Fortinet black logo

SD-WAN / SD-Branch Architecture for MSSPs

7.2.0

Secure SD-WAN/SD-Branch Solution

Secure SD-WAN/SD-Branch Solution

It is important to distinguish between Secure SD-WAN functionality and Secure SD-WAN Solution. The Secure SD-WAN functionality can be configured on any FortiGate device, without requiring a separate license or additional products and components. In other words, any FortiGate device can provide this functionality in a completely autonomous manner, including intelligent traffic steering towards multiple WAN links, health monitoring, and of course security.

This chapter will explain how to transform a group of autonomous devices, each providing local Secure SD-WAN functionality, into a comprehensive Secure SD-WAN Solution. FortiGate devices will act as intelligent SD-WAN nodes that are interconnected by an overlay network to provide secure connectivity across all sites, cloud services, and public Internet and to always select an optimal path for each application. Next, we will extend the intelligence into the LAN side, ending up with a complete Secure SD-Branch Solution.

However, before we discuss the design of the Secure SD-WAN/SD-Branch Solution, we must spend some time describing the SD-WAN functionality itself.

Secure SD-WAN/SD-Branch Solution

It is important to distinguish between Secure SD-WAN functionality and Secure SD-WAN Solution. The Secure SD-WAN functionality can be configured on any FortiGate device, without requiring a separate license or additional products and components. In other words, any FortiGate device can provide this functionality in a completely autonomous manner, including intelligent traffic steering towards multiple WAN links, health monitoring, and of course security.

This chapter will explain how to transform a group of autonomous devices, each providing local Secure SD-WAN functionality, into a comprehensive Secure SD-WAN Solution. FortiGate devices will act as intelligent SD-WAN nodes that are interconnected by an overlay network to provide secure connectivity across all sites, cloud services, and public Internet and to always select an optimal path for each application. Next, we will extend the intelligence into the LAN side, ending up with a complete Secure SD-Branch Solution.

However, before we discuss the design of the Secure SD-WAN/SD-Branch Solution, we must spend some time describing the SD-WAN functionality itself.