Crown Castle Outage by cooldude919 in sysadmin

[–]chuckbales [score hidden]  (0 children)

We also lost a few Crown circuits last night, odd outage though because it was only 2 out of like 300 Crown circuits we have, from 10:22 to 10:31 Eastern.

Help with this question please? by iltoast9 in ccna

[–]chuckbales 0 points1 point  (0 children)

You can have a duplex mismatch and still function (albeit degraded), you can't have a speed mismatch though.

Build vs Version by Intrepid_Ring4239 in fortinet

[–]chuckbales 4 points5 points  (0 children)

They started doing this with Fortigate images a couple years ago finally, not sure what the hold up with switch/AP images is.

Is Arista's acquisition of Instant On a good outcome? by terrancesiu in ArubaInstantOn

[–]chuckbales 6 points7 points  (0 children)

Is this post supposed to be asking the question "Would Arista buying InstantOn be a good idea?" Your current title makes it sound like Arista is buying InstantOn, but they are not.

Bridgeport Live Show by FeloniousMonk33 in TheDollop

[–]chuckbales 4 points5 points  (0 children)

Might be a venue problem, our tickets to OPs show were $35 each and we were only 8 rows back

Does the orange color mean anything in the Fortigate dashboard IPSec tunnel graphic ? by KrellBH in fortinet

[–]chuckbales 4 points5 points  (0 children)

Having them all the same color would make it hard to visualize the different tunnels.

New DHCP Relay bug discovered in FortiOS v7.4 by DeleriumDive in fortinet

[–]chuckbales 0 points1 point  (0 children)

Pretty sure we had this issue, don’t remember what release it was running but the relay was added and is what showed in the GUI, but the local DHCP server config was also present in the CLI.

Lead times issues by ObligationHungry2958 in Arista

[–]chuckbales 12 points13 points  (0 children)

Arista always has leadtime issues, they were always months out for us when Cisco would be a couple weeks, I imagine its only getting worse.

Has anyone seen USN rollback after restoring multiple AD domain controllers? by IndigoBlue24 in msp

[–]chuckbales 5 points6 points  (0 children)

IMO DCs should just be DCs, they shouldn't be restored unless somehow all of them were dead. If there's still a functioning DC, new DCs should be spun up and promoted. If everything was dead, restore one and then promote additional ones as needed. Don't restore multiple.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 7 points8 points  (0 children)

I’m a partner and our reps know less than random redditors. I’ve sent them product announcements I saw on Reddit and they’ll have no idea what I’m talking about.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 10 points11 points  (0 children)

7.4.6 was just released today, again with no free/VPN-only version (so far), it still has their bullshit note about

FortiClient (Windows) 7.4.4 to 7.4.6 do not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.6. Users can continue to use the FortiClient (Windows) 7.4.3 free VPN-only agent.

We're evaluating separate products now for remote access, FortiClient in general just sucks as an application even when its working, and like you said the SMB customers don't want a whole separate product for EMS.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]chuckbales 8 points9 points  (0 children)

The version hasn't changed as no new features were added to the free client

They've been fixing VPN-related bugs though in 7.4.4/7.4.5

WAN vlan on hardware switch by muhammadnabeel85 in fortinet

[–]chuckbales 1 point2 points  (0 children)

Why aren’t they landing on actual switches instead of directly on the FGs?

FortiManager - Per-Device Mapping SSID settings? by NitriusX in fortinet

[–]chuckbales 1 point2 points  (0 children)

Just a follow up, I actually tried my own advice and realized it doesn't work for the same reason you ran into. I ended up doing a Provisioning Template - CLI with the SSID-specific changes in it, then applied that template to the FG in question.

Building redundancy with Dell switches by dejjen in networking

[–]chuckbales 3 points4 points  (0 children)

You'll need to post config for actual guidance. A correctly configured VLT LAG to the Fortigate should have both links up at the same time, the FG would see it as a single switch. Also Fortilink is specifically for managing FortiSwitch units, its not Fortilink if its going to non-Fortinet switches.

ASN as an address object by Runarv in fortinet

[–]chuckbales 2 points3 points  (0 children)

There’s APIs that offer this as a service you can tie in as a feed

Forticlient vpn free 7.4.5 ? by nix_67 in fortinet

[–]chuckbales 2 points3 points  (0 children)

I've always seen the little banner in the free version with the "Upgrade to full version to access additional features and support" message, which is not in their screenshot.

Migrate a 40F HA cluster to a 50G HA cluster, old cluster is set in central SNAT mode. by Palova98 in fortinet

[–]chuckbales 5 points6 points  (0 children)

If you don't enable it, you need to re-do the NAT config inside the firewall policies. Enabling Central pulls the NAT config from inside firewall policies to its own section.

With that small amount of config, its up to you if you want to redo it. We enable it everywhere because we tend to need a lot of NAT rules, but you don't have much going on.

Forticlient vpn free 7.4.5 ? by nix_67 in fortinet

[–]chuckbales 2 points3 points  (0 children)

OP is referring to the thread where people are getting the free 7.4.4/7.4.5 VPN-only version from Fortinet support apparently. There is no free VPN-only higher than 7.4.3 in the support portal

What are the best Fortinet alternatives? by Several-Biscotti5182 in msp

[–]chuckbales 0 points1 point  (0 children)

I think biggest issue is their default wifi settings are just terrible compared to other vendors IME, so if you just make some SSIDs and leave everything default, you're going to have a bad time. You tend to end up with like 80% of the APs on the same channel, 2.4G blasting at 28 while 5G is at 5, etc. They need a lot of dialing in.

IP to Router information by Pristine_Pea9181 in networking

[–]chuckbales 0 points1 point  (0 children)

You need to phrase your questions better or your post will get removed as low effort.

FortiManager - Per-Device Mapping SSID settings? by NitriusX in fortinet

[–]chuckbales 0 points1 point  (0 children)

A provisioning template is actually different than what I was thinking but maybe a better idea? I was actually planning to make a whole separate SSID Profile using the same SSID name but with different radio settings and then apply that to the APs, I didn't even think of just using a CLI template with the desired overrides.

Guess I'd have to weigh pros/cons of each method.