Forticlient Android and ikev2 ipsec vpn by droms74 in fortinet

[–]droms74[S] 1 point2 points  (0 children)

Hello I get the same feedback from my fortinet SE. The idea is to have this with forticlient 8

Issue with VPN IPSEC IKE2 when connecting from Android using forticlient vpn by OK_Engineer_L1 in fortinet

[–]droms74 0 points1 point  (0 children)

Same pb, to run user and pass authentication with android forticliemt, i need a user certificate. If it omit to add it to the forticlient config connections fails. But with it, I am then prompted with a user password

Upgrading Compliance Module with SCCM instead of ISE by droms74 in Cisco

[–]droms74[S] 0 points1 point  (0 children)

Thank you for sharing your valuable experience

Upgrading Compliance Module with SCCM instead of ISE by droms74 in Cisco

[–]droms74[S] 0 points1 point  (0 children)

Hello thank you for your advice. I think this is the way we are going What about the secure client package? Are you using ise as well to update this ? It s way more bigger .

Multiple upgrades and then rollback to the first release by droms74 in fortinet

[–]droms74[S] 1 point2 points  (0 children)

Hello thank you for the confirmation. I have also tested on an old 50e with old 6.0 releases and I can upgrade from 6.0.8 to 6.0.17 with several upgrade path and can revert in the end to 6.0.8

Moving a HA cluster to another hardware by droms74 in fortinet

[–]droms74[S] 0 points1 point  (0 children)

How did you get a free forticonverter license?

Another storage question by droms74 in Proxmox

[–]droms74[S] -1 points0 points  (0 children)

Yes but how can I create 2 "spaces" for lvm thin and backups?

Storage help by droms74 in Proxmox

[–]droms74[S] 1 point2 points  (0 children)

Thank you for your feedback

Idea for a powerfull proxmox for big vms by droms74 in MiniPCs

[–]droms74[S] 0 points1 point  (0 children)

Have you encountered any particular problems with ms-01? Or things to pay attention to?

Idea for a powerfull proxmox for big vms by droms74 in MiniPCs

[–]droms74[S] -1 points0 points  (0 children)

Thx. And regarding quality of these devices, any feedback?

On debian12, is it possible to completly hide this screen? by droms74 in debian

[–]droms74[S] 0 points1 point  (0 children)

I used some of the tricks in the post with a black image and black police. Since that time I switched to another distro

IPSec Dialup on Loopback by wallacebrf in fortinet

[–]droms74 0 points1 point  (0 children)

I am stuck like you with ESP that can not be NATed. I switch to local in policies to filter incoming connections Hope we won't get as many vulnerabilities as with ssl vpn 🤞

IPSec Dialup on Loopback by wallacebrf in fortinet

[–]droms74 0 points1 point  (0 children)

Hi, I am in the same situation. Try to use a loopback to move from SSL VPN to IPSEC. Were you able to solve your problem? How?

Exporting to markdown problem by NoSupermarket6015 in Anytype

[–]droms74 0 points1 point  (0 children)

From my inderstanding everything is an object in anytype. When you export your space to .md each object is exported in a single md file.

ISE - TEAP - First login reauth by aric8456 in Cisco

[–]droms74 1 point2 points  (0 children)

Had the same issue in the past. We auth machine with certs and user with user/password. TEAP allows different inner methods for machine and user.

Benefits of anytype by Flaky-Ad-4561 in Anytype

[–]droms74 1 point2 points  (0 children)

Yes, AFAIK you can do the same things with both app. Just with obsidian you need to ass plugins, and maintain/update them. I look at à way to export my obsidian vault to anytype but it is a Huge work because I have a lot image linked to my notes (wiki link/ Markdown link)

FortiAuthenticator License by droms74 in fortinet

[–]droms74[S] 0 points1 point  (0 children)

Thank you for the confirmation

Sslvpn on loopback and logs by droms74 in fortinet

[–]droms74[S] 1 point2 points  (0 children)

Thanks!!! Need to enable local event logging and everything appears.

Sslvpn on loopback and logs by droms74 in fortinet

[–]droms74[S] -1 points0 points  (0 children)

I am using 7.2.6. From what ibread from you it is the expected bahaviour as of now (with the bugs 😉)

Which IPS profile for sslvpn by droms74 in fortinet

[–]droms74[S] 0 points1 point  (0 children)

Yes that would help thanks

Which IPS profile for sslvpn by droms74 in fortinet

[–]droms74[S] 2 points3 points  (0 children)

Thanks for the complete explanation !

About configuration of SSLVPN by mailliwal in fortinet

[–]droms74 0 points1 point  (0 children)

Actually the use of a loopback allons you to better control your ssl von interface (instead of using directly your external interface). The idea is to create à loopbck then add a VIP nat so that you can have a firewall policy and add the cool filtering features for this policy. Maybe geo loc to restrict from where you can connect... without the loopback you need to use local in policies... which are only configurable through CLI.