Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Flamby
New Contributor

SPA Design Advice

Hi,

We have 2 fortigates in different locations and each of them include SPA license, in a addition to a FortiSASE subscription.

To maintain policy consistency for remote users and also branch site users, we are planning to use the branch fortigate as an Edge Device in FortiSASE instead of establishing a direct tunnel between branch fortigate and the HQ one.

I'm just wondering how common is this ? it looks so complicated reading the admin guide

PS: we have UTP bundle with each fortigate (HQ and branch), in my opinion a direct tunnel between both sites is better, and FortiSASE will be used mainly for remote users only.

1 REPLY 1
fg_muc
New Contributor III

Hi,

I would also say that if UTP is available at the locations, a breakout at the location is used in the direction of the internet or to the other location.
This saves the hop to the SASE-cloud for the on prem users and security is still guaranteed.
For all remote users, the sites are also available via SPA from SASE and can be accessed securely.

 

I hope I have understood the question correctly and gave some input.

KR Fabian

"Latency is just your network being dramatic."
"Latency is just your network being dramatic."
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors