Hi, Basic version was present in 6.0.x firewall policy > source > device
and able to pick up device and device category. The whole concept of
device/devices category has disappeared which make little sense
especially with FortiGuard IoT service which...
Hi, What exactly is the point of subscribing to Fortiguard IoT with
FortiOS 6.4 as you can't apply any firewall policy based on device type
(like you could on 6.0). You would get slightly more detail in FortiView
but that's it. If you want anything e...
Hi, FGT60E, 6.0.1, Proxy mode. AV doesn't pick up eicar test file on
IPv6 traffic, tried with both proxy and flow mode AV profile (on a proxy
mode appliance). Unless it's a very subtile configuration issue (which I
doubt, as testing IPv6, so one rule...
Hi, Configured with self-signed trusted root CA (same root CA been used
since 5.2 without problem) Strange issue on 5.6 (on 200D) proxy-mode,
after a while (few hours) it seems that SSL Interception generated
certificate are not valid.Particularly vi...
Hi, Found a massive limitation in 5.6 NGFW mode: You can only configure
SSL Interception profile globally in Settings.If you got (closed)
devices that doesn't allow to add trusted root certificate you can't
force them to use a different (SSL Cert Ins...
Hi, Had to upgrade to 6.0.x to finally get this working. There is a
major change with creation of PPPoX profile separate from interface and
need to move the IPv6 section there, then assign the ppp profile to the
interface (or the other way round?). L...
Hi, Looks like devices are doing a (small) come back in
6.2.1:https://docs.fortinet.com/document/fortigate/6.2.1/new-features/370579
If I read correctly all predefined group and detection are still absent
(let's hope and wait for 6.2.2) but categorie...
Hi James, While in theory it's a good idea, in reality it's impossible.
Even without MAC randomisation, Apple MACs are impossible to group. I
had a quick look before replying and beside a batch of iPhone X bought
all together none of them have the sa...
Same here. James_G wrote:I have emailed my account manager at Fortinet
to voice concern about the removal of custom devices and groups. I
suggest anyone else with concerns does the same; as a forum post,
however long, is not likely to affect any real...