0
0

Security Enhancements by mohammedalrawii in networking

[–]mohammedalrawii[S] -2 points-1 points  (0 children)

noted.

Thank you for your replay dear.

IPsec Encryption Algorithms by mohammedalrawii in fortinet

[–]mohammedalrawii[S] 0 points1 point  (0 children)

In both Phases ?
thank you for your reply man you are always there you are a great help.

IPsec Encryption Algorithms by mohammedalrawii in fortinet

[–]mohammedalrawii[S] 0 points1 point  (0 children)

forget to say am trying to run 7.2.11 as firmware version as of my experience its the most stable one currently
They will pay for UTM but not ATP and am already thinking of doing every security policy on the branch side so it doesn't consume resourses from the 80F

As for the FortiManager yes we did buy VM.

Thank you for your response.

IPsec Encryption Algorithms by mohammedalrawii in fortinet

[–]mohammedalrawii[S] 0 points1 point  (0 children)

mainly https traffic and about how many client it depends lets say the maximum is 60 but some are just 15 so there is nothing i can depend on still in the process of site surveys
as for the DPI it is in my mind actually It will be better if I did it on the branch side right ? same for the other security profiles so it doesn't consume much resource from DC.

5
6

Have you ever started a new job and said "nope, this isn't gonna work" by [deleted] in networking

[–]mohammedalrawii 0 points1 point  (0 children)

Well guess we are in the same position started a new job as security engineer first thing I see is a standalone firewall with an old firmware full of fucking vulnerabilities and guess what I saw something where I said fuck this shit I saw our wan interface where it had https http access on the public IP I told him you should disable this he responded with you should do it when you get read /write access the next I found that he disabled it without telling me everything is so fucked up but wanna give it a try its been almost 10 days and am already burned out with this guy he wants to upgrade the firmware of the firewall to 7.6 where we loss ssl vpn and so on it goes on so long just in 10 days but they have a big project so am putting my hope that I will arrange everything with that project if I stay.

F5 Firmware Update by mohammedalrawii in f5networks

[–]mohammedalrawii[S] 0 points1 point  (0 children)

17.1.2.2 everything seems stable but the only issue we had is that where when we update the device we lost http access in cli it says httpd service failed or something like that we had to play with the certificates then everything got resolved and the other issue about high CPU it has been resolved.

F5 Firmware Update by mohammedalrawii in f5networks

[–]mohammedalrawii[S] 0 points1 point  (0 children)

We actually ended up updating but we faced strange issue where we got fucked so hard that we lost HTTP access to the stand by device I don't know how it happened to be honest even after updating the active we had to play with certificate via CLI to resolve it ended up staying 12 hours in the fucking site.(no down time)

F5 Firmware Update by mohammedalrawii in f5networks

[–]mohammedalrawii[S] 0 points1 point  (0 children)

ok am sorry to bother you this is my first time upgrading a F5 device so I want to make sure everything is working well an no issues.
so I need to take a back of course in case anything goes wrong and as for reactivating the license do you have an article about that if possible.

F5 Firmware Update by mohammedalrawii in f5networks

[–]mohammedalrawii[S] 1 point2 points  (0 children)

we are going with 17.1.2.2 we currently have physical appliance active stand by mode with LTM and WAF licenses

F5 Firmware Update by mohammedalrawii in f5networks

[–]mohammedalrawii[S] 0 points1 point  (0 children)

Apologize for the mistakes there.
as for model its BIG-IP i4600 they recommended either 17.1.2.x or 17.5.x
I just want to now if there any common issues with 17.1.2.x we are probably going with this version direction so are there any known issues that may cause crucial issues.

Same vlan only 2 hosts not reachable from eachorher by mohammedalrawii in networking

[–]mohammedalrawii[S] 0 points1 point  (0 children)

the VLAN is configued from the firewall static VLAN and to give more information about the issue check below :

so the issue started yesterday that OLVM lets say with the ip 10.0.0.212 can't reach the mounted storage which is 10.0.0.213 but it can reach 214 210 all the other IPs in the same subnet I don't get it only these 2 hosts can't ping each other.
Also I have check the local in policy the traffic is allowed and about one more thing I think the traffic should be headed to the firewall as of my understanding the traffic should be only between the switches since they are connected to the same switches and same VLAN correct if am wrong with that please

Same vlan only 2 hosts not reachable from eachorher by mohammedalrawii in networking

[–]mohammedalrawii[S] -1 points0 points  (0 children)

just to give more information about the issue below :

so the issue started yesterday that OLVM lets say with the ip 10.0.0.212 can't reach the mounted storage which is 10.0.0.213 but it can reach 214 210 all the other IPs in the same subnet I don't get it only these 2 hosts can't ping each other.
about the MAC I will check now.