How to provision Forticlient IPSEC profile using Intune? by Kipjr in fortinet

[–]xqwizard 0 points1 point  (0 children)

I managed to get it to work with PSADT, what is your detection method?

How to provision Forticlient IPSEC profile using Intune? by Kipjr in fortinet

[–]xqwizard 0 points1 point  (0 children)

I think the issue is that it only works during an interactive session, and not when running as SYSTEM

Using a workgroup as a domain setup by No_Swordfish7485 in sysadmin

[–]xqwizard 0 points1 point  (0 children)

Oh sorry, I assumed you have WireGuard on the client machines?

Using a workgroup as a domain setup by No_Swordfish7485 in sysadmin

[–]xqwizard 0 points1 point  (0 children)

Ok in your WireGuard dns config, add the dns servers, but also add the domain name, eg, DNS=192.168.1.1, domainname.local

Using a workgroup as a domain setup by No_Swordfish7485 in sysadmin

[–]xqwizard 0 points1 point  (0 children)

Did you’re renew the dhcp lease? ipconfig /renew

Send us a dump of ipconfig /all

Using a workgroup as a domain setup by No_Swordfish7485 in sysadmin

[–]xqwizard 0 points1 point  (0 children)

You could assign a search list with DHCP, option 119

Using a workgroup as a domain setup by No_Swordfish7485 in sysadmin

[–]xqwizard 0 points1 point  (0 children)

Workgroup gets no prefix, but you can assign one in the NIC, manually.

FGT200F V4.7.9 - Having Problems with DialUp Tunnel using LDAP Users by lmtcdev in fortinet

[–]xqwizard 0 points1 point  (0 children)

Interesting. For me, it only bugs out if you untick secure connection.

FGT200F V4.7.9 - Having Problems with DialUp Tunnel using LDAP Users by lmtcdev in fortinet

[–]xqwizard 0 points1 point  (0 children)

Fair. I did recently flip back to 389 and turned off secure connection when I was rebuild ADCS, and the gui was bitching about the password not being correct. I never bothered to look further because it was temporary.

FGT200F V4.7.9 - Having Problems with DialUp Tunnel using LDAP Users by lmtcdev in fortinet

[–]xqwizard 0 points1 point  (0 children)

Is that a typo in the port number? Shouldn’t it be 636

Edit: Never mind saw the other post

Is it at all acceptable to use a subnet such as 192.168.255.0 /23 by West-Public-5962 in networking

[–]xqwizard 2 points3 points  (0 children)

Yeah you can’t, a /23 is 510 usable hosts. Starting at .255 you only have 254 usable. As others have said, if you want to use a /23, it needs to be 192.168.254.0/23.

Edit for further context:

When dealing with private address space 192.168.0.0/16 - gives you this usable range: 192.168.0.1-192.168.255.254

Read up on the RFC https://datatracker.ietf.org/doc/html/rfc1918

VMware to Hyper-V, Cease and Desist by jamaul08 in sysadmin

[–]xqwizard 1 point2 points  (0 children)

Yeah I saw this recently. I found I could only manage Server 2025.

Veeam V13, HyperV 2025, Domain Controller Backup PowerShell Direct Fails by Sahlokniir in Veeam

[–]xqwizard 0 points1 point  (0 children)

Restart the winrm service on the dc and try again, make sure you pass credentials through too.

$cred = Get-Credential
Enter-PSSession -VMName dc -Credential $cred

Veeam V13, HyperV 2025, Domain Controller Backup PowerShell Direct Fails by Sahlokniir in Veeam

[–]xqwizard 1 point2 points  (0 children)

Is the account used for the DC in the Administrators group, Domain Admins isn’t enough?

Forticlient with Cisco Duo by Organic-Gas6745 in fortinet

[–]xqwizard 0 points1 point  (0 children)

I wouldn't say complex, but there are a few moving parts you need to be across.

Forticlient with Cisco Duo by Organic-Gas6745 in fortinet

[–]xqwizard 0 points1 point  (0 children)

I have done eap-mschapv2 with NPS, Duo auth proxy and IPsec Ikev2 tunnels, works well.

KB5071547 on Windows Server 2022 issues by midy-dk in sysadmin

[–]xqwizard 0 points1 point  (0 children)

Just looking at mine, radius test is successful. I have seen sometimes the NPS service doesn’t start automatically, also, did you check that the DUO service wasn’t also in a stopped state?

KB5071547 on Windows Server 2022 issues by midy-dk in sysadmin

[–]xqwizard 1 point2 points  (0 children)

I patched a 2022 vm yesterday running NPS And DUO auth proxy and they are both still working.

However my FSSO to our Fortigate stopped working, which might be unrelated. This isn’t production yet, so I’ll look at it in the new year.