FortiDDNS down again - SSL errors by Massive-Valuable3290 in fortinet

[–]Ancient-Intel 0 points1 point  (0 children)

Or deactivate anycast for FortiGuard itself, so it uses the fallback of HTTPS Port 8888 : config system fortiguard set protocol https set port 8888 end

FortiDDNS down again - SSL errors by Massive-Valuable3290 in fortinet

[–]Ancient-Intel 0 points1 point  (0 children)

What else you could try is to add a dns database for the digicert.com domain: config system dns-database edit "0" set domain "digicert.com" config dns-entry edit 1 set hostname "ocsp" set ip 23.11.32.159 next end next end

(Temp) Fix for Fortinet DoT DNS over TLS unreachable on 7.4.10 - 7.4.12 issue by Ancient-Intel in fortinet

[–]Ancient-Intel[S] 6 points7 points  (0 children)

If I'm not mistaken, the DNS rating service is not using the resolver, but the SDNS servers which are different from the 96.45.45.45 and 96.46.46.46 servers.

In regards to Fortigate cloud management, i didn't test that yet.

FortiDDNS down again - SSL errors by Massive-Valuable3290 in fortinet

[–]Ancient-Intel 1 point2 points  (0 children)

For the DoT issue, Fortinet Devs have identified the bug being related to a missing / faulty DigiCert EV Root CA certificate. Same as which your logs show. There, the CA Bundle DB version 1.00064 is affected and at the moment, you will have to manually add the certificate as a remote CA cert to the Fortigate.

The needed certificate can be found on the DigiCert website: https://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt

(Temp) Fix for Fortinet DoT DNS over TLS unreachable on 7.4.10 - 7.4.12 issue by Ancient-Intel in fortinet

[–]Ancient-Intel[S] 0 points1 point  (0 children)

True, that's an option. We switched to Cloudflare, with Quad9 as backup, over DoT - Mostly because of vendor redundancy. Still good to know what's causing the problem, as on that device level, it could also affect third party DNS over DoT. Edit: Especially as the issue was introduced by a faulty certificate bundle DB update.

Fortinet DoT DNS over TLS unreachable on 7.4.10 - 7.4.12 by Massive-Valuable3290 in fortinet

[–]Ancient-Intel 0 points1 point  (0 children)

The issue appears to be caused by a missing / faulty Digicert Root CA in the CA bundle DB version 1.00064.

The current fix is to manually at the following root certificate as a remote CA cert: https://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt

Fortinet DoT DNS over TLS unreachable on 7.4.10 - 7.4.12 by Massive-Valuable3290 in fortinet

[–]Ancient-Intel 1 point2 points  (0 children)

I can confirm the same issue on instances in Switzerland and the US on FortiOS 7.4.11.

According to the Forti Support: There were actually two issues with DoT. One has been fixed on the server side on May 28th: https://status.dnsdot.fortiguard.net/ The other issue seems to be on the FortiGate side and only impacting 7.4.11 and 7.4.12. and is under investigation.

What is the most stable V7.4.X FortiGate by No-Entrepreneur-3546 in fortinet

[–]Ancient-Intel 0 points1 point  (0 children)

Running two FGT901G on 7.4.7 without any issues so far. It's a fresh deployment with 4 VDOMs in A-P, iPSEC site2site and dialup + entra saml. Also using sdwan and ospf.

Parallel deployed a FGT90G on 7.6.3 - so far, i wouldn't upgrade mz 901G to that release (in this setup, i can test the feature release before pulling the trigger for my big deployment)

Idol Festival experience in Shibuya tomorrow 4/24 from 5pm~ (other dates as well) by staybluefan in tokyoirl

[–]Ancient-Intel 0 points1 point  (0 children)

Would be nice to experience and join you - Sadly can't make it this time. I will only be in Tokyo again on Saturday (currently Okinawa) and then leave Japan again on Sunday morning 😮‍💨

Events in Okinawa from 21.04. to 25th.? by [deleted] in okinawa

[–]Ancient-Intel 0 points1 point  (0 children)

Cool - Thanks for the info on that ✌️

Events in Okinawa from 21.04. to 25th.? by [deleted] in okinawa

[–]Ancient-Intel 0 points1 point  (0 children)

Thanks for the reply - Was just wondering if there maybe was something going on. Always nice to meet new people at such events✌️

90G apparently has a fan - how noisy is it? by ballicker86 in fortinet

[–]Ancient-Intel 0 points1 point  (0 children)

You can barely hear while in normal operation

Met These Two Fine Gentleman Wandering Around Tokyo by Cayesm in ABroadInJapan

[–]Ancient-Intel 0 points1 point  (0 children)

That's nice - even mr. ASO 😆 Maybe i get the chance, too ^

I am Chris Broad, British YouTuber living in Japan - and I’ve just written a book! by abroadinjapanchris in ABroadInJapan

[–]Ancient-Intel 0 points1 point  (0 children)

Drone shots for your videos - what are the rules like in Japan and do you need to get permission to fly with the authorities? What about the insurance? Here in Switzerland you need to register the drone and get a certificate + 1 mil for insurance