
Plan your lab for Fortinet NSE 4-FortiOS 7.6 administrator training (part 1 of 2) by downloading resources, topology, workbook, and images, and review common setup and licensing issues.
Master FortiOS 7.6 administration with hands-on labs and GUI/CLI exercises covering firewall policies, routing, authentication, and IPsec VPN configurations to prepare for the NC 440 7.6 exam.
NSE 4-FortiOS 7.6 administrator exam overview highlights a 90-minute, 50-question, pass/fail format in English for version 7.6, and its role as a core exam across four tracks.
Install the latest eve ng community edition on VMware Workstation Pro by downloading the ISO and configuring a Linux VM with 16 GB RAM and 4 CPUs.
Learn to upload ios switches to eve-ng via ftp with winscp, download and unzip images from google drive, and apply the license in the eve-ng bin directory.
Upload FortiGate lab images to EVE-NG and configure supporting OS images via FTP. Build the lab with a clear IP schema and proper directory structure.
Download a FortiGate image from Fortinet for a fresh deployment, unzip, upload to eve-ng, apply naming conventions and permissions, then start the image and set the initial password.
Learn to add a FortiAnalyzer image to EVE-NG from scratch, including downloading the 40 analyzer KVM image (version 7.63 build), preparing two virtual drives, and configuring permissions for lab use.
Learn how to add Kali Linux 2025 to eve-ng by downloading qcow2 image, extracting with seven zip, renaming, uploading, creating a directory, and booting as Kali.
Explore the FortiOS lab topology in eve-ng, configure two firewalls with dmz, lan, and multiple ISPs to test routing, sd-wan, vpn, security profiles, and remote access.
Export and import labs in EVE-NG using a readymade topology, adjust management cloud connections, and verify images for Fortigate and Linux guests.
Configure lab PCs with IPv4 addresses, DNS and gateway 10.0.1.254, and subnet 255.255.255.0 across PC1–PC4, remote PCs, and external PC; verify connectivity with ping and adjust firewall and time zone.
Configure server one and server two in the lab by assigning static IP addresses, gateways, and hostnames. Update the web configuration by editing var/www/html/index.html to reflect the new settings.
Configure the initial active directory on Windows Server 2019 by setting a static IP, DNS, and remote desktop, disabling firewall and real-time protection, and renaming the server.
Configure Active Directory on Windows Server 2019 by installing Active Directory Domain Services, promoting the server to a domain controller for a test.local forest, and setting up DNS and prerequisites.
configure dns for active directory on windows server 2019 by creating forward and reverse lookup zones, adding host and pointer records for firewall devices, and verifying with nslookup.
Create user and group accounts in Active Directory using the Active Directory Users tool, forming HR, IT support, sales, and admin groups, and add test users with a common password.
Configure Windows Server 2019 as ntp server by enabling global config, setting announce flag to 5, enabling windows time and ntp, then verify stratum 1 with an ntp tool.
Discover FortiGate factory default settings for FortiOS 7.6, including management port access, variant IP ranges and admin with no password, webgui/cli access, and factory reset via CLI or GUI.
Configure Fortigate 7.6 firewall one from the console by setting the admin password, setting the hostname, and assigning a management port IP with http, https, ssh, and ping enabled.
Learn four access methods for FortiGate firewall: gui, cli, api, and FortiManager, enabling easy configuration, scripting, automation, and centralized multi-device management.
Explore the FortiGate firewall dashboard to monitor device status, cpu usage, memory, and session count, then customize widgets for security, network, assets, identities, and wifi.
Create a custom FortiGate dashboard by adding and resizing widgets like dhcp, dns, sd-wan, cpu usage, sessions, and administrator status, then edit or delete the dashboard.
Explore how Fortigate widgets on the status dashboard provide quick actions, real-time info, and customization through adding, removing, resizing, and saving widgets as monitors.
Explore FortiGate FortiView monitors to view real-time and log-based data by source, destination, application, websites, and policies; drill down, end sessions, and create policies by MAC address or IP address.
Reset and switch Fortigate dashboard templates, selecting optimal for quick health checks or comprehensive for deep monitoring. Use the monitor menu and three-dot options to apply the template.
