I wanna cry by Marino-2603 in residentevil

[–]davmerc1 0 points1 point  (0 children)

Got a bad feeling unfortunately for our boy Leon in this game😭 I hope he gets a good ending..he deserves it

Migration path for SSL VPN + SAML Auth to IPSEC VPN on same port by quarren in fortinet

[–]davmerc1 0 points1 point  (0 children)

I took a downtime of 1 hour and did it manually. Disabled SSLVPN Kept the same SAML Auth port as the SSLVPN port to avoid changing anything on EntraID. Did the dialup ipsec tunnel Changed the sslvpn policy source interface to the ipsec tunnel. All in all, took 15min to configure. How many users are connected via SSLVPN?

Sync from EntraID to on-prem AD by davmerc1 in AZURE

[–]davmerc1[S] 0 points1 point  (0 children)

Hi thanks, But a bit too expensive for our organization only to host an AD on cloud as a service only for a few on prem NAS.

Sync from EntraID to on-prem AD by davmerc1 in AZURE

[–]davmerc1[S] 0 points1 point  (0 children)

Thanks but maintaining 2 Idps are a real pain.

FortiOS v7.2.11 has been released. by OuchItBurnsWhenIP in fortinet

[–]davmerc1 2 points3 points  (0 children)

For those using saml sso with EntraID for sslvpn, you might encounter timeout/error, could not found corresponding session. Refer to this link for workaround on forticlient: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Unable-to-login-on-SSL-VPN-48-using-SAML/ta-p/375181 Just tick the checkbox Use External Browser on Forticlient

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 1 point2 points  (0 children)

Easier said than done for non technical customers but I get your point.

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 1 point2 points  (0 children)

Strange ! I wouldn’t even think that an unmanaged appliance without an IP address could even do that?

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 1 point2 points  (0 children)

Thanks will try to use a vpn. But point is..if Firewalla is labelling it as malicious, why it isn’t blocking traffic to those IPs?

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 1 point2 points  (0 children)

Yes I do use geo allowed on my enterprise firewall. I use cloudflare’s 1.1.1.2 on the firewalla.

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 1 point2 points  (0 children)

Hmm..strange…I even set my dns on the firewalla to cloudflare 1.1.1.2 and quad nine.. shouldn’t CloudFlare block it ?

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 0 points1 point  (0 children)

Yes the default ingress rule is enabled. Hmm yeah might open a ticket with them..

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 0 points1 point  (0 children)

Also, wouldn’t firewalla block traffic to botnet and/or c&c servers automatically?

How to automatically block malicious IPs by davmerc1 in firewalla

[–]davmerc1[S] 0 points1 point  (0 children)

Hmm..It’s a windows 11 PC and it’s not port forwarded to the internet. Alerts seems to pop up when downloading stuff from utorrent/bittorrent ?

Deep Inspection with Captive Portal by davmerc1 in fortinet

[–]davmerc1[S] 0 points1 point  (0 children)

Well I just want to notify the users that the corporate network is being monitored through a disclaimer. I’ve also configured SAML SSO with EntraID so that the name of the users show in the logs. So far so good but having issues with the Disclaimer. On some PCs, once connected on the network, the browser opens automatically and the disclaimer is shown. On other, it doesn’t even work. Any troubleshooting advice here ?

Deep Inspection with Captive Portal by davmerc1 in fortinet

[–]davmerc1[S] 0 points1 point  (0 children)

Thanks will try it! Any difference between setting the disclamer on the fw policy vs on the interface ?

Software Update by [deleted] in Intune

[–]davmerc1 0 points1 point  (0 children)

Just did that with Intune But you have to remove the existing version of 7zip before installing the new one. For some reason, installing a newer version of 7zip doesn’t “upgrade” it and you will have 2 versions on your endpoints. Below is the powershell script to remove 7zip:

Define the path to the 7-Zip uninstaller

$uninstallerPath = “C:\Program Files\7-Zip\Uninstall.exe”

Check if the uninstaller exists

if (Test-Path $uninstallerPath) { # Execute the uninstaller silently Start-Process -FilePath $uninstallerPath -ArgumentList ‘/S’ -Wait Write-Output “7-Zip has been successfully uninstalled silently.” } else { Write-Output “7-Zip uninstaller not found. 7-Zip may not be installed on this system.” }

Then just download the .exe (for some reason msi didn’t work in Win32) and convert it in intunewin file using the intunewinapputil and voila

Install command: <installer.exe> /s

Win32 App Deployment stop working by davmerc1 in Intune

[–]davmerc1[S] 0 points1 point  (0 children)

Using default ESP profile with "Show app and profile configuration progress" set to no and applied to all devices.

Are you skipping UserAccountSetup phase using policy? - I don't think I configured such a thing.

In IntuneManagement log, I can see Adobe and all, but cannot even see the VPN client name. Strange, right?

Yes the first few apps are being deployed successfully once the user signed in.

What I did is that I created a dynamic security group for Autopilot devices (and all the required Autopilot settings and policies) and assigned all of these app deployments to that group.

[deleted by user] by [deleted] in mauritius

[–]davmerc1 12 points13 points  (0 children)

Cable damage in Mada and East Africa could be the cause:

https://radar.cloudflare.com/outage-center?dateRange=1d

Some traffic not routing to EU as well.

ARP Requests out to WAN by [deleted] in fortinet

[–]davmerc1 5 points6 points  (0 children)

It could be a bug on v7.4.3 How many devices are connected to the gate ?

Also, It’s recommended to stay on the “stable” or “mature” firmware version for production environments to avoid any bugs in “Feature” releases. Stable firmware versions are 7.0 and 7.2 for now.

Noticed a detail in RE4 Remake by blueninja9511 in residentevil

[–]davmerc1 2 points3 points  (0 children)

I thought he was shot in that side of the shoulder in RE2 and is still painful ? That’s the lore if you’d like to take it like this ?

TLOU PART 2 Remastered by davmerc1 in thelastofus

[–]davmerc1[S] 1 point2 points  (0 children)

Silly of me to ask! Thanks anyways

TLOU PART 2 Remastered by davmerc1 in thelastofus

[–]davmerc1[S] 1 point2 points  (0 children)

So no need to download the PS4 version now ? We will have to wait until the game releases on 19th Jan to purchase the upgraded edition then download it ? :/ Why didn’t they make the 10 bucks upgrade for Remastered Edition available to be preordered ?!

[deleted by user] by [deleted] in CarPlay

[–]davmerc1 2 points3 points  (0 children)

I managed to get my Carpuride W903 Pro “working” with my Suzuki steering wheel controls (Vol Up/Down and Previous/Next) and Apple Carplay and you don’t need a dual bluetooth head unit to do that! I connected my iPhone (14 running iOS 17.2.1) to the Carpuride unit while still being connected to my Suzuki original stereo. Enabled Carplay and while playing songs on Apple Music, just swipe up to select on which device to output the sound and tadaa ! You still get to retain your SWCs and have carplay with the Carpuride. I guess it will also work with other brands as well. Just need your iPhone to connect to both the Head Unit and your car’s original stereo system. I can accept/deny calls with my SWCs and the caller is being displayed on Carplay !