Пікірлер
@alwayskarbala
@alwayskarbala 2 күн бұрын
Bro love your videos. Could you provide me training session ?
@christopherdesouza7339
@christopherdesouza7339 5 күн бұрын
Had conversation with Fortinet. They said that 2.4Ghz is recommended for backhaul as it travels better the 5Ghz. Specially through objects and structure. They found that majority of APs in a Mesh configuration are in different rooms/areas and rare that they are in same open space. As users are connecting in same space to 1 of the APs then don't have to worry about going through walls as an example has worked out better. After change we notice better performance for sure on non cabled APs using mesh. Again it would depend on situation... A house with drywall instead of concreate filled block walls in office spaces probably better to go opposite or something like large venue halls, gyms definitely want to go backplane on 5Ghz.
@deepaksharma1906
@deepaksharma1906 8 күн бұрын
If we add ztna tag in sase for spa using sdwan, and then user moved to on-premise (on-net), how ztna will work in this scenario?
@etakwilkie
@etakwilkie 12 күн бұрын
Hey Alex have you set SASE up with ZTNA? I am trying to get it setup.
@standartmedia9937
@standartmedia9937 19 күн бұрын
I did the same, but my status is offline. Directly the router is working good. Can you help me? Thanks in advance
@aliabdulrazaq3852
@aliabdulrazaq3852 28 күн бұрын
can you a fortiswitch behind the leaf AP and authorize it?
@senseimillian6747
@senseimillian6747 Ай бұрын
Great job Alex! 🎉
@AnandNarine
@AnandNarine Ай бұрын
Nice.. but at 33:33, you said bridge mode does not use capwap? Isn't the fortiap itself managed by capwap to begin with? This is the security fabric connection checkbox that must be enabled on the fortigate interface that the ap connects to in order to be authorized. Formerly known as capwap in older fgt os.
@user-hp9dd5wz6c
@user-hp9dd5wz6c Ай бұрын
How do I setup a remote FortiAP
@user-hp9dd5wz6c
@user-hp9dd5wz6c Ай бұрын
Hey, how do I setup a remote fortiAP
@hoangtruonghuy4990
@hoangtruonghuy4990 Ай бұрын
Have a nice day! Mr Alex. Could you help to share the topology in this video ? ( Fortinet and Meraki MX ). Thank you so much.
@evangelosmj
@evangelosmj 2 ай бұрын
Nice brother, i really used this case in my lab, and it works perfect. :)
@BlizzTech
@BlizzTech 2 ай бұрын
Could you please do a video on FortiLAN FortiSwitch? Like how to configure, apply VLAN interface IP with gateway, etc.
@lovemoremanyere3371
@lovemoremanyere3371 2 ай бұрын
on the deployment network, what is the deploy monitor IP?
@italianfunplay
@italianfunplay 2 ай бұрын
Can i use the same tunel for fortisase and the spokes?
@nisaltharinda8517
@nisaltharinda8517 2 ай бұрын
What are the pre-requiesties for this configuration?
@anonymoususer6786
@anonymoususer6786 3 ай бұрын
One of this was “simplified.” Clearly needed more rehearsing and constantly talked over each other. Also, way way way too long. Simple = better.
@DusanSim
@DusanSim 3 ай бұрын
Good job Alex! This is a very good introduction to ZTNA and EMS.
@bandido428
@bandido428 3 ай бұрын
What settings do you have for long distance mesh?
@lazzybug007
@lazzybug007 4 ай бұрын
Thank you
@user-wr8zn4cf4b
@user-wr8zn4cf4b 4 ай бұрын
Cool, learned something new, thank you
@gokucanfly4593
@gokucanfly4593 4 ай бұрын
how do you make them statics? cant see this in any the settings so dumb vs cisco meraki
@roheetmishra9105
@roheetmishra9105 4 ай бұрын
I've set up 2 FortiAPs via FortiCloud. However, after a few days, clients connected to the second AP are unable to access the internet. Both APs are connected to the same network. Can you please provide any suggestions to resolve this issue?
@krzysztofjasion8549
@krzysztofjasion8549 4 ай бұрын
Great video! Thank you very much.
@emiljacobson7586
@emiljacobson7586 4 ай бұрын
Did you pre-configure the 'ZTNA Destinations' in FortiClient before configuring the 'ZTNA Destination' in FC-EMS? That's a step you don't show, and my destinations from EMS aren't synchronized to FortiClient. Thanks, E
@aerialfruitbat1848
@aerialfruitbat1848 4 ай бұрын
Thank you for a great video!
@kannanm7947
@kannanm7947 4 ай бұрын
Thanks for the video Alex...I have few doubts, the connection from the forticlient to fortigate to access ZTNA server is through the SSL VPN only right, you told that the packet will be wrapped in Https and send to fortigate, getting confused 😕....One more doubt is that the ZTNA rules will be applied after decrypting the SSL packet right, in this case the normal firewall policy will not be applied after decryption????
@sabine8507
@sabine8507 4 ай бұрын
very interesting video! Nicely done
@robertoallen2346
@robertoallen2346 5 ай бұрын
If a computer does not have Forticlient, how can I prevent it from connecting to my network?
