Home About For organisations The labs Gallery FAQ Contact
Fortinet NSE 4 - FortiOS Administrator

FortiGate firewall administration (NSE 4)
Professional-level course

Preparation for the NSE 4 certification - configuring, operating and troubleshooting a FortiGate firewall on real appliances in the lab. Participants leave able to run a FortiGate firewall on their own: policies, NAT, user authentication, content inspection, routing, IPsec VPN and a high-availability cluster.

Registration
Open now
Duration
65 academic hours
Format
In personHybrid
Level
Professional
Certification
Fortinet NSE 4 - FortiOS Administrator
Language
Hebrew, course materials in English
For organisations
4 intensive days - at the academy or hybrid

What you will be able to do

  • Set up a FortiGate firewall from factory defaults - administrator access, GUI and CLI, device registration and log settings.
  • Build IPv4 firewall policies with port forwarding, source NAT and destination NAT, and authenticate users with LDAP, RADIUS and FSSO.
  • Inspect encrypted traffic with certificates and apply web filtering, application control, antivirus and IPS.
  • Route traffic with static routes and distribute it across WAN links with SD-WAN.
  • Connect sites over IPsec VPN and run an FGCP high-availability cluster.
  • Diagnose resource and connectivity problems from the logs and the CLI.

The syllabus

14 modules over 65 academic hours. Open a module for its topics.

  • The FortiGate appliance and the FortiOS architecture
  • Working in the GUI and the CLI
  • Initial configuration, administrative access, system settings
  • DNS and NTP
  • Configuration backup and restore
  • Firmware upgrade and keeping the system maintained

  • Physical and logical interfaces
  • VLANs and zones
  • The DHCP server
  • Connectivity checks

  • Connected routes, static routing, default routes
  • The routing table
  • Administrative distance and priority
  • Route selection
  • Routing redundancy and load balancing

  • The stateful firewall and the structure of a policy
  • Address and service objects
  • Policy matching, policy order, the implicit deny
  • Sessions and traffic logging
  • Flow-based and proxy-based inspection

  • Source NAT, interface NAT, IP pools
  • Destination NAT, virtual IP, port forwarding
  • NAT together with the firewall policies

  • Local users and groups, AAA concepts
  • Active and passive authentication
  • LDAP and RADIUS
  • Identity-based firewall policies and user monitoring
  • FSSO architecture, the collector agent, DC agent mode
  • Active Directory integration, group filtering, FSSO troubleshooting

  • SD-WAN architecture, members and zones
  • Performance SLA and health checks
  • Latency, jitter and packet loss
  • Traffic steering and SD-WAN rules
  • WAN failover, routing behaviour, link quality and monitoring

  • FGCP and active-passive HA
  • Primary election and heartbeat interfaces
  • Configuration and session synchronisation, session pickup
  • Monitored interfaces, HA management, failover
  • Upgrading firmware on a cluster

  • IPsec architecture, IKE, phase 1 and phase 2
  • Site-to-site VPN and the IPsec wizard
  • Routing and firewall policies for a tunnel
  • Redundant IPsec VPN, VPN logs, troubleshooting

  • PKI fundamentals, certificates and certificate authorities
  • The certificate chain and endpoint trust
  • Certificate inspection and full SSL inspection
  • Inspection profiles and troubleshooting encrypted traffic

  • FortiGuard categories, web filter profiles, URL filtering
  • Static URL filters, flow and proxy inspection, events and logs
  • Application signatures and categories
  • Allow, monitor and block; application control profiles
  • Application detection and troubleshooting

  • Antivirus profiles, flow-based and proxy-based scanning
  • Protocol options, malware inspection, HTTPS inspection
  • IPS sensors, signatures, signature filters
  • Severity and actions, exploit detection, security events
  • Performance considerations and IPS troubleshooting

  • Traffic, event and security logs
  • The session table and the routing table
  • The packet sniffer and debug flow
  • CPU and memory monitoring, conserve mode
  • A working method for finding and fixing faults

  • The FortiGate VM and public cloud security concepts
  • FortiGate CNF
  • FortiSASE architecture and its security capabilities
  • Remote user connectivity and user onboarding
FortiGate firewall administration (NSE 4) Registering now +972 8-669-8400

Who it is for

Who takes this course, and what you need before the first session.

Network administrators taking over the firewall

IT and support technicians moving into network security

Teams that run FortiGate firewalls and want one common baseline

Prerequisites

Knowledge of network protocols and a basic understanding of firewall concepts; for the exam itself Fortinet recommends 1-2 years of networking experience.

The exam and the certification

The exam is Fortinet NSE 4 - FortiOS Administrator: 50-55 questions in 80-90 minutes, in English, at a Pearson VUE test centre or online through OnVUE. Each cohort follows the exam topics Fortinet publishes. The certification is valid for two years from the exam date, and it is the base every NSE 5, NSE 6 and NSE 7 certification is built on. We help with the Pearson VUE booking.

Fortinet NSE 4 - FortiOS Administrator

The certification

Fortinet NSE 4 - FortiOS Administrator

How it is sat

Through Pearson VUE, in English - at a test centre, or online with OnVUE for the NSE 4, 5 and 6 exams. NSE 7 exams are test-centre only from September 21, 2026.

Validity

Two years, like every Fortinet certification. NSE 5 and NSE 6 need an active NSE 4; passing NSE 7 renews NSE 1-4 and the NSE 5 or NSE 6 in the same track.

Retakes

A failed exam can be retaken after 15 days.

Where this course sits on the Fortinet ladder. The lit rung is the one it prepares for; the whole path, with what each level requires, is on the Fortinet track page.

The Fortinet track
  1. NSE 1-3 Cybersecurity fundamentals - free self-paced courses
  2. NSE 4 FortiOS Administrator Preparation at the academy
  3. NSE 5 Specialisation in a range of subjects, at Professional level
  4. NSE 6 Specialisation in a range of subjects, at Professional level
  5. NSE 7 Specialisation in a range of subjects, at an advanced level
  6. NSE 8 Cybersecurity Expert

The labs

You work on FortiGate firewalls from the academy's rack in Shoham, with FortiGate VMs in the virtual lab for the topologies that need more than one unit: two firewalls in an FGCP cluster, an IPsec VPN between two sites, SD-WAN over two WAN links. The logs go to a FortiAnalyzer lab environment built for the course, and Windows Server in the virtual lab stands behind the authentication labs - LDAP, RADIUS and FSSO. In the hybrid format the sessions held away from the classroom reach the same equipment through the virtual lab.

Real equipmentShohamHands-on
About the labs

What you build in the labs

The exercises of the course, in the order they come. Each one is built from nothing, verified, and then diagnosed when it is broken on purpose.

  • Standing a FortiGate up from nothing
  • Building VLANs and routing
  • Firewall policies and NAT
  • LDAP, RADIUS and FSSO
  • SD-WAN and WAN failover
  • High availability
  • Site-to-site and redundant IPsec VPN
  • SSL inspection
  • Web filtering and application control
  • Antivirus and IPS
  • Logging and diagnostics

Two ways to take the course

An open cohort for people enrolling themselves, or an intensive format for a team. The syllabus is the same; the pace and the place are set with you.

Open cohort

Registration is open. The dates on offer are in the registration form - choose the one that suits you and leave your details, and we will come back to you to confirm a place.

For your team

4 intensive days - at the academy in Shoham, or hybrid with part of the sessions remote. Small groups, and a syllabus adjusted to your equipment and environment.

Leave us your details

A few lines about what you are after - a course for yourself or training for a team - are enough. The message reaches the academy team directly.

Who is this for