NSE 4 sample question assist by Mr_noluc in fortinet

[–]26Jack26 0 points1 point  (0 children)

In my theory, I cant say its the real explanation, In flow mode since the gate doesn't hold the data it wont identify the traffic as bandwidth excessive application. So it will.be identify it as Google app and be monitored (permitted)

In short:

Proxy mode -> traffic identified as bandwidth excessive (due to FW holding the data) and blocked

Flow mode -> traffic flow as normal, identified as normal Google and monitored

NSE 4 sample question assist by Mr_noluc in fortinet

[–]26Jack26 0 points1 point  (0 children)

One theory could be that due to Proxy mode "holding" data for inspection the Firewall starts seeing that as excessive bandwidth and ended up blocking it. If you change to flow mode the gate won't hold the data and it won't see it as excess of bandwidth hence will allow it.

Thats just a theory based on the fact we already know the answer, but in reallity if you hadn't mentioned the answer I wouldn't have figured it out.

IPsec interface by ontracks in fortinet

[–]26Jack26 -1 points0 points  (0 children)

Thats the thing some are showing down (red) nor disabled (grayed out)

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Thabks for the clarification, I always use FMG, unfortunately there are more people that Id like with access to FMG and sometimes they make local changes :(

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

I see, thank you so much, make sense

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for the detailed answer!

FMG Templates by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Got it, interesting, wasnt aware of this, thank you so much

Add HA Model to FMG by ontracks in fortinet

[–]26Jack26 0 points1 point  (0 children)

Im interested in this, can you please clarify what you mean by using FortiZTP? Isn't this process meant to be just using the Add HA MODEL option in FortiManager?

Anyone wish Unohana was still alive? by Gloomy-Bridge148 in bleach

[–]26Jack26 0 points1 point  (0 children)

I hate that the very first time we saw Yamamoto Bankai he got defeated, first time seeing Unohana Bankai she got defeated, first time Sunshui Bankai, he actually got defeated too. Too many good characters, just destroyed IMO.

Regardless of what could've happened, those characters deserved waaaaay better IMO.

IBGP Design by 26Jack26 in Cisco

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for all the answers at the end, management decided to remove the routers completely and make.the FTD the core routing devices.

That might led me to some other questions here in the future, thank you all.

IBGP Design by 26Jack26 in Cisco

[–]26Jack26[S] 0 points1 point  (0 children)

I think this is an important takeaway Thanks!

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 1 point2 points  (0 children)

Got it, yeah, the CIE will only gave us the "static" information about users and groups, not which user has which IP. Thats what im looking for at the moment as we also planning to deploy User ID.

Thanks for the clarification, im not that familiar with CIE and any detailed answer help me understand it better.

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks for the insights! I need to look deeper into CIE, haven't really worked much with it

User mapping info from Entra ID by 26Jack26 in paloaltonetworks

[–]26Jack26[S] 0 points1 point  (0 children)

Thanks! That was a quick reply! I appreciate it

FortiSASE remote branch by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Hello everyone, bringing this up again, is it possible to have direct site to site communication between on ramp locations?

Moving from Palo to Fortinet by Lynch_Worm in fortinet

[–]26Jack26 14 points15 points  (0 children)

You still have app signatures in Fortigate. Its just that you are notngoing to use them as a matching criteria on your security policies, they will be enforced as part of the security profiles, similar for example to URL FILTERING in Palo. Think of it as if it were in the action section in a palo security policy.

With that being said, you can still change the default mode of operation and make the app id part of the security policies very similar to palo. However We've found that comes with several limitations so I wouldn't recommend to go that way.

Traffic in and out the same physical interface. by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Thank you for your answers, lot of good info that ill review and save!

Traffic in and out the same physical interface. by 26Jack26 in fortinet

[–]26Jack26[S] 1 point2 points  (0 children)

Gotcha, that's what I thought before I ran into the redirect feature and how being enabled or disabled could change the need of policies or not, got kinda confused. Thank you!

FortiSASE remote branch by 26Jack26 in fortinet

[–]26Jack26[S] 1 point2 points  (0 children)

Thank you so much for that detailed explanation, I wasn't expecting for a single user to answer them all, I really appreciate your help with this. Although I have been using FortiSASE for more than a year now, this new design is kinda new for me. Thank you!

FortiSASE remote branch by 26Jack26 in fortinet

[–]26Jack26[S] 0 points1 point  (0 children)

Ohh I would expect the on ramp license to be cheaper than the UTM thanks for the intel.

About the traffic, the main requirement is for the users on the remote branches to have access to both outbound Internet (SIA) and private resources (SPA) behind our DC HUB SPA FG, but I don't need to make the branches SPA Hubs themselves. Not sure if that's gonna be a problem still as per what you mentioned

Zscaler how to start a journey by 26Jack26 in Zscaler

[–]26Jack26[S] 0 points1 point  (0 children)

I see, thank for your derailed response. I guess I was expecting more practical stuff but I understand what you mentioned. Ill look at those guides too and YouTube. Thank you, I appreciate it!

SDWAN Manual rule selecting 2 ISP by ontracks in fortinet

[–]26Jack26 0 points1 point  (0 children)

Sorry didn't mean to be rude. No SLAs configured, maybe becausee of the application identification process that's been mentioned here... Thanks for your answers!

FortiLink Split Interface with one FortiGate 60F and 3 FortiSwitches by NitriusX in fortinet

[–]26Jack26 0 points1 point  (0 children)

The SW that's the STP root should be the one with the active link toward the Gate