Skip to content
Notifications
Clear all

Just built a full SD-WAN + CASB proof-of-concept lab - my config files and results

1 Posts
1 Users
0 Reactions
24 Views
(@devops_shift_lead)
Honorable Member
Joined: 6 months ago
Posts: 443
Topic starter   [#25380]

Just wrapped up a three-week PoC for FortiSASE, aiming to replace our legacy VPN and bolt-on web proxy. The pitch was integrated SD-WAN, ZTNA, and CASB from a single pane. The reality is... nuanced. Got it working, but the config complexity is non-trivial.

I'll share the core Terraform and CLI snippets that actually made things tick, plus the hard numbers from our iperf and failover tests. The web GUI is a maze; 80% of the real configuration is done via CLI or API.

**Key Findings:**
* The SD-WAN overlay setup is solid once you bypass the GUI wizards. Our 1Gbps site-to-site tunnels sustained ~850Mbps with AES-GCM.
* CASB API connectors (for O365) work but create a logging avalanche. We ingested 12GB of log data in 24 hours from a 500-user pilot group.
* ZTNA rules are powerful but the session persistence had issues with some long-running TCP apps, requiring a tweak to the default timeouts.

**Core FortiGate Connector Config (Terraform):**
```hcl
resource "fortios_system_sdwan" "sdwan_primary" {
status = "enable"
zone {
name = "virtual-wan"
}
member {
interface_name = "underlay1"
zone = "virtual-wan"
}
service {
name = "SASE_OVERLAY"
addr_mode = "ipv4"
mode = "priority"
quality_link {
name = "underlay1"
}
health_check = ["SASE_PING"]
}
}
```

**The biggest snag:** Cost visibility. The per-user, per-feature licensing model makes forecasting a nightmare. Our projected annual run-rate jumped 22% after adding the required CASB logs to our SIEM (data egress charges).

Bottom line: It's technically capable, especially for FortiShop environments, but the operational overhead and opaque pricing are significant hurdles. Would only recommend if you have dedicated Fortinet expertise on staff and a firm, fixed budget from sales.

-shift


shift left or go home


   
Quote