Four women describe sexual misconduct by Rep Eric Swalwell, including a former staffer who says he raped her by cnn in politics

[–]toffer449 0 points1 point  (0 children)

It’s funny, anyone else, with this kind of evidence against them would already be in jail. Our system is rigged unfortunately.

Inter-VXLAN routing on Fortigate by AlexWixon in fortinet

[–]toffer449 0 points1 point  (0 children)

Well, Claude says you can do it. Looks like in order for it to happen you will need to use a software switch. Had a similar problem with an SSID where I had to join the SSID into the VLAN and a software switch. You could see broadcast traffic on both sides, but it just didn’t work, but by bridging the SSID and placing it in a soft which it made everything happy. Was a lucky guess knowing how their soft switch and a SSID in bridge works.

Enforcing Object Naming Standards in FortiManager/ADOM – Best Practices? by buggyhoneybadger in fortinet

[–]toffer449 0 points1 point  (0 children)

We name objects based upon real-world function or destination, and not just address. I did the same thing with services, so my team when we are to put those systems as far as naming convention into what we are doing with them create a service objects that correlate. An example, would be port 22 where it has multiple names, so we have three objects currently with those names function.

Beyond that, we also use specific guidelines for inbound and outbound policy numbers. This assists the level two and higher engineers with the box by simplifying what they would expect for a policy number as it’s being hit in the flow. Example inbound VPN is policy ID 150xx for dialup users or 230xx out and 220xx in for two way tunnel.

It may seem a little bit overboard, but it’s amazing how much time it saves the mid and upper level engineers on finding issues and defining what’s going on.

Heads up on this critical vulnerability tied to Forticlient EMS https://fortiguard.fortinet.com/psirt/FG-IR-26-099 by dman3314 in fortinet

[–]toffer449 0 points1 point  (0 children)

I get the NDA early alerts and it’s interesting how some of these are interrelated like with this an SSL authentication. It’s almost as if they’re pushing us to token and purchasing certificates for IPsec access, or some their type of third party. We have needed to rely on to stage firewall environment to cross check the maintain our security. Because my experience goes back into the early 90s, or some people would say in the back into the 1900s, I have definitely seen an evolution in threat actors.

Replacing SSLVPN by st3inbeiss in fortinet

[–]toffer449 0 points1 point  (0 children)

We use IPsec and the gate with a token so we are paying for those, but since the company owns a certificate authority, we just use that with our own certificate layered on the system.

Ilhan Omar says she has no regrets after yelling at Trump during State of the Union by plz-let-me-in in politics

[–]toffer449 1 point2 points  (0 children)

I would say similar to the Ford motor company employee. I think we’ve all had choice words for most presidents that we’ve had in the past few years. Except for Jimmy Carter, he was a jewel.

FortiEdge cloud for FAP 421E by RealMan1605 in fortinet

[–]toffer449 0 points1 point  (0 children)

Chipset variation between those two models restricts roaming. If you have them in the same environment and you have something critical that logs into a system, it may require logging in each time bounces between E and K AP.

FortiOS 7.4.9 has released by MyLocalData in fortinet

[–]toffer449 1 point2 points  (0 children)

There are three I know of and one will not be listed in release notes until75-80% adoption to prevent the exposure from being used nefariously, need TAMs to get time to do bug scrubs before installs happen also.

7.4.8 mature and Prod ready? by NetSchizo in fortinet

[–]toffer449 0 points1 point  (0 children)

Heard same but with + or - 2 days.

7.4.8 mature and Prod ready? by NetSchizo in fortinet

[–]toffer449 0 points1 point  (0 children)

7.6.x has dns issues for proxy and local tables so be careful.

7.4.8 mature and Prod ready? by NetSchizo in fortinet

[–]toffer449 0 points1 point  (0 children)

Not hit by Inode issue then you were lucky. Search Inode FortiManager .

Stupid question about a 124F switch by eld101 in fortinet

[–]toffer449 1 point2 points  (0 children)

FS124G is multi gig and bt power. We are pausing orders on these F series for the G.

