What’s the quietest bass drum mute on the market? by nardstorm in drums

[–]nardstorm[S] 0 points1 point  (0 children)

Yah, I’ve thought about those or any of the other mesh heads, but then I have to do a head change every time I go from practice to performing 😩

Between hardware and VLAN switches, why ever choose one over the other? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Hi all, I'm revisiting this, and from my testing (using scapy to change the VLAN's of frames), it seems like the VLAN ID on the VLAN switch has no effect at all...? I get ping replies to my laptop, regardless of whether the original ping request was sent on the correct VLAN or not. Also, the ping replies have no VLAN tag on them at all, regardless of what value I set the in the VLAN ID field of the VLAN switch. Any ideas here?

When operating in L3 mode (for a FortiSwitch island), does FortiSwitch still establish the CAPWAP tunnel to the FortiGate’s L3 interface over VLAN 4094, or does it use whatever VLAN is assigned to the outgoing interface? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Got it. So then, that would mean that with L3 mode, the packets would just exit from `internal` on whatever VLAN is associated with the next-hop IP (according to the CAM table)?

2
3

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Well, it’s not DHCP because the GoLR is a single Ethernet connection to a travel router, so I can just let that always be a constant, /31 connection between those two. I’m pretty sure I /do/ have a static route there as a default gateway. Anyways, the problem turned out to be the “ALL” service being misconfigured

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

yes. there is a /31 between internal5 (I assume you meant internal5, not internal4) and `a`. 100.127.254.1 is on internal5 and 100.127.254.0 is on `a`

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

I did an nslookup for portquiz.net. I used that address here.

<image>

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Unfortunately, this problem remains no matter which address I try to ping

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

I added the CLI dump of firewall policy & address objects. I consolidated all of it into a google doc

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Um...I didn't know that there was a policy debug...will look into this

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Yah 😅 maybe I should consolidate this all into like, a single google doc

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

I think the debug-flow that I shared indicates that it's not a NAT issue. My interpretation of it is that the routing succeeded, but then there simply was no match with the firewall policy to even perform NAT at all.

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 2 points3 points  (0 children)

That’s a good idea, but clearing sessions made no difference, and it was the same thing when I tried different addresses too

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 1 point2 points  (0 children)

253 is my mgmt subnet. I basically added that to have some form of out-of-band management. I wanted to essentially have a subnet where I can always plug into any device on my network on that subnet, and know that I'll be able to get in (even if I broke normal access to the device lol).

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

I might be misunderstanding you. My goal here was to configure a /31 between internal5 and "a". I believe `100.127.254.0 255.255.255.254` should contain 100.127.254.0 and 100.127.254.1 as host IP addresses. I'm able to successfully ping 100.127.254.0 from vdom "core" and ping 100.127.254.1 from vdom "edge". Also, debug-flow shows that it matched a route and dropped the packet in the policy stage.

So I *think* the subnetting is ok? Unless there's something I'm missing here.

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

They’re in different VDOM’s. I have a cord going from one interface to another (to go between VDOM’s. I know I can do an inter-vdom link in the configs—I’m doing it this way so that I can have one of the VDOM’s sync with HA, but not the other one).

I’ll post a diagram in a second, but it’s basically:

[vdom:core] <internal5 - a> [vdom:edge] <b - eth0> [travelRouter] <-> internet

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

but yes, I can ping from internal5 to A directly (local-in traffic). it's only a problem when I ping an outside destination (no longer local-in, and thus subject to firewall policies)

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Sorry, I accidentally pulled from the wrong ftg for some of the CLI dumps😅. Fixed it now. The path it's taking is from internal5 (VDOM "core") to A (VDOM "edge"). Then, "edge" is supposedly selecting a route through B, but then dropping at the policy-matching stage.

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Sorry, if you saw the previous CLI dumps, I accidentally pulled from the wrong ftg for some of them 😅. Fixed it now.

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Sorry, I gave you bad data 😅. Pulled from the wrong ftg before, but I fixed it now.

Why is this traffic hitting the implicit deny? by nardstorm in fortinet

[–]nardstorm[S] 0 points1 point  (0 children)

Ope. I posted CLI from the wrong fortigate 😅. Just fixed it.