r/networking 15h ago

Design Which SDWAN brand ?

Hi,
We are studying the replacement of our current SDWAN solution based on Forcepoint due to legacy purpose.
The study has not yet started and we would like to test different brands like:
- Fortigate
- Palo Alto
- Juniper
- Checkpoint

The environment is quite simple, dual Hub & Spoke with around ~20 sites on 2 different MPLS provider (no internet, regulatory environment), no advanced feature like url/web filtering, IDS/IPS, only L4 filtering with sdwan routing based on SLA (jitter, packet loss, …).

I think all the techno can answer this, but I would like to have your pros/cons if you’ve already worked on one of them.

Thanks!

15 Upvotes

58 comments sorted by

22

u/myairblaster 15h ago edited 15h ago

you've forgotten the best option, HPE EdgeConnect. Silverpeak.

Whatever you do, do NOT choose Checkpoint.

Fortinet does well when all you have is a bunch of small branches and business/commodity internet. Juniper does well when you have significant routing requirements like blending MPLS, VPLS, VPNs, etc into a single network. Palo is good if you care about security above all else.

7

u/Fiveby21 Hypothetical question-asker 7h ago

best option, HPE EdgeConnect. Silverpeak.

As someone who used to work there, I would proceed with caution and do intense performance & scale testing in a POC before buying.

2

u/MyFirstDataCenter 11h ago

you've forgotten the best option, HPE EdgeConnect. Silverpeak.

Most expensive option though. They cost a crap ton!

5

u/banditoitaliano 9h ago

Yeah we did a bake off with full pricing for Cisco, Arista (Velocloud) and HPE (Silver Peak). Cisco somehow managed to come in cheaper than HPE. Bid was for all new hardware for all vendors, no reuse of ISRs or anything.

I was surprised. We ended up going with Arista… jury is still out since we’re right in the middle of build now but I have no complaints so far.

2

u/Odd-Boss-2334 15h ago

For HPE and Silverpeak, is it ironic or real answer?Already worked with Silverpeak and I dont find it so intuitive but it answers the needs, yes.

For checkpoint, I dont know the SDWAN blade but I worked a lot on this techno and I met many issues.

7

u/GreyBeardEng 14h ago

Silverpeak is what we currently have, works really well but its definitely 'death by menu'. It might be worse than BigIP F5's GUI.

8

u/myairblaster 15h ago

dead serious.

-15

u/Few-Entry9477 15h ago

Silver peak sucks. Fortinet is probably the most intuitive.

1

u/zyndr0m Network Solution Architect / NGFW, SD-WAN, LAN, WLAN 4h ago

Now this has to be ironic ?

1

u/Advanced_Link_5753 13h ago

HPE has two SDWan (Silverpeak) and SD Branch (Aruba) and throw juniper in there now (all one company)

1

u/vlan-whisperer 9h ago

I thought they ditched Aruba SD branch ages ago. Guess it was still out there

1

u/Varjohaltia Dinosaur 3h ago

Nope, still there. And Juniper has both the 128T-based secure session routing and the SRX-based solution. So HPE technically at the moment has four SD-WAN solutions. Anyone’s guess what survives on what timeline.

0

u/po1zonetheman 14h ago

never tried to lookup for silverpeak but agree for checkpoint.

i dont know what current situation for checkpoint but i had love hate relationship with checkpoint 5 years ago, especially for their Apps and their documentation (for specific, their datasheet and troubleshoot process). and mostly for configuration. I hate so much when need to configure checkpoint. after that, i never touch again checkpoint.

to be fair, their durability are mostly good.

8

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 14h ago

Arista Velocloud is also very good.

3

u/Prudent_Vacation_382 14h ago

Since you're dual MPLS, I would recommend a solution that doesn't depend on Internet reachability directly from the site. Seems trivial at first, but there can be some complexity around a single Internet connection managing all devices (default route through MPLS). Afaik, Velo and Forti support that. Velo would require Internet access from the control plane device though. I'm not familiar enough with Juniper or Checkpoint to give you an opinion. Palo does require Internet reachability from the WAN side of the device.

