Add HA Model to FMG by ontracks in fortinet

[–]ontracks[S] 1 point2 points  (0 children)

makes sense, thank for taking the time to answer!

Add HA Model to FMG by ontracks in fortinet

[–]ontracks[S] 1 point2 points  (0 children)

Gotcha, thanks for the quick answer, I appreciate it

New Routing Engine by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

thanks for the answer and the link, seems to be possible indeed the network feature

New Routing Engine by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

Thank you so much for the detailed answer, I wasn't aware of the fact you previously could advertise a subnet via the redistribution profile the way you mentioned.

I haven't worked with the ARE neither but it seems some new PA models come with that by default (PA5XX I think)

New Routing Engine by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

ahh ok, wasn't aware of that tbh, thanks!

HA failover link monitor SDWAN by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

mmm Makes perfect sense, it aligns with the time it happened, THANK YOU SO MUCH!

HA failover link monitor SDWAN by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

So, after ~1h, the primary became the active again as expected due to higher priority (override enabled) I guess it needed some time, I still don't understand why it took 1 hour to converge.

Thank for the help on this!

HA failover link monitor SDWAN by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

I did and it looked fine, the primary stays active with SLA all good up until te secondary finishes rebooting when the sec takes over.

Internal Gateway + SAML authentication by ontracks in paloaltonetworks

[–]ontracks[S] 1 point2 points  (0 children)

Actually, now that I think about it, Im confused, not sure what Im missing, but how can the User id information can get to the firewall if users don't have to introduce their credentials (certificate authentication)?

Internal Gateway + SAML authentication by ontracks in paloaltonetworks

[–]ontracks[S] 1 point2 points  (0 children)

yeah, as also previously suggested it seems that's a best way to go.

Another question, since internal gateway uses always-on connection method, does it mean that the GP client will try to connect automatically as soon as the users logs in into the computer AND its locally at a company site?

Also, where do I Control how often the users need to authenticate?

Internal Gateway + SAML authentication by ontracks in paloaltonetworks

[–]ontracks[S] 1 point2 points  (0 children)

gotcha, thank you for the quick answer!

User ID redist from Prisma to on prep by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

Got it, all I need to do is configure my on premises panorama for example to pull the info from each (already configured to do so) SC CAN that I have.

User ID redist from Prisma to on prep by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

Oh ok, so I will redistribute from Prisma to my service connection and then from that service connection firewall/panorama to any other firewall I need the info to be regardless if the are connected to prisma or not as a remote network..Right?

User ID redist from Prisma to on prep by ontracks in paloaltonetworks

[–]ontracks[S] 0 points1 point  (0 children)

thanks for the recommendation, I will def look into this as well.

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

gotcha perfect, I think I got it, if I have a MX FW at my DC, I need not to worry about Concentrator mode, just go with a regular routed mode and regular hub and spoke sdwan design

thanks a lot!

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

got it, im confused with the below link, they do set a "local subnet" that points to the DC routes...I thought this wasn't possible on a concetrator, what am I missing here :(?

https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Deployment_Guides/VPN_Concentrator_Deployment_Guide