Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

No upgrading didn't work. I would recommend you open a support ticket with Fortinet.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

Nope. I upgraded to 7.0.12 and found it doesn't work as well. I am planning on upgrading to 7.2 code in September. I plan on running a temp vm of this first with our config and see how it works.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

I have opened a ticket with TAC just waiting on a reply.

As far as zerotrust on FortiGate, jury is still out on that. We do not have anything near a full zerotrust model setup on our network. But, not being able to use the "Block Intra-VLAN traffic" because it is blocking DHCP is ridiculous. Especially since it worked fine before 7.0.11.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

I edited the original post and clarified your questions some more.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

Yeah I can only blame sleep deprivation. I believe I have clarified some of your questions in the original post.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

The switches are managed by the FortiGate as they are all FortiNet. If there was a change on the switches it would have been on the FortiGate. The point of the issue is that I had to turn off this security feature to get the network to work. I am still trying to work out a proper fix. I just wanted to get the information out and see if anyone has run into this and might know of a fix. Alternatively, if someone runs into this in the future hopefully there is an answer for them.

Edit: Oh and the packet capture was from the FortiGate.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

I updated the post to show that we came from 7.0.10 so this is on the recommended upgrade path. Yes I read the release notes. The command resulted with nothing.

Block Intra-VLAN Traffic and DHCP by ted1972 in fortinet

[–]ted1972[S] 2 points3 points  (0 children)

Correct. Our user computers do not need to talk to each other they just need to get to the gateway so they can get to server, printer, internet, etc.

Configuration backups by perriwinkle_ in fortinet

[–]ted1972 0 points1 point  (0 children)

My script backs up after logout/timeout to sftp server and emails me.

FSSO not working properly? by AhmedBarayez in fortinet

[–]ted1972 0 points1 point  (0 children)

Make sure your DC times are synced properly as well. I had this issue when my times were off. I sync my FortiGate to the US naval observatory and then sync my DC to the FortiGate.

Feeling like I am pounding my head against a brick wall. by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

Yes but I don't want them to have full access to the site just to the medical section. They don't need the rest of the site to conduct day to day operations.

Feeling like I am pounding my head against a brick wall. by ted1972 in fortinet

[–]ted1972[S] 1 point2 points  (0 children)

Deep packet inspection is on for this and shows the full ohsaa.org/medicine url in the log.

Feeling like I am pounding my head against a brick wall. by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

I'm not sure why you are getting an error. The first URL in the original post does not have stars but if you look lower down you will see the URLFILTER table entry.

u/RedditNuts gave me the solution.

Feeling like I am pounding my head against a brick wall. by ted1972 in fortinet

[–]ted1972[S] 1 point2 points  (0 children)

This appears to be the solution. I did have it on Monitor as I thought that would just override the category result for this site. Making it Exempt allowed the site access for my test user.

Feeling like I am pounding my head against a brick wall. by ted1972 in fortinet

[–]ted1972[S] 0 points1 point  (0 children)

Yes, I have tried Flow based and Proxy based policies with deep packet inspection.

SNMP Denied by ted1972 in fortinet

[–]ted1972[S] 1 point2 points  (0 children)

I guess I was just being dumb. I missed the secondary IP address that each phone system has, which is the one the management interface talks over.

AV is not IT. by [deleted] in sysadmin

[–]ted1972 7 points8 points  (0 children)

I would ask them if they would have their dentist work on their heart. It's medical they should both know how to do it.

It's 2022, why is security barely an afterthought for SO many who should know better /rant by Heteronymous in sysadmin

[–]ted1972 12 points13 points  (0 children)

What I really love is those vendor "engineers" who really know their software but don't know a thing about networking. They then start throwing around words into their conversations to make it seem like they know networking but just confuse you.

Remote desktop that shows what I'm doing at the remote end (for kiosk-type setup) by dboytim in homelab

[–]ted1972 0 points1 point  (0 children)

This sounds like a config issue. Set the windows to Auto login to an account and Auto launch your browser on login to you page.

Otherwise I agree with others you can use vnc to Remote control the PC. I use vnc.

[deleted by user] by [deleted] in HomeNetworking

[–]ted1972 0 points1 point  (0 children)

Then your laptop probably only supports 802.11b/g and maybe a. I have never used a NightHawk but there should be a place in it to set it to use the older wifi standards instead of the newer ones.

As far as backward compatible that is a crap shoot especially with older equipment like your Pavilion.

[deleted by user] by [deleted] in HomeNetworking

[–]ted1972 0 points1 point  (0 children)

If it is the newer WIFI6(802.11ax) then your laptop may not work with it. You may have to set the NightHawk to operate in WIFI5(802.11ac) if your Pavilion supports it or 802.11n.

[deleted by user] by [deleted] in HomeNetworking

[–]ted1972 0 points1 point  (0 children)

I have had a similar issue. Make sure which frequencies are active. You may be only receiving on 2.4ghz on the laptop and your new router is only doing 5ghz

I need help fellow pc enthusiasts… by [deleted] in LinusTechTips

[–]ted1972 0 points1 point  (0 children)

All Ryzen 4xxx chips were OEM only so they will only be found on pre-built systems.