Fortinet Secure Cloud Connectivity
This session will delve into Fortinet’s integrated approach to secure networking with FortiEdge Cloud and FortiSASE. We’ll highlight how the strategic synergy between these solutions strengthens security for modern enterprises. Additionally, we’ll showcase Fortinet’s innovative collaboration with Linksys, providing enterprise-grade security solutions specifically designed to meet the unique needs and budget constraints of the consumer market. Learn how these powerful integrations can elevate your organization’s security posture while simplifying network management.
Presented by Alexandre Vizzari, Senior Director, Product Management. Recorded live at Mobility Field Day 13 in Santa Clara, CA on May 8, 2025. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-mobility-field-day-13/ or visit https://techfieldday.com/event/mfd13/ or https://www.Fortinet.com for more information.
Transcript
So, good morning. Uh, my name is Alex. I'm presenting myself, uh, just for the recording.
Uh, so today we are going to talk, uh, of, uh, about three, uh, secure cloud connectivity. Uh, what does it mean? So I just wanted to emphasis the slide that SUM has been presenting.
Uh, we, despite of the different type of, uh, management platforms, we have all key elements is one single hardware and one firmware, meaning that an AP can connect to the cloud, can connect to FortiGate, can connect to SE, and you don't have to have a different type of AP or different type of firmware. So this is what we insist and we want to ensure that people have the choice when they purchase, but also they have the choice later on down the road if their business is evolving or if their, if their needs are evolving. So we talked about cloud, we talked about customers moving to cloud, moving to, uh, to SaaS.
Uh, also the trend, uh, that we, uh, have been focusing despite of having the FortiGate has our flagship product. We have been investing a lot in our SaaS solution because we did, we do see a lot of customers needing the cloud, needing to work from everywhere You can walk today from this hotel you can walk to tomorrow in your hq. You can also walk from a cafe.
So having the choice and the capability to work, but also to connect to all the needed infrastructure that you need to have to work on the day-to-day. And al also, uh, the traditional VPN way of doing, we have quite a fantastic and powerful, uh, uh, VP, uh, VPN, sorry, uh, feature on the FortiGate, but we do know that some customers and the market is moving towards the TNA and that's why we did invest also, uh, in, into this market. So this is what has been, um, the key elements for us to move into SSE.
Uh, and, and it was just here to explain that and, and go through, uh, through this, uh, idea that we have so that we, we have the FortiGate, we have SS E and we have 40 H Cloud as I think I did present that last year, where we do have all those different, uh, aps that can be, if you don't want to have security, if you don't want to have an on-prem FortiGate, uh, you can connect them to the cloud and have the full fledge management, uh, uh, feature from the cloud itself. So it can be ap, can be switches and can be, or, uh, one gateways from the cloud, uh, with multi-tenancy, with, um, a way to have, uh, service providers also to either bind users or even to bind their external IDP to, uh, to that. So not to have to reuse different, uh, user logins.
So really made it as easy as possible to get customers, uh, for just a cloud and cloud three and connectivity point of view. But you will say, but Alex, where is the security in there? So Fortinet is a security company, and you don't have security with the cloud.
So this is true. So the cloud is giving you direct access, as you know. Uh, so you would not have security, you would have to rely on the legacy VPN as I said, to connect to your, uh, remote devices or to your remote sites.
And you would be born to the local ING means that for any kind of traffic, which could be internet, which could be um, uh, Microsoft or SaaS applications or anything, you would have, you might have some challenges. So we, we said we have the cloud and we have SE, so why not coming with a solution where both would be with would coexist together. We have all the technology inside Fortinet to make the connectivity between any of those devices towards SE.
So this is what we are currently working on, bringing the SE connectivity into those devices for customers willing to hop in or opt out. So we cannot fault that you would still have the choice to stay with your local connectivity, but if you want to add on top of that security to that, if you want to have, uh, policies, UTP, uh, if you want to have DM also that is part of solution or even the, the T-N-A-Z-T-N-A. So this is the full feature being made available for customers that do not have FortiGate on premises.
So we did talk about, uh, data centers and, and, and things like that. You would say, yeah, but if you force the traffic to go to, um, to an IP sec, uh, uh, pop somewhere, you would have some latency. You would have your traffic being reduced.
That's why we have been investing a lot. We have around 150 plus pops across the globe to ensure that the traffic that is tunneled is as close as where our customers are. Meaning that you would not have the challenges of being like on the other side of the world and having the latencies that, uh, that could be induced.
This is for data path, right? And this is true, Yes. That's for data pass.
And Uh, can I, can I change my pop if I don't, if I, if I'm in the middle of two and I want to go east or west, You should be able to, I need to check that. I can come back to you, but you should be able, so we have a dynamic way to diver the traffic. Should the pop have an issue example?
Sure. Yeah. But deterministically, yeah, I need to check how it is done.
Uh, uh, but I don't see that as a challenge for sure, because everything is dynamic. Yes. Okay.
