Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Aware
Nov 18, 2003
Anyone deploying Versa? So far liking it a lot.

Adbot
ADBOT LOVES YOU

Aware
Nov 18, 2003
Seems very capable so far but very geared towards ISP/Telco/MSP space. Very complicated deployment but ticks what feels like every box, if you can work out how to get a configuration deployed. We're in PoC phase for some customers and replacing leased lines with it where it makes sense.

Aware
Nov 18, 2003
If you got meraki in your network I feel bad for you son, I got 99 problems but meraki ain't one.

Aware
Nov 18, 2003

GreenNight posted:

Or just put in 2 PSU's and save alot of work setting up HA and buying a second firewall.

And sell less firewalls and licenses? No... I don't think we'll be doing that.

Aware
Nov 18, 2003
On another note our Versa roll-out is going fairly well but multitenancy is a mindfuck in terms of configuring different elements in the right one. Also documentation is kinda poor and often you get better answers from the Juniper docs.

Aware
Nov 18, 2003
I think Mikrotik supports wireguard if that's an option st the remote sites? If the SRXs are already in place then I dunno.

Aware
Nov 18, 2003
The big vendors will be the last to implement wireguard support and it'll probably be not supported on old gear.

I just run wireguard on Linux behind a Fortigate myself but this is kind of the reverse of what you want.

Aware
Nov 18, 2003
Along the same line, are you sure they're routing the the fw subnet to the isr address .50 or did they provide two /30s for redundant equipment attached to the NTE?

Aware
Nov 18, 2003
Why would your router relay DHCP messages like that? It should only be configured to relay from your DHCP server and nothing else right?

Aware
Nov 18, 2003
My favourite meraki shitness was their routers didn't support vlan subinterfaces for WAN interfaces, dunno if they ever added that but ended up having to add switches in front of them to get it working a long time ago.

Aware
Nov 18, 2003

falz posted:

It's fortigate (firewall) 600e/1000d/etc.

You quoted from the FMG/FAZ manual not FGT.

Aware
Nov 18, 2003
It's probably not enterprise enough or too janky but for lab access I use Apache Guacamole to sit in between the RDP hosts and the clients which provides a seperate auth mechanism so your end users aren't directly logging in with RDP credentials, and use users/groups to control what RDP hosts they have access to.

Guacamole will use internally known credentials to automatically log into the chosen RDP host.

This runs in a browser, so you still need a the FortiVPN client to connect via the Fortigate (IPSEC/SSL mode doesn't really matter much), and then fire wall down access to only the Guacamole web interface.

I guess the other benefit is they can have a browser bookmark to gain access once they're on the VPN and you could stick Guacamole in some kind of DMZ to further limit access where it can only hit the RDP hosts via the Forti firewall as well.

Downside is you need a server to run Guac on. It's kind of a poor man's half assed secure remote access setup.

Adbot
ADBOT LOVES YOU

Aware
Nov 18, 2003
Comedy answer: just expose guacamole to the internet.

It's a rabbit whole you can go down into reverse proxies, SSL certs and some kind of SSO but I'd say a dialup client is still the simplest method. I think FortiWeb or whatever it's called does all this if you wanted to stick to a vendor solution.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply