
Prepare for the FortiGate 7.6 training by downloading part one and part two resources, lab workbooks, and topologies; note that licenses are not provided, and use 7.0 x if needed.
Learn how FortiGate security profiles attach to security policies to scan allowed traffic with antivirus, web, DNS filters, and application control, distinguishing policy control from profile filtering.
Learn how ssl inspection enables FortiGate firewalls to decrypt tls traffic by acting as a man-in-the-middle, installing a trusted firewall certificate on clients for inbound and outbound https inspection.
Explore ssl inspection modes on the FortiGate firewall, including certificate and full inspection. Certificate inspection reads certificate details without decrypting traffic; full inspection decrypts and inspects encrypted traffic.
Create a custom full SSL inspection profile and attach it to firewall policy for ISP one. Install the Fortinet CA certificate in the browser to avoid certificate warnings during testing.
Install the firewall ssl certificate on end-user devices, manually for a small lab or via active directory for many systems, and verify in the browser and trusted root store.
Explore FortiGate security profiles, including antivirus, web filter, application control, and IPS, to inspect allowed traffic for malware and malicious web content and enable layer-7 security within firewall policies.
Verify antivirus license status and enable FortiGuard antivirus in a custom profile, attach to firewall policy, and test using PC1 to confirm blocked malware and detailed security events.
Configure and verify FortiGate web filter profiles (FortiGuard categories) to block, warn, or authenticate access, test with real categories, and review logs and firewall policy integration.
Enable static url filtering in the FortiGate web filtering profile to block sites such as bbc.com and cnn.com. Confirm precedence over fortiguard category filters using security events logs.
Explore web profile override to grant temporary access to blocked sites for specific users or IPs with time limits, and use web rating override to reclassify sites by policy.
Configure web rating override to reclassify a URL from search engine to malicious website, test with an internal computer, and verify results in the web filter logs and security events.
Demonstrates configuring a web profile override in FortiGate 7.6, including IP-based and user-based overrides, proxy-base inspection, and testing with social networking blocked by default.
Enable the IPS profile to block malicious URLs, attach it to the LAN to ISP policy, and verify blocking and logs using Fortiguard intrusion prevention tests.
Configure and test custom IPS signatures in FortiGate 7.6 by adding signature blocks to an IPS profile, enabling logging, and validating with eicar tests and security logs.
Configure custom IPS filters in a FortiGate 7.6 environment, enable block action and logging, test with Kali Linux and Nmap, and monitor intrusion prevention logs to verify blocked traffic.
Configure application control by enabling the default profile, block social media categories, and attach the profile to the firewall policy, then verify blocks via security events and forward traffic.
Configure application override in FortiGate to selectively allow Twitter while blocking other social media apps, test the policy, and apply overrides within the security profile.
Configure filter override in the application control security profile to block video and audio categories, test YouTube access, and verify blocks via logs and security events.
Explore firewall authentication and Fortigate next-generation features that identify users by user ID and group, enabling precise policies, visibility, and user activity tracking.
Active authentication prompts for username and password (with optional two-factor) for guest or admin access, while passive Fortinet single sign on with Active Directory enables seamless enterprise access.
Configure captive portal authentication on Fortigate firewall's LAN interface, enforce a local group, and verify access flow with redirects and session duration before disabling.
Configure ldap server for active directory in FortiGate, test connectivity and credentials, map ad groups (air, sales, it) to FortiGate groups, and apply policies by group or user.
Verify Active Directory authentication by logging in from lab PCs, validating user identities and group mappings, and confirming results in firewall identities, sessions, logs, and CLI tests.
Install Network Policy and Access Services on Windows Server 2019, register in Active Directory, configure a firewall radius client, and create a policy for air, it, and sales.
Configure and verify radius active authentication on a FortiGate firewall using Windows Server 2019 as the radius server, map radius groups, and test credentials.
Verify radius active authentication for Fortigate firewall and Windows Server 2019 by testing user logins, checking identities, sessions, and forwarded traffic via firewall dashboards and the CLI.
Install the fso agent on the Active Directory to enable passive authentication; download the 7.60 version from Fortinet support, install the fso, and monitor user logins.
learn how to join a Windows 11 client to an Active Directory domain, configure DNS to the AD server, and sign in with domain users such as HR1 or IT1.
