🔐 SheynShield | FortiGate Cheat Sheets
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه میداشتم.
بعضیهاشون از Documentation میومدن،
بعضیهاشون از Lab،
و خیلیهاشون هم نتیجهی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا اینها فقط برای خودم بمونن؟
از همینجا ایدهی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet
داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی میخونی:
خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟
چرا Failover اتفاق افتاده؟
چرا Session عبور نمیکنه؟
از کجا Troubleshooting رو شروع کنم؟
کدوم Command واقعاً الان به دردم میخوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.
Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."
📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA
🔹 IPSec VPN
🔹 SD-WAN
🔹 Network
🔹 Policy & Objects
🔹 Security Profiles
🔹 Security Fabric
🔹 System
🔹 Troubleshooting
🔹 User Authentication
🔹 FortiGate VM
🔹 Hardware Acceleration
🔹 Logs & Reports
🔹 and more...
و این لیست قرار نیست همینجا تموم بشه.
🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو بهعنوان یک Knowledge Base برای Network & Security Engineering میسازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub
Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube
آموزشهای عمیقتر، Lab و Technical Videos
📸 Instagram
نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram
Notes، منابع، Cheat Sheetها و محتوای تکمیلی
🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
میخوام بهمرور این Knowledge Base رو در حوزههای مختلف گسترش بدم:
Network Engineering
→ Network Security
→ Firewall
→ WAF
→ Load Balancing
→ Network Design
→ Troubleshooting
و Vendorهای مختلف.
من این پروژه رو بیشتر شبیه یک Engineering Notebook میبینم که کمکم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار میکنید، خوشحال میشم این Repository به کارتون بیاد.
⭐ GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield
Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
یه مدت بود که همیشه موقع کار با FortiGate، یه سری Note، Command، نکته و تجربه برای خودم نگه میداشتم.
بعضیهاشون از Documentation میومدن،
بعضیهاشون از Lab،
و خیلیهاشون هم نتیجهی کار واقعی و Troubleshooting بودن.
بعد به این فکر کردم که چرا اینها فقط برای خودم بمونن؟
از همینجا ایدهی SheynShield FortiGate Cheat Sheets شکل گرفت.
🔗 GitHub:
https://github.com/Shayan-heydarikhah/sheynshield/tree/main/Fortinet/FortiGate/CheatSheet
داستانش چیه؟
من همیشه احساس کردم بین یادگیری FortiGate و کار واقعی با FortiGate یه فاصله وجود داره.
وقتی میخونی:
Configure HA
خب... خیلی خوب.
ولی وقتی واقعاً روی یک Firewall Production هستی و باید بفهمی:
چرا این Device Master شده؟
چرا Failover اتفاق افتاده؟
چرا Session عبور نمیکنه؟
از کجا Troubleshooting رو شروع کنم؟
کدوم Command واقعاً الان به دردم میخوره؟
اونجاست که داشتن یک Reference سریع و کاربردی خیلی ارزشمند میشه.
برای همین سعی کردم Noteهایی که خودم در مسیر Network & Security جمع کردم رو تبدیل کنم به Cheat Sheetهایی که واقعاً موقع کار هم بشه بهشون رجوع کرد.
Why did I create it?
The idea behind the SheynShield FortiGate Cheat Sheets is pretty simple.
Over the years, I collected a lot of:
CLI commands
configuration notes
troubleshooting steps
design considerations
lab experiences
and practical FortiGate tips
Some came from documentation.
Some came from labs.
And some came from real-world troubleshooting.
I didn't want them to stay as personal notes.
So I started turning them into practical, structured and easy-to-use FortiGate references.
The goal isn't just:
"Here is a command."
The goal is:
"Here is what you need to know when you actually have to work with it."
📚 What's inside?
The FortiGate Cheat Sheets are being organized around real topics such as:
🔹 HA
🔹 IPSec VPN
🔹 SD-WAN
🔹 Network
🔹 Policy & Objects
🔹 Security Profiles
🔹 Security Fabric
🔹 System
🔹 Troubleshooting
🔹 User Authentication
🔹 FortiGate VM
🔹 Hardware Acceleration
🔹 Logs & Reports
🔹 and more...
و این لیست قرار نیست همینجا تموم بشه.
🌐 SheynShield
در واقع این GitHub فقط یک Repository نیست.
دارم SheynShield رو بهعنوان یک Knowledge Base برای Network & Security Engineering میسازم.
هر پلتفرم هم نقش خودش رو داره:
💻 GitHub
Cheat Sheets, Checklists, Technical Notes & References
🎥 YouTube
آموزشهای عمیقتر، Lab و Technical Videos
نکات کوتاه، Technical Content و محتوای سریع
💬 Telegram
Notes، منابع، Cheat Sheetها و محتوای تکمیلی
🚀 هدف نهایی؟
فعلاً تمرکز اصلی روی Fortinet / FortiGate هست.
ولی هدف SheynShield فقط FortiGate نیست.
میخوام بهمرور این Knowledge Base رو در حوزههای مختلف گسترش بدم:
Network Engineering
→ Network Security
→ Firewall
→ WAF
→ Load Balancing
→ Network Design
→ Troubleshooting
و Vendorهای مختلف.
من این پروژه رو بیشتر شبیه یک Engineering Notebook میبینم که کمکم داره تبدیل به یک Knowledge Base عمومی میشه.
اگر شما هم با FortiGate و Network Security کار میکنید، خوشحال میشم این Repository به کارتون بیاد.
⭐ GitHub:
https://github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube:
https://www.youtube.com/@sheynshield
📸 Instagram:
https://www.instagram.com/sheynshield
💬 Telegram:
https://t.me/sheynshield
Learn it. Build it. Troubleshoot it. Document it.
🔐 SheynShield | Engineering Secure Networks
GitHub
sheynshield/Fortinet/FortiGate/CheatSheet at main · Shayan-heydarikhah/sheynshield
A repository for all network and security guys. Contribute to Shayan-heydarikhah/sheynshield development by creating an account on GitHub.
❤1
🛡 FortiGate Backup, Restore & Factory Reset
اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
⚠️
🔹 3. YAML Configuration
Backup:
Restore:
⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
🔹 4. Configuration Revision
ایجاد Revision روی Flash:
Restore یک Revision:
Diff vs Revert
💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
Memory:
🔹 7. Custom IPS Signatures
FTP:
TFTP:
اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
🔥 Factory Reset Commands
Reset + Reboot
Reset + Shutdown
Selective / Specific Reset Behavior
⚠️
🧠 NSE Exam Traps
1️⃣ Backup
2️⃣ YAML
3️⃣ Revision
4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
5️⃣ Factory Reset
⚡️ One-Minute CLI Recall
🔥 Golden Rule
FortiOS CLI Quick Reference
Backup • Restore • Configuration Revision • YAML • Logs • IPS Signatures • Certificates • Factory Reset
اگر قبل از یک تغییر مهم روی FortiGate دنبال یک Recovery Point هستید، این Commandها و نکات را حتماً داشته باشید. 👇
🔹 1. Standard Configuration Backup
execute backup config
برای گرفتن Backup معمولی از Configuration.
🔹 2. Full Configuration Backup
execute backup full-config
⚠️
config و full-config را یکی در نظر نگیرید.execute backup config
↓
Standard Configuration Backup
execute backup full-config
↓
More Complete Configuration / Recovery Data
🔹 3. YAML Configuration
Backup:
execute backup yaml-config tftp fgt.yml 192.168.254.254
Restore:
execute restore yaml-config tftp fgt.yml 192.168.254.254
⚠️ هنگام کار با YAML، Configuration Metadata Headers را حذف نکنید.
#config-version=...
#conf_file_ver=...
