
Explore Fortinet enterprise firewalls: physical, virtual, and cloud, delivered from edge to core with the security fabric and single pane management via 4D manager and 40 analyzer.
Apply zero trust security by never trusting anyone by default and always verifying identity and context. Enforce continuous monitoring, least privileges, multi-factor authentication, encryption, and micro-segmentation for resource access.
Fortinet NSE7 enterprise firewall training prepares you for the NSC7 enterprise firewall 7.2 exam, a 60-minute, 30–35-question test via Pearson Vue, leading to a two-exam Fortinet certification path.
Upload io switches to eve ng via sftp using winscp. Place images in the opt unit lib ads on iol bin and keep the license file and host name unchanged.
Upload required images to ifeng via ftp with winscp, unzip, and ensure correct naming in the opt unit lab edson and chemu folders; configure pfSense with six interfaces for lab.
Learn how to upload a FortiGate firewall image to EVE-NG, choosing the Fortinet image version such as 7.0.13, understanding licensing, naming conventions, folder structure, and deployment steps.
Upload FortiManager to eve-ng and boot Fortigate fmgs in a qemu lab using winscp. Choose new deployment or upgrade, and prepare the image with proper naming and two hard drives.
Upload FortiAnalyzer to Eve-NG using an ftp client like WinSCP, prepare Qemu images, create a hard drive, apply permissions, and boot the analyzer for lab use.
Explore an enterprise firewall lab topology with Fortigate devices, FortiManager, and FortiAnalyzer across HQ, DC, and branch sites, featuring switches, WAN links, and ready-made images.
Export and import the NSC seven enterprise firewall topology in EVE-NG, moving from professional to community edition, then wipe nodes, upload images, start all devices, and verify connectivity.
Configure four Fortinet firewalls using a script-driven CLI workflow, setting hostnames, management interfaces, WAN/LAN links, default routes, DNS, and group policies.
Configure Windows 10 and Linux clients with static IPs, gateways, and DNS; test connectivity by ping and route checks, and disable firewalls for lab testing.
Configure FortiManager for a team manager topology on first-time setup by setting management and inside interfaces, IPs, and gateway, then apply or upload a license and complete login and settings.
Enable administrative domains in FortiManager, create a new normal adom named FortiGate 7.0, remove unused 40 ap and 40 switch modules, and prepare to add FortiGate devices later.
Configure the FortiAnalyzer 40 analyzer by setting the host name, inside and management interfaces, and the default route. Upload the license, configure DNS if needed, and verify access after restart.
Enable and configure a FortiAnalyzer ADOM, create a Fortigate firewall ADOM, adjust disk usage to 12 GB, and verify login to prepare for adding devices.
Understand how Fortinet security fabric integrates tools to see, manage, and secure your entire network from one place, with root Fortigate coordinating downstream devices, analyzer, and manager in real time.
Explore Fortinet security fabric concepts, including physical and logical topology, security rating, and the asset identity center, with guidance on licenses and 60-day evaluation deployments.
Configure the root FortiGate as the security fabric root, deploy the 40 analyzer, enable fabric, and authorize downstream devices, then verify real-time status in the fabric dashboard.
Configure a downstream FortiGate to join the security fabric by enabling fabric on the HQ firewall, authorizing the branch device via the 40 analyzer, and verifying green status.
Deploy a downstream dc firewall by joining it to the root FortiGate via the security fabric, fabric connector, and HQ authorization steps.
Deploy downstream fortigate fw1 by joining it to the existing security fabric, authorizing via 40 analyzer and root fortigate, and moving branch, dc, and HQ devices into the fabric.
activate a 60-day fortigate evaluation license to unlock physical and logical topologies and security rating in fabric view.
Explore the full security fabric topology on the root fortigate, detailing physical and logical connections, device views by traffic, count, OS, and vendor, with security rating recommendations.
Security rating analyzes your security fabric with real-time monitoring to identify vulnerabilities and highlight best practices to improve security and performance through three scorecards: security posture, fabric coverage, and optimization.
Learn to configure security fabric synchronization to propagate addresses, services, and other objects from the root FortiGate to downstream firewalls, handle conflicts, and automatically rename objects.
Explore security fabric management with cli commands, verify pending authorization list, authorize or deny via cli, and view upstream and downstream devices on a FortiGate topology.
Learn how automation stitches link triggers and actions to automate responses like reboot events and address creation, with sequential and parallel execution across the root Fortigate and security fabric.
Create a security fabric automation stitch that triggers on device reboot and runs a CLI script to configure firewall addresses, automatically provisioning addresses across FortiGate firewalls.
Disable FortiAnalyzer feature on FortiManager, create admin EFG 709 on both devices, then add FortiAnalyzer, import and synchronize devices, and verify management IPs.
Import configurations for HQ, firewall one, branch, and DC using 40 manager. Resolve conflicts by selecting the 40 manager object, then finish the per-device import and verify policies.
Explore OSPF, a link-state dynamic routing protocol using the SPF algorithm, area zero backbone, MD5 or cleartext authentication, and Dijkstra-based topology to enable scalable enterprise routing.
Configure OSPF through FortiManager across firewall one and HQ firewall, assigning router IDs and area zero. Advertise 10.0.1, 192.168.100, and related networks, push settings, and verify OSPF neighbors and routes.
Configure OSPF through a CLI template in Fortinet NSE7 training, using FortiManager provisioning templates to push router OSPF config to HQ and firewall devices, then verify with CLI commands.
Explore the basics of the border gateway protocol (BGP), its role as an exterior gateway path-vector protocol, and the eBGP/iBGP neighbor relationships across autonomous systems on TCP port 179.
Configure iBGP using FortiManager to push BGP settings to firewall1 and HQ, establishing two neighbors with R1 and advertising loopback networks to enable internet reachability.
Configure ebgp between HQ firewall and the DC firewall using FortiManager, enable multihop TTL 255, push the change via the install wizard, and verify with BGP neighbor and summary.
Configure BGP routing across firewall devices via a post run CLI template in 40 manager. Verify routes with show ip route BGP and BGP summary.
Explore how VPN manager centralizes hub-and-spoke, full-mesh, and dial-up topologies through VPN communities, gateways, phase one and phase two, and security policies, with map view and SSL VPN monitoring.
Learn to set up a hub‑to‑spoke vpn using 40 manager’s vpn manager, creating a star topology with hub HQ and two spokes, using pre‑shared key 123456 and MD5.
Create a dynamic object to cover three subnets with per-device mapping, then configure normalized LAN interfaces across HQ, branch, and DC firewalls using per-device port mappings.
Create normalized interfaces to simplify VPN firewall policies across HQ, branch, and DC firewalls, mapping IPsec one, two, and three per device and verifying remote gateways.
Configure IPsec VPN firewall policies across HQ, DC, and branch by creating and cloning LAN to VPN and VPN to LAN rules, then install and verify across firewalls.
Configure a hub-and-spoke VPN with 40 manager, verify tunnels across HQ, DC, and branch firewalls, and monitor IPsec, logs, and policy hits in multiple views.
Learn to configure hub-to-spoke vpn with a cli template via 40 manager, assigning HQ as hub and DC/branch as spokes, with ikev2, psk, phase1/phase2, and verify via ping and traceroute.
Explore advpn theory and autodiscovery, enabling spoke-to-spoke dynamic on-demand tunnels in a hub-and-spoke Fortinet vpn, delivering full-mesh reachability with on-demand ipsec tunnels.
Explore ipsec vpn topologies, hub and spoke, partial mesh, and full mesh, and how a central hub governs spoke-to-spoke traffic, latency, and scalability trade-offs, with ad vpn addressing their limitations.
Configure ADVPN via CLI template to enable spoke-to-spoke communication by setting hub autodiscovery enabled and spoke autodiscovery receiver enabled, then push with 40 manager and verify with ping and traceroute.
Learn how ad vpn messages exchange works in a hub-and-spoke topology, with traffic from spoke A to hub, then to spoke B, including shortcut offer, query, and reply.
Learn essential AD VPN troubleshooting commands to identify local/remote IPs, view hub/spokes tunnels, verify BGP networks, and check phase one and phase two details.
Back up Fortinet firewalls graphically or via CLI, and use revisions to snapshot changes before applying updates. Restore after license expiry with factory reset or from backups via FTP/TFTP.
Learn how to back up and restore FortiManager configurations using the system settings dashboard or CLI, including optional encryption, FTP transfer, and user setup.
Learn to back up and restore a faulty FortiAnalyzer using the system settings dashboard or CLI, including optional encryption with a password and a reboot during restore.
Fortigate security profiles protect networks by inspecting traffic with tools like antivirus, web filter, DNS filter, SSL inspection, and application control, attached to firewall policies for flow or proxy mode.
Explore how ssl inspection decrypts https and tls traffic using a firewall as a man in the middle, enabling threat detection, inbound and outbound inspection, and policy-based blocking before re-encryption.
Reconfigure the HQ firewall from scratch to enable the 60-day security profile, including licensing, 40 guard activation, and rejoining to the 40 manager.
Discover and add the HQ firewall to FortiManager, import policy packages per device and port, and resolve object conflicts between FortiGate and FortiManager while ensuring synchronization.
Learn to configure a FortiAnalyzer with HQ firewall for centralized logging, authorize the analyzer in security fabric, test connectivity, and view logs and reports from the HQ firewall.
Download the SSL inspection certificate from the HQ firewall, install it as a trusted root certificate authority on the client, and import it into both browsers to enable deep inspection.
Configure the antivirus security profile on 40 manager, push to the HQ firewall, and verify enforcement on HQ and 40 analyzer, ensuring license and definitions are current.
Configure a web filter profile on footy manager, use static URL and wildcard filters to block Facebook, push to HQ firewall, and verify logs in 40 analyzer.
Explore Fortinet's web filter with FortiGuard category base filter in FortiManager, enabling block, warn, or authenticate rules for streaming media and web hosting, and verify results in FortiGate logs.
Configure application control with the social media category to block Facebook, Twitter, Instagram, and LinkedIn, push the policy from 40 manager to the HQ firewall, and verify via logs.
Learn how to override a social media block by creating an application override that allows Facebook while blocking other social media, using application control and deployment steps.
Create a custom IPS security profile to block malicious URL and botnet C&C, attach it to the HQ firewall policy, and verify results using logs and 40 analyzer.
Configure a custom IPS signature in the Fortinet firewall, enable logs, and test blocking of the EICAR virus with the IPS engine; verify blocks in logs and analyzer.
Configure IPS filters to block traffic by severity levels, attach to the security policy, enable packet logging, and push the changes to the HQ firewall for verification with nmap scans.
Create a custom file filter profile in FortiManager to block PDFs, enable SSL inspection in the policy, push the config to FortiGate, and verify blocks via logs.
Configure a DNS filter profile in the Fortinet NSE7 lab, enable it under security profile, block botnet DNS requests with 2.2.2 redirection, and verify logs.
Explore FortiGuard theory: Fortinet’s threat intelligence and security subscription powering FortiGate devices with real-time antivirus, intrusion prevention, web filtering, anti-spam, and more, plus command line interface and license management.
Configure FortiManager as a local FortiGuard server by enabling web filtering and update services on both management ports, then join Fortigate devices via GUI or script and manage updates.
Master high availability concepts like failover, redundancy, and clustering to keep services up. Use automatic backups, multiple devices, backup links, and protocols such as hsrp vrrp glbp and fortigate clustering.
Explore Fortigate high availability by pairing two firewalls in active-passive or active-active modes, using heartbeat links to synchronize and enable automatic failover for continuous services.
Explore high availability terminology for FortiGate firewalls, including failover, heartbeat, link monitoring, and how primary and secondary devices manage sessions and priorities.
Explore high availability for fortigate firewalls, comparing Fortigate clustering protocol, session life support, and VRRP open standards, and learn how active-active and active-passive configurations maintain traffic during failures.
Learn to configure an active-passive FortiGate HA cluster in GCP using FortiGate clustering protocol, with heartbeat ports 3 and 4, and verify failover via CLI and graphical dashboard.
Configure active active FortiGate clustering with two firewalls using a ha g group, heartbeat on ports, session pickup, and override to synchronize primary and secondary units.
Configure a FortiGate VRRP lab to link two firewalls, set a virtual gateway at 192.168.1.254, and prioritize master 200 and backup 50. Verify failover via 8.8.8.8 tests.
Course Description:
Fortinet NSE 7 Enterprise Firewall training prepares learners to integrate, administer, troubleshoot, and manage an enterprise firewall solution that relies on FortiOS, FortiManager, and FortiAnalyzer. After finishing the videos in this Fortinet NSE 7 Enterprise Firewall training, you'll know how to integrate, administer, troubleshoot, and manage an enterprise firewall solution that relies on FortiOS, FortiManager, and FortiAnalyzer. You will explore Fortinet Security Fabric, VPN, and how to protect your network using security profiles, such as IPS, antivirus, web filtering, application control, and advanced routing.
FCSS:
The FCSS in Network Security certification validates your ability to design, administer, monitor, and troubleshoot Fortinet network security solutions. This curriculum covers network security infrastructures using advanced Fortinet solutions. You will receive this certification, if you have passed any version of the Fortinet NSE 7—Enterprise Firewall exam and one of the following exams:
Fortinet NSE 7–SD-WAN
Fortinet NSE 7–LAN Edge
Fortinet NSE 7–Secure Access
Fortinet NSE 7–Network Security 7.2 Support Engineer
Objectives:
After completing this course, you should be able to:
o Integrate multiple FortiGate devices using the Fortinet Security Fabric.
o Integrate multiple FortiGate devices with FortiManager & FortiAnalyzer.
o Centralize the management and monitoring of network security events.
o Harden the enterprise services using IPS and Security Profiles.
o Implement a high availability solution on FortiGate Firewalls.
o Deploy IPsec tunnels to multiple sites using the FortiManager VPN console.
o Configure ADVPN to enable on-demand VPN tunnels between sites.
o Combine OSPF and BGP to route the enterprise traffic.
Target Audience:
The Enterprise Firewall course is intended for networking and security professionals who are involved in the administration and support of a security infrastructure using FortiGate appliances. This includes network managers, administrators, installers, sales engineers, systems engineers, professional services engineers (presales and post sales) and technical support professionals. Anyone planning to take Enterprise Firewall course is strongly recommended to complete the FortiGate Security, FortiGate Infrastructure and FortiManager courses before this course.
Prerequisites:
This course assumes advanced knowledge of networking, and extensive hands-on experience working with FortiGate, FortiManager, and FortiAnalyzer. It is also recommended that you have an understanding of the topics covered in the following courses, or have equivalent experience: FortiManager, FortiAnalyzer, FortiGate Security and FortiGate Infrastructure.
Product Versions:
FortiGate 7.X
FortiManager 7.2.x
FortiAnalyzer 7.2.x