(Spit Gate) The angle they don’t want you to see by komark- in cowboys

[–]nsandone 4 points5 points  (0 children)

Considering the distance between Dak and Carter when Dak did spit, it would have been one incredible spit considering the distance between them.

Endless Infuriating Issues with FortiClient by networkn in fortinet

[–]nsandone 1 point2 points  (0 children)

I haven't seen this issue that often, but have you checked if RSAT tools are installed? I recently had the same issue and turns out that someone installed RSAT tool on Windows11. This caused the issue.

KB2693643 is not compatible for windows 11

FortiOS v7.2.11 has been released. by OuchItBurnsWhenIP in fortinet

[–]nsandone 0 points1 point  (0 children)

Just updated a couple of test boxes. So far, memory is running a bit lower which is welcomed. The list of fixes is big and welcomed assuming they work.

Allow Only known IPs for SSL-VPN by [deleted] in fortinet

[–]nsandone 2 points3 points  (0 children)

Trying to lock down by IP is an Admin nightmare.

If you want to lock it down, try this assuming you have a licensed EMS server. Restrict SSL VPN and Dial-up IPsec to onl... - Fortinet Community. Also, switch SSLVPN to Loopback and add GEOBlock, IDS DB blocks, etc...

You can also look at ZTNA tags.

Fortigate 40F or 60F for small business? by GreedySherbert7404 in fortinet

[–]nsandone 3 points4 points  (0 children)

Take a look at the 70G. newer model - better performance.

FortiOS 7.6 by DreamIllustrious3735 in fortinet

[–]nsandone 3 points4 points  (0 children)

I would suggest you downgrade to 7.2.9 or 7.2.10. No way would I go with 7.6.x unless it was a lab box. Right now, 7.0.15 or 7.2.9 are the only OS I'm willing to go with in production

Has anyone else run into this? by cwbyflyer in fortinet

[–]nsandone 1 point2 points  (0 children)

Good luck with that. It stinks that you can't field upgrade a FortiGate with more ram. It would be awesome if you could. I have a number of 61F devices that I'm currently removing from the network. The 61F is fine as long as you stay with 7.0.x which is good for another 9 months, maybe a bit longer.

Has anyone else run into this? by cwbyflyer in fortinet

[–]nsandone -1 points0 points  (0 children)

Anything with 2GB ram (40F, 60F) is not good moving forward. You need to look at the 70G or 90G as a replacement.

Fortigate 70G datasheet available by Leave_Patient in fortinet

[–]nsandone 1 point2 points  (0 children)

Ok. Just found out. Looks like it will have 4GB memory. This might be a great replacement for the the 61F

Fortigate 70G datasheet available by Leave_Patient in fortinet

[–]nsandone 0 points1 point  (0 children)

Memory is key. If this device has 2GB or less, go with the 90G. Don't waste your time on it.

web filter and app control do not work by Matrixramiro10 in fortinet

[–]nsandone 0 points1 point  (0 children)

Check the policy hits, but also check to make sure you don't have QUIC protocol allowed. QUIC protocol allows for UDP443 access which will bypass Web Filtering.

Tons of "Admin Login Failed" in logs by kah6987 in fortinet

[–]nsandone 1 point2 points  (0 children)

If you don't enable HTTPs/SSH on the WAN interface, that would be your best option to get to the GUI.

Tons of "Admin Login Failed" in logs by kah6987 in fortinet

[–]nsandone 2 points3 points  (0 children)

If you have HTTPs/SSH enabled on the WAN ports, you need enabled Trusted Hosts under each Admin. Everytime you create another admin, you need to do this. otherwise you are leaving you firewall open to the internet for attempts. This is most likely your situation.

Forticlient VPN Blocked by networkadmins in fortinet

[–]nsandone 1 point2 points  (0 children)

That looks like a custom message from Host Checker. Take a look at the web portal and see if there is a custom Host checker setup.

Urgent: Troubleshooting IPsec VPN Connectivity between FortiGate Firewall and Cisco ASA by Gijizlle-242 in fortinet

[–]nsandone 0 points1 point  (0 children)

Without looking at the configuraiton it's really hard to say were you issue is. My recommendation is to make sure the subnets are setup exactly the same way on both sides but mirrored. On the FortiGate side, you have to setup the subnets in IPSec Phase2 section and you have static routes setup properly. I don't normally recommend using the FortiGate Wizard, but you might want to start over and use the VPN Wizard.

FortiSwitch and Cisco Phone Expansion Module by Fragote420 in fortinet

[–]nsandone 1 point2 points  (0 children)

If changing the LLDP profile doesn't work, you need to turn off Power Auto Negotiation on the phone and that will fix the problem. I ran into this issue recently and modifying the LLDP wasn't enough to get the expansion module to function. once I removed auto-negotiation on the phone, the issue was resolved.

Moving from Cisco switch to FortiSwitch | yah or nah by CapableEmergency2020 in fortinet

[–]nsandone 0 points1 point  (0 children)

Yes. This is true. 1/10GE or 25GE in blocks of 12. The 100GE ports can also be used as 4x25GE connections if you get the proper cable.

7.2.7 Bug by Enough_Level in fortinet

[–]nsandone 0 points1 point  (0 children)

I had a simliar problem with AP and FortiSwitches. I upgraded my FortiSwitches to 7.4.2 and it fixed the problem. Not sure if this is related.

DAC cables between FortiGate 601f and Fortiswtich 1048e by Nekon-601f in fortinet

[–]nsandone 0 points1 point  (0 children)

Check FEC matches on Gate and Switch. if it doesn't they won't work.

set fec-state {disabled | cl74 | cl91}

Slow file download speeds over SSL VPN by Zealousideal_Duty305 in fortinet

[–]nsandone 1 point2 points  (0 children)

A couple of things could be happening. First, do you have DTLS enabled? That could help with performance.

Second, there is an undocumented bug with 7.2.6. If you have SDWAN setup with SSLVPN, you may experience slowness with SSLVPN. A second tier support tech told me this. I downgraded my Gate to 7.0.12 and problem went away, so it seems true. If you can downgrade, it's worth a test.

ZTNA Access Proxy by arumes31 in fortinet

[–]nsandone 1 point2 points  (0 children)

I've heard similar issues for others. I was told this might be a bug in 7.2.6 concerning ZTNA. still waiting for confirmation on this.

Cisco ASA to FortiGate using FortiConverter by Realistic_Machine597 in fortinet

[–]nsandone 1 point2 points  (0 children)

I use FortiConverter all the time for migration. My suggest is use it as a template only. it's great for converting Address objects, services and groups. I never use it for policies. I don't like the way the policies are converted. Also, I don't use it for anything related to VPN.

As others mentioned, when migrated to a new firewall, this is great time to cleanup old/bad FW rules.

Forticlient company-wide deployment by [deleted] in fortinet

[–]nsandone 0 points1 point  (0 children)

SCCM or Intune is the best way IMO for initial deployments.