Alex Pavlock
Alex Pavlock
  • Видео 14
  • Просмотров 42 738
Fortinet FortiClient / FortiEMS / FortiGate - Paid vs Free VPN
The video everyone has been waiting for! This video is going to break down the differences between paid and free VPN for FortiGate. We dive into some of the features and benefits of the paid version vs. the free version. We also touch on web filtering and ZTNA ( Zero Trust Network Access ) which comes within the vpn/ztna tier of licensing. We look at the different licensing options of FortiClient and form factors as well as deployment options for both options. Hope everyone enjoys the video and finds it helpful! I encourage you to read the documentation if you have questions on FortiClient or FortiEMS. As always if you do have questions after watching the video please leave a comment on t...
Просмотров: 3 438

Видео

FortiCloud IAM Users and User Groups - Tackling least privilege with IAM Users
Просмотров 1825 месяцев назад
Here is a step-by-step guide on how to create users and users groups within FortiCloud. IAM is absolutely critical in cloud security and helps organizations tackle the first pillar of least privilege and identify and access management. FortiCloud IAM can create granular permissions for users to grant them access to only the resources they need to do their job. Smash the like and subscribe butto...
IPSec VPN Tunnel Between Fortinet FortiGate and Cisco Meraki MX - Configuration and Troubleshooting
Просмотров 4,7 тыс.10 месяцев назад
In this video, Marcellus and I go through configuring a site to site IKEv1 IPSec VPN tunnel between a FortiGate (firmware version 7.2.5) and a MX (Firmware 18.107.2). In this example, both Firewalls are behind NAT devices so some configurations may be different depending on your specific environment. We cover configurations within Meraki dashboard and FortiGate GUI mgmt interface, configuring f...
Fortinet FortiGate and FortiAnalyzer Integration Slack + Microsoft Teams automated notifications
Просмотров 1,2 тыс.10 месяцев назад
This is a step by step guide on setting up automations within Analyzer and FortiGate to send notifications to Microsoft teams or slack channels. Teams is a new integration with Analyzer released in version 7.4. This integration can send a channel notification whenever an incident is created (whether manually or through playbook action), updated, or deleted. Also included is setting up channel n...
Fortinet FortiZTP how to setup guide / FortiLAN Cloud / FortiGate Cloud / FortiManager
Просмотров 1,4 тыс.10 месяцев назад
FortiZTP ( Zero Touch Provisioning )TLDR: FortiZTP is super easy to provision devices (Gates/ AP's/ Swithes) and push down configs. Once the setup is complete companies can ship out devices to locations and have non IT people plug in and once connected to the internet will pull down assigned configs. This is a step by step how to guide that customers and partners can follow to take advantage of...
Fortinet FortiAP's- How to form a wireless mesh network to extend your WLAN
Просмотров 4 тыс.11 месяцев назад
This is a how to guide for Fortinet Acces Points aka FortiAP's to form a wireless mesh connection to extend the wireless local area network (WLAN). In this scenario my FortiGate 80F is acting as the wireless controller using the built WLAN controller that comes in FortiOS. Every FortiGate has this functionality built in with no additional licensing costs to utilize this feature. My FortiAP mode...
Onboarding to FortiSASE / FortiClient / Secure Web Gateway
Просмотров 94311 месяцев назад
This video is a demonstration on what the onboarding process to FortiSASE looks like. As you can see onboarding to FortiSASE is very easy with just a few clicks. This also will show you how to roll out the solution to the end points as well. Within the Fortinet FortiSASE portal you can either download an installer package and roll out with an MDM solution or you can email it out directly to use...
Inside the mind of a hacker- Fortinet's FortiDeceptor
Просмотров 41811 месяцев назад
I created this video to show at a high level how a hacker is thinking once inside of your network. This is a high level beginner guide so you can understand what they are trying to do and some different techniques they use. I coupled this video with Fortinet's FortiDeceptor product to show how honeypots or decoys work to fool malicious actors into thinking they are hacking a real server when in...
Connecting Fortinet FortiAP to FortiLAN Cloud
Просмотров 3,5 тыс.11 месяцев назад
This is a how to video guide hooking up an AP to FortiLAN Cloud along with some basic AP radio and SSID configurations. This process is very easy and straightforward. Only takes about 10 minutes in total from unboxing to online and broadcasting! Let me know in comments if you have any questions!
Fortinet FortiDeceptor Demo
Просмотров 1,1 тыс.Год назад
This is a demonstration on some of the features and use cases for using Fortinet FortiDeceptor. This includes a slideshow presentation and GUI demo of the product. If you have any questions please leave a comment!
FortiSASE Private Access Setup Guide
Просмотров 4,7 тыс.Год назад
This is a how-to video/demonstration/walk-through with GUI on how to configure Fortinet's FortiSASE and private access. This shows how you would utilize FortiSASE for your remote workers but also enable them to reach internal resources using traditional VPN tunnels and not ZTNA access proxies. In this video you will see us configure a FortiGate, FortiSASE, and FortiClient to reach a local ESXi ...
How to onboard to Fortinet SOCaaS
Просмотров 339Год назад
Short walk-through of the process to onboard to Fortinet's SOCaaS. If theres any questions please leave a comment, I am happy to assist! Doc to Onboarding: docs.fortinet.com/document/forticloud-socaas/latest/frequently-asked-questions/317544/subscription-and-onboarding SOCaaS User Guide: docs.fortinet.com/document/forticloud-socaas/latest/user-guide/352650/introduction
FortiSwitch FortiAP demo
Просмотров 2,5 тыс.Год назад
High level run through of FortiAP and FortiSwitch products. Short slide deck presenting the two solutions followed by GUI demos. Covering both management options of FortiLink controlled by FortiGate and short FortiLAN Cloud demo. Any questions feel free to comment!
Fortinet FortiClient/FortiEMS/FortiGate using ZTNA tags to reach RDP server how to guide
Просмотров 14 тыс.Год назад
Fortinet FortiClient/FortiEMS/FortiGate using ZTNA tags and TCP forwarding to reach RDP server how to guide. Demonstration on configuring FortiEMS and FortiGate to use RDP client and TCP forwarding with ZTNA tags to allow or deny remote users to reach internal RDP server.

Комментарии

  • @senseimillian6747
    @senseimillian6747 12 часов назад

    Great job Alex! 🎉

  • @AnandNarine
    @AnandNarine 10 дней назад

    Nice.. but at 33:33, you said bridge mode does not use capwap? Isn't the fortiap itself managed by capwap to begin with? This is the security fabric connection checkbox that must be enabled on the fortigate interface that the ap connects to in order to be authorized. Formerly known as capwap in older fgt os.

  • @user-hp9dd5wz6c
    @user-hp9dd5wz6c 14 дней назад

    How do I setup a remote FortiAP

  • @user-hp9dd5wz6c
    @user-hp9dd5wz6c 14 дней назад

    Hey, how do I setup a remote fortiAP

  • @hoangtruonghuy4990
    @hoangtruonghuy4990 23 дня назад

    Have a nice day! Mr Alex. Could you help to share the topology in this video ? ( Fortinet and Meraki MX ). Thank you so much.

  • @evangelosmj
    @evangelosmj Месяц назад

    Nice brother, i really used this case in my lab, and it works perfect. :)

  • @BlizzTech
    @BlizzTech Месяц назад

    Could you please do a video on FortiLAN FortiSwitch? Like how to configure, apply VLAN interface IP with gateway, etc.

  • @lovemoremanyere3371
    @lovemoremanyere3371 Месяц назад

    on the deployment network, what is the deploy monitor IP?

  • @italianfunplay
    @italianfunplay Месяц назад

    Can i use the same tunel for fortisase and the spokes?

  • @nisaltharinda8517
    @nisaltharinda8517 Месяц назад

    What are the pre-requiesties for this configuration?

  • @anonymoususer6786
    @anonymoususer6786 2 месяца назад

    One of this was “simplified.” Clearly needed more rehearsing and constantly talked over each other. Also, way way way too long. Simple = better.

  • @DusanSim
    @DusanSim 2 месяца назад

    Good job Alex! This is a very good introduction to ZTNA and EMS.

  • @bandido428
    @bandido428 2 месяца назад

    What settings do you have for long distance mesh?

  • @lazzybug007
    @lazzybug007 3 месяца назад

    Thank you

  • @user-wr8zn4cf4b
    @user-wr8zn4cf4b 3 месяца назад

    Cool, learned something new, thank you

  • @gokucanfly4593
    @gokucanfly4593 3 месяца назад

    how do you make them statics? cant see this in any the settings so dumb vs cisco meraki

  • @roheetmishra9105
    @roheetmishra9105 3 месяца назад

    I've set up 2 FortiAPs via FortiCloud. However, after a few days, clients connected to the second AP are unable to access the internet. Both APs are connected to the same network. Can you please provide any suggestions to resolve this issue?

