Full Fortinet Stack Environment

  Рет қаралды 66,669

Fortinet Guru

Fortinet Guru

3 жыл бұрын

A lot of people praise Meraki and UBNT for their capabilities of having a single ecosystem stack from edge to endpoint. I think you need to give Fortinet their due credit as well. Learn how to create a full stack in Fortinet for the Firewall, Switch and Access Point
Buy Hardware: bit.ly/2QZVeqh
Get Consulting: bit.ly/36FinSU
My Other Projects:
Office Of The CISO: bit.ly/3HGMH1o
Packet Llama: bit.ly/3SEX3H4
###### SOCIAL LINKS ######
Twitter: bit.ly/2WXiRAv
Facebook: bit.ly/3eigz4D
Instagram: bit.ly/3cZneAz
######################

Пікірлер: 123
@_stucki_
@_stucki_ 3 жыл бұрын
Hi Fortinet Guru, it's nice to see some hints and tips from you, I'm mainly working on the bigger devices in an enterprise environment. (FG1100, FG1800 and upwards) It's sometimes very helpful to see some ideas from a different side of view, it's helps in daily work. Thanks for sharing !
@disasstah
@disasstah Жыл бұрын
There were a lot of helpful tidbits of knowledge in here! I really appreciate it, especially since I'll be deploying stacks just like what you have shown.
@FlorianZevedei
@FlorianZevedei 3 жыл бұрын
Thanks for the impressive and simple introduction! Great stuff. Makes a lot of sense in that "Forti-Universe". Thanks!
@RichardDePas
@RichardDePas 3 жыл бұрын
Thanks! That was a great brief description of getting the stack up and running.
@cecilerasmussen8161
@cecilerasmussen8161 3 жыл бұрын
Giving this a go tomorrow, can't wait makes a lot of sense Thank you
@zgralewski
@zgralewski 2 жыл бұрын
I love your videos. The one brilliant source of fortiknowledge.
@Xyler94
@Xyler94 3 жыл бұрын
I have a Fortinet Full Stack at my house, and it's pretty cool.
@uByte2
@uByte2 2 жыл бұрын
Just what I needed. Thank you so much.
@Itisnot2late
@Itisnot2late 3 жыл бұрын
Brief introduction. Thanks a lot.
@saifemran4528
@saifemran4528 3 жыл бұрын
As always, great videos!
@ajibolayusuf2057
@ajibolayusuf2057 2 жыл бұрын
The way you explain things succinctly needs to be studied! For real thank you Mikey!
@keithlee4945
@keithlee4945 3 жыл бұрын
Have been following your blog and videos. Excellent walk through! Deployed my first full Fortinet Stack (101F configured in a ring mode on the 10G interfaces 2x FS148F-PoE w/10x FortiAP-231E) All i can say is that the video doesn't do justice what the whole solution can actually do. For my client's request, i got to see first hand how powerful the whole integration is. Being able to see devices is one thing, the FortiAP is pretty decent, as its able to also monitor the air in real time for the 231E (yes they even have the meraki spectrum analysis!). Roaming wasn't a problem and didn't require much configuration which i'm quite surprised coming from deploying Ubiquiti/Ruckus/Aruba. I just hope Fortinet has better QC on their Fortigate's firmware.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
The visibility is wonderful and helps people out a lot! I am a big fan of it. I do hope for higher QC on the firmware.
@5945751
@5945751 3 жыл бұрын
First time watching you video; love it. Now a subscriber
@dunnjustintime
@dunnjustintime 3 жыл бұрын
This was a great video! Thank you so much!!
@tonymarms8908
@tonymarms8908 3 жыл бұрын
Thanks for this great teaser of fortinet full stack 👍 I don't know if you already have this video but if you have time can you also discuss multi tenancy capabilities of fortinet firewall, like vdoms/vrf. I'm just collecting use cases that may help us build a network as service provider, currently reviewing fortinet as firewall for this project.. Hope to hear some inputs..🙂 cheers 👍👏 keep it up
@zgralewski
@zgralewski 2 жыл бұрын
Dziękujemy.
