跳到主要內容

發表文章

Edgd / Chrome Windows 整合式驗證 (WIA)

Ref:  Security Zones in Edge Ref:  使用者登入 Microsoft Edge 的方式 Ref:  Per-site configuration by policy Ref:  如何透過群組原則(GPO)將內部網站加入 近端內部網路 清單 Windows 整合式驗證 (WIA) Microsoft Edge 也支援在組織內部網路中針對使用瀏覽器進行其驗證的任何應用程式,進行驗證要求的 Windows 整合驗證。 所有版本的 Windows 10 和舊版 Windows 都支援這項功能。 根據 預設 ,Microsoft Edge 會使用 內部網路區域 作為 WIA 的 允許清單 。 透過群組原則(GPO),將 URL 加入 「區域清單」 內部網路區域(1) /  信任的網站區域(2) / 網際網路區域(3) / 受限制的網站區域(4) Ref:  Site to Zone Assignment List(指派網站到區域清單) 〔使用者設定〕→〔系統管理範本〕→〔Windows 元件〕→〔Internet Explorer〕→〔網際網路控制台〕→〔安全性畫面〕→〔指派網站到區域清單〕(Site to Zone Assignment List)

Windows 聲音輸出到多個裝置 (利用Virtual Audio Cable)

Windows 無法將聲音同時輸出到多個裝置,想要達到這個目錄,可以使用Virtual Audio Cable (VAC),請到 VAC 的官網去下載 https://vac.muzychenko.net/en/。 下載安裝後,會多了一個 『Line 1 (Virtual Audio Cable)』音訊裝置,並預設為預設撥放裝置,如下圖:。 再來開啟 『Audio Repeater』,Wave In 選擇 「Line 1」,Wave In 選擇你要輸出的裝置1。 之後要輸出的裝置,重複上個步驟(也就是想同時輸出幾個裝置,就開執行幾個『Audio Repeater』。

Fortigate IPS, DNS/WEB Filter, Domain & IP Reputation

 Fortigate 啟用 Fortigate IPS, DNS/WEB Filter, Domain & IP Reputation 相關功能 在 Fortigate 要使用一些功能,必須先到[Feature Visibility] 中啟用該功能。 DNS Filter Apply DNS category filtering, URL filtering to control user's access to web resources. Set up DNS Filter Profiles (Security Profiles > DNS Filter) and add them to Firewall Policies or add them to a DNS Server on a FortiGate interface. Some features require a subscription to FortiGuard Web Filtering. Web Filter Apply web category filtering, URL filtering, and content filtering to control user's access to web resources. Set up Web Filter Profiles (Security Profiles > Web Filter) and add them to Firewall Policies. Some features require a subscription to FortiGuard Web Filtering. 前兩項 ,個人認為比較偏向 Client (Outgoing),避免去到惡意的網站或網址 Domain & IP Reputation Enable the Reputation Lookup feature. This page allows querying of reputations for IPs or FQDNs as classified in FortiGuard databases. Databases require a valid FortiGuard subscription. Int...

External Block List (Threat Feed)

如何建立外部的 IP 封鎖清單 # Explame Paltfrom: Fortigate 20xE / 6.2.11 Ref: Fortigate Threat feeds(6.2.x) Ref: External Block List (Threat Feed) – Policy(6.2.0)   Ref: All Cybercrime IP Feeds by FireHOL [Security Fabric] → [Fabric Connectors]  → [Create New] → [IP Address] 以 [https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset] 為 List 來源 在 Policy 引用 (記得 Block Deny Policy 要在前面) 建議搭配 [Intrusion Prevention]及其Block [Botnet C&C]、DNS Filter、Web Filter

VNC Listening Viewer

TightVnc 下載網址: https://www.tightvnc.com/download.php 安裝 TightVnc: 以 Listening Mode 將畫面丟給協助者:

禁止 Windows Search 對 Outlook 編製索引(使用 outlook 內建索引)

 Ref:  Prevent indexing Microsoft Office Outlook [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search] 新增 "PreventIndexingOutlook" (REG_DWORD) =1 即可禁止 Windows Search 對 Outlook 編製索引,進而使 outlook 使用內建的方式搜尋。 因為沒有索引,所以搜尋速度會很慢,但不怕出問題。

Prefer IPv4 over IPv6

Ref:    Guidance for configuring IPv6 in Windows for advanced users Article 03/24/2022 5 minutes to read 7 contributors Windows Vista, Windows Server 2008, and later versions of Windows implement RFC 3484 and use a prefix table to determine which address to use when multiple addresses are available for a Domain Name System (DNS) name. By default, Windows favors IPv6 global unicast addresses over IPv4 addresses. Applies to:    Windows 10 - all editions, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2 Original KB number:    929852 Summary It is common for IT administrators to disable IPv6 to troubleshoot networking-related issues such as name resolution issues.  Important Internet Protocol version 6 (IPv6) is a mandatory part of Windows Vista and Windows Server 2008 and newer versions. We do not recommend that you disable IPv6 or its components. If you do, some Windows components may not function. We recommend using  Prefer IPv4 ove...