Mobile & Gadgets

The shift in SASE economics following Cisco Secure Access updates

Cisco's reduction of user counts for Secure Access Essentials and Advantage packages from 100 to 50 impacts total cost of ownership. This change shifts the competitive landscape against Fortinet, which offers 20 to 25 percent savings through its Security Fabric integration.

The shift in SASE economics following Cisco Secure Access updates

The reduction of the user count for Cisco Secure Access Essentials and Advantage packages from 100 to 50 users forces a recalculation of the total cost of ownership for many mid-market organizations this month. This pricing change in the Cisco ecosystem impacts how I evaluate the competitive position of Fortinet. While Cisco targets large enterprises with existing networking infrastructure, Fortinet remains a strong option for organizations prioritizing cost and consolidated branch security. The market is seeing a divergence between vendors who bundle everything into a single cloud service and those who maintain a hardware-centric approach to security.

Fortinet replaces individual SD-WAN SKUs with service bundles

Fortinet changed its SD-WAN packaging in 2026. Individual SD-WAN SKUs are gone. These are replaced by service bundles that cost between 35 and 50 percent of the FortiGate hardware base price per year. This change helps organizations that need to refresh branch firewalls and SD-WAN capabilities in one purchase. The economic story for Fortinet remains focused on consolidation. A branch that needs a firewall refresh gets SD-WAN in the same box and the same console. This structural advantage made Fortinet a leader in the July 2025 SASE Platforms Magic Quadrant.

Practitioners must maintain discipline regarding firmware to manage this model effectively. Community consensus suggests running the mature FortiOS branch instead of chasing the newest release. Major upgrades require the same care that Cisco shops give to controller upgrades. The convergence of networking and security through FortiOS provides a consistent experience across the Security Fabric. This includes FortiGate, FortiSASE, FortiClient, and FortiNAC.

FortiSASE pricing mechanics and the Security Fabric discount

FortiSASE pricing follows a per-user, per-month or per-user, per-annual model. List pricing for FortiSASE ranges from $8 to $20 per user per month depending on the feature set. Organizations that commit to 100 or more users see lower pricing in the $6 to $15 per user per month range. This tiered approach rewards larger deployments with volume discounts.

Feature/Metric FortiSASE List Pricing 100+ User Pricing Security Fabric Savings
Per User Monthly $8 to $20 $6 to $15 20% to 25%

The most significant lever for cost reduction is the Security Fabric. Organizations already running FortiGate hardware receive a preferred discount. This integration effectively delivers 20 to 25 percent savings compared to what a standalone FortiSASE customer pays. This discount is a primary argument for Fortinet against pure-play SASE vendors.

If you find yourself staring at a Fortinet quote with a mountain of layered SKUs, you need to map every add-on to your actual remote worker count before signing. The model rewards planning but punishes improvisation. Every new customer starts with a user-based license. Every other SKU registers on top of that initial purchase. An SD-WAN on-ramp contract cannot be applied on top of a FortiSASE Professional license. Standard and Advanced user subscriptions include up to four locations, selected at activation.

Cisco Secure Access tier structures and user counts

Cisco Secure Access provides three primary tiers: Secure Access Essentials, Secure Access Advantage, and Secure Access – DNS Defense. The Essentials and Advantage tiers provide Secure Internet Access (SIA) and Secure Private Access (SPA). The DNS Defense tier is a separate offering. The user count for the Essentials and Advantage packages recently dropped from 100 to 50. This change affects how IT departments calculate their license requirements for remote and roaming users.

The licensing model for Cisco is also subscription-based. Each customer has only one subscription, but that subscription can comprise different types of users. These include SIA, SPA, and DNS Defense users. Subscriptions are available in 12, 36, or 60 month terms. Following the end of a term, the subscription renews automatically for 12 months unless the customer deselects auto-renewal.

Cisco Secure Access Essentials includes several core capabilities. It provides secure private access using ZTNA and VPNaaS. It also includes secure internet access via roaming security, VPN tunnels, and proxy chains. For users needing more, the Advantage tier includes:

  • Malware analytics with unlimited samples per day
  • Layer 7 application visibility and control
  • RBI for any website
  • Multimode Data Loss Protection (DLP)

Hardware costs and subscription bundle math

Fortinet’s pricing architecture combines hardware capital expenditure with recurring software subscriptions. The base FortiGate firewall is a hardware appliance priced on throughput capacity. A FortiGate 60F with a UTM bundle might list at $800 to $1200 annually. A mid-range data center model like the FortiGate 1500D might list at $15,000 to $25,000 with a UTM bundle.

