Alastairb25 Posted February 13, 2024 Posted February 13, 2024 Hi All, Anyone finding issues? We have fails at 10%, on obvious internal reason Call logged.. TIA Alastair
snagrat Posted February 13, 2024 Posted February 13, 2024 I have submitted a ticket about it as well.
SchoolsBroadband Posted February 13, 2024 Posted February 13, 2024 Hi folks, sorry for my late reply on this I have been in meetings most of the day. Comms have gone out today and is in response to a new FortiGate 0 day vulnerability which we have quickly contained. Thanks Dave
Alastairb25 Posted February 13, 2024 Author Posted February 13, 2024 NHS site lists this issue as of 9th February https://digital.nhs.uk/cyber-alerts/2024/cc-4452 We just got cut off from VPN access No Comms - Emails or phone calls to explain why
snagrat Posted February 13, 2024 Posted February 13, 2024 Same here, not had any comms to either of the trusts I work for. Only one use the VPN. Support say they will setup an IPSEC VPN for me but can’t say when. CEO not happy, and just places orders for 7x new connections including 3x 10GB lines
SchoolsBroadband Posted February 13, 2024 Posted February 13, 2024 I've been assured we did send comms. I'll check with you both personally. Should have come in via email to you both if you're the contact in the hub Dave 1
Alastairb25 Posted February 14, 2024 Author Posted February 14, 2024 Comms did go to the hub However :- I raised a ticket via phone, told logged, no ticket was logged I checked hub, noted nothing logged, logged a ticket manually, no response on this No Email sent
Pheonix121 Posted February 15, 2024 Posted February 15, 2024 Has anyone had any luck getting their IP Sec details for their schools? We didnt get comms sent out either, just noticed checking the hub for another ticket there was an annoucement and we had also had lots of tickets logged so put two and two together.
SchoolsBroadband Posted February 15, 2024 Posted February 15, 2024 @Pheonix121 we are working through the backlog at the moment. We've 2,500 schools using our services so as you can imagine even if a quarter of them use SSL VPN then that's a lot of reconfiguration work to IPSEC. That said, its a lot better than if the bug in the SSL VPN engine was exploited and the chaos that could have caused. I do feel rather sorry for all those Fortinet MSPs that have to either upgrade their firewalls or turn SSL VPN off. Lets hope for their sake they're using FortiManager..... If its really important you need IPSEC VPN immediately please call the team and they'll try do it for you there and then. Dave
WannabrewUK Posted February 15, 2024 Posted February 15, 2024 Does anybody know if most of SBB are off for half term? It does feel like it. I reported the FortiGate Vulnerability over 48 Hours ago, firstly by phone, but was told to open a ticket on the Hub. We've had absolutely no communication back.
SchoolsBroadband Posted February 15, 2024 Posted February 15, 2024 We're here and the ticket will be closed an replied to. The team are flat out configuring IPSEC VPNs as per my last post and are having to prioritise tickets. I can though answer your question myself. Regarding the FortiGate vulnerability, this has been alleviated by disabling SSL VPN on our estate following us working with Fortinet. Having discussed with our NOC engineers we are now in receipt of new firmware which fixes the vulnerability in the SSL VPN engine of FortiOS. As we use very large hosted firewalls that each have hundreds of customers on, the new firmware must go through Q&A and rigorous testing before its rolled out so there's no impact to our customer base. We will communicate when the maintenance work to do this will go ahead in due course with a more in depth explanation that I've posted here. Thanks Dave
Pheonix121 Posted February 20, 2024 Posted February 20, 2024 A week later from the initial incident, has anyone recieved their IP Sec details yet?
snagrat Posted February 20, 2024 Posted February 20, 2024 I have, not tried them though as already setup an iOS config for us which works.
