Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

oh man I never saw this thread before, so here's an abridged version of a conversation I had with my favorite client.

:argh: While our systems are down we are losing 100k AN HOUR!!!! FIX IT
:toot: Well, your drobo storage took a poo poo because, well I dunno, it's a black box and you refused to buy a support contract, luckily we get a free 30-day trial so I am working with them.
:argh: I have lost 400K ALREADY TODAY BECAUSE WE HAVE BEEN DOWN FOR 2 HOURS!
:toot: We're working on it, but if you would like to not have this problem I do recommend upgrading your storage to something that is not a giant heap of poo poo
:argh: I'M SENDING EVERYONE HOME BECAUSE YOU CAN'T FIX IT
:toot: ok?

2 hours later

:toot: it is now fixed, no data lost, you'll be ready to go tomorrow, I've tested everything and all VMs are operating as expected (really lovely)
:angel: Thanks for all your help!
:toot: So because of all your lost revenue today, I do recommend buying a support contract or, more preferably, a device such as an HP SAN instead of a consumer level NAS
:angel: Nah too much money
:toot: but you supposedly lost half a million dollars today, a SAN will only cost you a fraction of that
:angel: have a nice day!


:derp::fuckoff:

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Bob Morales posted:

Hope you charged them a ton

Well I work at an MSP, so I don't charge poo poo, but I can tell you it's EXTREMELY likely that we make zero dollars on this client and, in fact, probably lose money with the amount of time the highest paid people (myself, our architect and a few other people) have to spend on them.

CommieGIR posted:

Been here, done that. Usually the other way around though. Usually I'm recommending the later part before the former happens, and then writing an "I-told-you-so" contract when I fix it for them.

Oh no, we told them multiple times that the thing was garbage and they should have a support contract at the very least or something is going to go wrong, but I definitely made a point of it during the outage to bring it up again.

MF_James fucked around with this message at 18:51 on Mar 15, 2018

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

We use nessus scans (one of our clients uses Qualys) and we use alienvault USM internally + at 2 clients.

I don't work with alienvault much that's our SOC team, it seems pretty decent. One thing that was annoying (but honestly expected) was that our one client cheaped out and wouldn't pay for the bigger USM with 2 NICs, well they have a fair amount of traffic and we needed SPAN from 2 switch stacks; we tried to install a NIC ourselves to give us 2 ports but it didn't work (again not surprising), so we're doing RSPAN to an edge switch from both stacks and then to the USM, I'm fairly certain we're missing some traffic because the port can't handle all the traffic, but it's hard to tell and there's more than enough there to keep our SOC guys informed and busy anyway.

Just something to be aware of if you want to go with alienvault, you really need to spec it out correctly from the start.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Secret server is kind of poo poo, we used it for a while and I did not like it; we use AuthAnvil now, also utilize them for 2FA for a few environments, it is generally decent, has decent reporting, the only issue is it can load a little slow, not sure if that's our environment or in general.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

SpaceCadetBob posted:

I'm trying to sort out brands and it is truely hellish.

I have no advice to give other than your mission is to find the least stinky piece of poo poo in the pile, good luck.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Gerdalti posted:

I'm struggling with a WDS/MDT deploy setup. I have everything configured, captures work great, domain join parameters with custom computer names, custom driver sets based on model, etc.

But. Now that I have the domain join setup properly, the deployment fails. The image is installed, and the computer reboots from Litetouch to Windows.
Windows has disabled the local admin account, which means the install script doesn't continue unless I boot into safe mode, enable local admin, reboot, and then manually continue it.

I read that this could be a gpo issue, so I created a new OU for the domain join script, disabled gp inherence, made sure the admin user is enabled via gp, etc. Same thing.


I just rejoined my image pc to ad, moved it to the blocked inherence OU, updated group policy, unjoined AD, and kicked off another capture. I'll test another deploy when it's done.

Any suggestions???

What version of windows are you installing? Are you setting the admin password? Is the password blank? I (think) sometimes windows doesn't like blank passwords and that might cause problems, if you're trying that.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Agrikk posted:

*cease and desist letter comes in: it is against the ToC to run services at the end of this connection*

Lol is this because you run a static webpage out of your garage or something?

100% surprised they didn't just block 443 inbound on your connection as soon as they sent that (if it is indeed for you)

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Do you use O365?

Microsoft is rolling this out if you have the license for it: https://docs.microsoft.com/en-us/office365/securitycompliance/attack-simulator

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

What would be the migration path to go from Server 2012 r2 essentials to server 2019 standard?

I've never loving dealt with essentials so this should be exciting...

This is about the closest I can find to something of an answer, but doesn't mention essentials -> standard: https://docs.microsoft.com/en-us/windows-server/get-started-19/install-upgrade-migrate-19

This says it applies to both 2016 and 2019 but it's mildly unclear and doesn't provide a path: https://docs.microsoft.com/en-us/windows-server/get-started/supported-upgrade-paths

I'm going to be installing 2019 on new hardware.

MF_James fucked around with this message at 02:52 on Mar 27, 2019

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

The Fool posted:

What components of essentials are you actually using? You would want to treat each component migration separately, with AD being migrated last.

Or just burn it all down and rebuild from scratch, that's my vote.

Yeah I'm really debating option 2.

As for what components, good question, I have no loving clue, I haven't even logged into this clients server yet; got a invoice in my email with client copied on it saying equipment is on the way to our office. Saw standard licensing and mentioned there's 2019 essentials but we're moving forward with standard anyway.

*edit*

I have seen a single essentials server before (logged into a different clients server a week ago) and I honestly have never looked it up because I never thought I'd be in a position where essentials would become my loving problem to upgrade/migrate/administer.

MF_James fucked around with this message at 03:06 on Mar 27, 2019

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Updating 2016 servers is slow as gently caress and awful, they really screwed something up with it, WSUS or regular WU doesn't matter.

2019 servers on the other hand patch fast as hell, I can have the monthly updates and reboots done in <15 minutes generally.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

The Fool posted:

Unifi is definitely easy to manage, but there have been a variety of quality issues with their AP's.

I'm not saying don't use them, but if you do keep that and mind and overbuild your network so that if you do have issues the impact is minimized.

The quality issues were from a run a few years ago, as long as you don't buy used, you should be fine.

Obviously there could be a new bad run I haven't heard of...

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Standing up some new hosts and a SAN for a client, they are currently on ESXi 6.5u3 on their older equipment.

I have not worked with vmware stuff much other than admining a couple already running clusters; most of my clients have used hyper-v.

The plan is to merely move the VMs to the new storage/cluster and then rebuild some of the VMs afterwards (not my choice but it is what it is).

If I install 6.7u3 onto the new hosts, is it going to cause problems for importing the VMs?

Should I build a new ESXi cluster (datacenter whatever vmware calls it) or can clusters run mixed versions?

Any other gotchas/stuff I should look out for?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

COOL CORN posted:

Not really between ESXi versions, I just did a big 6.5->6.7 upgrade and migrated hundreds of VMs between the two versions no problem.

If you're upgrading vCenter from 6.5 to 6.7, that's a bigger deal, but if it's just ESXi, you're fine.

I will probably just build a new vcenter server since the old one is server 2012r2 anyway.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Looks like 6.7 deprecates the windows version anyway.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Oh connectwise bought continuum? I thought it was the other way around.

Yeah my assumption is prices will go up in the next 6-12 months, service quality will go down; how it can go down further I don't know because Continuum's NOC is terrible and their monitoring is dog poo poo.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I think the goon in SA Mart sells server licenses, for a pet project (non-prod) I would trust those just fine, I run his windows 10 licenses and haven't had issues (at home).

Provided you have licensed all cores in the box, you can run hyper-v (and NO other roles) on your bare metal and then 2 VMs running whatever.

You just activate the hyper-v server and both VMs with the key

MF_James fucked around with this message at 00:07 on May 30, 2020

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Tapedump posted:

Yup, I've bought me-project Server keys from BT, you bet.


This is for my workplace, so we need to pay full boat (and have zero problem with that--I've got a generous budget). Thanks for the suggestion, though.

That's good info to have. I know the bare metal just can't be a DC/file server/anything-but-Hyper-V-Manager, gotcha.

Interesting to know. I was afraid that when I try to use the key the second (and third) times, it'd fail activation due to the repetition. 😀

Nope, won't fail, I'm not 100% sure how it works as I haven't tried to activate a key a bunch but I think you get X amount of activations (like 100 iirc). That way if you blow up a VM, rebuild and re-use the key you actually can, but if they see a bunch check into the microsoft servers with the same keys they're probably going to blacklist them.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

wolrah posted:

If this is the issue you might want to look in to USB-over-LAN. Those kinds of solutions are commonly used when virtualizing systems needing dongles. Depending on how the software actually uses the dongle it's legitimately possible that it works even over the internet, so you may or may not even need to worry about this problem.

