Skip to main content
AD Academy
Network security: Fortinet
Advanced16 minLast updated: Topic 12 of 14

A network view of the course attacks — what Fortinet adds

What the network layer sees versus DC logs, and how segmentation limits lateral movement.

Not read

What you will learn here

  • Related topics in this course
  • What the network layer adds
  • Lab practice

Worth reading first:802.1X and NAC — only authenticated devices get in

So far detection in this course lives on hosts and domain controllers: Event IDs, Sigma, Microsoft Defender for Identity. That is the right foundation, but it has two limits — a host can be turned off and logs can be cleared. The network layer sees differently: packets do not care whether the DC log is clean.

Related topics in this course

  • Event IDs and Sigma cover DC detection; the network layer backs it up when logs are cleared.
  • , and each leave distinct network traces (bursts of requests, replication from an unexpected host, odd hours).
  • Defender for Identity complements : identity versus traffic, two independent sources.

What the network layer adds

  • / AS-REP Roasting: from the network this is an anomalous profile — many requests (port 88) from one host to many services in a short window. FortiGate/ see the spike and help correlate, but precise detection (the RC4 anomaly) comes from 4769 plus Sigma/MDI. The network gives context, the host gives precision.
  • and coercion (PetitPotam, PrinterBug): here the network is the first line — relay lives on SMB/RPC between hosts. FortiGate segmentation limits who a workstation may speak SMB with; catches LSASS dump attempts on the host.
  • Credential dumping (mimikatz): is behavioural control — LSASS access from an unsigned process, injections, token creation. It complements rather than replacing it.
  • East-west lateral movement: the network's strongest suit. FortiGate knows who ( group) and where (VLAN/segment) and can cut movement with rules like "Tier 2 hosts do not speak SMB/RDP/WinRM to Tier 0/1" — tiering enforced on the firewall.
  • Endpoint management: is deployed via synced with (AD groups → FortiClient policies): who gets EDR, who gets VPN — by group membership.

Lab practice

Tier-based segmentation with groups. Create interfaces/VLANs: Workstations, Servers-T1, Infra-T0, then deny SMB/RDP/WinRM from workstations to servers and infrastructure:

config firewall policy
    edit 30
        set srcintf "Workstations"
        set dstintf "Servers-T1" "Infra-T0"
        set srcaddr "all"
        set dstaddr "all"
        set action deny
        set service "SMB" "RDP" "WINRM"
        set schedule "always"
    next
end
bash

Separate rules allow the required ports only from defined admin segments. Deploy via : Administration → Connectors → , a policy for CN=Workstations, and MSI installation through :

msiexec /i FortiClient.msi /quiet
powershell

If is available, collect FortiGate traffic logs alongside FAC logs and build a " spikes (88/TCP-UDP) per host" report. Next to the 4769 report from the it gives the full picture.

Risks and detection

  • The network cannot see inside encryption: is encrypted and FortiGate will not replace 4769 analysis. Do not promise a magic box — promise layers.
  • in policy means dependence on : after a compromise the group map lies. Restrict sensitive segments by IP as well.
  • is not : EDR reacts to behaviour, Credential Guard architecturally blocks hash reads. Both together is the right answer.

Mitigation

  • Default policy between segments is deny; allow rules are surgical.
  • Send FortiGate/FAC/ logs to one place (/) with correlation rules against the course Event IDs.
  • Test policies regularly: "can the accounting workstation reach the DC over SMB?" — the answer must be deny.

Check yourself

Which of the course attacks does the network layer detect best?

What does combining FSSO groups with segmentation give the tiering model?

How does FortiEDR complement Credential Guard in protecting LSASS?

Why does FortiGate not replace 4769 analysis for Kerberoasting?

Was this page helpful?