SASE is Secure Access Service Edge. FortiSASE provides secure remote access for remote users in various cases.
- SIA - Secure Internet Access. This is when remote users access the internet or web based applications.
- SPA - Secure Private Access. This is used when remote users attempt to access private company hosted servers or applications.
- SSA - Secure SaaS Access. This is when remote users attempt to access SaaS services/applications.
SPA integrate FortiSASE with SD-WAN to provide remote users with access to private applications hosted at the companies sites. FortiSASE POPs are located across the world and act as the spokes and communicate with the FortiGate SD-WAN hub that belongs to the company.
The remote users establish a VPN connection to the FortiSASE Spoke. Since FortiSASE is connected to the company hub, SD-WAN can steer SPA traffic to the HUB to access the internal resources.
To improve performance and ease traffic on the SD-WAN Hub, branch sites can form AD-VPN shortcuts with each other. These are secure and fast tunnels between each other.
To integrate FortiSASE into an SD-WAN topology SPA must be configured on the FortiSASE portal. Once configured to use this SD-WAN HUB, all FortiSASE POPs will act as spokes to this hub and rely on IPsec and BGP to secure and route traffic between POPs and the company network behind the Hub and Branch FortiGate devices.
- 1Remote User initiates RAVPN Connection to FortiSASE POP
- 2FortiSASE uses SPA to securely connect to the companies SD-WAN HUB
- 3SD-WAN HUB has the internal corporate resources behind itIt can forward traffic behind it or via WAN Links to other branch sites.
In summary, FortiSASE is just a bridge or connector to connect remote users securely to an SD-WAN hub or branch sites using SPA to access private company resources.
Comments