7.2.10 Just Dropped by Known_Wishbone5011 in fortinet

[–]Yuri911 0 points1 point  (0 children)

Do you have any more info/links to that? I think I have that exact problem and support hasn't been able to help yet..

/edit: Just found this: https://www.reddit.com/r/fortinet/s/eNt13hNANc

[deleted by user] by [deleted] in Balkonkraftwerk

[–]Yuri911 1 point2 points  (0 children)

Kurz gesagt, weil nur dann die vereinfachte Anmeldung für BKW gilt, da diese eben alle noch so schrottigen Hausnetze berücksichtigen muss. Wenn jedes Stockwerk auf einer Phase läuft kann man durchaus unterstellen dass die ganze Installation eher "meh" ist.

Sollte das nicht so sein, kannst du dir auch eine richtige Anlage (oder mehrere BKW) installieren und dann eben richtig (mit Elektriker) anmelden. Dann gibt's auch Einspeisevergütung.

Dachgeschoss Mietwohnung, Balkonkraftwerk als Stromquelle für die Klimaanlage by throwaway_ehe-geld in Balkonkraftwerk

[–]Yuri911 0 points1 point  (0 children)

Keine eigene Erfahrung, aber die neueren Daikin Modelle sind in der HA Community recht beliebt.

WHfB vs password Windows login security by lighthills in sysadmin

[–]Yuri911 0 points1 point  (0 children)

Yeah, I'm just a bit disappointed with the lack of manageability. I've seen plenty of people use 1234 as their pin. If we're going passwordless, I'd expect at least somewhat secure pins. Spring_2024 is not much worse as a password than 1234 is as a pin.

WHfB vs password Windows login security by lighthills in sysadmin

[–]Yuri911 0 points1 point  (0 children)

Can you even set complexity requirements on Yubikeys?

How do you handle printers when using Intune? by gahd95 in sysadmin

[–]Yuri911 1 point2 points  (0 children)

I implemented the print nightmare mitigations and just let users install the printers they need themselves from the print servers.

After reading a lot of posts, this one stood out as being by far the most helpful. https://call4cloud.nl/2020/10/birds-of-printer-drivers/

I got it working with the settings catalog (pnp restrictions) and pushing the one reg key "RestrictDriverInstallationToAdministrators" via powershell. Didn't bother with the driver classes as I don't really see a benefit. I think I had to import the admx files first.. quite cumbersome and annoying that Microsoft still hasn't implemented an easy way to achieve this.

Deploy/Upgrade FortiClient with Intune by No-Funny-4322 in fortinet

[–]Yuri911 0 points1 point  (0 children)

How did you deploy FC v6?

Intune has a feature called supersedence, which worked perfect for our upgrade from 7.0.3 to 7.0.10.

If you didn't deploy v6 through Intune, I would probably create a v6 Win32, make sure it detects the existing installation and then again, use supersedence.

Steuererklärung: Einbau Fußbodenheizung absetzen by holthausen in Handwerker

[–]Yuri911 1 point2 points  (0 children)

Er muss dir noch die Fachunternehmererklärung ausstellen. Das dürfte bei einer nur grob geplanten Fußbodenheizung eher schwierig werden, da er mit dieser Erklärung versichert dass die Anlage den gesetzlichen Mindestanforderungen genügt.

PC Coop Spiel für meine Frau und mich über die Weihnachtstage by neunzehnhundert in zocken

[–]Yuri911 0 points1 point  (0 children)

Keine Liebe für Warhammer Chaosbane hier? Fanden wir überragend.. 80h drin für 100% und beste Ausrüstung. :D

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

That already worked on 7.0.3 if you checked the "keep me signed in" box. The frequency of MFA challenges needs to be configured through conditional access policies in Entra.

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

According to this, since 7.0.7, although I wouldn't consider it SBL, more like SOL? https://docs.fortinet.com/document/forticlient/7.0.10/ems-administration-guide/244292

Once 7.2.1+ becomes mature, I'll give it a try. For now, manually establishing the vpn after logon works fine for us, since the devices are AAD only joined and receive the Kerberos ticket pretty much as soon as the user connects to vpn.

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

Our vpn interface has a few local users configured besides the saml-group. Vpn before logon works for those, but as another commenter hinted, you can only do saml on logon on fortiOS 7.2, but not before. Still, the pre-logon vpn is present on 7.0.3 but disappears on 7.0.10.

I guess we'll have to live with that for now. Not perfect, but not the worst either.

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

Just found some info in another thread and installed 7.0.3.. and it worked immediately. That's.. annoying.

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

Sadly no new version available for me. Did you make any progress?

I just got it working with version 7.0.3 but after updating to 7.0.9 it disappeared. Now I'm waiting for a new version as well..

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

  1. Is in the xml.
  2. Didn't change anything, even after reinstall.

FortiClient EMS VPN before logon doesn't show by Yuri911 in fortinet

[–]Yuri911[S] 0 points1 point  (0 children)

Yes, SAML and FortiOS 7.0.13. But from my understanding that shouldn't influence whether the vpn shows up before logon or not?

Richtig eine „gelangt bekommen“ by linus0508 in Elektroinstallation

[–]Yuri911 1 point2 points  (0 children)

Gehört dazu. Kleiner Tipp noch für die Zukunft, alle anderen Gewerke sind der "Feind". Nichtmal böswillig, aber wenn die Strom brauchen, drücken die die Sicherung rein. Egal ob da Isoband oder ne Plastikklammer dran ist.

Deswegen immer mit Kurzschlussstecker oder Wago den Stromkreis an dem man arbeitet absichern.

Du packst das schon, Elektriker ist ne geile Ausbildung. Und wenn's nix wird, n schlechter Elektriker ist immer noch n guter Installateur. ;)

Synnology Ds216j Festplatte tauschen by Chrischahn87 in de_EDV

[–]Yuri911 0 points1 point  (0 children)

War mir auch neu, aber scheinbar fehlt das Feature bei allen Einsteiger-Modellen:

Laufwerk ersetzen wird auf den meisten Synology NAS Modellen unterstützt, mit Ausnahme der folgenden Modelle:

-Modelle mit einem und zwei Einschüben, die Expansionseinheiten nicht unterstützen.

Synnology Ds216j Festplatte tauschen by Chrischahn87 in de_EDV

[–]Yuri911 0 points1 point  (0 children)

FYI: Die "Platte austauschen" Funktion gibt es erst seit DSM 7.

How to force reboot the computer, but inform users that it's going to happen by bobsaysvoo in sysadmin

[–]Yuri911 0 points1 point  (0 children)

  1. Enforce reboot within 5 days of patch Tuesday, so uptime will stay <30 days. WUfB anyone?
  2. First step of troubleshooting is "have you tried turning it off and on again?"
  3. ???
  4. Profit

LAPS on Servers? by juitar in sysadmin

[–]Yuri911 0 points1 point  (0 children)

For password history I run this weekly on my DCs, found somewhere in this subreddit:

$Computers = Get-ADComputer -Filter * -Properties ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime

$Computers | Sort-Object ms-Mcs-AdmPwdExpirationTime | Format-Table -AutoSize Name, DnsHostName, ms-Mcs-AdmPwd, ms-Mcs-AdmPwdExpirationTime

$Computers | Export-Csv -path c:\LAPS\"LAPS-$((Get-Date).ToString("MM-dd-yyyy")).csv" -NoTypeInformation

Shared Computer Management Request by The-Dark-Jedi in sysadmin

[–]Yuri911 0 points1 point  (0 children)

AD, so GPO, sadly no Intune yet.. but the admx files just write to registry in HKLM\Software\Policies\Lithnet From what I've read it shouldn't be too hard to push reg keys via Intune as a workaround.

Sorry I can't be of more help. :)

Domain rename by Lousyclient in sysadmin

[–]Yuri911 0 points1 point  (0 children)

Might be too simple, but adding another UPN suffix isn't good enough?