Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FGTuser
New Contributor III

FortiOS 5.0.6

5.0.6 is out share your experience please
64 REPLIES 64
ddskier

ORIGINAL: veechee GRRR!!! Why does Fortinet have something against .MSI all of a sudden? I am getting tired of opening a support ticket every time!
Sometimes I really hate Fortinet support, the tech on my support ticket isn' t getting the concept that the MSI file should be posted in the first place. Hopefully, I can finally get him to see the light.

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
FGTuser
New Contributor III

40C, 60D, 100D = OK Memory utilization is significantly lower, which is good especially on low memory model 40C. 40C history: 5.0.3 - average memory usage 76%, conserve mode several times 5.0.5 - average memory usage 66% 5.0.6 - average memory usage 53% so far
TheJaeene
Contributor

FWF 40C 5.0.6 Still no simple DNS Forwarder ...
ddskier

Really? So you can' t have the firewall take the DNS requests and forward them to another DNS server? Is that turned off on 40C and lower? Is there a model cut off?

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
pcraponi
Contributor II

For DNS forwarder: - Create a VIP using Fortigate internal interface and forward to DNS that you want... It' s always works... Example: config firewall vip edit " VIP_DNSFORWARD" set extip 192.168.1.1 -> Your Fortigate lan IP or whatever IP without use set extintf " port1" -> your LAN port set portforward enable set mappedip 8.8.8.8 -> example of external DNS set protocol udp set extport 53 set mappedport 53 next end create a firewall policy port1->port1 using this VIP as destination :) Regards, Paulo Raponi

Regards, Paulo Raponi

Regards, Paulo Raponi
TheJaeene

Hi Paulo, yes that " dirty trick" works in most cases but the point is that Fortinet dropped this BASIC Feature (the whole FGT Internal DNS Server/Forwarder) due to what they say " Performance Reasons" but they kept really unnecessary features like the " crippled" DLP on the low end models. In most scenarios where a 40C is used the Internal DNS Server/Forwarder would be much more useful than keeping the crippled DLP (without Fingerprinting). Regards, Jan
veechee

ORIGINAL: jkassner yes that " dirty trick" works in most cases but the point is that Fortinet dropped this BASIC Feature (the whole FGT Internal DNS Server/Forwarder) due to what they say " Performance Reasons" but they kept really unnecessary features like the " crippled" DLP on the low end models.
I second this opinion. Every $75 home router offers DNS forwarding. Why can a $400 firewall not?
JuhaLindstrom
New Contributor

100D Gen2. breaks web filtering. Ever since I upgraded to 5.0.6 my web filter hasn' t worked. Running debug to get status for it says the service isn' t activated. I have it present in multiple firewall rules with traffic definitely matching. And I have valid licenses and I can connect to fortiguard, with all license boxes nice & green. Also can update databases and connect via both udp 53 & 8888.. so not a connectivity issue either. //Juha
//Juha
//Juha
JuhaLindstrom

Managed to weed out this problem! There were some really weird config settings applied at some point. I haven' t got a clue where those have come, but they pretty much broke everything. Here are the offending settings: config system fortiguard set antispam-force-off enable set avquery-force-off enable set webfilter-force-off enable set webfilter-sdns-server-ip " 208.91.112.220" end config ips global set algorithm super end After changing those to defaults, the web filter was working again. Still experienced slow internet connectivity when browsing the web. Managed to track that down to dns-forwarder on the firewall. Migrated my devices into using public dns and things got back to normal. So, if you run into web filtering probs the check the fore mentioned settings in the CLI! And in case you' re using dns-forwarder, try disabling that. //Juha
//Juha
//Juha
billp
Contributor

This is frustrating. I use this also. I get the feeling that they want to subtly move Windows users to the unified Forticlient. If you want to post a ticket #, I' m willing to pile on. There must be others that use this.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Labels
Top Kudoed Authors