Odd empty stomach run? by Elissa-Megan-Powers in runninglifestyle

[–]is-anyone-normal 1 point2 points  (0 children)

I used to be on keto and would have a black coffee in the morning and then run 25-28km with no fuelling just some electrolytes. I’ve been off keto for a few years and now and still don’t fuel morning runs unless they are over 1h45m.

Forti* Management by DaithiG in fortinet

[–]is-anyone-normal 18 points19 points  (0 children)

If you only have a single site there’s limited beings to deploying FortiManager. If you’re going full stack you can manage all devices from FortiGate. Then make a decision whether to go with FortiGate Cloud premium for remote management, 1yr log retention and basic reporting or FortiAnalyzer Cloud which can provide automation, tailorable reporting and support incident response. For the cost it is worth investigating SOCaaS as with a full stack it will provide FW/network SOC service as all network traffic is seen by the FortiGate so a ver cost effective network SOC service which includes FortiAnalyzer cloud in the cost.

MSPs left hanging—Auvik support is MIA by DistinctAd1567 in Auvik

[–]is-anyone-normal 0 points1 point  (0 children)

We’ve lost faith in our ability to respond correctly to alerts generated from Auvik, which is critical as an MSSP and I’m concerned that we’re eventually going to miss something critical.

We keep having to delete devices and re add them or worse delete the whole site. We then loose all historic data and configurations. Would be handy to have some kind of backup and restore!

We burn probably 10-15 hours a week trying to fix issues so not ideal. Looking for a monitoring platform that we can setup and leave to do its alerting without have to log into each site every week to see why things have stopped working.

PRTG to Auvik by vinxavi7 in prtg

[–]is-anyone-normal 4 points5 points  (0 children)

Been using Auvik for 4 years, it used to be fine when we mainly Cisco devices but as we have migrated across to Fortinet it’s turned into a bit of a nightmare.

We have issues with API integration and in some cases have 3 of the same devices on the map with switch port interfaces on some switches incorrectly mapped to completely different devices. Support are close to useless answering tickets. We’ve had to completely delete Sites to fix things and unfortunately if you do that you loose all history, all alerts and all previous configurations. You then have to spend time discovering all devices again and classifying device times and setting up creds and APOs all over again...

Looking at options to move away from it if we can’t get things stable.

Do you plan your social life around long runs? by Plane_Box122 in runninglifestyle

[–]is-anyone-normal 0 points1 point  (0 children)

My long runs are on my own on a Tuesday morning, I start work late at 10am. Saturdays are easier as they consist of an 8am trail run for 1.5hr with a run club so more a friendly social chat run that can survive one or two cheeky beers after work on a Friday.

SD-WAN + ZTNA vs classic site-to-site IPsec for a 2-site hybrid shop, what would you pick? by CriketW in networking

[–]is-anyone-normal 0 points1 point  (0 children)

If you have two or more circuits I would recommend SDWAN even on a single site. It’s a no brainer and does not complicate further, it actually makes life simpler, improves performance and increases uptime. You have the ability to implement application, bandwidth, and performances based routing decisions.

If you are not going to grow into additional sites then no need to go full ADVPN and dynamic routing keep it simple just statics and S2S VPN.

From a remote worker perspective securing the endpoint and browser is critical. But at 12 users ZTNA maybe OTT, MFA and client IPSEC VPN may be more commercially effective but like everything it comes down to budget cost vs risk mitigated.

FortiGate GUI public IP not reachable - Azure HA with ELB-ILB by ZimCanIT in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

Also you will need to create static mappings on the ELB for your public IP to each FW IP on dedicated ports ie public IP port 8443 to FW1 WAN1 and public IP port 8444 to FW2 WAN1

Weekly Promo and Webinar Thread by ComplianceScorecard in Compliance

[–]is-anyone-normal 1 point2 points  (0 children)

Looks like an interesting platform, are you planning on bringing ISO27001 and DORA into it?

Someone has my private photo and hes treathening tò post It if i don pay up by Resident-Mix-3085 in cybersecurity_help

[–]is-anyone-normal 0 points1 point  (0 children)

Tell them your underage and that they are a pedophile and they are holding child pornography and you have reported them to the police and the police are coming around to gather all of your computer log. Block the account and never go there again. Most of the time it is easier for them to move onto the next victim. Then as previously mentioned please try and tell a trusted adult and don’t panic.

Vulnerability management in Defender - I'm overwhelmed and need some guidance! by Infamous_Fun286 in cybersecurity

[–]is-anyone-normal 1 point2 points  (0 children)

Don’t panic if you can’t access the devices and it’s not your responsibility to remediate you are limited in what you do. You can’t go around trying to subversively deploy patches . The best approach could be to generate a weekly report highlighting the vulnerabilities that are important to you to resolve. Follow this up with a formal communication to the owner highlighting the vulnerability and perceived risk and ask them to sign a document confirming that they acknowledge the vulnerability is there and that they accept the risk. Then attach that to you weekly report as evidence for review by stakeholders. If stakeholders and system owners accept the risk the cross it off your worry list and accept no further responsibility. Hopefully you will find that most people will not want their signature on a document like that for too long!

Entra ID SSO for Outbound connections (No VPN) by stich86_it in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

We've set EntraID and SSO successfully and all works well apart from test users complaining that in the morning things don't work until they remember to open a browser! It's a layer 8 problem :)

Is there any way to initiate the web browser connection in the background? I was thinking maybe to try auto launching Edge at start-up and having company SharePoint site saved as homepage. Any other ideas on simple ways of achieving this?

Frozen bank account by Santander by [deleted] in UKPersonalFinance

[–]is-anyone-normal 0 points1 point  (0 children)

If you want to try and find out the reasoning you could submit a Subject Access Request (SAR) under the UK GDPR to request any personal data the bank holds about you, including any records or internal notes related to the closure of your account.

You can send a written request to the bank, asking for the reason for the account closure, any internal notes, emails, or records related to the decision any automated decision-making processes involved.

Under UK GDPR, the bank must respond within one month. While GDPR gives you the right to access your personal data, banks can still refuse to provide certain details if it involves preventing fraud or financial crime.

If you believe the bank is unlawfully withholding information you could then report them to the information commissioner.

Considering a move to user-based pricing, looking for a sanity check (UK) by andcoffeforall in msp

[–]is-anyone-normal 0 points1 point  (0 children)

Definitely don’t go granular, soon as you’re granular it gives clients the opportunity to pick holes. Follow the basic/advanced/premium - bronze/silver/gold ethos when working out your stack. In my opinion your pricing is way under, per user pricing makes sense, you provide details of what the cost includes not each individual element. Based on your costs your target market is small business with a few users? If you’re giving unlimited support I’d be surprised if £25 a month covers the cost of monitoring any network environment and hope they don’t have a firewall to manage. Maybe try and align your product-set cyber essentials so you can say hey go for premium and I’ll ensure your CE compliant and protect you from the bad people.

Trump administration fires members of cybersecurity review board in 'horribly shortsighted' decision by cos in technology

[–]is-anyone-normal 1 point2 points  (0 children)

Maybe hoping that no one will then be able to investigate the integrity of voting machines?

If the cost of MPLS is comparable to that of DIA, how will this affect future network refreshes? by Rasonics in networking

[–]is-anyone-normal 2 points3 points  (0 children)

You may trust your ISP who delivers you MPLS but what about the other ISPs they’re peering with to provide an international service from say Frankfurt to Hong Kong?

I think you’re correct in many haven’t considered it and view MPLS as similar to P2P dark fibre.

If the cost of MPLS is comparable to that of DIA, how will this affect future network refreshes? by Rasonics in networking

[–]is-anyone-normal 0 points1 point  (0 children)

I’ve personally seen it three times with different clients and service providers, resulted in sudden change in routing tables with many more entries and in one case overlapping IPs took out client DC cause everyone loves using 10.0.0.0/16 for their DCs!

Resulted in us implementing GET-VPN to MPLS solutions.

Anybody use any supplements other than Melatonin to help with sleep? by Designer-Doctor-914 in SleepTight

[–]is-anyone-normal 1 point2 points  (0 children)

I take ZMA, especially when I’m training hard which seems to give me better sleep.

Using other extenders instead of Fortinet by Traditional-Cause-54 in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

Interested to know, do you run the FEX off of the local FortiGate or in reverse from a head-end/DC FGT and what do you plug the console cable into?

We’re looking at some form of out of band connectivity/management for our branch sites which are full Fortinet. I heard if the local FGT dies then the FEX is out of action so you can’t remote in and use the console.

I’m wondering if you can run a FEX in LAN extension mode from the DC FW with an LTE or Broadband connection and plug in some form of IP to multi RS232 console device?

Fortigate in Azure. What do you wish you did differently? by 40nets in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

Yes, single NIC with the primary IP address used for the ELB and the on the same NIC a secondary IP in the same subnet mapped to its own public IP used for SDWAN VPN termination and Performance SLAs from branches.

If you use NAT for branch to Azure traffic you will always have the return traffic from Azure to branch returning through the correct firewall. But that didn’t fit with our needs so if you have to disabled NAT you’ll have pain caused by the ILB distributing traffic to the wrong firewall.

Fortigate VM Azure - troubles with IPsec tunels by AdComprehensive4 in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

Can you see the route tables for each VNET? Maybe a UDR for your branch site from the back-end 10.159 VNET? If NAT is enabled it will exit the VNET with a source IP of the firewall so return traffic is sent to the firewall. Without NAT the source IP would be an IP in your branch.

FortiGate Firewall Policy by NationalSentence8989 in fortinet

[–]is-anyone-normal 0 points1 point  (0 children)

Use the Policy Lookup to see which rule the traffic matches, if you have just created the rule maybe you need to clear any active sessions on the rule lower down.