My networks talk to a prisoner, help.

Help, my networks talk to a prisoner. This was a funny one - client saw lots of DNS queries passing the Fortigate addressed at the prisoner.iana.org and was worried what this was about. No worry - it just means (misconfigured) clients in the LAN are trying to get PTR records …



sFlow in Fortigate disables Hardware Acceleration

Do not use sFlow in Fortigate - use Netflow instead I was approached last month by 2 unrelated Fortigate admins with the same problem - slow performance of otherwise very beafy Fortigate models. After some digging in the configuration the culprit was found - there was enabled on WAN interface sFlow. sflow collects …



Fortinet products Fortigate Fortiweb Fortimail and others online demo access details

Be it to learn the interface or preparing for NSE 5, 6, 7 exams, having the access to the real device is the best way to retain the information. Fortinet make available online access to all of their products for demo purposes, all for free. If not mentioned otherwise, the …



Transfer FortiTokens Mobile (FTM) between Fortigates - visual guide.

Table of Contents Introduction Steps in transferring the tokens Steps in transferring the tokens with screenshots Open a ticket to the Customer Service Once CS in the ticket confirm the license was transferred Debug Resources Introduction You may need to transfer Mobile FortiTokens from the failed Fortigate, on which you …



Tips on Upgrading Fortigate in HA Cluster

Table of Contents Upgrade - what actually happens Tips on HA upgrades About rollback/downgrade Troubleshooting tips Upgrade - what actually happens When upgrading a Fortigate HA Cluster the following happens: Admin uploads new FortiOS image via GUI to the Active member. Active Fortigate verifies validity of the image (tampered/broken image …



Fortinet Support - Tips on opening tickets with their TAC to make them more effective

Table of Contents Introduction There are 2 ways to open a ticket - via phone, and on the web, use both of them, if needed. Have someone NSE 4 certified to open the ticket - gets you straight to the Level 2 Support. Ongoing communication - phone or email? If you work for …



Fortigate cannot delete VDOM or other object in use problem solution

I file it under "feature, not a bug" category - you are trying to delete some object, say VDOM, which is NOT actually used anywhere, but the Fortigate throws an error command fail. Return code -23. Fortigate keeps reference count of all objects at all times, and if for any given …



Fortigate as DNS authoritative server with DNS database

Table of Contents Configuration Debug and diagnostics diag test application dnsproxy 8 diag test application dnsproxy 3 diagnose test app dnsproxy 2 diagnose test app dnsproxy 7 diagnose test app dnsproxy 6 diagnose test app dnsproxy 9 Windows DNS commands dnscmd server-name-or-IP /zoneinfo domain-name dnscmd server-name-or-IP /ZoneResetSecondaries domain-name dnscmd server-name-or-IP …



macOS mdfind examples cheat sheet

Table of Contents Introduction Find files with a given word in it Search for a word in file names only, not their contents Find a file with multiple keywords in its name Limit search to specific file format(s) Look up folder names Search for an exact match Search in …



tcpdump now shows interface names in its output, finally

Table of Contents Resources Actually it is not news - it happened with the new 4.99 tcpdump version starting 2 years ago. But most binary distributions still lack this version. So, I had to install it from sources even on the RHEL 9, the newest version. The steps are simple …