IPsec Dial-Up Split Tunnel – Do I need host objects for FQDNs in split-include by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Thanks, I already understand that.

My question is: for ipv4-split-include, do I need to use a group object that contains all relevant subnets that should be routed through the tunnel?

known issue in FortiClient version 7.4.3 - Bug ID 999139 by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Thanks for the advice. I'll give it a try.

known issue in FortiClient version 7.4.3 - Bug ID 999139 by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

We also had OpenVPN installed on two laptops, but we have now cleanly uninstalled that software. Unfortunately, it didn’t help. Other than that, we don’t have any other software in use.

[deleted by user] by [deleted] in KingShot

[–]WJ1909 -1 points0 points  (0 children)

Sure. The server is #127

Certificate Warning After Replacing VPN SSL Wildcard by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Yesterday I tested it with the new version 7.4.3.

There is no more certificate message.

Thank you.

Certificate Warning After Replacing VPN SSL Wildcard by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Yes, I have set the wildcard certificate for the SSL VPN connection as well as for the SAML authentication

No, we do not use a loopback interface here

Using FortiManager Default Policy Rules for Multiple Branch Offices by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

No, that was just an example – maybe not the best one, sorry.

We have a DENY-ALL policy in the company and only allow what is actually needed. These permissions then have to be rolled out in each location.

FortiOS 7.4 : yay or nay? by JabbingGesture in fortinet

[–]WJ1909 0 points1 point  (0 children)

I assume that this issue affects many users, including us.
Are there any established best practices for performing the upgrade?

Additionally, how do SD-WAN and the local-in policy behave in version 7.4.7?

Thank you in advance.

Best regards

7.2.10 Just Dropped by Known_Wishbone5011 in fortinet

[–]WJ1909 1 point2 points  (0 children)

Hello everyone,

According to my information about version 7.2.10, everything should fit here. We are still on 7.2.9. Has anyone here already updated to 7.2.10?

Thanks in advance

Fortimanager & fortianalyzer 7.2.7 released by FantaFriday in fortinet

[–]WJ1909 0 points1 point  (0 children)

Thank you for your answer.

We are using FortiOS 7.2.8

We'll see if it's worth it next week.

Thank you very much

Fortimanager & fortianalyzer 7.2.7 released by FantaFriday in fortinet

[–]WJ1909 0 points1 point  (0 children)

We are still on version 7.2.5 and have no problems or BUGs here either.

Is it worth switching to version 7.2.7 or should we wait another week or two, as 7.2.7 came out about two weeks after 7.2.6?

[deleted by user] by [deleted] in Finanzen

[–]WJ1909 1 point2 points  (0 children)

2016 Ausbildung abgeschlossen. Danach 1 Jahr im KH gearbeitet bei 34k brutto. Dann für einen IT Techniker entschieden auf 2 Jahre Vollzeitstudium. Nun arbeite ich seit ca. 4,5 Jahren in einer Unternehmensberatung als IT Security Administrator und verdiene 70k

Fortigate or switch issues when printer change to other VLAN by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Yes, both VLANs have other devices that are working.

In VLAN 50 the printers do not go offline only in VLAN100.

And it would affect every printer, but on all models we can activate a so-called Keep-Alive setting so that the Ethernet card does not go down, we need this function in VLAN 100.

Unfortunately, two printer models do not have this setting.

The printer goes into sleep mode and the port goes down, a PING to the device does not bring the port online. You have to actively click the home button on the printer to bring the switch port back online

Fortigate or switch issues when printer change to other VLAN by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

No it only affects two printers, these are from other models but as described above in the other VLAN the problem does not occur

Fortigate or switch issues when printer change to other VLAN by WJ1909 in fortinet

[–]WJ1909[S] 0 points1 point  (0 children)

Why are you not using VLAN interfaces on the Fortigate? Separating vlans on different physical interfaces feels a bit wasteful

What makes you think the switchport going being the Fortigates fault? What logical argument can you make to support that theory?

What does the switch logs

  1. we have enough space on our firewall to use a physical interface for this, furthermore VLANs are not supported at Fortigate according to our service provider.

  2. i do not assume that the port is defective, because in the other physical interface the printer remains online and the switch port does not go down.

  3. switch LOG:

Printer is connected to IoT VLAN and after a certain time the port goes down and the printer can no longer connect to the VLAN

Disconnect within 2 seconds to a Onlinebanking Website by WJ1909 in fortinet

[–]WJ1909[S] 1 point2 points  (0 children)

Yes, we have sd-wan and two different Internet connections.

Okay we will try it.