FortiGate TFTP : Backup To & Restore From
May26

FortiGate TFTP : Backup To & Restore From

FortiGate TFTP KB ID 0001788 Problem I know FortiGate prides itself on being able to do everything from the GUI, but if you can only get in at CLI and need to take a backup then you need to go old school. Recently I had an HA Pair of Fortis, the primary had broken and I could not get access to the GUI on the standby. My plan was to get a backup, blow both (virtual Firewalls) away, deploy two new ones, and restore the config. What...

Read More
FortiGate Web Filtering Setup and Deployment
May20

FortiGate Web Filtering Setup and Deployment

FortiGate Web Filtering KB ID 0001787 Problem In all honesty, enabling Web Filtering on your FortiGate really could not be simpler, you can simply enable it on your default users outbound policy, and select one of the three ‘pre-canned’ profiles, job done! But most companies not only want to filter their web traffic they want to see who is getting blocked, and what are users trying to get access to. Most businesses now...

Read More
FSSO FortiGate Single Sign On
May16

FSSO FortiGate Single Sign On

FSSO  KB ID 0001786 If you are applying polices with your FortiGate, e.g. Web Filtering or IPS, then the ability to track actual users rather than IP addresses is advantageous, it’s all very well blocking access to adult material or gambling sites, from the corporate network, but most companies want to know WHO is attempting to connect to what and when.  To do that the firewall needs to learn what users are where, we can make...

Read More
ESX SD Card?
May06

ESX SD Card?

KB ID 0001785 Problem For a while it’s been common knowledge that running ESX 7.x from a server that boots with an SD-Card is a no no. VMware themselves said (originally) that they would not support it. Then they said they would ‘sort of’ support it, if there was additional persistent storage. Then in the past week they’ve said, VMware will continue supporting USB/SD card as a boot device through the vSphere...

Read More
FortiGate IPS (IDS)
May05

FortiGate IPS (IDS)

KB ID 0001783 Problem If you want to employ the IPS service of a FortiGate firewall then you need a license for that privilege. At the time of writing you can get IPS as part of the following subscription licenses; Enterprise Protection SMB Protection (Only on firewalls SMALLER than 100F) Unified Threat Protection (UTP) Advanced Threat Protection (ATP) But Forti love to change the names of things, so double check with your vendor....

Read More
FortiCare Versions Essentials, Premium, or Elite?
May03

FortiCare Versions Essentials, Premium, or Elite?

KB ID 0001782 FortiCare Versions With the release of the Q2 2022 FortiNet price list, they have decided to split FortiCare up into three different versions FortiCare Essentials: Is the base-level service, and it is targeted toward devices that require a limited amount of support. This service is only offered to FortiGate models 8x and below and to low-end FortiWifi devices. Support includes web only tickets & chat, with next day...

Read More
Fortigate Hairpin NAT
May02

Fortigate Hairpin NAT

KB ID 0001781 Problem Imagine the following scenario, you have a PUBLIC web server and it’s either in the same network your uses are or attached to a DMZ on your FortiGate. So above our users open a web browser and attempts to go to www.ubique.com (1) Their PC will do a DNS lookup for www.ubique.com and (in this case) a public web server returns an ip of 192.168.100.200 (2). The browser then attempts to HAIRPIN to that IP which...

Read More
Mac: No Captive Portal
Apr22

Mac: No Captive Portal

KB ID 0001780 Problem I was on a train today, and they were offering free Wi-Fi but despite me being able to connect, I had no internet access. This has happened a few times to me and it’s when I need to connect to a captive portal to get internet access, then no captive portal ever appears. Note: A captive portal is just a pop up window that you usually see on ‘Free’ wifi services, so you can ‘Pay’ for...

Read More
vSphere Disable Timeout
Apr19

vSphere Disable Timeout

KB ID 0001118  Problem One annoying thing about the vSphere web client is the fact it throws you out after a period of inactivity. Now I know there are straight forward security reasons for this, and on a production environment thats fine. But on my test network theres just me, sighing every few minutes and logging back in again. As the ‘Flash’ client is getting depreciated I’ll concentrate on the HTML5 client, but...

Read More
Windows Server 2022 SFTP
Apr12

Windows Server 2022 SFTP

KB ID 0001779 Problem Note: This will also work on Server 2019 There’s really no excuse to be using FTP any more, it’s insecure and your username, passwords and data are sent in clear text! So let’s put the secure in FTP and deploy Windows Server 2022 SFTP instead!  Note: Yes there’s FTPS as well (and it’s not the same), that adds a secure layer to the old FTP protocol. SFTP is a completely different...

Read More