Research gate and version scope
Research date: 2026-07-19. Fortinet currently presents 8.0, 7.6, and 7.4 as primary documentation families; 7.2 is labelled legacy. Always verify the exact FortiGate model, target patch release notes, Fortinet Upgrade Path Tool, compatibility, and support entitlement before production change.
The reusable investigation method
- Confirm the exact symptom and time.
- Define source, destination, protocol, port, application, user, and VDOM.
- Confirm ingress interface and source validity/RPF.
- Verify route and return route.
- Verify policy and identity match.
- Verify VIP, central/policy NAT, or IP pool.
- Inspect session state and offload.
- Check security profiles and TLS inspection.
- Correlate logs.
- Run a narrow packet capture.
- Use filtered, limited debug flow only if needed.
- Test one hypothesis.
- Apply the lowest-risk correction.
- Repeat the original application test.
- Stop/reset debugging.
- Document evidence and rollback.
Visual whiteboard maps
15-minute revision guide
Say the tuple, VDOM, ingress, route/return route, RPF, policy, NAT, session, inspection, egress.
Explain policy NAT vs central SNAT, VIP/DNAT, IP pools/SNAT, and hairpin return path.
Explain IKE Phase 1, Phase 2, selectors, route, policy, NAT-T, DPD, and counters.
Explain SD-WAN members, routes, SLAs, ordered rules, session pinning, and fresh-flow validation.
Explain FGCP heartbeat, election, sync, session pickup limitations, FMG preview, and FAZ log path.
Clarify → Verify → Evidence → Hypothesis → Correct safely → Validate → Document.
Command and evidence cheat sheets
Evidence order: user symptom/time → five-tuple → VDOM → interfaces → route/return → RPF → policy ID → NAT tuple → session → security log → capture → filtered debug → original app retest.
Never run unrestricted production debug. Debug flow must have a narrow filter, a record limit, and an explicit trace-stop, debug-disable, and reset sequence. Offload changes and session clears are deliberately not published as routine fixes.
FG-001 to FG-080
30-symptom troubleshooting table
| Symptom | Layer | Evidence | Probable cause | Safe next step | Validation |
|---|
10 practical labs
10 mock incident tickets
20 rapid-fire questions
15 MCQs with explanations
30-question mock interview
Interview scoring rubric and readiness
| Dimension | 5 points | 3 points | 1 point |
|---|---|---|---|
| Scope | Exact tuple, user, time, VDOM | Most context | Generic symptom |
| Mechanism | Correct path and version caveat | Mostly correct | Definition only |
| Evidence | Route, policy, session, logs, capture | Two proof points | Guess/reboot |
| Safety | Narrow, reversible, explicit stop/rollback | Some caution | Broad disable/clear |
| Validation | Original app test plus counters/logs | Ping-only check | No retest |
FortiGate terminology glossary
Official references
- FortiGate / FortiOS 8.0 Document Library
- FortiOS 8.0 troubleshooting scenarios
- FortiOS 7.6 debugging packet flow
- FortiOS 8.0 central SNAT
- FortiOS 8.0 routing concepts and RPF
- FortiOS 8.0 FGCP
- FortiOS 8.0 session pickup
- FortiOS 8.0 SSL/TLS deep inspection
- FortiOS 8.0 VPN IPsec troubleshooting
- FortiManager 8.0 policy-package install
- FortiAnalyzer 8.0 log types
- Fortinet Product Lifecycle Policy