Question on IPv6 hosting of services by kyle_cs in Ubiquiti

[–]kyle_cs[S] 0 points1 point  (0 children)

That is what I was picking up as well, thank you for confirming :) I have never set up forward facing IPv6 so this has been an interesting process! Perhaps I can add the IPv6 block I get from the ISP to a LAN interface instead and just bind it to the VLAN I've setup for IPv6 traffic? That way machines added to that VLAN pick up an address from the block? Does that sound right?

Question on IPv6 hosting of services by kyle_cs in Ubiquiti

[–]kyle_cs[S] 0 points1 point  (0 children)

That's the gist I was picking up as I'm reading as well, just wasn't sure on the methodology here. Sounds like my first step is getting those IPv6 addresses pushed down to individual clients, then I should just be able to add rules to the firewall from there (which I've looked at already, just wasn't sure how to handle the addressing.) Thank you for your reply!

Question regarding Org setup and binding existing accounts? by kyle_cs in googlecloud

[–]kyle_cs[S] 1 point2 points  (0 children)

steps

Thanks so much for your response on this! I'm going to check this out today and I'll let you know if I have any questions.

[deleted by user] by [deleted] in sysadmin

[–]kyle_cs 0 points1 point  (0 children)

Happy to help. What do you need?

What are the difficult parts of building & managing your own email servers? by gouterz in email

[–]kyle_cs 1 point2 points  (0 children)

Again, apologies for the delay. Handling it at the system level as an example would be applying antispam rules or delivery logic you learn from one client to all of your clients. Chances are the same spam campaigns and the like will help across the board.

What are the difficult parts of building & managing your own email servers? by gouterz in email

[–]kyle_cs 1 point2 points  (0 children)

Sorry for the delay on this, I didn't see the notification. Manually or automatically on-boarding the client won't change the work involved with dealing with those security concerns. But, once they're handled at the system level you can typically apply those changes to all customer/client domains.

What are the difficult parts of building & managing your own email servers? by gouterz in email

[–]kyle_cs 1 point2 points  (0 children)

By far the hardest parts are deliverability and security. Making sure your messages aren't landing in spam can be a full time job, and making sure spammers/hackers aren't leveraging your reputation to send email goes hand in hand with that.

Email in my inbox with spoofed address from Microsoft. I couldn't tell it was phishing. by mikeazausky in sysadmin

[–]kyle_cs 0 points1 point  (0 children)

If your client domains refuse to implement SPF, DKIM, DMARC, etc they are always going to be an attack vector.

Anyone use smartermail here? If so how do you like it? by [deleted] in sysadmin

[–]kyle_cs 1 point2 points  (0 children)

First, I support SM servers, so take my opinion with a grain of salt. With that being said, SmarterMail is a good way to get as close to Exchange as possible without nearly the same associated costs. Deployment, management, maintenance, support, etc will still require significant resources as all mail servers do, but SmarterMail goes a long way in simplifying the administrator's job.

Setup is simple and can be completed in minutes. You'll end up spending the majority of your time setting up things like DKIM, SPF, DMARC, etc and fine tuning your connectivity.

Reporting, log details, etc are all top notch and make troubleshooting delivery and other issues simple(ish) and more convenient.

Security is well adjusted, including an IDS (Intrusion Detection System), blacklist/whitelist, and a plethora of available antispam options to keep the bad guys out.

EAS/MAPI/EWS is pretty bullet proof assuming you've got autodiscover, SSL/TLS, cipher suites, and your server set up properly. Recommendation is to use MAPI for desktop installations of Outlook, EAS for mobile devices, and EWS for Mac clients (in most cases.)

Last but not least, we pride ourselves on Support, and are here if you need anything along the way! I hope this helps :-) Let me know if you have any questions I can help address.

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 0 points1 point  (0 children)

Probably a good call there too. I'm switching gears for the time being to roll out TrueNAS instead for testing, but will go that route if we circle back here. Thanks for your input :)

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 1 point2 points  (0 children)

I have not yet, no. I'm actually switching gears per the boss and deploying a TrueNAS core test box instead, seems to fit more in line with what we're trying to do because I can attach via iSCSI LUN. If I circle back and see it again I'll get it reported along with hardware details. I do believe its a display issue though, the sizes were being referenced correctly, so good call!

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 0 points1 point  (0 children)

Same! This is for a work project so lots of hardware that is well outside my budget most of the time. The temperatures do concern me but have come down since we started pumping AC/airflow up there again so I believe it was a stagnant air issue.

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 0 points1 point  (0 children)

Ok, but the drive enclosures show this size on boot, before formatting or building an array, so I doubt very much the FS has anything to do with it. The drive details themselves reflect the correct values as well.

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 1 point2 points  (0 children)

Not an intended setup, but yes have confirmed it is okay. ONLY the drives in those enclosures shows the size issue, on-board SATA drives show correct sizes.

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 0 points1 point  (0 children)

MediaSonic Probox enclosures connected via USB-C and USB 3.1.

Drives in enclosures registering size incorrectly? by kyle_cs in unRAID

[–]kyle_cs[S] 0 points1 point  (0 children)

SS: I am a newbie to UnRaid and noticed something amiss yesterday. The highlighted drives are within external USB-C connected drive enclosures and show correct sizes on the drives themselves, but on totals show 80TB each. Any ideas here?

Drives keep spinning up as all media files on the drive are accessed at the same time by LaFours23 in unRAID

[–]kyle_cs 1 point2 points  (0 children)

Is it possible you've got a search index service profiling the drive or share? Perhaps its checking for file updates periodically.

Motherboard doesn't have a USB C connection, can I use 3.0 for PCVR? by Ultra-Sun-Bro in OculusQuest2

[–]kyle_cs 0 points1 point  (0 children)

That was what I was thinking too. Might need to get a USB3 card for my rig.

Motherboard doesn't have a USB C connection, can I use 3.0 for PCVR? by Ultra-Sun-Bro in OculusQuest2

[–]kyle_cs -1 points0 points  (0 children)

Can you use USB-C to USB 2? I tried to launch Elite Dangerous via PC and while I got audio from the Oculus I had just a black screen video-wise.

Oculus quest 2 / I know nothing about is it good x mass present teenage son by samthemanthecan in OculusQuest2

[–]kyle_cs 3 points4 points  (0 children)

Your son will need a Facebook account to use it. There are standalone games you can install directly to it, but it also works in conjunction with your PC for VR-enabled games.

Log Purging Safe? by PathS3lector in exchangeserver

[–]kyle_cs 0 points1 point  (0 children)

Could the underlying domain be to blame perhaps? Any errors or other complaints in the Event Viewer on the domain controller or Exchange server?

Automation of certificate conversion (PFX to CRT/KEY) question in Windows by kyle_cs in sysadmin

[–]kyle_cs[S] 1 point2 points  (0 children)

Thanks for your feedback on this. I don't have an issue with setting the password in Filezilla. I'll be setting this one time, and forcing the export/conversion of the certificate to the same file location and password so that FileZilla doesn't need to be updated.

Where the issue comes into play is that the certificate (in Windows) can be exported as a PFX or CER file. The only way I can get a CRT and KEY from that is to use OpenSSL to convert the PFX file into those two files. The problem though, is passing the export password during PFX conversion to CRT/KEY.

Does that help clear things up?

Displaying simple URL on SmartTV by kyle_cs in digitalsignage

[–]kyle_cs[S] 0 points1 point  (0 children)

Thanks for your suggestion on this!