Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
psydude
Apr 1, 2008

Wrath of the Bitch King posted:

Reading these last couple pages about crazy network setups where 802.1x and NPS aren't being leveraged makes me really sad.

Don't get me wrong, 802.1x is a huge pain in the rear end, especially if you do PXE deployments, but that's why you have an NPS configuration that drops failed authentications to an incredibly limited VLAN. poo poo has changed.

ISE lets you permit PXE and DHCP traffic before the 802.1X handshake so you don't even need to do that.

Adbot
ADBOT LOVES YOU

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
I just had to walk senior admin through installing the group policy management module. He's never once looked at the policies, didn't know the module existed, and couldn't figure out how to get it :cripes:

Collateral Damage
Jun 13, 2009

Re: 802.1X it's not a perfect solution. Someone who knows what they're doing and has physical access to an authenticated computer can circumvent it with relative ease.

But usually you're not looking to keep Mr Professional Blackhat out, you're mainly looking to keep Salesperson J. Bumblefuck from plugging in a rogue access point.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

Collateral Damage posted:

But usually you're not looking to keep Mr Professional Blackhat out, you're mainly looking to keep Salesperson J. Bumblefuck from plugging in a rogue access point.

This is exactly right; it's especially easy to get around if you have IP phones that you use with network passthrough. The goal is to catch the low-hanging fruit.

psydude posted:

ISE lets you permit PXE and DHCP traffic before the 802.1X handshake so you don't even need to do that.

I'll have to do a little research, but that sounds cool. I'm on the Systems side, not Networking, but our Network guys are pretty notorious for being dreadfully behind the times with everything. We've had to drag them into the modern age kicking and screaming (switching from MAC Sticky to 802.1x only happened about two years ago, for perspective). The business has had to buffer their lack of skillset with professional services an embarrassing number of times, I'm not really sure what the deal is.

KillHour
Oct 28, 2007


Collateral Damage posted:

But usually you're not looking to keep Mr Professional Blackhat out, you're mainly looking to keep Salesperson J. Bumblefuck from plugging in a rogue access point.

What do I do if I'm trying to keep out Feculent Q. Pus-Crust of the Society for Cornholing Unsuspecting Children?

CLAM DOWN
Feb 13, 2007




KillHour posted:

What do I do if I'm trying to keep out Feculent Q. Pus-Crust of the Society for Cornholing Unsuspecting Children?

uhhhhhhhhhhhhhhhhhhhhhhhhhh

George H.W. Cunt
Oct 6, 2010





God all these stories of incompetent senior level systems admins makes me really want to jump into management and ride the Peter principle as far as it will take me

Inspector_666
Oct 7, 2003

benny with the good hair

SaltLick posted:

God all these stories of incompetent senior level systems admins makes me really want to jump into management and ride the Peter principle as far as it will take me

It makes me really mad because they're doing (poorly/wrongly) the poo poo that I want to be doing and yet here I am still with Helpdesk Associate in my title and having just gotten "Answer the door for deliveries" added to my loving job responsibilities.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

Judge Schnoopy posted:

I just had to walk senior admin through installing the group policy management module. He's never once looked at the policies, didn't know the module existed, and couldn't figure out how to get it :cripes:

I refuse to believe this.
How did he, ya know, MANAGE GPOs before?

Sickening
Jul 16, 2007

Black summer was the best summer.

GnarlyCharlie4u posted:

I refuse to believe this.
How did he, ya know, MANAGE GPOs before?

On the domain controller through remote desktop.

MC Fruit Stripe
Nov 26, 2002

around and around we go

SaltLick posted:

God all these stories of incompetent senior level systems admins makes me really want to jump into management and ride the Peter principle as far as it will take me
My director only hires senior sys admins. Regardless of their skillset or experience, everyone he hires gets a senior title.

Nothing like getting 7 primadonnas in a room, none of who think that patching servers is their responsibility because that's not what a senior does. Ugh, you're 27, shut up and go patch.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

Sickening posted:

On the domain controller through remote desktop.

I'm still guilty of this from time to time and I'm very ashamed of it.

It's mostly because I'm too lazy to run the tools as my secondary, more elevated domain account.

H110Hawk
Dec 28, 2006

MC Fruit Stripe posted:

My director only hires senior sys admins. Regardless of their skillset or experience, everyone he hires gets a senior title.

