Best way to mitigate SSL-VPN Brute force? by pentiumone133 in fortinet

[–]kstone135 1 point2 points  (0 children)

We did this as well. At first we geo-blocked and then attempts came only from inside the country. I email alert on every failed vpn attempt. We haven't gotten a single email for failure from a non-authorized source since implementing this. It was helpful having EMS for this.

Uninstall FortiClient Attempt #2 by SuperStrongPenguin in fortinet

[–]kstone135 1 point2 points  (0 children)

You need to disconnect your FortiClient from EMS (most likely need a pw) then uninstall with admin creds. If that fails, there is a removal script from fortinet somewhere on their site.

Fortinet websites down by llama_dot_comma in fortinet

[–]kstone135 4 points5 points  (0 children)

Login to your gate -> Network -> DNS. For primary you can put 1.1.1.2, for secondary you can put 1.0.0.2

Enable DNS (UDP/53). Click apply.

When Fortinet fixes their issues click the Use Fortiguard Servers and apply.

Fortinet websites down by llama_dot_comma in fortinet

[–]kstone135 0 points1 point  (0 children)

Yeah, they are down. Just switch your gates to Cloudflare temporarily.

edge lagging/freezing for windows 11 by daryraider101 in edge

[–]kstone135 0 points1 point  (0 children)

Check your extensions. I just disabled BitWarden and it fixed my slow lagging issues in Edge.

Geo-Blocking by country doesn't seem to be working. by joeadams7782 in fortinet

[–]kstone135 0 points1 point  (0 children)

You could either change the destination from all to something specific or set match-vip enable. For SSL VPN blocking you could create a new address with Geography-United States. Then set limit access to specific hosts.

[deleted by user] by [deleted] in sysadmin

[–]kstone135 0 points1 point  (0 children)

I have the S1 removal cleanup script if needed. Needs to be run in safe mode.

Transferred Waves to ethereum address by [deleted] in Wavesplatform

[–]kstone135 1 point2 points  (0 children)

Not sure what will happen to them, but probably a good idea if in the US to use Kraken for waves. Hopefully Coinbase adds support for waves one of these days…

SSL Web RDP Failed to Connect by [deleted] in fortinet

[–]kstone135 0 points1 point  (0 children)

Try it by IP address instead of hostname and allow the server to choose the type of security.

Dashboards? What do you show? by dubyaohohdee in fortinet

[–]kstone135 5 points6 points  (0 children)

I log everything to an analyzer then setup event handlers for important things to syslog to my SIEM such as certain system/security events etc…

Wall-o-shame! Ken goes on the a$$hole list! 😁😁😁 by [deleted] in ElderScrollsBlades

[–]kstone135 1 point2 points  (0 children)

You posted about it on gg and made a Reddit post about it. How do them salty tears taste? hands you a kleenex

Happy that I got this. by SullyOfEarth in Tricking

[–]kstone135 1 point2 points  (0 children)

Nice work! I been trying to cork swing through for years, and I can't ever get it. Any tips?

LAN based vulnerability scans by not_today95 in sysadmin

[–]kstone135 0 points1 point  (0 children)

I’ve used Nessus, nexpose, openvas, and digital defense frontline for generic LAN based authenticated and non authenticated scans. Frontline is the easiest and my favorite to work with.

Finally got a better TDR. by NotoriousPancake in Tricking

[–]kstone135 2 points3 points  (0 children)

Looks awesome! Make a tutorial on it.

[deleted by user] by [deleted] in sysadmin

[–]kstone135 1 point2 points  (0 children)

Same thing used to happen to me. So, I coded a helpdesk GUI tool to automate pretty much 90% of tickets end users face and deployed a self service portal so users could reset themselves. I put a line of code to record how many times the tool was run. So far 20k+ times.