Intro Managed SDWAN
Intro Managed SDWAN
Romaric GUELIAGO
Sales Engineer TCAF
Infrastructure has become more Complex…
…leaving It Vulnerable to Attack
Users
Networks Applications
Devices
4.07 million cybersecurity 58% of organizations use a third- Top-tier CIOs are 4x more likely
roles are currently unfilled, party provider for at to partner with an MSSP3
a 39% increase year least some security operations
over year1 center (SOC) functions2
70% of enterprises want 56% of enterprises are looking 96% of organizations are using 41% of enterprises want integration
access to a 24/7 SOC1 for integration with existing cloud computing3 of their WAN and LAN management
security stack2 environments4
…MSSPs need to know what convinces a potential customer to move security out of house
1 “Managed Detection and Response Report,” Cybersecurity Insiders, September 18, 2019.
2 Ibid.
3 Marc Wilczek, “IT governance critical as cloud adoption soars to 96 percent in 2018,” CIO, April 2, 2018.
4 Shamus McGillicuddy, “Survey: Enterprises want end-to-end management of SD-WAN,” Network World, January 9, 2019.
48% Lack of internal security expertise • MSSPs that offer solutions to these
problems are more attractive to
potential customers.
41% Potential cost savings
1 “Managed Detection and Response Report,” Cybersecurity Insiders, September 18, 2019.
2 “How MSSPs Can Maximize Revenues with Various Security Service Models,” Fortinet, January 25, 2018.
FortiManager
Single OS
Core DC Azure
Segmentation FortiOS Firewall
Firewall
“By 2026, more than 60% of organizations will have more than one type of firewall deployment”
*Gartner Network Firewall MQ 2022
Converge security and Secure users anywhere and Detect, investigate and respond to
networking to protect every applications on any cloud threats at massive scale
edge and device
FortiGates
d Manage
tralize me
Branch SD-WAN en nt
Edge C
Cloud Cloud
Edge
NGFW
Edge Co-Location
Si
N
LA
ng
le d
OS an
SASE
Edge SaaS
for AN
F i r e w a l l, W
Data Center
Large scale, AIOps driven network Automation-driven Single Pane, Consistent security posture
visibility and dynamic insights for NOC Unified Management and Analytics across hybrid / multi-cloud
Network Security
Operations Operations
Cloud
Security
FortiAnalyzer
FortiManager User and
Device
Security (SOC)
(NOC) FortiGuard
Threat
Intelligence
Secure Open
Networking Ecosystem
Customer
Premises
Customer A Customer B
Option 1: Vdom mode Option 2: Clean Pipe mode Option 3: Cpe Mode
✓ Deployed on MSSP premises ✓ Deployed on MSSP premises ✓ Deployed on Customer premises
✓ Multitenant (VDOM per Customer) ✓ Dedicated to Customer ✓ Enterprise design flavor
✓ Usually FGT-VM
ADOM A ADOM B
MSSP Premises
or Public Cloud
Centralized
Management
Easy provisioning and Open Fabric API’s and integrations Extend security policies across
management with ecosystem partners hybrid/ multi-cloud environments
16K+
Customers
DevOPS Security
Terraform / Ansible Appliance Virtual Machine Cloud Security-as-a-Service
IPS Management FortiAnalyzer Integration SASE and ZTNA Upgrade and Backups
Centrally manage IPS View security fabric analysis Rule and Policy Management Firmware upgrades and
via FMG configuration backups
ATT
FortiManager
DIFFERENTATION
• Flexible deployment options: on-premise,
FMGR Cloud FMGR VM FMGR HW hybrid and/or multi-cloud.
