You are on page 1of 7

SECURE WIRELESS LAN

Complete Wi-Fi Security for Any Network Topology

SOLUTION GUIDE
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

OVERVIEW
The simple requirement of any access layer, markets fall short on another dimension. SECURE WIRELESS LANS
be it wired or wireless, is to allow simple They lack the comprehensive security found
You can enjoy the industry’s most
and secure client access. This can be a in corporate networks, which leaves cloud-
comprehensive wireless security,
challenge, but Fortinet has a wide range managed Wi-Fi users exposed to a growing
regardless of the size of your business,
of solutions. The Fortinet Secure WLAN number of cyber threats.
your network topology, and your choice
portfolio comprises three separate Wi-Fi
In contrast, the Fortinet Secure WLAN of integrated or cloud-based Wi-Fi
product lines. This document deals with
portfolio meets the needs of these different management.
the two security-focused product lines, the
market segments without sacrificing
Integrated solution, where APs are part of
comprehensive security, no matter which
the fabric controlled by the FortiGate, and
deployment model is selected.
the Cloud solution, where the FortiGuard
security can be deployed at the edge of the distributed enterprises because managing
network. Fortinet’s more traditional controller them is too complex and costly. Yet,
solution can of course be secured with the established cloud-managed Wi-Fi offerings
addition of a FortiGate, but this is more targeted at these underserved markets fall
akin to the rest of the industry as separate short on another dimension. They lack the
solutions working together. The purpose comprehensive security found in corporate
of this document is to focus on the full networks, which leaves cloud-managed
integrated solution where UTM is built into Wi-Fi users exposed to a growing number
the solution from the ground up. Solutions of cyber threats.
in this document are designed to meet the In contrast, the Fortinet Secure WLAN
needs of different market segments with portfolio meets the needs of these different CLOUD MANAGEMENT VS.
complete focus on comprehensive security, market segments without sacrificing
SECURITY TRADEOFFS
no matter which topology and network comprehensive security, no matter which Since the first Wi-Fi security crisis in 2005,
management model is best suited to the deployment model is selected. when a team at the FBI demonstrated how
business. WEP security could be cracked in less
COMMODITIZATION OF WI-FI than three minutes, wireless security has
INTRODUCTION SPEEDS AND FEEDS remained a top-ranking CIO concern. It
With 6.5 million Wi-Fi certified devices Throughout its evolution, Wi-Fi has faced began with requirements to let visitors and
shipping every day, Wi-Fi has become numerous deployment challenges, which guests access the Internet while on your
the network of choice in every type of have driven vendor innovation and new premises. Now with BYOD the accepted
business large and small, public venues, standards. New standards have largely norm, the need for complete mobile security
and hundreds of millions of homes. Wi-Fi taken care of the performance limitations: has never been more acute.
has become ubiquitous, from home and 802.11n, and MIMO, channel bonding, It’s generally accepted that WPA2 Enterprise
workplace to coffee shop and on aircraft, 802.11ac, MU-MIMO and these continue using 802.1X is a secure way for users to
Wi-Fi can keep you connected. to evolve. Standards also solved roaming, access a Wi-Fi network. But as the device
The days of one-size-fits-all enterprise QoS, device power drain, and many more landscape shifts from corporate-owned to
Wi-Fi are over. The wide range of different issues. Vendor innovation took care of employee-owned, and as network usage
use cases, deployment models, security the rest, including band steering, AP load shifts to an ever-greater reliance on cloud
requirements, and budgets dictate that balancing, and bandwidth management, to services, the security challenge has also
vendors deliver different Wi-Fi solutions name a few. morphed. Access control is no longer the
for different markets and deployment As is the way with technology, speeds and problem. The vulnerability is now your
topologies. Some vendors have been slower feeds and performance-enhancing features applications, content, and devices, which
to adapt than others. quickly get commoditized. Soon everyone are continually exposed to cyber threats via
has them. Management and security, the Internet.
Controller-managed WLAN solutions
designed for large enterprise are a poor however, remain perennial concerns that are Wireless security must go far beyond Wi-Fi
fit for SMBs and distributed enterprises very much in the limelight today. And unlike access control of the past. In addition to
because managing them is too complex and the speeds and feeds, vast differences exist facilitating BYOD, it must secure sessions,
costly. Yet, established cloud-managed Wi- between vendors. prevent users from visiting inappropriate
Fi offerings targeted at these underserved websites, ensure the integrity of connected

