Skip to main content
Said7
New Member
July 23, 2025
Solved

Fortisase guide - initial setup

  • July 23, 2025
  • 4 replies
  • 3105 views

Hi guys,

 

Can i get some help here?

 

This is my first experience with FortiSASE. I have 2 sites: 1 in NL & 1 in the USA + Remote users in NL, USA, and Bangkok)

I'm planning to deploy 2 FortiGate in each site in Active Standby setup. Each FortiGate will have 2 internet uplinks.

Would you please advise which deployment guide should I use? When checking the KB, i get lost!

What i understood is that I've to create SPA tunnel to the FortiSASE and deploy BGP for routing. but in the KB there are so many types of deployments!

The sites should be able to communicate with each other in a secure channel.

The users should use the FortiSASE to connect to the internet.

I would like to use the forticlient to access the fortigates via its management interface.

 

I already registered the fortigates/licenses and chose 2 PoPs in Europe and 2 in USA.

 

Thank you in advance.

 

Regards

Said

 

I re

 

 

Best answer by Said7

Hello Hatibi,

 

This is a new implementation. i will be installing 2 fortigates at each site in Active Standby with dual uplink.

I don't have experience with fortinet and that makes it a liuttle bit challenging.

 

When checking Fortinet KB, i get lost which deployment guide should i use to allow the sites to reach eachother as well as the internet + have remote users onboarded to reach networks behind those sites.

I only have those 2 sites in 2 different regions, no further spokes.

 

Based on my research, i came to the following conclusion and i hope you can share your thoughts about it:

 

  1. I will be enabling SDWAN on the fortigates in order to use both uplinks.
  2. Configure SPA + BGP towards the fortisase via each uplink.
  3. Configure the SPA in the fortisase portal.
  4. Configure SIA in the fortisase portal and integrate customer Entra ID with Fortisase.

What do you think?

Once again, your support is much appreciated.

 

Regards

Said

4 replies

Hatibi
Staff & Editor
Staff & Editor
July 23, 2025

You want public/internet traffic for your remote users to go through FortiSASE (Cloud)

In that case you need to implement SIA (Secure internet access).

 

a) SIA for agent-based remote users

 

Overview: https://docs.fortinet.com/document/fortisase/latest/architecture-guide/710519/sia-for-agent-based-remote-users
Deployment guide: https://docs.fortinet.com/document/fortisase/latest/mature-sia-agent-based-deployment-guide/891466/deployment-overview

 

 

If you want users to be able access private applications behind your FortiGate hubs then you need Secure private access.

 

b) SPA using NGFW

 

Overview:https://docs.fortinet.com/document/fortisase/latest/architecture-guide/861490/spa-using-ngfw
Deploment guide: https://docs.fortinet.com/document/fortisase/latest/mature-fortigate-ngfw-to-fortisase-spa-hub-conversion-deployment-guide/891466/deployment-overview

 

 

You do not need to configure IPSEC between your two FortiGates. Since they will be added in FortiSASE (converted to SPA hub), traffic will be directed by SASE towards them. For example user behind Site 1 can be allowed with appropriate policies to access a private app behind Site 2.

Said7
Said7Author
New Member
July 23, 2025

Hello Hatibi,

 

Thank you for the prompt response.

Deploying SIA is clear to me. I will need to link FortiSASE to customer Entra ID and push the FortiClient to the users.

 

Regarding SPA, What is the difference between SPA with SDWAN vs SPA with NGFW vs SPA with NGFW and Fabric overlay?

Which one fits my purpose?

I was told by Fortinet SA that traffic between the sites that is directed through FortiSASE will be metered, and additional cost will be applied.

 

Regards

Said

Hatibi
Staff & Editor
Staff & Editor
July 24, 2025

SPA with SDWAN - this means you already have an existing SDWAN deployment with FortiGate Hub and spokes mesh connection which are normally managed by a FortiManager with SDWAN templates. By integrating with SASE you provide SPA for remote users that need to access an app behind one of the spokes. They may connect directly to that resource through on-demand ADVPN tunnel.

 

SPA using NFGW with Fabric overlay orchestrator - this is the same as "SPA with NGFW" but instead of you making the FortiGate hub configuration manually through cli or GUI, you use a GUI wizard that guides you through the configuration of SDWAN overlay containing IPSEC and BGP settings.

It requires FortiOS 7.2.4 and greater. You can read how it works here: https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/60223/fabric-overlay-orchestrator

 

In your case you only have 2 Hubs. I think the SPA with NFGW will be able to accomplish both SIA and SPA scenarios in a simple manner and no big administration burdens.

I am not aware of the details regarding the charges for the amount of traffic in FortiSase. The scope or sizing information is something i would recommend you discuss in further details with your local Fortinet Sales rep.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!