Skip to content
Notifications
Clear all

Just built a full SD-WAN + CASB proof-of-concept lab - my config files and results

2 Posts
2 Users
0 Reactions
3 Views
(@jakeb)
Reputable Member
Joined: 1 week ago
Posts: 160
Topic starter   [#2862]

Hey everyone, I’ve been diving deep into evaluating SASE solutions for our mid-sized company, and I just finished building a full proof-of-concept lab with Fortinet FortiSASE. I focused on integrating the SD-WAN and CASB components specifically.

I wanted to see how it handles our typical workflow—remote developers accessing cloud repos and the marketing team using shared SaaS apps for collaboration. The setup process was... detailed. I have a bunch of config snippets from the FortiGate and the agent provisioning that I’d love to get some eyes on.

My main questions for those who have been using it in production:
* How stable is the tunnel health monitoring in real-world conditions with fluctuating home internet speeds?
* For the CASB part, I’m curious about the learning curve for setting up precise policies for apps like Google Workspace. Did you find the default templates sufficient, or did you have to do a lot of custom tweaking?
* Also, the pricing structure seems a bit layered. Is the per-user pricing pretty straightforward once you add the necessary feature sets, or were there unexpected costs for the security add-ons?

I’m leaning towards recommending it, but I want to make sure I’m not missing any big pitfalls in day-to-day management. Any insights from your own deployments would be super helpful



   
Quote
(@cloud_sec_enthusiast)
Estimable Member
Joined: 2 months ago
Posts: 90
 

Congrats on getting your PoC up and running - that's a solid lab. On your points:

> How stable is the tunnel health monitoring...
It's been pretty stable in my experience, but the key is tuning the sensitivity thresholds. If you leave them on defaults, you might see some unnecessary flapping on really poor residential links. The real-world gotcha is asymmetric routing when a user has multiple WAN paths (like Wi-Fi + cellular hotspot) - that can confuse the health checks.

For the CASB learning curve: the default templates for Google Workspace are a decent starting point for blocking obvious stuff, but they won't catch app-specific risks like a third-party Google Drive add-on exfiltrating data. You'll absolutely need custom rules. The time sink isn't the policy builder, it's mapping your internal data classification tags to their DLP engine.

On pricing, watch for the CASB add-on if you're scanning a high volume of SaaS data - it can push you into a higher tier unexpectedly. The per-user cost is straightforward until you bolt on the advanced threat protection features.


security by default


   
ReplyQuote