Skip to content
Early Tech Guy

Early Tech Guy.com

Early Tech Guy focuses on delivering news and advice on the latest trends in information technology.

Fortinet SD-WAN Review and Deep Dive

Posted on December 31, 2022December 26, 2022 By Gustav Eriksson No Comments on Fortinet SD-WAN Review and Deep Dive

The purpose of this article is to provide you with my review of Fortinet’s SD-WAN and its capabilities. The article discusses my Fortinet SD-WAN Review and Deep Dive which will include five major tenants: (1) Application Awareness; (2) WAN Resilience; (3) Multi-Path Intelligence; (4) Monitoring; and (5) Segmentation.

Fortinet SD-WAN Review and Deep Dive
Image Credit: Fortinet
Fortinet SD-WAN Review and Deep Dive

Who is Fortinet?

Fortinet is a global company focused on the development and distribution of cyber security and network infrastructure products. They are best known for FortiGate, their firewall product line which was originally started with the company in 2000. The company is headquartered in Sunnyvale, California and lead by Ken Xie and his brother Michael Xie. Their most popular products to date include:

  • FortiGate (Firewall + SD-WAN)
  • Secure Access Service Edge (SASE)
  • Intrusion Prevention Prevention Systems
  • Secure Web Gateway
  • Network Switching
  • Wireless Access Points
  • Network Access Control
  • Voice and Collaboration (Phone System)
  • Video Surveillance
  • Zero Trust Network Access (ZTNA)
  • VPN
  • Identity and Access Management
  • E-mail Security
  • EDR, MDR, and XDR
  • SIEM and SOAR Software
  • Inline Sandbox Solutions
  • Deception Systems

What is SD-WAN?

SD-WAN is a way for organizations and companies to increase network uptime and performance. It is a solution that connects a company’s site to multiple internet service providers. SD-WAN prioritizes and routes traffic to your ISPs according to your policies.

SD-WAN vs MPLS

MPLS provides private lines from internet carriers. A typical application of MPLS is to connect branch sites to a headquarters or data center location. The need for this network design was to provide application performance at the branch level. Due to the growth of cloud applications, branch sites needed a way to connect and guarantee performance to cloud applications as well as perhaps the data center. Due to the increased costs and complexity of MPLS, many organizations are choosing to leverage SD-WAN with redundant carriers.

Using SD-WAN changes the network design from backhauling internet to data center. Now with SD-WAN branch sites connect directly to their cloud resources as well as the data center over secured VPN connections. This usually includes one high speed (typically fiber) link and one slower backup link. It may also include a 4G LTE or 5G wireless connection as a tertiary link.

Fortinet SD-WAN Review and Deep Dive

Fortinet’s SD-WAN solution is included with all Fortinet FortiGate firewalls as a baseline feature. It has five core capabilities.

  1. Application Awareness
  2. Multi-Path Intelligence
  3. WAN Resiliency
  4. Monitoring
  5. Segmentation

SD-WAN Application Awareness

FortiGate SD-WAN allows you to see up to 5,000 applications. With this visibility, you can prioritize traffic on the most commonly used highly critical business applications. That includes horizontal applications like RingCentral, AWS, and Microsoft Office 365. That also includes social media and personal-use apps like Facebook, Youtube, Twitter, Spotify, Dropbox, and many others.

You can also add applications to your policies by using custom application signatures. With this you can set a policy to a custom application.

A common strategy with SD-WAN is to create application groups. For example, you could have an application group called “Cloud Apps” that contain O365, Dropbox, and Salesforce. You could have another group called “Voice” which includes applications like RingCentral, Zoom, and Microsoft Teams. You could also create a “social media” group that has Facebook, LinkedIn, and Twitter. Then, you can prioritize these groups based on your preferred policy.

WAN Resiliency

There are four strategies to use with Fortinet’s SD-WAN solution. Those are: Best Quality, Lowest Cost, Maximize Bandwidth, and Manual. By using these strategies, you can effectively increase your WAN resiliency.

When we implement Best Quality, we are telling our FortiGate SD-WAN solution to use the link with the lowest latency for any “X” application. The FortiGate will send traffic to a desired link based on requirements for latency, jitter, packet loss, downstream/upstream bandwidth, or some variation of a customized profile.

