Skip to main content
AD Academy
Network security: Fortinet
Beginner18 minLast updated: Topic 1 of 14

Infrastructure security devices

Defense in depth, L2/L3/L7 and the CIA triad.

Not read

What you will learn here

  • Component map
  • Practice: topology and CIA
  • Risks and detection

A modern network is more than a router and a switch. Defense in Depth uses different security layers so one failed control does not bring down the entire defense.

Component map

  • Switch (L2): VLANs separate traffic; , and reduce unauthorized connections, rogue DHCP and ARP spoofing; authenticates the port.
  • Router (L3): an ACL filters by source/destination address and port, but it does not remember connection state or understand application content.
  • A load balancer provides availability by distributing traffic; a proxy acts on behalf of LAN clients and enables centralized web policy.
  • A VPN server provides site-to-site IPsec or encrypted remote access. A protects layer 7 web applications and inspects HTTP against OWASP Top 10 threats.
  • URL filtering, application control, DLP and anti-malware inspect applications and content. combines several capabilities in one appliance — a trade-off between simplicity and depth.
  • A mail gateway in the DMZ filters spam and inspects SMTP, reverse DNS and content while keeping the internal mail server hidden.

Practice: topology and CIA

Draw a DC, workstations and a FortiGate. For each component, mark L2/L3/L7, which attack it stops, which it does not, and which part of confidentiality, integrity and availability it supports. For example, blocks an unknown device but not already running inside.

Risks and detection

  • “We have a firewall, so we are protected” is a mistake: a perimeter firewall does not necessarily stop internal , or .
  • An unconfigured component is not a defense. Verify that , and are enabled, and design VLANs by risk level rather than department alone.
  • Only the mail gateway should be exposed in the DMZ; the internal mail server stays hidden.

Mitigation and related topics

  • Give every layer a clear role; no single box solves everything.
  • Quarterly, verify , VLAN mappings and mail reverse DNS.
  • Related topics: , Fortinet detection layers and tiering.

Check yourself

Which component provides separation that contains internal network spread?

What is the main difference between a router ACL and a stateful firewall?

Why is a mail gateway placed in the DMZ?

Which component primarily supports availability?

Was this page helpful?