VOLKAN AVSAR

VOLKAN AVSAR

About Me.

IT Professional · Security Support Engineer · Researcher · Author

Hi, I'm Volkan — a Senior Technical Support Engineer at Fortinet in Prague, with nearly two decades of experience across IT infrastructure, system administration, project coordination and technical support.

Today I support Fortinet customers around the world on FortiClient and FortiClient EMS, covering everything from malware protection, SSL and IPsec VPN, and ZTNA to vulnerability management, web filtering and log collection. As part of the Managed Services team, I also help customers deploy EMS and FortiClient from the ground up with Intune, GPO and SCCM, and I write technical articles for the Fortinet Community.

Before Fortinet, I supported 500+ LC Waikiki stores in 46+ countries and helped launch the company's e-commerce operations in Georgia, Iraq, Kazakhstan and Ukraine. Earlier in my career I built data centers, fiber networks and IP telephony systems for manufacturing and aviation companies, and led the IT team of an airline cargo carrier at Istanbul Atatürk Airport.

I'm a firm believer in lifelong learning. I hold degrees in Management Information Systems, Public Administration, and Language & Literature, and I run a home lab where I rebuild real-world scenarios such as VPN, ZTNA and Entra ID SAML authentication.

This site is where I share what I've learned along the way. Feel free to explore the blog, and if you have a question or feedback, don't hesitate to reach out through the Contact section.

Outside of work, you'll usually find me swimming, reading fiction and history, or outdoors. I'm also a licensed climber with the Turkish Mountaineering Federation.

Personal Information

  • Name Volkan Avsar
  • Residence Prague, CZ
  • Address Prague3, Zizkov
  • Email volkanavsar@volkanavsar.com
  • Phone (+420) 732 22 4141
volkaninthespace666

QUALIFICATIONS

Nearly 20 Years in IT

Windows Server 2008–2019 · Windows 10/11
Microsoft 365 & Exchange
SQL Server Administration & Data Analysis
Data Center Design, Fiber Networks, Virtualization
Cisco, Avaya, Juniper · IP Telephony

Cyber Security

FortiClient, FortiClient EMS, FortiGate
ZTNA, SSL & IPsec VPN
Intune, GPO, SCCM
Active Directory, Entra ID (SAML)

ERP Systems

Microsoft Dynamics AX (Axapta), Navision, 1C, LOGO

Helpdesk & ITSM

Jira, ITSM, FortiCare

TESTIMONIALS

My Resume.

EXPERIENCE

  • Present Apr 2022

    Senior Technical Support Engineer

    Fortinet, Prague, Czech Republic

    Providing global technical support for FortiClient and FortiClient EMS, including malware protection, SSL/IPsec VPN, ZTNA, vulnerability management and web filtering. Member of the Managed Services team, deploying EMS with Intune, GPO and SCCM, and author of technical articles for the Fortinet Community.

  • Apr 2022 Jul 2020

    International Retail IT Establishment and Expansion Specialist

    LC Waikiki, Istanbul, Türkiye

    Supported IT operations for 500+ stores in 46+ countries and helped launch e-commerce operations in Georgia, Iraq, Kazakhstan and Ukraine. Supported ERP systems (Navision, Axapta, 1C), kept global sales data in sync with HQ, and worked with engineering teams on logistics, PDA and online store applications.

  • Aug 2019 Mar 2018

    International Retail IT Technical Support Specialist

    LC Waikiki, Istanbul, Türkiye

    Delivered remote support to 500+ stores via ITSM, phone and Teams, validated sales data with SQL, and prepared new stores for opening, including POS tills, servers and PDA devices. Ran monthly progress meetings with local IT teams worldwide.

  • Jan 2018 Aug 2015

    IT Supervisor

    SML Group Limited, Istanbul, Türkiye

    Built the IT infrastructure for a new headquarters five times larger than the previous one: fiber network on an Avaya backbone, Juniper/Avaya firewalls with SSL and site-to-site VPN, a dedicated fiber link to Hong Kong, IP telephony, and a Windows 10 rollout to 200+ computers.

