Diseño y evaluación de una arquitectura sd-wan segura basada en herramientas fortinet para la optimización de conectividad y seguridad en redes empresariales multi-sede en Colombia
| dc.contributor.advisor | Mancera Lagos, Pedro Alejandro | |
| dc.contributor.author | Merizalde Moreno, Camilo Alejandro | |
| dc.contributor.corporatename | Universidad Santo Tomás | |
| dc.contributor.cvlac | https://scienti.minciencias.gov.co/cvlac/visualizador/generarCurriculoCv.do?cod_rh=0000068920 | |
| dc.contributor.cvlac | https://scienti.minciencias.gov.co/cvlac/visualizador/generarCurriculoCv.do?cod_rh=0002514036 | |
| dc.date.accessioned | 2026-07-24T12:42:01Z | |
| dc.date.available | 2026-07-24T12:42:01Z | |
| dc.date.issued | 2026-07-08 | |
| dc.description | Esta monografía aborda el diseño de una arquitectura SD-WAN (Software-Defined Wide Area Network) sobre la plataforma Fortinet para empresas multi-sede en Colombia. La motivación nace de un patrón observado en el ejercicio profesional. Las redes WAN (Wide Area Network) basadas en MPLS (Multiprotocol Label Switching) son costosas. No permiten priorizar tráfico por aplicación. Obligan al backhauling al datacenter central. La operación del firewall, la VPN (Virtual Private Network) y el ruteo se hace en silos. La propuesta consiste en aprovechar la funcionalidad SD-WAN nativa de FortiOS. Un FortiGate por sede actúa como controlador SD-WAN y NGFW (Next-Generation Firewall) al mismo tiempo. La gestión es centralizada desde FortiManager. La visibilidad se obtiene desde FortiAnalyzer. El alcance se concentra en tres frentes orientados a empresas multi-sede colombianas con presencia entre tres y diez ubicaciones. El alcance se acota al diagnóstico del estado actual de la WAN, al diseño de la arquitectura SD-WAN con políticas SLA (Service Level Agreement) por aplicación y túneles IPSec (Internet Protocol Security), y a la validación del comportamiento en laboratorio virtualizado con GNS3 y FortiGate VM. El cronograma se ajusta a cuatro meses. | |
| dc.description.abstract | This monograph addresses the design of a Fortinet-based SD-WAN (Software-Defined Wide Area Network) architecture for multi-site enterprises in Colombia. The motivation comes from a pattern observed in the author's professional practice. MPLS-based WAN networks are expensive. They do not allow application-based traffic prioritization. They force traffic backhaul to the central datacenter. Firewall, VPN, and routing operations are siloed. The proposal leverages FortiOS native SD-WAN capabilities. One FortiGate per site acts as both SD-WAN controller and NGFW. Management is centralized through FortiManager. Visibility is obtained from FortiAnalyzer. The scope is bounded to Colombian multi-site enterprises with three to ten locations. | |
| dc.description.degreelevel | Pregrado | spa |
| dc.description.degreename | Ingeniero de Telecomunicaciones | spa |
| dc.description.domain | http://unidadinvestigacion.usta.edu.co | |
| dc.format.mimetype | application/pdf | |
| dc.identifier.citation | Merizalde Moreno, C. A. (2026). Diseño y evaluación de una arquitectura sd-wan segura basada en herramientas fortinet para la optimización de conectividad y seguridad en redes empresariales multi-sede en Colombia. [Trabajo de Grado, Universidad Santo Tomás]. Repositorio Institucional | |
| dc.identifier.instname | instname:Universidad Santo Tomás | spa |
