FortiSASE - Training
FortiSASE - Training
Systems Engineer
Rafael Claudio – Systems Engineer
Apoio:
Created by:
Diego Marcusso
Rafael Claudio
Agenda
• Arquitetura
• Principais funcionalidades
• Criação de BoM
• Kahoot
• Laboratório prático
Source
https://www.gartner.com/doc/reprints?id=1-2BE2MYZL&ct=221012&st=sb&submissionGuid=fe2094f3-1bd1-4fcd-a29f-c70fef180ddb
Feb. 2023 Magic Quadrant™ for Security Nov. 2022 Magic Quadrant™ for Network Sep. 2022 Magic Quadrant™ for SD-WAN
Service Edge Firewalls
FortiSASE
Fortinet: Fortinet provides a cloud-delivered SWG, CASB and ZTNA via ForitSASE and a universal ZTNA offering based on its next-generation
firewall (NGFW) acting as an in-line proxy. Fortinet has a large globally diverse client base. We excluded Fortinet because
as of 1 September 2022, it did not meet Gartner’s required minimum points of presence globally for direct customers of FortiSASE.
© Fortinet Inc. All Rights Reserved. 6
Why? How?
SASE
Too Many Security Acronysm
Branch
Applications
Users
On Network MPLS
FortiGuard
DLP
Web
IPS Filtering
SSL
Decryption Anti-
Virtus
Advanced User
Threat Security
Protection
Internet
Branch
MPLS
Applications
Users
On Network MPLS
FortiGuard
DLP
Web
IPS Filtering
SSL
Decryption Anti-
Virtus
Advanced User
Threat Security
Protection
Internet
Branch
MPLS
Internet-VPN Applications
Users
On Network
FortiGuard
DLP
Web
IPS Filtering
SSL
Decryption Anti-
Virtus
Advanced User
Threat Security
Protection
Internet
Branch
MPLS
Internet-VPN Applications
Users
On Network
FortiGuard
DLP
Web
IPS DLP
IPS Filtering
SSL
Decryption SSL
Decryption Anti-
Virtus
Advanced User
Threat
Anti- Security
Web Protection
Virtus
Filtering
FortiGuard User
Advanced
Security
Threat
Protection
Internet
Branch
MPLS
Internet-VPN Applications
Users
On Network
FortiGuard
DLP
DIA Web
IPS DLP
IPS Filtering
SSL
Decryption SSL
Decryption Anti-
Virtus
Advanced User
Threat
Anti- Security
Web Protection
Virtus
Filtering
FortiGuard User
Advanced
Security
Threat
Protection
Internet SaaS
Branch
MPLS
Internet-VPN Applications
Users
On Network
FortiGuard
DLP
DIA Web
IPS DLP
IPS Filtering
SSL
Decryption SSL
Decryption Anti-
Virtus
Advanced User
Threat
Anti- Security
Web Protection
Virtus
Filtering
FortiGuard User
Advanced
Security
Threat
Protection
Internet SaaS
Users
Agentless
Applications
Users
On Network
FortiGuard
DIA DLP
Web
IPS DLP
IPS Filtering
SSL
Decryption SSL
Decryption Anti-
Virtus
Advanced User
Threat
Anti- Security
Web Protection
Virtus
Filtering
FortiGuard User
Advanced
Security
Threat
Protection
Internet SaaS
Users
Agentless
IPS DLP
SSL
Users Decryption
Client-Based CASB Data Center
Branch SWG
Web Anti-
Filtering Virtus
Internet-VPN
FortiSASE
Cloud- Use Security Applications
Users Advanced
FWaaS SDWAN
On Network
Managed Threat ZTNA
Protection FortiGuard FortiGuard
DLP
Web
IPS DLP
IPS Filtering
SSL
Decryption SSL
Decryption Anti-
Virtus
Advanced User
Threat
Anti- Security
Web Protection
Virtus
Filtering
FortiGuard User
Advanced
Security
Threat
Protection
Internet SaaS
Cloud-delivered Security
FWaaS/SWG
ZTNA
DLP (optional)
SSE CASB
Browser Isolation (optional)
FWaaS/SWG
ZTNA
SD-WAN DLP (optional)
CASB
SASE Browser isolation (optional)
Single-vendor
SASE Benefits
Single-
Vendor SASE • Improved risk posture
On-prem Remote Users
Simplicity and reduced security gaps
NGFW Cloud-Delivered
SD-WAN
Consistent Security Security • Provide simplicity
Better User eliminating multiple products
Experience • Efficient operations
with single agent
• Cost savings from product
and vendor reduction
Securing Remote Users Cloud-delivered Security & Networking Improved User Experience
Cloud CASB
Managed
Web
FWaaS
Branch
Transformation
Router Secure SD-WAN
Proxy
Replacement
On-prem proxy Cloud proxy
Secure Remote
Access
SASE
Legacy VPN Zero-trust
https://status.fortisase.com/
turbo-customerB.edge.prod.fortisase.com
• Customer entitlement/PoP
• Customer A uses PoPs in Burnaby, Ottawa, Sophia, London
• DNS Translation
• Maps the resolved result to another IP
address that you have defined.
• Application Categories
• Application Overrides
• Customizable Categories
• Three profiles:
• Recommended - Scans traffic for all known
threats and applies the recommended action.
• Critical - Scans traffic for critical threats and
blocks them.
• Monitor - Scans traffic for threats but does not
apply any action. Primarily used for logging.
ZTNA
Never trust,
Access Proxy
always verify
Cloud
Secure just
Data Center enough access
Security Logs
Internet
Safe browsing from anywhere
FortiClient
2 3
1 Simplified FOS
Security from
1
single pane
2 Default profiles
available for fast
consumption
z
Internet
Apps Secure corporate app access
DCs/Cloud
Apps
ZTNA SD-WAN
HQs/Branches
Highly granular Access Control
Context-based zero-trust access enforcement,
FGT
app based and adaptive with AI/ML
SWG FWaaS
FortiClient
Private
Apps
SD-WAN Private Access
Data Center
Management
Plane
Augment to existing SD-WAN
ZTNA SD-WAN
Private
Apps Intelligent routing & steering
SWG FWaaS
Data Center
Agent
FortiClient
SD-WAN
Datacenters
Available
PoPs
Remote
User
Private
Apps Enabling Universal ZTNA
DCs/Cloud
App Gateway
Cloud provisioned
ZTNA connections
FWaaS Management
Plane
Private
Apps Device attributes, user info,
posture-based security
HQs/Branches
SWG ZTNA
App Gateway
Granular per-session
posture checks
Continuous posture
Agent re-assessment
FortiClient
IL-CASB Management
Plane
• Simplified license
• Per user (3) or endpoints
• Bandwidth
• SD-WAN on SASE
Policy Migration
ZTNA Policy
Policy Migration
Cloud Consulting
Network Edge Cloud Consulting Remote Users
© Fortinet Inc. All Rights Reserved. 71
LAB
Access to Lab – Instances Assignment
Use the following link to assign HOL Instance:
https://fndn.fortinet.net/cse
• Passphrase: SASE-SP1
• LAB GUIDE
Compartilhamento Canais
Password: wYxpDi5w
https://fortinet.egnyte.com/fl/Z0aAle7ecA