Full Fortinet Stack Environment

Поділитися
Вставка
  • Опубліковано 6 вер 2024
  • A lot of people praise Meraki and UBNT for their capabilities of having a single ecosystem stack from edge to endpoint. I think you need to give Fortinet their due credit as well. Learn how to create a full stack in Fortinet for the Firewall, Switch and Access Point
    Buy Hardware: bit.ly/2QZVeqh
    Get Consulting: bit.ly/36FinSU
    My Other Projects:
    Office Of The CISO: bit.ly/3HGMH1o
    Packet Llama: bit.ly/3SEX3H4
    ###### SOCIAL LINKS ######
    Twitter: bit.ly/2WXiRAv
    Facebook: bit.ly/3eigz4D
    Instagram: bit.ly/3cZneAz
    ######################

КОМЕНТАРІ • 121

  • @Xyler94
    @Xyler94 3 роки тому +4

    I have a Fortinet Full Stack at my house, and it's pretty cool.

  • @keithlee4945
    @keithlee4945 3 роки тому +1

    Have been following your blog and videos. Excellent walk through!
    Deployed my first full Fortinet Stack (101F configured in a ring mode on the 10G interfaces 2x FS148F-PoE w/10x FortiAP-231E)
    All i can say is that the video doesn't do justice what the whole solution can actually do.
    For my client's request, i got to see first hand how powerful the whole integration is. Being able to see devices is one thing, the FortiAP is pretty decent, as its able to also monitor the air in real time for the 231E (yes they even have the meraki spectrum analysis!). Roaming wasn't a problem and didn't require much configuration which i'm quite surprised coming from deploying Ubiquiti/Ruckus/Aruba.
    I just hope Fortinet has better QC on their Fortigate's firmware.

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      The visibility is wonderful and helps people out a lot! I am a big fan of it. I do hope for higher QC on the firmware.

  • @tonymarms8908
    @tonymarms8908 3 роки тому +2

    Thanks for this great teaser of fortinet full stack 👍
    I don't know if you already have this video but if you have time can you also discuss multi tenancy capabilities of fortinet firewall, like vdoms/vrf.
    I'm just collecting use cases that may help us build a network as service provider, currently reviewing fortinet as firewall for this project..
    Hope to hear some inputs..🙂 cheers 👍👏 keep it up

  • @thom71
    @thom71 3 роки тому +1

    That was a great explanation of all of that. I have the 60F, 124PoE, 221E, and a 222E and have just started working at dialing all of this stuff in on my home network. My 60F uploads to my office Fortianalyzer. I can police the kids and keep them off youtube and stuff, and shut off the netflix at night so they actually go to bed. I'd like to see some policy building, as I had a hard time getting the chromebooks locked down.

  • @_stucki_
    @_stucki_ 3 роки тому +1

    Hi Fortinet Guru, it's nice to see some hints and tips from you, I'm mainly working on the bigger devices in an enterprise environment. (FG1100, FG1800 and upwards)
    It's sometimes very helpful to see some ideas from a different side of view, it's helps in daily work. Thanks for sharing !

  • @ajibolayusuf2057
    @ajibolayusuf2057 2 роки тому

    The way you explain things succinctly needs to be studied! For real thank you Mikey!

  • @disasstah
    @disasstah Рік тому

    There were a lot of helpful tidbits of knowledge in here! I really appreciate it, especially since I'll be deploying stacks just like what you have shown.

  • @RichardDePas
    @RichardDePas 3 роки тому +1

    Thanks! That was a great brief description of getting the stack up and running.

  • @rhdtv2002
    @rhdtv2002 3 роки тому +1

    We just upgraded from a Juniper To Fortigate 100e..we are now going waiting to receive 4 FORTINET POE switches

  • @FlorianZevedei
    @FlorianZevedei 3 роки тому +1

    Thanks for the impressive and simple introduction! Great stuff. Makes a lot of sense in that "Forti-Universe". Thanks!

  • @zgralewski
    @zgralewski 2 роки тому

    I love your videos. The one brilliant source of fortiknowledge.

  • @iamnotnice1536
    @iamnotnice1536 3 роки тому +1

    Fortinet are awesome. Beats the like of Sophos, Juniper, barracuda and Watchguard. I want this technology and its a solutions will help ALL the small and mid size now and the future. Where can i learn more.

  • @uByte2
    @uByte2 2 роки тому +1

    Just what I needed. Thank you so much.

