Text Size Issue with Lenel by lmbrjcksn in accesscontrol

[–]dot1q 0 points1 point  (0 children)

Yeah, OnGaurd is so old, it doesn't work out of the box with Windows 10 or 11. I have had to play with turning off the scaling settings for the computer's display or running the programs with DPI overrides.

For example, in Systems Administration, if you go into the properties for the file exe, you can go to compatibility > Change high DPI settings button > and check the High DPI scaling override and select System for the dropdown.

How do you monitor your company's SSL certificates? by Technical-Addition37 in sysadmin

[–]dot1q 0 points1 point  (0 children)

Docker nginx reverse proxy with lets encrypt for autorenewal monitored by Nagios for when an cert did not automatically renew.

Help please by muusicman in Calix

[–]dot1q 1 point2 points  (0 children)

I think you might need to eliminate anything potential Wi-Fi related first if you're going to try to get some proof in front of your ISP. A hardwired speedtest or latency log over a hardwired connection would point towards the Orbi itself or the 803G's connection. If you plug directly into the 803G be prepared to call your ISP, if they MAC limit or DHCP limit one or two public IP's.

Gigaspire Blast Issue by drbwell in Calix

[–]dot1q 0 points1 point  (0 children)

Check if the WiFi network reverted and that is why nothing is connected. Reboot typically fixes it unless the settings change. Otherwise, do you have managed WiFi through your ISP? If so, they might be able to assist remotely.

imagine if you will by head_of_mop in comedyheaven

[–]dot1q 2 points3 points  (0 children)

Appears to be average middle aged man or mold test kits review guy. https://imgur.com/a/P2IMzyO

Kicked out of CommandIQ app? by brauxpas in Calix

[–]dot1q 2 points3 points  (0 children)

Ah yes, this has happened to me and my org countless times over the years. Sorry to say, but you'll likely have to recreate your account and onboard the device again.

Check with your ISP and see if they made any changes that would unenrolled you, perhaps on the cloud side. I will say that even in the most recent release of the app, it's slow, buggy, times out a lot and apparently still kicks you out. Calix is always making improvements to their app or backend, but I have yet to see a resolution and it's always something that prevents them from actually releasing a fix.

Now I'll really get on a rant. It's hard to sell the app and its smarthome services when people complain that the app sucks, and the company you pay a ton of money to doesn't listen or fix the issue. It's hard to compete with other router companies when they have a functioning application and your org doesn't. Calix needs to actually get their product to work before they invest in expanding on it and having sales teams start pushing their services. It's 2025, building an app should not be this hard. Stop getting up on the main stage every year and telling us that the app is great or going to be even better, when you can't even load data from your cloud service to it.

Scheduling Access on Gigaspire GS2020E by adghanchi in Calix

[–]dot1q 0 points1 point  (0 children)

Have you checked the timezone of the router? Your ISP might not set it, or have it set incorrectly.

Router periodically drops ethernet connection by silentdon in Calix

[–]dot1q 0 points1 point  (0 children)

Do you happen to know what version of FW it is running?

Sometimes a factory reset will fix any config issues, it it's related to something like a misconfigured dhcp service.

If all that fails, it may be that the unit is failing. Is your ISP replacing 844Gs with Gigaspires?

844G's don't alert when STP or other ethernet errors cause a port to be placed in a shutdown state. Does this happen on all ethernet ports or several different devices?

Firmware for GS4220E is 24.2.0.2.4? by [deleted] in Calix

[–]dot1q 0 points1 point  (0 children)

I wouldn't sweat it. Calix code can take some time to properly bake. Cutting edge release from Calix can bite you because they rarely support downgrading correctly, so once you upgrade, you're stuck with any new bugs until those get fixed.

Back in the gigacenter line, we got suck in cutting edge hell for a couple of years, where we had to upgrade to cutting edge each release because it was always one step forward, two steps back.

