FortiGate Port Reference: Every Port for FAZ, FMG, RADIUS, CAPWAP, and the Rest of the Fabric
Every FortiGate deployment eventually runs into the same wall: a firewall change request, a cloud security group, or an MSSP's...
Read More“diagnose hardware deviceinfo nic”: The Complete Field Reference
diagnose hardware deviceinfo nic: The Complete Field Reference No fluff. Just the config that works. Executive Summary Objective: diagnose hardware...
Read MoreWhat Your Optics Are Trying to Tell You: A Deep Dive into `get system interface transceiver`
The command nobody reads until something breaks Every FortiGate with SFP or SFP+ cages ships with a diagnostic command that...
Read MoreFortiDebug Builder Preview
I created an app named FortiDebug Builder. The idea is to create cli commands for use with troubleshooting FortiGate firewalls. ...
Read MoreTuning the FortiOS IPS Socket Buffer: A Deep Dive into socket-size
Executive Summary Objective: Explain, in real operational depth, what the FortiOS ips global socket-size setting actually does, why it exists,...
Read MoreFortiOS Automatic Restart of Node.js to Prevent Conserve Mode
This enables automatic restart of FortiOS's Node.js process (the "node" daemon), which handles things like Report management, FortiView, Security Fabric/CSF,...
Read MoreTroubleshooting IPSec VPN tunnels in FortiGate Firewalls 2026 Version
This is an updated, expanded version of an older Quick-Tip. Same goal as always: get a VPN tunnel talking again...
Read MoreDeploying OpenSpeedTest on Ubuntu 24.04 LTS for Internal Network Speed Testing
Executive Summary Objective: This guide walks through deploying OpenSpeedTest, a free and open source, self-hosted HTML5 network speed test, on...
Read MoremacOS CLI Networking Cheat Sheet
If you troubleshoot Macs on a network for a living, you already know the GUI only gets you so far....
Read MoreDisabling the FortiConverter Nag Message on Enterprise Bundle FortiGates
As you know, the Enterprise Bundle includes the following (IPS, AI-based Inline Malware Prevention, DLP, App Control, Adv Malware Protection,...
Read MoreDeploying Nuclei on Ubuntu Server
Executive Summary Objective This guide walks through a clean, repeatable installation of ProjectDiscovery's Nuclei vulnerability scanner on Ubuntu Server, covering...
Read MoreIP Addressing and VLSM Made Simple for Beginners
Subnetting has a reputation for being scary. It isn't. Underneath the notation and the math, it's just a way of...
Read MoreDHCP Server Health Checks on macOS with dhcping
1. Title & Executive Summary Objective dhcping sends a single targeted DHCPREQUEST or DHCPINFORM packet at a specific DHCP server...
Read MoreReplaying PCAPs in Scapy: Packet Injection, Address Rewriting, and Timing-Accurate Retransmission
Objective: This guide shows how to use Scapy to load a .pcap file and retransmit its packets onto a live...
Read Moreipcalc Deep Dive: Mastering Subnet Math Across Every Linux Implementation and Homebrew
Executive Summary ipcalc looks like a single, predictable command, but at least three functionally different programs answer to that name...
Read MoreCreating and IP Addressing Scheme Design
Objective: Give you a repeatable method for designing an IP addressing scheme that scales, summarizes cleanly, and doesn’t need to...
Read MoreFortiSwitch Upgrade Status Messages: A FortiLink Field Reference
You kick off a FortiSwitch firmware push from the FortiGate switch controller, and the status column just sits there. Is...
Read MoreUsing FortiExtender as a Terminal Server
This post was take from a document I created for a customer. In my lab, I used a FEX200F which...
Read MoreFortiExtender 511G Deployment Guide
Executive Summary This guide deploys a FortiExtender 511G (FEX-511G) as a cellular WAN extension for a FortiGate 120G running FortiOS...
Read MoreLimitations of an AWS Peering Connection
I had a customer over the weekend that has two VPCs (VPC-A and VPC-B). He created a peering connection between...
Read More