Hi
Questions: 1. Is it possible to build redundant site-to-site VPN with above lines? So can load balance and auto fail-over VPN and Internet?
ANS:
1. static route configuration. you can add multiple static route to same destination with different distance value
2. config OSPF routing in both end to load balance the VPN
2. Can choosen application be prioritized?
ANS :
specific ip traffic can be route through a particular tunnel. also you can use traffic shaping option
3. What is the recommended Fortigate Model for branches with 30 or 50 users? And HQ if to handle 7 or up to 70 branches.
ANS :
for 30 users you can use fortigate 30E and above 50 use Fortigate 60E. in HQ use fortigate 100E for better throughput 4. Any other areas we should look into or take into consideration for this kind of implementation?
ANS :
find a fortinet partner 5. It is possible if we only use 1 broadband and 1 3G/4G line with both running Dynamic IP?
ANS :
better use a dedicated lease line in HQ with static ip address. you can also use fortiddns free dynamic dns service
Regards
Mahesh
An addition: If the institution is growing, you may wish to order a larger device for the HQ head end. Also before you go out and buy dozens of 30E units, I would try one first. They may not fulfill you needs 100%. They are very...underpowered? Your mileage may vary. All dependent on how many value added features you plan on using with the box. Strictly VPN it may work. Web filtering, AV, etc. may stress it to the point of bringing it screaming to it's knees.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.