This website is originally written in the Czech language. Most content is machine (AI) translated into English. The translation may not be exact and may contain errors.
Statistics
Page has been view by 12 089 070 visitors. During today 255. Right now is here 97 guests.
Veeam Backup & Replication - VM migration using replication
The previous article described the basic options for using replication in Veeam Backup & Replication. Today we will build on that and look at a less typical situation, where we use replication to migrate a Hyper-V VM between two different Hyper-V clusters.
Veeam Backup & Replication - Replication Job
Veeam Backup & Replication is a well-known solution for data protection and disaster recovery. Many people think of it as just backup. But the name itself also contains a second function, which is replication. In this article we will look at the basic options for using replication.
Object First Storage in Veeam Backup & Replication
Object First Ootbi is an on-premises hardware appliance specifically designed as a secure backup object storage (S3-compatible) for Veeam. It is built on simplicity, security, and performance. The previous article covered basic information and described the cabling and configuration. Today we will look at actual usage together with Veeam Backup & Replication (VBR). Specifically creating an access key and a bucket, and adding it as a Backup Repository in VBR.
Object First Ootbi Appliance Basic Setup
Object First is an American company that primarily manufactures on-premises backup storage called Ootbi (Out-of-the-Box Immutability). This object storage is specifically designed for Veeam Backup & Replication. It is built on simplicity, security, and sufficient performance. Support for Immutability to protect backups against ransomware and access via S3 API are standard features.
Guest Processing and Group Managed Service Accounts (gMSA) in Veeam Backup & Replication
gMSA is a special type of account in Active Directory used for service accounts. It can be used on Windows for services, applications (that support it), or scripts (scheduled tasks). The administrator does not know its strong password, which is changed automatically. We will describe the options for using gMSA within Veeam Backup & Replication (VBR), where it is supported for Application-Aware Processing. We will also look more closely at Guest Processing on Windows and what accounts we need for certain situations.
Veeam ONE Reporting Service failed to start due to a missing certificate
One day, the Veeam ONE Reporting Service stopped starting without any warning. As a result, most Veeam ONE features stopped working. The cause turned out to be straightforward, a self-signed certificate for the Web API had disappeared from the system certificate store. How this happened could not be determined, but the fix was quick and simple.
Entra ID overview of registered user authentication methods
In this article, we will look at the various ways to find out which authentication methods a user has registered (available) in their Microsoft Entra ID work account. Authentication methods represent the ways in which users sign in to resources protected by Microsoft Entra. The first part of the article covers the options available to a regular user for viewing their own registered methods. The second part describes tools intended for Entra ID administrators, who can view information about a specific user's methods or obtain a summary overview across the entire tenant.
FIDO passkeys part 6 - registering Entra passkeys in Windows Hello
We have another update on using passkeys for user authentication within Microsoft Entra ID. This is a new way to register (add) passkeys to a Windows computer into Windows Hello. It works for both managed devices (joined or registered to Entra ID) and unmanaged devices. It is currently in Public Preview, but hopefully will reach GA soon.
FIDO passkeys part 5 - Entra ID passkey profiles and synced passkeys
Microsoft continues to expand the options for using passkeys for user authentication. Since March, new capabilities within Microsoft Entra ID for corporate accounts have become Generally Available. These are passkey profiles assigned to user groups. Instead of a single global setting, we can now configure allowed passkeys more granularly. The second new feature is support for synced passkeys, which are not tied to a single device.
FortiGate Migration to New Hardware and Configuration Conversion
This article describes my experience with replacing Fortinet FortiGate devices that are reaching end of support with new ones. Obviously, we want to transfer the current configuration as simply as possible and achieve minimal downtime during the switchover. We will use the FortiConverter service for configuration migration. The situation is somewhat more complex because the solution is built as a High Availability FGCP cluster with two nodes. Less significant is the use of VDOMs. FortiGate is currently running on FortiOS 7.4.11. The final device switchover went (after prior preparation) very well with only a five-minute outage.
Most viewed acrticles
TCP/IP - addresses, masks, subnets and calculations
The seventh part of the series on computer networks is more interesting and provides practical information. At the beginning there is a description of the basic terms for networks and subnets, IP addresses and masks. Next, the various network classes and how to write subnets are discussed. The second part deals with practical calculations of network ranges, network masks, number of hosts and subnets.
Windows commands for command line
My plan was to write down various useful commands for Windows in one place, along with a very brief description and example of common usage. I got some basics together but wanted to expand and fix it, but months go by and nothing, so I'm posting it in a not-so-finished state. Here you will find commands for use within the domain, but also for local matters. These are mostly commands used from the command line that are included with Windows. However, some are from Support Tools or Windows Resource Kits. I welcome your comments and additions in the comments.
VLAN - Virtual Local Area Network
The eighth part of the series on computer networks. VLAN, or Virtual Local Area Network, is a common technology these days that brings a number of advantages. I think that all medium-sized and larger companies use VLAN technology, and it can be interesting for small companies as well. VLANs are used to logically divide the network without being tied to physical division. In the article, I try to describe everything necessary to understand what VLAN is, what are the advantages and methods of deployment.
