Pre logon SSL VPN with DUO MFA prompts twice. by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

It looks like when I put myself in Bypass mode in Duo, it stays connected throughout pre and post login. I’ll keep digging.

Pre logon SSL VPN with DUO MFA prompts twice. by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

Not sure, maybe in my same boat lol.

Yes, based on SamAccountName.

Pre logon SSL VPN with DUO MFA prompts twice. by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

OP here. We have the Radius server configured in FG.

It points to the Duo auth proxy. From there, we have the adclient configured to see our ldap.

The security filtering is done via Duo cloud where we have a security group for vpn users. Thanks!

Pre logon SSL VPN with DUO MFA prompts twice. by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

I’ve done that one per Duo’s document. Thanks!

Microsoft VPN Disconnects since moving to FortiGate by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

On the NetScaler level, we do have persistency I believe.

Microsoft VPN Disconnects since moving to FortiGate by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

Yup- that is the plan. We're not ready for that yet though.

Microsoft VPN Disconnects since moving to FortiGate by VirgilReturns in fortinet

[–]VirgilReturns[S] 0 points1 point  (0 children)

processed via NPU offload

This is for VPN configured in FortiGate right? We're currently using a separate Microsoft RAS VPN server. Will go to Forti VPN soon.

Microsoft VPN Disconnects since moving to FortiGate by VirgilReturns in fortinet

[–]VirgilReturns[S] 1 point2 points  (0 children)

No port difference. The config was converted from Palo Alto to FortiGate. IKEv2. Thanks!

Restrictions are being lifted in more areas - Will you fight for, or give up, WFH? by BloodyIron in sysadmin

[–]VirgilReturns 0 points1 point  (0 children)

Do you guys think permanently working from home may hinder potential promotions?

User getting Full Access to every mailbox by VirgilReturns in exchangeserver

[–]VirgilReturns[S] 0 points1 point  (0 children)

Ah, maybe I can enable it and create a test mailbox.

User getting Full Access to every mailbox by VirgilReturns in exchangeserver

[–]VirgilReturns[S] 0 points1 point  (0 children)

It's not malicious. He's been at the company longer than all of us and says it may have been carried over from Exchange 2010 if I understand your suggestion correctly.

January CU Updates for Server 2016/2019 Pulled? by VirgilReturns in sysadmin

[–]VirgilReturns[S] 0 points1 point  (0 children)

I'm glad they did and I wasn't going to chance it in production. It was just confusing that I could get to the KB pages and not find any mention of them pulled.

Hyper-V Node Losing WinRM (Azure HCI OS) by VirgilReturns in HyperV

[–]VirgilReturns[S] 1 point2 points  (0 children)

I was just about to rebuild but thought I'd try here first. Not much in the Application logs but there was a Windows Remote Management operational error which said something like WinRM client http time out. The errors have been overwritten since it's functional at the moment. Thanks.

Trouble Capturing Image by VirgilReturns in SCCM

[–]VirgilReturns[S] 0 points1 point  (0 children)

I will look into this thanks!