#  @Roversword Roversword
Roversword posts on Reddit about i need, in a, ip, lenovo the most. They currently have [-----] followers and [--] posts still getting attention that total [--] engagements in the last [--] hours.
### Engagements: [--] [#](/creator/reddit::t2_9lbj5/interactions)

- [--] Week [---] +18%
- [--] Month [-----] +571%
- [--] Months [-----] +415%
- [--] Year [-----] +841%
### Mentions: [--] [#](/creator/reddit::t2_9lbj5/posts_active)

- [--] Month [--] -20%
- [--] Months [--] +7.10%
- [--] Year [--] +7.70%
### Followers: [-----] [#](/creator/reddit::t2_9lbj5/followers)

- [--] Months [-----] +8%
- [--] Year [-----] +44%
### CreatorRank: [---------] [#](/creator/reddit::t2_9lbj5/influencer_rank)

### Social Influence
**Social category influence**
[technology brands](/list/technology-brands) [stocks](/list/stocks) [social networks](/list/social-networks) [finance](/list/finance)
**Social topic influence**
[i need](/topic/i-need), [in a](/topic/in-a), [ip](/topic/ip), [lenovo](/topic/lenovo), [has been](/topic/has-been), [6969](/topic/6969), [azure](/topic/azure), [end of](/topic/end-of), [the only](/topic/the-only), [youtube](/topic/youtube)
**Top accounts mentioned or mentioned by**
[@corebootorgmessagev32ie5gkjotigxu4ewf7zytfl5wnw4tzhttpsmailcorebootorghyperkittylistcoreboot](/creator/undefined) [@corebootorgmessagev32ie5gkjotigxu4ewf7zytfl5wnw4tz](/creator/undefined)
**Top assets mentioned**
[Alphabet Inc Class A (GOOGL)](/topic/google)
### Top Social Posts
Top posts by engagements in the last [--] hours
"Missing configuration after restore of azure vm (fortigate vm) Hello all I have an odd issue with a Fortigate VM-64 (6.4.10) in Azure. The virtual machine and azure configuration is not maintained by me so I have no real detailed information. We tested the restore function of Azure and after restoring the fortigate vm from the snapshot there were configuration missing. In my case it was the configuration of a port (it was there and up but the correct IP was missing) a missing static route which was connected to said port and a firewall policy. The fortimanager was correctly configured and in"
[Reddit Link](https://redd.it/11m01dm) 2023-03-08T16:00Z [---] followers, [--] engagements
"HA cluster "split brain" when downstream cisco stack reloads Hi all I already opened a support ticket for this - however I'd like to have some input (maybe others had the same issue). **Situation:**We deploy fortigate (60f and 100f) currently with 6.4.9 as clusters. The (single) HA/cluster link/cable is physical and direct (without any switches etc.).Downstream there is a cisco stack with two cisco switch as members.Fortigate cluter node A is connected to cisco stack member A and fortigate cluster node B ist connected to cisco stack member B.This connection is made with a single copper cable"
[Reddit Link](https://redd.it/13eh0x7) 2023-05-11T08:22Z [---] followers, [--] engagements
"Default value of firewall policy for DENY/ACCEPT created on fortimanager"
[Reddit Link](https://redd.it/16yrbd2) 2023-10-03T13:01Z [---] followers, [----] engagements
"Routing (BGP) of location with two active VPNs to hubs that exchange routing info"
[Reddit Link](https://redd.it/17gv4kr) 2023-10-26T12:15Z [---] followers, [----] engagements
"Default value of firewall policy for DENY/ACCEPT created on fortimanager Hi all This might be a silly question: Is there an option in FortiMANAGER where I can change the default value of "Action" in a newly created firewall policy. When creating a new firewall policy in a policy package on fortimanager the default value of "Action" is "DENY". I would like to set it on "ACCEPT" Is there a way to do this Yes I am aware that this is potentially a risk - however we have tons of SLAs breached monthly because we forget to set it from DENY to ACCEPT (as we have nearly zero DENY-Rules). Thanks a lot."
[Reddit Link](https://redd.it/16yrbd2) 2023-10-03T13:01Z [----] followers, [--] engagements
"Routing (BGP) of location with two active VPNs to hubs that exchange routing info"
[Reddit Link](https://redd.it/17gv4kr) 2023-10-26T12:15Z [---] followers, [----] engagements
"diagnose traffictest on a Fortigate 600F with 6.4.14"
[Reddit Link](https://redd.it/180bks8) 2023-11-21T07:36Z [---] followers, [----] engagements
"ADVPN and firewall policies on the spokes Hello all This might be a stupid question - however I have simply no real ADVPN experience (some in theorie). I am unable to find an answer to my question likely because I am using the wrong keywords or such so I am asking you all: If spoke A and spoke B establish a direct VPN to each other due to ADVPN (which is dynamic and can happen on demand and all that) - how does the ruleset (firewall policy) look like for that particular connection look on spoke A and B Is ADVPN "only" doing the VPN and we need to make sure the appropriate firewall policies"
[Reddit Link](https://redd.it/18fptn5) 2023-12-11T08:25Z [---] followers, [----] engagements
"Hardware advice for pfsense and at least 2x [--] Gbit/s RJ45/copper interfaces"
[Reddit Link](https://redd.it/18i4a65) 2023-12-14T08:42Z [--] followers, [--] engagements
"Compatibility list for FP421E (FortiAPs) We still have some FP421E active which are managed by a fortigate.We are aware that those are end of support end of sale end of everything. Unfortunately I have difficulties to find an official (old) compatibility list with these FortiAPs listed to find out how far I can update the managing fortigate in order to have those FP421E (on 6.4.9) still being supprted (fortios wise) so that we can prepare the fortigate for newer FortiAP models. So far in the compatibiilty lists I found the only legacy models mentioned are the FAP221 and FAP223 but no FP421E."
