Full Fortinet Stack Environment

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ม.ค. 2025

ความคิดเห็น • 122

  • @zgralewski
    @zgralewski 2 ปีที่แล้ว

    Dziękujemy.

  • @Xyler94
    @Xyler94 3 ปีที่แล้ว +5

    I have a Fortinet Full Stack at my house, and it's pretty cool.

  • @_stucki_
    @_stucki_ 3 ปีที่แล้ว +1

    Hi Fortinet Guru, it's nice to see some hints and tips from you, I'm mainly working on the bigger devices in an enterprise environment. (FG1100, FG1800 and upwards)
    It's sometimes very helpful to see some ideas from a different side of view, it's helps in daily work. Thanks for sharing !

  • @disasstah
    @disasstah ปีที่แล้ว

    There were a lot of helpful tidbits of knowledge in here! I really appreciate it, especially since I'll be deploying stacks just like what you have shown.

  • @RichardDePas
    @RichardDePas 3 ปีที่แล้ว +1

    Thanks! That was a great brief description of getting the stack up and running.

  • @keithlee4945
    @keithlee4945 3 ปีที่แล้ว +1

    Have been following your blog and videos. Excellent walk through!
    Deployed my first full Fortinet Stack (101F configured in a ring mode on the 10G interfaces 2x FS148F-PoE w/10x FortiAP-231E)
    All i can say is that the video doesn't do justice what the whole solution can actually do.
    For my client's request, i got to see first hand how powerful the whole integration is. Being able to see devices is one thing, the FortiAP is pretty decent, as its able to also monitor the air in real time for the 231E (yes they even have the meraki spectrum analysis!). Roaming wasn't a problem and didn't require much configuration which i'm quite surprised coming from deploying Ubiquiti/Ruckus/Aruba.
    I just hope Fortinet has better QC on their Fortigate's firmware.

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      The visibility is wonderful and helps people out a lot! I am a big fan of it. I do hope for higher QC on the firmware.

  • @FlorianZevedei
    @FlorianZevedei 3 ปีที่แล้ว +1

    Thanks for the impressive and simple introduction! Great stuff. Makes a lot of sense in that "Forti-Universe". Thanks!

  • @zgralewski
    @zgralewski 2 ปีที่แล้ว

    I love your videos. The one brilliant source of fortiknowledge.

  • @uByte2
    @uByte2 3 ปีที่แล้ว +1

    Just what I needed. Thank you so much.

  • @ajibolayusuf2057
    @ajibolayusuf2057 2 ปีที่แล้ว

    The way you explain things succinctly needs to be studied! For real thank you Mikey!

  • @Itisnot2late
    @Itisnot2late 3 ปีที่แล้ว

    Brief introduction. Thanks a lot.

  • @cecilerasmussen8161
    @cecilerasmussen8161 3 ปีที่แล้ว

    Giving this a go tomorrow, can't wait makes a lot of sense Thank you

  • @thom71
    @thom71 3 ปีที่แล้ว +1

    That was a great explanation of all of that. I have the 60F, 124PoE, 221E, and a 222E and have just started working at dialing all of this stuff in on my home network. My 60F uploads to my office Fortianalyzer. I can police the kids and keep them off youtube and stuff, and shut off the netflix at night so they actually go to bed. I'd like to see some policy building, as I had a hard time getting the chromebooks locked down.

  • @tonymarms8908
    @tonymarms8908 3 ปีที่แล้ว +2

    Thanks for this great teaser of fortinet full stack 👍
    I don't know if you already have this video but if you have time can you also discuss multi tenancy capabilities of fortinet firewall, like vdoms/vrf.
    I'm just collecting use cases that may help us build a network as service provider, currently reviewing fortinet as firewall for this project..
    Hope to hear some inputs..🙂 cheers 👍👏 keep it up

  • @rhdtv2002
    @rhdtv2002 3 ปีที่แล้ว +2

    We just upgraded from a Juniper To Fortigate 100e..we are now going waiting to receive 4 FORTINET POE switches

  • @saifemran4528
    @saifemran4528 3 ปีที่แล้ว +1

    As always, great videos!

