原本很舊的Forti防火牆升級後,有一些人的VPN就無法連線了,本來以為跟client端的vpn程式版本有關,因為公司內有4、5、6、7四種版本。
但後來發現這4個版本也都有不同的使用者可連上VPN,所以不是這個問題。
所以就用就錯誤訊息去查
原本很舊的Forti防火牆升級後,有一些人的VPN就無法連線了,本來以為跟client端的vpn程式版本有關,因為公司內有4、5、6、7四種版本。
但後來發現這4個版本也都有不同的使用者可連上VPN,所以不是這個問題。
所以就用就錯誤訊息去查
在升級卡巴斯基安全管理中心前,官方文件建議要用內建的資料備份和還原程式(Program Files (x86) Kaspersky Lab Kaspersky Security Center klbackup .exe)先做備份。
但在按下備份時,程式就會直接關閉,無法備份,沒任何訊息。
然後在事件檢視器裡,就找到一個相關的錯誤訊,原因是因為在執行備份時,會需要連上db,但目前登入的帳號是網域帳號,但當初安裝時是用本機帳號,所以會連不上db做備份,這時只要改用原本安裝的帳號來執行就可以備份了。
Fortigate 本身就有含兩個token授權,可以指派其兩個帳號,做雙因子驗證使用。
在測試時,設備本身有簽維護,但版本很舊,在設定時發生一些狀況,後來就把它給刪了,想說應該可以重新加回來,上網找了一下,可以用全都是0的預設設號匯入就行了。
結果~不行,然後有一個按鈕是寫重新下載授權,按下去就跳出無法存取forti care,一整個搞不定。
明明就有維護,還不給我存取,最後就依廠商建議,系統太舊原廠不支援,升級到最新試試,就可以了。
After deleting the two free tokens on FortiGate, I couldn't add them back, and I couldn't access FortiCare.
FortiGate itself comes with two token licenses, allowing for the assignment of two accounts for two-factor authentication purposes.
During testing, the device had an existing maintenance agreement, but it was running on a very outdated version. While configuring it, some issues occurred, so I decided to delete it, thinking that I could add it back later. I searched online and found that I could import a default configuration with all zeros.
However, it didn't work. There was a button labeled "Re-download License," but when I clicked it, it showed an error message saying it couldn't access FortiCare. It was quite frustrating.
Despite having an active maintenance agreement, I was denied access. Finally, following the vendor's suggestion, I upgraded the system to the latest version, and that resolved the issue.