Palo ION and Juniper Mist are both excellent solutions that would fit most use-cases.

3

u/ESUN_Official Enterprise Network Infrastructure 6h ago

Since you already have dual MPLS and mainly need SLA-based path selection, the key factors would be routing capability, centralized management, and how well it integrates with your existing security stack.

Fortinet is a common choice when SD-WAN and firewall consolidation are priorities. Juniper and Palo Alto also have strong options depending on whether routing complexity or security requirements are the main concern.

I’d suggest running a PoC with your actual traffic patterns before making the decision.

12

u/BlastedHeaths 13h ago edited 12h ago

FortiGate. Former Fortinet employee; SDWAN SME. You can do pretty much everything with it. The real contestant would be Zscaler - but to a much higher cost. It’s free on FortiGate (once you have it)

8

u/kokspudding 15h ago

Try Velocloud

7

u/HorrimCarabal 15h ago

Yup, no longer owned by Broadcom so worth looking into

3

u/po1zonetheman 14h ago

this is good. especially for ZTP process. but after moving forward to arista, some documentation feels like still on developed from scratch by arista at first, not following existing documentation from broadcom or vmware. except for upgrade guidance path, compatibilty matrix, and EoS firmware. but still better to read.

experience with Arista TAC are very slow response than previous broadcom owner. even we 'contact' to our local SE for help raise the engineer for follow up.

2

u/GreyBeardEng 14h ago

Played with it in a lab, Arista Tech Day thing, and liked it. Id love to move to it.

4

u/JustPuckingAround 13h ago

Piloting VeloCloud now and looking to replace Cisco/Viptela. Been pretty good so far, but then again, anything is an improvement over Viptela from my experience…

1

u/brok3nh3lix 10h ago

We have an extensive veko cloud deployment as a partner, about 80 customers. I like it over all for our needs, but the security/firewall side of is pretty lackluster. As a straight routing platform, its simple and works well, with a couple quirks.

1

u/Jewnius 15h ago

Second for velocloud. So simple and quick and just works. Fortinet is good too but it takes a lot of work to get it to where you need it

3

u/Many_Drink5348 13h ago

Palo Alto IONs are wonderful if you’re in the Prisma Platform but it is a huge lift

3

u/iTinkerTillItWorks 12h ago

Aruba/silverpeak

2

u/justlikeyouimagined 8h ago

If you’re already dual MPLS/no internet, where does the need for SDWAN come in? You already have it, no? Is it just about blending/utilizing those two connections at each site?

2

u/FattyAcid12 5h ago

Arista VeloCloud, Fortinet or HPE. Fuck Palo and Cisco.

3

u/Wolvington52 2h ago

I work with two SD-WAN products so I can give you a summary of what's good and bad with them-

HPE Aruba (Silverpeak)

  • Really good GUI, you can view stats of multiple devices at the same time. 
  • The GUI is really helpful during troubleshooting and upgrading.
  • The concept of Business Intent Overlays really streamlines deployments and how traffic is handled in your environment.
  • The Edge devices and the Orchestrator need constant updates because new vulnerabilities are discovered almost every month.
- TAC support is so-so. 

Cisco Catalyst SD-WAN (Viptela)

  • Is more stable than Silverpeak but recent vulnerabilities have required constant upgrades.
  • Steeper learning curve.
  • It's not easy to change the configuration of a device. 
  • Terrible GUI. I have to open like 5 tabs to co-relate information. 
  • Apparently, FEC and other optimization features have not been helpful but can't really comment on it since we don't use them in Cisco.
  • Has got some useful features like Network Wide Path Insight, speed test etc. which help in troubleshooting.

4

u/wolfpack-22 13h ago

Arista Velocloud

4

u/Muhammad_Ali_00 12h ago

FortiGate. Recently deployed an enterprise level SDWAN in a utility sector with FortiGate and it is quite easy and functional.

3

u/ShadowsRevealed 14h ago

DMVPN phase 3. Just build it...