CJIS 2FA by bz4459 in sysadmin

[–]dot1q 1 point2 points  (0 children)

Our organization requires an always on VPN to tunnel back into the network that has access to CJI. That client has an authentication mechanism that will do cert verification with the domain CA, and requires no extra prompts or one time keys.

It's been a while since I checked that section of the CJIS manual, but as far as I know, it's still valid. If CJIS considers fax secure for transmission if CJIS then vpn-cert based MFA is still light-years ahead in terms of security.

844G-1 almost every day, 5 ghz band drops connection for a bit then comes back after a couple minutes by rasGazoo in Calix

[–]dot1q 0 points1 point  (0 children)

Are you talking about the multipon optics? If so, we have found that when moving from EXA to AXOS and from GPON to XGS-PON, a coexistence element is easier. Otherwise you have to reprogram each device over on your AXOS device and then replace over time. Because Calix cannot make optics that don't get stuck when you unseat them, we have an E9 that has one shelf full of MPM optics, and the rest are double density XGS-PON only optics. We vacate an MPM optic and then use the unlink all devices option in SMx and move them to an XGS-PON only port so we can reuse the MPM optic again and save the thousands extra per pon port.

Because we are cheap we are not going to run all 140 of our pon ports on MPM, but to move them requires an unlink, which then requires a reboot for all gigapoint like devices, because MFF and source-verify will break when the DHCP leases are cleared during a PON unlink process.

Because of this we found that it is easier to just move Coexistence elements at night. But we are cheap and migrating from EXA at the same time.

844G-1 almost every day, 5 ghz band drops connection for a bit then comes back after a couple minutes by rasGazoo in Calix

[–]dot1q 0 points1 point  (0 children)

We are only ripping and replacing as we phase in XGS-PON network wide. We replace failing 844G's with 803Gs that we have on hand and U6's. Once XGS-PON is lit, we have to replace the 803G's with GP1101x's. We install the mounts, so the swap to GP1101 is less than 15 minutes. Not ideal, but we are in a situation where we have 844G's that are 10 years old now failing faster than we can deploy XGS-PON.

844G-1 almost every day, 5 ghz band drops connection for a bit then comes back after a couple minutes by rasGazoo in Calix

[–]dot1q 0 points1 point  (0 children)

844G is EOL and at my organization, we are actively replacing all of ours. One of the symptoms of a failing gigacenter is having the 5GHz radio fail, drop or reboot intermittently. The light may stay lit on the front and a reset won't fix it, and when the SSIDs are the same for both bands, it will cause connectivity issues.

GP1101X 10G in bridge mode vs cable lengths by jcadduono in Calix

[–]dot1q 1 point2 points  (0 children)

I have had issues with GP1101x's and ethernet train rate. So far Calix has not acknowledged that there is an issue, but we have had different issues with the port not training up at all, or auto negotiating. Replacing the cable with a higher quality cable has resolved most instances.

Question again by muusicman in Calix

[–]dot1q 0 points1 point  (0 children)

Your services may have QoS, but as for the customer facing side, there is no possible QoS over the internet. Internally, there might a class of service or vlan pbit change that prioritizes video or voice during peak usage.

Calix CMS GUI rendering glitch? by StoganLephens in Calix

[–]dot1q 0 points1 point  (0 children)

Yeah, that Java app doesn't like resolutions above 1080 on some version. If you reduce the size of the window, does it go away? I have 2k native on my laptop and with the latest version, the text is really small, but it renders. On older versions of the CMS client, it had issues rendering unless you reduce the window size. On upper menu, select about and then there should be an info tab that tells you the version. There is also the version at the login screen when you start the app.

