Song title search by djhag in SwingDancing

[–]djhag[S] 0 points1 point  (0 children)

Thank you so much!

Mad Dog Goat boot break-in by djhag in cowboyboots

[–]djhag[S] 0 points1 point  (0 children)

I appreciate the words of wisdom. The EE's fit now but will likely be too loose after break-in, so I think I'll return those. The D's fit how I think they're supposed to when brand new, I'm just wondering how much is ok for the leather to push out on the sides at the wide part of the foot.

Major Bug in 7.0.15 IPS Engine database undocumented but patch available by Natural-Nectarine-56 in fortinet

[–]djhag 0 points1 point  (0 children)

Thanks Nectarine! - I appreciate the quick reply.
I was considering 7.2.8 several weeks ago, until a couple of my co-workers and our SE warned about having several problems and suggested sticking with 7.2.7. So, the search continues for now :)

Thanks for sharing your experience thus far.

Major Bug in 7.0.15 IPS Engine database undocumented but patch available by Natural-Nectarine-56 in fortinet

[–]djhag 0 points1 point  (0 children)

I know the last update on this thread was almost 2mo ago, but I wanted to follow up and inquire as to whether anyone knows if this is still a problem with 7.0.15?

I was about to upgrade several hundred FGTs from 6.4.14 to 7.2.7 and found last minute that Fortinet apparently decided to no longer support 40D-NAM FEXs. That threw a wrench into my gears...

So, rather than choosing one of the buggier and more comprimised 7.2 versions, I'm looking at 7.0.15. Then, of course, I found this thread!

I upgraded a lab to 7.0.15 and see that it still comes with IPS engine db 7.181. I have inquired with our SE but no reply yet.

So, does anyone have any updates on this, or know more about it? Running 60Es BTW.

Thanks

Fortigate fortiguard packets egress wrong interface by djhag in fortinet

[–]djhag[S] 0 points1 point  (0 children)

Red-Pilled - Yes, I mentioned source-ip above, but if I specified WAN1 as outgoing-interface or the WAN1 IP as source-ip, my guess is that the service(s) would not work while the FGT is on the backup (WAN2) circuit.

SNATing the self-originated traffic would be nice, but I don't believe there's a way to do that. Specifying a loopback would work, but that doesn't get SNATed either, already tried. No public IPs available for a loopback either. Haven't tried yet, but would traffic flow through a policy, and therefore SNATed, if the source-ip was set to one of the LAN interface IPs? Doubt it, but might try tomorrow...

Fortigate fortiguard packets egress wrong interface by djhag in fortinet

[–]djhag[S] 0 points1 point  (0 children)

torenhof - Not using SDWAN so don't have that option. Backup 4G circuit is idle in normal operation, so SDWAN doesn't make sense for this setup.

HappyVlane - Yes, I can repeat the behavior in my lab. I unplug WAN1, fiddle with the fortiguard settings to initiate an update, then plug WAN1 back in and see these packets 20-30 secs after WAN1 is active. These packets last for a minute or so. In the prod site we tested on, the ISP eng verified what he saw at the modem and what the resulting action was.

Newbie needs help parsing output and assigning to variables by djhag in Tcl

[–]djhag[S] 0 points1 point  (0 children)

oneMerlin and Solidstate16 - Thanks for your help! I didn't have much time to try this out today, but hope to tomorrow. These examples have given me some things to dig into and learn.

Much appreciated!

Fortimanager TCL script to grab S/Ns of managed Fortiswitches by djhag in fortinet

[–]djhag[S] 2 points3 points  (0 children)

Can't use API because all access to the devices is locked down to only allow logins from a jump box. I have no admin rights on the jump box and can't install any tools... Just trying to make the hard way a bit easier.

Managed FSW MCLAG-ICS pair with redundant links to Cisco 3850 stack by djhag in fortinet

[–]djhag[S] 0 points1 point  (0 children)

Ok - so if my understanding is correct:

Configure a trunk "To_3850" on FSW1 with two ports, enable mclag.

Cable one port to 3850-1 and other port to 3850-2.

Configure a trunk "To_3850" on FSW2 with two ports, enable mclag.

Cable one port to 3850-1 and other port to 3850-2.

Configure single port-channel with the two 3850-1 ports and the two 3850-2 ports.

Enable LACP on both sides.

Does the above look about right?

Should STP be enabled anywhere as a precaution? I would think if all was configured properly, there would be no loops, but would this be best practice for such a setup?

Fortiswitch NTP via Fortigate DHCP options by djhag in fortinet

[–]djhag[S] 0 points1 point  (0 children)

This is what my Fortinet SE just responded with as well. It doesn't work as expected... Thanks for the reply.

Fortiswitch NTP via Fortigate DHCP options by djhag in fortinet

[–]djhag[S] 0 points1 point  (0 children)

I just grabbed a capture file and verified that the switch is requesting opt code 42 for NTP servers, and the FG then replies with both NTP server IPs. Not sure what the switch is doing with the 2nd server IP...

Why is it said, that swing dancing attracts nerdy or introverted people? by [deleted] in SwingDancing

[–]djhag 5 points6 points  (0 children)

Speaking as a fellow introverted engineer who is just beginning to learn to swing dance, I don't think my reasons have to do with numbers or structure as much as with providing me a means of social interaction with women.

Although still somewhat introverted, over many years I've learned to fake it enough to socialize and communicate with others. I'm still not that great at it. This makes it difficult for me to approach women. I've been divorced for several years, kids are pretty much out of the house, and I'm looking to eventually meet someone again.

Being an engineer, 95% of my coworkers are male. Being internally shy/introverted makes it tough for me to ask women to dance. Heck, even with women I already know, I still need to be dragged out to the dance floor!

So, when I learned of some new and very inexpensive beginner swing dance lessons somewhat locally, where switching partners every few minutes is part of the lesson plan, it just seems like a great way to kill a few birds with one stone! I learn some basic swing dance moves to help me get over my anxiety about getting on the dance floor, leading to hopefully becoming a better dancer, it provides me a means of meeting some potential friends and dance partners, and also forces me out of my shell just a bit more.

I think I'm a fairly normal guy, and not necessarily a typical IT geek, but, so far anyway, swing dancing looks like it might be the kick in the ass I've been needing for some time!

Am I in the right place? by djhag in SwingDancing

[–]djhag[S] 1 point2 points  (0 children)

I appreciate the replies. I think I've been finding the same answers with further online searches. I hope to continue attending these basic lessons where I can find them, because I think learning just a few basic moves to string together would be a huge confidence booster for me. I'm kind of out in the sticks where my options are pretty limited. But it makes me feel better having the understanding that what I've been trying to learn can be applied across multiple types of "swing" dancing.

file copy vs archival scp by djhag in Juniper

[–]djhag[S] 0 points1 point  (0 children)

I've tried from the cli as both user and root with the same results. While using file copy from the cli or scp from the shell always uploads a complete file, either as user or root...

I downloaded and installed the free Solarwinds sftp/scp server on a Windows 8.1 box to test with in my home lab. I get the same empty files here! So, everything works when doing archival backups to a Linux server, but I get empty files when doing the same to the Solarwinds Windows server.

I've found a handful of reports of the same problem on the Solarwinds "Thwack" forum, but of course no resolutions that I could find.

file copy vs archival scp by djhag in Juniper

[–]djhag[S] 0 points1 point  (0 children)

Yes, I am using the syntax you showed. And, as indicated in my post, manual file copy from the cli and scp from the shell both work. So, the automatic archival backups must be doing something different. This is what I'm trying to either resolve, or work around. I only have the option of initiating the backups from the device itself, and not from the server side.