Introduction to FortiSASE
FortiSASE is a Software as a Service (SaaS) solution designed to secure internet access for clients, offering protection powered by FortiOS. It ensures consistent security policies for remote off-net endpoints and users, regardless of their location. The service operates on a subscription model based on the number of endpoints or users.
FortiSASE integrates with various FortiCloud services to deliver a seamless experience for securing internet access. Key security features include Antivirus, Web Filter, Intrusion Prevention, File Filter, Data Loss Prevention, Application Control, and SSL Inspection. These features are customizable and share familiar settings with FortiGate devices.
FortiSASE supports two primary modes:
- Endpoint Mode: Endpoints connect via an always-up VPN tunnel using FortiClient, enabling secure traffic scanning and Zero Trust Network Access (ZTNA) for role-based application access.
- Secure Web Gateway (SWG) Mode: Users configure FortiSASE as an SWG server in their browser or OS for secure web browsing, applying SWG policies to browser sessions.
User provisioning is streamlined, supporting local users, integration with Active Directory or LDAP, and SAML authentication. Users can also be grouped for simplified policy application.
Key Features and Configuration
This administration guide details various aspects of FortiSASE configuration and management, including:
- Dashboards: Monitoring device inventory, security threats, traffic, and network health through customizable dashboards like Status, Asset Map, and FortiView.
- Edge Devices: Configuration and management of FortiExtender and FortiGate devices as FortiSASE extensions.
- Network Security: Securing private access, configuring IPsec VPN tunnels, and managing endpoints.
- Configuration: Detailed steps for DNS settings, policies, SWG policies, security profiles, web filtering, SSL inspection, and authentication sources (LDAP, RADIUS, SSO with Entra ID and Okta).
- System Management: Handling certificates, HTML templates, SWG configuration, and analytics.
- Client Onboarding: Procedures for managed endpoint and SWG client onboarding, including PAC file customization and certificate installation.
- MSSP Portal: Features for Managed Security Service Providers to manage tenant instances.
- Troubleshooting: Guidance for resolving common issues.
- Appendices: Information on FortiSASE data centers, Beta features, REST API, and VPN performance.
For further details and support, Fortinet provides extensive resources including the Fortinet Document Library (https://docs.fortinet.com), Video Library (https://video.fortinet.com), and Customer Service & Support (https://support.fortinet.com).