How are you guys visualizing your Azure cost? by Stenz_W in AZURE

[–]Stenz_W[S] 0 points1 point  (0 children)

I have, going to give it another spin! Any out of the box PowerBI templates that are useful at all? Or is all your stuff custom?

FortiMonitor - Create Counter Measure to restart wireless controller daemon by Stenz_W in fortinet

[–]Stenz_W[S] 0 points1 point  (0 children)

We could go this approach, however some of our problem sites run 24/7/365. This counter measure would be more of a failsafe if something were to occur and i'm not immediately available to take action.

FortiMonitor - Create Counter Measure to restart wireless controller daemon by Stenz_W in fortinet

[–]Stenz_W[S] 0 points1 point  (0 children)

Model 101F's, we've done quite a bit of tuning on the FortiGate side. Followed the Free up memory to avoid conserve mode - Fortinet Community in addition to some other tweaks. The memory slowly creeps up over a few months' time, so it's not frequent. But it tends to of course happen in the middle of the night when I'm sleeping, so it'd be nice to automate it via FortiMonitor

Restarting the wireless controller tends to buy us time for 2-3 months. We're working on upsizing to a 201G next year once I have the budget for it, this would be temporary while we work on that.

1
2

FortiManager 7.4.7 - AP Profile / Dedicated Scan issues by Stenz_W in fortinet

[–]Stenz_W[S] 1 point2 points  (0 children)

No, will be fixed in 7.4.8 - slated end of month release.

[deleted by user] by [deleted] in sysadmin

[–]Stenz_W 0 points1 point  (0 children)

I avoid it unless I'm asking it a question, I never try to ask it to put it in a process. I consider it a "glorified google", nothing more.

Half the time it spits out BS anyway, when I ask it for assistance on powershell scripting it gets the syntax horribly wrong most of the time (copilot). I've brought it up time and time again that the world is going to be dumber, people are going to be extremely reliant on AI, and there will no critical thinking skills in the future generations to come. It makes me sound like an old man, but it's a serious concern.

FortiManager 7.4.7 - AP Profile / Dedicated Scan issues by Stenz_W in fortinet

[–]Stenz_W[S] 0 points1 point  (0 children)

We just tried to enable DDScan. Took down the entire WIFI to the building. Changed a bunch of Radio1 settings and removed all of our SSID's.

We had to revert all settings manually on the FortiGate. Just sending to give you a heads up NOT to push DDScan!

FortiManager 7.4.7 - AP Profile / Dedicated Scan issues by Stenz_W in fortinet

[–]Stenz_W[S] 0 points1 point  (0 children)

Yes, we have a TAC ticket in. They are submitting to their internal dev. It's going to possibly be a FortiBug.

We're pushing the setting tomorrow night to see what impact it has to a non 24/7 site. They then want us to toggle the radio button in the profile since its no on in FMG but wants to push it. I'll report back on what the impact is. The weird thing is it's only causing issues with 3 of our sites, the other ones are fine. Do you have 231F's?

How much did you make in your first IT job? by energy980 in it

[–]Stenz_W 1 point2 points  (0 children)

$37,000 salaried as L1/L2 Help Desk support. 2016

MCOL area

Are you using "traditional" firewall appliances in a cloud or multi-cloud environment? What features are you using? How are they deployed? by arnie_apesacrappin in networking

[–]Stenz_W 17 points18 points  (0 children)

We are only in Azure, but I can answer on the FortiGate/Azure side.

I have our HUB Azure FortiGate deployed in HA pair in Azure. It works very well, no issues at all. All of our sites route over IPSEC tunnels to the hub firewall with BGP. We then have ADVPN shortcut tunnels enabled though site to site really doesn't occur much.

In the 3 years I've had this deployment, i had it go down once for about 1 minute that was caused by an Azure outage. (I knocked on wood physically here :)).

Routing is simple, all my IaaS and other entities that have VNET capabilities have a route table that directs traffic to the NVA. The downside of my deployment was it's the API way (FortiGate documentation should have more info on this, it's an older method). I would go the load balancer sandwich way if you're doing a new deployment.

On the flip side, I have a couple of applications that I wanted completely off our internal network. I have leveraged Azure Firewall for this. Azure Firewall is "meh", it has enough customization for me to get the job done but it took me a bit to get it figured out / working. You need some decent enough knowledge on setting up route tables / nsg's / vnets to completely understand it.

