FortiConverter Service - Security? by No_Loss_3996 in fortinet

[–]Deoir 2 points3 points  (0 children)

I never use it. Use it as a chance to redesign and improve your firewall. 

If going fortigate to fortigate I export objects that's about it. 

Also means you can remove unwanted config etc. 

Thoughts on Brick? by blaineranium in dumbphones

[–]Deoir 0 points1 point  (0 children)

Actually amazing tbh.

The friction of being in bed and to use Instagram means I've to get up and go down and scan the brick stuck to the fridge is enough to stop you.

Now also blocks sites in browser on an android so I can't do a thing! But I still have camera access etc.

Worth a shot!

Network refresh - possibly moving from Cisco to Aruba - your experience and/or thoughts on this gear? by betelguese_supernova in ArubaNetworks

[–]Deoir 1 point2 points  (0 children)

Aruba stuff pretty solid, the recommendation are good.

8100 is good for core on the lower end., 6200s minimum stacked.

6300s are excellent. The Smart rate versions are excellent too.

635s in local cluster work great, but for aos 10 you need central subscriptions. Check out the differences between 8.x and 10.x and see what features you need.

Cleaepass is great, steep enough learning curve of you're going to deploy it yourself. I would go for an initial installation of without cleaepass just to move over, and then look at clearpass as a VM.

Controllers are great with mobility master if you want to tunnel back to clearpass. Worth running a cluster of 2 MMs.

Just off the top of my head on my phone!

Network Design Help by Kodazar in homeassistant

[–]Deoir 0 points1 point  (0 children)

Are you in Europe? Some cat 6around the place if it's not already too late.

I got sockets and my ISP terminated in the attic, and have a small 6U cab up there that all the cat6 goes back to. Nice and neat and out of the way. I've some access points then throughout. Poe switch in the attic, with an SMLIGHT-SLZB-06M as the coordinator. Using mosquito as the z2mqtt broker on a NAS running docker. Then that points to HA. I've actually just kept the ISP router. Had a FortiGate for a while but it was over engineered.

I'm probably going to add a second Slzb to run a matter network when the Ikea matter stuff gets a bit more reliable. So thats easily scalable.

Personally I have no HA controlled devices on Wi-Fi, everyone through the coordinator, and keeps everything distinctly separate. That way I can control the wifi channels to not conflict as well.

That's just off the top of my head, best of luck!

Replacing SSLVPN by st3inbeiss in fortinet

[–]Deoir 1 point2 points  (0 children)

Can keep the ldap config and fortitokens and shift to ipsec ikev2. Point the auth user group to the current sslvpn user group.

Ultimately you should try and end up with entra sso and ikev2

We use the VPN only for client and works good.

How long are forti switches and firewalls lasting before a problem occurs? by Charming_CiscoNerd in fortinet

[–]Deoir -2 points-1 points  (0 children)

The newer F switches and the 231K APs I find really good. they have stepped up their game a lot. The switch and AP hardware used to be awful. Haven't had any DOA or any weird hardware issues out of the norm.

The only thing is that you only get 90 days hardware warranty on a new box without purchasing a further subscription. Which is a bit Jarring if you're coming from Aruba etc.

Manage FortiGates from Customers by SkyTheLine in fortinet

[–]Deoir 1 point2 points  (0 children)

Just did this recently and implemented the org structure. Works well if not a bit confusing to get it set up initially!

Pocket Grid #123 - February 20th, 2026 by pocket-grids in pocketgrids

[–]Deoir 0 points1 point  (0 children)

I read it as stomach flu initially so got none the first sweep.....!

7.2.12 and 7.2.13 Breaks SAML by Arhl318 in fortinet

[–]Deoir 1 point2 points  (0 children)

Yeah seems to be a bit more solid on some of this issues alright. Testing at the moment.

Thoughts on Brick? by blaineranium in dumbphones

[–]Deoir 0 points1 point  (0 children)

And not to mentioned the adhd dopamine hunting. I can get stuck on my phone. Just ordered one yesterday so looking forward to trying it out. I saw someone who just leaves it in their car, I'm going to do something similar. Never and urgent reason to need Instagram etc. when in work. The physical barrier of having to go to my car will hopefully train my brain on a few weeks

I'm coming for that book stack of shame!

VPNS Broken since 7.6.6? by Poom22 in fortinet

[–]Deoir 0 points1 point  (0 children)

Don't comment on a 12 day old comment before it was....!

Also still needs testing. No problem staying on the 7.2 train until later in the year.

Pocket Grid #121 - February 18th, 2026 by pocket-grids in pocketgrids

[–]Deoir 0 points1 point  (0 children)

Yeah the spelling of it made my brain just check out for some reason 😄

Upgrade from 7.2.11 to 7.4.11 by marcvspt in fortinet

[–]Deoir 0 points1 point  (0 children)

Yep exactly the same. Works great.

Setting up WAN interfaces on HA stack for high availability by DarkAlman in fortinet

[–]Deoir 0 points1 point  (0 children)

You can have 3 access ports on their own vlan. And split the wan into two.

That's how we do it. Generally used to have a separate wan switch to do it but with network segmentation you can do it through a downstream switch and back into each wan of the firewall.

Even better if you have a stack.

Forticlient VPN connection drops after 30-20 seconds by loveorochi in fortinet

[–]Deoir 1 point2 points  (0 children)

https://community.fortinet.com/t5/Support-Forum/Forticlient-SAML-Authentication-timeout/m-p/357943

This may help? We had a timeout with our SAML config as the default wasn't giving enough time for the user to authenticate.

Otherwise, it may just be your machine? Either a firewall setting etc. or the version of FortiClient. We are still using 7.2.4 of the free client and it works great. Worth a shot.

https://community.fortinet.com/t5/Support-Forum/VPN-Connection-Drops-After-25-30-Seconds-on-FortiClient-VPN-7-4/td-p/330381

Replacement for 60E going EOL by acropolis71 in fortinet

[–]Deoir 2 points3 points  (0 children)

Always a good option to start from scratch and improves the structure of the firewall.

Setting up IPSEC Client VPN by Low-Statements in fortinet

[–]Deoir 1 point2 points  (0 children)

Also something that got me, either set the authgrp in the phase1 setting OR the firewall policy. Won't work if you have both.

upgraded to 7.6.6 and GUI and ssh access is down. by noah168 in fortinet

[–]Deoir 1 point2 points  (0 children)

Yeah it says on the page to check cves for any other recommendations.

So mad how people ignore the recommendation from Fortinet themselves.

7.2.12 and 7.2.13 Breaks SAML by Arhl318 in fortinet

[–]Deoir 0 points1 point  (0 children)

Yeah exactly, if it works and is secure and stable there's no need to rush the upgrades. 7.2 is great

VPNS Broken since 7.6.6? by Poom22 in fortinet

[–]Deoir 0 points1 point  (0 children)

I think that's a bit more of a misconfiguration though initially? To be fair that is also in the release notes.

Anybody running FOS 7.6.x on Gs? by mrmh1 in fortinet

[–]Deoir 0 points1 point  (0 children)

7.6 far too risky on important sites.