• Cloud-native connectivity integrations
with Fortinet Security Fabric
CAPABILITIES
• Distributed deployment at scale
• Secure cloud on-ramp for GCP, Amazon
and Azure
FortiGate FortiGate-VM • Efficient cloud operations with automation
BENEFIT
Branch Campus DC AWS Transit
Gateway
Azure
Virtual WAN
Colocation
Private Cloud
• Consistent security posture across multi-
cloud scenarios
18
© Fortinet Inc. All Rights Reserved. 18
WAN Edge
FortiExtender
FortiGate
Key Components
FortiGate
Secure SD-WAN
FortiGate, FortiGate VM
FortiGate VM Cloud-Native FortiGate
FortiManager FortiExtender
FortiManager
Key Components:
FortiGate
FortiGate, FortiGate VM, Cloud FortiGate
FortiSwitch
DC FortiGate FortiManager
FortiAP
FortiManager
DIFFERENTATION
Fabric Management Center
• Centralized management across the
security fabric (SD-WAN, SD-Branch,
NGFW and more) for visibility and control
• Accelerated Day 0 Zero-touch
provisioning (ZTP)
• Easily scale to 100K+ FortiGate's
CAPABILITIES
• Zero-Touch-Provisioning Templates
• Fortinet Management Extensions -
FortiAIOps
ZTNA NAC EMS SD-Branch SD-WAN NGFW Public Private Application
Cloud Cloud Delivery • Granular Role-based control
Adaptive BENEFIT
Zero-trust Security-driven
Access Networking Cloud Security • Fast time-to-deployment for Day 0/ Day 1
deployment and accelerate time to value
• Adapt to distinct customer use cases
Unified Console Across Security Fabric
21
© Fortinet Inc. All Rights Reserved. 21
Automate and Achieve Efficient Operations
Streamline workflows into Enterprise Ecosystem
DIFFERENTATION
• Integrate into existing enterprise
ecosystem
Fabric Fabric
Connector DevOps • DevOps tools to automate policies
and trigger actionable outcomes
CAPABILITIES
• Complete REST API and SDK
BENEFIT
• Increase Operational Efficiency &
Effectiveness – reduce truck-roll costs
450+ security fabric ecosystem integrations • Accelerate speed of operations
• Eliminate costly human errors
22
© Fortinet Inc. All Rights Reserved. 22
Core Elements
SD-WAN Configuration
• Grouped into SD-WAN Zones • Load-balance across Members that meet SLA target
Hybrid Mesh
Firewall
Hardware VM Cloud
Scalability • Best response time • Flexible and scalable • No hardware maintenance
• Better control & reliability • Quick deployment • Always updated
• Access Anywhere
200G (30) Perpetual or Subscription
3/10K
Comprehensive 400G (150) (10/10K)
Capabilities 1000G (1K)
3100G (4K→8K)
3700G (10K→100K)
(Devices: Default/Max)
Dedicated Local
FortiGuard Server
• Large Enterprise • Cloud Environment • Distributed networks
• Air-gapped network due to • Hybrid Environment • Limited IT Resources
data-sensitivity • Test and Development • Preference for OpEx over
Extended Fabric • Limited Cloud Connectivity CapEx
Ecosystem
© Fortinet Inc. All Rights Reserved. 25
Deployment Workflow
FortiManager
Provisioning Templates
Security Zero-Touch,
System CLI SD-WAN Policy Low-Touch
… Packages
Templates Templates Templates
Model
Device Groups
Device
Do per project
Do Per-Site
Reuse much!
Checkpoint Smart 1
Limited capacity (<5000 devices), only
for firewalls, no template, no security
rating, no signature update in air-
gapped network
01 02 03
Cisco Secure cdFMC
Converged Scaled Integrated
Limited capacity (<1000 devices), limited
firewalls models. No Switches and APs
management, no ZTNA, no template, no Single OS, networking 100K+ devices under a FortiAnalyzer, FortiAIOps,
signature update in air-gapped network and security single pane of FortiGuard and
management FortiSOAR
• Customized ransomware is • The age of IoT is here and • Hard to Prioritize Response
shifting down market must be equally protected
• Skills Gap & Resources
• Initial Access Brokers now • Aging OT systems and
specialize in accessing technologies are growing • Too Many IOCs, Pyramid of
“protected” businesses targets Pain
Eliminate Reduce
Blind Spots Complexity
Speed Converge
Investigations NOC/SOC
© Fortinet Inc. All Rights Reserved. © Fortinet Inc. All Rights Reserved. | Confidential 3131
Unified Logging & Analytics Threat Intel Driven Management
Single,analytics
Real-time Unified Management
& reporting enabling Enhanced network visibility with accurate
complete visibility of network devices,
Console threat prediction & faster response to
systems, and users across the Fortinet Improve SecOps efficiency
Security Fabric
• Log Consolidation: Centralizes logging across the • Workflow Automation: Automates responses to
security landscape for streamlined analysis. predefined security scenarios, increasing efficiency.
