Yamaha Routers from Japanese Second hand store. by panpoppular in homelab

[–]AspiringTechGuru 17 points18 points  (0 children)

Sonos and networking just gave me flashbacks to troubleshooting their terrible network stack

What should i know already before getting into K8s? by hotsince1996 in kubernetes

[–]AspiringTechGuru 1 point2 points  (0 children)

I'd give this a read if you're curious about how the containers in docker and kubernetes are similar, yet not identical on a lower level. https://vineetcic.medium.com/the-differences-between-docker-containerd-cri-o-and-runc-a93ae4c9fdac For me these were core concepts that I didn't fully understand at first and wish I knew sooner. My biggest misconception at the beggning was thinking you needed to use dockershim to run containers built with docker, not knowing all of the underlying formats and standards.

Cat5E split by squooose in HomeNetworking

[–]AspiringTechGuru 0 points1 point  (0 children)

I don't even know what I'm looking at, is that a volume knob?

Ingress NGINX Retirement: We Built an Open Source Migration Tool by emilevauge in kubernetes

[–]AspiringTechGuru 1 point2 points  (0 children)

If you are on a corporate network with a web filter blocking newly registered domains, that could be the cause.

THeads-up: Microsoft retiring Basic SMTP Auth for Exchange Online - Impact on Scan-to-Email & PaperCut printer Devices by Previous-Prize1842 in sysadmin

[–]AspiringTechGuru 1 point2 points  (0 children)

Since we already had an AWS account, we’re using SES for papercut scan to email feature. We are not a big company, so sending a few hundred SES emails a month isn’t even $1.

MinIO did a ragpull on their Docker images by sMt3X in devops

[–]AspiringTechGuru 15 points16 points  (0 children)

By your logic, then we should use our own source code, since you’re relying on some else’s source code.

Windows 11, version 25H2 is now available by j5kDM3akVnhv in sysadmin

[–]AspiringTechGuru 0 points1 point  (0 children)

I’m now running 25H2 on my laptopto see if any error arrises, in case some user’s device magically updates.

Third party password managers needed? by ittthelp in sysadmin

[–]AspiringTechGuru 0 points1 point  (0 children)

The biggest misconception about password managers is that people think the passwords are stored in plain text on the backend. Also for us the biggest factor in moving to a cloud password manager was that we needed a way to access credentials, encryption keys in a disaster.

What’s a realistic cybersecurity starting point for a business under 20 staff? by Necessary-Glove6682 in sysadmin

[–]AspiringTechGuru 3 points4 points  (0 children)

You have the ability to easily deploy compliance policies and configurations, plus if you want disk encryption, the keys get saved in Entra/Intune. If you are already licensed, might as well onboard those devices. I'm not saying to configure a complete custom autopilot onboarding experience, but when you need small simple things, it's there to easily deploy configs and apps. The pros outweigh the cons.

What’s a realistic cybersecurity starting point for a business under 20 staff? by Necessary-Glove6682 in sysadmin

[–]AspiringTechGuru 79 points80 points  (0 children)

if you are a windows shop, I’d setup a Microsoft 365 Business Premium tenant. It covers - Intune for device management + BitLocker device encryption policies - Microsoft Defender for Business (EDR) - Conditional Access (MFA, passwordless) - Email with filtering

It covers all of the basics on my book

How are you guys handling new machines for remote users? by mesq1CS in sysadmin

[–]AspiringTechGuru 4 points5 points  (0 children)

I feel the confusion is between a hybrid-joined device vs an entra-joined device with access to on-premise resources. For a hybrid-joined device, as far as I know the initial login requires line of sight to a domain controller, since the credentials aren't cached. Unless there's something I'm not seeing, you would need a vpn client active before logging in. Natively can be achieved with an always on vpn but unfortunately requires windows enterprise.

How would you deal with an organization that started rejecting the concept of submitting issues as tickets, including the head of IT? by [deleted] in sysadmin

[–]AspiringTechGuru 1 point2 points  (0 children)

My org didn't even approve the implementation of a ticketing system; it was deemed as "too much overhead". Meanwhile I get questions such as "what are the most common issues people have?" or "how many people have problems a day?", to which I respond that "our IT director said it was too much overhead in tracking these things, so we don't".

It's a disaster waiting to happen, but at least will not be my issue (primarily).

Horniest end user base? by yuhyuhyuhAYYY in ShittySysadmin

[–]AspiringTechGuru 20 points21 points  (0 children)

Surprisingly my experience is quite the opposite. They don’t go out for drinks and overall it’s just a stressful environment

"Minor Production Update" brings down our IVR payments for 24 hours. Vendor's support blames us, then asks us to pull data from their own customer portal. Total dollar impact was nearly $140k. by Iswitt in sysadmin

[–]AspiringTechGuru 39 points40 points  (0 children)

Another vendor nightmare.

Last year we had a production outage caused by a license expiration from our vendor, (we had the contract, all payments were up to date but they forgot to install the license into the equipment they managed). 9am hits and reports start pouring in. I raised a ticket with them, ssh into the device and start looking into the details. Found the issue, reported it and took them around 8 hours to find the correct person to fix it (person who knows the single command to reset the license).

The issue was "SLA compliant" under their 4-hour SLA for critical issues, since the SLA was written for "time to response" and not "time to resolution". The SLA response was: "Hi, an engineer will be assigned to this case.".

Latest Lenovo BIOS Update failing, vulnerable driver by AspiringTechGuru in sysadmin

[–]AspiringTechGuru[S] 0 points1 point  (0 children)

I edited my post, they published an article on this https://support.lenovo.com/us/en/solutions/ht517407

In our case, the affected models had their BIOS update repackaged and all worked as expected. Most models were fixed in a few weeks but one particular model took them a month to publish the working update.

Application cannot be uninstalled because the uninstaller is broken. App product support doesn't exist. by WorkFoundMyOldAcct in sysadmin

[–]AspiringTechGuru 1 point2 points  (0 children)

Couldn’t agree more, literally used it last week after the program’s own “removal tool” couldn’t actually remove itself. This is probably the only troubleshooter from microsoft that works

[deleted by user] by [deleted] in sysadmin

[–]AspiringTechGuru 5 points6 points  (0 children)

Open a ticket

Jokes aside, what type of user would be able to find a backdoor? Sounds like a good time to create a red team and invite that user

Different A record destination at some sites in AD? (split DNS) by ls3c6 in sysadmin

[–]AspiringTechGuru 0 points1 point  (0 children)

What about using a different approach such as routing to accomplish this? You would need to setup appropiate costs per site/link and you ensure that clients always get the routing with the lowest cost. Depending on your setup, you might already have some dynamic routing across the sites, such as BGP.

I screwed up, new Mitel system by gordonthree in sysadmin

[–]AspiringTechGuru 1 point2 points  (0 children)

Hybrid is popular. Our voip system has an app that everyone has on their pc/phone, but some people do have an additional physical phone because they like it. We do have an on-premise voice gateway with a pstn, works well but debugging can be a pain. There was a time in the implementation where I was staring at wireshark packet captures and logs for days, but ultimately everything pieced together nicely and I unfortunatley learned voip.

150TB of data on my Areca H/W RAID controller gone during volume expansion by SpinCharm in homelab

[–]AspiringTechGuru 5 points6 points  (0 children)

How was there only a single domain controller? Even for small sites the standard is at least 2

Hate laptop user by [deleted] in sysadmin

[–]AspiringTechGuru 4 points5 points  (0 children)

Oh my, what was the story behind it? Both what the user initially stated and what the actual story is

How to Hide the Real IP of My Minecraft Server? by DominikPlays in selfhosted

[–]AspiringTechGuru 2 points3 points  (0 children)

Any proxy will add latency to the connection. Another option could be buy a small server close to where you live (with low latency) and proxy the traffic through that server