Nothing like getting 7 primadonnas in a room, none of who think that patching servers is their responsibility because that's not what a senior does. Ugh, you're 27it's your job, shut up and go patch.

KillHour
Oct 28, 2007


CLAM DOWN posted:

uhhhhhhhhhhhhhhhhhhhhhhhhhh

I may have been reading popehat while writing that.

Thanks Ants
May 21, 2004

#essereFerrari


Wrath of the Bitch King posted:

I'm still guilty of this from time to time and I'm very ashamed of it.

It's mostly because I'm too lazy to run the tools as my secondary, more elevated domain account.

It would be nice if there was a way to use those tools without needing to be on a domain-joined machine - e.g. if you do work for a bunch of clients. I guess a random VM at each site would do the trick but I feel like I'm missing something.

Sickening
Jul 16, 2007

Black summer was the best summer.

MC Fruit Stripe posted:

My director only hires senior sys admins. Regardless of their skillset or experience, everyone he hires gets a senior title.

Nothing like getting 7 primadonnas in a room, none of who think that patching servers is their responsibility because that's not what a senior does. Ugh, you're 27, shut up and go patch.

Just assign the task to two of them on a permanent basis and be done with it. Patching can be a pain in the rear end but its loving critical.

Roargasm
Oct 21, 2010

Hate to sound sleazy
But tease me
I don't want it if it's that easy

Sefal posted:

I need to :yotj:
Had the performance review. The evalution went really well. But when we were discussing a raise and a promotion. I got shutdown and told we will discuss that at your next performance review, which will be in june. This was only a inbetween performance review.

That has to be bullshit right?

Not necessarily. Some companies only adjust salary budgets once per year, so if your company's fiscal year is July-July that could be legit

crunk dork
Jan 15, 2006

SaltLick posted:

God all these stories of incompetent senior level systems admins makes me really want to jump into management and ride the Peter principle as far as it will take me
lol ride the Peter

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

GnarlyCharlie4u posted:

I refuse to believe this.
How did he, ya know, MANAGE GPOs before?

He didn't! GPOs fell under the it department managers duties before I helped take it off her plate. The senior admin literally never once looked at them before today and didn't know how.

When we were discussing mapped drives policies he asked if I was looking at AD.

Kashuno
Oct 9, 2012

Where the hell is my SWORD?
Grimey Drawer
this thread is giving me lots of pain today.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

Sickening posted:

Just assign the task to two of them on a permanent basis and be done with it. Patching can be a pain in the rear end but its loving critical.

People need to get on board with automated patch cycles, even for servers. I get that it's a huge pain in the rear end, but System Center has the tools to get it done between Config Manager and Orchestrator.

Push for that patching SOP based on service/category of server (Dev, Test, Prod), just keep in mind that getting there is going to be one hell of a fight. Not to mention all the conditional poo poo you'll have to plug into your Orchestrator runbook. I'm sure there are other platforms that do it just as well, but Orchestrator is my go-to for this sort of thing and most enterprises with an EA agreement get CM and Orch. for free.

CLAM DOWN
Feb 13, 2007




I involuntarily twitch when someone pronounces SQL as "S-Q-L" rather than "sequel". Anyone else itt?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Wrath of the Bitch King posted:

People need to get on board with automated patch cycles, even for servers. I get that it's a huge pain in the rear end, but System Center has the tools to get it done between Config Manager and Orchestrator.

Push for that patching SOP based on service/category of server (Dev, Test, Prod), just keep in mind that getting there is going to be one hell of a fight. Not to mention all the conditional poo poo you'll have to plug into your Orchestrator runbook. I'm sure there are other platforms that do it just as well, but Orchestrator is my go-to for this sort of thing and most enterprises with an EA agreement get CM and Orch. for free.

We are finally switching from WSUS to N-Able for patching since upgrading to N-Able 10 (9 patching was straight hosed on it), and I believe the plan is to automate patching all our DV/QA systems so that a week after patch tuesday, QA can do their QA thing and provided QA goes well we can update all of our PD systems with the click of a couple buttons. Hopefully this goes smoothly and we can somewhat automate our backend patching as well, because our current process is time consuming and awful.

Inspector_666
Oct 7, 2003

benny with the good hair

MF_James posted:

We are finally switching from WSUS to N-Able for patching since upgrading to N-Able 10 (9 patching was straight hosed on it), and I believe the plan is to automate patching all our DV/QA systems so that a week after patch tuesday, QA can do their QA thing and provided QA goes well we can update all of our PD systems with the click of a couple buttons. Hopefully this goes smoothly and we can somewhat automate our backend patching as well, because our current process is time consuming and awful.

We don't even use WSUS where I am right now and it loving kills me. Physically walking to every computer in our office and manually kicking off Windows Updates is not an acceptable course of action as far as I'm concerned.

CLAM DOWN posted:

I involuntarily twitch when someone pronounces SQL as "S-Q-L" rather than "sequel". Anyone else itt?

Does it make you want to...squeal? *put on sunglasses*

KillHour
Oct 28, 2007


CLAM DOWN posted:

I involuntarily twitch when someone pronounces SQL as "S-Q-L" rather than "sequel". Anyone else itt?

I'm happy when I can understand what people are talking about, TBH.

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

Go into consulting and never be responsible for patching or routine day to day stuff again.

psydude
Apr 1, 2008

NippleFloss posted:

Go into consulting and never be responsible for patching or routine day to day stuff again.

And discover just how un-patched and decrepit your customers' environments are!

BaseballPCHiker
Jan 16, 2006

It's stories like these that make me think to myself maybe I'm not as worthless of an sysadmin as I fear. There is always something you don't know about and then you study it and learn more and just learn that you know even less than you thought and so you keep learning and the cycle just repeats itself until you think you are the least knowledgeable guy around. But nope, real worthless mouth breathers are still out there making bank. All I have to do is keep my head down and keep learning.

MrMoo
Sep 14, 2000

CLAM DOWN posted:

I involuntarily twitch when someone pronounces SQL as "S-Q-L" rather than "sequel". Anyone else itt?

Do you trigger on the product names as it is supposed to be Microsoft Sequel server and My S-Q-L server?

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

psydude posted:

And discover just how un-patched and decrepit your customers' environments are!

Yes, but then it's not your problem so who cares! It's nice to be able to throw "hey, maybe patch your poo poo" in a project report and then walk away.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.
No one cares about patching for its own sake, and certainly not the security. They only care about compliance and what kind of fine an audit will impose if poo poo doesn't change very quickly.

Our Information Security guys get very salty when we call them the "Audit Checklist Committee."

CLAM DOWN
Feb 13, 2007




Wrath of the Bitch King posted:

No one cares about patching for its own sake, and certainly not the security. They only care about compliance and what kind of fine an audit will impose if poo poo doesn't change very quickly.

This is bullshit, patching and keeping software/applications/etc up to date is an incredibly basic component of system security.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

CLAM DOWN posted:

This is bullshit, patching and keeping software/applications/etc up to date is an incredibly basic component of system security.

Of course it's bullshit, I'm speaking from the perspective of the LOB. And our Information Security guys, who essentially spend all day playing Solitaire and running Nexpose reports. The latter only started to give a poo poo about server patching when they found out we would start getting fined for it if we don't address it. We've been pushing to get it in for years but it took the money angle (and questions from our CTO asking them why they only started asking about security patching recently) to actually give a drat.

Wrath of the Bitch King fucked around with this message at 21:21 on Feb 19, 2016

MC Fruit Stripe
Nov 26, 2002

around and around we go
We hired a security guy and instructed him that we need to make sure we're always up to date on patching. He installed a bunch of auditing software and started sending patch reports to the sys admins on a near daily basis with the director copied, pointing out what we need to patch next. I'm like, we hired you as the guy who handles security and patches, and you're delegating it to the sys admins, how'd you swing that? I want your job.

His job basically consists of running automated scans, and handling all user creation and modification so as to busy himself. Oh, new DBA needs access to something? Throw it to the security guy, might as well.

I want to start trying that approach as a sys admin. "For our new build out, we're going to need 2 fully populated UCS chassis and if we don't need new storage, we're certainly going to tap our existing. (Implication: I hope someone contacts a vendor, buys this, installs it, and configures it.)" - Maybe every week or so send out one of those "Team, where are we at on the new build out?" emails that gets under my skin so effectively.

MC Fruit Stripe fucked around with this message at 21:26 on Feb 19, 2016

psydude
Apr 1, 2008

Wrath of the Bitch King posted:

No one cares about patching for its own sake, and certainly not the security. They only care about compliance and what kind of fine an audit will impose if poo poo doesn't change very quickly.