Alastairb25 Posted February 20, 2024 Author Posted February 20, 2024 (edited) Yes but only by nagging Calls to helpdesk either not answered or hung up Half the time it sounds like Staff are busy having a meal or coffee (work from home is not benefitting the customer) Does not work, example error below 2/20/2024 2:07:57 PM Information VPN id=96566 msg="negotiation information, loc_ip=X.X.X.X loc_port=500 rem_ip=X.X.X.X rem_port=500 out_if=0 vpn_tunnel=Work action=negotiate init=local mode=aggressive stage=1 dir=outbound status=success Initiator: sent X.X.X.X aggressive mode message #1 (OK)" vpntunnel=Work vpntype=ipsec 2/20/2024 2:08:09 PM Warning VPN id=96561 msg="locip=X.X.X.X locport=500 remip=X.X.X.X remport=500 outif=0 vpntunnel=Work status=negotiate_error No response from the peer, phase1 retransmit reaches maximum count..." vpntunnel=Work vpntype=ipsec This is via tethered mobiles Sometimes it did work but then instantly dropped Could well be ISP blocking port 500 Will only find out via proper home internet connection That said a number of Staff used SSL VPN via tethered mobile and its loss as a result of switch will not go down well Edited February 20, 2024 by Alastairb25
notalot Posted February 21, 2024 Posted February 21, 2024 The main issue I have is there is no way to deploy this VPN as its using Pre Shared Keys, most of our staff even with instructions would fail to set things up correctly not to mention the security implications of staff being able to add their personal devices to the VPN. So this requires my teams to go out to every staff device and set it up one by one and for some of my staff they need several VPN's as they access several sites and we don't permit inter-site communication (yet). Has any one had luck deploying this on mass via Intune, SCCM, script or GPO?
scooby1000 Posted February 24, 2024 Posted February 24, 2024 Hey notalot, and others no doubt, here is the solution to rolling out VPN settings via GPO: You’ll need access to a domain joined PC with the new IPSec settings already in Forticlient. Open the registry editor and go to the following key. Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Fortinet\FortiClient\IPSec\Tunnels Right click and export the entire key that has the name of the new IPSec connection. Go to the website below and upload the reg file just created. https://runecasters.com.au/reg2gpp Save the resulting XML file and copy it to the desktop of the DC. Open Group Policy editor and edit the relevant GPO (we used the same GPO that installs Forticlient), browse to Computer Policies > Preferences > Registry. You should be able to copy and paste the XML file directly into this window and it will import all the necessary reg keys. Give this a test on another computer that didn’t have the new connection manually setup just to ensure that the settings are rolled out correctly. Hope this helps everyone out! Nick Trust IT Part of Talk Straight Group http://www.trust-it.co.uk 1
Mr.Ben Posted February 24, 2024 Posted February 24, 2024 Going to suggest that uploading your VPN details to a random website isn't a great idea...
scooby1000 Posted February 24, 2024 Posted February 24, 2024 Hey Mr Ben, The psk is encrypted in the windows registry so won't mean a lot to anyone thankfully. User details are not saved there either, as far as I'm aware SBB do not allow saving of creds in the VPN config. Thanks Nick
free780 Posted February 25, 2024 Posted February 25, 2024 Why on earth isn’t certificate authentication or user authentication via SAML being used? It’s much more secure. You can disable accounts or revoke certificates.
notalot Posted March 5, 2024 Posted March 5, 2024 Hi all, so been working with Schools Broadband with this since the change and still no closer. As Mr.Ben pointed out the PSK is encrypted so cant be pushed out like the SSL VPN was. We looked in to certificate based Auth but this is a per user certificate so would require a certificate authority to be in place which for us currently doesn't exist as some of our sites are Azure joined and not domain joined, I haven't sunk much time in to identifying the requirements for a CA in an Azure Joined domain. Even if we did the VPN still wouldn't be automated and the certificate would change per device. Put bluntly if we ended up having to setup a CA for this we would practically be at a point for always on VPN (DirectAccess). Right now the only option we have is to deploy the tunnel with Reg for the settings then a tech is having to visit the device and add the PSK by hand which is far from ideal but preferred over staff having all the information needed to join their personal devices to our network.
whartomt01 Posted March 5, 2024 Posted March 5, 2024 Sure i've used this to export and import via PowerShell https://docs.fortinet.com/document/forticlient/6.0.1/xml-reference-guide/749677/back-up-and-restore-command-line-utility-commands-and-syntax
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now