Articles tagged with #Fortigate




Fortigate DNS Filter - All You Need to Know (almost)

Table of Contents Intro Local/Static Domain Filter Remote Category Fortiguard-based Categories Domains Feed IP addresses feed DNS Translation Applying the DNS Filter Profile on the Fortigate Interface Protecting Internal DNS Server Inspecting Encrypted DNS Traffic Debug and Verification Intro Few facts to remember: The DNS query/response traffic HAS …



Fortigate Web Filtering - All You Need to Know

Table of Contents Important facts to know Static URL Filter FortiGuard Category based Web filtering Category cache verification Action - Authenticate Allow User Override Usage Quota Custom/local Categories and Web rating Override Remote Category filter for external threat feed Search Engines Safe Search and Vimeo Rate by both IP Address …



Fortigate DLP file filtering and more examples

Table of Contents Important facts Block downloading PDF and MP4 files (FortiOS up to 7.2.4) File Filter (all versions of FortiOS, no lic needed) Fortigate up to 7.2.4 Fortigate 7.2.4 or newer Block uploading/downloading documents containing SSN or/and Credit Card numbers (7 …



Fortigate HA cluster FortiOS upgrade in pictures

I already wrote tips for upgrading your Fortigate HA cluster https://yurisk.info/2023/06/18/tips-on-upgrading-fortigate-in-ha-cluster/ , but didn’t include screenshots of the upgrade to illustrate what actually happens. Today I fix that - below are screenshots of the cluster upgrade I did, with description. It will be helpful to …



Tips for Network Engineers to make life easier

Not technical, but (hopefully) helpful list of tips learned the hard way by myself or from others before me. Color code your Terminal/CLI sessions. All terminals have this feature, I use SecureCRT and change background of the saved sessions according to the importance - backbone black, production - gray, lab - light …



Fortinet products code names used by community

Every technical field has its own jargon/abbreviations and it is true for the Fortinet world as well. The picture below lists major products with their code names as used by the community. I also write cheat sheets/scripts/guides to help in daily work, so make sure to check …



Debug Fortianalyzer mail notifications sending

Table of Contents Sending test mail from FAZ Enable real-time debug Restart fazmaild mail daemon on FAZ Sending mails via default Frotinet servers Sending test mail from FAZ FAZ has a command to actually send a test mail that checks if sending mails to/via the configured mail server works …



Create a custom Fortianalyzer report to show number of logs per Fortigate and per policy

Why did I do such report? Some of our clients are using VM Fortianalyzer (FAZ) which comes with the volume licensing of received logs, and so alerts frequently on logs intake exceeding this license. Other than buying additional license, I can drill down with the FAZ help on top policies …



Fortigate - revert configuration as a safety measure, analog to Cisco reload in, or Juniper commit confirmed

Table of Contents Introduction Step by step instructions for CLI Instructions for GUI Introduction I want to talk today about the safety switch the Fortigate has for us when changing its configuration and something goes wrong. Most reputable vendors have such rollback-if-sh*t-happens - Juniper has commit confirmed , Cisco routers …



Fortigate fnsysctl command options with examples

Table of Contents fnsysctl ifconfig fnsysctl ls fnsysctl cat fnsysctl date fnsysctl df fnsysctl du fnsysctl pwd fnsysctl ps fnsysctl kill fnsysctl killall fnsysctl mv fnsysctl printenv fnsysctl grep Important facts about fnsysctl command: You have to log in with a user having super_admin profile. For VM Fortigate, it has …