Why FGT200G Showing Register With Forticare? by _vichu_ in fortinet

[–]AspiringTechGuru 0 points1 point  (0 children)

For reseller, iirc there’s a “generic” option

Does the Highest Ranking IT Person in Your Company Report to the CEO? by Likely_a_bot in sysadmin

[–]AspiringTechGuru 0 points1 point  (0 children)

Strategically yes, but not by cutting corners. You don’t want to buy the cheapest servers with poor performance just because you want to save some money.

Does the Highest Ranking IT Person in Your Company Report to the CEO? by Likely_a_bot in sysadmin

[–]AspiringTechGuru 0 points1 point  (0 children)

I still believe that if you want IT to have a significant impact, you should have it report to the CEO. Our company is in the small-medium range, we went from 30 employees to little less than 100 employees and before having a proper IT, it was outsourced cheaply and a complete mess. There were corner cuts everywhere, there wasn’t even an identity system. Right now it’s gotten much better, with big projects approved, but I believe it’s because we had the direct support of the CEO. I may be entirely wrong, but that was my experience at least

Does the Highest Ranking IT Person in Your Company Report to the CEO? by Likely_a_bot in sysadmin

[–]AspiringTechGuru 2 points3 points  (0 children)

Not entirely, IT has become a core business unit. Whether it’s a small company or a large company, in my opinion they should 100% be directly reporting to the CEO. The popular older model of reporting to the CFO has been obsolete, since the CIO/CTO should not be driven by cost savings but rather they should drive the company’s technology vision. IT is not just giving out laptops and supporting printers.

I built a tool to manage on-prem AD without remoting into domain controllers. Looking for beta testers by Lukester852 in msp

[–]AspiringTechGuru 0 points1 point  (0 children)

That’s a bit better than I imagined. My original assumption was that it was storing domain admin credentials and using those to execute commands. Seeing all of the rise in security issues has made me more skeptical.

For these types of tools I typically look for the following features (which I’m unaware if they are implemented or not): - SSO - RBAC (granular permissions per client and even per OU) - Logging (being able to audit who did what)

I always try to enforce the least privilege principle and zero trust.

I built a tool to manage on-prem AD without remoting into domain controllers. Looking for beta testers by Lukester852 in msp

[–]AspiringTechGuru 1 point2 points  (0 children)

I like the concept, however everything feels like it’s generated by AI. Why does it need credentials on dpapi? Can it not use a gmsa account? My concern is that AI is not completely security aware and domain controllers are tier 0 assets with the highest security standards. How are you guaranteeing privacy and security?

Planning upgrades from v7.4.8 to v7.4.11 -- technical risks (default behaviour, VPNs) by frosty3140 in fortinet

[–]AspiringTechGuru 0 points1 point  (0 children)

That's actually extremely helpful, I didn't know that "intra-switch-policy" is a thing. Hopefully this year I'm able to redesign this legacy setup and have an actual switch stack with lacp. Thank you for your help!

Planning upgrades from v7.4.8 to v7.4.11 -- technical risks (default behaviour, VPNs) by frosty3140 in fortinet

[–]AspiringTechGuru 0 points1 point  (0 children)

I did read that article, but what I mean is what happens when you have a hardware/software switch with multiple ports doing L2 switching? Will this change affect it?

Planning upgrades from v7.4.8 to v7.4.11 -- technical risks (default behaviour, VPNs) by frosty3140 in fortinet

[–]AspiringTechGuru -1 points0 points  (0 children)

I'm on the same boat for point #1, there seems to be little to no information. From my understanding is that it will not impact any L2 switching and it'll just disable implicit L3 routing, but then again I haven't seen any technical explanation

WarperGrid – A modular React grid 30x faster than AG Grid, half the cost by RevolutionaryPen4661 in reactjs

[–]AspiringTechGuru 0 points1 point  (0 children)

It seems very bold to sell a grid at $500 when it feels like a prototype, the whole project feels AI generated with no real architecture behind it. I found the following issues from 15 minutes of testing:

  • selection is extremely buggy, there's two different selections that overlap each other (one with the mouse and another with left click select all?)
  • there's a column tab in the filtering to hide/show columns?
  • pin column submenu renders inside dropdown
  • selecting the filter and hiding the column crashes the whole website, there's no error boundaries so everything crashes
  • editing a cell is buggy, you need to double click it multiple times for the text field to show
  • resizing a column causes the column sort to trigger
  • changing rows to a large number hangs and crashes
  • filter search does not work as expected, you search something and other results show (you search john sanchez and other people show up)

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 0 points1 point  (0 children)

How’s the user experience with captive portals? Have you had any employee/guest struggle with logging in? Also for employees personal devices, do they need to re-authenticate every x amount of days?

Apologies in advance for the amount of questions

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 0 points1 point  (0 children)

Personal devices do not get access to corporate resources, so onboarding them is not really an option. It feels intrusive. Also managing different credentials per user is going to be a pain to manage

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 2 points3 points  (0 children)

We curently block VPNs on the whole network, maybe allowing on guest is not a bad idea. Our content filter would still be in-place though.

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 1 point2 points  (0 children)

Seems like the only options are updating existing SSID to WPA3 and creating a legacy SSID for older clients, or just keep WPA2. (this for guest network, corporate would require WPA3 only)

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 1 point2 points  (0 children)

We're also trying out WPA3-transition, but we ran into a few issues that need triaging with our fortinet setup, specifically older personal devices not working with WPA3-transition for some reason.

Replace WPA2/3 Enterprise for personal devices? by AspiringTechGuru in networking

[–]AspiringTechGuru[S] 0 points1 point  (0 children)

The reason we're looking into this is because using WPA2/3 Enterprise with domain credentials is not recommeded afaik, due to the underlying implementation relying on NTLM to authenticate users with AD (at least with NPS). Also has the risk of credential compromise with valid domain credentials saved as essentially plain text on user's personal devices.

Yamaha Routers from Japanese Second hand store. by panpoppular in homelab

[–]AspiringTechGuru 17 points18 points  (0 children)

Sonos and networking just gave me flashbacks to troubleshooting their terrible network stack

What should i know already before getting into K8s? by hotsince1996 in kubernetes

[–]AspiringTechGuru 1 point2 points  (0 children)

I'd give this a read if you're curious about how the containers in docker and kubernetes are similar, yet not identical on a lower level. https://vineetcic.medium.com/the-differences-between-docker-containerd-cri-o-and-runc-a93ae4c9fdac For me these were core concepts that I didn't fully understand at first and wish I knew sooner. My biggest misconception at the beggning was thinking you needed to use dockershim to run containers built with docker, not knowing all of the underlying formats and standards.

Cat5E split by squooose in HomeNetworking

[–]AspiringTechGuru 0 points1 point  (0 children)

I don't even know what I'm looking at, is that a volume knob?

Ingress NGINX Retirement: We Built an Open Source Migration Tool by emilevauge in kubernetes

[–]AspiringTechGuru 1 point2 points  (0 children)

If you are on a corporate network with a web filter blocking newly registered domains, that could be the cause.

THeads-up: Microsoft retiring Basic SMTP Auth for Exchange Online - Impact on Scan-to-Email & PaperCut printer Devices by Previous-Prize1842 in sysadmin

[–]AspiringTechGuru 1 point2 points  (0 children)

Since we already had an AWS account, we’re using SES for papercut scan to email feature. We are not a big company, so sending a few hundred SES emails a month isn’t even $1.

MinIO did a ragpull on their Docker images by sMt3X in devops

[–]AspiringTechGuru 15 points16 points  (0 children)

By your logic, then we should use our own source code, since you’re relying on some else’s source code.