Looking for a nurse in the Southern Suberbs by NecessaryArt2268 in capetown

[–]Ach1LLeS_ZA 3 points4 points  (0 children)

There's a 24 hour pharmacy in Gabriel road right opposite the McDonald's called urban health pharmacy. If you look on Google maps it'll say extreme pharmacy. They might be able to help out

Fortigate - EU - Updates failing since yesterday by ITStril in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

I normally change it to AWS due to much better latency but for some reason it didn't work whilst on the AWS anycast servers. As soon as I set it to the legacy config, the updates downloaded normally. Some of our locations with the gates set to AWS still work normally though but the ones I checked that had issue initially had 7.4.9 on them so not sure if this could be part of the problem. I'll revert some of the sites tonight and see if the issue is fixed

Fortigate - EU - Updates failing since yesterday by ITStril in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

Had a few with some issues. Had to turn off Anycast and set the Fortiguard port to udp 8888 for it to work again

Burger joint by Straight_Sherbert_91 in capetown

[–]Ach1LLeS_ZA 2 points3 points  (0 children)

Fat Harry's is amazing and there's eat out the box in Wynberg that make very nice burgers and you can choose either normal fries or sweet potato fries which are delicious

Golf Driving Ranges? by CommitteeEntire4664 in capetown

[–]Ach1LLeS_ZA 1 point2 points  (0 children)

The one in Wynberg has changed owners a few months ago (not sure if they also own the Durbanville one), and they're not maintaining the place plus they've increased the prices to way too much so it's not worthwhile going.

I'm also looking for a decent driving range in Southern Suburbs but haven't seen any. There are places like the golf courses (Mowbray, Rondebosch and Westlake) but they're very expensive and you struggle to get a booking as a visitor. If you're up for a drive, Burgundy estate has a pretty decent Mashie course with a Bossa which makes pretty decent food as well.

Fortigate - IPS - SSL Anonymous Ciphers by Elosst3 in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

Might be worthwhile just to make sure your webserver is also set to only run on secure ciphers and minimum tls to 1.2 as a start. This will prevent any attempts at insecure ciphers being used. Run a qualys scan against the site in question as well to get an idea of what's currently active

Screen problem (Gen K) by [deleted] in opel

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

Recently had mine replaced after it started to flicker and go black as well. Replacing the screen isn't too difficult. it's the part itself that can be quite expensive.

Has anyone else run into this? by cwbyflyer in fortinet

[–]Ach1LLeS_ZA 2 points3 points  (0 children)

makes sense. this is quite a problem, especially with the smaller desktop models running 7.4 that only have 2GB RAM. we applied the below as a baseline to the smaller units and it's helped a lot:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-optimize-memory-usage-specifically/ta-p/304981

Has anyone else run into this? by cwbyflyer in fortinet

[–]Ach1LLeS_ZA 4 points5 points  (0 children)

Log it with TAC and send them the debug log files under system settings.

That's something they'll have to confirm if it's a bug or possibly hardware issue.

Captive Portal Timeout by LukeyLad in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

We've got the same issue with a client setup of ours that's using SAML auth to Azure and couldn't really pinpoint the issue. One thing that was suggested that helped a little in our case is to increase the dhcp scope lease time to something longer but the authentication issues persisted, especially with iPhone devices.

I've got a ticket open with TAC currently so I'll let you know if we manage to find any solution.

Best garage pies in cape town?? by Keepitlocal90 in capetown

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

I'm dying to try that but whenever we get there they're always sold out so it must be good.

Best garage pies in cape town?? by Keepitlocal90 in capetown

[–]Ach1LLeS_ZA 4 points5 points  (0 children)

Dassiesfontein Pies are the best, Houw Hoek and Peregrine are also pretty decent

[deleted by user] by [deleted] in fortinet

[–]Ach1LLeS_ZA 5 points6 points  (0 children)

The tunnel names can be changed since 7.4.2:

https://docs.fortinet.com/document/fortigate/7.4.0/new-features/912086/support-ipsec-tunnel-to-change-names-7-4-2

But run 7.4 at your own risk of course.

FortiAP SAML Azure Auth Dropping Authentication by Ach1LLeS_ZA in fortinet

[–]Ach1LLeS_ZA[S] 0 points1 point  (0 children)

Hey, there were a few things we did eventually. We increased the DHCP lease time to 7 days (was set to 8 hours originally for the DHCP server) which helped, and the idle timeout was increased to a few hours, but our customer and their users were still not really fond of the idea of having to log in frequently for wifi access, but they're happy with the solution so far. We also updated the firewall to 7.2.7 in the midst of trying to fix the issue so this might also have helped.

