Hi all,Running 6.2.7, i'm trying to apply two different session profiles
in both IP policies, but with same source IPResult: always match the
first IP policy in order; it seems that the match is triggered just by
source IP and ignore everything else ...
Hello everybody A customer FAZ 1000D running 6.0.8 is showing a
permanent 100% disk I/O usage penalizing the whole operation since a
couple of days( widget screenshot attached) Could anyone please share
some strategies to attack the issue?Who would b...
Hello,Just asking for experiences and comments on the topic.Is anyone
importing Acunetix vulnerability scan results into Fortiweb? Could you
elaborate how do you integrate the xml file within the
configuration?Such integration, does depends on the Fo...
Hello everybody, There's available in-a-box the
'number-of-session-timeline" dataset querying Traffic log this way:
select $flex_timescale(timestamp) as hodex, sum(sessions) as sessions
from ###(select $flex_timestamp as timestamp, count(*) as sessio...
Hello all,in order to obtain a profile of bandwidth usage vs specific
FortiAPs, we found that all relevant an interesting values to build the
dataset are in Traffic Log.There's also a builtin report with
"Top-AP-By-Bandwidth".But, that report shows u...
Hello ThibautI'm sorry this issue continues; I´d suggest to open a TAC
ticket in order to troubleshoot your specific scenarioNo problem with
the 'solved'status you made, I guess that it can be removed, or
moderator could do thatbest regards
Hello ThibautIf your deploy mode is content routing , you should disable
HTTP/2 in the server pool config(and enabled in the server
policy)Explanation is: even clients use HTTP/2 , the traffic
Fortiweb<->server web must be HTTP; because of that you d...
Hello rabbitoyou shouldn't have any problem with smtp authentication.
Just define an authentication profile against your backend email server
and refer it in your incoming recipient policies (or IP policies if need
to)This is well documented in FML a...
HelloFirst comment: do you have yet equipment running Openssl old
deprecated version 1.0.1/1.0.2?If so, use IPS signatures in a IPS
profile with action block (reset/quarantine - your choice) for the
signature OpenSSL.TLS.Heartbeat.Information.Disclos...
Hello AlexAs with another products , if you run those products under non
officially supported hypervisor, FTNT TAC support refuses to pick up the
case;(even if the device is able to run in a non-supported environment
stated in Release Notes for each ...