  • @cecilerasmussen8161
    @cecilerasmussen8161 3 роки тому

    Giving this a go tomorrow, can't wait makes a lot of sense Thank you

  • @nagchampa4476
    @nagchampa4476 3 роки тому

    I love security fabric . Well done Fortinet, the best environnement ! ❤

  • @leonelsalah8950
    @leonelsalah8950 14 днів тому

    Tks for your video, I have a question: what is different between using port with fortilink(a&b) and normal port to connect to Fortiswitch?

  • @Itisnot2late
    @Itisnot2late 3 роки тому

    Brief introduction. Thanks a lot.

  • @musclekitchen3705
    @musclekitchen3705 3 роки тому +1

    Alright mate are you still going to do the video of cisco vs fortinet like you did with checkpoint and palo alto that was really good stuff 👍

  • @ErwinNiesten
    @ErwinNiesten 3 роки тому +1

    Hello Mike, I have watched a lot of your videos! You are doing a great job, thanks for that!
    I have a similar setup at home right now, unfortunately without multiple internet connections.
    Is there a possibility that you created a video regarding FortiSwitch NAC Policies and FortiSwitch Security Policies within this setup? Thank you!
    Keep up the good work! Regards!

  • @kostass8853
    @kostass8853 3 роки тому

    Hey long time no see a new video...! Missed your excellent videos!!!

  • @eraadw
    @eraadw 3 роки тому

    Thanks a lot for sharing your knowledge.
    I have been watching your videos for weeks/month now. And thanks to you I decided to buy a full stack (FG/FS/AP - Book) a week ago for myself and it seems this video came at the perfect moment.
    Since you mention other brand at the start of your video, I was wondering, even tho Fortinet seems way more advanced and reliable than many brand atm do you think installing Unifi or Edge for very small office is a good idea ?
    Anyway thanks again for sharing !!!!

  • @markusfrey3775
    @markusfrey3775 2 роки тому

    WOW, Amazing!I work an LAB with 2 FortiGate 60F and 2 FortiSwitch 124F and 4 AP231F What ist the best prec. for 100% HA Stack? Would you pleae so kind and give me a view hints?

  • @5945751
    @5945751 3 роки тому

    First time watching you video; love it. Now a subscriber

  • @sdfnhghjdfbgh5851
    @sdfnhghjdfbgh5851 Рік тому

    I have 100f , and need to switch over from the wan interface port to an sfp port. How would you proceed?

  • @camryds
    @camryds 2 роки тому

    I would like to know how to configure FWF -> FAP in a mesh environment wireless mesh with VLAN

  • @nbctcp3450
    @nbctcp3450 Рік тому

    in FortiSwitch how to set port to accept ip phone with VOICE vlan40 and DATA in vlan30
    because switch port > ip phone > pc all connected to switch using 1 ethernet port

  • @iamrichard8778
    @iamrichard8778 3 роки тому

    Hey man, you are pretty good at explaining things. Ever thought of doing a NS course? Heaps of CCNA YT focused channels around. Just a thought.

  • @ignaciosaravia5719
    @ignaciosaravia5719 3 роки тому

    Great video!! You make it easier to understand. Hey, do you know how to split an SD-WAN to share WAN1 through LAN port 2? Just a thought.

  • @tomerpeer6398
    @tomerpeer6398 2 роки тому

    Hi Fortinet Guru, can toy stack fortinet switches with DAC cabels? if so, can you advertise a short brief of how to. thanks in advance. Tomer

  • @saifemran4528
    @saifemran4528 3 роки тому +1

    As always, great videos!

  • @bboosss1065
    @bboosss1065 3 роки тому

    Can you please explore more of the lldp med thing and the logic of the allowed / native thing? How do you decide which port is a trunk port? Or basically it does dot1q and you just decide the native

  • @saikenjkd
    @saikenjkd 3 роки тому

    Any chance on a FortiEDR review? in light of all the latest outbreaks, would be a good time to talk about Fortinets offering compared to crowdstrike, S1, etc

  • @myanmarict1590
    @myanmarict1590 Рік тому

    That is really helpful. Thank you so much!

  • @stanleyilchev3503
    @stanleyilchev3503 3 роки тому

    Love the content!!
    What issues have you run into if you don't daisy-chain the switches, but connect them all directly to the firewall and "trunk" them from there?

  • @JasonLeaman
    @JasonLeaman 3 роки тому +1

    I've wanted to try a Fortinet firewall, but the licenses are expensive for a home lab :(

  • @dtcoleman05
    @dtcoleman05 3 роки тому

    Great video! Do you have any FortiNAC demo and/review videos?

  • @kaain775
    @kaain775 3 роки тому

    This pairs perfectly with Microsoft 365 services, two exceptionally seamless technologies.

