Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
arnbiguous
Feb 2, 2014
Gary’s Answer
Our sonicwall died a few days ago and it was way out of warranty with no support agreement, so I had to replace it with a bunch of little RV042Gs I had lying around. Today the ticket I'm dealing with is that not being able to print from wireless is Unacceptable (right now they're not configured properly with RIP and an edge router because I just didn't have enough time to learn how to do that while everything in the office was down, so there's no real proper communication between subnets except some stuff I fudged with port forwarding).

So, I'm looking for something to replace our old sonicwall that can handle multiple subnets, internal and external firewall rules, DMZ, etc. Are the newer sonicwalls worth the price? Their recommended replacement for a 4100 pro is this http://www.sonicwall.com/us/en/products/NSA-E8500.html but that seems like overkill even to me, and finance would absolutely never approve it. Is there a new favorite firewall/router manufacturer I should look at?

Bonus: I found out today that my boss (who technically works for a different company in the same building) put in notice last week, so now there's nobody with high-level network planning/provisioning experience in the office at all! Hooray for learning things because you have to or everything will blow up

arnbiguous fucked around with this message at 21:36 on Oct 7, 2014

Adbot
ADBOT LOVES YOU

m.hache
Dec 1, 2004


Fun Shoe

Siochain posted:

I love that where I work, that's not our rule. The problem is that everyone else thinks it is, so people are always calling us liars. Really frustrating when one and only one client is having issues, and they won't let us troubleshoot, because "I just know its on your end, fix it!". And then you find out they can't get online at all. We're a web-based service. Gee, I wonder why it may not work.

Well, I sorta meant that was the rule for all Router providers. I actually gave a poo poo when working for the ISP. It was easier to fix the problem then have them bounce back into the queue an hour later.


tehloki posted:

Our sonicwall died a few days ago and it was way out of warranty with no support agreement, so I had to replace it with a bunch of little RV042Gs I had lying around. Today the ticket I'm dealing with is that not being able to print from wireless is Unacceptable (right now they're not configured properly with RIP and an edge router because I just didn't have enough time to learn how to do that while everything in the office was down, so there's no real proper communication between subnets except some stuff I fudged with port forwarding).

So, I'm looking for something to replace our old sonicwall that can handle multiple subnets, internal and external firewall rules, DMZ, etc. Are the newer sonicwalls worth the price? Their recommended replacement for a 4100 pro is this http://www.sonicwall.com/us/en/products/NSA-E8500.html but that seems like overkill even to me, and finance would absolutely never approve it. Is there a new favorite firewall/router manufacturer I should look at?

How big of a network are you needing to manage? I have a tiny network here and stuck with the sonicwalls. Meraki devices are pretty good as well from what I saw.

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


m.hache posted:

Well, I sorta meant that was the rule for all Router providers. I actually gave a poo poo when working for the ISP. It was easier to fix the problem then have them bounce back into the queue an hour later.

Nah, it applies to a lot of ISPs, VoIP providers, and anyone else online. Had a lady today insistent our site was slow and causing her problems. As she also can't connect to her VoIP service (not with us). But Google works, so its not an ISP issue. Tried to remote in? Couldn't. But, still us :) Sorry, bad day, must rant.

arnbiguous
Feb 2, 2014
Gary’s Answer

m.hache posted:

How big of a network are you needing to manage? I have a tiny network here and stuck with the sonicwalls. Meraki devices are pretty good as well from what I saw.

Up to 100 wired devices on 4 subnets (it varies throughout the year), up to 200 wireless devices (already have unifi APs for this and they're working fine, just, the little RV042G craps out every day or two and fails to assign DHCP leases), 6 servers that require a public IP and external access rules

m.hache
Dec 1, 2004


Fun Shoe

tehloki posted:

Up to 100 wired devices on 4 subnets (it varies throughout the year), up to 200 wireless devices (already have unifi APs for this and they're working fine, just, the little RV042G craps out every day or two and fails to assign DHCP leases), 6 servers that require a public IP and external access rules

