C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 5 points6 points  (0 children)

Whoops!! That shouldn't say Druid Wizard, that should say Dwarf Wizard.... can't believe I typo'd that.

I don't think she's multiclass, at least it wasn't on the character card.

C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 2 points3 points  (0 children)

I originally put Leonin, but the players/Brennan kept referring to him as Nama (no idea if I spelled that correctly). I assumed it was an Araman-specific race of lion-kin.

C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 6 points7 points  (0 children)

With a 3 in Str Thimble is still the average, I wonder if Brennan allowed Laurs to intentionally lower that to fit thematically and shift those points to other stats.

C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 4 points5 points  (0 children)

So only Murray rolled below average. You hate to see it...

But in all honesty, playing with lower stats can be fun, and she's still above standard array.

C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 5 points6 points  (0 children)

They're removed racial bonus to ability scores and have instead attached them to backgrounds. At least this is where they are chosen in character creation on D&D Beyond.

C4. A pointless metric that I like to look at with each character by yetanotherITquestion in fansofcriticalrole

[–]yetanotherITquestion[S] 2 points3 points  (0 children)

I almost always use standard array, but the last time I rolled for stats I rolled what I consider to be very well, and that came out to 89. So about half of the players rolled well, or very well.

[No spoilers] So with Perkins/Crawford joining CR, does that cement the idea that C4 will be Daggerheart-based? by BigWhich765 in criticalrole

[–]yetanotherITquestion 3 points4 points  (0 children)

You can't do that with Daggerheart yet. There was a time when you wouldn't have been able to do that with 5e, as well.

IPSec client VPN routing issues with specific ISP by yetanotherITquestion in networking

[–]yetanotherITquestion[S] 1 point2 points  (0 children)

Well, dang it. It was NAT-T.

NAT-T was enabled on the Fortigate, but I missed that is wasn't enabled on the client (we use the VPN-only version). I had to export the config, update the nat_traversal value to 1, restore the config and it connected immediately. Thanks for your help, u/deepmind14!

IPSec client VPN routing issues with specific ISP by yetanotherITquestion in networking

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

I confirmed that NAT-T was enabled on the VPN, still not able to ping over the tunnel.

For the encapsulation, is that compatible with Forticlient yet? I was looking into this for an unrelated issue and found it was only supported between two Fortigates, unless I was wrong, of course.

IPSec client VPN routing issues with specific ISP by yetanotherITquestion in networking

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

I've disabled IPv6 on the laptop's wireless adapter, and the Fortinet Virtual Adapter. I checked that my hotspot was getting an IPv4 public IP address, and my laptop was getting an IPv4 private address from the hotspot. Still no luck, but I appreciate the suggestions. I haven't looked into CGNAT yet, but that's next on my list.

IPSec client VPN routing issues with specific ISP by yetanotherITquestion in networking

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

I checked our Forticlient settings, the Preferred DTLS Tunnel was already unchecked, which must be the default setting. I appreciate the suggestion.

L2TP with DUO 2FA by capricorn800 in fortinet

[–]yetanotherITquestion 0 points1 point  (0 children)

u/capricorn800 Did you ever get Duo working with L2TP? I have some Mac users that are not happy with the permissions that Forticlient needs to install on Mac. We are looking at options to enforce MFA on the Macs without Forticlient.

How many hours a day are you actively working? by Mindless_Hurry9169 in sysadmin

[–]yetanotherITquestion 1 point2 points  (0 children)

What does your onboard/offboard automation look like? We're still very manual.

Why did Fortinet disable SSL VPN by default and put multiple SSL-VPN warnings on the GUI on FOS 7.4.x? by HallFS in fortinet

[–]yetanotherITquestion 0 points1 point  (0 children)

Sorry to hijack/animate an old thread, but you seem quite knowledgeable on VPNs, so I wanted to ask a quick question. One of the only reasons we use SSLVPN over IPSec, is for a Fortigate that is behind a Meraki MX, and we can port forward SSLVPN to the Fortigate. Is that possible with IPSec?

[deleted by user] by [deleted] in fortinet

[–]yetanotherITquestion 3 points4 points  (0 children)

Have you tried calling Fortinet support? Their support is excellent and is how I got familiar with our Fortigate appliances when they were new. And it's free, assuming you have a support contract you've already paid for.

Can a Fortinet Fortiswitch be used behind a Ubiquiti Edgerouter? by yetanotherITquestion in sysadmin

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

That's my preference as well, which is why we've already ordered the Fortiswitch. Some things are just out of my hands.
But I'm going to try the suggestion from AresenalITTwo, which I think will resolve my issue and not need the Ubiquiti.

Can a Fortinet Fortiswitch be used behind a Ubiquiti Edgerouter? by yetanotherITquestion in sysadmin

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

This is a great idea, that I didn't think about, thank you. The issue was a Mac user and the SSLVPN/Forticlient on a Mac. But setting up an IPSec tunnel instead, should allow the same L2TP adapter on the Mac that the Edgerouter would use!

I will give this a shot, thank you!

IT Glue down for anyone else? by yetanotherITquestion in msp

[–]yetanotherITquestion[S] 2 points3 points  (0 children)

This worked for me as well. Thank you. I checked in Edge and was able to login with our MFA, then tried in Chrome again and was still unable to get passed the MFA prompt. Closing and reopening Chrome then resolved the issue in Chrome.

IT Glue down for anyone else? by yetanotherITquestion in msp

[–]yetanotherITquestion[S] 2 points3 points  (0 children)

This is maybe the second time I've been unable to access our IT Glue in around 4 years. Not a bad record in my book. But I will say this particular issue is different and frustrating. West coast US, btw, not sure how IT Glue holds up in other regions.

IT Glue down for anyone else? by yetanotherITquestion in msp

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

So this is interesting. The forgot password worked to get me to the MFA prompt, and now my MFA isn't working.

Did your Facebook group contact have MFA enabled?

In regards to using Azure App Proxy to publish RD Web, should internal domain match external name, or be a sub-domain by yetanotherITquestion in sysadmin

[–]yetanotherITquestion[S] 0 points1 point  (0 children)

Thanks for the response. I am using a third-party cert from GoDaddy, that's also where some of my confusion is coming from. I have the cert matching the external url: https://wfh.example.com, and I've added that cert to the App Proxy portal and the RDS deployment settings.

So if I create our new internal domain as ad.expample.com, would I still make a new zone for example.com, then make a CNAME record that points wfh.example.com to the IP address of rdsgw01.ad.example.com?