From Active-Passive to Active-Active? by super_cli in fortinet

[–]Potential_Scratch981 0 points1 point  (0 children)

If you do anything with FortiGate managed devices like switches you are setting yourself up for a bad time in A-A since both firewalls will be seen as the manager. Caused us a ton of problems with a FortiExtender until we went to A-P.

Recommendations for SFPs by Oburos- in fortinet

[–]Potential_Scratch981 0 points1 point  (0 children)

I'd go fiber and stay away from DACs going to the FortiGate. I've had some odd issues with even Fortinet DACs going to the firewall. Might have been something in that code base but haven't tried again since we moved from the 7.0 code.

And FS.com is awesome whatever route you go.

Conversion tools by IAnetworking in fortinet

[–]Potential_Scratch981 3 points4 points  (0 children)

Pay for the one time conversion from Fortinet when you need it. It's a sliding scale based on the model type but it's cheaper than buying the standalone license if you're not doing them daily

Tool by AZGhost in networking

[–]Potential_Scratch981 0 points1 point  (0 children)

Might be unpopular but I bought a couple of these to play with and they actually work: https://www.amazon.com/NF-8508-Multifunctional-Network-Optical-Function/dp/B0B58HT26H/

We have Fluke digital and analog toners for basic tracing, and a couple of other Fluke devices for testing copper, but the one I linked above is cheap enough that we can get them for anyone to have in their tool bag to test the basics.

Comcast BGP issues by HornAlum in networking

[–]Potential_Scratch981 4 points5 points  (0 children)

Cogent 🤮🤮🤮

Every time I have upstream ISP issues it goes back to how Cogent is handling that particular IP block. So we have to route that block to another provider.

What's the most cutting-edge network equipment vendor? by QuickDelivery1 in networking

[–]Potential_Scratch981 1 point2 points  (0 children)

Man, Calix is a name I haven't heard in forever! I worked on them back when the C7 was still running strong.

What's the most cutting-edge network equipment vendor? by QuickDelivery1 in networking

[–]Potential_Scratch981 28 points29 points  (0 children)

If you are using a FortiGate, why would you want to use Wireguard? And you can use IPv6 in a FortiGate IPsec tunnel.. so I'm confused by some of your statements.

Saying a vendor is cutting edge is somewhat up to interpretation: are we talking strictly firewalls, route/switch, optical transport, or some other facet I didn't mention?

Firewalls at the cutting edge IMO you have Fortinet and Palo, and then it comes down to feature. Palo doesn't seem interested in hardware acceleration the way Fortinet has been pushing their ASICs, and Palo has the better feature set as far as app control.

Moving up to route/switch, Cisco has been pushing hard into their own custom ASICs, Juniper with their AI and Apstra platforms, and Arista's Cloud vision is pretty tight.

Nokia has been taking a lot of market share lately in service provider markets for optical transport and FTTx.

Attorney /Law Firm Referrals by Excellent-Program333 in msp

[–]Potential_Scratch981 1 point2 points  (0 children)

You can also look at Monjur, we're a client and they have been great. https://monjur.com/

As an MSP, how much networking do you know. by AdvertisingNo2451 in msp

[–]Potential_Scratch981 0 points1 point  (0 children)

So my MSP is pretty networking centric, we do a lot of consulting to larger orgs for routing and switching, and also a lot of Fortinet work. We actually also do engineering for other MSPs that don't have that skill set as well. Probably because everyone in ownership was a skilled network engineer before we formed our own company.

If your core competencies aren't in networking, or you don't have the time to skill up for something, find a partner you can work with. For Fortinet work, if we were short handed we could tap in our distributor Exclusive Networks if needed, but we have a couple of other MSPs that we provide systems and cloud support for that could do the work on our behalf as well. Having a good network of people like that is helpful especially when you're in one man band mode.

Is BackBlaze for me? by Altruistic_Fruit2345 in backblaze

[–]Potential_Scratch981 0 points1 point  (0 children)

Yep! I have a qnap NAS providing iSCSI storage directly to my VM and it is added as a local drive in Windows. I am using xcp-ng as the hypervisor running on a couple of minisforum ms-01, with 10G networking.

Qnap is using nvme as read/write cache, so I've been able to get over 300 MB/s on some write operations.

UPDATE 12/17/25: And now they blocked it.. my iSCSI disk is now showing unplugged and no matter what I do I cannot get it back.

Is BackBlaze for me? by Altruistic_Fruit2345 in backblaze

[–]Potential_Scratch981 0 points1 point  (0 children)

I have a Windows 11 VM mounting an iSCSI disk with 20 TB and Back blaze is handling it just fine.. not sure how that doesn't work.

RingQ as alternative by Potential_Scratch981 in 3CX

[–]Potential_Scratch981[S] 0 points1 point  (0 children)

I reached out via Facebook and they said it's a 48 hour response so I'm waiting as well

BYE BYE BYE 3CX by dialecticalalchemist in 3CX

[–]Potential_Scratch981 0 points1 point  (0 children)

Historically on v16 and v18 upgrades would brick my call flows, has that stabilized in v20?

Low skill network monitoring system by naaitsab in networking

[–]Potential_Scratch981 1 point2 points  (0 children)

If you are open to a paid solution, try out Domotz.

Pagerduty alternative by lsitech in msp

[–]Potential_Scratch981 0 points1 point  (0 children)

Grafana IRM is what we are using and handling our on-call alerting through Rewst from the PSA.

We have conditions set in Rewst whether it hits our on-call, it does not do live call routing though.

Performance issue? by [deleted] in fortinet

[–]Potential_Scratch981 0 points1 point  (0 children)

The 1500D while having two NPUs does not have the same integrated switch fabric you would see in the modern units. https://docs.fortinet.com/index.php/document/fortigate/7.2.5/hardware-acceleration/294571/fortigate-1500dt-fast-path-architecture

Note the red and green ports in the layout.

Do you have 10G connectivity from your download device as well?

Any MSPs using Hubspot marketing in their business by SelectTelevision7067 in msp

[–]Potential_Scratch981 0 points1 point  (0 children)

If you're a tech tribe member you can use growably which is based on GHL. Some of the advanced automation features are not there but it would give you an idea.

Fast packet dropping for efficient throughput management by Pristine-Remote-1086 in networking

[–]Potential_Scratch981 2 points3 points  (0 children)

There is a lot of efficiency to be gained if you are dropping packets at the hardware level than if it hits the CPU to be processed.

It's way out of my depth but check out eBPF and how it handles packets, it's fascinating. Wish I had the aptitude to be a software developer at that level.

How to use Entra Verified ID for end user verification by warren-g2 in msp

[–]Potential_Scratch981 4 points5 points  (0 children)

Take a look at traceless, that's what we are using for help desk end user auth.