LAN Edge Overview

LAN Edge Overview and the Evolution of Integrated Networking

  • Historical Context: A Journey of Integration

    • In the early stages of computer networking, wired and wireless infrastructures were managed as distinct, separate entities.

    • Wired networks served as the backbone, while wireless networks were initially viewed as a convenient but less secure option for mobile users.

    • The Rise of Mobility and BYOD: The proliferation of mobile devices and the emergence of the "bring your own device" (BYOD) trend made secure wireless connectivity a mandatory requirement rather than an optional convenience.

    • Need for Unification: Changes in network user behavior highlighted the necessity for tighter integration between wired and wireless networks to enhance security, unify management, and reduce operational complexity/costs.

    • Technological Foundation: Advances in Wi-Fi, software-defined networks (SDN), network virtualization, and cloud-based management provided the infrastructure for a unified approach at the network edge.

  • Defining LAN Edge

    • Concept: LAN Edge represents the convergence of security and network access into a single, cohesive environment.

    • Core Characteristics:

      • Secure: Convergence of security (firewall, intrusion prevention, access controls) and network access managed as one entity.

      • Simple: An adaptive and integrated platform that eliminates "sprawl" regarding appliances, configurations, and licenses. It utilizes a single interface for centralized management of wired and wireless networks.

      • Intelligent: Utilizes extensive data to allow Artificial Intelligence (AI) and Machine Learning (ML) to drive resilient networking, better outcomes, and improved user experiences.

      • Scalable and Flexible: Adapts to varying network sizes, increasing device densities, and new service implementations.

Key Components and Protocols of the Fortinet LAN Edge Solution

  • Device Roles in LAN Edge

    • FortiGate: Functions as the central hub and a "single pane of glass" for managing both security and networking functions. It acts as the built-in wireless/switch controller.

    • FortiSwitch: Provides advanced switching capabilities and integrates with the Fortinet Security Fabric to extend security to Layer 22.

    • FortiAP: Ensures wireless scalability and flexibility, providing security features to wireless users through seamless integration.

    • FortiManager: Provides centralized management for all Fortinet devices at the LAN edge, including configuration, backup, and automated workflows.

    • FortiAuthenticator: Acts as the identity manager and gatekeeper, providing standards-based secure authentication (RADIUS, LDAP, 802.1X802.1X).

    • FortiExtender: Provides reliable 4G/5G4G/5G connectivity for branch offices and remote sites.

    • FortiAIOps: An AI-powered analytics platform for proactive issue detection and performance optimization.

  • FortiLink Protocol

    • Definition: FortiLink is the management interface and remote management protocol that allows a FortiGate to manage FortiSwitch devices.

    • Function: It transforms FortiSwitch and FortiAP into logical extensions of the FortiGate, allowing the network to be managed as a single unit.

    • Benefits: It enables automated provisioning, provides full visibility, and offers integrated security where firewall and switch ports are equally secure.

FortiGate as a Secure LAN Controller

  • Design Approaches

    • SD-Branch (Software-Defined Branch):

      • The main internet-access FortiGate directly controls secure LAN devices.

      • Ideal for small-to-medium offices.

      • FortiSwitch devices act as access layer models providing Power over Ethernet (PoE) to FortiAPs.

    • Dedicated Controller / Internal Segmentation Firewall (ISFW):

      • Also known as an "overlay design."

      • Ideal for large campus networks with many FortiAPs and existing switching infrastructure.

      • The FortiGate is dedicated to Wi-Fi traffic, acting as a controller and security inspection point rather than the primary internet uplink.

  • Controller Capacities by Model

    • 40F40F: Supports 88 to 1616 APs and 88 FSWs.

    • 80F80F: Supports 4848 to 9696 APs and 2424 FSWs.

    • 600F600F: Supports 512512 to 10241024 APs and 9696 FSWs.

    • 1800F+1800F+: Supports 20482048 to 40964096 APs and 196196 FSWs.

Centralized Management and Zero-Touch Deployment

  • The Role of FortiManager

    • Provisioning: Distributes firewall policies across the entire network.

    • Revision Control: Acts as a central repository for configuration history and security audits.

    • Private FDS: Acts as a private FortiGuard Distribution Server for managed devices.

    • Automation: Uses JSON APIs to script device provisioning and policy changes.

    • Templates: Includes predefined FortiSwitch and FortiAP templates for consistency and speed.

  • Zero-Touch Provisioning (ZTP)

    • Step 1: Deploy: Ship the FortiGate, FortiSwitch, and FortiAP to the site; plug them into the internet.

    • Step 2: Configure: The FortiGate automatically sends a message to the deployment server.

    • Step 3: Run: The deployment server pushes the pre-defined configuration to all devices.

Advanced Monitoring and Identity Management

  • FortiAuthenticator Features

    • Acts as a user authentication and identity manager.

    • RADIUS and LDAP: Provides standard central services.

    • Two-Factor Authentication (2FA): Compatible with FortiToken.

    • FSSO: Supports Fortinet Single Sign-On.

    • Portals: Includes captive portals and self-serve portals for users.

  • FortiAIOps (Artificial Intelligence for IT Operations)

    • Merges monitoring, troubleshooting, and AI insights into one platform.

    • Event Log Processing: Analyzes logs from all network devices.

    • Predictive Analysis: Predicts failure types using trained ML models.

    • Root Cause Analysis: Reviews status and configurations to identify the source of failures.

    • Remediation: Provides client-level recommendations to overcome network failures.

LAN Edge Use Case Scenarios

  • Secure Campus

    • Covers large physical areas (universities, hospitals, government facilities).

    • Hierarchical Design: Usually features two or three levels between the access switch and core equipment (Access -> Aggregation -> Core).

    • Connectivity: Uses cascading, high-bandwidth fiber-optic connections to overcome the reach limitations of copper Ethernet.

  • Secure SD-Branch

    • An extension of SD-WAN that integrates WAN, wired LAN, wireless LAN, security, and Network Access Control (NAC).

    • WAN Edge: Provides business-outcome-driven WAN and 5G/LTE5G/LTE wireless primary or backup links.

    • LAN Edge: Protects the access edge through convergence.

    • Device Edge (NAC): Automatically discovers, classifies, and secures the onboarding of IoT devices.

  • Operational Technology (OT) Solutions

    • Requires specialized cybersecurity for manufacturing, energy, and transportation.

    • Rugged Models: FortiSwitch rugged models are tailored for industrial cabinets.

    • Lossless Redundancy: Utilizes Parallel Redundancy Protocol/High-Availability Seamless Redundancy (PRP/HSR).

    • Time and Efficiency: Supports Precision Time Protocol (PTP) transparent clocks and Media Redundancy Protocol (MRP).

    • Voltage Support: Flexible direct current options ranging from 1818 to 125125 VDC.