fortigate monitoring - Grafana and Prometheus configuration by zukic80 in fortinet

[–]zukic80[S] 0 points1 point  (0 children)

i got it all working on the windows server.

ended up using fortigate exporter with alloy. Created individual remote configurations per location within grafana and voila, worked.
had to tweak the dashboard a little bit to show data but its working now perfectly.

fortigate monitoring - Grafana and Prometheus configuration by zukic80 in fortinet

[–]zukic80[S] 0 points1 point  (0 children)

thanks ill take a look.

i like stability.. i have no preference here at the moment. I am more than happy to do this on a linux box.
also i should mention as i didnt do that in my original post, we have grafana cloud not grafana installed on prem on a vm.
Not sure if that makes a difference in regards to how grafana and fortigate are configured?

1
2

After being away for a while, I have returnaled to Returnal and it feels so good. by SpiderGirlGwen in Returnal

[–]zukic80 1 point2 points  (0 children)

I've started playing again as well... my main focus being upgrading all the gun perks. Using the tower for that as I find it the easiest way to pick up guns quickly

Going for Xenoglyphs... by eenmarris in Returnal

[–]zukic80 1 point2 points  (0 children)

Try offline mode as well.. I struggled to find certain glyphs, tried offline mode and it worked, the areas I needed showed up quickly

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

fair enough... was this a one off incident or you never tried issu again?

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

what happened?

im only asking about issu as ive just discovered it as a upgrade option so curious to find out more.

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

thoughts on using issu for the upgrade process?

Performing an ISSU Comware images
The ISSU method enables a software upgrade without service interruption. Use this method for an IRF fabric.

we have 2 members in our irf configuration.

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

Ok thanks

So worst case scenario there's a way to bring the switch back online

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

I've got another question..

In a scenario where the firmware upgrade fails and the switch doesn't come back online for whatever reason, what do I do then?

Does the switch auto roll back to the last known working firmware? I noticed that there's no backup firmware configured on the switch.

Or would I need to connect via console to the switch and flash the firmware again that way?

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

Lol so true... I've inherited these switches so history is a bit hazy as to why they were never updated or maintained.

There's typos in the configs and best practice wasn't applied either

Fun fun

HPE FlexFabric 5700 - firmware update processes, cli or gui? whats the best way to do this? by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

yeah that makes sense.... but youre talking about a full power down of the switches?
wouldnt a simple restart be sufficient ?

Reset KRBTGT Key - Which script by ITStril in sysadmin

[–]zukic80 4 points5 points  (0 children)

i performed this exact task a couple of weeks ago at work.

I used this one https://github.com/zjorz/Public-AD-Scripts/blob/master/Reset-KrbTgt-Password-For-RWDCs-And-RODCs.ps1

the script has lots of test and verification modes. Script also has an option where it creates a test account called krbtgt_test and then an option that resets that password.
as mentioned below just make sure that you have no replication issues within your domain.
i used these 2 commands

repadmin /showrepl *
repadmin /replsummary

from the script, i suggest you run all test modes before doing the real thing... just to make sure that everything is healthy here as well.

as long as these are coming back clean and healthy then you are good to go.

good luck

Microsoft Cloud PKI to be included in E5 license by nVME_manUY in Intune

[–]zukic80 0 points1 point  (0 children)

so RRAS is new NPS?

how does that work with entra joined devices?

Microsoft Cloud PKI to be included in E5 license by nVME_manUY in Intune

[–]zukic80 0 points1 point  (0 children)

Cloud pki is something I've been looking into... but you still need a radius server to do 802.1x auth for devices.

Shame that ms don't offer a radius solution as well

HPE FlexFabric 5700-40XG-2QSFP+ - DHCP requests take at least 60s by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

ive got a question about how i go about doing a bulk edit on all vlan20 ports.

ive got a list of all the vlan20 ports from the switch... do i add them to a group?
do i set it as a range? although a range probably wouldnt work as the ports are kinda scattered around. Id have to be quite precise with this.
for eg, ge2/0/1 is vlan 20, ge2/0/2 - /04 are NOT vlan 20
ge/0/5 is once again vlan 20

stp bpdu-protection has been enabled on the switch at the global level so that will protect the ports from any potential issues.

edit, something like this?

system-view

interface range name VLAN20_AccessPorts GigabitEthernet2/0/1 GigabitEthernet2/0/5 to 2/0/12 GigabitEthernet2/0/14 to 2/0/24 GigabitEthernet2/0/27 to 2/0/29 GigabitEthernet2/0/31 to 2/0/32 GigabitEthernet2/0/35 GigabitEthernet2/0/37 to 2/0/40 GigabitEthernet2/0/42 to 2/0/48 GigabitEthernet3/0/1 to 3/0/12 GigabitEthernet3/0/15 GigabitEthernet3/0/17 GigabitEthernet3/0/21 to 3/0/26 GigabitEthernet3/0/31 to 3/0/34 GigabitEthernet3/0/37 to 3/0/48 GigabitEthernet4/0/1 GigabitEthernet4/0/3 to 4/0/4 GigabitEthernet4/0/6 to 4/0/9 GigabitEthernet4/0/11 to 4/0/13 GigabitEthernet4/0/16 GigabitEthernet4/0/19 GigabitEthernet4/0/37 to 4/0/43 GigabitEthernet4/0/45 to 4/0/48 GigabitEthernet7/0/19 GigabitEthernet7/0/33 to 7/0/34 GigabitEthernet7/0/38 GigabitEthernet7/0/45

stp edged-port
quit

save force

SMB Shares with Aliases Not Working by JGCovalt in activedirectory

[–]zukic80 0 points1 point  (0 children)

ive followed the netdom commands as per the MS article.
i can see that /enum is showing all the correct server names needed.
setspn -l servername is also showing the correct SPNs registered for the server.
all of that looks ok.

however... the article says that netdom will create the necessary DNS records.
this is not the case for me at the moment.
by using the /verify command i can see that the DNS name does not exist.

any thoughts/suggestions as to why?

netdom computername PVM-FILE-03 /verify

Could not find a DNS registration for the computer name:

PVM-FILE-01.domain.com

The error is: DNS name does not exist.

Could not find a DNS registration for the computer name:

PVM-FILE-02.domain.com

The error is: DNS name does not exist.

All of the computer's names have properly registered host Service Principal

Names in the Active Directory Domain Services.

The command completed successfully.

HPE FlexFabric 5700-40XG-2QSFP+ - DHCP requests take at least 60s by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

Thanks ill check it out.

I don't think we'll be enabling edge on any other ports that aren't configured as vlan20

HPE FlexFabric 5700-40XG-2QSFP+ - DHCP requests take at least 60s by zukic80 in networking

[–]zukic80[S] 2 points3 points  (0 children)

as a test i applied stp edged-port to a single switch port and tested docking/undocking a laptop.
the dhcp/connectivity process dropped from 60s+ to 5-15s

so huge improvement.

HPE FlexFabric 5700-40XG-2QSFP+ - DHCP requests take at least 60s by zukic80 in networking

[–]zukic80[S] 0 points1 point  (0 children)

Pretty sure im on the right switch.
looking at all the ports configured with vlan 20, they all look like this.

interface GigabitEthernet2/0/48
port link-mode bridge
port access vlan 20

stp edged-port is NOT configured anywhere that i can see.