Lab Overview
The network security team requires a virtual FortiGate firewall on the Proxmox VE hypervisor to support lab and testing requirements. You will provision the VM from scratch, configure first-boot settings, and verify management access — the foundational step before any firewall policy work can begin.
🎯 What You Will Build
- Upload or locate a FortiGate
.qcow2image on the Proxmox host - Create a QEMU VM with correct CPU, RAM, and disk sizing
- Import the vendor disk image as the primary boot disk
- Attach two virtual NICs mapped to Proxmox Linux bridges
- Complete FortiOS first-boot setup via the Proxmox noVNC console
- Assign a management IP, change the admin password, and activate the evaluation license
- Verify HTTPS GUI access and document the asset record
📋 Service Request Summary
Request Type: Build
Domain: Network Security · Virtualization · Firewall Administration
Estimated Time: 2–3 hours
Difficulty: 2 / 5
Learning Objectives
.qcow2 disk image as a bootable VM diskAddress Plan
These addresses are locked in the simulation inventory. Use them exactly as shown. Do not renumber existing 192.168.128.0/23 hosts. Management IPs for cloud-adapter devices are on 10.10.0.0/17, gateway 10.10.0.254.
| Hostname | Type / Role | Management IP | Subnet | Gateway | VLAN | Notes |
|---|---|---|---|---|---|---|
| proxmox | Hypervisor | 192.168.128.191 |
192.168.128.0/23 |
— | — | Existing Proxmox VE host. Inventory: wssesxihost.191.wss.local |
| fortigate-vm01 | Firewall (VM) | 10.10.0.6 |
10.10.0.0/17 |
10.10.0.254 |
— | FortiGate VM created during this lab. port1 = management/WAN bridge, port2 = LAN bridge. GNS3 overlay: 172.31.1.1/24 |
Follow-On Scenarios
- Configure FortiGate WAN and LAN interfaces with production IP addressing and default route
- Create basic security policies permitting outbound LAN-to-WAN traffic with NAT
- Enable and configure FortiGate SSL inspection and web filtering profiles
- Connect the FortiGate VM to a GNS3 topology to simulate a multi-site network environment
- Register and manage the FortiGate instance in FortiManager for centralized policy management
- Configure site-to-site IPsec VPN between two virtual FortiGate instances on Proxmox
Network Topology
🌉 Proxmox Linux Bridges
| Bridge | Purpose | FortiGate Port | Segment |
|---|---|---|---|
vmbr10 |
WAN / Management | port1 |
10.10.0.0/17 |
vmbr20 |
Internal LAN | port2 |
172.31.1.0/24 |
🖥 VM Resource Allocation
| Resource | Minimum | Recommended |
|---|---|---|
| vCPU | 1 | 2 |
| RAM | 1 024 MB | 2 048 MB |
| Boot Disk | 2 GB (.qcow2) | 2 GB (.qcow2) |
| NICs | 2 × VirtIO / E1000 | 2 × VirtIO |
| Machine Type | pc-i440fx or q35 (check Fortinet matrix) | |
This introductory build focuses entirely on hypervisor provisioning and FortiOS initial setup. No upstream or downstream devices are connected during this lab. The management workstation reaches fortigate-vm01 on 10.10.0.6 via the vmbr10 bridge on the management network. A follow-on lab will connect the FortiGate to a GNS3 topology.
Prerequisites
The lab administrator should run the provisioning script to verify resources and create the bridges. The learner must confirm access to the Proxmox web UI and the FortiGate image before proceeding.
Knowledge Prerequisites
Required Knowledge
- Basic familiarity with the Proxmox VE web interface (logging in, navigating nodes and VMs)
- Understanding of virtual machine concepts — vCPU, RAM, virtual disks, virtual NICs
- Basic understanding of Linux bridging and virtual networking
- Awareness of firewall concepts (WAN vs. LAN interfaces, management access)
- Ability to use a CLI console for basic command entry
Access Requirements
- Proxmox VE web UI credentials with VM creation privileges
- HTTPS access to
https://192.168.128.191:8006 - Fortinet Support Portal account or a pre-downloaded FortiGate VM image
- Evaluation or trial license for FortiGate VM
- Management workstation with modern browser
Lab Administrator — Pre-Lab Setup Script
Run the script below on the Proxmox host shell. It verifies resources, ensures vmbr10 and vmbr20 exist, and imports the FortiGate disk image into local storage. It does not create the VM — that step is left for the learner.
#!/usr/bin/env bash # ============================================================ # setup-virtual-fortigate-proxmox.sh # Lab Administrator Pre-provisioning Script # Platform : Proxmox VE Shell (Bash) # Purpose : Verify host resources, create Linux bridges, # and import the FortiGate .qcow2 disk image. # Does NOT create the VM — learner does that step. # Run as : root on the Proxmox node shell # ============================================================ # ── Configurable Variables ─────────────────────────────────── FORTIGATE_IMAGE="/var/lib/vz/template/iso/FGT_VM64_KVM.qcow2" STORAGE_POOL="local-lvm" # Target storage pool for disk import RESERVED_VMID="200" # VM ID reserved for learner's FortiGate VM BRIDGE_WAN="vmbr10" # WAN / Management bridge BRIDGE_LAN="vmbr20" # Internal LAN bridge MIN_FREE_MEM_MB=2048 # Minimum free RAM required (MB) MIN_FREE_DISK_GB=10 # Minimum free disk space required (GB) LOG="/var/log/simgym-fortigate-setup.log" # ── Logging Helper ────────────────────────────────────────── log() { echo "[$(date '+%Y-%m-%d %H:%M:%S')] $*" | tee -a "$LOG"; } err() { log "ERROR: $*"; exit 1; } log "=== SimGym FortiGate Pre-lab Setup START ===" # ── 1. Prerequisite Checks ────────────────────────────────── log "Checking required tools..." for cmd in qm pvesm ip grep awk free df; do command -v "$cmd" &>/dev/null || err "Required command not found: $cmd" done log "All required tools present." # ── 2. Verify FortiGate Image Exists ──────────────────────── log "Checking for FortiGate image at: $FORTIGATE_IMAGE" [ -f "$FORTIGATE_IMAGE" ] || err "FortiGate .qcow2 image not found at $FORTIGATE_IMAGE. Download from https://support.fortinet.com and place at the path above." log "FortiGate image found: $(du -sh "$FORTIGATE_IMAGE" | cut -f1)" # ── 3. Check Free Memory ──────────────────────────────────── FREE_MEM=$(free -m | awk '/^Mem:/{print $7}') log "Available memory: ${FREE_MEM} MB (minimum required: ${MIN_FREE_MEM_MB} MB)" [ "$FREE_MEM" -ge "$MIN_FREE_MEM_MB" ] || \ err "Insufficient free memory. ${FREE_MEM} MB available, ${MIN_FREE_MEM_MB} MB required." # ── 4. Check Free Disk Space ───────────────────────────────── FREE_DISK=$(df -BG /var/lib/vz | awk 'NR==2{gsub("G",""); print $4}') log "Available disk: ${FREE_DISK} GB (minimum required: ${MIN_FREE_DISK_GB} GB)" [ "$FREE_DISK" -ge "$MIN_FREE_DISK_GB" ] || \ err "Insufficient disk space. ${FREE_DISK} GB available, ${MIN_FREE_DISK_GB} GB required." # ── 5. Create vmbr10 (WAN/Management) if missing ──────────── if ip link show "$BRIDGE_WAN" &>/dev/null; then log "Bridge $BRIDGE_WAN already exists — skipping creation." else log "Creating Linux bridge: $BRIDGE_WAN (WAN/Management)" ip link add name "$BRIDGE_WAN" type bridge ip link set "$BRIDGE_WAN" up log "$BRIDGE_WAN created and brought up." log "NOTE: Persist this bridge in /etc/network/interfaces for reboot survival." fi # ── 6. Create vmbr20 (Internal LAN) if missing ────────────── if ip link show "$BRIDGE_LAN" &>/dev/null; then log "Bridge $BRIDGE_LAN already exists — skipping creation." else log "Creating Linux bridge: $BRIDGE_LAN (Internal LAN)" ip link add name "$BRIDGE_LAN" type bridge ip link set "$BRIDGE_LAN" up log "$BRIDGE_LAN created and brought up." log "NOTE: Persist this bridge in /etc/network/interfaces for reboot survival." fi # ── 7. Check VM ID availability ────────────────────────────── if qm status "$RESERVED_VMID" &>/dev/null; then err "VM ID $RESERVED_VMID is already in use. Free it before running this script." fi log "VM ID $RESERVED_VMID is available." # ── 8. Import Disk Image into Proxmox Storage ──────────────── log "Importing FortiGate disk image into storage pool: $STORAGE_POOL under VM ID $RESERVED_VMID" qm importdisk "$RESERVED_VMID" "$FORTIGATE_IMAGE" "$STORAGE_POOL" --format qcow2 \ 2>&1 | tee -a "$LOG" || err "Disk import failed. Check log at $LOG." log "Disk import