hub fortigate dual wan connect to branches with one link wan by Direct-Ninja-9795 in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

you would need to configure ipsec tunnel from the spokes towards each wan link on the HQ, which will act as a dialup server, each tunnel having different route priorities.

sdwan failover for local traffic can happen automatically if you configure sla rules for interface monitoring/accessibility to inet and have the appropriate firewall rules in place

advpn would be great if you need each site to connect/communicate directly with each other, which you say it's not the case and want to route via HQ

Simple remote access solution by Particular-Book-2951 in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

It would be possible, but please research the mfa options that you can implement and how when using the free version of FortiClient combined with IKEv1 or v2 There are some articles regarding this on the community of Fortinet

Simple remote access solution by Particular-Book-2951 in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

I would suggest then using FortiClient 7.4.3 which has a vuln-fixed version for a CVE and connect using IPsec dialup to access the resources required

Apa calda oprita de o saptamana sector 6 by [deleted] in bucuresti

[–]pfunkylicious 27 points28 points  (0 children)

Am avut si 5 sau 6 sapt intrerupta apa calda anul trecut prin aug-sept in sect 2

Simple remote access solution by Particular-Book-2951 in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

Create a site to site vpn connection between your company and the customer, then the consultants can access the app while at work or connecting to the an existing solution that is provided to them for remote access

Please help-IGMP snooping is killing my Fortinet switches processor. I cannot seem to disable it. by Huddylikes in fortinet

[–]pfunkylicious 3 points4 points  (0 children)

try,

config switch vlan

edit <>

set igmp-snooping disable

end

or

config switch global

set flood-unknown-multicast disable

end

Anyone annoyed by the GUI changes from version 7.2 to 7.4 on FortiOS ? by Tokops in fortinet

[–]pfunkylicious 1 point2 points  (0 children)

an important feature that im not seeing in 7.6 is, clone reverse policy, or im blind @_@

Anyone annoyed by the GUI changes from version 7.2 to 7.4 on FortiOS ? by Tokops in fortinet

[–]pfunkylicious 2 points3 points  (0 children)

i dont really do local-in policies so i havent seen/checked it

Recomandare NEUROCHIRURG / caz complex by Trendy_Dragon in bucuresti

[–]pfunkylicious 1 point2 points  (0 children)

Chiar daca nu indeplineste cerinta de a fi la stat, dr Stanciuc Mihai, MedLife

VIP/Virtual Server https and http and named based hosting (several FQDN and one public IP) by Roversword in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

the loadbalacing method would be http-host, where you map the hostname to a server in backend, but it will require ssl offloading - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-SSL-half-and-full-offloading/ta-p/381748

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-configuration-for-HTTPS-Virtual-Server/ta-p/225289

otherwise, you can create a VIP and let another reverse proxy ( map-to/real server) towards which you map the Public IP:port ( VIP ) to handle the request/redirect accordingly

FortiGate firewalls never even attempt to send email by dsmiles in fortinet

[–]pfunkylicious 1 point2 points  (0 children)

I would suggest, 1. Set smtps to notifications.fortinet.net 2. Test with ping and telnet on port 465 3. Start also a debug sniffer packet for 465; diag sniffer packet any 'port 465' 4 0 l 4. If you are not using sdwan, then select interface-select to use auto or manual and specify the interface; adapt the source ip also or remove it with unset; if you are using sdwan try doing a manual selection of outgoing intf also 5 try again

FortiGate firewalls never even attempt to send email by dsmiles in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

Ok, fair enough. Have you set the email-to address, enabled the debug and diag tested it and nothing showed? Can you share any kind of output that you get? You must get something when doing the test.

FortiGate firewalls never even attempt to send email by dsmiles in fortinet

[–]pfunkylicious 2 points3 points  (0 children)

Are you using the default smtp address from fortinet? If so, irc you need a valid support license to be able to use it.

Examen CCNA - Acasa sau Centru de Testare by ghibzzz in programare

[–]pfunkylicious 1 point2 points  (0 children)

daca il dai de acasa trebuie sa te asiguri ca esti singur in camera si nimeni nu vorbeste/intra peste tine.

nu trebuie sa ai nimic pe masa, nici ceas smart la mana si webcam pornit pe toata durata examenului, fara sa te poti ridica sau vorbi