#buildno=...
#global_vdom=...
🔹 4. Configuration Revision
ایجاد Revision روی Flash:
execute backup config flash test
Restore یک Revision:
execute restore config flash 2
Diff vs Revert
Diff
↓
Compare Configurations
Revert
↓
Rollback to Previous Configuration
💡 Diff قبل از Revert یک Rule بسیار مهم برای عملیات واقعی است.
🔹 5. Central Management Backup
execute backup config management-station
برای Backup Configuration به Management Station در سناریوهای Central Management.
🔹 6. Log Backup
Disk:
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
Memory:
execute backup memory alllogs
execute backup memory log
🔹 7. Custom IPS Signatures
FTP:
execute backup ipsuserdefsig ftp
TFTP:
execute backup ipsuserdefsig tftp
اگر Custom IPS Signature دارید، آن را بخشی از مجموعه Recovery خود در نظر بگیرید.
🔹 8. Certificate Export
Example:
execute vpn certificate local export tftp \
fortinet_ca_ssl cer cassl.cer 192.168.254.254
قبل از Reset یا Migration، Certificateهای موردنیاز را فراموش نکنید.
⚠️ Factory Reset
Factory Reset یک عملیات HIGH-RISK / DESTRUCTIVE است.
قبل از اجرای آن:
☑️ Configuration Backup
☑️ Full Backup if required
☑️ Certificates
☑️ Custom IPS Signatures
☑️ Required Logs
☑️ FortiOS Version
☑️ Console / OOB Access
☑️ Post-Reset Access Plan
🔥 Factory Reset Commands
Reset + Reboot
execute factoryreset
Reset + Shutdown
execute factoryresetshutdown
Selective / Specific Reset Behavior
execute factoryreset2
⚠️
factoryreset2 را صرفاً بهعنوان یک نام دیگر برای factoryreset حفظ نکنید؛ رفتار و Configuration Areas تحت تأثیر آن متفاوت است و باید با Release موردنظر بررسی شود.🧠 NSE Exam Traps
1️⃣ Backup
config ≠ full-config
2️⃣ YAML
Metadata Headers
↓
DO NOT DELETE
3️⃣ Revision
Diff → Compare
Revert → Rollback
4️⃣ Restore
قبل از Restore Configuration بررسی کنید:
MODEL
+
FORTIOS VERSION
+
VDOM / OPERATION MODE
+
CONFIGURATION COMPATIBILITY
5️⃣ Factory Reset
factoryreset
↓
Reset + Reboot
factoryresetshutdown
↓
Reset + Shutdown
factoryreset2
↓
Different / Selective Reset Behavior
⚡️ One-Minute CLI Recall
# Backup
execute backup config
execute backup full-config
# YAML
execute backup yaml-config tftp fgt.yml 192.168.254.254
execute restore yaml-config tftp fgt.yml 192.168.254.254
# Revision
execute backup config flash test
execute restore config flash 2
# Management
execute backup config management-station
# Logs
execute backup disk alllogs
execute backup disk ipsarchive
execute backup disk log
execute backup memory alllogs
execute backup memory log
# IPS
execute backup ipsuserdefsig ftp
execute backup ipsuserdefsig tftp
# Factory Reset
execute factoryreset
execute factoryresetshutdown
execute factoryreset2
🔥 Golden Rule
Backup Before Change
Revision Before Risk
Verify Before Restore
Diff Before Revert
Factory Reset = Destructive Operation
📚 SheynShield Resources
🎥 YouTube
https://youtube.com/@sheynshield
📚 Telegram
https://t.me/sheynshield
https://linkedin.com/in/shayan-heydarikhah
🐙 GitHub — Technical Knowledge Base
https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #Fortinet #NSE4 #NSE7 #Backup #Restore #Configuration #YAML #FactoryReset #NetworkSecurity #CyberSecurity👍1
https://lnkd.in/p/eEVTAj6m
بچه هایی که دنبال کاراموزی و استخدام هستن یه سر بزنن به این پست
بچه هایی که دنبال کاراموزی و استخدام هستن یه سر بزنن به این پست
LinkedIn
#استخدام #کارشناس | Alireza Ghahrood | 11 comments
#استخدام #کارشناس امنیت شبکه
شرکت کمان امن دیاکو بهمنظور توسعه تیم امنیت سایبری خود، از افراد توانمند، مستعد و علاقهمند به فعالیت حرفهای در حوزه امنیت شبکه برای موقعیت شغلی کارشناس مهندسی امنیت شبکه دعوت به همکاری میکند.
