Posts

Unable to obtain internal DNS server

Image
I encounter an issue that unable to ping to FQDN but able to ping to IP address after setting up a Fortigate firewall. The remote office do not have any DHCP server and DNS server. Therefore I setup the Fortigate 60D as the DHCP and create a IPSec to the HQ office. I then try to perform nslookup on the connected device and notice it provide me the ISP DNS instead of internal DNS. As resolution, go to Network > Interfaces > internal. Edit the internal interfaces and set the DNS server to Specify. Enter the internal DNS server IP.

Turn off Fortigate web access from public IP

Image
Accessing from external public IP to Fortigate devices are important especially for remote site. However, this might open up security loop hole for attacker to access to company environment via public IP. Login to Fortigate, navigate to Network > Interfaces > the wan interface > edit. Under Administrative Access > uncheck the HTTPS / HTTP. Also make sure the SSH & SNMP is not checked.

Set DNS suffix in Fortigate

Image
After sign in to Fortigate SSL VPN, user unable to access to local sites, unable to RDP to server or accessing network drive. When try to run ping to the FQDN, it will show could not find the host. However, if try to ping with suffix ad.local, it will be able to access. After searching for quite sometime, I found an article  show how to enter the dns suffix via CLI. For my case, it works as below. Set DNS search suffix using CLI config vpn ssl settings set dns-suffix ad.local end Set Client DNS Server in the GUI Navigate to VPN –> SSL –> Settings –> Tunnel Mode Client Settings.  Specify the DNS Server setting and enter the IP addresses of your corporate DNS servers. Finally it works.

Meeting Efficiency

This article explain why a presentation should not exceed 18 minutes total. For this, 15 minutes ideal meeting.  Not every meeting may be able to be done in 15 minutes, but for the general day to day stuff there's no reason to be wasting away for hours while nothing is accomplished. If you need a little help, try setting a 15 minute timer and when it goes off, meeting is done. If you guys heard of “meeting efficiency”, there are some company had begun practicing it. Why company practice meeting efficiency? 1. To improve productivity.    Employee able to attend several meetings/discussion in a day which also allow time for operation work related. 2. To avoid over shoot of meeting period due to limited meeting room available. This is to allow the room to free up on time for the next group that book the room. Rules in meeting efficiency: 1. 30 minutes is the maximum of a meeting for a group of less than 5 people and 1 hour is the maximum of a meeting for a group of more than 5 peop...

Defrost steak in 5 mins without electricity?

Image
This post from FineDiningLovers shows a good idea on how to defrost a steak in 5 minutes without microwave oven. By placing two metal pot, with the one on the top fill with water. This method allows ambient heats. How? The process is actually quite simple. All users have to do is place the steak on a metal pan that’s been turned over, place a second pan on top of that and fill the top pan with water. The increased pressure from the water and something called ambient heat, which is conducted very well by metal, work to defrost the meat without any electricity needed. I'm going to try this when there is a chance.

Betrothal (过大礼)

This procedure is the most important process to be done by the couple. Especially the groom. It is as important as tea ceremony. Even for some couple that prefer honeymoon wedding, they still require to have at least a tea ceremony with the parents and of course betrothal not to miss. This two process is unavoidable for Chinese culture. The betrothal gifts are delivered up to a month and at least three days before the wedding day. The groom and a friend or a matchmaker will deliver the gifts on the auspicious date chosen. Betrothal gifts 娉礼 The betrothal gifts (quantity of the following items to be determined by the bride's parents) are packed in a multi-tiered wedding basket that is borrowed from a Chinese wedding cake shop and typically include: western and chinese wedding cakes, which you may choose either one too. Most people will choose Chinese wedding cakes. You can also replace with the big size "tau sar pneah". two bottles of brandy. You can replace it with red wi...

Wedding Bed Installation (壓床)

Image
Things to Buy: Small Double Xi Plate (you can get it at any wedding shop) 2 Longans 2 Red Dates Dried Lotus Seeds Bai He (dried magnolia petals) 2 Red Packets (Any auspicious amount will do, eg. RM 8, 18, 28, 88) 4 Yan Ji (to place each at 4 corners of bed under mattress) 2 orange. * Take noted that all amount/figures need to be in even number. It means a pair / a couple. Procedures to Follow: 1) If groom's parents install, then couple give ang pow to each of them. 2) If couple install, no need ang pow for anybody. Some old people advise that parents to install are better. If only single parent, any happy married couple can do so. Just need to give ang pow to each of them. * A modern way of installation, the couple can get the bed ready probably left one corner bed sheet not tuck in or the pillow not place on top of the bed. Then when the old couple can just place the pillow and the rest of the stuff on the bed. It consider done by them too. 3) After an chuang, nobody supposed t...