ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Fortinet Experiences

    IT Discussion
    fortinet networking firewall router fips
    9
    26
    4.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KellyK
      Kelly
      last edited by

      My primary outlying requirement is I need FIPS 140-2 compliance on any encryption used. Otherwise it is just your standard SMB requirements: VPN; firewall; IPS; site-to-site; etc.

      1 Reply Last reply Reply Quote 0
      • KellyK
        Kelly @JaredBusch
        last edited by

        @JaredBusch said in Fortinet Experiences:

        @Kelly I do not recommend them, but I have had clients over time that have had them existing and they seem to work without any major issues.

        What feature of the Fortinet is being pushed?

        It is no secret that I am a fan of the Ubiquiti gear. But when people want more than just router and firewall in the edge device, Ubiquiti is not the right tool for the job.

        @JaredBusch Why would you not recommend them?

        JaredBuschJ 1 Reply Last reply Reply Quote 0
        • KellyK
          Kelly @brianlittlejohn
          last edited by

          @brianlittlejohn said in Fortinet Experiences:

          I seem to remember them having a pretty big security flaw not too long ago...not positive though.

          I'm not finding anything doing basic searches, e.g. fortinet cva

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @Kelly
            last edited by

            @Kelly said in Fortinet Experiences:

            @brianlittlejohn said in Fortinet Experiences:

            I seem to remember them having a pretty big security flaw not too long ago...not positive though.

            I'm not finding anything doing basic searches, e.g. fortinet cva

            http://thehackernews.com/2016/01/fortinet-firewall-password-hack.html

            KellyK 1 Reply Last reply Reply Quote 2
            • KellyK
              Kelly @JaredBusch
              last edited by

              @JaredBusch said in Fortinet Experiences:

              @Kelly said in Fortinet Experiences:

              @brianlittlejohn said in Fortinet Experiences:

              I seem to remember them having a pretty big security flaw not too long ago...not positive though.

              I'm not finding anything doing basic searches, e.g. fortinet cva

              http://thehackernews.com/2016/01/fortinet-firewall-password-hack.html

              Ouch

              JaredBuschJ 1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch @Kelly
                last edited by

                @Kelly said in Fortinet Experiences:

                @JaredBusch said in Fortinet Experiences:

                @Kelly I do not recommend them, but I have had clients over time that have had them existing and they seem to work without any major issues.

                What feature of the Fortinet is being pushed?

                It is no secret that I am a fan of the Ubiquiti gear. But when people want more than just router and firewall in the edge device, Ubiquiti is not the right tool for the job.

                @JaredBusch Why would you not recommend them?

                I do not recommend UTM functionality to clients. So I have no need for any feature of the gear beyond routing and firewall.

                There is no reason to pay $400 (CDW price) for the lowest model unit, the Fortinet FortiGate 30E, when I can buy the Ubiquiti EdgeMAX PoE for $150, or the LITE for $90.

                scottalanmillerS 1 Reply Last reply Reply Quote 2
                • JaredBuschJ
                  JaredBusch @Kelly
                  last edited by

                  @Kelly said in Fortinet Experiences:

                  @JaredBusch said in Fortinet Experiences:

                  @Kelly said in Fortinet Experiences:

                  @brianlittlejohn said in Fortinet Experiences:

                  I seem to remember them having a pretty big security flaw not too long ago...not positive though.

                  I'm not finding anything doing basic searches, e.g. fortinet cva

                  http://thehackernews.com/2016/01/fortinet-firewall-password-hack.html

                  Ouch

                  Not as bad as it sounds when you read all the details. It was supposedly fixed in 2014, but never published or announced. Either way, it is resolved now, and there was never more than a proof of concept hack built prior to the announcement, that any one knows of.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    We've also had bad luck with fortinet. Like Jared we don't recommend UTMs as a product category and Fortinet as a vendor we had issues with stability. Plus the security issue. Definitely not someone I'd choose.

                    JaredBuschJ 1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @scottalanmiller
                      last edited by

                      @scottalanmiller said in Fortinet Experiences:

                      We've also had bad luck with fortinet. Like Jared we don't recommend UTMs as a product category and Fortinet as a vendor we had issues with stability. Plus the security issue. Definitely not someone I'd choose.

                      Don't say also when no one else has stated anything about bad luck.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @JaredBusch
                        last edited by

                        @JaredBusch said in Fortinet Experiences:

                        There is no reason to pay $400 (CDW price) for the lowest model unit, the Fortinet FortiGate 30E, when I can buy the Ubiquiti EdgeMAX PoE for $150, or the LITE for $90.

                        Yeah, and I'd consider the EdgeMAX to be a vastly superior product. One that I would certainly trust more from a support and security perspective. That it is cheaper is just the icing.

                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                        • JaredBuschJ
                          JaredBusch @scottalanmiller
                          last edited by

                          @scottalanmiller said in Fortinet Experiences:

                          @JaredBusch said in Fortinet Experiences:

                          There is no reason to pay $400 (CDW price) for the lowest model unit, the Fortinet FortiGate 30E, when I can buy the Ubiquiti EdgeMAX PoE for $150, or the LITE for $90.

