Just wrapped up a three-week PoC for FortiSASE, aiming to replace our legacy VPN and bolt-on web proxy. The pitch was integrated SD-WAN, ZTNA, and CASB from a single pane. The reality is... nuanced. Got it working, but the config complexity is non-trivial.
I'll share the core Terraform and CLI snippets that actually made things tick, plus the hard numbers from our iperf and failover tests. The web GUI is a maze; 80% of the real configuration is done via CLI or API.
**Key Findings:**
* The SD-WAN overlay setup is solid once you bypass the GUI wizards. Our 1Gbps site-to-site tunnels sustained ~850Mbps with AES-GCM.
* CASB API connectors (for O365) work but create a logging avalanche. We ingested 12GB of log data in 24 hours from a 500-user pilot group.
* ZTNA rules are powerful but the session persistence had issues with some long-running TCP apps, requiring a tweak to the default timeouts.
**Core FortiGate Connector Config (Terraform):**
```hcl
resource "fortios_system_sdwan" "sdwan_primary" {
status = "enable"
zone {
name = "virtual-wan"
}
member {
interface_name = "underlay1"
zone = "virtual-wan"
}
service {
name = "SASE_OVERLAY"
addr_mode = "ipv4"
mode = "priority"
quality_link {
name = "underlay1"
}
health_check = ["SASE_PING"]
}
}
```
**The biggest snag:** Cost visibility. The per-user, per-feature licensing model makes forecasting a nightmare. Our projected annual run-rate jumped 22% after adding the required CASB logs to our SIEM (data egress charges).
Bottom line: It's technically capable, especially for FortiShop environments, but the operational overhead and opaque pricing are significant hurdles. Would only recommend if you have dedicated Fortinet expertise on staff and a firm, fixed budget from sales.
-shift
shift left or go home