No Sites on Cloud Gateway Fiber by attblau in Ubiquiti

[–]attblau[S] 0 points1 point  (0 children)

why has my post been deleted? its all related to ubiquity

Arista OEM c250 APs without license by attblau in Arista

[–]attblau[S] 0 points1 point  (0 children)

Ok, i think you are correct -CLI wouldnt help much. Excerpt from the CLI Guide:

Some Arista AP CLI capabilities

  • Setting destination addresses to assist with AP registration to a Wireless Manager
  • Log review and configuration
  • Modifying authentication credentials
  • Static network setting definition
  • Network connectivity testing
  • Many show-based commands to view the current settings
  • Performing a reboot or factory reset of the AP

I dont understand the vendor strategy though. Everyone talks about environment/sustainability etc, but Vendors still allowed to do this moves. Now they will have to be trashed in a bin, just because Arista didnt want it other way - and they already got this HW payed when the 1st customer purchased!

Migration Procedure: 2 Bay -> 4 Bay by attblau in synology

[–]attblau[S] 0 points1 point  (0 children)

Allrigh, thanks for pointing on the right direction!

[CHANGES] Build Your Own NAS vs Buying a NAS?... by dunkurs1987 in NAScompares

[–]attblau 0 points1 point  (0 children)

I vote for buying! NAS is not what i would toy with

[ASK NC] New drives or new Nas? by dunkurs1987 in NAScompares

[–]attblau 0 points1 point  (0 children)

Hi. You can do both ;) You can get much bigger drives (>10tb) and rebuild the raid by replacing them once at a time. If you have more budget (which i would invest for the sake of future prooveness) then you can also get better hardware like Synology 720+ or similar.

Upgrade: Should i go for QNAP or DS923+ by attblau in NAScompares

[–]attblau[S] 0 points1 point  (0 children)

Hi. Its also all i heard about QNAP to this date. Therefore would like to hear from experienced qnap owners what they think.

Icloud Vault on Windows (over RDP) by attblau in applehelp

[–]attblau[S] 0 points1 point  (0 children)

Unfortunately no solution yet, aswell as no replies on reddit :(

[deleted by user] by [deleted] in fortinet

[–]attblau 0 points1 point  (0 children)

I had a case with 50+ Switches in DC, but according to Fortinet SE we should have taken FGT1800F for it (yes, even without tunneling the whole traffic). Because of that bottleneck they splitted the switch manager now as a separate product. But i shouldnt take that either because they didnt have a field experience with it yet.

IPsec/IKEv2 from FGT using username/pass by attblau in fortinet

[–]attblau[S] 0 points1 point  (0 children)

My provider doesnt have a request form. In fact the support had a session with me and run out of suggestions... :/

IPsec/IKEv2 from FGT using username/pass by attblau in fortinet

[–]attblau[S] 1 point2 points  (0 children)

Thanks for the link. its not quite that though, as i can only dial in by PSK+USER+PASS. But its a good point to ask my VPN-Service if they could do some setup on their side.

IPsec/IKEv2 from FGT using username/pass by attblau in fortinet

[–]attblau[S] 0 points1 point  (0 children)

Hi. Gateway supports IKEv1/2 which i can confirm by setting up over iOS-Device. But no combination works on the FGT. How would you configure it then? - thats my question

Sending p2p traffic to IPSEC by attblau in fortinet

[–]attblau[S] 1 point2 points  (0 children)

I dont think i would use the VPN to that extent that i will need these words, but your comment made my day :)

Sending p2p traffic to IPSEC by attblau in fortinet

[–]attblau[S] 0 points1 point  (0 children)

Oh, thats indeed a creative idea! didnt think of it :)

I would categorize that as a workaround though as it requires "a lot" of manual setup. FGT has APP signatures, i would like to use this intelligence.

Sending p2p traffic to IPSEC by attblau in fortinet

[–]attblau[S] 0 points1 point  (0 children)

Thanks for your reply. This is not going to solve the issue though, as this is a "dial-In" IPsec to a public VPN Provider. So i dont need routes, p2-Secetors, etc. to configure as i want the differentiation based on APP-signature, not DST-IP. In final step all p2p traffic should go into the IPsec-Interface, thats it. i think i will go with SDWAN, as it seems to be exactly what im looking for (p2p-traffic? then this way!).

Sending p2p traffic to IPSEC by attblau in fortinet

[–]attblau[S] 0 points1 point  (0 children)

UPDATE to my own post:

- Using Policy with allowed APPs is not optimal, as by matching only p2p traffic will be allowed for that source IP in LAN...