Hi FortiGate adminsAny one used the "none" interface as SD-WAN member?I
wonder if we can use it like a black hole, like when we don't want to
route some traffic through any SD-WAN members when some SD-WAN members
are down (not to fall in the implicit...
Hi FortiGate adminFrom today the recommended release has changed from
7.0.14 to
7.2.7.https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-FortiOS/ta-p/227178
Hi FG adminsOn my FortiGate 7.2.3, freshly transferred to another
FortiCloud account successfully, when I click force update license &
signatures it doesn't work and it shows the below output.Any idea on
what can be the issue before I open a ticket?u...
Hello Fortinet teamIs this tech tip up to date? It says recommended FOS
release is still 7.0.14, while 7.0.15 is here since a week and 7.2 is
mature since two
months.https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-Release-for-Fo...
Hi FortiSwitch integratorsIf you have experience in this topic +
knowledge in both Cisco & FortiSwitch, can you enumerate the main
problems that we may encounter when we migrate Cisco core switch for
FortiSwitch? I mean in terms of capabilities and m...
Hi AKristofThanks for your reply.However I made a mistake.. I forgot
that with firewall policy it is not possible since with SD-WAN we can't
select a member as destination interface.
Hi AlexisBoth are essential and complementary. Do not neglect any of
them or think that one can replace the other. Firewall to protect at
perimeter level like unauthorized access, and AV protects the endpoint
from inside.
I don't know about this default behavior of FNAC. But I just know that
hosts in isolation should not be able to access anything (including FNAC
mgmt) except some necessary repo (like AV, Win update and so). And I
know that this should be denied at fi...
Both deep inspection and simple certificate inspection can block pages
due to certificate issue, like expired certificate, untrusted
certificate and so, but this is tunable in the related profile and you
can.You start by cloning the default profiles,...