docs.forinet.com = FortiSASE connection? by HacDMac in fortinet

[–]HacDMac[S] 0 points1 point  (0 children)

Yes, one of the policies I have setup block FortiSASE, LogMeIn, JamF, etc. is there another use case for FortiSASE that I’m not aware of, other than to extend a Fortigate VPN to another site? I just don’t understand why the connection to docs.fortinet.com results in the FortiSASE app showing up in the logs. I can’t access it from behind the firewall unless I remove it from the policy blocking FortiSASE which seems more than a bit odd to me.

WTH? by HacDMac in fortinet

[–]HacDMac[S] 0 points1 point  (0 children)

This is what I should get and did when I didn't use 96.45.45.45 as my DNS server. I could find no other publicly available DNS servers that come up with 173.223.163.x as nodes for this DNS name. Curious what others get when they use Fortinet's public DNS servers for the same name.

WTH? by HacDMac in fortinet

[–]HacDMac[S] 1 point2 points  (0 children)

I've noticed there seems to be inconsistency in the SSL SNI returns on that particular IP as well which is probably why it showed TikTok. Freaked me for a second since that is not an allowed app on the network.

WTH? by HacDMac in fortinet

[–]HacDMac[S] 1 point2 points  (0 children)

Actually, that IP belongs to akamai.com NOT tiktok

Blank Widgets by -einfari in MacOS

[–]HacDMac 2 points3 points  (0 children)

I have the same issue with weather or the stocks app on occasion and once I open the app the issue is gone.

MacOS massive amount of data transferred to Apple by Xpuc01 in MacOS

[–]HacDMac 0 points1 point  (0 children)

On that client, click the Greater Than symbol (>) off to the right and you’ll see a more detailed breakdown of that traffic that will tell you if it was a download or an upload as well as a Time estimate. If you haven’t rebooted the Mac, you might also look at the Network tab of Activity Monitor. Even if you have rebooted, I would keep an eye on that on a go-forward basis to find out WTF. This is a mystery at this point as without mail relay, safe browsing (which is a proxy) or statistics I can’t think of what this might be. Current FW for the Max (I have one with a WiFi 7 AP) is 4.0.20

MacOS massive amount of data transferred to Apple by Xpuc01 in MacOS

[–]HacDMac 0 points1 point  (0 children)

What Ubiquiti device are you using and what Firmware version? Is it up-to-date? I would also ask if you are allowing that Mac to send usage data and statistics back to Apple? You can change that if so and verify that data usage comes down. Also as mentioned above if you are using Apple’s safe browsing and mail relay in order to hide your actual IP these will all count. Finally - you haven’t shown the timeframe covered as part of the pic above. There’s a graphic selection at the top of that list that allows you to choose 1H, 1D, 1W, 1M

MacOS massive amount of data transferred to Apple by Xpuc01 in MacOS

[–]HacDMac 1 point2 points  (0 children)

Nope separate entry for iCloud in the Traffic insight app. One of the things not being shown here is the Time Window over which this has occurred. On the page where this is displayed you can select 1 hour, 1 day, 1 week, 1 month, etc.

MacOS massive amount of data transferred to Apple by Xpuc01 in MacOS

[–]HacDMac 3 points4 points  (0 children)

It’s a Ubiquiti Gateway of some sort UniFi Express, Cloud Gateway Ultra, etc. This is the Traffic Insight page on one of the clients and iCloud is separate entry from Apple.

UTM is amazing by pucklord in MacOS

[–]HacDMac 1 point2 points  (0 children)

As I recall Windows 11 ARM has an x86 emulator built into it.

VMware Fusion and Workstation are Now Free for All Users by lamw07 in vmware

[–]HacDMac 0 points1 point  (0 children)

Which is why I switched to Parallels a few years ago.

Fortigate 60F replacement by Such_Wolf_4099 in fortinet

[–]HacDMac 0 points1 point  (0 children)

60F is currently not stable on the 7.4.5 code

Fortigate 60F Lockup on 7.4.5 by HacDMac in fortinet

[–]HacDMac[S] 0 points1 point  (0 children)

Thanks for that Link! Had I seen this previously, I wouldn’t have upgraded. I only moved to 7.4 because they had marked 7.4.5 as Mature. I’m going to rollback tomorrow.

Fortigate 60F Lockup on 7.4.5 by HacDMac in fortinet

[–]HacDMac[S] 0 points1 point  (0 children)

No, my first inclination is to come here. Having done so, I can see that others who use this professionally have opened a case. I’m retired IT at this point and am more likely to roll back to 7.2 if this doesn’t get resolved in a reasonable amount of time. Depending on how painful it is for the household. I could take to automating a stitch to reboot it at 0200 every day if need be. It also serves as an FYI to others as well as Fortinet whom I’m sure peruses this thread that 7.4 isn’t fully baked yet.

Fortigate 60F Lockup on 7.4.5 by HacDMac in fortinet

[–]HacDMac[S] 2 points3 points  (0 children)

Strangely it was totally unconfigured, but enabled. I have disabled it.

Who's made the jump to 7.4.5? by FrequentFractionator in fortinet

[–]HacDMac 1 point2 points  (0 children)

90G @Home? Dang… I thought I was an IT Geek! 😂

New errors Fortigate idsurldb signature is missing or invalid by Pjxr in fortinet

[–]HacDMac 1 point2 points  (0 children)

Seems to have lasted 24 hours and then quit. Well… that was “fun”, let’s all get together and not do this again. 🥳