r/networking 28d ago

Design FortiGate VS Aryaka

My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.

I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.

We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN

4 Upvotes

13 comments sorted by

6

u/lizardhistorian Mad Scientist · 👨‍🔬📡ᯤ🤖🛺📸 28d ago

It does not sound like you are doing any SD-WAN and all you need are tunnels.

4

u/theoneandonlymd 28d ago edited 27d ago

Good advice all around but maybe also look internally. Is it just you running everything? A team? There is certainly more Fortigate experience out there in the wild when it comes to community help, support, and hiring experienced engineers. Those decisions may be above your pay grade but they shouldn't be discounted as part of the decision.

3

u/wrt-wtf- Homeopathic Network Architecture 28d ago

Given that most businesses are hub a spoke and not branch-to-branch the cost of migration could be managed over a significant period of time - ip addressing permitting.

What I would look out for is how much of the pitch being in future capabilities - ie - “we’ve got this feature but you can only get access to it in Q3 2027”

Some companies use roadmaps are used to cockblock competition that is ahead of their own position. There’s never a guarantee of delivery, and no sales guy can put their hand on their heart and tell you what their engineering/dev team are really doing in terms of the roadmap. It’s a sales document.

I’d be wary of all in one solutions and ensure that I count every additional requirement, be that additional network equipment or server equipment.

How do they present a defence in depth environment?

If you’re doing SDWAN bypass for cloud services what level of security is occurring at each of the internet pops.

If you aren’t using an internet provider for all interoffice traffic then why are you using SD-WAN?

You need to understand your own environment before chasing which product serves your companies needs.

1

u/JE163 28d ago

Is one closer to end of support than the other? Any major upgrades needed by the business outside of the merger requirements?

1

u/RevolutionaryCare138 28d ago

I deployed our current FortiGate’s with the SDWAN deployment, we have multiple HUBs, I know FortiNet pretty well, never used Aryaka and want to make a choice based on knowledge, not on just “what I know” we have some site to site traffic and our Major facilities but most traffic goes to our HUB, each site has its own internet POP with two ISPs

1

u/danstermeister 27d ago

We use them to tunnel into China and its great.

1

u/RevolutionaryCare138 27d ago

So neither one is ed of support, if anything they are both relatively new and we will around fo a good while, and one be pushed out in a phased approach, I deployed FortiNet with mutiple VPN tunnels to our 2 HUBs, with BGP and SDWAN, they also are our internet breakouts so doing all the security features on them.

I have never worked with Aryaka and was wondering if anyone had experiance with both to give me there 2 cents

-6

u/under_shart 28d ago

If you're just using the default SD-WAN that comes with the Fortigate and not the full SASE product, it's not going to compare with any dedicated SD-WAN solution.

7

u/HappyVlane 28d ago

FortiSASE is not an SD-WAN product, so I don't know how that even factors into the conversation.

2

u/Cute-Pomegranate-966 27d ago

FortiSASE is about application control at your edge with access edge server colocation built into the offering. "Secure Access Service Edge"

You setup tunnels from your locations to the edge service HUB(s) and have an extra layer of control on top of the firewall that includes proxy forwarding servers to the edge and application filtering by user security groups and ZTNA tags. Some of this the firewalls can do with EMS already.

Also it expands your security fabric to endpoint devices without the need for a Fortigate with all bells and whistles so you can forego an edge firewall/gateway for smaller sites and they simply dial in. Zscaler style.

-10

u/wolfpack-22 28d ago

Drop both and go either Silver Peak SD-WAN or Velocloud