Тёмный
Alex Pavlock
Alex Pavlock
Alex Pavlock
Подписаться
Комментарии
@Brijeshkumar-fo5mt
@Brijeshkumar-fo5mt День назад
Hi Alex, Really appreciate for your explanation, could you please confirm where 208.59.51.196 this was configured? was it NATTED Public IP of the FGT wan?
@gregterkanian5158
@gregterkanian5158 3 дня назад
Good video, but it would be helpful if you described why you were making those additional changes on the CLI. Fortinet is goofy and not always straight forward, so you have to explain why you're doing things, otherwise you're just another demo video.
@DTGMac
@DTGMac 16 дней назад
Tkx Alex!! This video saved me today!
@buzz4buzz428
@buzz4buzz428 16 дней назад
FortiClient is the worst VPN Client I have ever used. It constantly crashes. Just try telling them that though and they'll block you.
@hummer-k1k
@hummer-k1k Месяц назад
Is it possible to use SSO with ZTNA destinations? I mean not to type again the user/pass when establishing the RDP connection.
@chanmaharaj4822
@chanmaharaj4822 Месяц назад
Quite useful, appreciate the content
@alwayskarbala
@alwayskarbala Месяц назад
Bro love your videos. Could you provide me training session ?
@christopherdesouza7339
@christopherdesouza7339 Месяц назад
Had conversation with Fortinet. They said that 2.4Ghz is recommended for backhaul as it travels better the 5Ghz. Specially through objects and structure. They found that majority of APs in a Mesh configuration are in different rooms/areas and rare that they are in same open space. As users are connecting in same space to 1 of the APs then don't have to worry about going through walls as an example has worked out better. After change we notice better performance for sure on non cabled APs using mesh. Again it would depend on situation... A house with drywall instead of concreate filled block walls in office spaces probably better to go opposite or something like large venue halls, gyms definitely want to go backplane on 5Ghz.
@deepaksharma1906
@deepaksharma1906 2 месяца назад
If we add ztna tag in sase for spa using sdwan, and then user moved to on-premise (on-net), how ztna will work in this scenario?
@etakwilkie
@etakwilkie 2 месяца назад
Hey Alex have you set SASE up with ZTNA? I am trying to get it setup.
@standartmedia9937
@standartmedia9937 2 месяца назад
I did the same, but my status is offline. Directly the router is working good. Can you help me? Thanks in advance
@aliabdulrazaq3852
@aliabdulrazaq3852 2 месяца назад
can you a fortiswitch behind the leaf AP and authorize it?
@senseimillian6747
@senseimillian6747 2 месяца назад
Great job Alex! 🎉
@AnandNarine
@AnandNarine 3 месяца назад
Nice.. but at 33:33, you said bridge mode does not use capwap? Isn't the fortiap itself managed by capwap to begin with? This is the security fabric connection checkbox that must be enabled on the fortigate interface that the ap connects to in order to be authorized. Formerly known as capwap in older fgt os.
@MassyMotors-v2s
@MassyMotors-v2s 3 месяца назад
How do I setup a remote FortiAP
@MassyMotors-v2s
@MassyMotors-v2s 3 месяца назад
Hey, how do I setup a remote fortiAP
@hoangtruonghuy4990
@hoangtruonghuy4990 3 месяца назад
Have a nice day! Mr Alex. Could you help to share the topology in this video ? ( Fortinet and Meraki MX ). Thank you so much.
@evangelosmj
@evangelosmj 3 месяца назад
Nice brother, i really used this case in my lab, and it works perfect. :)
@BlizzTech
@BlizzTech 4 месяца назад
Could you please do a video on FortiLAN FortiSwitch? Like how to configure, apply VLAN interface IP with gateway, etc.
@lovemoremanyere3371
@lovemoremanyere3371 4 месяца назад
on the deployment network, what is the deploy monitor IP?
@italianfunplay
@italianfunplay 4 месяца назад
Can i use the same tunel for fortisase and the spokes?
@nisaltharinda8517
@nisaltharinda8517 4 месяца назад
What are the pre-requiesties for this configuration?
@anonymoususer6786
@anonymoususer6786 4 месяца назад
One of this was “simplified.” Clearly needed more rehearsing and constantly talked over each other. Also, way way way too long. Simple = better.
@DusanSim
@DusanSim 5 месяцев назад
Good job Alex! This is a very good introduction to ZTNA and EMS.
@bandido428
@bandido428 5 месяцев назад
What settings do you have for long distance mesh?
@lazzybug007
@lazzybug007 5 месяцев назад
Thank you
@ShowerJujube
@ShowerJujube 6 месяцев назад
Cool, learned something new, thank you
@gokucanfly4593
@gokucanfly4593 6 месяцев назад
how do you make them statics? cant see this in any the settings so dumb vs cisco meraki
@roheetmishra9105
@roheetmishra9105 6 месяцев назад
I've set up 2 FortiAPs via FortiCloud. However, after a few days, clients connected to the second AP are unable to access the internet. Both APs are connected to the same network. Can you please provide any suggestions to resolve this issue?
@krzysztofjasion8549
@krzysztofjasion8549 6 месяцев назад
Great video! Thank you very much.