  • @krzysztofjasion8549
    @krzysztofjasion8549 3 месяца назад

    Great video! Thank you very much.

  • @emiljacobson7586
    @emiljacobson7586 3 месяца назад

    Did you pre-configure the 'ZTNA Destinations' in FortiClient before configuring the 'ZTNA Destination' in FC-EMS? That's a step you don't show, and my destinations from EMS aren't synchronized to FortiClient. Thanks, E

  • @aerialfruitbat1848
    @aerialfruitbat1848 3 месяца назад

    Thank you for a great video!

  • @kannanm7947
    @kannanm7947 3 месяца назад

    Thanks for the video Alex...I have few doubts, the connection from the forticlient to fortigate to access ZTNA server is through the SSL VPN only right, you told that the packet will be wrapped in Https and send to fortigate, getting confused 😕....One more doubt is that the ZTNA rules will be applied after decrypting the SSL packet right, in this case the normal firewall policy will not be applied after decryption????

  • @sabine8507
    @sabine8507 3 месяца назад

    very interesting video! Nicely done

  • @robertoallen2346
    @robertoallen2346 4 месяца назад

    If a computer does not have Forticlient, how can I prevent it from connecting to my network?

  • @Klarkooi
    @Klarkooi 5 месяцев назад

    Does it work for other use cases beside RDP for example certain system based user account is used for powershell or other protocol access to corp server?

  • @dns_error
    @dns_error 5 месяцев назад

    Lets say, currently, there is one big trust envoirnment that has all items user needs and users use forticlient to connect back using ipsec vpn. and channel all traffic back in including internet, which then gets inspected via security profiles using only one primary fortigate corporate firewall. Isnt this doing the exact same thing?

  • @oinkersable
    @oinkersable 5 месяцев назад

    Thanks for the video Alex but just to point out that on prem EMS is an app on a windows server and not a VM image.

  • @joemcgowan7554
    @joemcgowan7554 5 месяцев назад

    Is the FortiClient Cloud/EMS a subscription based service?

    • @fortialex
      @fortialex 5 месяцев назад

      Yes FortiClient/FortiEMS is only offered as a subscription based solution whether it’s VM or Cloud. Perpetual does not exist.

  • @dararim476
    @dararim476 5 месяцев назад

    Thanks for your sharing. I have a question, Is the ZTNA function helpful for on-net users?

    • @fortialex
      @fortialex 5 месяцев назад

      Great question! Yes, posture checking and ZTNA tags/rules can be applied to on prem users as well as off prem

  • @Building-IT
    @Building-IT 5 месяцев назад

    Nicely done! I am a network engineer at an enterprise company, and we have Meraki at all the plant locations but have FortiGate in the cloud. I personally dislike Meraki for multiple reasons. Hoping to move to Fortinet in the future. Meraki is great for an SMB, but not enterprise.

  • @MG-pf9xf
    @MG-pf9xf 7 месяцев назад

    Hi. You mentioned Proxy IP is your wan interface IP which is setup on VIP. then what IP you are using on ZTNA server? please explain a bit.

  • @MG-pf9xf
    @MG-pf9xf 7 месяцев назад

    Hi. Do I need to put my on-prem EMS server on DMZ and allow port? Because when I am going off fabric the forticlient shows disconnected.

    • @fortialex
      @fortialex 7 месяцев назад

      Yes, on prem EMS needs to have ports open on the upstream firewall to allow remote devices to communicate with it. A list of the necessary ports can be found here: docs.fortinet.com/document/forticlient/7.2.2/ems-quickstart-guide/439480/required-services-and-ports

    • @MG-pf9xf
      @MG-pf9xf 7 месяцев назад

      @@fortialex Thanks. Do I need to put that EMS server into DMZ or VIP with static NAT will be fine and put that VIP on Forticlient so it can communicate with EMS server from outside world?

    • @MG-pf9xf
      @MG-pf9xf 7 месяцев назад

      ?

  • @manitou89
    @manitou89 7 месяцев назад

    Thanks for the video, it did help, but I had to contact Fortigate because the tunnel would not come up. It turned out that the Fortigate was advertising the FQDN and not the public IP. We had to enter the command "set localid-type address" and then both ends came up.

  • @user-pe6wr8xq9o
    @user-pe6wr8xq9o 7 месяцев назад

    is there a way to setup ZTNA just on a fortigate without EMS and such?

    • @fortialex
      @fortialex 7 месяцев назад

      No, the Fortinet solution requires EMS and FortiClient or SASE

  • @abiodunotusanya2679
    @abiodunotusanya2679 7 месяцев назад

    Great demo. you rock

  • @fabricembomda2045
    @fabricembomda2045 7 месяцев назад

    great !!!!!

  • @recardooneal9900
    @recardooneal9900 8 месяцев назад

    How do ZTNA rules interact with regular firewall policy?

    • @fortialex
      @fortialex 8 месяцев назад

      They do not interact with regular firewall policy rules they are separate. ZTNA rules protect ZTNA servers that you define

  • @deezgasx331
    @deezgasx331 8 месяцев назад

    Is there any configuration needed in the firewall policy? I followed the steps, but I am unable to RDP to my server using the local IP address.

  • @ac_playz865
    @ac_playz865 8 месяцев назад

    I was wondering - we have a Meraki Mesh ( Auto hub ) of 6 units in various states. Got the Fortigate to establish a tunnel from one of the Merakis in the mesh, but how would you go about creating the rest of the tunnels on the fortigate side, any tricks because we have tried duplicating what is working for the first, and no dice every time.

  • @alexalexeev695
    @alexalexeev695 8 месяцев назад

    diag deb application ike 4 .. and you'll see all Ph1 and Ph2 messaging, don't forget to apply the filter for the specific tunnel. Plus, you have to mention how Fortigate handles Ph2 SA per subnet vs Cisco or Meraki .

  • @erickj3929
    @erickj3929 8 месяцев назад

    Appreciate the video Alex! First time setting up VPN tunnel between MX and FortiGate, and this worked out perfectly for me.

  • @chrismoore1981
    @chrismoore1981 9 месяцев назад

    Great Video Alex!! Am I correct in saying that FSSO is no longer needed. I would think FortiClient with ZTNA is a much better solution for RBAC vs FSSO?

    • @fortialex
      @fortialex 8 месяцев назад

      FortiClient ZTNA is a more comprehensive RBAC than just FSSO as you can control access to resources based on a wider set of end point posture checks. FSSO allows/denies access to resources based on strictly whos logged into the end point and what AD group they are apart of where ZTNA has many many different posture checks you can perform including but not limited to just AD group.

  • @MeekiDeekay
    @MeekiDeekay 9 месяцев назад

    Thank you for your helpful videos!! I am currently also trying to get some FortAP's in FortiLan Cloud. I have them connected and are working perfectly with a normal SSID. But I want to configure Mesh for these AP's. The documentation seems hard to find for Forticloud on this subject. There is no place where I can set a SSID for the backhaul. Have you tried this in Forticloud? BTW i am trying this with the FortiAP FAP-U321EV model. Or is this new SSID where I select Mesh-link the backhaul?

  • @dohoathanh
    @dohoathanh 9 месяцев назад

    I want to configure mesh to forti ap on fortilan cloud but I not see tab ssids to add mesh.root so do you config mesh on fortilan cloud?

    • @fortialex
      @fortialex 9 месяцев назад

      Under the SSID configuration page you would turn on "mesh link". Wireless>Configuration>SSID>Add New> 5th option on the SSID config page is "mesh link" with a toggle you would flip to on

  • @user-hk4gf2nl5d
    @user-hk4gf2nl5d 9 месяцев назад

    Great Video

  • @FortiBytes
    @FortiBytes 10 месяцев назад

    Good videos guys, keep them coming.

  • @raini_does_stuff5173
    @raini_does_stuff5173 10 месяцев назад

    Thanks for the tutorial. I was missing the part with the CLI, but now everything works as intended

  • @AhmadSwailem
    @AhmadSwailem 10 месяцев назад

    Can you do a video about fortiauthenticator?

    • @fortialex
      @fortialex 10 месяцев назад

      Is there a specific feature around FortiAuthenticator your looking for a video on?

  • @praneethbashitha7136
    @praneethbashitha7136 10 месяцев назад

    Useful content

  • @AhmadSwailem
    @AhmadSwailem 10 месяцев назад

    Thank you

  • @AhmadSwailem
    @AhmadSwailem 10 месяцев назад

    Thank you for the great video.. keep up the good work ❤