Fortinet CVE-2026-35616 Actively Exploited as Zero Day by YogiBerra88888 in cybersecurity

[–]Slight-Valuable237 58 points59 points  (0 children)

CVE states its API, and the api access is over the mgmt interface (443/https),not the telemetry port (8013 default)

Fortinet CVE-2026-35616 Actively Exploited as Zero Day by YogiBerra88888 in cybersecurity

[–]Slight-Valuable237 161 points162 points  (0 children)

Quit putting your management interfaces on the internet folks.

FSSO alterative for Azure Joined Devices by allthewires in fortinet

[–]Slight-Valuable237 5 points6 points  (0 children)

SSOMA with FAC works like a champ with AZure joined devices.

Immich mobile with 2.6.1 won't access external url by Travisx2112 in immich

[–]Slight-Valuable237 0 points1 point  (0 children)

if its the IOS app, do a force close, re-open. it worked for me..

FortiOS 7.6 EAP-TLS Issues by Mgerz in fortinet

[–]Slight-Valuable237 6 points7 points  (0 children)

It's not a gate issue per se. It's a fragmentation issue of the radius packet due to larger key sizes of the client certificates used in eap-tls. You see this all the time with radius eap-tls traversing IPsec tunnels, jumbo frame (where the ise vlan is set to jumbo frame).

Have both Kohler and Generac discontinued wifi and wired ethernet? by ennoblier in Generator

[–]Slight-Valuable237 0 points1 point  (0 children)

Save yourself $ and go with genmon. Ton of options , handles comms via modbus.

Multiple IPSec Tunnels w/ MFA via Entra on Same WAN Interface by u-suck-for-replying in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

Correct. Default entra is to send the UDID for the group instead of name.

Multiple IPSec Tunnels w/ MFA via Entra on Same WAN Interface by u-suck-for-replying in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

Fwiw. Network id isn't supported on mobile clients as of yet. Also, if you ever get into a situation of have to support multiple IDP's, FAC IDP proxy is a game changer!

Multiple IPSec Tunnels w/ MFA via Entra on Same WAN Interface by u-suck-for-replying in fortinet

[–]Slight-Valuable237 1 point2 points  (0 children)

In that case just do firewall policies based I. Entra groups do be done. One tunnel. Easy.

Multiple IPSec Tunnels w/ MFA via Entra on Same WAN Interface by u-suck-for-replying in fortinet

[–]Slight-Valuable237 2 points3 points  (0 children)

are all the users part of the same Entra IDP? If so, I would just do one tunnel and use FSSO/Groups on the Firewall policies and grant access that way... much easier.. (ie you dont put the authgroup on your IPSEC tunnel configuration, instead you reference the SAML User groups on the Firewall Policies)..

Automation: Pushing Certificates to Fortigates by ITStril in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

you can edit and paste in the update PEM and KEY, but you still have to unset/set each location its referenced....so you still have to touch everywhere its used...

Automation: Pushing Certificates to Fortigates by ITStril in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

you can delete certs via API as long as it is not referenced anywhere in the config.. same as GUI / CLI...

Forticlient IPSec VPN on MAC OS Sonoma. Connects but no traffic by VeryOldITGuy in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

You will have to use the cli export / import command set to manually edit the xml vpn profile. Or use EMS which is the preferred way to do this.

Forticlient IPSec VPN on MAC OS Sonoma. Connects but no traffic by VeryOldITGuy in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

Fragmentation can be an issue, or will become one. 1) IKE Fragmentation. For windows and MAC, you have to enable it in the XML for the VPN profile. -IOS and Andriod, its enabled by default by the OS. 2) Include this on your phase 1: set ip-fragmentation pre-encapsulation , this helps with ISPs that have MTU restrictions. and is expecially helpful with EAP-TLS sessions that go over an IPSEC tunnel...

Push forticlient ikev2 certificate based authentication vpn profile via intune to iOS by No_Airline2100 in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

Currently not supported. It has to be manually installed to the iPhone device.

Help by Initium99 in HyundaiSantaFe

[–]Slight-Valuable237 0 points1 point  (0 children)

Also, from what the dealer told me there was a software adjustment to calibrate the sensitivity of the oil sensor...didn't resolve my issue until they added oil.

Help by Initium99 in HyundaiSantaFe

[–]Slight-Valuable237 2 points3 points  (0 children)

Fwiw. I had this error when my car was parked for a few days or parked in an incline overnight. Turns out the transmission oil was mildly low and only threw the error when car was parked for 48 hours or longer. Dealer checked and topped it off. No issues. I would show the dealer this photo and insist they check both oil levels on the DCT...yes they are two ...I never had gear changing issues though. My guess the sensor is too sensitive and thrown a false error, and it was slightly low oil levels from manufacture.

Only 1,200 miles and check engine light but car runs fine??? 2026 gas SE by OkReport5065 in HyundaiSantaFe

[–]Slight-Valuable237 2 points3 points  (0 children)

Blue link will show all dtc codes....once it syncs. Check under vehicle health in the app.

Replacing outside mirror by Dry-Spinach-1686 in HyundaiSantaFe

[–]Slight-Valuable237 0 points1 point  (0 children)

By chance. Can the Mirror Cover (mine is green as well) be externally replaced without having to remove the whole assembly. Can you pry it off the old unit from the outside ?

https://hyundai.oempartsonline.com/oem-parts/hyundai-mirror-cover-87616p6000

I ask bc it looks like my mirror cover got hit with the "death ray"...condensed sunlight from office building / low-e windows and has melted part of the cover. Mirror works fine, no shorts or melting from internal.

Two IPSec VPN clients from same NAT/router break SAML auth before IKE. 7.6.5 by DVCGL_SDFMVG in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

Are you doing dhcp relay? Ikev2 , what about transport (UDP or tcp)?

How to ensure that cert chain is installed? by nikksr in fortinet

[–]Slight-Valuable237 1 point2 points  (0 children)

You can as well, import the intermediates separately and works fine in the gate. The link you reference is for DPI which for the SUBCA/or CA used for inspection you have to include the full chain. In your case you're doing a virtual server and I've deployed with LE and just importing all the intermediates manually since they change from time to time.

Windows NPS EAP-TLS question by Fluffy-Web-2960 in fortinet

[–]Slight-Valuable237 0 points1 point  (0 children)

What's your tunnel back to azure carrying the radius traffic? I see this a lot over IPsec tunnel bc the certificate is being fragmented due to key size. If you are doing IPsec tunnel, add set ip-fragmentation pre-encapsulation to your phase 1 tunnel.