og-casb
og-casb
To ensure the reliable protection of corporate users’ access to SaaS applications, the Fortinet Security
Fabric presents a holistic approach comprising three layers. These layers can function together or
separately and are supported by various products. The first layer involves user authentication and posture
assessment, followed by the second layer of SaaS security policy, and finally, the third layer of Data
Content Scanning. The enforcement of SaaS security takes place through two methods: in-line with FortiOS
devices and at the API level utilizing the FortiCASB cloud security solution. The table below presents an
overview of the capabilities offered by each corresponding Fortinet product.
AUTHENTICATION AND POSTURE SAAS SECURITY, VISIBILITY, AND DATA SECURITY AND CONTENT
FORTINET PRODUCT
ASSESSMENT CONTROL SCANNING (DLP)
FortiClient Yes TCP Forwarding1 In Device / In motion2
Fortinet offers a comprehensive portfolio of security products designed to secure SaaS applications and support work from
anywhere transformation. This ordering guide provides quick reference to different options customers would have and
respective capabilities when they are looking to purchase a CASB solution.
1
ORDERING GUIDE | FortiCASB and FortiGuard CASB Service
PURCHASE OPTIONS
FortiSASE
These customers are entitled to the same capability set as the above, however all the inline capabilities are delivered with
FortiSASE instead of FortiGate and/or FortiProxy. Overall capabilities including FortiClient, FortiSASE, and FortiCASB seats are
based on the number of FortiSASE license seats.
FortiGate or FortiProxy
Customers that only have FortiGate and/or FortiProxy are entitled to Inline CASB capabilities that are part of FortiOS, these
licenses do not entitle usage of FortiClient and FortiCASB enhanced SaaS Security functionality.
FortiCASB
Customers are entitled to use FortiCASB SaaS Security application to monitor SaaS applications at the API level, these
customers are entitled to the number of FortiCASB seats based on the number of ZTNA seats they purchased or where entitled
to from their SASE purchase.
The following table outlines the capabilities available to customers based on product purchase.
CASB DELIVERY
OPTIONS AND
CAPABILITIES FORTIGATE FORTIPROXY UNIVERSAL ZTNA FORTISASE FORTICASB
Inline-CASB Included Add-on required No Included No
(SWG Protection Bundle)
* Would require either a FortiGate-HW, FortiGate-VM, or FortiProxy with SWG bundle to enable Inline-CASB.
2 2
ORDERING GUIDE | FortiCASB and FortiGuard CASB Service
PRODUCT CAPABILITIES
All FortiOS (FortiGate, FortiSASE, FortiProxy) customers have access to CASB features. Following is the mapping of capabilities
by product purchase.
1. FortiGate
All FortiGate models provide support for in-line CASB without any additional license needed. This feature means that in-line
CASB is available when you purchase the FortiGate appliance. All FortiGate hardware models including virtual form factors
(public/private cloud) are supported. The inline CASB feature comes as part of the FortiOS which is the core foundation of
Fortinet devices.
2. FortiProxy
FortiProxy delivers next generation secure web gateway capabilities that protect employees from Internet-borne threats.
FortiProxy is available in two forms, FortiProxy-HW and FortiProxy-VM. Hardware appliances include models such as 400E/G,
2000E/G, and 4000E/G. FortiProxy-HW licenses are paired with user licenses that can range from 500 and up to 50,000 users.
FortiProxy-VM provides support for private and public clouds (AWS, Azure, and GCP). FortiProxy-VM is yearly subscription for
IaaS/private cloud and is also paired with a user license. SWG protection bundle is required to enable inline CASB with FortiProxy
(HW or VM).
