Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pittstate
New Contributor III

Looking for Feedback on FortiAP and FortiSwitch in Large-ish Deployments

We are looking at FortiAPs and FortiSwitch(es) as alternatives to other hardware vendors we currently have deployed in our environment. Specific use case is residence hall wireless utilizing hospitality-style APs along with switch replacement.

 

I'm curious about your experience with deploying Fortinet's APs and switches in a large-ish environment.

In our case, around 900 APs and 50 switches.

 

  • What's your deployment size?
  • If you replaced/migrated your environment from another vendor, how do you think the Fortinet hardware/software/management compares?
  • Is there anything you miss that a Fortinet solution doesn't provide?
  • How reliable have your switches/ap been?
  • How have firmware updates gone?
  • Do you also utilize FortiManager for switch/ap management?
  • What are your major pain points with a Fortinet switch/ap solution?

Thank you in advance for any feedback on this.

 

 

 

 

3 REPLIES 3
distillednetwork
Contributor III

I have been involved in large school districts with many switches and aps.  Replacing it with the ecosystem makes is very easy to manage and inspect/segregate your traffic.  Everything has been running very well and upgrades will take some time based on your topology but have never had any major issues, just always read your compatability guides first.  

 

We have not used fortimanager because it all came back to one set of fortigates so didn't see much value.  

 

One thing to consider is bridge vs tunnel for ap management. 

 

We did a retirement home that had 2 aps in each room and ended up creating a network that bridged the SSID and ports in those two aps for each room.  Not sure if you are making the wired ports hot or not.

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
Pittstate

Thank you for your comments. We will be enabling the wired ports on the APs. While not a lot of students use the ports, the ones that do usually plug in their TVs, gaming systems or computers.

 

We are used to CAPWAP tunnels back to controllers in our existing environment. But we haven't decided on which way we would go on that. Still in the exploration phase. Aside from supporting half as many APs on the FG, do you see any advantages/disadvantages with bridging over tunneling in a Fortinet deployment?

distillednetwork

Bridging has less overhead on the FortiGate CAPWAP processes, etc, and allows local device communication on the switch ports, vs all the traffic going to the firewall.  This means you can't inspect it all, but it will reduce load on the uplinks.

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors