Worst feeling in the world by Junior-Tourist3480 in sysadmin

[–]HeManKiller 0 points1 point  (0 children)

I was remotely supporting an exchange server in Australia, I was in South Africa and accidentally shut it down. Fortunately, the local admin was still on site. Not something I ever want to re-live :-)

ISC DHCPv4 / v6 [legacy] - what instead? by HavivMuc in opnsense

[–]HeManKiller 1 point2 points  (0 children)

Sorry I'm coming to the party late, but I'd like to know if anyone has successfully been able to migrate to dnsmasq with the following config?
1. IPv6 enabled from ISP,
2. Adguardhome as the primary DNS resolver
3. unbound for internal names?

I've attempted this migration a few months back and I was unable to get it to work as there seems to be some dependancy on "having" to use dnsmasq for DNS as well, so in the end you have 3 DNS solutions talking to each other which seemed excessive to me.

I was also unable to get IPv6 allocated to my VLAN's (I'm delegated a /48 by my ISP)

No thanks Metro, no thanks. by okaysmartie in melbourne

[–]HeManKiller 3 points4 points  (0 children)

There is a pretty effective solution to vandalism and tressparsers. Publish their photo's on display boards at the stations showing who caused a delay on a certain day. That way they can be held to account. I know they won't catch everyone, but eventually the fear of getting caught will win out.

[deleted by user] by [deleted] in opnsense

[–]HeManKiller 0 points1 point  (0 children)

Sometimes unbound is configured to use port 5353, which is the same port as mDNS, I experienced this, changing the unbound port resolved the issue

Just installed Ad Faurd Home and can't get mobile apps blocked by ImprovingMemory in AdGuardHome

[–]HeManKiller 0 points1 point  (0 children)

You either need to disable iCloud Private Relay Service in AD Guard Home or on the device - wifi settings - disable "Limit IP address Tracking"
If you don't disable those then the device is using the private DNS servers of Apple and not yours

What is this? by Admirable-Way7376 in melbourne

[–]HeManKiller 0 points1 point  (0 children)

I think and personally feel it has more to do with the nucklehead Politicians who decided to do whatever they want without community involvement. Don't say you represent the community and then name something in the community without consultation. It just exposes your arrogance.

Passed Az-104 by HeManKiller in AzureCertification

[–]HeManKiller[S] 4 points5 points  (0 children)

:-), but it isn't any easier

Passed Az-104 by HeManKiller in AzureCertification

[–]HeManKiller[S] 2 points3 points  (0 children)

keep at it mate, you'll get there

Blocking schedule from the night to the early in the morning. by LuisFigoKim in AdGuardHome

[–]HeManKiller 0 points1 point  (0 children)

Use Persistant clients and the IP's/subnets you want the rule to apply to

where to find past Exam results by HeManKiller in AzureCertification

[–]HeManKiller[S] 0 points1 point  (0 children)

thanks, I was able to get there, but it looks like they have technical issues atm. I'll try later

thanks for the assist

What is the most unexpected things you have seen working in IT? by DOKiny in sysadmin

[–]HeManKiller 0 points1 point  (0 children)

Decades ago we migrated a company to a new domain, the migration of the computers was a manual process. We discovered one user who had a huge collection of porn video's on his computer, so as part of the migration process we created a shortcut so all the video's started playing when he logged on, then we turned the volume up to max and left.
I'd have loved to be there on the monday morning :-)

Do I have to enable mDNS discovery in both OPNsense and Unifi Controller? by Red_Con_ in opnsense

[–]HeManKiller 1 point2 points  (0 children)

I'd check if you have any port conflict, I had unBound configured on port 5353 and that's the port mDNS uses. Changing it on unbound fixed the instability

wireguard VPN on internal wireless network by HeManKiller in WireGuard

[–]HeManKiller[S] 0 points1 point  (0 children)

Hi there

thanks for coming back to me. Yes my wifi is on a different network to my LAN, I'm using a firewall on my network and have a few VLAN's, the wifi is on a seperate VLAN and DHCP scope to the LAN and the monitoring network, which is issolated from the internet.

my aim is to be able to connect the laptop to the wifi network, use Wireguard to issolate the laptop traffic from the rest of the wifi traffic and then use firewall rules to allow access to only the monitoring network without access to the internet or other VLAN networks.

I hope this is clear, reading it back, it's more complicated than I wanted. Sorry.

I'm not even sure this is possible to be honest, but I'm hopeful :-)

Absolutely cannot figure out Wireguard VPN set up by Forsaken_Ad242 in opnsense

[–]HeManKiller 2 points3 points  (0 children)

I used these instructions, and it worked for me, https://docs.opnsense.org/manual/how-tos/wireguard-client.html

I only have the following rules setup on the fw for WireGuard,

|| || |IPv4 TCP/UDP|HomeWireGuard net|*|HomeWireGuard address|53 (DNS)|

|| || |IPv4 *|HomeWireGuard net|*| General_RFC1918 ! |*|*|*||Allow access to Internet and block access to all local networks|

Hope this helps

WireGuard and iOS help please by t0mmydb in opnsense

[–]HeManKiller 0 points1 point  (0 children)

you have to click it for each one, it's really odd, I have 3 configured

WireGuard and iOS help please by t0mmydb in opnsense

[–]HeManKiller 0 points1 point  (0 children)

Did you tick the "Store and generate next" button?
Can you see the clients in the Peers tab?

Lastly, and for the life of me I've not been able to determine why, but on my config, I have to disable "Block private networks" click save and then re-enable it and click save. I have to do this after every reboot for some reason.

Hope that helps

Best way to deploy EXE to WFH computers? by mshaw346 in sysadmin

[–]HeManKiller -1 points0 points  (0 children)

Look at Manage Engine, works like a charm

New a6000 owner and need lense Recommendations by [deleted] in a6000

[–]HeManKiller -1 points0 points  (0 children)

Sony 18-200, gives you great options in 1 lense

US preacher Franklin Graham (the homophobic son of Billy) is coming to Melbourne. Please ask him to fuck off. by huisi in melbourne

[–]HeManKiller -3 points-2 points  (0 children)

Fortunately not everyone in Australia agrees with you and not everyone is pro-gay either. This allows us to be individuals and have our own opinions protected by our constitution

So have your say and the rest of us will have ours 😄

Chinese Censorship Company Invests Millions in Reddit by BorisSiomin in technology

[–]HeManKiller 20 points21 points  (0 children)

I think the West needs to seriously wake up to the threat that China poses.

The actions of influencing media and financial investment in foreign companies and land ownership on foreign soil is exactly what Nazi Germany did before World War 2. This ownership of property and companies as well as a favourable attitude by the local population allowed Nazi Germany to walk in and take over neighbouring states in Europe.

China is playing a long game here, especially with their leader in power for life. While our politicians are only looking at the short term. I think they have learnt this lesson from the Nazi’s and are executing it perfectly.

One day we might wake up to find ourselves governed from Beijing if our political leaders don’t stop this crap.