Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


Small business: where replacing a failing hard disk drive in a RAID array for a cost of around £60 becomes a three month argument

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


Could you not use Remote Desktop Gateway?

Thanks Ants
May 21, 2004

#essereFerrari


NevergirlsOFFICIAL posted:

will that let me do the thing I want to do

Assuming your brute force attack is against common RDP ports then it would mitigate against that since it just operates over HTTPS. It depends on whether this is targeted or just a drive-by scan for open ports as to how effective it will be.

Thanks Ants
May 21, 2004

#essereFerrari


The method that lets me change things around on the network without having to touch multiple devices.

Or just leave them all on DHCP on their own subnet and let DNS work it out :getin:

Thanks Ants
May 21, 2004

#essereFerrari


Crowley posted:

IIRC you can't even promote a server to DC if it's using DHCP.

You can because Azure VMs have to run DHCP even though the end up with addresses that don't change, and you can promote them into domain controllers. It just warns you against it.

Thanks Ants
May 21, 2004

#essereFerrari


Sonicwalls are loving trash and even if replacing it doesn't fix your problems, at least you don't have a Sonicwall any more.

Thanks Ants
May 21, 2004

#essereFerrari


:10bux: on Confluence

Thanks Ants
May 21, 2004

#essereFerrari


Morganus_Starr posted:

Looks pretty cool, but..



Holy smokes Batman.

I think they got their idea of how much their product is worth by looking at the Zendesk pricing.

They also charge an activation fee, and SAML is an 'enterprise' feature. gently caress everyone who does that.

Thanks Ants
May 21, 2004

#essereFerrari


^ same. If they are insisting on Outlook then Google Apps Sync won't cut it because there will be stuff missing like stupid voting buttons and contacts delegation.

If they are open minded then go with Google Apps. I have clients on both and all the ones with a startup mentality are on Google Apps and only use a browser or the Gmail app on phones to access their mail. They never have issues. The ones that have come from large law or financial firms and insist on Outlook are using it like they still have an on-premise Exchange server run by a 10-person messaging team, so they load the thing up with a dozen delegated calendars and get frustrated when things get out of sync.

Thanks Ants
May 21, 2004

#essereFerrari


ThinkingPhones, 8x8, any number of BroadCloud partners. I think it massively depends on where you're located as latency is obviously a potential issue, and any on-site element that's required will vary by region as to how competent they are.

Thanks Ants
May 21, 2004

#essereFerrari


Find a Veeam Cloud provider

Thanks Ants
May 21, 2004

#essereFerrari


Look man we stocked up on IP Office back in 2003 and we're not just going to write that off.

Thanks Ants
May 21, 2004

#essereFerrari


If you want a Sonicwall then get the TZ SOHO since the 105 is ancient now. I'm not really sure that what you're doing needs anything fancy though - presumably you're just going to block all inbound traffic and only allow outbound to your provider, and don't need QoS since the connection is only for phones to use.

Thanks Ants
May 21, 2004

#essereFerrari


I can't see a use case that would require anything above a basic router with NAT and ACL support but if you already work with Sonicwalls and you know them then it's probably worth a few hundred to keep some consistency.

One of the VoIP suppliers we work with puts little Juniper SRX110s out for this sort of usage and they seem to work really well.

Thanks Ants
May 21, 2004

#essereFerrari


Backup as in Azure Site Recovery or secondary DC as in a Windows VM and VPN?

Thanks Ants
May 21, 2004

#essereFerrari


Or look at Amazon WorkSpaces

Thanks Ants
May 21, 2004

#essereFerrari


Yeah if you try it yourself then someone will gently caress up and you'll get your actual used-for-business domain blacklisted.

Thanks Ants
May 21, 2004

#essereFerrari


Sheep posted:

I had to go through the de-blacklisting process when our company blasted a few hundred thousand people from an SMTP server they ran on an AWS instance :v:

That was several days of my life I'll never get back.

How the gently caress does someone have workloads on AWS and not see that there is a service designed for sending mass email right there in the dashboard?

Thanks Ants
May 21, 2004

#essereFerrari


Yeah start the process for speccing out a large order and you'll have a new rep at some point just before you sign off and have to start again.

Thanks Ants
May 21, 2004

#essereFerrari


Behold http://rclone.org/. You'll also want to get comfortable with https://github.com/jay0lee/GAM/wiki/GoogleDriveManagement.

Thanks Ants
May 21, 2004

#essereFerrari


They are really powerful and can do pretty much anything you'd want them to - including stuff like VRRP, VRF (coming soon), dynamic routing etc. But they are a totally different use model to a DrayTek - no DSL modems built in, no USB port for a 3G dongle and things like that. The DrayTek units have their central management server as well which you might use if you're an MSP.

It really depends on how good the team that are supporting these things are, and whether you just resell the connections or have a management VLAN provisioned alongside the Internet connectivity.

