Alex Pavlock
Alex Pavlock
  • 14
  • 46 694
Fortinet FortiClient / FortiEMS / FortiGate - Paid vs Free VPN
The video everyone has been waiting for! This video is going to break down the differences between paid and free VPN for FortiGate. We dive into some of the features and benefits of the paid version vs. the free version. We also touch on web filtering and ZTNA ( Zero Trust Network Access ) which comes within the vpn/ztna tier of licensing. We look at the different licensing options of FortiClient and form factors as well as deployment options for both options. Hope everyone enjoys the video and finds it helpful! I encourage you to read the documentation if you have questions on FortiClient or FortiEMS. As always if you do have questions after watching the video please leave a comment on this video! Happy secure networking to all!
www.fortinet.com/content/dam/fortinet/assets/data-sheets/forticlient.pdf
www.fortinet.com/content/dam/fortinet/assets/data-sheets/og-forticlient.pdf
docs.fortinet.com/product/forticlient/7.2
docs.fortinet.com/document/forticlient/7.2.3/ems-administration-guide/24450/introduction
มุมมอง: 4 404

วีดีโอ

FortiCloud IAM Users and User Groups - Tackling least privilege with IAM Users
มุมมอง 2136 หลายเดือนก่อน
Here is a step-by-step guide on how to create users and users groups within FortiCloud. IAM is absolutely critical in cloud security and helps organizations tackle the first pillar of least privilege and identify and access management. FortiCloud IAM can create granular permissions for users to grant them access to only the resources they need to do their job. Smash the like and subscribe butto...
IPSec VPN Tunnel Between Fortinet FortiGate and Cisco Meraki MX - Configuration and Troubleshooting
มุมมอง 5K11 หลายเดือนก่อน
In this video, Marcellus and I go through configuring a site to site IKEv1 IPSec VPN tunnel between a FortiGate (firmware version 7.2.5) and a MX (Firmware 18.107.2). In this example, both Firewalls are behind NAT devices so some configurations may be different depending on your specific environment. We cover configurations within Meraki dashboard and FortiGate GUI mgmt interface, configuring f...
Fortinet FortiGate and FortiAnalyzer Integration Slack + Microsoft Teams automated notifications
มุมมอง 1.3K11 หลายเดือนก่อน
This is a step by step guide on setting up automations within Analyzer and FortiGate to send notifications to Microsoft teams or slack channels. Teams is a new integration with Analyzer released in version 7.4. This integration can send a channel notification whenever an incident is created (whether manually or through playbook action), updated, or deleted. Also included is setting up channel n...
Fortinet FortiZTP how to setup guide / FortiLAN Cloud / FortiGate Cloud / FortiManager
มุมมอง 1.6Kปีที่แล้ว
FortiZTP ( Zero Touch Provisioning )TLDR: FortiZTP is super easy to provision devices (Gates/ AP's/ Swithes) and push down configs. Once the setup is complete companies can ship out devices to locations and have non IT people plug in and once connected to the internet will pull down assigned configs. This is a step by step how to guide that customers and partners can follow to take advantage of...
Fortinet FortiAP's- How to form a wireless mesh network to extend your WLAN
มุมมอง 4.4Kปีที่แล้ว
This is a how to guide for Fortinet Acces Points aka FortiAP's to form a wireless mesh connection to extend the wireless local area network (WLAN). In this scenario my FortiGate 80F is acting as the wireless controller using the built WLAN controller that comes in FortiOS. Every FortiGate has this functionality built in with no additional licensing costs to utilize this feature. My FortiAP mode...
Onboarding to FortiSASE / FortiClient / Secure Web Gateway
มุมมอง 1.1Kปีที่แล้ว
This video is a demonstration on what the onboarding process to FortiSASE looks like. As you can see onboarding to FortiSASE is very easy with just a few clicks. This also will show you how to roll out the solution to the end points as well. Within the Fortinet FortiSASE portal you can either download an installer package and roll out with an MDM solution or you can email it out directly to use...
Inside the mind of a hacker- Fortinet's FortiDeceptor
มุมมอง 466ปีที่แล้ว
I created this video to show at a high level how a hacker is thinking once inside of your network. This is a high level beginner guide so you can understand what they are trying to do and some different techniques they use. I coupled this video with Fortinet's FortiDeceptor product to show how honeypots or decoys work to fool malicious actors into thinking they are hacking a real server when in...
Connecting Fortinet FortiAP to FortiLAN Cloud
มุมมอง 3.8Kปีที่แล้ว
This is a how to video guide hooking up an AP to FortiLAN Cloud along with some basic AP radio and SSID configurations. This process is very easy and straightforward. Only takes about 10 minutes in total from unboxing to online and broadcasting! Let me know in comments if you have any questions!
Fortinet FortiDeceptor Demo
มุมมอง 1.2Kปีที่แล้ว
This is a demonstration on some of the features and use cases for using Fortinet FortiDeceptor. This includes a slideshow presentation and GUI demo of the product. If you have any questions please leave a comment!
FortiSASE Private Access Setup Guide
มุมมอง 5Kปีที่แล้ว
This is a how-to video/demonstration/walk-through with GUI on how to configure Fortinet's FortiSASE and private access. This shows how you would utilize FortiSASE for your remote workers but also enable them to reach internal resources using traditional VPN tunnels and not ZTNA access proxies. In this video you will see us configure a FortiGate, FortiSASE, and FortiClient to reach a local ESXi ...
How to onboard to Fortinet SOCaaS
มุมมอง 363ปีที่แล้ว
Short walk-through of the process to onboard to Fortinet's SOCaaS. If theres any questions please leave a comment, I am happy to assist! Doc to Onboarding: docs.fortinet.com/document/forticloud-socaas/latest/frequently-asked-questions/317544/subscription-and-onboarding SOCaaS User Guide: docs.fortinet.com/document/forticloud-socaas/latest/user-guide/352650/introduction
FortiSwitch FortiAP demo
มุมมอง 2.7Kปีที่แล้ว
High level run through of FortiAP and FortiSwitch products. Short slide deck presenting the two solutions followed by GUI demos. Covering both management options of FortiLink controlled by FortiGate and short FortiLAN Cloud demo. Any questions feel free to comment!
Fortinet FortiClient/FortiEMS/FortiGate using ZTNA tags to reach RDP server how to guide
มุมมอง 15Kปีที่แล้ว
Fortinet FortiClient/FortiEMS/FortiGate using ZTNA tags and TCP forwarding to reach RDP server how to guide. Demonstration on configuring FortiEMS and FortiGate to use RDP client and TCP forwarding with ZTNA tags to allow or deny remote users to reach internal RDP server.

ความคิดเห็น

  • @alwayskarbala
    @alwayskarbala 2 วันที่ผ่านมา

    Bro love your videos. Could you provide me training session ?

  • @christopherdesouza7339
    @christopherdesouza7339 5 วันที่ผ่านมา

    Had conversation with Fortinet. They said that 2.4Ghz is recommended for backhaul as it travels better the 5Ghz. Specially through objects and structure. They found that majority of APs in a Mesh configuration are in different rooms/areas and rare that they are in same open space. As users are connecting in same space to 1 of the APs then don't have to worry about going through walls as an example has worked out better. After change we notice better performance for sure on non cabled APs using mesh. Again it would depend on situation... A house with drywall instead of concreate filled block walls in office spaces probably better to go opposite or something like large venue halls, gyms definitely want to go backplane on 5Ghz.

  • @deepaksharma1906
    @deepaksharma1906 9 วันที่ผ่านมา

    If we add ztna tag in sase for spa using sdwan, and then user moved to on-premise (on-net), how ztna will work in this scenario?

  • @etakwilkie
    @etakwilkie 12 วันที่ผ่านมา

    Hey Alex have you set SASE up with ZTNA? I am trying to get it setup.

  • @standartmedia9937
    @standartmedia9937 19 วันที่ผ่านมา

    I did the same, but my status is offline. Directly the router is working good. Can you help me? Thanks in advance

  • @aliabdulrazaq3852
    @aliabdulrazaq3852 28 วันที่ผ่านมา

    can you a fortiswitch behind the leaf AP and authorize it?

  • @senseimillian6747
    @senseimillian6747 หลายเดือนก่อน

    Great job Alex! 🎉

  • @AnandNarine
    @AnandNarine หลายเดือนก่อน

    Nice.. but at 33:33, you said bridge mode does not use capwap? Isn't the fortiap itself managed by capwap to begin with? This is the security fabric connection checkbox that must be enabled on the fortigate interface that the ap connects to in order to be authorized. Formerly known as capwap in older fgt os.

  • @user-hp9dd5wz6c
    @user-hp9dd5wz6c หลายเดือนก่อน

    How do I setup a remote FortiAP

  • @user-hp9dd5wz6c
    @user-hp9dd5wz6c หลายเดือนก่อน

    Hey, how do I setup a remote fortiAP

  • @hoangtruonghuy4990
    @hoangtruonghuy4990 หลายเดือนก่อน

    Have a nice day! Mr Alex. Could you help to share the topology in this video ? ( Fortinet and Meraki MX ). Thank you so much.

