Sysadmin

12 readers
1 users here now

A reddit dedicated to the profession of Computer System Administration.

founded 2 years ago
MODERATORS
26
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/SK-Incognito on 2024-01-24 07:17:50+00:00.


We were looking for a lightweight, free, and easy to deploy network management tool to easily discover all devices across our enterprise network. We have a full Cisco network stack, which is easy enough to manage via DNA Center or by SSHing into a switch etc., but sometimes you just want to quickly find a device by hostname/IP/MAC address and find out what switch it's connected to in a clean, intuitive interface. Was chatting to our cybersec MSP and they recommended Netdisco, so I thought I'd look into it.

Was very easy to deploy, it discovered all network devices and hosts through SNMP, can display a network topology map, show ports that are shutdown or locked via port-security, network device OS/firmware versions, serial numbers, plus so much more. Auditing our VLANs is such a breeze now.

Our help desk have always had to ask us (systems and networks team) for help with anything network related, but since we've deployed Netdisco and given the help desk staff access, they've been able to easily do that level 1 network troubleshooting and get a better understanding of our enterprise network.

Just recently we needed to locate a bunch of devices and what switchports they were connected to, something that's fairly simple if you know what to do, but pretty time consuming if you don't. With Netdisco one of our help desk staff was able to locate the devices, IPs, MAC addresses, and the switchports they were connected to all in about 15 minutes.

Just thought I'd share for those who are in need of something like this. Amazing tool.

27
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/middlemangv on 2024-01-24 06:56:06+00:00.


first time posting here, as I just started with my Firewall journey and bought Fortinet 40F Fortiguard.

Basically I'm a noob, didn't work too much with Firewalls but I'm learning and trying.

I have two sites. 1st site: Fortinet 2nd site: Watchguard

I need to connect those two sites.

NO Public Static IPs:

1st site: Fortinet is using its build in DDNS. There is an ISP router before it. I configured the DMZ to 192.168.1.254 to point it to Fortinet. Fortinet uses other subnet 10.11.1.0/24

2nd site: There is no ISP router before it but the IP is not static. It changes from time to time and ISP won't do anything about it. I created DDNS with free public DDNS provider. Watchguard is using subnet 192.168.88.0/24

What I did:

Went to "IPsec Tunnels" and created new "Custom" tunnel

Remote Gateway was set to be a Dynamic DNS. I figured out, after reading documentation, that this is DDNS for the other site so I typed it in

Interface that I'm using is wan1. wan1 is basically, as the name says, my go out to the internet port

The rest for "Network" in Edit VPN tunnel settings is left on default

Regarding authentication I just set Pre-Shared key with and typed simple password.

On IKE Version I choose 2.

Phase 1 Proposal:

I left only AES256 for Encryption and SHA256 for Authentication. I removed any other encryption and authentication choices. Diffie-Helman group is 14

Phase 2 Selectors:

I basically just typed in my local IP for Fortinet on "Local Address" and I typed in local Watchguard IP on "Remote address" with their subnets which are /24.

So basically, after I was done with this, I went to Policy & Objects > Firewall Policy

I added two Policies - first one:

name: VPN remote site

Incoming interface: internal - this is my lan

Outgoing interface: I choose the tunnel interface that I created on IPSec tunnel option.

Source: 4 all

Destination: I created an address. I went to Network/Addresses and addes an address or a subnet with IP and its Netmask and I named it accordingly.

Service: ALL

Action: Accept

NAT: I switched it off

Everything else is left on default and I clicked OK.

Then, on the same menu - Firewall Policy I just clicked on newly created policy and "Created reverse policy".

After that I went to "Network > Static Routes>Create New"

Destination: Subnet, I just typed in subnet of the remote Watchguard

Interface: I choose that Tunnel Interface that was created on "IP Sec Tunnel" in the first steps.

So this should be it for Fortiguard, right? Hopefully I didn't make any mistakes. Or maybe I did, or maybe there is some practice that I am not aware of.

After that I logged in to Watchguard Firebox, and I may have some noobish problems but:

VPN > Branch Office VPN and on "Gateways" I clicked "Add". Added a name to my Gateway and on

Credential Method I selected "Use Pre-Shared Key" and typed in the same key as I did on Fortiguard.

