Fortinet NSE 6 - FortiAuthenticator 6.4 Exam Guide
The Fortinet NSE 6 - FortiAuthenticator 6.4 exam is aimed at practitioners who configure and operate FortiAuthenticator as an authentication and identity-management service. The available Fortinet material points to administration of LDAP, RADIUS, certificates, two-factor authentication, SAML, portals, 802.1X, FSSO, OAuth, and FIDO2 rather than simple product recognition. This guide helps you decide whether your current experience is sufficient, which documentation and lab tasks to prioritize, how the historical 6.4 exam fits Fortinet’s certification transition, and what to verify before booking.
What does the FortiAuthenticator 6.4 exam validate?
The exam validates practical administration of FortiAuthenticator 6.4 across authentication, identity, certificate, access, and integration functions. Fortinet’s 6.4 product documentation describes FortiAuthenticator as a centralized authentication service for the Fortinet Security Fabric, including single sign-on, certificate management, and guest management. The associated administrator training adds LDAP, RADIUS, two-factor authentication, SAML single sign-on, FSSO, portals, 802.1X, OAuth, and FIDO2. [https://docs2.fortinet.com/product/fortiauthenticator/6.4] [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
The product role behind the syllabus
Treat FortiAuthenticator as an identity control point, not as an isolated login page. It can provide authentication services to other systems, manage users and authentication methods, support certificate workflows, and exchange identity information with Fortinet products and standards-based services. Your preparation should therefore connect each feature to its client, protocol, identity source, policy decision, and troubleshooting evidence.
The FortiAuthenticator 6.4 documentation set is the most appropriate product-version reference supplied for this exam. The 6.4.6 release notes also identify strong authentication, wireless 802.1X authentication, certificate management, RADIUS authentication, authorization and accounting, and Fortinet Single Sign-On as product capabilities. [https://docs.fortinet.com/document/fortiauthenticator/6.4.6/release-notes/355786/fortiauthenticator-6-4-6-release]
Who should consider this exam
Fortinet recommends the related administrator training for people responsible for the day-to-day management of FortiAuthenticator. That is a better fit than approaching the exam as a general security overview: candidates should be able to make configuration decisions, recognize dependencies, and investigate failed authentication. Network and security administrators who support FortiGate-integrated identity services are natural candidates, provided they also understand the relevant FortiOS foundations. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
What should you verify before scheduling?
Verify the exam’s current name, availability, version, prerequisite rules, delivery choices, and booking path in your Fortinet Training Institute account before paying or scheduling. The supplied evidence confirms the historical FortiAuthenticator Administrator exam mapping and general NSE 6 certification rules, but it does not provide a current 6.4 exam blueprint, question count, duration, languages, price, or retirement date. Those details should not be guessed from third-party listings.
Historical 6.4 and the 2026 certification transition
Fortinet announced that the NSE 6 FortiAuthenticator 6.4 exam was released after September 15, 2022. A Fortinet transition article states that, under the certification transition effective July 15, 2026, the FortiAuthenticator Administrator exam maps to NSE 6 in Secure Networking. These are different pieces of information: the first identifies the historical exam release context, while the second explains the later certification mapping. [https://www.fortinet.com/content/dam/fortinet/assets/training/q4-22-nse-training-newsletter.pdf] [https://helpdesk.training.fortinet.com/support/solutions/articles/73000667144-how-will-recent-exams-transition-to-the-new-nse-certifications-on-july-15-2026-]
Because certification policy and exam catalogues can change, do not assume that an old exam title, a current certification track, or a product version remains bookable. Check the official exam catalogue and the transition FAQ immediately before scheduling. The supplied official transition material says that the updated NSE Certification Program grants an NSE certification after passing one exam at each NSE level and certification track; it does not by itself establish every booking detail for a historical 6.4 exam. [https://helpdesk.training.fortinet.com/support/solutions/articles/73000667144-how-will-recent-exams-transition-to-the-new-nse-certifications-on-july-15-2026-]
Prerequisite and certification decision
The current NSE 6 in Secure Networking requirements specify an active NSE 4 FortiOS certification and passing one proctored NSE 6 Security Networking exam within two years. The FortiAuthenticator Administrator exam is listed in the transition mapping as an NSE 6 in Secure Networking exam. Confirm how this rule applies to your intended exam and certification date, especially if your NSE 4 status is expired or your exam was taken under an earlier program. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking] [https://helpdesk.training.fortinet.com/support/solutions/articles/73000667144-how-will-recent-exams-transition-to-the-new-nse-certifications-on-july-15-2026-]
Fortinet states that the NSE 6 certification is active for two years from the date of the second exam under the current Secure Networking requirements. It also states that the NSE 6 certification is issued on the same date as the NSE 4 certification when the NSE 4 requirement is completed afterward within the stated scenario. These rules make certification timing a scheduling decision, not merely an administrative detail. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Which skills deserve the most study time?
