
Explore software defined wide area networks and how Fortinet sd-wan uses multi-connection virtual interfaces to dynamically choose the best path based on latency and jitter.
Explore Fortinet SD-WAN components, including FortiGate, FortiManager, FortiAnalyzer, AP and switches, and learn how management, control, data planes, and security are deployed.
Understand the five pillars of SD-WAN design—underlay, overlay, routing, security, and SD-WAN rules—and how they enable hub-and-spoke and spoke-to-spoke architectures.
Define sd-wan basics by explaining bandwidth as link capacity, delay and jitter, and show how congestion causes latency and packet loss; monitor with SLA targets and link status on FortiGate.
Compare underlay hardware infrastructure with the overlay virtual network in sd-wan, detailing ipsec tunnels, site-to-site vpns, and scalable, software-driven overlay versus hardware-dependent underlay.
Learn how to upload required Fortinet images to eve-ng and build a multi-device SD-WAN topology with FortiGate firewalls, FortiManager, and cloud links using a defined IP schema and six interfaces.
Set up a complete sd-wan lab in EVE-NG by downloading and uploading switch images and Fortinet devices, applying fixed permission, configuring IPs, and testing connectivity.
Export the lab topology to Google Drive or desktop, then import it back into the lab and reset by stopping and wiping all nodes before reuse.
In Fortinet NSE7 SD-WAN Training, learn to perform initial firewall configuration via CLI for three FortiGate devices: HQ, DC, and branch, setting hostnames, management interfaces, port configurations, and DNS.
Configure static ip addresses for HQ, branch, and data center clients according to the ip schema. Set gateways and dns, then verify with ifconfig and route, and ping gateways.
Learn how to backup, restore, and create revisions of FortiGate lab configurations to manage a 14-day evaluation license, using GUI or CLI across three firewalls.
Explore equal cost multipath (ecmp) in Fortinet sd-wan, balancing traffic across multiple next hops to the same destination. Learn load balancing methods, policy routing, and sd-wan concepts.
Explore equal cost multipath routing with two gateways, configure static routes with equal distance and priority, and observe source- and destination-based load balancing, failover, and verification.
Explore ECMP load balancing methods in an SD-WAN lab, including source IP base, weight base, usage base, and source-destination base, and verify traffic across dual links.
Explore policy routing on Fortinet FortiGate, showing how source, interface, destination, and protocol-based rules divert traffic before static and ISDB routes, with route cache and kernel routing tables.
Configure policy-based routing in Fortinet FortiGate using source and destination IP based rules. Route PC1 traffic to WAN1 and PC2 traffic to WAN2, and verify with traceroute and logs.
Create an sd-wan zone with two member interfaces, configure load balancing, add a static route, and apply a policy to route traffic across the sd-wan links.
Explore sd-wan rules and strategy, including services for path selection, implicit rules, and policy-like criteria (latency, jitter, packet loss) that dynamically choose and switch the best link.
Explore sd-wan load balancing methods, including source ip base, session/weight-based, spillover usage-based, source-destination base, and volume-based. Distinguish implicit rule balancing from user-defined rules and review default behavior.
Master sd-wan load balancing methods through hands-on labs. Test source ip base, and source/destination ip, session and volume based balancing, plus spillover thresholds, with cli and gui verification.
Configure and verify a manual sd-wan strategy rule, prioritizing when two over when one, and test using ping and traceroute across dc pc one and other hosts.
Practice configuring an SD-WAN best quality strategy, create a ping SLA, assign interface preferences, and test link selection by packet loss, latency, and jitter.
Explore the sd-wan lowest cost strategy by testing two links against latency, jitter, and packet loss, then use interface cost and top preference to choose the best path.
Demonstrates the maximize bandwidth SD-WAN rule, using both links with load balancing, ignoring interface preferences and cost, and validating with an SLA to optimize throughput.
Explore how performance SLA monitors SD-WAN links with continuous health checks, using ping and other protocols to measure latency, jitter, and packet loss, and trigger failover.
Configure and test a Fortinet sd-wan performance sla lab with active probes testing ping, http, dns, and tcp to measure latency, jitter, and packet loss; edit and monitor sla definitions.
Explore how passive and prefer passive sla modes in Fortinet sd-wan monitor latency, jitter, and packet loss using tcp-based health checks, with policy-level health measurement and cli configuration.
Monitor and diagnose sd-wan networks using dashboards and performance sla metrics; analyze bandwidth, volume, and sessions alongside packet loss, latency, jitter, and rule hits to troubleshoot and optimize sd-wan quality.
Explore the FortiGate cli as the essential alternative to graphical configuration, and learn core commands like config, get, show, diagnose, execute, alias, and exit with tab completion.
Configure sd-wan on the branch firewall via CLI, creating a zone and adding a member with gateway and static routes. Set load balancing and verify health checks and SLA thresholds.
Learn to migrate existing interfaces to sd-wan using integrated interfaces, automatically updating zones, policies, and routes while preserving configurations and avoiding manual deletion.
Learn how FortiManager centralizes management of Fortinet devices, enabling template-based policies, centralized configuration, and SD-WAN deployment from a single console.
