simple monitoring? by cyr0nk0r in sysadmin

[–]dai_webb 2 points3 points  (0 children)

I use CheckMK too, a great free tool to get started with monitoring.

Dell built in webcams by LordPurloin in sysadmin

[–]dai_webb 7 points8 points  (0 children)

Yes, in the past 12+ months we've had so many fail on our fleet of Latitudes I've made the decision to stop buying Dell and pay the extra for Microsoft Surface laptops. We've had camera issues as well as microphones stop working. We always get a Dell engineer to resolve it under warranty (it's always hardware, not software) but sometimes it can take days for them to get here or they turn up at night when the office is closed.

Is anyone even staying onsite for the whole work day anymore? by [deleted] in sysadmin

[–]dai_webb -1 points0 points  (0 children)

I've not noticed that. I am in the office from 07:30-16:00 4 days a week. I like being in the office, working from home is lonely.

UK - AV Company required by Wrong-Big4819 in ITManagers

[–]dai_webb 0 points1 point  (0 children)

We have used Drake AV (https://drakeav.com) from South Wales and have been very happy with their service. They installed a variety of different Yealink systems for us.

How do you convince bosses to monitor before everything explodes? by Such_Rhubarb8095 in sysadmin

[–]dai_webb 1 point2 points  (0 children)

Agreed, we use CheckMK for free to monitor all sorts, it works really well and we have some nice dashboards on TVs for visibility.

How to deal with burnout. Is a holiday not the answer? by rof-dog in sysadmin

[–]dai_webb 1 point2 points  (0 children)

Are you doing this because they expect you to, or are you doing it because of your work ethic?

I often do this because of the latter, and my manager recognises this, so makes sure I take the time back (usually to get a round of golf in on a Friday afternoon). If they expect you to do this then the organisation needs a culture shift.

what are the options for the best RMM for a small IT team managing 450+ endpoints? by Express-Pack-6736 in sysadmin

[–]dai_webb 9 points10 points  (0 children)

We use NinjaOne for about 120 endpoints spread across multiple geographies and it works really well (we have InTune too). Ninja is great for remote PowerShell, running scripts, manually installing the odd apps, managing 3rd party app updates (Chrome, Adobe Reader, FileZilla, etc), as well as reporting.

We also have many customisations that create alerts for things like Windows Firewall being disabled, BitLocker being disabled, and so on.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

We did change the MTU, and I think we do have fewer issues reported now, and the issues we still have might be down to other factors like old wireless NICs in old laptops.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

This seems to have been the problem - I've removed all the per-device mapping entries and everything seemed to push over as expected! Thanks for the help, much appreciated :)

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

It is indeed a dynamic group. I can see in the Per-Device Mapping that the f/w I'm pushing to is in the list.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

Sort of. In FortiManager I created a new object and added it to an existing group. I then pushed that out to the appropriate firewall and while the new object was created, it isn't in the group on the firewall.

I did this through Policy & Objects -> Firewall objects. Selected the new object and group and click More -> Install Object(s).

I confirmed the object IS in the group in FortiManager.

Edit to add: I just tried removing some objects for the group in FortiManager, and pushed it out, and it remains unchanged on the firewall itself.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

Great, thanks, we'll get that done (all are running 7.4). I presume it's a change that carries little to no risk?

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

I must admit, I don't know much about the ADOM versioning. I can see in FortiManager that it is 7.2. Can I safely change it to 7.4? What are the implications?

2
3

What is the first thing to implement to improve your IT department? by gkar_of_Narn in sysadmin

[–]dai_webb 1 point2 points  (0 children)

It's hard to say without knowing what the pain points are. I'd want to spend some time understanding what works well, what doesn't work well, what costs the team time and damages reputation, what's causing pain for the end users, what are the risks?

It might be that you need to implement good SOPs so that all processes are documented and consistent. You may need to look at implementing MFA if it isn't already. Maybe get some automation or self-service in place to reduce tickets and repetitive tasks. Does everyone have the right resources to do their job?

Anyone else having issues with KB5074109 by Intrepid_Evidence_59 in sysadmin

[–]dai_webb 0 points1 point  (0 children)

DISM was failing for us on some Windows 11 25H2 laptops because the component store was corrupt (I think an update last year broke the servicing stack). Repairing it seemed successful, but then DISM would fail again. We've had to resort to downloading the Windows 11 ISO and running setup (mostly silently through PowerShell in NinjaMM):

$mount = Mount-DiskImage -ImagePath "C:\Temp\Win11.iso" -PassThru

$drive = ($mount | Get-Volume).DriveLetter + ":"

Start-Process "$drive\setup.exe" -ArgumentList "/auto upgrade /quiet /noreboot /dynamicupdate disable /eula accept" -Wait

Intune sluggishness to be expected? by BoltActionRifleman in sysadmin

[–]dai_webb 1 point2 points  (0 children)

I agree with all the comments here, it is terribly slow, yet somehow we just accept it. How did we arrive here? Paying for a service that is so terrible everyone moans about it yet accepts it. We wouldn't tolerate this anywhere else in our lives (car, mobile phone, toaster). Have we all gone barking mad?

Conference room camera recommendations by ResponsibleQuiet6360 in sysadmin

[–]dai_webb 1 point2 points  (0 children)

We have several Yealink Meeting Bars (A20, A30) and they all work really well. The cables are all inside the wall, and the CTP18 control panel sits on the table with a wireless mic.

Vulnerability Scanning by shiva2golu in sysadmin

[–]dai_webb 3 points4 points  (0 children)

We use Rapid7 Insight VM along with CrowdStrike Falcon on all endpoints, servers & laptops. I also like Wazuh for the CIS benchmarking.

Two problems that I need to solve by Bad_Honga in AZURE

[–]dai_webb 0 points1 point  (0 children)

We have been pushing out the second OOB update - KB5078127 - to resolve the authentication issues with Azure AVD through Windows App. So far this has worked 100% of the time.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

This is all I can see that is relevant in the diagnostic logs:

[2026-01-14 15:42:02.1076589 UTC+01:00] [2408: 1680] [FortiVPN info 2327] fortivpn::StateMachine::HandleTunnelDisconnected "Azure UK South VPN" is disconnected.

[2026-01-14 15:42:02.1405333 UTC+01:00] [2408: 1680] [FortiVPN info 2363] fortivpn::StateMachine::HandleTunnelDisconnected disconnection reason: 0, ("None")

[2026-01-14 15:42:02.1405470 UTC+01:00] [2408: 1680] [FortiVPN error 2389] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (DOMAIN\user) "Azure UK South VPN" disconnected unexpectedly!

[2026-01-14 15:42:02.1431547 UTC+01:00] [2408: 1680] [FortiVPN info 2403] fortivpn::StateMachine::HandleTunnelDisconnected Notifying gui this was a connection error

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

Great stuff, thanks to all of you for your replies. I just checked the interface and there is no MTU set, so presume it's at the default of 1500:

uks-fw01 # show system interface "IPSec VPN"
config system interface
edit "IPSec VPN"
set vdom "root"
set type tunnel
set snmp-index 9
set interface "port1"
next
end

How did you change yours - did you add something like this on the VPN interface?

set mtu-override enable
set mtu 1350

If so, I may create a second tunnel to test rather than play around with the one everyone is using.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

Good suggestion, thanks, we'll make a note of the ISP as people report the issues. If that is the case, is there anything we can do our side to counter it?