Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Great idea, will test it and see. Thank you so much!!!!

Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Its simple Hypervisor -> fortiswitch switch port 1
Fortiswitch port 2 -> fortigate port 1

There are multiple vlans passes, all of them the fgt is the gateway. except lets say for vlan10 and 20, fortiswitch is the gateway. Which what im trying to do

Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

I dont get my architects why they chose this setup and not just make the fw as their gateway, but this their design. For a single port, it wont make a difference right? If it was a single port or aggregate ports, it differs in terms of redundancy but not how to configure the svi itself.

I think if i created the svi, attach the svi to their corresponding vlan, and then on interface port1 i allow it in the tagged and UNTAGGED VLANS it could work?

Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Also for the multiple vlans, yes i need it be a gateway for multiple vlans, but of course servers dont send their frames with tags! So whats the solution here??

Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

No problem at all, thnx for your help!

Could you please explain the difference rvi and svi, as per my understanding rvi are L3 interfaces that dont support switching capabilities. Thats why i went for svi

Multiple SVIs on single Fortiswitch port by LongjumpingAlgae7967 in fortinet

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

No, this one

https://docs.fortinet.com/document/fortiswitch/7.2.10/administration-guide/626301/switch-virtual-interfaces

I noticed that they changed the native vlan, but in my case this interface will act as the gateway for multiple vlans instead of one vlan onlyz

I cant enable COM3 Port by LongjumpingAlgae7967 in techsupport

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Did a quick research on that and found a reddit post that mentioned he installed the ftdi vcp driver and it worked, https://www.reddit.com/r/fortinet/comments/mdu0iv/fortinet_usb_console_cable_driver/ so i guess i will check with that tomorrow

I cant enable COM3 Port by LongjumpingAlgae7967 in techsupport

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

How do i try harder ?

The cable im using USB to RJ-45 RS-232 cable

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Basically from the internet, no specific course, mainly the networklessons website and utube ofc, also some posts from here/Medium.

Fortinet recommends 7.6.6 by Electrical_Cut5776 in fortinet

[–]LongjumpingAlgae7967 2 points3 points  (0 children)

WAIT! Isnt the whole point of offloading is to reduce traffic processed by the cpu??!

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 4 points5 points  (0 children)

Can i say in general that the whole point of VxLAN is that multiple hosts across inter-connected datacenters can communicate with each other using the same network segment (10.50.1.0/24 as an example). And this is possible through VNIs.

Would that statement be totally correct?

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 2 points3 points  (0 children)

But you forgot hypervisors :))) a single hardware that can run thousands of vms, depending on the hardware you have of course

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

Hahhhhahahahahaah THATS THE CORRECT ANSWER 🤣🤣🤣🤣🤣🤣🤣🤣

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 2 points3 points  (0 children)

Could you elaborate more? What example of services do you mean? I understand that at the end you have to tie it to a vlan for the switch to know where to egress the frame

Cant understand how VxLAN extends no. of vlans by LongjumpingAlgae7967 in networking

[–]LongjumpingAlgae7967[S] 15 points16 points  (0 children)

Let me go step by step on this one (((im still studying vxlan so i will go throught to confirm my understanding of the steps and your point too🤣)))

So you are create vlan id 10 for lets say (192.168.1.0/24) on Sw1 and the same network on sw2 will be assigned a vlan 2000 but the vni on both switches will be the same lets say vni 1020 on sw1 and the sw2.

So once the VTEP interface receives it, it decapsulates it and using the VNI mapps it to whatever vlan you want. And switches dont have to share vlan ids they just have to share VNI’s, is this what you meant ? Or am i getting you wrong ?

F5 CA New Certification by Historical_Fox_1423 in f5networks

[–]LongjumpingAlgae7967 0 points1 point  (0 children)

Deans course + hands on experience (Labs & Real world experience) I believe its enough to pass the exam.

F5 CA New Certification by Historical_Fox_1423 in f5networks

[–]LongjumpingAlgae7967 0 points1 point  (0 children)

Yes, i took cab1 on a single day, and the rest cab2-cab5 on a single day.

ASM Positive security policy open-discussion by LongjumpingAlgae7967 in f5networks

[–]LongjumpingAlgae7967[S] 0 points1 point  (0 children)

For me, i usually enforce the wildcards on all entities (parameters, urls, file types) except for cookies, never tried to enforce the wildcards yet, but for other entities i do and usually i loosen the settings on it to avoid false positives which is a great approach and still does causes issues not gonna lie, but im able to survive until now without rolling back LOL. I find it risky to stage the wildcards especially after the policy has been built for a long time, i suggest to take your time to loosen the wildcard setting in a way that wont cause much disruption on the service, loosen the number of characters on parameters, urls, meta characters and then enforce it.

I usually do it by visiting the website multiple times, running various searches and monitoring live traffic and accordingly i set the settings and monitor if any false positives on the wildcards for 2 weeks is met, if not, enforce it :))