Hi together, we started to play a little bit with IPv6. For cost reasons
we only use an internet connection with no static assigned address range
on branch offices so we have to use prefix delegation. The provider
delegates a /56 network which seems ...
Hi together, we are actually implementing Forti SRA for remote access
for our admins. We installed the SRA VM in our DMZ, only one interface
with a RFC1918 IP address. On the Fortigate in the datacenter we have a
VIP forwarding an external IP to the ...
Hi together, acutally I am dealing on the following issue:We tried to
setup a remote IPSec VPN as SSL-VPN wont't be supported in the
future.The connection establishes, routes are configured on the client
correctly. There are also packets sent from th...
Hi together, I have the following issue concerning the described network
structure:Two main sites which are connected to our MPLS-Network. Other
sites are also connected via MPLS. Each MPLS site has a MPLS-Router
exchanging BGP-Routes with the Site-F...
Hey everybody, I hope you can help me. I've got the problem, that
assigning a policy package is rarely possible on our FortiManager. I
first thought that the login is the problem (the last times I was only
able to assign policy packages to a firewall...
Hi Jean-Philippe, Thanks for your reply!Unfortunately this is not
successful. ND-Proxy is already deactivated. The interface config is
listed up in the first post and as far as I can see there should be no
configurations causing the NS messages. Firm...
Thanks for your reply! We followed the guide when setting it up. Is it
necessary to use two different IP addresses? One for the physical
interface (management gui) and one different for the vip (web portal)?
The admin guide tells to enable synchroniz...
We have physical access to the MLPS routers but not configuration
access. Our provider responded they use local preference for the path so
AS prepending unfortunately won't work. They offered to manually
configure the remote sites on the MPLS routers...
Toshi: As we can't hot-cut due to our network size and criticaility this
won't work.Nathan: network topology like this (other VPN-Locations as
site 2, other MPLS-Locations as site 1).Example: Connection (or answer)
of site 1 to site 2: site 1 sends t...