2
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

devices, and more. Large enterprises handle preventing access to malicious websites, solutions don’t cater to these requirements.
these complex security requirements in a endpoint integrity, checking and controlling Fortinet has a novel approach that
variety of ways, with centralized firewalls, application usage. But typical cloud Wi-Fi completely addresses this shortcoming in all
intrusion prevention systems (IPS), web- existing cloud Wi-Fi offerings.
filtering and antivirus appliances, and so on,
Integrated Cloud Managed
and by tunneling branch office traffic though Many APs per site Few APs per site
the corporate network. Enterprise Campus / HQ FortiGate + FortiAPs
Not so for education and distributed Large Branch FortiGate + FortiAPs FortiAP-S
enterprises such as retail chains, health FortiAPs tunneled or
Small Branch FortiAP-S
clinics, hospitality, and transportation FortiWiFi [+FortiAPs]

providers. They don’t have the Small Business FortiWiFi [+FortiAPs] FortiAP-S

infrastructure, IT resources, or the networks FIGURE 1: FORTINET’S WI-FI SOLUTIONS FOR DIFFERENT REQUIREMENTS
to emulate the large enterprise hub-and-
spoke security model. No wonder they have ENTERPRISE CLOUD WI-FI network topologies are better suited than
been slow to adopt enterprise-grade Wi-Fi, MIGRATION FEARS others for migration to cloud-managed Wi-Fi.
unless it is managed by a service provider, However, for the majority of hub-and-spoke
Certain hypersensitive verticals (federal,
and they have sometimes had to make do deployments and large enterprise campuses,
financial, etc.) simply don’t want any
with consumer-grade products. there is more to lose than there is to gain
traffic to leave their network, not even AP
because security enforcement beyond
This dichotomy has given rise to cloud- management traffic, for fear of possible
basic authentication becomes all the more
managed Wi-Fi and cloud Wi-Fi vendors security breaches. But in general, large
complicated. For distributed, enterprises
focused on these underserved markets, enterprises have been reluctant to move
cloud-managed Wi-Fi can make sense,
and it has created a flourishing market for to cloud-managed Wi-Fi solutions. There
provided the equivalent security found in
managed security service providers. But are several reasons for this. The first is the
corporate networks can be replicated.
as vendors have shifted their focus from per-AP subscription fees typical of cloud
controller-managed to cloud-managed Wi- Wi-Fi offerings. For a large network, these
recurring fees can, within a few years,
GAPS IN TYPICAL CLOUD WI-FI
Fi, they’ve taken one step forward and two SECURITY
steps back. Security above Layer 2 is more eclipse the cost of local management
about reporting than actual control and servers and the staff to run them. Second, All cloud Wi-Fi vendors’ solutions claim to
focuses on the known and easily recognized they already have a substantial investment be secure. And they are, up to a point. If the
applications rather than any real threat. in controller and management infrastructure. scope of your security is limited to access
Third, while it may no longer be true, control or wireless intrusion detection, this
FORTINET WI-FI SECURITY there is a general perception that cloud is an easy checkbox to fill. However, on a
WITHOUT COMPROMISES management provides less control and broader scope there are significant gaps. No
more limited reporting. other vendor matches the comprehensive
Fortinet WLANs are different. Security is at
security available with Fortinet’s integrated
the core of these Wi-Fi offerings. Fortinet But above all, the biggest barrier is the
or cloud-managed Wi-Fi solutions. The
Secure Wireless LAN solutions are designed disruption to the security framework that
comparison table below illustrates the voids
to provide the same award-winning and moving to the cloud would entail. Some
found in typical cloud Wi-Fi offerings.
third-party-validated security in every type
of deployment, from a stand-alone AP in an Typical Cloud Wi-Fi Fortinet Cloud Wi-Fi
isolated office to a handful of APs in a retail Configuration Management
store to hundreds of APs deployed across a Bandwidth & Traffic Analysis
large enterprise campus. Our Wi-Fi product Connected Client Analysis
families enable any business to choose Guest Access Management
the topology and network management
Access Control - WPA2, 802.1X
that best suits them, without having to
WIDS & Rogue AP Detection
compromise on security protection.
Network IPS
Securing business communications, Web Filtering
personal information, financial transactions, Antivirus
and the mobile devices of your users Application Contol
involves much more than Wi-Fi access Private Cloud for MSPs
control. It requires scanning for malware,
FIGURE 2: COMPARISON OF FORTINET VS. TYPICAL CLOUD WI-FI

3
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

FORTINET SECURE WLAN


SOLUTION PORTFOLIO
Fortinet has different Wi-Fi hardware
platforms optimized for different use cases.
The same security protection is available
across these product families, which
allows businesses to choose the topology
and management model that suits them
best, without giving up important security
capabilities.

FortiAP-S SERIES
The FortiAP-S Series is a family of single-
and dual-radio 802.11ac access points
designed for deployment in SMBs and
distributed enterprise sites. They contain
advanced security functions embedded
in the AP hardware. Equipped with extra
memory and twice the processing power of
typical thin APs, they can perform real-time
security processing at the network edge,
not in the cloud or on the corporate LAN.
FIGURE 3: DISTRIBUTED OFFICES USING FORTIAP-S SERIES
By implementing IPS, application controls,
web filtering, and malware protection on Configuration management and reporting applications and it adds latency, not to
the AP hardware itself, precious network is provided by FortiCloud. The FortiCloud mention the cost of needing bigger pipes.
bandwidth is conserved, and infected provisioning and management portal No one wants to backhaul a guest’s high-
devices and applications are stopped in their provides comprehensive details on per-user bandwidth videos and Facebook traffic
tracks. SMBs and distributed enterprises and device application usage, bandwidth, through the corporate network, only to be
get the simplicity of cloud management and traffic analysis, plus all the management able to provide application-level security in
through FortiCloud and the protection of tools needed for adds, moves and changes, the remote site. But until now, enterprises
enterprise-class security without needing the user management including BYOD have not have much choice. The alternative
collection of expensive security appliances onboarding, and guest access captive portal is to directly connect each site to the Internet
normally required in large enterprise network management. What’s more, FortiCloud which leaves these sites with limited control
deployments. offers a free tier, which allows basic of application usage and leaves them
The APs receive regular exploit, malware, and management and reporting for no cost. An exposed to all manner of cyber threats.
application signature updates from Fortinet’s enterprise license adds advanced features The FortiAP-S Series overcomes this
award-winning FortiGuard security service, and a FortiGuard subscription, along with a deficiency, allowing distributed enterprise
providing immediate protection against full year of log information. sites to connect to the Internet directly,
newly discovered virus and malware threats. without sacrificing security. Corporate users
And with over 3,300 application signatures, COMPLETE SECURITY AT THE
can still be authenticated against corporate
versus a few hundred at best from the NETWORK EDGE
RADIUS servers over the WAN if desired, or
nearest rival, FortiAP-S Series APs have Because of the sheer volume of Internet via FortiCloud, while all traffic from employees
the granularity to enforce laser-precision traffic, some enterprises prefer to avoid or guests is protected by enterprise-class
prioritization and bandwidth management tunneling Internet traffic from branches Layer 7 security directly at the AP, without
far superior to crude WMM priority classes. through the corporate network. This squandering WAN bandwidth.
Together, this means corporate content and is especially true when the number of
The FortiAP-S Series allows distributed
application policies can now extend beyond locations is large or when guest traffic
enterprises to benefit from superior security
the corporate network to any size location, predominates, as it does in hospitality, retail,
at all remote sites, without altering their
without backhauling all traffic over the and restaurants. Tunneling traffic through
existing security infrastructure at corporate
corporate WAN. the corporate WAN is inefficient for cloud
or backhauling traffic through the corporate

4
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

network, and without needing anything since 2009, FortiGate enforces the most enterprises, hospitals and schools scalability
more than FortiAP-S Series APs at these stringent access control and enables for thousands of APs and tens of thousands
locations. effortless BYOD onboarding. Complete of clients, without the complexity of adding
PCI-DSS and HIPAA compliance is an assortment of point security products in
FortiAP SERIES assured, along with the industry’s order to provide complete threat protection.
The FortiAP Series is a family of integrated most comprehensive protection for all Branch offices equipped with FortiAPs can
access points that function in cooperation manner of wireless and Internet threats. tunnel their traffic back to the corporate
with a FortiGate Wi-Fi Integrated Controller. Enterprises can centrally administer security network over the Internet, and they don’t
The FortiGate is much more than just a policies through a “single-pane-of-glass” need a local controller. Thus, centralized
Wi-Fi controller. It combines comprehensive management interface. Like other Fortinet security policies are extended enterprisewide,
network security and WLAN control by security products, FortiGate is Secured by with no fear of overloading the centralized
consolidating all the functions of Firewall, FortiGuard and receives regular signature controller. Independent tests show FortiGate
IPS, Anti-malware, VPN, WAN Optimization, updates, ensuring immediate protection is the world’s fastest Wi-Fi controller, capable
Web Filtering, and Application Control in a from zero-day cyber threats. of over 100 Gbps WLAN throughput—almost
single platform. The combination of FortiGate security twice the performance of Cisco’s and Aruba’s
Recognized as a leader in Gartner’s Magic and coordinated FortiAPs gives large flagship WLAN controllers.
Quadrant for Unified Threat Management

FIGURE 4: LARGE AND SMALL BRANCH OFFICES USING FORTIAP

5
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

FORTIWIFI SERIES corporate network, FortiWiFi appliances to 3,000 square feet, making it an ideal one-
provide complete threat protection locally in box solution for small locations including
The FortiWiFi Series are compact, stand-
branch offices, while inheriting centralized retail establishments, clinics, and assisted
alone appliances that combine, in one
corporate security policies. living facilities. In larger sites, wireless
platform, a full-featured wireless access
coverage and capacity can be expanded
point, a LAN switch, and an entry-level Corporate traffic can be routed or bridged
with up to 32 additional FortiAP access
FortiGate equipped with WAN features and to the corporate network, while Internet
points, enabling support for hundreds of
all the same security and WLAN functionality traffic is bridged locally, fully protected by
mobile devices.
as its bigger brothers. the FortiWiFi appliance implementing the
same or different security policies as those Equipped with world-class unified threat
Ideal for branch offices and small
at corporate. management and WAN connectivity,
businesses, a single FortiWiFi appliance
FortiWiFi makes an ideal entry-level Wi-Fi
provides everything from wired and With up to 3.5 Gbps firewall throughput,
solution for managed service providers
wireless access, BOYD onboarding, and FortiWiFi appliances have the capacity
targeting SMBs. With one device they
guest portal to unified threat management to handle security for wired and wireless
can cover network access and security
and WAN connectivity. It even supports clients without becoming a performance
requirements in one fell swoop, and they
backup broadband access over a 3G/4G/ bottleneck. A single FortiWiFi appliance
can easily extend Wi-Fi coverage with
LTE network. Remotely managed from the provides wireless coverage for locations up
FortiAPs as needed.

