“Learn from every situation today, good or bad. No matter how I feel about it, take a lesson from it
Monday, August 17, 2020
Wednesday, August 5, 2020
How to enable e-mail as a two-factor authentication for a user and increase token timeout on FortiGate
I would say absolutely that FortiToken (be it a mobile app or a physical
token) is the most secure and preferable way today for multi-factor
authentication. The other two - SMS message and e-mail message are vulnerable
to many attacks, including not so technically sophisticated SMS swapping. But
sometimes a less secure method is better than none. Two catches with using an
e-mail as MFA on Fortigate though:
- It is not available in the GUI until you turn it on at the CLI.
- e-mails tend to get delayed sometimes, and the default validity time for any Fortigate produced token code (SMS, e-mail, FortiToken) is 60 seconds. If the user doesn't enter the token code within 60 seconds of issuing - code becomes invalid. It is usually not a problem, but recently I had to enable e-mail MFA for our branch location with substantial e-mail delays being a norm. So optionally below you can find how to increase the default timeout.
- Enable e-mail option as MFA
for a user:
config user local
edit "karthi"
set type password
set two-factor email
set email-to "karthi@abc.com"
next
end
Now the option for e-mail as 2-factor authentication appears in GUI:
(Optional) Increase
token code validity from 1 to 2 minutes:
config system
global
(global) #
set two-factor-email-expiry ?
two-factor-email-expiry Enter an integer value from <30> to <300> (default =
<60>).
(global) #
set two-factor-email-expiry 120
Thanks for reading my blog.
Thursday, December 13, 2018
How to Disable HTTP Method OPTIONS for the web applications in IIS 7.5 and above
- Open IIS Manager.
- Select the name of the machine to configure this globally (or change to the specific web site for which you need to configure this).
- Double click on "Request Filtering".
- Change to the HTTP Verbs tab.
- From the Actions pane, select "Deny Verb".
- Insert 'OPTIONS' in the Verb, and press OK to save changes.
Tuesday, July 3, 2018
list of Windows PowerShell commands Useful for administrators
Add a DLL to the GAC
1. Run the Power Shell console as Administrator.
2. Enter the following PowerShell
Set-location "c:\Folder Path" [System.Reflection.Assembly]::Load("System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a") $publish = New-Object System.EnterpriseServices.Internal.Publish $publish.GacInstall("c:\Folder Path\DLL.dll") iisreset
Remove a DLL from the GAC
2. Enter the following Power Shell
Set-location "c:\Folder Path" [System.Reflection.Assembly]::Load("System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a") $publish = New-Object System.EnterpriseServices.Internal.Publish $publish.GacRemove("c:\Folder Path\DLL.dll") iisreset
Regards
R Karthikeyan
Monday, March 26, 2018
users temp profile deleting without restart
Tuesday, October 10, 2017
MCSA 2016 Prepartion and practice Exam
The test is free and you can retake it as often as you like: on desktop, tablet or mobile. The questions were handwritten and I do not approve of PDF braindumps - you won’t find any copied material here.
Braindumps - It’s worth asking yourself if you’re ok with braindumps. These barely legal documents essentially equate to cheating your way through life. Where’s the self satisfaction or even the challenge in cheating? You’ll get greater pleasure and reward for actually learning the material and passing the exam legitimately. Stick to official training material and do yourself justice in passing the exam yourself - you know you can!
Practice Exam Free
http://www.accelerated-ideas.com/exams/practice-exam.aspx?group=70-740&fq=1&qmax=30
Reference Book:
MCSA 70-740 : http://amzn.to/2g8bhR8
MCSA 70-741 : http://amzn.to/2wKkYbw
MCSA 70-742 : http://amzn.to/2g8CTpi
Regards
R.Karthikeyan
Thursday, October 5, 2017
Friday, September 22, 2017
Adding NANO Server to Domain controller 2016
- We need set IP Address
- We need to enable ALL file share and printer sharing session from the inbound firewall rule
Monday, September 11, 2017
Direct download .bak files through IIS Windows 2012 R2
Hi,
Some time for some reason we avoid using FTP Server and we wold like to have alternate for dwolading huge size files.
In My Case almost 20 GB file i need to transfer from one location to another location.
I can use FTP but some of speed restriction policy applied in my FTP server during the peak hours.
we do have alternate ISP in this we are not configure any FTP.
In this i just used IIS Server.(note: Source server I am having public IP access).
I just Followed these three steps and Stared Donwload.
