Fortinet black logo

SPA with a FortiGate SD-WAN Deployment Guide

Configuring SPA to the FortiGate SPA hub in FortiSASE Secure Private Access

Copy Link
Copy Doc ID 8c54df13-c519-11ee-8c42-fa163e15d75b:443423
Download PDF

Configuring SPA to the FortiGate SPA hub in FortiSASE Secure Private Access

Note Before configuring the Secure Private Access settings in the FortiSASE portal, to ensure proper secure private access (SPA) functionality, you must ensure that the FortiSASE SPA hub conforms to details mentioned in all previous sections of this guide up until this point, especially those sections covering Design concept and considerations, Product prerequisites, and Reviewing configuration settings of an existing FortiGate SD-WAN hub deployment previously configured using FortiManager.

To allow FortiSASE remote users with SPA to resources behind your FortiGate SD-WAN hub network, you can configure FortiSASE security points of presence as spokes in your hub-and-spoke network using the Secure Private Access page.

Configuration workflow

To configure SPA service connections (hubs), you must follow this configuration workflow in Network > Secure Private Access:

  1. Click the Network Configuration tab at the top of the page and configure the common network configuration settings. See Configuring network configuration.

  2. Click the Service Connections tab at the top of the page, click Create, and configure a new service connection (hub). See Configuring a new service connection.

Note You cannot configure a service connection or hub without first configuring Network Configuration settings.

Configuring SPA to the FortiGate SPA hub in FortiSASE Secure Private Access

Note Before configuring the Secure Private Access settings in the FortiSASE portal, to ensure proper secure private access (SPA) functionality, you must ensure that the FortiSASE SPA hub conforms to details mentioned in all previous sections of this guide up until this point, especially those sections covering Design concept and considerations, Product prerequisites, and Reviewing configuration settings of an existing FortiGate SD-WAN hub deployment previously configured using FortiManager.

To allow FortiSASE remote users with SPA to resources behind your FortiGate SD-WAN hub network, you can configure FortiSASE security points of presence as spokes in your hub-and-spoke network using the Secure Private Access page.

Configuration workflow

To configure SPA service connections (hubs), you must follow this configuration workflow in Network > Secure Private Access:

  1. Click the Network Configuration tab at the top of the page and configure the common network configuration settings. See Configuring network configuration.

  2. Click the Service Connections tab at the top of the page, click Create, and configure a new service connection (hub). See Configuring a new service connection.

Note You cannot configure a service connection or hub without first configuring Network Configuration settings.