On "Phase 1 Settings" I selected IKEv2 version and left everything else on default.

I went back and clicked "add" on "Gateway Endpoint" > Local Gateway

External interface: External

Interface IP Address: Primary interface IPv4 Address

Specify the gateway ID for tunnel authentication > By Domain Name and I typed in domain name or DDNS of the local gateway aka Watchguard. I don't know if this is correct, but to me, its logical that Local Gateway ID is local gateway for Watchguard.

On "Remote Gateway" I selected Dynamic IP address for "Specify the remote gateway IP address for a tunnel"

and I selected "By Domain Name" on "Specify the remote gateway ID for tunnel authentication" and I typed in Fortiguard DDNS that I created when I bought Fortiguard. Everything else was left on default.

After that I went on creating Tunnel in "Branch Office VPN"

Added, named it, and on "Addresses" I added Local IP (Watchguard) and Remote IP (Fortiguard) and for the type I choose Network IPv4.

Direction: bidirectional

For Phase 2 Settings:

I enabled perfect Forward Secrecy and Choose Diffie-Hellman Group 14

On IPSec Proposals I choose ESP-AES256-SHA256, as I did on my fortiguard AES256 and SHA256.

Clicked save, and the rest of the settings are on default.

What now? What are my next steps? Do I have to add some policy in Watchguard or what, because I think that some policies are already added after creating BoVPN? I tried to be as much as detailed as possible.

Any answer is highly appreciated.

Btw it is worth nothing that there is already one site to site connection on fortinet to another remote destination. I don't know if it means something but maybe you should know. Thanks!

TUNNEL STATE from Fortinet: I typed this command in CLI: get vpn ipsec tunnel summary

Output: 'MZ RemoteVPN' IP address:0 selectors(total,up): 1/0 rx(pkt,err): 0/0 tx(pkt,err): 0/0

#diagnose vpn tunnel list

list all ipsec tunnel in vd 0

name=MZ RemoteVPN ver=2 serial=7 192.168.1.254:0->IP address:0 tun_id=10.0.0.7 tun_id6=::10.0.0.7 dst_mtu=0 dpd-link=off weight=1

bound_if=5 lgwy=static/1 tun=intf mode=auto/1 encap=none/552 options[0228]=npu frag-rfc run_state=0 role=primary accept_traffic=1 overlay_id=0

proxyid_num=1 child_num=0 refcnt=3 ilast=43646953 olast=43646953 ad=/0

stat: rxp=0 txp=0 rxb=0 txb=0

dpd: mode=on-demand on=0 idle=20000ms retry=3 count=0 seqno=0

natt: mode=none draft=0 interval=0 remote_port=0

fec: egress=0 ingress=0

proxyid=Deponija remote proto=0 sa=0 ref=1 serial=2

src: 0:10.11.0.0-10.11.0.255:0

dst: 0:192.168.88.0-192.168.88.255:0

On Firebox using WSM I clicked on Branch office VPN Tunnels and on Gateway there is red X and the message from Endpoint: 1 - No response for IKE_SA_INIT request message. Check connection between the local and remote gateway endpoitns Local 192.168.88.0 Remote 10.11.0.0 (inacti

28
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/MACAVITYARTS on 2024-01-24 06:55:19+00:00.


Hey guys, so today I was downloading maya 2024 cracked and when I click setup.exe and this box appears" preparation for installation" but after 10/20 this box disappears..does anybody know how to fix this? I tried every possible way from the autodesk site solution and YouTube but nothing helps..I also deleted all older autodesk files by revo uninstaller and also removed them from the registry editor? Any solutions for those who got issues from this?

29
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/blackholden on 2024-01-24 05:41:29+00:00.


Hi All,

I wanted to see what the best process that everyone is now following to install windows updates on production servers. Updates can be downloaded whenever but they can only be installed / restart the server on select dates / times.

Currently there is a Automatic deployment rule in SCCM that is being used but i find it clunky and not super intuitive / easy to navigate.

Any assistance would be appreciated!

30
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/AlexRosi69 on 2024-01-24 05:35:46+00:00.


