Private Cloud Security

Advanced Security for Private Cloud, SDN, and Virtualization Platforms

Key Use Cases and Strategies for Private Cloud
Available in:
web product icon private cloud

Private Cloud Overview

Virtualization and software-defined network (SDN) security are rapidly transforming data centers into agile, innovative, software-defined, and cost-effective private clouds. Yet, security is often an afterthought when it comes to private cloud deployments. Traditional security cannot keep up with these new environments, creating security gaps or manual security processes that negate the benefits of virtualization and SDN firewalls. Private cloud requires a software-defined approach to security due to the lack of visibility posed by east-west traffic and virtualized services.  Private cloud and software-defined data center (SDDC) assets need advanced protection from evolving threats, both known and unknown. 

diagram-private-cloud-security-overview-1.jpg

Secure the virtualized data center and private cloud

Fortinet’s software-defined security solution is certified by leading SDN, virtualization and network function virtualization (NFV) platforms and can be applied to any data center transformed into a cloud environment.  Integration with leading hypervisor and private cloud solutions from VMware, Nutanix, Cisco, OpenStack, Microsoft and more, allows automated insertion and orchestration of private cloud security throughout software defined data centers as well as rich API extensibility. Fortinet Fabric Connectors provide open, API-based integration and orchestration with multiple SDN and private cloud platforms, enabling security automation and simplified management.

Fortinet’s Private Cloud Security strategy is defined by three key pillars - Native integration of security capabilities to each private cloud platform by abstracting the cloud specific intricacies; Broad protection of applications across all private cloud platforms by offering the broad set of security products and Single pane of glass management via unified management of policy, events and analytics across physical, virtual and cloud infrastructure to eliminate security and compliance gaps

The FortiGate-VM Series is a virtual appliance version of our market-leading, high-performance FortiGate next-generation firewall (NGFW) that delivers advanced protection for north-south and east-west traffic in virtualized data centers and private cloud.  

As an innovator and leader in data center security, Fortinet offers the largest range of virtual appliances that provide in-depth visibility and control of virtual network traffic with scalability, performance, and value. Virtual appliances also deliver elasticity, automation, and orchestration for comprehensive private cloud security, SDN security, and VM security.  

 

Telco Cloud/Mobile Security/NFV

For virtualized service provider infrastructures, Fortinet offers a broad range of next generation virtual firewalls virtualized network functions (VNFs). Powered by Fortinet’s Virtual SPU Technology, FortiGate VNFs deliver significant increases in application and carrier security performance through innovative security processing optimizations and the latest packet processing acceleration technologies. The FortiGate NGFW VNFs provide comprehensive network security capabilities; these VNFs have a small footprint, boot within seconds, and require less storage, thereby enabling service providers to protect their virtual networks and cloud platforms cost effectively.  For more info, click here.

 

Private Cloud Security News

Private Cloud Videos

Securing Your Next-Generation Data Center and Cloud with SDN Security
Transforming Network Security with FortiGate VMX
Fortinet Fabric Connector – FortiGate VMX and VMWare NSX

Private Cloud Security Use Cases:

Security in the cloud enables the confidence to safely deploy applications in the software-defined data center and private cloud, improving overall organizational agility and ability to respond to market demand. By leveraging Fortinet Security Fabric solutions to deploy use case driven security capabilities, organizations benefit from market-leading security with streamlined management functionality. Following is a set of common deployment scenarios of Fortinet’s Security Fabric in the private cloud.    

 

Inside Out IaaS Security

North-South Advanced L7 Security Protection

Organizations expanding their networks to accommodate the rapid deployment of data center-based services may often discover a strain on the security architecture’s ability to handle a subsequently growing security threat landscape. Implementing a virtual next-generation firewall with FortiGate-VM in the virtualized data center or private cloud provides extensive visibility and control of the infrastructure. FortiGate-VM automatically provisions and scales security, and has broad support for leading hypervisors, software-defined networks (SDNs) and cloud platforms. It provides advanced Layer 7 protection for north-south traffic in virtualized data centers.  