  • @kostass8853
    @kostass8853 3 ปีที่แล้ว

    Hey long time no see a new video...! Missed your excellent videos!!!

  • @5945751
    @5945751 3 ปีที่แล้ว

    First time watching you video; love it. Now a subscriber

  • @musclekitchen3705
    @musclekitchen3705 3 ปีที่แล้ว +1

    Alright mate are you still going to do the video of cisco vs fortinet like you did with checkpoint and palo alto that was really good stuff 👍

  • @demandredlfc4180
    @demandredlfc4180 3 ปีที่แล้ว

    Am I right that if I use tunnel mode SSIDs then I will not be able to see Wi-Fi clients from FortiSwitch Ports view, as it is on 23:24?

  • @leonelsalah8950
    @leonelsalah8950 4 หลายเดือนก่อน

    Tks for your video, I have a question: what is different between using port with fortilink(a&b) and normal port to connect to Fortiswitch?

  • @naveedsa6429
    @naveedsa6429 9 วันที่ผ่านมา

    How’s the performance of the AP against Meraki & Ruckus?

  • @CristobalRuiz
    @CristobalRuiz 3 ปีที่แล้ว

    Love the shirt bro.

  • @yesforarab
    @yesforarab ปีที่แล้ว

    Thank you!

  • @dtcoleman05
    @dtcoleman05 3 ปีที่แล้ว

    Great video! Do you have any FortiNAC demo and/review videos?

  • @myanmarict1590
    @myanmarict1590 2 ปีที่แล้ว

    That is really helpful. Thank you so much!

  • @markusfrey3775
    @markusfrey3775 3 ปีที่แล้ว

    WOW, Amazing!I work an LAB with 2 FortiGate 60F and 2 FortiSwitch 124F and 4 AP231F What ist the best prec. for 100% HA Stack? Would you pleae so kind and give me a view hints?

  • @ErwinNiesten
    @ErwinNiesten 3 ปีที่แล้ว +1

    Hello Mike, I have watched a lot of your videos! You are doing a great job, thanks for that!
    I have a similar setup at home right now, unfortunately without multiple internet connections.
    Is there a possibility that you created a video regarding FortiSwitch NAC Policies and FortiSwitch Security Policies within this setup? Thank you!
    Keep up the good work! Regards!

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว +2

      Let me see what I can do!

  • @thomasjoseph9609
    @thomasjoseph9609 2 ปีที่แล้ว

    it is really nice and helpful

  • @JunLYeap
    @JunLYeap 3 ปีที่แล้ว

    Thanks for sharing sir!

  • @brendanbass5495
    @brendanbass5495 3 ปีที่แล้ว

    Great content learned plenty.

  • @JasonLeaman
    @JasonLeaman 3 ปีที่แล้ว +1

    I've wanted to try a Fortinet firewall, but the licenses are expensive for a home lab :(

  • @stephensukhai3311
    @stephensukhai3311 3 ปีที่แล้ว +1

    Great Video......followed your video but noticed with my FortiAP 231F I’m not getting anything faster then 100MB download. I do have a 1gig connection. Wired connections I have no issues. Any thoughts?

    • @vewo234
      @vewo234 3 ปีที่แล้ว +1

      Are you using Capwap by any chance? Some smaller/older FGT models can‘t offload Capwap and CPU speed will limit the throughput.

