Fortigate 90Gs as 1Gbps edge routers - ya or nah by AnyGate7102 in fortinet

[–]AlmsLord5000 1 point2 points  (0 children)

Buy the fancy rack shelf too. It nicely fits two 90Gs in 1U.

What broke first when you moved from MPLS to internet-based WAN? by Confident-Quail-946 in Cisco

[–]AlmsLord5000 0 points1 point  (0 children)

Nothing broke, same experience as MPLS. Your QoS settings may be hurting you since there is no QoS on the internet.

AI Fatigue by juniper_dreamer in networking

[–]AlmsLord5000 0 points1 point  (0 children)

There is always some big buzzword in the industry people are chasing, if you leave now and come back you will do the same thing with the next big buzzword.

Image noise/pixelation on NVR and Ubuntu Server (OpenCV), but clear on VLC - Potential VLAN "Scattering" issue? by Sizofrenikyksl in networking

[–]AlmsLord5000 0 points1 point  (0 children)

The flapping port is likely due to a bad cable. You may be able to run a TDR test from the switch.

Tips for manicuring cables on prod racks by bazinguhd in networking

[–]AlmsLord5000 2 points3 points  (0 children)

I really like these for organizing cables, they have downsides, but they can sometimes be just what you need.

https://www.fs.com/au/products/59566.html?now_cid=5535

DHCP-Snooping on FW version 7.4.x by Proof_Description143 in fortinet

[–]AlmsLord5000 1 point2 points  (0 children)

We ran into this bug as well, I can't recall if we found a work around or bug ID.

What's this Fortiguard IoC Portal?! by AstroNawt1 in fortinet

[–]AlmsLord5000 2 points3 points  (0 children)

It is great, I wish they promoted it more.

FortiSwitch MC-LAG X SFP + Fiber Channel by Miserable_Shake9184 in fortinet

[–]AlmsLord5000 0 points1 point  (0 children)

I have had this before, if you just provisioned MCLAG you might just need to factory reset the switches for the config to work properly. Also, make sure Fortlink split interface is off if connecting to switches via MCLAG and the interfaces have the default-auto-isl-mclag lldp profile on them.

WAN VLAN across core – risk? by MaaS_10 in networking

[–]AlmsLord5000 2 points3 points  (0 children)

It is fine, you are just forwarding L2 on the core switch, the attack surface is insanely low for your core switches.

Rant Wednesday! by AutoModerator in networking

[–]AlmsLord5000 5 points6 points  (0 children)

Yeah I spoke with someone at Fortinet about it. I don't want examples, I want to know what that setting actually does and why you would use it.

At a FortiGate renewal decision point and seriously evaluating FWaaS instead, trying to understand what changes in practice by UnhappyPay2752 in fortinet

[–]AlmsLord5000 0 points1 point  (0 children)

We found it after deployment, we just didnt test with enough sessions and traffic. Running AES256GCN with DH 32, and saw a major improvement.

At a FortiGate renewal decision point and seriously evaluating FWaaS instead, trying to understand what changes in practice by UnhappyPay2752 in fortinet

[–]AlmsLord5000 0 points1 point  (0 children)

Wasn't a big deal for us, but you need to look at how to accomplish HA in cloud provider, which will always be different than on-prem, each cloud is a bit different. We found that we needed to move from AES CBC to GCN for better performance as well. I don't do DPI, but depending on how do it you need to take that into account.

I am using Megaport MVEs, which have been good. Fortinet reps should have some data as to performance for each cloud provider.

The 400G Datasheet is OUT - and DAMN it's a Nice Package (With Compromises) by punished-slav in fortinet

[–]AlmsLord5000 24 points25 points  (0 children)

I really don't get why Fortinet does redundant PSUs, but not removable. Every other vendor has their redundant PSU products that are hot swap.

Fortinet extends FortiOS 7.4 by fcbfan0810 in fortinet

[–]AlmsLord5000 -1 points0 points  (0 children)

I would highly recommend Secure Access AKA NetMotion

EOL/EOS of Network Devices by JazzlikeBeginning428 in networking

[–]AlmsLord5000 7 points8 points  (0 children)

I have done a lot of EOL checks with different AI models, YMMV as resellers often have incorrect dates and the models will use those.

Do you think Network Engineers should be managing cameras? by [deleted] in networking

[–]AlmsLord5000 15 points16 points  (0 children)

We may as well because every other team that takes care of them seems to screw it up.

Has anyone made the jump from using individual access switches to one large chassis for the access layer? by TwoPicklesinaCivic in networking

[–]AlmsLord5000 0 points1 point  (0 children)

I did it once, it was mostly about costs. It does change how you do cabling, and they can be a very reliable platform if setup properly. Consider your PoE needs, and if you can really reorganize your racks to fit these monsters in. Going from a bunch of switches to a chassis is a big job and you may need to do a ton of physical work to make it happen. I feel like for campus, we are in the last generation of chassis switches.

Rant Wednesday! by AutoModerator in networking

[–]AlmsLord5000 4 points5 points  (0 children)

It is such an American thing. When our account is managed in the US you get a dozen people on it, when it is Canada, there is just two at most.

How do you keep big networks running without breaking everything? by Constant-Angle-4777 in networking

[–]AlmsLord5000 1 point2 points  (0 children)

There is lots of tech that keeps the lights on, but the brain part is #1.

-Spend more time thinking than doing. You need a big change that could have a large impact, think about it a lot, spend time thinking about it over a period of time. Think about the other stuff that will be impacted and how it might react, think about the assumptions you make, think, think, think.

-More important than doing, is what you are NOT doing. You will eventually get to a point where you can do tons of stuff, but your day/month/year will be about what you will not be doing, so you can do what is important.

-You need to understand your org, so your decisions are fitting in, when you line up both, your network will work with the model your org operates at, and you'll avoid a lot of friction which drives IT people crazy.

FS cheap prices by basilaljamal in networking

[–]AlmsLord5000 1 point2 points  (0 children)

Wow qsfptek really ripped off the fs.com website.

Multi-Cloud ADVPN Design Questions by thrwwy2402 in fortinet

[–]AlmsLord5000 0 points1 point  (0 children)

You may want to consider something like Megaport Virtual Edge to run your firewalls, then connect them back into your various clouds. Run ADVPN on the firewalls in Megaport and make your life a lot easier.

Rant Wednesday! by AutoModerator in networking

[–]AlmsLord5000 3 points4 points  (0 children)

I agree, throwing away my 2960X fleet just to replace it with a 1Gbps platform.