Configuring SAML SSO for FortiGate Administrator Login with Microsoft Entra ID
This guide outlines the steps to set up SAML-based Single Sign-On (SSO) for FortiGate administrator access, leveraging Microsoft Entra ID as the Identity Provider (IdP). Overview Terminology Mapping FortiGate Term…
Read moreUbuntu – Hot to Change a SSH host key?
Follow these steps to regenerate OpenSSH Host Keys
Read moreHow to Upgrade TimeScaleDB Docker
To upgrade TimescaleDB within Docker, you need to download the upgraded image, stop the old container, and launch the new container pointing to your existing data. Connect to the upgraded…
Read moreHow to Upgrade a PostgreSQL Database in a Docker Environment
Upgrading a PostgreSQL database within a Docker environment requires careful planning to ensure data integrity and system stability. Here’s a structured approach to performing a major version upgrade: Prerequisites Step…
Read moreDebugging FortiGuard Web Filter Issues After Firewall Reboot
When working with FortiGate firewalls, you might encounter a situation where FortiGuard Web Filtering services become unreachable after a reboot. This can prevent users from accessing web-filtered resources, leading to…
Read moreAuto Expand Disk size via cron
First prep the system for the auto expand script Add the Script to crontab to run every 15 minutes Save the script in /etc/expand-disk/auto-expand-disk.sh (Full copy-paste command is present below…
Read moreRestore a configuration backup on a FortiGate HA cluster
When restoring a configuration backup on a High Availability (HA) cluster, the process should be performed only on the primary unit. The configuration will then automatically synchronize with the secondary…
Read moreInstalling and Logging In to Windows 11 Without an Online Microsoft Account
By default, Windows 11 requires you to log in with a Microsoft account during the initial setup process, also known as the Out-of-Box Experience (OOBE). This requirement is part of…
Read morePowerhslel: Renew Certificate with Specific Template
If it should be executed by a GPO and only once, use the following
Read moreCreate DHCP Scope via CLI in Microsoft Server
Create scope through powershell Set options like, DNS Server, DNS Suffix and Default Gateway
Read moreInstall docker on Ubuntu ( Without SNAP )
If you do not want to run sudo before docker commands add your user to the docker group.This is not recommended
Read moreExtend standard disk ( Non lvm)
After the disk has been extended, then rescan for changes. This guide is based on the SDA disk and the 3 partition. Change the device and partition to match your…
Read moreRequired Domain Controller Ports through Firewall
Domain controllers play a crucial role in your network. To protect them, ensure that the firewall is enabled and that only the necessary ports for your Domain Controller are open.…
Read moreHow to upgrade Windows 2022 from EVAL to Full Version
If you attempt to convert or upgrade Windows Server Evaluation to a fully licensed edition using the standard command line or the CHANGE KEY GUI, you may encounter errors such…
Read moreExtend LVM with extra disk
Find the LVM details of the volume group that you want to add a disk to: Example output, The two with bold are the needed information in this example Find…
Read moreTrust Certificates in Ubuntu/Debian system
Debian as an example. Install the ca-certificates package: You then copy the public half of your untrusted CA certificate (the one you use to sign your CSR) into the CA…
Read moreSubmit CSR to Microsoft CA using CertReq
1: Generate CSR. It will be required in step 3. 2: Right-click Start | select Windows PowerShell (Admin) to launch PowerShell as administrator.3: Execute the following certreq command: CertificateTemplateName Substitute…
Read moreIPMI Cli Commands
1. Man and help info for IPMItool ipmitool help man ipmitool 2. To check firmware version ipmitool mc info 3. To reset the management controller ipmitool mc reset [ warm…
Read moreEVE-NG Node Credentials List
Instance Name Username Password Console type Cisco ASA 802 no passwd, hit enter telnet Cisco ASA 8.4.2, 9.1.5 no passwd, hit enter telnet Cisco ASAv no passwd, hit enter telnet Cisco…
Read moreExtend default LVM Volume
After the disk has been extended, then rescan for changes. This guide is based on the SDA disk and the 3 partition. Change the device and partition to match your…
Read moreRsyslog Troubleshooting Guide
Initiating Debug Mode To kick off debug logging from the get-go, prepend your rsyslog.conf file with these lines. This ensures debug logging activates immediately upon the rsyslog service launching: After…