Check out Cisco Meraki. They have a pretty solid offering and I've heard good things about them. Not too sure price wise though. Might be a little more than you're willing to spend.

arnbiguous
Feb 2, 2014
Gary’s Answer
I'm really going to miss my boss because he was the one who could say something like "we need to spend $x or you will not have this [stability/feature/security policy] you want" and management would actually listen to him, after ignoring me

chin up everything sucks
Jan 29, 2012

Siochain posted:

Nah, it applies to a lot of ISPs, VoIP providers, and anyone else online. Had a lady today insistent our site was slow and causing her problems. As she also can't connect to her VoIP service (not with us). But Google works, so its not an ISP issue. Tried to remote in? Couldn't. But, still us :) Sorry, bad day, must rant.

3 years doing tech support for an ISP, and I can see why everyone tries to dodge fault... call times. It takes less time to tell somebody to call someone else than to properly troubleshoot, which lowers you call time average. However, when EVERYONE does this, average call times drop around the board, so everyone gets told to stay under the average again, so you push back sooner and... eventually you have 0 time to do proper troubleshooting, and are just passing the buck around until the customer is so pissed that somebody HAS to troubleshoot with the screaming person.

I just love the circular logic that runs businesses.

Daylen Drazzi
Mar 10, 2007

Why do I root for Notre Dame? Because I like pain, and disappointment, and anguish. Notre Dame Football has destroyed more dreams than the Irish Potato Famine, and that is the kind of suffering I can get behind.
We've been passing around a Remedy ticket for the last couple days for everyone to chuckle about - apparently a MSgt put in a request to have Minecraft installed on SIPRnet. We're not sure how the ticket got routed to us since we only handle Exchange and Instant Messaging. Something tells me, however, that there is going to be an interesting meeting between a MSgt and their commanding officer sometime soon.

sfwarlock
Aug 11, 2007

guppy posted:

The company is splitting into two. One for computers and printers and the like, one for "business technology" (whatever that means) and services. And yes, 55,000+ employees laid off, which is more people than Google employs. Ars Technica article here: http://arstechnica.com/business/2014/10/hp-confirms-breakup-layoffs-hit-an-entire-googles-worth-of-employees/

Heh. HP Ink.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof


god damnit malwarebytes.

arnbiguous
Feb 2, 2014
Gary’s Answer
Well, that's the first time I've seen windows say that.

What were you trying to clean, so I can avoid that terrible mess? I've been using malwarebytes a lot since I finally accepted MSE does absolutely nothing

Malek
Jun 22, 2003

Shut up Girl!
And as always: Kill Hitler.

GnarlyCharlie4u posted:



god damnit malwarebytes.

I haven't seen Malware Bytes change a permission (or quarantine the entire Program Files (x86) folder.) What points to them?

arnbiguous
Feb 2, 2014
Gary’s Answer
Maybe he was saying like "god drat, malware just bites"

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

Malek posted:

I haven't seen Malware Bytes change a permission (or quarantine the entire Program Files (x86) folder.) What points to them?

I suppose it could just be a harddrive failure but... I clicked on the program folder to open malwarebytes, ran a scan, quarantined a couple of things, went to rescan and got that.

Renegret
May 26, 2007

THANK YOU FOR CALLING HELP DOG, INC.

YOUR POSITION IN THE QUEUE IS *pbbbbbbbbbbbbbbbbt*


Cat Army Sworn Enemy

Kurieg posted:

Did belkin basically DDOS their heartbeat server by having all their routers try and refresh at once, or is it something even stupider than that?

eh, I think it was more like some sort of internal network problem that took down their heartbeat server, or at least caused connections to drop, and for whatever reason this broke DNS. I didn't pay 100% attention to it because it wasn't my outage and I had better things to do.

Malkar
Aug 19, 2010

Taste the cloud
http://krebsonsecurity.com/2014/10/huge-data-leak-at-largest-u-s-bond-insurer/

^ Bet that generated a few tickets.

dennyk
Jan 2, 2005

Cheese-Buyer's Remorse

Renegret posted:

What follows are steps on how to change your DNS settings to Google DNS.

