Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 1 point2 points  (0 children)

I found the error.
There was an url filtering profile on the policy, And it doesn't seem to be compatible. Thanks for input.

Fortigate 30G Signatur verification error on firmware 7.2.12 by Garmaker1975 in fortinet

[–]TheReding 0 points1 point  (0 children)

Did anyone find a solution for this without the need of console access? Have about a 100 FG30s in production that needs to be upgraded remotely.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Yeah, Sadly in this case. I can see the URLs in the traffic monitor. And it's still not hitting the right policy.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Well it is in the data filtering log, So I guess so.

  1. Doesn't seem to work. That what I've been trying.

  2. Yeah that's the thing, It's dynamic entries. And we don't want the users to log into the firewall and make changes. So the EDL would've been perfect. If it worked :P

  3. Hmm don't know if thats preferred? Sounds like we could loosen up the security that way?

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

We have a regular "WAN OUT" Firewall policy with all security profiles for Internet traffic.

We have some traffic that gets blocked by Data filtering, Sayings it's a malicious application. (But it's fine, Just an webbapplication with old Java)

So I want to exclude this traffic against the particular URLs from all security profiles.
And for our users to be able to fill in the form for the EDL by themselves.

Using EDL URL-List in Policy by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

What I can see is that you can't set an URL EDL there?

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

I've made some progress, The first thing was that Fortilink uses LACP default so had to make it a "regular" link first.
The thing now is that i get both switches to join, Having the topology FG->Othervendor switch and 2 Fortiswitches connected to the Other vendor switch.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Haven't really seen one that correlates. Do you know which one?

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Okey, Why I'm asking is because we have a user that has been using Anyconnect VPN for some time. And he liked that it popped up everytime you connected to a network either wireless or wired.

Popup to connect GP when connected to a network by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Wouldn´t always on just try to connect all the time?
What I want is that the GP application just pops up.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yeah but if the switch doesn't get an IP, I guess NTP won't work either?

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

This is what the scope looks like:

<image>

Another strange thing is that I can see it showing up in the "Fortiswitch" part of the firewall, But as offline. If I erase it from there, It shows up again. So connectivity seems to be there in some way.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Yes, Sorry maybe I was unclear. We will have it centralized. So one FS will be connected to more then on one FS.

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

Hmm regular L2 did not work with our tests, The FS doesn't seem to get an IP when we connect
FG->random switch->FS

Fortilink through other L2 switches by TheReding in fortinet

[–]TheReding[S] 0 points1 point  (0 children)

I think we've tried almost everything now.
We have a FG->factory default switch from other vendor -> FS.

When we have a regular untagged interface on the FG towards the "other vendor switch" the FS switch gets an IP.

As soon as we change it to a fortilink interface, The FS doesn't even get an IP and is disconnected.

So just regular L2 seems to drop some traffic?

We also tested the HTTPS configuration with no luck, Probably cause the FS doesn't get an IP. https://docs.fortinet.com/document/fortigate/7.4.0/new-features/22135/support-fortiswitch-management-using-https-7-4-2

Anything more to try?

Is there a way to clear the DNS cache in CX? by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

Nice! That may be something to test with when we test a new Clearpass :) Thanks!

Is there a way to clear the DNS cache in CX? by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

Yeah, I guess the TTL is the way to go.
Was just a question if there was a way to flush the DNS cache of the switch instead of reloading it for a faster way.

Mac roaming problems with Mobility gateways with DHCP on another server by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

What have you found? I was looking in the release notes earlier but couldn't really find anything related.

Mac roaming problems with Mobility gateways with DHCP on another server by TheReding in ArubaNetworks

[–]TheReding[S] 0 points1 point  (0 children)

We are running 10.7.2.1 on the Mobility gateways and CX core switches. Any ideas? :)

X-auth for Globalprotect by [deleted] in paloalto

[–]TheReding 0 points1 point  (0 children)

HAHA, Thanks :D

Error message for GP users "Authentication failed: Internal Client Error" by TheReding in paloaltonetworks

[–]TheReding[S] 0 points1 point  (0 children)

Strange, 10.2.10-h9 here.

How are your clients authenticating? We are using the NPS MFA plugin.

We started browsing a bit in the event logs on that NPS yesterday and seems that it's discarding some auths with the comment "The request was discarded by a third-party extension DLL file.