-فرد موردنظر در پروژههای راهاندازی،…
شرکت کمان امن دیاکو بهمنظور توسعه تیم امنیت سایبری خود، از افراد توانمند، مستعد و علاقهمند به فعالیت حرفهای در حوزه امنیت شبکه برای موقعیت شغلی کارشناس مهندسی امنیت شبکه دعوت به همکاری میکند.
-فرد موردنظر در پروژههای راهاندازی،…
🛡️ SheynShield | Engineering Secure Networks
اگر در حوزه Network، Network Security، Cybersecurity یا Enterprise Infrastructure فعالیت میکنید، SheynShield را برای همین ساختهام:
یک Knowledge Base فنی و عملی برای یادگیری، طراحی، پیادهسازی، Troubleshooting و Security در محیطهای واقعی Enterprise.
🔐 موضوعات اصلی:
• Fortinet / FortiGate / FortiOS / FortiWeb
• Cisco / Firepower / FTD / ISE
• F5 BIG-IP / LTM
• Palo Alto / Juniper
• Firewall & NGFW
• WAF / Web Security
• Routing & Switching
• BGP / OSPF / MPLS
• SD-WAN / VXLAN / EVPN
• Network Automation & Infrastructure
📚 در GitHub، مطالب به شکل Cheat Sheet، Checklist، Configuration Guide، Technical Notes و Reference منتشر میشوند.
🎥 در YouTube، همین مفاهیم بهصورت ویدیویی و کاربردی تشریح میشوند.
🎯 فلسفه SheynShield ساده است:
Concept → Design → Implementation → Verification → Troubleshooting → Security
هدف فقط حفظ کردن Command نیست؛
هدف این است که بفهمیم یک تکنولوژی چرا کار میکند، چگونه طراحی و پیادهسازی میشود، چطور Verify و Troubleshoot میشود و چگونه باید آن را Secure کرد.
🔗 GitHub | Knowledge Base
github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube | Technical Videos
youtube.com/@sheynshield
📢 Telegram | Updates & Technical Content
T.me/sheynshield
📸 Instagram | Short-form Technical Content
https://www.instagram.com/sheynshield
💼 LinkedIn | Professional Profile
"LinkedIn
https://www.linkedin.com/in/shayan-heydarikhah
⭐ اگر در مسیر Network Engineering → Network Security → Security Architecture هستید، خوشحال میشوم SheynShield را دنبال کنید.
SheynShield
Understand the technology. Build the architecture. Secure the network.
اگر در حوزه Network، Network Security، Cybersecurity یا Enterprise Infrastructure فعالیت میکنید، SheynShield را برای همین ساختهام:
یک Knowledge Base فنی و عملی برای یادگیری، طراحی، پیادهسازی، Troubleshooting و Security در محیطهای واقعی Enterprise.
🔐 موضوعات اصلی:
• Fortinet / FortiGate / FortiOS / FortiWeb
• Cisco / Firepower / FTD / ISE
• F5 BIG-IP / LTM
• Palo Alto / Juniper
• Firewall & NGFW
• WAF / Web Security
• Routing & Switching
• BGP / OSPF / MPLS
• SD-WAN / VXLAN / EVPN
• Network Automation & Infrastructure
📚 در GitHub، مطالب به شکل Cheat Sheet، Checklist، Configuration Guide، Technical Notes و Reference منتشر میشوند.
