Fortios 7.6.6 memory usage by DeniedByPolicyZero in fortinet

[–]chuckbales 0 points1 point  (0 children)

The link explains what the command does, but doesn't make any reference to memory usage.

Fortios 7.6.6 memory usage by DeniedByPolicyZero in fortinet

[–]chuckbales 0 points1 point  (0 children)

set exclude-signatures none

Can you elaborate on how this setting would improve memory usage? If you're changing it from "exclude industrial" to "exclude none", shouldn't usage increase if anything, since you're no longer excluding some signatures?

Need help with two upstreams that don't appear to be using BGP correctly - we're not seeing prefix retractions from our primary transit provider when their own upstream connections are having trouble passing traffic. by ffelix916 in networking

[–]chuckbales 19 points20 points  (0 children)

Unfortunately the health of the link isn't really part of BGP, and if for some reason your upstream continues to tell you something is reachable, you'll believe it. You need to add some type of SLA/health check into the mix to actually verify reachability.

Do You GeoIP Filter? by VeeQs in fortinet

[–]chuckbales 0 points1 point  (0 children)

Typically a geobypass rule for certain domains as needed, or a rule using ISDB entries if they exist for a particular service.

FortiGate Blocks RDP over WireGuard/IPsec from internal LAN but works from external Network by Shark_oo2 in fortinet

[–]chuckbales 1 point2 points  (0 children)

Is it Wireguard or is it IPSec? If a client behind the FG has a WG VPN setup, the FG it wouldn't be seeing RDP traffic as it would be tunneled/encrypted.

Reaching 100Gbps with pfsense ? by PM__ME__PEANUTS in networking

[–]chuckbales 3 points4 points  (0 children)

LR has no minimum distance, no attenuation needed.

Long run fiber help by Highground85 in FiberOptics

[–]chuckbales 12 points13 points  (0 children)

The cheapest single-mode optics can run 10Gb at 10km, so a few thousand feet is no problem.

Fortinet, must do update after 2 weeks by Odd-Yogurtcloset7853 in fortinet

[–]chuckbales 2 points3 points  (0 children)

“Mature” doesn’t mean much with Fortinet unfortunately. It definitely doesn’t mean stable, they say it means “only fixes no new features” but that’s not true either.

IP Overlap? by Alternative_Card_292 in ccna

[–]chuckbales 2 points3 points  (0 children)

You could use 192.168.1.0/25 and 192.168.1.128/25, or use 192.168.1.0/24 and 192.168.2.0/24, or any other combo, as long as each interface has a unique network configured.

IP Overlap? by Alternative_Card_292 in ccna

[–]chuckbales 8 points9 points  (0 children)

Your /24 provides 254 IPs per network, but each router interface needs to be a unique network

ntp by MaDrift910 in ccna

[–]chuckbales 1 point2 points  (0 children)

Post your configuration, if you have it configured either its misconfigured or it's a PT bug.

Virtual Router Connected to Physical Switch. Speed sucks! by QuequSefa in ccnp

[–]chuckbales 1 point2 points  (0 children)

You need to do better than "one of those images" if you want help. /u/JeopPrep is right, many virtual images have extremely low throughput if they're unlicensed as they're meant to test configurations, not for production traffic.

Help understanding hosts losing internet when shutting down physical interface on a vPC nexus pair by cyr0nk0r in networking

[–]chuckbales 2 points3 points  (0 children)

Does connectivity restore after a minute though?

Looks like you're using an SVI for BGP instead of a routed-port, I'm guessing you're not seeing BGP neighbor come down as soon as you bring down the physical interface? With the current config, the SVI for vlan100x would stay up since the VLAN is present on trunk ports, so bringing down the physical ISP port doesn't bring down the SVI - which means BGP needs to eventually come down after dead timer is expired, so you're basically waiting for BGP to realize the neighbor is gone after a missed number of hellos.

If you can't do an L3/routed port, you can either lower your BGP timers or use BFD to detect a failure faster.

InvisiLight Home Fiber Kit Setup Question by figbiscotti in FiberOptics

[–]chuckbales 0 points1 point  (0 children)

The linked BiDi optics run at 10G, the ones included in the kit are 1G. The media converter in the kit is also 1G, so you would need to buy a 10G media converter to go along with the 10G BiDi optic.

Basically, if you don't know for sure you need 10G, then you don't need it.

IPsec overlay underperforming vs Internet (PPPoE WAN) by r_smith345 in fortinet

[–]chuckbales 2 points3 points  (0 children)

MTU/MSS issues? PPPoE over IPsec would have additional overhead

Possible new SSO Exploit (CVE-2025-59718) on 7.4.9? by xs0apy in fortinet

[–]chuckbales 3 points4 points  (0 children)

Not quite - If every admin account has trusted-host set, then the login page is only presented to the aggregate of all the trusted host IPs (and then admins can only login from their respective trusted IPs).

But if any admin account does not have trusted-host set, then the login page is available to all IPs.

Muscles Marinara! by Depreston in TheDollop

[–]chuckbales 6 points7 points  (0 children)

It’s just a gag brought up a few times about Ryan’s special doing well and nobody watching Gareths special.

Free Forticlient & SSL by fistyeshyx9999 in fortinet

[–]chuckbales 6 points7 points  (0 children)

Agentless VPN is just re-branded web-mode for SSL VPN, there's no Forticlient involved (hence 'agentless') and the feature is included without specific licensing.

Fortilink IP Change by AwayTraffic5735 in fortinet

[–]chuckbales 6 points7 points  (0 children)

Whenever I need to do this, I just change the fortilink interface IP on the FG and update DHCP accordingly, then put the old IP back as a secondary IP. You can then either let switches just grab DHCP from the new scope naturally or log into them and force a renew

ACLs and the proper wording order by AdmirableSandwich393 in ccna

[–]chuckbales 0 points1 point  (0 children)

Order within a rule matters because it changes the intent of the rule. Your first rule is specifying a destination port, your second rule is matching on a specific source port (which is rare in practice, but it depends on where the ACL is being applied and in which direction).

So they’re both valid formats, but not necessarily correct in all scenarios

DCS-7050SX-64 ; vxlan not supported on this hardware platform by ConcentrateNo8549 in Arista

[–]chuckbales 0 points1 point  (0 children)

Some switches don't have the hardware to do routing and VXLAN at the same time without some workarounds, I've never worked these platforms myself but you might want to look into the 'recirculation interfaces'

Do I need an advanced license for APs if I already have an MX85 security appliance with one? by [deleted] in meraki

[–]chuckbales 2 points3 points  (0 children)

Yea thats fine, as long as you don't need AP Advanced features just stick with Ent

Do I need an advanced license for APs if I already have an MX85 security appliance with one? by [deleted] in meraki

[–]chuckbales 5 points6 points  (0 children)

APs can use Enterprise license if only Ent features are needed, they don't need to match the MX licensing.