The FortiGate Interfaces You Never Created: naf.root, ssl.root, and Every Default VLAN Explained
Version target: FortiOS 7.6.x, with behavior flagged where 7.0 / 7.2 / 7.4 differ. Commands are shown from the CLI....
Read MoreStandardizing FortiGate Interface Roles: LAN, WAN, DMZ, and Undefined
1. Executive Summary Objective This guide establishes a deterministic, auditable interface role standard across a FortiGate estate and explains precisely...
Read MoreMastering FortiGate SSID Settings: Traffic Mode, Security Mode, Broadcast Suppression, Quarantine, VLAN Pooling, and NAC Profiles
1. Executive Summary Objective This guide walks through the six SSID settings that determine how a FortiGate-managed wireless network actually...
Read MoreDeploying FortiClient on Ubuntu Linux: The Complete CLI Reference for Desktop and Headless Endpoints
1. Executive Summary Objective This guide takes an Ubuntu 22.04 or 24.04 LTS host from bare OS to a fully...
Read MoreEVPN Route Types: The Practitioner’s Field Guide
Everyone learns EVPN as "type 2 carries MACs and type 5 carries prefixes," then gets wrecked the first time a...
Read MoreXDR vs. SOAR: Is Your Tech Stack Redundant or Resilient?
The short answer. XDR and SOAR overlap on automated response and enrichment. They do not overlap on scope. XDR automates...
Read MoreThe Clock Is Ticking: What CA/B Forum’s Ballot SC-081v3 Means for the Future of Web Security
If your team manages SSL/TLS certificates using spreadsheets, calendar reminders, or manual renewals, consider this your official wake-up call. In...
Read MoreBeyond the Prompt Series: Multimodal Models: Teaching the Transformer to See
Vision encoders, projectors, and the 2026 move from bolt-on bridges to native multimodality. A multimodal model is an LLM that...
Read MoreThe Certificates Your FortiGate Ships With, and What to Do With Them
Every FortiGate arrives with a populated certificate store. Nobody put them there for decoration. Some are load-bearing device identity you...
Read MoreThe SSH Key Fallacy: Why Static Keys Are Not Access Control, and How to Fix It With an SSH Certificate Authority
1. Executive Summary Objective: Moving from passwords to SSH public keys feels like a security upgrade, and in one narrow...
Read MoreWake-on-LAN from the FortiGate: Firing a Magic Packet with execute wake-on-lan
You need to power on a box that is sitting dark on a remote segment. A lab host, a NAS,...
Read MoreDeploying a FortiGate as an IPsec IKEv2 Remote-Access VPN Concentrator for Linux Clients with FortiToken MFA
1. Title & Executive Summary Objective: This guide stands up a single FortiGate as an IPsec IKEv2 dialup VPN concentrator...
Read MoreSecuring Email with DNS: A Practitioner’s Guide to SPF, DKIM, DMARC and the Modern Authentication Stack
Executive Summary Objective This guide walks you end to end through the DNS-published controls that authenticate email and stop domain...
Read MoreDecoding SMTP Errors and Mail Failure Messages: A Practitioner’s Diagnostic Guide
1. Executive Summary Objective: This guide turns cryptic SMTP reply codes, enhanced status codes, and bounce (NDR/DSN) messages into a...
Read MoreA little TCP story…
Today I was on LinkedIn in the AM to monitor for friends moving companies etc. And I came across a...
Read MoreHTTP Error Messages Decoded: A Practitioner’s Field Guide to Status Codes and What They Actually Mean
1. Executive Summary Objective. This guide turns the three-digit HTTP status code sitting in your logs, your browser dev tools,...
Read MoreDeploying FRRouting on Ubuntu 24.04 LTS: Production BGP and OSPF Routing
1. Executive Summary Objective. This guide turns a stock Ubuntu 24.04 LTS host into a fully functional software router using...
Read MoreBuilding a Stateful Host Firewall and NAT Gateway with nftables
1. Executive Summary Objective: This guide walks you through building a complete, production-grade firewall on modern Linux using nftables: a...
Read MoreFortiGate VDOM Deep Dive: Designing, Deploying, and Operating Multi-VDOM on FortiOS
Note: Version target: FortiOS 7.6.x on an NP6/NP7-class FortiGate. CLI is consistent from 6.2 onward except where flagged. Where a...
Read MoreAuditing Web Servers with Nikto 2.6.0: A Practitioner’s Field Guide to Configuration Scanning
1. Executive Summary Objective: This guide takes you from a clean host to a repeatable, reportable Nikto workflow you can...
Read More