@myanmarict1590
@myanmarict1590 Жыл бұрын
That is really helpful. Thank you so much!
@thom71
@thom71 3 жыл бұрын
That was a great explanation of all of that. I have the 60F, 124PoE, 221E, and a 222E and have just started working at dialing all of this stuff in on my home network. My 60F uploads to my office Fortianalyzer. I can police the kids and keep them off youtube and stuff, and shut off the netflix at night so they actually go to bed. I'd like to see some policy building, as I had a hard time getting the chromebooks locked down.
@yesforarab
@yesforarab Жыл бұрын
Thank you!
@brendanbass5495
@brendanbass5495 3 жыл бұрын
Great content learned plenty.
@JunLYeap
@JunLYeap 3 жыл бұрын
Thanks for sharing sir!
@Desertedx
@Desertedx 3 жыл бұрын
So great video!
@hudsonatlantis6754
@hudsonatlantis6754 3 жыл бұрын
Great Video!
@kostass8853
@kostass8853 2 жыл бұрын
Hey long time no see a new video...! Missed your excellent videos!!!
@thomasjoseph9609
@thomasjoseph9609 Жыл бұрын
it is really nice and helpful
@ignaciosaravia5719
@ignaciosaravia5719 2 жыл бұрын
Great video!! You make it easier to understand. Hey, do you know how to split an SD-WAN to share WAN1 through LAN port 2? Just a thought.
@eraadw
@eraadw 3 жыл бұрын
Thanks a lot for sharing your knowledge. I have been watching your videos for weeks/month now. And thanks to you I decided to buy a full stack (FG/FS/AP - Book) a week ago for myself and it seems this video came at the perfect moment. Since you mention other brand at the start of your video, I was wondering, even tho Fortinet seems way more advanced and reliable than many brand atm do you think installing Unifi or Edge for very small office is a good idea ? Anyway thanks again for sharing !!!!
@stanleyilchev3503
@stanleyilchev3503 3 жыл бұрын
Love the content!! What issues have you run into if you don't daisy-chain the switches, but connect them all directly to the firewall and "trunk" them from there?
@CristobalRuiz
@CristobalRuiz 3 жыл бұрын
Love the shirt bro.
@dtcoleman05
@dtcoleman05 3 жыл бұрын
Great video! Do you have any FortiNAC demo and/review videos?
@bboosss1065
@bboosss1065 3 жыл бұрын
Can you please explore more of the lldp med thing and the logic of the allowed / native thing? How do you decide which port is a trunk port? Or basically it does dot1q and you just decide the native
@iamrichard8778
@iamrichard8778 3 жыл бұрын
Hey man, you are pretty good at explaining things. Ever thought of doing a NS course? Heaps of CCNA YT focused channels around. Just a thought.
@ErwinNiesten
@ErwinNiesten 3 жыл бұрын
Hello Mike, I have watched a lot of your videos! You are doing a great job, thanks for that! I have a similar setup at home right now, unfortunately without multiple internet connections. Is there a possibility that you created a video regarding FortiSwitch NAC Policies and FortiSwitch Security Policies within this setup? Thank you! Keep up the good work! Regards!
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Let me see what I can do!
@G1rlyG33k
@G1rlyG33k 3 жыл бұрын
Hey Mike, have you completed your NSE 8 exam? Your content is very helpful.
@musclekitchen3705
@musclekitchen3705 3 жыл бұрын
Alright mate are you still going to do the video of cisco vs fortinet like you did with checkpoint and palo alto that was really good stuff 👍
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Will check it out.
@saikenjkd
@saikenjkd 3 жыл бұрын
Any chance on a FortiEDR review? in light of all the latest outbreaks, would be a good time to talk about Fortinets offering compared to crowdstrike, S1, etc
@ibrahimngueyon9688
@ibrahimngueyon9688 2 жыл бұрын
Great
@rhdtv2002
@rhdtv2002 2 жыл бұрын
We just upgraded from a Juniper To Fortigate 100e..we are now going waiting to receive 4 FORTINET POE switches
@iamnotnice1536
@iamnotnice1536 3 жыл бұрын
Fortinet are awesome. Beats the like of Sophos, Juniper, barracuda and Watchguard. I want this technology and its a solutions will help ALL the small and mid size now and the future. Where can i learn more.