complete. The learner will attach this disk when creating the VM." # ── 9. Post-Setup Validation ───────────────────────────────── log "--- Validation ---" log "Bridge $BRIDGE_WAN state : $(ip link show $BRIDGE_WAN | grep -o 'state [A-Z]*')" log "Bridge $BRIDGE_LAN state : $(ip link show $BRIDGE_LAN | grep -o 'state [A-Z]*')" log "Imported disk location : $(pvesm list $STORAGE_POOL | grep "vm-${RESERVED_VMID}" || echo 'Check storage manually')" log "=== Setup COMPLETE. Learner may now begin the lab. ===" # ── Teardown Instructions ───────────────────────────────────── # To clean up after the lab: # qm destroy 200 # Remove VM (after learner finishes) # pvesm free local-lvm:vm-200-disk-0 # Free imported disk # ip link del vmbr10 # Remove WAN bridge (if created by script) # ip link del vmbr20 # Remove LAN bridge (if created by script) # rm -f /var/log/simgym-fortigate-setup.log # ─────────────────────────────────────────────────────────────
Pre-Lab Checklist
-
Proxmox web UI is accessible Open a browser and navigate to
https://192.168.128.191:8006. Confirm you can log in with your Proxmox credentials and see the node in the left-hand tree. -
FortiGate image is present on the host The lab administrator should confirm the
.qcow2file is at the path used in the provisioning script. If using a.vmdk, convert it first:qemu-img convert -f vmdk FGT.vmdk -O qcow2 FGT.qcow2 -
Linux bridges are ready In the Proxmox web UI, go to Node → System → Network. Confirm
vmbr10andvmbr20appear in the list with type Linux Bridge. -
Evaluation license is available Log in to support.fortinet.com and confirm access to a FortiGate VM evaluation license, or verify with your lab administrator that a license has been pre-staged.
-
VM ID reserved Confirm that VM ID
200is not currently in use. In the Proxmox web UI, scroll the left-hand tree and verify no VM with that ID exists.
Configuration
Ensure the lab administrator has run the provisioning script and all pre-lab checklist items are confirmed before starting here.
Create the FortiGate VM in Proxmox
-
Log in to the Proxmox Web UI Open your browser and navigate to
https://192.168.128.191:8006. Log in with your Proxmox credentials. Select your node in the left-hand resource tree (e.g., pve). -
Start the Create VM Wizard Click the Create VM button in the top-right corner. The New Virtual Machine wizard will open.
-
General Tab — Set VM ID and Name
- Node: your Proxmox node
- VM ID:
200(reserved) - Name:
fortigate-vm01
-
OS Tab — No ISO Media Select Do not use any media. We will attach the imported
.qcow2disk manually after the wizard completes. Set Guest OS Type to Linux, version 6.x - 2.6 Kernel. Click Next. -
System Tab — Machine Type
- BIOS: SeaBIOS (default)
- Machine: pc-i440fx (recommended; check the Fortinet VM compatibility matrix for your FortiOS version)
- SCSI Controller: VirtIO SCSI
-
Disks Tab — Remove the Default Disk Delete the pre-created disk by clicking the 🗑 delete icon. We will attach the imported FortiGate image after the wizard. Click Next.
-
CPU Tab — Assign vCPUs
- Sockets: 1
- Cores: 2 (minimum 1)
- Type: host (best performance) or kvm64
-
Memory Tab — Assign RAM Set Memory (MiB) to
2048(minimum1024). Uncheck Ballooning Device for consistent FortiOS performance. Click Next. -
Network Tab — Add port1 (Management / WAN)
- Bridge:
vmbr10 - Model: VirtIO (paravirt) or E1000
- Uncheck Firewall (managed by FortiOS)
- Bridge:
-
Confirm and Finish — Uncheck Start After Created Review the summary. Uncheck "Start after created" — we need to attach the disk first. Click Finish.
Attach the FortiGate Disk Image and Second NIC
-
Attach the Imported .qcow2 Disk In the Proxmox web UI, select VM 200 → Hardware → Add → Hard Disk. Alternatively, if the disk was already imported via the provisioning script, select Unused Disk 0 from the Hardware list and click Edit to add it as the primary boot disk.
