Skip to content
Notifications
Clear all

FortiSASE vs. VMware SASE (formerly Velocloud) for manufacturing sites with legacy gear.

1 Posts
1 Users
0 Reactions
0 Views
(@felixr47)
Eminent Member
Joined: 4 days ago
Posts: 16
Topic starter   [#16934]

Hello everyone,

I've been involved in a lengthy architectural review for a client in the manufacturing sector, and we've finally narrowed down the SASE shortlist to two primary contenders: Fortinet FortiSASE and VMware SASE (the platform formerly known as Velocloud). The environment is the classic, yet challenging, mix of modern cloud initiatives and decades-old factory floor gear. I'd like to share our key considerations and hear from the community, especially those who have navigated similar deployments.

Our primary constraints are non-negotiable:
* **Legacy Integration:** Several sites rely on serial-to-Ethernet converters, old SCADA systems, and proprietary protocols that simply cannot tolerate deep packet inspection or high-latency tunnels.
* **Traffic Segmentation:** We need to cleanly separate "OT" (Operational Technology) traffic from general corporate internet traffic at the branch, applying very different security policies to each.
* **Operational Simplicity:** The team managing these remote sites is small and more familiar with traditional CLI than complex cloud dashboards. Zero-touch deployment is a must.
* **Reliability/Uptime:** Any solution must have a proven, deterministic failover mechanism. Production line downtime is measured in tens of thousands per minute.

Here is a high-level comparison of our current understanding:

**FortiSASE (FortiGate as a Service)**
* **Pro:** The unified policy model across FortiGate hardware and SASE service is compelling. We can build a security policy once in FortiOS and have it apply consistently.
* **Pro:** Strong SD-WAN capabilities with rich application-level steering, which could be tuned to keep legacy protocol traffic on a direct local breakout path.
* **Con:** The "security-driven" approach might be overkill for legacy OT VLANs. We'd likely need to configure bypass rules or use dedicated virtual interfaces with minimal inspection.
* **Con:** While the Fortinet Security Fabric is deep, it's also a proprietary ecosystem. Integration with third-party OT security tools might require more work.

**VMware SASE (Velocloud)**
* **Pro:** Arguably best-in-class SD-WAN, with fantastic performance on poor-quality links (a reality at some older facilities). Its Dynamic Multipath Optimization (DMO) is a proven technology.
* **Pro:** The architecture seems more network-centric first, with security layered on. This might offer a simpler path for "transparently" tunneling or passing through legacy traffic.
* **Con:** The security stack, while robust, feels less integrated than Fortinet's single-vendor story. We'd be managing more discrete policy points.
* **Con:** We have some concerns about the depth of L7 inspection for non-standard protocols compared to FortiGate's long history with custom IPS signatures.

From an architectural standpoint, we're leaning towards a hybrid design regardless of the vendor, something like:

```text
Manufacturing Site
├── Legacy OT VLAN
│ └── Traffic → Direct Internet Breakout (or dedicated tunnel with no inspection)
└── Corporate VLAN
└── Traffic → SASE Tunnel → Full Security Stack (ZTNA, SWG, CASB)
```

The crux of the decision seems to be: Do we want a **security platform that does excellent SD-WAN** (FortiSASE), or an **excellent SD-WAN platform that does security** (VMware SASE)?

I'm particularly interested in real-world stories. Has anyone implemented either solution in a plant with similar legacy constraints? How did you handle the split-tunneling or policy bypass for sensitive OT traffic? Were there any unexpected pitfalls with the physical or virtual edge appliances?

—Felix



   
Quote