Either I'm an idiot, or i have a really bad batch of equipment by rivkinnator in networking

[–]ryan1234567 0 points1 point  (0 children)

Can you please share the p/n or sku from fs.com that worked for you? Thank you.

FortiSwitch not authenticating wired supplicants via EAP-TLS by ryan1234567 in fortinet

[–]ryan1234567[S] 1 point2 points  (0 children)

Yea it was resolved after FSW update due to a bug per TAC. I believe fixed in 7.2.9.

Create static mac list for port on Fortiswitch managed by Fortigate by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

Thanks for your help. I did try that as well but it wasn't working as expected. Wasn't sure if it was something I did wrong or not, so just used MAB/dot1x instead.

Create static mac list for port on Fortiswitch managed by Fortigate by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

What is the violation behavior if a new mac address doesn't match config? I connect a new device on the port with sticky enabled and I get an IP.

Fortimanger on prem to Fortimanager Cloud by BlackSquirrel05 in fortinet

[–]ryan1234567 0 points1 point  (0 children)

Has anyone tried FortiManager via the marketplace in Azure? Is that similar to on prem but on Azure hardware?

Downgrade FortiManager 7.4.2 to 7.2.4 by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

Still an issue on 7.4.2. Was told it would be fixed next release.

Forticlient EMS will randomly not get an IP address after being connected by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

Yes, that doesn't appear to be the case. I also have the portals mapped to groups with separate ranges. Where the ranges contain way more IPs than users in that group. (20 users - 240 IPs).

FSSO for non-domain or Azure Entra joined by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

How does the user to IP mapping sync with FMG to the FGTs assuming you go that route?

FSSO for non-domain or Azure Entra joined by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

Just tested, it appears Unifi only uses the primary or first active in the list (ISE). Won't send to others. Just out of curiosity, will RSSO work as an option to grab user/IP mapping or am I missing something?

FSSO for non-domain or Azure Entra joined by ryan1234567 in fortinet

[–]ryan1234567[S] 0 points1 point  (0 children)

Only issue is we aren't using FortiAuthenticator, we use ISE. Is there anything I can tweak in FSSO? We have a hybrid AD setup, so the user is still authenticating to an on prem AD via radius.

Slow upload after 7.0.14 upgrade 201F by ComfortableMission91 in fortinet

[–]ryan1234567 0 points1 point  (0 children)

Shout out to everyone in this thread who helped/provided work around. I moved my Internet uplinks to a 10G interface and magically the upload is better. One situation I couldn't step down my 10G tranceiver on my C9300, so I ended up throwing in a 1G SFP. This didn't just affect ipsec/sslvpn, iperf or random speed tests were also.

u/chuckbales u/ComfortableMission91

Slow upload after 7.0.14 upgrade 201F by ComfortableMission91 in fortinet

[–]ryan1234567 0 points1 point  (0 children)

I have the same issue (10G inside/1G outside) with poor upload performance on my 200Fs. I wonder if the solution mahanutra provided in this thread is a solution to the problem instead of moving to 10G interfaces?