| dc.identifier.reponame | reponame:Repositorio Institucional Universidad Santo Tomás | spa |
| dc.identifier.repourl | repourl:https://repository.usta.edu.co | spa |
| dc.identifier.uri | http://hdl.handle.net/11634/73478 | |
| dc.language.iso | spa | |
| dc.publisher | Universidad Santo Tomás | spa |
| dc.publisher.branch | CRAI-USTA Bogotá | |
| dc.publisher.faculty | Facultad de Ingeniería de Telecomunicaciones | spa |
| dc.publisher.program | Pregrado Ingeniería de Telecomunicaciones | spa |
| dc.relation.references | Varios, "Software-Defined Wide Area Networks (SD-WANs): A Survey", Electronics, MDPI, 2024. Disponible: https://www.mdpi.com/journal/electronics | |
| dc.relation.references | Varios, "A Risk Assessment Analysis to Enhance the Security of OT WAN with SD-WAN", J. Cybersecur. Priv., MDPI, 2024. Disponible: https://www.mdpi.com/journal/jcp | |
| dc.relation.references | Ibrahim et al., "Comprehensive Strategies for Enhancing SD-WAN: Integrating Security, Dynamic Routing and QoS", IET Networks, Wiley, 2025. Disponible: https://ietresearch.onlinelibrary.wiley.com/journal/20474962. | |
| dc.relation.references | Lamdakkar et al., "Toward a Modern Secure Network Based on Next-Generation Firewalls", Procedia Computer Science, 2024. | |
| dc.relation.references | Fortinet Inc., "Fortinet Secure SD-WAN Reference Architecture", 2024. Disponible: https://www.fortinet.com/products/sd-wan | |
| dc.relation.references | P. Gupta, "Review of Next-Generation Firewalls", SSRN, 2024. | |
| dc.relation.references | M. Shaik, "Next-Generation Firewalls: Beyond Traditional Perimeter Defense", ResearchGate, 2025 | |
| dc.relation.references | WWT Advanced Technology Center, "Fortinet SD-WAN/SD-Branch Proof of Concept Testing", 2023. | |
| dc.relation.references | Enterprise Strategy Group, "Analyzing the Economic Benefits of FortiGate Secure SD-WAN", 2023. Disponible: https://www.fortinet.com/resources-content. | |
| dc.relation.references | Forrester Consulting, "Total Economic Impact: Fortinet Secure SD-WAN", 2022 | |
| dc.relation.references | Al-Mohamad, "Performance Evaluation of Firewall Technologies", IEEE, 2024. | |
| dc.relation.references | Gambo y Almulhem, "Zero Trust Architecture: A Systematic Literature Review", arXiv, 2025. | |
| dc.relation.references | Weinberg et al., "Zero Trust Implementation in the Emerging Technologies Era: A Survey", Complex Engineering Systems, 2024. | |
| dc.relation.references | Costanzo y Anene, "NGFW Effectiveness Against Encrypted Threats", IEEE, 2025. | |
| dc.relation.references | Heino, Hakkala y Virtanen, "Endpoint-Aware Inspection in NGFW", IEEE Access, 2022. | |
| dc.relation.references | Rezaei y Liu, "Deep Learning for Encrypted Traffic Classification: An Overview", IEEE Communications, 2021. | |
| dc.relation.references | Pinto et al., "IDS Based on ML for Critical Infrastructure", Computers, MDPI, 2023. | |
| dc.relation.references | Tendikov et al., "SIEM Data Analysis with Machine Learning", Results in Engineering, 2024. | |
| dc.relation.references | Sheeraz et al., "Effective Security Monitoring Using SIEM Architecture", IEEE Access, 2023. | |
| dc.relation.references | M. A. Islam, "AI/ML Application in a Security Operations Center", ResearchGate, 2023. | |
| dc.relation.references | MDPI Authors, "Automated Policy Management in NGFW", Applied Sciences, MDPI, 2024. | |
