FortiGate TRAINING SIMULATOR
FGT-LAB-01
FortiOS 7.6.x simulation
● FortiGuard Services Available

Dashboard › Status

System health and operational overview

CPU
14%
Current utilization
Memory
42%
1.72 GB / 4.00 GB
Sessions
3,842
of 1,500,000 maximum
Threats Blocked 24h
287
IPS · AV · Web · DNS
System Information FGT-LAB-01
HostnameFGT-LAB-01
Serial NumberFGVM-LAB-DEMO
FirmwareFortiOS v7.6.x (simulated)
System Time
Uptime12 days, 04:31:18
Operation ModeNAT
NGFW ModeProfile-based
Licenses & Services
FortiCare SupportValid
IPS DefinitionsUp to date
AntiVirusUp to date
Web FilteringAvailable
FortiSandbox CloudEvaluation
Application ControlUp to date
Security Fabric Topology
FGT-LAB-01FortiGate LAN24 devices WANOnline
Bandwidth Last 5 minutes
↓ 182.4 Mbps↑ 37.8 MbpsPeak 241 Mbps
Interface Bandwidth
wan1
66%
lan
42%
DMZ
18%
VPN
26%

FortiView › Sources

Traffic analytics and visibility

Traffic Over Time Bytes / second
Top Applications
HTTPS 44%YouTube 20%Microsoft 365 17%DNS 10%Other 9%
Top Sources
SourceDeviceSessionsBandwidthThreats
192.168.10.41STUDENT-PC-074283.81 GB0
192.168.10.22LAB-WS-023172.96 GB2
192.168.10.15INSTRUCTOR2442.11 GB0
192.168.20.11LAB-SERVER1981.83 GB5

Network › Interfaces

Physical and logical network interfaces

Network › SD-WAN

Members, zones, health checks, and steering rules

wan1
12 ms
Latency
Packet loss0.0%
Jitter1.8 ms
StatusAlive
wan2
27 ms
Latency
Packet loss0.2%
Jitter4.2 ms
StatusAlive
SLA Health
100%
2 of 2 members meet SLA
PriorityNameSourceDestinationStrategyPreferred MembersStatus
1Voice-PriorityVoice_VLANallLowest latencywan1, wan2Enabled
2Default-InternetallallMaximize bandwidthwan1, wan2Enabled

Network › Static Routes

IPv4 routing table configuration

DestinationGatewayInterfaceDistancePriorityStatus

Network › DNS

System DNS and DNS-over-TLS settings

DNS Servers

Network › DHCP Server

Address assignment scopes and leases

InterfaceGatewayNetmaskRangeDNSLease TimeStatus
lan192.168.10.1255.255.255.0192.168.10.100 - 192.168.10.220System DNS86400 sEnabled
Guest192.168.30.1255.255.255.0192.168.30.50 - 192.168.30.200System DNS14400 sEnabled

Policy & Objects › Firewall Policy

IPv4 traffic policies evaluated from top to bottom

IDStatusNameIncomingOutgoingSourceDestinationServiceActionNATSecurity ProfilesBytes
Simulator behavior: policy matching follows interface, source, destination, service, and schedule logic. Unmatched simulated traffic is treated as implicitly denied.

Policy & Objects › Addresses

Reusable IPv4/IPv6 hosts, subnets, ranges, FQDNs, and groups

NameTypeAddressInterfaceReferences

Policy & Objects › Services

Predefined and custom protocol/port definitions

NameCategoryProtocolDestination Port
HTTPWeb AccessTCP80
HTTPSWeb AccessTCP443
DNSNetwork ServicesTCP/UDP53
SSHRemote AccessTCP22
RDPRemote AccessTCP3389
ALL_ICMPGeneralICMP—

Policy & Objects › Virtual IPs

Destination NAT and port-forwarding objects

NameInterfaceExternal IPMapped IPPort ForwardingReferences
WEB-SERVER-VIPwan1203.0.113.50192.168.20.10TCP 443 → 4431
LAB-SSH-VIPwan1203.0.113.51192.168.20.15TCP 2222 → 220

Policy & Objects › Central SNAT

Centralized source NAT rules

Central SNAT is typically used when central NAT is enabled. In FortiOS policy-based NGFW mode, central NAT is enabled and source NAT is defined separately from the security policy.
IDIncomingOutgoingSourceDestinationNATStatus
1lanwan1LAN-NETallUse outgoing interface addressEnabled