[Reddit Link](https://redd.it/1agcjwc) 2024-02-01T14:41Z [----] followers, [--] engagements
"surprisingly passed after 125Q and a little less than 1.5h Hi all About three and half hour ago my CISSP exam stopped after (or with) the 125th questions - after using about 1.5h of the exam time. Honestly I was devastated because I had a rather terrible feeling about it1. And to my surprise I (provisionally) passed the exam. I used mostly youtube videos (crams) and learnzapp - accordingly to my kindle I only read 11% of the OSG. [--] As others in this subreddit already mentioned - it ended up less about knowledge but rather about actually understanding the question asked and deciphering what"
[Reddit Link](https://redd.it/1b32wwx) 2024-02-29T15:24Z [----] followers, [--] engagements
"Changing HA cluster password in an existing cluter without physical access Hello all This might sound weird but.I have been given a remote fortigate cluster which I have admin access to and which I need to configure (but there was first a third party involved that configured the bare minimum like admin access and cluster ha config). I would like to change the HA password those two physical fortigates use and I am not sure how to go about it (and I don't have a lab at hand to test it). Are those steps correct [--]. Login into primary node and then use its CLI to log into secondary node [--]. Change"
[Reddit Link](https://redd.it/1bbgtqf) 2024-03-10T18:12Z [----] followers, [--] engagements
"per device config of a single shared traffic shaper (on FortiManager) Hi all Reference: https://www.reddit.com/r/fortinet/comments/ea4yoa/fortimanager_new_feature_request_perdevice_mapped/(https://www.reddit.com/r/fortinet/comments/ea4yoa/fortimanager_new_feature_request_perdevice_mapped/) which is four years old. I have the same issue - several fortigates that use the same named traffic shaper however have different values within (in my example its the maximum bandwith). We would love to centralise that on the Fortimanager (7.0.11) and would love to use one single traffic shaper for that. In"
[Reddit Link](https://redd.it/1bptl1d) 2024-03-28T11:47Z [----] followers, [--] engagements
"ISDB search and "obsolete" entries Hi all I am a little stumped where to start my search here. One location has 6.4.x running and a ISDB object in a static routing entry. Another (new) location should get the same static routing entries but is running 7.0.x. Turns out that Microsoft Intune (ID 327886) appears to be obsolete and I can't find it anywhere in 7.0.x database. So.what can I do here How can I find out whether a ISDB object/entry has just change name or ID or whether it has been replaced etc. I need the same services routed and I can't find any intune stuff (however I might just be"
[Reddit Link](https://redd.it/1byt9l6) 2024-04-08T09:07Z [--] followers, [--] engagements
"Windows [--] enrollment - what internet rules are needed Hello all This will likely be a cross post. We have a customer who rolls out Windows [--] at their locations. We don't have much details unfortunately. It seems as if those devices need internet access to be enrolled activated etc. and the customer hits a wall (blocked ports or IPs) as the internet is obviously not completely open for the corporate network. So far we found out that adding a rule with "Microsoft-Web" (ISDB) as destination seems to work. For the live of me my google fu fails me - I don't find nothing concerning win11 and"
[Reddit Link](https://redd.it/1c59ewi) 2024-04-16T06:41Z [--] followers, [--] engagements
"BGP prefix-list (or route-map) that denies all Hi all We want to introduce a new connection and that new connection will be propagating/advertising its networks/prefixes via BGP to us. As a first step we would like NOT to process those information from the new connection so that we can have a look at them first (checking first with "received-routes") and then build the future correct new prefix-list step by step. However I am not sure about this. * An empty prefix-list would likely allow everything so that will not work the way I want * Would it be sufficient to have one single deny statement"
[Reddit Link](https://redd.it/1cftx80) 2024-04-29T08:25Z [----] followers, [--] engagements
"Explicit Proxy on FGT - what does "Default Firewall Policy Action" do Hi all I can't wrap my head around this one and I am still reading the documentations (and what ever I find online) but to no avail. In the Explicit Proxy feature of the Fortigate there is a parameter called "Default Firewall Policy Action" which can be set to "Accept" or "Deny". However I don't understand what a) it actually does b) what it does when its on accept or on deny and c) what is being influenced by this setting. Does anyone have any insights for me Side note: In the official documentation"
[Reddit Link](https://redd.it/1cj41wz) 2024-05-03T09:02Z [----] followers, [--] engagements
"Funny wifi issues in a large building Hi all I have an issue with Wifi which I can't wrap my head around it. **Setup:** There is a large building with more than [--] FortiAPs (same models; FAP231F). Those have been connected to FortiSwtiches and handled with tunnel mode. The Fortigate has a dedicated VLAN and DHCP on this VLAN to give those FortiAP an internal IP. And they are managed by the Fortigate. They all had the same profile for this specific coutry (for testing purposes later we made a "default" one). They are all running the same firmware (7.0.7 at first downgraded temporarily to"
[Reddit Link](https://redd.it/1cm4pr9) 2024-05-07T05:52Z [----] followers, [--] engagements
"Issues with auth in explicit proxy feature in fgt100f (6.4.15) Dear all I have configured an explicit proxy on at fgt100F with 6.4.15. The goal is to use kerberos as an authentication for the users. Unfortunately this doesn't work yet. To start troubleshooting I disabled the autbentication need on the proxy policy (all where allowed then without need of login credentiaks) and let the customer test. We were able to verify that the explicit proxy works (if authentication is not needed). Then I added the authentication again in the proxy policy and the customer confirms the browser receives a"
[Reddit Link](https://redd.it/1cn0okb) 2024-05-08T09:51Z [----] followers, [--] engagements
"Additional LAN interface which can also be used as Mgmt interface Hi all I received hardware with opnsense pre-installed - so I need to configure it. The WAN and LAN are 10Gbps SFP modules and I wanted to add another RJ45 interface so I can use it as "out of band" management beforehand. The management works on the LAN interface perfectly fine (was able to do the wizard and all other configs) but the LAN works on 192.168.x.0/24 which actually is my network. I configured an unused interface to 192.168.x+1.0/29 and added DHCP - this works so far (I get an IP on the laptop I am using) however I"
[Reddit Link](https://redd.it/1cwc7ar) 2024-05-20T10:23Z [---] followers, [--] engagements
"prefix list that does NOT advertise anything (BGP) Hi all Just for sanity's sake: I am about to establish a new BGP neighborship and the customer wants to make sure nothing happens at the start. I need to surpress all adverstisement from my side to the customer and surpress all implementations into my routing table of the prefixes they send me. So that is basically the following prefix-list (for both directions) right config router prefix-list edit "DENY_ALL" config rule edit [--] set prefix 0.0.0.0/0(http://0.0.0.0/0) set le [--] set action deny next end next end Cheers fortinet fortinet"
[Reddit Link](https://redd.it/1d1mxef) 2024-05-27T08:34Z [--] followers, [--] engagements
"Can a wazuh agent on a device/asset see or discover an unmanaged device Hi all My google fu seems off I can't find definitive answer to my questions: * Can a wazuh agent installed on an asset see other unmanaged (without wazuh agent) devices and report them Basically I would love if wazuh would tell me "hey there are some devices which are in your network that have no wazuh client you know about them". And then preferably allow me to exclude them from reports (after I have checked and dealt with them). Cheers Wazuh Wazuh"
[Reddit Link](https://redd.it/1er1j8b) 2024-08-13T07:14Z [---] followers, [--] engagements
"Dedicated Server - disable enemies (after starting it/playing it) Dear all I am running a dedicated server on linux (linux-gsm) and would like to disable enemies now (after playing for about 90h). Is this possible And if so what variable in the config-file would I need to change or add Thanks a lot SatisfactoryGame SatisfactoryGame"
[Reddit Link](https://redd.it/1ghwei8) 2024-11-02T13:26Z [----] followers, [--] engagements
"Problems with one single PC (win 11) and 2.5Gbit/s connection (LAN) Hi everyone I am actually completely out of ideas and I need help. A few months ago we got fiber to the home (10 Gbit/s). My internal equipment was for [--] Gbit/s (switches and such). My linux computer worked fine my wife's windows [--] computer worked fine. I then changed the equipment to unify switches (**Enterprise [--] PoE - https://eu.store.ui.com/eu/en/category/switching-utility/products/usw-enterprise-8-poe**) that offer [---] Gbit/s interfaces. Then the trouble started for my wife. She had non-stop network failures (was"
[Reddit Link](https://redd.it/1goxys2) 2024-11-11T17:37Z [----] followers, [--] engagements
"Download all (newest) revisions/backups of Fortigates on a Fortimanager Hi all Is there a way to download the latest revision (backups/conf-file) of all Fortigates on a Fortimanager in one single download (opposed to clicking every single Fortimanager and downloading them one by one) Thank you very much fortinet fortinet"
[Reddit Link](https://redd.it/1guy2qr) 2024-11-19T14:14Z [--] followers, [--] engagements
"Reset passwords of local SSL VPN users Hi all So far I was only confronted with SSL VPN user via Radius/AD etc. but not with local ones. Is there a way to reset the password of local users (which can use sslvpn) so that they need to change their password No Web-mode activated. only tunnel mode. Thank you. fortinet fortinet"
[Reddit Link](https://redd.it/1guyal4) 2024-11-19T14:24Z [----] followers, [--] engagements
"Sanity Check: Is coreboot able to disable E-Cores on Intel CPUs Hello everybody I need a sanity check (am I understanding it correctl) I am refering to these two posts: * https://mail.coreboot.org/hyperkitty/list/coreboot@coreboot.org/message/V32IE5GKJOTIGXU4EWF7ZYTFL5WNW4TZ/(https://mail.coreboot.org/hyperkitty/list/coreboot@coreboot.org/message/V32IE5GKJOTIGXU4EWF7ZYTFL5WNW4TZ/) * https://review.coreboot.org/c/coreboot/+/73790(https://review.coreboot.org/c/coreboot/+/73790) Am I correct to understand that coreboot is (now) capable of disabling E-Cores (and P-Cores) on (all available) Intel"
[Reddit Link](https://redd.it/1h2j7bu) 2024-11-29T10:47Z [----] followers, [--] engagements
"Hardware recommendation: Mini PCs with coreboot Dear all My apologies bothering you with this - please let me know if there are other subreddits I should ask. I am looking for a mini PC (size of approx. a NUC Geekom Minisforum etc.) that has enough power to run two VMs at a time and the OS (Linux distribution) and.uses preferably coreboot. As I understand e-cores are still an issue with virtualisation outside windows [--] and AMD isn't an option as it is not really suppored by coreboot yet (as far as I understood). So my question is - do you have any recommendation for a NUC sized mini PC that."