When we implement Lowest Cost, we are telling our FortiGate SD-WAN solution to use the link with the lowest cost for any “X” application. We set the cost of the link in the FortiGate itself and give it a numerical value. This will then send traffic for a specific application to the lowest cost link as long as it meets your desired SLAs for latency, packet loss, jitter, downstream/upstream bandwidth, or some variation of a customized profile.

When we implement Maximize Bandwidth, we are telling our FortiGate SD-WAN solution to use all links and distribute bandwidth across all applications as long as the links meet the minimum SLAs for latency, packet loss, jitter, and downstream/upstream bandwidth.

These strategies can be used on both applications and groups of people. FortiGate has integration with Active Directory, so you can select departments, such as the Executive Leadership Team and delegate bandwidth accordingly.

Furthermore, FortiGate SD-WAN has Forward Error Correction and packet duplication built in to remediate WAN issues. This is a useful SD-WAN feature for VoIP survivability and WAN resiliency.

Multi-Path Intelligence

Of course, we would not be able to provide application steering and bandwidth policies for user groups without knowing the health of WAN links. Fortinet provides a Mean Opinion Score (MOS) of WAN links by measuring latency, jitter, packet loss, and downstream/upstream bandwidth.

Based on these four categories, the FortiGate SD-WAN solution provides the MOS. The MOS is a numerical value of 5.0 to 1.0, with 5 being the best and 1 being the worst. Using the MOS, you can then set quality standards for applications such as VoIP. For example, if a WAN link is below 3.5 MOS, then move VoIP traffic to a better WAN link that meets the threshold (Best Quality Strategy).

SD-WAN Monitoring

FortiView is the dashboard which you will use for visibility into your network.

Fortinet SD-WAN Traffic Shaping Monitor
Image Credit: Fortinet
Traffic Shaping Monitor

You can view a lot of different categories visually with FortiView, including the following.

  • Sources and Destinations
  • Applications / Cloud Applications
  • Country
  • Websites
  • Threats,
  • Failed Authentications
  • System Events
  • Admin and VPN Logins
  • FortiSandbox
  • Policy
  • Interface
  • WiFi Clients
  • Threat Map
  • Traffic Shaping
  • Endpoint Vulnerability

These tools are going to be useful for a number of different use cases, such as:

  • Monitoring your ISPs and ensuring they meet your desired SLAs
  • Quarantining IP addresses
  • Expose Shadow IT
  • Remediate vulnerable endpoints
  • Create new policies and enforce existing policies

SD-WAN Segmentation

You can achieve more security, better performance for applications, better monitoring, and better compliance through segmentation at the WAN (SD-WAN) level. This is achieved by layer 3 network segmentation, Virtual Routing and Forwarding (VRF).

VRF is to Routing as VLANs are to LANs. They are virtual routing tables. This will allow you to do things like completely segment your data sensitive traffic (e.g. PCI, HIPAA, etc.) from guest Wi-Fi and critical performance applications like VoIP.

FortiGate firewalls include VRF natively within the SD-WAN solution. SD-WAN, VPN, and BGP configurations support L3 VPN segmentation over a single overlay.

Who is the Target Audience for FortiGate SD-WAN?

SD-WAN is a good fit for any organization looking to increase WAN reliability and performance. FortiGate SD-WAN is especially attractive to organizations with these types of characteristics:

  • Industry vertical includes healthcare, financial services, government, manufacturing and retail.
  • Those who are consolidating WAN vendors
  • Those who have multiple remote sites
  • Organizations that are or have adopted cloud services as business critical
  • Organizations going through a digital transformation initiative (IoT, new customer services, conversion of back-office paper-based operations)
  • Organizations who are looking to reduce WAN expenses from MPLS
  • Organizations who want to reduce network complexity and obtain centralized management of their WAN

Conclusion

The Fortinet SD-WAN Review and Deep Dive provided here was my attempt at helping you with understanding at a high level how Fortinet’s FortiGate could be used as an SD-WAN solution. If you are interested in discovering more about Fortinet’s FortiGate solution, I would recommend you fill out the information below. I will partner you with a solution expert that will walk you through how FortiGate SD-WAN could work for your organization.

