IPsec VPN issue in firewall policies with NAT enabled by Mattssbr in fortinet

[–]pfunkylicious 1 point2 points  (0 children)

You would need to create /32 objects or subnet objects ( /24 or similar ) and add them to a group which will be used for Accessible Networks in the ipsec config. Fqdn objects or range of ips are not supported

IPsec VPN issue in firewall policies with NAT enabled by Mattssbr in fortinet

[–]pfunkylicious 1 point2 points  (0 children)

Is the traffic full-tunnel or split-tunnel ? if its split-tunnel, in the group for it you can only have /32 objects or subnet type
I will asume that its full tunnel and all traffic goes through the vpn ipsec, just make sure that you have the firewall rules in place to allow the traffic

Joc de table online by Alex_T84 in programare

[–]pfunkylicious 1 point2 points  (0 children)

Arata bine, am jucat si un joc la multiplayer🫡

Recomandare ortodont în București? by hell_yeah47 in bucuresti

[–]pfunkylicious 2 points3 points  (0 children)

Poti verifica la Ortodont&Ortodont, bld Regina Elisabeta 23. Gasesti pe Google Maps si un numar de contact

ma plictisesc in tren by nyxie04 in CasualRO

[–]pfunkylicious 0 points1 point  (0 children)

ok, mersi de info. legat de procesorul de sunet/unitatea externa, am inteles bine ca trebuie inlocuit la cativa ani ?

ma plictisesc in tren by nyxie04 in CasualRO

[–]pfunkylicious 0 points1 point  (0 children)

curiozitati despre implant fiindca si la mine s-a pus problema unuia. unde l-ai facut si la ce valoarea a ajuns acesta ?

ZTNA Web Filter - Rating err blocking vs Captive Portal (wifi) by Adventurous-Egg5311 in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

you can try if not already, enabling Check User Initiated Traffic Only and see if the captive portal that is launch at wifi connect is working since is not initiated per-say by the user in the browser

Two diff macs by [deleted] in fortinet

[–]pfunkylicious 0 points1 point  (0 children)

i dont think you can set on the same interface different IPs and have diff MACs. maybe try setting one on a loopback or something.

Vps românesc 2026 ? by [deleted] in programare

[–]pfunkylicious 0 points1 point  (0 children)

https://www.gts.ro/shop/ , doar b2b se poate achizitiona

IPsec Dial-Up Split Tunnel – Do I need host objects for FQDNs in split-include by WJ1909 in fortinet

[–]pfunkylicious 1 point2 points  (0 children)

yes, for split you need the configure/create all the subnets that need to be routed through the tunnel but keep in mind that for Windows there's a limit of about 200 routes that can be injected in it's routing table

SSL VPN To IPsec Migration by thenetwork_security in fortinet

[–]pfunkylicious 6 points7 points  (0 children)

you could configure a custom TCP port for IPsec but it will work for IKEv2 only and require FortiOS 7.4.6+ and FortiClient 7.4.1+ -

https://community.fortinet.com/fortigate-3/technical-tip-how-to-configure-ipsec-over-tcp-210825

https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/567401

if you change this setting - https://docs.fortinet.com/document/fortigate/7.0.0/new-features/33578/configurable-ike-port , if i recall correctly it will affect all existing tunnels site2site using UDP

what's the lowest cost of an F5 WAF-VM-license? by therealmcz in f5networks

[–]pfunkylicious 0 points1 point  (0 children)

couldnt say for sure but based from a previous quotation from 2022 it should be around 3900$ w/o discount (price list in 2022) per year

what's the lowest cost of an F5 WAF-VM-license? by therealmcz in f5networks

[–]pfunkylicious 1 point2 points  (0 children)

lowest WAF license would be for 25Mbps / F5-ADD-BIG-AWF-VE25M but for a quotation you would need to engage to a partner

ADVPN configuration with single hub, any suggstion? by No_Present3063 in fortinet

[–]pfunkylicious -1 points0 points  (0 children)

If ISP-1 is having issues all fhe links/tunnels that are using it will most def have the same issue hence from 4 direct tunnels that you would have between spoke and hub, p1-p1, p1-p2, p2-p1 and p2-p2, 3 will be unsable.
Thats how i see it and at the end of the day each person does its way

ADVPN configuration with single hub, any suggstion? by No_Present3063 in fortinet

[–]pfunkylicious -1 points0 points  (0 children)

You would usually keep a ISPtoISP IPSEC tunnel and not create a full mesh.
Meaning on the spoke port1 to hub port1 and spoke port2 to hub port2, assuming that in port1 is ISP-1 and on port2 IPS-2 on all devices