                          Yeah, and I'd consider the EdgeMAX to be a vastly superior product. One that I would certainly trust more from a support and security perspective. That it is cheaper is just the icing.

                          Support from 3rd party, yes. Support from UBNT is email only still. So, that affects things for some.

                          scottalanmillerS BRRABillB 2 Replies Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @JaredBusch
                            last edited by

                            @JaredBusch said in Fortinet Experiences:

                            @scottalanmiller said in Fortinet Experiences:

                            @JaredBusch said in Fortinet Experiences:

                            There is no reason to pay $400 (CDW price) for the lowest model unit, the Fortinet FortiGate 30E, when I can buy the Ubiquiti EdgeMAX PoE for $150, or the LITE for $90.

                            Yeah, and I'd consider the EdgeMAX to be a vastly superior product. One that I would certainly trust more from a support and security perspective. That it is cheaper is just the icing.

                            Support from 3rd party, yes. Support from UBNT is email only still. So, that affects things for some.

                            Fortinet support and documentation was bad and wrong when we tried to use them. Email support from UBNT is, IMO, better.

                            1 Reply Last reply Reply Quote 0
                            • BRRABillB
                              BRRABill @JaredBusch
                              last edited by

                              @JaredBusch said i

                              Support from 3rd party, yes. Support from UBNT is email only still. So, that affects things for some.

                              Is the Unifi line different?

                              I've used the LIVE CHAT option on the controller before.

                              Deleted74295D 1 Reply Last reply Reply Quote 0
                              • Deleted74295D
                                Deleted74295 Banned @BRRABill
                                last edited by

                                @BRRABill said in Fortinet Experiences:

                                @JaredBusch said i

                                Support from 3rd party, yes. Support from UBNT is email only still. So, that affects things for some.

                                Is the Unifi line different?

                                Hugely different. EdgeMax Pro can do much more than the USG for example but the Unifi line gives you all of your devices from a single management tool with tracking and stats between devices seamlessly, also the alerts and reporting is good.

                                EdgeMax and other devices outside the Unifi range you have to treat like traditional stand alone devices but you get more performance and features as a result.

                                JaredBuschJ 1 Reply Last reply Reply Quote 1
                                • JaredBuschJ
                                  JaredBusch @Deleted74295
                                  last edited by

                                  @Breffni-Potter said in Fortinet Experiences:

                                  @BRRABill said in Fortinet Experiences:

                                  @JaredBusch said i

                                  Support from 3rd party, yes. Support from UBNT is email only still. So, that affects things for some.

                                  Is the Unifi line different?

                                  Hugely different. EdgeMax Pro can do much more than the USG for example but the Unifi line gives you all of your devices from a single management tool with tracking and stats between devices seamlessly, also the alerts and reporting is good.

                                  EdgeMax and other devices outside the Unifi range you have to treat like traditional stand alone devices but you get more performance and features as a result.

                                  UniFi = Meraki style cloud management that you don't pay for because it is on a controller you set up instead of on theirs.

                                  EdgeMax = Traditional stand alone router and switches.

                                  1 Reply Last reply Reply Quote 1
                                  • KellyK
                                    Kelly
                                    last edited by

                                    Unfortunately UBNT and none of their products show up on the FIPS validated list that I am required to use.

                                    travisdh1T 1 Reply Last reply Reply Quote 0
                                    • travisdh1T
                                      travisdh1 @Kelly
                                      last edited by

                                      @Kelly said in Fortinet Experiences:

                                      Unfortunately UBNT and none of their products show up on the FIPS validated list that I am required to use.

                                      What is FIPS? I don't remember running into that one yet.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @travisdh1
                                        last edited by

                                        @travisdh1 said in Fortinet Experiences:

                                        @Kelly said in Fortinet Experiences:

                                        Unfortunately UBNT and none of their products show up on the FIPS validated list that I am required to use.

                                        What is FIPS? I don't remember running into that one yet.

                                        https://en.wikipedia.org/wiki/Federal_Information_Processing_Standards

                                        System for making sure that vendors that pay off politicians get listed and guaranteed sales 😉

                                        DashrenderD 1 Reply Last reply Reply Quote 1
                                        • DashrenderD
                                          Dashrender @scottalanmiller
                                          last edited by

                                          @scottalanmiller said in Fortinet Experiences:

                                          System for making sure that vendors that pay off politicians get listed and guaranteed sales 😉

                                          Yeah - that's probably why they aren't on the list. To help keep their prices low!

                                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @Dashrender
                                            last edited by

                                            @Dashrender said in Fortinet Experiences:

                                            @scottalanmiller said in Fortinet Experiences:

                                            System for making sure that vendors that pay off politicians get listed and guaranteed sales 😉

                                            Yeah - that's probably why they aren't on the list. To help keep their prices low!

                                            Yup

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post