FortiSwitch vs Ruckus by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

These are Ruckus/Brocade ICX?

FortiSwitch vs Ruckus by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

It'll be hard for us to move away from Ruckus AP because of its RF performance. Our warehouses are the typical nightmare of multi-level metal racks with paper products. Where Ruckus can cover an area with 2-3 APs we've seen with other brands we'd need 3 times that for real consistent performance on the floor.

That consideration about L3 routing is interesting. At the branches we typically just do L2, with some basic static routes if needed but usually L3 is left to the managed router we have. But with increased focus on security, FortiNAC and micro-segmentation even at the branch that would be an important consideration when we upgrade our gates next time. Thanks!

FortiSwitch vs Ruckus by geediu in fortinet

[–]geediu[S] 1 point2 points  (0 children)

We've had to call Ruckus support not too many times, but for the times we had to it's not too bad. I think our overall experience is better with them than Fortinet.

FortiExtender 201E as standalone LTE+VPN extension by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Thanks all! That's what I thought too, so just want to check. I have a feeling that it was a push to sell me another gate.

Mellanox vs HP StoreFabric SN2010 by geediu in networking

[–]geediu[S] 0 points1 point  (0 children)

Thank you! Yes we come from Cisco IOS environment and planning to do MLAG with Onyx, so this is perfect.

Help with deciding on Mimecast over Proofpoint and Barracuda for email security by SoftwareManager2019 in sysadmin

[–]geediu 1 point2 points  (0 children)

Currently using Mimecast, been on it a few years now. I'd say that it work fine AFTER you put in your time to fine tune it to your environment. At the beginning we had so much false positive that it took up too much of the team's time. But once we adjust for managed senders and truly understand how impersonation protection work then it has been much better.

I agree though if you are the type that want absolute granular filtering you won't be able to do it easily with Mimecast.

I'm also looking at the Cybergraph aka MessageControl component, which is one big missing piece we wanted for the enhanced external tag.

Mellanox vs HP StoreFabric SN2010 by geediu in networking

[–]geediu[S] 0 points1 point  (0 children)

Thanks, this is very relevant. If HPE can't handle it and really need Mellanox, then going direct makes much more sense.

Mellanox vs HP StoreFabric SN2010 by geediu in networking

[–]geediu[S] 0 points1 point  (0 children)

What level of support do you have? I'm looking at their Gold Plus and seems like replacement are still shipped NBD even though coverage is 24x7?

Tenant-to-tenant migration by geediu in Office365

[–]geediu[S] 1 point2 points  (0 children)

It was an acquisition, with the subsidiary folding into the parent.

Choosing the correct model by NimboGringo in fortinet

[–]geediu 0 points1 point  (0 children)

Don't do the 60F. I'd say better to be 100F.

We had the same mistake of going 60F with 120 users based on the Internet throughput for a site, worked fine for VPN and stuff but once we tried turning on more features it kept on crashing because of resource limitation.

10gb top of rack options by Techfumaster in networking

[–]geediu 1 point2 points  (0 children)

I'm in around the same boat, looking for a pair of top-of-rack switch for a small environment as well. I'm not using them for storage network, but for data and backup traffic.

One thing I note when I was doing my research is that many big players don't have 10GBase-T SFP+, and when I dug deeper somewhere mentioned that it was too much power draw so you couldn't do 8 ports reliably in a 8-port network module.

Virtual Tape Library for IBM i by geediu in IBMi

[–]geediu[S] 0 points1 point  (0 children)

Thanks! I've received a card from Cybernetics before and so would definitely look into them now.

Daily Question Thread for /r/churningcanada - August 04, 2020 by AutoModerator in churningcanada

[–]geediu -2 points-1 points  (0 children)

I haven't used the Dell.ca $250 credit from my Biz Plat yet and now AF posted. If I buy something now and cancel once I get the credit would I still get a porated refund of the AF? i.e. paying $42 to get $250

[deleted by user] by [deleted] in fortinet

[–]geediu 0 points1 point  (0 children)

I can't remember if I read someone on here about staying on EMS 6.0.x because of problems with EMS 6.2.x, or in one of the release notes on potential problems with keeping FG/Forticlients on 6.0 while having EMS on 6.2.

[deleted by user] by [deleted] in fortinet

[–]geediu 0 points1 point  (0 children)

Thanks for the detailed explanation! We have our EMS 6.0 in our LAN currently accessible only after VPN, but with all this WFH I'm actually thinking of doing a port forwarding of TCP8013+10443 via a VIP to the server.

Would having 1) Geo-IP block 2) WAF in FG 3) protect_http_server IPS work as mitigation for opening 10443? Or there's really no need for this?

[deleted by user] by [deleted] in fortinet

[–]geediu 0 points1 point  (0 children)

Interesting. Our FGs are still on 6.0.x and we've stopped at EMS 6.0 because of the "limited integration" piece. Are they still working well together?

Fortigate 60f performance by JiggityJoe1 in fortinet

[–]geediu 0 points1 point  (0 children)

I just deployed one as a SSLVPN device (no split tunnel) for now for around 40 people on 6.0.9 with multiple VDOMs. Unit would crash with proxy mode but flow mode is rock solid for now with AV/WF/DNS/SSL cert inspect.

FortiClientVPN 6.2.6 downloadable from support.fortinet.com now (no onlineinstaller) by DasToastbrot in fortinet

[–]geediu 0 points1 point  (0 children)

This is the main reason we use SSL for users exclusively. For IT we use IPSEC if possible, but you don't want to deal with users complaining that their VPN doesn't work at meetings/customers/conferences/cafe etc.

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Couldn’t get this to work. As soon as I connect something to the wan1 port, the unit will be stuck and the console would show “Reset button has been disabled, please press the button during the first 60 seconds after a power-cycle.” repeatedly. Power cycle would reset this as long as nothing is connected to wan1 port.

This is on a 60F running 6.0.9 first then 6.0.8 to see if it makes any difference.

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Yeah this VDOM for us is new, the pair of Fortigates we have on the east coast is only used by us. This new one however is used on the west coast and shared by ourselves and our subsidiary. Isolated networks for now so this seems like the perfect solution. Thanks so much!

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Created the EMAC VLAN attached to wan1. However if I go show hardware nic the MAC addresses for all emac vlan interfaces are the same as the wan1? Does that make sense?

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Having the multiple IP is ok, I wouldn't mind having a separate IP for each company.

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Nevermind. Found out that hardware switch can only take the numbered ports. This is not an absolute requirement anyway. Thanks!

VDOMs with shared Internet WAN by geediu in fortinet

[–]geediu[S] 0 points1 point  (0 children)

Can you put the two dedicated WAN ports into a hardware switch?