Fortinet black logo

SPA with a FortiGate SD-WAN Deployment Guide

Deployment plan

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. Ensure the FortiGate SD-WAN deployment has the proper configuration:
    1. Configure a new FortiGate SD-WAN deployment using FortiManager.
    2. Review and modify the configuration settings of an existing FortiGate SD-WAN deployment using FortiManager.
  3. Using the FortiSASE Secure Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.

Deployment plan

This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:

  1. Provision your FortiSASE instance and select the regions where your users will be located. Input licenses as needed.
  2. Ensure the FortiGate SD-WAN deployment has the proper configuration:
    1. Configure a new FortiGate SD-WAN deployment using FortiManager.
    2. Review and modify the configuration settings of an existing FortiGate SD-WAN deployment using FortiManager.
  3. Using the FortiSASE Secure Private Access page, configure the FortiSASE security points of presence as spokes of the FortiGate SD-WAN Hub using its specific network attributes as parameters.
  4. Configure the DNS settings to allow resolving hostnames for external and internal domains.
  5. Verify IPsec VPN tunnels on the FortiGate SD-WAN hub(s).
  6. Verify BGP routing on the FortiGate SD-WAN hub(s).
  7. Test private access connectivity to the FortiGate SD-WAN network from remote users.