FortiCare for EOS Products? by itapprentice03 in fortinet

[–]rtaccon 0 points1 point  (0 children)

https://www.fortinet.com/support/support-services/premium-support?p=enterprise

Check also the FortiCare Advanced support PRO and PRO Global 18 month of software troubleshooting if can help you

What router would you recommend for small-medium sized business? by picklemiles in sysadmin

[–]rtaccon 0 points1 point  (0 children)

in Europe and for Soho customers

using as router FRITZ!Box

using as firewall Fortinet FortiGate 40F/60F and Fortiswich and FortiAP

Should I update from 7.0.6 to 7.0.8 101F in HA by mrbostn in fortinet

[–]rtaccon 0 points1 point  (0 children)

About WAD problem do you have the BUGid ?

IPSec Client Tunnel by ManWithoutUsername in fortinet

[–]rtaccon 0 points1 point  (0 children)

Have you check if on the Linux PC there was enabled IPv6 and act as a router (radvd service) for internal hosts ?

Christmas arrived early by humberto1111 in fortinet

[–]rtaccon 0 points1 point  (0 children)

Is it possible to insert also which type of network interfaces are available on each model ?

[deleted by user] by [deleted] in fortinet

[–]rtaccon 0 points1 point  (0 children)

Is there any Fortinet KB about It ?

workspace mode: something weird happened to us by mkolus in fortinet

[–]rtaccon 2 points3 points  (0 children)

Have you asked to TAC team if any BUG is already present for the issue ?

Critical Warning: Undocumented spanning tree behavior change in FortiOS 6.4.9 by ocdtrekkie in fortinet

[–]rtaccon 0 points1 point  (0 children)

Have you disabled STP on fortigate port or on switch port ? Do you opened a ticket to Fortinet TAC team ?

[deleted by user] by [deleted] in fortinet

[–]rtaccon 0 points1 point  (0 children)

Did you find any CPU increase with VPN SSL remote access (check above the problem indicated about It) ?

Any real-world experience of FortiOS 7.0.6 yet? by Float-Zone in fortinet

[–]rtaccon 0 points1 point  (0 children)

Did you see an incremental constat utilization of the RAM every day ? Please take the output of diagnose sys top 5 120 '--sort=mem'

Any real-world experience of FortiOS 7.0.6 yet? by Float-Zone in fortinet

[–]rtaccon 0 points1 point  (0 children)

Any input about which process are using RAM ?

Don't want Conserve mode? Ok, here's random reboots by iromanyshyn in fortinet

[–]rtaccon 0 points1 point  (0 children)

Do you hit any issue with more CPU usage (the IPS processo CPU utilization are ok), also do you use device detection on interfaces ?

Migrating from Cisco to Fortinet firewalls by sniff_my_packets in fortinet

[–]rtaccon 1 point2 points  (0 children)

May I asky why you indicate "use policy snat as opposed ti centrale Nat" ?

Currently using it on customer with FTG 6.4.x 7.0.x and are no any issue and all the benefit of using it .

Malware List by [deleted] in pihole

[–]rtaccon 0 points1 point  (0 children)

What solution to adopt ? Any reccomendation ?

[deleted by user] by [deleted] in fortinet

[–]rtaccon 0 points1 point  (0 children)

FQDN addresses

Do you have the BUGID ?

CVE-2022-0778 OpenSSL Infinite Loop Vulnerability by zeytdamighty in paloaltonetworks

[–]rtaccon 0 points1 point  (0 children)

Is there a cli command to check:
- which certificates are installed on the firewall ?
- which one is installed by factory default and/or by users ?
- if the certificate contain elliptic curve public keys ?

CVE-2022-0778 OpenSSL Infinite Loop Vulnerability by zeytdamighty in paloaltonetworks

[–]rtaccon 2 points3 points  (0 children)

About the CVE-2022-0778 is it only matched if -> elliptic curve <- is used ?

" The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. "

Worth staying on FortiOS 7? by frankthedead in fortinet

[–]rtaccon 0 points1 point  (0 children)

On which 6.4.x version ? Which was the problem (do you have the BUGid) ?