@nagchampa4476
@nagchampa4476 3 жыл бұрын
I love security fabric . Well done Fortinet, the best environnement ! ❤
@marcingowacki3647
@marcingowacki3647 3 жыл бұрын
Great video and just on time as I am preparing to deploy full stack. Video proposal: Trusted CA certificate for deep SSL inspection. Can you recommend any commercial SSL certificate? First certificate I bought has CA:FALSE parameter and I am having problems finding certificate provider that will work for deep inspection and does not cost 200$. Is there any 20$ certificate on the market that will do the job?
@nielstaildeman
@nielstaildeman 2 жыл бұрын
Nice video! One question though: As I understand from the example in the video, the fortiswitch is handling the L3. But is the Fortigate then still able to check traffic between l3 vlans?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
The fortigate will be handling all routing and access control.
@markusfrey3775
@markusfrey3775 2 жыл бұрын
WOW, Amazing!I work an LAB with 2 FortiGate 60F and 2 FortiSwitch 124F and 4 AP231F What ist the best prec. for 100% HA Stack? Would you pleae so kind and give me a view hints?
@kimhalavakoski5189
@kimhalavakoski5189 2 жыл бұрын
Hello! Great video! One question though: I am testing out a similar setup with a FG-40F and have some issues in that the VLANs created on the FortiSwtich are not "easily" used on the FortiGate, meaning that I can not use a FortiSwitch VLAN on the FortiGate internal ports...seems like the two devices can't use the same VLANs? Any thoughts / feedback on that and how to use the some VLANs on both devices and possible to configure FortiGate with VLANs from Fortiswitch?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
I recommend keeping all VLANs on the FortiSwitch interface and switches. The ports on the FortiGate itself I only use for Fortilink access honestly. You can do Software switches to group ports and interfaces together but then you lose hardware acceleration.
@eaperezh
@eaperezh 3 жыл бұрын
I want to buy that t-shirt!!!! Where can I get it? Thankfully same applies here in Panama, Central America
@tomerpeer6398
@tomerpeer6398 2 жыл бұрын
Hi Fortinet Guru, can toy stack fortinet switches with DAC cabels? if so, can you advertise a short brief of how to. thanks in advance. Tomer
@alarsen77
@alarsen77 3 жыл бұрын
Great video! I am currently running a 60f and a 231f at home in a home lab. I have been thinking about adding a switch. I have a small network with only 5 wired devices (including the AP) so I was thinking the 108e PoE would be fine, but do you think the 124e PoE is worth the extra cost for future proofing?
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Depends on your port density needs. It would meet your future requirements tho.
@alarsen77
@alarsen77 3 жыл бұрын
@@FortinetGuru I currently only have a few devices and don't have a plan for too many more right now, so was thinking the 8 port would be good and save on cost and I could always upgrade it later if needed. I just wasn't sure if the 24 poet had any better components that made it perform better.
@AhmadSwailem
@AhmadSwailem 3 жыл бұрын
I loved your T-shirt 😂❤
@lkfng
@lkfng 3 жыл бұрын
I wonder if he has hoodies for sale with the same slogan?
@AhmadSwailem
@AhmadSwailem 3 жыл бұрын
@@lkfng i do too..
@hanold5049
@hanold5049 3 жыл бұрын
love from china...
@demandredlfc4180
@demandredlfc4180 2 жыл бұрын
Am I right that if I use tunnel mode SSIDs then I will not be able to see Wi-Fi clients from FortiSwitch Ports view, as it is on 23:24?
@kaain775
@kaain775 3 жыл бұрын
This pairs perfectly with Microsoft 365 services, two exceptionally seamless technologies.
@ebrahimshaikjee6799
@ebrahimshaikjee6799 2 жыл бұрын
Great video, just curious why would you use the 3rd octet as your site identifier instead of the 2nd octet which makes alot more sense.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
It’s personal preference / scalability. I have situations where I use the second octet (when proposed future branches are smaller than 256). Otherwise, the third octet enables up to 2500 (although smaller potential subnets) branches
@sdfnhghjdfbgh5851
@sdfnhghjdfbgh5851 11 ай бұрын
I have 100f , and need to switch over from the wan interface port to an sfp port. How would you proceed?
