What Is SASE? The FortiSASE Approach for Branches and Remote Workers
What is SASE? Secure Access Service Edge is an architecture that merges SD-WAN with a secure web gateway (SWG), CASB, ZTNA and firewall as a service (FWaaS) into a single cloud-delivered service. Branch offices and remote workers are governed by the same policy, and traffic is inspected at the nearest security point of presence instead of being hauled back to headquarters.
What Is SASE and Why Did It Emerge?
SASE (Secure Access Service Edge) is an architectural model that securely connects users, devices and applications wherever they are by consolidating networking and security functions into one cloud-centric service. Gartner coined the term in 2019; the goal is to move a security perimeter designed around the data center to wherever the user actually is.
For years enterprise network security rested on one assumption: users sit in the office, applications live in the data center, and internet breakout happens at the central firewall. Three developments broke that assumption. Applications moved to SaaS, employees left the office, and as branch counts grew, deploying a separate security stack at every location became both expensive and unmanageable. Carrying a remote user's Microsoft 365 traffic to headquarters over VPN and then out to the internet created latency and capacity problems at the same time.
SASE solves this by inverting the perimeter: inspection no longer happens in the organization's data center but at the provider's globally distributed security points of presence (PoPs). A user or branch connects to the nearest PoP, policy is enforced there, and traffic takes the shortest path to its destination. Under Gartner's definition, a SASE platform delivers SD-WAN together with secure access to the web, cloud services and private applications regardless of the user's location, the device used or where the application is hosted.
Threat data explains why the model became urgent. According to the Verizon DBIR 2025, edge devices and VPNs accounted for 22% of vulnerability exploitation actions, roughly eight times the prior year's 3%. Making an internet-facing VPN portal the single door into the corporate network means being exactly what that statistic targets. SASE closes that door and reduces access to identity, device posture and the application level.
SASE Components: SD-WAN, SWG, CASB, ZTNA and FWaaS
SASE components fall into two layers: the network layer is SD-WAN, and the security layer, known as SSE (Security Service Edge), consists of SWG, CASB, ZTNA and FWaaS. For a solution to count as SASE, these functions must be delivered under one policy and one management plane rather than as separate boxes.
The table below summarizes where each component sits, what it does and which problem it typically solves in an SMB or multi-branch organization. We recommend using it as a checklist during evaluation, because some offerings marketed as "SASE" include only a subset of these components.
| Component | Layer | Function | Typical use |
|---|---|---|---|
| SD-WAN | Network | Application-aware routing; combined use of multiple WAN links (fiber, LTE, MPLS) | Reducing MPLS dependency at branches, link redundancy |
| SWG (Secure Web Gateway) | Security (SSE) | Inspection of web and TLS traffic for URL category, reputation and malicious content | Inspecting a remote user's internet breakout without backhauling |
| CASB (Cloud Access Security Broker) | Security (SSE) | Visibility of SaaS usage, data sharing control, shadow IT discovery | Microsoft 365, Google Workspace and unsanctioned cloud apps |
| ZTNA (Zero Trust Network Access) | Security (SSE) | Access at the application level rather than the network, tied to identity and device posture | External access to ERP, file servers and management interfaces |
| FWaaS (Firewall as a Service) | Security (SSE) | Full firewall, IPS and DNS inspection including non-web protocols | Branch internet breakout, server-client traffic |
| DEM (Digital Experience Monitoring) | Operations | Measurement of latency and packet loss from user to application | Root-cause analysis of "the system is slow" complaints |
ZTNA is the most decisive item on this list because it fundamentally changes the remote access model. The user connects to a defined application rather than the network, and identity and device state are re-evaluated on every session. Our guide to ZTNA, which covers the concept and its differences from VPN in detail, is the natural prerequisite reading for this article.
How Does SASE Differ from Classic VPN and a Central Firewall?
The fundamental difference between SASE and the classic model is the traffic path: in the classic model, remote users and branches carry traffic to headquarters for inspection, whereas SASE inspects it at the cloud point closest to the user. The second difference is the unit of access: VPN grants a network segment, while ZTNA inside SASE grants only an application.
