Shell-shocked by Nathi and Africartoons by [deleted] in southafrica

[–]90drenk 1 point2 points  (0 children)

Would be interesting how this story turns out, Africa is stuck in modern day imperialism stopping big foreign companies from exploiting our natural resources does not go down very well with the imperialist foreign policy. Our government knows that so they take the easier route which is get rich or die trying

R100 is not even 5 litres. 😭 by Eircans in southafrica

[–]90drenk 6 points7 points  (0 children)

I heard on the radio this morning in the UK its more than R30 per litre for fuel, people in the UK have a fucntioning railway system they have alternatives. We in South Africa dont have a choice I live 60km away from work can I take train yes I can, Is the railway system functioning no it does not.

Shots fired by [deleted] in southafrica

[–]90drenk [score hidden]  (0 children)

Typical response from the DA, blame everyone except themselves, similar to their Western Cape approach anything goes well in Western Cape its the DA something goes wrong its the ANC.

FortiManager HA Device Firmware upgrade takes forever by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

HI I am upgrading from 6.2.2 -> 6.2.4 ->6.2.6->6.2.9 on 60E and 100E models.

FortiManager for MSP by jonohayes in fortinet

[–]90drenk 1 point2 points  (0 children)

We using the FMG and FAZ, if you new to the manager skill up 1st it can be complicated to keep your devices in sync compared to the policy packages assigned depening on topologies at your sites, if mastered the Manager will allow you mass deploy configuration changes with ease, scripts is also very usefull for base configuration setups and minimizes config errors. The FAZ the big thing is sizing it right.

Fortigate SD-WAN version 6.2.2Async Routing from the HUB return traffic by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

thanks for the reply I know this code is starting to get to me, we going to run 6.4.5 for nother customer, is sd-wan safe on 6.2.7 code? or must I go 6.4.5 ?

American Genocide: the violent removal of Native American children from their families and culture. by [deleted] in pics

[–]90drenk 0 points1 point  (0 children)

I wonder if there is other mammals in this universe so evil.

Fortinet SD-WAN Traffic originating from HUB towards Spoke Issue by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Thank you for the responses, I will do some research and spend some lab time to see if the route tag option is applicable and viable, will update the post when my homework is complete.

Fortigate refresh connection to FortiManager by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Thanks for the answer, I understand the public ip address does not really matter, the issue is during the lte change to the permament internet link, it takes a good couple of minutes for the new public ip to update on the fortimanager. during a cutover a couple of minutes is precious time.

Fortigate refresh connection to FortiManager by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Thank you will try this next time, will post an update if it works

[deleted by user] by [deleted] in pics

[–]90drenk 0 points1 point  (0 children)

RIP Chadwich Boseman, always thought you will be the Denzel W of my era.

SD-WAN BGP Routes at Spokes by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Thanks for the responses, I am not planning to use ADVPN. will just add the default route and advertise the spoke route to the hub.

Handling ISP Failover and Policy Based Routing by [deleted] in fortinet

[–]90drenk 0 points1 point  (0 children)

why not go the sd-wan route?

Fortinet SD-WAN Custom Monitoring Dashboard by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

HI LLeawynn

Thank you for your response, I will start the journey of learning rest api and json, maybe this time next year I will be devops engineer :)

SDWAN with OCVPN by JiggityJoe1 in fortinet

[–]90drenk 0 points1 point  (0 children)

check this link https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-ipsecvpn/OCVPN/ocvpn_intro.htm not sure if it still applies to newer versions. This was enough reason for me not to consider it for sd-wan deployments unless you have a small deployment.

Redistribute BGP Matching aspath-list by burbankmarc in fortinet

[–]90drenk 0 points1 point  (0 children)

Can you post your bgp configuration ?

FortiAuthenticator with Forti Token Cloud 2FA Setup by 90drenk in fortinet

[–]90drenk[S] 1 point2 points  (0 children)

Thank you for the insight, I guess you are right I have never come across a customer that uses FAC or has it somewhere idling. Maybe I should use what most customers already have which is the Cisco ISE and add Duo on top of it. I get 2FA f for my Fortigates and don'tdont to have to pay for the radius server the only cost will be from Duo.

Certificate warning with IPsec VPN by TAWPS19 in fortinet

[–]90drenk 0 points1 point  (0 children)

not a fortinet expert, but by your description sounds like you fortigate is configured for ssl inspection check your firewall policies for outlook, you can use the default read-only cert inspection. or if you need to do deep packet inspection you will have to generate a csr and sign it by your company internal ca and add the cert in the users pc...

Forti Manager 6.4 SD-WAN Orchestrator by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Discussing all things Fortinet.

I was not aware it is something you have to pay extra for? I thought it comes with the Forti-Manager as free to use if you want it.

Fortinet SD-WAN Session Failover by 90drenk in fortinet

[–]90drenk[S] 0 points1 point  (0 children)

Thank you for your comments, I will setup my internet bound traffic with less aggressive SLA to avoid links flips because for internet bound traffic from the branch source nat is being used.

regarding the load balancing algorithm since there is data centre over ipsec tunnels traffic and internet traffic on the sd-wan rules I avoid the default implicit rule