• Threat Identification: Employs AI-driven analytics to • Incident Handling: Tools and interfaces for
pinpoint and alert security incidents. comprehensive incident lifecycle management.
• Event Correlation: Detects patterns across data points • Playbook Customization: Allows for tailored security
to identify and flag complex threats. response workflows via configurable playbooks.
• Compliance Reporting: Automates the creation of • Security Fabric Integration: Seamless integration
detailed reports that adhere to regulatory standards. within the Fortinet ecosystem for cohesive security
• Real-Time Monitoring: Provides instant visibility into management.
network and security events for prompt action
© Fortinet Inc. All Rights Reserved. 34
Key Functions & Capabilities
• FortiGuard Labs Data: Integrates Fortinet's leading • Vulnerability Insights: Scans for and identifies system
threat intelligence for up-to-date security insights. weaknesses and potential entry points.
• Threat Contextualization: Offers in-depth context for • Network Profiling: Automatically maps the network,
threats, aiding in accurate identification. highlighting assets and potential vulnerabilities.
• Dynamic Adaptation: Continuously updates with the • Posture Assessment: Regularly assesses network
latest intelligence for proactive defense measures security posture to ensure policy compliance and identify
risks.
© Fortinet Inc. All Rights Reserved. 35
FortiAnalyzer
Max Number of
90 28 50 60 30 60
Days Analytics
2x GE RJ45, 2x GE RJ45, 2x 10GE RJ45,
4x GE RJ45,
Total Interfaces 2x GE RJ45 4x GE RJ45 2x 25GE 2x 25GE 2x 25GE
2x GE SFP
SFP28 SFP28 SFP28
60 x 4TB HDD
Storage capacity 2x 2 TB 2x 4 TB 4x 4 TB 8x 4TB 16x 4TB + 6x 3.2TB
NVMe SSD
Yes, (RAID 0, Yes, (RAID 0, Yes, (RAID 0,
RAID support Yes (0,1) Yes (0,1) Yes (0,1,5,10) 1, 5, 6, 10, 50, 1, 5, 6, 10, 50, 1, 5, 6, 10, 50,
60) 60) 60)
© Fortinet Inc. All Rights Reserved. 37
FortiAnalyzer VM-Series
Competitive Customer
advantage loyalty
Mai 2024
Recognized by Industry Analysts
#1
On-Premises #1
Security- WAN for Small
Sensitive Branches
WAN
Gartner, Magic Quadrant for Enterprise Wired and Wireless LAN Infrastructure, by
Tim Zimmerman, Christian Canales, Nauman Raja, Mike Leibovitz on 6th March
2024.
Customer’s Choice
Wired and Enterprise
Wireless Firewall SD-WAN
• Firewall Configuration • Managed IPS • Managed LAN access • Firewall Configuration • Web Apps Protection
• Firewall Supervision • Managed Antimalware • Managed WiFi access • Firewall Supervision • Mail Protection
• Backup & Restoration • Managed Cloud Sandbox • Managed 4G/5G access • Backup & Restoration • Phishing Simulations
• Log Retention & Audit • Managed Web Protection • Managed Authentication • Log Retention & Audit • SASE (Secure Access)
• etc … • etc … • etc … • etc … • etc …
FortiCloud
Etc …
Management
Tools
FortiGate FortiGate FortiGate FortiGate .
Cloud Cloud Cloud Cloud . …
FortiWeb FortiSASE
FortiGate FortiGate FortiGate
Customer …
Network FortiGuard FortiGate VM
Services
FortiMail FortiPhish
SaaS or
Public Cloud