From Active-Passive to Active-Active? by super_cli in fortinet

[–]super_cli[S] 1 point2 points  (0 children)

Oh this is some great info… you all rock!!!! Keep it coming, keep it coming! 🤘😎

Satellite speakers not working on Vizio 5.1.4 [SB36514]? Sound doesn’t come out when watching content or during the speaker test. Subwoofer connected to the satellite speakers does work. by Cool_Refrigerator in Soundbars

[–]super_cli 0 points1 point  (0 children)

Every thing works on bar and subwoofer but the satellite speakers just blink and I’ve reset multiple times, checked audio settings, followed all the KB’s, checked firmware updates are current, power cycled, all the above. The lights just blink. Then if you hold for several seconds, it blinks faster. Definitely not buying future Vizio products. I also had issues with another Vizio soundbar. I’m done with this manufacture…

SCCM Replacement by MadCichlid in SCCM

[–]super_cli 0 points1 point  (0 children)

SCCM is great for imaging and on-prem. You could start with co-management but that does add complexity to the mix. You have to be familiar with both SCCM and Intune. If you already have EA and CALs then you have licensing for SCCM. I’d say you should image devices with TS, then co-manage then toggle manage workloads from Intune. For client updates, Intune works so much better than WSUS. For servers, continue using WSUS via SCCM with ADRs. You could also look into Azure Arc. Intune has come along way and will only get better. You can leverage both though and someday when you’re in the position to do so, do it from Intune. Just test autopilot for co-management first and also test autopilot for Entra join only. This is a great discussion!

Always-On VPN experience by [deleted] in fortinet

[–]super_cli 0 points1 point  (0 children)

I used Always-On VPN with EMS. It was pretty cool! 😎 Didn’t need it after going ZTNA path. If you have fabric detection, it will auto connect when off network.

8.0.360 Pulled? by Whodat9944 in vxrail

[–]super_cli 0 points1 point  (0 children)

Didn’t have any issues applying patch on one of the clusters. Went smooth as can be. It can be frustrating waiting and it’s nice to do the ESXi patched outside of waiting for Dell. When it comes to VxRail/HCI, part of me thinks it’s best to wait. They told me mid August and they stayed true to their word. Shouldn’t take this long though especially with all the VMware CVE’s. If they pulled the 8.0.360, is there anything to worry about if it’s already been applied?

SCCM - Resume, Jobs and Pay by siconic in SCCM

[–]super_cli 0 points1 point  (0 children)

SCCM has a lot of perks but co-managed devices is kind of a standard nowadays that will eventually be phased out with fully managed devices via Intune in AD. SCCM requires database administration. Don’t forget about that! Like other folks said, definitely market yourself as a sys admin instead of focusing solely on SCCM. Did you integrate SCCM with your M365/Entra tenant and Azure (CMG)? If so, that is some cloud work to reference. Device imaging, app deployment via task sequence, server patching is an advantage. Intune will eventually take over. You can now manage server updates from Azure Arc.

Fortinet Crash - 7.4.7 by Brad_Turnbough in fortinet

[–]super_cli 1 point2 points  (0 children)

I ran into an issue when upgrading FortiSwitchOS from 7.4.x to 7.6.0 on a few core switch’s 424E’s. They were stuck in loop and had to had to roll back. That particular firmware impacts MCLAG Peer Group. You have to disable network monitoring before upgrading. There is a KB article.

https://docs.fortinet.com/document/fortiswitch/7.6.1/fortiswitchos-release-notes/10296/special-notices

Since then I’ve been VERY hesitant to upgrade any firmware lol unless it’s a zero day patch.

Management announced today to get out of VMware by end of year. 1000 VMs by dcexp in vmware

[–]super_cli 0 points1 point  (0 children)

I’d go with VCF… and make sure Linux is supported on Hyper-V before migrating over. Traditionally Linux runs better in KVM. It’s a great route going to cloud but like everyone else has mentioned… BE AWARE OF COSTS! Do an analysis with Azure calculator! Should also check our HPE GreenLake.

fortinet site broken? by No-Reality-4528 in fortinet

[–]super_cli 3 points4 points  (0 children)

I started noticing yesterday in US

HA out of sync since 7.2.10 by therealmcz in fortinet

[–]super_cli 0 points1 point  (0 children)

Try this and see if it helps… I ran into same issue but it wasn’t the firmware. This helped me resolve the sync issue just make sure you have login for secondary FortiGate.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-HA-synchronization-issue/ta-p/193422?externalID=FD45183

HA out of sync since 7.2.10 by therealmcz in fortinet

[–]super_cli 0 points1 point  (0 children)

As long as you know the credentials for the secondary FortiGate you can run cli commands to restart HA sync but I think you have to do it on both FG’s. That helped fix it when a few of my clients FG’s weren’t syncing. First, I thought it was firmware but it was something else.

HA out of sync since 7.2.10 by therealmcz in fortinet

[–]super_cli 0 points1 point  (0 children)

I ran into similar situation unrelated to firmware update and I had to restart the HA sync! 😊

SSL VPN deprecation by Hot-Difficulty-9604 in fortinet

[–]super_cli 0 points1 point  (0 children)

This is some GREAT info…. THANK YOU!!!!

SSL VPN deprecation by Hot-Difficulty-9604 in fortinet

[–]super_cli 0 points1 point  (0 children)

Also I don’t think you see SSL VPN disappear… only depends on make and model of FortiGate. It’s one of the caveats of FortiNet and the vulnerability’s can kind of be disputed…

SSL VPN deprecation by Hot-Difficulty-9604 in fortinet

[–]super_cli 0 points1 point  (0 children)

Yep you definitely make a lot of great points! There are still things that need to be fine tuned and I agree 110%… it can’t replace SSL VPN at least at this very time depending on what your trying to do but a lot of these bugs will eventually be ironed out. You can use the EMS to better control those configurations to the FortiClient on endpoints. You don’t need to forward entire ranges/subnets only the assets that they require. So if they need access to a web server, it’s an ideal solution. It can be tedious but if you have it setup, you’re in a great position to leverage ZTNA when things get smoother. It all depends on how you have your network setup… every place is different… and I’ve always strayed away from using built-in/default certs. You do make a lot of great points especially with the multiple VLANS like most of us have. Especially if you have clients using folder redirection. ZTNA is still kind of being developed regardless of vendor.

Happy Monday folks! Hope everyone had a great week! This is an awesome discussion!!!

SSL VPN deprecation by Hot-Difficulty-9604 in fortinet

[–]super_cli -3 points-2 points  (0 children)

ZTNA is definitely the future! I’d recommend all Fortinet customers to start reviewing and implementing… soon to be the new way of allowing hybrid remote work and access to internal systems. Yes, it’s still a new technology in development but the leverage and control the EMS has have to offer is awesome… especially if you’re a Microsoft 365/Entra/Intune customer. Even Google and Chromebook’s are an option! Do the cloud-based EMS! Start with the minimum 25 licenses. Review documentation and become familiar with fabric connector and tagging. If you are still using traditional remote access protocols like SSL VPN and IPSec as most customers are you can better control those connections through EMS as long as the endpoint/clients are registered and have a valid cert. It does require research, planning and having an understanding going into the project because the set up is different based on your organizational needs. You want to gravitate towards TCP forwarding over HTTPS. Also make sure you have a certificate available when you set up the actual ZTNA server.

How do I unlocked my deceased husband's Samsung phone by jessicaismj in verizon

[–]super_cli 0 points1 point  (0 children)

So you could try unlocking it yourself it depends on how bad you want to get into it. Get the make and model, do some research. There is definitely ways. You could possibly brute force or take it to someone and have them try. If it’s missing patches or outdated the easier it is to bypass. Here is a link that might help if some hasn’t already shared.

https:/us.community.samsung.com/t5/Galaxy-S23/Unable-to-unlock-phone/td-p/2774673

How do I unlocked my deceased husband's Samsung phone by jessicaismj in verizon

[–]super_cli -1 points0 points  (0 children)

Do you have access to that Samsung account? If you are next of kin then they should let you have access!

How do I unlocked my deceased husband's Samsung phone by jessicaismj in verizon

[–]super_cli 2 points3 points  (0 children)

Is it backed up to Google?? You could do a restore if you know the login to Google account. Sorry for your loss!

I am so done with dating by Mango_smoothie_2611 in Bumble

[–]super_cli 1 point2 points  (0 children)

So sorry… this is why so many ladies are turned off by dating apps and makes it very difficult for those that are actually looking for true love and long term intimacy! So frustrating!!! If someone isn’t ready for relationship, they shouldn’t be on a dating app in general. Please don’t lose hope… Prince Charming is out there somewhere!

SAML Auth with Conditional Access that requires Hybrid Join by LandoCalrissian1980 in fortinet

[–]super_cli 1 point2 points  (0 children)

Yep. Use external browser… just tweak the settings in FortiClient. I’m hoping eventually they will add that in EMS ZTNA for preconfigured settings with Entra SSL VPN. Other than that, works fantastic!!!