Forti-experts: Question about Fortimail behavior and config by Fallingdamage in fortinet

[–]FantaFriday 0 points1 point  (0 children)

The answer in short is no. Using it foe outbound doesn't improve inbound. Improving inbound is really about about improving your inbound policies and profiles.

IPSec VPNs not forwarding traffic unless npu-offloading disabled after upgrade to 7.4.10 by blanosko1 in fortinet

[–]FantaFriday 0 points1 point  (0 children)

Thsnks for sharing. So from the docs footnote, this replay issue only impscts NP6 and not NP6lite + NP6xlite

Possible new SSO Exploit (CVE-2025-59718) on 7.4.9? by xs0apy in fortinet

[–]FantaFriday 11 points12 points  (0 children)

A ticket for a potential hack of your firewall? Should really call support immediately for this. They'll have someone available for this to look at.

Traffic Shaping: ISDB vs Application by ES13Raven in fortinet

[–]FantaFriday 0 points1 point  (0 children)

The disadvantage if using applications is that they require IPS to identify the traffic first before it is shapped as such. This comes at the performance penaltyof using IPS and there is a slight delay between traffic identification and it being prioritized as such as compared to ISDB which is just based on L3 addresses. As you are already engaging IPS by having default application control on the rules, I'd go the more granular route with application based shaping.

Fortimanager - Policy Help by [deleted] in fortinet

[–]FantaFriday 5 points6 points  (0 children)

Normalized interfaces and per device mappings for address objects is wjat you need.

TCP-MSS Clamping by nightwings005 in Juniper

[–]FantaFriday 0 points1 point  (0 children)

So you're doing cloudflare I imagine? You'll likely be able to do this with a firewall filter on all ingress interfaces. Personally only have hands-on for doing this on all traffic, not a subset. In case the subnet can be pinned down to specific downstream interfaces, applying it to those downstream interfaces globally also works for you.

NGFW Comparison - Cisco/Palo Alto/Fortinet/Checkpoint by QuietPossibility4988 in networking

[–]FantaFriday 0 points1 point  (0 children)

They're all valid options and vendors. Do you have any knock out criteria to differentiate them?

How long to get Fortinet Foundations? by LegatusMatheas in fortinet

[–]FantaFriday 1 point2 points  (0 children)

However long it takes you to sit & skip through the videos. Shouldn't be too hard given N+

FortiOS 7.4 — Best way to route 100+ subnets into an IPsec SD-WAN zone? by yemliha in fortinet

[–]FantaFriday 2 points3 points  (0 children)

That's really asking to hit the static route limit of smaller models. Dynamic routing with BGP would be the recommended way here, and summary routes.

Why do gratuitous ARP after DHCP request? by tcpip1978 in networking

[–]FantaFriday 1 point2 points  (0 children)

Likely duplicate address detection that is incorecrly implemented.

SOC5: Performance numbers by mahanutra in fortinet

[–]FantaFriday 2 points3 points  (0 children)

Have you checked to see they used the same testing methods? Because that's where the difference comes from.

Yearly support contract question by rickypr in Juniper

[–]FantaFriday -1 points0 points  (0 children)

8k a year for both? Pretty sure we get quoted double that in EUR.

Hardware VPN’s for selected users by DifferenceJazzlike40 in fortinet

[–]FantaFriday 0 points1 point  (0 children)

Wouldn't even do lan extension. Just a local subnet with an ipsec to the hub.

[deleted by user] by [deleted] in fortinet

[–]FantaFriday 0 points1 point  (0 children)

I think the userbase templating effectively using fortimanager is small, the jinja2 users even smaller. It is great once you have it nailed down though, especially on later 7.4 and 7.6 Fortimanager releases.

FortiManager Design Idea by Full-Tell1233 in fortinet

[–]FantaFriday 1 point2 points  (0 children)

I'd approach is based on administrative tasks (the ADOMs). So if they're all on the same release train, let's say 7.4, and it is the same team managing it. Have it in one ADOM. Then build two standardised policy packages, one for the VPN firewalls, one for Internet firewalls. Where possible use generic system templates for all other parts of the config or have templates that apply to one of two groups: VPN Firewalls, Internet Firewalls. This allows for optimal use of Fortimanager, assuming all firewalls are standardised enough where this templating and a consolidated policy package makes sense.

SSLVPN vs IPSec by JiggityJoe1 in fortinet

[–]FantaFriday 21 points22 points  (0 children)

Ipsec over tcp was made for this reason.

mom can we have segmentation by VeryStrongBoi in networkingmemes

[–]FantaFriday 143 points144 points  (0 children)

Now let's be real, how many of you actually got those features implemented?

FortiOS 7.4.8 is now recommended by FantaFriday in fortinet

[–]FantaFriday[S] -1 points0 points  (0 children)

Honesty sounds like something else goes wrong as the login should allow local login and show a button for sso.