1. Host the test Application.
2. Enable Directory Browsing Give Permisiion to IIS_IUser and IUSR
3. Adding MIME Type.
Add additional MIME types for PKGs:
a. Select Default Web Site in the left sidebar.
b. Double-click MIME Types.
c. Click Add from the right sidebar and type ".bak" in the File name extension field and "application/octet-stream" in the MIME type field. Then, click OK.
Not everything has a custom mime type. For generic binary files

Friday, May 19, 2017
Moving Temp DB to Different Folder / Location
---Determine the logical file names of the tempdb database and their current location on the disk.
SELECT name, physical_name AS CurrentLocation
FROM sys.master_files
WHERE database_id = DB_ID(N'tempdb');
GO
----Change the location of each file by using ALTER DATABASE.
USE master;
GO
ALTER DATABASE tempdb
MODIFY FILE (NAME = tempdev, FILENAME = 'F:\TEMPDB\tempdb.mdf');
GO
ALTER DATABASE tempdb
MODIFY FILE (NAME = templog, FILENAME = 'F:\TEMPLOG\templog.ldf');
GO
--Stop and restart the instance of SQL Server.
--Verify the file change.
SELECT name, physical_name AS CurrentLocation, state_desc
FROM sys.master_files
WHERE database_id = DB_ID(N'tempdb');
--Delete the tempdb.mdf and templog.ldf files from the original location.
Thursday, May 11, 2017
How to identify what features has been installed in your SQL Server
Yes, there is an easy way.
Method 1:
we can navigate to the Following Path and see the summary file.
SQL server 2012 Features Installation Discovery.
C:\Program Files\Microsoft SQL Server\110\Setup Bootstrap\Log\Summary.txt
Tuesday, May 2, 2017
Ports for windows file sharing
Sharing a folder or file creates a Windows Firewall exception for File and Printer Sharing. The exception opens the ports listed in the following table.
| Connection | Ports |
|---|---|
TCP
|
139, 445
|
UDP
|
137, 138
|
Regards
காŕ®°்த்திகேயன்
Karthikeyan
Thursday, August 25, 2016
useful commands-Fortinet Firewall-Part 2
execute dhcp lease-clear <ip_addres> –> clear the DHCP lease of a specific ip
execute dhcp lease-clear all —> clear all the DHCP leases
Thursday, July 14, 2016
The database principal owns a schema in the database, and cannot be dropped
SELECT s.name
Friday, July 8, 2016
Fortigate Firmware upgrade Process On HA
1) Check the release notes for supported upgrade path, special notices, product integration, known issues and limitations if any.
2) Backup configuration before and after each upgrade.
3) Plan a maintenance window for the upgrade.
3) Have some one available on the remote site in case something went wrong during the upgrade.
4) Make sure check sum is matching between cluster members using the following CLI commands:
# get sys ha status
# diag sys ha showcsum
# execute ha manage <Slave ID> <<-- could be 0 or 1, check "get sys ha status" results
$ diag sys ha showcsum
$ exit
The results of "diag sys ha showcsum" should be the same on all levels (all/global/vdoms)
Thursday, July 7, 2016
Windows Time Service Issue
- net stop w32time
- w32tm /unregister
- w32tm /register
- net start w32time
- “net time /setsntp: ” (Note the blank space prior to the end “) [This tells the client (whether a DC or workstation) to delete the current registry settings for time and use default settings.]
- Restart the time service: Net stop w32time && net start w32time
- W32tm /config /manualpeerlist:time.nrc.ca /syncfromflags:manual /reliable:yes /update
- W32tm /resync /rediscover
- Restart the time service: net stop w32time && net start w32time
- w32tm /config /syncfromflags:domhier /update
- W32tm /resync /rediscover
- Restart the time service: net stop w32time && net start w32time
Tuesday, June 28, 2016
Boot from ISO image failed on Generation 2 VM in Hyper V
- Attempt
to boot from the CD SCSI device containing the Windows 8 ISO. This is
where the ‘Press any key…’ message came from. As no key was pressed, we
went to the next boot entry. (And this is where we didn’t clear the
message from the EFI CD boot loader)
- I
didn’t press F12 (in fact, this VM wasn’t connected to a network), so
network boot failed
- The
SCSI VHDX is raw with no partitioning or file system, so this too failed
or
http://api.256file.com/download/87465_oscdimg.exe
d:\Software>oscdimg -o -u2 -udfver102 -bootdata:2#p0,e,b"D:\Software\win2012nop
rompt\boot\etfsboot.com"#pEF,e,b"D:\Software\win2012noprompt\efi\microsoft\boot\
efisys.bin" "D:\Software\win2012noprompt" C:\Working\WIN2012noprompt.iso