[Reddit Link](https://redd.it/1h2j9yu) 2024-11-29T10:52Z [----] followers, [--] engagements
"Problem with second screen and thinkpad docking station Hi all Sorry I am not sure where to start investigating with this problem. My second screen at home (home office) turns of randomly with "no signal" (without warning of sleep mode or anything). Even when I am actually doing something actively on said screen. * I have a Lenovo Thinkpad T14 with windows [--] issued by my employer. * The T14 is attached (via USB-C) to a thinkpad docking station (Lenovo ThinkPad Hybrid USB-C / -A llisted as Docktype 40AF with firmware 1.0.40 from 2024-11-28). * The docking station is attached to both screens"
[Reddit Link](https://redd.it/1h734op) 2024-12-05T06:44Z [----] followers, [--] engagements
"Issues with windows [--] thinkpad docking station thinkpad T14 and second screen Hi all Sorry I am not sure where to start investigating with this problem. My second screen at home (home office) turns of randomly with "no signal" (without warning of sleep mode or anything). Even when I am actually doing something actively on said screen. Windows [--] still finds it as the second screen (it is just black/turned off due to "no signal"). And I can't wake it up anymore. * I have a Lenovo Thinkpad T14 with windows [--] issued by my employer. * The T14 is attached (via USB-C) to a thinkpad docking"
[Reddit Link](https://redd.it/1h736y0) 2024-12-05T06:48Z [----] followers, [--] engagements
"Linux - game crashes after landfall (tutorial) Hi all Maybe some fellow linux users might be able to help. I could game over 270h in this game without any issues but that was when I skipped the intro/tutorial. So I started with tier [--] and all that. Now I wanted to get the achievement for the tutorial and started a new game and opted to NOT skip the intro. The intro plays I am getting ascended to the planets surface and after the pioneer opens the capsule and steps out the game crashes (ADA finishes the speech but the screen already froze by then) and.then nothing. Anyone an idea what I could"
[Reddit Link](https://redd.it/1h82zsk) 2024-12-06T14:49Z [----] followers, [--] engagements
"How to get the achievement Anyone an idea how to get the achievement I am somewhat lost on how to do this (and my google fu escapes me apparently). Thanks. StarCommandGalaxies StarCommandGalaxies"
[Reddit Link](https://redd.it/1hjdpls) 2024-12-21T16:47Z [----] followers, [--] engagements
"Sanity check - Mgmt IPSec tunnels NAT routing and services Hi all This is a sanity check - because I am pretty sure I am missing something but I can't put my finger on it. **Scenario:** * We have several fortigates to manage. Those are managed via ipsec vpn tunnel which is terminated on a main fortigate in a datacenter (and managed FGT obviously). * Every managed FGT out there gets a (unique) 198.18.x.x/29 IP address range for said management IPSec tunnel. * The first IP address in this /29 range is configured as IP on the tunnel interface of the management VPN on the managed FGT. * The /29"
[Reddit Link](https://redd.it/1ij13ob) 2025-02-06T12:11Z [----] followers, [--] engagements
"Sanity Check - SNAT and DNAT info in diag sys session list Hello all I need a sanity check. It it is about information of source NAT and destination NAT in "diagnose sys session list" of a session. **From the official FCSS Support Engineer [---] training:** screenshot of official fcss training stuff (partials)(https://preview.redd.it/9vxhcx1jdkse1.pngwidth=1620&format=png&auto=webp&s=1bf93659a58f6219d86bd851a3f294fda23fd326) Am I wrong in saying: * The original source is 10.9.31.117(http://10.9.31.117) and this original source gets translated (snat) to 10.1.0.3(http://10.1.0.3) and the original"
[Reddit Link](https://redd.it/1jqbhpa) 2025-04-03T06:43Z [--] followers, [--] engagements
"How to parse and use the JSON data that is sent by webhook to a teams channel Dear all I am at a loss and need help. I try to send a webhook (with JSON data) from an external source to a teams channel. It works as I do get a message in the teams channel from the external source however I can't parse and use the JSON data trasmitted (to post it in the teams channel message). The interesting data I want to use in the teams message is in the body/text object in the webhook - and optimally I would like to use the different objects within said data to design a message into the teams channel. But I"
[Reddit Link](https://redd.it/1jqd6m0) 2025-04-03T08:37Z [----] followers, [--] engagements
"Checkpint GenAI - equivalent for Fortinet Dear all I hadn't the chance to go to accelerate in Berlin or having too many discussions with Fortinet yet. So this is a shot in the dark :) My management told me about Checkpoint GenAI which seems primarely targeting the security of the clients/users and their usage of (any kind of) AI during their working. The only thing that popped into mind was FortiAI but that doesn't seem to be the same (unless I have misunderstood the "SecureAI" part). Does some have already had a look at this and can share whether "SecureAI" of FortiAI might do the same as"
[Reddit Link](https://redd.it/1k7g2f9) 2025-04-25T08:41Z [----] followers, [--] engagements
"Anyone using FortiPortal (FPC) locally/on-site Having issues with FAZ logs Hi all This is a long shot as I don't know how many people really have dedicated/on-site/local FortiPortal running (in a VM) to offer for their customer. We are testing it at the moment and one of the biggest pain points is that I don't see logs in the view. Maybe someone has an idea what I am doing wrong here (Fortinet is already involved but I thought I might get an idea or two from someone in this sub). **What is the problem** When logging into FCP as a normal customer I should be able to look at (traffic) logs from"
[Reddit Link](https://redd.it/1kn2ew0) 2025-05-15T07:37Z [----] followers, [--] engagements
"FortiAuthenticator 6.6.4 released Apparently FortiAuthenticator 6.6.4 has been released See: https://docs.fortinet.com/index.php/document/fortiauthenticator/6.6.4/release-notes(https://docs.fortinet.com/index.php/document/fortiauthenticator/6.6.4/release-notes) I just took a quick look so I might have missed something - the following BugIDs seem to be new (known issue) in 6.6.4 compared to 6.6.3 as of 2025-05-27: [-------] - Debug report generation fails due to python logic error [-------] - Importing local users using FortiGate configuration file fails. [-------] - Cache-Control header not present"
[Reddit Link](https://redd.it/1kwewqk) 2025-05-27T04:55Z [----] followers, [--] engagements
"Can't see TLS server cert for ssl/ssh inspection object on FMG Dear all I am somewhat stumped but sure it is something obvious I am missing - I kindly ask for your help. We are on FMG 7.4.7 and on FortiOS 7.4.8 (FGT-200G). * Uploaded a (in my opinion) valid TLS server cert "subdomain.domain.com" on to FortiManager for the specific device. * The TLS cert is visible in Fortimanager in "Local Certificates" * It is also visible after installing device DB on the Fortigate (in "Local Certificates") * On both devices the tls cert is considered "valid" Problem: * The TLS cert is not llisted when I"
[Reddit Link](https://redd.it/1l9foi7) 2025-06-12T06:45Z [--] followers, [--] engagements
"Local-In-Policy blocks ipsex dialup TCP/443 requests from my IP Hi all I am trying to setup ipsec dialup (IKEv2) using port tcp/443 on a FGT200G with 7.4.8 and with Forticlient (vpn only version) 7.4.3. Amongst other issues I am facing a connection block (not negotiation error I seem not to get that far). My connection requests from my client (from my IP) are seen on the fortigate (on port tcp/443) as expected but are being blocked by local-in-policy number [--]. I have added one single local-in-policy that should allow ssh icmp and https (which is tcp/443 in the service object) from my IP"
[Reddit Link](https://redd.it/1lckthd) 2025-06-16T05:27Z [--] followers, [--] engagements
