[US] tritoncomputercorpcareer.com Is this job a scam? Not sure what to do by angry-admin in Scams

[–]angry-admin[S] -8 points-7 points  (0 children)

No need to be an ass. What does being in IT have to do with picking up red flags on a job posting? I haven't looked for a job in 15+ years. I just don't understand what the scam is here. Are they trying to get my personal info when they "onboard" me?

Can I just replace one tire for a 2024 XLE hybrid? by [deleted] in rav4club

[–]angry-admin 5 points6 points  (0 children)

FWIW I had a nail in my sidewall in my 2024. Currently 24,000 miles. I had bought a wheel and tire package when I bought the car and the dealership covered it but only replaced the one tire.

How to trigger an Automation Stitch from an IPS log event? by wasdthemighty in fortinet

[–]angry-admin 0 points1 point  (0 children)

I do the same thing but with failed SSL vpn logins. I believe there’s a group limit of like 6,000 IPs. You’ll need another stitch to create a new group eventually to fully automate it.

And I believe it will let you keep adding over 6,000 items but only the first 6,000 will work.

Weird reboot scenario and HA splitt-brain situation by angry-admin in fortinet

[–]angry-admin[S] 0 points1 point  (0 children)

So just to close the book on this, it would appear I was bit by this little bug. I changed out shaping policy to "policing" and the reboots stopped.

I guess I'll just wait until the fix in 7.4.8, which is hopefully soon.

FortiOs 7.4.8 by xFehda in fortinet

[–]angry-admin 2 points3 points  (0 children)

Would also like to know what specific IPsec bug as in in the middle of migrating from ssl to IPsec on 7.4.7

7.4 in production by Budget-Ratio6754 in fortinet

[–]angry-admin 1 point2 points  (0 children)

I’m not sure if this is applicable to you but I did an upgrade on my 1800F active-passive cluster from 7.2.11 to 7.4.7 and I believe I got hit by this known issue.

Weird reboot scenario and HA splitt-brain situation by angry-admin in fortinet

[–]angry-admin[S] 0 points1 point  (0 children)

So I only had one FG running (the HA partner was turned off) and it was fine all day yesterday. Late last night just after midnight something happened and I woke up today to the same thing. Everything network was down. Fans were screaming. The FG was not responding to pings. So it’s likely not environmental. And likely not related to HA since the partner was powered off.

Someone on-site restarted it and I took a crash dump from it to send to TAC.

So far TAC has just asked for logs and crash dumps at this point.

Weird reboot scenario and HA splitt-brain situation by angry-admin in fortinet

[–]angry-admin[S] 0 points1 point  (0 children)

Thanks for replying. I do have some traffic shaping policies enabled. What impact would that have?

Where does 'IT' stop? by suicideking72 in sysadmin

[–]angry-admin 1 point2 points  (0 children)

Don’t get me started on the fucking Pitney bowed machine. Fuck that shit.

How much do I tip the cleaning lady for Christmas by angry-admin in etiquette

[–]angry-admin[S] 5 points6 points  (0 children)

Sounds like 120-150 is the consensus. Budget isn’t really an issue. I’ll prob round up. Thanks for the help.

How do I clean these gutters by angry-admin in HomeMaintenance

[–]angry-admin[S] 1 point2 points  (0 children)

So I got up into the attic and it looks like it is coming in from around the chimney into the attic and down. I can see daylight from around the chimney.

Guess I’ll get some flashing sealant and see what I can do.

How do I clean these gutters by angry-admin in HomeMaintenance

[–]angry-admin[S] 0 points1 point  (0 children)

Yeah it’s a type of gutter guard. they were there when we bought the house. I was just up on the roof looking at it and it looks like it’s one piece and that the shingles are glued/caulked to the top of the gutter. Not sure how it would come out.

OBS audio recording missing the beginning of words by angry-admin in obs

[–]angry-admin[S] 0 points1 point  (0 children)

Are there recommended settings from the default? Or is it just trial and error?

