Fortinet white logo
Fortinet white logo
7.2.4

FortiGate-VM as the application gateway

FortiGate-VM as the application gateway

FortiGate is central to ZTNA as it is the trust broker that receives inputs for its trust algorithm, makes policy decisions, applies policy enforcement and routes allowed traffic to the protected resources; see Trusted Identities in the ZTNA Concept Guide. Usually, the connections between the ZTNA application gateway and the protected resources is over a trusted private network, while traffic between remote clients and the application gateway is encrypted over SSL/TLS. Therefore, it is best practices to place the ZTNA application gateway close to the protected resources. As such, the Zero Trust application gateway solution for SaaS applications places the FortiGate-VM in the cloud where the SaaS applications reside.

In the Zero Trust application gateway deployment for SaaS applications, the FortiGate-VM can be launched from any supported marketplaces such as the AWS marketplace or Azure marketplace. Users can apply their FortiGate-VM license for BYOL licensing during the pre-configuration stage, along with specifying other configurations. The cloud provider will then launch the FortiGate marketplace offering with the bootstrap configurations, which will apply necessary FortiGate configurations to get basic ZTNA up and running on the application gateway.

For more information about the role of FortiGate, see FortiGate as a Trust Broker in the ZTNA Concept Guide.

FortiGate-VM as the application gateway

FortiGate-VM as the application gateway

FortiGate is central to ZTNA as it is the trust broker that receives inputs for its trust algorithm, makes policy decisions, applies policy enforcement and routes allowed traffic to the protected resources; see Trusted Identities in the ZTNA Concept Guide. Usually, the connections between the ZTNA application gateway and the protected resources is over a trusted private network, while traffic between remote clients and the application gateway is encrypted over SSL/TLS. Therefore, it is best practices to place the ZTNA application gateway close to the protected resources. As such, the Zero Trust application gateway solution for SaaS applications places the FortiGate-VM in the cloud where the SaaS applications reside.

In the Zero Trust application gateway deployment for SaaS applications, the FortiGate-VM can be launched from any supported marketplaces such as the AWS marketplace or Azure marketplace. Users can apply their FortiGate-VM license for BYOL licensing during the pre-configuration stage, along with specifying other configurations. The cloud provider will then launch the FortiGate marketplace offering with the bootstrap configurations, which will apply necessary FortiGate configurations to get basic ZTNA up and running on the application gateway.

For more information about the role of FortiGate, see FortiGate as a Trust Broker in the ZTNA Concept Guide.