TCP/IP - Routing
In the eleventh part of the series on computer networks, I deal with routing, i.e. routing in networks. There is a brief description, explanation of terms, and then some more common routing methods (RIP, IGRP, EIGRP and OSPF) are described very briefly, including the division of these methods. For the methods, there is a sample of the basic configuration on Cisco. The article is far from exhaustive and the description is often to the point. Finally, rooting on Windows is mentioned.
Azure AD / Entra ID identity and authentication
Articles related to user and device identity (not only) in Microsoft Entra ID. Different login and authentication options. Areas such as modern authentication, multi-factor authentication, password-less login, etc. Often involving the use of FIDO Authentication, for example using the FIDO2 security key or Windows Hello for Business.
(articles in the series: 18)
Basics of computer networks
I wrote this series for Connect magazine. It contains most of the same information as my older series Computer networks, but it is written in a slightly different way. Computer network technologies are first briefly summarized and then discussed in a little more detail from the lowest layers up.
(articles in the series: 4)
Cisco IOS
A large series about the operating system of Cisco's active elements. It contains some of the most read articles on this site. The articles describe the configuration of switches and routers, primarily with Cisco IOS. Things about ports, VLANs, STP, ACLs, QoS, etc.
(articles in the series: 45)
Computer networks
This series covers the basics of computer networking. Important practical aspects that everyone interested in networking should know are briefly described. It contains some of the most widely read articles on this site. It is used for teaching in schools.
(articles in the series: 26)
Computer Storage
Data storage is a vast and complex issue in the computer world. Here you will find articles dedicated to Storage Area Networks (SAN), iSCSI technologies, Fiber Channel, disk arrays (Storage System, Disk Srray) and data storage and storage in general.
(articles in the series: 22)
Fortinet FortiGate and more
Fortinet security solutions. Mostly focused on the Next Generation Firewall (NGFW) FortiGate. Configuration of FW, policies, NAT, but also VPN and authentication options. Marginally working with logs using FortiAnalyzer and with clients using FortiClient EMS.
(articles in the series: 28)
Kerberos protocol with focus on SSO in AD DS
A new series that deals in detail with the Kerberos V5 protocol, mainly in the Microsoft Active Directory environment. It also describes a number of related things that are needed to understand how Kerberos Single Sign-On (SSO) works.
(articles in the series: 14)
Microsoft Exchange
Almost since the beginning of my practice, I have been involved in the administration of the Microsoft mail server, i.e. Exchange Server. I started with the 2003 version and worked my way up to Exchange Online. The articles cover many areas of management. Most since the migration to Exchange Server 2016 and its complete configuration. But also Exchange Hybrid and e-mail security.
(articles in the series: 47)
Veeam Backup & Replication
Articles that focus on Veeam Software's backup solution. It is a platform for Backup, Replication and Restore. In other words, a Data Protection and Disaster Recovery solution.
(articles in the series: 41)
Most recent comments
Im doing this exact conversion right now, but with some extras like ipsec/sslvpn currently, great guide, thanks!
In year 2026 there is an useful documentation about the details you can see in debug log: docs.fortinet.com/document/fortigate/7.4.4/administration-guide/32970/configuring-os-and-host-check
[8]
V Users Attirbutes and Claims nastavte na položce s hodnotou user.groups místo "All groups" "Groups assigned to the application". Pak se nebudou přenášet všechny skupiny uživatele (ve vašem případě více než limit 150), ale jen jedna přiřazená této aplikaci.
Pro atribut Tunnel-Private-Group-ID dlouhodobě používám radši směrování na vlan group, řeší to spoustu věcí:
- jedna policy pro lokality kde mám v každé lokalitě pro stejnou síť jiný vlan ID
- jedna policy pro lokality kde mám v každé lokalitě pro stejnou síť jinak vlany pojmenovaný (zpravidla většinou i kvuli IPAMu ty vlany jsou ve jmeny konvecni countrycode-town-environment-usage "CZ-HK-IT-USR = Česko , Hradec Králové, Business prostředí, uzivatelska lan)
Na Catalystu to pak jednoduše:
vlan group INFRA vlan-list 858
vlan group USERS vlan-list 856
vlan group PRINTERS vlan-list 853
vlan group TEAMS-ROOMS vlan-list 887
A dokonce mám pocit, že to ve spojení se snoopingem pak umí provozovat víc vlan per list v případě že budu mít barák kde sedí 3000 lidí tak tam nebudu dělat XxC velkej subnet, ale rozhazim to na C/2xC per vlan
I deploy whfb hybrid cloud trust and certificate for edp as described by microsoft. Connection to rdp fails with error code :0x8007013d.Any idea?
Dear Petr,
thank You for Your great web and sharing Your experiences! :-)
Please, when we would need on some service account/s use IMAPS running against only Exchange on prem. not using HMA, which is not supported, I understand, we can use for some accounts some policy with -BlockModernAuthImap.
But when we will enable HMA globaly, will some service's account using IMAPS with applied our custom policy still work, will not go for MFA to cloud (after enabling HMA), but will continue to work directly to IMAPS service running on Exchange on prem.?
Do You use some IMAPS connection to Exchange on prem. with custom policy and is it working while other accounts use HMA to cloud?
Eventually thank you.
My sincere congratulations on the article — it is very detailed and clears up many doubts before taking the (delicate) step toward HMA. Thank you very much!