The built in feature of Virtual Servers on the FortiGate gives you some flexibility on publicly (or load balanced internal) accessible resources. What examples and use cases are you utilizing this feature for?
@oleksandrlytvyn5324 жыл бұрын
I use "Virtual Server" for Active / Stand-by load balancing - in case main webserver goes down -> Fortigate will use Stand-by webserver and traffic will go there. This minimizes downtime of webserver availability for end-clients.
@marc0523 Жыл бұрын
Thanks for the video. Only issue I had with it is that you didn't explain what a virtual server is in simple terms. I spent 2/3 of the video wondering why anyone would want their Firewall to host a server; before I worked out the Firewall was just hosting a virtual IP, and that the actual server was still a physical device behind it.
@SevenLies4 жыл бұрын
Another point worth mentioning is that if the Virtual Server functionality on your FortiGate can take care of your load balancing, you may no longer need a separate hardware or software loadbalancer like an F5, haproxy or a FortiADC! The feature set you get for virtual servers you get out of the box with the FortiGates is pretty generous SSL, persistence and health checks are pretty good features. We are currently using FortiADCs for our load balancers, mostly for our internal Microsoft Exchange environment, once we finish moving to Office 365 we should be able to decomission them and move the other websites to run off the FortiGates
@FortinetGuru4 жыл бұрын
I have been offloading more and more items to my FortiGates.
@TheDervMan4 жыл бұрын
We use the FortiGate with great success. For the more complex requirements we use ADC's. Primarily we use it for exposing services to third parties via site to site VPN's. I'd high recommend using the Virtual Server feature on the FortiGates, super easy to setup and very reliable.
@FortinetGuru4 жыл бұрын
Absolutely. The ADC is a wicked good product as well.
@RowanKaag4 жыл бұрын
Adam Back I agree for the majority, but FortiGate can also load balance on HTTP Host header which is definitely L7.
@michaelrunyon3834 жыл бұрын
Learned something new here! Great video. Would love see a configuration example in the lab.
@FortinetGuru4 жыл бұрын
Will be doing a walk through instructional video on this either this week or next!
@imperionllc4 жыл бұрын
SSL offloading is another great feature of the Virtual Server.
@FortinetGuru4 жыл бұрын
Absolutely. Works well too!
@nickyadlosky38664 жыл бұрын
This is how I use Virtual Servers - helps mitigate external risks and vulnerabilities when legacy devices are present with Exchange that require TLS 1.0/1.1, while securing external traffic over TLS 1.2
@dine2139 Жыл бұрын
What if the environment already have a load balancer already, how would you implement FortiGate to do deep packet inspection on inbound traffic?
@FortinetGuru Жыл бұрын
Sounds like another video for us to do!
@tobibabatunde1377 Жыл бұрын
When use cases do I really need a FortiADC and not just FortiGate?
@FortinetGuru Жыл бұрын
ADC for big enterprise deployments or deployments where you are going to have a robust application that absolutely must be manageable and protected.
@reinaldootero44992 жыл бұрын
Can i comunicate two hosts between their public IPs trought diferent ISP under the samer fortigate?
@FortinetGuru2 жыл бұрын
You would have to do hairpin VIPs or something of that sort if I am understanding the question properly.
@loganbat13104 жыл бұрын
Off-topic: I have 5 sites that connect to each other via elan. If I am copying address objects and firewall objects from one router to another, do I have to remove or change the UUIDs in the text config? What happens if they were all the same UUIDs?
@FortinetGuru4 жыл бұрын
Wont matter. In fact, most of the time CLI will kick out an error about UUID not being able to be set anyways. So it will just skip that parameter and set it locally itself.
@loganbat13104 жыл бұрын
@@FortinetGuru Thank you for that info. My manager was worried and was going to have me remove about 400 UUID lines of code in the config for when we copy/paste the cli. Oooph
@manotas05A4 жыл бұрын
There is another uses fort virtual servers?
@FortinetGuru4 жыл бұрын
More along the lines of granularity and how you use them. Public facing DNS, load balancing web apps, the types of health checks used etc
@finchy2310 Жыл бұрын
Are you able to load balance a VPN server?
@chrisfarrugia53974 жыл бұрын
Nice Stratocaster!! ;)
@Alk3fan224 жыл бұрын
Mike, I love your content, but I would much rather see an illustration of the content you’re talking about. You could still do cut scenes where the video pans back to your camera, but I think I would be much more interested in your videos if you had illustrations to support your points and explain them better. Would you like me to provide a video of an example of what I’m referring to?
@FortinetGuru4 жыл бұрын
Will work on it
@Alk3fan224 жыл бұрын
Fortinet Guru check out the channel “The CISO perspective “