Fortinet Secure Sdwan
Fortinet Secure Sdwan
Traditional WANs may utilize SLA-backed private multiprotocol label switching (MPLS) or
• World’s only ASIC-
leased line links to an organizations’ main data centers for all application and security needs.
accelerated SD-WAN
But that comes at a premium price for connectivity. While a legacy hub-and-spoke architecture
• 5000+ applications
may provide centralized protection, it increases latency and slows down network performance
identified with real-time
SSL inspection
to distributed cloud services for application access and compute. The result is operational
• Self-healing capabilities for complexity and limited visibility associated with multiple point products. This scenario adds
enhanced user experience significant management overhead and difficulties, especially when trying to troubleshoot and
• Cloud on-ramp for efficient resolve issues.
SaaS adoption
Fortinet’s Secure Networking strategy tightly integrates an organization’s network
• Simplified operations with
infrastructure and security architecture, enabling networks to transform at scale without
NOC/SOC management and
analytics
compromising security. This next-generation approach provides consistent security
• Enhanced granular analytics enforcement across flexible perimeters by combining a next-generation firewall with advanced
for end-to-end visibility and SD-WAN networking capabilities. This combination paves the way to Fortinet Single-Vendor
control SASE approach empowering organizations to consistently apply enterprise grade security and
• Foundational for a single- superior user experience across all edges converging networking and security across a unified
vendor SASE operating system and agent. FortiSASE extends FortiGuard security services across Thin Edge,
• Gartner Magic Quadrant Secure Edge, and remote users enabling secure access to users both on and off the network.
Leader for both SD-WAN Furthermore, infrastructure networks are simplified by extending SD-WAN into wired and
and Network Firewalls wireless access points of branch offices.
Fortinet Secure SD-WAN Data Sheet
Business Outcomes
Improved User Experience
An application-driven approach provides broad application steering with accurate granular
identification, advanced WAN remediation, and accelerated cloud on-ramp for optimized
network and application performance. Furthermore, a Secure Private Access via FortiSASE to
secure access to private applications for remote users.
Accelerated Convergence
The industry’s only organically developed, purpose-built, and ASIC-powered SD-WAN enables
Secure Edge (FortiGate SD-WAN) and thin edge (FortiExtender Wireless WAN) to transition to
Fortinet Single-Vendor SASE solution to secure all applications, users, and data anywhere.
Efficient Operations
Simplify operations with centralized orchestration and enhanced analytics for SD-WAN,
security, and SD-Branch at scale.
2
Fortinet Secure SD-WAN Data Sheet
Core Components
Fortinet Secure SD-WAN consists of the industry’s only organically developed software
complemented by an ASIC-accelerated platform to deliver the most comprehensive SD-WAN
solution.
FortiGate
Provides a broad portfolio available in different form factors: physical appliance and virtual
appliances, with the industry’s only ASIC acceleration using the SOC4 SPU or vSPU.
• Reduce cost and complexity with next generation firewall, SD-WAN, advanced routing, and
ZTNA application gateway on a unified platform that allows customers to eliminate multiple
point products at the WAN edge
• ASIC acceleration of SD-WAN overlay tunnels, application identification, steering,
remediation, and prioritization ensure the best user experience for business-critical, SaaS,
and UCaaS applications
FortiOS
Fortinet’s unified operating system delivers a security-driven strategy to secure and accelerate
network and user experience. Continued innovation and enhancement enable:
ASIC
ASIC Virtual FortiOS
SP5 Acceleration
3
Fortinet Secure SD-WAN Data Sheet
Core Components
NOC Operations
Simplify centralized management, deployment, and automation to save time and respond
quickly to business demands with end-to-end visibility. With a single pane of glass
management that offers deployment at scale, customers can:
• Centrally manage 100K+ devices, including firewalls, switches, access points, and LTE/5G
