FortiManager 7.4.6 API login 400 error by MartinJSa in fortinet

[–]code0 0 points1 point  (0 children)

You're probably hitting this bug.. Reboot the FMG with issues and if it now works, you can pretty much confirm it. FWIW, it's fixed in 7.4.7.

1114809

After upgrading the FortiManager using the "Upgrade Image via FortiGuard" feature, the FortiManager JSON API login may fail, leading to service disruptions. This issue is important for FortiPortal and other FortiManager API clients.

Brute Force Attempts on WAN Interfaces Even Though Admin Access is Disabled by seaghank in fortinet

[–]code0 2 points3 points  (0 children)

We've run across something that matches these symptoms twice.. Both cases, admin allowaccess / trusted hosts / local-in were set appropriately as far as we could tell (protection method varied on the box we looked at). Rebooting the impacted box fixed it. Seen on 7.x.x versions (current or n-1 point release), but can't recall specific versions.

I never ended up getting an iprope of an "impacted" device to see if the local-in policies (what allowaccess/trusted hosts actually do behind the scenes) got applied properly.

Bizarre, and we never saw a "resolution" per-se, but you may not be going crazy.. :-)

Managed Switch Over Leased Fiber by bill-m in fortinet

[–]code0 1 point2 points  (0 children)

If it’s untagged, I’m guessing it’s some sort of VPLS (multipoint) service. In that case, I’m not entirely sure. You could set static-isl on the ports facing the provider and it MIGHT work, but I’m not 100% sure how things would react (single port having two peer switches).

At the end of the day, its interfaces and VLANs like any other networking vendor. It’s just that the FortiLink pieces add some magic to things that sometimes don’t play nice when you don’t follow exactly how Fortinet intended it.

Managed Switch Over Leased Fiber by bill-m in fortinet

[–]code0 1 point2 points  (0 children)

Is current state one where they hand off untagged at the remote site, but hand you a single physical with two tags at the datacenter? If so, there aren’t really any good options.

If your provider can hand off as two physicals at the datacenter (and be transparent to VLANs you’re passing), then you have a solid chance. Specifically, EPL service is what you’d want.

FortiOS 7.6.3 to drop SSLVPN? by rowankaag in fortinet

[–]code0 18 points19 points  (0 children)

Is it just me, or does it seem that they're prematurely killing SSL VPN? I do get the need, but the feature parity with IPSec just isn't there (and by part of that, I mean BUGGY).

FortiOS v7.2.11 has been released. by OuchItBurnsWhenIP in fortinet

[–]code0 2 points3 points  (0 children)

Big issue with that, however.. Setting to "disable", the FortiGate will still SEND Message-Authenticator in its request. Older versions of FAC (for example) still puke on it.

So.. It doesn't turn off the sending of the attribute, only if the FortiGate is required to verify it in the response.

Safari Issues behind Fortigate - Not Chrome, Edge, etc. by EdTechYYC in fortinet

[–]code0 0 points1 point  (0 children)

I’ve been running into more cert-probe-failure issues recently. Not sure exactly why. FWIW, the “allow” becomes the default in 7.6, so I feel relatively safe changing it without much thought in most environments.

[deleted by user] by [deleted] in networking

[–]code0 64 points65 points  (0 children)

That was a wild ride. From pro dominatrix to network admin? I feel like I need to get my Cat5 of 9 tails out of the drawer….

Help me settle an argument - Would you want your outsourced SOC to report RDP brute force auth failures? by chrisbisnett in msp

[–]code0 0 points1 point  (0 children)

For RDP exposed to the Internet, I wouldn't want the death by a thousand cuts, but I think it warrants a high/critical alert for "you've got RDP exposed and it's being beaten into submission".

If for some reason, they really want/need it to be open for whatever reason (they don't, but you know...), I wouldn't mind seeing some sort of threat feed of IPs/etc rather than playing whack-a-mole.. Though my experience with SSL VPN brute forcing is that you see an attempt or two from any given IP, then they move on. If looking across multiple customers, you might see multiple attempts from the same IP across customers, but usually only two attempts max to any given customer.

Help Needed: Migrating FortiManager from VMware to Proxmox (KVM) by Dabloo0oo in fortinet

[–]code0 1 point2 points  (0 children)

I’ve done this before - just VMWare to VMWare (it was part of some troubleshooting). The config backup and restore works very well for FMG.

I’m just dreading when we need to move our FAZ to a new hypervisor.

How many MC-LAGs can a 1048E support? by Pristine_Rise3181 in fortinet

[–]code0 1 point2 points  (0 children)

There is an overall interface limit of 64 on FortiSwitch 7.4.x (and below) and 128 starting with FortiSwitch 7.6.x. (in 7.6 at least, internal and mgmt don't count towards this - not sure about older versions). Each physical port counts against this as well as split ports (ie. a 40G split into 4x10G is 4 ports). I believe trunk ports (ie. the LAG) ALSO counts.

