The Fortinet NSE 4 & NSE 5 in SASE Certification Training is a comprehensive technical program designed to develop the knowledge and practical skills required to administer Fortinet security and Secure Access Service Edge (SASE) environments.
The program combines the core competencies associated with NSE 4 FortiOS Administrator with the specialized SASE competencies required for NSE 5 in SASE. It covers FortiGate administration, firewall policies, authentication, security profiles, VPN technologies, routing, SD-WAN, FortiSASE architecture, secure internet access, SaaS security, endpoint connectivity, remote-user security, monitoring, and troubleshooting.
Under Fortinet’s current certification structure, NSE 5 in SASE requires an active NSE 4 certification plus successful completion of the NSE 5 in SASE proctored exam. The SASE certification validates the ability to secure internet and SaaS access and to design, deploy, and manage small- and medium-sized SASE infrastructures.
Duration 10 Days – 70 hrs.
Objectives
- Explain Fortinet’s security architecture and the role of FortiGate and FortiSASE.
- Configure and administer FortiGate security appliances.
- Configure firewall policies, network objects, NAT, routing, and security services.
- Implement user and device authentication.
- Configure security profiles for web, application, malware, and threat protection.
- Configure and manage IPsec and SSL-based secure connectivity.
- Implement and manage Fortinet SD-WAN.
- Understand SASE concepts, architecture, components, and deployment models.
- Explain the integration of networking and cloud-delivered security within a SASE architecture.
- Configure secure connectivity for remote and hybrid users.
- Implement secure internet and SaaS access using Fortinet SASE solutions.
- Understand endpoint onboarding and FortiSASE connectivity.
- Apply security policies to users, endpoints, applications, and internet traffic.
- Monitor SASE users, sessions, applications, and security events.
- Diagnose common FortiGate, SD-WAN, and SASE connectivity issues.
- Develop the technical knowledge relevant to the NSE 4 and NSE 5 in SASE certification pathway.
Target Audience
- Network Administrators
- Network Engineers
- Security Administrators
- Security Engineers
- Cybersecurity Professionals
- Firewall Administrators
- Infrastructure Engineers
- System Administrators
- SOC Engineers
- Network Security Specialists
- SASE Engineers
- SD-WAN Engineers
- Technical Support Engineers
- IT Infrastructure Professionals
- IT Professionals responsible for Fortinet environments
- Professionals preparing for NSE 4 and NSE 5 in SASE certification
Prerequisites
- Basic to intermediate knowledge of networking concepts.
- Understanding of TCP/IP, IP addressing, and subnetting.
- Familiarity with routing, switching, DNS, DHCP, and NAT.
- Basic understanding of firewall and cybersecurity concepts.
- General knowledge of VPN and secure remote-access technologies.
- Familiarity with cloud computing and SaaS concepts is beneficial.
- Previous FortiGate experience is helpful but not mandatory.
- Basic understanding of SD-WAN is beneficial for the NSE 5 SASE portion.
Course Outline
Day 1 – Fortinet Security and FortiOS Fundamentals
Module 1: Introduction to Fortinet Security Architecture
- Fortinet security ecosystem
- FortiGate and FortiOS overview
- Fortinet Security Fabric concepts
- FortiGate deployment scenarios
- Administrative interfaces
- Initial system configuration
Module 2: FortiGate System Administration
- Administrator accounts and profiles
- System settings
- Interfaces and zones
- Configuration management
- Backup and restore
- Firmware and system maintenance
Module 3: Network Fundamentals in FortiOS
- Interface configuration
- IPv4 and IPv6 concepts
- DNS and DHCP services
- Network objects
- Address groups
- Service objects
Day 2 – Firewall Policies and Network Security
Module 4: FortiGate Firewall Policies
- Firewall policy architecture
- Policy matching and processing
- Source and destination objects
- Services and schedules
- Policy actions
- Logging and monitoring
Module 5: Network Address Translation
- Source NAT
- Destination NAT
- Virtual IPs
- Central NAT concepts
- NAT troubleshooting
Module 6: Firewall Policy Management
- Policy organization
- Policy sequencing
- Security policy best practices
- Policy optimization
- Troubleshooting policy behavior
Day 3 – Authentication and Security Profiles
Module 7: User Authentication
- Local users and groups
- Remote authentication
- LDAP and RADIUS concepts
- Authentication policies
- Identity-based security
- Single sign-on concepts
Module 8: Security Profiles
- Antivirus