In the classic design the firewall sits at headquarters and works well; the problem begins when users and applications move away from the center. A remote worker connects to the VPN, receives an IP address and effectively lands inside a network segment. A branch tunnels to headquarters and uses the central link for internet breakout. The result is that the central appliance and circuit must be sized for SaaS traffic that has nothing to do with headquarters at all.
| Criterion | Classic VPN + central firewall | SASE (SD-WAN + SSE) |
|---|---|---|
| Traffic path | All traffic hauled to headquarters (backhaul) | Internet and SaaS traffic exits at the nearest security PoP |
| Unit of access | Network segment / IP range | Individual application (ZTNA) |
| Device posture | Usually checked only at connection time | Continuously evaluated on every session |
| Attack surface | Internet-facing VPN portal | Published applications and a broker proxy; no portal |
| Lateral movement risk | High once inside the network | Limited by per-application authorization |
| Branch security | Separate UTM stack per branch or backhaul to headquarters | Branch device focuses on networking, inspection in the cloud |
| Capacity growth | Re-sizing central hardware | Subscription based on user count |
| Experience measurement | Separate tooling required | DEM included in the platform |
For Fortinet customers this difference comes with a concrete timeline. Fortinet retired SSL-VPN on some entry-level FortiGate models with FortiOS 7.6; which mode was removed on which model and when should be verified against the release notes. We cover that change and the options for moving to IPsec and ZTNA in our FortiOS 7.6 SSL VPN migration plan. If you intend to keep your existing VPN, the FortiGate VPN configuration guide explains the IPsec option; SASE is the third, longer-term alternative to both paths.
What Is FortiSASE and Which Components Does It Deliver in One Console?
FortiSASE is Fortinet's cloud-delivered, single-vendor SASE service. According to the FortiSASE data sheet, it delivers SWG, ZTNA, CASB, FWaaS, SaaS security posture management (SSPM), a secure browser, secure SD-WAN and digital experience monitoring (DEM) in one console with one agent; the policy engine is FortiOS.
The practical meaning of the single-vendor model is this: the FortiGate at the branch, the FortiClient on the remote device and FortiSASE in the cloud speak the same policy language, use the same FortiGuard threat intelligence and produce logs in the same format. Fortinet's FortiSASE product page states that the service runs on a global network of more than 200 PoPs, while the data sheet uses the phrase "hundreds of security PoPs" without giving a figure. We do not promise a latency figure for Türkiye without a source; instead we take real measurements from your own locations during the pilot.
Technical values highlighted in the data sheet: the web filtering engine classifies hundreds of millions of URLs into more than 90 categories and analyzes TLS 1.3 traffic; application control recognizes more than 8,000 applications including industrial control signatures. The service is SOC 2 Type II certified against the AICPA Trust Services criteria, and Fortinet states that it commits to a latency-backed 99.999% SLA. The last two are the vendor's own statements; the scope and exclusions of the SLA should be read separately at contract stage.
On the analyst side an honest picture is needed. According to Fortinet's own announcements, the company was positioned as a Leader in the 2025 Gartner Magic Quadrant for SASE Platforms and as a Challenger in the 2026 report. FortiSASE is therefore a strong platform but not the undisputed leader of the category; its strongest area is branch modernization that integrates with an existing FortiGate estate. We have gathered the product's components, platform support and limitations with sources on our FortiSASE solution page.
FortiSASE for Branch Offices: Hybrid Architecture with FortiGate
At the branch, FortiSASE does not replace FortiGate; it divides the work. The physical FortiGate handles local segmentation, LAN/WLAN control and SD-WAN routing, while traffic bound for the internet and SaaS is steered to a FortiSASE security PoP and passes through the same inspection as headquarters. Instead of running a heavy UTM license set at every branch, inspection is centralized in the cloud.
This design brings three concrete benefits. First, branch device sizing gets lighter: because SSL inspection, sandboxing and advanced threat protection happen in the cloud, the branch FortiGate focuses on networking. Second, policy becomes unified: the headquarters employee, the branch user and the field team connecting from home are subject to the same web filtering and application control rules. Third, opening a new branch gets faster: the FortiGate connects to the PoP over SD-WAN and policy is pulled from the cloud.
Fortinet documentation calls this scenario "Secure Private Access (SPA) via SD-WAN": the FortiSASE security PoPs behave like spokes of the organization's FortiGate SD-WAN hub, and traffic between PoP and hub is carried over IPsec overlays and BGP. According to the Fortinet Document Library, FortiSASE SPA supports up to 12 FortiGate hubs. Remote users reach internal applications behind the hub through these tunnels, without a VPN portal.
