Hot!Fortigate and Bitlocker Network Unlock

Author
Robin Svanberg
Bronze Member
  • Total Posts : 49
  • Scores: 8
  • Reward points: 0
  • Joined: 2013/03/17 14:20:57
  • Status: offline
2018/09/26 02:44:43 (permalink)
0

Fortigate and Bitlocker Network Unlock

Hi,
 
have an issue with Bitlocker Network Unlock and a Fortigate.
 
We have configured DHCP relays to both the DHCP server and WDS where the Bitlocker Network Unlock role is installed and can see that traffic to both relays work fine.
 
But when the client sends the actual Bitlocker boot request the packet isn´t being forwarded by the Fortigate. We can see the broadcast but nothing happens to it :( The packet looks OK so not really sure why it isn´t forwarded.
 
Anyone running Bitlocker Network Unlock and Fortigates or have any idea why the packets aren´t being forwarded? 
 

 
BR Robin
post edited by Robin Svanberg - 2018/09/26 02:46:05

Attached Image(s)

#1

2 Replies Related Threads

    Hultis
    New Member
    • Total Posts : 1
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/31 03:35:57
    • Status: offline
    Re: Fortigate and Bitlocker Network Unlock 2019/01/31 03:38:39 (permalink)
    0
    Hello,
     
    I have the same problem. Have you solved it?
     
    #2
    Robin Svanberg
    Bronze Member
    • Total Posts : 49
    • Scores: 8
    • Reward points: 0
    • Joined: 2013/03/17 14:20:57
    • Status: offline
    Re: Fortigate and Bitlocker Network Unlock 2019/02/06 16:53:16 (permalink)
    0
    Hultis
    Hello,
     
    I have the same problem. Have you solved it?
     




    We haven´t solved the root cause but did a workaround with a multicast policy which only forwards broadcasts for port 67-68 UDP to be proceed with the Bitlocker Network Unlock POC. 
     
    config system interface
    edit "Clients"
    set broadcast-forward enable
    next
    end
     
    config firewall multicast-policy
    edit 1
    set srcintf "Clients"
    set dstintf "Servers"
    set srcaddr "all"
    set dstaddr "broadcast"
    set protocol 17
    set start-port 67
    set end-port 68
    next
    end
     
     
    #3
    Jump to:
    © 2019 APG vNext Commercial Version 5.5