#TIL Fortinet IPsec VPNs: they claim to support IKEv2 2FA (Certificate + EAP password), but they don't strictly enforce RFC 4739 for multiple authentication rounds.
If a native client (like strongSwan) ignores the cert and just asks for EAP, the FortiGate silently accepts it and falls back to password-only. It literally fails open!
Cloudflare becomes first SASE platform with post quantum encryption across entire stack
https://fed.brid.gy/r/https://nerds.xyz/2026/02/cloudflare-post-quantum-sase/
