# Interview: say the box, the policy id, and the proof command

Source: https://ai.techclick.in/blog_fortigate_interview_20
Markdown: https://ai.techclick.in/blog_fortigate_interview_20.md
Publisher: Techclick Infosec Pvt Ltd

Twenty FortiGate interview scenarios from this lab: first match, VIP, debug flow, IPsec, SSL-VPN, SD-WAN, VDOM, HA.

## The ticket

 You have 12 minutes. The interviewer draws WAN 203.0.113.10 and Priya 10.20.30.80. Talk like you have closed that ticket.

  Strong answer pattern

 Name the feature → name the GUI/CLI path → name the proof (policyid / debug flow / ha status / vpn tunnel list) → name the classic trap. Weak: “check the logs.” Strong: “Forward Traffic policyid, then diagnose debug flow filter addr 10.20.30.80.”

  Hero · whiteboard

 If you cannot draw first match, you are not ready.
  Lab data · dummy only
 FortiGate  fgt-hq  mgmt  10.10.10.1  · WAN  203.0.113.10  · LAN  10.20.30.0/24  · FortiManager  10.10.10.5  · FortiAnalyzer  10.10.10.6  · Priya  10.20.30.80  · branch peer WAN  198.51.100.10  · Azure VPN GW public  203.0.113.50  · AWS VGW public  203.0.113.60 . RFC 5737. Not a customer.

## Twenty questions (say these out loud)

- FGT vs FMG vs FAZ — who forwards?

- Why zones on day one?

- First match vs most specific.

- How do you see which policy hit?

- SNAT vs VIP.

- VIP without WAN-to-LAN policy.

- Certificate vs deep SSL inspection.

- Profile on a shadowed policy.

- Why filter debug flow?

- Stale session after policy change.

- Phase-1 up, Phase-2 down.

- SAs up, ping dead.

- ssl.root vs WAN policy for SSL-VPN.

- Split vs full tunnel.

- Why SSL-VPN CVE caution?

- SD-WAN SLA vs policy route.

- Policy dest-intf must be the SD-WAN zone.

- VDOM leak via routing.

- FGCP monitor-interface vs heartbeat.

- Split-brain two actives.

## Weak vs strong

   Weak  Strong

  Reboot Fortinet  Which product, then which proof
  Add any-any  Policy match, then shrink
  VPN is up  IKE SA vs IPsec SA vs selectors vs route

## How to rehearse

- #### Side A Draw the lab from memory.

- #### Side B Answer five questions with a command each.

- #### Side C Take the quiz. Misses send you back to that lesson.

## Four interview fails

### 1 · Feature dump

 They asked for a path.

### 2 · No proof command

 Theory only.

### 3 · Mixing SSL-VPN and IPsec S2S

 Different objects.

### 4 · Cloud NAT confusion

 Next series. Don’t fake Azure SKUs.

## How to prove it

  You are ready when

 You can walk tickets 1–20 without opening the notes, and you name a command for each.

## Traps

 Memorising menu names without first-match will still fail the lab interview.

## Knowledge check

   Judgment items. One best answer. Reasons send you back to the matching section.

       Q1
       Best proof of which policy hit?

           Guess from the name
           policyid in Forward Traffic or debug flow
           Reboot
           FMG hostname

       Correct:  b . Lessons 3 and 6.

       Q2
       “VPN is up” is incomplete until you name…

           IKE vs IPsec SA and selectors
           Only the PSK length
           FAZ disk
           VDOM count

       Correct:  a . Lesson 7.

       Q3
       SSL-VPN tunnel policy interface is usually…

           ssl.root
           ha1
           fortilink
           any

       Correct:  a . Lesson 8.

       Q4
       SD-WAN without a health-check is basically…

           A policy route with extra GUI
           Deep inspection
           A VDOM
           FGCP

       Correct:  a . Lesson 9.

       Q5
       HA did not fail over on WAN cut. Ask…

           Is WAN a monitor-interface?
           Is Facebook allowed?
           Is FMG licensed?
           Is NTP a VDOM?

       Correct:  a . Lesson 11.

       Q6
       Strong interview pattern?

           Feature + path + proof command + trap
           Reboot first
           List every UTM logo
           Say Fortinet is one box

       Correct:  a . This lesson.

       Check answers
       Reset

  FortiGate class series:   FGT / FMG / FAZ  ·  First day  ·  Policy first match  ·  SNAT vs VIP  ·  Profiles + SSL  ·  debug flow  ·  IPsec S2S  ·  SSL-VPN vs RA  ·  SD-WAN SLA  ·  VDOM  ·  FGCP HA  ·  Interview

## Sources

- This series lessons 1–11 — FortiOS 7.4 Administration Guide pages cited there.
- FortiOS 7.4 Administration Guide .

 Related:  FortiGate session factory  ·  VPN series .

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