ORDER INFORMATION
PRODUCT HARDWARE ACCELERATED SUBSCRIPTIONS
MODEL 400E 400G 2000E 2000G 4000E 4000G
3
ORDERING GUIDE | FortiCASB and FortiGuard CASB Service
FortiClient (ZTNA agent) is an integral part of the ZTNA solution, which can be provisioned on a per-user or per-endpoint basis
and managed from cloud-based console (SaaS) or on-premises depending on corporate requirements. Customers purchasing
ZTNA are entitled to use FortiCASB with the same seat count, furthermore these customers are entitled to the equivalent of
1GB of Data at Rest protection for their SaaS applications per user per year – entitlement is at the customer level multiplying the
number of seats by 1GB per year and are not tied to a specific user. Please see FortiCASB documentation for more details.
ORDER INFORMATION
FORTITRUST USER RANGE SKUS USER QUANTITY ZTNA AGENT MANAGED ZTNA AGENT
100-499 FC2-10-EMS05-509-02-DD FC2-10-EMS05-556-02-DD
4. FortiSASE
FortiSASE is Fortinet’s cloud-based firewall and secure web gateway as a service, delivered as a hosted service; that provides
security driven by FortiGuard labs for remote users regardless of location when accessing the internet, SaaS, or private
applications. FortiSASE licensing is based upon user-range (same as ZTNA); and includes Inline CASB and FortiCASB as part of
the product. No additional licenses are required to enable CASB when you deploy FortiSASE.
ORDER INFORMATION
REMOTE USERS BANDS USER LICENSE
50-499 FC2-10-EMS05-547-02-DD
500-1999 FC3-10-EMS05-547-02-DD
FortiSASE User Subscription
2000-9999 FC4-10-EMS05-547-02-DD
10 000 + FC5-10-EMS05-547-02-DD
4 4
ORDERING GUIDE | FortiCASB and FortiGuard CASB Service
5. FortiCASB
FortiCASB is a Fortinet-developed cloud-native Cloud Access Security Broker (CASB) solution designed to provide visibility,
compliance, data security, and threat protection for cloud-based services employed by an organization. FortiCASB licensing
is based upon user-range. These user SKUs include data security scanning (data amount varies) per year. Additionally, users
purchasing the FortiCASB SKU directly are entitled to the equivalent of 10GB of data protection per user per year. Additional
data protection is available as an add-on. In-line CASB is not available with FortiCASB; you would require purchasing a FortiOS
based solution for In-line CASB functionality.
ORDER INFORMATION
UNIT SKU DESCRIPTION
FortiCASB SaaS Protection FC1-10-FCASB-145-02-DD FortiCASB SaaS Protection 100 User SKU. Includes 1TB of Data Security scanning capacity per year
FC2-10-FCASB-145-02-DD FortiCASB SaaS Protection 500 User SKU. Includes 5TB of Data Security scanning capacity per year
FortiCASB Data Protection FC1-10-FCASB-307-02-DD FortiCASB Data Protection 100GB, add-on subscription license for malware/sensitive data scan/DLP on SaaS
platforms, requires one of FC1-10-FCASB-145-02-DD or FC2-10-FCASB-145-02-DD or FortiClient ZTNA licenses.
FC5-10-FCASB-307-02-DD FortiCASB Data Protection 1 TB, add-on subscription license for malware/sensitive data scan/DLP on SaaS platforms,
requires one of FC1-10-FCASB-145-02-DD or FC2-10-FCASB-145-02-DD or FortiClient ZTNA licenses.
With the FortiGate model to obtain CASB, would one require to purchase any additional license add-on to enable full CASB capabilities?
With the FortiGate model, in-line CASB comes with FortiGate since it is embedded within the FortiOS. To obtain API-CASB, you would have to purchase
FortiCASB license.
What CASB delivery model would provide holistic CASB feature set?
FortiSASE user-based licensing included both in-line CASB as well as API-CASB leveraging FortiCASB.
FortiSASE would be the most comprehensive offering which includes all CASB features.
Is there any difference between CASB offering for the five options listed above?
CASB functionalities can be delivered from multiple models listed, but the features and capabilities would stay the same per model.
Copyright © 2023 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product
or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other
conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser
that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any
such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise
revise this publication without notice, and the most current version of the publication shall be applicable.
FCASB-OG-R02-20231108
STRICTLY CONFIDENTIAL