T Techclick ← All lessons
Fortinet · FortiOS 7.4 · Lesson 12 of 12

Interview: say the box, the policy id, and the proof command

Interviewers do not want “FortiGate is a firewall.” They want: first match, VIP vs SNAT, debug flow, Phase-1 vs Phase-2, ssl.root, SLA vs policy route, VDOM leak, FGCP monitor. Walk the dummy lab out loud.

Updated 2026-08-18·20 min read·L2 primary·Quiz at end

After this page you can

The ticket

You have 12 minutes. The interviewer draws WAN 203.0.113.10 and Priya 10.20.30.80. Talk like you have closed that ticket.

Strong answer pattern

Name the feature → name the GUI/CLI path → name the proof (policyid / debug flow / ha status / vpn tunnel list) → name the classic trap. Weak: “check the logs.” Strong: “Forward Traffic policyid, then diagnose debug flow filter addr 10.20.30.80.”

Hero · whiteboard
Interview whiteboard with FortiGate lab IPs
If you cannot draw first match, you are not ready.
Lab data · dummy only

FortiGate fgt-hq mgmt 10.10.10.1 · WAN 203.0.113.10 · LAN 10.20.30.0/24 · FortiManager 10.10.10.5 · FortiAnalyzer 10.10.10.6 · Priya 10.20.30.80 · branch peer WAN 198.51.100.10 · Azure VPN GW public 203.0.113.50 · AWS VGW public 203.0.113.60. RFC 5737. Not a customer.

Twenty questions (say these out loud)

  1. FGT vs FMG vs FAZ — who forwards?
  2. Why zones on day one?
  3. First match vs most specific.
  4. How do you see which policy hit?
  5. SNAT vs VIP.
  6. VIP without WAN-to-LAN policy.
  7. Certificate vs deep SSL inspection.
  8. Profile on a shadowed policy.
  9. Why filter debug flow?
  10. Stale session after policy change.
  11. Phase-1 up, Phase-2 down.
  12. SAs up, ping dead.
  13. ssl.root vs WAN policy for SSL-VPN.
  14. Split vs full tunnel.
  15. Why SSL-VPN CVE caution?
  16. SD-WAN SLA vs policy route.
  17. Policy dest-intf must be the SD-WAN zone.
  18. VDOM leak via routing.
  19. FGCP monitor-interface vs heartbeat.
  20. Split-brain two actives.

Weak vs strong

WeakStrong
Reboot FortinetWhich product, then which proof
Add any-anyPolicy match, then shrink
VPN is upIKE SA vs IPsec SA vs selectors vs route

How to rehearse

  1. Side A

    Draw the lab from memory.

  2. Side B

    Answer five questions with a command each.

  3. Side C

    Take the quiz. Misses send you back to that lesson.

Four interview fails

1 · Feature dump

They asked for a path.

2 · No proof command

Theory only.

3 · Mixing SSL-VPN and IPsec S2S

Different objects.

4 · Cloud NAT confusion

Next series. Don’t fake Azure SKUs.

How to prove it

You are ready when

You can walk tickets 1–20 without opening the notes, and you name a command for each.

Traps

Memorising menu names without first-match will still fail the lab interview.

Knowledge check

Judgment items. One best answer. Reasons send you back to the matching section.

Q1

Best proof of which policy hit?

Correct: b. Lessons 3 and 6.
Q2

“VPN is up” is incomplete until you name…

Correct: a. Lesson 7.
Q3

SSL-VPN tunnel policy interface is usually…

Correct: a. Lesson 8.
Q4

SD-WAN without a health-check is basically…

Correct: a. Lesson 9.
Q5

HA did not fail over on WAN cut. Ask…

Correct: a. Lesson 11.
Q6

Strong interview pattern?

Correct: a. This lesson.

FortiGate class series: FGT / FMG / FAZ · First day · Policy first match · SNAT vs VIP · Profiles + SSL · debug flow · IPsec S2S · SSL-VPN vs RA · SD-WAN SLA · VDOM · FGCP HA · Interview

Sources

Related: FortiGate session factory · VPN series.