Read moreLimit Windows RPC Ports
When using domain services through a firewall the RPC ports must be limited from the range 1025-65535 to specific ports. Windows registry settings, must be implemented at least on domain…
Read moreRepairing FortiAnalyzer when disk are in Read-Only mode
Maintenance Mode indicates that the system is unable to detect the hard drives, the hard drives cannot be correctly mounted, or the disk is experiencing corruption. If the hard drives…
Read moreHAProxy – Set Backend Server in maintenance mode
First install socat Execute the following command where <backend> and <Server> are replaced Example We can verify the servers with socat with the following command We get the following output…
Read moreWindows – Add NTP Server
Execute the following command, change the timesource to a FQDN or an IP Address Stop time Service unregister and register time service Start time Service Open a Command Prompt. Type…
Read moreUnifi – Set Option 43 for controller IP
Unifi uses option 43 so the switches and AccessPoints can find its controller if it is not present on the same L2 network. Option 43 should be filled out with…
Read moreRsyslog – Forward logs to another server
Create a new config file under the rsyslog config directory Use single @ for udp forwardingUse double @ for tcp forwarding Example of udp forwarding Example of tcp forwarding
Read moreRsyslog – Save login to a seperate file
Create a new rsyslog config file Add the following text
Read moreHAProxy Use Multiple Config Files from a folder
Create a folder to contain the .cfg files Change the systemd file used for the HAProxy Service Find the line that starts with Environment Edit the line so it contains…
Read moreTwo-Tier CA structure ( Online Subordinate CA )
Prerequisites IIS must be installed and working from the clients that will need the RootCA or certs signed by the RootCA server. See more for a simple IIS install guide…
Read moreTwo-Tier CA structure ( Offline RootCA )
Prerequisites IIS must be installed and working from the clients that will need the RootCA or certs signed by the RootCA server. See more for a simple IIS install guide…
Read moreInstall IIS for Certificate Authority CRL and Root Certificate distribution
Open powershell and install the iis windwos feature Open the IIS manager Expand the Sites and expand the Default Web site. Right click and create new virtual directory Create the…
Read moreFortigate Best practices – CLI Examples
Management *Missing from this guide. Management users from central user database ( LDAP, SAML etc ) Configure the web management portsHostname and the Alias of the firewalls.I enable LLDP for…
Read moreFortigate Best practices – Introduction
Management Network Should be independent from production or business traffic, it does not have to compete for resources and management access can be maintained when reconfiguring the production network. Policies…
Read moreAdd VLAN to a Lenovo switch in a MCLAG cluster
There are consistency check in the Lenovo swtiches when they are participating in a MCLAG cluster. Therefor the switche will shutdown the ports if there are an inconsistency between the…
Read moreMicrosoft CA Server installation
Install the Windows feature. Open powershell as admin and execute the following command I strongly reccomend to not use the server name as the CA Common Name, since this will…
Read moreSCP into an arista switch
The username you use must be defined explicitly with “privilege 15” as part of the definition, so it will look like this perhaps: That puts your user in privileged mode…
Read moreFortigate – Airprint multicast forwarding between two different subnets
1) Enable Multicast forwarding: 2) Interface configuration:Two different interface having two different IP addresses assigned. 3) Configuring Multicast Policies: 4) Check if multicast routing is enabled or not:
Read moreEnable remote connections in Forticonverter
The new FortiConverter is designed as a web application. The application (FortiConverter.py) should be run with Administrator privileges because it reads and writes data from/to high privilege directories. For security…
Read moreForgot admin password on a Fortigate
Factory reset when forgot admin password Reboot the fortigate When the login prompt appears you have max 14 seconds to login with the maintainer account Username: maintainer Password: bcpb<FORTIGATE…
Read moreDiagnose Traffic Flow on a Fortigate
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33882
Read more