IPSec vendor interoperability war stories

Hi everyone, I have a business need to support IPSEC tunnels with many different vendors as we don't get to select our partner's equipment vendors. We've had some recent problems with our existing equipment. At the moment we're look at whether whether software upgrades will help our current situation. While we're doing that we're also looking at what other options exist. I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-) Beer for those who can offer their experiences! Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000

On Thu, Aug 29, 2013 at 11:47 AM, Mark Goldfinch < mark.goldfinch(a)modicagroup.com> wrote:
I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-)
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie? -JB

I was going to keep quiet but I'll chime in now. I've run an IPSec tunnel for many years between a Mikrotik and a Juniper SRX. In the past (for many years as well) I've run an IPSec tunnel between the same Mikrotik and a Fortigate. Has been rock solid stable the whole time in general. Cheers Dave On Thu, Aug 29, 2013 at 12:43 PM, Jonathan Brewer <jon.brewer(a)gmail.com>wrote:
On Thu, Aug 29, 2013 at 11:47 AM, Mark Goldfinch < mark.goldfinch(a)modicagroup.com> wrote:
I'd appreciate anyone's operational experiences between different IPSec vendors, either on-list or to me directly if you want to protect the identities of the not so innocent :-)
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
-JB
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog

On 29 August 2013 12:43, Jonathan Brewer <jon.brewer(a)gmail.com> wrote:
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
We've had the opposite experience, RouterOS client and Fortinet without a problem. You sure can have a cookie, may need to be beer flavoured to pass list regs though! :-) Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000

I know this is SOT; but have you considered using a different tunnel tech or are you completely married to IPSEC? I have similar experiences in the past - i've found that for a large chunk of use cases switching to OpenVPN on an commodity box sitting at the edge is far more simple and reliable (and has a number of performance gains). On 29 August 2013 13:02, Mark Goldfinch <mark.goldfinch(a)modicagroup.com>wrote:
On 29 August 2013 12:43, Jonathan Brewer <jon.brewer(a)gmail.com> wrote:
I've consistently failed to get a Mikrotik client to talk to Fortinet gateway. Can I have a cookie?
We've had the opposite experience, RouterOS client and Fortinet without a problem. You sure can have a cookie, may need to be beer flavoured to pass list regs though! :-)
Thanks, -- * *Mark Goldfinch | Systems Team Leader
MODICA GROUP
nz: +64 4 498 6000
_______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog

On 29 August 2013 16:15, Joel Wirāmu Pauling <joel(a)aenertia.net> wrote:
I know this is SOT; but have you considered using a different tunnel tech or are you completely married to IPSEC?
I have similar experiences in the past - i've found that for a large chunk of use cases switching to OpenVPN on an commodity box sitting at the edge is far more simple and reliable (and has a number of performance gains).
Yes we are somewhat married to requiring good cross-vendor IPSec support. We already utilise OpenVPN where we can, our experience has been similar to yours. Thanks, -- * *Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000

Hi Mark, Two things I suggest there, one is look for ICSA ipsec cert, at least a 3rd party has tested the IPSEC implementation of a vendors product. FortiGate is certified in this area. 2nd I have a enterprise in Akld, where they ran FortiGate at HQ and interop with almost all vendors you can imagine, Watchguard, CP, ASA, etc. Also Fortinet's KB online has a list of articles of what we are compatible with. Br, Jack Fortinet From: Mark Goldfinch <mark.goldfinch(a)modicagroup.com<mailto:mark.goldfinch(a)modicagroup.com>> Date: Thursday, 29 August 2013 4:32 PM To: Joel Wir?mu Pauling <joel(a)aenertia.net<mailto:joel(a)aenertia.net>> Cc: nznog <nznog(a)list.waikato.ac.nz<mailto:nznog(a)list.waikato.ac.nz>> Subject: Re: [nznog] IPSec vendor interoperability war stories On 29 August 2013 16:15, Joel Wir?mu Pauling <joel(a)aenertia.net<mailto:joel(a)aenertia.net>> wrote: I know this is SOT; but have you considered using a different tunnel tech or are you completely married to IPSEC? I have similar experiences in the past - i've found that for a large chunk of use cases switching to OpenVPN on an commodity box sitting at the edge is far more simple and reliable (and has a number of performance gains). Yes we are somewhat married to requiring good cross-vendor IPSec support. We already utilise OpenVPN where we can, our experience has been similar to yours. Thanks, -- Mark Goldfinch | Systems Team Leader MODICA GROUP nz: +64 4 498 6000<tel:%2B64%204%20498%206000> *** Please note that this message and any attachments may contain confidential and proprietary material and information and are intended only for the use of the intended recipient(s). If you are not the intended recipient, you are hereby notified that any review, use, disclosure, dissemination, distribution or copying of this message and any attachments is strictly prohibited. If you have received this email in error, please immediately notify the sender and destroy this e-mail and any attachments and all copies, whether electronic or printed. Please also note that any views, opinions, conclusions or commitments expressed in this message are those of the individual sender and do not necessarily reflect the views of Fortinet, Inc., its affiliates, and emails are not binding on Fortinet and only a writing manually signed by Fortinet's General Counsel can be a binding commitment of Fortinet to Fortinet's customers or partners. Thank you. ***
participants (6)
-
Andrew Thrift
-
Dave Mill
-
Jack Chan (Fortinet)
-
Joel Wirāmu Pauling
-
Jonathan Brewer
-
Mark Goldfinch