LAN Edge Overview
LAN Edge Overview and the Evolution of Integrated Networking
Historical Context: A Journey of Integration
In the early stages of computer networking, wired and wireless infrastructures were managed as distinct, separate entities.
Wired networks served as the backbone, while wireless networks were initially viewed as a convenient but less secure option for mobile users.
The Rise of Mobility and BYOD: The proliferation of mobile devices and the emergence of the "bring your own device" (BYOD) trend made secure wireless connectivity a mandatory requirement rather than an optional convenience.
Need for Unification: Changes in network user behavior highlighted the necessity for tighter integration between wired and wireless networks to enhance security, unify management, and reduce operational complexity/costs.
Technological Foundation: Advances in Wi-Fi, software-defined networks (SDN), network virtualization, and cloud-based management provided the infrastructure for a unified approach at the network edge.
Defining LAN Edge
Concept: LAN Edge represents the convergence of security and network access into a single, cohesive environment.
Core Characteristics:
Secure: Convergence of security (firewall, intrusion prevention, access controls) and network access managed as one entity.
Simple: An adaptive and integrated platform that eliminates "sprawl" regarding appliances, configurations, and licenses. It utilizes a single interface for centralized management of wired and wireless networks.
Intelligent: Utilizes extensive data to allow Artificial Intelligence (AI) and Machine Learning (ML) to drive resilient networking, better outcomes, and improved user experiences.
Scalable and Flexible: Adapts to varying network sizes, increasing device densities, and new service implementations.
Key Components and Protocols of the Fortinet LAN Edge Solution
Device Roles in LAN Edge
FortiGate: Functions as the central hub and a "single pane of glass" for managing both security and networking functions. It acts as the built-in wireless/switch controller.
FortiSwitch: Provides advanced switching capabilities and integrates with the Fortinet Security Fabric to extend security to Layer .
FortiAP: Ensures wireless scalability and flexibility, providing security features to wireless users through seamless integration.
FortiManager: Provides centralized management for all Fortinet devices at the LAN edge, including configuration, backup, and automated workflows.
FortiAuthenticator: Acts as the identity manager and gatekeeper, providing standards-based secure authentication (RADIUS, LDAP, ).
FortiExtender: Provides reliable connectivity for branch offices and remote sites.
FortiAIOps: An AI-powered analytics platform for proactive issue detection and performance optimization.
FortiLink Protocol
Definition: FortiLink is the management interface and remote management protocol that allows a FortiGate to manage FortiSwitch devices.
Function: It transforms FortiSwitch and FortiAP into logical extensions of the FortiGate, allowing the network to be managed as a single unit.
Benefits: It enables automated provisioning, provides full visibility, and offers integrated security where firewall and switch ports are equally secure.
FortiGate as a Secure LAN Controller
Design Approaches
SD-Branch (Software-Defined Branch):
The main internet-access FortiGate directly controls secure LAN devices.
Ideal for small-to-medium offices.
FortiSwitch devices act as access layer models providing Power over Ethernet (PoE) to FortiAPs.
Dedicated Controller / Internal Segmentation Firewall (ISFW):
Also known as an "overlay design."
Ideal for large campus networks with many FortiAPs and existing switching infrastructure.
The FortiGate is dedicated to Wi-Fi traffic, acting as a controller and security inspection point rather than the primary internet uplink.
Controller Capacities by Model
: Supports to APs and FSWs.
: Supports to APs and FSWs.
: Supports to APs and FSWs.
: Supports to APs and FSWs.
Centralized Management and Zero-Touch Deployment
The Role of FortiManager
Provisioning: Distributes firewall policies across the entire network.
Revision Control: Acts as a central repository for configuration history and security audits.
Private FDS: Acts as a private FortiGuard Distribution Server for managed devices.
Automation: Uses JSON APIs to script device provisioning and policy changes.
Templates: Includes predefined FortiSwitch and FortiAP templates for consistency and speed.
Zero-Touch Provisioning (ZTP)
Step 1: Deploy: Ship the FortiGate, FortiSwitch, and FortiAP to the site; plug them into the internet.
Step 2: Configure: The FortiGate automatically sends a message to the deployment server.
Step 3: Run: The deployment server pushes the pre-defined configuration to all devices.
Advanced Monitoring and Identity Management
FortiAuthenticator Features
Acts as a user authentication and identity manager.
RADIUS and LDAP: Provides standard central services.
Two-Factor Authentication (2FA): Compatible with FortiToken.
FSSO: Supports Fortinet Single Sign-On.
Portals: Includes captive portals and self-serve portals for users.
FortiAIOps (Artificial Intelligence for IT Operations)
Merges monitoring, troubleshooting, and AI insights into one platform.
Event Log Processing: Analyzes logs from all network devices.
Predictive Analysis: Predicts failure types using trained ML models.
Root Cause Analysis: Reviews status and configurations to identify the source of failures.
Remediation: Provides client-level recommendations to overcome network failures.
LAN Edge Use Case Scenarios
Secure Campus
Covers large physical areas (universities, hospitals, government facilities).
Hierarchical Design: Usually features two or three levels between the access switch and core equipment (Access -> Aggregation -> Core).
Connectivity: Uses cascading, high-bandwidth fiber-optic connections to overcome the reach limitations of copper Ethernet.
Secure SD-Branch
An extension of SD-WAN that integrates WAN, wired LAN, wireless LAN, security, and Network Access Control (NAC).
WAN Edge: Provides business-outcome-driven WAN and wireless primary or backup links.
LAN Edge: Protects the access edge through convergence.
Device Edge (NAC): Automatically discovers, classifies, and secures the onboarding of IoT devices.
Operational Technology (OT) Solutions
Requires specialized cybersecurity for manufacturing, energy, and transportation.
Rugged Models: FortiSwitch rugged models are tailored for industrial cabinets.
Lossless Redundancy: Utilizes Parallel Redundancy Protocol/High-Availability Seamless Redundancy (PRP/HSR).
Time and Efficiency: Supports Precision Time Protocol (PTP) transparent clocks and Media Redundancy Protocol (MRP).
Voltage Support: Flexible direct current options ranging from to VDC.