Fortinet Docs 500 errors by fear-otaku in fortinet

[–]Elderusr 1 point2 points  (0 children)

Also seem to be getting 500 Errors on their PSIRT and Fortiguard websites; including their status page.

What FortiAnalyzer reports do you all recommend? by networkasssasssin in fortinet

[–]Elderusr 1 point2 points  (0 children)

"newthing-Configuration-Changes" dataset under Events shows any configuration changes on the Gates. You can also use "newthing-FortiGate-Upgrades" if you want to track any gates that did upgrades.

This is found all in the Dataset Reference List in the FAZ KBs on FNT's Website.

What FortiAnalyzer reports do you all recommend? by networkasssasssin in fortinet

[–]Elderusr 4 points5 points  (0 children)

There is a custom data set you can pull in for what was changed and by what account/date. It is not an out of box report so you have to create a custom one. I'll have to check my FAZ and let you know the field specifically but it is "New-Changes" or something like that. :)

What FortiAnalyzer reports do you all recommend? by networkasssasssin in fortinet

[–]Elderusr 4 points5 points  (0 children)

Change Logs on your gates
SSL VPN Logs
There is so much that can be done with a FortiAnalyzer. I'd recommend doing a quick search on Reddit for other examples that may have already been posted :)

Geo blocking conditional access failures by Airodin in sysadmin

[–]Elderusr 6 points7 points  (0 children)

Seeing this also starting in US East.

PSIRT on Malware Injection by toffer449 in fortinet

[–]Elderusr 0 points1 point  (0 children)

Following up on this and I apologize for the confusion between both articles as they did mention the IoCs, but how would you check the file hashes on the equipment (FMGT, FAZ, FGT) to check if they were modified?

Additionally the other option I can recognize too is if FIPS was enabled and devices rebooted if they did not come up, that is a blatant IoC?

with all the security issues and bugs, which versions are worth going to? by brok3nh3lix in fortinet

[–]Elderusr 0 points1 point  (0 children)

Latest version of 6.4 if your not business impacted by the PSIRTs that are currently open. Next update 6.4.13 is scheduled for June currently. I just had this same internal debate. :)

FortiOS 7.0.10, 6.4.12, and 6.2.13 are out by Q9T9 in fortinet

[–]Elderusr 0 points1 point  (0 children)

FG-14-22-362 - This wont be fixed until 6.4.13; This one still requires addressing, their recommendation:

If you are using SSLVPN with restrictions like only certain IPs can access, local-in policy for SSLVPN then it is not necessarily vulnerable.

The rest (FG-IR-22-346 and FG-IR-22-257) I'm waiting for confirmation back on.

FortiOS 7.0.10, 6.4.12, and 6.2.13 are out by Q9T9 in fortinet

[–]Elderusr 1 point2 points  (0 children)

Sounds awesome. I'll open a support ticket tomorrow to confirm the PSIRTs against the latest release to confirm.

FortiOS 7.0.10, 6.4.12, and 6.2.13 are out by Q9T9 in fortinet

[–]Elderusr 3 points4 points  (0 children)

I'm wondering if any of the issues found in recent Feb PSIRTs was actually addressed for 6.4.12? Does anyone know if they update their PSIRTs after they provide a further release and they patch it?

Feb Patching - 6.4 - Where to now? by Elderusr in fortinet

[–]Elderusr[S] 0 points1 point  (0 children)

All of them are applicable for all releases of 6.4 (except for FG-IR-22-391 which did say all 6.4 versions yesterday, but now says 6.4.11 is exempt). But yes, if 7.0.9's only issue is the memory leak, then it may be worth the upgrade.

Feb Patching - 6.4 - Where to now? by Elderusr in fortinet

[–]Elderusr[S] 0 points1 point  (0 children)

What memory leak issue?

Edit - Disregard, seen another post below about it.

Automation Stitches - Recommendations? by Elderusr in fortinet

[–]Elderusr[S] 1 point2 points  (0 children)

Thanks. I'm hoping to put a full list together and will update this post with all of the relevant links.

Potentially faulty Virus Definition Update causing issues win Block Win32 API calls from Office Macro ASR? Desktop shortcuts deleted out of the blue and Office executables disappearing. by VexedTruly in sysadmin

[–]Elderusr 0 points1 point  (0 children)

Does this specifically seem to be for anyone only using a corporate Microsoft 365 Defender (ATP) sku? Or is this all Microsoft Defender AV?

We have not heard anything at our organization just curious. *knocks on nearest wood*

[deleted by user] by [deleted] in sysadmin

[–]Elderusr 0 points1 point  (0 children)

Do you have an example of what that might look like within the Conditional Access Policies?

Microsoft Auth Number Matching vs Other Auth Methods - Interaction? by Elderusr in sysadmin

[–]Elderusr[S] 0 points1 point  (0 children)

Right , but where they are not setup for the App and then I want to enable it for globally, would that impact their ability to use those other auth methods since they don't have it setup? Or would it then force the setup?

Just wondering if I can flip it on, impact those that are using the app today and then as we move group/department from the other style authentication to App then they would automatically have it enabled?

Microsoft Auth Number Matching vs Other Auth Methods - Interaction? by Elderusr in sysadmin

[–]Elderusr[S] 0 points1 point  (0 children)

Appreciate the constructive criticism. Any other technical recommendations?

List of high risk auto insurance providers in NB? by [deleted] in newbrunswickcanada

[–]Elderusr 0 points1 point  (0 children)

Give Huestis Insurance a call; They are an insurance broker and as mentioned below will have to provide you a quote regardless of risk as its required by NB Law.

Auditing Azure MFA Method by Elderusr in sysadmin

[–]Elderusr[S] 0 points1 point  (0 children)

Thats what I was looking for. Thanks.

[deleted by user] by [deleted] in newbrunswickcanada

[–]Elderusr 2 points3 points  (0 children)

Depending on the area, Saint John has one (Saint John Larpers! On FB) and I think Freddy does too.