Download the eBook to learn more about the use cases
Cloud Services Hub

Intent-Based Segmentation: East-West Advanced L7 Security Protection

Microsegmentation is a method of creating secure zones in data centers and cloud deployments that allows companies to isolate workloads from one another and secure them individually. Virtualization and SDN increase east-west traffic in software-defined data centers (SDDC), and poor visibility into traffic between VMs increases risk from security breaches. FortiGate-VM provides microsegmentation and control of east-west traffic in the SDDC, for workload isolation and application-aware security policy. It allows granular policy segmentation and isolation across clustered resources to provide visibility across the entire SDDC infrastructure.  

 

Download the eBook to learn more about the use cases
Remote Access VPN

Form Factor Consolidation

Enterprises can scale out or scale up with Fortinet FortiGate-VM virtual appliance offerings-virtualized versions of physical network security elements that deliver the same capabilities as a physical appliance in a virtual form factor. FortiGate virtual firewalls deliver advanced security capabilities in a virtual form factor and are ideally suited to secure virtualized resources in the data center or private cloud. Fortinet Security Fabric elements are all available packages as virtual appliances on a broad range of hypervisors.

The FortiGate-VMs run the same FortiOS operating system and FortiGuard threat intelligence as hardware models. Multiple VM sizes are available for maximizing throughput and performance.

Download the eBook to learn more about the use cases
Hybrid Cloud

Security Virtual Network Function (VNF)

Service providers need to deliver security services as virtual network functions both on-premises and in cloud. VNF handles specific network functions that run on one or more VMs on top of the hardware-networking infrastructure. Individual VNFs can be connected or combined together as building blocks to offer a full-scale networking communication service. Fortinet’s security VNF is deployed as an uCPE on-premises edge, or vCPE hosted in data center/cloud. FortiGate-VM is a small footprint security VNF with consolidated networking and security. It provides full application layer security with next-generation firewall, Intrusion prevention, AV, web filtering, and embedded Secure SD-WAN. VNF orchestration and service chaining is done via partner orchestrators such as Amdocs, Nuage, OpenStack, and others. 

Security Virtual Network Function (VNF)

Download the eBook to learn more about the use cases
Advanced application protection

Security for the Mobile Core/Telco Cloud

Mobile carriers need to deliver security services as virtual network functions for LTE and 5G mobile infrastructures. Fortinet VNFs provide a rich set of security functions for the virtual mobile infrastructure, particularly: 4G to 5G, edge cloud, cloud RAN, and telecommunications cloud. FortiOS helps secure critical control plane traffic throughout the telecommunications core. Fortinet VNFs for MEC include edge security and control, user-plane inspection, service chaining, and secure gateways.   VNFs support all modern acceleration technologies such as DPDK, SR-IOV, and AES-NI.  

Download the eBook to learn more about the use cases
Security Management from the Cloud

Compliance and Regulatory Requirements

Achieving regulatory compliance with regulation mandates such as PCI DSS, HIPPA, SOX, and GDPR can be a complex and time-consuming burden. Security or governance issues force organizations into using a private cloud. Certain countries require that application data pertaining to people in a particular locale remain within the country. For a broader view of compliance across cloud platforms, FortiSIEM can create compliance reports at the push of a button. FortiAnalyzer provides a closed-loop compliance-gap mitigation and collects fabric logs, while FortiManager enables customers to audit, review, approve, and implement changes from a central place. The benefits are automated compliance auditing and reporting on-premises, in the data center, and in the cloud. 

Download the eBook to learn more about the use cases

   

Fortinet Security Fabric for the Cloud

Fortinet Security Fabric is an architectural approach that unifies the security technologies deployed across the digital network, including multi-cloud, endpoints, email and web applications, and network access points, into a single security system integrated through a combination of open standards and a common operating system.    

FortiGate Virtual Next-generation Firewall Models and Specifications

FortiGate-VM next-generation firewall can be deployed as a virtual appliance in private and public cloud environments, either as a BYOL instance or provisioned on-demand via public cloud marketplaces.

Download the brief - Performance as a key attribute of Virtual Firewalls. 

