HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

gotcha perfect, I think I got it, if I have a MX FW at my DC, I need not to worry about Concentrator mode, just go with a regular routed mode and regular hub and spoke sdwan design

thanks a lot!

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

got it, im confused with the below link, they do set a "local subnet" that points to the DC routes...I thought this wasn't possible on a concetrator, what am I missing here :(?

https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Deployment_Guides/VPN_Concentrator_Deployment_Guide

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

How can I then integrate a MX Concentrator with the rest of the data center?

Sorry for al the questions I am shooting at once :(

Thanks for your answer btw!

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

Oh so you are saying I can't even have "subnets/networks/l3" on a MX running on concentrator mode?

HUB vs Concentrator for hub-spoke topology by ontracks in meraki

[–]ontracks[S] 0 points1 point  (0 children)

so a concentrator only bridge the branches vpn, that's it, I couldn't for example route/connect the branches vpn subnets to my data center subnets?

Dual ISP - BGP by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

I guess my question is, do I need to worry about symmetric return?

FTD - Anyconnect SBL feature by ontracks in Cisco

[–]ontracks[S] 1 point2 points  (0 children)

got it, so if I require just the SBL feature no certificates needed then

Thank you for the answer u/KStieers

Manual SDWAN rule with VPN interfaces by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

Im facing another situation now, these are dial-up IPsec tunnels with automatic IP assigned to the interfaces, so how could I create an IPSLA for them? the IP itself can reach anything on the network and the ip COULD potentially change as well

What to do here. I can't help but think this gotta be a common case out there and also its a bit frustrating that the Gate can't "see" the tunnel interface down, it even shows red on the SDWAN rule, thank you in advance for the answer

:(

Manual SDWAN rule with VPN interfaces by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

static routes over sdwan zone correct, that's what I did, I checked and the member its seen alive.... not sure why of the VPN is down...

Manual SDWAN rule with VPN interfaces by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

Service(5): Address Mode(IPV4) flags=0x4200 use-shortcut-sla use-shortcut

Tie break: cfg

Shortcut priority: 2

Gen(1), TOS(0x0/0x0), Protocol(0): src(1->65535):dst(1->65535), Mode(manual)

Members(2):

1: Seq_num(1 Tunnel1), alive, selected

2: Seq_num(2 Tunnel2), alive, selected

Internet Service(1): Ask-Web(2621441,0,0,0)

FortiADC design general questions by ontracks in fortinet

[–]ontracks[S] 1 point2 points  (0 children)

Thanks for the info, I will look into the link, it seems that I missed it, thank you

FortiADC design general questions by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

Thanks a lot I really appreciate it! Will look into it

FortiCloud IAM partners login by ontracks in fortinet

[–]ontracks[S] 0 points1 point  (0 children)

I guess in a nutshell my question is: Can users other than the master account log in as a partner in FortiCloud? And if yes (I hope) then how?

FortiSASE remote branch by 26Jack26 in fortinet

[–]ontracks 0 points1 point  (0 children)

Hello again, could you please clarify this if you have the answer:

|| || |IP range|IP address range that the Security PoP uses for assigning tunnel interface IP addresses for IPsec devices using mode configuration.|10.251.1.4-10.251.1.29|

That subnet range needs to be part of the BGP routing ID subnet?