Useful Links 1. https://customersso1.fortinet.com/saml-idp/mwfjn4canlgdkl6a/login/ 2. https://docs.fortinet.com/ 3. https://docs.fortinet.com/upgrade-tool/fortigate 4. https://support.fortinet.com/support/#/dashboard 5. https://support.fortinet.com/support/#/downloads/firmware ===================== POST ==================== FortiGate-200B (14:40-09.14.2010) Ver:04000007 RAM activation Total RAM: 1024MB Enabling cache...Done. Scanning PCI bus...Done. Allocating PCI resources...Done. Enabling PCI resources...Done. Zeroing IRQ settings...Done. Verifying PIRQ tables...Done. Disabling local APIC...Done. Boot up, boot device capacity: 3824MB. Press any key to display configuration menu... ========================= Boot Failed after POST ======================= FortiGate-200B (14:40-09.14.2010) Ver:04000007 RAM activation Total RAM: 1024MB Enabling cache...Done. Scanning PCI bus...Done. Allocating PCI resources...Done. Enabling PCI resources...Done. Zeroing IRQ settings...Done. Verifying PIRQ tables...Done. Disabling local APIC...Done. Boot up, boot device capacity: 3824MB. Press any key to display configuration menu... ...... Open boot device failed. ========================== Press any key = Main configuration Menu ========================== [G]: Get firmware image from TFTP server. [F]: Format boot device. [B]: Boot with backup firmware and set as default. [I]: Configuration and information. [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter Selection [G]: Enter G,F,B,I,Q,or H: -------------- "B" Pressed -------------- Loading backup firmware from boot device... Open boot device failed. -------------- "Q" Pressed -------------- Open boot device failed. -------------- "F" Pressed -------------- All data will be erased,continue:[Y/N]? Formatting boot device... .................................... Format boot device completed. ******************************** "I" Pressed = Sub Menu ******************************** [S]: Set serial port baudrate(will take effect on next boot). [T]: Set image download port(will take effect on next boot). [C]: Set DHCP enable (will take effect on next boot). [I]: Display hardware information. [Q]: Quit this menu. [H]: Display this list of options. Enter S,T,C,I,Q,or H: --------------- "S" Pressed: = serial port baudrate -------------- Please select serial console baudrate: [9600] [1]: 9600 [2]: 19200 [3]: 38400 [4]: 57600 [5]: 115200 --------------- "I" Pressed: = Display hardware information -------------- OS image name : flatkc vendor_id : GenuineIntel cpu family : 6 model : 5 model name : Celeron (Covington)ocessor 1.20GHz stepping : 0 CPU MHz : 1199.933 cache size : 0 KB RAM :1024MB 800MHz IDE device channel 0 drive 0 :No device drive 1 :No device IDE device channel 1 drive 0 :No device drive 1 :No device Enter S,T,C,I,Q,or H: ================================== OS Image Recovery via TFTP Server ================================== -------------- "T" Pressed: = Set image download port -------------- 1: 1 2: 11 3: 12 Enter image download port number [1]: 1 Enter S,T,C,I,Q,or H: -------------- "C" Pressed: = Set DHCP enable -------------- Current setting: Enabled Please select DHCP setting [1]: Enable DHCP [2]: Disable DHCP Enter S,T,C,I,Q,or H: 1 -------------- "Q" Pressed: = Set DHCP enable -------------- Open boot device failed. -------------- Reboot Device -------------- FortiGate-200B (14:40-09.14.2010) Ver:04000007 RAM activation Total RAM: 1024MB Enabling cache...Done. Scanning PCI bus...Done. Allocating PCI resources...Done. Enabling PCI resources...Done. Zeroing IRQ settings...Done. Verifying PIRQ tables...Done. Disabling local APIC...Done. Boot up, boot device capacity: 3824MB. Press any key to display configuration menu... -------------- Pressed any key -------------- [G]: Get firmware image from TFTP server. [F]: Format boot device. [B]: Boot with backup firmware and set as default. [I]: Configuration and information. [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter Selection [G]: Enter