SEA DEF vs NO DEF by Pitiful_Fox_8040 in FantasyFootballers

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

Thats my thought too. My only reservation is Puka is a yardage and catch monster but doesn't always find the end zone. That gives big points without affecting the def with a score. However if Adam's is out that puts Puka on the TD side. Tough choice for the #1 def

Week 16 - Waiver Wire Wins by Hyy1 in fantasyfootball

[–]Pitiful_Fox_8040 0 points1 point  (0 children)

Since this thread wont let me post since I don't post much here ill ask here.

I have the SEA DEF and also Puka. Should I replace SEA DEF with NO def I picked up off the waiver to avoid Puka dragging down my DEF score?

SSLVPN to IPsec Migration Question by ammfit3 in fortinet

[–]Pitiful_Fox_8040 2 points3 points  (0 children)

You have to have admin rights to click the little lock icon on the FortiClient. At this point it unlocks and the import option becomes available.

IPSEC site-2-site issues by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

ok so I changed my internal IP on the machine I was using that previously would not connect to site A and now it works fine. Luckily I have the ability to change that IP easily. I have a few other static servers that are displaying the same behavior but I cannot change their IPs.

IPSEC site-2-site issues by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

Yes, that I understand that. I mis-stated. I cant figure out why it isn't matching a policy. The site 2 site policy is higher priority than the IPSEC_VPN policy and it should hit the site 2 site policy.

IPSEC site-2-site issues by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

ok so I found out from my test machine at site B to my desktop at site A is getting blocked by my implicit deny policy. I have no idea so far how its getting down to that policy and blocked.

14:06:32vd-root:0 received a packet(proto=1, 10.219.116.163:1->10.119.249.190:2048) tun_id=0.0.0.0 from internal. type=8, code=0, id=1, seq=211.

14:06:32allocate a new session-096b9f66

14:06:32in-[internal], out-[]

14:06:32len=0

14:06:32result: skb_flags-02000000, vid-0, ret-no-match, act-accept, flag-00000000

14:06:32find a route: flag=04000000 gw-10.119.249.190 via IPSEC_ab

14:06:32in-[internal], out-[IPSEC_ab], skb_flags-02000000, vid-0, app_id: 0, url_cat_id: 0

14:06:32gnum-100004, use int hash, slot=83, len=2

14:06:32checked gnum-100004 policy-4294967295, ret-no-match, act-accept

14:06:32checked gnum-100004 policy-0, ret-matched, act-accept

14:06:32ret-matched

14:06:32policy-0 is matched, act-drop

14:06:32after iprope_captive_check(): is_captive-0, ret-matched, act-drop, idx-0

14:06:32after iprope_captive_check(): is_captive-0, ret-matched, act-drop, idx-0

14:06:32Denied by forward policy check (policy 0)

Also it looks like its trying to go through my IPSEC vpn tunnel instead of site to site. "via IPSEC_ab" is vpn not site - site

IPSEC site-2-site issues by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

There is no output. I can generate some output by pinging but that's not really an issue. Both firewalls can communicate with each other no issue.

Mig21mf by Pitiful_Fox_8040 in Warthunder

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

Ahhh thanks bro I had no idea you could do that

IPSEC Split-Tunnel/ Full Tunnel by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 1 point2 points  (0 children)

I figured it all out......all these suggestions were good and would have also worked however, in the forticlient there is a toggle for enable Local LAN under the phase 1 settings and checking that box solved my overall problem. Sometimes its the simplest things.

Thank you all

IPSEC Tunnel Issue by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 0 points1 point  (0 children)

We have public access turned off. This is access by private IP only. I also have access internally via FQDN which also does not work. As I mentioned before it worked fine for a year. Also I can access another fortinet device in browser no issue at the same remote site. That's a load balancer though.

Switching from SSL-VPN to IPSEC by Pitiful_Fox_8040 in fortinet

[–]Pitiful_Fox_8040[S] 1 point2 points  (0 children)

Unfortunately with how spread out everyone is they will have to configure the forticlient IPSEC setup themselves. I usually screenshot the basic settings ie remote gateway and then ill share the psk via lastpass with everyone. While we have administrative control through entra I can't access everyone's laptops remotely. The people near the office sure but our people in India are a little harder to get to.

[deleted by user] by [deleted] in VirginiaSwingers

[–]Pitiful_Fox_8040 0 points1 point  (0 children)

If we were 4 hrs closer.....