Jump to content

Recommended Posts

Posted

Same here, not had any comms to either of the trusts I work for. Only one use the VPN.

 

Support say they will setup an IPSEC VPN for me but can’t say when.

 

CEO not happy, and just places orders for 7x new connections including 3x 10GB lines

Posted

Comms did go to the hub

 

However :-

 

I raised a ticket via phone, told logged, no ticket was logged

I checked hub, noted nothing logged, logged a ticket manually, no response on this

No Email sent

Posted

Has anyone had any luck getting their IP Sec details for their schools?

 

We didnt get comms sent out either, just noticed checking the hub for another ticket there was an annoucement and we had also had lots of tickets logged so put two and two together.

Posted

@Pheonix121 we are working through the backlog at the moment. We've 2,500 schools using our services so as you can imagine even if a quarter of them use SSL VPN then that's a lot of reconfiguration work to IPSEC. That said, its a lot better than if the bug in the SSL VPN engine was exploited and the chaos that could have caused. I do feel rather sorry for all those Fortinet MSPs that have to either upgrade their firewalls or turn SSL VPN off. Lets hope for their sake they're using FortiManager.....

 

If its really important you need IPSEC VPN immediately please call the team and they'll try do it for you there and then.

 

Dave

Posted

Does anybody know if most of SBB are off for half term? It does feel like it.

 

I reported the FortiGate Vulnerability over 48 Hours ago, firstly by phone, but was told to open a ticket on the Hub. We've had absolutely no communication back.

Posted

We're here and the ticket will be closed an replied to. The team are flat out configuring IPSEC VPNs as per my last post and are having to prioritise tickets.

 

I can though answer your question myself.

 

Regarding the FortiGate vulnerability, this has been alleviated by disabling SSL VPN on our estate following us working with Fortinet. Having discussed with our NOC engineers we are now in receipt of new firmware which fixes the vulnerability in the SSL VPN engine of FortiOS. As we use very large hosted firewalls that each have hundreds of customers on, the new firmware must go through Q&A and rigorous testing before its rolled out so there's no impact to our customer base. We will communicate when the maintenance work to do this will go ahead in due course with a more in depth explanation that I've posted here.

 

 

Thanks

 

Dave

Posted (edited)

Yes but only by nagging

Calls to helpdesk either not answered or hung up

 

Half the time it sounds like Staff are busy having a meal or coffee (work from home is not benefitting the customer)

 

Does not work, example error below

 

2/20/2024 2:07:57 PM Information VPN id=96566 msg="negotiation information, loc_ip=X.X.X.X loc_port=500 rem_ip=X.X.X.X rem_port=500 out_if=0 vpn_tunnel=Work action=negotiate init=local mode=aggressive stage=1 dir=outbound status=success Initiator: sent X.X.X.X aggressive mode message #1 (OK)" vpntunnel=Work vpntype=ipsec

2/20/2024 2:08:09 PM Warning VPN id=96561 msg="locip=X.X.X.X locport=500 remip=X.X.X.X remport=500 outif=0 vpntunnel=Work status=negotiate_error No response from the peer, phase1 retransmit reaches maximum count..." vpntunnel=Work vpntype=ipsec

 

 

This is via tethered mobiles

Sometimes it did work but then instantly dropped

 

Could well be ISP blocking port 500

Will only find out via proper home internet connection

 

That said a number of Staff used SSL VPN via tethered mobile and its loss as a result of switch will not go down well

Edited by Alastairb25
Posted

The main issue I have is there is no way to deploy this VPN as its using Pre Shared Keys, most of our staff even with instructions would fail to set things up correctly not to mention the security implications of staff being able to add their personal devices to the VPN.

 

So this requires my teams to go out to every staff device and set it up one by one and for some of my staff they need several VPN's as they access several sites and we don't permit inter-site communication (yet).

 

Has any one had luck deploying this on mass via Intune, SCCM, script or GPO?

Posted

Hey notalot, and others no doubt, here is the solution to rolling out VPN settings via GPO:

 

You’ll need access to a domain joined PC with the new IPSec settings already in Forticlient.

Open the registry editor and go to the following key.

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\IPSec\Tunnels

Right click and export the entire key that has the name of the new IPSec connection.

Go to the website below and upload the reg file just created.

https://runecasters.com.au/reg2gpp

Save the resulting XML file and copy it to the desktop of the DC.

Open Group Policy editor and edit the relevant GPO (we used the same GPO that installs Forticlient), browse to Computer Policies > Preferences > Registry. You should be able to copy and paste the XML file directly into this window and it will import all the necessary reg keys.

Give this a test on another computer that didn’t have the new connection manually setup just to ensure that the settings are rolled out correctly.

 

Hope this helps everyone out!

 

Nick

Trust IT

Part of Talk Straight Group

http://www.trust-it.co.uk

  • Thanks 1
Posted

Hey Mr Ben,

 

The psk is encrypted in the windows registry so won't mean a lot to anyone thankfully.

 

User details are not saved there either, as far as I'm aware SBB do not allow saving of creds in the VPN config.

 

Thanks

 

Nick

Posted

Why on earth isn’t certificate authentication or user authentication via SAML being used?

 

It’s much more secure.

 

You can disable accounts or revoke certificates.

  • 2 weeks later...
Posted

Hi all, so been working with Schools Broadband with this since the change and still no closer.

 

As Mr.Ben pointed out the PSK is encrypted so cant be pushed out like the SSL VPN was.

 

We looked in to certificate based Auth but this is a per user certificate so would require a certificate authority to be in place which for us currently doesn't exist as some of our sites are Azure joined and not domain joined, I haven't sunk much time in to identifying the requirements for a CA in an Azure Joined domain. Even if we did the VPN still wouldn't be automated and the certificate would change per device.

 

Put bluntly if we ended up having to setup a CA for this we would practically be at a point for always on VPN (DirectAccess).

 

Right now the only option we have is to deploy the tunnel with Reg for the settings then a tech is having to visit the device and add the PSK by hand which is far from ideal but preferred over staff having all the information needed to join their personal devices to our network.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...