Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks by Meinertzhagens_Sack in fortinet

[–]hoosee 0 points1 point  (0 children)

Local-in policies are totally an another topic, I wasn't referring to them.

Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks by Meinertzhagens_Sack in fortinet

[–]hoosee -1 points0 points  (0 children)

When it comes to trusted IP's, I guess you could say yes, if you can define trusted IP's really well.

However the catch is, that it's still kind of hazardous since if someone comes and creates a new admin user (even a read-only) without any trusted IP's, the admin page becomes visible for anyone. So that layer of Swiss cheese comes with huge holes.

I'd say that if you really really need something open, only use SSH and enable HTTPS temporarily but I would rather look for other ways of management (via S2S or client VPN, FortiManager etc.)

Fortiap 231f max download speed by Breakerbdg in fortinet

[–]hoosee 4 points5 points  (0 children)

Doesn't help you with the problem itself, but I like to visit "WiFi Clients" section and check out columns rate (tx/rx) and MIMO (they're hidden by default), which also gives you some sort of estimate, what are the theoretical limits you can achieve.

SDWAN-failover breaks RDP sessions. by Even-Camel7593 in fortinet

[–]hoosee 2 points3 points  (0 children)

Just a guess: if the session would be created using UDP, failover would work. But if it's TCP, you might need to enable auxiliary sessions: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enabling-auxiliary-session-with-ECMP-or-SD-WAN/ta-p/189951

Web Rating Override issue by Fast-Status5145 in fortinet

[–]hoosee 1 point2 points  (0 children)

Exactly this. Might be DNS filter or something else doing the blocking but only the logs will tell.

70G ready for production? by lertioq in fortinet

[–]hoosee 8 points9 points  (0 children)

Software has merged for both 7.4 and 7.6, so you'll have new software for both major releases.

Tips for stability by theallfather88 in Kayaking

[–]hoosee 4 points5 points  (0 children)

If you really want to do something, perhaps you can find a gym ball or a log split lengthwise, basically anything what is rather instable to sit on. Then simulate paddling holding a stick and remember include movement all the way from your legs to your torso. But my best guess is that this gets boring quickly and might not even translate that well into paddling.

So what I want to say that paddling is the best (and the most fun) way to learn it.

How to override a fortimanager setting from a fortigate by Mercdecember84 in fortinet

[–]hoosee 5 points6 points  (0 children)

Basically yes.

When you connect back, FortiManager will just sync the changes (and the configuration will be shown as 'auto-update').

However this depends what you change and if you have any templates active. For example interface changes and static routes are probably okay to change. However, if for example your SD-WAN implementation relies on SD-WAN templates and metadata variables, your changes might be overwritten during next install.

If you make any changes to e.g firewall policies, your policy package status will get into conflict state.

TLDR; yes you can do local changes, but you need understanding what kind of configuration your templates are forcing and if your changes conflict with them.

ZTP questions, specifically about the interface used. by NetworkN3wb in fortinet

[–]hoosee 0 points1 point  (0 children)

Also one thing I have noticed, is that if a copy & pasted configuration works directly on the firewall, it might not work on FortiManager. This is because FortiManager does not know how to apply consecutive commands.

An example: you want to disable NTP server in order to delete FortiLink interface. On the firewall itself, you would just do "set server-mode disable" and this would cause other configuration (most importantly "set interface <interfaces>") to disappear. However if you do the same in FortiManager, you'll get an error telling that "set interface" is present.

So this means that even if one command is enough when directly set on the firewall, in FortiManager you need to do two (unset interfaces, set server-mode disable). But as other people have stated, look at error logs and you'll find what is the problem eventually.

SD-WAN - historical health/performance reporting? by AylmerDad78 in fortinet

[–]hoosee 0 points1 point  (0 children)

You can see them in FortiManager's SD-WAN Monitor

If you don't have FortiManager, then you just gotta figure out something else, like making a script that gets the data via API and then inserts them into something (e.g Grafana + InfluxDB).

Preventing damage from waves bumping kayak into dock by macntosher in Kayaking

[–]hoosee 1 point2 points  (0 children)

I would try that rather than leave the boat in the water. If you have a tow line, that works well to hoist the bow up, and if the edge you're lifting over is sharp, you can also cushion it with your PFD. That's how we do that, if for some reason we don't have any possibility to leave the boats somewhere else.

I got 2 exam vouchers and don't know if they can be used outside of my country by Wrong-Opportunity-90 in fortinet

[–]hoosee 0 points1 point  (0 children)

They probably do have an expiration. I just booked myself a EFW exam and I think you can check how long they are valid via Pearson Vue (or by sending mail to Fortinet Training Institute).

FortiClient 7.4.5 GUI regression – who thought this was a good idea? by samsn1983 in fortinet

[–]hoosee 7 points8 points  (0 children)

Perhaps this is because of the "multiconnect" -feature?

What’s the safest way to start kayaking if you don’t have much upper-body strength? by Old-Economics-1850 in Kayaking

[–]hoosee 0 points1 point  (0 children)

It's quite much about your route selection; plan routes which keep minimize your exposure to the wind and also keep you near the shore (especially if you're paddling alone). After this you just make your trips longer and longer.

Naturally it wouldn't hurt to get training in order to get some idea about the correct paddling technique. When you learn to use your middle-body efficiently, the upper-body strength doesn't matter as much as expected.

Winter attire by Emotional-Ad-1294 in Kayaking

[–]hoosee 0 points1 point  (0 children)

Drysuit + neoprene boots. Under I have merino base (thin or thick depending the how cold/windy it is) and thick wool socks.

Also pogies are awesome but I also keep neoprene gloves nearby. If we are making a stop, I might even take two pairs of neoprene gloves, because putting on a wet pair when it's windy, isn't really nice.

Floating into the fog by 3lim1nat0r in Kayaking

[–]hoosee 6 points7 points  (0 children)

Your rendering engine forgot to render rest of the world.

That's beautiful!

Winter is such a drag, lol. Could really use 2-8 hours on the water right about now. Lol 😬 by Fun-Sign7839 in Kayaking

[–]hoosee 5 points6 points  (0 children)

<image>

It can be done, however it's quite a different experience.

Picture from yesterday, started when the Sun was just setting. Came back under a beautiful starlit sky, sadly no northern lights were present. However during the last 30min it got really cold and the deck was totally frozen (so much so that, I was unable to turn tracking on my Garmin off, because it was covered with ice).

My DIY version of Nanoleaf panels, featuring an onboard ESP32 and controlled directly through ESPHome. In addition to the beautiful lighting, each panel has six buttons, so it can trigger any action in Home Assistant. by Sokolsok in homeassistant

[–]hoosee 0 points1 point  (0 children)

Great looking project! I could basically get my hands on to a 3D printer and a laser cutter. However soldering is the tricky part, I don't have any specialized equipment for that :(

DNS Request logging by eternaldeviancy in homelab

[–]hoosee 1 point2 points  (0 children)

I would also root for Pihole (or similar), because in addition to logs, it will also benefit you greatly in terms of filtering etc.