G,F,B,I,Q,or H: -------------- "G" Pressed: = Get firmware image from TFTP -------------- Please connect TFTP server to Ethernet port "1". Enter TFTP server address [192.168.1.168]: >>>> [enter TFTP server address or keep Default = 192.168.1.168] Enter firmware image file name [image.out]: >>>> [Enter image name or keep Default = image.out] Can not get local address from DHCP server. >>>> [message appears if DHCP set via above options & IP cannot get] Enter local address [192.168.1.188]: >>>> [Enter IP of your Subnet or keep Default = 192.168.1.188 if DHCP fails] >>>> [Now Press Enter and image will be started copying] ========================================================================================================= ================== firmware download linkdeos for Fortigate 200B ================== https://fortiweb.ru/en/file/23126/FGT_200B-v5-build0292-FORTINET.out.html ================== YT videos for Fortigate 200B ================== https://www.youtube.com/watch?v=4hZ9xDBAcw0 https://www.youtube.com/watch?v=_didEkuFhEo ========================== Reset Fortinet Password ========================== https://www.youtube.com/watch?v=9hcB-lWRmPY maintainer bcpb[SerialNumber] reboot and copy paste the above code when promt to login and hit ENTER and here's GO # config system admin # edit admin # set password [PASSWORD] ================================= firewall and application delivery terminology ================================== In firewall and application delivery terminology, UTM, LTM, and similar acronyms refer to different roles and feature sets. ----------- UTM — Unified Threat Management ----------- A UTM is a firewall that combines multiple security functions into one device. Typical UTM features on a FortiGate: ✅ Stateful Firewall ✅ NAT ✅ IPS (Intrusion Prevention System) ✅ Antivirus ✅ Web Filtering ✅ Application Control ✅ Anti-Spam ✅ SSL Inspection ✅ VPN (IPsec/SSL) Example: Fortinet FortiGate Sophos XG Firewall WatchGuard Firebox A UTM sits between users and the Internet and inspects traffic for threats. ----------- LTM — Local Traffic Manager ----------- LTM is a term most commonly associated with F5 BIG-IP. An LTM is primarily a load balancer and application delivery controller (ADC). Functions include: ✅ Load Balancing ✅ SSL Offloading ✅ Health Monitoring ✅ Application Acceleration ✅ Traffic Distribution ✅ High Availability Example: Internet | v LTM | \ v v Web1 Web2 The LTM decides which server receives each connection. ----------- GTM / DNS Load Balancing ----------- GTM (Global Traffic Manager), now often called DNS/GSLB, distributes traffic between different data centers. Example: User in Europe -> London DC User in Asia -> Singapore DC User in USA -> Dallas DC IPS — Intrusion Prevention System Detects and blocks attacks such as: Port scans Exploits Malware traffic Known vulnerabilities FortiGate's IPS engine is part of the UTM package. ----------- WAF — Web Application Firewall ----------- Protects web applications from attacks such as: SQL Injection XSS CSRF Examples: F5 Advanced WAF Cloudflare WAF Fortinet FortiWeb ----------- ADC — Application Delivery Controller ----------- A broader category that includes: Load balancing SSL offloading Traffic optimization Health checks LTM is essentially an ADC product. ----------- NGFW — Next-Generation Firewall ----------- Modern firewalls that provide: ✅ Stateful inspection ✅ IPS ✅ Application awareness ✅ User identity integration ✅ SSL inspection FortiGate is considered an NGFW. Simple Comparison Feature UTM / NGFW LTM Firewall ✅ ❌ NAT ✅ ❌ IPS ✅ ❌ Antivirus ✅ ❌ Web Filtering ✅ ❌ Load Balancing Limited ✅ SSL Offload Limited ✅ Server Health Checks Limited ✅ Application Delivery Limited ✅ In a Telecom/Data Center A common flow is: Internet | FortiGate (UTM/NGFW) | F5 BIG-IP (LTM) | Application Servers FortiGate protects the network. F5 LTM distributes traffic among servers. Servers provide the application. For hardware FortiGates, the firmware filenames are platform-specific. Examples: | Image Name | Meaning | | ----------- | --------------------------------------------------------------------------------------------------------- | | flatkc | Flat kernel image, compressed. Very common on older x86-based FortiGate units such as the 100/200 series. | | flatk | Flat kernel image, uncompressed (seen on some older platforms). | | image.out | Generic firmware filename used during TFTP recovery; not an image type itself. | | Platform | Firmware Prefix | | ----------------------------- | ---------------- | | FortiGate hardware appliances | FGT_ | | FortiWiFi appliances | FWF_ | | FortiGate VM (KVM) | FGT_VM64_KVM | | FortiGate VM (VMware) | FGT_VM64 | | FortiGate VM (Hyper-V) | FGT_VM64_HV | | FortiGate VM (AWS) | FGT_VM64_AWS | | FortiGate VM (Azure) | FGT_VM64_AZURE | | FortiGate VM (ARM64 cloud) | FGT_ARM64_* | | Platform | Typical Firmware Filename Pattern | | -------------- | --------------------------------------------------------------- | | FortiGate 200B | FGT_200B-v400-buildxxxx-FORTINET.out | | FortiGate 100D | FGT_100D-v600-buildxxxx-FORTINET.out | | FortiWiFi 60CM | FWF_60CM-v400-buildxxxx-FORTINET.out | | FortiGate VM | VM-specific images (different format from hardware appliances) | ================ basic routed/NAT deployment template that covers the most important initial setup tasks ============== # ========================= # HOSTNAME # ========================= config system global set hostname FGT-200B end # ========================= # ADMIN PASSWORD # ========================= config system admin edit admin set password YourStrongPassword next end # ========================= # DNS SERVERS # ========================= config system dns set primary 8.8.8.8 set secondary 1.1.1.1 end # ========================= # TIMEZONE # ========================= config system global set timezone 75 end # ========================= # NTP # ========================= config system ntp set status enable set server-mode disable end # ========================= # WAN INTERFACE # ========================= config system interface edit wan1 set ip 203.0.113.2 255.255.255.252 set allowaccess ping https ssh next end # ========================= # DEFAULT ROUTE # ========================= config router static edit 1 set gateway 203.0.113.1 set device wan1 next end # ========================= # LAN INTERFACE # ========================= config system interface edit internal set ip 192.168.1.1 255.255.255.0 set allowaccess ping https ssh next end # ========================= # DHCP SERVER # ========================= config system dhcp server edit 1 set interface internal set default-gateway 192.168.1.1 set netmask 255.255.255.0 set dns-service default config ip-range edit 1 set start-ip 192.168.1.100 set end-ip 192.168.1.200 next end next end # ========================= # FIREWALL POLICY # LAN -> INTERNET # ========================= config firewall policy edit 1 set srcintf internal set dstintf wan1 set srcaddr all set dstaddr all set action accept set schedule always set service ALL set nat enable next end # ========================= # ENABLE PING TO WAN # ========================= config system interface edit wan1 set allowaccess ping next end # ========================= # SAVE CONFIG # ========================= execute backup config flash =============== Daily Troubleshooting Commands ============== get system status get hardware status get system performance status get router info routing-table all show system interface show firewall policy diagnose sys top diagnose hardware deviceinfo nic execute ping 8.8.8.8 execute traceroute 8.8.8.8 diagnose debug enable diagnose debug flow show console enable diagnose debug flow filter addr diagnose debug flow trace start 100 execute ping 8.8.8.8 execute ping google.com get router info routing-table all Backup Configuration: execute backup config tftp backup.conf 192.168.1.10 Restore Configuration: execute restore config tftp backup.conf 192.168.1.10 Show Factory Defaults: show full-configuration