StudyToCert

All certifications / FortiGate Admin / Lessons

Fortinet NSE 4 - FortiOS 7.6 Administrator NSE4_FGT_AD-7.6 · Domain 2: Firewall policies and authentication

Firewall policy matching: incoming/outgoing interface, source (address, user, ISDB), destination, service, schedule; top-down first match; implicit deny (policy 0)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Firewall policies are the heart of a FortiGate, and understanding exactly how a session is matched to a policy is the single most tested concept in the firewall domain. A policy is an ordered rule that says: for traffic entering on this interface and leaving on that interface, from these sources to these destinations, using these services during this schedule, take this action (accept or deny) and apply these settings.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study FortiGate Admin for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the FortiGate Admin study plan