We were using synctoy to backup user pc to NAS. But now we purchased M365 and sync all data to OneDrive. However, i am looking for a way to make another backup of user data to NAS in background without any user intervention on a daily basis. Anyone done something like this before?

31
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/RavennaDoug on 2024-01-24 05:12:18+00:00.


At my company, we have a number of teams trying to leverage GenAI to provide various services internally. Automated responses to IT inquires, summarizing zoom conversations, our own private ChatGPT style chat interface. While these features are nice, nothing seems to be needle moving or having a meaningful impact on our business.

Curious to hear from other folks? Is GenAI living up to the hype where you work or no?

32
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/koliqv on 2024-01-24 04:31:12+00:00.


Hi fellow members,

Im currently having issue on our sub company which having split management. They just subs to microsoft 365 Business standard without azure and entra.

currently they dont want to use MFA as the staff are mostly contract user.

the question is how to disable MFA in business standard since it didnt link to parent company and totally have different company name and domain.

Thank you in advance

33
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/SilvaHaloOne on 2024-01-24 04:23:54+00:00.


Hi,

We had a SQL server crash in mid December during operating hours. The databases on it were all related to customer facing services, and we are still dealing with some fallout from it a month later.

It turns out this server, a Dell Poweredge R740, with 128gb Registered ECC DDR 4 RAM (8x HMA82GR7CJR8N-XN) was having a bunch of single bit memory errors and eventually had a memory error it could not recover from. The SupportAssist logs I gathered after the event showed 4 of the DIMMs malfunctioning and unable self-heal, so Dell dispatched replacement DIMMs, we got them replaced and the server hasn’t had a full on crash since then.

However, now we are getting several events a day in Windows where we are told a single bit memory error was corrected or that a corrected hardware error for Memory error type 13 has occurred. The SupportAssist logs now show that 2 different DIMMs (meaning DIMM’s that were not among the 4 replaced) are going through degradation and then self healing after reboot.

Our Dell support guy says that the issue is addressed and that what is left here is normal and under expected parameters. That doesn’t really seem right to me… like to me, normal and expected parameters might be one of these every couple of months and none of the tens of our other servers have these kinds of errors, however this server has twice the memory of its closest stablemate and I also have other fires that I’m trying to put out as well.

So… do I say “Ok, thank you, I will continue to monitor” and start another service request when/if things change or do I push more now?

Thank you for the advice!

34
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/1yv0s on 2024-01-24 03:26:35+00:00.


I had a user have their account compromised and approved an MFA prompt, allowing an attacker to register their own device with the authenticator app.

35
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/Administrative_Line3 on 2024-01-24 03:09:00+00:00.


Hi y'all!

There's some weird issue going on with 2/70 users with their outlooks. 2 users are receiving really obvious spam emails in their inbox and the weird thing is that the same spam email that they recieve is being caught in quarantine for the rest of the users.

We haven't made any changes to our anti-spam policies or anything else for that matter. Are any of y'all experiencing something like this or have experienced this before? What would y'all recommend I look into to resolve this?

36
1
Side-hustles (zerobytes.monster)
submitted 1 year ago by [email protected] to c/[email protected]
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/dogcmp6 on 2024-01-24 03:03:21+00:00.


What do you guys do to bring in extra income on the side while limiting liability? I don't want to use my car for something like Uber/Lyft/Door dash, and touching another business's systems opens me up to more liability than it's worth... so wanted to see what you guys all do for side hustles?

37
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/therisinggirl on 2024-01-24 02:43:38+00:00.


In your company, what is your file policy. Like who manages the files, who identifies what is important or not. I am currently undecided who should be the one to manages the files. Us IT are the one responsible on its storage but not the management or identification of it. I hope you get my point.

38
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/InternationalMark474 on 2024-01-24 02:39:53+00:00.


I have been tasked with setting up the Barracuda Client-to-Site Network Access Client (Barracuda VPN Client) on some laptops. When the VPN is connected, the device can access everything (internal web apps, RDP) in the network but shares... At least for a certain amount of time. For no rhyme or reason and for no estimated time, the shares will start working. Once the shares start working, it doesn't matter who logs into the device and the Barracuda VPN client, it will stay working. If you delete the Barracuda VPN profile (say to increase security protocols after testing) you have to do the same waiting period. It seems that once the profile has "established" then everything works.

