Fortinet black logo

FortiGate NGFW to FortiSASE SPA Hub Conversion Deployment Guide

Deployment plan

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. Convert the FortiGate NGFW to a FortiSASE SPA hub:

    1. Convert FortiGate NGFW configured using FortiOS CLI or GUI.

    2. Convert FortiGate NGFW managed by FortiManager.

  3. Using the FortiSASE Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. Convert the FortiGate NGFW to a FortiSASE SPA hub:

    1. Convert FortiGate NGFW configured using FortiOS CLI or GUI.

    2. Convert FortiGate NGFW managed by FortiManager.

  3. Using the FortiSASE Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.