1. Fortinet SD-WAN Architecture for Enterprise 7.4 Guide
Page 12
Section: Hub Placement: "If a large amount of traffic is exchanged between the branches
then a hub-and-spoke topology is recommended... The hub should be placed in a location that is central to all the branches to minimize latency." This directly supports option B as a key performance consideration for hub placement.
2. Fortinet SD-WAN for MSSPs Solution Guide
Page 6
Section: SD-WAN Hub/Controller: This guide notes that while the hub is typically in the MSSP PoP
it can be deployed on-premise for reasons including "Integration with existing on-premises infrastructure
such as authentication servers or security devices." This supports the rationale for option A
where SIA must integrate with the customer's on-prem security stack.
3. Fortinet SD-WAN Architecture for Enterprise 7.4 Guide
Page 12
Section: Hub Placement: "For centralized internet breakout
all internet-bound traffic from the branches is routed to the hub
where it is inspected by the security features of the FortiGate before being sent to the internet." This confirms the mechanism of option A
which
when combined with a customer's on-premise security stack
necessitates an on-premise hub.