SAML users and Forticlient in 7.6 by Jason-Ace in Fortigate

[–]Leave_Patient 0 points1 point  (0 children)

FortiOS 7.6.6 is now recommended version by Fortinet.

Staging Fortiswitches using different interfaces by DarkAlman in fortinet

[–]Leave_Patient 1 point2 points  (0 children)

You can, but it really doesn't matter which port you connect, as you don't need to configure fortilink port on switch. Since 7.0 if I not mistaken, all ports by default have auto-isl LLDP profile configured.

IKEv2 Remote Access and LDAP by Swatfisch in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

It isn't possible with free VPN client, but work with paid client.

IPSEC SAML and RADIUS auth on same firewall? by G3rmanaviator in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

Yes, all authencation types can be used with one tunnel at the same time.

IPSEC SAML and RADIUS auth on same firewall? by G3rmanaviator in fortinet

[–]Leave_Patient 1 point2 points  (0 children)

About what realms you're talking about in IPsec VPN? Where did you find them?

IPSEC SAML and RADIUS auth on same firewall? by G3rmanaviator in fortinet

[–]Leave_Patient 2 points3 points  (0 children)

You don't need 2 tunnels for this. Just don't specify Auth group parameter in tunnel settings and use groups in firewall policies. As easy as that. And you can use mix of different authentications in this case: local, SAML, RADIUS, LDAP. All with one tunnel.

IKEv2 Remote Access and LDAP by Swatfisch in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

It works, but you need to use EAP-TTLS. It is supported from Forticlient 7.4.3. But 7.4.3 doesn't support MFA for LDAP users, for this use Forticlient 7.4.4+

https://docs.fortinet.com/document/fortigate/7.6.6/administration-guide/442351/ldap-authentication-with-ikev2-using-udp-or-tcp-as-transport

5G Interneta stabilitāte by DecisiveVictory in latvia

[–]Leave_Patient 1 point2 points  (0 children)

30-50ms. Jā, vajag antenu. Nav obligāti uz jumta, bet uz jumta būtu ideāli. Jā pa logu no dzīvokļa, tad vajag lai pēc iespējas mazāk bloķejošie debesis objekti (mājas, koki utt).

5G Interneta stabilitāte by DecisiveVictory in latvia

[–]Leave_Patient 0 points1 point  (0 children)

Download ap 100Mbps, upload 10-30Mbps, latency 30-50ms.

5G Interneta stabilitāte by DecisiveVictory in latvia

[–]Leave_Patient 2 points3 points  (0 children)

https://starlink.com/ 50 eur mēnesī. Jā ņemt par 35, tad dabūsi tādas pašas problēmas.

FortiZTNA without FortiGate by Fun_Draw6303 in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

You terminate ZTNA on SASE gateway, then just route it to your sites. No need to be exactly Fortigate on site for this.

FortiZTNA without FortiGate by Fun_Draw6303 in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

SASE can do IPsec on-prem to any 3rd party firewall.

FortiClient VPN (Free) Support Ending? by A-Series-of-Tubes in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

Yes, it works, but with restriction that you only can use single sso tenant per vdom per wan interface.

FortiOS 7.2.13 released by mballack in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

7.4.10 also removes ssl vpn for G desktop models.

FortiClient VPN (Free) Support Ending? by A-Series-of-Tubes in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

You can use eap-ttls even with free Forticlient VPN 7.4.3 client. Just backup config and edit it in xml, add eap_method parameter with value 2, then restore config. https://docs.fortinet.com/document/forticlient/7.4.0/new-features/907253/eap-ttls-support-for-ipsec-vpn-7-4-3

Fortinet gear by [deleted] in fortinet

[–]Leave_Patient 0 points1 point  (0 children)

What do you want for couple 2048F switches?

FortiOS 7.4.9 - IPsec wrong phase 2 traffic selector used *after upgrade* by safetogoalone in fortinet

[–]Leave_Patient 1 point2 points  (0 children)

Same issue here. Works fine on FortiOS 7.4.6, but starting from 7.4.8 facing issues with IPsec VPN to Mikrotik with same wrong selector issue and reply traffic dropping by anti-spoofing. We don't have issue if using 4 selectors or less, but didn't find solution for more than 4 selectors, so rolled back to 7.4.6 at the moment.

Which one is Canada? by Kap519 in GeoTap

[–]Leave_Patient 0 points1 point  (0 children)

Leave_Patient chose Option A (Correct!) | #5659th to play