  • @evangelosmj
    @evangelosmj 2 หลายเดือนก่อน

    Nice brother, i really used this case in my lab, and it works perfect. :)

  • @BlizzTech
    @BlizzTech 2 หลายเดือนก่อน

    Could you please do a video on FortiLAN FortiSwitch? Like how to configure, apply VLAN interface IP with gateway, etc.

  • @lovemoremanyere3371
    @lovemoremanyere3371 2 หลายเดือนก่อน

    on the deployment network, what is the deploy monitor IP?

  • @italianfunplay
    @italianfunplay 2 หลายเดือนก่อน

    Can i use the same tunel for fortisase and the spokes?

  • @nisaltharinda8517
    @nisaltharinda8517 2 หลายเดือนก่อน

    What are the pre-requiesties for this configuration?

  • @anonymoususer6786
    @anonymoususer6786 3 หลายเดือนก่อน

    One of this was “simplified.” Clearly needed more rehearsing and constantly talked over each other. Also, way way way too long. Simple = better.

  • @DusanSim
    @DusanSim 3 หลายเดือนก่อน

    Good job Alex! This is a very good introduction to ZTNA and EMS.

  • @bandido428
    @bandido428 3 หลายเดือนก่อน

    What settings do you have for long distance mesh?

  • @lazzybug007
    @lazzybug007 4 หลายเดือนก่อน

    Thank you

  • @user-wr8zn4cf4b
    @user-wr8zn4cf4b 4 หลายเดือนก่อน

    Cool, learned something new, thank you

  • @gokucanfly4593
    @gokucanfly4593 4 หลายเดือนก่อน

    how do you make them statics? cant see this in any the settings so dumb vs cisco meraki

  • @roheetmishra9105
    @roheetmishra9105 4 หลายเดือนก่อน

    I've set up 2 FortiAPs via FortiCloud. However, after a few days, clients connected to the second AP are unable to access the internet. Both APs are connected to the same network. Can you please provide any suggestions to resolve this issue?

  • @krzysztofjasion8549
    @krzysztofjasion8549 4 หลายเดือนก่อน

    Great video! Thank you very much.

  • @emiljacobson7586
    @emiljacobson7586 4 หลายเดือนก่อน

    Did you pre-configure the 'ZTNA Destinations' in FortiClient before configuring the 'ZTNA Destination' in FC-EMS? That's a step you don't show, and my destinations from EMS aren't synchronized to FortiClient. Thanks, E

  • @aerialfruitbat1848
    @aerialfruitbat1848 4 หลายเดือนก่อน

    Thank you for a great video!

  • @kannanm7947
    @kannanm7947 4 หลายเดือนก่อน

    Thanks for the video Alex...I have few doubts, the connection from the forticlient to fortigate to access ZTNA server is through the SSL VPN only right, you told that the packet will be wrapped in Https and send to fortigate, getting confused 😕....One more doubt is that the ZTNA rules will be applied after decrypting the SSL packet right, in this case the normal firewall policy will not be applied after decryption????

  • @sabine8507
    @sabine8507 4 หลายเดือนก่อน

    very interesting video! Nicely done

  • @robertoallen2346
    @robertoallen2346 5 หลายเดือนก่อน

    If a computer does not have Forticlient, how can I prevent it from connecting to my network?

  • @Klarkooi
    @Klarkooi 6 หลายเดือนก่อน

    Does it work for other use cases beside RDP for example certain system based user account is used for powershell or other protocol access to corp server?

  • @dns_error
    @dns_error 6 หลายเดือนก่อน

    Lets say, currently, there is one big trust envoirnment that has all items user needs and users use forticlient to connect back using ipsec vpn. and channel all traffic back in including internet, which then gets inspected via security profiles using only one primary fortigate corporate firewall. Isnt this doing the exact same thing?

  • @oinkersable
    @oinkersable 6 หลายเดือนก่อน

    Thanks for the video Alex but just to point out that on prem EMS is an app on a windows server and not a VM image.

  • @joemcgowan7554
    @joemcgowan7554 6 หลายเดือนก่อน

    Is the FortiClient Cloud/EMS a subscription based service?

    • @fortialex
      @fortialex 6 หลายเดือนก่อน

      Yes FortiClient/FortiEMS is only offered as a subscription based solution whether it’s VM or Cloud. Perpetual does not exist.

  • @dararim476
    @dararim476 6 หลายเดือนก่อน

    Thanks for your sharing. I have a question, Is the ZTNA function helpful for on-net users?

