DHCP Server Health Checks on macOS with dhcping
1. Title & Executive Summary Objective dhcping sends a single targeted DHCPREQUEST or DHCPINFORM packet at a specific DHCP server...
Read MoreReplaying PCAPs in Scapy: Packet Injection, Address Rewriting, and Timing-Accurate Retransmission
Objective: This guide shows how to use Scapy to load a .pcap file and retransmit its packets onto a live...
Read Moreipcalc Deep Dive: Mastering Subnet Math Across Every Linux Implementation and Homebrew
Executive Summary ipcalc looks like a single, predictable command, but at least three functionally different programs answer to that name...
Read MoreCreating and IP Addressing Scheme Design
Objective: Give you a repeatable method for designing an IP addressing scheme that scales, summarizes cleanly, and doesn’t need to...
Read MoreFortiSwitch Upgrade Status Messages: A FortiLink Field Reference
You kick off a FortiSwitch firmware push from the FortiGate switch controller, and the status column just sits there. Is...
Read MoreUsing FortiExtender as a Terminal Server
This post was take from a document I created for a customer. In my lab, I used a FEX200F which...
Read MoreFortiExtender 511G Deployment Guide
Executive Summary This guide deploys a FortiExtender 511G (FEX-511G) as a cellular WAN extension for a FortiGate 120G running FortiOS...
Read MoreLimitations of an AWS Peering Connection
I had a customer over the weekend that has two VPCs (VPC-A and VPC-B). He created a peering connection between...
Read MoreTCP Flags Deep Dive: Meaning, Behavior, and Troubleshooting
Objective: This guide breaks down all nine TCP control bits, traces exactly how they combine across a connection's lifecycle from...
Read MoreFortiGate Packet Capture: The Complete Advanced Filter Syntax Reference
Every filter you can type into the Advanced field is standard BPF, the same syntax tcpdump and diagnose sniffer packet...
Read MoreWhere does the “Sequence Group” live in the FortiGate CLI Config
Do you use Sequence Groups In your Firewall Policies? I absolutely love them. I used to use them in Checkpoint. ...
Read MoreRemoving NAG Screen on Wireshark 4.6.7
The other day, I opened my Wireshark for macOS and found some ads and some nag stuff about donations and...
Read MoreBuilding a GRE Tunnel Between a FortiGate Firewall and a Cisco Router
1. Executive Summary Objective This guide walks through the end-to-end deployment of a Generic Routing Encapsulation (GRE) tunnel between a...
Read MoreCisco ASA and FTD Encryption Schemes. What is supported on what version : The Complete Reference
If you have ever tried to stand up a site-to-site tunnel between an ASA running 9.8 code and a newer...
Read MoreMastering FortiGate Service Objects: Custom Services, Groups, Categories, and the Options Nobody Uses
1. Executive Summary Objective This guide takes the FortiGate service object from the five fields everyone knows to the full...
Read MoreFortiGate Firewall Policy: Every Option set ? Will Show You
The FortiGate GUI shows you maybe forty percent of what a firewall policy can actually do. The rest lives in...
Read MoreThe FortiGate Interfaces You Never Created: naf.root, ssl.root, and Every Default VLAN Explained
Version target: FortiOS 7.6.x, with behavior flagged where 7.0 / 7.2 / 7.4 differ. Commands are shown from the CLI....
Read MoreStandardizing FortiGate Interface Roles: LAN, WAN, DMZ, and Undefined
1. Executive Summary Objective This guide establishes a deterministic, auditable interface role standard across a FortiGate estate and explains precisely...
Read MoreMastering FortiGate SSID Settings: Traffic Mode, Security Mode, Broadcast Suppression, Quarantine, VLAN Pooling, and NAC Profiles
1. Executive Summary Objective This guide walks through the six SSID settings that determine how a FortiGate-managed wireless network actually...
Read MoreDeploying FortiClient on Ubuntu Linux: The Complete CLI Reference for Desktop and Headless Endpoints
1. Executive Summary Objective This guide takes an Ubuntu 22.04 or 24.04 LTS host from bare OS to a fully...
Read More