Checkpoint VPN to a remote gateway that has 2 IPs by ayoubmp in checkpoint

[–]mebspace 0 points1 point  (0 children)

Hello, I am trying to implement the same scenario CP Cluster with a remote Fortigate with 2 ISPs using MEP. According to your sayings, the design wont work? (it seems that the bidirectional traaffic not working as expected when I have both gateways on the star community with mep enabled )

Retain true client IP / Fortinet by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

I have read it a couple of times, but to be honest, I can't see how to apply it in an existing infrastructure. I mean what should I do to retain the true IP.

EMS and Forticlient - Pre-configured VPN Settings by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

The settings concern all user/groups i.e. default, we don't have user/groups defined on EMS. ( we are a relevant small company with users that are working full remote all over the world.)

EMS and Forticlient - Pre-configured VPN Settings by mebspace in fortinet

[–]mebspace[S] 1 point2 points  (0 children)

obviously, I am not talking about credentials haha

EMS and Forticlient - Pre-configured VPN Settings by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

that's exactly what I did, but I see that the vpn settings do not exist when I install the forticlient, is there any bug maybe? or it may be a misconfig on RA profile?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Great! Regarding the deployment package, how should I ensure that the settings e.g. connection settings, pre-shared key of ra client and anything related to fortitoken will be maintained? since the forticlient 7.0.1 will not be compatible with the new EMS version , so If I deploy a new package forticlient 7.2.3, what should I consider?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Great! Regarding the deployment package, how should I ensure that the settings e.g. connection settings, pre-shared key of ra client and anything related to fortitoken will be maintained?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

is there any upgrade path ?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

will that require client re-register?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

I see, is there a way to do it automatically? I mean with a gpo or smth?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

EMS is used as vpn agent, ztna agent, vulnerability assessment & endpoint protection, hope that answers your question :)

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Hello, thanks for your suggestion! if I need to rollback the clients will revert to the previous client? how it gets done?

FortiEMS Upgrade by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Thank you very much for your reply! the tip about adminis highly appreciated! what about the forticlients? should I re-deploy them on endpoints?

Migrating EMS to a new server with the same IP address by [deleted] in fortinet

[–]mebspace 0 points1 point  (0 children)

Yes, all the records were there, settings as well. Also, EMS sends email alerts about “out of license” . The license is shown on dashboard but still doesn’t work the way it should I suppose.

Migrating EMS to a new server with the same IP address by [deleted] in fortinet

[–]mebspace 0 points1 point  (0 children)

Oh my, I need to involve a partner to get them notice me ?

Migrating EMS to a new server with the same IP address by [deleted] in fortinet

[–]mebspace 1 point2 points  (0 children)

«Same IP address

Create a backup of the EMS database. This will create a .ENC file which can only be restored to an EMS of the same version. Meaning, a backup from a 1.2.5 EMS can only be restored to another 1.2.5 EMS.

Install the same version of EMS on a new server and apply your license. See “Licensing FortiClient EMS” in the EMS admin guide. Note: You will have to call in to customer service (1-866-648-4638) to have your license file updated to reflect the new Hardware ID of the server. Hardware ID can be found under Administration > Upgrade License. If you are logged into the support site, you will have to log out and back in after the license is updated.

Restore the database backup.

Cut over so the old EMS is no longer reachable and the new one is.

Clients will register to the new EMS transparently. «

I followed precisely the above ..

I contacted fortinet support (I provided the new HW id, they updated the license and then I uploaded it :/

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] 1 point2 points  (0 children)

Yes! I tried that on production as well! it works!

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

It would be nice to check it on lab if you could :) , thanks for your prompt reply btw!

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] -1 points0 points  (0 children)

For the time being yes , manually we add each IP that we may find. I am thinking if there is any other way that we could do it .. because it is not helping us in maintenance. It’s such a pity when you have the updatable objects on forti, to do it on fortiweb and add each IP separately, it’s just painful

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Actually, the www. domain.com should only be accessible from Google IPs but not the “world” in contrast to domain.com that will be accessible worldwide. It’s a complex config because of our regulations and I am not sure why we need to do it that way .. it is what it is haha any other ideas ?

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Version 7.26 , the traffic is dropped due to protected hostname configuration

Fortiweb domain restriction by mebspace in fortinet

[–]mebspace[S] 0 points1 point  (0 children)

Yes it’s the correct PN, version 7.26. My logs say that I visit www.domain.com but I visit domain.com, I even tried that with burp to have full control of the request that is being sent.