Description | This article describes the differences between FortiSASE policies and provides guidance on how to configure each one. |
Scope |
FortiSASE. |
Solution |
Overview:
FortiSASE has three types of policies, each serving a specific purpose tailored for different use cases.
Note that every type of policy may be necessary to configure when all of the above use cases are configured on the environment. Traffic will match the relevant Policy based on the destination of the traffic and the type of the endpoint.
Creating an Internet Access Policy (SIA Policy):
Go to Configuration -> Policies -> Internet Access -> Create.
In the policy below, only users connected to SSL-VPN with a Windows-Compliant tag as part of the 'IT_Group' user group will be allowed to access the internet.
Creating an SWG Policy:
Go to Configuration -> SWG Policies -> Create and configure the options most appropriate for the current setup.
Creating an SPA Policy:
Before Configuring the SWG policy, make sure that Secure Private access is configured and the IPSec tunnel is up as shown in the screenshot below. The FortiSASE will not show an option to gain private access to the Policy option when Secure private access is not configured.
Go to Configuration -> Policies -> Private Access -> Create.
Configure the options based on requirements. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.