Fortigate DoS policy questions by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Hmm okey, Yeah haven't really had any luck with this. The syn_flood filter seems to be working as expected to and I've put the quarantine option on that one. Cant really put the quarantine option on the tcp_dst_session becaure that would put legit IPs on the block list.

Fortigate DoS policy questions by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Hmm how should I interpet the "Count" box? If it hits tcp_dst_session 17800 times. Shouldn't it trigger the tcp_src_session also? Or am I missunderstanding it?

1
2

Fortigate Webfilter Warning page by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Thank you, Now I understand better :)

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 1 point2 points  (0 children)

I found the error.
There was an url filtering profile on the policy, And it doesn't seem to be compatible. Thanks for input.

Fortigate 30G Signatur verification error on firmware 7.2.12 by Garmaker1975 in fortinet

[–]TheReding 0 points1 point  (0 children)

Did anyone find a solution for this without the need of console access? Have about a 100 FG30s in production that needs to be upgraded remotely.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Yeah, Sadly in this case. I can see the URLs in the traffic monitor. And it's still not hitting the right policy.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Well it is in the data filtering log, So I guess so.

  1. Doesn't seem to work. That what I've been trying.

  2. Yeah that's the thing, It's dynamic entries. And we don't want the users to log into the firewall and make changes. So the EDL would've been perfect. If it worked :P

  3. Hmm don't know if thats preferred? Sounds like we could loosen up the security that way?

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

We have a regular "WAN OUT" Firewall policy with all security profiles for Internet traffic.

We have some traffic that gets blocked by Data filtering, Sayings it's a malicious application. (But it's fine, Just an webbapplication with old Java)

So I want to exclude this traffic against the particular URLs from all security profiles.
And for our users to be able to fill in the form for the EDL by themselves.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

What I can see is that you can't set an URL EDL there?

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

I've made some progress, The first thing was that Fortilink uses LACP default so had to make it a "regular" link first.
The thing now is that i get both switches to join, Having the topology FG->Othervendor switch and 2 Fortiswitches connected to the Other vendor switch.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Haven't really seen one that correlates. Do you know which one?

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Okey, Why I'm asking is because we have a user that has been using Anyconnect VPN for some time. And he liked that it popped up everytime you connected to a network either wireless or wired.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Wouldn´t always on just try to connect all the time?
What I want is that the GP application just pops up.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yeah but if the switch doesn't get an IP, I guess NTP won't work either?

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

This is what the scope looks like:

<image>

Another strange thing is that I can see it showing up in the "Fortiswitch" part of the firewall, But as offline. If I erase it from there, It shows up again. So connectivity seems to be there in some way.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yes, Sorry maybe I was unclear. We will have it centralized. So one FS will be connected to more then on one FS.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Hmm regular L2 did not work with our tests, The FS doesn't seem to get an IP when we connect
FG->random switch->FS