"FEX-511G as Wifi Client Dear all We are looking at FortiExtender-511G as our out-of-band management for the important Fortigates (in datacenters and such). Challenge is that some datacenters do not have good cell reception (by design) but offer "internal" Wifi within their centers which is a different ISP than the one we use to manage our fortigates. Has anyone used the FortiExtender-511G as a "wifi client" to connect it to a wifi (rather than using 4G/5G) We unfortunately will get our test FEX in a couple of months and I am eager to check the box on the most important questions beforehand"
[Reddit Link](https://redd.it/1lzhodp) 2025-07-14T09:13Z [--] followers, [--] engagements
"Let us welcome another change to Fortinet certs (or welcome them back) Appears that Fortinet revisits the NSE1-8 names for their exams: https://www.fortinet.com/nse-training-update(https://www.fortinet.com/nse-training-update) Retiring some exams re-shuffle the exams and topics.and going back to the NSE1-8 names. In any case - good luck with the exams you are taking and plan to take. fortinet fortinet"
[Reddit Link](https://redd.it/1m0hc3n) 2025-07-15T13:09Z [--] followers, [---] engagements
"sporadic issues with forticlient 7.4.3 and fortios 7.2.10 on ssl vpn (tcp/443) Dear all I need some insights from you who have more experience with forticlients than I do. Our customer has a fortigate (7.2.10) with ssl vpn configured. Our customer offers ssl vpn connection to partners and suppliers of theirs. A few days ago one of the suppliers mentioned that their new user can't connect to the ssl vpn. We figured out that they got the wrong password. Strangely I wasn't able to see all the connection tries from said supplier. Only a few. Yesterday we had a call - supplier our customer and us."
[Reddit Link](https://redd.it/1mczo64) 2025-07-30T06:55Z [--] followers, [--] engagements
"What to do when FQDNs resolve differently Dear community My google fu and chatgpt/AI-fu might be off today but I couldn't find any "good" answers to my problem. **Challenge:** The clients (printers in this particular case) try to resolve FQDNs which appear to resolve to different IP addresses (there is not one single IP). I have no information how they determine the IP you get (loadbalanced or geolocation etc.) and it appears that I get only ONE single IP each time (sometimes you get a bunch which might change but at least you get a bunch - that is not the case here). I am still in the"
[Reddit Link](https://redd.it/1mw2jqo) 2025-08-21T05:41Z [--] followers, [--] engagements
"FortiProxy in FortiManager Anyone experience with it Dear all It has been ages since I have been confronted with FortiProxy - and back then it was configured/managed directly (no central management). From what I have seen in my internet searches: It seems possible to add a FortiProxy to a Fortimanager but there is vry limited "management" feature available (not even close to Fortigates management features). Is this correct or can a FortiProxy be managed via FortiManager with the same or at least very similar equivalent feature set as a Fortigate can be managed from a FMG (eg. policies"
[Reddit Link](https://redd.it/1mw9imf) 2025-08-21T12:26Z [--] followers, [--] engagements
"Sanity Check - monitor tls cert expiration via FAZ logs/events Hi all Our fortinet devices all log to FAZ /(7.4.7). We would need a way to be informed if a tls certificate on those fortinet devices is expiring (or expired even). Unfortunately FAZ doesn't have a template for a basic handler for this. So I have to make my own. Sanity Check - does someone else have this setup up and can give me a pointer what I need to add or change So far I have a basic handler with a single rule with "log filter by text" with the following filter: logdesc"certificate will expire soon" Unfortunately I cannot"
[Reddit Link](https://redd.it/1n5lhrk) 2025-09-01T10:49Z [--] followers, [--] engagements
"IPSec DialUp on same IP (UDP and TCP) - questions fortinet fortinet"
[Reddit Link](https://redd.it/1qe9w2p) 2026-01-16T07:50Z [--] followers, [--] engagements
"Are configurations of FortiGate and FortiWifi (same model same fortios version) interchangeable fortinet fortinet"
[Reddit Link](https://redd.it/1b0as8e) 2024-02-26T06:26Z [--] followers, [--] engagements
"OSPF between FGT and Meraki MX - how fortinet fortinet"
[Reddit Link](https://redd.it/1de4tyl) 2024-06-12T12:04Z [--] followers, [--] engagements
"Issues with pipes and issues with copying buildings SatisfactoryGame SatisfactoryGame"
[Reddit Link](https://redd.it/1h4rflb) 2024-12-02T09:54Z [--] followers, [--] engagements
"Schedulded Backup on FAZ 7.4.6 not working - any hints Good day everyone I am in need of some hints on what I am doing wrong here. We have a linux vm offering ssh/sftp with a particular user so that we can send scheduled backups from our devices (fortigates etc.) to it. The scheduled backups from the fortigates work - they are sent via sftp and are visible on the correct directory ("current" of the home directory of the backup-user). We have the FAZ (7.4.6) and said linux VM in the same subnet. The FAZ can ping and "execute ssh" to the linux vm with said backup user. So connectivity isn't the"
[Reddit Link](https://redd.it/1iuke00) 2025-02-21T06:22Z [----] followers, [--] engagements
"Recommended way to protect ipsec dialup (loopback or local-in-policies) fortinet fortinet"
[Reddit Link](https://redd.it/1laddj6) 2025-06-13T11:26Z [--] followers, [---] engagements
"Certain settings not available in ipsec dialup why fortinet fortinet"
[Reddit Link](https://redd.it/1lcl843) 2025-06-16T05:56Z [--] followers, [--] engagements
"How to trigger a "conflict" in device DB of a device in FMG fortinet fortinet"
[Reddit Link](https://redd.it/1ljxi9k) 2025-06-25T05:31Z [--] followers, [--] engagements
"Rumour - does SSL VPN come back fortinet fortinet"
[Reddit Link](https://redd.it/1nvzglq) 2025-10-02T10:05Z [--] followers, [---] engagements
"FortiGuard Webfilter website slow/non-working fortinet fortinet"
[Reddit Link](https://redd.it/1oc79jr) 2025-10-21T09:19Z [--] followers, [--] engagements
"New Releases - FortiClientEMS 7.4.5 and FortiAuthenticator 6.6.8 fortinet fortinet"
[Reddit Link](https://redd.it/1pkmjwb) 2025-12-12T08:13Z [--] followers, [--] engagements
"OSPF route advertising and neighboring without ospf interface fortinet fortinet"
[Reddit Link](https://redd.it/1qcimnl) 2026-01-14T09:11Z [--] followers, [--] engagements
"Version of FortiClient (free) wrong fortinet fortinet"
[Reddit Link](https://redd.it/1qeetkm) 2026-01-16T12:36Z [--] followers, [--] engagements
"Sanity Check: TLS certs with IPs and resolving local hostnames on a FGT for RADSEC fortinet fortinet"
[Reddit Link](https://redd.it/1od3ij4) 2025-10-22T10:18Z [--] followers, [--] engagements
"FMG admins via FAC (radius) and admin profiles fortinet fortinet"
[Reddit Link](https://redd.it/1qdj7nu) 2026-01-15T13:25Z [--] followers, [--] engagements
"Authentication failure with DialUp IPSec (EAP failure) fortinet fortinet"
[Reddit Link](https://redd.it/1qeerft) 2026-01-16T12:35Z [--] followers, [--] engagements
"Sanity Check - SSL VPN Removal in 7.4.8 and 7.6.3 fortinet fortinet"
[Reddit Link](https://redd.it/1n1dmyp) 2025-08-27T10:51Z [--] followers, [--] engagements
"Planet Craft on Linux - sudden power off/shutdown using portals theplanetcrafter theplanetcrafter"
[Reddit Link](https://redd.it/1q5lj2d) 2026-01-06T15:28Z [--] followers, [--] engagements
"OpenSSL CVE-2025-15467 - FG-IR-26-076 fortinet fortinet"
[Reddit Link](https://redd.it/1qqxwds) 2026-01-30T06:57Z [--] followers, [---] engagements
"Sanity Check - PSIRT showing mixed information fortinet fortinet"
[Reddit Link](https://redd.it/1r3iib6) 2026-02-13T07:06Z [--] followers, [--] engagements
Limited data mode. Full metrics available with subscription: lunarcrush.com/pricing
@Roversword RoverswordRoversword posts on Reddit about i need, in a, ip, lenovo the most. They currently have [-----] followers and [--] posts still getting attention that total [--] engagements in the last [--] hours.
