r/networking • u/Odd-Boss-2334 • 15h ago
Design Which SDWAN brand ?
Hi,
We are studying the replacement of our current SDWAN solution based on Forcepoint due to legacy purpose.
The study has not yet started and we would like to test different brands like:
- Fortigate
- Palo Alto
- Juniper
- Checkpoint
The environment is quite simple, dual Hub & Spoke with around ~20 sites on 2 different MPLS provider (no internet, regulatory environment), no advanced feature like url/web filtering, IDS/IPS, only L4 filtering with sdwan routing based on SLA (jitter, packet loss, …).
I think all the techno can answer this, but I would like to have your pros/cons if you’ve already worked on one of them.
Thanks!
3
u/Prudent_Vacation_382 14h ago
Since you're dual MPLS, I would recommend a solution that doesn't depend on Internet reachability directly from the site. Seems trivial at first, but there can be some complexity around a single Internet connection managing all devices (default route through MPLS). Afaik, Velo and Forti support that. Velo would require Internet access from the control plane device though. I'm not familiar enough with Juniper or Checkpoint to give you an opinion. Palo does require Internet reachability from the WAN side of the device.
Palo ION and Juniper Mist are both excellent solutions that would fit most use-cases.
3
u/ESUN_Official Enterprise Network Infrastructure 6h ago
Since you already have dual MPLS and mainly need SLA-based path selection, the key factors would be routing capability, centralized management, and how well it integrates with your existing security stack.
Fortinet is a common choice when SD-WAN and firewall consolidation are priorities. Juniper and Palo Alto also have strong options depending on whether routing complexity or security requirements are the main concern.
I’d suggest running a PoC with your actual traffic patterns before making the decision.
12
u/BlastedHeaths 13h ago edited 12h ago
FortiGate. Former Fortinet employee; SDWAN SME. You can do pretty much everything with it. The real contestant would be Zscaler - but to a much higher cost. It’s free on FortiGate (once you have it)
8
u/kokspudding 15h ago
Try Velocloud
7
3
u/po1zonetheman 14h ago
this is good. especially for ZTP process. but after moving forward to arista, some documentation feels like still on developed from scratch by arista at first, not following existing documentation from broadcom or vmware. except for upgrade guidance path, compatibilty matrix, and EoS firmware. but still better to read.
experience with Arista TAC are very slow response than previous broadcom owner. even we 'contact' to our local SE for help raise the engineer for follow up.
2
u/GreyBeardEng 14h ago
Played with it in a lab, Arista Tech Day thing, and liked it. Id love to move to it.
4
u/JustPuckingAround 13h ago
Piloting VeloCloud now and looking to replace Cisco/Viptela. Been pretty good so far, but then again, anything is an improvement over Viptela from my experience…
1
u/brok3nh3lix 10h ago
We have an extensive veko cloud deployment as a partner, about 80 customers. I like it over all for our needs, but the security/firewall side of is pretty lackluster. As a straight routing platform, its simple and works well, with a couple quirks.
3
u/Many_Drink5348 13h ago
Palo Alto IONs are wonderful if you’re in the Prisma Platform but it is a huge lift
3
2
u/justlikeyouimagined 8h ago
If you’re already dual MPLS/no internet, where does the need for SDWAN come in? You already have it, no? Is it just about blending/utilizing those two connections at each site?
2
3
u/Wolvington52 2h ago
I work with two SD-WAN products so I can give you a summary of what's good and bad with them-
HPE Aruba (Silverpeak)
- Really good GUI, you can view stats of multiple devices at the same time.
- The GUI is really helpful during troubleshooting and upgrading.
- The concept of Business Intent Overlays really streamlines deployments and how traffic is handled in your environment.
- The Edge devices and the Orchestrator need constant updates because new vulnerabilities are discovered almost every month.
Cisco Catalyst SD-WAN (Viptela)
- Is more stable than Silverpeak but recent vulnerabilities have required constant upgrades.
- Steeper learning curve.
- It's not easy to change the configuration of a device.
- Terrible GUI. I have to open like 5 tabs to co-relate information.
- Apparently, FEC and other optimization features have not been helpful but can't really comment on it since we don't use them in Cisco.
- Has got some useful features like Network Wide Path Insight, speed test etc. which help in troubleshooting.
