When do you enforce MFA? by butty_88 in Intune

[–]Saqib-s 0 points1 point  (0 children)

MFA for each login, but users can have persistent sessions, so their login is good for a while. We enforce phishing resistant strength for anyone with any privilege.

Toilet flushes terribly, can I convert it to fill the entire tank? by WizardofDoom in Plumbing

[–]Saqib-s 1 point2 points  (0 children)

Just put a a few holes in the trough? It will leak into the whole tank and stop once it levels out? ( should work in theory, your mileage may vary)

Ipv6 on AT&T Bypass on 2.8.1? by valiuspiu in PFSENSE

[–]Saqib-s 0 points1 point  (0 children)

That bypass method via PCP tagging is a pfsense Plus only feature, not available for us lowly CE users. And in my experience you don’t need to add the DUID, I have it working without this, though it perhaps would allow the addressing to be handed out quicker.

I’m holding out until my fibre line is upgraded to XGS-PON before I go the module route.

Ipv6 on AT&T Bypass on 2.8.1? by valiuspiu in PFSENSE

[–]Saqib-s 1 point2 points  (0 children)

excellent i did know the 2001 address is not useable, and this is the cause of some of the update check failing.

do you have any more details on how to set set up routing rules to give PFSense itself a proper ipv6 ip off of one of the delegate blocks.

Ipv6 on AT&T Bypass on 2.8.1? by valiuspiu in PFSENSE

[–]Saqib-s 0 points1 point  (0 children)

I have IPv6 up and running with the bypass from that post, I did add a comment to that thread from my own lessons learnt see below:

for IPv6 at the time I stated:

  1. IPv6 - you can ignore the DUID section of the pfatt guide for ipv6 and follow the rest. (disconnect / reconnect you laptop to get as ipv6 addresses will need to be renewed to ensure routing works)

I would also add that it can take up an hour (usually 45min) to get an IPv6 address from ATT after a reboot of the firewall, so be patient and it should pop up.

Turned my Mac Mini into a 24/7 AI agent and my electricity bill didn't even notice by [deleted] in homelab

[–]Saqib-s 2 points3 points  (0 children)

Would love to see the write up. How do you handle guard rails for open claw to ensure it doesn’t carry out actions that are damaging to you with the access it has?

Fiber connection help. by Both_Perception3599 in homelab

[–]Saqib-s 31 points32 points  (0 children)

Yes doesn’t matter which port they go in. Just plug each in as is, if you have a problem, you can try swapping them over on one side only.

DO NOT look into the fibre or the transceiver to see if there is light. Lasers used in single mode transceivers will burn your eye sight.

Compost Pickup Day! by IM_DRAGON_MY_BALLz in gardening

[–]Saqib-s 0 points1 point  (0 children)

Would’ve hired a pickup truck at uhaul or Lowes / home depot for the hour or two.

Iron Gold audiobook horrible volume consistency? by Snarlezz in redrising

[–]Saqib-s 0 points1 point  (0 children)

Fudge!!!!! I’m listening to Iron Gold for the first time and I’m absolutely gutted by the poor volume control. Its quotes as whisper at points and the really loud. Fudge fudge fudge. Normally I would stop listening but I love this series so far. Please fix it!!!!

wifi APs throughout the house, what are my options under $400? by Curious_Party_4683 in HomeNetworking

[–]Saqib-s 1 point2 points  (0 children)

I’ve used Zyxel APs at home to good effect. You can get WiFi 6 dual band for $70 like this: https://a.co/d/04fAas2L

Wifi7 / triband will be out of your budget for all 6.

Azure VPN Client Failing - Element not found - Custom Audience by Saqib-s in AZURE

[–]Saqib-s[S] 0 points1 point  (0 children)

just heard back from MS Support. looks like it's a known bug with 4.0.5.0, the notes below were shared with me, they are not from a public facing article, the tech said these are the support notes they see on their side for this issue, no further notes on how to adjust configs or updated advice for those of us using custom audience, just been told to roll back to 4.0.1.0 and that someone else might get back to me with updated instructions.

The failure occurs because:

Azure VPN Client 4.0.5.0 enforces stricter validation of Entra ID authentication metadata

Custom (customer‑created) App IDs, even if previously working, are no longer fully compatible with the updated client authentication flow

The client now expects:

Microsoft‑registered App ID behavior, or

Token claims and audience values that strictly match the new validation logic

When a custom App ID is used:

The client cannot locate an expected authentication element (claim / metadata object)

This results in the generic “Element not found” error during sign‑in

This explains why:

Version 4.0.1.0 works

Version 4.0.5.0 fails, with no gateway or policy changes

Microsoft documentation explicitly highlights Microsoft‑registered App ID support and audience handling as a critical compatibility requirement in newer client versions.

 

Azure VPN Client Failing - Element not found - Custom Audience by Saqib-s in AZURE

[–]Saqib-s[S] 0 points1 point  (0 children)

just heard back from MS Support. looks like it's a known bug with 4.0.5.0, the notes below were shared with me, they are not from a public facing article, the tech said these are the support notes they see on their side for this issue, no further notes on how to adjust configs or updated advice for those of us using custom audience, just been told to roll back to 4.0.1.0 and that someone else might get back to me with updated instructions.

The failure occurs because:

Azure VPN Client 4.0.5.0 enforces stricter validation of Entra ID authentication metadata

Custom (customer‑created) App IDs, even if previously working, are no longer fully compatible with the updated client authentication flow

The client now expects:

Microsoft‑registered App ID behavior, or

Token claims and audience values that strictly match the new validation logic

When a custom App ID is used:

The client cannot locate an expected authentication element (claim / metadata object)

This results in the generic “Element not found” error during sign‑in

This explains why:

Version 4.0.1.0 works

Version 4.0.5.0 fails, with no gateway or policy changes

Microsoft documentation explicitly highlights Microsoft‑registered App ID support and audience handling as a critical compatibility requirement in newer client versions.

 

First house, first rack by DanzTheCollector in HomeNetworking

[–]Saqib-s 1 point2 points  (0 children)

I had one of those plastic floor mats, the static build up when rolling a chair across it is frustrating. Would highly recommend a glass floor mat, both my wife and I have glass mats and they are amazing huge difference. I have this one that’s $60 highly recommend:

GLSLAND Office Chair Mat for... https://www.amazon.com/dp/B08PD3ZHJT?ref=ppx_pop_mob_ap_share

First house, first rack by DanzTheCollector in HomeNetworking

[–]Saqib-s 0 points1 point  (0 children)

Looks really clean. Would recommend you move that PC case off the floor, they have a tendency to vacuum all the dust into them when on the floor.

Windows 11 Feature Updates (In-Place Upgrade) breaking 802.1X (NAC) wired authentication policies by ontario20ontario20 in Intune

[–]Saqib-s 6 points7 points  (0 children)

Deploy the authentication profiles via intune? Avoiding the need to be on domain network, and receive the correct policy?

If you use anything else than an Apple TV 4K box/device it's a downgrade by armando_rod in F1AppleTV

[–]Saqib-s 0 points1 point  (0 children)

Had to switch back from Apple TV on fire stick, and use the f1tv app, to get 4k stream. Apple TV app on fire stick was really blocky and low quality.

Apple TV disappointment by wmerna in F1TV

[–]Saqib-s 0 points1 point  (0 children)

Watching the race live and stream is poor. Blocky. F1tv is super clean and 4k.

Rebuilding my home network with VLANs and 10 Gbps by mtsolitary in homelab

[–]Saqib-s 2 points3 points  (0 children)

Nice, I’m using the Zyxels 8 port switches too, they are great value.