extenders from a single console
• Provision and monitor Secure SD-WAN at the application and network level across branch
offices, datacenters, and cloud
• Reduce complexity by leveraging automation enabled by REST APIs, scripting tools such as
Ansible/Terraform, and fabric connectors
• Separate and manage domains leveraging ADOMS for compliance and operational efficiency
• Accelerate troubleshooting and enhance user experience with Digital Experience Monitoring
(DEM) and AIOps
• Role-based access control to provide management flexibility and separation
• Coordinated real-time detection and prevention against known and unknown protecting
content, application, people, and devices
• Real-time insights are achieved by processing extensive amounts of data at cloud-scale,
analyzing that data with advanced AI, and then automatically distributing the resulting
intelligence back for enforcement and protection
4
Fortinet Secure SD-WAN Data Sheet
Features
FEATURES DESCRIPTION
FortiOS — SD-WAN Application Identification and Control 5000+ application signatures, 3000+ industrial signatures, first packet Identification, deep packet
inspection, custom application signatures, SSL decryption, TLS1.3 with mandated ciphers, and deep
inspection
SD-WAN Granular application policies, application SLA based path selection, dynamic bandwidth measurement
(Application aware traffic control) of SD-WAN paths, active/active and active/standby forwarding, overlay support for encrypted transport,
Application session-based steering, probe-based SLA measurements
Advanced SD-WAN Forward Error Correction (FEC) for packet loss compensation, packet duplication for best real-time
(WAN remediation) application performance, Active Directory integration for user based SD-WAN steering policies, per packet
link aggregation with packet distribution across aggregate members
SD-WAN deployment Flexible deployment – hub-to-spoke (partial mesh), spoke-to-spoke (full mesh), multi-WAN transport
support
SASE Secure remote users/branches to private applications (Secure Private Access) by establishing IPSec
tunnels from SASE PoP to multiple SD-WAN Hubs
FortiOS — Networking QoS Traffic shaping based on bandwidth limits per application and WAN link, rate limits per application and
WAN link, prioritize application traffic per WAN link, mark/remark DSCP bits for influencing traffic QoS on
egress devices, application steering based on ToS marking
Advanced Routing (IPv4/IPv6) Static routing, Internal Gateway (iBGP, OSPF v2/v3 , RIP v2), External Gateway(eBGP), VRF, route
redistribution, route leaking, BGP confederation, router reflectors, summarization and route-aggregation,
route asymmetry
VPN/Overlay Site-to-site ADVPN – dynamic VPN tunnels, policy-based VPN, IKEv1, IKEv2, DPD, PFS, ESP and ESP-
HMAC support, symmetric cipher support (IKE/ESP): AES-128 and AES-256 modes: CBC, CNTR, XCBC,
GCM, Pre-shared and PKI authentication with RSA certificates, Diffie-Hellman key exchange (Group 1, 2,
5, 14 through 21 and 27 through 32), MD5, and SHA-based HMAC
Multicast Multicast forwarding, PIM spare (rfc 4601), dense mode (rfc 3973), PIM rendezvous point
Advanced Networking DHCP v4/v6, DNS, NAT – source, destination, static NAT, destination NAT, PAT, NAPT, Full IPv4/v6 support
FortiOS — Security On-prem Security Next Generation Firewall with FortiGuard threat intelligence – SSL inspection, application control, Intrusion
prevention, antivirus, web filtering, DLP, and advanced threat protection. Segmentation – micro, macro,
single task VDOM, multi VDOM, ZTNA application gateway
Cloud-delivered Security Universal zero-trust network access (ZTNA), next-generation dual-mode cloud access security broker
(CASB), Firewall-as-a-Service (FWaaS), secure SD-WAN integration, and hollistic visibility (apps, threats,
sessions, policies)
NOC Operations Centralized Management and FortiManager provides zero touch provisioning, centralized configuration, change management,
Provisioning dashboard, application policies, QoS, security policies, application specific SLA, active probe
configuration, RBAC, multi-tenant.
Fabric Overlay Orchestrator capability is built directly into FortiOS allowing automatic connectivity
between devices without FortiManager.
Overlay-as-a-Service is a SaaS offering that delivers efficient setup and management of new SD-WAN
regions via the easy-to-use FortiCloud portal.
