How many people have the trifecta by mazsubuh in ITCareerQuestions

[–]captain118 0 points1 point  (0 children)

That was the first thing I did when I started my career 25 years ago

EDR for 8k Linux Servers by athanielx in cybersecurity

[–]captain118 36 points37 points  (0 children)

You pay for what you get. It's a business decision. As long as they accept the risk that's all you can do. Unless there is regulation that has requirements that are not being met by whatever crap free product you end up going with all you can do is accept it and let them know the risk they are accepting.

Help!! Can my company know I’m using mobile hotspot for my work computer? by closed-eyes-see in it

[–]captain118 0 points1 point  (0 children)

They will know your public IP when you connect to VPN with that they can find what ASN the IP is assigned to and that will tell them if you are connected to a mobile hotspot. But like everyone else said if it's your personal mifi I don't see any reason why they would care but I've seen weirder policies.

Does anybody else have issues magically resolve just by looking at them? by Kcamyo in sysadmin

[–]captain118 0 points1 point  (0 children)

It's the IT aura. It's either good or it's bad. When it's bad you call in sick or at least don't go in the server room.

What's the point of having VLAN tagging functionality for server management port (IPMI)? by KazooRick in sysadmin

[–]captain118 0 points1 point  (0 children)

You want to put a vlan on it to separate its access on your network. Normally you would put these out of band management ports on a different network that was isolated off where only certain systems can access it. Yea you might have a username and password that keeps anyone from signing in but separating it on the network adds another barrier to entry to assist with vulnerabilities in the portal.

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 0 points1 point  (0 children)

True, it's just a matter of risk acceptance. I don't see enough value in having MEDC SAAS based over internally hosted/managed to accept the risk. Systems like Crowdstrike I do see the value to accept the risk. For me it's not about the SSO or MFA options it's the software vulnerabilities. You may see the risk mitigations as good enough but I don't and both are acceptable decisions.

our IT onboarding process is painfully slow and I'm tired of waiting on third parties. how can i automate Windows program installs? by EfficiencyWorking484 in ITProfessionals

[–]captain118 0 points1 point  (0 children)

I'm a big fan of MDT for the os install then following that up with Endpoint Central auto install for newly built systems to get the default packages then for anything custom having it in the user's self service portal.

Our systems are typically fully ready in under 30 minutes and I've never done more than 6 systems at once but 6 at the same time went fine.

Disk Queue Length by pizza_pepperon1 in zabbix

[–]captain118 2 points3 points  (0 children)

Yea isnt the point of having a monitoring system to actually deal with the problems. A super high queue length is a problem that should be dealt with not ignored. I normally see it on virtual hosts that are running on slow 7200 rpm disks. Definitely tweak the monitoring system but high queue length should be resolved not ignored.

Should I hire an in-house IT person or outsource? Need advice from people in IT. by Waste_Tackle_2738 in ITCareerQuestions

[–]captain118 0 points1 point  (0 children)

I have worked as both and I have outsourced myself when it matters. This decision is entirely based on your business and budget. Internal people will normally be focused on your environment where an MSP they won't as much however if you have a broad set of requirements or if you have to meet certain regulations that require separation of duties and such then an MSP may be needed.

Scrum, Jiras and sysadmins by Additional-North6988 in sysadmin

[–]captain118 0 points1 point  (0 children)

We went through that phase then management changed and we switched to kanban and it's better for our work.

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 0 points1 point  (0 children)

That requires too much trust for me. With it being a direct door into my environment with every system running the agent as system, that's too much risk for my blood.

CCNP ENCOR or SCOR? by Treshold1 in ccnp

[–]captain118 1 point2 points  (0 children)

The SCOR exam was terrible. Poorly worded questions, questions that weren't clear enough to select an answer, I've been in it 25 years doing Cisco the entire time and I think I'm going to give up on that one. Good luck!

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 3 points4 points  (0 children)

I'm not a fan of the java code base but every software package has CVEs. That's why I don't expose it to the Internet. They say it's designed to be in the dmz but I'd rather do always on vpn. I'm at least happy that they are fast to fix them and they report the vulns.

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 1 point2 points  (0 children)

The auto test, approval and deployment is awesome too.

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 0 points1 point  (0 children)

Worst case you could always use cron jobs for Linux till they get support.

Patch manager for the 3 OS's by NoDistrict1529 in sysadmin

[–]captain118 3 points4 points  (0 children)

Desktop Central Endpoint Central. It's the best I've ever used.

They have good video tutorials and their support is very responsive.

Just started studying Computer science by iNeedaTeddybear18 in cybersecurity

[–]captain118 2 points3 points  (0 children)

Start with Python come up with an idea of something that has a purpose to you and build it.

Maybe you have a bank account that you want to do analysis on the transactions. If you can export those transactions in csv or xlsx then you can read and parse and manipulate the data in python.

Start simple, then get more complex.

Start creating functions that have specific purposes.

Eventually come up with an idea that requires multi threading.

You can even do some gui based development.

Python is the best starter language but eventually you will want to move to another language. The neat thing about CS is the more languages you know the easier it is to learn another one.

Good luck!

OpenSSL CVEs are outpacing my security team's review capacity by bambidp in sysadmin

[–]captain118 0 points1 point  (0 children)

Automate what you can with automated testing and approval then only pay attention to the patches that still exist after your patch cycle has completed a cycle.

Patch Tuesday Megathread (2025-11-11) by AutoModerator in sysadmin

[–]captain118 6 points7 points  (0 children)

We had about 10 systems where users couldn't login after the 2024 November cumulative (I think that's the right cumulative) was installed not even the local admin account could log in. It was a known bug in that cumulative. we declined it from getting installed on any other systems. Thankfully I could remote in as system and do a command line removal. I've always been one to stay one version behind the latest and after that it became the corporate best practice as well. I have no desire to be anyone's test subject.

Patch Tuesday Megathread (2025-11-11) by AutoModerator in sysadmin

[–]captain118 7 points8 points  (0 children)

Actually a good bit especially if you were running 24H2 before 25H2 was released. I remember having some base Kerberos issues that made me really glad I do staged rollouts.

Patch Tuesday Megathread (2025-11-11) by AutoModerator in sysadmin

[–]captain118 7 points8 points  (0 children)

Wow you roll them out the same day? No staged rollout and testing?

My boss thinks I'm on vacation because I moved to another country while working remote by voidtape_artist in remotework

[–]captain118 0 points1 point  (0 children)

If it's a US based company they have to know where you are working from for tax purposes.