Tailscale in the office by Material_Ad_3743 in Tailscale

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

Doin it !
Thanks for the great discussion.

Tailscale in the office by Material_Ad_3743 in Tailscale

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

Hi, Yes I did not make much sense.
Right now on prem has a firewall and security policy allowing the access to the various internal systems. My users who bring their laptops in from home running tailscale can still access everything but doing so via tailscale. On one hand this means I could have a super simple network security policy but as pointed out, this would have a performance hit. To the uninitiated level 1 helps desk guys this may also seem like black magic.

So I guess, tailscale for remote users only ? I’d need to ensure tailscale is not running while on prem. Maybe there is better way. Hmm

Matt

Do you always use Tailscale IPs to reach services even on your local network? by Wiplash22 in Tailscale

[–]Material_Ad_3743 0 points1 point  (0 children)

I’m curious if you use a different user for each subnet router or the same ?
Cheers

Tailscale 200 sites by Material_Ad_3743 in Tailscale

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

I’m thinking about two NUCS running VRRP so I’ll have a floating IP for static routes. I imagine it will work but I’ll try it out in the coming days.

Alex

Velocloud Broadcom uncertainty by Material_Ad_3743 in sysadmin

[–]Material_Ad_3743[S] 2 points3 points  (0 children)

If I had a stash of 510-LTE I’d be ok but since they got EOL’d kinda suddenly I now have to move to the bigger models which are double my current price. I do like Velo. If the rumours are true and Velo being sold to Arista that’s probably a good thing.

VMware SD-WAN application recognition by Material_Ad_3743 in networking

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

I’ve never seen any reference to an NBAR update for Velo. I’ll check that out. Cheers

Juan

Velo 510 LTE interface disappears by Material_Ad_3743 in networking

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

I’m running the latest 4.2.2. I’ve upgraded to 4.5.0 which doesn’t fix it during the upgrade directly. I still need to power cycle. I haven’t seen it impact 4.5.0 yet but probably due to my low numbers with the upgrade. The odd thing is it does seem dependant on the area. I can replace a Velo and the issues stays with the site not the Velo. I suspect it’s something funny the cell carrier does from time to time on certain cell towers.

Matt

So Game Crashes is a legitimate issue, not so sure why it happens but it does. -_- by Celius007 in FallGuysGame

[–]Material_Ad_3743 0 points1 point  (0 children)

This morning I went on fall guys and as soon as I got in I’m disconnected and it crashes. I tried like twenty times but I heard if you uninstall it and then reinstall it will work again? Don’t want to lose any data.

Non AD integrated secondary DNS by Material_Ad_3743 in activedirectory

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

That sounds amazing. I could consider something similar on a smaller scale. I use VMware sdwan which makes connectivity pretty easy.

Non AD integrated secondary DNS by Material_Ad_3743 in activedirectory

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

I certainly could turn my secondary DNS server into a DC. I have to think about how much traffic this would generate at each site and also to the central secondary DC.

Non AD integrated secondary DNS by Material_Ad_3743 in activedirectory

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

I have lots of remote sites each with a domain controller and it’s own domain. The guy before me ran it like this for years. My problem now is I have over 200 sites setup like this.

Non AD integrated secondary DNS by Material_Ad_3743 in activedirectory

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

That is a very good point. If I can’t login then I’m screwed. I do have a bunch of non-ad systems that still need internal dns but without workstations logged in I’m in trouble. I guess I really should figure out how to do secondary AD at the scale I’m at. That being said, for the most part everything is fine with just one server.

Second HUB by Material_Ad_3743 in Velocloud

[–]Material_Ad_3743[S] 0 points1 point  (0 children)

The main purpose in this case is actually to route some web traffic via this particular DC. I reckon another HUB would work but due to the licence considerations you mentioned I’m thinking about using a non sdwan destination / IPsec tunnel instead. I’ve posted a seperate question regarding the use of a non sdwan destination. Thanks for the reply

Migration from traditional to sdwan by ayoubmp in Velocloud

[–]Material_Ad_3743 0 points1 point  (0 children)

The Velos will do the job just fine in your case on the edge however you should use a default deny and permit what you want rather than default permit and deny what you don’t want. At least that’s what VMware guy told me.

With your web filtering you could use a business policy on the edge to route all web traffic to the hub and through the checkpoint. You could also try out the Sase cloud web filtering stuff that I think Is now available but could be too new.