@camryds
@camryds 2 жыл бұрын
I would like to know how to configure FWF -> FAP in a mesh environment wireless mesh with VLAN
@erikbakke5401
@erikbakke5401 3 жыл бұрын
Do you have url to the compatibility matrix regarding upgrade? I have also run into issues when upgrading fortigate with fortiswitch via fortilink
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Google Fortilink Compatibility Matrix and you are set
@user-fd8mt9pf3i
@user-fd8mt9pf3i Жыл бұрын
How would you do your vlans if you have your fw interfaces configured to handle the DHCP?
@FortinetGuru
@FortinetGuru Жыл бұрын
My vlans themselves would handle the dhcp so no other edits would be necessary other than defining parameters.
@DonJudd
@DonJudd 3 жыл бұрын
Mike, if you don't mind answering a dumb question for me. My internal LAN is 192.168.70.x. I have a gateway to gateway VPN to 192.168.1.x. My Data vlan is 10.70.10.x and is part of my INSIDE zone. Firewall policy for INSIDE>VPN is set to allow traffic. I am assuming my static route need to also be set for the 10.70.10.0/24 network, but how? Following this video, I have my VLANs working like yours (Data and Guest, I have no voice) but computers on my Data vlan can't reach the remote end of the VPN.
@stephensukhai3311
@stephensukhai3311 3 жыл бұрын
Great Video......followed your video but noticed with my FortiAP 231F I’m not getting anything faster then 100MB download. I do have a 1gig connection. Wired connections I have no issues. Any thoughts?
@vewo234
@vewo234 3 жыл бұрын
Are you using Capwap by any chance? Some smaller/older FGT models can‘t offload Capwap and CPU speed will limit the throughput.
@dineshchandrawanshi4683
@dineshchandrawanshi4683 3 жыл бұрын
Use Appropriate fortiSwitch
@luchobeto
@luchobeto 3 жыл бұрын
how can you add fortigate hardware switch ports to the fortiswitch vlan after the fortilink is up and running ?
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Depending on how your fortilink interface is configured you can add and removal physical interfaces to it.
@JoseSilva-mf5te
@JoseSilva-mf5te 2 жыл бұрын
Hello. I have a question for you: Is it possible in Fortigate to implement ADVPN using IPsec aggregate tunnels both on HUB and Spoke? Thank you.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
In theory addressable interfaces that enable you to do BGP across them makes it doable. I’ve never tried but would probably be a good lab.
@JoseSilva-mf5te
@JoseSilva-mf5te 2 жыл бұрын
@@FortinetGuru Thank you for the quick reply. I tried to aggregate two IPsec tunnels on the hub and configure the auto-discovery-sender enable on the phase2-interface (not possible on phase1-interface once you say it is an aggregate member). Problem is, on the Spokes, there is no auto-discovery-receiver enable option not even on the phase2-interface, therefore the tunnels are not coming up.
@JasonLeaman
@JasonLeaman 3 жыл бұрын
I've wanted to try a Fortinet firewall, but the licenses are expensive for a home lab :(
@reneereitel944
@reneereitel944 3 жыл бұрын
same here
@Mir_Aus
@Mir_Aus 3 жыл бұрын
Can someone help with fqdn as I need to learn to to acess PCs with host name instead of IP when using Vpn
@tj71tj71
@tj71tj71 3 жыл бұрын
I noticed the warning "Security Fabric Connection is disabled" but obviously you are running security fabric? I seem to recall full fabric needs a FortiAnalyzer, is that so and why if so?
@FortinetGuru
@FortinetGuru 3 жыл бұрын
To run the full security fabric you do need the analyzer in order for it to hold and do all of the correlations and data associations. Otherwise, the FortiGate can't hold enough data to maintain the database.
