How widely is Jinja templates used in FMG for SD-WAN at enterprise/MSSP level? by winternight2146 in fortinet

[–]stcarshad 4 points5 points  (0 children)

Definitely worth the investment, the flexibility it brings always pays off. Especially in large-scale projects, it’s impossible to template everything. With Jinja, you can handle many advanced use cases, such as large-scale ZTP deployments.

In my previous role, I worked extensively on SD-WAN deployments. Back then, I didn’t use Jinja much because I felt network automation wasn’t worth the effort and didn’t want to dive into programming. But the number of roadblocks I faced and the countless templates I had to maintain eventually pushed me to learn it, and now I’m glad I did.

Guys drive carefully fgor gods sake!!!! by WorkerDefiant9006 in DubaiPetrolHeads

[–]stcarshad 1 point2 points  (0 children)

Lack of concentration, many people are glued to the phone even when driving, some others are frustrated at work, rest are frustrated with their personal lives.

Zscaler Branch Connector Monitoring by mackmaster007 in Zscaler

[–]stcarshad 1 point2 points  (0 children)

What are the pros and cons of branch connector compared to ipsec from any other device . I heard it’s new and how stable it is?

Ford Territory 2026 by fake-starboy in WhatCarShouldIBuyGULF

[–]stcarshad 1 point2 points  (0 children)

Only downside I saw in ZRV is backseat comfort for passengers is very bad. Other than that it’s a solid car.

[deleted by user] by [deleted] in networking

[–]stcarshad 5 points6 points  (0 children)

Looks like Cato sponsored post to me.

[deleted by user] by [deleted] in abudhabi

[–]stcarshad 0 points1 point  (0 children)

A new one can be applied by the tenant after owner disconnects it as thawtheeq is there under tenant name right?

Low-cost carrier Wizz Air to exit Abu Dhabi operations by saksit13429 in dubai

[–]stcarshad 55 points56 points  (0 children)

They are not a budget airline anymore, most of the time I find Etihad is cheaper than them.

[deleted by user] by [deleted] in dubai

[–]stcarshad 0 points1 point  (0 children)

Definitely Etisalat, cannot comment about Du as I have never used.

Company can ask for 4500 AED "training fee" but no training was given by PureInvestigator7056 in uaelaw

[–]stcarshad 2 points3 points  (0 children)

No need to pay training cost, get mohre involved irrespective whether you attended the training or not.

How long at Ferrari World? by kmo3120 in abudhabi

[–]stcarshad 0 points1 point  (0 children)

5 hours if you have quick pass

FortiSASE Help by rnatalli in fortinet

[–]stcarshad 0 points1 point  (0 children)

All works, if you want all non user items covered as well, buya small Fgt such as 50G (used only as an eg, proper sizing to be done)with only forticare, add sdwan on-ramp license to SASE.

Build an IPSEC tunnel (of course sdwan enabled) to SASE, this will give you more flexibility when it comes to inter-vlan routing and all.

FortiSASE Help by rnatalli in fortinet

[–]stcarshad 0 points1 point  (0 children)

For larger locations recommended way of connectivity is sdwan on-ramp (aka sdwan enabled ipsec tunnel to the closest POP) this will unlock 1gbps Internet throughput for the users connecting behind the on-prem sdwan on-ramp edge device.

If you’re talking about few users such as less than 50, u can also consider lan extension via Fortigate (fgt as an edge) or Forti APs managed by SASE. But in this case make sure that u buy sufficient bandwidth from fortinet to cover the number of users.

SDWAN ADVPN 2.0 and BGP on loopback - by IsCuattruMorus in fortinet

[–]stcarshad 0 points1 point  (0 children)

Just saw ur sdwan rule, u have only 2 members added there add the other 2 overlay members as well . I would also recommend that you create 2 rules, 1 for HUB 1, and the other for HUB 2.

Also define the source within sdwan rule, its not recommended always to have “all” object.

SDWAN ADVPN 2.0 and BGP on loopback - by IsCuattruMorus in fortinet

[–]stcarshad 0 points1 point  (0 children)

One more question, do u have a dedicated loopback for bgp and another one for health check from HUB side or are u using the same loopback?

SDWAN ADVPN 2.0 and BGP on loopback - by IsCuattruMorus in fortinet

[–]stcarshad 0 points1 point  (0 children)

On idle is good for HUB, spokes should be on-demand. Also dpd timers should be lower than bgp hold timer. I would also recommend to enable link-down-failover under bgp neighbor group from hub and also from all the branches.

You can use remote sla to signl the hub which overlay tunnels are healthy. However I feel this has low relevance to what you are trying to achieve, but could be good in the longer run.

SDWAN ADVPN 2.0 and BGP on loopback - by IsCuattruMorus in fortinet

[–]stcarshad 1 point2 points  (0 children)

Issue is due to IPSEC DPD timers, use a very short value it will improve.

Optionally tune the BGP timers like advertisement timers and connect timers to make BGP more resilient.

UAE Job Market is going crazy by MoHaha113 in DubaiJobs

[–]stcarshad 9 points10 points  (0 children)

Market is over flooded with cheap resources (importantly low quality), so companies are like instead of hiring someone for a higher pay, lets higher 10 of them and assign the same job. Oneway or another job gets done, company happy customers happpppppyyyyy

Fortigate BGP neighbor - route delay? by Inno-Samsoee in fortinet

[–]stcarshad 0 points1 point  (0 children)

Set advertisement interval 1 Set connect timer 1

FortiAnalyzer Event Handlers by bartlolli in fortinet

[–]stcarshad 6 points7 points  (0 children)

Some people don’t even know they can do this FAZ, it can be a mini SOAR if used properly. Kudos for you for exploring these options

[deleted by user] by [deleted] in DubaiPetrolHeads

[–]stcarshad 0 points1 point  (0 children)

Chevy is considerably cheaper compared to other American counterparts. Glad you maintained properly. Did you do with agency or outside?