Fortinet black logo

SD-WAN / SD-Branch Architecture for MSSPs

7.2.0

Introduction

Introduction

This document describes the reference architecture of Fortinet Secure SD-WAN/SD-Branch solution. It is mainly written for Managed Service Providers, although it may benefit any type of customer looking for a better understanding of our solution, its components, planning guidelines, and best-practice designs.

  • In Secure SD-WAN/SD-Branch Solution, we describe the Secure SD-WAN functionality available on any FortiGate device. We also explain how the functionality can grow into a full SD-WAN (or, optionally, SD-Branch) solution, with fully functional FortiGate devices that control the local wired and wireless connectivity deployed on every site and centrally managed by FortiManager and FortiAnalyzer.

  • Next, in MSSP deployment blueprints, we cover the main deployment models recommended for those willing to offer our solution as a Managed Service, that is, for the MSSPs.

  • The next chapter, Overlay network designs, provides a deeper technical description of the routing designs used in our solution and the overlay network topologies used to interconnect the SD-WAN sites. We also discuss in depth the topic of multi-VRF segmentation across the SD-WAN network.

  • Finally, in Additional topics we cover other important use cases widely seen in practice.

In all these chapters our aim is to help you design a highly scalable, redundant, and secure SD-WAN/SD-Branch solution, either for your organization or for your customers.

This document is complemented by the SD-WAN Deployment for MSSPs Guide, which describes our recommended approach to configuring the designs described in this document.

Introduction

This document describes the reference architecture of Fortinet Secure SD-WAN/SD-Branch solution. It is mainly written for Managed Service Providers, although it may benefit any type of customer looking for a better understanding of our solution, its components, planning guidelines, and best-practice designs.

  • In Secure SD-WAN/SD-Branch Solution, we describe the Secure SD-WAN functionality available on any FortiGate device. We also explain how the functionality can grow into a full SD-WAN (or, optionally, SD-Branch) solution, with fully functional FortiGate devices that control the local wired and wireless connectivity deployed on every site and centrally managed by FortiManager and FortiAnalyzer.

  • Next, in MSSP deployment blueprints, we cover the main deployment models recommended for those willing to offer our solution as a Managed Service, that is, for the MSSPs.

  • The next chapter, Overlay network designs, provides a deeper technical description of the routing designs used in our solution and the overlay network topologies used to interconnect the SD-WAN sites. We also discuss in depth the topic of multi-VRF segmentation across the SD-WAN network.

  • Finally, in Additional topics we cover other important use cases widely seen in practice.

In all these chapters our aim is to help you design a highly scalable, redundant, and secure SD-WAN/SD-Branch solution, either for your organization or for your customers.

This document is complemented by the SD-WAN Deployment for MSSPs Guide, which describes our recommended approach to configuring the designs described in this document.