@emiljacobson7586
@emiljacobson7586 6 месяцев назад
Did you pre-configure the 'ZTNA Destinations' in FortiClient before configuring the 'ZTNA Destination' in FC-EMS? That's a step you don't show, and my destinations from EMS aren't synchronized to FortiClient. Thanks, E
@aerialfruitbat1848
@aerialfruitbat1848 6 месяцев назад
Thank you for a great video!
@kannanm7947
@kannanm7947 6 месяцев назад
Thanks for the video Alex...I have few doubts, the connection from the forticlient to fortigate to access ZTNA server is through the SSL VPN only right, you told that the packet will be wrapped in Https and send to fortigate, getting confused 😕....One more doubt is that the ZTNA rules will be applied after decrypting the SSL packet right, in this case the normal firewall policy will not be applied after decryption????
@sabine8507
@sabine8507 6 месяцев назад
very interesting video! Nicely done
@robertoallen2346
@robertoallen2346 7 месяцев назад
If a computer does not have Forticlient, how can I prevent it from connecting to my network?
@Klarkooi
@Klarkooi 7 месяцев назад
Does it work for other use cases beside RDP for example certain system based user account is used for powershell or other protocol access to corp server?
@dns_error
@dns_error 7 месяцев назад
Lets say, currently, there is one big trust envoirnment that has all items user needs and users use forticlient to connect back using ipsec vpn. and channel all traffic back in including internet, which then gets inspected via security profiles using only one primary fortigate corporate firewall. Isnt this doing the exact same thing?
@oinkersable
@oinkersable 7 месяцев назад
Thanks for the video Alex but just to point out that on prem EMS is an app on a windows server and not a VM image.
@joemcgowan7554
@joemcgowan7554 8 месяцев назад
Is the FortiClient Cloud/EMS a subscription based service?
@fortialex
@fortialex 8 месяцев назад
Yes FortiClient/FortiEMS is only offered as a subscription based solution whether it’s VM or Cloud. Perpetual does not exist.
@dararim476
@dararim476 8 месяцев назад
Thanks for your sharing. I have a question, Is the ZTNA function helpful for on-net users?
@fortialex
@fortialex 8 месяцев назад
Great question! Yes, posture checking and ZTNA tags/rules can be applied to on prem users as well as off prem
@80andybrown80
@80andybrown80 13 дней назад
@@fortialex if the gateway is the Firewall
@Building-IT
@Building-IT 8 месяцев назад
Nicely done! I am a network engineer at an enterprise company, and we have Meraki at all the plant locations but have FortiGate in the cloud. I personally dislike Meraki for multiple reasons. Hoping to move to Fortinet in the future. Meraki is great for an SMB, but not enterprise.
@MG-pf9xf
@MG-pf9xf 10 месяцев назад
Hi. You mentioned Proxy IP is your wan interface IP which is setup on VIP. then what IP you are using on ZTNA server? please explain a bit.
@MG-pf9xf
@MG-pf9xf 9 месяцев назад
?
@MG-pf9xf
@MG-pf9xf 10 месяцев назад
Hi. Do I need to put my on-prem EMS server on DMZ and allow port? Because when I am going off fabric the forticlient shows disconnected.
@fortialex
@fortialex 10 месяцев назад
Yes, on prem EMS needs to have ports open on the upstream firewall to allow remote devices to communicate with it. A list of the necessary ports can be found here: docs.fortinet.com/document/forticlient/7.2.2/ems-quickstart-guide/439480/required-services-and-ports
@MG-pf9xf
@MG-pf9xf 10 месяцев назад
@@fortialex Thanks. Do I need to put that EMS server into DMZ or VIP with static NAT will be fine and put that VIP on Forticlient so it can communicate with EMS server from outside world?
@MG-pf9xf
@MG-pf9xf 10 месяцев назад
?
@manitou89
@manitou89 10 месяцев назад
Thanks for the video, it did help, but I had to contact Fortigate because the tunnel would not come up. It turned out that the Fortigate was advertising the FQDN and not the public IP. We had to enter the command "set localid-type address" and then both ends came up.
@AustinRyou
@AustinRyou 10 месяцев назад
is there a way to setup ZTNA just on a fortigate without EMS and such?
@fortialex
@fortialex 10 месяцев назад
No, the Fortinet solution requires EMS and FortiClient or SASE
@abiodunotusanya2679
@abiodunotusanya2679 10 месяцев назад
Great demo. you rock
@fabricembomda2045
@fabricembomda2045 10 месяцев назад
great !!!!!
@recardooneal9900
@recardooneal9900 10 месяцев назад
How do ZTNA rules interact with regular firewall policy?
@fortialex
@fortialex 10 месяцев назад
They do not interact with regular firewall policy rules they are separate. ZTNA rules protect ZTNA servers that you define
@deezgasx331
@deezgasx331 11 месяцев назад
Is there any configuration needed in the firewall policy? I followed the steps, but I am unable to RDP to my server using the local IP address.
@ac_playz865
@ac_playz865 11 месяцев назад
I was wondering - we have a Meraki Mesh ( Auto hub ) of 6 units in various states. Got the Fortigate to establish a tunnel from one of the Merakis in the mesh, but how would you go about creating the rest of the tunnels on the fortigate side, any tricks because we have tried duplicating what is working for the first, and no dice every time.