Академический Документы
Профессиональный Документы
Культура Документы
Section Two: Lab, covers the configuration of Secure Access with FortiLink.
2
What’s the value of SD-Branch to a Fortinet partner?
Hottest market in the networking industry SD-WAN, refresh rarely stop at the
WAN edge.
“Users also see a need for WAN solutions that effectively integrate with
local wireless LANs in the branch and IoT applications being deployed.
This means an opportunity of convergence and deeper integration
between the WAN and LAN platforms used in the branches.”
5
Challenge: New WAN and Access edge paradigm
Each user and device now represents an edge
6
Evolution of the WAN Edge at the Remote Branch
WAN Edge
WAN Edge • Traditional WAN too expensive
• SD-WAN
SD-
SD-WAN Offers cost savings and improvements but
Branch lack Security and Visibility
• Secure SD-WAN
Secure SD-WAN Provides visibility and security but there are
too many additional point products
• SD-Branch
SD-Branch
Provides integration of WAN and LAN
platforms, extending Secure SD-WAN
Access Edge features into the network.
7
Fortinet Approach to Branch Architecture
Fortinet Secure SD-WAN
Security, Simplicity, Low Total Cost of Ownership
10
Fortinet Secure SD-Branch
Securing the access edge through Security Driven Networking
13
Secure Unified Access Ethernet
Pervasive Security with Fortinet Security Fabric Integration powered by FortiLink.
Internet
MPLS
LTE
Secure
FortiSwitch becomes a logical extension of WAN Edge
the FortiGate when connected via FortiLink
Simple
FortiSwitch
Simplified Management, Deployment, and
Network Architectures.
Scalable
Stackable up to 300 switches per
FortiGate.
14
FortiSwitch Access Switch Family
Entry Mid Range Premium Aggregation
100 Series 200 Series 400 Series 500 Series
Entry Level Switch Mid level Switch Enterprise Switch Aggregation Switch
8 to 48 gigabit Ethernet 24 to 48 gigabit Ethernet 24 to 48 gigabit Ethernet 24 to 48 gigabit Ethernet
ports, POE Capable ports POE+ Capable ports POE+ Capable ports POE+ Capable
Desktop to wiring closet. Typical wiring closet switch Larger wiring closet or high Up to (4) 10 Gigabit
throughput requirements. Ethernet (2) 40 Gigabit
(2-4) Gigabit Ethernet (4) Gigabit Ethernet SFP
Ethernet SFP uplinks
SFP uplink ports uplink ports Up to (4) 10 Gigabit
Ethernet SFP uplinks
15
FortiSwitch Data Center Switch Family
1000 Series 3000 Series
Data Center Aggregation Switch Data Center Switch
24 or 48 10 Gigabit Ethernet SFP slots 3000 series offers 32 x 100
Up to four QSFP28 100 GbE Uplinks or Gigabit Ethernet capable
Six 40 GbE QSFP+ QSFP28 slots
Two Dual hot swappable power supplies Dual hot swappable power
supplies
16
Introducing FortiAP
17
Secure Unified Wireless Access with FortiAP
Wireless a logical extension of the FortiGate with FortiLink
Internet
MPLS
LTE
Secure
Pervasive security with Security Fabric WAN Edge
integration.
Simple FortiAP
19
FortiAP Naming Structure
FAP-U421E FAP-
Number of
Radios
2 1 2
Internet
MPLS
LTE
Enhanced Visibility
• Identify and profile all endpoints, IoT devices, WAN Edge
IoT
• Segmentation based on endpoint characteristics
FortiNAC
and profile
Automated Response
• Continuous risk assessment and anomaly
detection
• Automated responses for dynamic network control
21
Deployment
22
FortiLink enables Access SD-Branch
FortiLink protocols enable FortiGate to manage Fortinet’s network access layer
Simplicity FortiGate NGFW
Security
• Firewall and switch ports equally secure,
SSIDs tied directly to firewall policies
• Global Security polices down to port and
WLAN level
Lower Cost of Ownership FortiLink
FortiAP
23
Deploy and Secure your Access Edge in just a few steps
26
SD Branch Management Options
Simplified Management
Integrated Security Data-Center
Lower TCO NOC/SOC FortiManager Centralized
FortiNAC
Multi-Cloud SaaS
Internet
MPLS
LTE
WAN Edge
Network Access
SD-BRANCH
IoT
FortiNAC
28
SD-Branch:
Opportunity Discovery and Development
Discovery Questions to Ask
1. How many sites do you support?
2. What is the current solution for branch connectivity? (# Branches, #
Technology Vendors?, Link Types, Service Provider(s), etc.)
3. How are you currently securing the remote branch networks?
4. What is your current strategy to support digital transformation/
improved customer experience/efficiency of process and operations?
5. What is the business application architecture in your branch
locations? (number of apps, traditional vs. cloud, any plans for new
applications or services)
6. How are you dealing with IoT devices entering your remote branch
networks?
31
How We Win
Demo Demo Demo!
The Secure Access Solution using FortiLink solution demos
extremely well and easy to set up.
If FortiGate is set up takes less than five minutes
Validates consolidation of services and integration via FortiLink.
32
Why SD-Branch
Flexible Architecture
• Consolidation does not have to mean a single box
• Scale to meet branch needs
Security
• Ethernet switch ports as secure as FortiGate ports
• WLAN configured as FortiGate interface
• IoT discovery security and anomaly detection
Simplified management
• Zero touch deployment model
• Manage directly from FortiGate or at scale with
FortiManager.
Low TCO
• No licensing fee for FortiGate management
SD BRANCH
34
SD-Branch Quiz
https://kahoot.it
Lab Exercise:
Part 1: FortiSwitch FortiLink Lab
Part 2: FortiAP FortiLink Lab
<Fast Track> Session
https://use.cloudshare.com/Class/22l1i
Student Name: <student email>
Passphrase: Fortinet1!
Student Access
• Classroom URL and Password provided from Instructor Email
38
Lab Topology
FortiSwitch Lab Main Gate
POD-3
to a POD.
POD-16
39
Lab Topology
The credentials to access the lab environments are different that those used to
log into CloudShare.
40
Part 1:
FortiSwitch FortiLink Lab Course
This is a short technical lab designed to walk you through the steps
necessary to configure FortiLink between the FortiGate and
FortiSwitch enabling the Fortinet Security Fabric in the Ethernet
access layer.
41
Part 2:
FortiAP FortiLink Lab Course
This is a short technical lab designed to walk you through the steps necessary to
configure a variety of common wireless network types on FortiAPs using the FortiLink
wireless protocol running across CAPWAP.
42
FortiFIED Overview
FortiFIED Interactive Lab Guide
• Application Banner
• Objectives List
• Display Tabs
• Rich Text
• Answer Choice
• Complete
• Request Hint
• Status Bar
• Scale Text Slider
• Resize Display Bar
44
Contatos – Fortinet GOV Brasília