Throughput
12 Gbps
vCPU
1x vCPU core, (up to) 2 GB RAM
Throughput
12 Gbps
vCPU
1x vCPU core, (up to) 2 GB RAM
Throughput
15 Gbps
vCPU
2x vCPU cores, (up to) 4 GB RAM
Throughput
28 Gbps
vCPU
4x vCPU cores, (up to) 6 GB RAM
Throughput
33 Gbps
vCPU
8x vCPU cores, (up to) 12 GB RAM
Throughput
36 Gbps
vCPU
16x vCPU cores, (up to) 24 GB RAM
Throughput
50 Gbps
vCPU
32x vCPU cores, (up to) 48 GB RAM
vCPU
Unlimited vCPU cores and RAM

“V” Series VMs do not include VDOM licenses by default.  VDOM licenses can be added separately.

Actual performance may vary depending on the network and system configuration. Performance metrics were observed using a DELL R740 (CPU Intel Xeon Platinum 8168 2.7 GHz, Intel X710 network adapters), running FOS v5.6.3. Tested with VMware vSphere 6.5 Enterprise Plus. SR-IOV is enabled.

FortiGate-VMX for VMware NSX delivers automated deployment of advanced security and micro-segmentation in virtualized environments.   FortiGate-VMX secures workloads in dynamic NSX software-defined data centers to enable protection and close compliance gaps.

vCPU Support
1/Unlimited
Memory Support (minimum/maximum)
1 GB/Unlimited
Virtual Domains (Default/Maximum)
10/250
FW throughput with App Control(1)
3.1 Gbps
Threat protection throughput (2)
1.4 Gbps
New sessions per second
30,000
FW throughput with App Control (1)
5.3 Gbps
Threat protection throughput (2)
2.3 Gbps
New sessions per second
30,000
Note: All performance values are “up to” and vary depending on system configuration. Specification is measured on a Dell PowerEdge R630 server, 14 cores Intel(R) Xeon(R) CPU E5-2630v4 @ 2.60 GHz with VMware ESXi 6.0.0. (1). Application Control performance is measured with 64 Kbytes HTTP traffic. (2). Threat Protection performance is measured with IPS and Application Control and Malware protection enabled, based on Enterprise Traffic Mix.

Please see the product page for more information on these and many more Product features.  

 

Virtual Machines

FortiManager virtual machines are all supported on VMware vSphere, Citrix Xen Server, Xen, KVM, and Microsoft Hyper-V.

Devices/VDOMs (maximum)
10
GB/Day of Logs
1
Storage Capacity
100 GB
Devices/VDOMs (maximum)
+10
GB/Day of Logs
2
Storage Capacity
200 GB
Devices/VDOMs (maximum)
+100
GB/Day of Logs
5
Storage Capacity
1 TB
Devices/VDOMs (maximum)
+1,000
GB/Day of Logs
10
Storage Capacity
4 TB
Devices/VDOMs (maximum)
+5,000
GB/Day of Logs
25
Storage Capacity
8 TB
Devices/VDOMs (maximum)
+10,000
GB/Day of Logs
50
Storage Capacity
16 TB

Please see the product page for more information on these and many more Product features.  

 

Virtual Machines

FortiAnalyzer virtual machines are all supported on VMware vSphere, Citrix Xen Server, Xen, KVM, and Microsoft Hyper-V.

Devices/VDOMs (maximum)
10,000
GB/Day of Logs
1
Storage Capacity
500 GB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+1
Storage Capacity
+500 GB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+5
Storage Capacity
+3 TB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+25
Storage Capacity
+10 TB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+100
Storage Capacity
+24 TB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+500
Storage Capacity
+48 TB
Devices/VDOMs (maximum)
10,000
GB/Day of Logs
+2,000
Storage Capacity
+100 TB

FortiGuard Services

FortiGuard Services for FortiGate-VM enable you to implement critical security controls and threat remediation within your virtual infrastructure, providing protection for north-south and east-west virtual traffic. 

FG Application Control

Application Control

Improve security and meet compliance with easy enforcement of your acceptable use policy through unmatched, real-time visibility into the applications your users are running. With FortiGuard Application Control, you can quickly create policies to allow, deny, or restrict access to applications or entire categories of applications.

FG Web Filtering

Web Filtering

Protects your organization by blocking access to malicious, hacked, or inappropriate websites.

Icon cloudsandbox

FortiCloud Sandbox

FortiCloud Sandbox Service is an advanced threat detection solution that performs dynamic analysis to identify previously unknown malware. Actionable intelligence generated by FortiCloud Sandbox is fed back into preventive controls within your network—disarming the threat.

FG Antivirus

Antivirus

FortiGuard Antivirus protects against the latest viruses, spyware, and other content-level threats. It uses industry-leading advanced detection engines to prevent both new and evolving threats from gaining a foothold inside your network and accessing its invaluable content.

security audit service icon

Content Disarm & Reconstruction

Content Disarm & Reconstruction (CDR) strips all active content from files in real-time, creating a flat sanitized file. All active content is treated as suspect and removed. CDR processes all incoming files, deconstructs them, and removes all elements that do not match firewall policies.

FG Intrusion Prevention

Intrusion Prevention

FortiGuard IPS protects against the latest network intrusions by detecting and blocking threats before they reach network devices.

Security Rating Service icon

Security Rating Service

Security Audit Update Service is intended to guide customers to design, implement and continually maintain the target Security Fabric security posture suited for their organization. The Security Fabric is fundamentally built on security best practices and by running these audit checks, security teams will be able to identify critical vulnerabilities and configuration weaknesses in their Security Fabric setup, and implement best practice recommendations.

forticasb service icon

FortiCWP

FortiCWP is a cloud-native Cloud Access Security Broker (CASB) subscription service that is designed to provide visibility, compliance, data security, and threat protection for cloud-based services being used by an organization. With support for major SaaS service providers, FortiCWP provides insights into users, behaviors, and data stored in the cloud with comprehensive reporting tools.

FG AntiBotnet

IP Reputation & Anti-botnet Security

The FortiGuard IP Reputation Service aggregates malicious source IP data from the Fortinet distributed network of threat sensors, CERTs, MITRE, cooperative competitors, and other global sources that collaborate to provide up-to-date threat intelligence about hostile sources. Near real-time intelligence from distributed network gateways combined with world-class research from FortiGuard Labs helps organizations stay safer and proactively block attacks.

FG Mobile Security

Mobile Security

Fortinet’s Mobile Security Service provides effective protection against the latest threats targeting mobile devices. It employs industry-leading advanced detection engines to prevent both new and evolving threats from gaining a foothold inside your network and gaining access to its invaluable information.

Industrial Control systems icon

Industrial Control Systems

The FortiGuard Industrial Security Service continuously updates signatures to identify and police most of the common ICS/SCADA (supervisory control and data acquisition) protocols for granular visibility and control. Additional vulnerability protection is provided for applications and devices from the major ICS manufacturers.

FG AntiSpam

AntiSpam

FortiGuard Antispam provides a comprehensive and multi-layered approach to detect and filter spam processed by organizations. Dual-pass detection technology can dramatically reduce spam volume at the perimeter, giving you unmatched control of email attacks and infections.

 

FortiGuard Service Bundles for FortiGate

Enterprise Protection Bundle
Protection to address today's advanced threat landscape. It delivers all FortiGuard security services available for the FortiGate including: NGFW Application Control and IPS, Web Filtering, FortiCloud Sandbox, Antivirus, Mobile Security, IP Reputation & Antibotnet, Antispam, and core FortiCare security services with a choice of 8x5 or 24x7 support.

UTM Protection Bundle
Traditional UTM security services including NGFW Application Control and IPS, Web Filtering, Antivirus, Antispam, and core FortiCare security services with a choice of 8x5 or 24x7 support

Threat Protection Bundle 
Core protection technologies including: Application Control, IPS, AV, Botnet IP/Domain and Mobile Malware Service. FortiCare security services include 24x7 support. 

Resources

Product Demo

FortiGate-VM is a full-featured FortiGate packaged as a virtual appliance. FortiGate-VM virtual appliance is ideal for monitoring and enforcing virtual traffic on leading virtualization, cloud, and SDN platforms including VMware vSphere, Hyper-V, Xen, KVM, and AWS. FortiGate-VM can be orchestrated in software-defined environments to provide agile and elastic network security services to virtual workloads. Through this demo, you can see how to deploy firewall, intrusion prevention, VPN, antivirus, and other consolidated security functions to virtual workloads, as well as evaluate the easy-to-use web interface and contextual displays.

SDN and Private Cloud Ecosystem