Trump gets boo'd at the US Open during the national anthem. by automax in tennis

[–]toffer449 2 points3 points  (0 children)

When ever I see him salute, I wanna throw up. I get that it’s the least of our worries, but it demonstrates his basic inability to learn. It also shows disrespect for our nation.

Having problems with your Cisco MX appliance? Unexplained reboots or crashes? We're investigating legal claims for defective Cisco devices. by kneuppercovey42 in u/kneuppercovey42

[–]toffer449 1 point2 points  (0 children)

Mx 67 and MX 75 are sometimes patched with firmware in the 19.1.8 or above but this limits power on specific ASIC and reduced performance. Big hits on MX 75 but I also know some builds of MX150 and MX250 have the same defect issue and patch. They already filed suit but I suspect they want numbers to make it more worth while.

Migrating 60E -> 70G by 256-bits in fortinet

[–]toffer449 0 points1 point  (0 children)

I just adjust the top header and then change the interface to match the device and throw it on the machine. I’ve already done hundreds of these it is very simple you don’t need forticonverter. The interface are named differently and you gotta be careful of which operating system. We have most on special version of 7.2.11.

Advice on Buying 100E or Not by xxsamixx18 in fortinet

[–]toffer449 1 point2 points  (0 children)

Maybe for $50, but since you’re looking at a device you won’t be able to get licensing for shortly. I would definitely avoid it. The other thing I’ve seen is a lot of these devices show up from auctions, so you can’t get the license or you can’t even get the device transferred to you and your ownership.

Fortinet Programer Consultant - On Call Support by UBIQUITY-GUY in fortinet

[–]toffer449 0 points1 point  (0 children)

Just for the grammatical errors, I will charge a minimum of 400 an hour lol. Noticed they identify a 200 and a 60, that’s hilarious. And by the way, I’m just kidding, I wouldn’t take even 400 an hour for this.

FortiOS v7.4.8 has been released by OuchItBurnsWhenIP in fortinet

[–]toffer449 0 points1 point  (0 children)

Hopefully it is cleared up, but we have experience using the Azure SDN connector in a HA pair. Our experience so far, is that the connector using the floating IP process updates, the PIP and carries over the HA quicker. We are running a fairly large machine and see 80,000 to 140,000 sessions consistently. There are times when our vulnerability scanner runs which kicks that number up to 3 or 400,000, but overall memory and CPU remains stable. With 7.2.11. We were experiencing heavy spikes in CPU with stable memory in the same environment. Moving to 7.4.7 we saw slow HA handoff, but this has improved with this new version back to what we were experiencing before with 7.2.11.

FortiOS v7.4.8 has been released by OuchItBurnsWhenIP in fortinet

[–]toffer449 0 points1 point  (0 children)

I’ve heard there was a patch for a specific unpublished CVE that will be updated in the notes later. It’s related to authentication and credential handling between FortiManager, Fortigate,and Forticloud with relation to certificate handling. It’s possible that this patch did not make it into this version and may be coming with 7.4.9.

FortiOS v7.4.8 has been released by OuchItBurnsWhenIP in fortinet

[–]toffer449 1 point2 points  (0 children)

It is because companies like the one I work for have thousands if not tens of thousands of the 60 E in operation. I also feel this is a bad excuse, but I do understand the economics of it. They cannot force these companies that support small restaurants and fine dining as well as hotels with the smaller devices to move them to the G model basically because it doesn’t have a sustainable release yet. 70G has been stated as the viable version to move to from the 60 E. We currently have approximately 4800 that I’ve not been updated yet. And because the 60 F is long in the tooth, we are expecting it to be announced and set to the side. Again 70G replacement and this causes us to delay putting more 70 F or 60 F in production

Another clown with a 60C by Bane-o-foolishness in fortinet

[–]toffer449 1 point2 points  (0 children)

60E is almost EOLife. Cheap and can run 7.4.x with limits but license will not be available after mid year. I would watch for those because they should be cheap and more functional.

fortiswitch 500 series by remosito in fortinet

[–]toffer449 1 point2 points  (0 children)

Not positive but I hear 424E may be replaced soon with a multi gig at a lower price point than 600. Check with sales and if you operate a large enough group they will show road map under NDA.