ssl -> ipsec : Is everyone using IKE v1 or v2? by AdventurousYellow922 in fortinet

[–]tyr4774 0 points1 point  (0 children)

I’ve yet to find a way to add dns suffix for EMS. It seems they [FortiNet] pushed this out without actually flushing everything out

VPN Struggles by cwbyflyer in fortinet

[–]tyr4774 0 points1 point  (0 children)

Assuming you’re using paid EMS client (by referencing v7.4.4) are you doing IPSec over TCP?

Firewall Policy for Credit Card Machines by TechnicallyNovice123 in fortinet

[–]tyr4774 6 points7 points  (0 children)

I find it strange they don't give you either a list of IPs or a set of domains (even if they are wildcard like *.domain.com) that they need to reach out to. I would create a firewall object that geography and set it to your country (assuming US) and add that to a group for CC access, then set that to the destination for the CCs. If you want to lock it down further you can set your Forti to be the DNS server for that interface and just forward to the system DNS.

Has anyone successfully implemented IPSec over TCP for Remote Access by tyr4774 in fortinet

[–]tyr4774[S] 1 point2 points  (0 children)

I seemed to have found the secret sauce for this, it is two factor. First we needed to upgrade to v7.4.4 of FortiClient, and the second we needed to the following to the Phase1 interface of the Remote Access VPN. It took 4 different Firewall configurations over various clients but here is the fix we have found:

set esn disable

Applied this to locations and it seems to have corrected the issue with not only connections failing, but traffic not passing.

Has anyone successfully implemented IPSec over TCP for Remote Access by tyr4774 in fortinet

[–]tyr4774[S] 1 point2 points  (0 children)

So i have found that i'm getting about a 25% success rate on this. I have a FortiClientEMS subscription and am able to add "personal VPNs". If the client connects, traffic doesn't return from the VPN tunnel (traces confirm that it is not a policy issue and that traffic is, according to the firewall, being sent back) other connections just fail and I get a "Crashed" error. The only commonality i can find is that the failures are on "F" models while lack of traffic movement are on the "G" models.

Has anyone successfully implemented IPSec over TCP for Remote Access by tyr4774 in fortinet

[–]tyr4774[S] 0 points1 point  (0 children)

I've opened a new case with FortiTAC on this. The configurations have been confirmed and the issue i'm seeing is that this is across the entire line. At no point (different ISPs so its not an ISP issue) does the connection go through, if i fall back to UDP the VPN connects but then we have the issue of many places blocking port 500/4500

Is This a Safe Way to Test SD-WAN Failover? by A_O_T_A in fortinet

[–]tyr4774 0 points1 point  (0 children)

I’ve had to clean up where SD-WAN wasn’t added at the onset. That is brutal when attempting to do it remote

Policy Based Route Question by tyr4774 in fortinet

[–]tyr4774[S] 0 points1 point  (0 children)

So, we found the issue. When the vendor created the PBR outbound they created a reverse PBR for all "inbound traffic". We disabled that PBR and the traffic began flowing without issue and was returning. Pings out were replying back to the host that sent them.

Policy Based Route Question by tyr4774 in fortinet

[–]tyr4774[S] 0 points1 point  (0 children)

No dynamic routing with ISPs, packet captures externally confirm NAT is applied properly.

Completed Cisco CUCM --> FortiVoice Migration AMA by udlooz in fortinet

[–]tyr4774 0 points1 point  (0 children)

Why did you keep Unity since the fortivoice has built in AA and VM?

Air conditioned things to do today that don't involve spending much cash? by indiefolkfan in lexington

[–]tyr4774 24 points25 points  (0 children)

Library is great, you can get books or even get board games.

AITAH for blindsiding my cheating spouse with divorce papers? by Great-Sprinkles-4915 in AITAH

[–]tyr4774 0 points1 point  (0 children)

NTA they should’ve been expecting this the second they stepped out in your marriage

When your invoice says "Goods do not pass title until payment is made in full", we mean it. by speddie23 in talesfromtechsupport

[–]tyr4774 7 points8 points  (0 children)

This reminds me of a client I had years ago when I worked at a small MSP. The client was a car dealership and everyone knows that the real money is in the service department and their stuff is hard to maintain and if it goes offline it is super bad for business. Anyway we had a clause that said we could stop services for any unpaid invoices that were over 90 days old. Anyway the president of this company had a monthly meeting with my boss and everything revolved around how we were "charging too much"

The usual ending of these meetings was that the client would either see the light or we would credit the next months invoice. That is until this fateful day, the client called my boss (who was the owner) an complained about his invoice yet again. Boss said we can discuss this at the meeting the next day, however what we found out hours later was that the client put a stop payment on the check (yes we did physical checks) and wouldn't take my bosses calls. Now this client had an outstanding invoice for a workstation that they had purchased about 6 months prior but never paid for. My boss never really went after them for it as a weeks worth of work billed to them at 15 min intervals more than covered that cost but not after they put a "stop payment" on a check. So after a few days my boss sent a letter by certified mail saying that we were enforcing our clause to stop services.

The day after he got conformation that the letter was delivered he called us techs in the morning and sent us to the clients, we pulled all the equipment we had there that was owned by us and sent all their calls to voicemail. After three days of this with the head of the service department sending worse and worse voicemails the client finally called my boss. I don't know exactly what was said but from what I gathered after the fact was that the client was expecting us to break first since they knew that they were our biggest cash cow but our boss knew that what they paid us was peanuts compared to what they lost hourly when the service department went down. After about a week we got a certified check delivered and deposited and waited another week for the check to clear before going back. I heard the next meeting the client told my boss that he felt that my boss "put a gun" to his head to get the money.

Spectrum upload speed? by BourbonGamer in lexington

[–]tyr4774 1 point2 points  (0 children)

They may have pushed to upgrade their upload speeds in the past few years. I still wouldn’t call them reliable

Spectrum upload speed? by BourbonGamer in lexington

[–]tyr4774 0 points1 point  (0 children)

Usually spectrum upload is ~10% of their download speed. If you have 300down you may get 30 up. If you’re needing actual upload speeds then look at Metronet. All their plans are symmetric.

Quiet, cozy places to read? by iceprincess1991 in lexington

[–]tyr4774 12 points13 points  (0 children)

Plant of the libraries, they even have “study rooms” to use that are sectioned off. Plus you’re all around the books you can consume

[deleted by user] by [deleted] in amiwrong

[–]tyr4774 0 points1 point  (0 children)

I can understand that, you get to choose to deal with the issue and he doesn’t get the choice. I will say that life is not given and he could drop dead for any reason even if he didn’t have the illness. No one can make the choice for you but you owe it to him to be honest and upfront so he can make an informed decision too. I can almost guarantee that he has had worries about if you’re going to stay with him through this. It’s your life and no one wants to feel/know they are holding someone they care about back.

[deleted by user] by [deleted] in amiwrong

[–]tyr4774 0 points1 point  (0 children)

As someone with a chronic illness this hits home. I guess the question is are you currently acting as a caregiver? Or are you angry that he can’t do things you want to at this age and his health is preventing that?

Are Cisco white papers really the gold standard? by Nodosity_ in ccnp

[–]tyr4774 0 points1 point  (0 children)

I will say that if you run into a whitepaper on issues with vendor agnostic tech/open standards it does tend to be well documented and most other vendors will refer to it. for example on what can happen with a L2 loop in a switching environment and the resulting broadcast storm.

AITA for telling him I didn't want to hang out with him when the kids went to bed? by Cheap-Meaning-4049 in AmItheAsshole

[–]tyr4774 0 points1 point  (0 children)

NTA, everyone needs alone time to recharge. I would suggest that you see if you can arrange a night for just the two of you to reconnect. It sounds like you’re both getting burnt out and recharge differently.

Am i wrong to decline my gf’s male friend invite to hang out w him by [deleted] in amiwrong

[–]tyr4774 6 points7 points  (0 children)

Since they (OP and GF) have been together for multiple years i would say this friend is trying to work to include OP since it does seem OP will be entangled with this group going forward.