The ticket
You have 12 minutes. The interviewer draws WAN 203.0.113.10 and Priya 10.20.30.80. Talk like you have closed that ticket.
Name the feature → name the GUI/CLI path → name the proof (policyid / debug flow / ha status / vpn tunnel list) → name the classic trap. Weak: “check the logs.” Strong: “Forward Traffic policyid, then diagnose debug flow filter addr 10.20.30.80.”
FortiGate fgt-hq mgmt 10.10.10.1 · WAN 203.0.113.10 · LAN 10.20.30.0/24 · FortiManager 10.10.10.5 · FortiAnalyzer 10.10.10.6 · Priya 10.20.30.80 · branch peer WAN 198.51.100.10 · Azure VPN GW public 203.0.113.50 · AWS VGW public 203.0.113.60. RFC 5737. Not a customer.
Twenty questions (say these out loud)
- FGT vs FMG vs FAZ — who forwards?
- Why zones on day one?
- First match vs most specific.
- How do you see which policy hit?
- SNAT vs VIP.
- VIP without WAN-to-LAN policy.
- Certificate vs deep SSL inspection.
- Profile on a shadowed policy.
- Why filter debug flow?
- Stale session after policy change.
- Phase-1 up, Phase-2 down.
- SAs up, ping dead.
- ssl.root vs WAN policy for SSL-VPN.
- Split vs full tunnel.
- Why SSL-VPN CVE caution?
- SD-WAN SLA vs policy route.
- Policy dest-intf must be the SD-WAN zone.
- VDOM leak via routing.
- FGCP monitor-interface vs heartbeat.
- Split-brain two actives.
Weak vs strong
| Weak | Strong |
|---|---|
| Reboot Fortinet | Which product, then which proof |
| Add any-any | Policy match, then shrink |
| VPN is up | IKE SA vs IPsec SA vs selectors vs route |
How to rehearse
Side A
Draw the lab from memory.
Side B
Answer five questions with a command each.
Side C
Take the quiz. Misses send you back to that lesson.
Four interview fails
1 · Feature dump
They asked for a path.
2 · No proof command
Theory only.
3 · Mixing SSL-VPN and IPsec S2S
Different objects.
4 · Cloud NAT confusion
Next series. Don’t fake Azure SKUs.
How to prove it
You can walk tickets 1–20 without opening the notes, and you name a command for each.
Traps
Memorising menu names without first-match will still fail the lab interview.
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
FortiGate class series: FGT / FMG / FAZ · First day · Policy first match · SNAT vs VIP · Profiles + SSL · debug flow · IPsec S2S · SSL-VPN vs RA · SD-WAN SLA · VDOM · FGCP HA · Interview
Sources
- This series lessons 1–11 — FortiOS 7.4 Administration Guide pages cited there.
- FortiOS 7.4 Administration Guide.
Related: FortiGate session factory · VPN series.