Transcript
Don't reinvent the wheel. Whether you're securing a new cloud-native application, migrating an existing system to the cloud, or even looking to leverage a cloud provider's global network as a global transport for your SD-WAN, chances are it's been done before. That's where reference architectures come into play. Fortinet's set of tested and validated security architectures for cloud network security are based on our experience with thousands of deployments from customers ranging from small businesses to international giants. You can download our white paper on trusted and validated architectures for detail. Here's a taste of what you encounter. These aren't detailed step-by-step instructions for cloud security, nor do they offer a comprehensive approach to cloud security. As the slide says, network security is only part of the security equation. These architectures don't describe a complete security fabric. The Fortinet solutions are designed to be woven into a true cybersecurity mesh. These architectures offer a conceptual view as to how to best position network security tools like firewalls for common cloud use cases. You'll need to customize these approaches to match your environment. Fortinet offers four architectures for the most common cloud compute use cases. Ingress inspection, egress filtering, east-west traffic inspection for segmentation, and cloud on-ramp, be it through SD-WAN or VPN. Here we see an architecture for routed ingress traffic inspection. The architecture is easy to read. The zones are clearly laid out, traffic flows are straightforward, and the VPCs are clearly defined. In this case, the front-end load balancer receives incoming traffic from the right on a public IP address, and it denets the traffic to the private IP address of the firewalls. Traffic is received on the public interface, the public subnet of the FortiGate VMs, where security and routing policies are applied. Traffic is then sent to the destination application. Return traffic is routed back through the public load balancer in most scenarios. The accompanying white paper will fill in a lot of the details, from clarifying goals of the approach to specifying what FortiGuard services or threat feeds you should subscribe to and suggest related products that may enhance your deployment. Products like FortiManager for central management, FortiAnalyzer for analytics, as well as load balancing and sandboxing tools. It even specifies how the architecture can be used to enforce COO trust architect policies. Here we see a similar approach for egress security. Again, the diagram is easy to read and understand. It specifies conceptual locations for the firewall and management tools, and codes route tables to clarify traffic flows. And again, the white paper fills in the details, including how high assurances achieve, threat services required, and supporting products. In this case, we see east-west traffic inspection use case, which refers to securing of network traffic that moves laterally within a data center or within a cloud network, you know, between servers and storage systems and applications within the same security perimeter. Usually east-west segmentation deployments focusing on filtering traffic based on ports and protocols. But honestly, you need more. You need to be able to perform deep traffic inspection between segments, including IPS, malware detection, and data loss prevention. You also want to enforce access and routing controls based on applications, users, and content. The goals are to gain visibility into all east-west traffic flows, to apply granular least privilege access controls between segments, to detect and prevent lateral movements and threats, to isolate critical assets and sensitive data. Many of the most serious attacks are enabled by breach transversals, and this architecture will help limit that blast radius. It's become increasingly common to use cloud transitive networks as a global backbone for your SD-WAN deployments. This approach, often referred to as cloud-enabled SD-WAN or cloud-based SD-WAN, offers several advantages for organizations looking to build global high-performance networks, including taking advantage of the global reach of your cloud provider's backbone, improved performance in SLAs, and cost savings and scalability, especially when compared with MPLS systems. We see customers using tools like AWS's recently announced Cloud WAN, Tunnelless Connect, and Azure Virtual WAN. And then there are tools like Google's Cross-Cloud Networks and Oracle's Distributed Cloud Services that offer multi-cloud support. This video gave you just a taste for what you'll find in a white paper on Tested and Validated Architectures for Cloud Network Security. Download it today. And don't forget to download our accompanying cloud security toolkit. You can try our solutions on Fortinet.com or by signing up for a free trial on any of the major cloud platforms. Thank you.