u/Busbyuk

I wonder if anyone here is using Fortimanager to manage maybe 100 devices and could tell me how much ingress/egress data they see come into and out of their Fortimanager appliance?

Obviously this will differ depending on usage but I'm trying to get a rough idea. This is for pricing something into Azure where inbound is free but anything above 100Gb a month you pay for.

Logging will be on a a seperate device btw.

thanks!

reddit.com
u/Busbyuk — 9 days ago

With IKEV1 support being removed from the new Forticlient and SSL-VPN being removed from the Fortigates themselves, I've been migrating everyone to IKEV2 using EMS.

For around 100 users I would say 80 of them are connecting fine using IKEV2, LDAP and 2FA (Fortitokens) however around 20% are consistently having issues and end up reverting back to SSL-VPN.

I've created both an UDP and TCP (443) IKEV2 profile for people to try. The TCP did solve some issues but a lot of people just cannot use IKEV2. I'm pretty sure it's likely their ISP/Router blocking it but I'm just wondering if there are any other tips I could check for when setting up the client on the Fortigate?

I've forced NAT Traversal and setup IKE fragmention. Any one else had issues which changing any settings helped at all?

Thanks!

reddit.com
u/Busbyuk — 14 days ago