Yeah, we use digi USB devices at a few manufacturers I have for clients and they work great, I'd recommend them versus plugging directly into systems.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

GreatGreen posted:

So this coming week, I have to deploy several dozen new VMs in a VMware environment, so I figure now is a great time to learn how to automate that!
I'll be working in vSphere 6.7. I've deployed plenty of individual VMs from scratch but I really don't know how I'd go about automating the deployment of multiple VM's.


The main unique variables per VM:
-Computer name
-Static IP

A few VM's will need:
-a larger C drive than most of the other VM's
-an additional data drive.

Additional info:
-all VM's are connecting to the same domain
-all of them will need our antivirus installed, which creates a unique PC record in its database and screws up if you rename a PC it's on, so it needs to be automatically installed after the PC has been named and added to the domain.



There are probably a few ways to do this but I don't know about them. Are there any straightforward guides anywhere that detail how to do this? Has anybody recently done something like this themselves?

You can use templates for some of this, not sure how/if that will handle your AV install properly, but you can get unique machines up and running easily with them.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

GreatGreen posted:

Will templates let you to specify a computer name and static IP address directly within the vSphere environment?

Just did a quick google for the docs, these are for 5.1 but you can find the updated stuff somewhere https://pubs.vmware.com/vsphere-51/index.jsp?topic=%2Fcom.vmware.vsphere.vm_admin.doc%2FGUID-40BC4243-E4FA-4A46-8C8B-F50D92C186ED.html here's the 6.7 info https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.vm_admin.doc/GUID-FE6DE4DF-FAD0-4BB0-A1FD-AFE9A40F4BFE.html

and yeah what Thants said above, just use the console to deploy you can't effectively clone things that need unique GUIDs and windows doesn't have a package manager (except it kind of does but is in preview) https://devblogs.microsoft.com/commandline/windows-package-manager-preview/

MF_James fucked around with this message at 02:11 on Jun 15, 2020

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

We use LMI, it's fine, better than most, comes up short in some areas, but I handle some remote support and a lot of remote server/network engineering and do not have problems.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

codo27 posted:

If you were buying a MFP what would you be looking for? What would you avoid? I've dealt a lot with Xerox at my previous job and they dont make sticks long enough for me to touch them with again. We did have good luck mostly with our HPs. Is Brother to be trusted at all? (Yes I know all printers are inherently garbage and the bane of our existence)

Don't buy an MFP, lease it from a company, though I know you're living/working on tethered ice flows so not sure if there are leasing companies available out there...

I have clients with HPs and they seem fairly solid and I've had good luck with Ricoh's; Sharp printers are also not too bad and they offer managed services which are typically cheaper per print than competitors, but, again, the tethered ice flow problem.

Every printer I've had to deal with for more than "how does I scan" and "it won't print" (hint: it's out of paper) has been under a contract so take what I say with a grain of salt.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

ohhh ok, I'd probably roll Brother if it were me, I could get you a model rec if you want.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Boywhiz88 posted:

OK, so I've got a dumb question/situation.

I have a client that's part of a commercial office building. We upgraded his network w/ an 8-port switch from a 5-port switch. It's at that time that I noticed the building's network is just wide open. I used an unmanaged switch in part because I assumed that wouldn't be the case, and because I didn't know any better. Quickly learned the difference when I got home and researched.

So, I want to swap it for them here so that I can setup a more secure network. I only want the Internet connectivity incoming and to push whatever through that so that their devices wouldn't show up on the building's network at large.

I wouldn't be able to affect anything but this switch, so no other modifications to the network would be available to me.

Would this be possible?

So, what is the upstream device that your client's switch runs to?

What is handling DHCP?

What types of devices are on your client's network? (i.e. PCs/laptops, servers etc)

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

NevergirlsOFFICIAL posted:

I think you should get a cheap firewall. Like the sonic wall tz100 is what I’m familiar with but whatever equivalent to that will handle everything. Put it in front of the switch.

I thought I had responded after the initial questions I asked, but yeah, this is the thing to do.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

8x8 is fairly decent, cloud pbx and all that, we resell them to our customers.

Their support can be iffy, they have pretty decent KBs for most common items.

I've run into random weird things that don't work well such as..

Speed dials on physical phones randomly disappearing when the phone reboots/updates
iOS softphone app doesn't have a way to set it to not ring other than being logged out (android app does)

I'm sure there are a few other things I can't think of rn, but honestly despite the short comings it works fairly well.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

bolind posted:

Got a link or CVE for that?

