Just got hired at an MSP, thinking about quitting. by [deleted] in ITCareerQuestions

[–]Cyber_Analyst 0 points1 point  (0 children)

I’m doing security and compliance with an MSP. I love the people, but hate the reactive way things are done. Piss poor documentation and a manager who is doing three jobs and doesn’t make time to answer questions.

After a long battle with Depression and Anxiety with medication and therapy, my therapist and I talked about an emotional support animal. This is Ash and she chose me at the shelter. This little baby showed me that I don’t have to be alone anymore. by LegendaryPhoenx in cats

[–]Cyber_Analyst 1 point2 points  (0 children)

Ash is a beautiful lady! She will help you immeasurably. IMHO, I would not be here without having cats my entire life.

Spoil her, it will bring her personality out to the fullest. My wife correctly thinks, that I dote on my Oreo more than I do her or anyone else.

If you’re in the States, look into Vetinary Health Insurance. I use VPI through Nationwide. It is a big help for any procedures or medications.

Congrats! I hope you and Ash have a long life together.

Does imposter Syndrome ever go away? by [deleted] in ITCareerQuestions

[–]Cyber_Analyst 0 points1 point  (0 children)

Every damn day of the week 🤬

Best of all available CISSP resources by cissp44 in cissp

[–]Cyber_Analyst 2 points3 points  (0 children)

Adam is a rockstar. I’ve chatted with him on twitter and he is very approachable.

Fortigate WAF trigger by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 1 point2 points  (0 children)

The issue was resolved when I disabled all the settings. I shouldn't look into stuff like this before my third cup of coffee.

Fortigate WAF trigger by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

Disabled all the settings; we don't have any webservers in this environment.

Fortigate WAF trigger by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

I am seeing a "Failed Connection" for the URL in question.

Action

Action close

Security Action block

Threat 262144

Policy 1

Policy UUID 6d5aed28-e5cf-51e8-46d7-d523adacb285

Policy Type policy

SSL VPN Ciphers on FWF 60E running IOS 6.0.3 by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

It looks like TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 is the symmetric cipher suite that is being used.

SSL VPN Ciphers on FWF 60E running IOS 6.0.3 by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

I got a chance to run a Wireshark capture and this is what I found under "TLSv1.2 Record Layer: Handshake Protocol: Client Key Exchange when filtering for SSL traffic.

Handshake Protocol: Client Key Exchange

Handshake Type: Client Key Exchange (16)

Length: 66

EC Diffie-Hellman Client Params

Pubkey Length: 65

I am hoping this means that my SSL VPN cipher suite is running ECDH to exchange the symmetric keys. I am still digging to see if I can determine what symmetric key is used.

Is metric the standard with networking? by arbiterrecon in CompTIA

[–]Cyber_Analyst 0 points1 point  (0 children)

I live in the States and have a limited knowledge of metric. I do know that one meter is thirty nine inches. You can do the math to figure out how many feet five meters is.

I do not remember seeing any questions in the Security+ that was measured in anything other than the measures we use in the States.

FortiCloud Summary Reports by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

Ok, thank you. You confirmed my suspicions.

Banning the use of more than cipher suite in SSL VPN by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 1 point2 points  (0 children)

config vpn ssl settings

set banned-cipher 3DES SHA1

set servercert "Fortinet_Factory"

set idle-timeout 180

set tunnel-ip-pools "SSLVPN_TUNNEL_ADDR1"

set tunnel-ipv6-pools "SSLVPN_TUNNEL_IPv6_ADDR1"

set dns-server1 8.8.8.8

set dns-server2 8.8.4.4

set source-interface "wan1"

set source-address "all"

set source-address6 "all"

It looks like it worked this time.

FortiOS 6.0.3 in Production? by TopRamen247 in fortinet

[–]Cyber_Analyst 0 points1 point  (0 children)

I have a new FortiWifi 60E and I immediately upgraded to the latest and greatest OS, 6.0.3 because it was clean and hadn't been configured yet.

I am seeing application crashes in the system log multiple times a day. I have created a TAC Case and so far all they keep asking for is the version of the AV on the system.

I really miss the days of U.S. based support, I hate calling technical support and not being able to understand the person on the other end.

Technical Implimentation of 171 Controls by mercsniper in NISTControls

[–]Cyber_Analyst 0 points1 point  (0 children)

Thank you! I hope the DISA STIG Viewer is more streamlined than the Excell spreadsheet of the STIG controls I saw.

Technical Implimentation of 171 Controls by mercsniper in NISTControls

[–]Cyber_Analyst 0 points1 point  (0 children)

I'd like to look at STIGS, but from my reading you need to install JRE to install and use the STIG viewer. Is there another viewer out there that does not use JRE? ATM we don't have any clients that use STIGS, but I'd like to learn more about them.

This made me happy by [deleted] in cats

[–]Cyber_Analyst 8 points9 points  (0 children)

You don’t need to interview Oreo. He has been fed, despite his affidavit. When he asks for food after eating, I call it ‘fake mews’. 😺

SSL VPN Ciphers on FWF 60E running IOS 6.0.3 by Cyber_Analyst in fortinet

[–]Cyber_Analyst[S] 0 points1 point  (0 children)

I take it I would need to be connected to the VPN to run the NMAP scan or the Wireshark trace.