How to request Google, Cloudflare, and OpenDNS/Umbrella DNS servers cache clearing for your domain records

It is rare for these well-known DNS providers to cause problems to your domain records, but everything is possible. More often though, you may need to refresh some DNS record of your domain sooner than its TTL expires. Below you will find links how to do so for the aforementioned …



Cisco router - disconnect VTY user forcefully without reloading the router

Today's log. - Alert on a suspicious connection via ssh to the VTY line of the Cisco ISR 1100 router. - Logged in to the router, saw an established connection from IP belonging to Chinanet ISP (the router is in Israel) to the port 22. The router was compromised as someone removed …



Check Point Certified Troubleshooting Administrator (CCTA) 156-580 Exam Preparation Tips and Impressions

The following, I hope, will help you to prepare better for the exam as there is no information I could find anywhere. Note Links to all the resources I mention in the text are at the end. Also, for obvious reasons this article does not contain actual questions from the …



You CAN and probably should rename/delete the default admin user on Fortigate, here is how

Many best practices in security and regulations (PCI-DSS, NIST 800-53) demand or recommend renaming/deleting the default administrative accounts that come with the equipment. And every Fortinet product comes with the admin account built-in. Some people are afraid to lose administrative access by such changes, but with the Fortinet Fortigate …



Fortigate - doing SNAT and DNAT on the same traffic in traditional and Central NAT modes how-to

Table of Contents Translate source IP address (SNAT) and Destination IP (DNAT) in usual, non-Central NAT mode Configuration Verification: Translate Source and Destination IP addresses when the Central NAT is enabled Configuration Verification CLI configuration Related: When the situation requires to translate both - source and destination addresses in incoming packets …



Checkpoint API tutorial, part 1 - getting started

Table of Contents Introduction Enable API remote access and verify Create authenticated session, record session identifier Create a login session Create a Host object and publish the result Verification In this, 1st part of tutorial series, I will show how to enable remote access to API on Checkpoint Management Server …



Fortianalyzer diagnose and debug cheat sheet

Table of Contents General Health Communication debug Logs from devices Licensing Example debug session on Fortianalyzer Show connected to the FAZ devices General state of FAZ (version, serial, HA status, license status) Performance stats (appliance FAZ will have more data) Running processes and CPU load Logging devices with quotas for …



Fortianalyzer Custom Reports from Custom Datasets Visual Guide How-to

In this short visual guide I will show how to create a custom report from your own SQL query in Fortianalyzer. Fortianalyzer comes with plethora of datasets and reports defined - more than 800. My issue with all of them - they are overly complex and are geared more towards C-level management …



Fortigate FortiOS 7.0 is out - what's new Visual Guide

On 30th of March Fortinet released FortiOS 7.0 for all the supported models (alas, many D series Fortigates like 500D, are not supported), and here is the visual walkthrough of changes that can be seen in GUI. Note All the videos below come without sound. New color themes were …



Fortigate VM Evaluation License 15 Days Limitations Explained

Update August 2022: All the said below is still true, but starting with FortiOS 7.2.1 the process of issuing the evaluation license has changed. So, after reading this article, make sure to read this one as well: Fortigate free VM Evaluation License is now permanent, not limited to …