Tuesday, August 24, 2021

Anyone running a full Fortinet stack (FortiGates, switches, APs)?

Hey all,

We are planning an expansion of our infrastructure soon and are planning for rapid growth. Currently our stack is a jumbled mess of Ubiquiti and other prosumer junk. We have several remote sites that are pretty small footprint (probably requires 1-2 switches, 3-5 APs) and more on the way.

I currently run a Fortinet stack in my lab, and it gets the job done (although I do find the FortiLink interface to break after upgrades/reboots). One thing I love about Fortinet is that policy changes are instant (unlike Palo, Check Point) and generally seem to have a lower TCO (I could be wrong on this). I do know there is always a debate of which version of FortiOS you should be running in production and that their releases are sometimes considered to be more "beta" than production ready. (I'm currently running 7.0.1 in my lab.)

Does anyone have experience running a full Fortinet network stack in production? I'm talking the whole package - Fortigates, FortiSwitches, FortiAPs, and even their SD-WAN feature. I'd love to know your thoughts on it. Pros, Cons, Pain points, costs, upgradability, and any other things I should know.

Also, if anyone has experience with running Fortinet products in a more "infrastructure-as-code" manner, I'd love to know how that's going.



No comments:

Post a Comment