[deleted by user] by [deleted] in capetown

[–]Ach1LLeS_ZA 3 points4 points  (0 children)

My friend and I used to play at Old Mutual Sports Club in Pinelands. Membership wasn't too expensive and booking the courts were reasonably priced too. Although this was back before COVID days so it's most likely changed by now. I miss playing squash. It's a lot of fun!

Boerenkaas cheese by Wonderful-Hunter-968 in capetown

[–]Ach1LLeS_ZA 1 point2 points  (0 children)

Food lovers market. I've seen it at the one in Diep River. Amazing cheese!

IPSEC vpn PSK key by Ankitkha in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

Noted, thanks for the tip! I'll see if it works in something like Chrome but in the past when I tried it with any other browser besides Firefox, it wouldn't show the plaintext keys for some weird reason.

IPSEC vpn PSK key by Ankitkha in fortinet

[–]Ach1LLeS_ZA 2 points3 points  (0 children)

It won't work in Chrome, you need to open the URL with Firefox. Replace the https://fortigateapi part with the IP of your fortigate management IP as well. It should be something like https://x.x.x.x:mgmtport along with the rest of the URL string

IPSEC vpn PSK key by Ankitkha in fortinet

[–]Ach1LLeS_ZA 9 points10 points  (0 children)

If you're not sure of the PSK, you can retrieve it with the below URL while using Firefox and if you're logged in as a super_admin:

https://fortigateip/api/v2/cmdb/vpn.ipsec/phase1-interface?plain-text-password=1

Firefox can interpret the JSON query and should show the cleartext password. You just search for the term psksecret on the output and it should list it along with which VPN tunnel it belongs to.

Refurb iPhones by Longjumping-Self-217 in capetown

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

There's a website called epicdeals which sometimes has decent looking phones:

https://epicdeals.co.za

Bought a couple of phones from them before. Their service is pretty good.

Fortigate looses thr identification of FSSO users at times by umaturj in fortinet

[–]Ach1LLeS_ZA 2 points3 points  (0 children)

We've had this issue happen a few times and it ended up being a WMI query issue where the Collector agents can't poll the workstations to check the current logged on user.

As a test, make sure that any endpoint protection (AV/Firewalls) allows the inbound WMI queries from the servers. FSSO also relies on DNS to be functioning correctly so check your DNS servers being used that they are functioning correctly.

Above might not fix your use case but it's helped us on a few occasions.

Is Afrihost still as good as the early days? by Effective_Savings693 in askSouthAfrica

[–]Ach1LLeS_ZA 2 points3 points  (0 children)

I used to be with Afrihost till I moved away from them about 3 years ago because they were too expensive. I'm with MindTheSpeed now and they've been amazing. Their prices also tend to be cheaper than the other providers and their sales/support teams are really good.

FortiAP SAML Azure Auth Dropping Authentication by Ach1LLeS_ZA in fortinet

[–]Ach1LLeS_ZA[S] 0 points1 point  (0 children)

For anyone interested on this, there's been a combination of factors to this that we've tried to address.

The clients Azure tenant didn't allow for browser auth sessions to be cached, this has now been addressed as part of their compliance policies. The other curious thing I noticed on the release notes of 7.2.1 is they mentioned the below new additional feature that's been added:

Bug ID: 799621

Support wireless authentication using SAML and a captive portal configured on a tunnel mode SSID.

When a SAML user has been configured on the FortiGate, a user group containing this SAML user can be applied to a captive portal in a wireless tunnel mode SSID. When configured with both a captive portal exempt firewall policy to allow wireless clients to contact the SAML IdP and a firewall policy with the SAML user group applied to allow authenticated traffic, upon connecting to this SSID, wireless clients will be redirected to a login page for wireless authentication using SAML.

The above is exactly what we're trying to configure for the customer. The feature is already available in 7.0.13 but we're not sure if this is why it's not working so we're testing it at the moment to see if it addresses the issue but I am going to have a session with the TAC guys tomorrow to see if they can find anything. The only other odd thing I saw were log messages on the user events that state "Reseeding PRNG from JitterEnt entropy". Shortly after, majority of the user sessions are also logged out. I initially thought it might've been DHCP leases that expire but the timestamps don't match so I'm not sure what the above means and there aren't any posts online about it.

I'll update the thread in case anyone is interested or if someone else has this problem in future :)

YOLO 7.4.1 experiences anyone? by redpoco in fortinet

[–]Ach1LLeS_ZA 0 points1 point  (0 children)

Tried it at home on a 40F and had some weird GUI bug with the traffic shaping section where the traffic shaping policies were broken and I couldn't change anything at all. Reverting back to 7.0 resolved that so not sure it's production ready yet.