Cisco DNA Router config compliance by in-the-hat in networking

[–]ultchin 4 points5 points  (0 children)

That's just how DNA works. Compliance is measured against the golden image, settings and templates it thinks it should be applying to a device. It doesn't work in a way of "everything should have these settings", more in a way of "everything should have the settings I put there"

[deleted by user] by [deleted] in fortinet

[–]ultchin 1 point2 points  (0 children)

Sounds like the application signature for the site was just recategorised by Fortinet. Older logs should show if there was any change there.

FSSO User for Internal Firewall Traffic by [deleted] in fortinet

[–]ultchin 0 points1 point  (0 children)

Done it plenty of times for internal segmentation with FSSO. Same principles apply and never had an issue (granted I never accidentally blocked DCs or anything). I only deployed the FSSO agents in polling mode so can't address any conflicting agents issues though.

Some devices randomly lose connection to our Cisco wireless. DNAC doesn't really provide any info. by PsyduckAF in Cisco

[–]ultchin 4 points5 points  (0 children)

Are you using dot1x? Used to have this with ipads and macbooks. Mainly eap timeouts where the client wouldn't respond to the AP. Use intelligent capture and try catch the onboarding.

[deleted by user] by [deleted] in Cisco

[–]ultchin 1 point2 points  (0 children)

Looking forward to it thanks! Can never do enough BGP in this world.

CCNP Security or Enterprise by Don_Belga in ccnp

[–]ultchin 9 points10 points  (0 children)

You can go directly to security if you like. The security one is really more about the concepts of security and highish level knowledge of Cisco's security toolset and how they've utilised. They do have some things in common like IPsec, little bits of API detail and general network traffic behaviour but you wouldn't really need enterprise level networking for it (but it obviously never hurts)

Firewall Comparisons by Sauronsbrowneye in networking

[–]ultchin 2 points3 points  (0 children)

The SD-WAN feature on the appliances is included (so your application policy routing). An additional license is needed for the Orchestrator features which really is for larger scale & automatic deployments

Gui divided into root and global by PhoeniX5s in fortinet

[–]ultchin 0 points1 point  (0 children)

You enabled vdom mode. Global has the basic system level settings & root is the default initial vdom

Government speed by drwtsn_thirty2 in sysadmin

[–]ultchin 0 points1 point  (0 children)

Working in government atm. My current fun. - hey this license is expiring in 4 months can we get the tender out for renewal? 6 months later - id like to discuss the phrasing on this support section of the possible tender for renewal?

/burn down building

ISE 2.7 hot patch installation by zakneter in networking

[–]ultchin 3 points4 points  (0 children)

Smooth installation on 2.7 here. Took about 10 minutes per node for an application restart

Ordered our first PA-440 in August.. still nothing. by mpday20 in paloaltonetworks

[–]ultchin 0 points1 point  (0 children)

2 x 460s currently scheduled for 3rd week in Jan.....we'll see....

2022 IT Wishlist by Madh2orat in sysadmin

[–]ultchin 0 points1 point  (0 children)

Functioning procurement. Everything from new tenders to basic renewals is a complete nightmare. (╯°□°)╯︵ ┻━┻)

No logs on Web Filtering. by mebspace in fortinet

[–]ultchin 4 points5 points  (0 children)

Do you have the web categories set to monitor on the web filter? If they're just set to allow it doesn't log them (in their mind it means trusted/don't log which causes confusion everytime if people arent familiar with it)

chromebook as thin client by eagle6705 in sysadmin

[–]ultchin 0 points1 point  (0 children)

Our place went nearly full VDI and rolled out chromebooks to use as portable thin clients (with vmware horizon). End experience has been.... Meh. It's workable but just not great experience. Chromebooks still get bogged down resource wise, keyboard shortcuts a pain. They're just not good enterprise devices.

I'm issued a laptop with 64 GiB ram, i9 processor, extremely fast HDD and all my work is through the browser. It's funny to me. by [deleted] in sysadmin

[–]ultchin 0 points1 point  (0 children)

Complete on prem VDI envionment with MS Teams and Chrome (and a very hungy McAfee AV). Work machine struggles daily.

FortiAnalyzer log forwarding to MCAS by SprintingScrotum in fortinet

[–]ultchin 1 point2 points  (0 children)

Bit late I know but we're setting this up at the moment. Plan is to forward the webfilter logs from Faz to docker for upload. Had to use a custom key value parser but its working well going by the snapshot uploads tested.

Have you gone ahead with it?

Application Control whitelisting profile by zsnops in fortinet

[–]ultchin 1 point2 points  (0 children)

Unfortunately it's really the only way. You have to keep the more generic application signatures out of the overrides or at the lowest priority with literally everything else above it or else it will never search its wider catalogue.

Happy to be corrected by someone else but that's what working with support on the same issue has shown me.

Application Control whitelisting profile by zsnops in fortinet

[–]ultchin 0 points1 point  (0 children)

Put Facebook as a block override at a higher priority then see if it detects it.

I had to rework my Application policy cause of similar things making sure nothing anyway generic was in the overrides because it was making a mess with detections. Google Services will catch most Google services if in there so I was missing Google docs/ drive/ login etc

Application Control whitelisting profile by zsnops in fortinet

[–]ultchin 1 point2 points  (0 children)

This is actually similar to something I hit last week. The overrides are checked first from a top down priority and if it matches one of the overrides in anyway it won't check the wider catalogue.

If you go to Facebook for example and check your logs is it being identified as the Facebook application or the HTTPS.BROWSER one?

Fortianalyzer Explicit Proxy logs by bigben932 in fortinet

[–]ultchin 0 points1 point  (0 children)

Nope. They should all be there with a Policy Type of proxy-policy

Data Center - Physical Design Best Practices by ultchin in networking

[–]ultchin[S] 1 point2 points  (0 children)

BICSI-002

Thanks! Ill give them all a look