- Web filtering
- DNS filtering
- Application control
- Intrusion prevention
- File filtering
- SSL/SSH inspection
Module 9: Threat Protection
- Malware protection
- Application visibility
- Threat detection
- Security profile integration
- Security event analysis
Day 4 – Routing, VPN, and Secure Connectivity
Module 10: Routing with FortiGate
- Static routing
- Policy routes
- Dynamic routing concepts
- Routing tables
- Route selection
- Routing troubleshooting
Module 11: IPsec VPN
- IPsec architecture
- Phase 1 and Phase 2 configuration
- Site-to-site VPN
- Remote connectivity concepts
- VPN monitoring
- VPN troubleshooting
Module 12: Secure Remote Access
- Remote-user security concepts
- Authentication considerations
- Secure access policies
- Remote access troubleshooting
Day 5 – SD-WAN and FortiGate Operations
Module 13: Fortinet Secure SD-WAN Fundamentals
- SD-WAN concepts
- SD-WAN architecture
- SD-WAN members and zones
- Performance SLAs
- Health checks
- Traffic steering
Module 14: SD-WAN Policies and Operations
- SD-WAN rules
- Application-aware routing
- Link selection
- Failover
- Load balancing
- SD-WAN monitoring
Module 15: FortiGate Monitoring and Troubleshooting
- Dashboard and system monitoring
- Logs and events
- Traffic analysis
- Diagnostic commands
- Packet flow concepts
- Common troubleshooting techniques
Day 6 – SASE Fundamentals and Architecture
Module 16: Introduction to Secure Access Service Edge
- Evolution of enterprise networking
- Traditional perimeter security limitations
- SASE concepts
- SASE architecture
- Networking and security convergence
- SASE use cases
Module 17: Fortinet SASE Architecture
- FortiSASE overview
- Fortinet SASE components
- Cloud-delivered security
- Points of presence
- User and branch connectivity
- Fortinet Security Fabric integration
Module 18: SASE Deployment Planning
- SASE deployment models
- Remote workforce requirements
- Branch connectivity
- Hybrid environments
- Application and SaaS access considerations
Day 7 – FortiSASE User and Endpoint Connectivity
Module 19: FortiSASE Administration
- FortiSASE management environment
- Administrative configuration
- User management
- Groups and identity
- Policy concepts
- Tenant administration
Module 20: Endpoint and Remote-User Connectivity
- Endpoint onboarding
- User authentication
- Remote-user connectivity
- Endpoint integration
- Secure internet connectivity
- User access considerations
Module 21: Identity and Access in SASE
- User identity
- Authentication integration
- Identity-based policies
- User groups
- Access controls
- Zero Trust principles in SASE
Day 8 – SASE Security Services
Module 22: Secure Internet Access
- Internet security policies
- Web security
- Application control
- DNS security
- Malware protection
- Threat prevention
Module 23: SaaS and Cloud Application Security
- SaaS application visibility
- SaaS access controls
- Cloud application risks
- Application-based policies
- Data security considerations
- Shadow IT visibility
Module 24: SSL Inspection and Advanced Security
- Encrypted traffic inspection
- Certificate considerations
- Inspection modes
- Security policy integration
- Privacy and operational considerations
Day 9 – FortiSASE and SD-WAN Integration
Module 25: SASE and SD-WAN Architecture
- Role of SD-WAN within SASE
- Branch-to-SASE connectivity
- Distributed enterprise architecture
- Secure application access
- Traffic steering concepts
- Resiliency considerations
Module 26: FortiSASE and SD-WAN Core Administration
- Core configuration concepts
- SD-WAN connectivity
- Security policy integration
- Application-aware connectivity
- Performance considerations
- Operational management
Module 27: SASE Monitoring and Visibility
- User activity monitoring
- Application visibility
- Security events
- Traffic monitoring
- Logs and reporting
- Operational dashboards
Day 10 – SASE Troubleshooting and Certification Review
Module 28: FortiSASE Troubleshooting
- Connectivity troubleshooting
- Authentication problems
- Endpoint connectivity issues
- Policy-related problems
- Application access troubleshooting
- Internet access troubleshooting
Module 29: SD-WAN and SASE Troubleshooting
- Link and tunnel issues
- Traffic steering problems
- Performance degradation
- Policy validation
- Log analysis
- Systematic troubleshooting workflow
Module 30: NSE 4 & NSE 5 in SASE Certification Review
- NSE 4 FortiOS Administrator competency review
- FortiGate administration review
- Security and networking concepts review
- NSE 5 in SASE competency review
- FortiSASE and SD-WAN concepts review
- Key configuration and troubleshooting areas
- Certification preparation guidance

