Skip to main content
FG1kc
New Member
May 29, 2013
Question

Features that you would like to see

  • May 29, 2013
  • 30 replies
  • 110704 views
Why limit to Authentication-based routing,can' t fortinet have Address-based and Device Identity routing on the policy tab itself rahter than putting it on the policy route tab would be very nice to have when your using/have multiple gateways

    30 replies

    hemantraturi
    New Member
    October 4, 2013
    Route based failover (eg IPSLA in cisco)
    SMabille
    New Member
    October 4, 2013
    RFC5072 - IPv6CP - IPv6 over PPP New to Fortigate (200D - 5.0.4) and one serious limitation is the lack of support for IPv6 over PPP. Need it for my backup connection (WAN2) which is PPP over ADSL.
    Jay_Libove
    New Member
    October 22, 2013
    I would like to have a comments or notes field for pretty much every object type. For example, DNS entries do not offer comments or notes fields at all. Being able to make comments/notes (including fairly long texts, over 256 bytes, at least 1024 bytes) can make future administration much easier, by including information right next to each object about why the object exists/existed. thank,
    ppowell
    New Member
    November 5, 2013
    +1 on this. Comment, comment, comment. Running a system with a coupe of hundred entries and without self documentation it can be a real bear to makes changes months after the fact without thorough comments.
    TMX1
    New Member
    November 15, 2013
    I would like to see less " Features" and more of fixing the existing bugs! OH and stop changing/renaming stuff around for no reason.
    SteveRoadWarrior
    New Member
    December 4, 2013
    I' m really enjoying the FortiDDNS service. It is making my life a lot easier. I do have a request though. Could the DDNS name be determined from the actual external address (like STUN) instead of what the Fortigate thinks it is? For example: an IPSEC VPN or a remote access rule can be limited to a source DNS name. However, if the Internet service is doing NAT and hands out a private IP, then the DDNS name is invalid (points to 192.168.1.11, etc). If the DDNS service could return the connecting IP to the Fortigate, and the Fortigate would use that IP as its registration instead of the actual WAN IP, it would save a lot of money. An internet provider (Verizon) likes to make their 3G cards show up as 10.x.x.x numbers unless you pay blood money for static IP' s. Having the DDNS service use the connecting IP as the registration name would solve several long-standing issues. Thanks!
    Carl527
    New Member
    December 13, 2013
    The ability to have multiple ports that answer SSL for a given IP address. Some clients are still using port 10443 but the new default is 443. Choice to either change existing install base or remind new users to enter a custom port.
    Maik
    New Member
    December 15, 2013
    The ability to have multiple ports that answer SSL for a given IP address. Some clients are still using port 10443 but the new default is 443. Choice to either change existing install base or remind new users to enter a custom port
    Not needed: You can create a port-forwarding VIP for that: Public IP, 443 -> 10443. This goes into a WAN to WAN policy
    ede_pfau
    SuperUser
    SuperUser
    December 14, 2013
    Using local-in policy in FOS 5.x, you should be able to redirect the destination port via VIP. Would be worth to try.
    netmin
    New Member
    December 15, 2013
    The current ssh proxy - from what documentation provides, a sort of rfc6187 (?), is not suitable for most sftp implementations (and clients). So a VIP of server-type: SSH/SFTP would be very valuable. - upload a public and private ssh key to the FGT for each VIP - authenticate firewall users by pub key, password or both - authenticate ldap users by ldap stored ssh pub key, password or both - act as a trusted host to the backend server - authenticate to the inside using VIP pub key, password or both (a.k.a. RequiredAuthentications2 on RHEL, implemented by many current SFTP solutions as well) - be able to scan/block, what' s passed through the FGT without requiring rfc6187 certs, servers or clients.
    babo
    New Member
    December 19, 2013
    I' d really like to be able to adjust the cookie name for persistence. Lync / Exchange setups require a specific custom cookie name of like MS-WSMAN or something similar. The current Fortigate product seems to let you setup cookies and cookie types, but without being able to adjust the cookie name really doesn' t help much for Microsoft products. It really caught me by surprise on a recent project. http://blogs.technet.com/b/nexthop/archive/2011/11/03/hardware-load-balancer-requirements-for-lync-server-2010.aspx
    FlashOver
    New Member
    January 10, 2014
    I would like to have a " time budget" feature to be able to sell time vouchers in hotels for example. And the ability to assign a Dialup VPN configuration to a FQDN like Cisco ASA does it really well.
    FlashOver
    New Member
    January 10, 2014
    That we can define, from which network a admin interface will respond in general, independ if the admin account is allowed to access the admin interface form this network. this could be improved within the Local In Policy. http://support.fortinet.com/forum/tm.asp?m=105154&p=1&tmode=1&smode=1