    • @dineshchandrawanshi4683
      @dineshchandrawanshi4683 3 ปีที่แล้ว

      Use Appropriate fortiSwitch

  • @ebrahimshaikjee6799
    @ebrahimshaikjee6799 2 ปีที่แล้ว

    Great video, just curious why would you use the 3rd octet as your site identifier instead of the 2nd octet which makes alot more sense.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว +1

      It’s personal preference / scalability. I have situations where I use the second octet (when proposed future branches are smaller than 256). Otherwise, the third octet enables up to 2500 (although smaller potential subnets) branches

  • @ruellerz
    @ruellerz 3 ปีที่แล้ว

    I challenge your subnet and vlan design. The second octet should be the site identifier while the 3rd is for the VLAN ID. Maybe you said it wrong @ 12:20

    • @ruellerz
      @ruellerz 3 ปีที่แล้ว

      You lose the ability to do any summary routes . Give a site /16 and slice it up

  • @iamnotnice1536
    @iamnotnice1536 3 ปีที่แล้ว +1

    Fortinet are awesome. Beats the like of Sophos, Juniper, barracuda and Watchguard. I want this technology and its a solutions will help ALL the small and mid size now and the future. Where can i learn more.

  • @dunnjustintime
    @dunnjustintime 3 ปีที่แล้ว

    This was a great video! Thank you so much!!

  • @tomerpeer6398
    @tomerpeer6398 3 ปีที่แล้ว

    Hi Fortinet Guru, can toy stack fortinet switches with DAC cabels? if so, can you advertise a short brief of how to. thanks in advance. Tomer

  • @Desertedx
    @Desertedx 3 ปีที่แล้ว

    So great video!

  • @camryds
    @camryds 3 ปีที่แล้ว

    I would like to know how to configure FWF -> FAP in a mesh environment wireless mesh with VLAN

  • @harrylumsdon6773
    @harrylumsdon6773 3 ปีที่แล้ว

    Any ideas on the fortiextenders?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      They work ok. I only use them for failover

    • @harrylumsdon6773
      @harrylumsdon6773 3 ปีที่แล้ว

      Us too. Horrible reboot issues, seem fixed after 2 SW updates. modems would disconnect, til poe reboot. sometimes 17 a day.

  • @hudsonatlantis6754
    @hudsonatlantis6754 3 ปีที่แล้ว

    Great Video!

  • @eaperezh
    @eaperezh 3 ปีที่แล้ว

    I want to buy that t-shirt!!!! Where can I get it? Thankfully same applies here in Panama, Central America

  • @sdfnhghjdfbgh5851
    @sdfnhghjdfbgh5851 ปีที่แล้ว

    I have 100f , and need to switch over from the wan interface port to an sfp port. How would you proceed?

  • @shanemallard-n1i
    @shanemallard-n1i ปีที่แล้ว

    How would you do your vlans if you have your fw interfaces configured to handle the DHCP?

    • @FortinetGuru
      @FortinetGuru  ปีที่แล้ว +1

      My vlans themselves would handle the dhcp so no other edits would be necessary other than defining parameters.

  • @eraadw
    @eraadw 3 ปีที่แล้ว

    Thanks a lot for sharing your knowledge.
    I have been watching your videos for weeks/month now. And thanks to you I decided to buy a full stack (FG/FS/AP - Book) a week ago for myself and it seems this video came at the perfect moment.
    Since you mention other brand at the start of your video, I was wondering, even tho Fortinet seems way more advanced and reliable than many brand atm do you think installing Unifi or Edge for very small office is a good idea ?
    Anyway thanks again for sharing !!!!

  • @nielstaildeman
    @nielstaildeman 3 ปีที่แล้ว

    Nice video! One question though: As I understand from the example in the video, the fortiswitch is handling the L3. But is the Fortigate then still able to check traffic between l3 vlans?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      The fortigate will be handling all routing and access control.

  • @ibrahimngueyon9688
    @ibrahimngueyon9688 2 ปีที่แล้ว

    Great

  • @iamrichard8778
    @iamrichard8778 3 ปีที่แล้ว

    Hey man, you are pretty good at explaining things. Ever thought of doing a NS course? Heaps of CCNA YT focused channels around. Just a thought.

  • @ignaciosaravia5719
    @ignaciosaravia5719 3 ปีที่แล้ว

    Great video!! You make it easier to understand. Hey, do you know how to split an SD-WAN to share WAN1 through LAN port 2? Just a thought.

  • @danycontrerastorre87
    @danycontrerastorre87 3 ปีที่แล้ว

    how to get a tshit like that ?

  • @AhmadSwailem
    @AhmadSwailem 3 ปีที่แล้ว +1

    I loved your T-shirt 😂❤

    • @lkfng
      @lkfng 3 ปีที่แล้ว

      I wonder if he has hoodies for sale with the same slogan?

    • @AhmadSwailem
      @AhmadSwailem 3 ปีที่แล้ว

      @@lkfng i do too..

    • @hanold5049
      @hanold5049 3 ปีที่แล้ว

      love from china...

  • @stanleyilchev3503
    @stanleyilchev3503 3 ปีที่แล้ว

    Love the content!!
    What issues have you run into if you don't daisy-chain the switches, but connect them all directly to the firewall and "trunk" them from there?

  • @alarsen77
    @alarsen77 3 ปีที่แล้ว

    Great video! I am currently running a 60f and a 231f at home in a home lab. I have been thinking about adding a switch. I have a small network with only 5 wired devices (including the AP) so I was thinking the 108e PoE would be fine, but do you think the 124e PoE is worth the extra cost for future proofing?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      Depends on your port density needs. It would meet your future requirements tho.

    • @alarsen77
      @alarsen77 3 ปีที่แล้ว

      @@FortinetGuru I currently only have a few devices and don't have a plan for too many more right now, so was thinking the 8 port would be good and save on cost and I could always upgrade it later if needed. I just wasn't sure if the 24 poet had any better components that made it perform better.

  • @saikenjkd
    @saikenjkd 3 ปีที่แล้ว

    Any chance on a FortiEDR review? in light of all the latest outbreaks, would be a good time to talk about Fortinets offering compared to crowdstrike, S1, etc

  • @germanvas63
    @germanvas63 3 ปีที่แล้ว

    How can I contact you so I can ask for some advice? I’m in CA

  • @tj71tj71
    @tj71tj71 3 ปีที่แล้ว

    I noticed the warning "Security Fabric Connection is disabled" but obviously you are running security fabric? I seem to recall full fabric needs a FortiAnalyzer, is that so and why if so?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      To run the full security fabric you do need the analyzer in order for it to hold and do all of the correlations and data associations. Otherwise, the FortiGate can't hold enough data to maintain the database.

  • @luchobeto
    @luchobeto 3 ปีที่แล้ว

    how can you add fortigate hardware switch ports to the fortiswitch vlan after the fortilink
    is up and running ?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว +1

      Depending on how your fortilink interface is configured you can add and removal physical interfaces to it.

  • @bboosss1065
    @bboosss1065 3 ปีที่แล้ว

    Can you please explore more of the lldp med thing and the logic of the allowed / native thing? How do you decide which port is a trunk port? Or basically it does dot1q and you just decide the native

  • @punkeyengineer
    @punkeyengineer 2 ปีที่แล้ว

    what is a perimeter firewall ? please can someone answer me ! I have been hearing this word from so long, but still dont have a clue , whats a "perimeter" firewall

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Perimeter firewall, also known as the edge firewall. It provides security and such at the edge of a network going out to the world. ISFW (internal segmentation firewalls) provide more specific security services WITHIN the infrastructure (think along the lines of keeping accounting stuff only visible to them etc)

  • @kimhalavakoski5189
    @kimhalavakoski5189 3 ปีที่แล้ว

    Hello! Great video! One question though: I am testing out a similar setup with a FG-40F and have some issues in that the VLANs created on the FortiSwtich are not "easily" used on the FortiGate, meaning that I can not use a FortiSwitch VLAN on the FortiGate internal ports...seems like the two devices can't use the same VLANs? Any thoughts / feedback on that and how to use the some VLANs on both devices and possible to configure FortiGate with VLANs from Fortiswitch?

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      I recommend keeping all VLANs on the FortiSwitch interface and switches. The ports on the FortiGate itself I only use for Fortilink access honestly.
      You can do Software switches to group ports and interfaces together but then you lose hardware acceleration.

  • @erikbakke5401
    @erikbakke5401 3 ปีที่แล้ว

    Do you have url to the compatibility matrix regarding upgrade? I have also run into issues when upgrading fortigate with fortiswitch via fortilink

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว +1

      Google Fortilink Compatibility Matrix and you are set

  • @marcingowacki3647
    @marcingowacki3647 3 ปีที่แล้ว

    Great video and just on time as I am preparing to deploy full stack. Video proposal: Trusted CA certificate for deep SSL inspection. Can you recommend any commercial SSL certificate? First certificate I bought has CA:FALSE parameter and I am having problems finding certificate provider that will work for deep inspection and does not cost 200$. Is there any 20$ certificate on the market that will do the job?

  • @nagchampa4476
    @nagchampa4476 3 ปีที่แล้ว

    I love security fabric . Well done Fortinet, the best environnement ! ❤

  • @stage666
    @stage666 2 ปีที่แล้ว

    Do you work for fortinet?

  • @SoulJah876
    @SoulJah876 3 ปีที่แล้ว

    Is 6.4.6 considered stable now? I was considering upgrading from 6.2.1 to 6.2.8 on my 301E and 501E.

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      I’m running 6.4.6 on most gear now

    • @SoulJah876
      @SoulJah876 3 ปีที่แล้ว

      @@FortinetGuru Thanks for the feedback. I'll test it out.

    • @synchit1593
      @synchit1593 3 ปีที่แล้ว

      We are using that on an 1100e, experience memory leak issues which does follow through till 7 and all fortinet support has advised is to kill wad proxy process… one of the worst support experience we have in a mixed vendor environment, no one else can take that crown..

  • @G1rlyG33k
    @G1rlyG33k 3 ปีที่แล้ว

    Hey Mike, have you completed your NSE 8 exam? Your content is very helpful.

  • @amj-sauce
    @amj-sauce 2 ปีที่แล้ว

    I currently have this...
    [FGT-61F]──(LAN-AGG (Fortilink))──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE]──(Ports 23+24Ports 9+10)──[FSW-108E-FPOE]
    I want to do this...
    ┌──(Ports A+BPorts 9+10)─────[FSW-108E-FPOE]
    [FGT-61F]──(LAN-AGG (Fortilink))─┤
    └──(Ports 2+3+4+5Ports 25+26+27+28)──[FSW-124E-FPOE]
    Is this possible with FortiLink split interface? Per the research I have done, things keep pointing to MCLAG but I don't want to complicate things. Any advice?

  • @NorrisCarden
    @NorrisCarden 3 ปีที่แล้ว

    The AP on the FortiWiFi only has one radio, so can only run either 2.4ghz or 5ghz.

    • @zobs1234
      @zobs1234 3 ปีที่แล้ว

      Depends on the model really. 40F/60F has single radio. 80F has 3 radios (2 to serve customer +1 scanning). There was also a 50e-2r model with 2radios, but it's probably eos now.

  • @DonJudd
    @DonJudd 3 ปีที่แล้ว

    Mike, if you don't mind answering a dumb question for me. My internal LAN is 192.168.70.x. I have a gateway to gateway VPN to 192.168.1.x. My Data vlan is 10.70.10.x and is part of my INSIDE zone. Firewall policy for INSIDE>VPN is set to allow traffic. I am assuming my static route need to also be set for the 10.70.10.0/24 network, but how? Following this video, I have my VLANs working like yours (Data and Guest, I have no voice) but computers on my Data vlan can't reach the remote end of the VPN.

