All certifications / FortiGate Admin / Lessons
FortiGate Admin NSE4_FGT_AD-7.6 lessons
Study FortiGate Admin for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the FortiGate Admin study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Deployment and system configuration
- Initial setup: default management IP 192.168.1.99, admin account, forced password change, interface roles and access (HTTPS, SSH, ping)
- Administrator accounts: admin profiles, trusted hosts, MFA for admins, password policy
- Firmware management: the upgrade path, config backups and restore
- VDOMs: what they separate, root VDOM, when to use multi-VDOM
- FGCP HA: active-passive vs active-active, heartbeat links, primary election (monitored ports, uptime, priority, serial, override)
- HA operations: session pickup, config sync, checksums, `get system ha status`, `execute ha manage`
- Security Fabric: root and downstream FortiGates, authorization, FortiAnalyzer/cloud logging requirement, Security Rating
- Automation stitches: triggers and actions (email, webhook, CLI script, quarantine)
- Logging: log types (traffic, event, security), severity, memory/disk/FortiAnalyzer/FortiGate Cloud/syslog, log allowed traffic
- FortiGate-VM and cloud deployments: VM licensing, public cloud images, cloud-native firewall concepts
- Diagnostics: `get system performance status`, `diagnose sys top`, conserve mode and av-failopen, `diagnose debug flow`, `diagnose sniffer packet`
Domain 2: Firewall policies and authentication
- Firewall policy matching: incoming/outgoing interface, source (address, user, ISDB), destination, service, schedule; top-down first match; implicit deny (policy 0)
- Address objects and groups, FQDN and geography objects, Internet Service Database (ISDB) entries
- Policy logging, policy lookup tool, policy ID vs sequence, schedules
- Source NAT: outgoing interface address, IP pools (overload, one-to-one, fixed port range, port block allocation)
- Central SNAT table and when to use it
- Destination NAT with VIPs: static NAT, port forwarding, VIP groups
- Firewall authentication: local users, LDAP (regular bind), RADIUS and TACACS+ servers, user groups
- Active (captive portal) vs passive authentication, authentication timeouts, allowing DNS before login
- FSSO: collector agent, DC agent mode vs polling mode, group filters, `diagnose debug authd fsso list`
- Two-factor authentication with FortiToken
Domain 3: Content inspection
- SSL/SSH inspection: certificate inspection vs deep inspection, CA trust, exemptions, certificate pinning, untrusted certificate handling
- Inspection modes: flow-based vs proxy-based, set per policy; profile-based vs policy-based NGFW mode
- Web filtering: FortiGuard categories and actions (allow, monitor, warning, authenticate, block), static URL filter (exempt vs allow), rating errors, overrides
- DNS filtering and safe search
- Application control: sensors, categories, application overrides, filter overrides, need for deep inspection
- Antivirus: flow vs proxy scanning, signature databases, FortiSandbox/cloud sandbox, content disarm and reconstruction (proxy), grayware
- IPS: sensors and signature filters, rate-based signatures, botnet C&C blocking, IP exemptions, fail-open
- DoS policies and anomaly thresholds
- Security profile logs and troubleshooting (FortiGuard connectivity, `diagnose autoupdate versions`)
Domain 4: Routing
- Route lookup order: policy routes, then the routing table (longest match, distance, priority)
- Static routes: administrative distance, priority, ECMP and load-balancing methods
- Routing table vs routing database: `get router info routing-table all` and `database`
- Reverse path forwarding (RPF) check
- Link health monitors and blackhole routes
- SD-WAN members and zones, and routes that point to the zone
- Performance SLAs: probes, latency, jitter, packet loss, SLA targets
- SD-WAN rules: manual, best quality, lowest cost (SLA), maximize bandwidth (SLA); implicit rule
- SD-WAN monitoring and troubleshooting: `diagnose sys sdwan health-check`, `diagnose sys sdwan service`
Domain 5: VPN
- IPsec basics: IKEv1 vs IKEv2, phase 1 and phase 2, proposals, DH groups, PFS, UDP 500/4500 and NAT-T
- Route-based (interface-mode) vs policy-based IPsec
- Site-to-site with static peers and dial-up (dynamic) peers
- Routes and firewall policies needed for tunnel traffic
- Redundant VPNs: two tunnels, route distance/priority, DPD, tunnel monitoring
- Topologies: hub and spoke, full mesh, partial mesh, ADVPN short-cuts
- Troubleshooting: `diagnose vpn ike gateway list`, `diagnose vpn tunnel list`, `diagnose debug application ike -1`
- Remote access VPN on FortiOS 7.6: FortiClient dial-up IPsec, and the SSL VPN changes in later 7.6 builds (tunnel mode removed, web mode renamed agentless VPN)