  • Aug 2014 Feb 2012

    IT Project Coordinator

    Orthaus Trailers, Sakarya, Türkiye

    Led the complete IT setup of a new 20,000 m² manufacturing facility: an ISO-compliant data center, Cisco fiber network, PBX telephony, CCTV and facility-wide Wi-Fi, plus L1/L2 support for 200+ users.

  • Aug 2014 Sep 2010

    IT Systems Chief

    ULS Airlines Cargo, Istanbul, Türkiye

    Headed IT for a 6-aircraft cargo airline in line with ISO, ICAO and EASA standards. Migrated email to Microsoft Exchange, built an ISO-compliant data center and moved headquarters in a single day with zero downtime.

  • Nov 2010 Sep 2007

    IT System Specialist

    KUZU Group, Istanbul, Türkiye

    Provided on-site support across several construction sites for 300+ desktops, and managed 5 Windows servers, PBX, the Linux mail server, LOGO ERP and IP CCTV.

EDUCATION

  • 2020 2019

    Barton International College

    Academic English, Sydney, Australia

    Seven-month intensive academic English program in Sydney, six days a week, completed with a B2-level IELTS certificate.

  • 2018 2016

    Haliç University

    Master's Degree, Management Information Systems, Istanbul, Türkiye

    Graduate program focused on IT management, research and information systems strategy, completed with a GPA of 3.69/4. My thesis is available on the YÖK National Thesis Center.

  • 2015 2011

    Istanbul University

    Bachelor's Degree, Language and Literature, Istanbul, Türkiye

    Studies in language, linguistics and literature.

  • 2013 2009

    Anadolu University

    Bachelor's Degree, Public Administration, Istanbul, Türkiye

    Studies in public administration, management and accounting.

CERTIFICATIONS

NSE 1 – Information Security Awareness

100%

NSE 2 – The Evolution of Cybersecurity

100%

NSE 3 – Fortinet Product Awareness

100%

NSE 4 – Network Security Professional

100%

NSE 5 – Network Security Analyst

100%

Microsoft – Programming in C#

100%

Microsoft – Programming in HTML5 with JavaScript and CSS3

100%

Microsoft Certified Application Developer (MCAD)

100%

Microsoft Certified Professional (MCP) E736-9827

100%

Microsoft Technology Associate (MTA) E736-9828

100%

SKILLS

FortiClient & FortiClient EMS

99%

FortiGate

77%

ZTNA, SSL & IPsec VPN

90%

Windows Server 2008–2019

92%

Windows 10 / 11

99%

Active Directory & Entra ID

80%

Intune, GPO & SCCM

85%

Networking (DHCP, LAN, WAN, Wi-Fi)

83%

Home Lab.

A small but realistic Fortinet environment I run at home to reproduce customer scenarios, test new FortiOS and FortiClient EMS releases before they reach production, and break things safely. It covers the full path from identity (Microsoft Entra ID SAML) and MFA, through IPsec IKEv2 and ZTNA remote access, to segmented Wi-Fi and a highly available EMS cluster. Most of my troubleshooting know-how and several of my technical articles started here.

Swipe sideways to see the full diagram.

What I test here

EMS high availability

Two EMS application nodes on a PostgreSQL HA cluster in Docker (two database nodes plus a witness), all on Ubuntu 24.04: failover behaviour, what endpoints see, how long it takes and what to check in the logs.

Web filter from FortiGate to EMS

Importing FortiGate web filter profiles into EMS and pushing them to FortiClient, so on-net and off-net users get the same policy.

ZTNA destinations

Live ZTNA access proxy with TCP forwarding destinations and Entra ID SAML login, combined with EMS endpoint tags – the setup that turns “VPN for everything” into per-application access.

