<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Fortigate on heezy.blog</title><link>https://heezy.blog/tags/fortigate/</link><description>Recent content in Fortigate on heezy.blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 12 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://heezy.blog/tags/fortigate/index.xml" rel="self" type="application/rss+xml"/><item><title>Networking the Heezy: VLANs, Firewall Zones, and How Traffic Moves</title><link>https://heezy.blog/posts/networking-vlans-and-firewall/</link><pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate><guid>https://heezy.blog/posts/networking-vlans-and-firewall/</guid><description>&lt;p&gt;The network is the foundation of everything in the lab. Four VLANs, a FortiGate doing all the routing, a Cisco 3560 doing the switching, and a set of rules about what can talk to what. This post covers how it&amp;rsquo;s all wired together, how DNS works across zones, and how remote access gets in without exposing anything to the internet.&lt;/p&gt;</description></item><item><title>Tailscale, FortiGate CVEs, and Remote Access That Doesn't Suck</title><link>https://heezy.blog/posts/tailscale-remote-access/</link><pubDate>Tue, 10 Feb 2026 00:00:00 +0000</pubDate><guid>https://heezy.blog/posts/tailscale-remote-access/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;🚧 UNDER CONSTRUCTION 🚧&lt;/strong&gt;
This post is a work in progress.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="the-problem"&gt;The Problem&lt;/h2&gt;
&lt;p&gt;I need to reach into my home network from anywhere. SSH into nodes, check Grafana dashboards, access services that aren&amp;rsquo;t exposed through Cloudflare. The traditional answer is a VPN, and I have a FortiGate sitting right there with IPSec and SSL VPN capabilities built in.&lt;/p&gt;</description></item><item><title>Terraform, Ansible, and the Automation That Runs Everything</title><link>https://heezy.blog/posts/terraform-ansible-automation/</link><pubDate>Sat, 20 Dec 2025 00:00:00 +0000</pubDate><guid>https://heezy.blog/posts/terraform-ansible-automation/</guid><description>&lt;p&gt;This is the story of taking a homelab that was 100% manually configured and turning it into something where every change is a git commit, every deployment is a GitHub Actions run, and I never SSH into a box to make a &amp;ldquo;quick fix&amp;rdquo; again. It took a lot of hours, a lot of broken credential chains, and one memorable incident where I leaked secrets because of echo output. But it works now, and it works well.&lt;/p&gt;</description></item></channel></rss>