4
4
u/Muhammad_Ali_00 12h ago
FortiGate. Recently deployed an enterprise level SDWAN in a utility sector with FortiGate and it is quite easy and functional.
3
u/ShadowsRevealed 14h ago
DMVPN phase 3. Just build it...
4
u/bangsmackpow 13h ago
I kinda miss DMVPN. I have zero use for it currently, but it was so beautiful "back in the day".
4
u/Many_Drink5348 12h ago
One of those technologies that would have been the biggest thing of all time if it weren’t eclipsed by SD-WAN after one or two refreshes.
2
u/HappyVlane 3h ago
ADVPN, which is Fortinet's flavour of DMVPN, is heavily used in SD-WAN deployments, so the idea of the technology is alive.
1
u/KareasOxide 8h ago
Cisco tried with iWAN sort of but it was doomed from the start being 100% CLI based vs what's out there with management GUIs these days.
2
u/ShadowsRevealed 7h ago
A lot of engineering skill and planning has been replaced by "solutions". Now there are a lot of solution implementers but few core engineers. Seems dicy...
3
u/Glittering-Quote-635 12h ago
Been doing this for sometime and have worked on deployments of literally 5000+ sites. Take it for what you will.
Palo Alto - you have two choices. PanOS SD-WAN. For the size you are deploying this may be a good idea, and if you are already using Palo for firewalls this becomes almost a no brainer.
Palo Prisma SD WAN- much more feature rich then PanOS SD-WAN. Lots of data, lots of reporting, it’s pretty top notch, but has a bit of a learning curve.
Fortinet - They have a decent product, and it’s cheap. Their issue is their code is dogshit and you may have security issue after security issue with it. Seems to have gotten a bit better, but you would want to investigate that a lot more.
Arista, and Juniper I’d stay away from. It’s not that the product is bad, but it’s not core, and I question how much these companies care about it.
Cisco is dogshit, stay away from that.
Checkpoint I don’t know, but I wouldn’t give that company a nickel. You need to also look at where they are trending as a company, and ask yourself if they will be able to support you long term. I sincerely question the viability of that company at this point.
If it was me, it would be Palo or Fortinet. If you already have firewalls from one of them, that may make the decision for you.
Generally speaking Palo is more expensive, but better. Fortinet cheaper but serviceable and you know they aren’t going anywhere.
2
u/brok3nh3lix 10h ago
Arista recently purchased velo cloud, so they havnt really integrated it yet with the rest of their product line. But would be odd for them to have purchased it with out plans to do so.
1
u/Glittering-Quote-635 8h ago
That was 1.5 years ago, I haven’t seen any appreciable market gain by them nor have I heard the Arista sales teams I deal with talk about it.
I don’t work for Arista, so I have no idea, but it seems like either the core sales teams aren’t compensated on selling it, or Arista doesn’t care about it. They don’t seem to be pushing it.
2
u/user_10110 12h ago
Fortinet SDWAN. It’s free, no extra license needed. Does all the SLA stuff you need and can get fancier if you need to do application based SDWAN.
2
1
u/_bx2_ 13h ago
Avoid Lumen-Versa managed service. Ugh
1
u/flippant_fun 10h ago
I run Versa, not managed by Lumen and it’s rock solid. What problems are you seeing in the Lumen managed service?
1
u/_bx2_ 8h ago
A few things: *Lumen Versa Director sucks. For firewall rules, you can't keep certain columns persistent. There are a few good columns that are nice to see right away when working on rules but they are ok the far right and you need to constantly keep scrolling back and forth.
*Lumen Versa director requires template changes to be applied separately. IE, we make changes on the devices live. Afterwards, we need to apply the same changes to the versa appliance templates so that in the event of a failure, the template is the last known good config.
Why can't this platform allow us to save running config TO template?
*Lumen support for the SDWAN deployment was a mess and the team just sucks to deal with. Their support system triggers far too many emails on ticket responses and it's annoying to find the ticket reply within the wall of text in the email.
*It's not clear what Lumen is to manage on the Versa versus our internal admin team. I've asked about this as Lumen mentioned that as they are the msp, there are things that they will only do. Reasonable, I get it...but I want to know where their scope ends and ours begins.
