fnsysctl is frequently helpful in troubleshooting Fortigates, and while
its options are mentioned in the Forums here and there, no single
article lists them, and not all options are mentioned, so I wrote a post
to summarize the info.Originally posted...
Good day everyone,I added to my repo folder with FortiAnalyzer Handlers
collection ready to use.Your feedback, and ideas for new Handlers are
always welcome.Repo:
https://github.com/yuriskinfo/Fortinet-tools/tree/main/Fortianalyzer-handlers
Thanks.
Good day everyone, hope you all are doing well. I created a Github repo
where will collect scripts, tools, anything that helps in daily work
with Fortinet products.So far put a collection of Fortigate automation
stitches (21) you may find helpful. Ne...
Good day everyone, was wondering - I am reading Fortinet documentation a
lot (here in community "Tips", admin guides etc.) and sometimes stumble
on incorrect/outdated or plain typo/incorrect info. Is there a way to
alert someone on that?Thanks E.g.
h...
Good day everyone, here is a guide I wrote to harden your Fortigate VPN
SSL in additional ways.Your feedback is welcome and will be included in
the updates.Linkedin: Fortigate VPN SSL Hardening Guide Thanks P.S.
Tried to upload the original PDF but s...
Funny one. Have you looked at email headers, to see which SMTP server is
sending you the mails? It may be Fortiguard (then can't say if they
can/will want to help) or may be it is someone SMTP server and you could
find its admin to block such email s...
If you could post more of the actual log it'd easier to point in the
right direction. It may be allowed by Web Filtering but then blocked by
AppCOntrol. If you are not using Security profiles in a rule, only FQDN
*.bitdefender, may be DNS resolving b...
Blocking .exe files download is pretty trivial configuration in
Fortigate EXCEPT for it to be effective you HAVE to enable Deep SSL
Inspection as 99% web traffic (including file downloads) today are via
HTTPS. Here is someone did video of how to conf...
Think of each VDOM as a standalone physical Fortigates connected to each
other with Inter-VDOM links and do policies/routing accordingly. You can
create a single VIP on WAN interface in root VDOM pointing to IP address
of the server in the another VD...