Skip to content
Notifications
Clear all

Deployed FortiSASE across 10 remote sites - what we learned

19 Posts
18 Users
0 Reactions
1 Views
(@cost_optimizer_elle)
Estimable Member
Joined: 2 months ago
Posts: 142
 

That fingerprinting exception list is where your FinOps nightmare starts. It isn't just operational tax, it's a financial blind spot. You've now got traffic bypassing the metered SASE tunnel, so how are you attributing that bandwidth cost back to the diagnostic terminal team?

I've seen this blow a cloud budget - the local breakout for kiosks meant those massive firmware pulls hit the raw internet egress line item instead of the "all-in" SASE fee. Suddenly, a predictable cost model is gone because you had to work around the product's limitations.


- elle


   
ReplyQuote
(@cloud_watcher_99)
Reputable Member
Joined: 2 months ago
Posts: 269
 

Spot on. We solved the attribution problem by forcing that breakout traffic through a tiny proxy instance in the same site's AWS VPC. All egress gets a tag for the terminal team. It's a total hack, and now we're paying for compute and data processing just to get a clean bill back.

The real kicker? The SASE vendor's own cost reporting tool can't ingest those proxy logs, so we've got another dashboard to maintain.


cost first, then scale


   
ReplyQuote
(@cloud_ops_amy_2)
Estimable Member
Joined: 5 months ago
Posts: 142
 

The 15-device break-even you found lines up with our own math, and it gets even tighter if you factor in power and cooling for those on-prem appliances they're replacing. It's a hidden capex-to-opex win the vendor doesn't always highlight.

>the expensive per-user connections

That's the real killer. We tried prioritizing VOIP traffic within the SASE tunnel, but without a hard bandwidth reservation, it's just a suggestion to the aggregate pool. During a mid-day Teams migration sync from one site, all the executive calls tanked. You can't explain that with "shared cloud economics." We ended up putting a cheap, separate DIA circuit in just for critical apps, which completely undercuts the consolidated cost model.


terraform and chill


   
ReplyQuote
(@baller_analytics)
Reputable Member
Joined: 2 months ago
Posts: 201
 

Your kiosk example is the perfect case of a vendor metric ignoring actual usage. They sell per-user but track per-device, so you're penalized for operational efficiency.

The bandwidth deception is worse than you think. Even if you stay under the cap, the shared pool means one site's backup can throttle another site's calls. You're paying for 1Gbps but never actually getting it anywhere.

Your fallback plan to offload guest traffic with basic firewalls proves the point. You're adding complexity back in to fix their pricing model. So much for simplification.


If it's not a retention curve, I don't care.


   
ReplyQuote
Page 2 / 2