Tag: cloud

  • From the Edge to the Air, Fortinet’s Full Stack End to End Solution

    As much as I hate to admit it, Fortinet is more than just “those guys who bought Meru.”  In fact they are way more than just a wireless company.  As we already know, Fortinet is best known in the industry as a security company with a rock solid reputation.  The truth is, Fortinet is a true end to end solution, beginning with their FortiGate, moving through their switching, and into their wifi.

    Fortinet’s wireless solution is  broken into three distinct management platforms; FortiGate, FortiCloud, and controller (WLC).  Check out one of my blog posts from earlier in the year where I broke down the differences here.

    Until recently I had been mostly unfamiliar with anything but the controller solution which is built on the legacy Meru product.  As most of you already know I have an affinity for the FortiRu product line which goes beyond the controversial Single Channel Architecture.  The hardware is rock solid and it seems as though their code is a lot less buggy than what I hear from customers of other vendors.  The cloud managed solution also seems to be a very viable solution as it chugs along in the lab at my house.  This is of course a far cry from a true enterprise deployment but from what I know it seems to be reliable. Compared to other cloud managed competitors who have been around awhile, the one downside to Fortinet’s cloud managed solution is it could stand to be somewhat more intuitive during configuration.  In Fortinet’s defense, it is hard to stay unique, not re-invent the wheel, and yet remain intuitive in an already saturated cloud managed playing field.  The third management option is via a FortiGate.  In all honestly, I have not tried this method before so I shouldn’t comment until I am more familiar.  I have been graciously provided a FortiGate 81E as well as FortiSwitch 108E to check out but haven’t had the time to dive in yet.

    Those who aren’t familiar with Fortinet should pay very close attention to their licensing platform.  Aside from a select few products, THERE ISN’T ONE!  You don’t need to sift through confusing price lists to find licensing for APs, firewall features, etc because there are no additional licenses required to operate the equipment you bought!  If there is one thing that sticks in the craw of IT professionals these days, it is licensing that needs to be considered for what seems like every single feature/widget that comes with “Box X.”  Not only do you have to think about the confusing and cumbersome licensing when you purchase “Box X,” you have to deal with it each time those licenses come up for renewal.  Not with Fortinet!  Reliable hardware, mostly stable code, and no licensing should move Fortinet onto your short list for consideration the next time you are evaluating equipment for your next purchase, and give you comfort in it’s potential to be a that true end to end solution.

    Check out the following videos from our visit with Fortinet at MFD3 below.

    Fortinet Company Introduction: From Security to Wireless with Chris Hinsz

    Fortinet Portfolio Overview: Access Points and More with Chris Hinsz

    Fortinet FortiGate as a Wireless Controller: Bringing the Security Fabric to the Edge with Koroush Saraf

    Fortinet FortiGate Demonstration with Koroush Saraf

    Fortinet Wireless Analytics: Birthed in Retail, Applicable to Everyone with Koroush Saraf

    For those who lived through the Meru presentation a few years ago at Wireless Field Day 5, many were left with questions about Single Channel Architecture.  This year Ted Fornoles gave a brief presentation on how the “special sauce” behind Single Channel Architecture actually works.  Ted is one of the last remaining “Original Gangsta” Meru guys left within Fortinet.  More time could have been spent here but overall the presentation was great.  Although no questions were asked, there were still some skeptics in the room.  I know it works, Fortinet knows that it works, but there are some out there who will always refuse to accept SCA as a viable, scalable option regardless of what is said.  I stick to my original position on Fortinet’s  publicity of Single Channel Architecture.  If you aren’t already familiar, check out a blog post from earlier in the year here.  I wish there was more talk about SCA from Fortinet’s camp as their silence gives off the appeal that they don’t have confidence in Single Channel Architecture going forward.  Even though SCA has been around for several years now, and is getting somewhat long in the tooth without further advancement, there has to be something Fortinet can do to bolster the SCA solution and make it a heavy hitter in future wireless adaptations.  Check out Ted’s video explaining Single Channel Architecture below.