Perform the FortiManager first time configuration by setting management and inside interfaces, adding a static route, and activating a license via FortiCloud or 40 cloud.
Add a FortiGate firewall to FortiManager by enabling 40 manager access on the LAN interface, creating a dom with a version, discovering the device in device manager, and importing policies.
Enable display options in FortiManager to reveal all policy and object settings, manage certificates, and prepare FortiGate management features for future labs.
Configure sd-wan through FortiManager by unifying the FortiGate under FortiManager, remove existing static routes and policies, then create an sd-wan zone with members, sla, and monitoring.
Explore sd-wan monitoring via FortiManager, viewing device location on a map, monitoring bandwidth, volume, sessions, service level agreement, and per-interface latency, jitter, and packet loss, with table and map views.
Learn how FortiGate builds a session table to track traffic and uses dirty and murder session flags as policies evolve. Understand how TCP/UDP/ICMP states guide session creation and return traffic.
Master cryptography fundamentals for VPN and network traffic protection by learning encryption and decryption, plaintext and ciphertext, and key concepts like confidentiality, integrity, and authentication.
Contrast symmetric encryption with a single key and asymmetric encryption with public and private keys, noting symmetric is faster and lighter than asymmetric.
Explore how hash functions generate a fixed-size digest from data to ensure integrity with MD5 and SHA variants, and how MAC and HMAC provide authentication for VPNs and IPsec.
Explain how diffie-hellman lets two parties derive a shared secret over an insecure network without exchanging private keys, using primes, generators, and group options.
discover ipsec, an open standard that secures side-to-side and remote access vpn with esp or ah, delivering confidentiality, integrity, and authentication.
Explore how internet key exchange negotiates IPsec security associations between VPN peers, configuring authentication, encryption, hash, group, and lifetime across phase one and phase two, including IKEv1 and IKEv2.
Discover how virtual private networks secure data across public networks with IPsec and SSL/TLS, offering site-to-site and remote access VPNs, client-based and clientless options, and strong protections.
Explore Fortinet ADVPN and its transition from hub-and-spoke topologies to dynamic spoke-to-spoke tunnels, reducing single points of failure, latency, and cost.
Master Advanced SD‑WAN Design, Deployment & Troubleshooting with FortiOS 7.x
This course is designed for professionals who want to master Fortinet Secure SD‑WAN and validate their skills through the Fortinet NSE7 SD‑WAN certification exam. Whether you’re improving your existing Fortinet knowledge or continuing from the FortiGate NSE4 Part 1 & Part 2, this course gives you the complete theory and hands‑on practice needed to deploy SD‑WAN in real enterprise environments.
You will learn how to design, configure, optimize, and troubleshoot SD‑WAN using FortiGate and FortiManager — supported by a full EVE‑NG + VMware lab environment included at no additional cost. A minimum of 16GB RAM is recommended for smooth lab performance.
This training helps you deliver superior solutions to clients, improve operational efficiency, and elevate your professional career.
What You Will Learn
Capabilities of the Fortinet Secure SD‑WAN solution
SD‑WAN components, architecture, and key terminologies
ECMP concepts and ECMP load‑balancing methods
Policy routing fundamentals and configuration
Firewall session behavior: clean, dirty, and may‑dirty sessions
Performance SLAs and link‑health monitoring
Deploying SD‑WAN using FortiManager
Configuring basic SD‑WAN features
Configuring advanced SD‑WAN features
SD‑WAN route and rule lookup process
Rule criteria, strategies, and decision logic
SD‑WAN response to changing link conditions
Deploying SD‑WAN with basic IPsec + routing
Deploying SD‑WAN with advanced IPsec + routing
Troubleshooting SD‑WAN routing and rule‑matching issues
Course Overview
This course covers common SD‑WAN deployment scenarios using Fortinet Secure SD‑WAN. You will learn how to configure SD‑WAN rules, performance SLAs, IPsec tunnels, routing strategies, and advanced automation using FortiManager. The course includes extensive hands‑on labs to reinforce every concept.
Why This Course Is Valuable
Hands‑on labs using EVE‑NG and VMware (included at no extra cost)
Real enterprise deployment scenarios — not just theory
Clear explanations suitable for beginners and experienced engineers
Perfect continuation of your FortiGate NSE4 training
Covers all exam‑relevant topics for NSE7 SD‑WAN
Ideal for engineers designing or supporting SD‑WAN infrastructures
Who Should Enroll
Network & Security Engineers
Fortinet professionals designing SD‑WAN solutions
SOC/NOC analysts supporting distributed networks
IT managers overseeing WAN modernization projects
Candidates preparing for the NSE7 SD‑WAN certification exam
Prerequisites
Basic networking fundamentals
Familiarity with FortiGate recommended (NSE4 Part 1 & Part 2 ideal)
16GB RAM recommended for lab environment
Product Versions Covered
FortiOS 7.x
FortiManager 7.2.0
Start Mastering Fortinet Secure SD‑WAN Today
Gain the skills to design, deploy, and troubleshoot SD‑WAN solutions — and confidently prepare for the NSE7 certification.