The supplied official material does not include percentage weights or a measured-skills table for the FortiAuthenticator 6.4 exam. Do not create a percentage-based study plan from unsupported figures. Instead, use the official administrator course objectives and the FortiAuthenticator 6.4 documentation as the working scope, then allocate time according to your practical weakness and the importance of each service to your intended role.
Initial configuration, administration, and availability
Begin with deployment and baseline administration. You should be able to explain how an administrator reaches the appliance, how administrative users are managed, and what changes when high availability is introduced. The training agenda explicitly includes introduction and initial configuration, administrative users, and high availability. The supplied 6.4 administration references also identify high availability, firmware upgrades, and integration information as relevant documentation areas. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator] [https://docs.fortinet.com/document/fortiauthenticator/latest/administration-guide/80962/fortiauthenticator-6-2-0]
Study this area as a sequence rather than a list of menu names: define the service role, establish management access, configure identity sources, enable a required service, test a client, and record the evidence that confirms success. Repeat the sequence after introducing a failure or a failover condition. This develops the operational reasoning that memorizing interface labels cannot provide.
Users, LDAP, RADIUS, and AAA
User administration and authentication services form the core of the preparation plan. Fortinet’s course objectives include configuring LDAP and RADIUS services, administering and troubleshooting users, and using FortiAuthenticator for two-factor authentication. The course prerequisite also recommends familiarity with authentication, authorization, and accounting, so revise AAA concepts before attempting complex integrations. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
For every lab, write down four answers: where the user record originates, which service receives the request, how the user is authorized, and what accounting or event evidence is generated. Then deliberately test a wrong shared secret, an unavailable directory, an unknown user, an authorization mismatch, and an invalid token. The purpose is to learn to isolate the failing layer rather than repeatedly changing unrelated settings.
Two-factor authentication and FortiToken
Two-factor authentication is not only a token-enrollment task. The objectives include configuring FortiAuthenticator and FortiGate for two-factor authentication and provisioning FortiToken hardware and mobile software tokens. Prepare to trace enrollment, assignment, challenge, verification, and recovery as separate stages, including the relationship between the FortiAuthenticator configuration and the FortiGate request. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
A useful exercise is to document the expected flow for a valid user, then identify what would happen if the token is unassigned, the user is disabled, the client cannot reach the authentication service, or the request does not match the intended policy. Avoid studying token terminology without drawing the end-to-end transaction.
FSSO and identity propagation
Fortinet Single Sign-On is a distinct study area because it concerns how identity information is collected and communicated for access decisions. The course agenda covers the FSSO process and methods, deployment, and troubleshooting, while the objectives include configuring FortiAuthenticator as a logon event collector using the FSSO communication framework. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
Prepare by mapping the source of the logon event, the component that collects or receives it, the identity group or association created, and the Fortinet device that consumes the information. Troubleshooting should begin with event visibility and identity correctness before you inspect downstream policy behavior. This prevents confusing an FSSO collection problem with a FortiGate authorization problem.
