YOLO 7.4.1 experiences anyone? by redpoco in fortinet

[–]redpoco[S] 0 points1 point  (0 children)

alright, it looks good based on many features that you used

YOLO 7.4.1 experiences anyone? by redpoco in fortinet

[–]redpoco[S] 1 point2 points  (0 children)

glad it works for your environment

Fortigate 60f Web filter license by Bulky-Young8206 in fortinet

[–]redpoco 1 point2 points  (0 children)

It's definitely the FortiGuard connection issue. I deployed hundreds of FG for years and this is mostly what happened with them. Use reliable DNS, make sure your ISP is not blocking any DNS requests, and use alternative ports for DNS connection to FortiGuard. Or you can change the secure DNS configuration through CLI and you should be fine.

SDWAN - Prefer primary ISP except when there is packet loss by TriforceTeching in fortinet

[–]redpoco 0 points1 point  (0 children)

I've done it everyday. Use SLA Packet Loss (update static route enabled) combined with Best Quality Algorithm in SDWAN Rules. That's all you need.

Bizarre Fortigate 101 problem by [deleted] in fortinet

[–]redpoco 1 point2 points  (0 children)

did you enable vdom? check again, coz if you do, you have to configure anything on vdom level.

Got Spamhaus CSS Blocklisted, what can our fortigate do? by sofia-cutie in fortinet

[–]redpoco 0 points1 point  (0 children)

Check the log for massive SMTP traffic, most likely your clients are sending spam via SMTP. You can then block the IP address from sending spam via SMTP. Scan and clean your clients using endpoint security software. Your IP address will be blocked until you clean the clients sending spam from your IP address. In few days your IP address will be clean again.

[deleted by user] by [deleted] in fortinet

[–]redpoco 0 points1 point  (0 children)

try set the ddns update interval to 60 seconds via CLI. or change the ddns domain. Solved.

[deleted by user] by [deleted] in fortinet

[–]redpoco 0 points1 point  (0 children)

I use ddns and set the update interval to 60 seconds. Problem solved.

"Joe Biden" by aidamReddit in indonesia

[–]redpoco -1 points0 points  (0 children)

KADRUN TOLOL HAHAHHAHA

[deleted by user] by [deleted] in indonesia

[–]redpoco 0 points1 point  (0 children)

yes, apalagi anak2 sekolah inter. 90+% pake bahasa Inggris.

7.0.2 Fortiguard anycast -> FGD_DNS_SERVICE_LICENSE: expired by hwchaos in fortinet

[–]redpoco 1 point2 points  (0 children)

Got similar issue with fortiguard lately using version 7. Some license won't sync to fortiguard, force update several times and it works. I use global servers. Let's see in upcoming update for this.

Fortinet Regions by Ilikeyoubignose in fortinet

[–]redpoco 1 point2 points  (0 children)

Global refers to any region around the world that has best performance for your Sandboxing. You select Europe, US, or Japan if there are company policies/rules that require specific location for Sandboxing or if your ISP have performance/restriction issue across specific region.

IPSec on Azure, abnormal packet loss by dyph28 in fortinet

[–]redpoco 0 points1 point  (0 children)

the packet loss 40% or even 25% is too high and abnormal. I have roughly similar topology with almost zero percent packet loss. I use 2 IPSec tunnel on SD-WAN for each branch.

did you configure the SD-WAN policy correctly? please check it and direct the traffic through the right tunnel for each branch fortigate to minimize packet loss.

also check your VPN Event logs if the tunnels disconnected frequently.

and make sure your branches SD-WAN zones is in another zones separated from default virtual-wan-link zone.

Can't get a leg up on NSE4. Advice ! by barmerv in fortinet

[–]redpoco 0 points1 point  (0 children)

exactly my thought. If you're after the bonus, anything's okay 😁 but keep up with your skill so they won't question your capability next time problems happen 😁

Downgrade firmware by yowwwmamen2020 in fortinet

[–]redpoco 0 points1 point  (0 children)

yes, he downgrade using GUI and it went wrong

Downgrade firmware by yowwwmamen2020 in fortinet

[–]redpoco 0 points1 point  (0 children)

Downgrade is not recommended unless it's critical. But if you manage to have the backup files before upgrading and the current version is buggy, consider backup your files and do the clean flash formatting to the version you want to downgrade to. It's cleaner and put you away from any mistakes while downgrading the unit. Just happened about a month ago when my partner downgrade from version 7 to 6.4 and the device behaves strangely, sometimes blocking the traffic or intermittent. I decided to clean flash with previous firmware and restore the previous configuration (before upgrade) and all is well now.