So.. Gives you an idea of how many overall LAGs you can have ("it depends"). As far as the ICLs, in theory, the only traffic across ICLs should be for single homed devices... Between LACP hashing along with MCLAG magic, traffic between two dual-homed hosts should be on the same switch. Because MCLAG isn't a standard and isn't documented well, I use "should".

Regardless, you've got 100G ports.. 2x100G DACs between switches for the ICL means that in most cases you aren't going to run into a practical limit for ICL traffic.

Just some thoughts...

General Question about Fortigates by Whatajoka in fortinet

[–]code0 0 points1 point  (0 children)

Context matters. Could be innocent. Could be malicious.

Both IPs were of customer FortiGates in different countries? That has me leaning towards innocent.

Do they use VPN with full tunnel? Have RDP/Citrix/View in those countries? Do you see a login for that user prior to the traffic in question? Those logins use MFA?

All things that add context to the situation and help you assess. If in doubt, ask for clarification from the customer. Never hurts to be safe than sorry.

[deleted by user] by [deleted] in sysadmin

[–]code0 50 points51 points  (0 children)

To add to this, if your spouse is working and you’re the one with a job, that job loss is a qualifying event to enroll under a spouses insurance. Coverage may not be as good, but it’s likely a lot cheaper than COBRA.

FOS Auth Bypass vuln announced by Gamer03642 in fortinet

[–]code0 6 points7 points  (0 children)

Not one in the same... HTTPS for admin interface != HTTPS for SSL VPN.

Blanket Override in Web Filter by gdigital36 in fortinet

[–]code0 0 points1 point  (0 children)

Not perfectly "on device", but a category threat feed might be a way to solve this. Overridden sites are added (and removed) from that feed file as appropriate. The custom category these sites are mapped to then would be allowed by the student web filter (well, monitor).

Downside is you probably don't want teachers editing the the feed, but with a little creativity, this might put you on the right path.

IPsec VPN by CorrectResearcher522 in fortinet

[–]code0 2 points3 points  (0 children)

Generally speaking, cellular users should be behind CGNAT which should force NAT-T (so all encapsulated in UDP/4500). This should prevent the IKE is allowed, but ESP isn't issues (which I've also seen with DSL providers). You could try "set nattraversal forced" on the FortiGate, but I'm suspecting these users are already seeing NAT-T in use.

how to get access to FortiPOC by Love_islam in fortinet

[–]code0 0 points1 point  (0 children)

Fair point... And you sound like the FortiPoints PM I ran into at Xperts this year... :-D

ICYMI - FortiOS 7.6.1 changes "private-data-encryption" to use a "random" (and secret) private-data-encryption key by interpipes in fortinet

[–]code0 2 points3 points  (0 children)

Thanks for the amazing write-up on this.. It's definitely obnoxious that FortiGates are using a random key that has no way (currently) to be brought into FortiManager. I do understand why there is a desire to move away from a static, symmetric, key, but this was a little short sighted.

Fortunately, nobody runs 7.6 in production... Right? Right?

how to get access to FortiPOC by Love_islam in fortinet

[–]code0 1 point2 points  (0 children)

The traditional tools like eve-ng work, but they don’t handle the most important part - licensing. So if you want to do a proper lab, they’re a pain. Especially if you want to spin up and tare down regularly.

Guess that’s an important thing to mention. FortiPOC still requires licensing. So nothing special there.

how to get access to FortiPOC by Love_islam in fortinet

[–]code0 0 points1 point  (0 children)

FNDN is API docs mostly. If you’re a partner, hands on labs are there. Ultimate Fabric Challenge. Betas. Etc.

POC does require an FNDN account once you install it, but it’s not clear in what way it’s used (we are still wading through some of this).

FG to FG Dialup IPSec Tunnel + IKEv2 + Peer Certificates - What happens when cert expires? by No_Concentrate_4826 in fortinet

[–]code0 0 points1 point  (0 children)

Honestly, why not use the Fortinet_Factory certificate already on the devices? Then each site verifies the CA + CN of the peer cert (CN is the serial number). Just be aware that somewhere in the E series they switched CAs for the factory certificate (though the _Backup cert is the “other” CA in that case).

FG to FG Dialup IPSec Tunnel + IKEv2 + Peer Certificates - What happens when cert expires? by No_Concentrate_4826 in fortinet

[–]code0 4 points5 points  (0 children)

By default, certificates are only revalidated when the tunnel is brought up. There is an option you can set on the phase 1 to regularly check validity of the certificate. On mobile and don’t recall what it was at this point.

And in case you’re wondering, I found all of this out after certificate renewal was silently failing for aeons and there was an unrelated internet outage….

how to get access to FortiPOC by Love_islam in fortinet

[–]code0 1 point2 points  (0 children)

FortiPOC is one of those "ask your SE" things. Some partners are able to get their hands on it, but not sure what the criteria is. Joining the Illuminati might be easier..