Portals, guest access, and self-service
Portal services combine user experience with identity administration. Fortinet lists self-service portal configuration, guest and local user management, and portal services in the course objectives and agenda. Prepare to distinguish a portal’s purpose, the user population it serves, the information it collects, and the authentication or account-management action it triggers. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
Create a small design note for a guest workflow: account creation, activation or verification, access period, authentication, and administrative visibility. Then compare it with a self-service workflow for an existing local or directory-backed user. This contrast helps you reason about identity lifecycle rather than treating all portals as interchangeable pages.
PKI, certificates, and SCEP
Certificate management deserves deliberate practice because it spans trust, issuance, service identity, and revocation. The objectives cover root CA, subordinate CA, user, and local-service certificates; SCEP; certificate revocation lists; and certificate signing requests. FortiAuthenticator documentation also includes certificate-management coverage. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator] [https://docs.fortinet.com/document/fortiauthenticator/latest/administration-guide/80962/fortiauthenticator-6-2-0]
Build a certificate map that labels the issuer, subject, intended use, trust anchor, renewal responsibility, and revocation path. Practice identifying which certificate belongs on a service, which certificate a client must trust, and where a CSR is generated. Include an expired certificate and an incomplete chain in troubleshooting exercises. The important distinction is between possessing a certificate and establishing a verifiable trust relationship.
802.1X and EAP decision-making
The course objectives cover wired and wireless 802.1X authentication, MAC-based authentication, machine-based authentication, and supported EAP methods. These topics require more than recalling acronyms: you need to connect the endpoint, authenticator, authentication server, identity source, certificate or credential, and authorization result. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
For each access method, record what the endpoint presents, which system forwards the request, what FortiAuthenticator validates, and what the network device does after success or failure. Compare user-based, machine-based, and MAC-based scenarios. When reviewing a failure, ask whether the problem is endpoint supplicant configuration, certificate trust, EAP selection, RADIUS reachability, directory lookup, or authorization.
OAuth, SAML, SCIM, and FIDO2
The administrator course includes the fundamentals of OAuth, SAML, and SCIM, configuring SAML identity-provider and service-provider roles, monitoring and troubleshooting SAML, and configuring FIDO for passwordless authentication. Study these as separate protocol roles and flows, not as one broad category called single sign-on. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
For SAML, make two diagrams: FortiAuthenticator acting as identity provider and FortiAuthenticator acting as service provider. Label the relying application, assertions, trust configuration, user identity, and failure point. For OAuth, distinguish the authorization function from the protected resource. For FIDO2, focus on the passwordless authentication relationship and enrollment lifecycle. Use the documentation to confirm version-specific terminology before final revision.
How should you turn documentation into exam preparation?
Use a three-pass method: understand the service, perform a controlled configuration, and troubleshoot a deliberately broken configuration. Read the FortiAuthenticator 6.4 documentation with a task in mind, reproduce the task in an authorized lab, and keep a short decision log explaining why each setting was selected. This is more reliable than highlighting every page or collecting isolated commands.
Pass one: build a service map
Start with the 6.4 product documentation and create a map of service families: administration and availability; users and directories; RADIUS and AAA; tokens and strong authentication; FSSO; portals; PKI; 802.1X; OAuth; SAML; SCIM; and FIDO2. For each family, write its purpose, dependencies, client systems, and likely evidence of success. The supplied documentation portal is the authoritative starting point for version-specific references. [https://docs2.fortinet.com/product/fortiauthenticator/6.4]
Do not read every topic with equal intensity on the first pass. Mark concepts you can explain but cannot configure, concepts you can configure but cannot troubleshoot, and concepts you have not yet encountered. Those three labels produce a more useful study backlog than a generic checklist.
