Hi,
We have 2 fortigates in different locations and each of them include SPA license, in a addition to a FortiSASE subscription.
To maintain policy consistency for remote users and also branch site users, we are planning to use the branch fortigate as an Edge Device in FortiSASE instead of establishing a direct tunnel between branch fortigate and the HQ one.
I'm just wondering how common is this ? it looks so complicated reading the admin guide
PS: we have UTP bundle with each fortigate (HQ and branch), in my opinion a direct tunnel between both sites is better, and FortiSASE will be used mainly for remote users only.
Hi,
I would also say that if UTP is available at the locations, a breakout at the location is used in the direction of the internet or to the other location.
This saves the hop to the SASE-cloud for the on prem users and security is still guaranteed.
For all remote users, the sites are also available via SPA from SASE and can be accessed securely.
I hope I have understood the question correctly and gave some input.
KR Fabian
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.