  • @Building-IT
    @Building-IT 6 หลายเดือนก่อน

    Nicely done! I am a network engineer at an enterprise company, and we have Meraki at all the plant locations but have FortiGate in the cloud. I personally dislike Meraki for multiple reasons. Hoping to move to Fortinet in the future. Meraki is great for an SMB, but not enterprise.

  • @MG-pf9xf
    @MG-pf9xf 8 หลายเดือนก่อน

    Hi. You mentioned Proxy IP is your wan interface IP which is setup on VIP. then what IP you are using on ZTNA server? please explain a bit.

    • @MG-pf9xf
      @MG-pf9xf 7 หลายเดือนก่อน

      ?

  • @MG-pf9xf
    @MG-pf9xf 8 หลายเดือนก่อน

    Hi. Do I need to put my on-prem EMS server on DMZ and allow port? Because when I am going off fabric the forticlient shows disconnected.

    • @MG-pf9xf
      @MG-pf9xf 8 หลายเดือนก่อน

      @@fortialex Thanks. Do I need to put that EMS server into DMZ or VIP with static NAT will be fine and put that VIP on Forticlient so it can communicate with EMS server from outside world?

    • @MG-pf9xf
      @MG-pf9xf 8 หลายเดือนก่อน

      ?

  • @manitou89
    @manitou89 8 หลายเดือนก่อน

    Thanks for the video, it did help, but I had to contact Fortigate because the tunnel would not come up. It turned out that the Fortigate was advertising the FQDN and not the public IP. We had to enter the command "set localid-type address" and then both ends came up.

  • @user-pe6wr8xq9o
    @user-pe6wr8xq9o 8 หลายเดือนก่อน

    is there a way to setup ZTNA just on a fortigate without EMS and such?

    • @fortialex
      @fortialex 8 หลายเดือนก่อน

      No, the Fortinet solution requires EMS and FortiClient or SASE

  • @abiodunotusanya2679
    @abiodunotusanya2679 9 หลายเดือนก่อน

    Great demo. you rock

  • @fabricembomda2045
    @fabricembomda2045 9 หลายเดือนก่อน

    great !!!!!

  • @recardooneal9900
    @recardooneal9900 9 หลายเดือนก่อน

    How do ZTNA rules interact with regular firewall policy?

  • @deezgasx331
    @deezgasx331 9 หลายเดือนก่อน

    Is there any configuration needed in the firewall policy? I followed the steps, but I am unable to RDP to my server using the local IP address.

  • @ac_playz865
    @ac_playz865 9 หลายเดือนก่อน

    I was wondering - we have a Meraki Mesh ( Auto hub ) of 6 units in various states. Got the Fortigate to establish a tunnel from one of the Merakis in the mesh, but how would you go about creating the rest of the tunnels on the fortigate side, any tricks because we have tried duplicating what is working for the first, and no dice every time.

  • @alexalexeev695
    @alexalexeev695 9 หลายเดือนก่อน

    diag deb application ike 4 .. and you'll see all Ph1 and Ph2 messaging, don't forget to apply the filter for the specific tunnel. Plus, you have to mention how Fortigate handles Ph2 SA per subnet vs Cisco or Meraki .

  • @erickj3929
    @erickj3929 9 หลายเดือนก่อน

    Appreciate the video Alex! First time setting up VPN tunnel between MX and FortiGate, and this worked out perfectly for me.

  • @chrismoore1981
    @chrismoore1981 10 หลายเดือนก่อน

    Great Video Alex!! Am I correct in saying that FSSO is no longer needed. I would think FortiClient with ZTNA is a much better solution for RBAC vs FSSO?

  • @MeekiDeekay
    @MeekiDeekay 10 หลายเดือนก่อน

    Thank you for your helpful videos!! I am currently also trying to get some FortAP's in FortiLan Cloud. I have them connected and are working perfectly with a normal SSID. But I want to configure Mesh for these AP's. The documentation seems hard to find for Forticloud on this subject. There is no place where I can set a SSID for the backhaul. Have you tried this in Forticloud? BTW i am trying this with the FortiAP FAP-U321EV model. Or is this new SSID where I select Mesh-link the backhaul?

  • @dohoathanh
    @dohoathanh 10 หลายเดือนก่อน

    I want to configure mesh to forti ap on fortilan cloud but I not see tab ssids to add mesh.root so do you config mesh on fortilan cloud?

    • @fortialex
      @fortialex 10 หลายเดือนก่อน

      Under the SSID configuration page you would turn on "mesh link". Wireless>Configuration>SSID>Add New> 5th option on the SSID config page is "mesh link" with a toggle you would flip to on