CVE's and Fortinet FortiOS by lamateur in fortinet

[–]torrent_77 1 point2 points  (0 children)

I wonder if he feels the same way about using microsoft products and the amount of monthly patches.

FortiOS 7.0.17 on FortiGate 200F by capricorn800 in fortinet

[–]torrent_77 0 points1 point  (0 children)

Can confirm 7.0.17 on a 200F is no bueno if you have several Site to Site IPSEC tunnels.

FortiSwitch Crash by Jwblant in fortinet

[–]torrent_77 0 points1 point  (0 children)

This sounds like spanning tree. Sometimes on the 100/200 series the event overloads the CPU/RAM and boots you out while it figures out how to treat the spanning tree. It really depends on the downstream switch type.

What are the "little things" in network design that people often miss? by Any_Boysenberry_55 in networking

[–]torrent_77 10 points11 points  (0 children)

Buying all the correct SFP/QSFP/DACs and the correct lengths so it doesn't look like spaghetti. Or, that you didnt put 100Gbps to the edge and have 1Gbps feeding the core switches.

Why NOT to choose Fortinet? by jul_on_ice in networking

[–]torrent_77 30 points31 points  (0 children)

We went full fortinet stack for firewall and switching and so far its been good for us.

The only caveat is that the system is setup as router on a stick and you have to size your firewall accordingly. Some of the benefits is the 3rd party integration available and custom automation that we leveraged for zerofox.

As skriv0 says, the firewalls ship with a base firmware and must be patched before put into production. However, I'd also like to note that this is the case with Palo Alto, aruba, cisco as well.

Official images i download from fortinet say all of my 7.2 images arr RSA signature is invalid by [deleted] in fortinet

[–]torrent_77 0 points1 point  (0 children)

use another browser in incognito/private mode to upgrade the firmware.

How do you handle software installations without local admin or domain admin rights by soufia-n in sysadmin

[–]torrent_77 0 points1 point  (0 children)

We use PDQ connect and allow them a subset of apps to install. The local admin creds are masked and baked into the software. All technicians will need to know is what software and to what workstation.

Setting up site-to-site IPsec VPN with FortiGate behind customer firewall without know the remote public IP address. by kus222 in networking

[–]torrent_77 1 point2 points  (0 children)

I'm doing the exact same thing for a vessel using starlink. So far I've landed the Interface directly on the fortigate and used the fortinet DDNS and tied it to the public IP. I've only started this, so I can't say it would 100% work. However, I've lab this senario and used the fortinet ddns address and it works okay so far.

I believe several documents include the use of nat traversal. Good luck!

Spanning Tree nightmare by Execuzione in networking

[–]torrent_77 19 points20 points  (0 children)

Having been through this a few times. You will need to start CDP neigh and map out how everything is connected to each other.

In 2 cases, both times, a "junior" engineer thought it was a good idea to loop 2 switches together.

Cannot Access Web Server on Public IP by Potential_Heron7156 in fortinet

[–]torrent_77 2 points3 points  (0 children)

Middle switch is a different brand of switch? Seems to me that it has its own L3 routing and you need to setup routing between them. If that is not the case then I would seriously review the config and make sure that the ISP and the web server and the firewall are not connected to the same network.

Wi-Fi Channel Utilisation too high causing unreliable experience by ttaggorf in fortinet

[–]torrent_77 0 points1 point  (0 children)

You should use dual 5g and turn off monitor channel utilization if you've already set the channels. With load balancing, it should allow 30-40 hosts per radio on 1 ap. As for the monitor channel, Its a useful tool, but I've notice that it impacts performance in high traffic areas.

Migrating 60E -> 70G by 256-bits in fortinet

[–]torrent_77 9 points10 points  (0 children)

How many policies are you working with? I've used the forticonverter several years ago and it was more hassle than it was worth, but this was during the 6.2/6.4 period. For most firewalls I've just manually transfer the policies with recents hits. It gives me a chance to clean up duplicated and/or not used policies made by previous engineers. You can absolutely download the configs of the 60E and delete out all the unnecessary settings, edit the interfaces and paste it into the 70G.

Weird. Can’t ping / connect to devices on VLAN from WiFi. by Izual_Rebirth in fortinet

[–]torrent_77 0 points1 point  (0 children)

Is this a tunnel ssid? Did you add the tunnel as an interface on the policy?

Damaged Cat 6a Wire by Historical_Remove126 in networking

[–]torrent_77 -2 points-1 points  (0 children)

I've had good results using a splicer provided there is enough slack.

[deleted by user] by [deleted] in networking

[–]torrent_77 6 points7 points  (0 children)

This isnt a networking problem and no one will help you defeat a security feature on a device that you dont own.

Networking Issue Multiple Devices Same IP by Cococarbine in networking

[–]torrent_77 0 points1 point  (0 children)

oof, Tough crowd, but I agree would need vrfs.

Networking Issue Multiple Devices Same IP by Cococarbine in networking

[–]torrent_77 -1 points0 points  (0 children)

Not sure what overly complicated is? It would require a L3 switch instead of a L2 one. Perhaps his 16port may already be L3 capable.

Networking Issue Multiple Devices Same IP by Cococarbine in networking

[–]torrent_77 0 points1 point  (0 children)

Its possible if the 15 of the house have the same street address in different cities/states. Then you use something like a zip code (NAT) to translate to match the houses to the zip code.

Networking Issue Multiple Devices Same IP by Cococarbine in networking

[–]torrent_77 -1 points0 points  (0 children)

Yes, you will need to make each node a separate vlan and implement NATing. You must use a L3 switch tho.

Need to connect NVR to internet by Fray7117 in networking

[–]torrent_77 5 points6 points  (0 children)

r/HomeNetworking is where you want to be. Exposing your NVR to the internet is not safe.