Windows – Certificate Enrollment Fails
May27

Windows – Certificate Enrollment Fails

KB ID 0000921  Problem I first saw this problem a few years ago trying to get some Windows clients to auto enrol with server 2008, then this week my colleagues could not get  new 2019 Domain Controller to enrol for a Kerberos certificate, and the this was caused by the same problem. Symtoms (RPC Error) 1. Test to make sure the client can see the CA, and is able to communicate with it, issue the following command; certutil -pulse As...

Read More
FortiGate TFTP : Backup To & Restore From
May26

FortiGate TFTP : Backup To & Restore From

FortiGate TFTP KB ID 0001788 Problem I know FortiGate prides itself on being able to do everything from the GUI, but if you can only get in at CLI and need to take a backup then you need to go old school. Recently I had an HA Pair of Fortis, the primary had broken and I could not get access to the GUI on the standby. My plan was to get a backup, blow both (virtual Firewalls) away, deploy two new ones, and restore the config. What...

Read More
FortiGate Web Filtering Setup and Deployment
May20

FortiGate Web Filtering Setup and Deployment

FortiGate Web Filtering KB ID 0001787 Problem In all honesty, enabling Web Filtering on your FortiGate really could not be simpler, you can simply enable it on your default users outbound policy, and select one of the three ‘pre-canned’ profiles, job done! But most companies not only want to filter their web traffic they want to see who is getting blocked, and what are users trying to get access to. Most businesses now...

Read More
FSSO FortiGate Single Sign On
May16

FSSO FortiGate Single Sign On

FSSO  KB ID 0001786 If you are applying polices with your FortiGate, e.g. Web Filtering or IPS, then the ability to track actual users rather than IP addresses is advantageous, it’s all very well blocking access to adult material or gambling sites, from the corporate network, but most companies want to know WHO is attempting to connect to what and when.  To do that the firewall needs to learn what users are where, we can make...

Read More
ESX SD Card?
May06

ESX SD Card?

KB ID 0001785 Problem For a while it’s been common knowledge that running ESX 7.x from a server that boots with an SD-Card is a no no. VMware themselves said (originally) that they would not support it. Then they said they would ‘sort of’ support it, if there was additional persistent storage. Then in the past week they’ve said, VMware will continue supporting USB/SD card as a boot device through the vSphere...

Read More