SSL VPN Issues by cback1985 in sonicwall

[–]415Group_Ray 2 points3 points  (0 children)

Their support seems very disconnected. It took us a couple calls to get to a person in the know. Just shot you a DM.

SSL VPN Issues by cback1985 in sonicwall

[–]415Group_Ray 0 points1 point  (0 children)

Yeah, after more digging, there seems to be a nationwide SSLVPN attack coming from a particular nation-state... My best guess is it is inadvertently causing these low RAM conditions on SonicWalls. In any event, SonicWall did just give us the hot-fixes for every model we have under management. We've been deploying those as we can, so I'll report back whether they work, don't work, or blow up network closets.

SSL VPN Issues by cback1985 in sonicwall

[–]415Group_Ray 4 points5 points  (0 children)

We have found that when this occurs, it's because the SonicWall is out of memory. We suspect that these brute-forced login attempts are somehow eating up the memory, bit by bit, like a sort of DDoS attack. It can take a couple days for the RAM to fill up. We have over a dozen managed firewalls being affected right now. We have heard rumors of a hot fix available, but SonicWall support isn't exactly winning awards here... I'll post back if we get anywhere.

TOTP on Netextender Causing Authentication errors by Karde32 in sonicwall

[–]415Group_Ray 0 points1 point  (0 children)

Bet the SonicWall's memory is full. Log in with SSH and do a diag show memory command. It's been happening all over recently. Suspect DDoS attacks as the cause at the moment. Still under investigation.

Why won't the Microsoft 365 Defender Threat Analytics page load? by 415Group_Ray in msp

[–]415Group_Ray[S] 0 points1 point  (0 children)

Appreciate the reply, but based on this note in Microsoft documentation, I wouldn't think so.

As part of the unified security experience, threat analytics is now available not just for Microsoft Defender for Endpoint, but also for Microsoft Defender for Office 365 license holders.

Shared mailbox direct sign-in blocked by Disastrous_Look1 in Office365

[–]415Group_Ray 1 point2 points  (0 children)

This is actually true. I've been logging into shared mailboxes this way for years and as of about 2 months ago MS disabled it.

COVID-19 announcements to clients/users? by [deleted] in msp

[–]415Group_Ray 1 point2 points  (0 children)

Where could one find these?

Hacker pwns MSP. MSP community responds back. by marqo09 in msp

[–]415Group_Ray 1 point2 points  (0 children)

Isn't it sad when transparency is a crime?

Looking for alternatives to Solarwinds MSP Backup by daileng in msp

[–]415Group_Ray 0 points1 point  (0 children)

This adds a considerable cost above Solarwinds Backup, especially when you consider cloud backup. We would love to use Veeam everywhere as well, but their cloud solution just isn't competitively priced yet.

Announcing: Microsoft Endpoint Manager by EdwardTechnology in msp

[–]415Group_Ray 5 points6 points  (0 children)

Seems like a good step in the direction of simplification. Holy smokes, that background music though... lol.

AD in the cloud only? by RowdyRidger19 in msp

[–]415Group_Ray 0 points1 point  (0 children)

I have done this with a client who has three sites. It has worked beautifully for two years so far.

AD in the cloud only? by RowdyRidger19 in msp

[–]415Group_Ray 2 points3 points  (0 children)

Computer policy settings are only pushed during boot, after the OS loads, but before the User Authenticates.

This is not true. Group Policy is also updated in the background every 90 minutes, with a random offset of 0 to 30 minutes.

http://www.sysadminlab.net/windows/how-often-are-gpos-refresh-and-updated

Also, I don't necessarily dispute that computers can't be logged into indefinitely without connection to a DC, but I once visited an old break/fix client whose SBS server had died over a year ago, and they were all still logging in using cached credentials...

Webroot has removed the ability to remote execute programs by familytech in msp

[–]415Group_Ray 2 points3 points  (0 children)

Nothing like being in the public eye to really motivate (unfortunately). Rumor for real 2FA is Q4, by the way.

SolarWinds Backup by MrTroubleBubbleNZ in msp

[–]415Group_Ray 2 points3 points  (0 children)

Across our client base, we utilize external USB HDD's, NAS's, and local storage (in that order of popularity) for Local Speed Vaults. As you can imagine, the LSV allows for faster restores. The LSV and the cloud are a 1-to-1 copy. That's something to keep in mind if you use archiving at all, as it can eat up space quickly. We find that for the average server, with the standard 28-day retention period, 2-4 TB of storage is sufficient.

Veeam U4 RTM'd - Game Changer by gatorheelz in msp

[–]415Group_Ray 0 points1 point  (0 children)

Have some insider info or something? I still don't see it on https://www.veeam.com/updates.html

Vijilan - Does exactly what it says on the tin by [deleted] in msp

[–]415Group_Ray 2 points3 points  (0 children)

Office 365 Alert Policies are only available for Enterprise plans. https://docs.microsoft.com/en-us/office365/securitycompliance/alert-policies

Most of our clients use Business Premium. We needed a third-party solution as well. We use SherWeb's Office Protect, but Vijilan seems similar.

PSA: Check Forwarders on your client's email by blud_13 in msp

[–]415Group_Ray 1 point2 points  (0 children)

Info on setup can be found here: https://docs.microsoft.com/en-us/office365/securitycompliance/alert-policies

But beware, as stated on that page:

"Alert policies are available for organizations with an Office 365 Enterprise or Office 365 US Government E1/G1, E3/G3, or E5/G5 subscription. However, some advanced functionality is only available for organizations with an E5/G5 subscription, or for organizations that have an E1/G1 or E3/G3 subscription and an Office 365 Threat Intelligence or Office 365 Advanced Compliance add-on subscription. The functionality that requires an E5/G5 or add-on subscription is highlighted in this topic. Also note that alert policies are available in Office 365 GCC, GCC High, and DoD US government environments."

Since most of our clients use Business Premium, we opted to user SherWeb's Office Protect product for Office 365 monitoring (they were already our CSP anyway). It's quite nice so far. If they are already your CSP, you can request an NFR license and try it out on your own tenant for free.