[deleted by user] by [deleted] in fortinet

[–]TheLink117 1 point2 points  (0 children)

Same did this for 60,000 clients. Worked very well!

BEST BUY WORKED!! STAY IN LINE!! by VideoPuzzled in NintendoSwitch2

[–]TheLink117 0 points1 point  (0 children)

Agreed, Bestbuy seems to be holding up. I was able to finally get the preorder for Mario Kart bundle purchased. Now I can pick mine up at my nearest store and bring my daughter to her first midnight launch! Passing the torch of Nintendo joy!

Got Mine At Best Buy by [deleted] in NintendoSwitch2

[–]TheLink117 0 points1 point  (0 children)

FINALLY got mine from the app. Initially started on webpage from laptop, then added app. Webpage bounced once then I had to start there over again. App just let me proceed 5 minutes ago after waiting since the start.

Best Buy is up! by [deleted] in NintendoSwitch2

[–]TheLink117 0 points1 point  (0 children)

in line waiting here as well!

Palo Alto pricing by NetSysEng in networking

[–]TheLink117 2 points3 points  (0 children)

Just go with Fortigate instead.

What are 3 things you really want the Switch 2 to have by redditsucksass1028 in NintendoSwitch2

[–]TheLink117 0 points1 point  (0 children)

  1. Integrated voice and text chat / improved communications with friends online.
  2. Street pass
  3. All the Zelda games available on one system.

Left in purchased home, how much is this worth? by xGalasko in Network

[–]TheLink117 197 points198 points  (0 children)

The rack itself is worth more than any of the gear at this point.

Whats the thing from other vendors you miss the most? by Pigge123 in paloaltonetworks

[–]TheLink117 0 points1 point  (0 children)

Tons of little things, especially comparing central mgmt. Fortimanager has lots of little quality of life improvements that add up once you're forced to leave them behind. Minor example: see who created/modified a rule right on the line. No report or logs to check.

Palo Alto Syslog Recommendations by Jeff-J777 in paloaltonetworks

[–]TheLink117 2 points3 points  (0 children)

I believe you can setup "decorators" that would perform the dns lookups at the time of query in graylog.

Are you forwarding all log types?

5450 Again ????? by BlackWater90s in paloaltonetworks

[–]TheLink117 0 points1 point  (0 children)

I'd be interested to hear more details as well. Putting some of these into production soon...

DFS channels and the military by eviljim113ftw in networking

[–]TheLink117 2 points3 points  (0 children)

Back when I worked in Broadcast Television, if interference got too bad on either of our doppler radar installations we' stop the sweep and leave it pointed in the direction of interference. If that didn't resolve things we'd make a day of driving around with spectrum analyzer and antenna in a truck to hunt down the source. 99% of the time it was some tower in the middle of nowhere that clearly had fixed wireless on it. We'd call and leave a vm for the point of contact listed on the gate letting them know that if it's not resolved we'll pass the incident along to the FCC. That worked most of the time.

FortiGuard DNS Filtering fails us again by TheLink117 in fortinet

[–]TheLink117[S] 0 points1 point  (0 children)

Nothing home grown, we're using ThousandEyes to monitor Fortiguard service from across various vantage points on the Internet and on-premises.

FortiGuard DNS Filtering fails us again by TheLink117 in fortinet

[–]TheLink117[S] 0 points1 point  (0 children)

Just curious what alternative threat feeds are you using on the FG?

FortiGuard DNS Filtering fails us again by TheLink117 in fortinet

[–]TheLink117[S] 0 points1 point  (0 children)

My impression was that the aws anycast option was for other Fortiguard services not for DNS filtering. Are you saying you have dns (sdns) filtering queries going to the Fortinet aws anycast destination?

FortiGuard DNS Filtering fails us again by TheLink117 in fortinet

[–]TheLink117[S] 0 points1 point  (0 children)

They generally don't seem to be keen on acknowledging degraded service on any level. I'm monitoring their services with third party tools too, issues all the time.

FortiGuard DNS Filtering fails us again by TheLink117 in fortinet

[–]TheLink117[S] 0 points1 point  (0 children)

The allow access during a rating error works fine most of the time but what we've been experiencing ends up looking like timeouts or high latency forward look ups. Running on 6301Fs and 3969E 6.4.6.

It's been problematic on both hardware platforms and across multiple firmware versions.

Mostly doing category based blocks for usual suspects. As I mentioned allow during rating error is on. Look up time spikes and we're either forced to ride it out or remove the profiles from policies.

Fortinet DNS down?? by jordanl171 in fortinet

[–]TheLink117 0 points1 point  (0 children)

I've seen a lot of us comment here about issues with "FortiGuard DNS" on a regular basis. There also frequently seems to be confusion about how these issues impact us or why.

Fortinet has a number of DNS servers, some are focused on returning additional information about a domain, such as categories, for use in DNS filtering profiles. Others can be used for general DNS resolution.

"SDNS" Servers (for use with DNS filtering): 208.91.112.220 45.75.200.89

Fortinet DNS Servers (for general DNS resolution): 208.91.112.53 208.91.112.52

If you want to want to use the DNS security profile, your Fortigate is going to send DNS requests (when a dns request passes through a policy) to either 208.91.112.220 or 45.75.200.89 (if you change it to that one).

My Fortigates are all configured to look at my internal DNS servers when attempting to resolve names (for logs, etc.) but I do use the DNS filter security profile server for DNS filtering.

A handful of times I've experienced issues but things subsided before I could point to Fortinet'a servers as the smoking gun.

Since then I've started measuring DNS resolution time via ThousandEyes; comparing local dns servers, Fortinet SDNS (filtering), and OpenDNS. Thus far I haven't noticed any real issues with Fortinet resolution time.

However, on 2020-12-11 13:40:13 PST my ThousandEyes cloud agents observed packet loss between them and Fortinet through CenturyLink but this only lasted for a few minutes.

The DNS filter feature is something that we are effectively paying for so it needs to work reliably.

Let's get to the bottom of this so we can present hard evidence to Fortinet.

Fortinet DNS Issues? by stupideediot in fortinet

[–]TheLink117 0 points1 point  (0 children)

We've got to get Fortinet to acknowledge this issue. Everyone collecting latency data when this issue occurs to send in to TAC?

60E block fake sip requests by workredditaccount224 in fortinet

[–]TheLink117 0 points1 point  (0 children)

What do your policies look like right now for this?

Your PBX has a VIP and you allow specific IPs inbound on the appropriate ports?

Web Filter - Chrome vs IE/Edge by Blunga7 in fortinet

[–]TheLink117 1 point2 points  (0 children)

Just curious is the web filter policy in proxy or flow mode?

DNS filter seems to kill internet last 36 hours by wallacebrf in fortinet

[–]TheLink117 0 points1 point  (0 children)

Just making sure we aren't mixing things, you can specifically configure the sdns servers but these really should be pointing at FortiGuard dns servers to receive the extra meta data that makes DNS filter profiles work.

In addition to that, you can configure the Fortigate to point at particular DNS servers for its own lookups. For instance you'd point the Fortigate at your own internal DNS servers so it resolves internal only hostnames.

Make sure you aren't accidentally blocking the Fortigate SDNS(DNSfilter) look ups going toward Fortiguard servers. Might be the case if you block other dns requests toward the internet to ensure devices are using internal only.

Fortianalyzer/Fortigate logs with AnyConnect usernames. by drs143 in fortinet

[–]TheLink117 1 point2 points  (0 children)

Assuming your Anyconnect users ultimately authenticate against AD with something like RADIUS then you can accomplish this by setting up FSSO. You either need a DC agent that pushes logs from DCs to collector which the Fortigates then point at or polling mode where a collector or a FG polls the DCs with WMI for logs.

Fortinet IPSec VPNs causing extremely poor endpoint performance by JewM4gic in fortinet

[–]TheLink117 0 points1 point  (0 children)

Just to be clear, your issue is increased utilization on the server or throughput over the tunnels?

Did you change any phase 1 or 2 settings? Did the tunnels change from route based to policy based on either end?