Social category influence technology brands stocks social networks finance
Social topic influence i need, in a, ip, lenovo, has been, 6969, azure, end of, the only, youtube
Top accounts mentioned or mentioned by @corebootorgmessagev32ie5gkjotigxu4ewf7zytfl5wnw4tzhttpsmailcorebootorghyperkittylistcoreboot @corebootorgmessagev32ie5gkjotigxu4ewf7zytfl5wnw4tz
Top assets mentioned Alphabet Inc Class A (GOOGL)
Top posts by engagements in the last [--] hours
"Missing configuration after restore of azure vm (fortigate vm) Hello all I have an odd issue with a Fortigate VM-64 (6.4.10) in Azure. The virtual machine and azure configuration is not maintained by me so I have no real detailed information. We tested the restore function of Azure and after restoring the fortigate vm from the snapshot there were configuration missing. In my case it was the configuration of a port (it was there and up but the correct IP was missing) a missing static route which was connected to said port and a firewall policy. The fortimanager was correctly configured and in"
Reddit Link 2023-03-08T16:00Z [---] followers, [--] engagements
"HA cluster "split brain" when downstream cisco stack reloads Hi all I already opened a support ticket for this - however I'd like to have some input (maybe others had the same issue). **Situation:**We deploy fortigate (60f and 100f) currently with 6.4.9 as clusters. The (single) HA/cluster link/cable is physical and direct (without any switches etc.).Downstream there is a cisco stack with two cisco switch as members.Fortigate cluter node A is connected to cisco stack member A and fortigate cluster node B ist connected to cisco stack member B.This connection is made with a single copper cable"
Reddit Link 2023-05-11T08:22Z [---] followers, [--] engagements
"Default value of firewall policy for DENY/ACCEPT created on fortimanager"
Reddit Link 2023-10-03T13:01Z [---] followers, [----] engagements
"Routing (BGP) of location with two active VPNs to hubs that exchange routing info"
Reddit Link 2023-10-26T12:15Z [---] followers, [----] engagements
"Default value of firewall policy for DENY/ACCEPT created on fortimanager Hi all This might be a silly question: Is there an option in FortiMANAGER where I can change the default value of "Action" in a newly created firewall policy. When creating a new firewall policy in a policy package on fortimanager the default value of "Action" is "DENY". I would like to set it on "ACCEPT" Is there a way to do this Yes I am aware that this is potentially a risk - however we have tons of SLAs breached monthly because we forget to set it from DENY to ACCEPT (as we have nearly zero DENY-Rules). Thanks a lot."
Reddit Link 2023-10-03T13:01Z [----] followers, [--] engagements
"Routing (BGP) of location with two active VPNs to hubs that exchange routing info"
Reddit Link 2023-10-26T12:15Z [---] followers, [----] engagements
"diagnose traffictest on a Fortigate 600F with 6.4.14"
Reddit Link 2023-11-21T07:36Z [---] followers, [----] engagements
"ADVPN and firewall policies on the spokes Hello all This might be a stupid question - however I have simply no real ADVPN experience (some in theorie). I am unable to find an answer to my question likely because I am using the wrong keywords or such so I am asking you all: If spoke A and spoke B establish a direct VPN to each other due to ADVPN (which is dynamic and can happen on demand and all that) - how does the ruleset (firewall policy) look like for that particular connection look on spoke A and B Is ADVPN "only" doing the VPN and we need to make sure the appropriate firewall policies"
Reddit Link 2023-12-11T08:25Z [---] followers, [----] engagements
"Hardware advice for pfsense and at least 2x [--] Gbit/s RJ45/copper interfaces"
Reddit Link 2023-12-14T08:42Z [--] followers, [--] engagements
"Compatibility list for FP421E (FortiAPs) We still have some FP421E active which are managed by a fortigate.We are aware that those are end of support end of sale end of everything. Unfortunately I have difficulties to find an official (old) compatibility list with these FortiAPs listed to find out how far I can update the managing fortigate in order to have those FP421E (on 6.4.9) still being supprted (fortios wise) so that we can prepare the fortigate for newer FortiAP models. So far in the compatibiilty lists I found the only legacy models mentioned are the FAP221 and FAP223 but no FP421E."
