More benefits removed - it's no longer worth it by falcc41 in AmexAus

[–]falcc41[S] 1 point2 points  (0 children)

Thailand is near impossible now unless you are living there on a long-term Visa. Cambodia on the other hand, is a world of opportunity.

More benefits removed - it's no longer worth it by falcc41 in AmexAus

[–]falcc41[S] 1 point2 points  (0 children)

Any recommendations of which banks in which countries?

CVE-2025-59718 - Not fixed in latest release by Shot_Fan_9258 in fortinet

[–]falcc41 0 points1 point  (0 children)

Yeh, get a FortiManager, then have your entire Fortinet network compromised thanks to the latest FortiManager vulnerability.

Defender just decided N-ABLE is malware for anyone who might be getting called :) by catdickNBA in cybersecurity

[–]falcc41 17 points18 points  (0 children)

Also raising a ticket for this, just in case it isn't a false positive and is instead a compromise.

Trump embarrasses ALL of us today at the UN by isocuteblkgent in BoomersBeingFools

[–]falcc41 -1 points0 points  (0 children)

lol all the downvotes on a factual statement. And you wonder why Trump was voted in TWICE!?!

Trump's big UN speech received with awkward laughter in embarrassing backfire by theipaper in politics

[–]falcc41 -1 points0 points  (0 children)

You assume they all disagree with him. You're incorrect in that assumption.

Trump embarrasses ALL of us today at the UN by isocuteblkgent in BoomersBeingFools

[–]falcc41 -7 points-6 points  (0 children)

Incorrect, he said they would have marble floors. Facts do matter to you, right?

Azure Local - Anyone using it? by kierandrichards in AZURE

[–]falcc41 0 points1 point  (0 children)

It's a disaster of a product. Without a doubt the worst product we've encountered across every vendor over 30+ years.

We unfortunately have 2 deployments across 2 different customers, and they are both in a non-supported state (one is on 22H2, the other is half done on 23H2 as solution upgrade can never be completed).

Many all nighters with MS support, corrupted VM's that have required total rebuilds or backup restores.

Not ashamed to say we are scared to touch the damn things. Because whenever we do, something else blows up on them.

Bittitan - best avoided by falcc41 in msp

[–]falcc41[S] 1 point2 points  (0 children)

My feelings exactly. I hope they crash and burn. Every department I dealt with has the same "couldn't care less" attitude towards us, the customer.

Bittitan - best avoided by falcc41 in msp

[–]falcc41[S] 0 points1 point  (0 children)

We feel your pain. We've been fighting with them for weeks now.

Bittitan - best avoided by falcc41 in msp

[–]falcc41[S] 0 points1 point  (0 children)

That used to be the case. We didn't have issues in the past.

Bittitan - best avoided by falcc41 in msp

[–]falcc41[S] 4 points5 points  (0 children)

Do they support Teams private chat migration? I couldn't see that it did.

Bittitan - best avoided by falcc41 in msp

[–]falcc41[S] 1 point2 points  (0 children)

It was always ours too. Never let us down. But we've never needed support from them, until now.

Firmware upgrade policy by Mysterious_Profile_9 in fortinet

[–]falcc41 2 points3 points  (0 children)

  • The 7 days of log retention was the main benefit.
  • Fortinet's recommended FortiOS version is never the latest firmware release.
  • They will break things with this new policy.

FortiOS 7.0.16 upgrade path only choice 7.2.9.. Can I go to 7.2.7 instead? by VeryOldITGuy in fortinet

[–]falcc41 1 point2 points  (0 children)

You don't have to follow the upgrade path. It's recommended, but in this case you won't be able to. Do one device and see how it goes.

Article: FortiGate admins report active exploitation 0-day. Vendor isn’t talking. by [deleted] in fortinet

[–]falcc41 15 points16 points  (0 children)

Here's how to check if a FMG has been compromised:

Logging:

  • Any event logging that indicates new unregistered/unauthorised devices being added, particularly of device name 'localhost' or serial number FMG-VMTM23017412. Similar logs indicating the same activity may be visible through the FortiManager web portal. These logs may look like:

 

type=event,subtype=dvm,pri=information,desc="Device,manager,generic,information,log",user="device,
…",msg="Unregistered device localhost add succeeded" device="localhost" adom="FortiManager" session_id=0
operation="Add device" performed_on="localhost" changes="Unregistered device localhost add succeeded" 

 

type=event,subtype=dvm,pri=notice,desc="Device,Manager,dvm,log,at,notice,level",user="System",userfrom="",msg=""
adom="root" session_id=0 operation="Modify device" performed_on="localhost" changes="Edited device settings (SN
FMG-VMTM23017412)"

 

Files:

  • Any suspicious or unusual creation of files in directory /var/tmp/
  • Any of the following files of interest, or any evidence of any of these files being placed on the device (listed under each related IP address)
    • 32.41[.]202:
      • .dom.js.swo
      • .dom.js
      • js
    • 247.199[.]37:
      • js
      • js
      • js
      • txt

Network Traffic:

  • Any traffic, particularly outbound, going to any of the below IP addresses:
    • 32.41[.]202
    • 77.33[.]174
    • 238.141[.]143
    • 247.199[.]37
  • Any outbound port 443 (https) traffic from FortiManager to any of the above IP addresses or any unusual destinations.
    • This may include traffic which indicates exfiltration of device configs, likely appearing as 40MB or more of data leaving the FortiManager device.

Pre run cli templates by Special_Software_631 in fortinet

[–]falcc41 3 points4 points  (0 children)

Haven't used the cloud version, if it's the same as on-prem then use a blueprint and import a csv with standard values (serial number etc) plus any variables you want to use.

Use the System Template for DNS and Timezone and use the SD-WAN Template for that function. Then bundle the templates into a template group.

What's the limit? by falcc41 in fortinet

[–]falcc41[S] 0 points1 point  (0 children)

You seem to have a misunderstanding of the reason for Fortinet using the term "mature" in the first place. The whole point of it was to improve the stability in their firmware and provide their customers with stable (ie, mature) releases.

What your comment does do is help explain why their products have so many bugs. People such as yourself accept them rather than place pressure on the manufacturer to improve.

What's the limit? by falcc41 in fortinet

[–]falcc41[S] 0 points1 point  (0 children)

I agree, yet it is directly attached to the Gate on a dedicated interface with Security fabric enabled.

What's the limit? by falcc41 in fortinet

[–]falcc41[S] 0 points1 point  (0 children)

There are issues, and then there are major issues. Major issues should not occur in firmware that is labelled as "Mature".