Hi all I already opened a support ticket for this - however, I'd like to
have some input (maybe others had the same issue?). Situation:We deploy
fortigate (60f and 100f), currently with 6.4.9, as clusters.The (single)
cluster link is physical and dir...
Hello all I have an odd issue with a Fortigate VM-64 (6.4.10) in
Azure.The virtual machine and azure configuration is not maintained by
me so I have no real detailed information.We tested the restore function
of Azure and after restorting the fortiga...
Hello everyone I have two virtual Fortigates (one in Azure, one on
ESXi). Both of them have local disks and both are configured to send the
logs to a Fortianalyzer. Both Fortigates are on 6.4.9. When enabling
disk logging (config log disk setting - s...
Dear all We have a Fortigate VM in Azure (6.4.10) which is supposed to
have about six (6) IPSec tunnels to ZScaler.The reason for that many
tunnels: Each tunnel is supposed to only offer 400 Mbit/s (we tested 1
Gbit/s, but its still not enough). This...
Hello all Our clients have a phone software installed which needs
internet connection.There are several firewall policies in place to
allow said phone software to connect to several internet places. The
producer of the phone software needs us to allo...
Good day Adrian Thank you SO much for your reply.I didn't add the
underlay (internet connection) as SDWAN zone. I first tried to just add
the IPsec tunnels to a SD-WAN Zone and gave them (in the SD-WAN-Zone as
members) a fake/dummy IP address. And th...
Thank you very much for the information about the ISDB, much
appreciated.As for the client - we will investigate some more. The web
based application uses several wildcard domains and those are working
(meaning: they are getting populated with IP add...
Hello gfleming The clients (laptops - no phones per se) use an internal
DNS server.Those internal DNS servers are reachable over a VPN that is
established on the branch fortigate. The reason why I think some of the
DNS requests get "hidden" of sorts ...
Hello abarushka My apologies:I was refereing to the "out of band
Management" IP addresses which are (partially) configured in "system
ha". Those are not mentioned in the documentation when you are having a
single box (those are only mentioned in the ...