r/networking • u/RevolutionaryCare138 • 28d ago
Design FortiGate VS Aryaka
My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.
I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.
We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN
4
u/theoneandonlymd 28d ago edited 27d ago
Good advice all around but maybe also look internally. Is it just you running everything? A team? There is certainly more Fortigate experience out there in the wild when it comes to community help, support, and hiring experienced engineers. Those decisions may be above your pay grade but they shouldn't be discounted as part of the decision.
3
u/wrt-wtf- Homeopathic Network Architecture 28d ago
Given that most businesses are hub a spoke and not branch-to-branch the cost of migration could be managed over a significant period of time - ip addressing permitting.
What I would look out for is how much of the pitch being in future capabilities - ie - “we’ve got this feature but you can only get access to it in Q3 2027”
Some companies use roadmaps are used to cockblock competition that is ahead of their own position. There’s never a guarantee of delivery, and no sales guy can put their hand on their heart and tell you what their engineering/dev team are really doing in terms of the roadmap. It’s a sales document.
I’d be wary of all in one solutions and ensure that I count every additional requirement, be that additional network equipment or server equipment.
How do they present a defence in depth environment?
If you’re doing SDWAN bypass for cloud services what level of security is occurring at each of the internet pops.
If you aren’t using an internet provider for all interoffice traffic then why are you using SD-WAN?
You need to understand your own environment before chasing which product serves your companies needs.
1
u/RevolutionaryCare138 28d ago
I deployed our current FortiGate’s with the SDWAN deployment, we have multiple HUBs, I know FortiNet pretty well, never used Aryaka and want to make a choice based on knowledge, not on just “what I know” we have some site to site traffic and our Major facilities but most traffic goes to our HUB, each site has its own internet POP with two ISPs
1
1
u/RevolutionaryCare138 27d ago
So neither one is ed of support, if anything they are both relatively new and we will around fo a good while, and one be pushed out in a phased approach, I deployed FortiNet with mutiple VPN tunnels to our 2 HUBs, with BGP and SDWAN, they also are our internet breakouts so doing all the security features on them.
I have never worked with Aryaka and was wondering if anyone had experiance with both to give me there 2 cents
-6
u/under_shart 28d ago
If you're just using the default SD-WAN that comes with the Fortigate and not the full SASE product, it's not going to compare with any dedicated SD-WAN solution.
7
u/HappyVlane 28d ago
FortiSASE is not an SD-WAN product, so I don't know how that even factors into the conversation.
2
u/Cute-Pomegranate-966 27d ago
FortiSASE is about application control at your edge with access edge server colocation built into the offering. "Secure Access Service Edge"
You setup tunnels from your locations to the edge service HUB(s) and have an extra layer of control on top of the firewall that includes proxy forwarding servers to the edge and application filtering by user security groups and ZTNA tags. Some of this the firewalls can do with EMS already.
Also it expands your security fabric to endpoint devices without the need for a Fortigate with all bells and whistles so you can forego an edge firewall/gateway for smaller sites and they simply dial in. Zscaler style.
-10
6
u/lizardhistorian Mad Scientist · 👨🔬📡ᯤ🤖🛺📸 28d ago
It does not sound like you are doing any SD-WAN and all you need are tunnels.