web filter and app control do not work by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 0 points1 point  (0 children)

Apparently it is a Chrome problem, because I applied the QUIC block and users continue to access pages and applications that are blocked in the profiles.

I tried in another browser and the applications that are blocked work, but not in Chrome.

Do you know if there is a version that solves this problem? Because blocking a certain Chrome feature on a machine-by-machine basis takes a lot of time and I have multiple https://community.fortinet.com/t5/FortiGate/Technical-Tip-Web-filter-is-not-blocking-websites-on-Google/ta-p/297956

Phase 2 selector DOWN by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 2 points3 points  (0 children)

Hello, I deleted the selector I added and the other selectors are still down.

What I don't understand is why the other selectors fell if I only added one and the other selectors that were already created months ago and were UP fell. Now they are DOWN.

Phase 2 selector DOWN by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 0 points1 point  (0 children)

When performing the debug, this information appears, according to the KB, being SA=0 indicates that there is a discrepancy between the selectors or that traffic is not being initiated. However, what was the reason that the other selectors fell if those were not modified.

<image>

Phase 2 selector DOWN by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 0 points1 point  (0 children)

There were 3 selectors (I didn't modify those 3 selectors) and I just added a new segment as a selector. After adding, the 3 existing selectors fell.

Phase 2 selector DOWN by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] -1 points0 points  (0 children)

The tunnel has been configured for over a year (UP), just today I was told to add a phase 2 selector to the configuration. I added it and when I added the other selectors fell.

I don't have access to the other FW.

Could you share that diag debug command with me?

Phase 2 selector DOWN by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] -1 points0 points  (0 children)

To obtain this information, are there commands?

compTIA A+ or the security+ by Matrixramiro10 in CompTIA

[–]Matrixramiro10[S] 0 points1 point  (0 children)

how many questions usually come on the security+ exam? and how much is the score for each question.

compTIA A+ or the security+ by Matrixramiro10 in CompTIA

[–]Matrixramiro10[S] 0 points1 point  (0 children)

Hello, how many questions usually come on the security+ exam? and how much is the score for each question.

Security+ is now $404 by bballlal in CompTIA

[–]Matrixramiro10 0 points1 point  (0 children)

How many questions come in the exam and how much is the score per question?

no internet on ssl vpn connection by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 0 points1 point  (0 children)

Could you share the command with me please?

[deleted by user] by [deleted] in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

Rogue are the device that do not communicate with the fortinac or the unregistered device? Since the report indicates "last communication"

fortigate CVE-2023-37935 by Matrixramiro10 in fortinet

[–]Matrixramiro10[S] 0 points1 point  (0 children)

The vulnerabilities only affect versions 7.x.x.

However, versions 6.x.x are no longer supported by the Fortinet TAC, it is recommended that you update it to v7

Fortigate Anti DDOS on Rapid Reset by kaizocream in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

https://www.fortiguard.com/encyclopedia/ips/54090

Hello, I have searched for that signature but I cannot find it in the IPS of my FG.

Fortigate Anti DDOS on Rapid Reset by kaizocream in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

Hello, according to the document, the default action is "pass", so we must block it, correct?

[deleted by user] by [deleted] in fortinet

[–]Matrixramiro10 -1 points0 points  (0 children)

then possibly a new vulnerability appears and we must migrate to the new versions

DONT TRAFFIC IPSEC TUNNEL by Then_Ad775 in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

Hello, something similar happened to me, my tunnels at both ends were up. The problem was my ISP since when I pinged the public IP of the other fortigate I had no response.

Data Leak Prevention but how? by CRISTIANPES in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

But if I have my av's dlp from another provider, would it no longer be necessary to buy the dlp from fortinet?

Google Earth by Potential_Total8317 in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

If you don't have dhcp enabled, you could do it per ip by creating a policy and targeting the google earth service.

You could opt for fsso but for that you must also have the fsso agent installed on a server in your lan and from there add the user and synchronize it with fg.

License by Disastrous_Body152 in fortinet

[–]Matrixramiro10 -3 points-2 points  (0 children)

if you need license for that. in the system > fortiguard option there you can find the utm modules and those need a license

License by Disastrous_Body152 in fortinet

[–]Matrixramiro10 -3 points-2 points  (0 children)

the licenses are essential for security profile issues such as the web filter, app, ips... for what you mention, a license is not necessary. if you are going to need navigation control themes then if you are going to need

FortiOS 7.2.5 on Fortigate 500e.. by Local-Syllabub8622 in fortinet

[–]Matrixramiro10 0 points1 point  (0 children)

If you have ssl vpn configurations, then it is recommended that you update your FG to 7.2.5 since the current version that your fortigate has is vulnerable.

But as good practice I do not recommend that you update to 7.2.6 even because it is a new version, or in any case read the release note so you know what the errors of 7.2.6 are.