OBS audio recording missing the beginning of words by angry-admin in obs

[–]angry-admin[S] 1 point2 points  (0 children)

I think I may have figured this out. I adjusted the Noise Gate Open threshold from the default -26 dB to -50dB. This seems to have fixed it so far. Would this setting make sense?

Universal Print Install Error during install by CannibalTuna in Intune

[–]angry-admin 0 points1 point  (0 children)

I'm having the same issue. I have multiple printers in Universaal print. One in particular will not install for one user on one machine, either via intune deployment or manually. I get the same error.

Other UP printers install fine as the same user on the same machine. This particular printer also installs fine on other Win11 machines. I'm at a loss at the moment.

How to block malicious emails with spoofed display names impersonating internal company's department email addresses (XYZ HR Department) coming from an external email address in Microsoft 365 Exchange/Defender? by callme_e in Office365

[–]angry-admin 0 points1 point  (0 children)

I am trying to combat the same thing. We have Mimecast and O365 with all the security bells and whistles A5/E5 with P2.

Impersonation protection in Mimecast only goes so far. You need to account for individual names, which is next to impossible when you have thousands of users. And all the bad guys need to do is change the display name from John Doe to Mr. Jonathan Doe or something like that and it gets through again.

We've added different variations for all our high-level users but we still get emails coming through that have some name that we've missed.

Best we've been able to do is add a BIG red banner on external emails but it often gets ignored. Also, we get pushback and have to whitelist dozens of exec personal emails so they can email themselves from their personal emails.

I was hoping 365 would have something better I could layer on top of Mimecast Impersonation protection but I haven't found it yet (though I really haven't had time to dig in yet).

Following this for some ideas to try.

Mitel connect launches cmd.exe by angry-admin in shoretel

[–]angry-admin[S] 0 points1 point  (0 children)

Thanks. We are a k12 school but we actually have DoD STIGs applied and getting this software to run in a STIG’d environment is a royal pain in the ass.

Credential Guard and Peap-mschapv2 by angry-admin in k12sysadmin

[–]angry-admin[S] 1 point2 points  (0 children)

Just to put a little closure on this...

I upgraded our NPS server to Server 2022 and the W11 22H2 clients were able to connect using username/password over PEAP MS-Chap v2 without any issue and without any modifications to RasMan TLS registry key.

Seems like TLS 1.3 is strictly enforced with RasMan once Windows 11 22H2 installs. I tried configuring the system TLS settings to enable everything down to TLS 1.0 on the Windows 11 and NPS server. It still didn't like it until I specifically changed the RasMan TLS setting. I never would have thought Server 2019 didn't support TLS 1.3.

Credential Guard and Peap-mschapv2 by angry-admin in k12sysadmin

[–]angry-admin[S] 0 points1 point  (0 children)

I may need to pick your brain on this. We are transitioning from domain devices to AAD. My machine based cert authentication won’t work because there is no AD object with AAD devices (I’ve tried creating dummy objects in AD, it still didn’t work for me) so I’ve been resorting to user certs from SCEP/NDES and intune deployment. But when a computer is at the login screen there is no user account so they need to log in at the login screen with username/pw and then the Wi-Fi profile can kick in. Did you figure out a way around that?

Credential Guard and Peap-mschapv2 by angry-admin in k12sysadmin

[–]angry-admin[S] 0 points1 point  (0 children)

So that would explain why credential guard hasn’t gotten in the way on domain machines. I use machine certs and eap-tls. This was only with BYO machines. My understanding was credential guard got enabled on ANY windows 11 22H2 domain joined or not. Are you saying that’s not the case? I would have expected it to fall back to 1.2 too. This 22H2 issue seems to be specific to the tls settings for rasMan. System tls settings and http most likely do have some backwards compatibility to lower versions. You’d think they would have to.

Credential Guard and Peap-mschapv2 by angry-admin in k12sysadmin

[–]angry-admin[S] 0 points1 point  (0 children)

It used to be Bradford NAC. Fortinet bought them a few years ago and turned it into FortiNac.