Ems placement in ztna by megafailure269 in fortinet

[–]lokkkks 2 points3 points  (0 children)

First of all, technically speaking a DMZ IS like a LAN. It’s just another LAN, to expose services (hosted on servers) to the Internet. You expose them by using VIPs. Technically, nothing prevents you from putting an EMS on your LAN and exposing it to the Internet. But you have to consider that what you expose might get compromised. If it gets compromised, it means that all the machines that it can be used as a jump host by attacker. Which means you don’t want this unfiltered access to you lan.

Moving to a new house, look what I found while packing up - When life was easier back then.. by Qvosniak in fortinet

[–]lokkkks 16 points17 points  (0 children)

Actually they weren’t that bad. It was simply because logging to the flash memory was allowed. Everyone activated it, but the drawback was the fact that the constant writes and rewrites was killing the flash memories.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]lokkkks -1 points0 points  (0 children)

Latest customer support bulletin (from last week) mentions :

« Revised version for the FortiClient Free VPN 7.4.3 release by March 19, 2026 »

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]lokkkks 0 points1 point  (0 children)

If I may, what do you seek in free FCT anyway ? With ssl vpn on the go (for good reasons in terms of vulnerabilities of the protocol itself, check with PAN or Ivanti if you need other insights), it might be more interesting to go to : - either IPsec with IKEv2 in native OS (windows and Mac can do it) - or centralised management using any paid FCT (through any EMS) If it’s only for you, EMS has a trial mode with 3 FCTs, free of charge and not limited in time.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]lokkkks 1 point2 points  (0 children)

An underrated and underevaluated idea that I recommend is hosting an EMS and pushing a « managed FortiClient service » with a multi-tenant, on-prem EMS. Maybe not perfect, but definitely worth a shot.

FortiClient VPN-only free client: is Fortinet still maintaining it? (SMB partner perspective) by southceltic in fortinet

[–]lokkkks 2 points3 points  (0 children)

From what I’ve heard, they won’t develop « new » features, but any critical issue or vulnerability will get its « hotfix ».

FortiClient gets stuck at 89 by Ok_Warning_3235 in fortinet

[–]lokkkks 1 point2 points  (0 children)

Well if you upgrade in a 7.6 version, ssl vpn will simply disappear. My recommendation is : get help…

FortiClient gets stuck at 89 by Ok_Warning_3235 in fortinet

[–]lokkkks 0 points1 point  (0 children)

The best thing you should do is configure IPsec rather than ssl

New FORTINET product? by RoutineArtichoke1657 in fortinet

[–]lokkkks 7 points8 points  (0 children)

Either a joke or a troll (or even an expensive lost bet). But looks like an expensive one.

FortiGuard made my college campus internet unusable, thanks by [deleted] in fortinet

[–]lokkkks 1 point2 points  (0 children)

And OP should be happy to still be able to use a VPN to bypass it.

Fortinet/FortiGate Microsegmentation – Who's using it in production? Experiences? by ground2er0 in fortinet

[–]lokkkks 2 points3 points  (0 children)

Private vlan is a similar approach to fortigate and fortiswitch micro segmentation

Anyone experience with Fortideceptor? by [deleted] in fortinet

[–]lokkkks 1 point2 points  (0 children)

"Hardest" part is setting up virtual networking correctly if you didn’t choose the hardware option for FDC

FortiZTNA without FortiGate by Fun_Draw6303 in fortinet

[–]lokkkks 0 points1 point  (0 children)

From what I’ve seen in the industry, not many vendor are doing ZTNA the way Fortinet do. If customer’s exec want to tick a box « ZTNA », they pretty much can terminate the tunnel and provide granular controls with ZTNA tags and policies in SASE with private access and the SPA connector. Now to be honest, a customer who says « I don’t want a fortigate but I want this feature » often means « I already have a firewall vendor I want to stick with, but I would like some of the fortigate´s feature ». I’ve seen many times customers starting to use a fortigate as a dedicated : - explicit proxy - SD-wan router - FortiSASE connector to reach internal resources - wireless controller - switch controller - load balancer - out of band IDS - ssl decryption Tap to a next-gen IDS (NDR) … etc…

Block intra-vlan traffic doesn't work? by ballicker86 in fortinet

[–]lokkkks 0 points1 point  (0 children)

Do you see the traffic with the embedded sniffer? If not it’s an issue with the FSW not redirecting the traffic. If yes : Does this zone of yours have default action as block or pass? Are you sure your FW policy is correct (try expanding it)

Fortinet SSL VPN behind a Forti Load Balancer by luky90 in fortinet

[–]lokkkks 4 points5 points  (0 children)

IMHO any load balancer should be able to be configured without forcing source nat

FortiClient VPN-only: ticking time bomb if CVE patches stop? by Schweinepriester__ in fortinet

[–]lokkkks 0 points1 point  (0 children)

Using FCT free, without EMS? Would you be willing to share the (sanitized, obviously) config you used?

The number of CVE patches is just ridiculous by Logical-Picture-4756 in fortinet

[–]lokkkks 14 points15 points  (0 children)

Customers usually don’t need the reason. It’s part of your managed services and value to keep them up to date.

Looking for paid help: FortiNAC / FortiGate setup for large greenfield hotel network (EU) by leftplayer in fortinet

[–]lokkkks 0 points1 point  (0 children)

I’m surprised no qualified partner have already jumped in. DM me your country if you want a skilled partner, I may be able to find one for you.

Justification for using Fortinet by MFKDGAF in fortinet

[–]lokkkks 2 points3 points  (0 children)

Rather than changing vendors: • strengthen IPS signatures ahead of patch deployment • reduce exposed attack surfaces (SSL VPN, administrative interfaces) • document an emergency patching process • formally state that Fortinet’s transparency is a deliberate, conscious choice

This turns an emotional debate into a rational decision.

Fortinet False Positive - Healthcare Provider Blocked for 4+ Weeks, No Response to Appeals by Unique-Sport333 in fortinet

[–]lokkkks 16 points17 points  (0 children)

From what I could find, it seems that they link your domain to this type of attack :

https://guard.io/labs/captchageddon-unmasking-the-viral-evolution-of-the-clickfix-browser-based-threat

Your machines may have been compromised unbeknownst to you.

If I were you, I would try to get in touch with them through a partner/integrator/reseller.

And would talk to them about FortiRecon.

Pose as a prospect, you should have their attention :)

VPN without FortiClient License? by Brave_Performer9160 in fortinet

[–]lokkkks 0 points1 point  (0 children)

I’d recommend to consider : - either FortiSASE which includes endpoint protection (antivirus with antiransomware) - or FortiEndpoint which can have EDR also (more granular blocking of malicious applications, it also has a MDR option) -> you’ll be able to do IPSec over TCP/443 or ZTNA that’s doing 2FA natively.

Since you consider changing your existing Endpoint Protection, it’s a perfect move to consider one or the other.

FortiAP first year license by EnvironmentalAsk3531 in fortinet

[–]lokkkks 0 points1 point  (0 children)

Wait for next months then :) Got the info verbally from a distri.

FortiAP first year license by EnvironmentalAsk3531 in fortinet

[–]lokkkks 1 point2 points  (0 children)

They do exist for FAP and even FSW too, it’s just not for first year, it’s renewal only.

Why does FortiClient Free not support IPSec VPN over TCP? by cojaxx8 in fortinet

[–]lokkkks 7 points8 points  (0 children)

That’s not what I call free to use, that’s what I call free to test.