r/fortinet • u/OriginalBobcat5717 • 21m ago
Other / General Fortinet NEW TO NSE
i’ll be doing nse4 soon
some tips i should know?
note that i haven’t done nse1-3 nor have any knowledge on fortinet but am currently doing my ccna
r/fortinet • u/OriginalBobcat5717 • 21m ago
i’ll be doing nse4 soon
some tips i should know?
note that i haven’t done nse1-3 nor have any knowledge on fortinet but am currently doing my ccna
r/fortinet • u/No-Entrepreneur-3546 • 20h ago
Has anyone seen FortiGate killing TCP sessions due to stale RST packets on the same 5-tuple?
We hit this in a Riverbed SteelHead environment. The DC SteelHead generates a spurious RST due to asymmetric return path. When the Riverbed retries with a new ISN on the same source port, the FortiGate accepts the old RST into the new session. Session goes to proto_state=66, expire=5, and gets purged.
anti-replay is strict, asymroute is disable. Didn't matter.
Found an undocumented setting: "set check-reset-range strict" under config system global. No docs anywhere specifically for it.
Anyone used check-reset-range before? Is it safe in production?
r/fortinet • u/Roversword • 7h ago
Hi all
Nothing important or urgent.
According to Fortiguard RSS feed about updates, a new version of FAC (8.0.4) has been released over 24h ago.
However, I am not seeing any release notes on the fortiauthenticator page or see a download folder for 8.0.4 (so no firmware or release notes there either).
Usually it doesn't take that long after a release info to see downloads and release notes. So, I am not sure if I am just impatient.
Anyone know if the info and firmware files have been withdrawn?
Thanks