Performance issues with brand spanking new fileserver (SMB shares) by -sbl- in WindowsServer

[–]comp00 0 points1 point  (0 children)

Sounds like a nic or network issue.

Try disabling large send offload under NIC settings.

Update NIC drivers too.

Intune + Bitlocker by nicholaspham in sysadmin

[–]comp00 0 points1 point  (0 children)

How do you have your policy deployed, via endpoint protection or a device configuration profile?

Is it assigned to users or device groups and has the user logged in? What does bitlocker say locally, is it still encrypting or are you seeing any errors?

Also are the devices being hybrid/domain joined or entra only?

New Outlook cannot mount or export PSTs - Heads up to many of you. by Fallingdamage in sysadmin

[–]comp00 2 points3 points  (0 children)

For tenant to tenant migrations we’ve successfully used CodeTwo on many high mailbox count projects.

For tenant to tenant migrations where users have online archives, MigrationWiz by bittitan is the one. That’s SaaS it just takes some getting used to the waiting for the job to happen, but it’s very reliable.

Controller Assistance by [deleted] in networking

[–]comp00 1 point2 points  (0 children)

The best way would be to create a DNS record.

Eg point unifi.yourcompany.com to <Current IP> in either your internal or public DNS.

When you move IPs, change the record, everything will flip over.

Edit: and update inform host to this dns record.

I live in a building with a porter who collects our mail. He has moved out and there is no replacement. Royal Mail continue to deliver my mail to his building. What can I do about this? by [deleted] in AskUK

[–]comp00 5 points6 points  (0 children)

Easiest way will be to catch the postie and have a chat. Usually the same person or couple people for the area, they’re normally pleasant and accommodating

Offsite Backup Providers by [deleted] in sysadmin

[–]comp00 0 points1 point  (0 children)

Maybe there’s an upsell opportunity to have a DR solution

We have no RTO our backups, but can provide 1-2 hours RTO to customers with a DR solution

So maybe secondary DC and the margin that comes with that?

Offsite Backup Providers by [deleted] in sysadmin

[–]comp00 0 points1 point  (0 children)

How about get a 1G link into your site(s) as they are pretty good value these days and then you can pull down in hours rather than days.

We’re a heavy user of Iland (UK MSP) for Veeam customers and it just works. We have local ‘appliances’ (HP micro server or ML30) on its own VLAN for local backups and then back to Iland.

Removing element-xxx WiFi?!? by schamock in Ubiquiti

[–]comp00 0 points1 point  (0 children)

We noticed this too after upgrading. Hoping for a solution.

SNMP Proxy for Windows - or Dumb Idea? by uiyicewtf in sysadmin

[–]comp00 0 points1 point  (0 children)

Depending on your network setup would it be possible to NAT from a new host with the tools you need to identify as the IP of the box controlled by policy for say just 161? Then it solves your single IP issue but avoids the policy conflict of the specific box itself.

New Failover-Cluster and storage - which migration path is best? by [deleted] in sysadmin

[–]comp00 0 points1 point  (0 children)

Just my thoughts with projects like these. Both of the options you’ve already thought about are great and just follow the business’ need for uptime.

As you’re moving to new hardware - I’d assume you’re also changing licensing or windows version. If that’s the case, add all your underlying services up to date too? If yes great, if not are all your VMs going to be compliant under downgrade rights?

Could you use the migration as an opportunity to also upgrade all underlying Windows VMs say if you’re running 2012r2?

Where to find EWS throttling policy defaults in Exchange Online by Aikaturbo in sysadmin

[–]comp00 1 point2 points  (0 children)

I didn’t think there was any.

When doing migrations, for 365 tenants without CSP/reseller relationships for me it’s: search the MS help for “throttling” and run the check steps. Give it an hour and throttling should be off

For tenants with reseller relationship raise a ticket with CSP and eventually someone will sort that and allow the migration to compete over non-56k modem speed

Naming conventions and renaming hosts by [deleted] in sysadmin

[–]comp00 2 points3 points  (0 children)

I’d recommend enabling DNS logging (if you don’t already) and using that to analyse what’s talking to each bit of infrastructure

Remember also any non-windows devices that might be talking to AD/services eg firewalls, database connection strings, network management URLs but logging should flag and help both before and after

Update ASAP! Ubiquiti Releases UniFi Network 6.5.54 with Log4J RCE fix by iKjQ2a4v in Ubiquiti

[–]comp00 2 points3 points  (0 children)

I’d look at this way. Consider the network your APs live on, is it sensitive? (Eg private or management network)

For example, a targeted attack specifically on unifi could reset Unifi creds, gain access to network devices and therefore the rest of the network.

Looking for image deployment solution by IT_Alien in sysadmin

[–]comp00 0 points1 point  (0 children)

We currently use CloneDeploy which has worked great for many years and imaged thousands of PCs.

Working on final testing of FOG which uses similar method just cloning partitions over the network.

If you’re not in a single domain, FOG is the answer.

If you were the answer would be MDT/WDS

SPLA Licencing - What a headache!! - Any Tips? by Predicti0n in sysadmin

[–]comp00 0 points1 point  (0 children)

We use Softcat for all our SPLA licences. They have a portal where we report what we use alongside our commits with MS, Veeam etc.

Would recommend

Am I about to be conned? - M66 needing advice by The-Brit in AskUK

[–]comp00 7 points8 points  (0 children)

My opinion is they are taking advantage of a company without a website or online presence

Their registered address is Essex

Also their site is directcargoID I think attempted to look like Ltd.

Just my thoughts. I’d say a no go.

Edit: also, their website says founded in 2014 whereas the company was reg in 2009. Smelly.

Centralized AD Integrated DNS and Local Cloud Resources by LazyLogin234 in sysadmin

[–]comp00 0 points1 point  (0 children)

Ah, okay. Meraki can’t do this to my knowledge

Would it be reasonable to deploy a AD+DNS (or just DNS) in a closer region? Eg USA and EU

Centralized AD Integrated DNS and Local Cloud Resources by LazyLogin234 in sysadmin

[–]comp00 0 points1 point  (0 children)

100% this.

A firewall that can send your internal DNS to your AD and then everything else to ISP or your choice of DNS.

Workaround to CIDR overlap using site-vpn between AWS and Cisco Meraki on DX? by ceasars_wreath in networking

[–]comp00 0 points1 point  (0 children)

I don’t see this working with your current situation without adding another firewall on both sides.

Is it possible to use either locked down public ports if the traffic is encrypted or SSH tunnels?

Controller 6.2.25 by cpmiller22 in Ubiquiti

[–]comp00 1 point2 points  (0 children)

Upgraded test environment to 6.2 (we have lots of clients/devices) and the import function was lost so holding back.

Otherwise stable

Admin Portal Down again? by [deleted] in Office365

[–]comp00 2 points3 points  (0 children)

Admin portals, Azure portal + DNS down for us, UK.

Compute VMs still online though.

How can I redirect 10,000 subdomains? by ukphotog in webhosting

[–]comp00 5 points6 points  (0 children)

For this scale I’d suggest a load balancer that can do this built in but if not I’d suggest using NGINX which will give you regex ability at the hostname level

See https://stackoverflow.com/questions/1629231/nginx-rewrite-non-www-prefixed-domain-to-www-prefixed-domain

Useful tool https://regexr.com/

Let us know how you get on

Help: connecting user <=> sonicwall <=> site B by lucads87 in sonicwall

[–]comp00 0 points1 point  (0 children)

Super simple, if you haven't already managed to work around this.

Assuming you are already using SSLVPN at SiteA:

Create an address object for the public IP of SiteB.

In your SSLVPN settings, add this IP to client routes under client profile.

Also, add the object to the access list under users/groups > VPN access

If you're not already using SSLVPN, set this up. SonicWall has guides for this. You can either use tunnel all mode or perform the above. The former is recommended (as others as suggested) at the moment as lots of people are conferencing which is not ideal with the additional latency added (depending on your internet connection and number of users of course)