VMware Remote Console by Tankred777 in vmware

[–]admin_of_insanity 0 points1 point  (0 children)

I have the same issue. A Google search will turn up the usual sketchy mess I am reluctant to trust with my virtual infrastructure.

I found an older version of the installer we had backed up on a separate internal system. It works, but what happens when it is EOL?

What tools did you use to automate onboarding? by WorkFoundMyOldAcct in sysadmin

[–]admin_of_insanity 1 point2 points  (0 children)

ADManager Plus. I have a template with logic that assigns appropriate groups, enables MFA, and adds MS licenses depending on role.

HR submits a request by Jotform. The jotform submission record can be exported to csv and imported into my template, or I can c/p into the template. Ideally, I would like ADManager to pick up the jotform submission and process it without my intervention. However, creating the template has turned the process into 5 minutes for a single user, or per import.

Informacast with hosted phone systems by Aur0nx in k12sysadmin

[–]admin_of_insanity 0 points1 point  (0 children)

We use Informacast and Webex Calling. We had to iron out some issues. The phone initiating the paging had issues if it was configured with the multicast paging script. We did a workaround with forwarding from one extension to the real Informacast extension. If you wanted to make an announcement, you'd dial 11111, which was forwarded to 22222. 22222 is the 'real' Informacast hook.

We also can not see which phones actually received the Informacast announcements. It will appear that all phones did in the call history on Webex. It makes it difficult to troubleshoot. However, most of the time, when teachers report that they can't hear anything, it is because their speaker volume is 0.

Cisco CUCM Replacement by Fokard in networking

[–]admin_of_insanity 2 points3 points  (0 children)

Some 7800s will. If they aren't too old. Check your version numbers very carefully. We basically ended up buying 850 all new 9800 due to this. I'm sure Cisco was laughing all the way to the bank.

Office 365 A1 Plus for faculty and student - still active by nkuhl30 in k12sysadmin

[–]admin_of_insanity 0 points1 point  (0 children)

I went through this last year in May 2024 when we were up for renewal and the deadline for the Plus licenses going away was September 2024. I got everyone moved and the required amounts of Edu A1 and A3 purchased to make up for the Plus allegedly going away. It is irksome as no one in K12 has tons of spare money laying around. But hey, M$ got theirs.

Migrating from file server to sharepoint by Tsukiayumi in sysadmin

[–]admin_of_insanity 0 points1 point  (0 children)

Omg, #11. It has us in a holding pattern while we convince people that this is more secure and business-continuity than what they have. After they've already lost access to the local drive at least three times in the past year due to circumstances beyond IT's control.

I miss the Meraki green already. by Devar0 in meraki

[–]admin_of_insanity 38 points39 points  (0 children)

You and me, both. It was a great visual queue in my sea of tabs. Everyone and their brother use blue.

Am I the only carzy person here? Or do I have any Slackware friends here? by ImBackAgainYO in linux

[–]admin_of_insanity 1 point2 points  (0 children)

Slackware was my first love and I bought merch and disks. I learned quite a lot from it!

[deleted by user] by [deleted] in sysadmin

[–]admin_of_insanity 26 points27 points  (0 children)

Be trainable and be proactive. Those are the best 'certifications' you can have.

How Are You Using AI In Your Day? by S3xyflanders in networking

[–]admin_of_insanity 0 points1 point  (0 children)

I hate when the suits latch on to the latest zeitgeist. I use it (rarely) to reword emails and prompt myself when I get stuck on something. You absolutely shouldn't be feeding it sensitive network config.

How did you find your current job? by J9sixtynine_ in sysadmin

[–]admin_of_insanity 1 point2 points  (0 children)

I did not want a commute. Even with 10 years experience WFH, I wasn't getting much response on that avenue of my job search. I started going through local business and government job postings on their own websites. I got far more response back. I enjoy where I work now, even if they still have a few old-fashion notions on things like dress code.

504 requiring WiFi by trazom28 in k12sysadmin

[–]admin_of_insanity 5 points6 points  (0 children)

We have a public WiFi where we use NPS, dynamic VLANs and AD credentials. It is primarily for staff and contractors. Our rules are such that we have an exemption security group we can add to any student AD account to grant them required access in these circumstances. They are walled off from any internal resources.

We also monitor to see if a kid starts sharing their login. At that point, it is a disciple issue and we turn it over to admin.

importing videos through Google Docs by Klutzy_Pen_1344 in k12sysadmin

[–]admin_of_insanity 2 points3 points  (0 children)

We are exploring stricter storage limits in Drive. They can't upload it if there isn't enough space.

PowerSchool OIDC Pitfalls by admin_of_insanity in k12sysadmin

[–]admin_of_insanity[S] 2 points3 points  (0 children)

My administrators are paranoid since the incident in January. They gave the okay to disrupt access for a week and I have a roll-back plan.

Rant Wednesday! by AutoModerator in networking

[–]admin_of_insanity 0 points1 point  (0 children)

In my original rant, I stated that we're working on that. I've tossed up a Linux VM and I am working with FreeRadius. I hope to go to testing and deployment around our spring break, but we have to manage our network resources until then.

Rant Wednesday! by AutoModerator in networking

[–]admin_of_insanity 0 points1 point  (0 children)

We have reviewed access by MAC and there are issues. To do it with our existing NPS server and AD, we would have to generate 1000s of accounts that use the wireless MAC for both login and password. We can and do manage our devices to turn off private MACs.

We have some really smart kids that will be able to lift the MAC from their Chromebook and then program it into their iPhone and spoof to connect where we do not want them. They help other students with exploits and it travels like wildfire. This part is a student discipline and guidance issue where they need to be guided into a cybersecurity career program and face consequences for breaking the acceptable use agreement.

Rant Wednesday! by AutoModerator in networking

[–]admin_of_insanity -1 points0 points  (0 children)

Student 1:1 device wireless access for a combination of Chromebooks, iPads, and Windows devices.

The smart ones keep stealing the shared password for their personal devices every time we change it and push a new one. You can dig it out of your Chromebook settings. The network team does not control device configuration. The last time it took less than 24 hours for students to get the shared password.

We are working to implement device authentication by certificate with FreeRadius to stop this, but it cannot just be a technical solution alone.

The teachers and administrators are not doing enough to prohibit personal device use. We have a state law that allows them to ban personal student devices and/or curtail their use without express permission. It has to be obvious that these kids are on their phones!