Pass two: perform complete workflows
A workflow is complete only when you can configure it, test a successful transaction, inspect the result, and undo or adjust the configuration safely. Use the administrator course objectives as lab prompts, but verify product-version behavior in the 6.4 documentation rather than assuming that a current course interface is identical to the historical exam version. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
Useful lab records contain the initial state, intended outcome, dependencies, configuration decisions, test input, observed evidence, and rollback step. Keep credentials, certificates, and tokens inside an authorized lab. Never use leaked questions or unauthorized exam material as a substitute for product practice.
Pass three: troubleshoot by layer
Troubleshooting questions become easier when you classify the failure before changing settings. Check reachability and time first, then service configuration, protocol exchange, identity lookup, authentication result, authorization result, and downstream enforcement. This layered method applies to RADIUS, LDAP, SAML, certificates, 802.1X, FSSO, and token workflows, although the available logs and protocol details differ. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
For each failure, write the smallest test that separates two possible causes. For example, if a RADIUS request fails, test whether the request reaches the service before changing the user record. If SAML fails, separate metadata or trust problems from assertion or account-mapping problems. If 802.1X fails, separate EAP negotiation from RADIUS authorization.
What study resources are appropriate?
Use Fortinet’s FortiAuthenticator 6.4 documentation for version-specific behavior, the official administrator course for a structured task sequence, and the release notes for upgrade, integration, resolved-issue, and known-issue context. The course page offers self-paced training and instructor-led options, but the supplied evidence does not establish that every current course version matches the historical 6.4 exam. Treat current training as a learning aid and verify version alignment. [https://docs2.fortinet.com/product/fortiauthenticator/6.4] [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator] [https://docs.fortinet.com/document/fortiauthenticator/6.4.6/release-notes/355786/355786/fortiauthenticator-6-4-6-release]
Using the administrator course without mistaking it for the exam
The course description says it teaches secure authentication and identity management, deployment, certificate management, two-factor authentication, LDAP and RADIUS authentication, and SAML single sign-on. Its objectives provide a practical scope, but the course page also lists current product versions as FortiAuthenticator 8.0 and FortiGate 7.6. Therefore, use its workflow structure while checking the 6.4 manuals for labels, supported behavior, and release-specific differences. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
The course page states that the online format requires a high-speed Internet connection, an up-to-date web browser, a PDF viewer, speakers or headphones, and either HTML 5 support or an up-to-date Java Runtime Environment with Java Plugin enabled. It also recommends a wired Ethernet connection and requires firewalls to allow online-lab connections. These are course requirements, not evidence of exam delivery requirements. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
Using release notes intelligently
Release notes are most useful near the end of preparation. Review hardware and virtual-machine support, upgrade instructions, product integrations, resolved issues, and known issues, all of which are identified in the supplied FortiAuthenticator 6.4.6 release-note evidence. Do not turn release-note reading into memorization of issue identifiers; use it to understand operational constraints and to find the correct version-specific documentation. [https://docs.fortinet.com/document/fortiauthenticator/6.4.6/release-notes/355786/355786/fortiauthenticator-6-4-6-release]
What delivery details are officially supported?
The current Fortinet NSE 6 certification page states that certification exams are available worldwide at Pearson VUE test centers and through OnVUE. It also states that exams include multiple-choice and drag-and-drop questions, answers must be 100% correct to receive credit, no partial credit is awarded, and there are no deductions for incorrect answers. The supplied evidence does not establish the FortiAuthenticator 6.4 exam’s duration, question count, language, or current booking status. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
How to prepare for the scoring model
Because the stated scoring method awards credit only when an answer is 100% correct, read every option for scope, prerequisites, sequence, and side effects. Do not select an answer merely because it contains a familiar feature name. The statement about no deductions for incorrect answers supports answering every item, but it does not make rapid guessing a preparation strategy. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Drag-and-drop practice should focus on relationships and order: map a component to its role, place a workflow step in sequence, or associate a failure with the correct layer. Build these exercises from your own lab notes rather than seeking purported live questions. Exam dumps and leaked questions are not reliable evidence of current objectives and do not replace verified product knowledge.
Retake and result planning
Fortinet states that a candidate must wait 15 days before retaking a failed exam and cannot retake an exam already passed. Schedule the first attempt only after reviewing your weak areas, completing representative workflows, and confirming the current exam listing. If a retake becomes necessary, use the waiting period to repair specific knowledge gaps instead of repeating the same reading plan. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Which mistakes most often weaken preparation?
The most damaging mistakes are version confusion, feature-name memorization, skipping troubleshooting, and ignoring certification prerequisites. Candidates also lose time by trying to cover every protocol at the same depth or by using unsupported exam specifications as a planning anchor. A disciplined scope, version check, and lab evidence are safer than a larger pile of notes.
Mistake: treating current course content as 6.4 proof
The official course page currently identifies FortiAuthenticator 8.0 and FortiGate 7.6 as product versions, while this guide concerns FortiAuthenticator 6.4. That does not make the course useless; it means you must compare its objectives with the 6.4 documentation. Highlight any changed menu path, protocol behavior, integration, or prerequisite and resolve it from the version-specific source. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
Mistake: studying protocols without roles
SAML, OAuth, RADIUS, LDAP, SCEP, and FIDO2 are not interchangeable labels. A candidate who remembers definitions but cannot identify the client, server, trust relationship, credential, assertion, or authorization result will struggle with configuration and troubleshooting scenarios. Draw a role diagram for every protocol and explain one valid flow and one failure flow aloud.
Mistake: skipping identity lifecycle tasks
Authentication is only one part of administration. Include user creation or synchronization, group and authorization handling, token assignment, certificate issuance and renewal, guest access, self-service, and account troubleshooting. These lifecycle tasks reveal whether you understand how an identity is created, trusted, used, monitored, and removed.
Mistake: assuming a successful login proves the design
A single successful login does not prove correct authorization, failover, certificate trust, accounting, or downstream enforcement. Add negative tests and inspect the relevant evidence. A strong lab result explains why the transaction succeeded and identifies the exact observation that would prove failure in a production incident.
What is a practical study roadmap?
A practical roadmap moves from dependencies to core authentication, then to identity propagation, PKI and network access, federation, and finally mixed troubleshooting. The sequence below is a recommendation, not an official exam schedule. Adjust it to your experience and use the 6.4 documentation to confirm every version-sensitive behavior.
Stage one: confirm scope and prerequisites
Open the official FortiAuthenticator 6.4 documentation, the FortiAuthenticator Administrator course page, and the current NSE certification page. Confirm your NSE 4 FortiOS status and determine whether you are pursuing the historical 6.4 exam, a mapped certification, or another current exam. Record questions the booking portal must answer, including availability and version. [https://docs2.fortinet.com/product/fortiauthenticator/6.4] [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator] [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Stage two: establish the administration baseline
Practice initial configuration, administrative access, user administration, high availability concepts, and safe upgrade planning. Create a one-page architecture diagram showing management access, identity sources, authentication services, Fortinet clients, and logging or monitoring evidence. Do not proceed to advanced federation until you can explain the baseline dependencies.
Stage three: master core authentication
Configure and test LDAP, RADIUS, AAA behavior, two-factor authentication, and FortiToken workflows. For each service, include a valid transaction and at least one failure caused by a deliberately incorrect dependency. Keep a troubleshooting table with symptom, likely layer, test, evidence, and correction.
Stage four: add identity and access services
Work through FSSO, portals, guest or local user management, wired and wireless 802.1X, MAC-based authentication, and machine-based authentication. Compare the identity and authorization path for each. This stage is where a diagram-driven approach pays off: similar-looking access failures can originate in very different components.
Stage five: complete the trust and federation layer
Practice root and subordinate CA relationships, user and service certificates, CSR and CRL handling, SCEP, OAuth, SAML identity-provider and service-provider roles, SCIM fundamentals, and FIDO2. At the end, explain which system trusts which certificate or assertion and what event would invalidate that trust.
