Fortinet Ecosystem Overview
Fortinet Ecosystem Overview
Fortinet Ecosystem Overview
Agenda
Fortinet Overview
Fortinet EcoSystem Overview
Fortinet Advanced Threat Prevention
Fortinet SDN Framework
FortiGuard Threat Intelligence
Questions
Fortinet Facts
FOUNDED
2000
IPO
2009
HQ
SUNNYVALE, CA
100+
OFFICES
WORLDWIDE
OVER
MILLION
2
DEVICES SHIPPED
#1
UNIT SHARE
WORLDWIDE
1.17B
CASH
40%
GROWTH
3,900+
EMPLOYEES
MARKET LEADING
TECHNOLOGY
255,000+
CUSTOMERS
257 PATENTS
228 PENDING
280+ 0-DAYs
Discovered
3
3.2
BILLION
INTERNET
USERS
10,000x
INCREASE IN CYBER THREATS
1.3
BILLION
SMARTPHONES
SHIPPED
WORLDWIDE
BILLION
NEW DEVICES
PER YEAR
THROUGH 2020
$191 BILLION
4
NO LONGER WORK
TOO MUCH FOCUS
ON COMPLIANCE
Advanced
Security
Network
Performance
Client
Security
Secure
Access
Network Security
Application
Security
Cloud
Security
FortiGate
SEAMLESS
Consistent threat posture
end-to-end, across the
expanding attack surface
INTELLIGENT
Threat intelligence and advanced threat
protection from the inside out for full
visibility and control
POWERFUL
Unrivaled network
performance for today and
the power to take on the
future
7
FortiGuard
Labs
200+
Full Visibility
Single Pane of Glass
FortiGuard
Services
FortiGuard
Sensors
2M+
8
10
Agenda
Fortinet Overview
Fortinet EcoSystem Overview
Fortinet Advanced Threat Prevention
Fortinet SDN Framework
FortiGuard Threat Intelligence
Questions
11
FortiAnalyzer
Log Analysis
FortiAP
Secure Wireless
FortiAuthenticator
Authentication
FortiCamera
IP Video Security
FortiClient
DATA CENTER
FortiAuthenticator
User Identity Management
FortiDB
Database Security
FortiDDoS
DDoS Protection
FortiExtender
FortiGate
FortiMail
Email Security
FortiManager
Centralized Management
FortiSandbox
FortiSwitch
FortiToken
2FA Token
FortiVoice
FortiWeb
FortiWiFi
Cloud
FortiManager
Endpoint Security
FortiCloud
FortiGate
FortiGate
FortiDB
Top-of-Rack
Database
Protection
FortiGateVMX
Centralized Management
SDN, Virtual
Firewall
FortiAnalyzer
Switching
FortiADC
Logging, Analysis,
Reporting
Application
Delivery
FortiWeb Controller
Web Application
Firewall
CAMPUS
FortiSandbox
FortiGate
Advanced Threat
Protection
Next Gen
IPS
FortiGate
DCFW
FortiAP
Secure Access
Point
FortiGate
FortiGate
Internal NGFW
NGFW
FortiMail
Application Security
Email Security
FortiDDoS
FortiSwitch
Application Delivery/SLB
DDoS Protection
Switching
FortiWiFi
Endpoint Security
UTM
FortiToken
Two Factor
Authentication
FortiCamera
IP Video Security
FortiClient
FortiClient
FortiExtender
Endpoint Protection
LTE Extension
FortiVoice
IP PBX Phone System
More
BRANCH
OFFICE
12
Solution-Based Ecosystem
Enterprise
Firewall
ENTERPRISE
NextGen FIREWALL
CONNECTED UTM
ATP FRAMEWORK
CLOUD SECURITY
SECURE ACCESS
ARCHITECTURE
Reputation
App Control
Antivirus
Anti-Botnet
IPS
Web App
Mobile
Security
Web
Filtering
Anti-spam
13
ENTERPRISE FIREWALL
5.4
FortiASIC
FortiGuard
FortiAuthenticator
FortiOS
Physical
IPS
Virtual
SWG
FortiManager
Cloud
VFW
Rugged
FortiAnalyzer
SDN
FortiGate
14
5.4
FortiASIC
FortiGuard
FortiManager
FortiPrivateCloud
FortiCloud
FortiSwitch
FortiAP
FortiClient
FortiVoice
FortiMail
FortiOS
FortiWiFi
Physical
FortiExtender
FortiWAN
Cloud
FortiGate
15
FortiGate
50-900 SERIES
UNIFIED THREAT
MANAGEMENT
FortiGate
FortiGate
1000-2000 SERIES
3000-6000 SERIES
Ensures continuous protection from the latest threats with dynamic updates from FortiGuard Labs.