Learn the Fortigate firewall command line interface (CLI) and its tree-like command structure, including commands, subcommands, objects, tables, fields, values, and options for interface configuration.
Learn 40 Fortigate firewall command line interface shortcuts, including question mark, tab auto-complete, and control keys for moving, deleting, and clearing, plus command history navigation with arrows and page up/down.
Update the Fortigate firewall system settings by switching from Fortiguard to 8.8.8.8 and 1.1.1.1 for dns, and configure ntp with a custom server, time zone, and related cli commands.
Configure FortiGate interfaces with role and alias to streamline management and policy setup. Role defines interface purpose and behavior, while alias provides a custom label for easy identification and troubleshooting.
Configure FortiGate interfaces by assigning aliases, roles, IP addresses, and subnet masks, enabling administrative access across ports for management, ISPs, LAN, and DMZ, with subinterfaces planned.
Configure administrative access on the Fortigate firewall by selecting secure protocols per interface. Enable https, ssh, and ping, while avoiding http or telnet, and align access with IP assignment.
Understand routing and routed protocols, how IPv4 and IPv6 carry user data, and how routers use routing protocols, static or dynamic, to find the best path.
Understand static routing as manual, simple, and secure for small networks with low resource use. Explain Fortigate routes (gateway of last resort) with admin distance 10 and priority 1.
Administrative distance is the first tie breaker, with lower values more reliable; direct connected routes have 0, while static 10, OSPF 110, IBGP 220, RIP 120, and ISIS 115.
Explore how route priority acts as a tie breaker for static routes with equal administrative distance, showing how the routing table selects the lowest distance and priority to forward traffic.
Metric selects the best path in routing protocols, with Fortigate preferring lower values; administrative distance compares protocols, while ospf uses cost, rip uses hop count, and bgp uses path count.
Configure static and default routes on a Fortigate firewall, verify routing in dashboard and CLI, and set two gateways with defined administrative distance and priority for management connectivity.
Configure a primary and backup path for internet redundancy using static routes, administrative distance, and priority; monitor link health to fail over seamlessly in routing table, enabling ECMP and SD-WAN.
Configure primary and backup routes on a Fortigate firewall with different administrative distances or priorities. Verify that the lower distance or priority route is active and test failover.
Explain equal cost multi-path in FortiGate, where traffic uses multiple next-hops with destination and distance, and explore source ip base, weight base, usage base, and source-destination ip base methods.
Configure equal-cost multipath on FortiOS Fortigate by aligning administrative distance and priority, test with traceroute, adjust ECMP mode from source IP to source and destination, and verify automatic switching.
Explore ecmp load balancing methods in Fortinet FortiOS 7.6, including source IP base, weight base, usage base, and source-destination IP base, in a two-WAN lab.
Explain how Fortigate's link health monitor checks WAN interfaces, pings gateways, and automatically switches routing to a backup link when the primary fails, updating the routing table accordingly.
Configure health link monitor via cli to enable internet service provider failover between primary and backup links, monitoring icmp to a target such as 8.8.8.8 and adjusting static routes accordingly.
Discover how policy routing on Fortigate forwards traffic along different paths using source, destination, protocol, or port criteria, ahead of static routes and SD-WAN.
Configure policy routing on a Fortigate firewall to route PC1 to gateway 1 and PC2 to gateway 2, with verification via traceroute and logs.
Create static routes using name addresses on the Fortigate firewall. Enable routing configuration for address objects and use the name address as the static route destination and gateway.
Configure a static route with named addresses on a Fortigate firewall by creating an address object and mapping Google to a gateway, then verify with routing table and logs.
Demonstrate FortiGate's internet service routing using the built-in internet service database (Isdb) to route traffic by service names such as Microsoft Office 365, Google, and YouTube, via policy routes.
Configure internet service routing in a Fortigate lab by creating static routes through internet services and verify traffic uses the policy route via ICMP tests.
Explore the routing information base and forwarding information base in Fortigate, including how routes are learned, stored, and used for packet forwarding, with route cache and kernel routes.