🎥 در YouTube، همین مفاهیم بهصورت ویدیویی و کاربردی تشریح میشوند.
🎯 فلسفه SheynShield ساده است:
Concept → Design → Implementation → Verification → Troubleshooting → Security
هدف فقط حفظ کردن Command نیست؛
هدف این است که بفهمیم یک تکنولوژی چرا کار میکند، چگونه طراحی و پیادهسازی میشود، چطور Verify و Troubleshoot میشود و چگونه باید آن را Secure کرد.
🔗 GitHub | Knowledge Base
github.com/Shayan-heydarikhah/sheynshield
🎥 YouTube | Technical Videos
youtube.com/@sheynshield
📢 Telegram | Updates & Technical Content
T.me/sheynshield
📸 Instagram | Short-form Technical Content
https://www.instagram.com/sheynshield
💼 LinkedIn | Professional Profile
https://www.linkedin.com/in/shayan-heydarikhah
⭐ اگر در مسیر Network Engineering → Network Security → Security Architecture هستید، خوشحال میشوم SheynShield را دنبال کنید.
SheynShield
Understand the technology. Build the architecture. Secure the network.
GitHub
GitHub - Shayan-heydarikhah/sheynshield: A repository for all network and security guys
A repository for all network and security guys. Contribute to Shayan-heydarikhah/sheynshield development by creating an account on GitHub.
❤1
🛡 FortiGate Licensing & FortiGuard Updates
یکی از اشتباهات رایج در FortiGate این است که License، FortiOS و FortiGuard را یک مفهوم در نظر بگیریم.
بیایید مرز بین اینها را روشن کنیم. 👇
🧠 1. FortiOS ≠ FortiGuard
🔥 بنابراین:
و:
🔐 2. License چه چیزی را کنترل میکند؟
قبل از Troubleshooting بررسی کنید:
☑️ Device Registration
☑️ Subscription Status
☑️ Service Entitlement
☑️ Bundle / SKU
☑️ Expiration Date
☑️ Required FortiGuard Services
اما:
🌐 3. FortiGuard Update چگونه کار میکند؟
File-Based
معمولاً برای مواردی مانند:
مدل ذهنی:
Query-Based
برای سرویسهایی مانند:
مدل ذهنی:
💡 Memory Trick:
🚨 4. وقتی FortiGuard Update Fail میشود
اشتباه رایج:
در واقع باید Dependency Chain را Trace کنیم:
🔥 این دقیقاً همان Mindset موردنیاز Troubleshooting در سطح NSE7 است:
🔎 5. DNS را فراموش نکنید
بنابراین:
⏰ 6. System Time
زمان اشتباه میتواند باعث مشکل در TLS/Certificate Validation شود:
پس NTP را هم بررسی کنید.
📴 7. Online vs Offline Update
Online
Offline
Offline Update برای محیطهایی مثل:
☑️ Air-Gapped
☑️ Isolated Lab
☑️ Restricted Network
کاربرد مهمی دارد.
🔄 8. FortiGuard Through Proxy / Tunnel
در شبکههای محدود:
در Troubleshooting بررسی کنید:
☑️ Proxy Address
☑️ Port
☑️ Authentication
☑️ DNS
☑️ TLS
☑️ FortiGuard Connectivity
🚀 9. Firmware Upgrade
این دو را کاملاً جدا کنید:
قبل از Upgrade:
☑️ Current Version
☑️ Target Version
☑️ Supported Upgrade Path
☑️ Release Notes
☑️ Known Issues
☑️ Hardware Compatibility
☑️ HA/VPN/SD-WAN Impact
☑️ Configuration Backup
☑️ Rollback Plan
☑️ Maintenance Window
❌ این منطق اشتباه است:
✅ منطق درست:
🧠 NSE Exam Traps
Trap 1
Trap 2
Trap 3
Trap 4
Trap 5
Trap 6
⚡️ 60-Second FortiGuard Troubleshooting
اگر فقط یک Flow بخواهید حفظ کنید:
🔥 Golden Rule:
FortiOS • FortiGuard • Licensing • Security Updates • Troubleshooting
یکی از اشتباهات رایج در FortiGate این است که License، FortiOS و FortiGuard را یک مفهوم در نظر بگیریم.