VPN › IPsec Tunnels

Site-to-site and remote-access IPsec VPN configuration

NameGatewayPhase 1Phase 2InterfaceBytes InBytes OutStatus
Branch-HQ198.51.100.20AES256 / SHA256 / DH14AES256 / SHA256wan11.31 GB844 MBUp
DR-Site198.51.100.89AES256 / SHA256 / DH14AES256 / SHA256wan20 B0 BDown

VPN › SSL-VPN Settings

Remote access portal, authentication, and tunnel settings

SSL-VPN Configuration

VPN › Monitor

Active IPsec and SSL-VPN sessions

TypeName/UserRemote GatewayAssigned IPDurationBytesStatus
IPsecBranch-HQ198.51.100.20—4d 03:142.15 GBUp
SSL-VPNstudent.lab203.0.113.9110.212.134.1200:31:42214 MBConnected

User & Authentication › User Definition

Local users and remote authentication sources

UserTypeTwo-factorEmailStatus
student.labLocalDisabled[email protected]Enabled
lab-adminsLDAPRemote—Enabled

User & Authentication › User Groups

Group membership for authentication policies and VPN portals

NameTypeMembersReferences
SSLVPN-StudentsFirewallstudent.lab2
Network-AdminsFirewalllab-admins1

Log & Report › Forward Traffic

Simulated session logs for allowed and denied traffic

Date/TimeSourceDestinationServiceActionPolicy IDApplicationBytes

Log & Report › Security Events

IPS, antivirus, web filter, DNS filter, and application events

Date/TimeSeveritySecurity ActionSourceDestinationEventProfile
2026-09-27 18:02:51WarningBlocked192.168.10.22203.0.113.99Suspicious URL categorydefault-webfilter
2026-09-27 17:48:09CriticalReset198.51.100.66192.168.20.10IPS signature match (training event)protect_servers
2026-09-27 17:32:18NoticeMonitor192.168.10.41142.250.0.1Streaming.Mediastudent-app-control

Log & Report › System Events

Administrator, routing, VPN, HA, and configuration events

Date/TimeSeverityEventMessage
2026-09-27 18:05:12InformationAdmin loginAdministrator admin logged in from 192.168.10.15
2026-09-27 17:55:22NoticeConfigurationFirewall policy configuration changed
2026-09-27 16:41:07InformationVPNIPsec phase 1 negotiation completed for Branch-HQ

Log & Report › Log Settings

Local, FortiAnalyzer, FortiCloud, and syslog targets

Local Log
Disk logging
Event logging
Local traffic
Remote Logging
FortiAnalyzerNot Configured
FortiCloudConnected
Syslog192.168.20.50

System › Administrators

Administrative accounts and access profiles

AdministratorTypeAdmin ProfileTrusted HostsTwo-factorLast Login
adminLocalsuper_admin192.168.10.0/24DisabledNow
helpdeskLocalread_only192.168.10.0/24Enabled2 days ago

System › High Availability

FortiGate Clustering Protocol simulation

HA Configuration
Cluster Members
This simulator currently runs in standalone mode. Change the mode to explore HA settings without affecting any real device.

System › Certificates

Local certificates, CA certificates, and signing requests

NameTypeSubjectIssuerExpires
Fortinet_FactoryLocalFGT-LAB-01Fortinet Factory CA2035-01-01
lab-certLocalfirewall.lab.localLab Root CA2027-09-27

System › Firmware & Registration

Firmware information, upgrades, and configuration backups

Firmware
7.6.x
Training build

This browser simulator does not install firmware. Upgrade controls are simulated.

Configuration

Save or restore the simulator's local browser state.

System › Settings

Administrative, hostname, session, and feature settings

Training › Lab Center

Hands-on tasks that use the same simulator state as the GUI and CLI

Nothing here touches a real FortiGate. Student changes are stored only in this browser using localStorage. Complete tasks in the GUI or simulated CLI, then use Check Lab.
CLI Console — FGT-LAB-01simulation
FortiGate Training Simulator FGT-LAB-01 login: admin Welcome to the FortiOS CLI simulator. Type ? or help for supported commands.
FGT-LAB-01 #