Model choice still matters when selecting branch hardware; even though SASE moves inspection to the cloud, the branch device carries local traffic, the wireless layer and SD-WAN. Our firewall selection guide for SMBs walks through which model fits which office, and the full model family is on our FortiGate solution page. In our projects we prefer this hybrid design for multi-branch retail: the branch device stays small while inspection depth matches headquarters.
FortiSASE for Remote Workers: One Agent, One Policy
In the remote worker scenario, FortiSASE replaces the classic VPN tunnel with identity and network access with application access. FortiClient runs as the single agent on the user's device; internet and SaaS traffic is inspected by SWG and CASB at the nearest PoP, and access to internal applications is granted at the application level through ZTNA.
The architecture has three parts: the FortiClient agent, the cloud-hosted FortiSASE Endpoint Management Service and the ZTNA access proxy. According to the Fortinet Document Library, FortiSASE applies ZTNA tagging rules to FortiClient; when an access request arrives, the proxy grants or denies it based on the client certificate and those tags. The organization can apply the same ZTNA model without operating its own EMS server. If FortiClient EMS is already running on premises, how the two management planes will coexist should be the project's first design decision.
The value of the single-agent approach is the disappearance of the three or four security agents stacked on laptops. According to the FortiSASE data sheet, FortiClient combines endpoint protection, ZTNA, SSE, CASB, DEM, sandbox, vulnerability management and USB device control in one client. One licensing detail deserves attention: according to the FortiClient data sheet, under the user-based FortiTrust license a single user can install the agent on at most three devices. For mobile teams using a laptop, phone and tablet, that limit directly affects the user count. We list the agent's platform support on our FortiClient page.
On the experience side, the DEM component replaces "the VPN is slow" complaints with measurable data: latency and loss from user to PoP and from PoP to application are visible separately. In our field experience this visibility shortens the "is it the network or the application" debate on which support teams spend the most time in remote access projects.
Who Is SASE Right For, and Who Is It Not?
Organizations that suit SASE are those where a significant share of employees connect from outside the office, that operate multiple branches and whose business applications have largely moved to SaaS. For a single-site SMB whose applications live on a local server and whose remote access is limited, a well-configured FortiGate with IPsec VPN is usually sufficient.
The decision is less a product comparison than a profile match. The checklist below summarizes the questions we ask in discovery meetings on our projects; organizations that lean toward the right-hand column should prioritize SASE, while for those in the middle column strengthening the current model is usually the more economical path.
| Criterion | Current model may be sufficient | Points toward SASE |
|---|---|---|
| Share of remote users | A small fraction of staff, occasionally | Permanently hybrid or fully remote teams |
| Number of branches | Single site or 2–3 branches | Multi-branch, frequent openings and closures |
| Application location | Mostly on local servers | Mostly Microsoft 365 and other SaaS |
| Remote access estate | IPsec VPN, current FortiOS, adequate capacity | SSL-VPN dependency, capacity limits, release-schedule pressure |
| Third-party access | Rare, limited | Contractors, consultants, BYOD on a continuous basis |
| Compliance requirements | Basic KVKK measures | Audits demanding per-user access logs and SaaS data visibility |
| IT team | Can manage branch devices one by one | Needs central policy and a single console |
A note on compliance: the Turkish Personal Data Protection Authority's Personal Data Security Guide (Technical and Administrative Measures) lists firewalls and gateways as the first line of defense against unauthorized access from the internet and includes logging of user activity among technical measures. In a remote workforce the "gateway" is no longer the device at headquarters but the SASE PoP the user connects to; consolidating the log stream in one place through FortiAnalyzer integration simplifies the audit file. We recommend verifying current legislation and the official guide.
FortiSASE Migration Plan and Sizing
Migrating to FortiSASE starts with two questions: how many users, and which traffic will pass through SASE. The user count determines subscription volume, and the traffic scope determines policy design. In practice most organizations do not move everything to the cloud on day one; a staged plan lowers both risk and the chance of disruption.
| Stage | Scope | Deliverable |
|---|---|---|
| 1. Inventory and discovery | User groups, device fleet, internal applications to publish, current VPN usage | Application-to-user access matrix |
| 2. Tenant and identity | FortiSASE tenant, identity provider federation, group mapping, region selection | Employee sign-in flow |
| 3. Pilot (SWG) | Inspecting internet breakout for a limited user group, latency measurement | Performance report with real measurements |
| 4. ZTNA publishing | Publishing the 3–5 highest-priority internal applications via ZTNA, device posture rules | VPN-free application access |
| 5. CASB and SSPM | SaaS visibility, data sharing rules, configuration posture checks | Shadow IT inventory and remediation list |
| 6. Branch integration | Steering FortiGates to the PoP, SD-WAN policies | One policy for branch and remote user |
| 7. VPN retirement | Shutting down remaining VPN usage, handover of logging and reporting | Reduced attack surface |
The variables that determine cost are user count, subscription term, the component set chosen (SSE only, or together with SD-WAN), log retention options and overlap with FortiGate licenses on the branch side. We do not quote figures on this page; the most frequently overlooked issue is avoiding buying the same capability twice across existing FortiClient EMS, FortiGate UTM subscriptions and FortiSASE. If you share your inventory and renewal dates, we identify the overlaps and propose a design containing only the components you need. For tenant setup, identity integration and automation, our DevOps and infrastructure team works within the same project.
Frequently Asked Questions
What is the difference between SASE and SSE?
SSE (Security Service Edge) is only the security layer of SASE: SWG, CASB, ZTNA and FWaaS. SASE adds the SD-WAN network layer to SSE. An organization without branches that only wants to protect remote users can start with SSE; multi-branch structures need full SASE including SD-WAN.
Do I need to remove the branch FortiGate for FortiSASE?
No. In the hybrid architecture we recommend, the FortiGate stays at the branch and handles local segmentation, LAN/WLAN control and SD-WAN routing. Internet and SaaS traffic is steered to the FortiSASE PoP. Branch device sizing gets lighter, but a device is still required for local network functions.
Which agent does FortiSASE use, and how many devices per user are supported?
The single agent is FortiClient; ZTNA, SWG, CASB and DEM functions are consolidated in the same client. According to the FortiClient data sheet, under the user-based FortiTrust license one user can install the agent on at most three devices. Calculate devices per user accordingly when sizing.
Does moving to SASE eliminate VPN completely?
That is the goal, but the migration is staged. Internet breakout is inspected by SWG first, then priority internal applications are published via ZTNA; VPN remains only for exceptions that cannot be published through ZTNA and is shut down in the final stage. The removal of SSL-VPN on some models with FortiOS 7.6 accelerates that timeline.
Where does FortiSASE inspect traffic, and is there added latency?
Traffic is inspected at the Fortinet security PoP closest to the user. Fortinet's product page mentions more than 200 PoPs; latency measured from Türkiye varies by location. That is why we take real measurements from your own users during the pilot and report them with DEM data.
Is SASE too much for an SMB?
For a single-site SMB whose applications sit on a local server, a well-configured FortiGate with IPsec VPN is usually enough. For SMBs with a high share of remote workers, multiple branches or a Microsoft 365-centric workload, SASE offers a more manageable path than building a UTM stack at every branch.
What determines the price of FortiSASE?
User count, subscription term, component set, log retention options and overlap with existing Fortinet licenses are the determining factors. Because the amount changes with configuration we do not give a fixed figure; we prepare a configured quote based on your user count and location distribution.
Conclusion
SASE is an architecture that moves the security perimeter from the data center to wherever the user is; it unifies SD-WAN with SWG, CASB, ZTNA and FWaaS under one policy. FortiSASE applies this model within the Fortinet ecosystem: it works in a hybrid design with FortiGate at the branch, uses FortiClient as the single agent on remote devices and performs inspection at the nearest PoP. The right question is not "SASE or FortiGate" but "which traffic should be inspected where"; the answer depends on your user distribution, branch count and SaaS dependency.
At Sora Yazılım we are your independent project and procurement partner for Fortinet solutions; we run needs analysis, licensing, tenant setup, ZTNA application publishing, migration from the existing VPN and post-deployment managed services within a single project. Sharing your user count, location distribution and the internal applications you want to publish is enough; you can schedule a free discovery call on our contact page and request a quote configured for your project.
