SD-Branch

SD-Branch Overview and Architecture within FortiOS 7.67.6

In the current landscape of information technology, the transition from a traditional local area network edge to a software-defined wide area network and beyond represents a fundamental shift in how networks are designed, managed, and secured. Key trends driving this evolution include the acceleration of digital transformation where organizations invest in technologies like SD-WAN to become cloud-ready, the simplification of management and deployment for network infrastructure, and the enhancement of visibility into network assets and applications. Furthermore, implementing robust security at remote edges allows administrators to establish global security policies while reducing management and licensing complexity to lower costs and enhance performance. SD-Branch acts as an extension of the software-defined approach by integrating LAN, WAN management, security, and connectivity into a unified platform. It provides a comprehensive solution encompassing wired and wireless components, Network Access Control, and security within the single operating system, FortiOS 7.67.6.

The architecture of SD-Branch is characterized by its flexibility, scalability, and convergence with security. It allows organizations to manage both WAN and LAN from a single platform, integrating intelligent and dynamic routing across multiple WAN links with Unified Threat Management functions such as firewalls, intrusion prevention systems, and secure web gateways. Centralized management ensures that administrators can monitor and configure branch networks from a single pane of glass, while LAN and WLAN management is unified with WAN connectivity. Additional critical features of the SD-Branch architecture include the incorporation of Zero Trust Network Access principles, seamless cloud integration, robust IoT management for visibility and control over unconventional device traffic, and the increasing use of AI and machine learning through automation and intelligence.

Core Product Components and Management Platforms

The Fortinet SD-Branch architecture relies on five core product components: FortiGate, FortiAP, FortiSwitch, NAC, and FortiExtender. FortiGate serves as a Next-Generation Firewall and the central hub of the SD-Branch architecture. FortiAP provides secure and high-performance wireless connectivity, while FortiSwitch ensures secure and manageable LAN connectivity within the branch environment. NAC is responsible for enforcing security policies on devices attempting network access, protecting the edge by discovering, classifying, and onboarding IoT devices. FortiExtender expands WAN capabilities by providing LTELTE or 5G5G connectivity as either a primary or backup link. These components are supported by auxiliary tools such as FortiAIOps, FortiMonitor, and management interfaces like FortiLink, FortiLAN Cloud, and FortiManager.

FortiSwitch VLAN and Port Management

When a FortiGate discovers its first switch, it automatically applies essential configuration settings required for switch management, including several preconfigured VLANs with predefined IDs. The Default VLAN serves as the native VLAN assigned to all ports. The Quarantine VLAN is used for traffic from devices that have been isolated on the FortiGate. The RSPAN VLAN facilitates encapsulated mirrored traffic across the network. Specialized VLANs for Voice and Video are utilized when endpoint devices are detected via LLDP-MED. The Onboarding VLAN is the destination for devices that do not match configured NAC policies, and the NAC segment VLAN prevents hosts from needing to renew IP addresses when moving between segments. Except for the Default and Onboarding VLANs, all preconfigured VLANs are automatically assigned a DHCP scope. These VLANs can be edited or deleted as required by the administrator.

Managing FortiSwitch from the FortiGate essentially makes the switch an extension of the firewall itself. VLANs on a managed switch function identically to standard FortiGate VLANs and support features like device detection and captive portals. However, a FortiSwitch VLAN must be bound to the FortiLink interface to be selectable in switch port settings. The Ports Configuration page in FortiSwitch Manager allows for granular control over individual ports, where administrators can set the Native VLAN and the Allowed VLAN list. The Native VLAN handles untagged ingress traffic and sends egress traffic matching that VLAN untagged. The Allowed VLAN list specifies which tagged and untagged frames are permitted, which is critical for inter-switch links and FortiLink trunks. The Untagged VLAN setting defines which egress traffic is sent without tags, typically for features like quarantine MAC or dynamic assignment.

Advanced Switch Features: PoE, Trunks, and Access VLANs

For PoE-enabled switches, administrators can monitor power delivery through the FortiSwitch Manager faceplates or via the FortiGate CLI using the command diagnoseswitchcontrollerswitchinfopoedetaildiagnose\,switch-controller\,switch-info\,poe\,detail, which provides details on power class, voltage, current, and maximum power. Resetting PoE on a specific port can be accomplished with the command executeswitchcontrollerswitchactionpoeresetportexecute\,switch-controller\,switch-action\,poe\,reset\,\,port. Regarding connectivity, FortiSwitch defines a trunk as a Link Aggregation Group interface. While auto-ISL features utilize LLDP to form trunks automatically between switches or to a FortiGate, other devices require manual trunk configuration.

Access VLANs provide a security mechanism to prevent direct intra-VLAN communication, forcing devices to communicate only with the FortiGate controller; any traffic destined for other devices in the same VLAN is dropped by the switch. This is useful for separating devices during the onboarding or discovery phases and preventing the lateral spread of malware. Access VLAN settings are enabled by default on the quarantine and onboarding VLANs and can be manually enabled via the CLI with the command setswitchcontrolleraccessvlanenableset\,switch-controller-access-vlan\,enable. If intra-VLAN communication is required while an Access VLAN is active, administrators must configure Proxy ARP on the FortiGate and create a firewall policy that specifies the same VLAN interface for both the source and destination.