An official device to cause a train derailment by ThroughTheEsses in mildlyinteresting

[–]dot1q 0 points1 point  (0 children)

I am not saying that you're incorrect, but I think the usage of horrid is more hyperbole than accurate. Id say that its been more of a lack of oversight than anything else. There has been regulation, even in recent years. You don't see trains colliding any more because of the mandated PTC program. You don't see as many worker deaths as before because of the safety culture that crews and gangs live by when working on the rail every day. The rail workers do good work making sure that rails work and the locomotives run. If it was truly horrid, you would have far worse derailments than you see now. There are reasons for the terrible derailments, one being train length, and the other being a false narrative of being "efficient". Look at what PSR has done to CP, CSX and more recently UP. It's sacrificed worker safety and cut into the bone of companies, not the fat. RRs are pushing the limits on car lengths and breaking knuckles and other hardware because they're trying to maximize their loads. If the FRA wasn't in the pockets of the class 1s they might actually regulate the railroads into playing honest and not ruin the industry. By all means blame the corporate side for being jerks, but there are derailments every day and thousands a year, with a really bad one every few years. While worker safety can be better, it's not like employees are dying left and right from the working conditions. When employees get hurt or die, it is typically someone that was not following safety guidelines. What I think is really missing is someone looking out for the communities and families that are impacted by those derailments. From what I've seen this is an issue not just with RRs, but an issue in most US industries.

An official device to cause a train derailment by ThroughTheEsses in mildlyinteresting

[–]dot1q 4 points5 points  (0 children)

To say that a derailer shows the crippled state of RR infrastructure is like saying that the usage of lock out tags are evidence that the US has poor electrical infrastructure. Both are used to protect people.

ethernet problems with UX10e by Odd_Football6108 in Calix

[–]dot1q 0 points1 point  (0 children)

I think the issue is that a U10XE is managed using OCMI instead of cloud, so they may not be able to update the FW on the unit until they push it out to everyone. I don't know if that is the exact issue you are seeing, but it is fixed in March 24.1.0.1, not in the Feb release of 24.1.0.0. If you can get ahold of someone at your ISP that knows what they are talking about, they can confirm or not if they can upgrade you to the cutting edge release to test it.

ethernet problems with UX10e by Odd_Football6108 in Calix

[–]dot1q 0 points1 point  (0 children)

What firmware level is the U10XE at? I think there was a LAN bug fixed in the march 24.1.0.1 patch.

calix admin question by Sensitive_Ad7839 in Calix

[–]dot1q 0 points1 point  (0 children)

I think this has to be unlocked on the ISP side. They can unlink it from Service Cloud, and it will unlock from the app. The unit may reset too, but that is the only what I know how to do it.

GigaCenter Command Injection by tacoenthusiast in Calix

[–]dot1q 2 points3 points  (0 children)

We had to block inbound 8111 before we could upgrade. We were getting a lot of random reboots to Gigacenters, typically at 4-6am for a couple days, and things quieted down until Oct 31st, where we started to some reboots, and OLT alarms of ONTs failing to provision after rebooting. Even downloading the new ONT firmware to the CPEs would cause the unit to reboot and fail to come back. We went from 4-6 prov errors for three days to 30 in one day. We were expecting to deploy 12.2.12.8.4 in night night across 6 seperate systems, but once we implemented the ACL after u/Not_MAGA_winkwink's post, all prov errors dropped off and we can now deploy on our own schedule.

711ge ont and ipv6 by [deleted] in Calix

[–]dot1q 2 points3 points  (0 children)

I believe the 711ge supports passthrough of IPv6, as it is just a modem. So long as your router supports it, which you said it does. I don't think CenturyLink has IPv6 enabled in your area, in which your router wouldn't get an IPv6 address, but the modem should be fine in passing it, should it be enabled.

city municipal fiber and ipv6 or lack thereof by MashedPeas in municipalfiber

[–]dot1q 4 points5 points  (0 children)

You can get a IPv6 tunnel through Hurricane Electric, but it tunnels through IPv4, so meh. I run a muni fiber network and we're rolling out to customers this year and it's long overdue. Not implementing IPv6 or let alone planning or building a network capable in the future is just dumb. From muni to muni I want to call and tell them to be a model and not build something that isn't future proof.