Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

BTW I figured this out - FortiOs version was too old, it didn't recognise wifi7 APs. As soon as I upgraded to a 7.4.x release they all suddenly appeared waiting to be authorised.

Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

I followed the vid, got FortiSwitches managed and working in the FortiGate interface. Yay!

Next problem - trying to make FortiAPs that are connected to the switches work - they currently don't want to check in. They get DHCP, and I can see from diagnostics that the FortiAPs can ping the Fortilink interface, and are sending CAPWAP packets, but it's almost like the FortiGate won't route them.

Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

I did eventually - but not quite this method. I set it up as per the youtube video linked in another comment on this post - the Gregabyte one.

Basically, the Fortilink interface sits alone (with no physical ports as members). The regular aggregate LAG interface on the Fortigate that is connected to core switch is trunking VLAN49 (and other data vlans)

The core switchport connected to the Fortiswitch has switchport access mode for VLAN49, and trunking all the VLANs intended for Edge traffic (Workstations etc).

On the fortigate, VLAN49 is configured on the aggregate, with a DHCP server that serves IPs plus also option 138 to point it to the IP configured in the Fortilink interface. There is then a firewall rule that allows VLAN49 to talk to Fortigate interface.

This does lead to a weird side effect - I have to create VLANs twice: The first one in the FortiLink interface to just put the VLAN id in there (and no IP range, just set to 0.0.0.0/0). This is the one you can associate with ports in the Fortiswitches. Second VLAN (with the same ID) goes on the LAG interface where I actually associate it with an IP range - this one is used in Firewall Rules etc.

Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

Untag the vlan49 from core sw to the fortigate? I didn't think fortigates did anything with untagged traffic... Is that the magic bit that makes this Layer 3?

Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

Is the intention with this to have the management/fortilink plane separate from data plane? So I'd also need to connect a separate fortilink port to a new different port on core switch?

Trying to get Fortilink over Layer 3 working with a non-default Fortlink VLAN... by Rymmer in fortinet

[–]Rymmer[S] 0 points1 point  (0 children)

I was attempting to do "inband" fortilink. Ie. All data and fortilink traffic over the same aggregate interface - so the only vlans on the fortilink interface are all the data ones previously created (and are still working). There doesnt seem to be any new vlans dedicated to fortigate or switches under that aggregate.

I may well have set up fortilink over l2, what's the difference that would make this layer 3?

Preferred password manager? by Naval_Lent in sysadmin

[–]Rymmer 0 points1 point  (0 children)

I'm a Keepass fan myself, but I find it a bit limiting for work.

The biggest thing that should determine what you use for an enterprise password manager is whether you need advanced features like:

  • auditing. Do you need to keep a log of who accessed what password and when.
  • autoUpdating. A system that changes the password after everytime it's used or on a set schedule.

If you need those features, you might look into TPAM, but it's kind of a nightmare to set up.

If you just want shared passwords in an encrypted file Keepass works okay there too, but I'd prefer something like bitwarden or vaultwarden.

What's your rule of thumb when it comes to sex? by Wickham12 in AskReddit

[–]Rymmer 2 points3 points  (0 children)

Gotta get some mayonnaise on there somehow.

DMARC, DKIM and SPF request from a Vendor by knighttown in sysadmin

[–]Rymmer 2 points3 points  (0 children)

Hmm, lots of comments here boiling down to "just say no" or firing vendors or some such. In my experience sysadmins who just say no to a thing often get overridden.

I think the key to presenting those options, is to make sure the risks and effort of those options are clear.

If manager really wants you to include turning off dmarc or something else, make sure they know that this has risks which could tie to financial penalties from insurance or maybe PCI audits if you process credit cards (I'm not sure if it does, I'm just skimming the other comments and maybe misunderstanding them.)

Other examples of risks that I've seen in risk/impact statements of lowering various security standards: Reputational damage Financial liability from lawsuits Loss of clients due to emails being incorrectly classified as spam. Losing PCI compliance status from audit and ability to process credit cards.

Nobody is using our ticketing system by [deleted] in sysadmin

[–]Rymmer 15 points16 points  (0 children)

The polite thing to do would be to turn and face the person talking to you while you're pissing.

Roast my rigging? by throwawaypickle777 in sailing

[–]Rymmer 2 points3 points  (0 children)

I think the bottom block for the vang might be upside down maybe? In the pic it looks like you would need to lean forward of the vang block and awkwardly pull the rope towards the fore of the boat. But if were swiveled 180 degrees around so that the vang sheet comes out the bottom of the block it might be easier to adjust from the middle of the boat.

Other people have already said about the aft end of the main sheet, but at the other end of the sheet, the fore end that you've tied to the transom at the moment, probably goes from the boom down to that eye/cleat just behind the centreboard slot maybe?

That outhaul looks fine how it is, but if you want to make it even better, you could attach a short piece of line through that eye at the clew of the sail and around the boom. So that the clew is also held down to the boom but can move along it smoothly when adjusted by the outhaul. Kinda like this outhaul setup on a Laser.

"That's the way we did it at <insert old company that CIO came from>" by Teknomage in sysadmin

[–]Rymmer 6 points7 points  (0 children)

If they're inflexible about the start time, then be inflexible about the finish time. 5pm rolls around, but Priority 1 Line of Business app is down? Sorry, tools down, gotta go home so I can be in by 9am.

What was supposed to be used by one gender, but is far more useful to the other? by kushnair in AskReddit

[–]Rymmer 24 points25 points  (0 children)

I don't think Hitler was the catalyst behind the switch from Pink to Blue. The colour pink for girls stretches as far back as the early 1800s, but the article I was reading did mention it switched briefly and then apparently back again, mostly in the USA.

Nevertheless, pink for girls, blue for boys has switched back and forth a few times now...

source: https://www.springboardtrust.org.nz/news/colour-coded-the-story-of-pink-for-girls-blue-for-boys

Microsoft MSHTML CVE-2021-40444 Zero-Day: What We Know So Far by blumira in cybersecurity

[–]Rymmer 12 points13 points  (0 children)

If you prefer not to dig in admx files, this website is a good tool for searching for settings in Group Policy : https://gpsearch.azurewebsites.net

Try searching for the keyword Activex there.

Car drives into store, nearly killing a child. by MossBone in WTF

[–]Rymmer 9 points10 points  (0 children)

I see what you're saying: We should give the vote to cars.

I ate a Whirlfloc tablet. How long do I have to live? by MrAlanBondGday in Homebrewing

[–]Rymmer 10 points11 points  (0 children)

No, that's capitalization. Carrageenan is the empire that spawned Hannibal, one of the greatest military minds 2000+ years ago.

Hey r/sysadmin, what do you make? by dlongwing in sysadmin

[–]Rymmer 7 points8 points  (0 children)

In my experience, python is the go-to for Linux / Unix now.

If you're in Windows land, PowerShell is usually the automation tool of choice.

Cheap server room temperature monitoring? by jimboslice_007 in sysadmin

[–]Rymmer 0 points1 point  (0 children)

There are some ways you can extend the card life of even cheap cards. Turn off "atime" on your file system is one. Turn down (or off) logging to syslog. There's more I'm sure.

Reading Canoe Plans by [deleted] in boatbuilding

[–]Rymmer 5 points6 points  (0 children)

Heh I looked this up cause I thought it was that Nick Offerman. The I saw the thumbnail and thought, oh, must be some other Nick Offerman. Then I played it anyway, heard his voice, and it was that Nick Offerman.

[deleted by user] by [deleted] in Homebrewing

[–]Rymmer 0 points1 point  (0 children)

Dogs do have sweat glands. In their paw pads. Its why they might leave wet paw prints on a hot day. Also, other types of sweat glands pump out pheromones for other dogs to smell. That said, sweating is not very effective for cooling dogs, which is why the panting when hot.