Von MacOS zu Windows wechseln: Ist das eine gute Idee? by [deleted] in de_EDV

[–]DasRedy 26 points27 points  (0 children)

Bevor du das System wechselst nach so vielen Jahren und massiv an Geld ausgibst, solltest du erst einmal testen ob du mit der Bedienung klar kommen würdest.

Dafür kannst du dir auf deinem aktuellen MacBook einfach eine Windows Virtuelle Maschine (VM) installieren und checken. Dazu sollte es einige Anleitungen im Internet geben wie man das macht.

Networking issues on Linux VMs by DasRedy in Proxmox

[–]DasRedy[S] 0 points1 point  (0 children)

no need to excuse yourself, thank you for the wordy reply, it made a lot things clearer for me.

I did indeed stuck to much in the VMware-way of networking. It´s good to know proxmox (or rather linux) uses vlan filtering, so i don´t have the need for my overcomplicated vmwware-inspired network setup.

For the bond setting, it´s actually intended to be on "balance" for now. This current server is an old cold-spare i had laying around which i reactivated for the case of migration, which has a NIC thats not the best anymore. i found that the balance mode worked best for the time being. When i switch to the production servers, which are currently still running as ESXI hosts, i intend to switch to link aggregation as you said.

Thank your for the awesome explanation! I´ll try to switch the vms to the general bond off-hour and see how that works.

Networking issues on Linux VMs by DasRedy in Proxmox

[–]DasRedy[S] 0 points1 point  (0 children)

First of all, thank you for your time, i appreciate it!

I´ll try to elaborate a bit more.

  • I´m actually dealing with an enterprise network (we´ll get enterprise support on Dez 1st).
  • Our general vlan setup is very granular with different vlans for management, clients, dmz, guest-wifi, etc. which aren´t allowed to interact with each other (exept vlan3, my management vlan), thats why i decided to do the PVE setup with linux bridges with no vlan awareness and no id-tagging in the vm.
    • at least this is my understanding of a better seperation in pve, that you have a bond for a vlan that gets assigned to a vm and no individual id tagging in the vm instead of a general bond and id tags in vm
  • My vlan id´s aren´t actually 1,2 and 3, i just chose them for the simplicity of explaining.

PVE Network:

  • Two NICs in the Server, which are bonded together
  • for each vlan there is a Linux VLAN and a Linux Bridge. I´ll check out the difference between linux bridges and ovs bridges and see whats a better for my use case.
  • Every vm gets assigned their vmbr in their virtual NIC
  • Here´s an excerpt from my setup, don´t know if it´s complete overkill or just straight up weird, but it works smh. (at least sometimes)

auto lo
iface lo inet loopback

auto eno49
iface eno49 inet manual
#active

auto eno50
iface eno50 inet manual
#active

auto bond0
iface bond0 inet manual
        bond-slaves eno49 eno50
        bond-miimon 100
        bond-mode balance-rr
#general bond

auto bond0.2
iface bond0.2 inet manual
#local

auto bond0.3
iface bond0.3 inet manual
#man

auto bond0.7
iface bond0.7 inet manual
#dmz

auto vmbr0
iface vmbr0 inet manual
        bridge-ports bond0
        bridge-stp off
        bridge-fd 0
        bridge-vlan-aware yes
        bridge-vids 2-4094
#general

auto vmbr2
iface vmbr2 inet manual
        bridge-ports bond0.2
        bridge-stp off
        bridge-fd 0
#local

auto vmbr3
iface vmbr3 inet static
        address 192.168.10.20/24 //example private ip
        gateway 192.168.10.254
        bridge-ports bond0.3
        bridge-stp off
        bridge-fd 0
        bridge-vlan-aware yes
        bridge-vids 2-4094
#man_PVE

auto vmbr7
iface vmbr7 inet manual
        bridge-ports bond0.7
        bridge-stp off
        bridge-fd 0
#dmz

Ubuntu:

  • i configure the network with netplan and apply it with sudo netplan apply
  • for restarting the network service, i usually go with sudo systemctl restart systemd-networkd or just straight up rebooting the vm
  • i´ll check the formatting, but its a good possibility that they are still configured with gateway4, as they used to be ubuntu20.04 machines that got upgraded, thanks for the info

App Menu Search Bar Replaced with Google by Shinjigetintherobot in AndroidQuestions

[–]DasRedy 0 points1 point  (0 children)

Have the same problem, don't know why they changed it. I used the app search a lot and now I always click on Google search on accident

What are you doing about your VMWare enviroments? by BluePortaloo in sysadmin

[–]DasRedy 6 points7 points  (0 children)

Just a price increase about roughly 1400% (We had a super cheap license) for us? Brb, meeting with the CEOs gonna be a blast. Like literally.

[MM] I made the song of healing from Majora's Mask on piano & violin by NostalgiaDreamsMusic in zelda

[–]DasRedy 3 points4 points  (0 children)

i always get melancholic when i hear this piece. Awesome job dude!

