Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BIRO
New Contributor

Connect FortiSASE to branch Fortigates

Hello All,

I’m working on a case and would like your input on the best approach to resolve it.

The current setup is as follows:

  • FortiSASE is configured as a spoke to a FortiGate “Hub” via SPA hub-and-spoke.

  • Two branch FortiGates are connected to the Hub through IPsec VPN tunnels.

My goal is to allow FortiClient users connected to the FortiSASE to access resources located behind both branch FortiGates.

Do you have any recommendations or best practices on how to implement this?

 

FortiSASE Network Diagram.png

2 REPLIES 2
ozkanaltas
Valued Contributor III

Hello @BIRO ,

 

I don't have experience related to topology. But if I think logically, you can use existing ipsec tunnels for service access. Normally direct tunnel from the branch to SASE would work better than this scenario, but if I know correctly, you should buy a SPA license for these branch FortiGates. Because of that, your scenario looks like the best implementation scenario now.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
BIRO

Thanks for your reply.

I am aware of purchase of new SPA license for the branch, but I am looking for a work around to access private network behind the branches firewalls.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors