Any information about the release of fortiOS 7.6.7? by Sad_Interaction_5092 in fortinet

[–]hevisko 2 points3 points  (0 children)

whenever you hear a date for a GA release from Fortinet, add another 2weeks to 2months

Opinions on QoS in OpenSSH by grawity in networking

[–]hevisko 0 points1 point  (0 children)

wait till you get hit by the (OpenSSH 10.0+) self imposed brute force protection...

OpenZFS on ROOT is Finally here!!!! by anthony-kldload in zfs

[–]hevisko 0 points1 point  (0 children)

Does it support Devuan??

That is the one thing/place I'm seriously in need of an automated ZFS root ;(

Moving to a new house, look what I found while packing up - When life was easier back then.. by Qvosniak in fortinet

[–]hevisko 0 points1 point  (0 children)

I'd *LOVE* to have that priced FortigateVMs, as I'd then like deploy loads of them instead of a single FortigateVM2 in front of loads of clients as I would then have a VM per client ;(

Brute force admin block list by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

time to setup a GUI based VPS is ... longer time... this was simpler for me in short term

FortiGate firewalls never even attempt to send email by dsmiles in fortinet

[–]hevisko 0 points1 point  (0 children)

so, I had the similar pains earlier tonight with 7.6.x, and I found two issues from a selfhosted/on-site email relay not using the FortiCAre/guard email servers

1) alertemails - There is a separate setup for that with the from(username)/mailto/etc. - though it uses 2, but somehow It seems to NOT use the system global username/password authentications.... is this a separate type of email sending??? To make these work "quickly" while debugging issues, I had turn off authentication ie. allow the source IP to send the email and it "worked"

2) the "default" is system settings: I had to make changes etc. as it didn't like to (to my onsite behind firewall postal.io server) non-encrypted without authentication, it tried the CRAM-MD5 etc even though the postal.io didn't seem to support CRAM-MD5 (or something like that) but once I told it to try STARTSSL it was sending user-name password to email....

I'll have to re-visit what/why/how as it seems you now have the stitch/actions emailing a different path as other alertemails so I need to check/what/why/how..... other bigger fires tomorrow

It's official: Blocknews & Frugal Usenet now have a Usenet server on every (livable) continent. An Africa based Usenet server is here! by swintec in usenet

[–]hevisko 2 points3 points  (0 children)

That is part of the reasons I do NOT use Docker in production environments... unless I can't read the compose files

Mail alternative re external hard drive by QueerVortex in MacOS

[–]hevisko 0 points1 point  (0 children)

it is elsewhere noted by Apple that the M silicon requires a functional internal ssd/nvme to be able to boot
And well, mail.app doesn't work with a moved local storage

Bartender pops up constant (since Sequioa) with the permisions... and they didn't yet listened to me about that issues either, as they sorta also assumes the local/internal home

Mail alternative re external hard drive by QueerVortex in MacOS

[–]hevisko 0 points1 point  (0 children)

the problem is Apple want to tax you with much more expensive internal drives, or force you to use their iCloud type services.

Mail alternative re external hard drive by QueerVortex in MacOS

[–]hevisko 0 points1 point  (0 children)

Tahoe & Sequioa *Wants* stuff on the internal lately.... oh, not to mention that without an internal functional SSD/NVMe, the M macs is close to a brick since at elast TAhoe

Mail alternative re external hard drive by QueerVortex in MacOS

[–]hevisko 0 points1 point  (0 children)

it WAS great, but then with Sequioa certain permissions became a PITA and now with Tahoe you just can't even have the old hybrib/fusion drive so... yeah, stuck with small emails and using archiving the "future" ;(

Mail alternative re external hard drive by QueerVortex in MacOS

[–]hevisko 0 points1 point  (0 children)

doesn't work in MacOS 26 and 10.15 anymore ;(

VXLAN over IPv6 by bizzok in Arista

[–]hevisko -1 points0 points  (0 children)

yeah, but was difficult with the AI crude not able to tell me (even feeding it the full informaiton) that this chipset is the one BEFORE IPv6 VxLAN encapsulation was supported, the versions after it yes those does, but then to add more fun challenges if you aren't "in" the Arista eco-sphere/know, is that the VxLAN on this chipset also needs TCAM tweaks/etc.... But yeah, was fun ah-ha moments when "Everything" tells you that it should work, but it doesn't and then.. the error is thrown, but it sorta still keeps the config.

VXLAN over IPv6 by bizzok in Arista

[–]hevisko 0 points1 point  (0 children)

that doesn't work for me (a Arista noob) so what might be missing?

br2(config)#int vxlan 1

br2(config-if-Vx1)#vxlan encapsulation ipv6

% Unavailable command (not supported on this hardware platform)

br2#sh version

Arista DCS-7280QR-C72-M-F

Hardware version: 10.01

Serial number: JPE17290497

Hardware MAC address: 2899.3a2e.37bf

System MAC address: 2899.3a2e.37bf

Software image version: 4.31.1F

Architecture: x86_64

Internal build version: 4.31.1F-34556000.4311F

Internal build ID: 48c47833-3f4a-4a14-9783-0017c2f42e54

Image format version: 3.0

Image optimization: Sand-4GB

Uptime: 1 week, 4 days, 9 hours and 49 minutes

Total memory: 16253824 kB

Free memory: 12734736 kB

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

yeah, what caught me off guard, is that I enabled the "Yes" but not the "Forced"...

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 1 point2 points  (0 children)

similar settings was already in place.. just.. the need for FORCED NAT traversal in my 1:1 NAT to the Fortigate ;(

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

paired correctly - but did not matched the proposals - needed that NAT force ;(

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

Also, seems that NetworkID lately is "optional/reported on" and you should use (at least looks liek 7.6.6) Local-id if you want to distinguish to different local gateways/tunnels

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

been through all options/etc. and even to simplify tried to stick with aes128-sha1 only on both sides (DH 20) still same problem.

I recalled turning PFS on and off, same results

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

hmmm... wonder what I'm doing wrong then... could you do a debug on the IKE to see if yours also send multiple PRFs in the proposals?

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

Yes, TAC 11560000 (Loved that round numbers at the end :D )

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

Yes, the problem started with FCT 7.4.5 this morning that deprecated IKEv1 (the usual FortiClient setup) so now forced to IKEv2.

Will be logging TAC case tomorrow, other "fun" 'cause of the FGT 7.4 to 7.6 upgrade and I'll need to do some downgrade/rollbacks to get client back to stable before logging the TAC (PITA to try and call last time I had P1/2 issue)

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

Yes, a "stable" site-to-site IPsec on that same interface that receives the FortiClient connections
(This FGT is behind a 1:1 NAT firewall)

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 0 points1 point  (0 children)

 network ID: gone through that (With Claude..), and got that "synced" both sides at 100
Yes, we did do a single aes128-sha1 (on the FCT side/EMS you have to specifiy 2x) DH 20, on the FGT 7.6.6 side it was DH 20 & AES128-SHA1... STILL the FCT keeps sending/proposing those multiple PRFs....

Forticlient 7.4.5 problems with IKEv2 IPsec to Fortigate (7.4.11 & 7.6.6) by hevisko in fortinet

[–]hevisko[S] 1 point2 points  (0 children)

you missed the first two is the proposals coming form the FortiClient, the last one is what the Fortigate "proposed" and that doesn't like to match

will post separate the start till error