For notes

  • Pings work both ways (server to endpoint, vice versa) when the shares do not work
  • Event viewer shows nothing outstanding. General SMB client errors that say can't connect until it can.
  • Windows firewall was disabled for testing purposes on the endpoints.
  • Network firewall shows traffic between server and endpoint on port 445.
  • Wireshark shows RST, ACK when not working, nothing determinable.
  • I have been in contact with Barracuda Support for over a month with zero solutions. To the point where they went dark and got the email gateway professional services involved.

Can anyone please give me some type of answer that will save my sanity on this issue? Please.

39
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/ReddyFreddy- on 2024-01-24 02:17:19+00:00.


TL;DR

Where can I find evidence of a computer account creation (Event 4741) when the new computer object is not created on the domain controller?

I tried to make that as succinct as possible, but here's what I mean.

Let's say I have a domain controller and a separate designated server where I do my AD work. We'll call them DC and Other.

If I create a computer account manually on DC, Event 4741 is easy enough to find. No problem there. However, if I create a computer account manually on Other, there's nothing in DC to show that a new computer account was created.

Shouldn't there be some trace event on the main DC somewhere to show that a new account was created? I've been reading the Event Log all day, and the novelty of that wore off long ago. Worse, there are several "Others" in this problem, and I can't realistically monitor them all.

[edit for clarity]

This is not about user accounts, either domain or local. I mean computer accounts, or computer objects. For reference, here is what Microsoft has to say about Event 4741.

40
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/Omgfunsies on 2024-01-24 01:36:12+00:00.


is there a reasonable option out there for VDI on the ipad when used with magic keyboard that will override the weird ipad behaviors and allow me to really use the trackpad and keyboard as if I was a full blown desktop pc.

I'd be happy with a linux based desktop even but it needs to be a full on desktop OS.

The weirdness with mouse clicks and other elements are throwing me off. maybe i'm missing something obvious but it seems liker ehere is no good solution

41
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/Timf135 on 2024-01-24 00:20:31+00:00.


Hello everyone,

I was curious of methods during an Intune rollout to force remote users to enroll in Intune.

We have remote users who have a mix of local accounts and already AzureAD joined. We are considering creating a cloud app policy that prevents devices not enrolled in Intune from accessing all 365 apps, so users must call in to help enroll their devices immediately.

Are there better methods to force enrollment? And are there any better methods to enroll devices other than having the users use the "Add work/school account" or for the existing joined devices the script linked here? ()

Thanks!

42
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/Past-Tomorrow6439 on 2024-01-24 00:17:04+00:00.


Would it be bad to use my company’s LLM Chatbot for non work related things? Would this be seen as breaking code of conduct or something if I used their chatbot for just my own personal things I am interested in searching about? I’ve thought about using the company chatbot for doing research on my own time since it can use CHATGPT4, I am not sure if this would get me flagged or anything if I don’t use the chatbot for direct work related things.

43
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/edgyguy2 on 2024-01-24 00:10:54+00:00.


Hi!

Using my throwaway for anonymity purposes.

I'm a sysadmin in charge of several clients (meaning everything from helpdesk to server upgrades, documentation, training, on-calls, to SOC is on me). I love working with different verticals and exploring different venues that come with an MSP space. I'm working on several certifications and have obtained some basic ones in the past. I have grown a lot in the current place and it shows in every other aspect but financial. I have 4.5-ish years of enterprise experience. 10-ish volunteering and collecting experience in very niche MS technologies that are very useful, but not very marketable.

I've brought it up and there's really little to no leeway here. I had my performance review last week and they seem very happy with me in every aspect. I LOVE the team, the company culture, basically everything about the company except the fact that raises are close to non-existent.

I definitely want to move to the cloud/infra side in the (near) future with little to no client-facing roles. My plan is to get some additional and advanced SC and AZ certs as well like SC-300/AZ-104.

I will not disclose the exact location, but I will say it's HCOL area and I'm around the 50k mark.

My current plan is work on my skills more while I see if there's anything out there that's paying more and then make an informed decision.

Am I wrong or should I be paid more?

44
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/bexhilliac on 2024-01-24 00:01:23+00:00.


Been in IT since 2000. Started in desktop support, moved into Server Team and basically been in infrastructure ever since but never made the move to management.

Worked overseas for a year during that time and in the last 2 years have changed jobs three times thinking my loathing for IT was because of the company.

Turns out I just loathe IT and therefore I am seriously thinking of changing careers. The constant learning and adapting to the changes in the industry is driving me slowly insane.

I’m seriously thinking of becoming a train driver. Barring the 55 weeks of training at relatively lower pay, once fully trained I would earn base pay that is slightly lower than I am on now but with the chance of doing lots of shift work which would increase the salary massively.

Thoughts?

Has anyone else got so sick of their job so much they’ve switched to a completely different career?

How did that go for you?

45
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/kiwikatz on 2024-01-24 06:27:28+00:00.


Hello all, as the title says, when I connect to a server successfully, the connection lasts for about 10-15 seconds before it “freezes” and then times out without giving any error messages. While connecting I used verbose output just to see if everything is alright in that part, and it is. I googled the possible solution for it all over various forums and sites, but none worked for this case. Has anyone had a similar or same issue? Or perhaps knows what the reason behind this could be? I know it’s the macbook and not the server because I was able to connect to the server from a different pc and laptop without any problems. Thank you for any possible answers.

46
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/CACodeBro on 2024-01-24 02:58:15+00:00.


Just curious how you folks are managing multiple administrators on say 30 Linux servers.

Currently I'm using Ansible to keep SSH keys updated across all servers for a generic shared "admin" account that is a member of sudoers. The main drawback to this is I lose granular auditing. I can see who SSH'd and from what host, but no direct link of command to user.

I'd like to create individual accounts on all the boxes...whether local or LDAP, but how do you deal with modification of files that expect to be owned by root? I don't like the idea of changing permissions of something like an nginx directory.

Just wondering how you folks are handling this?

47
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/shushine4neptune on 2024-01-24 02:47:51+00:00.


Wondering what solutions others use for on- premise MFA for AD authentication. Very recently migrated into O365, Entra ID sync next. We have some remote users currently using DUO already before they hit the VPN. What are your recommendations?

48
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/a_crossing on 2024-01-24 01:41:39+00:00.


Hi All,

I was wondering if others are experiencing an increase in spam getting though from random Gmail accounts in the last few weeks?

I personally am getting a lot trying to sell website development, SEO, leads etc.

I've had a number of clients also complaint about similar issues in the last 2 weeks or so.

People reporting the issue are using a mix of M365 default anti-spam with others using a full blown 3rd party anti-spam solution in front of the M365 tenancy. Both configurations are receiving these spam messages more often than normal now.

Are others experiencing this, or worked out a way to stop it?

49
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/UniqueSteve on 2024-01-23 22:55:52+00:00.


It seems that Dell makes our contact information available to an army of salespeople who all claim they are our contact and can save us the most money.

When I logged into Dell.com to ask who our salesperson was the guy I chatted with said he can get us the best deal, then gave me a quote with the wrong customer ID.

I do not want to email or talk to a salesperson to tell them what I want only to have them botch it, or hear a story about how their manager got us an extra special deal only available today.

All I want is a portal where I can maybe configure a standard build and set preferences like no McAfee, or bloatware of any kind, ever. I also want to know I’m getting the best price without having to look for coupons like I’m shopping on QVC.

I thought what I wanted was Dell Premier, but we don’t spend the $100k/yr necessary I guess.

We might buy 5-10 workstations a year, but each time I kind of dread it.

Any other small operations figured out a solution?

50
1
Humor - PEBKAC (zerobytes.monster)
submitted 1 year ago by [email protected] to c/[email protected]
 
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/pAceMakerTM on 2024-01-24 01:32:43+00:00.


Sorry, just had to share this. The guys in the office were talking about user error and I just came across this.

Lenovo got a good chortle out of me.

view more: ‹ prev next ›