What you'll learn:
- Introduction to Web Application Security
- FortiWeb Configuration and Administration
- Configuring SSL offloading and inspection
- Performance Optimization
- Configure server pools, policies, and protected host names
- Build and configure a lab environment for FortiWeb step by step.
- Understand the fundamental concepts of Web Application Firewalls (WAF).
- Configure Content Routing
- Protect against DoS/DDoS attacks.
- Control traffic flow with Redirects & Rewrites.
- Control traffic flow with Redirects & Rewrites.
- Enable Bot Protection to stop malicious automated activities.
- Deploy FortiWeb in EVE‑NG and configure it for real web apps.
- Implement SSL offloading, load balancing, persistence, and health checks.
- Protect against common web vulnerabilities
- Configure Signatures — built‑in and custom signatures
- Configure Virtual Server, VIPs, and Server Pool
- Web App Vulnerabilities & Protection
Course Description:
Master Fortinet FortiWeb WAF administration with hands-on labs in EVE‑NG and learn how to secure web applications and APIs against real-world threats. This course takes you step by step through deployment, configuration, tuning, and advanced web protection techniques.
You’ll start by setting up FortiWeb in EVE‑NG, adding virtual images, configuring servers and clients, and importing labs. From there, you’ll dive into core WAF concepts, including server policies, virtual servers, VIPs, server pools, and web protection profiles.
Learn how to protect web applications from vulnerabilities such as SQL injection, XSS, CSRF, command injection, file uploads, and web shells. You’ll also configure SSL offloading, load balancing, persistence, content routing, and HTTP rewriting to optimize traffic and improve security.
Advanced sections cover DoS/BOT protection, API gateway security, JSON schema validation, and access control, giving you the practical skills to defend any web application or API. Each module includes realistic labs, testing, verification, and troubleshooting exercises.
By the end of this course, you will be able to confidently deploy, configure, and manage FortiWeb WAFs to protect web applications, detect attacks, and ensure high availability and performance.
Who this course is for:
Network and security engineers seeking hands-on WAF experience.
Penetration testers and ethical hackers wanting to understand WAF deployment and tuning.
DevOps and application security professionals securing web apps and APIs.
IT professionals and system administrators enhancing web traffic monitoring and threat protection skills.
Requirements:
Basic networking knowledge (IP, routing, VLANs).
Understanding of web servers, HTTP/HTTPS, and web application basics.
A PC capable of running virtual labs (EVE‑NG, VMware, or VirtualBox).
Familiarity with Fortinet products, Linux/Windows server administration, or security tools like OWASP ZAP or Burp Suite.
What You Will Learn
Deploy FortiWeb in Reverse Proxy, Transparent, and WCCP modes
Configure Web Protection, API Security, and Advanced Threat Defense
Implement Signature-based, Behavior-based, and Machine Learning security models
Protect applications against OWASP Top 10, SQLi, XSS, CSRF, RCE, and more
Configure DoS protection, Bot mitigation, and Geo‑IP controls
Build and tune Custom Rules, URL Access Policies, and Parameter Validation
Analyze logs, investigate attacks, and perform real‑world troubleshooting
Apply best practices for production‑grade WAF deployments
Why This Course Stands Out
Hands‑on labs for every major FortiWeb feature
Real configurations, not theory or slides
Clear, simple explanations — ideal for beginners and professionals
Professional, concise delivery aligned with your teaching style
Downloadable configs, diagrams, and cheat sheets
Lifetime access + regular updates based on new FortiWeb releases