  • @yesforarab
    @yesforarab Рік тому

    Thank you!

  • @stephensukhai3311
    @stephensukhai3311 3 роки тому +1

    Great Video......followed your video but noticed with my FortiAP 231F I’m not getting anything faster then 100MB download. I do have a 1gig connection. Wired connections I have no issues. Any thoughts?

    • @vewo234
      @vewo234 3 роки тому +1

      Are you using Capwap by any chance? Some smaller/older FGT models can‘t offload Capwap and CPU speed will limit the throughput.

    • @dineshchandrawanshi4683
      @dineshchandrawanshi4683 3 роки тому

      Use Appropriate fortiSwitch

  • @dunnjustintime
    @dunnjustintime 3 роки тому

    This was a great video! Thank you so much!!

  • @demandredlfc4180
    @demandredlfc4180 2 роки тому

    Am I right that if I use tunnel mode SSIDs then I will not be able to see Wi-Fi clients from FortiSwitch Ports view, as it is on 23:24?

  • @eaperezh
    @eaperezh 3 роки тому

    I want to buy that t-shirt!!!! Where can I get it? Thankfully same applies here in Panama, Central America

  • @zgralewski
    @zgralewski 2 роки тому

    Dziękujemy.

  • @marcingowacki3647
    @marcingowacki3647 3 роки тому

    Great video and just on time as I am preparing to deploy full stack. Video proposal: Trusted CA certificate for deep SSL inspection. Can you recommend any commercial SSL certificate? First certificate I bought has CA:FALSE parameter and I am having problems finding certificate provider that will work for deep inspection and does not cost 200$. Is there any 20$ certificate on the market that will do the job?

  • @TheDarrenSR
    @TheDarrenSR 3 роки тому

    The last ports on all switches LAN devices should always be your uplink ports it is best practice really

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      It is how I like to do it. If you have a standard and it works and is repeatable ultimately it will work fine.

  • @user-fd8mt9pf3i
    @user-fd8mt9pf3i Рік тому

    How would you do your vlans if you have your fw interfaces configured to handle the DHCP?

    • @FortinetGuru
      @FortinetGuru  Рік тому +1

      My vlans themselves would handle the dhcp so no other edits would be necessary other than defining parameters.

  • @ebrahimshaikjee6799
    @ebrahimshaikjee6799 2 роки тому

    Great video, just curious why would you use the 3rd octet as your site identifier instead of the 2nd octet which makes alot more sense.

    • @FortinetGuru
      @FortinetGuru  2 роки тому +1

      It’s personal preference / scalability. I have situations where I use the second octet (when proposed future branches are smaller than 256). Otherwise, the third octet enables up to 2500 (although smaller potential subnets) branches

  • @smokeforless3071
    @smokeforless3071 2 роки тому

    Hi any spare REG REF you could borrow me ? thanks

  • @punkeyengineer
    @punkeyengineer 2 роки тому

    what is a perimeter firewall ? please can someone answer me ! I have been hearing this word from so long, but still dont have a clue , whats a "perimeter" firewall

    • @FortinetGuru
      @FortinetGuru  2 роки тому

      Perimeter firewall, also known as the edge firewall. It provides security and such at the edge of a network going out to the world. ISFW (internal segmentation firewalls) provide more specific security services WITHIN the infrastructure (think along the lines of keeping accounting stuff only visible to them etc)

  • @ibrahimngueyon9688
    @ibrahimngueyon9688 2 роки тому

    Great

  • @ruellerz
    @ruellerz 2 роки тому

    I challenge your subnet and vlan design. The second octet should be the site identifier while the 3rd is for the VLAN ID. Maybe you said it wrong @ 12:20

    • @ruellerz
      @ruellerz 2 роки тому

      You lose the ability to do any summary routes . Give a site /16 and slice it up

  • @danycontrerastorre87
    @danycontrerastorre87 3 роки тому

    how to get a tshit like that ?

  • @JunLYeap
    @JunLYeap 3 роки тому

    Thanks for sharing sir!

  • @CristobalRuiz
    @CristobalRuiz 3 роки тому

    Love the shirt bro.

  • @nielstaildeman
    @nielstaildeman 2 роки тому

    Nice video! One question though: As I understand from the example in the video, the fortiswitch is handling the L3. But is the Fortigate then still able to check traffic between l3 vlans?

    • @FortinetGuru
      @FortinetGuru  2 роки тому

      The fortigate will be handling all routing and access control.

  • @AhmadSwailem
    @AhmadSwailem 3 роки тому +1

    I loved your T-shirt 😂❤

    • @lkfng
      @lkfng 3 роки тому

      I wonder if he has hoodies for sale with the same slogan?

    • @AhmadSwailem
      @AhmadSwailem 3 роки тому

      @@lkfng i do too..

    • @hanold5049
      @hanold5049 3 роки тому

      love from china...

  • @NorrisCarden
    @NorrisCarden 3 роки тому

    The AP on the FortiWiFi only has one radio, so can only run either 2.4ghz or 5ghz.

    • @zobs1234
      @zobs1234 2 роки тому

      Depends on the model really. 40F/60F has single radio. 80F has 3 radios (2 to serve customer +1 scanning). There was also a 50e-2r model with 2radios, but it's probably eos now.

  • @G1rlyG33k
    @G1rlyG33k 3 роки тому

    Hey Mike, have you completed your NSE 8 exam? Your content is very helpful.

  • @thomasjoseph9609
    @thomasjoseph9609 2 роки тому

    it is really nice and helpful

  • @brendanbass5495
    @brendanbass5495 3 роки тому

    Great content learned plenty.

  • @Mir_Aus
    @Mir_Aus 3 роки тому

    Can someone help with fqdn as I need to learn to to acess PCs with host name instead of IP when using Vpn

  • @DonJudd
    @DonJudd 3 роки тому

    Mike, if you don't mind answering a dumb question for me. My internal LAN is 192.168.70.x. I have a gateway to gateway VPN to 192.168.1.x. My Data vlan is 10.70.10.x and is part of my INSIDE zone. Firewall policy for INSIDE>VPN is set to allow traffic. I am assuming my static route need to also be set for the 10.70.10.0/24 network, but how? Following this video, I have my VLANs working like yours (Data and Guest, I have no voice) but computers on my Data vlan can't reach the remote end of the VPN.

  • @kimhalavakoski5189
    @kimhalavakoski5189 2 роки тому

    Hello! Great video! One question though: I am testing out a similar setup with a FG-40F and have some issues in that the VLANs created on the FortiSwtich are not "easily" used on the FortiGate, meaning that I can not use a FortiSwitch VLAN on the FortiGate internal ports...seems like the two devices can't use the same VLANs? Any thoughts / feedback on that and how to use the some VLANs on both devices and possible to configure FortiGate with VLANs from Fortiswitch?

    • @FortinetGuru
      @FortinetGuru  2 роки тому

      I recommend keeping all VLANs on the FortiSwitch interface and switches. The ports on the FortiGate itself I only use for Fortilink access honestly.
      You can do Software switches to group ports and interfaces together but then you lose hardware acceleration.

  • @tj71tj71
    @tj71tj71 3 роки тому

    I noticed the warning "Security Fabric Connection is disabled" but obviously you are running security fabric? I seem to recall full fabric needs a FortiAnalyzer, is that so and why if so?

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      To run the full security fabric you do need the analyzer in order for it to hold and do all of the correlations and data associations. Otherwise, the FortiGate can't hold enough data to maintain the database.

  • @hudsonatlantis6754
    @hudsonatlantis6754 3 роки тому

    Great Video!

  • @Desertedx
    @Desertedx 3 роки тому

    So great video!

  • @jankockv
    @jankockv 3 роки тому

    The UTP cable that's comes with the fortiSwitsh or FortiGate esa WHITE, NOT yellow

  • @alarsen77
    @alarsen77 3 роки тому

    Great video! I am currently running a 60f and a 231f at home in a home lab. I have been thinking about adding a switch. I have a small network with only 5 wired devices (including the AP) so I was thinking the 108e PoE would be fine, but do you think the 124e PoE is worth the extra cost for future proofing?

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      Depends on your port density needs. It would meet your future requirements tho.

    • @alarsen77
      @alarsen77 3 роки тому

      @@FortinetGuru I currently only have a few devices and don't have a plan for too many more right now, so was thinking the 8 port would be good and save on cost and I could always upgrade it later if needed. I just wasn't sure if the 24 poet had any better components that made it perform better.

  • @luchobeto
    @luchobeto 3 роки тому

    how can you add fortigate hardware switch ports to the fortiswitch vlan after the fortilink
    is up and running ?

    • @FortinetGuru
      @FortinetGuru  3 роки тому +1

      Depending on how your fortilink interface is configured you can add and removal physical interfaces to it.

