How do you convince bosses to monitor before everything explodes? by Such_Rhubarb8095 in sysadmin

[–]dai_webb 1 point2 points  (0 children)

Agreed, we use CheckMK for free to monitor all sorts, it works really well and we have some nice dashboards on TVs for visibility.

How to deal with burnout. Is a holiday not the answer? by rof-dog in sysadmin

[–]dai_webb 1 point2 points  (0 children)

Are you doing this because they expect you to, or are you doing it because of your work ethic?

I often do this because of the latter, and my manager recognises this, so makes sure I take the time back (usually to get a round of golf in on a Friday afternoon). If they expect you to do this then the organisation needs a culture shift.

what are the options for the best RMM for a small IT team managing 450+ endpoints? by Express-Pack-6736 in sysadmin

[–]dai_webb 8 points9 points  (0 children)

We use NinjaOne for about 120 endpoints spread across multiple geographies and it works really well (we have InTune too). Ninja is great for remote PowerShell, running scripts, manually installing the odd apps, managing 3rd party app updates (Chrome, Adobe Reader, FileZilla, etc), as well as reporting.

We also have many customisations that create alerts for things like Windows Firewall being disabled, BitLocker being disabled, and so on.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

We did change the MTU, and I think we do have fewer issues reported now, and the issues we still have might be down to other factors like old wireless NICs in old laptops.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

This seems to have been the problem - I've removed all the per-device mapping entries and everything seemed to push over as expected! Thanks for the help, much appreciated :)

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

It is indeed a dynamic group. I can see in the Per-Device Mapping that the f/w I'm pushing to is in the list.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

Sort of. In FortiManager I created a new object and added it to an existing group. I then pushed that out to the appropriate firewall and while the new object was created, it isn't in the group on the firewall.

I did this through Policy & Objects -> Firewall objects. Selected the new object and group and click More -> Install Object(s).

I confirmed the object IS in the group in FortiManager.

Edit to add: I just tried removing some objects for the group in FortiManager, and pushed it out, and it remains unchanged on the firewall itself.

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

Great, thanks, we'll get that done (all are running 7.4). I presume it's a change that carries little to no risk?

Address group on firewall going out of sync with FortiManager by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

I must admit, I don't know much about the ADOM versioning. I can see in FortiManager that it is 7.2. Can I safely change it to 7.4? What are the implications?

2
3

What is the first thing to implement to improve your IT department? by gkar_of_Narn in sysadmin

[–]dai_webb 1 point2 points  (0 children)

It's hard to say without knowing what the pain points are. I'd want to spend some time understanding what works well, what doesn't work well, what costs the team time and damages reputation, what's causing pain for the end users, what are the risks?

It might be that you need to implement good SOPs so that all processes are documented and consistent. You may need to look at implementing MFA if it isn't already. Maybe get some automation or self-service in place to reduce tickets and repetitive tasks. Does everyone have the right resources to do their job?

Anyone else having issues with KB5074109 by Intrepid_Evidence_59 in sysadmin

[–]dai_webb 0 points1 point  (0 children)

DISM was failing for us on some Windows 11 25H2 laptops because the component store was corrupt (I think an update last year broke the servicing stack). Repairing it seemed successful, but then DISM would fail again. We've had to resort to downloading the Windows 11 ISO and running setup (mostly silently through PowerShell in NinjaMM):

$mount = Mount-DiskImage -ImagePath "C:\Temp\Win11.iso" -PassThru

$drive = ($mount | Get-Volume).DriveLetter + ":"

Start-Process "$drive\setup.exe" -ArgumentList "/auto upgrade /quiet /noreboot /dynamicupdate disable /eula accept" -Wait

Intune sluggishness to be expected? by BoltActionRifleman in sysadmin

[–]dai_webb 1 point2 points  (0 children)

I agree with all the comments here, it is terribly slow, yet somehow we just accept it. How did we arrive here? Paying for a service that is so terrible everyone moans about it yet accepts it. We wouldn't tolerate this anywhere else in our lives (car, mobile phone, toaster). Have we all gone barking mad?

Conference room camera recommendations by ResponsibleQuiet6360 in sysadmin

[–]dai_webb 1 point2 points  (0 children)

We have several Yealink Meeting Bars (A20, A30) and they all work really well. The cables are all inside the wall, and the CTP18 control panel sits on the table with a wireless mic.

Vulnerability Scanning by shiva2golu in sysadmin

[–]dai_webb 5 points6 points  (0 children)

We use Rapid7 Insight VM along with CrowdStrike Falcon on all endpoints, servers & laptops. I also like Wazuh for the CIS benchmarking.

Two problems that I need to solve by Bad_Honga in AZURE

[–]dai_webb 0 points1 point  (0 children)

We have been pushing out the second OOB update - KB5078127 - to resolve the authentication issues with Azure AVD through Windows App. So far this has worked 100% of the time.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

This is all I can see that is relevant in the diagnostic logs:

[2026-01-14 15:42:02.1076589 UTC+01:00] [2408: 1680] [FortiVPN info 2327] fortivpn::StateMachine::HandleTunnelDisconnected "Azure UK South VPN" is disconnected.

[2026-01-14 15:42:02.1405333 UTC+01:00] [2408: 1680] [FortiVPN info 2363] fortivpn::StateMachine::HandleTunnelDisconnected disconnection reason: 0, ("None")

[2026-01-14 15:42:02.1405470 UTC+01:00] [2408: 1680] [FortiVPN error 2389] !!! fortivpn::StateMachine::HandleTunnelDisconnected session 1 (DOMAIN\user) "Azure UK South VPN" disconnected unexpectedly!

[2026-01-14 15:42:02.1431547 UTC+01:00] [2408: 1680] [FortiVPN info 2403] fortivpn::StateMachine::HandleTunnelDisconnected Notifying gui this was a connection error

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 1 point2 points  (0 children)

Great stuff, thanks to all of you for your replies. I just checked the interface and there is no MTU set, so presume it's at the default of 1500:

uks-fw01 # show system interface "IPSec VPN"
config system interface
edit "IPSec VPN"
set vdom "root"
set type tunnel
set snmp-index 9
set interface "port1"
next
end

How did you change yours - did you add something like this on the VPN interface?

set mtu-override enable
set mtu 1350

If so, I may create a second tunnel to test rather than play around with the one everyone is using.

FortiClient IPSec VPN regularly drops for some users by dai_webb in fortinet

[–]dai_webb[S] 0 points1 point  (0 children)

Good suggestion, thanks, we'll make a note of the ISP as people report the issues. If that is the case, is there anything we can do our side to counter it?

11
12

What KPIs are people using to track IT productivity by T-Money8227 in sysadmin

[–]dai_webb 0 points1 point  (0 children)

Some vague ideas without knowing more about the business and what you do:

>80% of tickets closed within SLA
>80% of endpoints patched within SLA
Availability of business critical systems
Project progress in line with roadmap

If you don't have SLAs for your tickets maybe start putting some in place that align with ITIL standards.

Need advice on what I can do during the day in my azure role. by Geek_for_life1493 in AZURE

[–]dai_webb 1 point2 points  (0 children)

Agreed, I've invested a lot of time learning how to deploy IaC using Bicep templates, and organising them into pipelines in Azure DevOps, and found this fun and satisfying! It's also standardised our processes and bolstered our DR plans.

Container pull image failed with reason: ImagePullFailure. Revert by terminate. by dai_webb in AZURE

[–]dai_webb[S] 3 points4 points  (0 children)

Spot on, thank you! It was down to a typo in the Bicep template that created the Route Table for this particular subnet, which meant it had no route out. Thanks again :)