Reddit Link 2024-02-01T14:41Z [----] followers, [--] engagements
"surprisingly passed after 125Q and a little less than 1.5h Hi all About three and half hour ago my CISSP exam stopped after (or with) the 125th questions - after using about 1.5h of the exam time. Honestly I was devastated because I had a rather terrible feeling about it1. And to my surprise I (provisionally) passed the exam. I used mostly youtube videos (crams) and learnzapp - accordingly to my kindle I only read 11% of the OSG. [--] As others in this subreddit already mentioned - it ended up less about knowledge but rather about actually understanding the question asked and deciphering what"
Reddit Link 2024-02-29T15:24Z [----] followers, [--] engagements
"Changing HA cluster password in an existing cluter without physical access Hello all This might sound weird but.I have been given a remote fortigate cluster which I have admin access to and which I need to configure (but there was first a third party involved that configured the bare minimum like admin access and cluster ha config). I would like to change the HA password those two physical fortigates use and I am not sure how to go about it (and I don't have a lab at hand to test it). Are those steps correct [--]. Login into primary node and then use its CLI to log into secondary node [--]. Change"
Reddit Link 2024-03-10T18:12Z [----] followers, [--] engagements
"per device config of a single shared traffic shaper (on FortiManager) Hi all Reference: https://www.reddit.com/r/fortinet/comments/ea4yoa/fortimanager_new_feature_request_perdevice_mapped/(https://www.reddit.com/r/fortinet/comments/ea4yoa/fortimanager_new_feature_request_perdevice_mapped/) which is four years old. I have the same issue - several fortigates that use the same named traffic shaper however have different values within (in my example its the maximum bandwith). We would love to centralise that on the Fortimanager (7.0.11) and would love to use one single traffic shaper for that. In"
Reddit Link 2024-03-28T11:47Z [----] followers, [--] engagements
"ISDB search and "obsolete" entries Hi all I am a little stumped where to start my search here. One location has 6.4.x running and a ISDB object in a static routing entry. Another (new) location should get the same static routing entries but is running 7.0.x. Turns out that Microsoft Intune (ID 327886) appears to be obsolete and I can't find it anywhere in 7.0.x database. So.what can I do here How can I find out whether a ISDB object/entry has just change name or ID or whether it has been replaced etc. I need the same services routed and I can't find any intune stuff (however I might just be"
Reddit Link 2024-04-08T09:07Z [--] followers, [--] engagements
"Windows [--] enrollment - what internet rules are needed Hello all This will likely be a cross post. We have a customer who rolls out Windows [--] at their locations. We don't have much details unfortunately. It seems as if those devices need internet access to be enrolled activated etc. and the customer hits a wall (blocked ports or IPs) as the internet is obviously not completely open for the corporate network. So far we found out that adding a rule with "Microsoft-Web" (ISDB) as destination seems to work. For the live of me my google fu fails me - I don't find nothing concerning win11 and"
Reddit Link 2024-04-16T06:41Z [--] followers, [--] engagements
"BGP prefix-list (or route-map) that denies all Hi all We want to introduce a new connection and that new connection will be propagating/advertising its networks/prefixes via BGP to us. As a first step we would like NOT to process those information from the new connection so that we can have a look at them first (checking first with "received-routes") and then build the future correct new prefix-list step by step. However I am not sure about this. * An empty prefix-list would likely allow everything so that will not work the way I want * Would it be sufficient to have one single deny statement"
Reddit Link 2024-04-29T08:25Z [----] followers, [--] engagements
"Explicit Proxy on FGT - what does "Default Firewall Policy Action" do Hi all I can't wrap my head around this one and I am still reading the documentations (and what ever I find online) but to no avail. In the Explicit Proxy feature of the Fortigate there is a parameter called "Default Firewall Policy Action" which can be set to "Accept" or "Deny". However I don't understand what a) it actually does b) what it does when its on accept or on deny and c) what is being influenced by this setting. Does anyone have any insights for me Side note: In the official documentation"
Reddit Link 2024-05-03T09:02Z [----] followers, [--] engagements
"Funny wifi issues in a large building Hi all I have an issue with Wifi which I can't wrap my head around it. Setup: There is a large building with more than [--] FortiAPs (same models; FAP231F). Those have been connected to FortiSwtiches and handled with tunnel mode. The Fortigate has a dedicated VLAN and DHCP on this VLAN to give those FortiAP an internal IP. And they are managed by the Fortigate. They all had the same profile for this specific coutry (for testing purposes later we made a "default" one). They are all running the same firmware (7.0.7 at first downgraded temporarily to"
Reddit Link 2024-05-07T05:52Z [----] followers, [--] engagements
"Issues with auth in explicit proxy feature in fgt100f (6.4.15) Dear all I have configured an explicit proxy on at fgt100F with 6.4.15. The goal is to use kerberos as an authentication for the users. Unfortunately this doesn't work yet. To start troubleshooting I disabled the autbentication need on the proxy policy (all where allowed then without need of login credentiaks) and let the customer test. We were able to verify that the explicit proxy works (if authentication is not needed). Then I added the authentication again in the proxy policy and the customer confirms the browser receives a"
Reddit Link 2024-05-08T09:51Z [----] followers, [--] engagements
"Additional LAN interface which can also be used as Mgmt interface Hi all I received hardware with opnsense pre-installed - so I need to configure it. The WAN and LAN are 10Gbps SFP modules and I wanted to add another RJ45 interface so I can use it as "out of band" management beforehand. The management works on the LAN interface perfectly fine (was able to do the wizard and all other configs) but the LAN works on 192.168.x.0/24 which actually is my network. I configured an unused interface to 192.168.x+1.0/29 and added DHCP - this works so far (I get an IP on the laptop I am using) however I"
Reddit Link 2024-05-20T10:23Z [---] followers, [--] engagements
"prefix list that does NOT advertise anything (BGP) Hi all Just for sanity's sake: I am about to establish a new BGP neighborship and the customer wants to make sure nothing happens at the start. I need to surpress all adverstisement from my side to the customer and surpress all implementations into my routing table of the prefixes they send me. So that is basically the following prefix-list (for both directions) right config router prefix-list edit "DENY_ALL" config rule edit [--] set prefix 0.0.0.0/0(http://0.0.0.0/0) set le [--] set action deny next end next end Cheers fortinet fortinet"
Reddit Link 2024-05-27T08:34Z [--] followers, [--] engagements
"Can a wazuh agent on a device/asset see or discover an unmanaged device Hi all My google fu seems off I can't find definitive answer to my questions: * Can a wazuh agent installed on an asset see other unmanaged (without wazuh agent) devices and report them Basically I would love if wazuh would tell me "hey there are some devices which are in your network that have no wazuh client you know about them". And then preferably allow me to exclude them from reports (after I have checked and dealt with them). Cheers Wazuh Wazuh"
Reddit Link 2024-08-13T07:14Z [---] followers, [--] engagements
"Dedicated Server - disable enemies (after starting it/playing it) Dear all I am running a dedicated server on linux (linux-gsm) and would like to disable enemies now (after playing for about 90h). Is this possible And if so what variable in the config-file would I need to change or add Thanks a lot SatisfactoryGame SatisfactoryGame"
Reddit Link 2024-11-02T13:26Z [----] followers, [--] engagements
"Problems with one single PC (win 11) and 2.5Gbit/s connection (LAN) Hi everyone I am actually completely out of ideas and I need help. A few months ago we got fiber to the home (10 Gbit/s). My internal equipment was for [--] Gbit/s (switches and such). My linux computer worked fine my wife's windows [--] computer worked fine. I then changed the equipment to unify switches (Enterprise [--] PoE - https://eu.store.ui.com/eu/en/category/switching-utility/products/usw-enterprise-8-poe) that offer [---] Gbit/s interfaces. Then the trouble started for my wife. She had non-stop network failures (was"
Reddit Link 2024-11-11T17:37Z [----] followers, [--] engagements
"Download all (newest) revisions/backups of Fortigates on a Fortimanager Hi all Is there a way to download the latest revision (backups/conf-file) of all Fortigates on a Fortimanager in one single download (opposed to clicking every single Fortimanager and downloading them one by one) Thank you very much fortinet fortinet"
Reddit Link 2024-11-19T14:14Z [--] followers, [--] engagements
"Reset passwords of local SSL VPN users Hi all So far I was only confronted with SSL VPN user via Radius/AD etc. but not with local ones. Is there a way to reset the password of local users (which can use sslvpn) so that they need to change their password No Web-mode activated. only tunnel mode. Thank you. fortinet fortinet"
Reddit Link 2024-11-19T14:24Z [----] followers, [--] engagements
"Sanity Check: Is coreboot able to disable E-Cores on Intel CPUs Hello everybody I need a sanity check (am I understanding it correctl) I am refering to these two posts: * https://mail.coreboot.org/hyperkitty/list/coreboot@coreboot.org/message/V32IE5GKJOTIGXU4EWF7ZYTFL5WNW4TZ/(https://mail.coreboot.org/hyperkitty/list/coreboot@coreboot.org/message/V32IE5GKJOTIGXU4EWF7ZYTFL5WNW4TZ/) * https://review.coreboot.org/c/coreboot/+/73790(https://review.coreboot.org/c/coreboot/+/73790) Am I correct to understand that coreboot is (now) capable of disabling E-Cores (and P-Cores) on (all available) Intel"
Reddit Link 2024-11-29T10:47Z [----] followers, [--] engagements
"Hardware recommendation: Mini PCs with coreboot Dear all My apologies bothering you with this - please let me know if there are other subreddits I should ask. I am looking for a mini PC (size of approx. a NUC Geekom Minisforum etc.) that has enough power to run two VMs at a time and the OS (Linux distribution) and.uses preferably coreboot. As I understand e-cores are still an issue with virtualisation outside windows [--] and AMD isn't an option as it is not really suppored by coreboot yet (as far as I understood). So my question is - do you have any recommendation for a NUC sized mini PC that."
