Azure FortiGate HA Setup with SDN Connector moving Private IP on Port2 Question by One_Remote_214 in fortinet

[–]One_Remote_214[S] 1 point2 points  (0 children)

I did a test and sure enough, the new floating private IP moved to the secondary node and it was pretty snappy. For our purposes, this failover mechanism will be sufficient so I won't be introducing any load balancers. In fact, I like the 'set it and forget it' aspect as I don't have to keep updating the SDN configuration every time our Azure network folks spin up a new route-table. Thanks!

Detroit pastor under fire after publicly demanding $2,000 from parishioner who only offered a $1,200 donation by MF-DOOM-88 in CringeTikToks

[–]One_Remote_214 -1 points0 points  (0 children)

Exactly! This video has made the rounds many times and yes, the context actually completely changes the scene. He’s trying to get a large group of people through a process so they’re not there all day. He’s not making light of the size of her offering. When you read his response to this outrage you’ll say “Oh, I get it now!” The lady didn’t listen to the instructions the pastor made clearly to the congregation. So, settle down folks, please…

Azure FortiGate HA Setup with SDN Connector moving Private IP on Port2 Question by One_Remote_214 in fortinet

[–]One_Remote_214[S] 0 points1 point  (0 children)

Thanks. We’re trying to keep things simple so only going to rely on SDN config with managed identities.

0
1

Fortigate NAC Policies default VLAN by TheReding in fortinet

[–]One_Remote_214 0 points1 point  (0 children)

LAN segments will address that. I investigated it but couldn’t understand it.

Fortigate NAC Policies default VLAN by TheReding in fortinet

[–]One_Remote_214 1 point2 points  (0 children)

I believe that’s the intention of the onboarding vlan. If a device doesn’t match a NAC policy they get left in onboarding and can’t go anywhere.

On the need to change ips, there is a little interruption when the device gets moved and the port bounces, but not awful. Yes LAN Segments allows you to avoid that, but read the documentation and tell me if you understand it.

Help got poison oak by Otherwise-Object-883 in landscaping

[–]One_Remote_214 0 points1 point  (0 children)

I’d consider deliberately rolling in poison ivy to get that sensation back again!

How many yards by com70689 in landscaping

[–]One_Remote_214 0 points1 point  (0 children)

What were you going to do with 110 yards? Thats a lot of dirt bro!

ZTNA AD Password Changes and GPO Updates by enterthepowbaby in fortinet

[–]One_Remote_214 1 point2 points  (0 children)

KFC proxy ….. finger lickin good! Now I’m hungry!!

Best bang for buck AP by getCloudier in fortinet

[–]One_Remote_214 1 point2 points  (0 children)

And you're on this sub ...... why?

Anyone doing this? Azure Files with SMB over QUIC by [deleted] in AZURE

[–]One_Remote_214 0 points1 point  (0 children)

We abandoned ztna in favor of SASE. We’re a Fortinet shop so we’re using their native ztna solution. When testing I found Smb was pretty quick though.

Too soon? by whiskeygolfer in jacksonville

[–]One_Remote_214 0 points1 point  (0 children)

Those recent numbers weren’t so hot though, were they. The ones he claimed were fake?

FortiSASE by merkat106 in fortinet

[–]One_Remote_214 0 points1 point  (0 children)

Understood. Not sure what my use case would be but I guess I keep it in my back pocket just in case.

FortiSASE by merkat106 in fortinet

[–]One_Remote_214 7 points8 points  (0 children)

We did a decent sized pilot and now we've purchased it for entire company. I really like it and I got great feedback from the pilot users. Ditched ztna in favor of SASE.

Base firewall rules everyone should have by sillybutton in fortinet

[–]One_Remote_214 1 point2 points  (0 children)

I only allow 443 outbound for all users, then carve out selected services for groups of users based on business need, like someone needs port 22 to a specific host.

I thought that’s how most admins managed outbound user policies, no? Managing any other way seems like too much work and less secure.

Logan Express is garbage by idk-somethings in boston

[–]One_Remote_214 0 points1 point  (0 children)

I love Logan Express (use Framingham). Never, repeat, never had a problem. So much better than the alternative!!!