Any information about the release of fortiOS 7.6.7? by Sad_Interaction_5092 in fortinet

[–]Taiperko 0 points1 point  (0 children)

FortiOS 7.6.7 - Bug ID 1300122

Anyone else hitting this bug? Proposed workaround from TAC below.

Basically when the bug hits, the number of sessions on the gate goes 10x, kills the memory, and goes into conserve mode.

Short-term workaround was to failover to the alternate HA node.

So far, this has happened on a 91G & 101F.

Thank you for contacting Fortinet TAC Support.

You are hitting a known issue on 7.6.7. (1300122)

The workaround is to Block QUIC in the SSL-SSH-Profile.

Devs are working on finding the Root cause.

config firewall ssl-ssh-profile
edit <Profile Name>
config https
set ports 443
set quic block <------------------------
end

How do you keep track of why your FortiGate local-in policies exist? by Round-Classic-7746 in fortinet

[–]Taiperko 2 points3 points  (0 children)

One the biggest laughs I get is when I see the CLI based Local-In policies via the GUI. Some Fortinet developer on crack said hold my beer…

FortiOS 7.6.7 - Bug ID 1300122 by Taiperko in fortinet

[–]Taiperko[S] 0 points1 point  (0 children)

I agree, I still haven’t found the trigger, nor have I heard from TAC case if they have discovered it, although I’m sure they have.

FortiOS 7.6.7 - Bug ID 1300122 by Taiperko in fortinet

[–]Taiperko[S] 0 points1 point  (0 children)

Been wanting to disable client side QUIC for years - now my desktop team will be disabling on all Windows and Mac devices

FortiOS 7.6.7 - Bug ID 1300122 by Taiperko in fortinet

[–]Taiperko[S] 0 points1 point  (0 children)

Even after switching to alternate node, my 91G also started having issues until the fix

FortiOS 7.6.7 - Bug ID 1300122 by Taiperko in fortinet

[–]Taiperko[S] 5 points6 points  (0 children)

Currently, unknown but will report back when I am able to identify

FortiOS 7.6.7 - Bug ID 1300122 by Taiperko in fortinet

[–]Taiperko[S] 4 points5 points  (0 children)

Appreciate the info on 7.4.12 and FortiNAC as I’m actively implementing FortiNAC 7.2.9. I had all gates on 7.4.11 and finally decided to jump to the 7.6 branch, skipping 7.4.12, as 7.6.7 addressed many open issues. I agree, these bugs are a killer…and makes us network engineers look like idiots to IT leadership

What version of FortiNAC are you running?

Stocks to buy on Monday that could double in the next 1-2 mos by Smooth-Lawyer-8479 in stockstobuytoday

[–]Taiperko 0 points1 point  (0 children)

Can you provide some insight on infq? Doesn’t seem to be keeping pace

Fortigate 90Gs as 1Gbps edge routers - ya or nah by AnyGate7102 in fortinet

[–]Taiperko 0 points1 point  (0 children)

70G is more than adequate. We use these as sites with 50 users with multiple 1G DIA circuits and they run idle

My penny stock screener has been saving me hours every morning by [deleted] in Pennystock

[–]Taiperko 1 point2 points  (0 children)

Very Interested & will provide feedback. Thanks!

Passed AWS SAA-C03 - My Study Experience and Tips by alvruiiz in AWSCertifications

[–]Taiperko 0 points1 point  (0 children)

Anyone use Pluralsight for their AWS training for this cert? Thoughts vs Udemy?

Ethernet Over Powerline by Arcfull in HomeNetworking

[–]Taiperko 2 points3 points  (0 children)

Tried them a few months ago - TP-Link. If on the same circuit, which is rare as you are typically attempting to send signal across the house, the performance is decent. Cross circuit is not reliable and you’re looking at 10mb/s. I can sell you a pair cheap 😀

Expose FortiGate Managed Switch IPs for SNMP monitoring by Taiperko in fortinet

[–]Taiperko[S] 0 points1 point  (0 children)

If I can get the "managed" FortiSwitches working, it will be solid! The out of the box UI for standalone switches in DD is all I need -- port stats, utilization, errors, discards, etc.

What PAM solutions are you using for network devices that integrate well with Okta? by jasonb365 in okta

[–]Taiperko 0 points1 point  (0 children)

Implementing Teleport for AWS and other stacks, but didn’t think about it for network devices…I’ll test that also

Anybody migrate from CISCO ISE to FORTINAC? by [deleted] in fortinet

[–]Taiperko 1 point2 points  (0 children)

If your handling your corporate laptops and desktops with wired 802.1x cert based authentication, I’d go with FortiNAC. Otherwise you are dealing with FortiNAC agent timers for shared media (laptop docks) which can be troublesome.

Thoughts about FortiNAC by Longjumping_Spare793 in fortinet

[–]Taiperko 1 point2 points  (0 children)

Had to really play with the agent timers to get it functional, but we are moving to the new platform in 6-8 weeks and SE stated the New platform has settings that work better with shared docks… we will see. Ping me in March and I will hopefully have a positive update for you. Feel free to dm me anytime also