@TheDarrenSR
@TheDarrenSR 3 жыл бұрын
The last ports on all switches LAN devices should always be your uplink ports it is best practice really
@FortinetGuru
@FortinetGuru 3 жыл бұрын
It is how I like to do it. If you have a standard and it works and is repeatable ultimately it will work fine.
@nbctcp3450
@nbctcp3450 Жыл бұрын
in FortiSwitch how to set port to accept ip phone with VOICE vlan40 and DATA in vlan30 because switch port > ip phone > pc all connected to switch using 1 ethernet port
@SoulJah876
@SoulJah876 3 жыл бұрын
Is 6.4.6 considered stable now? I was considering upgrading from 6.2.1 to 6.2.8 on my 301E and 501E.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
I’m running 6.4.6 on most gear now
@SoulJah876
@SoulJah876 3 жыл бұрын
@@FortinetGuru Thanks for the feedback. I'll test it out.
@synchit1593
@synchit1593 3 жыл бұрын
We are using that on an 1100e, experience memory leak issues which does follow through till 7 and all fortinet support has advised is to kill wad proxy process… one of the worst support experience we have in a mixed vendor environment, no one else can take that crown..
@punkeyengineer
@punkeyengineer 2 жыл бұрын
what is a perimeter firewall ? please can someone answer me ! I have been hearing this word from so long, but still dont have a clue , whats a "perimeter" firewall
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Perimeter firewall, also known as the edge firewall. It provides security and such at the edge of a network going out to the world. ISFW (internal segmentation firewalls) provide more specific security services WITHIN the infrastructure (think along the lines of keeping accounting stuff only visible to them etc)
@NorrisCarden
@NorrisCarden 3 жыл бұрын
The AP on the FortiWiFi only has one radio, so can only run either 2.4ghz or 5ghz.
@zobs1234
@zobs1234 2 жыл бұрын
Depends on the model really. 40F/60F has single radio. 80F has 3 radios (2 to serve customer +1 scanning). There was also a 50e-2r model with 2radios, but it's probably eos now.
@germanvas63
@germanvas63 2 жыл бұрын
How can I contact you so I can ask for some advice? I’m in CA
@ruellerz
@ruellerz 2 жыл бұрын
I challenge your subnet and vlan design. The second octet should be the site identifier while the 3rd is for the VLAN ID. Maybe you said it wrong @ 12:20
@ruellerz
@ruellerz 2 жыл бұрын
You lose the ability to do any summary routes . Give a site /16 and slice it up
@harrylumsdon6773
@harrylumsdon6773 3 жыл бұрын
Any ideas on the fortiextenders?
@FortinetGuru
@FortinetGuru 3 жыл бұрын
They work ok. I only use them for failover
@harrylumsdon6773
@harrylumsdon6773 3 жыл бұрын
Us too. Horrible reboot issues, seem fixed after 2 SW updates. modems would disconnect, til poe reboot. sometimes 17 a day.
@danycontrerastorre87
@danycontrerastorre87 3 жыл бұрын
how to get a tshit like that ?
@smokeforless3071
@smokeforless3071 2 жыл бұрын
Hi any spare REG REF you could borrow me ? thanks
@anicetomorenojr6311
@anicetomorenojr6311 2 жыл бұрын
I currently have this... [FGT-61F]──(LAN-AGG (Fortilink))──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE]──(Ports 23+24Ports 9+10)──[FSW-108E-FPOE] I want to do this... ┌──(Ports A+BPorts 9+10)─────[FSW-108E-FPOE] [FGT-61F]──(LAN-AGG (Fortilink))─┤ └──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE] Is this possible with FortiLink split interface? Per the research I have done, things keep pointing to MCLAG but I don't want to complicate things. Any advice?
@jankockv
@jankockv 3 жыл бұрын
The UTP cable that's comes with the fortiSwitsh or FortiGate esa WHITE, NOT yellow
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Astute observation there sir.
@stage666
@stage666 Жыл бұрын
Do you work for fortinet?
@FortinetGuru
@FortinetGuru Жыл бұрын
Nope
@SR_EMM
@SR_EMM 3 жыл бұрын
Did you have a problem where Access Points Randomly disconnect from Controller? we have 2 networks of about 150 APs each and it happens all the time. Every week there is at least 5 Disconnected AP.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Negative. What version of code and what model of AP / Gate?
