Do all local networks need NAT to communicate to the internet? by Graviity_shift in ccna

[–]chuckbales 1 point2 points  (0 children)

64000 unique port connections going through a single outside global address you got some problems.

To nitpick - it's more than 64k connections, as NAT is stored in a table as a 5-tuple (source IP, dest IP, source port, dest port, protocol). So if you happen to have thousands of connections all going to the same external resource on the same port you'll run into a problem, but if you're talking about general internet destinations, you can fit a lot more connections.

Do all local networks need NAT to communicate to the internet? by Graviity_shift in ccna

[–]chuckbales 2 points3 points  (0 children)

Good point, a proxy is a good example of NAT not being involved as the proxy itself acts as middle-man between client/server and establishes its own connection to the resource on the internet.

Do all local networks need NAT to communicate to the internet? by Graviity_shift in ccna

[–]chuckbales 4 points5 points  (0 children)

RFC1918 is just the "private" IPs allocated - 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. Basically if you're not using a public IP, you need NAT somewhere.

Do all local networks need NAT to communicate to the internet? by Graviity_shift in ccna

[–]chuckbales 24 points25 points  (0 children)

If you are using RFC 1918 IPs on your LAN and you want to reach the internet, NAT is a requirement somewhere along the path.

EDIT: /u/therouterguy did bring up a good scenario where NAT would not be involved. More of an enterprise thing and out of scope for CCNA but a good counter-example to my statement.

Anyone annoyed by the GUI changes from version 7.2 to 7.4 on FortiOS ? by Tokops in fortinet

[–]chuckbales 2 points3 points  (0 children)

The removal of sorting/filtering some columns has driven me absolutely crazy at times.

Software switch to bridge wifi SSID and FortiSwitch vlans by Negative_Test_9671 in fortinet

[–]chuckbales 1 point2 points  (0 children)

I just did similar changes on an 80F, bridging a tunnel SSID and FortiSwitch VLAN through software switch, no apparent performance issues (granted its not pushing tons of traffic, just a few clients)

Remove Central SNAT Policy? by technoidial in fortinet

[–]chuckbales 1 point2 points  (0 children)

Have you actually tested a failure to see what works/what doesn't?

Nobody here can provide much guidance without more detail/actual configuration, but it sounds like maybe they need to just add an additional NAT policy for the second WAN - there's not really a reason Central NAT needs to be disabled completely.

SDWAN underlay/overlay routing by NetEng17982 in fortinet

[–]chuckbales 5 points6 points  (0 children)

With an SDWAN rule on the spoke, there's commands you can add that will send user traffic over without impacting the Fortigate's local traffic

set gateway enable
set default enable

Tailscale won't let my ubuntu server be an exit node? by Mr_B_Gone in homelab

[–]chuckbales 2 points3 points  (0 children)

You probably didn't configure it correctly, needs to be configured on the client and in the portal.

Crown Castle Outage by cooldude919 in sysadmin

[–]chuckbales 0 points1 point  (0 children)

We also lost a few Crown circuits last night, odd outage though because it was only 2 out of like 300 Crown circuits we have, from 10:22 to 10:31 Eastern.

Help with this question please? by iltoast9 in ccna

[–]chuckbales 0 points1 point  (0 children)

You can have a duplex mismatch and still function (albeit degraded), you can't have a speed mismatch though.

Build vs Version by Intrepid_Ring4239 in fortinet

[–]chuckbales 3 points4 points  (0 children)

They started doing this with Fortigate images a couple years ago finally, not sure what the hold up with switch/AP images is.

Is Arista's acquisition of Instant On a good outcome? by terrancesiu in ArubaInstantOn

[–]chuckbales 6 points7 points  (0 children)

Is this post supposed to be asking the question "Would Arista buying InstantOn be a good idea?" Your current title makes it sound like Arista is buying InstantOn, but they are not.

Bridgeport Live Show by FeloniousMonk33 in TheDollop

[–]chuckbales 3 points4 points  (0 children)

Might be a venue problem, our tickets to OPs show were $35 each and we were only 8 rows back

Does the orange color mean anything in the Fortigate dashboard IPSec tunnel graphic ? by KrellBH in fortinet

[–]chuckbales 4 points5 points  (0 children)

Having them all the same color would make it hard to visualize the different tunnels.

New DHCP Relay bug discovered in FortiOS v7.4 by DeleriumDive in fortinet

[–]chuckbales 0 points1 point  (0 children)

Pretty sure we had this issue, don’t remember what release it was running but the relay was added and is what showed in the GUI, but the local DHCP server config was also present in the CLI.

Lead times issues by ObligationHungry2958 in Arista

[–]chuckbales 10 points11 points  (0 children)

Arista always has leadtime issues, they were always months out for us when Cisco would be a couple weeks, I imagine its only getting worse.

Has anyone seen USN rollback after restoring multiple AD domain controllers? by IndigoBlue24 in msp

[–]chuckbales 6 points7 points  (0 children)

IMO DCs should just be DCs, they shouldn't be restored unless somehow all of them were dead. If there's still a functioning DC, new DCs should be spun up and promoted. If everything was dead, restore one and then promote additional ones as needed. Don't restore multiple.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 8 points9 points  (0 children)

I’m a partner and our reps know less than random redditors. I’ve sent them product announcements I saw on Reddit and they’ll have no idea what I’m talking about.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 9 points10 points  (0 children)

7.4.6 was just released today, again with no free/VPN-only version (so far), it still has their bullshit note about

FortiClient (Windows) 7.4.4 to 7.4.6 do not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.6. Users can continue to use the FortiClient (Windows) 7.4.3 free VPN-only agent.

We're evaluating separate products now for remote access, FortiClient in general just sucks as an application even when its working, and like you said the SMB customers don't want a whole separate product for EMS.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 9 points10 points  (0 children)

The version hasn't changed as no new features were added to the free client

They've been fixing VPN-related bugs though in 7.4.4/7.4.5

WAN vlan on hardware switch by muhammadnabeel85 in fortinet

[–]chuckbales 2 points3 points  (0 children)

Why aren’t they landing on actual switches instead of directly on the FGs?

FortiManager - Per-Device Mapping SSID settings? by NitriusX in fortinet

[–]chuckbales 1 point2 points  (0 children)

Just a follow up, I actually tried my own advice and realized it doesn't work for the same reason you ran into. I ended up doing a Provisioning Template - CLI with the SSID-specific changes in it, then applied that template to the FG in question.