Our Information Security guys get very salty when we call them the "Audit Checklist Committee."

Exactly. IT security governance exists only because lazy infrastructure personnel brought it upon themselves.

Sickening
Jul 16, 2007

Black summer was the best summer.

MC Fruit Stripe posted:

We hired a security guy and instructed him that we need to make sure we're always up to date on patching. He installed a bunch of auditing software and started sending patch reports to the sys admins on a near daily basis with the director copied, pointing out what we need to patch next. I'm like, we hired you as the guy who handles security and patches, and you're delegating it to the sys admins, how'd you swing that? I want your job.

His job basically consists of running automated scans, and handling all user creation and modification so as to busy himself. Oh, new DBA needs access to something? Throw it to the security guy, might as well.

I want to start trying that approach as a sys admin. "For our new build out, we're going to need 2 fully populated UCS chassis and if we don't need new storage, we're certainly going to tap our existing. (Implication: I hope someone contacts a vendor, buys this, installs it, and configures it.)" - Maybe every week or so send out one of those "Team, where are we at on the new build out?" emails that gets under my skin so effectively.

Thats a every day security job in a nutshell. They press the generate report button and..........


Wrath of the Bitch King posted:

No one cares about patching for its own sake, and certainly not the security. They only care about compliance and what kind of fine an audit will impose if poo poo doesn't change very quickly.

Our Information Security guys get very salty when we call them the "Audit Checklist Committee."

Plenty of people care and its definitely for the security. Outside of social engineering, compromised systems are mostly done though outdate/unpatched systems it seems like. I am not saying every system patch is equal, but regularly patching systems is just something you should be doing if systems are your responsibility. Not doing so is just lazy and putting your systems at un-needed risk.

Sickening fucked around with this message at 21:31 on Feb 19, 2016

psydude
Apr 1, 2008

Ah, to be a Thumb Drive Cop and complain about FreeBSD not being authorized to run on the network.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

MC Fruit Stripe posted:

We hired a security guy and instructed him that we need to make sure we're always up to date on patching. He installed a bunch of auditing software and started sending patch reports to the sys admins on a near daily basis with the director copied, pointing out what we need to patch next. I'm like, we hired you as the guy who handles security and patches, and you're delegating it to the sys admins, how'd you swing that? I want your job.

His job basically consists of running automated scans, and handling all user creation and modification so as to busy himself. Oh, new DBA needs access to something? Throw it to the security guy, might as well.

I want to start trying that approach as a sys admin. "For our new build out, we're going to need 2 fully populated UCS chassis and if we don't need new storage, we're certainly going to tap our existing. (Implication: I hope someone contacts a vendor, buys this, installs it, and configures it.)" - Maybe every week or so send out one of those "Team, where are we at on the new build out?" emails that gets under my skin so effectively.

Security is an "advisement" position, not a "take action" one.

Our Security group sends out reports from Nexpose and will act as an approval gateway for giving individual users access to typically banned/blocked websites. That's it. Whenever a security intrusion/infection is detected somewhere in the environment they open a ticket and tell our Deskside team to go handle it.

It's an incredibly cushy gig.

Also, to restate, we've been wanting to get a patch management solution in place for years, but it took the threat of audit/financial impact to actually make it a reality. As said, the Line of Business/Security groups don't actually give much of a poo poo about being hardened, they care about losing face and performing the absolute bare minimum that is required of them.

thebigcow
Jan 3, 2001

Bully!

MrMoo posted:

Do you trigger on the product names as it is supposed to be Microsoft Sequel server and My S-Q-L server?

Postgres-Q-L

Adbot
ADBOT LOVES YOU

orange sky
May 7, 2007

Hey guys, I need to absorb some of your knowledge.

I work for a consulting company that sells quite a big spectrum of IT solutions. Due to this wide range of possibilties it's really hard to keep the sales team up to speed on what they can and cannot sell. How do you guys transfer knowledge to your sales team regarding estimating prices, cross-selling, up-selling and about what you can and can not do? I think our sales team has Salesforce, is there a good add-on or something like that? I'm not really responsible for this area (and that's why I don't know much about it) but I think that's a great problem in my company and I want to help fix it.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply