Skip to main content
FG1kc
New Member
May 29, 2013
Question

Features that you would like to see

  • May 29, 2013
  • 30 replies
  • 110652 views
Why limit to Authentication-based routing,can' t fortinet have Address-based and Device Identity routing on the policy tab itself rahter than putting it on the policy route tab would be very nice to have when your using/have multiple gateways

    30 replies

    TheJaeene
    New Member
    June 4, 2013
    Virtual Routers would be nice too... the C.E.O. should know this Feature Assigning a " Next Hop" Router via FW-Policy (like WGuard does) would save a lot of PBR Entries...
    Antonio_Milanese
    New Member
    September 19, 2013
    Hi All, +1 for PBR within firewall policy I would like to be able to see more routes state aware PBR to track availbility (DGD) of next hop gw..or even better IP SLA echo and track rtr as in CISCO gears..this should be great for PDR against redundant ipsec tunnels! Best regards, Antonio
    Phill_Proud
    New Member
    June 5, 2013
    Byte-based quotas for users, applied to firewall policies.
    Adrian_Lewis
    New Member
    June 5, 2013
    Decouple both the server load balancing health checks and the dead gateway detection tests into their own ' section' so that they could be used to control not only gateway detection or server pools but also individual routes, firewall policies, or a number of other functions within FortiOS that could be turned on or off depending on the results of one or more checks. Adding things like latency as a metric for the tests could also enable things like performance based routing.
    FortiRack_Eric
    New Member
    June 10, 2013
    I would like to be able to nat with different IP address (ip-pool) depending on the chosen outbound interface. So you can use IP-pool with 2 internet connections.
    RH2
    New Member
    September 5, 2013
    ban ip from DOS Policy We get many alerts for icmp sweeps etc, and they are blocked from the DOS Policy, but I can' t ban an IP that keeps triggering the rule!
    Omar_Hermannsson
    New Member
    September 5, 2013
    ORIGINAL: RH ban ip from DOS Policy We get many alerts for icmp sweeps etc, and they are blocked from the DOS Policy, but I can' t ban an IP that keeps triggering the rule!
    You can do this from CLI. See set quarantine here: http://docs.fortinet.com/fgt/handbook/cli_html/index.html#page/FortiOS%25205.0%2520CLI/config_firewall.10.10.html
    Uwe_Sommerfeld
    New Member
    September 6, 2013
    a) Support for 6rd sit-tunnels with DHCP wan IPv4 addresses b) DNS autoupdates of DNS database zones (for client DNS updates - IPv6 without names is no fun). c) serial port on 60D ;) d) Implementation of a " good" and " bad" CA certificate for UTM SSL filtering (usage: sign with " good" certificate if external page cert is valid, sign with " bad" certificate when external page cert is invalid).
    Sean_Toomey_FTNT
    Staff
    Staff
    July 31, 2014
    Newer versions of 60D and 90D come with serial port on the front. See the datasheet for 60D http://www.fortinet.com/sites/default/files/productdatasheets/FortiGate-60D.pdf That was something I immediately noticed about some of the newer desktop models and I am happy to say it' s back for most (if not all) of those units. For those that do not have serial console, you can use FortiExplorer and a USB cable to get to the boot menu where you can interrupt boot. In fact, if you have a few of the older revisions of 60D without console port deployed remotely at a location, one possible solution is just to plug the USB into a server or even a dedicated device like a Mac Mini.
    billp
    New Member
    September 6, 2013
    +1 for byte-based quotas +1 for point " d" . Not having that is big liability when doing SSL deep scanning.
    Zeihold_von_SSL
    New Member
    September 8, 2013
    I would like to see that the local (on fortigate) dhcp server is able to update the local (on fortigate) dns database! The reason why I want this is really simple. I don' t have any (external) DHCP or DNS server in my lab. But I' am sick of typing ip-addresses while testing some features. There should be no performance impact or secruity risk. All features are there. Fortinet just has to combine them. ;)
    bobm
    New Member
    September 23, 2013
    What I' d really like to see, and saw someone else post in another thread, is a streamlined SMB FW track. I' m using a single 60C for a couple dozen users with fairly simple requirements. Seems that 5.0 has pretty much universally hosed most of us with the small desktop boxes. Lots of functionality that doesn' t apply to us is killing our performance. And I have to keep reconfiguring stuff I' ve had running for two years to fit the new firmware parameters. FG is capable of some great stuff, just not in my environment, so I' d kind of like to keep it simple for us simple little users.
    emnoc
    New Member
    September 25, 2013
    OSPFv3 authentication The ease of region ip-ban ( BLK list ) by countries geoip 2letter ISO 3166code. Heck pfsense has the covered with ease