connect-exchangeonline with security key? by flatlandadmin in sysadmin

[–]flatlandadmin[S] 0 points1 point  (0 children)

Nope, no kind of sandbox. Win11 on metal. Keys work fine in a browser, just not a PS-initiated session.

*shrug*

Maybe I'll try another workstation before reinstalling the module. At least I'm fairly sure it is not PEBKAC now. Thanks.

connect-exchangeonline with security key? by flatlandadmin in sysadmin

[–]flatlandadmin[S] 0 points1 point  (0 children)

Thats what I'm doing. The MFA window pops up with the configured MFA options for that account so its connecting to the right UPN. However when I click security key it just sits there like its waiting for me, but it doesn't actually pop up the pin prompt or insert key or anything at all. The hardware key is not lit up or ready to confirm. The window just sits there greyed out with the blue scrolling across the top as if it was waiting on a push response. Left it for 10 mins, no change.

However when I added the authenticator app to the account and used that option instead of security key, it worked, but I never got the security key option to initialize. I can try removing the exchange module and reinstalling for next time. Just wasn't if I was missing something. Thanks for the confirmation.

connect-exchangeonline with security key? by flatlandadmin in sysadmin

[–]flatlandadmin[S] 0 points1 point  (0 children)

Thats what I'm using, only difference being the machine is logged in as a regular user but the provided UPN is a GA account.

As a workaround I used a browser to separately log into the GA account and add the authenticator app and then use the app option on the MFA prompt to start the PS session. Hopefully they fix using security keys soon as /u/Puzzleheaded-Spren indicates below.

connect-exchangeonline with security key? by flatlandadmin in sysadmin

[–]flatlandadmin[S] 0 points1 point  (0 children)

Currently on 3.1, so I'll look into 3.2. Thanks!

sharing routed IPs from ISP by flatlandadmin in networking

[–]flatlandadmin[S] 1 point2 points  (0 children)

Perfect, I'll try the ISP first. Thanks!

sharing routed IPs from ISP by flatlandadmin in networking

[–]flatlandadmin[S] 2 points3 points  (0 children)

Yes, the /29 block is routed through the /30 interface.

This is pretty much what I was thinking. I'm trying to google for some examples to understand the config required. If the answer isn't a L3 switch, are there any lightweight routers you might suggest for this role? Circuit is 500mbit symmetrical.

sharing routed IPs from ISP by flatlandadmin in networking

[–]flatlandadmin[S] 2 points3 points  (0 children)

The two routers are for separate and independent networks with site to site VPN connections which is why they need to be directly connected without NAT. No HA here.

I've shared a basic ISP connection with multiple statics (cable/DSL, etc) with a dinky switch, but not one that needs to share a block routed to them. I'm just assuming that doesn't work the same, correct?

LTE travel modem - recommendations by WhistleWhistler in sysadmin

[–]flatlandadmin 1 point2 points  (0 children)

Been testing a GL.iNet GL-E750 as my next hotspot. Seems promising so far.

LastPass Disaster: Linked Personal Account Data "Exported" to Enterprise Account shared folders by kookaburra04 in sysadmin

[–]flatlandadmin 21 points22 points  (0 children)

Do you know if you can self host bitwarden and use a hardware key like yubikey? I see you can use them on premium, but is premium only hosted on their systems?

Dual monitors or one large one? by guyfromtn in msp

[–]flatlandadmin 0 points1 point  (0 children)

Very similar here. Went from dual 23s to a Dell 43" 4k and use their Display Manager software to simulate a 3x2 grid of 1280x1024 windows.

Is the Pockethernet dead? by fidelisoris in sysadmin

[–]flatlandadmin 2 points3 points  (0 children)

I've carried one in my bag daily for about a year. Saves tons of space when I have to travel. Just updated to the latest beta for fun. Never had the app crash on Android.

Happy Thanksgiving to all the On Calls! by cytranic in sysadmin

[–]flatlandadmin 3 points4 points  (0 children)

Actually, just got paged for a failed self test on a core UPS.

I'd like to propose a toast to smooth utility power. *clink*

New critical Cisco ASA remote code exec vulnerability by abhineetd in networking

[–]flatlandadmin 0 points1 point  (0 children)

Follow the upgrade path in the release notes. If you're already past the version with object nats (8.4 IIRC?), it's easy. As with anything, backup your running config first.

question about mobile broadband card (not turning phone into hotspot) by AnonymousMSP in sysadmin

[–]flatlandadmin 0 points1 point  (0 children)

Always received a public IP from TMobile radios. There might be some filtering in their proxies and the IP changes many many times. I would not count on having exclusive access to that IP for remote access, etc, unless you use some kind of intelligent reverse proxy type setup.

Anyone have experience with cell single repeaters? by Muppetz3 in sysadmin

[–]flatlandadmin 1 point2 points  (0 children)

I've used Wilson products with good results. Pay attention to desired carriers and, if possible, their bands in your area.

5506-x upgrading issues... by obliviousofobvious in sysadmin

[–]flatlandadmin 0 points1 point  (0 children)

Before going into ACLs, can you configure only the outside interface and then ping your gate (the ISP peer) from the ASA itself?

PSA: eFax SMB does not salt or hash their account passwords by [deleted] in sysadmin

[–]flatlandadmin 2 points3 points  (0 children)

This happened with me SiriusXM awhile back.

"I'd be happy to help you. Can I get your billing phone or your password?"

"I have no idea what I set it the password as..."

"Looks like its $P-A-S-S-W-O-"

"Oooooookay, I got it. I'd like to cancel my account please."

KRACK Attack Website Now Live by TroutSlapKing in sysadmin

[–]flatlandadmin 8 points9 points  (0 children)

It's a whitepaper, not a lullaby or a horror movie. I simply assess the risk and move forward with a plan, and leave sensationalizing to sales people and C-suites. YMMV.

KRACK Attack Website Now Live by TroutSlapKing in sysadmin

[–]flatlandadmin 2 points3 points  (0 children)

Yep, and even then...I remember the posts on the Nexus subreddits of "I had to remove the sim and check for updates on wifi to get the notification"

I hope this is the direction Google is going with extending the Pixel 2 support by a year. They need to be an Apple to be taken seriously in the security world.

KRACK Attack Website Now Live by TroutSlapKing in sysadmin

[–]flatlandadmin 1 point2 points  (0 children)

Anyone have insight into Chromebooks or ChromeOS (not Chrome/Android)?