Skip to main content
fohe
Visitor III
December 13, 2022
Solved

Secure Fabric Fortigate to Fortiagte

  • December 13, 2022
  • 1 reply
  • 962 views

Hello, 

i have 3 sites with fortigates (+APs, + SWs), all are connected directly to the internet. is it possible to put the im one security fabric and does it make sense to do that? In the documentation and cookbooks i can only find examples with fortigates which are on the same site. 

thank you in advance

Feho

 

Best answer by Cajuntank

Yes you can. Here is a link from the 7.2 admin guide

https://docs.fortinet.com/document/fortigate/7.2.0/administration-guide/453842/security-fabric-over-ipsec-vpn 

also a link from the community

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Security-fabric-over-IPsec-VPN/ta-p/196719

 

What the documentation also mentions, that you did not list as part of your inventory, is that you will need a FortiAnalyzer for centralized monitoring/reporting where all of the device then send logs to. The FortiAnalyzer along with the FortiGates are the required core components needed to establish Security Fabric while all of the other devices are recommended...but not required.

 

 

1 reply

Cajuntank
CajuntankAnswer
Contributor III
December 13, 2022

Yes you can. Here is a link from the 7.2 admin guide

https://docs.fortinet.com/document/fortigate/7.2.0/administration-guide/453842/security-fabric-over-ipsec-vpn 

also a link from the community

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Security-fabric-over-IPsec-VPN/ta-p/196719

 

What the documentation also mentions, that you did not list as part of your inventory, is that you will need a FortiAnalyzer for centralized monitoring/reporting where all of the device then send logs to. The FortiAnalyzer along with the FortiGates are the required core components needed to establish Security Fabric while all of the other devices are recommended...but not required.