The problem is not limited to Fortinet or Palo Alto Networks software. Since the cause for the problem is a design flaw in the RADIUS protocol, this flaw affects most products using RADIUS for authentication or accounting.
Is Your FortiGate Under Attack?
In this article, we want to point out some indicators used to determine if your FortiGate is under attack.
FortiGate with FortiOS 7.4: First Configuration Steps
Last update: 11. October 2024 In our daily support work we often see FortiGates in use on which the basic settings like time zone, host name and so on have never been set correctly. Therefore we would like to provide you with a small guide on this page, with which…
FortiSwitch not Applying Configuration from FortiGate
Do you have FortiSwitches that do not accept configuration changes made on the FortiGate switch controller? Also, when you run the CLI command ‘execute switch-controller get-conn-status’, do you see the ‘flag’ with a value of ‘E’?
Remediation Steps if your FortiGate got Hacked or Attacked
… or accessed from any unauthorized party. In some cases it’s not even necessary to hack a system to gain access to it. For example it may be enough to leak a configuration file to allow unauthorized system access. Fortunately, many cases of a suspected hack turn out to be…
MS365 Exchange Online and SeppMail Mailflow interrupted (UntrustedRoot)
We have received several support requests regarding interrupted mailflow between Exchange Online and SeppMail appliances. The mailflow is interrupted since 07.03.2024 at 23:00 CET time. In the MS365 logs, the following error message is shown:
How to configure the FortiGate for a 3CX UC system with SIP trunk
3CX is a very widespread UC solution (phone system or also known as PBX). FortiGate is a very widespread firewall solution. Both of the products are very good in doing their thing. But to work together, a littlebit of configuration work is needed. Below you can find an example configuration…
SeppMail and MS365 Exchange Online: So wird das ARC sealing konfiguriert
Im Boll Support treffen in den letzten Wochen vermehrt SeppMail Anfragen ein. Seit Microsoft in MS365 Exchange Online einige Anpassungen im Spamfilter (Defender Funktion) gemacht hat, werden die Mails als Spam quarantänisiert, welche von der SeppMail zu MS365 in paralleler Konfiguration hochgesendet werden. Offenbar wurde die Änderung noch nicht auf…
FortiGate virtual server webpages loading infinite
Fortinet has introduced a new configuration parameter in FortiOS 7.2.4 and higher. The setting is “http-supported-max-version” that is configurable under “config firewall vip”. Symptoms After an upgrade of the FortiOS to 7.2.4, some websites that are published over a virtual server on the FortiGate are loading infinite. A part of…
FortiGate Memory and CPU Troubleshooting
From time to time we face performance problems on FortiGate units in our daily support life. Most often the impacts of performance problems on the FortiGate are not typical. Or let’s say “not as an admin that is not familiar with FortiGates would expect”. The expectations vary from high delay…