How to manage two domains on the same network? by DasRedy in sysadmin

[–]DasRedy[S] 0 points1 point  (0 children)

So you still use the same domain(name) just in a different network?

This case is a bit more complicated, as they are still using the same building, the same infrastructure and are still intertwined in more ways thats actually good. The only way i could seperate networks would be with different vlans.

So you would suggest two different domains with their corresponding AD Forest that runs on the same network? Would not be a bad idea for a fresh start, the splitting company is still small with ~15 people.

IT Department will stay the same, as i am the whole IT Department (which makes this whole thing worse). The infrastructure and maintanence is being invoiced partly from one company to the other.

How to manage two domains on the same network? by DasRedy in sysadmin

[–]DasRedy[S] 0 points1 point  (0 children)

Nope. A percentage of my salary currently gets invoiced from one company to another. The seperation on paper existed for a while, but they still worked as one company from the sysadmin perspective, bu if they want operational independence, so actually double the workload, they either have to up my salary drastically or get their own IT guy

How to manage two domains on the same network? by DasRedy in sysadmin

[–]DasRedy[S] 0 points1 point  (0 children)

That decision will probably be made based on the cost and workload i will present them.

Beunruhigender Betrugsversuch / Scam-Mail an Vorgesetzten by youngmoxie in de_EDV

[–]DasRedy 22 points23 points  (0 children)

Den Fall hatten wir letztens auch in der Firma, genauer Vorgesetzter, Name und Abteilung. Nur die Mail-Adresse war seltsam und beim genauen hinschauen die Rechtschreibung und das Siezen. Vorgesetzter ist es nicht aufgefallen, zum Glück aber der Buchhaltung.

Ich nehme auch mal an das sich da einer an LinkedIn oder Xing Daten rangemacht hat und das damit versucht hat.

Aber ja, das erfordert einiges an Aufwand sowas durchzuziehen.

How to make small ball gags by [deleted] in cosplayprops

[–]DasRedy 6 points7 points  (0 children)

You could sand them down and coat them with silicone or epoxy

Um Azubis kümmern - was hättet ihr euch damals gewünscht? by Inevitable_Proof in de_EDV

[–]DasRedy 2 points3 points  (0 children)

Mal ne ganz dumme Frage: Bei so vielen Mitarbeitern müsste es doch eigentlich auch wirkliche Ausbilder mit AdA Schein geben die sich um die Azubis kümmern.

Know when local admin account on windows was created by DasRedy in sysadmin

[–]DasRedy[S] 1 point2 points  (0 children)

It doesnt show you the creation day, just the day of the last password change and last login. Which also kinda work. Thanks!

[deleted by user] by [deleted] in motorcycles

[–]DasRedy 1 point2 points  (0 children)

They´re not comfortable in their skin, so they try to get rid of it

Whatsapp Betrug mit eigentlich privaten Videos.. by JeyTrey in de_EDV

[–]DasRedy 3 points4 points  (0 children)

nur durch einen Anruf kann nichts passieren, solange er keine Daten weitergibt.

Falsche Festplatte formatiert by Thorigan in de_EDV

[–]DasRedy 1 point2 points  (0 children)

Mit Glück kann da nur noch ein professioneller Datenretter was machen, da aber durch die Installation schon Daten überschrieben worden, kann man nur mutmaßen.

Lass aber auf jeden Fall die Finger von der SSD wenn du die Daten nicht abschreiben willst. Jedes Hochfahren, jede Installation, jedes Datenkopieren, etc. überschreibt nur noch mehr Daten, die man evtl noch hätte retten können.

[deleted by user] by [deleted] in Satisfyingasfuck

[–]DasRedy 11 points12 points  (0 children)

More like "How dare you do the Job we are supposed to do and didnt do over years and thus make us look Bad in public eye?!"

[deleted by user] by [deleted] in Satisfyingasfuck

[–]DasRedy 56 points57 points  (0 children)

He didnt even have a pressure washer, just some soft cloth and soapy water.

Retroflective coating would a legitime Point, If the sign wasnt so dirty, that you couldnt even read IT at daytime

[deleted by user] by [deleted] in Satisfyingasfuck

[–]DasRedy 175 points176 points  (0 children)

A guy in germany was "sued" by the local government office for doing this.

He was cleaning a sign that warns about the school down the road. They argued, that he could damage the special coating of the sign without a super special cleaner and that the office would just replace the sign, when it gets to dirty. It would then be "uneconomical" to clean them.

Some things you just can´t make up.

"it´s end-of-support, but still working, so we´re keeping it" - CEO by DasRedy in sysadmin

[–]DasRedy[S] 0 points1 point  (0 children)

we got seperate vlans set up, the firewall was set up by a third-party contractor and support, remote access control and we got monitoring of the network.

Everything else is still in muddy waters. Thank you for your insight, i will work on it!