1.7 FortiGate CNF, FortiGate VM in Public Cloud & FortiSASE Administration

Key Takeaways

  • FortiGate-VM is the virtual-appliance form factor running the same FortiOS as hardware appliances, deployed across public clouds (AWS, Azure, GCP, OCI, IBM, Alibaba) and private hypervisors with PAYG, BYOL, s-series, or FortiFlex licensing.
  • FortiGate CNF is a SaaS-delivered cloud-native firewall service for AWS VPCs and Azure VNets where Fortinet manages the infrastructure, scaling, and patching; a single instance can protect multiple AWS accounts or Azure subscriptions in a region with one unified policy.
  • Choose FortiGate-VM for tailored network design and full FortiOS features (NAT, IPsec/SSL VPN, SD-WAN); choose FortiGate CNF for minimal integration effort and automated, Fortinet-operated protection.
  • FortiSASE is Fortinet's cloud-delivered SASE service combining ZTNA, SWG, CASB, FWaaS, and SD-WAN, administered from a cloud management portal rather than the on-box FortiOS CLI/GUI.
  • FortiSASE user onboarding supports local users, SAML SSO (Entra ID, Okta, FortiAuthenticator as IdP with FortiSASE as SP), SCIM server provisioning for automated lifecycle management, and authenticated endpoint onboarding via invitation codes.
Last updated: July 2026

FortiGate CNF, FortiGate VM in Public Cloud & FortiSASE Administration

The FCP_FGT_AD-7.6 blueprint extends the Deployment and System Configuration domain beyond on-box hardware administration. Candidates must be able to describe FortiGate CNF and FortiGate VM in public cloud and explain FortiSASE administration and user onboarding methods. These objectives test conceptual fluency with the Fortinet cloud portfolio — what each delivery model is, when to choose it, and how users are provisioned — rather than deep CLI configuration.


FortiGate-VM: The Virtual Appliance Form Factor

FortiGate-VM is the virtual-machine form factor of FortiGate, running the same FortiOS firmware as the hardware appliances. It is intended for private and public cloud environments where you want full control over network design and the complete FortiGate feature set — NAT, IPsec and SSL VPN, SD-WAN, and Security Fabric integration.

Supported platforms:

  • Public clouds: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), IBM Cloud, and Alibaba Cloud.
  • Private clouds / hypervisors: VMware vSphere/NSX-T, OpenStack/KVM, Microsoft Hyper-V, Nutanix, and Citrix Xen.

Licensing options:

  • PAYG (Pay-As-You-Go): per-hour pricing based on vCPU count, purchased through the cloud marketplace and billed monthly.
  • BYOL (Bring Your Own License): apply an existing FortiGate-VM license to a marketplace-deployed VM.
  • FortiGate-VM s-series: term-based subscription.
  • FortiFlex: points-based consumption model (12, 36, or 60 months) for enterprises and managed security service providers (MSSPs).

A 30-day free trial is available on the AWS, Azure, and Google Cloud marketplaces. FortiGate-VM integrates with cloud transit fabrics such as Azure vWAN, AWS Cloud WAN, and Google Cloud Interconnect to enforce consistent security policy across hybrid and multi-cloud transit paths, and it supports FGCP HA in cloud-adapted topologies.


FortiGate CNF: Cloud-Native Firewall as a Service

FortiGate CNF (Cloud-Native Firewall) is a SaaS-delivered next-generation firewall service that secures AWS VPCs and Azure VNets without requiring you to deploy, patch, or maintain any firewall infrastructure. Fortinet manages the underlying infrastructure, scaling, and patching; your security team focuses only on policy.