IPsec IKEv2 with MFA

Dial-up IKEv2 remote access with EAP, Entra ID SAML single sign-on and FortiToken Cloud tokens, plus mode-config address assignment – a modern replacement for SSL VPN.

Wi-Fi segmentation

Multiple SSIDs mapped to separate subnets and VLANs, each with its own firewall policies, so different device groups never share the same network.

Policy design

Least-privilege rules built from EMS dynamic tags, zones, geo and Internet Service objects, with explicit deny rules and logging on every path.

Endpoint compliance

Compliance rules, vulnerability scans and Security Fabric integration between FortiClient, EMS and FortiGate.

Entra ID SAML

FortiGate as a SAML service provider for Microsoft Entra ID, with separate enterprise apps for IPsec IKEv2 and ZTNA and group claims mapped to firewall user groups.

Hardening & logs

Regular reviews of admin access, 2FA, trusted hosts and exposed services, plus syslog and debug output for repeatable troubleshooting checklists.

Lab notes

  • Size matters less than design. A witness node needs very few resources, while the EMS application nodes need the most RAM. Planning VM sizes up front keeps a five-VM cluster usable on a single workstation.
  • IKEv2 + MFA beats legacy VPN. Moving remote access to IPsec IKEv2 with Entra ID SAML and FortiToken, and publishing individual apps through ZTNA, removes the need to expose a full SSL VPN portal.
  • Snapshots before every upgrade. Testing a new EMS or FortiOS build is only safe when rolling back takes minutes, not an evening.
  • Treat the lab like production. 2FA for administrators, trusted hosts for service accounts and restricted management access apply at home too.

Built with

  • FortiOS
  • FortiWiFi
  • FortiAP
  • FortiClient EMS 8.0
  • FortiClient
  • FortiToken Cloud
  • ZTNA access proxy
  • IPsec IKEv2
  • Microsoft Entra ID
  • SAML SSO
  • EMS tags
  • Multi-SSID / VLAN
  • Security Fabric
  • VMware Workstation
  • Ubuntu 24.04
  • PostgreSQL HA
  • Docker
  • Syslog

For security reasons this page shows the architecture only – no addresses or configuration details of the real environment.

Contact me.

Open to new conversations

Let’s talk.

I’m open to conversations about endpoint security, FortiClient/EMS, IT infrastructure projects and collaboration. Send me a message and I usually reply within 1–2 business days.

Send a message

    Privacy Policy.

    Last updated: 30 September 2026

    This privacy policy explains what personal data is collected when you visit www.volkanavsar.com, why it is collected, how it is used and what rights you have. This is a personal website, and I try to collect as little data as possible.

    1. Who is responsible for your data

    The data controller for this website is:

    Volkan Avsar
    Prague, Czech Republic
    Email: volkanavsar@volkanavsar.com

    Because I am based in the European Union, personal data on this website is processed in accordance with the EU General Data Protection Regulation (GDPR).

    2. What data is collected and why

    Contact form

    When you send a message through the contact form, I receive your name, email address and message. I use this information only to reply to you. Messages are delivered to my mailbox by email and are not sold or shared for marketing. Legal basis: your request and my legitimate interest in responding to it (Art. 6(1)(b) and (f) GDPR).

    Blog comments

    When you leave a comment, the name, email address and website you enter are stored, together with your IP address and browser user agent, to help detect spam. Your comment and name are shown publicly; your email address is never published. An anonymized string created from your email address (a hash) may be sent to the Gravatar service to check whether you have a profile picture there; see the Automattic privacy policy. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

    Server and security logs

    Like every website, my hosting server automatically records technical data such as your IP address, the date and time of your visit, the pages requested and your browser type. A security service on the server uses this data to block attacks and malicious traffic. These logs are used only for security and troubleshooting and are deleted automatically after a short period. Legal basis: legitimate interest in running a secure website (Art. 6(1)(f) GDPR).

