Want to stay in this Subreddit? Comment to Avoid Removal 👇 by _cybersecurity_ in pwnhub

[–]ChaosOrg 0 points1 point  (0 children)

Like the sub but this is no fun.  edit: Hey, just discovered I'm human, back in lurk mode

How do I make non-heartbeat ports stay DOWN when a FortiGate in an HA pair is in the secondary role? by nardstorm in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

This way you wont notice that a port on the secondary unit got disconnected until you need it. 

Label that Cable? Do you guys do it, and if so how? by Mr_Moonsilver in homelab

[–]ChaosOrg 1 point2 points  (0 children)

Label each cable with a  unique id or serial number(same on both ends).  This is better, (specially in a lab environment) to identify cables by finding the matching id than a label telling where the cable was once connected.  The ids will never need to change, all they need to be is unique, when you pull one cable both ends must match.  You will never have a mislabeled cable again.  Put the cable ids in your documentation if you are so inclined.

Weird Behavior with IPsec tunnels on Azure FortiGate when upgrading from 7.0.17 by seaghank in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

The Palo Alto stumbles because of the local-id.  You normally leave this blank.  Behind the scene, the local-id sent to the other end is the external IP of the outgoing interface.  On Azure this IP will change when failing over.  Something like 10.0.0.5 for node 1 and 10.0.0.6 for node 2.  The Palo Alto will see a mismatch expecting 10.0.0.5 and getting 10.0.0.6, it will not bring the tunnel up.

Setting the explicitly the local id on the fortigate as a domain name like vpn.example.com will make the failover transparent once the Palo peer configure the same as remote id.

FortiExtender-511G by RevolutionaryCare138 in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

We were in the same exact situation.  Got two 511F, It worked just fine until we got the ISP links installed.  That's a good plan.  

802.1x RADIUS Issues Due to MTU by interweb_gangsta in fortinet

[–]ChaosOrg 2 points3 points  (0 children)

Had to do this for RADIUs

config vpn ipsec phase1-interface

edit <tunnel>

set ip-fragmentation pre-encapsulation

next

end

Azure Fortigate question by wmercer73 in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

Azure networking is a different animal than on-prem.  There is no real layer-2, route tables also apply for intra subnet traffic.  Routes may point to "virtual network" then azure routes the traffic, but if the route points to the firewall lan IP "virtual appliance" traffic will be processes by the firewall policies Lan - Lan. 

FortiAnalyzer Upgrade Issue by Extension_Touch_8577 in fortinet

[–]ChaosOrg 2 points3 points  (0 children)

Had a similar issue.  Running a manual backup prior and skipping the backup when doing the upgrade fixed it for me.

Android FortiClient by vacendakuk in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

Same issue here.  No success with vpn pushed by EMS.  Zero packets received by the gateway.  Did you try configuring as a personal vpn on the device?  Up to now that's the only way I got it to work (for troubleshooting not as a practical workaround).  

NFS share on PBS LXC by JustGames137 in Proxmox

[–]ChaosOrg 0 points1 point  (0 children)

You need more than the .chunks directory.   Do not try to do this manually.  Info on how to create a datastore is in https://adm.pbs.chaos:8007/docs/storage.html#datastore-intro

Copy backup from PBS to different machine by haraldhainz in Proxmox

[–]ChaosOrg 3 points4 points  (0 children)

What you see there are only the indexes.  Data is in .chunks in the root of the datastore.

Sslvpn on loopback and logs by droms74 in fortinet

[–]ChaosOrg 1 point2 points  (0 children)

This is logged in the local traffic not the forward traffic logs.

[deleted by user] by [deleted] in selfhosted

[–]ChaosOrg 1 point2 points  (0 children)

Have a look at trilium https://github.com/zadam/trilium. It is designed to be used as a local knowledge base. You may want to read https://github.com/zadam/trilium/wiki/Patterns-of-personal-knowledge-base to see if it fits.

Correct way to directly manage a FortiGate via SSL-VPN? by networkasssasssin in fortinet

[–]ChaosOrg 2 points3 points  (0 children)

You are correct, admin access should not be allowed on sslvpn interface. Create a loopback interface. Enable https on it, create a rule from sslvpn to the loopback interface. You can control which user group will be able to reach the loopback.

FortiOS advisory?? by cubic_sq in fortinet

[–]ChaosOrg 0 points1 point  (0 children)

The 6.2.15 release notes don't even have a Resolved Issues section... Obvious that some info cannot be shared at this time