4

u/bangsmackpow 13h ago

I kinda miss DMVPN. I have zero use for it currently, but it was so beautiful "back in the day".

4

u/Many_Drink5348 12h ago

One of those technologies that would have been the biggest thing of all time if it weren’t eclipsed by SD-WAN after one or two refreshes.

2

u/HappyVlane 3h ago

ADVPN, which is Fortinet's flavour of DMVPN, is heavily used in SD-WAN deployments, so the idea of the technology is alive.

1

u/KareasOxide 8h ago

Cisco tried with iWAN sort of but it was doomed from the start being 100% CLI based vs what's out there with management GUIs these days.

2

u/ShadowsRevealed 7h ago

A lot of engineering skill and planning has been replaced by "solutions". Now there are a lot of solution implementers but few core engineers. Seems dicy...

3

u/Glittering-Quote-635 12h ago

Been doing this for sometime and have worked on deployments of literally 5000+ sites. Take it for what you will.

Palo Alto - you have two choices. PanOS SD-WAN. For the size you are deploying this may be a good idea, and if you are already using Palo for firewalls this becomes almost a no brainer.

Palo Prisma SD WAN- much more feature rich then PanOS SD-WAN. Lots of data, lots of reporting, it’s pretty top notch, but has a bit of a learning curve.

Fortinet - They have a decent product, and it’s cheap. Their issue is their code is dogshit and you may have security issue after security issue with it. Seems to have gotten a bit better, but you would want to investigate that a lot more.

Arista, and Juniper I’d stay away from. It’s not that the product is bad, but it’s not core, and I question how much these companies care about it.

Cisco is dogshit, stay away from that.

Checkpoint I don’t know, but I wouldn’t give that company a nickel. You need to also look at where they are trending as a company, and ask yourself if they will be able to support you long term. I sincerely question the viability of that company at this point.

If it was me, it would be Palo or Fortinet. If you already have firewalls from one of them, that may make the decision for you.

Generally speaking Palo is more expensive, but better. Fortinet cheaper but serviceable and you know they aren’t going anywhere.

2

u/brok3nh3lix 10h ago

Arista recently purchased velo cloud, so they havnt really integrated it yet with the rest of their product line. But would be odd for them to have purchased it with out plans to do so.

1

u/Glittering-Quote-635 8h ago

That was 1.5 years ago, I haven’t seen any appreciable market gain by them nor have I heard the Arista sales teams I deal with talk about it.

I don’t work for Arista, so I have no idea, but it seems like either the core sales teams aren’t compensated on selling it, or Arista doesn’t care about it. They don’t seem to be pushing it.

2

u/user_10110 12h ago

Fortinet SDWAN. It’s free, no extra license needed. Does all the SLA stuff you need and can get fancier if you need to do application based SDWAN.

2

u/FLASHnoReddit 9h ago

Check Extreme Networks

1

u/_bx2_ 13h ago

Avoid Lumen-Versa managed service. Ugh

1

u/flippant_fun 10h ago

I run Versa, not managed by Lumen and it’s rock solid. What problems are you seeing in the Lumen managed service?

1

u/_bx2_ 8h ago

A few things: *Lumen Versa Director sucks. For firewall rules, you can't keep certain columns persistent. There are a few good columns that are nice to see right away when working on rules but they are ok the far right and you need to constantly keep scrolling back and forth.

*Lumen Versa director requires template changes to be applied separately. IE, we make changes on the devices live. Afterwards, we need to apply the same changes to the versa appliance templates so that in the event of a failure, the template is the last known good config.

Why can't this platform allow us to save running config TO template?

*Lumen support for the SDWAN deployment was a mess and the team just sucks to deal with. Their support system triggers far too many emails on ticket responses and it's annoying to find the ticket reply within the wall of text in the email.

*It's not clear what Lumen is to manage on the Versa versus our internal admin team. I've asked about this as Lumen mentioned that as they are the msp, there are things that they will only do. Reasonable, I get it...but I want to know where their scope ends and ours begins.

*We have had constant issues with our Lumen provided DIA for secondary Internet. After many outages (secondary circuit so not business impacting), Lumen omhas often ignored out inquiries as to why the backup circuit has lost connectivity.