So for that, we have invested in on holding on all data centers. We have been partnering with, uh, some colocation and also with GCP to be quicker, uh, to, to market where a customer is really needing something and we don't have local presence. So that's quite, uh, so the map of the world is not, uh, really well, uh, displayed here.
But yeah, this is our presence and we continue to invest in too hard. So if you don't have, uh, one in the center of, uh, uh, of us, maybe because no one did has yet, or maybe because there is no one I'm kidding. But, so we are really, uh, focusing into that.
And as we grow, uh, we are bringing more and more and more in 2026 for sure. I have a question about the pops. 'cause I I think it's interesting.
You guys have your, your own, and then you have the ones you're Yes. Kind of colo and then Google. Um, and there's always a lot of argument between vendors about, oh, this is better versus, that's better.
You guys have both models, so it's kind of the, the best of both worlds or maybe the worst of both worlds. Um, how do you make the decision around the pop? Is that a customer decision or, or do you guys just have a, a whole ecosystem and you, you path it?
So We did start initially with a list of sites. We did it, uh, then it was based on, uh, customers requests. So we are really listening to what our customers are needing.
And that's why I said is we do believe in our own data centers, but the time to get them to deploy them and to go to market will be too long. That's why we do partner with co-location or GCP to go faster and eventually at some point come back with our own solution. Okay, But is it all one?
So to the customer, is it all one seamless? They Don't Infrastructure or do they choose to use your versus No. So it's one infrastructure.
Okay. Interesting. Cool.
So Suma was talking about that. Uh, we have been focusing and talking about how we, uh, uh, secure, uh, our customers, but also we have been acquiring, uh, sy. So it's not a partnership.
It's, we did acquire them, uh, over the years and are fully part of fortunate. Family name will stay linky, so it'll not like be like 40 linky or Portis or whatever. So the idea is really to onboard them and to go to the consumer market.
So the consumer market, as you know, is, uh, different from the enterprise. Uh, a lot of service providers are really keen to get, uh, uh, their customers, uh, having security and bring more revenue about security from that. Uh, on the other side, uh, the customers generally have a box.
They don't touch it, they don't configure it. They, even if there are extra security features, they would not enable them. Uh, and they don't generally don't want to pay.
So we had to come up with an idea on, uh, making that flexible, not increasing the cost of the device because the consumer, uh, devices are light in terms of performances compared to having a FortiGate at home. We're not going to ask each like consumer to have, uh, a chassis FortiGate just like to, to run, like to, uh, to stations. So we have to take that into consideration when we bring security into this consumer market.
So all those devices can be provisioned with, uh, TR 69. And the idea is, again, as we did or as we are doing with our, uh, standalone devices and 48 cloud, the idea is really to go to the consumer market in the same way, bring a clean pipe solution for the operators, for the service providers, and link that with our, uh, sovereigns e or SE solution. Meaning that it would be the same thing.
So you would have in your, um, in your home, you would have your, uh, linky device that would then based on, uh, an extra license, that asset can be opt in or opt out. Uh, and then you would be able to stack into add on top of that the a e security. Uh, if you want to have that bear in mind, it could be, um, a company willing to have older employees, which is the trend is more to go to reverse.
But you could have maybe one day or two days a week at home, but still want to have some kind of security for your employees to ensure that they will not come back, uh, in the office with some, uh, malwares and viruses and so on. And The last part I wanted to touch today with you is, um, we did present that, sorry, Question on Yes. So You've got, um, the 40 and GATE solution.
You can have a remote ap Yes. Which you can for home work in. Do you see you being able to allow at some point, links it aps to connect to get remotely?
So that's a good question and there is no clear answer today. As of today, it's two different companies, two different use cases. Mm-hmm.
Despite the fact that our goal is to bring SY devices into our sais solution, uh, it's not excluded, but it's not part of the short term, medium term roadmap. Okay. Uh, just to the fact that, um, there would be some kind of integration, like the integration that someone was talking about dual boot or making VOS, uh, having the same capabilities on one sided the other.
So we didn't take that yet, but doesn't mean we'll never do it. Okay. Go ahead.
Just to follow on that, from a business model standpoint, two different reseller channels, can Fortinet resellers sell Linksys or vice versa? As of now, the Fortinet is not reselling Linksys Direct To consumer only through retail channels, All markets. So we have nothing to do with liny.
Okay. We, we wanted to separate the enterprise with the consumer. So for this 'cause I see like managed by the telco service provider.
So like as a, as a person, as as a, so I could go by one of these myself and then connect to the SASSI cloud, or is this reliant on me getting the CPE equipment from Speak? No, well, most of the time it would be, uh, the service provider shipping that to you and, uh, you helped for, uh, extra security and they would provision that, uh, towards your device once it's connected and you will benefit from it. So are the, are you aiming for partnerships with like at and t Google?