Stage six: run a readiness review
Close the manuals and rebuild selected workflows from your notes. Explain each configuration choice, troubleshoot a broken transaction, and identify the version source for any uncertain behavior. Review official booking and certification information again, then schedule only after the exam title, version, prerequisite status, and delivery option are clear.
How can you tell whether you are ready?
You are ready to schedule when you can perform the major administrator workflows without copying a procedure line by line and can diagnose failures by layer. Readiness is demonstrated by repeatable configuration and explanation, not by recognizing product terms or finishing a large number of practice questions.
A capability-based self-check
You should be able to explain FortiAuthenticator’s centralized authentication role; deploy and configure the service; configure LDAP and RADIUS; administer users; troubleshoot authentication; provision FortiToken hardware and mobile software tokens; configure FSSO; operate portal services; manage certificates and SCEP; support 802.1X; configure OAuth and SAML roles; monitor and troubleshoot SAML; and configure FIDO2 passwordless authentication. These capabilities come from the official administrator course objectives. [https://training.fortinet.com/local/staticpage/view.php?page=library_fortiauthenticator-administrator]
A final documentation check
For every topic you mark as ready, retain one version-specific reference and one practical test result. For every topic you mark as uncertain, write a precise question rather than a vague note such as “review SAML.” Examples include “Which side initiates this exchange in the intended deployment?” or “What evidence distinguishes an untrusted certificate from an account-mapping failure?” Precise questions make final review efficient.
What should you do after passing?
After passing, verify the result and certification status in your Fortinet Training Institute account, then record the certification and exam dates for renewal planning. Fortinet states that the Training Institute account is updated within 5 business days after passing an exam for digital-badge purposes. Continue maintaining product-version knowledge because operational competence extends beyond the exam’s historical release context. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Certification maintenance
Under the current Secure Networking requirements, renewal involves an active NSE 4 FortiOS certification and an approved renewal route, such as passing an NSE 6 exam in the track, completing the applicable online recertification assessment when its conditions are met, or achieving or renewing the NSE 7 certification in the Security Network track. Fortinet also states that earning or renewing an NSE 6 certification recertifies active NSE 1, NSE 2, and NSE 3 certifications. Confirm the current route before relying on it. [https://training.fortinet.com/local/staticpage/view.php?page=nse_6_secure_networking]
Operational next action
Turn your study lab into a maintenance reference. Keep the architecture diagram, certificate inventory, authentication flow diagrams, tested recovery steps, and version notes under change control. When FortiAuthenticator is upgraded or integrated with another Fortinet product, review the relevant release notes and documentation rather than assuming that an older runbook remains correct. [https://docs.fortinet.com/document/fortiauthenticator/6.4.6/release-notes/355786/355786/fortiauthenticator-6-4-6-release]
Conclusion
The strongest preparation decision is to treat FortiAuthenticator 6.4 as an operational identity platform and prepare through complete workflows, controlled failures, and version-specific documentation. Confirm the historical exam or current mapped certification before booking, verify the NSE 4 requirement, and do not rely on unsupported claims about weights, duration, question counts, price, or retirement. Once you can configure and explain LDAP, RADIUS, strong authentication, FSSO, portals, PKI, 802.1X, federation, and FIDO2, your final review should focus on precise troubleshooting and the official scheduling rules.
Related exams
- NSE6_EDR_AD-7.0 exam — Fortinet NSE 6FortiEDR 7.0 Administrator
- NSE6_FAC-6.1 exam — Fortinet NSE 6 - FortiAuthenticator 6.1
- NSE6_FAD-6.2 exam — Fortinet NSE 6 - FortiADC 6.2
- NSE6_FML-7.2 exam — Fortinet NSE 6 - FortiMail 7.2
- NSE6_FAZ-7.2 exam — Fortinet NSE 6FortiAnalyzer 7.2 Administrator
- NSE6_FNC-9.1 exam — Fortinet NSE 6FortiNAC 9.1