The choice of security bundle directly impacts the total cost. UTM bundles include application control, web filtering, antivirus, and IPS. Enterprise bundles add FortiSandbox Cloud and additional threat intelligence. ATP bundles are the most comprehensive tier.

Bundle Type Small Appliance List % of HW Enterprise Appliance List % of HW
UTM 30% to 50% 20% to 40%
Enterprise 40% to 60% 30% to 50%
ATP 50% to 70% 40% to 60%

Buyers purchasing UTM bundles on multi-year terms often achieve 15 to 30 percent discounts. ATP bundles are commonly negotiated with volume discounts, and buyers often achieve 25 to 40 percent off list pricing. This disparity shows why understanding the hardware-to-software ratio is necessary for budget planning.

Technical configuration and compatibility requirements

Connecting a FortiGate firewall to Cisco Secure Access requires specific technical alignment. The configuration relies on IKEv2 for the VPN tunnel. Administrators must set the Phase 1 proposal to use AES256 for encryption and SHA256 for authentication. The Diffie-Hellman group must be set to 20 to avoid potential issues.

The Phase 2 proposal requires different settings to maintain stability. The encryption must be AES128 and the authentication must be SHA256. Perfect Forward Secrecy must be disabled in this phase. NAT Traversal must be enabled, and Dead Peer Detection should be set to on idle. The key lifetime for Phase 2 is 43200 seconds.

The implementation also requires a policy route to redirect traffic. The destination addresses in the policy must include the VPN Profile IP Pool and the CGNAT range of 100.64.0.0/10. After the tunnel is created, a new interface appears behind the WAN port. This interface requires a non-routable IP address and a netmask of 30.

Documented limitations in Fortinet’s cloud security

Fortinet’s appliance heritage introduces certain gaps in the FortiSASE cloud service. Documentation shows that proxy mode is not supported on iOS. The DNS filter is not supported for the SWG. Additionally, agentless RBI does not work when SWG single sign-on is configured. These gaps can lead to policy workarounds or increased help-desk tickets for mobile users.

The integration of different Fortinet components can also create complexity. FortiSASE assembles established components into one controller. This can lead to longer setup times and unintended gaps in security policy because the platform is composed of parts that grew up separately. The layered licensing model adds to this difficulty. The stacking order of SKUs matters for the quote to work correctly.

The mindshare for FortiSASE in the SASE category is 5.2%, which is down from 7.2% in the previous year. This decline reflects the intense competition from pure-play SASE vendors. Some reviewers note that while Fortinet is a leader in SD-WAN, the SASE component is still maturing compared to specialized competitors.

Convergence of NAC and SASE across the industry

The market is seeing a convergence between Network Access Control (NAC) and SASE. SASE provides cloud-based security but cannot see what is happening at a physical switch port. NAC handles device discovery and 802.1X authentication at the campus edge. This gap makes integration necessary for complete security.

Fortinet has a tight native integration through the Security Fabric. This connects FortiNAC, FortiGate, FortiSASE, and FortiClient through a common telemetry and policy framework. This provides a seamless path from campus NAC to cloud SASE. However, FortiNAC is currently undergoing a significant platform rebuild.

Other vendors take different approaches to this convergence. Aruba integrates ClearPass device identity into its EdgeConnect SD-WAN platform. This allows customers to choose from many different cloud security providers. Cisco uses its ISE platform to feed posture assessments into Secure Access. Will the convergence of NAC and SASE finally bridge the gap between campus switch ports and cloud applications for all enterprises?

Choosing the right platform for your deployment

The decision to stay with Cisco or move to Fortinet depends on your existing infrastructure. Choose Cisco Catalyst SD-WAN if you run 500 or more users on Cisco routing and switching and need deep segmentation. If your engineers are fluent in IOS XE and you have an enterprise agreement, the 25 to 40 percent discounts make staying with Cisco the right move.

Choose Fortinet if your branch firewalls are due for a refresh and you want to consolidate security and WAN in one box. Fortinet is the strongest all-in cost story for mid-market organizations. It is the best choice for those already deep in the Fortinet Security Fabric.

Choose Palo Alto Prisma if your security organization is standardizing on Palo Alto and needs a single subscription for SSE and SD-WAN. Their platformization deals can discount list by 30 to 60 percent. Choose Cato or Aryaka if you want a managed service or a single cloud console with minimal operational footprint.

Vendor Best Use Case Primary Pricing Model
Cisco Cisco-heavy enterprises Per-user bundled subscription
Fortinet Consolidated branch security Appliance plus service bundles
Palo Alto Security-first SASE programs Per-user annual subscription
Cato Cloud-managed simplicity Capacity-based subscription
Aryaka Managed global WAN T-shirt-sized site tiers