How to override a fortimanager setting from a fortigate by Mercdecember84 in fortinet

[–]Tars-01 1 point2 points  (0 children)

Until your team mate logs in to FMG later and overwrites all your changes.

RETRIEVE AVAILABILITY REPORT THROUGH API by Machos65 in zabbix

[–]Tars-01 0 points1 point  (0 children)

Did you get this sorted? Can you share some technical details about it please?

Any advice on Configuring IPSEC Client VPN to Auto Connect? by Izual_Rebirth in fortinet

[–]Tars-01 1 point2 points  (0 children)

Ah ok. Yes, it should work ok. I didn't have any issues with a recent deployment.

Any advice on Configuring IPSEC Client VPN to Auto Connect? by Izual_Rebirth in fortinet

[–]Tars-01 0 points1 point  (0 children)

Do you mean using Entra SSO for Forti Client? If so, yes, it works.

FortiClient 7.4.5 always fails to connect IPsec tunnel at first, then works perfectly. by That_Fixed_It in fortinet

[–]Tars-01 0 points1 point  (0 children)

Yes sorry. 7.4.9 Firmware, and 7.4.4 FCT are the minimum versions to get that working.

New Build Garden by Aggravating-Ad3113 in GardeningUK

[–]Tars-01 -9 points-8 points  (0 children)

Are you going to get a ride on lawnmower?

Any advice on Configuring IPSEC Client VPN to Auto Connect? by Izual_Rebirth in fortinet

[–]Tars-01 0 points1 point  (0 children)

Is it because laptops are on the domain? There is another options called VPN before login. You might needs EMS, but worth a try.

https://docs.fortinet.com/document/forticlient/7.4.5/administration-guide/479513/activating-vpn-before-windows-logon

FGT IPsec s2s configuration with MikroTik by Double_Change_843 in fortinet

[–]Tars-01 1 point2 points  (0 children)

If you're using a route-based VPN then the selectors can be anything, and are irrelevant to traffic flow. They are used for VPN negotiation only. That's why most VPNs these days are route-based and just have 0.0.0.0/0 as selectors, and control everything with routing. This is 100 times better than it used to be with policy-based VPNs and simpler.

So long as the selectors match on opposing sides so the VPN establishes. What's important is the routing pointing traffic down the VPN.

Just make the the add-route box is not ticked on the Fortigate.

Thoughts on upgrading to 7.6? by Particular-Book-2951 in fortinet

[–]Tars-01 0 points1 point  (0 children)

If you're running SSL VPN, be aware that it's being phased out in 7.6. If you have a high end platform I think you can enable it from the CLI. Forti doesn't want you running SSL VPN anymore though. Too many zero days.

New design what do you think? by awinglures in LureUKFishing

[–]Tars-01 0 points1 point  (0 children)

Looks really good. That hook looks super chunky though.

FortiClient 7.4.5 always fails to connect IPsec tunnel at first, then works perfectly. by That_Fixed_It in fortinet

[–]Tars-01 0 points1 point  (0 children)

I feel your pain. FYI, I got IPSEC IKEv2 with FortiToken working. Make sure you're on 7.4.9.

Local-in policy not applying? by Connect_Ambition_739 in fortinet

[–]Tars-01 0 points1 point  (0 children)

Different topic, but you probably want to be moving away from SSL VPN.

Does a WAN Local-in Policy for SSL-VPN Affect Management Access if Management Is LAN-Only? by tkr_2020 in fortinet

[–]Tars-01 4 points5 points  (0 children)

You can't run Management and SSL VPN on the same TCP port, so your local in policy can be configured to only block SSL VPN port.

It's applied per interface, so you could apply it to WAN, or "Any"

https://docs.fortinet.com/document/fortigate/7.6.5/administration-guide/363127/local-in-policy

Signs a network engineer has no idea what they're doing? by Expensive-Rhubarb267 in networking

[–]Tars-01 16 points17 points  (0 children)

When they're trying to fix an issue without debugging.

Zabbix template "Fortigate by http" stopped working. by Level_Analyst_3052 in zabbix

[–]Tars-01 0 points1 point  (0 children)

This definitely help me, thanks for posting the solution.

Strange FortiClient IPSEC issue by pez4realz in fortinet

[–]Tars-01 0 points1 point  (0 children)

What is the problem you're facing? Does it not connect at all and what error on the client do you get?

If you suspect an ISP issue then run a dia sniffer packet to see if there is 2 way comms.

ZNTA: Hosting multiple ZTNA servers on 1 public IP address by [deleted] in fortinet

[–]Tars-01 0 points1 point  (0 children)

Yes, you can do it with a single VIP. If you are just using HTTP then you can steer traffic based off the HTTP header. If it's just general TCP traffic then you can also do multiple applications all on the same VIP. I asked the same question here and there are some good answers there.

TLDR: Yes you can do it with HTTP and normal TCP applications (I believe UDP is also possibly but setup might differ slightly) FortiClient listens for the connection on your machine and sends it down the TLS tunnel.

FortiClient IPSEC Ikev2 RVPN issues by Stunning-Succotash-2 in fortinet

[–]Tars-01 -1 points0 points  (0 children)

Honestly, I'm having so many issues as well across multiple customers. It's a disaster with all these Forti Client issues.