Create site-to-site VPN with FortiGate to Microsoft Azure

I know, it is an unsupported configuration to create a site-to-site VPN to Microsoft Azure with a FortiGate firewall. But a FortiGate device is what i have and only to run some test’s I don’t want to buy some of this expensive supported firewalls.

I tried a lot of configurations, but nothings seams to run with Azure and my Fortigate firewall. So this week, I started a new try with this problem and after a few test’s I was successfully.

First I detected, that there is a new Option in Windows Azure, I never saw before: Dynamic Routing GateWay. After trying the old option Static Routing Gateway, I tried the new one and was successfully. The differences between dynamic and static routing gateways are described here. read more

recover deleted Bitlocker Recovery Informations

Today I had a request from a first-level-admin which need the Bitlocker Recovery Password for a already deleted computer object. Here is what I came up with:

Please note that you need to be a Domain Admin (or equivalent) to be able to read the Deleted Objects Container. The tombstones will have a lifetime, after their expiration, you can’t access anymore to the recovery passwords.

With PowerCLI, you can add AD authentication to a single managed ESXi Host. For this you need to add your ESXi-Host to the AD (line 9) and then add permissions (line 11):

sometimes line 11 will fail, then you have to wait for domain replication and repeat it.

i like vCheck to daily report my virtual environment status. But a lot of our guest systems are not in my responsibility, so the VM Tools are not uptodate or aren’t installed.

i wroted this plugin for vCheck:

Proxy autoconfiguration with WPAD.dat and multiple network adapters

If you use a proxy server in your company, you would like to automatically configure your clients using a WPAD.dat-file. If you use the myIpAddress()-function, this function will returns the ip address from one active network adapter, maybe from the wrong one. This function couldn’t determine, which network adapter would made the connection to your proxy server. In this case you couldn’t connect to the internet, cause the WPAD.dat file returns the wrong result.

There is no automatic metric inside the WPAD.dat to detect, which adapter is the active adapter, nearest to your proxy server. You need to set the ip metric manualy on each network adapter: read more

auto-update Antivirus Essential for Synology NAS behind proxy

Since DSM 4.1 you can configure proxy service at the Control Panel – Network:

but if you have installed the AntiVirus Essential package, it wouldn’t use this settings to update it’s virus definitions and will fail:

To configure autoupdate for the virus definitions behind a proxy server, you need to configure some settings manualy:

activate ssh on your NAS:

connect to your NAS by SSH and login as root (not as admin!)

create a new script:

change vi to the insert mode by press key i, then insert this lines: read more

network calculations in Excel 2010

i need often to calculate network addresses, subnet-masks/bits, Hosts and more. For this i wrote this script Network.bas, which you can implement in your Excel file or your Default template book.xltm:

i implemented this functions:

  • NetworkCalculate
    • Add or subract from an IP-Address:
    NetworkBitsToSubnetmask
    NetworkBroadCastAddress
    NetworkClientHighestAddress
    NetworkClientLowestAddress
    NetworkClientRange
    NetworkSubnetAddress
    NetworkSubnetMaskToBits
    NetworkBitsToSubnetMask
add second default route to Synology NAS

Shortly i need to connect a Synology NAS to two separated networks. At default you can only define one Gateway for your Synology NAS. To define a second route, do this steps:

Activate SSH access to your Synology NAS:

configure first LAN interface:

configure second LAN interface:

configure default gateway:

Connect to NAS by ssh and configure the second route:

after configuring this, you can disable ssh access again.

There are several valid reasons to demand that a vbscript runs in CSCRIPT instead of WSCRIPT, like for example to allow the use of Standard Input or to prevent a separate popup for each Wscript.Echo line.

The following code can be copied and pasted at the top of your own scripts to force them to run in CSCRIPT:

The code may look more complicated than necessary, that’s because it returns CSCRIPT‘s return code to the WSCRIPT engine, just in case this return code is monitored by the program that started the script in WSCRIPT. read more