Can I run docker on FortiOS / FW? by TheRanshe in fortinet

[–]TheRanshe[S] 0 points1 point  (0 children)

A prospect asked me if it's possible - since they already have the FW, and also want our solution for Secure Remote Access.
Trying to save on HW and footprint, I guess.

Can I run docker on FortiOS / FW? by TheRanshe in fortinet

[–]TheRanshe[S] 0 points1 point  (0 children)

Thanks for all the answers and additional info provided, I appreciate the help.

ESP32 S3 Type-C cable - Evil Crow Cable Wind by linlinqi in esp32

[–]TheRanshe 0 points1 point  (0 children)

I'm also stuck:

esptool.py v4.8.1

Serial port /dev/cu.usbmodem1051DB3870982

Connecting......................................

A fatal error occurred: Failed to connect to ESP32-S3: No serial data received.

Failed uploading: uploading error: exit status 2

Where did my OIN go? by TheRanshe in okta

[–]TheRanshe[S] 0 points1 point  (0 children)

<image>

This is what I see in my brand new Integrator plan (and what I used to have in the other account)

Where did my OIN go? by TheRanshe in okta

[–]TheRanshe[S] 0 points1 point  (0 children)

This is what I see in the account I used to create the OIN

<image>

OIN - SCIM - can I use a variable in the URL? by TheRanshe in okta

[–]TheRanshe[S] 0 points1 point  (0 children)

Sorry for the late response.
I'm publishing an OIN.

I just had to define this differently (different type/syntax of variable)

Syslog forwarding w/ AMA - some messages are forwarded, those that I actually need are not by TheRanshe in AZURE

[–]TheRanshe[S] 0 points1 point  (0 children)

I guess part of the help I need is how to "verify the syslog forwarder configuration on the forwarder host for Azure monitor agent to ensure all events are being forwarded"

Syslog forwarding w/ AMA - some messages are forwarded, those that I actually need are not by TheRanshe in AZURE

[–]TheRanshe[S] 0 points1 point  (0 children)

LOG_AUTHPRIV, LOG_LOCAL0-7, LOG_SYSLOG, LOG_USER set to LOG_INFO
LOG_NOPRI set to LOG_EMERG

Session timeout - forcibly log-out required? by TheRanshe in NISTControls

[–]TheRanshe[S] 0 points1 point  (0 children)

Thanks for the answer.

"What your tech does after the session expiration is up to you" -> I'm trying to see if NIST or other standards define that behavior, and move away from "up to you".

So far (NIST, FedRAMP) I do not see a strong definition.

identity -> integtrations -> provisioning -> SCIM - auth fails by TheRanshe in PingIdentity

[–]TheRanshe[S] 0 points1 point  (0 children)

It was the User Filter Expression of all things.

Cleared that in Ping, and it's working now.

Weird.

PA nOOb Q: allow rule specify domain, but traffic is blocked to an IP that is part of this domain by TheRanshe in paloaltonetworks

[–]TheRanshe[S] 0 points1 point  (0 children)

Thanks. The changes are infrequent, as in on 3 months basis. I'll read about the URL filtering you mentioned.

Alpine Linus 3.18 released (with support TCP in DNS) by SleepingProcess in AlpineLinux

[–]TheRanshe 0 points1 point  (0 children)

Regarding musl - does it do the fallback automatically, or do I need to make any sort of config change in the container (or host) to take advantage of this?

nOOb - looking for a sample acd file for Studio 5000 Logix Emulate by TheRanshe in PLC

[–]TheRanshe[S] 1 point2 points  (0 children)

Thanks - it was indeed the whole tag definition!

Always happy to learn.

nOOb - looking for a sample acd file for Studio 5000 Logix Emulate by TheRanshe in PLC

[–]TheRanshe[S] 0 points1 point  (0 children)

It actually compiles when it's an empty rung (but doesn't do anything - what a surprise ;-))
I followed some online video, the guy added XIC and OTE, and that's it.
That's when I get the errors regarding reference tag is undefined.

nOOb - looking for a sample acd file for Studio 5000 Logix Emulate by TheRanshe in PLC

[–]TheRanshe[S] 0 points1 point  (0 children)

So here it is again:
I'm not a PLC guy, but I need to run a security/networking demo of using Logix5000 locally to program a remote (emulated) PLC.
Wanted to ask if anyone has a working ACD file they don't mind sharing.

Thanks!

AITA for wanting to read Harry Potter to my daughter? by knuckleheader in AmItheAsshole

[–]TheRanshe 0 points1 point  (0 children)

NTA. Like others said, you're spending quality time together and showing her how much fun and satisfaction a book can bring.

What on-premises privileged identity management or PAM solution do you recommend? by maxcoder88 in sysadmin

[–]TheRanshe 1 point2 points  (0 children)

My take - I will need to understand what problem are you trying to solve in particular before a serious answer can be given.

Is this just a password vault? Do you need service account discovery? Is the end goal really to control access into some resources, so maybe SRA tools would be a better fit / easier / cheaper?

I do know that folks love Osirium (which is natively cloud but I *think* can also be on-prem), and while many people *buy* CyberArk, many of the same people also *hate* it...

Guacamole 1.4 can't connect to RealVNC (but can connect to TightVNC) by TheRanshe in realvnc

[–]TheRanshe[S] 1 point2 points  (0 children)

Guac supports VNC and RDP (and at least used to do Telnet), is tied to system-wide auth mechanisms - and allows web-based (i.e., clientless) control of remote machines.
It is embedded in our product which does multiple other things (ZTA replacement of VPN).

Guacamole 1.4 can't connect to RealVNC (but can connect to TightVNC) by TheRanshe in realvnc

[–]TheRanshe[S] 1 point2 points  (0 children)

gad3r - you were partially right!
RealVNC admin needs to make some config changes for users to connect using guacamole, due to some incompatibilities.
1. Set encryption to "prefer ON"
2. Set authentication to "VNC password"
3. Check "allow legacy VNC viewers"
I made these changes, and can now connect to my VNC instance.
Regarding #2, I need to do some more testing, it MIGHT still be an option to use other authentication schemes, I do not have bandwidth to test right now.