  • @nbctcp3450
    @nbctcp3450 ปีที่แล้ว

    in FortiSwitch how to set port to accept ip phone with VOICE vlan40 and DATA in vlan30
    because switch port > ip phone > pc all connected to switch using 1 ethernet port

  • @smokeforless3071
    @smokeforless3071 2 ปีที่แล้ว

    Hi any spare REG REF you could borrow me ? thanks

  • @TheDarrenSR
    @TheDarrenSR 3 ปีที่แล้ว

    The last ports on all switches LAN devices should always be your uplink ports it is best practice really

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      It is how I like to do it. If you have a standard and it works and is repeatable ultimately it will work fine.

  • @Mir_Aus
    @Mir_Aus 3 ปีที่แล้ว

    Can someone help with fqdn as I need to learn to to acess PCs with host name instead of IP when using Vpn

  • @kaain775
    @kaain775 3 ปีที่แล้ว

    This pairs perfectly with Microsoft 365 services, two exceptionally seamless technologies.

  • @Peteveneno
    @Peteveneno 3 ปีที่แล้ว

    The UTP cable that's comes with the fortiSwitsh or FortiGate esa WHITE, NOT yellow

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      Astute observation there sir.

  • @mosins5779
    @mosins5779 3 ปีที่แล้ว

    The vedio is not clear my friend

  • @SR_EMM
    @SR_EMM 3 ปีที่แล้ว

    Did you have a problem where Access Points Randomly disconnect from Controller? we have 2 networks of about 150 APs each and it happens all the time. Every week there is at least 5 Disconnected AP.

    • @FortinetGuru
      @FortinetGuru  3 ปีที่แล้ว

      Negative. What version of code and what model of AP / Gate?

    • @Mrrtbrs
      @Mrrtbrs 3 ปีที่แล้ว

      What FOS are you running on the FortiGate? What are your L2 Switches? any duplicate IP/DHCP Exhaustion? When then are "disconnected" can you ping/SSH etc to the devices?

  • @vmened
    @vmened 3 ปีที่แล้ว

    Mikrotik works better than fortinet)

  • @noah9341
    @noah9341 3 ปีที่แล้ว

    Palo is better

  • @RaviChinasamy
    @RaviChinasamy 3 ปีที่แล้ว

    First 😂

  • @anonymoususer1367
    @anonymoususer1367 3 ปีที่แล้ว

    What a shitty products. It is probably great for SOHO, but Fortinet has really weak IPS.

  • @lesterawalt3184
    @lesterawalt3184 3 ปีที่แล้ว

    That thing is junk and nothing but problems. I went back to Cisco stuff

  • @friedrice7707
    @friedrice7707 ปีที่แล้ว

    I have the same Fortinet stack connecting my Fortigate to FortiSwtich via FortiLink Interface A and from FortiSwitch PoE connection to FortiAP 221E. Using the 7.2.4 firmware on FG & FS. But I am getting rid of FortiSwitch and ForiAP as the switch is highly unreliable when connecting via FortiLink. The Fortilink between the Fortigate and FortiSwitch will drop to 100mbps despite replacing with brand new Cat 6E cables. And the only way to resolve the issue was to hard reset the switch. After reset and re-established the FortiLink, the same cable that was reporting 100mbps suddenly becomes 1Gbps. But on and off the Fortigate will report the authorized FortiSwitch is Offline. And I had to hard reset, authorized the switch and everything become normal again. The FortiAP wifi performance also sucks as my client will complain about the slow speed when connected to it. I had checked all the configs and the thing is a Asus home AP is more reliable then the more expensive FAP. I am keeping the Fortigate as it's very reliable in my opinion. Already ordered Unifi switch and U6E AP to replace my FortiSwitch and FortiAP. Will be testing them together with Fortigate before deploying them to Production sites. Give up hopes for FortiSwitch and FortiAP. Sad.

  • @youtubegarbage4u
    @youtubegarbage4u 2 ปีที่แล้ว

    you missed mikrotik!