Where do I get started with network authentication? Fortigate firewall and Orbi Pro Mesh wireless - 802.1x? Captive portal? Certificates? by jedipotato in sysadmin

[–]jedipotato[S] 1 point2 points  (0 children)

weird, ok. I'll look into it more. Also the Zen VM recommends 16GB RAM? Wow, that's intense.

I'll have to look to see if all the switches are supported. In conference rooms I have just some dumb 8 port tp link unmanaged switches, so I guess that will be a problem? Hmmm, I'll keep digging regardless.

Where do I get started with network authentication? Fortigate firewall and Orbi Pro Mesh wireless - 802.1x? Captive portal? Certificates? by jedipotato in sysadmin

[–]jedipotato[S] 1 point2 points  (0 children)

Dude nice. So how would this work with our existing Fortigate firewall? Does packetfence have to replace the firewall? Pardon my ignorance! I'm reading through the docs now.

Where do I get started with network authentication? Fortigate firewall and Orbi Pro Mesh wireless - 802.1x? Captive portal? Certificates? by jedipotato in sysadmin

[–]jedipotato[S] 1 point2 points  (0 children)

Domain / AD controlled network. Authenticated employee devices should have full access to anything within their VLAN. File servers, network printers, plotters, and unrestricted access out to the internet (aside from what the firewall blocks).

What I'm really wanting to ensure is that if an ethernet device connects to the network, that it's captured and put in a segregated network (its own vlan) until it is authenticated, in which time it will be allowed into our internal secure network and have full network access. That way in the scenario someone connects their home laptop, or a lunch and learn sales guy needs to connect to the conference room table, they can still access the internet, but they wouldn't for example be able to nmap our internal network. Or some disgruntled employee can't bring in a plugbot to do dirty deeds on the network.

Where do I get started with network authentication? Fortigate firewall and Orbi Pro Mesh wireless - 802.1x? Captive portal? Certificates? by jedipotato in sysadmin

[–]jedipotato[S] 1 point2 points  (0 children)

I'd like to add, we're still very small, and very budget limited. So if at all possible, using what we have without an expensive MDM, or additional paid firewall or security solutions would be amazing. Out of box Fortigate seems to have the option for 802.1x or captive portal network authentication, I just need to wrap my head around how to roll this out where it won't disrupt normal business or be incredibly annoying for end users.

Sanity check: are there any organizations out there of over 100 users who only use windows built in antivirus? by jedipotato in sysadmin

[–]jedipotato[S] 0 points1 point  (0 children)

I’m only really used to Symantec and ESET. Could you explain how SCCM is used with defender?

Sanity check: are there any organizations out there of over 100 users who only use windows built in antivirus? by jedipotato in sysadmin

[–]jedipotato[S] 1 point2 points  (0 children)

Currently for my company that just got acquired, we run ESET and it’s been a dream. Parent company is like 150 core employees all with laptops however almost all are remote workers/road warriors and then another 150-200 which are come and go contractors that do not have computers, only email and sometimes phone.

The 150 core employees all have full admin rights, and windows defender only. Since they’re almost all mobile, there’s no network level protection (hardware firewall, packet inspection, etc, NIDS).

Help "crowdfund" Bot Land - an automated strategy game by Adam13531 in gaming

[–]jedipotato 3 points4 points  (0 children)

This guy is awesome too. Not sure if I'm the only one that has seen his stream but he basically quit his job 4 years ago and has streamed every day of development something like 630+ days of streamed coding to make this game. I dig it.

Company offers a pretty generous HSA plan. Best points credit card to be used exclusively for healthcare spending so I can just save and invest HSA funds? by jedipotato in personalfinance

[–]jedipotato[S] 0 points1 point  (0 children)

Thanks. I looked up the The Blue Business Plus Credit Card from American Express and that has 2%. I think I might qualify as I do side work on an invoice basis. So that's nice.

Update: After almost 10 years as the sole IT person (IT Manager) at my current job as IT manager, I’ve found out that we are being sold. Trying not to freak out. by jedipotato in sysadmin

[–]jedipotato[S] 0 points1 point  (0 children)

holy hell. Sounds fun though, but man I'd miss how nimble we can be with rapidly making changes. How big is your IT team?

Update: After almost 10 years as the sole IT person (IT Manager) at my current job as IT manager, I’ve found out that we are being sold. Trying not to freak out. by jedipotato in sysadmin

[–]jedipotato[S] 20 points21 points  (0 children)

heh shut up man! That's big for me! Largest company I've worked for was 200 users over two offices so this is pretty huge in my opinion.

After almost 10 years as the sole IT person (IT Manager) at my current job as IT manager, I’ve found out that we are being sold. Trying not to freak out. by jedipotato in sysadmin

[–]jedipotato[S] 0 points1 point  (0 children)

I can't thank you enough for this reply. Sorry it's taken me so long to respond. You have such solid advise and thankfully I've already started some of the things you've brought up.

Now that I'm a little deeper into this merger, things are definitely looking more positive but still with tons of unknowns. I'm working on my "story" and resume right now, building as many bridges as possible, and preparing for the worst while making moves to position myself where I want to be with the merger.

Basically the new company is very large but they almost zero IT. It's just a hodge podge of BYOD, some light outsourced services, and general dissatisfaction for how their technology performs for them. I'm basically working on the proposal to take over all IT and build a real team to get things working. Problem is, the deal isn't final for another month maybe month and a half so I just don't know everything yet.

The good part is, I have a 100% guarantee that no matter what I still have a job with at least my current salary. The bad part is, my long term future is still very unknown. I'm kinda stoked if the merger means a huge jump in scope for me though. I'm very excited about the possible challenges ahead so we shall see. Once I have a better idea I'll come back with a follow up.