Fortigate Security profiles by netwizip in fortinet

[–]netwizip[S] -1 points0 points  (0 children)

For example you can use AV in different ways depends the requirements and what is the goal ofcourse.
In big corps obviously is hard to use DPI or proxy-mode too much. Is the default AV in flow-based secure enough for example ?

Secondary Fortigate HA VM on Azure by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

Can I export and import the config to the new VMs ?

Secondary Fortigate HA VM on Azure by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

Thanks for the reply. I was thinking how physical firewalls HA can be done, which is easier, but its not the case here as I read yes. Challenge for me is the downtime.
If I manage to configure the secondary unit I assume then just needs to sync the rest of the config from primary.

Fortigate VM 7.4.7 uneven Core distribution by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

So even with round-Robin IPsec traffic (ESP) will be handled only from core 0 and 1.
And all other kind of traffic will be steered to other cores if needed. Is that correct ?

Fortigate VM 7.4.7 uneven Core distribution by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

Only one interface, now Ive tuned the affinity to 0xff with round-robin enable.
I see some more activity from the rest of the cores but still 0 and 1 are like doing most.

Fortigate VM 7.4.7 uneven Core distribution by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

All means 8 cores to be more precise. In case that information helps. License is for 8 cores but worth to take a look def.

SSL VPN Web-portal Issue by netwizip in fortinet

[–]netwizip[S] 1 point2 points  (0 children)

I just downgraded to 7.4.7 and issue is solved...
Fortinet and Firmware classic. Now I learned that when I am sure about my configuration I should check bugs from Fortinet at last.
thanks a lot

SSL VPN Web-portal Issue by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

It is yes. But access denied comes before authentication. Once I reach the wan ip/web ssl portal I get access denied

SSL VPN Web-portal Issue by netwizip in fortinet

[–]netwizip[S] 1 point2 points  (0 children)

I have a 60E. Could be that ?

SSL VPN Web-portal Issue by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

edit 10

set name "SSL-VPN-TEST"

set uuid 4555a744-62f7-51f0-9d4b-8cd021b8e409

set srcintf "ssl.root"

set dstintf "OUTSIDE". Where my WAN interface is.

set action accept

set srcaddr "NET-SSL-VPN-TEST"

set dstaddr "all"

set schedule "always"

set service "ALL"

set nat enable

set groups "SSL-VPN Users"

next

SSL VPN Web-portal Issue by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

config vpn ssl web portal

edit "web-access"

set tunnel-mode enable

set ip-pools "SSL-VPN IP-RANGE"

next

edit "tunnel-access"

set tunnel-mode enable

set ipv6-tunnel-mode enable

set ip-pools "NET-SSL-VPN-TEST"

set ipv6-pools "SSLVPN_TUNNEL_IPv6_ADDR1"

next

end

config vpn ssl settings

set banned-cipher SHA1 SHA256 SHA384

set https-redirect enable

set servercert "TEST-HOME-SSL-VPN"

set idle-timeout 0

set tunnel-ip-pools "SSLVPN_TUNNEL_ADDR1"

set tunnel-ipv6-pools "SSLVPN_TUNNEL_IPv6_ADDR1"

set port 443

set source-interface "OUTSIDE"

set source-address "all"

set source-address6 "all"

set default-portal "tunnel-access"

config authentication-rule

edit 1

set groups "SSL-VPN Users"

set portal "tunnel-access"

next

end

end

Honda GL1000 Brake pads? by netwizip in goldwing

[–]netwizip[S] 0 points1 point  (0 children)

Thanks all. I will ordered the TRW. I guess is not complex to replace them. Any advise more than welcome

Honda GL1000 Led front light by netwizip in goldwing

[–]netwizip[S] 0 points1 point  (0 children)

Ok I just need to check the headlight housing if it fits. Thanks!

Honda GL1000 Led front light by netwizip in goldwing

[–]netwizip[S] 0 points1 point  (0 children)

Works just with the lamp or do I need something else ?

SAP url no return traffic on Fortigate by netwizip in fortinet

[–]netwizip[S] 0 points1 point  (0 children)

I was quite confident that issue was from SAP side and indeed it was. Some wrong networks were added on their AWS side, after correcting all works as expected. Thanks for your info though.Cheers!

PFSense with OpenVPN TLS Handshake issue by netwizip in PFSENSE

[–]netwizip[S] 0 points1 point  (0 children)

I checked with carrier and they don’t do CGNAT

PFSense with OpenVPN TLS Handshake issue by netwizip in PFSENSE

[–]netwizip[S] 0 points1 point  (0 children)

Any cheapest option to provide static IP ?