Key characteristics:

  • Available for AWS and Azure, purchased through the AWS and Azure marketplaces.
  • You select the cloud networks and resources to protect, attach them to a CNF instance, and define the security policy — CNF handles the rest.
  • A single CNF instance can protect multiple AWS accounts, Azure subscriptions, and networks within a region with a unified policy, eliminating per-VPC firewalls.
  • Pricing dimensions: CNF instance plus support hours (per hour), traffic processing (firewall engine), and security processing (IPS, URL/DNS filtering, sandbox) charged per-GB.
  • Procurement options: PAYG, cost-optimized PAYG, private offer, and BYOL.

FortiGate-VM vs. FortiGate CNF — when to choose which

DimensionFortiGate-VMFortiGate CNF
FormVirtual appliance you operateSaaS service Fortinet operates
Best forTailored network design; full FortiOS (NAT, VPN, SD-WAN)Minimal integration effort; automated cloud-native protection
FortiOS expertiseRequiredNot required
CloudsAWS, Azure, GCP, OCI, IBM, Alibaba + private hypervisorsAWS and Azure
Scaling & patchingCustomer-managedFortinet-managed

FortiSASE Administration & User Onboarding

FortiSASE (Fortinet Secure Access Service Edge) is Fortinet's cloud-delivered convergence of networking and security, combining Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall-as-a-Service (FWaaS), and SD-WAN into one cloud service. The FortiGate Administrator exam expects you to explain how FortiSASE is administered and how users are onboarded.

User onboarding methods

FortiSASE supports several ways to provision and authenticate users:

  1. Local users — An administrator defines users manually in Configuration > Users and sends an invitation directly. This is the simplest method, suitable for small deployments.
  2. Single Sign-On (SSO) via SAML — FortiSASE acts as the SAML Service Provider (SP) and integrates with an external Identity Provider (IdP) such as Microsoft Entra ID, Okta, or FortiAuthenticator. SSO groups can be applied to policies for identity-based access control.
  3. SCIM server support — FortiSASE can act as a SCIM (System for Cross-domain Identity Management) server for automated user and group provisioning from SAML IdPs (Entra ID, Okta, FortiAuthenticator). The IdP (SCIM client) pushes user and group changes to FortiSASE (SCIM server) periodically or on-demand, enabling dynamic user lifecycle management — adds, updates, and deletions sync automatically. This is a select-availability feature that requires an instance enabled with IPsec remote agent support and is not available with hybrid IPsec/SSL.
  4. Authenticated endpoint onboarding — FortiSASE can enforce SAML SSO during endpoint client onboarding, so only authenticated users and authorized endpoints can register with the FortiSASE Endpoint Management service, preventing unauthorized endpoints even when they hold a valid invitation code. The Onboard Users button on the Remote User Management widget sends invitation emails; users then download and install FortiClient and register to FortiSASE using the invitation.

Administration model

FortiSASE is administered from a cloud management portal that is separate from the on-box FortiGate GUI and CLI. The exam-relevant distinction is conceptual: on-premises FortiGate administration is performed directly through FortiOS CLI/GUI, whereas FortiSASE administration is policy-driven through the SASE management interface, with users and groups sourced from an identity provider rather than defined locally on a firewall.


Exam-Focused Takeaways

  • FortiGate-VM is full FortiOS in a VM you operate; choose it for tailored designs and features such as VPN and SD-WAN in the cloud.
  • FortiGate CNF is a Fortinet-operated SaaS firewall for AWS and Azure VPCs; choose it for minimal effort and automated multi-account protection.
  • FortiSASE is cloud-delivered SASE; administer it through the portal and onboard users via local accounts, SAML SSO, or SCIM provisioning from an IdP.
Loading diagram...
Fortinet Cloud Delivery Models & FortiSASE User Onboarding
Test Your Knowledge

Which Fortinet solution is a SaaS-delivered cloud-native firewall service that protects AWS VPCs and Azure VNets without requiring customers to deploy or maintain any firewall infrastructure?

A
B
C
D
Test Your Knowledge

FortiSASE supports automated user and group provisioning from a SAML identity provider using which protocol, where FortiSASE acts as the server and the IdP acts as the client?

A
B
C
D