Is there anyone left who hasn't done this already (or who somehow has found an ISP whose DNS servers don't regularly poo poo the bed anyway)?

The Electronaut
May 10, 2009

Daylen Drazzi posted:

We've been passing around a Remedy ticket for the last couple days for everyone to chuckle about - apparently a MSgt put in a request to have Minecraft installed on SIPRnet. We're not sure how the ticket got routed to us since we only handle Exchange and Instant Messaging. Something tells me, however, that there is going to be an interesting meeting between a MSgt and their commanding officer sometime soon.

Found "Big Booty Bitches" on a SFC's SIPR side lappy in Iraq. Also, on that same day a 1LT got picked for having a map with grid cords with bases, etc. listed on his personal laptop.

Good times.

Pudgygiant
Apr 8, 2004

Garnet and black? More like gold and blue or whatever the fuck colors these are

Collateral Damage posted:

I hate docking stations with the burning passion of a thousand suns. I swear we have more docking station related issues than any other.

"The computer doesn't switch the display to my big screens when I dock it."
"The computer forgot my screen settings after I undocked and docked it."
"I docked the computer but when I close the lid it goes into sleep mode."
"Computer is stuck in the dock"
"Computer doesn't go into the dock"
"Network doesn't work after I docked the computer"
"Wireless doesn't turn on after I undocked the computer"
"Computer wouldn't fit in the docking station so I pushed a bit harder and now it's broken" (No you can't put an HP laptop in a Dell dock. :cripes:)


gently caress docking stations.

I know this is from a page ago but I have a good one. We had an issue where certain models of Dells with certain models of docks wouldn't pull DHCP only on certain switch ports. They'd work fine everywhere else, anything else would work fine on those ports. It was a relatively basic setup and I didn't see anything VLAN or port-security related that could have caused it. The only straw I could even grasp at was some sort of line or voltage issue that those docks were intolerant of? But really, who the gently caress knows. The workaround was "don't issue these docks to these floors" and everybody was happy with it.

e

The Electronaut posted:

Found "Big Booty Bitches" on a SFC's SIPR side lappy in Iraq. Also, on that same day a 1LT got picked for having a map with grid cords with bases, etc. listed on his personal laptop.

Good times.
And this. Christ there was so much porn on SIPR in Afghanistan. For a while there was a porn share on the same SIPR SAN as legit secure poo poo like grid coords, AO freqs, and crypto keys. It's always the really senior guys too, I never caught a SPC with anything iffy but every loving major or SGM had them right on their desktop.

Every cross-domain violation (basically plugging a secure device into an unsecure network or vice versa) was a senior person too, with the exception of retarded joes that try to charge their iPhone off the SIPR USB port. We had to take down an entire medevac comms site until an audit took place because the dumbass CPT surgeon plugged his SIPR external drive with a giant fuckoff DO NOT PLUG THIS INTO ANY COMPUTER OTHER THAN SIPR label on it into his personal laptop, then NIPR, then SIPR.

Pudgygiant fucked around with this message at 06:48 on Oct 8, 2014

less than three
Aug 9, 2007



Fallen Rib

Pudgygiant posted:

NIPR, then SIPR.

These stories sound great, but what is SIPR and NIPR for non-Amerigoons?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Non-classified and Secret computer networks.

Ahdinko
Oct 27, 2007

WHAT A LOVELY DAY

dogstile posted:

I would always assume it was someone with access who just, you know, did it. For their own use.

The thing is, IT have their own policy, IT are the only people who can manage the proxy (so I know one of 7 people made the change), and no IT staff are in the Directors policy, and infact the IT policy lets you get to absolutely anything anyway so we could browse as much porn as we liked.

So it means that someone actually requested this, and someone actually actioned it. The directors policy consists of the CEO and less than a dozen very senior management staff

Exit Strategy
Dec 10, 2010

by sebmojo

less than three posted:

These stories sound great, but what is SIPR and NIPR for non-Amerigoons?

