به‌صورت ویدیویی و کاربردی تشریح می‌شوند.

🎯 فلسفه SheynShield ساده است:

Concept → Design → Implementation → Verification → Troubleshooting → Security

هدف فقط حفظ کردن Command نیست؛
هدف این است که بفهمیم یک تکنولوژی چرا کار می‌کند، چگونه طراحی و پیاده‌سازی می‌شود، چطور Verify و Troubleshoot می‌شود و چگونه باید آن را Secure کرد.

🔗 GitHub | Knowledge Base
github.com/Shayan-heydarikhah/sheynshield

🎥 YouTube | Technical Videos
youtube.com/@sheynshield

📢 Telegram | Updates & Technical Content
T.me/sheynshield

📸 Instagram | Short-form Technical Content
https://www.instagram.com/sheynshield

💼 LinkedIn | Professional Profile
"LinkedIn
https://www.linkedin.com/in/shayan-heydarikhah

⭐ اگر در مسیر Network Engineering → Network Security → Security Architecture هستید، خوشحال می‌شوم SheynShield را دنبال کنید.

SheynShield
Understand the technology. Build the architecture. Secure the network.
❤1
🛡 FortiGate Licensing & FortiGuard Updates
FortiOS • FortiGuard • Licensing • Security Updates • Troubleshooting

یکی از اشتباهات رایج در FortiGate این است که License، FortiOS و FortiGuard را یک مفهوم در نظر بگیریم.
بیایید مرز بین این‌ها را روشن کنیم. 👇
🧠 1. FortiOS ≠ FortiGuard
FORTIGATE
│
├── FORTIOS
│ ├── Firewall
│ ├── Routing
│ ├── NAT
│ ├── VPN
│ ├── HA
│ └── SD-WAN
│
└── FORTIGUARD
├── AV Intelligence
├── IPS Signatures
├── Application Data
├── Web Filtering
├── Anti-Spam
└── Threat Intelligence

🔥 بنابراین:
FortiGuard License Expired
≠
FortiGate Shutdown

و:
Firmware Upgrade
≠
FortiGuard Signature Update

🔐 2. License چه چیزی را کنترل می‌کند؟
قبل از Troubleshooting بررسی کنید:
☑️ Device Registration
☑️ Subscription Status
☑️ Service Entitlement
☑️ Bundle / SKU
☑️ Expiration Date
☑️ Required FortiGuard Services
اما:
Valid License
≠
Guaranteed Connectivity

🌐 3. FortiGuard Update چگونه کار می‌کند؟
File-Based
معمولاً برای مواردی مانند:
AV
IPS
Application Control

مدل ذهنی:
FortiGate
↓
Download
↓
Database / Signature

Query-Based
برای سرویس‌هایی مانند:
Web Filtering
Anti-Spam
Reputation

مدل ذهنی:
FortiGate
↓
Query
↓
FortiGuard
↓
Classification / Reputation

💡 Memory Trick:
AV / IPS / Application
↓
UPDATE

Web Filter / Anti-Spam
↓
QUERY

🚨 4. وقتی FortiGuard Update Fail می‌شود
اشتباه رایج:
«FortiGuard کار نمی‌کند، پس License مشکل دارد.»

در واقع باید Dependency Chain را Trace کنیم:
License
↓
DNS
↓
Routing
↓
NAT
↓
Firewall Policy
↓
Required Port
↓
Proxy
↓
TLS / System Time
↓
FortiGuard
↓
Specific Service
↓
Logs

🔥 این دقیقاً همان Mindset موردنیاز Troubleshooting در سطح NSE7 است:
Don't Guess → Trace Dependencies

🔎 5. DNS را فراموش نکنید
FortiGate
↓
DNS Query
↓
FortiGuard FQDN
↓
IP Resolution
↓
Connection

بنابراین:
DNS Failure
↓
FQDN Resolution Failure
↓
Possible FortiGuard Failure

⏰ 6. System Time
زمان اشتباه می‌تواند باعث مشکل در TLS/Certificate Validation شود:
Wrong Time
↓
TLS / Certificate Validation
↓
Possible FortiGuard Failure

پس NTP را هم بررسی کنید.
📴 7. Online vs Offline Update
Online
FortiGate
↓
Internet
↓
FortiGuard
↓
Update

Offline
Connected System
↓
Download Package
↓
Secure Transfer
↓
Isolated FortiGate
↓
Install
↓
Verify

Offline Update برای محیط‌هایی مثل:
☑️ Air-Gapped
☑️ Isolated Lab
☑️ Restricted Network
کاربرد مهمی دارد.
🔄 8. FortiGuard Through Proxy / Tunnel
در شبکه‌های محدود:
FortiGate
↓
Proxy / Relay
↓
Internet
↓
FortiGuard

در Troubleshooting بررسی کنید:
☑️ Proxy Address
☑️ Port
☑️ Authentication
☑️ DNS
☑️ TLS
☑️ FortiGuard Connectivity
🚀 9. Firmware Upgrade
این دو را کاملاً جدا کنید:
FortiOS Upgrade
≠
FortiGuard Update

قبل از Upgrade:
☑️ Current Version
☑️ Target Version
☑️ Supported Upgrade Path
☑️ Release Notes
☑️ Known Issues
☑️ Hardware Compatibility
☑️ HA/VPN/SD-WAN Impact
☑️ Configuration Backup
☑️ Rollback Plan
☑️ Maintenance Window
❌ این منطق اشتباه است:
New Version
↓
Upgrade Immediately

✅ منطق درست:
Current
↓
Target
↓
Upgrade Path
↓
Release Notes
↓
Known Issues
↓
Compatibility
↓
Backup
↓
Upgrade
↓
Validation

🧠 NSE Exam Traps
Trap 1
License Expired
≠
FortiGate Shutdown

Trap 2
Firmware Update
≠
Signature Update

Trap 3
Internet Works
≠
FortiGuard Works

Trap 4
Valid License
≠
Guaranteed Connectivity

Trap 5
FortiGuard Failure
≠
Always License Failure

Trap 6
Wrong System Time
↓
Possible TLS Failure

⚡️ 60-Second FortiGuard Troubleshooting
اگر فقط یک Flow بخواهید حفظ کنید:
LICENSE
↓
DNS
↓
ROUTE
↓
NAT
↓
POLICY
↓
PORT
↓
PROXY
↓
TLS / TIME
↓
FORTIGUARD
↓
SPECIFIC SERVICE
↓
LOGS

🔥 Golden Rule:
❤1
FortiGuard Failure → Don't Guess. Identify the Failure Domain.

📚 SheynShield | Engineering Secure Networks
🎥 YouTube: https://youtube.com/@sheynshield
📚 Telegram: https://t.me/sheynshield
🐙 GitHub: https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #FortiGuard #Fortinet #NSE4 #NSE7 #Troubleshooting #NetworkSecurity
اینجا قراره طی ۶ ماه با هم وارد دنیای واقعی IT بشیم؛
از Network و Infrastructure شروع می‌کنیم و می‌رسیم به:
🌐 Network & Infrastructure
🛡️ Security & Firewall
🐳 DevOps & Automation
☁️ Cloud & Virtualization
💻 Linux & Programming
🤖 AI & AI Infrastructure
🔧 Troubleshooting & Real-World Scenarios
اینجا قرار نیست فقط تئوری یاد بگیریم؛
یاد می‌گیریم، می‌سازیم، خراب می‌کنیم، عیب‌یابی می‌کنیم و دوباره می‌سازیم.
🎯 هدف NBC اینه که بعد از این ۶ ماه، فقط اطلاعات بیشتری نداشته باشیم؛
بلکه بهتر فکر کنیم، بهتر حل مسئله کنیم و واقعاً مهارت بسازیم.

Learn • Build • Secure • Automate 🚀

آدرس گروه :
@networkbiteclub