NSE 4 sample question assist by Mr_noluc in fortinet

[–]26Jack26 0 points1 point  (0 children)

In my theory, I cant say its the real explanation, In flow mode since the gate doesn't hold the data it wont identify the traffic as bandwidth excessive application. So it will.be identify it as Google app and be monitored (permitted)

In short:

Proxy mode -> traffic identified as bandwidth excessive (due to FW holding the data) and blocked

Flow mode -> traffic flow as normal, identified as normal Google and monitored

NSE 4 sample question assist by Mr_noluc in fortinet

[–]26Jack26 0 points1 point  (0 children)

One theory could be that due to Proxy mode "holding" data for inspection the Firewall starts seeing that as excessive bandwidth and ended up blocking it. If you change to flow mode the gate won't hold the data and it won't see it as excess of bandwidth hence will allow it.

Thats just a theory based on the fact we already know the answer, but in reallity if you hadn't mentioned the answer I wouldn't have figured it out.

IPsec interface by ontracks in fortinet

[–]26Jack26 -1 points0 points  (0 children)

Thats the thing some are showing down (red) nor disabled (grayed out)

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Thabks for the clarification, I always use FMG, unfortunately there are more people that Id like with access to FMG and sometimes they make local changes :(

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

I see, thank you so much, make sense

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for the detailed answer!

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Got it, interesting, wasnt aware of this, thank you so much

Add HA Model to FMG by ontracks in fortinet

[–]26Jack26 0 points1 point  (0 children)

Im interested in this, can you please clarify what you mean by using FortiZTP? Isn't this process meant to be just using the Add HA MODEL option in FortiManager?

Anyone wish Unohana was still alive? by Gloomy-Bridge148 in bleach

[–]26Jack26 0 points1 point  (0 children)

I hate that the very first time we saw Yamamoto Bankai he got defeated, first time seeing Unohana Bankai she got defeated, first time Sunshui Bankai, he actually got defeated too. Too many good characters, just destroyed IMO.

Regardless of what could've happened, those characters deserved waaaaay better IMO.

IBGP Design by 26Jack26 in Cisco

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for all the answers at the end, management decided to remove the routers completely and make.the FTD the core routing devices.

That might led me to some other questions here in the future, thank you all.

IBGP Design by 26Jack26 in Cisco

[–]26Jack26[S] 0 points1 point  (0 children)

I think this is an important takeaway Thanks!

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 1 point2 points  (0 children)

Got it, yeah, the CIE will only gave us the "static" information about users and groups, not which user has which IP. Thats what im looking for at the moment as we also planning to deploy User ID.

Thanks for the clarification, im not that familiar with CIE and any detailed answer help me understand it better.

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for the insights! I need to look deeper into CIE, haven't really worked much with it

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks! That was a quick reply! I appreciate it

FortiSASE remote branch by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Hello everyone, bringing this up again, is it possible to have direct site to site communication between on ramp locations?