| dc.relation.references | SANS Institute, "IDS and NGFW Integration for Enterprise Security", SANS Reading Room, 2023. | |
| dc.relation.references | St. Cloud State University, "A Study on Security Attributes of Software-Defined Wide Area Network", 2023. | |
| dc.relation.references | Naveen, Sharma y Ahlawat, "SD-WAN: The Future of Networking", IJRASET, 2023. | |
| dc.relation.references | Varios, "Software Defined WAN: Current Challenges and Future Perspectives", IEEE Conference, 2023. | |
| dc.relation.references | CISA, "Firewall Vulnerabilities and Exploit Patterns", 2024. Disponible: https://www.cisa.gov. | |
| dc.relation.references | Cisco Research, "Evaluating NAC Integration with Firewalls", 2023. | |
| dc.relation.references | Suresh y Priya, "A Holistic Exploration of Firewall Technologies", IJRPR, 2024 | |
| dc.relation.references | Aljabri et al., "Classification of Firewall Log Data Using ML/DL", Sensors, MDPI, 2022. | |
| dc.relation.references | Ahmadi, "Adaptive Cybersecurity: Dynamically Retrainable Firewalls", IEEE, 2025. | |
| dc.rights | Attribution-NonCommercial-NoDerivs 2.5 Colombia | en |
| dc.rights.accessrights | info:eu-repo/semantics/openAccess | |
| dc.rights.coar | http://purl.org/coar/access_right/c_abf2 | |
| dc.rights.local | Abierto (Texto Completo) | spa |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/2.5/co/ | |
| dc.subject.keyword | SD-WAN | |
| dc.subject.keyword | Fortinet | |
| dc.subject.keyword | FortiGate | |
| dc.subject.keyword | NGFW | |
| dc.subject.keyword | MPLS | |
| dc.subject.keyword | SLA | |
| dc.subject.keyword | IPSec | |
| dc.subject.keyword | FortiManager | |
| dc.subject.lemb | Ingeniería de Telecomunicaciones | |
| dc.subject.lemb | Redes de área amplia (WAN) | |
| dc.subject.lemb | Seguridad informática | |
| dc.subject.proposal | SD-WAN | |
| dc.subject.proposal | Fortinet | |
| dc.subject.proposal | FortiGate | |
| dc.subject.proposal | NGFW | |
| dc.subject.proposal | FortiManager | |
| dc.subject.proposal | MPLS | |
| dc.subject.proposal | SLA | |
| dc.subject.proposal | IPSec | |
| dc.title | Diseño y evaluación de una arquitectura sd-wan segura basada en herramientas fortinet para la optimización de conectividad y seguridad en redes empresariales multi-sede en Colombia | |
| dc.type | bachelor thesis | |
| dc.type.category | Producción Técnica y Tecnológica: Innovación generada en la gestión empresarial | |
| dc.type.coar | http://purl.org/coar/resource_type/c_7a1f | |
| dc.type.coarversion | http://purl.org/coar/version/c_ab4af688f83e57aa | |
| dc.type.drive | info:eu-repo/semantics/bachelorThesis | |
| dc.type.local | Trabajo de grado | spa |
| dc.type.version | info:eu-repo/semantics/acceptedVersion |
Archivos
Bloque original
1 - 1 de 1
Cargando...
- Nombre:
- 2026camilomerizalde.pdf
- Tamaño:
- 1.22 MB
- Formato:
- Adobe Portable Document Format
Bloque de licencias
1 - 3 de 3
Cargando...
- Nombre:
- license.txt
- Tamaño:
- 807 B
- Formato:
- Item-specific license agreed upon to submission
- Descripción:
Cargando...
- Nombre:
- Carta_de_aprobacin_facultad_Crai (1).pdf
- Tamaño:
- 512.51 KB
- Formato:
- Adobe Portable Document Format
- Descripción:
- Carta de facultad
Cargando...
- Nombre:
- Carta_autorizacion_autoarchivo_autor_2021.pdf
- Tamaño:
- 930.15 KB
- Formato:
- Adobe Portable Document Format
- Descripción:
- Carta derechos de autor

