In FortiSASE site-based (remote internet access) deployments, FortiExtender is used to onboard branch or remote sites without a local FortiGate.
According to FortiSASE and FortiExtender architecture documentation:
FortiExtender integrates with FortiSASE using a secure VXLAN-over-IPsec tunnel
This tunnel:
Extends the site network to FortiSASE
Transparently forwards traffic for inspection
Preserves network segmentation and routing context
This design is similar to cloud-based LAN extension and is not proxy-based
Why the other options are incorrect
B: FortiClient is used for agent-based user access, not FortiExtender
C: Secure Web Gateway (SWG) is a service, not a transport mechanism
D: PAC files and explicit proxies are used in agentless / proxy-based access, not site-based FortiExtender deployments
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit