Corona-Info: Support Links for Home-/Remote-Office and MultiFactor Authentication

Here you will find the most important support links of our vendors regarding Home-/Remote-Office, Dialup VPNs and MultiFactor Authentication:

Fortinet

Specific documentation for FortiClient, FortiToken and FortiAuthenticator: Fortinet Tele-Working

Additional FortiClient Download: Boll Mirror

Palo Alto Networks

Many important information regarding GlobalProtect, Prisma Access:
The COVID-19 Response Center for GlobalProtect and Prisma Access

Watchguard

Helpful information about Remote Worker Security:
WatchGuard Resources to Aid with Remote Worker Security

Specific information regarding Mobile User VPN and MFA with AuthPoint:

Kaspersky

Free protection for healthcare oganizations:

https://www.kaspersky.com/blog/protecting-healthcare-organizations/34269/

 575 total views,  5 views today

Re-Certification Policies during COVID19

Because it’s very difficult to take exams at PearsonVUE right now, you may get in trouble regarding the timely recertification of existing certifications. Therefore some vendors have announced an extension for their recertification expiration:

PaloAltoNetworks is extending the certification expiration date by six month for Credential holders with expiration date between March 1, 2020 and July 31, 2020.

Fortinet is extending the certification expiration by one month so far. We assume that this extension will be extended again :-).
Update March 27th: Fortinet will extend the expiry dates of all existing NSE certifications by 6 months as of March 16th 2020 (the date of PV’s test center closures).

FortiClient VPN: Download Mirror

Da die Server von www.forticlient.com gut ausgelastet sind, können unsere Reseller den FortiClient VPN temporär von unserem Mirror beziehen.

FortiClient VPN 6.2 (VPN Client only)

FortiClient 6.0 (Fabric Agent with Endpoint Protection)

Bitte pro Reseller nur einmal herunterladen und anschliessend intern verteilen.

Fortinet hat übrigens aufgrund der grossen Supportanfrage zum Thema eine eigene Seite für Home-Office/Remote-Office Thematiken erstellt. Darauf sind viele Anleitungen und Videos zum Thema zu finden. Der Artikel ist hier zu finden.

 1,326 total views,  22 views today

FortiGate: Admin GUI mit Chrome Browser on Mac nicht erreichbar

Mit iOS 13 und macOS 10.15 (Catalina) hat Apple die Schraube bei den TLS Zertifikaten angezogen: https://support.apple.com/en-us/HT210176

Dies führt dazu, dass bei frisch aufgesetzten FortiGates das Admin GUI per Chrome Browser nicht mehr erreichbar ist. Als Fehlermeldung wird NET::ERR_CERT_REVOKED angezeigt.

Verantwortlich ist folgende Richtlinie: TLS server certificates [issued after July 1, 2019] must have a validity period of 825 days or fewer.

Um das Problem permanent zu lösen, braucht es ein SSL Zertifikat, welches den neuen Apple Richtlinien entspricht (Gültigkeit <= 825 Tage). Das Zertifikat fürs Admin GUI wird unter System > Settings konfiguriert.

Als Workaround kann man in Chrome auf der Fehlerseite den Text thisisunsafe eintippen. Anschliessend erfolgt die Weiterleitung auf die gewünschte Seite.

OneSpan Authentication Server Appliance 3.19 Upgrade Issue

Official information from OneSpan published on January 10, 2020:

We have discovered an issue when upgrading OneSpan Authentication Server Appliance from version 3.18.x to 3.19. The upgrade brings the appliance in a non-operational state.

The Authentication Server Appliance and Authentication Server Virtual Appliance offline upgrade packages have been taken offline on January 9th. The online upgrade process to version 3.19 has also been disabled.

If you have a local copy of the version 3.19 offline upgrade package, do NOT use it to upgrade from 3.18.x to 3.19.

The issue does not occur when you perform a fresh installation of Authentication Server Virtual Appliance version 3.19 and the installation files can still be downloaded.

We are working on a solution for this problem and will make the version 3.19.1 available as soon as possible. We estimate version 3.19.1 will be available in week 4 (Week of January 20th).

FortiClient VPN 6.2

Mit dem Release von FortiClient 6.2 wurde der bisherige Full Featured FortiClient lizenzpflichtig und setzt einen FortiClient EMS Server voraus. Im Gegenzug hat Fortinet einen separaten VPN-only Client veröffentlicht. Fortinet beschreibt den FortiClient VPN folgendermassen:

For FortiGate administrators, a free version of FortiClient VPN is available which supports basic IPsec and SSL VPN and does not require registration with EMS. This version does not include central management, technical support, or some advanced features.

Basic IPsec and SSL VPN bedeutet in diesem Zusammenhang, dass folgende Features nicht enthalten sind:

  • IKEv2 support
  • VPN auto-connect/always-up
  • on-net/off-net
  • host check features
  • Central management

Ebenfalls gibt es für die Version 6.2 kein FortiClient Configuration Tool . Um benutzerdefinierte Installationspakete zu erstellen, wird zwingend ein FortiClient EMS Server benötigt.

Der FortiClient VPN ist unter https://www.forticlient.com/downloads erhältlich. Weitere Informationen dazu gibt es im KB Limitation and features on Forticlient.

FortiGate: 802.1x Authentication mit Windows NPS

Die Verbindung zum Windows NPS Server steht und die 802.1x-Authentication ist auf dem Hardware-Switch aktiviert. Obwohl scheinbar alles richtig konfiguriert ist, schlägt die 802.1x Authentication fehl.

Fehlermeldung: 802.1x EAP authentication failed. The port [internal4] is unauthorized and under virtual switch [switch2].
„FortiGate: 802.1x Authentication mit Windows NPS“ weiterlesen

WatchGuard Authentication fails with AuthPoint Gateway lower than version 5.1.5

What is the problem?
AuthPoint Gateway software must be updated to the latest available version, v5.1.5 before the week of 10 October 2019. If you do not update your AuthPoint Gateway before 10 October, it is likely that all authentication will fail for your AuthPoint user base.

When must I update my AuthPoint Gateway?
If you use AuthPoint Gateway software v5.1.3.158 or lower, you must update your Gateway software to v5.1.5 as soon as possible. If you update your Gateway software before the dates referenced below, this issue will not impact you.

  • For AuthPoint users in the APAC cloud region – 10 October 2019
  • For AuthPoint users in the EMEA cloud region – 16 October 2019
  • For AuthPoint users in the AMER cloud region – 17 October 2019
„WatchGuard Authentication fails with AuthPoint Gateway lower than version 5.1.5“ weiterlesen