NSE7 — Secure Networking Architect
A 13-part walk through the official Fortinet NSE 7 - Secure Networking Architect exam blueprint (NSE7_FSN_AR-7.6). Covers the five blueprint domains in order: system configuration and SD-WAN setup, central management, security profiles, rules and routing, and advanced IPsec, closing with a full multiregion design walkthrough and exam-day notes. Requires an active NSE 4 certification plus either NSE 5 or NSE 6 Secure Networking — the NSE4, NSE5, and NSE6 series on this site cover those prerequisites.
-
NSE7 Part 1: Exam Blueprint and Study Roadmap
What the NSE 7 - Secure Networking Architect exam actually tests, how the blueprint's five domains break down by weight, the prerequisites, and the roadmap for the 13 parts that follow.
-
NSE7 Part 2: Security Fabric at Enterprise Scale
Fabric Connectors versus external connectors, Automation Stitches, and the four integration use cases the NSE 7 blueprint names by name: SAML SSO, automated IoC quarantine, FortiNAC dynamic addressing, and FortiNDR.
-
NSE7 Part 3: High Availability, FGCP, FGSP, and Where VRRP Still Fits
Active-active load balancing, virtual clustering for VDOM partitioning, FGSP standalone session sync across asymmetric and cloud topologies, and the honest case for still reaching for VRRP.
-
NSE7 Part 4: VLANs and VDOMs at Enterprise Scale
The virtual LAN switch, the three VDOM types, and the segmentation and inter-VDOM-routing use cases that separate a lab VDOM demo from a real enterprise design.
-
NSE7 Part 5: Enterprise SD-WAN Fundamentals: DIA and Monitoring
SD-WAN's basic components at the architecture level, direct internet access topologies and best practices, and the monitoring surface (widgets, traffic logs, and events) that a live deployment actually gets judged on.
-
NSE7 Part 6: Central Management, ZTP and SD-WAN Manager on FortiManager
Zero-touch provisioning of SD-WAN branches, device blueprints and CSV import, and how FortiManager's SD-WAN-specific tooling (metadata variables, IPsec templates, and the overlay template) turns one hub-and-spoke design into hundreds of devices.
-
NSE7 Part 7: Security Profiles at Scale: SSL/SSH Inspection and UTM Performance
Certificate inspection versus full inspection as a design decision, the SNI check, false positives, and the honest performance cost of stacking web filtering, application control, IPS, and ISDB.
-
NSE7 Part 8: OSPF for Enterprise Routing
The FortiOS-specific pieces the blueprint actually tests: access lists, prefix lists, route maps, redistribution, running OSPF over an IPsec interface, and ECMP with OSPF routes.
-
NSE7 Part 9: BGP for Enterprise Routing
Loopback interfaces as BGP sources, the neighbor-group command for scaling peer configuration, and optimizing for rapid convergence: route reflectors, the BFD parameter, and graceful-restart on FortiOS.
-
NSE7 Part 10: Designing SD-WAN Rules and Routing
The SD-WAN rule lookup process, application steering and learning, ISDB as a matching criterion, and the routing-table mechanics underneath it all: policy routes, the route lookup process, session tables, and what happens to routing mid-session under SNAT.
-
NSE7 Part 11: Advanced IPsec: Multihub, Multiregion, and Large Deployments
DPD modes, outbound NAT against interfaces with no IP, MTU and fragmentation, hardware offload and the NPU-Flag field, dual-hub topologies with BGP self-healing, and VRF-aware overlays for MSSP-scale deployments.
-
NSE7 Part 12: ADVPN: On-Demand Shortcuts and BGP on Loopback
Shortcut negotiation mechanics, IBGP and EBGP hub-and-spoke designs, shortcut timeout and dependent shortcuts, and what ADVPN 2.0 actually changes about a problem ADVPN 1.0 never fully solved.
-
NSE7 Part 13: A Full Design Walkthrough, and Exam Day
A two-region, dual-hub, ADVPN, VDOM-segmented MSSP design tying every domain in this series together, the diagnostic commands that confirm each layer is working, and the logistics of the exam itself.