Introduction
This document describes the reference architecture of Fortinet Secure SD-WAN/SD-Branch solution. It is mainly written for Managed Service Providers, although it may benefit any type of customer looking for a better understanding of our solution, its components, planning guidelines, and best-practice designs.
-
In Secure SD-WAN/SD-Branch Solution, we describe the Secure SD-WAN functionality available on any FortiGate device. We also explain how the functionality can grow into a full SD-WAN (or, optionally, SD-Branch) solution, with fully functional FortiGate devices that control the local wired and wireless connectivity deployed on every site and centrally managed by FortiManager and FortiAnalyzer.
-
Next, in MSSP deployment blueprints, we cover the main deployment models recommended for those willing to offer our solution as a Managed Service, that is, for the MSSPs.
-
The next chapter, Overlay network designs, provides a deeper technical description of the routing designs used in our solution and the overlay network topologies used to interconnect the SD-WAN sites. We also discuss in depth the topic of multi-VRF segmentation across the SD-WAN network.
-
Finally, in Additional topics we cover other important use cases widely seen in practice.
In all these chapters our aim is to help you design a highly scalable, redundant, and secure SD-WAN/SD-Branch solution, either for your organization or for your customers.
This document is complemented by the SD-WAN Deployment for MSSPs Guide, which describes our recommended approach to configuring the designs described in this document.