Create vlan 20 shr v1 and vlan 30 srv two, assign ethernet 0101 to vlan 20 and 0102 to vlan 30, then set 0/0 as dot1q trunk to firewall.
Configure vlan 20 and vlan 30 on the firewall and switch, create subinterfaces, assign ip addresses, and test connectivity with pings and firewall policies.
Configure a DMZ zone on a Fortigate firewall to consolidate VLANs into a single zone, replace separate VLAN policies with the zone policy, and verify traffic via dashboard and CLI.
Learn how FortiGate NAT translates private to public IP addresses and ports, saves IPv4 space, and improves security by hiding internal networks using source and destination NAT.
Explore NAT types in Fortigate firewall, including source net and destination net, with static/dynamic NAT, central source net, and virtual IP with port forwarding for inbound and outbound traffic.
Describe source network address translation (Xnet) on a Fortigate firewall, translating private to public IPs using static, dynamic, and central net, with overload, 1-to-1, fixed port, and port block options.
Configure policy source interface overload (static net) on a FortiGate firewall, translating internal source IPs to the outside interface IP 192.168.1.1, and verify via system session list and view sessions.
Configure policy source overload nat by creating a dynamic ip pool, assigning it to the policy, and verifying traffic uses the pool across multiple hosts via session and log checks.
Configure policy source 1-to-1 NAT with a dynamic net, create an IP pool for 1-to-1 translation, apply it to the firewall policy, and observe two concurrent translations.
Configure a source fixed port range net by creating an IP pool with an internal IP range and start/end ports, then apply it to a firewall policy with log verification.
Configure policy source port block allocation NAT by creating an IP pool, setting a block size 128 and block per user, and applying port block allocation in firewall policy.
Enable central source net and create central source net policies across firewall policy to use external interface IP for outgoing traffic, with options like dynamic IP pool and port mapping.
Explore destination network address translation on a Fortigate firewall, mapping external public IPs to internal servers via static virtual IPs, services, and port forwarding.
Configure destination net on a Fortigate firewall using virtual IP or static net to expose internal server 10.0.2.1 in the dmz to external http and https traffic.
Configure destination net with port forwarding, mapping external port 8080 to internal port 80 for server two, using a DMZ virtual IP and firewall policy, then verify.
Configure a virtual IP without central SNAT, disable central net, convert net to VIP, and update firewall policies to use server IP destinations.
Fortigate firewall policies centralize traffic control by top-to-bottom matching of source, destination, interfaces, services, and time, enforcing accept or deny actions.
Explain firewall policy parameters on Fortigate: incoming/outgoing interfaces, source/destination addresses, users, services, schedule, security profiles, and policy IDs, with implicit deny and logging.
Explore per-policy inspection modes in Fortigate firewall: flow-based delivers real-time, high-throughput inspection with no buffering, while proxy-based offers deeper content scanning at the cost of resources and latency.
Enable the multiple interface policy and any policy in system feature visibility, apply changes, then configure firewall policies for multiple interfaces and any in the policy editor.
Demonstrate Fortigate firewall policy configuration by blocking China, Iran, and Russia, and enabling DNS, LAN to Active Directory, LAN to DMZ, and DMZ to Internet with logging and implicit denial.
Explore the Fortigate policy table to view and configure firewall rules, including IDs, policy names, sources, destinations, services, actions, NAT, and security profiles with logging.
Learn to use FortiOS policy match to identify which firewall policy applies to specific traffic, by examining interface, IP, protocol, and ports, and edit the policy directly.
Understand firewall policy views: interface pair view, by sequence, and sequence grouping view, and see how each organizes policies and available actions.
Enable firewall policy logging to record security events or all sessions; security events save storage and CPU, while all sessions provide full traffic visibility, with optional session start logs.
Configure FortiGate firewall policies by customizing policy table columns, applying filters, and editing or copying rules; view logs and use CLI for policy management.
Create a local user and group, apply a user-based firewall policy on FortiGate to require authentication for internet access, and verify access via logs and dashboards.
Attach security profiles to firewall policies to scan allowed traffic for threats, and reuse profiles across policies, noting logs and the distinction from policy rules.
Explore how fortigate firewall uses ssl inspection to act as a man-in-the-middle, decrypting https traffic for inbound and outbound connections after installing its root certificate.
Explore SSL inspection modes in FortiGate firewalls. Differentiate certificate inspection, which reads certificate details without decrypting traffic, from deep SSL inspection that decrypts, inspects, and blocks threats inside encrypted traffic.
Create a custom full ssl inspection profile, attach it to the firewall policy, and test browser warnings until the root CA is installed, with PayPal and finance sites exempt.
install and verify the fortinet firewall certificate on end-user devices (pc1, pc2, pc3, and attacker) either by manual installation or via active directory, and confirm via browser and MMC checks.
Course Description:
Are you ready to master FortiGate firewalls and earn your Fortinet NSE 4 - FortiOS 7.6 Administrator certification?
This course is designed to take you from foundational concepts to advanced configurations, using real-world scenarios and hands-on labs. Whether you're an IT professional, network engineer, or cybersecurity student, this course will give you the skills and confidence to deploy, manage, and troubleshoot FortiGate devices running FortiOS 7.6.
You’ll learn how to set up FortiGate firewalls in EVE-NG for your own lab environment, ensuring practical, job-ready knowledge every step of the way. Through step-by-step guidance, we’ll cover everything from basic policy creation to VPNs, high availability, and threat protection features like antivirus, IPS, and application control.
By the end of this course, you will be fully prepared to take the Fortinet NSE 4 - FortiOS 7.6 Administrator exam and apply your skills confidently in real-world networks.
FortiOS Administrator Certification:
I recommend this course for network and security professionals who are involved in the day-to-day management, implementation, and administration of a security infrastructure using FortiGate devices.
Course Description:
In this course, you will learn how to use the most common FortiGate features. In interactive labs, you will explore firewall policies, user authentication, high availability, SSL VPN, site-to-site IPsec VPN, Fortinet Security Fabric, and how to protect your network using security profiles, such as IPS, antivirus, web filtering, application control, and more. These administration fundamentals will provide you with a solid understanding of how to implement the most common FortiGate features.
Agenda:
01. System and Network Settings
02. Firewall Policies and NAT
03. Routing
04. Firewall Authentication
05. Fortinet Single Sign-On (FSSO)
06. Certificate Operations
07. Antivirus
08. Web Filtering
09. IPS and Application Control
10. SSL VPN
11. IPsec VPN
12. SD-WAN Configuration & Monitoring
13. High Availability
14. Diagnostics and Troubleshooting
Certification:
This course is intended to help you prepare for the Fortinet NSE 4 - FortiOS 7.6 Administrator exam. This exam is part of the following certification tracks:
o Fortinet Certified Professional - Secure Networking
o Fortinet Certified Professional - Cloud Security
o Fortinet Certified Professional - Security Operations
o Fortinet Certified Professional - SASE
Product Versions:
FortiOS 7.6
Objectives:
After completing this course, you will be able to:
o Configure FortiGate basic networking from factory default settings
o Configure and control administrator access to FortiGate
o Use the GUI and CLI for administration
o Control network access to configured networks using firewall policies
o Apply port forwarding, source NAT, and destination NAT
o Analyze a FortiGate route table
o Route packets using policy-based and static routes for multi-path and load-balanced
o Authenticate users using firewall policies
o Monitor firewall users from the FortiGate GUI
o Offer Fortinet Single Sign-On (FSSO) access to network services, integrated with AD
o Understand encryption functions and certificates
o Inspect SSL/TLS-secured traffic to prevent encryption used to bypass security policies
o Configure security profiles including viruses, torrents, and inappropriate websites
o Apply application control techniques to monitor and control network applications
o Offer an SSL VPN for secure access to your private network
o Establish an IPsec VPN tunnel between two FortiGate devices
o Configure static routing
o Configure SD-WAN to load balance traffic between multiple WAN links effectively
o Deploy FortiGate devices as an HA cluster for fault tolerance and high performance
o Diagnose and correct common problems