FortiGate IPS (IDS)
KB ID 0001783 Problem If you want to employ the IPS service of a FortiGate firewall then you need a license for that privilege. At the time of writing you can get IPS as part of the following subscription licenses; Enterprise Protection SMB Protection (Only on firewalls SMALLER than 100F) Unified Threat Protection (UTP) Advanced Threat Protection (ATP) But Forti love to change the names of things, so double check with your vendor....
FortiCare Versions Essentials, Premium, or Elite?
KB ID 0001782 FortiCare Versions With the release of the Q2 2022 FortiNet price list, they have decided to split FortiCare up into three different versions FortiCare Essentials: Is the base-level service, and it is targeted toward devices that require a limited amount of support. This service is only offered to FortiGate models 8x and below and to low-end FortiWifi devices. Support includes web only tickets & chat, with next day...
Fortigate Hairpin NAT
KB ID 0001781 Problem Imagine the following scenario, you have a PUBLIC web server and it’s either in the same network your uses are or attached to a DMZ on your FortiGate. So above our users open a web browser and attempts to go to www.ubique.com (1) Their PC will do a DNS lookup for www.ubique.com and (in this case) a public web server returns an ip of 192.168.100.200 (2). The browser then attempts to HAIRPIN to that IP which...
Mac: No Captive Portal
KB ID 0001780 Problem I was on a train today, and they were offering free Wi-Fi but despite me being able to connect, I had no internet access. This has happened a few times to me and it’s when I need to connect to a captive portal to get internet access, then no captive portal ever appears. Note: A captive portal is just a pop up window that you usually see on ‘Free’ wifi services, so you can ‘Pay’ for...
vSphere Disable Timeout
KB ID 0001118 Problem One annoying thing about the vSphere web client is the fact it throws you out after a period of inactivity. Now I know there are straight forward security reasons for this, and on a production environment thats fine. But on my test network theres just me, sighing every few minutes and logging back in again. As the ‘Flash’ client is getting depreciated I’ll concentrate on the HTML5 client, but...