Simplifies config and troubleshooting via single-pane-of-glass management.
16
SECURITY MANAGEMENT
FortiManager
FortiAnalyzer
FortiMoM
CENTRALIZED DEVICE
MANAGEMENT
CENTRALIZED LOGGING
AND REPORTING
HYPERSCALED SECURITY
ENTERPRISE MANAGEMENT
FIREWALL CONVERSION
FortiConverter
CONFIGURATION AND
MIGRATION TOOL
18
Virtual
Physical
Virtual
Physical
FortiADC
Virtual
Physical
FortiWeb
Physical
Physical
FortiMail
FortiDB
FortiDDoS
19
FortiWeb
FortiADC
FortiDDoS
WEB APPLICATION
FIREWALLS
APPLICATION DELIVERY
CONTROLLERS
DDOS ATTACK
MITIGATION APPLIANCES
20
Web Application
Servers
FortiWeb WAF
INTERNET
21
APPLICATION LEVEL
DDOS ATTACKS
IMPROPER
HTTP RFC
KNOWN APPLICATION
ATTACK TYPES
VIRUSES, MALWARE,
LOSS OF DATA
FORTIGATE AND FORTISANDBOX
APT DETECTION
IP REPUTATION
DDOS PROTECTION
PROTOCOL VALIDATION
ATTACK SIGNATURES
ANTIVIRUS/DLP
INTEGRATION
SCANNERS, CRAWLERS,
SCRAPERS
ADVANCED PROTECTION
UNKNOWN APPLICATION
ATTACKS
BEHAVIORAL VALIDATION
CORRELATION
APPLICATION
23
5.4
FortiASIC
Physical
FortiGuard
Virtual
FortiOS
Physical
FortiAnalyzer
Virtual
FortiManager
VMX
FortiCore
FortiGate VMX
Physical
Virtual
FortiGate
25
CLOUD SECURITY
5.4
FortiGuard
Cloud
Virtual
FortiOS
Cloud
Virtual
FortiAnalyzer
FortiManager
FortiSandbox
FortiWeb
Cloud
Virtual
FortiGate
26
ADVANCED THREAT
PROTECTION FRAMEWORK
5.4
FortiGuard
FortiOS
FortiClient
FortiManager
FortiWeb
FortiAnalyzer
FortiMail
FortiMonitor
FortiSandbox
FortiGate
Virtual
Physical
Cloud
27
FortiSandbox
Bit9
Internet
FortiMail
FortiGateNGFW
ATP Integration
Detailed
Status Report
Signatures,
URL lists
Advanced Threat
Protection Framework
Executive Summary
33 days
Malicious Samples
279
Innocuous Apps
318
Test Runs
597
% Detected
99.6%
% False Positives
1.6%
Certified
Test Period: Q1 2016
Certified Since: 12 / 2015
ATD-FORTINET-2016-0330-01
30
Internet
Satellite Offices
Branch Offices
Customers and
Partners
FireEye
(NX900)
FireEye
(EX8400)
FireEye
(NX2400)
FireEye
(CM9400)
FireEye
(AX5400)
FireEye
(NX4400)
Main Offices
FireEye
(NX10000)
FireEye
(FX8400)
Datacenters
FireEye
(CM9400)
FireEye
(AX5400)
Enterprise-Wide
? Firewalls- $?m
30 Sandboxes- $5.7m
31
Mobile Users
Internet
Next Generation
Firewall
(NGFW)
Customers and
Partners
Branch Offices
Web
Application
Firewalls
Perimeter
Firewalls
Secure Mail
Gateways
Advanced
Threat Protection
(ATP)
NGFW &
ATP (Opt.)
Core Firewalls
Main Offices
NGFW &
ATP (opt.)
Datacenters
Remote
Access
Firewalls
Partner
Access
Firewalls
Authentication,
Management &
Reporting
Enterprise-Wide
4.7M NGFW+ATP
32
SECURE ACCESS
ARCHITECTURE
FortiPresence
FortiAuthenticator
FortiManager
FortiWLM
FortiClient
FortiWiFi
FortiWLC
FortiGate Controller
FortiSwitch (POE)
FortiAP
33
Infrastructure
Infrastructure WLAN solution to provide scale and flexibility
Why Infrastructure?
Mobile: Fit for highly mobile and scalable deployments where low latency and roaming support matter
Channel Flexibility: Channel planning flexibility to shorten site survey and deployment times
Stand-alone: Able to separate access infrastructure purchase decision from security purchase
Security
WLAN Management
Stand-alone Flexibility
Security and access unbundled
Ability to pick and choice best options
34
Integrated
Integrated WLAN solution to provide security and wireless control in one box
Why Integrated?
