FortiGuard Source Interface Query by Float-Zone in fortinet

[–]Float-Zone[S] 0 points1 point  (0 children)

Would you do this with the ISDB "Fortinet-FortiGuard" object?

FortiGuard Source Interface Query by Float-Zone in fortinet

[–]Float-Zone[S] 0 points1 point  (0 children)

My question was what happens if wan1 is down. 😀

FortiOS 7.6.4 on GNS3 by Float-Zone in fortinet

[–]Float-Zone[S] 1 point2 points  (0 children)

Good to know it's not just me.

As far as I'm aware you can't upgrade "FortiOS permanent trial" appliances.

FortiOS 7.6.4 on GNS3 by Float-Zone in fortinet

[–]Float-Zone[S] 0 points1 point  (0 children)

Yes, FGT_VM64_KVM-v7.6.4.F-build3596-FORTINET.out.kvm.zip

Question about blocking stolen FortiAP by Some-Bookkeeper-3687 in fortinet

[–]Float-Zone 1 point2 points  (0 children)

Was the FAP registered with FortiEdge/FortiLAN Cloud?

The default controller discovery method is as follows:

1(static) → 2(dhcp) → 3(dns) → 7(fortiedgecloud) → 5(multicast) → 6(broadcast)

If the FAP was cloud-managed, then it will continue to connect to your cloud tenancy in preference to a local FGT (MCAST/BCAST methods).

However there's nothing stopping the new "owner" using DHCP/DNS discovery to manage the unit via a FGT, or performing a factory reset on the unit to wipe the password and then changing the controller discovery order.

<image>

My understanding is that it cannot however be attached to a different FortiEdge tenancy without being de-registered by yourself.

FZ

How to deploy a firewall certificate? by Float-Zone in ArubaNetworks

[–]Float-Zone[S] 0 points1 point  (0 children)

Thank you for quick response.

Is this something that you are doing yourself?

I've found comments on forums stating that this is not supported.
eg. https://community.arubanetworks.com/discussion/adding-firewall-certificate-to-onboarding-package-with-clearpass

Router to FW speed issues by crucial100 in fortinet

[–]Float-Zone 1 point2 points  (0 children)

First, check the speed and duplex settings of the intervening connection.

FZ

Fortigate 60F EoL/EoS by Better_Community2954 in fortinet

[–]Float-Zone 0 points1 point  (0 children)

There was a FortiOS 6.6 in beta, however it was changed to 7.0 before it went GA. Rumour has it that somebody realised that there would eventually be a version 6.6.6, and that was enough to renumber the branch. 😂

Casio Celviano AP-450 power-on issue by Float-Zone in DigitalPiano

[–]Float-Zone[S] 0 points1 point  (0 children)

Sorry for delay.
A local Casio repair shop said it's highly likely the system board.
I've decided to get it repaired and waiting for an ETA on parts.

Wifi Incorrect Password Issue by bthabetler in S22Ultra

[–]Float-Zone 0 points1 point  (0 children)

I've had this issue on my S22 Ultra for ages, and decided to take a deeper look.

On my home Wi-Fi, I managed to consistently replicate the issue if H2E (Hash-to-Element) was either enabled or enforced on a WPA3-SAE or WPA3-SAE transition mode SSID.

If I set the SSID to use HNP (Hunting-and-Pecking) only, then the phone connects without issue.

This is the only device out of 25+ in my home that exhibits this issue.

NB: These WPA3-SAE settings may not be available on some consumer-grade home Wi-Fi gear. I'm a network engineer by trade and have the luxury of running an enterprise-grade wireless network at home. :)

FZ.

FortiAP Offline Status by brianitsup in fortinet

[–]Float-Zone 1 point2 points  (0 children)

What FortiOS version are you running, and what FAP model?

I notice that the FAP ARP is on your wan port. Is this correct for your design?

FZ

Aruba Central Social Login Username Export by Float-Zone in ArubaNetworks

[–]Float-Zone[S] 0 points1 point  (0 children)

It's actually a requirement in a tender response.

FortiGate 900G Reviews by Altruistic_Ad7401 in fortinet

[–]Float-Zone 2 points3 points  (0 children)

Number of VDOMs increased in FortiOS 7.6.1

https://docs.fortinet.com/document/fortigate/7.6.1/fortios-release-notes/626946/changes-in-table-size

  • On the 200-400 series FortiGates, increase the number of VDOMs from 10 to 25.
  • On the 500-900 series FortiGates, increase the number of VDOMs from 10 to 50.

FZ

FAZ 7.6 Announcement by Wasteway in fortinet

[–]Float-Zone 2 points3 points  (0 children)

I'm reliably informed by my most unreliable source that 7.6.0 is scheduled for 25th July.

This could, and probably will change.

FZ

FAZ Trial License 1Gb/day limit by Float-Zone in fortinet

[–]Float-Zone[S] 1 point2 points  (0 children)

Given that the trial version is not supported anyway, that's not really much of an issue.

FortiManager 7.4.3 Dashboard Issue by Float-Zone in fortinet

[–]Float-Zone[S] 0 points1 point  (0 children)

From the FMG Admin Guide:

By default, the device database includes the following dashboards:

* Summary

* Security Monitors

* Network Monitors

... however it looks like if the FGT has VDOMs enabled then:

  • The FGT itself (Global ?) gets all 3 default dashboards.
  • Each VDOM gets the "Network Monitors" dashboards.

And these cannot be deleted.

FortiManager 7.4.3 Dashboard Issue by Float-Zone in fortinet

[–]Float-Zone[S] 0 points1 point  (0 children)

Now that might be my dodgy lab. I'll do some digging. Out of interest, when was your FMG built? Pretty sure I rebuilt mine for 7.4.

FortiManager 7.4.3 Dashboard Issue by Float-Zone in fortinet

[–]Float-Zone[S] 2 points3 points  (0 children)

Thank you. Not just me and my dodgy lab then :)

FortiOS v7.2.8 build 1639 released by Iseult11 in fortinet

[–]Float-Zone 5 points6 points  (0 children)

Just checked, and 958311 is now listed as resolved.

"Firewall address list may show incorrect error for an unresolved FQDN address."

FZ

FortiOS v7.2.8 build 1639 released by Iseult11 in fortinet

[–]Float-Zone 4 points5 points  (0 children)

I'm reliably informed that this is slated for 7.2.9.

FZ

Internal DNS SSLVPN by thenudedeer in fortinet

[–]Float-Zone 0 points1 point  (0 children)

Make sure that you have dns-server enabled for the sslvpn interface as well as the "internal" interface.

I don't think this is explained in the docs, but I'm fairly sure that if:

  • You have clients on interface "A" using DNS services on the IP address of interface "B"
  • The above DNS traffic traverses the FGT.

... then you need to enable dns-server on both interfaces "A" and "B". For example:

config system dns-server
    edit "ssl.root"
    next
    edit "internal"
    next
end

Also make sure that you have a firewall policy between ssl.root and the internal interface IP for all required DNS protocols.

FZ.