The following snippets summarize the FortiSASE Secure Private Access (SPA) using ZTNA (zero trust network access) agent-based deployment, which is also known as the FortiSASE endpoint with ZTNA shortcuts deployment. To view the complete guide, go to SPA Using ZTNA Deployment Guide.
FortiSASE Endpoint with ZTNA Shortcuts Deployment
This guide examines how FortiSASE can integrate with FortiGate ZTNA to provide a seamless experience for end users while securing your most important corporate assets behind the FortiGate application gateway. Unlike traditional SSL and IPsec VPN, FortiSASE SPA using ZTNA offers direct connections to protected resources without requiring establishment of a persistent tunnel. The key to ZTNA is verifying the connecting device's and user's identities and ensuring the device's security posture before admitting it to the protected network. These security checks happen instantly and transparently thanks to the integration between FortiSASE, FortiGate, and the FortiClient endpoint. If a device cannot pass these security checks, it is considered untrusted and the connection is rejected.
The following illustrates the architecture of the FortiSASE, FortiGate, and FortiClient integration.
This guide explores the setup between FortiSASE and your corporate FortiGate firewall in detail to cover the SPA using ZTNA use case. It first reviews the components in this solution to understand more about the inner workings, then dives into design concepts and considerations. Finally, it steps through a deployment scenario to build a working FortiSASE and ZTNA environment.
Deployment Plan
This outlines the major steps to deploy this solution. Go to Deployment procedures for detailed configuration steps:
For more information, go to SPA Using ZTNA Deployment Guide.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.