Central Location
Security
Access
Control
FortiCloud
Remote
Branch Office
Sizing Scalability
From 5 APs to 10K Aps
Management options (bridge, tunnel)
35
FortiGate
NGFW/UTM
WLAN
Controller
Access
Points
Wireless Plane
FortiSwitch
POE
Access
Points
Data
Control
Management
36
Cloud
Cloud WLAN solution to provide simplified management
Why Cloud?
Cloud
Management
Controller-less
37
Agenda
Fortinet Overview
Fortinet EcoSystem Overview
Fortinet Central Management
Fortinet SDN Framework
FortiGuard Threat Intelligence
Questions
38
SaaS-Based Portal
Public Cloud
Physical Networks
Virtualization
VM VM VM VM
VMware
39
FortiMonitor
FortiManager
FortiMoM
FortiCloud
FortiDeploy
Subscription-based provisioning,
management & analytics in the cloud
FortiPrivateCloud
40
43
44
45
FortiManager Features
Traditional
FortiManager
Functions
ADOM &
Notifications
Menu
Traditional
FortiAnalyzer
Functions
46
Total Devices
Device
Connections
Device Config
Changes
Policy
Package
Changes
47
FortiAnalyzer Overview
FortiAnalyzer is an integrated network
logging, analysis, alerting and reporting platform
FortiMail
FortiCarrier
FortiWeb
FortiGate
FortiCache
FortiSandbox
FortiClient
Syslog
48
49
51
52
53
54
What is FortiAnalyzer
Breach Detection?
55
Analytics Logs
DATA & COMPLIANCE POLICY
90 DAYS
SIEM
(Compressed 8:1)
(SQL Insertion)
FortiGates, etc.
Archived Logs
FortiAnalyzer
(Fetch Client)
365 DAYS
56
FortiAnalyzer
FortiDDoS
FortiWeb
FortiMail
FortiMoM
57
FortiMoM Features
Manager of Managers
Central policy editor and objects DB
Domain (ADOMS) Manager ADOM Grouping, Clone, Migrate
Manages multiple products
Services
Objects
Domains
FortiManager 1
FortiManager 2
Policies
FortiAnalyzer 1
FMGR
FAZ
FDOS
FWEB
FMAIL
58
Agenda
Fortinet Overview
Fortinet EcoSystem Overview
Fortinet Advanced Threat Prevention
Fortinet SDN Framework
FortiGuard Threat Intelligence
Questions
59
Data Plane
FortiManager
FortiAnalyzer
Splunk Connector
Mgmt
APIs
Mgmt Plane
SDNS Framework
Platform
Orchestration
& Automation
Network
Data Plane
Function
Virtualization
Control
Plane
On-Demand
Self-Service
Single
Pane-of-Glass
Management
Management
SaaS
Plane
Multi-Tenancy
XML
Platform Extensibility
Virtual
Appliances/
Services
JSON
Other
Interfaces
CLI/
Scripting
Logging/
Event
VNF Support
NFV MANO
Integration
Utility Pricing
AWS & Azure
Marketplace Integration
FortiCloud
FortiPrivateCloud
Cloud/SDN
Ecosystem
SDN
Controllers
Orchestration
Platforms
Programmable
Switches
Cloud
Management
Centralized
Policy &
Analytics
60
ORCHESTRATION PLATFORMS
Platform Extensibility
APIs
PROGRAMMABLE SWITCHING
61
VM
VM
VMware
Elastic provisioning
Distributed
NSX
Object-based policy
Control Plane
Fortinet Service VM
ACI
Benefits
Auto-Scaling
Firewall & Rule
Provisioning
SDN Flow
Visibility (dynamic
flow control,
overlay/
underlay traffic)
Dynamic Policies
(follow logical port,
IP, MAC)
62
2. Auto-deploy FortiGate-VMX to
all hosts in security cluster
vDistributed Switch
VMware Kernel
VMware Kernel
63
FortiGate-VMX
Service Manager
FGT-VMX
2
Packet Flow
NetX NSX Filter Driver
dvSwitch
VMware Kernel
int
ext
1.
2.
3.
4.
Cisco ACI
Spine nodes
APIC
VM
Internal
External
NET-b
NET-a
Leaf nodes
VM
VM
65
66
FortiGate Connector for Cisco ACI enables Fortinet orchestration in APIC console
FortiGate device package contains XML metadata describing Fortinets device and
security services
Admininstrator assigns Fortinet security policies to traffic (Contracts) between
applications (Endpoint Groups)
Use Cases
67
Pipeline Security
FortiGuard security intelligence
Augments partner/open SDN/NFV
architectures
Hypervisor
Hypervisor
68
Agenda
Fortinet Overview
Fortinet EcoSystem Overview
Fortinet Advanced Threat Prevention
Fortinet SDN Framework
Questions
69