@Klarkooi
@Klarkooi 6 ай бұрын
Does it work for other use cases beside RDP for example certain system based user account is used for powershell or other protocol access to corp server?
@dns_error
@dns_error 6 ай бұрын
Lets say, currently, there is one big trust envoirnment that has all items user needs and users use forticlient to connect back using ipsec vpn. and channel all traffic back in including internet, which then gets inspected via security profiles using only one primary fortigate corporate firewall. Isnt this doing the exact same thing?
@oinkersable
@oinkersable 6 ай бұрын
Thanks for the video Alex but just to point out that on prem EMS is an app on a windows server and not a VM image.
@joemcgowan7554
@joemcgowan7554 6 ай бұрын
Is the FortiClient Cloud/EMS a subscription based service?
@fortialex
@fortialex 6 ай бұрын
Yes FortiClient/FortiEMS is only offered as a subscription based solution whether it’s VM or Cloud. Perpetual does not exist.
@dararim476
@dararim476 6 ай бұрын
Thanks for your sharing. I have a question, Is the ZTNA function helpful for on-net users?
@Building-IT
@Building-IT 6 ай бұрын
Nicely done! I am a network engineer at an enterprise company, and we have Meraki at all the plant locations but have FortiGate in the cloud. I personally dislike Meraki for multiple reasons. Hoping to move to Fortinet in the future. Meraki is great for an SMB, but not enterprise.
@MG-pf9xf
@MG-pf9xf 8 ай бұрын
Hi. You mentioned Proxy IP is your wan interface IP which is setup on VIP. then what IP you are using on ZTNA server? please explain a bit.
@MG-pf9xf
@MG-pf9xf 7 ай бұрын
?
@MG-pf9xf
@MG-pf9xf 8 ай бұрын
Hi. Do I need to put my on-prem EMS server on DMZ and allow port? Because when I am going off fabric the forticlient shows disconnected.
@MG-pf9xf
@MG-pf9xf 8 ай бұрын
@@fortialex Thanks. Do I need to put that EMS server into DMZ or VIP with static NAT will be fine and put that VIP on Forticlient so it can communicate with EMS server from outside world?
@MG-pf9xf
@MG-pf9xf 8 ай бұрын
?
@manitou89
@manitou89 8 ай бұрын
Thanks for the video, it did help, but I had to contact Fortigate because the tunnel would not come up. It turned out that the Fortigate was advertising the FQDN and not the public IP. We had to enter the command "set localid-type address" and then both ends came up.
@user-pe6wr8xq9o
@user-pe6wr8xq9o 8 ай бұрын
is there a way to setup ZTNA just on a fortigate without EMS and such?
@fortialex
@fortialex 8 ай бұрын
No, the Fortinet solution requires EMS and FortiClient or SASE
@abiodunotusanya2679
@abiodunotusanya2679 9 ай бұрын
Great demo. you rock
@fabricembomda2045
@fabricembomda2045 9 ай бұрын
great !!!!!
@recardooneal9900
@recardooneal9900 9 ай бұрын
How do ZTNA rules interact with regular firewall policy?
@deezgasx331
@deezgasx331 9 ай бұрын
Is there any configuration needed in the firewall policy? I followed the steps, but I am unable to RDP to my server using the local IP address.
@ac_playz865
@ac_playz865 9 ай бұрын
I was wondering - we have a Meraki Mesh ( Auto hub ) of 6 units in various states. Got the Fortigate to establish a tunnel from one of the Merakis in the mesh, but how would you go about creating the rest of the tunnels on the fortigate side, any tricks because we have tried duplicating what is working for the first, and no dice every time.
@alexalexeev695
@alexalexeev695 9 ай бұрын
diag deb application ike 4 .. and you'll see all Ph1 and Ph2 messaging, don't forget to apply the filter for the specific tunnel. Plus, you have to mention how Fortigate handles Ph2 SA per subnet vs Cisco or Meraki .
@erickj3929
@erickj3929 9 ай бұрын
Appreciate the video Alex! First time setting up VPN tunnel between MX and FortiGate, and this worked out perfectly for me.
@chrismoore1981
@chrismoore1981 10 ай бұрын
Great Video Alex!! Am I correct in saying that FSSO is no longer needed. I would think FortiClient with ZTNA is a much better solution for RBAC vs FSSO?
@MeekiDeekay
@MeekiDeekay 10 ай бұрын
Thank you for your helpful videos!! I am currently also trying to get some FortAP's in FortiLan Cloud. I have them connected and are working perfectly with a normal SSID. But I want to configure Mesh for these AP's. The documentation seems hard to find for Forticloud on this subject. There is no place where I can set a SSID for the backhaul. Have you tried this in Forticloud? BTW i am trying this with the FortiAP FAP-U321EV model. Or is this new SSID where I select Mesh-link the backhaul?
@dohoathanh
@dohoathanh 10 ай бұрын
I want to configure mesh to forti ap on fortilan cloud but I not see tab ssids to add mesh.root so do you config mesh on fortilan cloud?
@fortialex
@fortialex 10 ай бұрын
Under the SSID configuration page you would turn on "mesh link". Wireless>Configuration>SSID>Add New> 5th option on the SSID config page is "mesh link" with a toggle you would flip to on