Secure
Internet
Protocol
Routing

Nonclassified
Internet
Protocol
Routing

Lord Dudeguy
Sep 17, 2006
[Insert good English here]

tehloki posted:

So, I'm looking for something to replace our old sonicwall that can handle multiple subnets, internal and external firewall rules, DMZ, etc. Are the newer sonicwalls worth the price? Their recommended replacement for a 4100 pro is this http://www.sonicwall.com/us/en/products/NSA-E8500.html but that seems like overkill even to me, and finance would absolutely never approve it. Is there a new favorite firewall/router manufacturer I should look at?

For 200 wireless devices and 100 wired, plus WAN? Overkill. SonicOS devices are, features-wise, identical as long as you pay the licensing costs. It's all about capacity.

A TZ215 at minimum, maybe a NSA 220?

How much throughput are we talking, here? Connections/Sec and Mbit/sec?

Renegret
May 26, 2007

THANK YOU FOR CALLING HELP DOG, INC.

YOUR POSITION IN THE QUEUE IS *pbbbbbbbbbbbbbbbbt*


Cat Army Sworn Enemy

dennyk posted:

Is there anyone left who hasn't done this already (or who somehow has found an ISP whose DNS servers don't regularly poo poo the bed anyway)?

Your average user. So basically anybody dumb enough to buy a Belkin router in the first place.

Kurieg
Jul 19, 2012

RIP Lutri: 5/19/20-4/2/20
:blizz::gamefreak:

less than three posted:

These stories sound great, but what is SIPR and NIPR for non-Amerigoons?

According to wikipedia, NIPR is for semi-secure but not classified documents and communications. SIPR is for classified stuff.

So he took a classified hard drive, hooked it up to the internet, then to the secure domain, then to the classified domain.

Ahdinko
Oct 27, 2007

WHAT A LOVELY DAY

Kurieg posted:

So he took a classified hard drive, hooked it up to the internet, then to the secure domain, then to the classified domain.

But surely a hard drive carrying that kind of data is locked down tighter than a ducks arse anyway, so data couldn't have been written/read outside of the fancy secure network?

Caconym
Feb 12, 2013

Ahdinko posted:

But surely a hard drive carrying that kind of data is locked down tighter than a ducks arse anyway, so data couldn't have been written/read outside of the fancy secure network?

:allears:

Domnu
Jan 14, 2006

Ahdinko posted:

But surely a hard drive carrying that kind of data is locked down tighter than a ducks arse anyway, so data couldn't have been written/read outside of the fancy secure network?

How dare you apply logic and sense to this situation!

Irritated Goat
Mar 12, 2005

This post is pathetic.
A call came in...

I don't even remember what the original issue was. I ask her for a contact number. She responds that she could give me her cel number but she doesn't have the phone on her. :negative: The phones she calls from have numbers on them. There are people around who she can ask for the extension to the department she's in.

I field calls all day from people who work in a place and have no idea what number people can call them at.

dogstile
May 1, 2012

fucking clocks
how do they work?

Ahdinko posted:

The thing is, IT have their own policy, IT are the only people who can manage the proxy (so I know one of 7 people made the change), and no IT staff are in the Directors policy, and infact the IT policy lets you get to absolutely anything anyway so we could browse as much porn as we liked.

So it means that someone actually requested this, and someone actually actioned it. The directors policy consists of the CEO and less than a dozen very senior management staff

Oh, ok.

:yikes:

Bloodborne
Sep 24, 2008

Is your IT just those 7 people? Having IT able to get out to any site whatsoever is likely more dangerous than Facebook Sue up on 9.

Sirotan
Oct 17, 2006

Sirotan is a seal.


An update came in, to my KACE box. From the list of resolved issues:



It only took them 4 months after I submited bug reports for both these items but I CAN FINALLY USE APOSTROPHES IN TICKET WORK FIELDS woooooooooooooooooooooooooooooooooo

:circlefap:

Irritated Goat
Mar 12, 2005

This post is pathetic.