    Fortinet Virtual Cell & Single Channel Demystified with Ted Fornoles

    A Very Special Thanks

    As many of you know I use FortiRu gear to provide wifi to 100,000ish students and staff every day at Loudoun County Public Schools.  Before I worked for LCPS, I installed and configured FortiRu wireless gear for a VAR.  Pretty much my entire wifi career has been based around FortiRu wireless networks and more specifically Single Channel Architecture.  Over the last several years working with FortiRu, I have had the chance to build many relationships with people who work(ed) for Meru/Fortinet.  Three fellas of note within Fortinet SWAT (TAC) I work with on a regular basis are Kaushik, Harish, and Vikas.  These guys are always available to help me and I often feel bad for interrupting their day by not going through the traditional methods of seeking help, such as submitting a ticket or calling support.  They go out of their way to make sure I get the assistance I need as quickly as possible.  I can’t say enough about these guys as they have truly made a positive impact on my wifi career.  Without them, the success I have had would not have been possible.  While at Mobility Field Day 3, I had the chance to meet Harish and Vikas in person.  It was great to shake the hands of these terrific engineers and thank them in person for all that they do to support me.  Again, thank you very much Harish, Kaushik, and Vikas.  You guys are huge assets to Fortinet.  I hope they know how great you guys are!

    Me and Harish at MFD3

    Another special word of thanks goes to Paul Lambert.  I met Paul via Marcus Barman a couple years back.  Paul has been an invaluable asset to me as I strive to provide fast, reliable wifi to 80,000 concurrent devices at peak every day.  Paul is also one of the very few “Original Gangsta” Meru guys left at Fortinet.  Paul spends most of his time on the security side of things these days but he is still one of the most knowledgeable people in the world (aside from Dr. B.) on Virtual Cell.

  • Nyansa; A Clearer Picture From a Data Gathering Powerhouse at #MFD3

    Nyansa was back at Mobility Field Day again this year and I have to admit, I took away more from them this year than last.  Nyansa makes a product called Voyance which delivers a crazy amount of data and insight into your network.  You might think you have a good idea about what is going on in the network, but I bet Voyance can show you things you never knew were there.  In a market full of dashboards, this dashboard gives you a plate full of data that you may or may not be able to consume.

    Anand Srinivas, Co-founder and CTO of Nyansa, began by describing how Voyance gives us a full client picture.  Voyance can give you full end to end visibility into your network; meaning it can deliver most/all data you have between your client and your application, which includes all the pieces in between.  This data can be collected several different ways before it is ultimately delivered to Voyance.  Nyansa also has an agent which can be loaded on a client (supporting most major client types) to collect.  At this time Voyance has built in support for Cisco, Aruba, and Extreme infrastructure equipment, as well as specialized equipment in specific verticals (ie. medical devices).  When listening to the presentation you start to wonder about the amount of data they are talking about.  Several delegates including myself had questions about how they expect customers to translate the data, how they support the data, and even how data is shared.  Watch the video below where Anand goes into detail about gathering the full client picture.

    More than a few delegates had questions about Nyansa’s agent.  Installing agents on every device in an enterprise can be a daunting undertaking.  There are also questions about which devices are out of bounds for an enterprise to deploy to; such as BYOD devices.  As an example, in my case the overwhelming majority of the wireless clients on my network are BYOD devices.  Being able to deploy an agent on enterprise owned equipment shows a VERY small piece of the pie.  IT support members also become hesitant with how much overhead agents put onto a client as well as other factors.  This question seems even more relevant based on what sounds like an overwhelming amount of data that is being sent.  We were assured by Anand that data sent via the agent was done so with minimal impact to the client or network.  Even though it may sound like there are more downsides than upsides with the agent, an agent will give you the best visibility into how the client is behaving.  You will be able to see things such as driver versions, software versions, hardware specs, client roaming information, etc.  These are all very awesome details to have when troubleshooting and are often the parts left out when using a vendor specific NMS solution within your wireless network.  Watch and listen to Anand explain the Voyance agent below.

    Nyansa is also taking on another hot button topic in the wifi industry; IoT.  For those who don’t know what IoT is, it is short for Internet of Things.  Manufactures are putting wifi capability into all kinds of crazy “things” these days.  Refrigerators, thermostats, TVs, coffee makers, door bells, lighting, etc can all be connected to your wireless network now.  Most of the time the wireless devices that manufacturers put into their “things” are very limited in capability, poorly designed, or of poor quality.  A refrigerator manufacturer is usually very good at making refrigerators, but they may not be educated in the ways of wireless networking.  Lacking an understanding of wireless networking could potentially cause poor performance for the refrigerator, the wireless network it is connected to, or both.  Keep in mind that IoT devices are not all novelty.  There are very important “things” out there such as life supporting devices in healthcare, robots in manufacturing, or other devices critical to specific verticals.  Either way Nyansa has something to keep those pesky IoT devices in check.  Check out both videos below.