FIGURE 5: SMALL OFFICE USING FORTIWIFI

6
SOLUTION GUIDE: COMPLETE WI-FI SECURITY FOR ANY NETWORK TOPOLOGY

FortiCLOUD PROVISIONING AND SAME SECURITY ON ALL Fi solutions must sacrifice the additional
MANAGEMENT SERVICE WIRELESS PLATFORMS security measures often found in controller-
managed deployments.
FortiCloud offers a free, cloud-based To provide the same level of security as
provisioning, configuration management, Fortinet, all competing WLAN vendors In contrast, the Fortinet Secure WLAN
and analytics service for FortiGate, FortiWiFi, need a variety of different supplementary portfolio offers the same comprehensive
FortiAP, and FortiAP-S Series product lines. security products, depending on the WLAN security across all its Wi-Fi platforms, whether
It lets you quickly get up and running with solution architecture deployed. This adds integrated or cloud-managed. This makes
Fortinet products and maintain centralized to the operational complexity and TCO of it easy for businesses to mix and match
control and visibility of your network, all from their solutions. Lacking integrated security deployment models for different use cases,
the cloud, avoiding the cost of centralized of their own, their cloud-managed Wi- without giving up critical security protection.
management gear. FortiCloud eases
provisioning of wireless and security devices FortiAP FortiAP-S
FortiWiFi
with FortiGate with FortiCloud
at remote sites where on-site configuration
WPA2, 802.1X, Captive Portal √ √ √
expertise is unavailable.
WIDS √ √ √
FortiWiFi, FortiAP, FortiAP-S Series and Rogue AP Detection √ √ √
FortiGate all include FortiCloud registration
Network IPS √ √ √
functionality in their firmware, enabling zero-
WAN / VPN √ √
touch provisioning with minimal on-premise
Web Filtering √ √ √
expertise. From Rogue AP detection to
Antivirus √ √ √
guest access management to custom
Application Control √ √ √
reporting, FortiCloud gives you everything
you need to manage the complete Wi- FIGURE 6: COMPARISON OF FORTINET WIRELESS PLATFORMS
Fi security environment at all enterprise
locations and maintain full visibility of
PRESENCE ANALYTICS cloud, empowering retailers with the ability
SOLUTION to instantly measure consumer footfall,
wireless health and the quality of experience
connect to customers through social Wi-Fi,
for clients. FortiCloud also can be upgraded Among the distributed enterprises most
and influence them directly while they are in
to a multi-tenant solution, which allows interested in deploying secure cloud
the store.
MSPs to offer a managed service with no Wi-Fi are retailers. Retail industry leaders
significant investment. recognize that Wi-Fi is about more than
guest access these days. Naturally they
COMPLETE WI-FI SECURITY, NO
COMPROMISES
FortiPORTAL FOR MSPS want PCI compliance and stringent security,
with the full benefit of fast Wi-Fi for their As a global leader in network security,
MSPs can manage their clients’ wireless,
guests. But they also need value-added Fortinet provides complete and
WAN, and security remotely through
security and analytics services such as comprehensive security for wired and
FortiPortal. FortiPortal is a feature-rich VM
social Wi-Fi, web filtering, and presence wireless users, no matter how large or small
software platform designed specifically
analytics. your business, on the network deployment
for MSPs, which enables them to deploy
model you prefer. Campus, large office,
managed services on their own hosted Complementing the industry’s most
branch office, corner shop…controller-
services infrastructure. Designed with multi- secure wireless portfolio, Fortinet’s
managed, cloud-managed, service provider
tier, multi-tenant capabilities, it allows MSPs Presence Analytics solution gives retailers
managed…tunneled traffic, bridged traffic,
to manage all their customers’ networks much-needed consumer intelligence by
both…The Fortinet Secure Wireless
through one console, while also providing combining presence information and big
LAN solution portfolio delivers the same
management access to their customers, data. FortiPresence gathers presence
enterprise-class security in every scenario,
allowing different privileges for different users. data from access points distributed in a
without compromises.
store and processes it in real time in the

www.fortinet.com

Copyright © 2017 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law
trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other
results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied,
except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in
such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal
lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most
current version of the publication shall be applicable. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this
publication without notice, and the most current version of the publication shall be applicable. Feb 10, 2017

You might also like