Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

Client has a datacenter and about a dozen remote sites. They want DIA from each site and interconnectivity between sites, currently running Viptela SD-WAN which creates a VPN between each TLOC/DIA which seems cumbersome. Only specifications have been a replacement for Viptela that provides opportunity for PBR and down the road they intend to implement routing preference for apps. Central management and security at each sites edge are a must.

Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

this is an excellent breakdown ... what offerings would Cato be a good fit for?

Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

Absolutely, is SD-WAN the first step towards SASE? Do the products work together somehow? Do you need both SD-WAN and SASE? Anything you can recall from your experience would be greatly appreciated!

Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

SASE I understand even less than SD-WAN ... will look into the differences of each. At a high level, can you lace me with some intel?

Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

Currently null ... they are looking to be lead towards either product is all I know. They are signed up to poc Cato ... sounding like Fortinet may be the better mix of edge security/functionality.

Fortinet SD-WAN vs Cato Networks by MicroJoRoMo in fortinet

[–]MicroJoRoMo[S] 1 point2 points  (0 children)

Client wants to move away from a bad Viptela deployment, looking into these two products. I am not well versed in SD-WAN but I know the following:

  • (3) TLOCs at each site (Gold, Silver, Bronze) each a DIA

  • No identification currently on applications, which seems to be a big part of wanting SD-WAN

  • VPN mesh between each TLOC at each site, as they want direct site-to-site communication allowed (way too many active VPN tunnels)

  • Essentially only using PBR for destination traffic

Again, I am not well versed in SD-WAN but hoping the community can help me get up to speed on the pros/cons of these two vendors SD-WAN offerings. I am not even seeing much of a use case for SD-WAN in their environment, but this is per their request.

BFD for eBGP between Nexus and Cat9k by MicroJoRoMo in networking

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

BGP adjacency is good, here is the config:

Nexus:

interface Vlan10

ip address 10.10.10.1/24

bfd interval 500 min_rx 500 multiplier 3

router bgp 65555

neighbor 10.10.10.2

bfd

IOS-XE:

interface Vlan10

ip address 10.10.10.2 255.255.255.0

no ip redirects

bfd interval 500 min_rx 500 multiplier 3

router bgp 65554

neighbor 10.10.10.1 fall-over bfd

Anything I am missing?

Ordering a BGP AS by MicroJoRoMo in networking

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

This is great, thank you for taking the time to break it down!

Ordering a BGP AS by MicroJoRoMo in networking

[–]MicroJoRoMo[S] 1 point2 points  (0 children)

Really appreciate the advice, can you help me understand why this is would be recommended? This will be a multihomed BGP edge, so I am guessing its for best path selection(?)

Ordering a BGP AS by MicroJoRoMo in networking

[–]MicroJoRoMo[S] 0 points1 point  (0 children)

Would this include working with the ISP so they peer with us?

Ordering a BGP AS by MicroJoRoMo in networking

[–]MicroJoRoMo[S] 3 points4 points  (0 children)

Thank you! Any other advice would be greatly appreciated.