بیایید مرز بین اینها را روشن کنیم. 👇
🧠 1. FortiOS ≠ FortiGuard
FORTIGATE
│
├── FORTIOS
│ ├── Firewall
│ ├── Routing
│ ├── NAT
│ ├── VPN
│ ├── HA
│ └── SD-WAN
│
└── FORTIGUARD
├── AV Intelligence
├── IPS Signatures
├── Application Data
├── Web Filtering
├── Anti-Spam
└── Threat Intelligence
🔥 بنابراین:
FortiGuard License Expired
≠
FortiGate Shutdown
و:
Firmware Upgrade
≠
FortiGuard Signature Update
🔐 2. License چه چیزی را کنترل میکند؟
قبل از Troubleshooting بررسی کنید:
☑️ Device Registration
☑️ Subscription Status
☑️ Service Entitlement
☑️ Bundle / SKU
☑️ Expiration Date
☑️ Required FortiGuard Services
اما:
Valid License
≠
Guaranteed Connectivity
🌐 3. FortiGuard Update چگونه کار میکند؟
File-Based
معمولاً برای مواردی مانند:
AV
IPS
Application Control
مدل ذهنی:
FortiGate
↓
Download
↓
Database / Signature
Query-Based
برای سرویسهایی مانند:
Web Filtering
Anti-Spam
Reputation
مدل ذهنی:
FortiGate
↓
Query
↓
FortiGuard
↓
Classification / Reputation
💡 Memory Trick:
AV / IPS / Application
↓
UPDATE
Web Filter / Anti-Spam
↓
QUERY
🚨 4. وقتی FortiGuard Update Fail میشود
اشتباه رایج:
«FortiGuard کار نمیکند، پس License مشکل دارد.»
در واقع باید Dependency Chain را Trace کنیم:
License
↓
DNS
↓
Routing
↓
NAT
↓
Firewall Policy
↓
Required Port
↓
Proxy
↓
TLS / System Time
↓
FortiGuard
↓
Specific Service
↓
Logs
🔥 این دقیقاً همان Mindset موردنیاز Troubleshooting در سطح NSE7 است:
Don't Guess → Trace Dependencies
🔎 5. DNS را فراموش نکنید
FortiGate
↓
DNS Query
↓
FortiGuard FQDN
↓
IP Resolution
↓
Connection
بنابراین:
DNS Failure
↓
FQDN Resolution Failure
↓
Possible FortiGuard Failure
⏰ 6. System Time
زمان اشتباه میتواند باعث مشکل در TLS/Certificate Validation شود:
Wrong Time
↓
TLS / Certificate Validation
↓
Possible FortiGuard Failure
پس NTP را هم بررسی کنید.
📴 7. Online vs Offline Update
Online
FortiGate
↓
Internet
↓
FortiGuard
↓
Update
Offline
Connected System
↓
Download Package
↓
Secure Transfer
↓
Isolated FortiGate
↓
Install
↓
Verify
Offline Update برای محیطهایی مثل:
☑️ Air-Gapped
☑️ Isolated Lab
☑️ Restricted Network
کاربرد مهمی دارد.
