Fortinet black logo

Version:


Table of Contents

FortiGate NGFW to FortiSASE SPA Hub Conversion Deployment Guide

23.3.25
Download PDF
Copy Doc ID 66d7cd51-4d9c-11ee-8e6d-fa163e15d75b:834810
Copy Link

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. 2. Convert the FortiGate NGFW to a FortiSASE SPA hub:

    1. Convert FortiGate NGFW configured using FortiOS CLI or GUI.

    2. Convert FortiGate NGFW managed by FortiManager.

  3. Using the FortiSASE Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. 2. Convert the FortiGate NGFW to a FortiSASE SPA hub:

    1. Convert FortiGate NGFW configured using FortiOS CLI or GUI.

    2. Convert FortiGate NGFW managed by FortiManager.

  3. Using the FortiSASE Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.