FortiAP Discovery and CAPWAP Messaging

FortiAPs are managed centrally by the FortiGate wireless controller and must discover the controller using one of six specific methods. The Static method involves a preconfigured controller IP. The DHCP method uses Option 138138 to retrieve the controller IP. The DNS method uses the hostname defined in the AC_HOSTNAME_1AC\_HOSTNAME\_1 parameter. The FortiCloud method uses the hostname apctrl1.fortinet.comapctrl1.fortinet.com. The Multicast method uses the address 224.0.1.140224.0.1.140, and the Broadcast method sends a request to the local subnet. If discovery fails, the AP enters a SULKING state before retrying. Management is conducted via the CAPWAP protocol, which uses UDP port 52465246 for the control channel and UDP port 52475247 for the data channel. Encryption for the data channel can be provided by DTLS or IPsec, with IPsec being recommended for remote links to take advantage of hardware offloading.

AP Provisioning and Hardware Profiles

Provisioning FortiAPs through FortiManager can be done in either transition management mode or per-device management mode. In central management, profiles are stored on FortiManager and applied across multiple controllers, whereas per-device mode manages profiles locally on each FortiGate. AP Profiles dictate critical hardware settings, including management passwords, administrative access, allowed radio channels, transmission power levels, and the specific SSIDs to be broadcast. While FortiGate automatically assigns a default profile upon discovery and authorization, FortiManager requires manual assignment or pre-authorization using serial numbers. To establish a CAPWAP tunnel, CAPWAP must be enabled on the FortiGate interface (now part of Security Fabric Connection access), and the managing user must have Read-Write JSON API Access. After configuration, changes must be pushed to the controller using the Install Wizard.

CAPWAP Tunnel Fragmentation and Performance

One challenge in managing APs over WAN links is fragmentation caused by CAPWAP tunnel overhead increasing the packet size beyond the MTU. This can lead to data loss, latency, and management failures. Administrators can mitigate this by reducing the tunnel maximum transmission units for the uplink and downlink. The tcpmssadjusttcp-mss-adjust feature, enabled by default, allows the AP to limit the maximum segment size of TCP packets by injecting a reduced value into SYN packets, ensuring the final CAPWAP packet matches the tunmtuuplinktun-mtu-uplink size. Additionally, the icmpunreachableicmp-unreachable option causes the AP to drop packets with the Don't Fragment bit set if they would cause fragmentation, sending back an ICMP Type 33 Code 44 destination unreachable message to the source. A common starting value for troubleshooting MTU issues is 15001500, though it may need to be reduced for specific WAN configurations.

SSID Traffic Modes: Tunnel, Bridge, and Mesh

There are three primary traffic modes for SSIDs: tunnel, bridge, and mesh. Tunnel mode is the default and involves sending all wireless traffic through a CAPWAP tunnel to the FortiGate for centralized security inspection and session-level tracking. This requires the FortiGate to be sized correctly for the traffic load. In contrast, Bridge mode forwards wireless traffic directly to the AP's local Ethernet interface, allowing wireless and wired stations to share the same broadcast domain. This mode is ideal for remote locations where controllers are across a WAN, as traffic stays local while only CAPWAP control messages go to the controller. Mesh mode is used exclusively as a backhaul for APs to create a wireless mesh network. For tunnel mode SSIDs in remote locations, split tunneling can be enabled via an Access Control List to allow local traffic, such as printing, to egress locally while corporate traffic is tunneled back to the main site.

Wireless Security and Captive Portal Configurations

SSID security modes determine the encryption and authentication for wireless clients. Supported standards include WPA2WPA2, WPA3WPA3, and OSEN for Hotspot 2.02.0. WPA3SAEWPA3\,SAE transition mode is available to support both WPA2PSKWPA2\,PSK and WPA3SAEWPA3\,SAE on a single SSID. For guest access, Captive Portals can be used to present disclaimers or authentication pages. A notable feature is Multiple Pre-shared Keys, available only for WPA2PSKWPA2\,PSK, which allows unique keys for different users or groups. MPSK facilitates dynamic VLAN assignment based on the key used and enables administrators to limit the number of devices per key or revoke access for a single user without impacting the whole network. In bridge mode, some AP models can also support standalone security profiles for Antivirus, IPS, Application Control, and Web Filtering, allowing for local inspection even if the controller is unreachable.

FortiExtender as a LAN Extension Solution

FortiExtender LAN extension provides a thin-edge connectivity solution for the modern distributed network, addressing challenges like secure remote work and IT complexity. In this mode, FortiExtender acts as a plug-and-play device that extends the corporate LAN to remote branches through a Layer 2VXLAN2\,VXLAN over an IPsec tunnel. The remote FortiGate serves as the DHCP server and performs all NGFW functions for the remote site. The discovery process involves the FortiGate authorizing the FortiExtender and establishing a CAPWAP control plane. Once the LAN-extension profile (such as the default for the FEX200FEX-200) is assigned, the IPsec tunnel and VXLAN data plane are established. This provides unified security policies and cost-effective redundancy using 5G5G, LTELTE, or Ethernet backhaul options.