🔥

Deploy a Virtual FortiGate Firewall on Proxmox VE

SimGym Lab Guide · Build Simulation · Network Security / Virtualization
Build Difficulty 2 / 5 ⏱ 2–3 Hours Network Security Firewall Admin Virtualization

Lab Overview

ℹ️
Simulation Context

The network security team requires a virtual FortiGate firewall on the Proxmox VE hypervisor to support lab and testing requirements. You will provision the VM from scratch, configure first-boot settings, and verify management access — the foundational step before any firewall policy work can begin.

🎯 What You Will Build

  • Upload or locate a FortiGate .qcow2 image on the Proxmox host
  • Create a QEMU VM with correct CPU, RAM, and disk sizing
  • Import the vendor disk image as the primary boot disk
  • Attach two virtual NICs mapped to Proxmox Linux bridges
  • Complete FortiOS first-boot setup via the Proxmox noVNC console
  • Assign a management IP, change the admin password, and activate the evaluation license
  • Verify HTTPS GUI access and document the asset record

📋 Service Request Summary

Request Type: Build

Domain: Network Security · Virtualization · Firewall Administration

Estimated Time: 2–3 hours

Difficulty: 2 / 5


FortiGate FortiOS Proxmox VE QEMU/KVM Firewall VM Deployment Fortinet Network Security

Learning Objectives

Navigate the Proxmox VE web UI to create and configure a new QEMU virtual machine
Import a vendor-supplied .qcow2 disk image as a bootable VM disk
Correctly size a virtual machine for a network security appliance workload
Attach and map virtual network interfaces to Proxmox Linux bridges
Complete FortiOS first-boot setup including password change and management IP assignment
Activate a FortiGate VM evaluation license and verify licensing status
Access and navigate the FortiGate web GUI after successful deployment
Document virtual appliance build details in an ITSM asset record

Address Plan

⚠️
Locked Address Table — Do Not Modify

These addresses are locked in the simulation inventory. Use them exactly as shown. Do not renumber existing 192.168.128.0/23 hosts. Management IPs for cloud-adapter devices are on 10.10.0.0/17, gateway 10.10.0.254.

Hostname Type / Role Management IP Subnet Gateway VLAN Notes
proxmox Hypervisor 192.168.128.191 192.168.128.0/23 — — Existing Proxmox VE host. Inventory: wssesxihost.191.wss.local
fortigate-vm01 Firewall (VM) 10.10.0.6 10.10.0.0/17 10.10.0.254 — FortiGate VM created during this lab. port1 = management/WAN bridge, port2 = LAN bridge. GNS3 overlay: 172.31.1.1/24

Follow-On Scenarios

🚀
After completing this lab, continue your learning with:
  • Configure FortiGate WAN and LAN interfaces with production IP addressing and default route
  • Create basic security policies permitting outbound LAN-to-WAN traffic with NAT
  • Enable and configure FortiGate SSL inspection and web filtering profiles
  • Connect the FortiGate VM to a GNS3 topology to simulate a multi-site network environment
  • Register and manage the FortiGate instance in FortiManager for centralized policy management
  • Configure site-to-site IPsec VPN between two virtual FortiGate instances on Proxmox