Thanks Ants
May 21, 2004

#essereFerrari


If Virgin can give you ~1Mbps of private connectivity on each of the connections you resell then you can make yourself a management interface on the Ubiquiti routers to make up for the lack of central management. Alternatively you can enable management from the WAN side and just restrict it to your office.

They are text-based configurations so easy enough to template and write scripts to configure the WAN and LAN addresses for each deployment and then have a common set of config for default firewall rules, QoS settings etc.

Thanks Ants
May 21, 2004

#essereFerrari


Get the Lite rather than the X or SFP if you want a small box for testing. It runs the same software but the console port is really handy if you gently caress up because you won't have to start over each time.

Thanks Ants
May 21, 2004

#essereFerrari


Block ActiveSync except to the Outlook app, enforce policies in the Office 365 apps to ensure content can only move around between those apps. Call it a day. No we don't support your iCloud account.

Thanks Ants
May 21, 2004

#essereFerrari


I am trying to make the only MS licensing I deal with stuff like Office 365 that is impossible to be under-licensed on. I am happy for our connectivity provider to build and maintain their own VMware environment and have SPLA handle the Windows licensing.

Thanks Ants
May 21, 2004

#essereFerrari


Yeah, being able to have a set in stone price per user is great.

Thanks Ants
May 21, 2004

#essereFerrari


If you work for people who are tight though you end up running Exchange 2007 a decade later on an old HP Gen5 with a SAS shelf attached because, "it works fine why do you need to waste money?". That's not an option on 365.

Thanks Ants
May 21, 2004

#essereFerrari


You can create a domain and move DNS/DHCP across to AD-joined servers without actually going around and binding all of your clients, things will just carry on as they were before. So you don't need to rush around to get things migrated as such.

I'd definitely take it slowly if you haven't done it before, get it labbed out etc.

Thanks Ants
May 21, 2004

#essereFerrari


Or just use UniFi Elite

Thanks Ants
May 21, 2004

#essereFerrari


Egnyte Connect if you have the budget https://www.egnyte.co.uk/file-access/desktop-access.html

Thanks Ants
May 21, 2004

#essereFerrari


Google Team Drives and Drive File Stream have been announced at Next '17 so that might be worth looking at as well.

Thanks Ants
May 21, 2004

#essereFerrari


Probably quite poorly, I haven't tried to use G Suite with the email stuff disabled. A service that only does files is likely going to be a better fit for you.

Thanks Ants
May 21, 2004

#essereFerrari


I like the Geist monitors:

http://www.geistglobal.com/products/monitor/environmental-monitors

Thanks Ants
May 21, 2004

#essereFerrari


Buy Software Assurance with your CALs and keep it renewed so you never have to gently caress around with it again.

Thanks Ants
May 21, 2004

#essereFerrari


Have they fixed the Intune portal yet to not require Silverlight?

Thanks Ants
May 21, 2004

#essereFerrari


Helpdesk software for a small-shop quantity of agents is free/cheap. There's no reason to try and keep all that poo poo in your head or a cluttered inbox.

Thanks Ants
May 21, 2004

#essereFerrari


Like to throw Zoho Desk into the ring - free for 10 agents is a pretty sweet deal, and the paid plans are not expensive either.

https://www.zoho.com/desk/pricing.html

Thanks Ants
May 21, 2004

#essereFerrari


I tested Okta once and they didn't support changing the dashboard timezone so it wasn't showing all log events in UTC-08:00. Sort of gave up on it after that.

Thanks Ants
May 21, 2004

#essereFerrari


Keep an eye on your MS licensing because it's easy to subscribe to mutiple different products and end up spending more than something like EMS would cost you.

https://business.microsoft.com/en-gb/products/enterprise-mobility-suite

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


GargleBlaster posted:

Please see comments about not being able to spend money.

Honestly quite often that is my response. That it's not possible to make it any faster because it's slow old poo poo and we literally have a £0 budget (the company, like many in the country, is struggling after spending year after year being clobbered with credit crunches, recessions and this Brexit crap. Which for the uninitiated, was the United Kingdom's decision to throw itself off a very tall building. So they loathe to spend anything at all).

But sometimes you get the "surely you can do something, tweak something, paint some go-faster stripes on it, anything!!" people and they think that if we say no then we're just "being lazy". So about the best we can do is use some cleanup placebos to get them off our backs for a couple more weeks.

But if you geniuses have other £0 computer speeding up ideas be my guest. Please note, "install gentoo" will get you told to gently caress off back to 4chan - company relies on several Windows-only packages.

I've worked for and around enough UK firms to know that the Brexit excuse is mostly utter bollocks. Poor leadership is using it as an excuse, but UK companies being led like utter poo poo and refusing to invest have been a problem for loving ages.

£3k is less than the cost of a person for a month, to make 60 people more productive. Any cost/benefit analysis would provide the answer that the upgrades are A Good Idea. lovely managers with their 1980s methods are the problems here, and a desire to spend as little as possible to look good to the people above them.

Thanks Ants fucked around with this message at 16:25 on Apr 28, 2017

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply