u/YellowOnline
Sophos XG 125: which power adapter V/A is correct?
This morning my day started bad, with my whole infrastructure being down. The Sophos XG 125 looked dead. I measured the voltage and got 12V, so I feared the whole machine was bricked, not just the power adapter. Using a all-purpose power adapter however, I found out the device still works, so it seems to be the power adapter that is b0rked nevertheless.
Anyway: I'm on the temporary power adapter now, which is 12V/5A. I don't know how good that is in the long run for the firewall, so I want to buy (two of) the right model. But which one? I find conflicting information about the amps. 3, 3.3 or 3.4. Does anyone know what the device expects? Or does a 3 to 3.4A range (and even 5A) not matter so much?
Opvallende uitdaging voor Sébastien Pocognoli: Belg is de nieuwe bondscoach van Schotland
sporza.beIdentifizieren Internetverbindung das zu Telekom-Vertrag gehört
Ein Kunde hat zwei Telekom-Leitungen. Ein ist ein Vertrag von der Kunde selbst (Connect IP 300 BE-Flat), das andere gehört zu Gebäude.
Das Hauseigene würde gekündigt. Kein Problem, wenn das MX Record nicht auf ein von die beide verwies und ich nicht weiß welche jetzt verschwindet.
In die Firma (Behörde) sind keine Zugangsdaten vorhanden. Es wird erfahrungsgemäß Wochen dauern, um neue Zugangsdaten zu bekommen per Post.
Wenn es nicht anders geht, dann ist das so, aber vielleicht kann jemand der sich mit der Segmentierung von Telekom auskennt von die IPs ableiten was am plausibelsten ist.
Laut Firewall-Kommentar:
„ADSL“ 217.7.x.x
„SDSL“ 194.25.x.x
Dankeschön.
^^^und ^^^sorry ^^^für ^^^mein ^^^Grammatik
[VBR 12] Backup can't talk to NetApp storage after restructuring
At a site, I replaced the whole network infrastructure and replaced all cables. After 40 hours of working in 3 days, I went home satisfied, because everything works. I thought.
Now I notice Veeam Backup no longer works, and I'm not sure how to interpret the error.
[23.07.2026 15:21:55.367] <45> Error (3) NFC storage connection is unavailable. Storage: [stg:datastore-1016,nfchost:host-3005,conn:esx.acme.org]. Storage display name: [netapp:esxdata].
[23.07.2026 15:21:55.367] <45> Error (3) Failed to create NFC download stream. NFC path: [nfc://conn:esx.acme.org,nfchost:host-3005,stg:datastore-1016@AnvilServer/AnvilServer.vmx].
[23.07.2026 15:21:55.367] <45> Error (3) Agent failed to process method {Transfer.FileToText}.
[23.07.2026 15:21:55.367] <45> Error (3) (System.AggregateException)
[23.07.2026 15:21:55.367] <45> Error (3) NFC storage connection is unavailable. Storage: [stg:datastore-1016,nfchost:host-3005,conn:esx.acme.org]. Storage display name: [de00v58m:esxdata]. (Veeam.Backup.Common.CCppComponentException)
[23.07.2026 15:21:55.367] <45> Error (3) Failed to create NFC download stream. NFC path: [nfc://conn:esx.acme.org,nfchost:host-3005,stg:datastore-1016@AnvilServer/AnvilServer.vmx]. (Veeam.Backup.Common.CCppComponentException)
[23.07.2026 15:21:55.367] <45> Error (3) in c++: Unable to open source file [nfc://conn:esx.acme.org,nfchost:host-3005,stg:datastore-1016@AnvilServer/AnvilServer.vmx].
Veeam can reach the ESX, but apparently it has trouble with the storage (Netapp). I'm just unsure whether this is a physialc issue or a firewall issue or something else. The storage is in another network, but everything is allowed between these networks.
Can't get pump to suck
I installed a small pool (300cm ⌀ x 120cm), but I can't get my pump - above water level - to pull water. Am I doing something against the laws of physics in my setup?
It's Sunday evening, I worked 14 hours, and I'm locked up in the top of an office building because the door handle of the only exit is broken. At least there's a room with a sofa for the night.
No, I don't have tools to disassemble it. I will just surf the net and sleep for 10 hours, when the employees come in. I have a few remarks about fire safety too.
Edit: for 10 hours the only drama I make is on R3ddit. I'm not calling the fire department or police for that
Edit2: I managed to reach a colleague who I can throw the keys to, to free me. Yay.
The dangers of free licenses for Non-Profit
A non-profit asked my help because suddenly all of their 365 licenses were gone. I got access and checked: indeed, they got 10 free Business Premium (Nonprofit) licenses 5 years ago. Apparently, in June Microsoft deprecated those licenses, and no one noticed, as they only logon a few times per year. Microsoft says they try to find out why the bill says 18 June while in reality it was earlier (less than 30 days), but even if there was an error on their end: all of data is irreversible gone, "as per Microsoft policy".
Yes, the organization should have had an up-to-date contact email address where they would receive news of their free license being deprecated; and yes, backups are always necessary; but still I think Microsoft could handle this the deletion and recovery better.
Edit: we're talking about a 5 person non-profit of volunteers for a kindergarten who meet 4 times per year and used Sharepoint accordingly.
Sophos CS110-24FP switch does not boot, also can't connect through console to try restore over TFTP
[FortiOS 7.6.6] IPsec VPN fails in phase 1 after introducing FIC 2FA
I have an LDAP group role-de-vpn containing users who need VPN access.
Yesterday I added the LDAP server for authentication. Authentication works.
config user ldap
edit "ad-ldap-auth"
set server 10.0.0.100
set cnid "samaccountname"
set dn "dc=fortinet-fsso,dc=com"
set type regular
set username "cn=Administrator,cn=users,dc=fortinet-fsso,dc=com"
set password **********
set two-factor fortitoken-cloud
next
end
Next, I created an IPsec VPN. In my firewall rule (not in the tunnel), I allow only traffic from users in the role-de-vpn group. Everything still works.
Now I want to introduce 2FA and added two more settings to user ldap (thank you, u/r-r-r-r-r-r-r):
set two-factor fortitoken-cloud
set two-factor-filter "(memberOf=CN=role-de-vpn,OU=groups,OU=Administration,DC=fortinet-fsso,DC=com)"
Synchronization is fine: I see the users from the LDAP group in FIC, and they received an email with their Fortitoken QR code.
However, they can't establish a VPN connection anymore. It does not prompt for a token, and I get
XAUTH authentication failed
in Phase 1. Something I must be doing wrong here, and I hope someone can point me in the right direction. I'm sure it is related to the 2FA and not to the phase 1 config itself, as it worked before.
Edit: relevant might be that they're using IKE v1
Edit3: I created a new tunnel with IKE v2. Same issue.
Edit2: here's some debugging:
[1003] __ldap_next_state-State: User Membership Query -> Done
[1997] ldap_copy_grp_list-copied CN=Domain Users,OU=Users,DC=acme,DC=org
[1997] ldap_copy_grp_list-copied CN=Donald Duck,OU=external,OU=users,OU=Administration,DC=acme,DC=org
[690] fnbam_user_auth_group_match-req id: 10810690658325, server: MYDC, local auth: 0, dn match: 1
[596] __group_match-Use 'dduck' for user group matching.
[633] __group_match-Check if MYDC is a group member
[209] find_matched_usr_grps-Failed group matching
[888] update_auth_token_session-mfa_mandatory is off, only success results may require 2fa
[279] fnbamd_comm_send_result-Sending result 1 (nid 0) for req 10810690658325, len=2816
[597] destroy_auth_session-delete session 10810690658325
[1972] fnbamd_ldap_stop-
ike V=root:0:User_VPN_0:3995: XAUTH 10810690658325 result FNBAM_DENIED
ike V=root:0:User_VPN_0: XAUTH failed for user "dduck", retry(2).
Edit4: FOUND IT! For future people looking into this:
Out of despair, I checked if Fortigate actually sees the right groups. And lo!
MYFG # diagnose test authserver ldap MYDC dduck p@ssw0rd
authenticate 'dduck' against 'MYDC' succeeded!
Group membership(s) - CN=Domain users,CN=Users,DC=acme,DC=org
CN=Daffy Duck,OU=users,OU=Administration,DC=acme,DC=org
CN=Bugs Bunny,OU=users,OU=Administration,DC=acme,DC=org
CN=Wile E. Coyote,OU=users,OU=Administration,DC=acme,DC=org
Domain of user is acme.org
That can't be correct. Instead of the groups my user is a member of, I get all other users in the group.
Some googling later, I added set group-member-check group-object
The full LDAP config:
config user ldap
edit "MYDC"
set server "mydc.acme.org"
set secondary-server ''
set tertiary-server ''
set status-ttl 300
set source-ip ''
set source-ip-interface ''
set source-port 0
set cnid "sAMAccountName"
set dn "DC=acme,DC=org"
set type regular
set two-factor fortitoken-cloud
set username "svcFortigate"
set password Hunter2
set group-member-check group-object
set group-object-filter "(&(objectcategory=group)(member=*))"
set secure disable
set port 389
set password-expiry-warning disable
set password-renewal disable
set member-attr "memberOf"
set account-key-processing same
set account-key-cert-field othername
set account-key-filter "(&(userPrincipalName=%s)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))"
set obtain-user-info enable
set user-info-exchange-server ''
set interface-select-method auto
set vrf-select 0
set antiphish disable
next
end
And now:
MYFG # diagnose test authserver ldap MYDC dduck p@ssw0rd
authenticate 'MYDC' against 'MYDC' succeeded!
Group membership(s) - CN=role-de-vpn,OU=groups,OU=Administration,DC=acme,DC=org
CN=Domain Users,CN=Users,DC=acme,DC=org
Domain of user is acme.org
With this result, I tested the VPN again, and it works.
FortiIdentity Cloud & LDAP Group
Fortigate 7.6.6, no FortiAuth.
In this environment, I have an LDAP Group of VPN users. These should get FortiTokens through FortiIdentity Cloud. Am I correctly seeing that, to assign tokens I need to create all 200 users locally?
My aim in the end is that I add a user to an LDAP group and they automatically get 2FA activated and a mail with their QR code.
Nothing that can't be done with scripting I suppose, but it would surprise me that it's not possible out of the box.
Sophos Home on XGS Hardware
I find some old threads about this, but maybe things changed.
With SG it was possible to use the software version on the hardware, provided you changed a string somewhere if I remember well.
I'm considering to privately return to Sophos after a few years of another product. Professionally I use both Sophos XGS and Fortinet, so I can get retired hardware relatively easily (e.g. XGS 2100) to use at home, but that doesn't help me if I can't use the Home license somehow.
In the past, the co-processor being detected was apparently a show stopper. So what's the current status in XGS hardware and home licenses? Or would it work with an old XG 115?
[Exchange 2019] Mystery Forwarding
daffy.duck@acme.org complained that all of his mails are forwarded to bugs.bunny@acme.org.
There are no forwarding rules active on Exchange, neither ForwardingAddress nor ForwardingSmtpAddress. There are no server-side mailbox rules, also no hidden ones. I even checked with MFC MAPI Tool. There are no client-side mailbox rules on his computer. There are also no other clients except an iPhone, which is the only thing where I can't check myself if some kind of forwarding is configured, as that's a private device.
They use the CodeTwo signature tool which can do forwarding, but no forwarding is configured in there. I also checked the mail flow rules, and there is no relevant rule.
What could still be causing this forwarding, except the iPhone? From the way it is forwarded, I know it's a client-side forwarding, as Bugs receives Daffy as a sender and not the original sender.
Update1:
- iPhone account was removed, problem persists
- Moving mailbox to another DB
Update2: Solved! Thank you u/ScottSchnoll!
How does this phishing / URL manipulation work?
The last days I saw several phishing attempts with an URL like the following:
Careful, active phishing website, no hyperlink
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?state=test@test.com&scope=openid&prompt=none&client_id=8c73402b-669c-4bfd-9fcb-911cdd1b0430
This resolves into
Careful, active phishing website, no hyperlink
https://account.compliance.vu/configurations.html?reviews=test@test.com
Sadly, I don't know enough about OAuth to understand how this is done with these parameters:
state=test@test.com
scope=openid
prompt=none
client_id=8c73402b-669c-4bfd-9fcb-911cdd1b0430
I can imagine the client_id being where some kind of injection takes place, but I would like someone else's opinion.
Get all completed Teams meetings for a user
The page https://admin.teams.microsoft.com/users/{some_userid}/activity shows a good overview of the Teams meetings a user has had in the past. It shows organizer, participants, date/time and duration (though not subject it seems). I would like to integrate this in the time management tool, but for that I need the data programmatically. I've been playing around with MsGraph, but I'm not sure how to find the data in there. I think I need a course only on MS Graph.
All other suggestions I find online talk about scavenging the mailboxes, but 1) the users have no connected EXO, and 2) apparently the Teams admin page can show the data. Copilot isn't helpful. I thought, for once I can use AI, but it just suggested me to do an invoke-webrequest...
So, if anyone has an idea how to get this data through power shell, I would be very happy.