Configure passive authentication with active directory using the fso agent, map ad groups to fortinet single sign on, and implement firewall policies and routes for ad access.
Verify ad passive authentication by logging in with ad users on pc1, review agent logs, and check identities, policy, and forward traffic to confirm seamless login without manual credentials.
Explore Fortigate admin accounts, including the admin, and login via command line interface, graphical user interface, application programming interface, or ssh, while understanding administrator profiles, two-factor authentication, and remote authentication.
Create a local administrator account and a dedicated local profile to define permissions, then test access by logging in to verify restricted features like CLI access and view permissions.
Configure remote administrator accounts with Active Directory via LDAP, map admin and support groups, create admin and support profiles, and verify access through logins and events.
Configure FortiGate firewall two via cli, including management interface, entropy, hostname, and admin timeout; define and verify when-one and when-two policies, routes, and addresses, then test traffic.
Understand virtual private networks and how a secure tunnel encrypts, authenticates, and protects data from eavesdropping over the internet, delivering confidentiality, integrity, and scalable, cost-saving connectivity.
Identify site-to-site and remote access vpn types, including routed and policy-based site-to-site and client-based vs clientless remote access. Compare ipsec and ssl/tls protocols, encryption and hashing options, and authentication methods.
Explore remote access IPsec and ssl vpn types, with web and tunnel modes. Learn how FortiClient and FortiGate enable secure connections, split versus full tunnel, and access options.
Deploy ssl vpn web mode on Fortigate 7.6, map ad groups for web access via CLI. Test tunnel and web policies from an external pc to dmz servers over TLS.
Deploy ssl tunnel mode with firewall one, configure tunnel access, split tunneling, and routing to dmz vlan 20 and 30; install Forticlient on linux and connect via ssl vpn.
Deploy ipsec remote access vpn on a FortiGate firewall via the wizard; configure pre-shared key, ike v1, phase one and two proposals, and nat traversal for remote access.
Deploy a template-based IPv6 site-to-site IPsec VPN between two FortiGate firewalls, with automated policy, address groups, and routes, and verify connectivity and logs in FortiOS 7.6.
Learn how to deploy a static IPv6 site-to-site IPsec VPN between two FortiGate firewalls, configuring phase 1 and 2, NAT traversal, firewall policies, and static routes for end-to-end reachability.
Deploy a dial-up ipsec site-to-site vpn between firewall one and firewall two in a lab, configuring the ipsec tunnel, phase one and two, and policies.
Explore software-defined wide area networks with FortiGate: central control, load balancing across MPLS, broadband, and LTE, application-based routing, health checks, and visibility for optimal WAN performance.
Learn the FortiGate sd-wan components: sd-wan members up to 256 and zones, performance sla, health checks, and sd-wan rules, including manual rules, to route traffic across multiple links and failover.
Deploy SD-WAN on a firewall with two ISPs, create an underlay zone, add SD-WAN members, configure source-destination IP load balancing, and verify multi-link traffic.
Configure and verify SD-WAN source IP load balancing on two WAN links; traffic from the same source IP sticks to one interface, with CLI and GUI options.
Configure session-based load balancing for dual SD-WAN links by assigning weights (20% to port one, 80% to port two) and verify via GUI, CLI, trace routes, and logs.
Configure and verify spillover load balancing method in an SD-WAN setup with two links and a 1024 threshold. Use GUI and CLI, adjust policies, and test via traceroute and dashboard.
Configure and verify SD-WAN volume load balancing with an 80/20 ratio using graphical and CLI methods, and validate traffic distribution via traceroute, sessions, and logs.
Explore sd-wan rules that control path selection and policy routing on firewall, using top-to-bottom first-fit evaluation, manual assignments, and an implicit 80% weight rule for when nothing matches.
Configure a manual sd-wan rule on firewall one to direct traffic top-to-bottom by source, destination, protocol, and interface preferences, enabling switchover when a link fails.
Understand how the sd-wan performance sla, or health check, monitors latency, jitter, and packet loss and automatically reroutes traffic to a healthy link using thresholds, intervals, and multiple targets.
Configure and validate SD-WAN performance SLA across two links by testing ping, HTTP, and DNS, tracking latency, jitter, and packet loss, and verifying link health.
Explore how dhcp automates ip address, subnet, gateway, and dns assignment, and how FortiGate can act as dhcp server, client, or relay across multiple interfaces.