    Website analytics

    I use Google Analytics (Google Ireland Limited) to understand how many people visit the site and which pages they read. Google Analytics uses cookies and collects information such as the pages you visit, approximate location, device and browser, in pseudonymized form. I do not use this data to identify you. You can prevent Google Analytics from collecting data by blocking cookies in your browser or by installing the Google Analytics opt-out browser add-on. More information: Google Privacy Policy.

    Spam protection (Google reCAPTCHA)

    To protect the contact form and comments from spam and abuse, this site uses Google reCAPTCHA. reCAPTCHA analyzes information such as your IP address, mouse movements and browser details to tell humans from bots, and this data is sent to Google. See the Google Privacy Policy and Terms of Service. Legal basis: legitimate interest in protecting the website (Art. 6(1)(f) GDPR).

    Fonts

    Some of the fonts used on this site may be loaded from Google Fonts. When this happens, your browser connects to Google’s servers, which can see your IP address.

    Performance and caching

    The site uses LiteSpeed Cache to load faster. Its optimization service (QUIC.cloud) processes the site’s own files, such as images and style sheets, but does not receive personal data about visitors.

    3. Cookies

    Cookies are small text files stored in your browser. This site uses the following:

    CookiePurposeDuration
    Comment cookies (comment_author_*)Remember your name and email if you choose to when commenting1 year
    Cache cookies (_lscache_vary)Serve the correct cached version of pagesSession
    Google Analytics (_ga, _ga_*)Count visits and measure how the site is usedUp to 2 years
    Google reCAPTCHA (_GRECAPTCHA)Spam and bot protectionUp to 6 months
    WordPress login cookiesUsed only when the site administrator logs inSession / up to 14 days

    You can delete or block cookies at any time in your browser settings. Blocking some cookies may affect how the site works, for example the contact form’s spam protection.

    4. Embedded content and external links

    Blog posts may include embedded content such as videos, PDF files or images. Embedded content from other websites behaves exactly as if you had visited that website, which may collect data about you, use cookies and track your interaction with the embedded content. The site also links to external websites such as LinkedIn and the Fortinet Community. I am not responsible for the privacy practices of those websites.

    5. Who your data is shared with

    I do not sell, rent or trade your personal data. Data is shared only with service providers that are needed to run this website:

    • my web hosting provider (hosting, server logs and security);
    • Google (Analytics, reCAPTCHA and fonts);
    • my email provider (to deliver contact form messages);
    • Automattic / Gravatar (profile pictures for comments).

    Some of these providers, such as Google, may process data outside the European Economic Area. In those cases, transfers are protected by appropriate safeguards such as the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.

    6. How long your data is kept

    • Contact form messages: for as long as needed to handle your request and any follow-up correspondence.
    • Comments: kept indefinitely so that follow-up comments can be recognized and approved automatically, unless you ask me to delete them.
    • Analytics data: kept for up to 14 months, after which it is deleted automatically.
    • Server and security logs: deleted automatically after a short period.

    7. Your rights

    Under the GDPR, you have the right to:

    • access the personal data I hold about you;
    • have inaccurate data corrected;
    • have your data deleted (“right to be forgotten”);
    • restrict or object to the processing of your data;
    • receive your data in a portable format;
    • withdraw your consent at any time, where processing is based on consent.

    To exercise any of these rights, email me at volkanavsar@volkanavsar.com. I will respond within one month. You also have the right to lodge a complaint with a data protection authority; in the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).

    8. Security

    This site is served only over an encrypted HTTPS connection and is protected by a server-side security service and regular software updates. No method of transmission over the internet is completely secure, but I take reasonable measures to protect your data.

    9. Children

    This website is not directed at children under 16, and I do not knowingly collect personal data from them.

    10. Changes to this policy

    I may update this privacy policy from time to time, for example when I add new features or services to the site. The date at the top of this page shows when it was last updated.

    11. Contact

    If you have any questions about this privacy policy or how your data is handled, please contact me at volkanavsar@volkanavsar.com.