@Mrrtbrs
@Mrrtbrs 3 жыл бұрын
What FOS are you running on the FortiGate? What are your L2 Switches? any duplicate IP/DHCP Exhaustion? When then are "disconnected" can you ping/SSH etc to the devices?
@mosins5779
@mosins5779 3 жыл бұрын
The vedio is not clear my friend
@youtubegarbage4u
@youtubegarbage4u 2 жыл бұрын
you missed mikrotik!
@RaviChinasamy
@RaviChinasamy 3 жыл бұрын
First 😂
@vmened
@vmened 3 жыл бұрын
Mikrotik works better than fortinet)
@noah9341
@noah9341 3 жыл бұрын
Palo is better
@lesterawalt3184
@lesterawalt3184 3 жыл бұрын
That thing is junk and nothing but problems. I went back to Cisco stuff
@anonymoususer1367
@anonymoususer1367 3 жыл бұрын
What a shitty products. It is probably great for SOHO, but Fortinet has really weak IPS.
@friedrice7707
@friedrice7707 Жыл бұрын
I have the same Fortinet stack connecting my Fortigate to FortiSwtich via FortiLink Interface A and from FortiSwitch PoE connection to FortiAP 221E. Using the 7.2.4 firmware on FG & FS. But I am getting rid of FortiSwitch and ForiAP as the switch is highly unreliable when connecting via FortiLink. The Fortilink between the Fortigate and FortiSwitch will drop to 100mbps despite replacing with brand new Cat 6E cables. And the only way to resolve the issue was to hard reset the switch. After reset and re-established the FortiLink, the same cable that was reporting 100mbps suddenly becomes 1Gbps. But on and off the Fortigate will report the authorized FortiSwitch is Offline. And I had to hard reset, authorized the switch and everything become normal again. The FortiAP wifi performance also sucks as my client will complain about the slow speed when connected to it. I had checked all the configs and the thing is a Asus home AP is more reliable then the more expensive FAP. I am keeping the Fortigate as it's very reliable in my opinion. Already ordered Unifi switch and U6E AP to replace my FortiSwitch and FortiAP. Will be testing them together with Fortigate before deploying them to Production sites. Give up hopes for FortiSwitch and FortiAP. Sad.
FortiGate 60F HA Cluster Build
22:25
Fortinet Guru
Рет қаралды 49 М.
КАРМАНЧИК 2 СЕЗОН 7 СЕРИЯ ФИНАЛ
21:37
Inter Production
Рет қаралды 537 М.
아이스크림으로 체감되는 요즘 물가
00:16
진영민yeongmin
Рет қаралды 54 МЛН
Я нашел кто меня пранкует!
00:51
Аришнев
Рет қаралды 4,4 МЛН
FortiGate: Simple WAN Fail-Over
13:12
Fortinet Guru
Рет қаралды 44 М.
My Standard Network Architecture For Deployments
6:33
Fortinet Guru
Рет қаралды 10 М.
Best operating system for Servers in 2024
11:41
VirtualizationHowto
Рет қаралды 30 М.
Manage FortiAP with FortiGate (Wireless Controller)
6:37
ToThePoint Fortinet
Рет қаралды 28 М.
FortiSwitch FortiAP demo
55:12
Alex Pavlock
Рет қаралды 2,4 М.
FortiGate 7.0 - How to Add a Managed FortiSwitch
9:40
Imperion
Рет қаралды 32 М.
My FortiGate SDWAN Configuration and Some Use Cases
16:25
Fortinet Guru
Рет қаралды 51 М.
Common FortiSwitch Topologies: Ring and MCLAG
20:55
ToThePoint Fortinet
Рет қаралды 10 М.
FortiGate : 5 Admin Access Security Hardening Tips
9:38
Fortinet Guru
Рет қаралды 26 М.
КАРМАНЧИК 2 СЕЗОН 7 СЕРИЯ ФИНАЛ
21:37
Inter Production
Рет қаралды 537 М.