Reddit Link 2024-11-29T10:52Z [----] followers, [--] engagements
"Problem with second screen and thinkpad docking station Hi all Sorry I am not sure where to start investigating with this problem. My second screen at home (home office) turns of randomly with "no signal" (without warning of sleep mode or anything). Even when I am actually doing something actively on said screen. * I have a Lenovo Thinkpad T14 with windows [--] issued by my employer. * The T14 is attached (via USB-C) to a thinkpad docking station (Lenovo ThinkPad Hybrid USB-C / -A llisted as Docktype 40AF with firmware 1.0.40 from 2024-11-28). * The docking station is attached to both screens"
Reddit Link 2024-12-05T06:44Z [----] followers, [--] engagements
"Issues with windows [--] thinkpad docking station thinkpad T14 and second screen Hi all Sorry I am not sure where to start investigating with this problem. My second screen at home (home office) turns of randomly with "no signal" (without warning of sleep mode or anything). Even when I am actually doing something actively on said screen. Windows [--] still finds it as the second screen (it is just black/turned off due to "no signal"). And I can't wake it up anymore. * I have a Lenovo Thinkpad T14 with windows [--] issued by my employer. * The T14 is attached (via USB-C) to a thinkpad docking"
Reddit Link 2024-12-05T06:48Z [----] followers, [--] engagements
"Linux - game crashes after landfall (tutorial) Hi all Maybe some fellow linux users might be able to help. I could game over 270h in this game without any issues but that was when I skipped the intro/tutorial. So I started with tier [--] and all that. Now I wanted to get the achievement for the tutorial and started a new game and opted to NOT skip the intro. The intro plays I am getting ascended to the planets surface and after the pioneer opens the capsule and steps out the game crashes (ADA finishes the speech but the screen already froze by then) and.then nothing. Anyone an idea what I could"
Reddit Link 2024-12-06T14:49Z [----] followers, [--] engagements
"How to get the achievement Anyone an idea how to get the achievement I am somewhat lost on how to do this (and my google fu escapes me apparently). Thanks. StarCommandGalaxies StarCommandGalaxies"
Reddit Link 2024-12-21T16:47Z [----] followers, [--] engagements
"Sanity check - Mgmt IPSec tunnels NAT routing and services Hi all This is a sanity check - because I am pretty sure I am missing something but I can't put my finger on it. Scenario: * We have several fortigates to manage. Those are managed via ipsec vpn tunnel which is terminated on a main fortigate in a datacenter (and managed FGT obviously). * Every managed FGT out there gets a (unique) 198.18.x.x/29 IP address range for said management IPSec tunnel. * The first IP address in this /29 range is configured as IP on the tunnel interface of the management VPN on the managed FGT. * The /29"
Reddit Link 2025-02-06T12:11Z [----] followers, [--] engagements
"Sanity Check - SNAT and DNAT info in diag sys session list Hello all I need a sanity check. It it is about information of source NAT and destination NAT in "diagnose sys session list" of a session. From the official FCSS Support Engineer [---] training: screenshot of official fcss training stuff (partials)(https://preview.redd.it/9vxhcx1jdkse1.pngwidth=1620&format=png&auto=webp&s=1bf93659a58f6219d86bd851a3f294fda23fd326) Am I wrong in saying: * The original source is 10.9.31.117(http://10.9.31.117) and this original source gets translated (snat) to 10.1.0.3(http://10.1.0.3) and the original"
Reddit Link 2025-04-03T06:43Z [--] followers, [--] engagements
"How to parse and use the JSON data that is sent by webhook to a teams channel Dear all I am at a loss and need help. I try to send a webhook (with JSON data) from an external source to a teams channel. It works as I do get a message in the teams channel from the external source however I can't parse and use the JSON data trasmitted (to post it in the teams channel message). The interesting data I want to use in the teams message is in the body/text object in the webhook - and optimally I would like to use the different objects within said data to design a message into the teams channel. But I"
Reddit Link 2025-04-03T08:37Z [----] followers, [--] engagements
"Checkpint GenAI - equivalent for Fortinet Dear all I hadn't the chance to go to accelerate in Berlin or having too many discussions with Fortinet yet. So this is a shot in the dark :) My management told me about Checkpoint GenAI which seems primarely targeting the security of the clients/users and their usage of (any kind of) AI during their working. The only thing that popped into mind was FortiAI but that doesn't seem to be the same (unless I have misunderstood the "SecureAI" part). Does some have already had a look at this and can share whether "SecureAI" of FortiAI might do the same as"
Reddit Link 2025-04-25T08:41Z [----] followers, [--] engagements
"Anyone using FortiPortal (FPC) locally/on-site Having issues with FAZ logs Hi all This is a long shot as I don't know how many people really have dedicated/on-site/local FortiPortal running (in a VM) to offer for their customer. We are testing it at the moment and one of the biggest pain points is that I don't see logs in the view. Maybe someone has an idea what I am doing wrong here (Fortinet is already involved but I thought I might get an idea or two from someone in this sub). What is the problem When logging into FCP as a normal customer I should be able to look at (traffic) logs from"
Reddit Link 2025-05-15T07:37Z [----] followers, [--] engagements
"FortiAuthenticator 6.6.4 released Apparently FortiAuthenticator 6.6.4 has been released See: https://docs.fortinet.com/index.php/document/fortiauthenticator/6.6.4/release-notes(https://docs.fortinet.com/index.php/document/fortiauthenticator/6.6.4/release-notes) I just took a quick look so I might have missed something - the following BugIDs seem to be new (known issue) in 6.6.4 compared to 6.6.3 as of 2025-05-27: [-------] - Debug report generation fails due to python logic error [-------] - Importing local users using FortiGate configuration file fails. [-------] - Cache-Control header not present"
Reddit Link 2025-05-27T04:55Z [----] followers, [--] engagements
"Can't see TLS server cert for ssl/ssh inspection object on FMG Dear all I am somewhat stumped but sure it is something obvious I am missing - I kindly ask for your help. We are on FMG 7.4.7 and on FortiOS 7.4.8 (FGT-200G). * Uploaded a (in my opinion) valid TLS server cert "subdomain.domain.com" on to FortiManager for the specific device. * The TLS cert is visible in Fortimanager in "Local Certificates" * It is also visible after installing device DB on the Fortigate (in "Local Certificates") * On both devices the tls cert is considered "valid" Problem: * The TLS cert is not llisted when I"
Reddit Link 2025-06-12T06:45Z [--] followers, [--] engagements
"Local-In-Policy blocks ipsex dialup TCP/443 requests from my IP Hi all I am trying to setup ipsec dialup (IKEv2) using port tcp/443 on a FGT200G with 7.4.8 and with Forticlient (vpn only version) 7.4.3. Amongst other issues I am facing a connection block (not negotiation error I seem not to get that far). My connection requests from my client (from my IP) are seen on the fortigate (on port tcp/443) as expected but are being blocked by local-in-policy number [--]. I have added one single local-in-policy that should allow ssh icmp and https (which is tcp/443 in the service object) from my IP"
Reddit Link 2025-06-16T05:27Z [--] followers, [--] engagements
"FEX-511G as Wifi Client Dear all We are looking at FortiExtender-511G as our out-of-band management for the important Fortigates (in datacenters and such). Challenge is that some datacenters do not have good cell reception (by design) but offer "internal" Wifi within their centers which is a different ISP than the one we use to manage our fortigates. Has anyone used the FortiExtender-511G as a "wifi client" to connect it to a wifi (rather than using 4G/5G) We unfortunately will get our test FEX in a couple of months and I am eager to check the box on the most important questions beforehand"
Reddit Link 2025-07-14T09:13Z [--] followers, [--] engagements
"Let us welcome another change to Fortinet certs (or welcome them back) Appears that Fortinet revisits the NSE1-8 names for their exams: https://www.fortinet.com/nse-training-update(https://www.fortinet.com/nse-training-update) Retiring some exams re-shuffle the exams and topics.and going back to the NSE1-8 names. In any case - good luck with the exams you are taking and plan to take. fortinet fortinet"
Reddit Link 2025-07-15T13:09Z [--] followers, [---] engagements
"sporadic issues with forticlient 7.4.3 and fortios 7.2.10 on ssl vpn (tcp/443) Dear all I need some insights from you who have more experience with forticlients than I do. Our customer has a fortigate (7.2.10) with ssl vpn configured. Our customer offers ssl vpn connection to partners and suppliers of theirs. A few days ago one of the suppliers mentioned that their new user can't connect to the ssl vpn. We figured out that they got the wrong password. Strangely I wasn't able to see all the connection tries from said supplier. Only a few. Yesterday we had a call - supplier our customer and us."