  • @erikbakke5401
    @erikbakke5401 3 роки тому

    Do you have url to the compatibility matrix regarding upgrade? I have also run into issues when upgrading fortigate with fortiswitch via fortilink

    • @FortinetGuru
      @FortinetGuru  3 роки тому +1

      Google Fortilink Compatibility Matrix and you are set

  • @germanvas63
    @germanvas63 3 роки тому

    How can I contact you so I can ask for some advice? I’m in CA

  • @friedrice7707
    @friedrice7707 Рік тому

    I have the same Fortinet stack connecting my Fortigate to FortiSwtich via FortiLink Interface A and from FortiSwitch PoE connection to FortiAP 221E. Using the 7.2.4 firmware on FG & FS. But I am getting rid of FortiSwitch and ForiAP as the switch is highly unreliable when connecting via FortiLink. The Fortilink between the Fortigate and FortiSwitch will drop to 100mbps despite replacing with brand new Cat 6E cables. And the only way to resolve the issue was to hard reset the switch. After reset and re-established the FortiLink, the same cable that was reporting 100mbps suddenly becomes 1Gbps. But on and off the Fortigate will report the authorized FortiSwitch is Offline. And I had to hard reset, authorized the switch and everything become normal again. The FortiAP wifi performance also sucks as my client will complain about the slow speed when connected to it. I had checked all the configs and the thing is a Asus home AP is more reliable then the more expensive FAP. I am keeping the Fortigate as it's very reliable in my opinion. Already ordered Unifi switch and U6E AP to replace my FortiSwitch and FortiAP. Will be testing them together with Fortigate before deploying them to Production sites. Give up hopes for FortiSwitch and FortiAP. Sad.

  • @amj-sauce
    @amj-sauce 2 роки тому

    I currently have this...
    [FGT-61F]──(LAN-AGG (Fortilink))──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE]──(Ports 23+24Ports 9+10)──[FSW-108E-FPOE]
    I want to do this...
    ┌──(Ports A+BPorts 9+10)─────[FSW-108E-FPOE]
    [FGT-61F]──(LAN-AGG (Fortilink))─┤
    └──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE]
    Is this possible with FortiLink split interface? Per the research I have done, things keep pointing to MCLAG but I don't want to complicate things. Any advice?

  • @SoulJah876
    @SoulJah876 3 роки тому

    Is 6.4.6 considered stable now? I was considering upgrading from 6.2.1 to 6.2.8 on my 301E and 501E.

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      I’m running 6.4.6 on most gear now

    • @SoulJah876
      @SoulJah876 3 роки тому

      @@FortinetGuru Thanks for the feedback. I'll test it out.

    • @synchit1593
      @synchit1593 3 роки тому

      We are using that on an 1100e, experience memory leak issues which does follow through till 7 and all fortinet support has advised is to kill wad proxy process… one of the worst support experience we have in a mixed vendor environment, no one else can take that crown..

  • @harrylumsdon6773
    @harrylumsdon6773 3 роки тому

    Any ideas on the fortiextenders?

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      They work ok. I only use them for failover

    • @harrylumsdon6773
      @harrylumsdon6773 3 роки тому

      Us too. Horrible reboot issues, seem fixed after 2 SW updates. modems would disconnect, til poe reboot. sometimes 17 a day.

  • @mosins5779
    @mosins5779 3 роки тому

    The vedio is not clear my friend

  • @SR_EMM
    @SR_EMM 3 роки тому

    Did you have a problem where Access Points Randomly disconnect from Controller? we have 2 networks of about 150 APs each and it happens all the time. Every week there is at least 5 Disconnected AP.

    • @FortinetGuru
      @FortinetGuru  3 роки тому

      Negative. What version of code and what model of AP / Gate?

    • @Mrrtbrs
      @Mrrtbrs 3 роки тому

      What FOS are you running on the FortiGate? What are your L2 Switches? any duplicate IP/DHCP Exhaustion? When then are "disconnected" can you ping/SSH etc to the devices?

  • @stage666
    @stage666 2 роки тому

    Do you work for fortinet?

  • @youtubegarbage4u
    @youtubegarbage4u 2 роки тому

    you missed mikrotik!

  • @vmened
    @vmened 3 роки тому

    Mikrotik works better than fortinet)

  • @noah9341
    @noah9341 3 роки тому

    Palo is better

  • @RaviChinasamy
    @RaviChinasamy 3 роки тому

    First 😂

  • @anonymoususer1367
    @anonymoususer1367 3 роки тому

    What a shitty products. It is probably great for SOHO, but Fortinet has really weak IPS.

  • @lesterawalt3184
    @lesterawalt3184 3 роки тому

    That thing is junk and nothing but problems. I went back to Cisco stuff