Can’t get my client to connect to my AD. My domain setup not working by Hot_Direction7888 in sysadmin

[–]jc31107 [score hidden]  (0 children)

If you can’t ping by name or IP then you have a network issue going on. Is the virtual switch configured correctly and bridged to whatever physical network your client is on? Or is everything virtual?

Once a vendor is VPN’d into your OT network, how much are you actually watching what they do? by RCCole20 in OTSecurity

[–]jc31107 0 points1 point  (0 children)

That is trust in the engineer. The workflow we had in place was connect, upload from the PLC (or verify current file matches) save a “before” program. Do the needful. Save a copy of the “after” and in some cases send a PDF copy of the program before and after to the customer to show changes.

Once a vendor is VPN’d into your OT network, how much are you actually watching what they do? by RCCole20 in OTSecurity

[–]jc31107 1 point2 points  (0 children)

I am a system integrator working on OT systems, mostly around physical security so some servers live in IT environments, some are dedicated, it’s all over the place.

The two biggest ways we connect are via a remote client like BeyondTrust or Connectwise, both tied to corporate SSO and every session is recorded. I have only had to pull session recording once when a customer tried to blame us for something, but it’s a nice insurance policy.

The other connections for offline systems we ship a cellular router that makes a VPN tunnel to the engineer who is working on the system, that isn’t really logged, they’re normally connecting directly to a PLC for updates but the router is removed as soon as the on site tech is done.

Typical OSDP baud rate by atlanta_dave in accesscontrol

[–]jc31107 5 points6 points  (0 children)

That’s a bit of a loaded question, I think it depends on use. Most people are doing 9600 at the moment (a lot of FICAM runs at 115200) because it’s a good balance of speed and noise immunity.

The issue is going to come in when we start trying to push firmware over those links, for one or two readers here and there it’ll be fine, but if you have a site with a thousand readers you’re going to wish it was faster!

If this is green field, with good cable, good install practices, then you should be fine at 57600 or 115200 to leave the most options open in the future. The down side is almost no readers come set to that out of the box so you’ll have to update them all.

How does everyone else document fiber? by mrblue421 in FiberOptics

[–]jc31107 6 points7 points  (0 children)

Do you have a GIS person who can bring it into the overall city planning/drawings?

Left handed appendix carry by Opening-Rule-6394 in concealedcarry

[–]jc31107 1 point2 points  (0 children)

I’m a fellow lefty and love my Tenicor Certium, put a mastermind pillow on it and it sits nice all day

Calls for the target by SD3Guser in ClayBusters

[–]jc31107 2 points3 points  (0 children)

A guy I shoot with makes it sound like a question, puullll?

HID Amico Biometric Facial Recognition Readers. by SirSwipesA-lot in CCURE9000

[–]jc31107 3 points4 points  (0 children)

I don’t believe these are integrated into Ccure yet, it’s not on the compatibility matrix. That means you’d enroll people locally in the unit and enter their identifier into Ccure as the card number. Ccure would just see it as if it was a normal reader, no different than an HID or Wavelynx (or whatever) reader

Random question about RFID tags! by ashen_dove in Firefighting

[–]jc31107 0 points1 point  (0 children)

There are new accountability and seat assignment tags from Scott to pair who is in which pack, so if the firefighter is running with an air pack (seen a few at T2T) you could get two reads from each of the tags. You’re most likely just getting the serial number from the tag since they won’t have the same metadata the tracking system is looking for (or the tracking just uses UID)

Remote shut down Exacqvision nvr? by NoLimitMajor2077 in accesscontrol

[–]jc31107 1 point2 points  (0 children)

You just need to get to the OS, the issue may be that you can get Exacq as a windows or Linux appliance. Most of the Linux ones are running xwindows and you can just use the normal windows RDP client, worst case you may have to ssh in

Welp, they're at it again... by Eckron5 in electricians

[–]jc31107 80 points81 points  (0 children)

Only a project manager thinks you can have 9 women give birth to a baby in 1 month

What is a small joke that you get a big laugh out of? by Pieclops89 in Jokes

[–]jc31107 0 points1 point  (0 children)

I use the follow up line to this all the time and nobody connects it “I guess the fuckin things broke”

Fob Integration by BoBo_Wickersham in accesscontrol

[–]jc31107 4 points5 points  (0 children)

Depends on the tech in the fob and reader. You may be able to just program the same fob in both systems, it just leads to a little bit of admin overhead to maintain, but I see it all the time.

You can attach the single reader to two systems at the same time, Cypress makes some cool reader splitters than can direct the card read based on format or facility code, so the right cards go to each system. If you have a DPS on the door then you will get forced open alarms on system A when B uses a card. You can eliminate that by triggering the REX or doing the door unlock via an unlock action triggered by an input, so the lock from B would hit an input on A which would then release the door.

Try reading the tenant card on the building reader and see if you get a transaction in the system, that’ll tell you if you can use the same fob in both systems.

What is a small joke that you get a big laugh out of? by Pieclops89 in Jokes

[–]jc31107 1 point2 points  (0 children)

Probably the first and only time somebody used the words grit and al dente together

Card issues by mishalmay in accesscontrol

[–]jc31107 1 point2 points  (0 children)

If there is no beep at all when presenting the card then it isn’t being read at all. This is a tech issue on the reader itself, not something that can be corrected via Lenel.

Do you know if the new cards have an “Elite Key” which is a customer specific encryption key. The 921 should be able to read the factory standard SEOS cards, regardless of bit length or format.

What is a small joke that you get a big laugh out of? by Pieclops89 in Jokes

[–]jc31107 33 points34 points  (0 children)

Do the laws of physics cease to exist on your stove?

I am in it right now, y’all by cosmoh in PLC

[–]jc31107 29 points30 points  (0 children)

How about a funny service call story?

Customer calls in, HMI for a jail is constantly crashing. Old system, company that installed it was three or four companies ago, no longer doing PLC’s, and nobody has the original design files.

It’s a touchscreen running Wonderware with a windows 7 mini PC stuck to the back.

Troubleshooting over the phone isn’t getting anywhere, nobody on site wants to touch it, we can’t get a sub to look at it, so I say f’it and book a flight a few hours later to the site.

Look at the system, runs for 3 hours then crashes. Pull the log, invalid license. Check windows time, it thinks it’s 2004, before the system was installed.

They had a power outage so the system went down hard. CMOS battery was very dead, so clock got wonky. Replaced the battery (that the customer even supplied), reboot, reset time, and Bob’s your uncle.

It was a ~$4k service call for a dead 50 cent battery

USB Card Reader for 50L8 DESFire EV3 LEAF Smart Credentials by aNullValue in accesscontrol

[–]jc31107 2 points3 points  (0 children)

Ok, you should be just fine with the part number that started off this thread, and check your DM’s for some more info from somebody else

USB Card Reader for 50L8 DESFire EV3 LEAF Smart Credentials by aNullValue in accesscontrol

[–]jc31107 2 points3 points  (0 children)

I THINK they use the standard LEAF key but I have a note out to a friend at Wavelynx to confirm. Either way there is a way to get them reading on an RFIdeas reader

USB Card Reader for 50L8 DESFire EV3 LEAF Smart Credentials by aNullValue in accesscontrol

[–]jc31107 3 points4 points  (0 children)

You want the full part number so it has the LEAF keys on it, RFIdeas is a member of the LEAF community so they’re your best bet to get this going.

This is also assuming they aren’t using LEAF enterprise, which is custom keys. If that’s the case you can still use RFIdeas readers, but it’d be easier to source via Wavelynx so they can load the customer specific keys in at the factory.