First time managing FortiWeb - courses only covered ~30%, feeling lost. Looking for guidance on how to actually get proficient
Hi everyone,
I recently stepped into managing a live, deployed FortiWeb environment as my first time ever working with the appliance. I've completed a couple of official courses, but honestly, they only covered about 30% to 40% of what I'm dealing with day-to-day. I don't have a formal development or heavy AppSec background, and some colleagues mentioned that dev experience is needed, which has me feeling a bit overwhelmed and clueless about what's actually happening under the hood.
Right now, I'm diving heavily into the official administration documentation because it seems like the only place that covers the device end-to-end. Specifically, I'm currently facing practical operational tasks like onboarding new websites into production.
Could the community share some guidance and best practices on how to bridge this gap and get truly proficient? I'm looking for:
- Reading & Resource Roadmap: Beyond the official admin guide, what documentation sections, admin guides, or troubleshooting references are absolute must-reads to cover almost everything comprehensively?
- Handling False Positives: What are the most common beginner mistakes when tuning false positives, and how do you handle them safely without accidentally lowering your security posture?
- Essential Skills: For someone without a software development background, what specific concepts (HTTP protocols, regular expressions, JSON/XML structures) do I need to master to feel confident managing WAF rules?
Any advice, recommended workflows, or "lessons learned" from seasoned FortiWeb admins would be hugely appreciated. Thanks!