    My Take

    I believe Nyansa can be a player in the wireless analytics market.  There were many discussions among delegates about the feasibility of a high cost, third party analytics platform for wireless networks.  As already noted, many of the current wireless solutions themselves have “more than basic” analytics cooked into their respective controllers.  This does not downplay the information that Voyance is capable of providing though.  Voyance can give you great insight into the client, end point, as well as all things in between, which most controllers cannot.  There are upsides and downsides to this amount of information though.  I think that the amount of information could potentially be overwhelming to prospective customers.  I believe Nyansa understands this.  Molding the data that is collected by Voyance to suite each customer’s need is of utmost importance as to not overwhelm a customer.  There could be a very thin line that separates information overload and just the right amount of data to solve a problem in an enterprise.  That is where Nyansa should be careful.

    The more I listen to Nyansa the more I am intrigued by the product.  Last year I was left somewhat confused.  This year I have a better idea about what they are about and where they are going.  There is no dispute that the information gathered by Voyance could be very helpful, but are potential customers going to bite on a product that adds another dashboard into an already crowded dashboard arena?  I often wonder if Nyansa is candidate for purchase by an existing wireless vendor for integration into their own portfolio.  This idea makes more sense to me as it doesn’t add an additional dashboard to a customer’s toolbox, but offers a potential “single pane of glass” to their existing wireless infrastructure.  A solid infrastructure paired with built in analytics from Voyance could be a very powerful combination.

  • Fortinet, Meru, FortiRu Forti-WHO?

    Since last week’s open letter to FortiRu, I came to the realization that there may be some confusion related to Fortinet’s AP product line.  I decided to throw this post together so that it is easier to understand which APs are what, and which category they fall into.  Keep in mind this is a high level overview to simply point out the different AP product lines.

    Lets jump right into it…

    Fortinet offers three different management options under it’s Enterprise Secure Wifi solution; FortiGate, Cloud, or dedicated controller, and five different AP lines that fall into one or more of those management options.

    Excerpt from Fortinet Product Matrix

    Access points that can be managed via the ForiGate or the Cloud are broken down here:

    Standard 802.11ac

    Standard 802.11n

    Smart APs

    Universally Manageable APs

    The FortiAP-S313C, which was given to attendees of the recent Wireless LAN Professionals Conference, falls into the preceding category.  You can read a great blog post about the FortiAP-S313C AP written by my apple butter lovin’ buddy Lee Badman here.  Please pay close attention to what Lee says concerning the licensing for these APs.  A true game changer…

    FortiAP-S313C

    There may have been some confusion with the FortiAP-S313C stemming from the Fortinet presentation at WLPC.   The FortiAP-S313C is NOT from the Meru pedigree of access points of which I will elaborate on next.

    Access points that are managed from a dedicated controller are broken down here:

    Standard APs

    Universally Manageable APs

    AP1020
    AP832

    These APs ARE from the Meru lineage of access points which I affectionately refer to as FortiRu.  These APs support Virtual Cell/Single Channel Architecture and are still commonly referred to as Meru access points.  The APs in the Standard AP list are all carry over from the Meru purchase.  The AP1020 and AP832 are models that we use in our school district and the models that I have the most experience with.  Both the AP1020 and AP832 have been rock solid since their release to market.  It is often confused that these standard APs are only capable of operating under Virtual Cell/Single Channel Architecture.  All traditional Meru access points can operate in EITHER a multi channel OR Virtual Cell configuration.

    You may have noticed that under each section there was a group of APs referred to as Universally Manageable.  These APs can be managed using any of the three management solutions.  Just like its’ Meru predecessor, the Universal AP can be used in EITHER a multi channel OR Virtual Cell configuration depending on the chosen management solution.  I should have more to write on the “U” line of APs in the near future as we should be receiving some very soon.

    FAP-U421EV

    As previously stated, this blog post was intended to be a high level overview of the Fortinet/Meru (FortiRu) AP product line.  Clicking on the links and reading through the material will give you a deeper explanation into each of the access points.  As always, if there are any questions, comments, corrections, etc, please feel free to reach out to me.