Fortinet FortiAP-S Series Deployment Manual Download Page 3

 

3

DEPLOYMENT GUIDE:

 

Secure Cloud-managed Wireless LAN Solution

Beyond Wi-Fi Security

How important is security beyond WLAN access control? Today’s 
Wi-Fi authentication and encryption standards (WPA2, 802.1X etc.) 
are generally accepted as robust Wi-Fi access control mechanisms. 
Why does anyone need more security than that? Well, the threat 
landscape has moved up the stack, and it is constantly evolving. 
Our growing dependence on the Internet and cloud services, along 
with BYOD has resulted in exponential growth in potential threat 
vectors and targets. 

Threats enter your network through common applications like 
email, web browsers and social networking tools, as well as 
seemingly innocent apps and games on the mobile devices 
belonging to your staff, or customers. Worms and virus on an 
infected mobile device can infect other Wi-Fi attached devices, 
even without either of them accessing the Internet. 

Securing business communications, personal information, financial 
transactions, and the mobile devices of your users, involves 
much more than Wi-Fi access control. It requires scanning for 
malware, preventing access to malicious websites, and controlling 
application usage. But typical Cloud Wi-Fi solutions do not cater 
to these requirements. Fortinet has a novel approach which 
completely addresses this shortcoming in all existing Cloud Wi-Fi 
offerings.

Fortinet Secure Cloud-managed Wi-Fi

Fortinet’s Cloud Wi-Fi solution is unlike any other Cloud Wi-Fi 
offering. Based on the FortiCloud provisioning and management 
service, and a new class of access points the - the FortiAP-S series - it 
offers the same network security capabilities typically found only 
in controller-managed enterprise WLAN solutions combined with 
supplementary security services.

Normally, if you want to apply comprehensive security for all types 
of traffic from access points in remote offices, you need to tunnel 

traffic through centralized security devices on the corporate LAN, 
and often hairpin it back to where it came from. All this adds 
latency and burns the capacity of your network links, forcing 
premature costly upgrades. 

Doing this is not only complicated, it also masks your visibility of 
client and user behavior, as it requires entire VLANs, not unique 
sessions to be mapped from one security appliance to the next, to 
process security in multiple passes through different devices. It is 
highly inefficient.

Distributed enterprises in hospitality, retail and healthcare which 
have large numbers of guests would rather not be tunneling video, 
gaming and other high-bandwidth traffic from their guests through 
the corporate network. But if they want to control application 
usage, such as preventing a guest from watching inappropriate 
content in their coffee shop, or if they want to fully protect devices 
from cyber-threats they’ve had no alternative, until now.

Many vendor’s controller-managed WLAN solutions, including 
Fortinet’s solution, allow split routing at remote offices whereby 
corporate traffic is tunneled over the WAN to undergo security 
processing at the head office or data center, while Internet traffic 
goes directly to the Internet. But this Internet traffic is no longer 
protected by corporate IPS, antivirus, and web filtering appliances. 

Alternatively, all traffic from authenticated corporate users may be 
tunneled through the WAN, while only guest traffic goes directly 
to the Internet. In this case only guest traffic is unprotected and 
uncontrolled. Still, neither approach is ideal.

With the FortiAP-S series all traffic from any type of user can be 
protected and controlled regardless whether it is corporate or 
Internet traffic, without tunneling everything through the corporate 
WAN. Not only is this efficient and cost-effective, it is also the most 
secure and least complex of all options.

Summary of Contents for FortiAP-S Series

Page 1: ...DEPLOYMENT GUIDE FortiAP S Series Deployment Guide Secure Cloud managed Wireless LAN Solution...

Page 2: ...address this growing market enterprise WLAN vendors have ported their management and controllers to the cloud simplifying management and reducing CAPEX With a cloud managed Wi Fi architecture customer...

Page 3: ...curity for all types of traffic from access points in remote offices you need to tunnel traffic through centralized security devices on the corporate LAN and often hairpin it back to where it came fro...

Page 4: ...the network access edge not in the cloud or on the corporate LAN Processing L2 L7 security at the AP in one pass is efficient Plus it allows exceptionally granular user and device policies and preser...

Page 5: ...mited network scalability with all the benefits of centralized management Fig 2 Secure Remote Offices with FortiAP S series FortiCloud simplifies provisioning of access points and other Fortinet secur...

Page 6: ...buted enterprises need to provide secure Internet access for guests and visitors FortiCloud allows businesses to associate any number of SSIDs with a fully customized captive portal and to operate mul...

Page 7: ...ventional thin APs from other WLAN vendors is how they handle real time content and application security Once configured and operational they download the latest threat exploit and application signatu...

Page 8: ...classes When bandwidth is scarce you can ensure mission critical applications prevail while lower priority applications are throttled FortiAP S Series Highlights Zero touch Provisioning When powered o...

Page 9: ...their patrons have an all round pleasant experience on or off the Internet In order to maximize revenue from video entertainment in rooms they can use Web Filtering or Application Control features on...

Page 10: ...eing if not their lives at risk With built in IPS web filtering antivirus protection and application control Fortinet s secure Cloud Wi Fi provides complete protection for medical devices and the smar...

Page 11: ...roviding wireless LAN security for distributed enterprise locations With FortiCloud providing a single dashboard to unify infrastructure and security management businesses can enjoy unlimited scalabil...

Reviews: