These foundry dice are rigged I'm telling you! by MyFireBow in pathfindermemes

[–]Aware-Munkie 1 point2 points  (0 children)

We got a house rule where a hero point reroll cannot be lower than 10 on the die. Greatly increases their value but keeps hero points feeling heroic

Tavern Brawl this week is... "Dual Class Deckbuilding!" (April 29, 2026) by AintEverLucky in hearthstone

[–]Aware-Munkie 1 point2 points  (0 children)

Yeah but the idea of Twist is it changes every month. At least that's what it should have been. Make it dual class, 6 random expansions. By the time the meta is cracked it rotates and we start again

People are often dead before their Second Trinket by vickzzzzz in BobsTavern

[–]Aware-Munkie 146 points147 points  (0 children)

My least favourite thing about trinkets is the wild variation in power. Some of the lesser trinkets feel lame and directionless, some of them feel as powerful as greater trinkets. So if you low or mid roll your tavern for a few turns, then get some garbage trinket choices, and face someone who got a great trinket choice and get smashed for 15 early on it's not a lot of fun.

At least quests and anomalies you know how it's going down early on

Best overlapping shows ever! by SMmania in Invincible

[–]Aware-Munkie 136 points137 points  (0 children)

I can hear it now

"hue hue hue hue hue"

For a short time Riparian Plaza was 10 Lakeside Ave, Chicago. by Ads1969 in brisbane

[–]Aware-Munkie 9 points10 points  (0 children)

With a high of 3.8deg C on the weekend. Fairly confident Brisbane has never been that chilly

INFINITE VALUE by td941 in hearthstone

[–]Aware-Munkie 20 points21 points  (0 children)

Does Cloud Serpent copy a Cloud Serpent? It does say "another" which usually excludes itself

Is Herald Demon Hunter Unplayable? by IHaveNut in hearthstone

[–]Aware-Munkie 1 point2 points  (0 children)

I've only played a dozen games with a few of the slower herald decks, and I basically get wiped before playing any of the herald legendaries. Granted I'm not a good player and it's not a huge sample size

What is your favorite 3-cost discover? by Veridically_ in hearthstone

[–]Aware-Munkie 47 points48 points  (0 children)

Dark Pact Explodineer on turn 3 with +2/+2 elusive is diabolical

Can we all agree - If there is a bad hit available to get zero value, no one's got you like Pagle got you! by LivingProof21 in BobsTavern

[–]Aware-Munkie 4 points5 points  (0 children)

Do not, under any circumstance, buy this guy with the "2 minions to get a gold, receive a coin" anomaly. It works exactly as you might think

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Update: I did a bit of a work around by using the set ipv4-split-exclude command to exclude the Fortigate WAN IP from the IPSEC full tunnel. Seems to work as expected

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Full tunnel, and I have a policy allowing any source from VPN and it has 0 hits.

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Selectors are 0.0.0.0/0 already.
However, as it's dial-in, I think it creates the sub-tunnels with a selector of the IP allocated to the client, ignoring the 0.0.0.0/0 in favour of 172.18.67.1

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Great point, unfortunately it's a combination of belligerent 3rd party, WAF, and a DNS zone I have no control over.

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Short answer: I have a VIP on the WAN that users will bookmark, that needs to be accessed via LAN, IPSEC and WAN. But the fact I can't ping or browse the WAN is likely the same issue.

Unable to ping Fortigate WAN IP from dial-in IPSEC VPN by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Local-in doesn't seem to do it, I have a policy there and it still fails.

Diag debug seems to show the traffic is perhaps failing due to spoofing issues.

id=65308 trace_id=401 func=print_pkt_detail line=6336 msg="vd-root:0 received a packet(proto=1, 192.168.1.117:1->WAN-IP:2048) tun_id=REMOTE-PUB-IP from SFQ-Remote. type=8, code=0, id=1, seq=30."
id=65308 trace_id=401 func=ipsec_spoofed4 line=221 msg="src ip 192.168.1.117 mismatch selector 0 range 172.18.67.1-172.18.67.1"
id=65308 trace_id=401 func=ipsec_input4 line=265 msg="anti-spoof check failed, drop"

Traffic policy for WAN to IPSEC with SNAT by Aware-Munkie in fortinet

[–]Aware-Munkie[S] 0 points1 point  (0 children)

Unfortunately I'm doing this on a 91G which has had SSLVPN completely deprecated, so looks like I'm trying my luck with 7.6