I mean like that level of, Of consumer internet, we need to talk with the team in charge of that, but uh, uh, if we have that it's coming from, sorry, from customers or partners requirements. So most likely, yes. Okay.
But I don't know what would be Woo. And what then, So you're not thinking of using a LINY as a managed device to extend the enterprise kind of thing, where your enterprise customers should say, Hey, we want to deploy this to our homes as, Okay, so we already have, as SUM was saying, yeah, the, uh, remote ap, we have the one that, this one, uh, I think it's a 2 3 1 K, um, uh, a small factor. So yeah, we, we don't think that at the moment, so we prefer to have that separated.
Sure. Except for the SE security. Okay.
That's okay. For the ones that were there last year, we did present, uh, a feature on four TH cloud, uh, allowing to connect on those extenders. Here we have a USB port and you can connect a USB hub and up to 16 USB to console cables.
And from the cloud you can access any device and debug that should you have an issue. So if you have a switch, a router or a 48 or anything that is broken or stuck, you can connect to that and get it, um, get it, uh, sorry, get the console, uh, connectivity. So we have a way to auto detect the speed, uh, auto detect all the settings and also label the port for you to go back and know what connection is what and things like that.
But you will tell me, Alex, you talk about the cloud, but a lot of your customers have a FortiGate on premises. How do you address that? And that's something that we are working towards by, uh, by end of the year, is bring this excellent feature we have to all of FortiGate customers that have for manager, meaning that most of the time what you would get is you would get a full stack of, uh, a 40 GATE AP and switches, and you would have one of those, uh, 4G 5G gateways giving you a redundant, uh, backup connectivity or primary connectivity whatever, uh, towards internet, uh, over the, uh, SZ one feature.
But what if the underneath FortiGate or site, or even the one connectivity is failing? So what we do is we would have two streams, two, uh, control plane, one towards the FortiGate as primary and the secondary towards the cloud dedicated for the ofAnd management, meaning that once you would go to your, um, to your 40 manager, you would be able to get the connectivity of the console devices remotely from the cloud. So this is allowing us to benefit from this cloud feature, this really good outbound feature for all the customers that have a large amount of deployments, and they cannot afford to send someone each time to just reboot a device out to check something.
And that's all I have to say today. Uh, any question? Just, Just, So would that secondary be on a 5G or 4G?
Yes, it is relying on the 5G 4G. Yes. Because yeah, if you did lose the, uh, internal connectivity, you have to get that Yes.
Correct. Is this designed to replace the requirement for something third party, like the ZPE? It, it can, it can replace, yeah.
So it's, uh, because the extender is here to do whatever you want, it can be a standalone device. It can, uh, it can even, we have some vicular ones that can provide you, uh, access or insights or elements. So it's really, uh, I would say, uh, like a Swiss knife, uh, tool that is allowing you to do, uh, backup primary connectivity, remote access, and whatever you want For the, uh, Linksys product line, uh, gathering that it's, it's still, uh, details to be worked out.
However, if you can share, say by the end of this year, how will you define success in terms of, you know, uh, taking over the links assets, what can we look at and say, okay, uh, this is really, uh, resonating in the market? Yeah. Uh, I don't have all the insights of what are the plans overall like with the acquisition of xi.
Uh, but yeah, I, I'm sorry, I don't have real answers to, to, to say on that, but we are actively working yet to, uh, make them onboarding out of the Fortinet a million and, uh, and going to success. Yes. How long, when did, how long ago did that acquisition occur?
So in fact, we did go through different phases. We had, uh, up to like, like we started maybe two years ago, maybe It's been a minute, this is not like very brand new Right. Acquire 51% of flexes.
And recently, few months back, we did acquire the most of it. Okay. And for the, uh, yeah, sovereign sass e uh, drivers, uh, it sounds like, uh, the service providers are keen on using this capability.
Uh, I guess what else is driving Fortinet to, you know, put more portfolio development focus on sovereign SASS e capabilities? The, Well, the, the needs are, are, well, there are multiple, um, well, we have said you have the service providers, you have also large deployments where customers just want, uh, remote people to just get security. Um, and there are few others that not coming to my head, but it, it's really giving security and giving connectivity without having thel.
I said, uh, mm-hmm. We did. So it's not just like, uh, a connectivity.
We did bring, um, connectivity, UTP, firewalling, DM all part and the ZTNA. So just making the life as easy as possible for the remote worker or hybrid workforce to, to work. So that's, that's what is driving us.
So there are multiple use cases, uh, but yeah, I don't have them in on my head, but yeah, so it's really different based on what the customers want. Some just don't want to have a gauge, don't want to have a a, a standalone cloud. They just want ssi.
So we are there to offer that. But some want a bit of both, so it's Right on. And yeah, we're, we're also seeing simply compliance with the local.
So we do have two, two things. So we have the regular one and we have one where we do also cherry pick the data centers with the level of security just to ensure that the customers with some specific needs can also have that without having some challenges.