Cloud Orchestration FortiManager Cloud through FortiCloud, Single Sign-on portal to manage Fortinet NGFW and SD-WAN,
Cloud-based network management to streamline FortiGate provisioning and management, extensive
automation-enabled management of Fortinet devices
Enhanced Analytics Bandwidth consumption, SLA metrics – jitter, packet loss, and latency, real-time monitoring, filter based
on time slot, WAN link SLA reports, per-application session usage, threat information - malware signature,
malware domain or URL, infected host, threat level, malware category, indicator of compromise
Cloud On-ramp Cloud integration – AWS, Azure, Alibaba, Oracle, Google. AWS – transit, direct and VPC connectivity,
transit gateways, Azure – Virtual WAN connectivity, Oracle – OCI connectivity
FortiGate Redundancy/High-availability FortiGate dual device HA – primary and backup, FortiManager HA, bypass interface, interface
redundancy, redundant power supplies
Integration RESTful API/Ansible for configuration, zero touch provisioning, reporting, and third-party integration
Virtual environments VMware ESXi v5.5 / v6.0 / v6.5/ v6.7, VMware NSX-T v2.3
Microsoft Hyper-V Server 2008 R2 / 2012 / 2012 R2 / 2016
Citrix Xen XenServer v5.6 sp2, v6.0, v6.2 and later
Open source Xen v3.4.3, v4.1 and later
KVM qemu 0.12.1 & libvirt 0.10.2 and later for Red Hat Enterprise Linux / CentOS 6.4 and later / Ubuntu
16.04 LTS (generic kernel) ,KVM qemu 2.3.1 for SuSE Linux Enterprise Server 12 SP1 LTSS
Nutanix AHV (AOS 5.10, Prisim Central 5.10)
Cisco Cloud Services Platform 2100
5
Fortinet Secure SD-WAN Data Sheet
6
Fortinet Secure SD-WAN Data Sheet
HUBS
HUBS
7
Fortinet Secure SD-WAN Data Sheet
HUBS
VMware VSphere Citrix Xen Xen KVM Microsoft Hyper-V Nutanix AHV
FG-VM ⃝✓ ⃝✓ ⃝✓ ⃝✓ ⃝✓ ⃝✓
Amazon AWS Microsoft Azure Oracle OCI / OPC Google GCP Alibaba AliCloud
FG-VM ⃝✓ / # ⃝✓ / # ⃝✓ / # ⃝✓ / # ⃝✓ / #
# - On-demand
Standalone Site Hub and Spoke (Single DC) Hub and Spoke with ZTP (Single DC)
SDWAN FortiGate Deployment QuickStart Service FP-10-QSSDWAN-DP1-00-00 FP-10-QSSDWAN-DP2-00-00 FP-10-QSSDWAN-DP3-00-00
The QuickStart SD-WAN service is a consulting service that provides assistance for the deployment of a pre-defined FortiGate SD-WAN configuration into a customer’s environment.
8
Fortinet Secure SD-WAN Data Sheet
Hardware Subscription
200G 400G 1000F 3000G 3700G Cloud VM
Default Devices/VDOMs 30 150 1000 4000 10 000 10
Max Devices/VDOMs with add-on
8000 100 000 10 000 100 000
license
Default ADOMs 30 150 1000 4000 10 000 Add-On
Max ADOMs with add-on license 8000 12 000 1200
Management Extension Application
⃝✓ ⃝✓ ⃝✓
(MEA) enabled
Additional Services
FortiCare Premium Contract Subscription ⃝✓ ⃝✓
FortiCare Elite Contract Subscription No No
FortiCare Best Practice Services (BPS) Included in hardware bundle + a la carte ⃝✓ ⃝✓
Replacement Disks ⃝✓ ⃝✓ ⃝✓
Multi-Device VM Bundle/
How to Buy Hardware Bundle Hardware Bundle Hardware Bundle Hardware Bundle Hardware Bundle
Subscription Subscription
FORTIMANAGER VM
10 Devices 100 Devices 1000 Devices Description
All in one subscription bundle including FortiManager VM
Subscription
FC1-10-FMGVS-448-01-DD FC2-10-FMGVS-448-01-DD FC3-10-FMGVS-448-01-DD S-series, FortiCare Premium Contract, and FortiCare Best
Bundles
Practice services. Fully stackable.
10 Devices 100 Devices 1000 Devices 5000 Devices Description
Perpetual license. Purchase FortiCare Premium Contract
Perpetual
FMG-VM-10-UG FMG-VM-100-UG FMG-VM-1000-UG FMG-VM-5000-UG and FortiCare Best Practices services separately. Only the
License
number of managed devices is stackable.