Sirotan posted:

An update came in, to my KACE box. From the list of resolved issues:



It only took them 4 months after I submited bug reports for both these items but I CAN FINALLY USE APOSTROPHES IN TICKET WORK FIELDS woooooooooooooooooooooooooooooooooo

:circlefap:

I'm sure that broke something else horribly. :(

BOOTY-ADE
Aug 30, 2006

BIG KOOL TELLIN' Y'ALL TO KEEP IT TIGHT

Inspector_666 posted:

Dude, Linksys has been dead for a while now. The Belkin versions look and feel like 2nd rate DealExtreme knockoffs.

I know that, just making a point that it's not just strictly Belkin branded stuff that's affected now, in case anyone still uses (or recently bought) Linksys products. My dad got a new Linksys wireless router earlier this summer to replace his old Linksys gateway that was probably like 7-8 years old, and the new one performs WORSE than the old gateway did - random connection drops, constantly having to powercycle it, slow speeds, you name it. Even a firmware update didn't fix it, it's just a huge pile of poo poo and I wish Cisco would've either held on to the Linksys brand, or sold it to another company that knew what the hell they were doing.

Sirotan
Oct 17, 2006

Sirotan is a seal.


Irritated Goat posted:

I'm sure that broke something else horribly. :(

Yeah actually the list of resolved issues is 2 pages long, and the list of known issues is 4....................

I'm installing the update right now, can't wait to see what will go wrong this time!!

peak debt
Mar 11, 2001
b& :(
Nap Ghost

Sirotan posted:

An update came in, to my KACE box. From the list of resolved issues:



It only took them 4 months after I submited bug reports for both these items but I CAN FINALLY USE APOSTROPHES IN TICKET WORK FIELDS woooooooooooooooooooooooooooooooooo

:circlefap:

Someone clearly needs to teach them about magic quotes.

Ahdinko
Oct 27, 2007

WHAT A LOVELY DAY

internet jerk posted:

Is your IT just those 7 people? Having IT able to get out to any site whatsoever is likely more dangerous than Facebook Sue up on 9.

Yeah 7 onsite and certain stuff is escalated to a third party, but it always pisses me off that every other time I'm trying to google a network issue/download something/whatever, then being blocked because of "Computers" or "Malware" or "hacking site", so I'm all for having open internet in IT
Plus SA is classed as "Questionable" or "Cult/Occult" or something really stupid like that.

Ahdinko fucked around with this message at 15:56 on Oct 8, 2014

chin up everything sucks
Jan 29, 2012

Ahdinko posted:

Plus SA is classed as "Questionable" or "Cult/Occult" or something really stupid like that.

Sounds about right. We worship Slenderman.

Adbot
ADBOT LOVES YOU

BigPaddy
Jun 30, 2008

That night we performed the rite and opened the gate.
Halfway through, I went to fix us both a coke float.
By the time I got back, he'd gone insane.
Plus, he'd left the gate open and there was evil everywhere.


tehloki posted:

Our sonicwall died a few days ago and it was way out of warranty with no support agreement, so I had to replace it with a bunch of little RV042Gs I had lying around. Today the ticket I'm dealing with is that not being able to print from wireless is Unacceptable (right now they're not configured properly with RIP and an edge router because I just didn't have enough time to learn how to do that while everything in the office was down, so there's no real proper communication between subnets except some stuff I fudged with port forwarding).

So, I'm looking for something to replace our old sonicwall that can handle multiple subnets, internal and external firewall rules, DMZ, etc. Are the newer sonicwalls worth the price? Their recommended replacement for a 4100 pro is this http://www.sonicwall.com/us/en/products/NSA-E8500.html but that seems like overkill even to me, and finance would absolutely never approve it. Is there a new favorite firewall/router manufacturer I should look at?

Bonus: I found out today that my boss (who technically works for a different company in the same building) put in notice last week, so now there's nobody with high-level network planning/provisioning experience in the office at all! Hooray for learning things because you have to or everything will blow up

You could take a look at http://www.sophos.com/en-us/products/unified-threat-management.aspx since Sonicwall is someone they want to take a swing at you might be able to get a good price as a current sonicwall customer.

  • Locked thread