We just got FortiCloud Premium license to manage our customer's FTNT
cloud services like EMS Cloud under our master account/org. But I'm
struggling to set those customers under "Organizations". Originally I
thought we would have to create an Sub-OU p...
Does anybody know the reason why it skipped 7.x.x and jumped from 6.6.x
to 8.0.0?And, most importantly what is the major change with this new
version in the software structure compared to any 6.6.xs? What's new
section in the release notes doesn't in...
I saw some conversation about stopping auto-upgrade on FGTs before after
7.2.8. And, we're doing it manually for those FGTs that are NOT managed
by FMG. Then when we tried the same for those managed by FMG, the change
was rejected because it's manage...
This version of FMG was released last week and now CVE-2024-47575 is
released as well.https://www.fortiguard.com/psirt/FG-IR-24-423However,
the release notes doesn't have anything in the resolved issue section.
Does this actually have the vulnerabili...
A basic question: Would Websocket app (TCP 443) traffic be filtered by a
policy with a Web Filter profile? Or do we need to match it with
Application Control in a separate policy before or after the web filter
policy?Thanks, Toshi
That screen shot shows not only DH group change but also IKEv1->IKEv2
conversion. If that's true, the client side needs to change to IKEv2 as
well.Toshi
The topology is as in the KB @AEK pointed you to, but only difference is
in your case those cisco switches are stacked, which make them as a
single switch. Therefore, all four ports in the KB example, need to have
a different number each. Of course, ...
By the way, when you test it with another device, like a switch, then
doesn't work, don't blame this Cisco SFP+ on the FGT immediately. The
other end might have a compatibility issue unless its a Cisco switch + a
Cisco SFP+. Toshi
If you already have them you just need to try them, right? Then if they
don't work, you have to order different ones. But at that time, I
recommend FTNT compatible ones since you'll order new ones. I'm almost
sure they just work fine though.You spent...
Most likely the source IP of the ping packets is outside of phase2
network selector(s). Use "exe ping-option source
[the_LAN_interface_IP_inside_of_the_network_selector]". Then ping
packets pick that IP for the source IP.If you're curious what source...