Where NOC work leaves gaps
If your day job is watching FortiGates but not building them, these are the topics you've never actually configured — spend extra time here.
- FSSO — you've seen it work, never stood it up
- NGFW policy-based mode — a config style you've probably never touched
- Central NAT — most shops use policy NAT
- Redundant & meshed IPsec — beyond a single tunnel
Build two phase 1s, one per WAN path, each with its own tunnel interface.
- SD-WAN rules, performance SLAs, and rule vs route interaction
Building blocks: zones → members (interfaces) → performance SLAs → rules.
- Building the SSL inspection CA chain and the exemption list
The default re-signing CA is Fortinet_CA_SSL. If the server's certificate is invalid, FortiGate re-signs with Fortinet_CA_Untrusted instead