- Bus/Device: VirtIO Block or IDE — confirm against the Fortinet VM guide for your FortiOS version
- Storage:
local-lvm - Leave disk size as imported (typically 2 GB)
ℹ️Alternative: Import via Proxmox ShellIf the disk was not pre-imported by the admin script, run this command on the Proxmox host shell:
Proxmox Shellroot@pve:~# qm importdisk 200 /var/lib/vz/template/iso/FGT_VM64_KVM.qcow2 local-lvm --format qcow2
-
Set Boot Order Go to VM 200 → Options → Boot Order. Enable the imported disk and move it to the top of the boot list. Disable network boot (PXE) if listed.
-
Add port2 (Internal LAN NIC) Go to VM 200 → Hardware → Add → Network Device.
- Bridge:
vmbr20 - Model: VirtIO (paravirt) or E1000
- Uncheck Firewall
net0→vmbr10andnet1→vmbr20. - Bridge:
-
Verify Hardware Summary Before booting, confirm the VM 200 Hardware tab shows:
- ✅ 2 vCPU (Sockets: 1, Cores: 2)
- ✅ 2 048 MiB RAM, Ballooning off
- ✅ Boot disk:
local-lvm:vm-200-disk-0 - ✅ Network Device 0:
vmbr10(port1) - ✅ Network Device 1:
vmbr20(port2)
First Boot and FortiOS Console Setup
-
Start the VM and Open the Console Click Start on VM 200. Then click Console to open the Proxmox noVNC console. Wait for FortiOS to boot — this typically takes 60–90 seconds. You should see the FortiOS login prompt.✅Expected Output
You should see:
FortiGate-VM64 login:at the console. If you see BIOS errors or a boot loop, revisit the boot order and disk attachment settings. -
Log In with Default CredentialsFortiOS will prompt you to set a new password immediately.FortiOS Console — First Login
FortiGate-VM64 login: admin Password: (press Enter — no password on first boot)
-
Set the Admin PasswordFortiOS Console
You are forced to change your password. Please input a new password. New Password: YourSecurePass123! Confirm Password: YourSecurePass123!
⚠️Password PolicyFortiOS requires a minimum 8-character password including uppercase, lowercase, and a number or symbol. Record your password in the ITSM asset record.
-
Assign Management IP to port1 Configure
port1with the management IP address from the locked address table:FortiOS CLI — port1 Management IPfortigate-vm01 # config system interface fortigate-vm01 (interface) # edit port1 fortigate-vm01 (port1) # set mode static fortigate-vm01 (port1) # set ip 10.10.0.6 255.255.128.0 fortigate-vm01 (port1) # set allowaccess https ssh ping fortigate-vm01 (port1) # set description "Management-WAN" fortigate-vm01 (port1) # next fortigate-vm01 (interface) # end
-
Configure port2 for Internal LANFortiOS CLI — port2 LAN IP
fortigate-vm01 # config system interface fortigate-vm01 (interface) # edit port2 fortigate-vm01 (port2) # set mode static fortigate-vm01 (port2) # set ip 172.31.1.1 255.255.255.0 fortigate-vm01 (port2) # set allowaccess ping fortigate-vm01 (port2) # set description "Internal-LAN" fortigate-vm01 (port2) # next fortigate-vm01 (interface) # end
-
Set the Default GatewayFortiOS CLI — Default Route
fortigate-vm01 # config router static fortigate-vm01 (static) # edit 1 fortigate-vm01 (1) # set device port1 fortigate-vm01 (1) # set gateway 10.10.0.254 fortigate-vm01 (1) # next fortigate-vm01 (static) # end
-
Set HostnameFortiOS CLI — Hostname
fortigate-vm01 # config system global fortigate-vm01 (global) # set hostname fortigate-vm01 fortigate-vm01 (global) # end
License Activation
FortiGate VMs require a valid license to pass traffic. An evaluation license provides full features for a limited trial period. Without a license, the FortiGate will operate in restricted mode — you can still access the GUI and CLI but traffic processing is limited.