Reddit Link 2025-07-30T06:55Z [--] followers, [--] engagements
"What to do when FQDNs resolve differently Dear community My google fu and chatgpt/AI-fu might be off today but I couldn't find any "good" answers to my problem. Challenge: The clients (printers in this particular case) try to resolve FQDNs which appear to resolve to different IP addresses (there is not one single IP). I have no information how they determine the IP you get (loadbalanced or geolocation etc.) and it appears that I get only ONE single IP each time (sometimes you get a bunch which might change but at least you get a bunch - that is not the case here). I am still in the"
Reddit Link 2025-08-21T05:41Z [--] followers, [--] engagements
"FortiProxy in FortiManager Anyone experience with it Dear all It has been ages since I have been confronted with FortiProxy - and back then it was configured/managed directly (no central management). From what I have seen in my internet searches: It seems possible to add a FortiProxy to a Fortimanager but there is vry limited "management" feature available (not even close to Fortigates management features). Is this correct or can a FortiProxy be managed via FortiManager with the same or at least very similar equivalent feature set as a Fortigate can be managed from a FMG (eg. policies"
Reddit Link 2025-08-21T12:26Z [--] followers, [--] engagements
"Sanity Check - monitor tls cert expiration via FAZ logs/events Hi all Our fortinet devices all log to FAZ /(7.4.7). We would need a way to be informed if a tls certificate on those fortinet devices is expiring (or expired even). Unfortunately FAZ doesn't have a template for a basic handler for this. So I have to make my own. Sanity Check - does someone else have this setup up and can give me a pointer what I need to add or change So far I have a basic handler with a single rule with "log filter by text" with the following filter: logdesc"certificate will expire soon" Unfortunately I cannot"
Reddit Link 2025-09-01T10:49Z [--] followers, [--] engagements
"IPSec DialUp on same IP (UDP and TCP) - questions fortinet fortinet"
Reddit Link 2026-01-16T07:50Z [--] followers, [--] engagements
"Are configurations of FortiGate and FortiWifi (same model same fortios version) interchangeable fortinet fortinet"
Reddit Link 2024-02-26T06:26Z [--] followers, [--] engagements
"OSPF between FGT and Meraki MX - how fortinet fortinet"
Reddit Link 2024-06-12T12:04Z [--] followers, [--] engagements
"Issues with pipes and issues with copying buildings SatisfactoryGame SatisfactoryGame"
Reddit Link 2024-12-02T09:54Z [--] followers, [--] engagements
"Schedulded Backup on FAZ 7.4.6 not working - any hints Good day everyone I am in need of some hints on what I am doing wrong here. We have a linux vm offering ssh/sftp with a particular user so that we can send scheduled backups from our devices (fortigates etc.) to it. The scheduled backups from the fortigates work - they are sent via sftp and are visible on the correct directory ("current" of the home directory of the backup-user). We have the FAZ (7.4.6) and said linux VM in the same subnet. The FAZ can ping and "execute ssh" to the linux vm with said backup user. So connectivity isn't the"
Reddit Link 2025-02-21T06:22Z [----] followers, [--] engagements
"Recommended way to protect ipsec dialup (loopback or local-in-policies) fortinet fortinet"
Reddit Link 2025-06-13T11:26Z [--] followers, [---] engagements
"Certain settings not available in ipsec dialup why fortinet fortinet"
Reddit Link 2025-06-16T05:56Z [--] followers, [--] engagements
"How to trigger a "conflict" in device DB of a device in FMG fortinet fortinet"
Reddit Link 2025-06-25T05:31Z [--] followers, [--] engagements
"Rumour - does SSL VPN come back fortinet fortinet"
Reddit Link 2025-10-02T10:05Z [--] followers, [---] engagements
"FortiGuard Webfilter website slow/non-working fortinet fortinet"
Reddit Link 2025-10-21T09:19Z [--] followers, [--] engagements
"New Releases - FortiClientEMS 7.4.5 and FortiAuthenticator 6.6.8 fortinet fortinet"
Reddit Link 2025-12-12T08:13Z [--] followers, [--] engagements
"OSPF route advertising and neighboring without ospf interface fortinet fortinet"
Reddit Link 2026-01-14T09:11Z [--] followers, [--] engagements
"Version of FortiClient (free) wrong fortinet fortinet"
Reddit Link 2026-01-16T12:36Z [--] followers, [--] engagements
"Sanity Check: TLS certs with IPs and resolving local hostnames on a FGT for RADSEC fortinet fortinet"
Reddit Link 2025-10-22T10:18Z [--] followers, [--] engagements
"FMG admins via FAC (radius) and admin profiles fortinet fortinet"
Reddit Link 2026-01-15T13:25Z [--] followers, [--] engagements
"Authentication failure with DialUp IPSec (EAP failure) fortinet fortinet"
Reddit Link 2026-01-16T12:35Z [--] followers, [--] engagements
"Sanity Check - SSL VPN Removal in 7.4.8 and 7.6.3 fortinet fortinet"
Reddit Link 2025-08-27T10:51Z [--] followers, [--] engagements
"Planet Craft on Linux - sudden power off/shutdown using portals theplanetcrafter theplanetcrafter"
Reddit Link 2026-01-06T15:28Z [--] followers, [--] engagements
"OpenSSL CVE-2025-15467 - FG-IR-26-076 fortinet fortinet"
Reddit Link 2026-01-30T06:57Z [--] followers, [---] engagements
"Sanity Check - PSIRT showing mixed information fortinet fortinet"
Reddit Link 2026-02-13T07:06Z [--] followers, [--] engagements
Limited data mode. Full metrics available with subscription: lunarcrush.com/pricing
/creator/reddit::Roversword