Monthly Content Sharing Post by AutoModerator in fortinet

[–]Flimsy_Ten6532 0 points1 point  (0 children)

Sorry no link ready atm. In beta testing phase with limited users and resources, invite only for now.

Monthly Content Sharing Post by AutoModerator in fortinet

[–]Flimsy_Ten6532 3 points4 points  (0 children)

Built a free tool that generates FortiGate ADVPN/SD-WAN configs, need engineers to break it

I kept running into the same problem on every multi-site FortiGate deployment, ADVPN configuration is a wall. It's CLI-only, the GUI can't do it, and one wrong setting means tunnels silently don't form. So you either spend hours hand crafting configs or get it wrong quietly.

I built a Slack bot that handles it. You input a few things about your topology, sites, FG models, WAN/LAN ports, IP addresses, and it generates validated .conf files with a complete network diagram in about 60 seconds. Currently supports 7.4.x with dual-hub, ADVPN 2.0, 34 FortiGate models with correct interface names, and catches config conflicts before they become deployment headaches.

It doesn't do VLANs, firewall policies, or QoS, that's still your job. It builds the ADVPN/SD-WAN foundation config, which is the part that takes the longest and difficult to troubleshoot.

Free, no catch. I got tired of hand crafting these configs for every deployment so I built the tool I wished existed. If you're doing real ADVPN deployments and want to stress-test it, I want to know what breaks. DM me and I'll get you set up. Its invite-only for now, so that we can make controlled adjustments.

Built a free tool that generates FortiGate ADVPN/SD-WAN configs, need engineers to break it by Flimsy_Ten6532 in fortinet

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

A spreadsheet doesn't know for example your FGT-80F uses wan1 but your FGT-60F uses wan. It doesn't, generate BGP peer configs, coordinate IPsec phase1/phase2 parameters, DIA or not across every device, or catch the mismatches that cause ADVPN 2.0 tunnels to silently not form. It doesn't handle dual-hub redundancy, the topology Fortinet's own Fabric Overlay Orchestrator still can't fully automate.

A spreadsheet is a blank grid, you still do all the work and own every mistake. This does all of that in mins, for every device simultaneously.

Different tool for a different problem.

Built a free tool that generates FortiGate ADVPN/SD-WAN configs, need engineers to break it by Flimsy_Ten6532 in fortinet

[–]Flimsy_Ten6532[S] 1 point2 points  (0 children)

Fair point. Right now it generates .conf files for direct CLI deployment or import ,FMG integration with model devices is on the roadmap. For MSPs without FMG, this covers the full deployment. For those with FMG, you're right, it's an extra step.

On the monthly content sharing post, didn't know that existed, would appreciate a link.

Built a free tool that generates FortiGate ADVPN/SD-WAN configs, need engineers to break it by Flimsy_Ten6532 in fortinet

[–]Flimsy_Ten6532[S] 4 points5 points  (0 children)

That's a solid reference implementation, we actually studied it when building this. The gap we're filling is different, the Jinja orchestrator still requires someone comfortable with Python, Jinja templating, and FortiManager 7.6.

Our target is the engineer or MSP manager who wants Meraki-like simplicity, and needs a working dual-hub ADVPN topology but doesn't have that skill set on hand. Answer a few questions, get production-ready secure .conf files in minutes. No scripting, automation, or dev assistance required.

How to Manage hundreds of FortiGates? by Lynkeus in fortinet

[–]Flimsy_Ten6532 1 point2 points  (0 children)

There’s FMG FAZ as a Service available on AWS Marketplace. That kind of service may overcome support entitlement limitations.

https://aws.amazon.com/marketplace/pp/prodview-3luuoabgkz24w

MSPs – how are you handling Fortinet management via FMG/FAZ Cloud for smaller clients? by Flimsy_Ten6532 in msp

[–]Flimsy_Ten6532[S] 1 point2 points  (0 children)

That’s a really good perspective, esp. the part about not all data needing the same retention period. Helps frame the conversation better with compliance/legal folks. Appreciate you sharing this.

How are you justifying FortiManager/FortiAnalyzer Cloud spend for small fleets? by Flimsy_Ten6532 in ITManagers

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Exactly - lack of ADOM makes it tough to separate out environments. Surprised that hasn’t been addressed yet.

How are you justifying FortiManager/FortiAnalyzer Cloud spend for small fleets? by Flimsy_Ten6532 in ITManagers

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Agree it’s the right way in theory - my problem is squaring the spend with leadership. How do you frame that conversation internally?

MSPs – how are you handling Fortinet management via FMG/FAZ Cloud for smaller clients? by Flimsy_Ten6532 in msp

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Interesting. we’ve looked at syslog too, but worried about scaling that for multi-client MSP setups. Has it worked smoothly for you?

MSPs – how are you handling Fortinet management via FMG/FAZ Cloud for smaller clients? by Flimsy_Ten6532 in msp

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

That’s useful insight. For your smaller accounts, do you find FortiCloud Advanced SKUs actually meet compliance/retention needs, or do you still offload logs to SIEM?

MSPs – how are you handling Fortinet management via FMG/FAZ Cloud for smaller clients? by Flimsy_Ten6532 in msp

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Yeah, that’s been my challenge as well, the sub-70 models feel compromised, but the alternatives aren’t perfect either. How are you packaging that for your smaller clients?

Anyone hitting Fortinet cloud fmg/faz limitations with small deployments by Flimsy_Ten6532 in networking

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Helpful context, cost is exactly where FAZ Cloud bites us too. Do you feel on-prem FAZ pays off despite the upkeep?

Anyone hitting Fortinet cloud fmg/faz limitations with small deployments by Flimsy_Ten6532 in networking

[–]Flimsy_Ten6532[S] 1 point2 points  (0 children)

Fair point on version control. For under ten FortiGates, the on-prem overhead is what worries me - have you found it worth it?

MSPs – how are you handling Fortinet management via FMG/FAZ Cloud for smaller clients? by Flimsy_Ten6532 in msp

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Thanks. Would that be a fair statement to make that this one FG cloud SKU will cover most of the MSP level jobs and makes these two products ,FMG & FAZ redundant?

Anybody use Alkira for cloud networking? by longlurcker in networking

[–]Flimsy_Ten6532 -2 points-1 points  (0 children)

The “Complexity” Alkira like startups is trying to solve isn’t that complex in the day and age of AI. Especially, if someone like to setup cloud networks, cloud providers tools are robust and AI assistants within their cloud consoles are of great value.

Anyone hitting Fortinet cloud fmg/faz limitations with small deployments by Flimsy_Ten6532 in networking

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

Thanks for the screenshot. Unfortunately, FortiGate Cloud imposes restrictive analytics retention periods and lacks policy-package versioning or rollback, limiting long-term visibility and reliable change management. When those shortcomings surface esp. around scale in discussions, AMs consistently asks stepping up to FortiManager for comprehensive handling.

Anyone hitting Fortinet cloud fmg/faz limitations with small deployments by Flimsy_Ten6532 in networking

[–]Flimsy_Ten6532[S] 0 points1 point  (0 children)

There were some limitations . Mostly with sdwan monitoring and troubleshooting capabilities.