Configure FortiGate as a DHCP server on the LAN interface with a 1–253 address range and DNS, then verify leases on PCs and reserve addresses as needed.
Install the DHCP server role on Windows Server 2019 and create an IPv4 scope with a /24 subnet, gateway, and DNS. Prepare a firewall relay to serve clients.
Configure the fortigate firewall as a dhcp relay to forward client requests to the windows server 2019 dhcp server, enabling relay mode and specifying the server IP.
Learn how to back up and restore a FortiGate firewall using the graphical interface and CLI, including encrypted backups, local and remote transfers, and the reboot that follows restoration.
Learn how to upgrade Fortigate firewall firmware using manual and automatic upgrade paths, verify versions, back up configurations, and manage upgrades for single or multiple devices.
Course Description:
Are you ready to master FortiGate firewalls and earn your FCP – FortiGate 7.6 Administrator certification?
This course is designed to take you from foundational concepts to advanced configurations, using real-world scenarios and hands-on labs. Whether you're an IT professional, network engineer, or cybersecurity student, this course will give you the skills and confidence to deploy, manage, and troubleshoot FortiGate devices running FortiOS 7.6.
You’ll learn how to set up FortiGate firewalls in EVE-NG for your own lab environment, ensuring practical, job-ready knowledge every step of the way. Through step-by-step guidance, we’ll cover everything from basic policy creation to VPNs, high availability, and threat protection features like antivirus, IPS, and application control.
By the end of this course, you will be fully prepared to take the Fortinet Certified Professional (FCP) – FortiGate 7.6 Administrator exam and apply your skills confidently in real-world networks.
FortiGate Administrator Certification:
I recommend this course for network and security professionals who are involved in the day-to-day management, implementation, and administration of a security infrastructure using FortiGate devices.
Course Description:
In this course, you will learn how to use the most common FortiGate features. In interactive labs, you will explore firewall policies, user authentication, high availability, SSL VPN, site-to-site IPsec VPN, Fortinet Security Fabric, and how to protect your network using security profiles, such as IPS, antivirus, web filtering, application control, and more. These administration fundamentals will provide you with a solid understanding of how to implement the most common FortiGate features.
Agenda:
01. System and Network Settings
02. Firewall Policies and NAT
03. Routing
04. Firewall Authentication
05. Fortinet Single Sign-On (FSSO)
06. Certificate Operations
07. Antivirus
08. Web Filtering
09. IPS and Application Control
10. SSL VPN
11. IPsec VPN
12. SD-WAN Configuration & Monitoring
13. Security Fabric
14. High Availability
15. Diagnostics and Troubleshooting
Certification:
This course is intended to help you prepare for the FCP - FortiGate 7.6 Administrator exam. This exam is part of the following certification tracks:
o Fortinet Certified Professional - Network Security
o Fortinet Certified Professional - Public Cloud Security
o Fortinet Certified Professional - Security Operations
Product Versions:
FortiOS 7.6
Objectives:
After completing this course, you will be able to:
o Configure FortiGate basic networking from factory default settings
o Configure and control administrator access to FortiGate
o Use the GUI and CLI for administration
o Control network access to configured networks using firewall policies
o Apply port forwarding, source NAT, and destination NAT
o Analyze a FortiGate route table
o Route packets using policy-based and static routes for multi-path and load-balanced
o Authenticate users using firewall policies
o Monitor firewall users from the FortiGate GUI
o Offer Fortinet Single Sign-On (FSSO) access to network services, integrated with AD
o Understand encryption functions and certificates
o Inspect SSL/TLS-secured traffic to prevent encryption used to bypass security policies
o Configure security profiles including viruses, torrents, and inappropriate websites
o Apply application control techniques to monitor and control network applications
o Offer an SSL VPN for secure access to your private network
o Establish an IPsec VPN tunnel between two FortiGate devices
o Divide FortiGate into two or more virtual devices, (VDOMs)
o Configure static routing
o Configure SD-WAN to load balance traffic between multiple WAN links effectively
o Identify the characteristics of the Fortinet Security Fabric
o Deploy FortiGate devices as an HA cluster for fault tolerance and high performance
o Diagnose and correct common problems
Who This Course is For:
Network/security professionals aiming for FCP certification
Students and IT admins seeking hands-on FortiGate experience
Anyone interested in Fortinet firewall technologies