It's turning out to not be so bad overall from what SonicWALL is saying: https://www.sonicwall.com/support/p...10122173415410/

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

After reading a few times, I think this is how things are setup? sorry for the terrible paint I'm tired and don't care to do more work:



So, a few things:

1) The VPN you speak of, is it an IPSEC tunnel off the sonicWALL or is it a VPN client of some kind from PC1?
1a) If it's a VPN client is it doing full tunnel or something weird like that?

2) Building on the above, what is the subnet on the other side of the VPN that PC1 talks to, does it in some way overlap one of the local subnets? (this probably isn't the issue but whatever)

3) If there isn't something weird due to the aforementioned VPN setup/subnets, I would packet capture on the SonicWALL and it should show you what's going on.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I was going to say Datto workplace is pretty decent but with the amount of data and file sizes you're talking about it's probably not a good fit.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

BonoMan posted:

No we're good - we have a solution. It's just me trying to convince the higher ups who chase shiny objects that Google Drive is *not* the option ha.

Yeah I don't think ANY cloud storage is going to fit the bill unless you pay $texas$ (comparatively speaking) for WAN and storage costs

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

bolind posted:

Does anyone here have experience with Dell Wyse terminals?

Some and experience is about 3-4 years old.

They weren't bad, probably better than the HP thin client, we didn't have a ton of hardware problems from what I recall. The configuration can be a bit of a pain in the rear end unless all your devices are going to be configured the same. Brain is a little fuzzy on the details now but I was using their configuration utility to drop a basic config on them and then we'd manually configure the connection based on the location the device was shipped to, but I think when the device rebooted the connection we created would disappear because it would reload the configuration you initially dropped on it and wipe out any changes you made afterwards. I think that's what the issue was, there might have been a FW update that fixed this or something, as we eventually started using only them for a bit, then I think got a better deal with someone else and switched again.

Do you have specific questions?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

bolind posted:

Cool!

So first let me say that I'm not married to Wyse, but we are a Dell shop, and so far it looks like they could work.

The problem I'm trying to solve is that, currently, we have about a dozen "workstations" which are Dell SFF PCs of various vintages running Linux, that basically act as a glorified X canvas. User starts a terminal, immediately sshs to more powerful server. Same with most other programs. In fact, I don't think my users are smart enough to distinguish between, say, a browser window running locally and one running on the server.

This is, obviously, a medium pain in the rear end, so I got the idea of scrapping them all and getting some thin clients to hook up to a VNC server. It's very local, the thin clients would literally have gigabit connection and sub half milisecond latency to the VNC server.

I realize most people hook them up to Windows or something, but I do see in the docs that they support VNC.

Haven't used them for anything other than RDP to a Windows Server, so I can't attest to the quality of VNC connections.

The devices themselves were fine enough, better than HP (we had a lot of hardware issues with HP TCs) and at least on par with most other TCs we tried.

I would assume as long as the VNC integration isn't poo poo they should be fine for what you're doing but again, no experience in that space so hopefully potato has some.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Duo honestly isn't too bad and is fairly decently priced (the $3 a month version will handle 99% of use cases) our big reason for using it at a few clients is they want on-prem admin access to servers protected, which is not done well by Azure MFA yet; unless I'm mistaken, you need to host your own MFA VM to handle any on-prem servers.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Pretty sure you can't remove printers with GPO, but I'd love to be proven wrong.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

You can also use the file server migration tool, if all your fileserver does is act as a file server, that will make life much easier, though not sure where you're at in the process.

I've also never used it because all my clients have their file servers doing multiple things.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Speaking of AT&T and their royal fuckups.

I've got a client moving offices, they put an order in for a new circuit turnup back in April, had it scheduled for mid-july. The office move was supposed to happen tomorrow.

AT&T did the install, but no connectivity. After a lot of faffing about on AT&T's end, my client emailed the CEO and, in his words, "ripped him a new one", he got multiple calls from CS reps promising to fix it.

After more faffing about, they found yesterday that someone entered the address in wrong and so everything is configured all hosed up.

They've promised to have it fixed Monday; my clients lease is up on his old building on Saturday.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

We had a client acquire a company, they had an MSP, that MSP was friendly enough to do a decent handoff.

The problem was that half of their passwords were wrong, poo poo was wildly undocumented, it was great.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Silly Newbie posted:

Doesn't matter what you put in the reply to address, doesn't even have to be an address that exists, so long as it's in your tenant.

This isn't 100% true, you absolutely CANNOT use an address that exists as a user.

Also, O365s spam filter loves to catch the emails so you might have to do some work there as well to get the mail to get passed to mailboxes.

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Aruba's are perfectly fine for smaller offices if you're not all in on Meraki gear, I've deployed a ton of Aruba poo poo; easy to deploy and Just Works.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply