FortiSASE
Cloud-delivered secure access for a workforce that is not behind your firewall
- Licensing
- Per user, subscription term
- Components
- SWG, CASB, ZTNA, FWaaS, SD-WAN integration
- Policy
- Shared with on-premises FortiGate via FortiManager
FortiSASE delivers secure web gateway, CASB, zero-trust network access and firewall-as-a-service from Fortinet's points of presence, so a user gets the same policy at home, in the office and on hotel WiFi. Policy is shared with your on-premises FortiGates rather than maintained separately.
Where it fits, and where it stops fitting
The case strengthens the more distributed your workforce is. If everyone is in the office every day, a FortiGate at the edge is cheaper and simpler. The moment you are backhauling remote users through a head-end firewall purely so they get inspected, SASE is the better architecture.
Highlights
- One policy set covering office, home and travel
- ZTNA grants access per application, not per network
- CASB visibility over sanctioned and shadow SaaS
- Integrates with existing FortiGate estate rather than replacing it
Typical deployments
- Retiring VPN backhaul for a hybrid workforce
- Giving contractors application-level access without network access
- Consistent web filtering and DLP wherever the user is sitting
What to work out first
FortiSASE delivers the security stack as a cloud service to wherever the user actually is: secure web gateway, CASB, zero-trust network access and firewall-as-a-service, from Fortinet's points of presence rather than from a box in your building.
It is the natural answer once backhauling remote users through a head-end firewall stops making sense, which for most organisations happened when the workforce stopped being in one place. Policy is shared with your on-premises FortiGates, so a user gets the same rules at home, in the office and on hotel WiFi.
It replaces the pattern where remote users get weaker protection than office users purely because of where they are sitting.
Questions worth answering before you order
How many users, and how much of the time are they remote?
Licensing is per user. If everyone is in the office every day, a FortiGate at the edge is cheaper. The more distributed the workforce, the stronger the SASE case.
Do you need ZTNA, or is VPN still fine?
ZTNA grants access per application rather than per network, which removes the lateral movement a VPN allows. For contractors and third parties this is usually the deciding argument.
What is your SaaS exposure?
If sanctioned and unsanctioned SaaS is where the data now lives, the CASB component is the part that earns its money.
Does it need to coexist with FortiGate?
Yes, and it should. Shared policy across on-premises and SASE is the whole point, and it is what distinguishes this from a standalone SASE vendor.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per user, subscription term |
|---|---|
| Components | SWG, CASB, ZTNA, FWaaS, SD-WAN integration |
| Policy | Shared with on-premises FortiGate via FortiManager |
| Deployment | Cloud service, no hardware |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Per user, subscription term |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.