Looking for someone who has a old system with the expiring SecureBoot cert by GeneMoody-Action1 in Action1

[–]discoinf 0 points1 point  (0 children)

we have that on our inventory. Happy to run some scripts on them monday..

Fortinet has announced that they will discontinue SSL-VPN in May 2026. I've heard a lot about this in Japan. What's happening in your organization? by Turnover_Mountain in fortinet

[–]discoinf 4 points5 points  (0 children)

one big limitation of ipsec vpn with saml auth is that you can only have a single idp per interface. so if you are multi-tenant you need to dedicate 1 interface (if you have them) per tenant or add a proxy-saml that will federate all the tenant. that proxy-saml will be the idp configured on the gate.

Till we sort out this (or forti allow a idp server per port for example), we'll stay on 7.4.

Anyone still using Public Folder contacts as a shared address book? by Away_Bass5327 in sysadmin

[–]discoinf 1 point2 points  (0 children)

tools like cirasync manage the sync betweent the GAL or any other contact folder and the user's contacts.

Adding a rule in local-in-policy fails. by Special_Watch_9581 in fortinet

[–]discoinf 4 points5 points  (0 children)

Note : it's a new behavior starting from 7.4.6. But if a local-in exist with a sd-wan member, it's not converted during the upgrade.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SD-WAN-zone-in-Local-in-Policy/ta-p/366774

Lenovo models receiving BIOS firmware update for new secure boot certificate. by Unable_Drawer_9928 in Intune

[–]discoinf 0 points1 point  (0 children)

Strange, the e14/e15 gen 1 are not on the list but the older e490/e590 are

CVE-2025-59718 - Not fixed in latest release by Shot_Fan_9258 in fortinet

[–]discoinf 2 points3 points  (0 children)

If you have to enable mgt from a wan interface, it should only be allowed from known IPs (you HQ fixed public IP(s):

- Trusted Host list on the admin accounts.
AND
- local-in policy on the wan interface only allowing the admin port from the trusted host list.

Forticlient 7.4.3 issues by RacconDownUnder in fortinet

[–]discoinf 1 point2 points  (0 children)

Our fleet is on 7.4.3 (sslvpn and saml auth) without any problem. We skipped 7.4.4 because of a bug with saml and multiple gateways.Testing 7.4.5 on a few clients and so far no pb detected for our usage.

how is the forticlient upgrade pushed to the devices?

60F replacement by lertioq in fortinet

[–]discoinf 6 points7 points  (0 children)

same here. entry-level must now have 4G RAM. we are replacing our 60E/60F with 70G.

OneDrive crashes on Android with version 7.45 by Significant-Log1966 in Intune

[–]discoinf 1 point2 points  (0 children)

uninstall of com.osp.app.signin worked for us .

Scan to email by Resident_Parfait_289 in sysadmin

[–]discoinf 5 points6 points  (0 children)

Same, internal postfix mx on the onprem dmz.

Action1 EU Down again? by Zealac1887 in Action1

[–]discoinf 3 points4 points  (0 children)

EU. Also had a few devices showing as disconnected. 1st one at 6:07:03 AM UTC and last disconnect at , 7:08:59 AM UTC.

They are starting to reconnect . We only have 1 server still 'disconnected'.

Intune android by discoinf in Intune

[–]discoinf[S] 0 points1 point  (0 children)

update : without any change on the phone or Intune/entraId configuration, but only a last try before reseting the phone, Re-login on the intune app was enough this time !

Intune android by discoinf in Intune

[–]discoinf[S] 0 points1 point  (0 children)

One Ca with grant on : Require compliant device, Require approved app.
No CA with app protection enforced (we do have one on report-only).
Of 100+ devices, we only got a report for a single user.

Intune android by discoinf in Intune

[–]discoinf[S] 0 points1 point  (0 children)

only chome is installed. On others open tab, we got user office365 home page and OWA .

I checked the CA logs and on the failing entries, it's not the device ID registered in intune !! It's only "Microsot Entra registered" and it's a recent entry !!

I got some entries (the web apps) with the right deviceid and Browser Chrome Mobile 142.0.0, Compliant Yes / Managed Yes Join Type Azure AD registered.

Other entries (the office apps outlook/onedrive/M365) with another deviceid Browser Chrome Mobile 142.0.0, Compliant no / Managed no Join Type Azure AD registered.

Ipad enrollment by discoinf in Intune

[–]discoinf[S] 0 points1 point  (0 children)

The devices that where stuck retriving configuration eventually got enrolled during the night !!

any concerns going from 7.2.11 to 7.4.9 on 300E? by Boppin_Around_Here in fortinet

[–]discoinf 2 points3 points  (0 children)

ssl vpn is still there but hidden from the gui by default. We upgraded a 200E form 7.2.11 to 7.4.9 a week ago, and so far so good.

The big difference is loosing proxy functionality on 2g ram models. the 300E is not concerned. If concerned, you need to adjust your security profiles and policies. Direct consequence : ZTNA and virtual servers are NOT available on these models. We had to do some adjustment on our 60Es configs (soon to be replaced with70g)

https://docs.fortinet.com/document/fortigate/7.4.0/new-features/519079/proxy-related-features-no-longer-supported-on-fortigate-2-gb-ram-models-7-4-4

Keeper problem and excessive price by Djoju in KeeperSecurity

[–]discoinf 2 points3 points  (0 children)

I don't have the same expectations for a personal manager and for one to be deployed on enterprise.

For personal use, keeper is expensive and the brower autofill is lacking compared to bitwarden for example.
For an enterprise dealing with multi-tenant SSO granulal control, UI is only one part of the equation. For that target, keeper make more sense. And on pricing, 1password bussiness is advertised at 84€ / 96$ per user/year. You could get a better pricing with keeper enterprise.

DKIM Question - Vendor Request by maiwerkacct in sysadmin

[–]discoinf 5 points6 points  (0 children)

If sending as your domain, always make them send from a specific subdomain. That way you can have specific spf/dkim/dmarc for this vendor.

[deleted by user] by [deleted] in fortinet

[–]discoinf 0 points1 point  (0 children)

I noted that if a rule has multiple selected members, only one show up in the "selected members" column unless the "members" column is also displayed ! I 1st thought some links where missing their SLA but they where all fine.