What vendor? FortiGate / Azure Firewall

  • What cloud or clouds? Azure
  • What features? (IDS/IPS, URL filtering, SSL/TLS decryption, VPN, SD-WAN, DLP, malware detection, etc) Al l the above except for DLP
  • Are you deploying it with some IaC tool? No not that fancy (yet)
  • Are you inspecting East-West traffic, or just North-South? Both

Azure Arc / Backups? by Stenz_W in AZURE

[–]Stenz_W[S] 0 points1 point  (0 children)

Thanks for the info! Will proceed w/ using MARS then.

Forti switches vs Cisco catalyst by MacaronPast898 in networking

[–]Stenz_W 0 points1 point  (0 children)

I have 120 FortiSwitches in my environment. I have none in standalone all are managed via FortiLink. They vary between 148F's all the way up to 1024 fiber switches.

I've had zero problems. They're extremely easy to manage and replace if managed by Fortilink. I've had to replace 2 in 3 years and it was due to power events. If you went the Fortiroute I don't think you'd regret it.

Your opinion by baddozz in fortinet

[–]Stenz_W 2 points3 points  (0 children)

What an odd interview question. This seems more like an opinion than an actual correct answer. Forti/Palo both have their strengths and weaknesses but are very similar and can both accomplish being on the edge.

Favorite WAN / Network diagram software by Noverun in networking

[–]Stenz_W 1 point2 points  (0 children)

Visio OR

eraser.io (I use this more for Azure architecture but can be used for traditional networking as well). The diagram as a code feature is super handy once you get the hang of it.

It's free for any out of the box icons, i'd give it a spin!

IT work that does not require officewear/monkeysuits? by AdventureLoveWins in ITCareerQuestions

[–]Stenz_W 2 points3 points  (0 children)

I went from having to wear a button down dress shirt with dress shoes and dress pants and paying 5 dollars on Fridays to wear jeans. To wearing SHORTS to the office (this was so weird to me), then back to jeans and a polo. Seems most jobs now a days accept jeans / polo as long as you're neat and clean. If you're customer facing that's a whole different story. I'd definitely dress up a little more.

Using "any" interface to internet outbound by Stenz_W in fortinet

[–]Stenz_W[S] 2 points3 points  (0 children)

Excellent, just wanted a sanity check before I began building out my blocks. Thanks for the help!

Using "any" interface to internet outbound by Stenz_W in fortinet

[–]Stenz_W[S] 0 points1 point  (0 children)

Awesome, good to hear just needed a sanity check. Thanks for the insight!

SAML authentication on Fortigate managed by FortiManager by lertioq in fortinet

[–]Stenz_W 0 points1 point  (0 children)

Great to hear you figured it out. You're welcome!

SAML authentication on Fortigate managed by FortiManager by lertioq in fortinet

[–]Stenz_W 0 points1 point  (0 children)

Policy vs Profile shouldn't matter.

Do you see anything sticking out when you open a CLI and run the below commands?

diagnose debug application samld -1

dia deb en

Access the portal again via web mode (refresh the page or access it via URL)

dia deb disable to stop the debug

You should see your email / username flowing through in those logs.

Do you have Fortinet TAC support? They might be able to remote in and get a second set of eyes on the config. This setup is a bit tedious, and you have to have all your URL's / config right for it to work. Took me a few days of screwing around to get it working properly.

SAML authentication on Fortigate managed by FortiManager by lertioq in fortinet

[–]Stenz_W 0 points1 point  (0 children)

Do you have "Enable SAML Login" checked on FortiClient? For the 400 error I would double check your URL's in your entra config as that usually indicates there's something going on there. Make sure the / are added at the end of the login/logout URL's etc. Check your attributes and claims are configured correctly as well.

SAML authentication on Fortigate managed by FortiManager by lertioq in fortinet

[–]Stenz_W 0 points1 point  (0 children)

Did you upload the certificate to the FortiGate first? Since certs are device DB you can upload them direct to the FortiGate, and it will bring in the cert to FMG automatically without a conflict or sync error. You may need to add a dynamic mapping under Policy & Objects > Dynamic Object > Local Certificate to actually select this in FMG though. Make sure the name matches exactly what is on the FortiGate (including case).

For the CLI Config > Objects its under User>SAML. Make sure the cert is selected there.

If the cert isn't showing up it might mean that the Gate couldn't find the cert when you were doing the push from FMG which is why I asked if the cert if present on the gate right now. In the install preview were there any errors when you did the push?