WELCOME TO FORTINET FORTIWEB WAF
ADMINISTRATOR TRAINING
Hands-On EVE-NG Labs for Real-World
Web Application Security
COURSE INTRODUCTION:
Welcome to this comprehensive, hands-on course designed to help you master Fortinet
FortiWeb, one of the most powerful Web Application Firewalls (WAF) used by enterprises
worldwide. Whether you are a network security professional, DevOps engineer, or penetration
tester, this course provides a step-by-step practical roadmap — from deployment to advanced
protection techniques.
You’ll build your own fully functional lab using EVE-NG, upload and configure FortiWeb images,
integrate real web servers, and implement protection policies against modern web threats.
Through guided labs and real-world scenarios, you’ll learn how to detect, block, and mitigate
attacks such as SQL Injection, XSS, CSRF, File Upload abuse, DoS/BOT attacks, and more.
WHAT YOU WILL LEARN:
🔹 FortiWeb Fundamentals:
Understand FortiWeb architecture, deployment modes (Reverse Proxy, Transparent, Offline),
and its role in web application security.
🔹 EVE-NG Lab Deployment:
Set up a realistic lab environment with FortiWeb, web servers, and clients to simulate real
attack and defense scenarios.
🔹 Initial Configuration & Server Policies:
Configure interfaces, VIPs, server pools, virtual servers, and server policies to secure traffic.
🔹 Health Checks & Load Balancing:
Implement ICMP, TCP, and HTTP health checks. Configure Round Robin, Weighted Round Robin,
and Persistence methods.
1 | P a g e Created by Ahmad Ali E-Mail: accessahmadali@[Link] , WhatsApp: 00971543127181
🔹 Web Protection Profiles:
Apply signatures, anomaly detection, and custom rules to secure applications against common
and advanced threats.
🔹 Content Routing & SSL Offloading:
Configure HTTP rewriting, X-Forwarded-For headers, SSL certificates, and offloading for
encrypted traffic.
🔹 Web Attack Protection:
Block Command Injection, File Inclusion, File Upload abuse, SQL Injection, XSS, CSRF, and web
shell attacks with FortiWeb security profiles.
🔹 DoS, BOT, and Access Control:
Set up DoS protection, BOT detection, cookie security, GEO restrictions, and IP protection lists.
🔹 API Gateway & JSON Protection:
Secure REST APIs with FortiWeb API gateway protection and JSON schema validation.
🔹 Testing, Verification & Reporting:
Validate configurations with real attack simulations, logs, and reports to ensure robust
protection.
📥 DOWNLOAD COURSE RESOURCES
You’ll get access to everything you need to follow along:
✅ Ready-made EVE-NG Topologies
✅ Pre-built Lab Images & Sample Web Apps
✅ Step-by-Step Workbook and Notes
✅ Attack Simulation Scripts & Testing Tools
➡️ All downloadable files will be available under the Resources
section of the first video.
2 | P a g e Created by Ahmad Ali E-Mail: accessahmadali@[Link] , WhatsApp: 00971543127181