Skip to main content

Description

Fortinet's FortiWeb is an application firewall program designed to optimize the security of Web applications in the face of various computer threats. This course will teach you how to deploy and master FortiWeb's features to protect your Web applications. It is part of the preparatory course for Fortinet NSE6 certification.

Day 1: Introduction and configuration of FortiWeb

  • General introduction to FortiWeb and its features.
  • Initial configuration of FortiWeb for optimal protection.
  • Integration with external SIEM systems for enhanced monitoring.

Day 2: Security and Threat Management

  • Setting up protection against defeat and denial-of-service attacks.
  • Use of signatures, data sanitization and self-learning mechanisms.
  • Application of SSL and TLS protocols to secure communications.

Day 3: Access Control and Optimization

  • Implementation of authentication and access control methods.
  • PCI DSS 3.0 compliance for data security.
  • Caching, compression, rewriting and redirection techniques to optimize performance.
  • Troubleshooting and diagnostics with FortiWeb.

This course is aimed at IT professionals involved in FortiWeb administration.

Participation in this course requires :

  • Mastering the concepts of OSI layers and HTTP protocol.
  • Basic knowledge of HTML and JavaScript.
  • Basic knowledge of a dynamic server-side page language such as PHP.
  • Know how to use FortiGate port forwarding.

This course is designed to introduce you to Web application security management using FortiWeb. You'll gain an in-depth understanding of security principles, followed by learning how to manage various computer threats. This includes basic FortiWeb configuration, setting up a firewall and troubleshooting FortiWeb server issues. The program is made up of theoretical modules and practical exercises, enabling you to apply your new skills in real-life situations. This course is also part of the preparatory curriculum for the Fortinet NSE 6 certification exam.

At the end of this course, you will be able to :

  • Identify and prevent risks to application layers.
  • React to hacks such as defacement and denial-of-service attacks.
  • Manage zero-day vulnerabilities and exploits while maintaining direct traffic.
  • Ensure backward compatibility of applications with OWASP Top 10 2013 and PCI DSS 3.0 standards.
  • Optimize the security of your Web servers and applications by identifying vulnerabilities.
  • Enhance protection of HTTP and XML applications via FortiGate and FortiWeb.
  • Manage the operation of FTP and SSH protocols to prevent accidental bypassing.
  • Configure blocking and reporting options for FortiADC or external FortiGate and FortiAnalyzer.
  • Manage the load on a server pool.
  • Master bare-metal application protection, including SSL/TLS, authentication and advanced access control.
  • Establish a blacklist of suspects.
  • Solve traffic flow problems.
  • Diagnose false positives.

We design, build and support digital products for clients who want to make a positive impact in their industry. Creative with technology, we develop great solutions to help our clients grow and especially by strengthening our relationships based on continuous improvement, maintenance, support and hosting services.

Follow us