IPSec vendor interoperability war stories
Hi everyone, I have a business need to support IPSEC tunnels with many different vendors as we don't get to select our partner's equipment vendors. We've had some recent problems with our existing equipment. At the moment we're look at whether whether software upgrades will help our current situation. While we're doing that we're also looking at what other options exist. I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-) Beer for those who can offer their experiences! Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000
On Thu, Aug 29, 2013 at 11:47 AM, Mark Goldfinch < mark.goldfinch(a)modicagroup.com> wrote:
I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-)
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie? -JB
I was going to keep quiet but I'll chime in now.
I've run an IPSec tunnel for many years between a Mikrotik and a Juniper
SRX. In the past (for many years as well) I've run an IPSec tunnel between
the same Mikrotik and a Fortigate. Has been rock solid stable the whole
time in general.
Cheers
Dave
On Thu, Aug 29, 2013 at 12:43 PM, Jonathan Brewer
On Thu, Aug 29, 2013 at 11:47 AM, Mark Goldfinch < mark.goldfinch(a)modicagroup.com> wrote:
I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-)
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
-JB
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
On 29 August 2013 12:43, Jonathan Brewer
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
We've had the opposite experience, RouterOS client and Fortinet without a problem. You sure can have a cookie, may need to be beer flavoured to pass list regs though! :-) Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000
I know this is SOT; but have you considered using a different tunnel tech
or are you completely married to IPSEC?
I have similar experiences in the past - i've found that for a large chunk
of use cases switching to OpenVPN on an commodity box sitting at the edge
is far more simple and reliable (and has a number of performance gains).
On 29 August 2013 13:02, Mark Goldfinch
On 29 August 2013 12:43, Jonathan Brewer
wrote: I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
We've had the opposite experience, RouterOS client and Fortinet without a problem. You sure can have a cookie, may need to be beer flavoured to pass list regs though! :-)
Thanks, -- * *Mark Goldfinch | Systems Team Leader
MODICA GROUP
nz: +64 4 498 6000
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
On 29 August 2013 16:15, Joel Wirāmu Pauling
I know this is SOT; but have you considered using a different tunnel tech or are you completely married to IPSEC?
I have similar experiences in the past - i've found that for a large chunk of use cases switching to OpenVPN on an commodity box sitting at the edge is far more simple and reliable (and has a number of performance gains).
Yes we are somewhat married to requiring good cross-vendor IPSec support. We already utilise OpenVPN where we can, our experience has been similar to yours. Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000
Hi Mark,
Two things I suggest there, one is look for ICSA ipsec cert, at least a 3rd party has tested the IPSEC implementation of a vendors product. FortiGate is certified in this area.
2nd I have a enterprise in Akld, where they ran FortiGate at HQ and interop with almost all vendors you can imagine, Watchguard, CP, ASA, etc.
Also Fortinet's KB online has a list of articles of what we are compatible with.
Br,
Jack
Fortinet
From: Mark Goldfinch
participants (6)
-
Andrew Thrift
-
Dave Mill
-
Jack Chan (Fortinet)
-
Joel Wirāmu Pauling
-
Jonathan Brewer
-
Mark Goldfinch