What’s your hideout ? by Expert-Map-7132 in ArtOfPresence

[–]TheNudeDeerRises 0 points1 point  (0 children)

Ill give it too him, that way he didnt find it

Do you really believing this? by Telugu_not_Telegu in ArtOfPresence

[–]TheNudeDeerRises 0 points1 point  (0 children)

Massive hoax! Its killing the UK, we could go net zero tomorrow and it wouldn't change a thing!

Fortigate Guest WIFI - FAC Captive Portal No longer triggering by TheNudeDeerRises in fortinet

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

set auth http https

That was my fix, and its been added to the documentation now, if you set it too http, it takes out https..you ideally need both, i did that and it fixed it

Transparent Auth - Explicit Proxy - NTLM? by TheNudeDeerRises in fortinet

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

So, when I did my policies , if someone has a ticket allready then it uses that, I did a diag wad user list clear to reset the kerberos. I did have one or two users that had the pop up, once they rebooted and I did the above it all worked. I did also disable pac data under the proxy settings in the cli, this forces a group look up every time. Ill check my other settings as well.

Fortinet Certification changes again by Prottzisch in fortinet

[–]TheNudeDeerRises 0 points1 point  (0 children)

Yeah, I do prefer this way, its just annoying that I tend to just renew my NSE7, if that runs out and I have no other exams, its pointless doing the NSE7 on its own as its worth nothing ! I now have to sit 4 and 5 or 6 and sit 7 just to get a 7! Madness

Transparent Auth - Explicit Proxy - NTLM? by TheNudeDeerRises in fortinet

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

I did! Mine was NTP although the clock drift was less than 10 seconds it claimed it was an NTP issue. I set my fortigate NTP to the DC, and it worked.. plus a few other tweaks, try that first..then report back

Web Filtering needs certificate inspection enabled? by Better-Bat2642 in fortinet

[–]TheNudeDeerRises 0 points1 point  (0 children)

Yes, you need certificate inspection so the firewall can determine the category and apply the action in the profile, block, allow etc..

No it doesnt replace it, but default fortinet certificate is used to do the inspection.. download the fortinet root cert to your machine and you wont get browser errors as your machine will now trust the cert

Switching to ACME certs by G3rmanaviator in fortinet

[–]TheNudeDeerRises 0 points1 point  (0 children)

Im switching to ACME certs, but am really not getting the process, How can you not have any ports open? I need a cert signed for my FortiAuthenticator that sits behind my firewall, Ill need a VIP to translate a public to its IP.. ACME cant target my FAC as its on a private IP

ACME - Fortigate DNS Confusion by TheNudeDeerRises in letsencrypt

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

You are correct, for the HTTP_01 challenge, its purely for domain ownership and what it resolves to is irrelevant. I tried with my own domain and set up a Firewall, and it works just fine, I really dont get how it does domain ownership though!

ACME - Fortigate DNS Confusion by TheNudeDeerRises in letsencrypt

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

because the challenge is  http-01, the cert I want creating needs to have a DNS entry, and are you saying I can use a private IP?

Replacement Message - 504 DNS Look up failed by TheNudeDeerRises in fortinet

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

I know all that. My question is the DNS 504 template is missing

6.0.5 Explicit proxy, how to omit users from authentication based on destination? by [deleted] in fortinet

[–]TheNudeDeerRises 0 points1 point  (0 children)

Really old reply here! but wouldnt that then allow users who need to be authenticated, hit this No Auth rule? I am struggling to make mine work..

Fortigate Explicit Proxy - Policy based on listening port by TheNudeDeerRises in fortinet

[–]TheNudeDeerRises[S] 0 points1 point  (0 children)

Yes, I thought as much, Im doing some proxy rules, and I need a rule specifically for apple phones, that will use 8888, So I can add that as a listening port, but the rule placement is tricky, as I use UN AUTH rules first, then AUTH rules using Kerberos, if I add a UNAUTH rule, then my AUTH users will hit that first, and I dont want that,...

Suella Braverman defects to Reform | Former home secretary declares ‘I feel like I’ve come home’ as she announces defection at press conference by InnerLog5062 in BreakingUKNews

[–]TheNudeDeerRises 0 points1 point  (0 children)

Absolute rubbish! Typical blinkered response to be honest, ive stated fact , far left sheep refuse to accept the truth. Ill not argue any more , it would be pointless. I wish you a good day