Loading
(Visited 359 times, 1 visits today)
Firewalls Tags:FortiGate, Fortinet, SD-WAN

Post navigation

Previous Post: Top 5 Cybersecurity Solutions to Mitigate Risk in 2023
Next Post: Managed IT Services – 8 Trends for 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • VMware Alternatives: What Organizations Are Choosing in 2026 — and Why the Market Is Shifting
  • The Coming Memory Shortage of 2026: What the Data Tells Us and How to Prepare
  • “VxRail Is No Longer a Thing”: What Customers Should Do Next
  • Halcyon Review: Fortifying Cyber Resilience with Halcyon’s Anti-Ransomware Platform
  • Palo Alto Networks’ Bold Move into Observability with Chronosphere Acquisition
  • The Best EDR to Pair With Splunk: Why SentinelOne is the Clear Winner
  • Top IT Skillsets for 2026: What Will Define the Next Generation of Tech Talent
  • Critical Cisco Firewall Zero-Days: CVE-2025-20333 & CVE-2025-20362 – What You Must Know
  • SonicWall Breach: All You Need to Know.
  • Cisco Launches Foundation-sec-8b: The First Open-Source AI Security Model
  • Dave Shull to Step Down as President of HP Inc.’s Solutions Business
  • Cisco Launches Unified Edge: Bringing AI Power Closer to the Source
  • Mastering the Art of Negotiating with Tech Vendors: A Comprehensive Guide for CIOs, VPs and IT Directors
  • Descriptive Analysis of Managed Services on a Small Business
  • How Managed IT Services Can Meet the Needs of Community Banks
  • The Crucial Role of Managed IT Services in Patching and Updates
  • Is It More Cost Effective To Outsource IT?
  • Technology Trends for Wisconsin’s Biggest Companies
  • Review by Early Tech Guy: Networking Administration Degree from Dakota County Technical College (DCTC)
  • Managed Firewall Services in Minnesota
  • Top 6 Key Features of AIOps
  • Aruba vs Fortinet Switches – EarlyTechGuy Review
  • Top 6 Cybersecurity Issues with Moving to the Cloud in 2024
  • 24/7 IT Support and Monitoring: Why Businesses Need It
  • FortiSASE Diagram by Early Tech Guy
  • Unleashing Business Potential: Real-Life Success Stories of SMBs Partnering with Managed IT Service Providers
  • SASE Explained in a Diagram by Early Tech Guy
  • Managed IT Services Help Enhance Manufacturing Operations
  • What is 24×7 Log Monitoring? Explained by Early Tech Guy
  • Financial and Management Considerations of Outsourced IT Support
  • Cisco Systems: Empowering the Future of Manufacturing Through Innovation
  • How Artificial Intelligence is Shaping Helpdesk Services for MSPs
  • List of Managed Services Providers for Fortinet FortiGate Firewalls
  • Top 7 Backup Solutions for 2024
  • My IT Manager is Retiring. Can I Replace Him with an MSP?
  • Aureon Expands Presence with Acquisition of Northwest Communications’ Managed Services Division
  • Fortinet Managed Services: Enhancing Firewall Security with Managed Service Providers
  • Top 5 Cybersecurity School Programs in Minnesota in 2024
  • The Landscape of Managed Services Providers in Minneapolis
  • Corporate Technologies Expands Services with Acquisition of NuMSP
  • Exploring Zero Trust Network Architecture (ZTNA) and Its Impact on Modern Security
  • Top 5 Cybersecurity Certificates in 2024 by ETG
  • Advantages of an Information Systems Management Degree from Dakota County Technical College
  • Top 5 Entry-Level IT Certificates in 2024 by ETG
  • Key Performance Metrics for Managed IT Service Providers: A Customer-Centric Guide
  • Can I Use Cisco Catalyst 9200 as Core Switches?
  • Managed Services Providers for Cisco FirePOWER Firewalls
  • DKIM, DMARC, and SPF Records, Explained.
  • Enhancing Efficiency and Security: The Role of Managed IT Services for Credit Unions
  • How to Configure DKIM in Your FortiGate Firewall

Copyright © 2026 Early Tech Guy.com.

Powered by PressBook WordPress theme