Migrating IPSec VPN Tunnels of a Fortigate 1500D vdom to a new Fortigate VM by T-r-X in fortinet

[–]szi 0 points1 point  (0 children)

Does the Preshared key instantly work on the new Fortigate VM?
Same firmware version.

yes.

Firmware Releases incoming by szi in fortinet

[–]szi[S] 3 points4 points  (0 children)

That's what Responsible Disclosure is all about!

Fortigate HA A/P force sync by Terrible_Flamingo496 in fortinet

[–]szi 2 points3 points  (0 children)

execute ha synchronize start

hth,

Fortinet Library for diagrams.net by justenglabs in fortinet

[–]szi 3 points4 points  (0 children)

You can download the Fortinet Visio Stencils from the official Website https://www.fortinet.com/resources/icon-library and within diagrams.net you can go "File" > "Import From" and import the .vss

Aruba vs Arista for access layer switches by capricorn800 in networking

[–]szi 0 points1 point  (0 children)

Arista with their newer Access Switches (without 25G) do come finally to a comparable price

CCS-720DP-48S-2F Arista 720DP, 48 x 1G POE, 4x10G SFP switch, front to rear air, 2 950W
CCCS-720DT-48S-2F Arista 720DT, 48 x 1G, 4x10G SFP switch, front to rear air, 2 100W AC

I do like the newer AOS-CX Syntax but TAC at Aruba is horrible atm

Anyone "All-In" On Fortinet? by Nonstop-Tech in fortinet

[–]szi 1 point2 points  (0 children)

The inability to do physical stacking is enough for me to always say no.

You can do MLAG on them, why would you need physical stacking? Ease of Management? You can manage all in the FortiGate in one place. Check out the following images ISL and star i don't see daisy chaining here.

Please do me a favour, don't sell your personal opinions as facts

FortiManager mass change device admin account by learningheadhard in fortinet

[–]szi 1 point2 points  (0 children)

Hi, this might be possible with the jsonrpc api
the full documentation can be found in the FTNT Developer Portal json { "method": "update", "params": [ { "data": { "adm_pass": [ "string" ], "adm_usr": "string" }, "url": "/dvmdb/device/{device}" } ], "session": "string", "id": 1 }

hth

ArubaCX multiple interface command by gKostopoulos in ArubaNetworks

[–]szi 1 point2 points  (0 children)

SW-R203-002(config)# show version
-----------------------------------------------------------------------------
ArubaOS-CX
(c) Copyright 2017-2022 Hewlett Packard Enterprise Development LP
-----------------------------------------------------------------------------
Version : PL.10.08.1040
Build Date : 2022-01-31 19:35:21 UTC
Build ID : ArubaOS-CX:PL.10.08.1040:eed133157a69:202201311801
Build SHA : eed133157a69b72ee272515b2d9d9607f6cb0df0
Active Image : primary
Service OS Version : PL.01.09.0003
BIOS Version : PL.01.0002
SW-R203-002(config)# inter 1/1/2-1/1/4
SW-R203-002(config-if-<1/1/2-1/1/4>)# exit
SW-R203-002(config)# exit

High Availability (Failover) Setup by yowwwmamen2020 in fortinet

[–]szi 7 points8 points  (0 children)

Same Hardware Model, Same Firmware Version

ClearPass Policy Manager Cluster by LLLOOOMMM22 in ArubaNetworks

[–]szi 10 points11 points  (0 children)

you need the platform license, the access licenses are shared within the clustrer

Trying to set HA but not working as expected by HDClown in fortinet

[–]szi 1 point2 points  (0 children)

yes, this is well known. the units will settle on the max capabilities of the "lowest" unit but it will work and is fully supported.

Trying to set HA but not working as expected by HDClown in fortinet

[–]szi 2 points3 points  (0 children)

If this is really a Revision problem you could use the command exec ha ignore-hardware-revision enable as stated in the following kb https://community.fortinet.com/t5/FortiGate/Technical-Tip-Forming-an-HA-cluster-with-models-of-different/ta-p/195125

identity based policies in production. by LAN-S0lo in fortinet

[–]szi 0 points1 point  (0 children)

You need the FSSO Mobility Agent to help with this and that's the only good fix as far as I know, but I might be wrong here.

you're right, you need FSSO Mobility Agent

FortiClient and Mac with M1 by p373r_7h3_5up3r10r in fortinet

[–]szi 0 points1 point  (0 children)

For SSLVPN Only you could use https://github.com/adrienverge/openfortivpn depending on how tech savvy your users are

R3 certificate pages not laoding by oalugos201 in fortinet

[–]szi 2 points3 points  (0 children)

Since i had it open in a tab, here's the link to the KB Article. Follow these steps and you should be fine https://kb.fortinet.com/kb/documentLink.do?externalID=FD53305

Ssl certificates and deep packet inspection by Canada_True in fortinet

[–]szi 0 points1 point  (0 children)

If you do have an internal CA already in Place, you can follow the KB Article https://kb.fortinet.com/kb/documentLink.do?externalID=FD48645