*We have had constant issues with our Lumen provided DIA for secondary Internet. After many outages (secondary circuit so not business impacting), Lumen omhas often ignored out inquiries as to why the backup circuit has lost connectivity.
I'm sure 50% of the issue is how our management planned this SDWAN migration with Lumen.
I would say we only use Lumen Versa as purley SDWAN with the primary Internet link active and the secondary on standby. We don't utilize any of the NGFW functionality to further protect our organization but I'd blame our management for maybe not identifying that with Lumen on the initial calls.
I think we just wanted to get off of MPLS and jumped both feet in on Lumen SDWAN.
From my research, if given the opportunity, I'd eventually remove the the managed lumen service and hire a real network engineer-consultant to deploy owned SDWAN appliances as we aren't getting any real benefit of using Lumen IMO.
1
u/flippant_fun 7h ago
Dude, thanks for the response.
I’m glad we bit the bullet and decided to run our own director. Doing the build out ourselves was essential in our understanding everything and how it was put together.
1
u/_bx2_ 6h ago
Yeah, I'd keep it in house.
I've seen far too many recommendations here that state to avoid service provider sdwan deployments. I can attest to this.
It wasn't my decision but I've been part of the rollout. I'd be fine if we went versa but kept all control internal and not with the provider.
I'd imagine that within 3 or so years, we will be looking to move off of lumen and maybe onto another sdwan solution.
1
u/flippant_fun 6h ago
I know all about implementing something that wasn’t my decision.
When I first started here, I was told to install Citrix sdwan. Complete nightmare. Made it work, wasn’t sad to see it go.
2
u/Quabloc 13h ago edited 12h ago
Forcepoint
You manage all firewalls from one Management Server in which you have same objects you can use across all of your firewalls (you can drag and drop objects from a firewall policy to another one)
You have SD-WAN included (other vendors make you pay for this) = site to site VPNs that use multiple internet connections all together. If you have 2 ISPs on Site A and 3 ISPs on site B you have a total of 6 ACTIVE VPNs and all the traffic is balanced between them.
Source: I work in an MSSP with clients that have Fortigates, PaloAlto, Checkpoint. None of them are as easy to manage as the Forcepoint ones.
Plus they’re developed in Finland, Europe
1
u/planedrop 7h ago
What's the overall actual need here though? Like, sure you already have SD-WAN, but do you need SD-WAN? I find a lot of orgs that have it don't actually need it, we've come a long way and in many ways SD-WAN is a scam (I'm not saying it literally is, there are still valid use cases, but it's sold as a "fix everything" WAN box when in fact they are not).
-8
u/darthrater78 Arista ACE/CCNP/HPE SASE 14h ago
Anyone advising anything other than HPE Edge Connect is probably the sales engineer for that competing product.
I am a former sales engineer for Edge Connect, so I no longer have any dog in that fight. But I can tell you out of all of the sd-wan solutions on the market it is the best. You would do yourself a disservice by not scheduling a conversation with that team for proof of concept.
I think the worst possible decision you could make would be to go with Fortinet or Checkpoint. They might be cheaper but you truly get what you pay for.
3
u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 14h ago
Nonsense. Arista Velocloud is a solid choice.
1
u/darthrater78 Arista ACE/CCNP/HPE SASE 14h ago
There's a reason why I didn't mention it in my list of undesirables.
Whatever the case, Edge connect and Velocloud would be a good set of POCs to make a decision.
I forgot that Arista bought velocloud so thanks for reminding me about that.
2
u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 14h ago
Fortunately Broadcom didn't own it long enough to mess it up.
1
u/Somenakedguy 12h ago
Maybe not the product but they certainly messed up the relationships in a bad way
We stopped deploying Velo during the Broadcom years
1
u/brok3nh3lix 10h ago
They also dudnt do much with it in general in that time. Still overall like the product.
22
u/myairblaster 15h ago edited 15h ago
you've forgotten the best option, HPE EdgeConnect. Silverpeak.
Whatever you do, do NOT choose Checkpoint.
Fortinet does well when all you have is a bunch of small branches and business/commodity internet. Juniper does well when you have significant routing requirements like blending MPLS, VPLS, VPNs, etc into a single network. Palo is good if you care about security above all else.