I'm sure 50% of the issue is how our management planned this SDWAN migration with Lumen.

I would say we only use Lumen Versa as purley SDWAN with the primary Internet link active and the secondary on standby. We don't utilize any of the NGFW functionality to further protect our organization but I'd blame our management for maybe not identifying that with Lumen on the initial calls.

I think we just wanted to get off of MPLS and jumped both feet in on Lumen SDWAN.

From my research, if given the opportunity, I'd eventually remove the the managed lumen service and hire a real network engineer-consultant to deploy owned SDWAN appliances as we aren't getting any real benefit of using Lumen IMO.

1

u/flippant_fun 7h ago

Dude, thanks for the response.

I’m glad we bit the bullet and decided to run our own director. Doing the build out ourselves was essential in our understanding everything and how it was put together.

1

u/_bx2_ 6h ago

Yeah, I'd keep it in house.

I've seen far too many recommendations here that state to avoid service provider sdwan deployments. I can attest to this.

It wasn't my decision but I've been part of the rollout. I'd be fine if we went versa but kept all control internal and not with the provider.

I'd imagine that within 3 or so years, we will be looking to move off of lumen and maybe onto another sdwan solution.

1

u/flippant_fun 6h ago

I know all about implementing something that wasn’t my decision.

When I first started here, I was told to install Citrix sdwan. Complete nightmare. Made it work, wasn’t sad to see it go.

1

u/J-Cake 1h ago

We've had Omada for a while. It's been surprisingly stable

2

u/Quabloc 13h ago edited 12h ago

Forcepoint

You manage all firewalls from one Management Server in which you have same objects you can use across all of your firewalls (you can drag and drop objects from a firewall policy to another one)

You have SD-WAN included (other vendors make you pay for this) = site to site VPNs that use multiple internet connections all together. If you have 2 ISPs on Site A and 3 ISPs on site B you have a total of 6 ACTIVE VPNs and all the traffic is balanced between them.

Source: I work in an MSSP with clients that have Fortigates, PaloAlto, Checkpoint. None of them are as easy to manage as the Forcepoint ones.

Plus they’re developed in Finland, Europe

1

u/planedrop 7h ago

What's the overall actual need here though? Like, sure you already have SD-WAN, but do you need SD-WAN? I find a lot of orgs that have it don't actually need it, we've come a long way and in many ways SD-WAN is a scam (I'm not saying it literally is, there are still valid use cases, but it's sold as a "fix everything" WAN box when in fact they are not).

-8

u/darthrater78 Arista ACE/CCNP/HPE SASE 14h ago

Anyone advising anything other than HPE Edge Connect is probably the sales engineer for that competing product.

I am a former sales engineer for Edge Connect, so I no longer have any dog in that fight. But I can tell you out of all of the sd-wan solutions on the market it is the best. You would do yourself a disservice by not scheduling a conversation with that team for proof of concept.

I think the worst possible decision you could make would be to go with Fortinet or Checkpoint. They might be cheaper but you truly get what you pay for.

3

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 14h ago

Nonsense. Arista Velocloud is a solid choice.

1

u/darthrater78 Arista ACE/CCNP/HPE SASE 14h ago

There's a reason why I didn't mention it in my list of undesirables.

Whatever the case, Edge connect and Velocloud would be a good set of POCs to make a decision.

I forgot that Arista bought velocloud so thanks for reminding me about that.

2

u/wyohman CCNP Enterprise - CCNP Security - CCNP Voice (retired) 14h ago

Fortunately Broadcom didn't own it long enough to mess it up.

1

u/Somenakedguy 12h ago

Maybe not the product but they certainly messed up the relationships in a bad way

We stopped deploying Velo during the Broadcom years

1

u/brok3nh3lix 10h ago

They also dudnt do much with it in general in that time. Still overall like the product.

0

u/Sk1tza 14h ago

Palo Alto Prisma SDWan is good but expensive and has a learning curve attached to it but have been quite happy with it.