-
Verify Current License Status via CLIFortiOS CLI
fortigate-vm01 # get system status Version: FortiGate-VM64 vX.X.X Serial-Number: FGVMEVXXXXXXXX License Status: Valid / Evaluation / Invalid
-
Option A — Register License via FortiGate GUI
- Open your browser and go to
https://10.10.0.6 - Log in with
adminand the password you set - If prompted by the license wizard, enter your FortiGate VM serial number and follow the Fortinet registration workflow
- Go to System → FortiGuard and click Update Now to pull license status from Fortinet's servers
- Open your browser and go to
-
Option B — Register License via CLI (offline or eval)FortiOS CLI
fortigate-vm01 # execute update-now Updating license and signatures from FortiGuard... # Verify after update: fortigate-vm01 # diagnose debug vm-print-license
⚠️Internet Access Required for Online ActivationThe FortiGate must reach Fortinet's FortiGuard servers to validate licenses online. If the lab environment has no internet path via
port1, use an offline license file supplied by your Fortinet account team or lab administrator.
Troubleshooting
🔴 FortiGate VM Does Not Boot / Boot Loop
Symptom: The Proxmox noVNC console shows BIOS errors, a grub prompt, or the VM reboots continuously without reaching the FortiOS login prompt.
Likely Causes & Fixes
- Wrong boot order: Confirm the imported disk is at the top of the boot list under VM 200 → Options → Boot Order.
- Disk not attached: Check Hardware tab — the disk should appear as
local-lvm:vm-200-disk-0, not as Unused Disk. - Wrong bus type: FortiOS versions before 7.x may not support VirtIO Block — try changing the disk bus to IDE in the Hardware settings.
- Corrupt image: Verify the
.qcow2checksum against the Fortinet download portal.
root@pve:~# qemu-img info /var/lib/vz/template/iso/FGT_VM64_KVM.qcow2 image: FGT_VM64_KVM.qcow2 file format: qcow2 virtual size: 2 GiB (2147483648 bytes) disk size: 1.2 GiB root@pve:~# pvesm list local-lvm | grep vm-200
🔴 Cannot Ping or Reach 10.10.0.6 from Management Workstation
Symptom: After setting the management IP, pings to 10.10.0.6 time out and HTTPS GUI does not load.
Likely Causes & Fixes
- Bridge misconfiguration: Confirm
vmbr10exists and that VM 200'snet0is attached to it. - port1 allowaccess not set: Run
show system interface port1and confirmset allowaccess https ssh pingis present. - IP address entered incorrectly: Verify with
show system interface port1— the IP should be10.10.0.6/255.255.128.0. - Management workstation on wrong network: Confirm the workstation's IP is in
10.10.0.0/17and its default gateway is10.10.0.254.
fortigate-vm01 # show system interface port1 config system interface edit "port1" set mode static set ip 10.10.0.6 255.255.128.0 set allowaccess ping https ssh next end fortigate-vm01 # get hardware nic port1 name: port1 MAC: 00:xx:xx:xx:xx:xx Link: up Speed: 1000Mbps
🔴 FortiGate GUI Loads but Shows "Invalid License" or Restricted Mode
Symptom: The FortiGate web GUI is accessible but shows a prominent license warning banner and some features are unavailable.
Likely Causes & Fixes
- License not yet activated: Ensure you completed Phase 4 (License Activation). Run
execute update-nowto pull license status from FortiGuard. - No internet access for FortiGuard: The FortiGate needs outbound HTTPS access to
guard.fortinet.net. Confirm the default route is set and the lab network allows outbound traffic. - Evaluation license expired: Request a new evaluation license from your Fortinet account team or lab administrator.
fortigate-vm01 # get system status fortigate-vm01 # diagnose debug vm-print-license fortigate-vm01 # execute ping guard.fortinet.net
🟡 Proxmox Web UI Shows VM as Stopped / VM ID Conflict
Symptom: VM 200 appears in the UI but won't start, or the wizard showed an error about VM ID already in use.
Likely Causes & Fixes
- VM ID 200 already exists: Use a different VM ID, or destroy the existing VM with
qm destroy 200after confirming it is safe to do so. - Disk lock: If a previous failed import left a locked disk, run
qm unlock 200on the Proxmox shell.
root@pve:~# qm list root@pve:~# qm unlock 200 root@pve:~# qm start 200
🟡 Linux Bridge Not Found / Missing from Proxmox Network Tab
Symptom: When adding network devices to the VM, vmbr10 or vmbr20 do not appear in the bridge drop-down.
Likely Causes & Fixes
- Admin script not run / bridges not persisted: Re-run the setup script on the Proxmox shell, or manually create the bridges via Node → System → Network → Create → Linux Bridge.
- Changes not applied: After creating bridges in the web UI, click Apply Configuration at the top of the Network page.
root@pve:~# ip link show type bridge root@pve:~# brctl show
Verification
Complete all verification steps in order. Each step corresponds to a success criterion from the service request. Document your results in the ITSM asset record.
Check off each item as you complete it. All six criteria must be met to consider the lab successfully completed.
✅ Test 1 — VM Visible in Proxmox Inventory
In the Proxmox web UI, confirm VM 200 (fortigate-vm01) appears under your node in the left-hand tree with status Running.
Also verify via the shell:
root@pve:~# qm list VMID NAME STATUS MEM(MB) BOOTDISK(GB) PID 200 fortigate-vm01 running 2048 2.00 12345
Expected: VM ID 200, name fortigate-vm01, status running, memory 2048 MB.
✅ Test 2 — FortiOS Login Prompt on Console
Open VM 200 → Console in the Proxmox web UI. Confirm the FortiOS login prompt is displayed and you can log in with your admin credentials.
fortigate-vm01 login: admin Password: YourSecurePass123! Welcome!
Expected: Successful login, FortiOS CLI prompt displayed.
✅ Test 3 — FortiOS Version and License Status
fortigate-vm01 # get system status Version : FortiGate-VM64 v7.x.x,build xxxx (GA) Virus-DB : ... IPS-DB : ... Serial-Number : FGVMEV0000000000 License Status : Valid VM Resources : 2 CPU/2048MB RAM Hostname : fortigate-vm01 Operation Mode : NAT
Expected: FortiOS version displayed, hostname = fortigate-vm01, License Status = Valid or Evaluation.
✅ Test 4 — Management IP Reachable by Ping
From your management workstation, open a terminal or Command Prompt and ping the FortiGate management IP:
C:\Users\Admin> ping 10.10.0.6 Pinging 10.10.0.6 with 32 bytes of data: Reply from 10.10.0.6: bytes=32 time=1ms TTL=64 Reply from 10.10.0.6: bytes=32 time=1ms TTL=64 Reply from 10.10.0.6: bytes=32 time=1ms TTL=64 Reply from 10.10.0.6: bytes=32 time=1ms TTL=64 Ping statistics for 10.10.0.6: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss)
Expected: 0% packet loss, RTT < 10 ms.
✅ Test 5 — HTTPS GUI Accessible
Open your browser and navigate to https://10.10.0.6. Accept any self-signed certificate warning. Log in with admin and your password.
Expected: FortiGate management dashboard loads. You should see the System Overview widget showing the hostname, FortiOS version, uptime, and CPU/memory utilization.
Confirm the license status widget shows Valid or Evaluation. If it shows Unlicensed or Invalid, revisit Phase 4 of the Configuration tab.
✅ Test 6 — Asset Record Documentation
Create or update the ITSM asset record with the following information. All fields are mandatory for successful completion.
| Field | Value to Record |
|---|---|
| Proxmox VM ID | 200 |
| VM Name | fortigate-vm01 |
| Proxmox Host | 192.168.128.191 (wssesxihost.191.wss.local) |
| vCPU Allocation | 2 vCPU |
| RAM Allocation | 2 048 MB |
| Boot Disk | local-lvm:vm-200-disk-0 (2 GB .qcow2 import) |
| port1 Bridge | vmbr10 — WAN/Management |
| port2 Bridge | vmbr20 — Internal LAN |
| Management IP | 10.10.0.6/17, GW 10.10.0.254 |
| LAN IP | 172.31.1.1/24 |
| FortiOS Version | Record from get system status |
| Serial Number | Record from get system status |
| License Type | Evaluation / Production (record expiry date) |
| Admin Access | HTTPS GUI and Proxmox noVNC console |
Knowledge Check
Answer each question to test your understanding of FortiGate VM deployment on Proxmox VE. Select the best answer and click Check Answer.
Progress: 0 / 8 correct
1. When importing a FortiGate .qcow2 image into Proxmox as a VM disk, which qm subcommand is used?
2. In this lab, which Proxmox Linux bridge is mapped to FortiGate port1 (management/WAN)?
3. What is the management IP address assigned to fortigate-vm01 port1 in this lab?
4. Why should you uncheck Ballooning Device when creating the FortiGate VM in Proxmox?
5. Which FortiOS CLI command verifies the operating system version, serial number, and license status in a single output?
6. The Proxmox admin setup script stops short of creating the VM itself. What is the primary educational reason for this design decision?
7. After the FortiGate VM boots for the first time and you log in with username admin, what password should you enter?
8. What FortiOS CLI command would you use to trigger an immediate license and signature update from Fortinet's FortiGuard servers?