🔄 8. FortiGuard Through Proxy / Tunnel
در شبکههای محدود:
FortiGate
↓
Proxy / Relay
↓
Internet
↓
FortiGuard
در Troubleshooting بررسی کنید:
☑️ Proxy Address
☑️ Port
☑️ Authentication
☑️ DNS
☑️ TLS
☑️ FortiGuard Connectivity
🚀 9. Firmware Upgrade
این دو را کاملاً جدا کنید:
FortiOS Upgrade
≠
FortiGuard Update
قبل از Upgrade:
☑️ Current Version
☑️ Target Version
☑️ Supported Upgrade Path
☑️ Release Notes
☑️ Known Issues
☑️ Hardware Compatibility
☑️ HA/VPN/SD-WAN Impact
☑️ Configuration Backup
☑️ Rollback Plan
☑️ Maintenance Window
❌ این منطق اشتباه است:
New Version
↓
Upgrade Immediately
✅ منطق درست:
Current
↓
Target
↓
Upgrade Path
↓
Release Notes
↓
Known Issues
↓
Compatibility
↓
Backup
↓
Upgrade
↓
Validation
🧠 NSE Exam Traps
Trap 1
License Expired
≠
FortiGate Shutdown
Trap 2
Firmware Update
≠
Signature Update
Trap 3
Internet Works
≠
FortiGuard Works
Trap 4
Valid License
≠
Guaranteed Connectivity
Trap 5
FortiGuard Failure
≠
Always License Failure
Trap 6
Wrong System Time
↓
Possible TLS Failure
⚡️ 60-Second FortiGuard Troubleshooting
اگر فقط یک Flow بخواهید حفظ کنید:
LICENSE
↓
DNS
↓
ROUTE
↓
NAT
↓
POLICY
↓
PORT
↓
PROXY
↓
TLS / TIME
↓
FORTIGUARD
↓
SPECIFIC SERVICE
↓
LOGS
🔥 Golden Rule:
❤1
FortiGuard Failure → Don't Guess. Identify the Failure Domain.
📚 SheynShield | Engineering Secure Networks
🎥 YouTube: https://youtube.com/@sheynshield
📚 Telegram: https://t.me/sheynshield
🐙 GitHub: https://github.com/Shayan-heydarikhah/sheynshield
#FortiGate #FortiOS #FortiGuard #Fortinet #NSE4 #NSE7 #Troubleshooting #NetworkSecurityاینجا قراره طی ۶ ماه با هم وارد دنیای واقعی IT بشیم؛
از Network و Infrastructure شروع میکنیم و میرسیم به:
🌐 Network & Infrastructure
🛡️ Security & Firewall
🐳 DevOps & Automation
☁️ Cloud & Virtualization
💻 Linux & Programming
🤖 AI & AI Infrastructure
🔧 Troubleshooting & Real-World Scenarios
اینجا قرار نیست فقط تئوری یاد بگیریم؛
یاد میگیریم، میسازیم، خراب میکنیم، عیبیابی میکنیم و دوباره میسازیم.
🎯 هدف NBC اینه که بعد از این ۶ ماه، فقط اطلاعات بیشتری نداشته باشیم؛
بلکه بهتر فکر کنیم، بهتر حل مسئله کنیم و واقعاً مهارت بسازیم.
Learn • Build • Secure • Automate 🚀
آدرس گروه :
@networkbiteclub
از Network و Infrastructure شروع میکنیم و میرسیم به:
🌐 Network & Infrastructure
🛡️ Security & Firewall
🐳 DevOps & Automation
☁️ Cloud & Virtualization
💻 Linux & Programming
🤖 AI & AI Infrastructure
🔧 Troubleshooting & Real-World Scenarios
اینجا قرار نیست فقط تئوری یاد بگیریم؛
یاد میگیریم، میسازیم، خراب میکنیم، عیبیابی میکنیم و دوباره میسازیم.
🎯 هدف NBC اینه که بعد از این ۶ ماه، فقط اطلاعات بیشتری نداشته باشیم؛
بلکه بهتر فکر کنیم، بهتر حل مسئله کنیم و واقعاً مهارت بسازیم.
Learn • Build • Secure • Automate 🚀
آدرس گروه :
@networkbiteclub