Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortinet: Cloud Network Security Reference Architectures Overview

Fortinet
07/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Don't reinvent the wheel. Whether you're securing a new cloud-native application, migrating an existing system to the cloud, or even looking to leverage a cloud provider's global network as a global transport for your SD-WAN, chances are it's been done before. That's where reference architectures come into play. Fortinet's set of tested and validated security architectures for cloud network security are based on our experience with thousands of deployments from customers ranging from small businesses to international giants. You can download our white paper on trusted and validated architectures for detail. Here's a taste of what you encounter. These aren't detailed step-by-step instructions for cloud security, nor do they offer a comprehensive approach to cloud security. As the slide says, network security is only part of the security equation. These architectures don't describe a complete security fabric. The Fortinet solutions are designed to be woven into a true cybersecurity mesh. These architectures offer a conceptual view as to how to best position network security tools like firewalls for common cloud use cases. You'll need to customize these approaches to match your environment. Fortinet offers four architectures for the most common cloud compute use cases. Ingress inspection, egress filtering, east-west traffic inspection for segmentation, and cloud on-ramp, be it through SD-WAN or VPN. Here we see an architecture for routed ingress traffic inspection. The architecture is easy to read. The zones are clearly laid out, traffic flows are straightforward, and the VPCs are clearly defined. In this case, the front-end load balancer receives incoming traffic from the right on a public IP address, and it denets the traffic to the private IP address of the firewalls. Traffic is received on the public interface, the public subnet of the FortiGate VMs, where security and routing policies are applied. Traffic is then sent to the destination application. Return traffic is routed back through the public load balancer in most scenarios. The accompanying white paper will fill in a lot of the details, from clarifying goals of the approach to specifying what FortiGuard services or threat feeds you should subscribe to and suggest related products that may enhance your deployment. Products like FortiManager for central management, FortiAnalyzer for analytics, as well as load balancing and sandboxing tools. It even specifies how the architecture can be used to enforce COO trust architect policies. Here we see a similar approach for egress security. Again, the diagram is easy to read and understand. It specifies conceptual locations for the firewall and management tools, and codes route tables to clarify traffic flows. And again, the white paper fills in the details, including how high assurances achieve, threat services required, and supporting products. In this case, we see east-west traffic inspection use case, which refers to securing of network traffic that moves laterally within a data center or within a cloud network, you know, between servers and storage systems and applications within the same security perimeter. Usually east-west segmentation deployments focusing on filtering traffic based on ports and protocols. But honestly, you need more. You need to be able to perform deep traffic inspection between segments, including IPS, malware detection, and data loss prevention. You also want to enforce access and routing controls based on applications, users, and content. The goals are to gain visibility into all east-west traffic flows, to apply granular least privilege access controls between segments, to detect and prevent lateral movements and threats, to isolate critical assets and sensitive data. Many of the most serious attacks are enabled by breach transversals, and this architecture will help limit that blast radius. It's become increasingly common to use cloud transitive networks as a global backbone for your SD-WAN deployments. This approach, often referred to as cloud-enabled SD-WAN or cloud-based SD-WAN, offers several advantages for organizations looking to build global high-performance networks, including taking advantage of the global reach of your cloud provider's backbone, improved performance in SLAs, and cost savings and scalability, especially when compared with MPLS systems. We see customers using tools like AWS's recently announced Cloud WAN, Tunnelless Connect, and Azure Virtual WAN. And then there are tools like Google's Cross-Cloud Networks and Oracle's Distributed Cloud Services that offer multi-cloud support. This video gave you just a taste for what you'll find in a white paper on Tested and Validated Architectures for Cloud Network Security. Download it today. And don't forget to download our accompanying cloud security toolkit. You can try our solutions on Fortinet.com or by signing up for a free trial on any of the major cloud platforms. Thank you.

TL;DR

  • Fortinet offers four tested reference architectures covering ingress inspection, egress filtering, east-west segmentation, and cloud on-ramp for SD-WAN/VPN deployments.
  • These architectures provide conceptual frameworks for positioning firewalls in cloud environments, not step-by-step instructions or complete security solutions.
  • East-west traffic inspection requires deep inspection capabilities including IPS, malware detection, and DLP to prevent lateral movement and limit breach blast radius.
  • Cloud-enabled SD-WAN using provider backbones from AWS, Azure, Google, or Oracle offers global reach, improved performance, and cost savings compared to MPLS.

Summary

This overview introduces Fortinet's tested and validated reference architectures for cloud network security, designed to help organizations avoid reinventing the wheel when securing cloud environments. The video covers four primary use cases: ingress inspection for incoming traffic, egress filtering for outbound traffic, east-west traffic inspection for lateral movement protection and segmentation, and cloud on-ramp configurations for SD-WAN and VPN deployments. Each architecture provides a conceptual framework showing how to position network security tools like firewalls within cloud environments, with clear zone definitions and traffic flow diagrams. The presenter emphasizes that these architectures are starting points requiring customization, not comprehensive security solutions, and are meant to integrate into a broader cybersecurity mesh. The video highlights the importance of deep traffic inspection capabilities including IPS, malware detection, and data loss prevention for east-west segmentation, and discusses the growing trend of using cloud provider backbones as global transport for SD-WAN deployments, referencing tools from AWS, Azure, Google, and Oracle.

Chapters

0:00 - Introduction to Reference Architectures
1:11 - Four Cloud Compute Use Cases
1:25 - Ingress Traffic Inspection
2:25 - Egress Security Architecture
2:45 - East-West Traffic Segmentation
3:43 - Cloud-Enabled SD-WAN

Key Quotes

0:22 "That's where reference architectures come into play. Fortinet's set of tested and validated security architectures for cloud network security are based on our experience with thousands of deployments from customers ranging from small businesses to international giants."
0:52 "These architectures don't describe a complete security fabric. The Fortinet solutions are designed to be woven into a true cybersecurity mesh."
3:36 "Many of the most serious attacks are enabled by breach transversals, and this architecture will help limit that blast radius."

FAQ

What cloud security use cases do Fortinet's reference architectures cover?

The architectures address four common use cases: ingress inspection for incoming traffic, egress filtering for outbound traffic, east-west traffic inspection for segmentation and lateral movement prevention, and cloud on-ramp configurations for SD-WAN or VPN connectivity.

Are these reference architectures complete security solutions?

No, these architectures focus specifically on network security and are designed to be customized for your environment. They provide conceptual frameworks for positioning firewalls and are meant to be woven into a broader cybersecurity mesh that includes additional security controls.


Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Network Security
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Network Security
  • Zero Trust
  • SASE
  • SSE
  • Technical Deep Dive
  • cloud network security
  • reference architectures
  • ingress inspection
  • egress filtering
  • east-west segmentation
  • SD-WAN
  • cloud on-ramp
  • lateral movement prevention
  • zero trust
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortinet: Cloud Network Security Reference Architectures Overview

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    22

                    Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                    07/22/202601:00 PM ET
                    • Aug
                      19

                      Becoming Agent Ready: Insights from Cyera's Expertise

                      08/19/202612:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 07/21/2026
                        04:00 AM
                        07/21/2026
                        Strategies for Managing AI Governance: Safeguarding App-to-LLM API Traffic
                        https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-safeguarding-app-to-llm-api-traffic/
                      • 07/22/2026
                        06:30 AM
                        07/22/2026
                        Insights and Strategies for Effective Data Privacy and Protection
                        https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection/
                      • 07/22/2026
                        01:00 PM
                        07/22/2026
                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                        https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                      • 07/28/2026
                        01:00 PM
                        07/28/2026
                        Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                        https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                      • 07/29/2026
                        04:00 AM
                        07/29/2026
                        Real-Time Strategies for Safeguarding Against Prompt Injections
                        https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                      • 07/29/2026
                        01:00 PM
                        07/29/2026
                        Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                        https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                      • 08/19/2026
                        12:00 PM
                        08/19/2026
                        Becoming Agent Ready: Insights from Cyera's Expertise
                        https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version