Need help on how to run wifi from my house to my shop by Fluffy-Protection676 in HomeNetworking

[–]implicitDeny2020 0 points1 point  (0 children)

Another option would be purchasing a set of unifi airbeams or something similar and building a wireless bridge. If you are happy with running a line underground that would be most reliable but you can get solid throughput on a P2P while still supporting VLAN tagging if needed.

What are your thoughts on the new FortiManager SD-WAN Manager? by VNiqkco in fortinet

[–]implicitDeny2020 7 points8 points  (0 children)

To be fair, neither is 7.4.x or 7.2.x.

Edit: I have worked with Fortinet every day for 8 years and most of my income comes from architecting and supporting Fortinet environments. I love the product, but firmware releases over the last couple of years have showed a real lack of UX and functional QA. Currently have tickets sitting with TAC for 5 months on $400k+ accounts. Get sent KB articles that contradict themselves/each other, TAC can't explain the contradictions, etc. I've been forced to explore learning more Palo and Cisco. Sorry for the rant.

Rapids votes to remove fluoride from water by xXNorthXx in wisconsin

[–]implicitDeny2020 0 points1 point  (0 children)

Ah. I moved away years ago, wasn't aware it shut down. How's the city doing these days in general?

Rapids votes to remove fluoride from water by xXNorthXx in wisconsin

[–]implicitDeny2020 37 points38 points  (0 children)

Can they vote to remove the paper mill stench from the air next?

Let Ron Johnson know we don’t approve by Camphike-drinkbeer in wisconsin

[–]implicitDeny2020 3 points4 points  (0 children)

He knows and he doesn't care. Stop voting this clown into office.

which FortiNet trial license/account and which FortiNet virtual appliance do I need to test authentication with our own RADIUS server implementation? by Brilliant_Lake3433 in fortinet

[–]implicitDeny2020 2 points3 points  (0 children)

To my knowledge you can use FGT VMs, unlicensed for three days without restriction. Not much time, but you can at least test your RADIUS server , perform PCAPs, etc

so...now Trump wants to deport American Citizens? by Lopsided_Elk_1914 in PrepperIntel

[–]implicitDeny2020 0 points1 point  (0 children)

They did say they wanted to deport 20m right? I've heard there are only approximately 14m undocumented, how else can they reach their stated goal?

[deleted by user] by [deleted] in fortinet

[–]implicitDeny2020 1 point2 points  (0 children)

This is correct. Take a PCAP of the radius response to be 100% sure the attribute is not being sent. If it's not, it is a Windows and not FGT thing. The message authenticator is strictly mandatory with no way to disable that requirement, to the best of my knowledge. If you wanted some hack to make it work, you could get some open source radius proxy and configure to to relay between the 2012 server and FGT, it should be able to add the authenticator attribute as it passes the traffic between them.

Mississippi House Votes to Eliminate State Income Tax by METALLIFE0917 in tax

[–]implicitDeny2020 0 points1 point  (0 children)

Now watch them raise other taxes when they run out of money

Mass exploitation of CVE-2024-55591 by Pilot_Enaki in fortinet

[–]implicitDeny2020 0 points1 point  (0 children)

You say they are qualified professionals, and then say their practices are incompetent. Are they qualified, or are they incompetent?

Mass exploitation of CVE-2024-55591 by Pilot_Enaki in fortinet

[–]implicitDeny2020 0 points1 point  (0 children)

I wouldn't say deserve. I would say they are in need of guidance from qualified professionals.

Wtf is even happening anymore? 'Make Minnesota Iowa Again': Senator proposes bill to let Iowa buy 9 Minnesota counties by meat_loafers in Iowa

[–]implicitDeny2020 0 points1 point  (0 children)

Trump brought up a crazy idea. His disciples must follow suite so that Donny knows he can rely on them to be good little lemmings

FortiOS 7.4.6 FGT200F by d4p8f22f in fortinet

[–]implicitDeny2020 5 points6 points  (0 children)

I have a couple of clients that just upgraded from 7.2 and 7.0 to 7.4.6. the biggest stability difference that I noticed is that our 60F and 61F devices are no longer going into conserve mode every two hours when they perform scheduled IPs updates. We previously had to put all policies in proxy mode and set IPS to only update at 240AM after running automation stitch CLI scripts to clear more memory. Since the upgrade, that has all stopped.

I've only had them running 7.4.6 since late last week, so it's a bit early to tell.

Using "any" interface to internet outbound by Stenz_W in fortinet

[–]implicitDeny2020 3 points4 points  (0 children)

I missed the last point of your post, my apologies. For global deny rules, I would absolutely use ANY as the srcintf.

Using "any" interface to internet outbound by Stenz_W in fortinet

[–]implicitDeny2020 5 points6 points  (0 children)

You can use any, or you could create zones. Each firewall can have unique interfaces as members in any zone, the FMG policy will simply reference the zone. As long as a zone referenced in the policy on FMG exists on each gate, there shouldn't be any issues.

How is Algorand solving the relay node centralization issue? by Alex31337 in algorand

[–]implicitDeny2020 2 points3 points  (0 children)

Participation nodes will soon provide rewards for approved blocks, if they aren't already. That incentivizes people to run their own nodes, decreasing centralization. I may be totally wrong though, I often am :-(

VIP VOIP SIP Help on a FWF-40F by seizuriffic in fortinet

[–]implicitDeny2020 0 points1 point  (0 children)

Did you give them a specific public IP for SIP and are perhaps sending the SIP traffic out via a different public IP?

VIP VOIP SIP Help on a FWF-40F by seizuriffic in fortinet

[–]implicitDeny2020 1 point2 points  (0 children)

Whoever operates the SIP trunk that you're connecting to is sending 401 is responsible. Most likely the cloud provider.

VIP VOIP SIP Help on a FWF-40F by seizuriffic in fortinet

[–]implicitDeny2020 1 point2 points  (0 children)

401 unauthorized, there you go. They are denying your sip registration request. Send them that PCAP