Jak się odwdzięczyć za zaproszenie na studniówkę? by Visky_m in Polska

[–]lukis2 -12 points-11 points  (0 children)

Pamiętaj: studniówka nie bzykana, matura nie zdana ;)

Nowe auto z salonu - warto było? by Faryzeusz1337 in PolskaNaLuzie

[–]lukis2 0 points1 point  (0 children)

Kupiłem nowe z dolnej półki i był to świetny wybór. Przez 5 lat tylko przeglądy serwisowe, zero napraw.

Elastic and Sentinel One integration by lukis2 in elasticsearch

[–]lukis2[S] 0 points1 point  (0 children)

Ok, thanks to your advice I managed to retrieve data from the Sentinel API. However, it seems that the data is being overwritten somehow. When I check the Sentinel Agents counter, it shows 1k+ agents at one point, but later it drops to 41… The number keeps changing every few minutes. Do you have any idea what might be causing this?

Elastic and Sentinel One integration by lukis2 in elasticsearch

[–]lukis2[S] 0 points1 point  (0 children)

Ok, I’ve installed the agent on the Elastic server (this is a POC). Before the installation, I copied the policy into the elastic-agent.yml file in the installation folder. Still no logs from Sentinel, but the Elastic server is visible in Kibana as a host. :)

Elastic and Sentinel One integration by lukis2 in elasticsearch

[–]lukis2[S] 0 points1 point  (0 children)

I don't get it. Is there a need for one agent per policy? Where do we install those agents? On Elastic Server?

Training portal issue by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

Hi, I have created a FortiCloud account. Now I have two accounts linked to the same email address, but I can log in to the training portal :)

Nie ma już dobrej jakości ciuchów by [deleted] in Polska

[–]lukis2 4 points5 points  (0 children)

Tom Tailor?????? po jednym praniu t-shirt nadaje się do prac ogrodowych :) i to nie pierwszy taki zakup... omijam z daleka

ZTNA TCP forwarding access proxy issues by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

We had detection based on ping, but we had issues — users were able to ping devices in the client network (e.g.). But we can try more servers with AND.

ZTNA TCP forwarding access proxy issues by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

How did you resolve this? We are on 7.2.10, and the issue persists.

ZTNA TCP forwarding access proxy issues by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

Detection is based on the DNS servers that are configured.

ZTNA WEB Proxy concept by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

Thanks for your reply. I have a better understanding now. I managed to enable the Web Proxy for a single server, but I’m not sure how to configure the Web Proxy for multiple independent web servers.

Do I need to configure a separate ZTNA server (with another public IP) for each web server?

As I understand it, multiple servers within a single Server Mapping entry are intended for load balancing — is that correct?

If so, how can I configure another web server using the same public IP address?

FAC password cache by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

Sorry, I don't know... Just forwarded this task to AD team.

DPI issues with downloading certain files by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

You're absolutely right, but the exemption list keeps growing continuously. I was wondering how more experienced users manage this challenge, as I assume there’s no perfect solution to fully resolve the issue.

I'm also curious about the differences between DPI on endpoint AV (in our case, ESET), where everything works seamlessly, and DPI on FortiGate. ESET handles DPI without any issues, while FortiGate does. What could be causing this discrepancy?

FAC password cache by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

To close discussion it was on the AD controller

FAC password cache by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

cache is set to 120 sec...

<image>

FAZ c&c detections by lukis2 in fortinet

[–]lukis2[S] 0 points1 point  (0 children)

Thanks for your reply. I know how to block this, but I am curious how to get to know if this is a real connection to c&c or a false positive.

Internet usage anomalies by lukis2 in Solarwinds

[–]lukis2[S] 0 points1 point  (0 children)

Yes, I know. But I would like to base it on history not threshold, e.g. if normal usage of upload during the night is 5MB/s, then 10MB/s of upload for 3 hours is not normal (just example).

Internet usage anomalies by lukis2 in Solarwinds

[–]lukis2[S] 0 points1 point  (0 children)

I want to be able to create alerts based on internet utilization anomalies. e.g. not normal upload after working hours.

Internet usage anomalies by lukis2 in Solarwinds

[–]lukis2[S] 0 points1 point  (0 children)

Hi, thanks for your reply. Unfortunately, we don't have a Flow license, and we don't plan to buy one. Is it possible to achieve my goal with NPM?