FORTIMANAGER CLOUD
10 Devices 100 Devices 1000 Devices
FortiManager Cloud Central Management and Orchestration
Multi-Device Subscription FC1-10-MVCLD-227-01-DD FC2-10-MVCLD-227-01-DD FC3-10-MVCLD-227-01-DD
Service including 24x7 FortiCare support. Fully stackable.
9
Fortinet Secure SD-WAN Data Sheet
Ordering Information
SKU DESCRIPTION
FT-SD-WAN Instructor-led Training - Four days
FT-SD-WAN-LAB On-demand Labs (self-paced)
NSE-EX-FTE2 Certification Exam
Pre-requisites
You must have an understanding of the topics covered in the following courses, or have
equivalent experience.
• FCP - FortiGate Security
• FCP - FortiGate Infrastructure
• FCP - FortiManager
References
Course description
10
Fortinet Secure SD-WAN Data Sheet
No, SD-WAN is a feature included in FortiOS at no additional cost. Fortinet recommends purchasing
security subscription services as necessary and utilizing a FortiManager for central management.
Fortinet does not charge for bandwidth usage and you are free to use as much as the box will physically
support.
Any FortiGate model can be utilized as an SD-WAN Hub or Branch. This document provides guidance on
Branch and Hub models based on common deployment use cases.
IPSec phase1 interfaces have no hard limit and are only limited by system memory. Our tests have shown
to support several hundred tunnels on even the smallest box but varies based on many factors.
The licensing model is per-FortiGate device. This approach means each FortiGate that participates in the
SDWAN overlay region will need an individual device entitlement and be registered to the same FortiCloud
account. No other purchase or license is necessary. Upon activating the service from the OaaS portal,
FortiGate HUB devices will be assigned and allocated for the SDWAN overlay region.
How is the SDWAN Underlay Monitoring service priced? Is a FortiManager license required?
SDWAN Underlay Monitoring is licensed per-FortiGate and no additional licensing is required. FortiManager
allows you to execute and monitor the speed test service from a remote FortiGate device with the proper
license.
A Pack refers to the total number of FortiGates that will integrate with FortiMonitor OnSight agents. Agents
integrate with SD-WAN to monitor all available WAN underlay links. There is no licensing limits on the
number of WAN underlay links to be monitored. Example: 10-Pack includes 10 FortiGates, 25-Pack includes
25 FortiGates.
Threat Protection performance is measured with Firewall, IPS, Application Control, URL Filtering and
Malware Protection enabled, Enterprise Mix traffic.
The Unified Threat Protection license includes: IPS, Advanced Malware Protection, Application Control,
Botnet DB, Mobile Malware, Outbreak Prevention, Web and Video Filtering, Cloud sandbox, Secure DNS
filtering, AntiSpam Service, and 24x7 support. For more information, please see the FortiGuard Security
Services datasheet here.
Where could I find the maximum values for SD-WAN components, such as rules and performance SLAs?
The maximum system values for all FortiGates can be found here.
ZTP can be accomplished a number of different ways. For most deployments, we recommend purchasing
FortiDeploy (FDP-SINGLE-US) with your purchase order. FortiDeploy will link the serial numbers in your
order to your FortiCloud account. A FortiManager IP address can be assigned to your devices automatically
so they retrieve their configuration from the FortiManager of your choice.
11
Fortinet Secure SD-WAN Data Sheet
FortiGuard Bundles
FortiGuard Labs delivers a number of security intelligence services to augment the FortiGate
firewall platform. You can easily optimize the protection capabilities of your FortiGate with one
of these FortiGuard Bundles.
Professional Services
Fortinet offers QuickStart SD-WAN consulting services to help customers accelerate the time-
to-value of their SD-WAN network based on predefined configurations. This best-practice-
based service also includes both as-built documentation and knowledge transfer.
FortiCare Elite
FortiCare Elite services offers enhanced service-level agreements (SLAs) and accelerated
issue resolution. This advanced support offering provides access to a dedicated support team.
Single-touch ticket handling by the expert technical team streamlines resolution. This option
also provides Extended End-of-Engineering-Support (EoE’s) of 18 months for added flexibility
and access to the new FortiCare Elite Portal. This intuitive portal provides a single unified view
of device and security health.
12
www.fortinet.com
Copyright © 2023 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product
or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other
conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser
that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any
such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise
revise this publication without notice, and the most current version of the publication shall be applicable.
SSD-WAN-DAT-R19-20231127