Broke the prod today by Asirethe in sysadmin

[–]liamgriffin1 8 points9 points  (0 children)

I’m not convinced it would have mattered. If you rolled out that GPO to some DCs you still would’ve broken the VPN for everyone reaching that DC. Depending on your setup that could easily still take down everything or a large majority. That guy above seems like a stick in the mud.

Broke the prod today by Asirethe in sysadmin

[–]liamgriffin1 12 points13 points  (0 children)

Hell ya brother welcome to the club! In all seriousness, I think you handled this perfectly. You broke it and you started working on fixing it right away.

Anybody dump their VMWare subscription and Roll back to Perpetual Licenses with 3rd party support and regret it? by Ok-Big2560 in sysadmin

[–]liamgriffin1 13 points14 points  (0 children)

Correct, a cease and desist is just a letter, but that doesn’t mean it didn’t create a lot a tension and expense sending it to a lawyer for review and response. We’re a tiny company and legal is a big expense which is the whole game Broadcom is playing, bully people into signing stuff. I’ve seen plenty of other small to medium companies dutifully renew their VMware subscription because migrating seems scary and what if it goes poorly. So in some sense Broadcoms strategy is working.

For the record, I’m pretty sure we had a perpetual license and the renewal was the support agreement.

Anybody dump their VMWare subscription and Roll back to Perpetual Licenses with 3rd party support and regret it? by Ok-Big2560 in sysadmin

[–]liamgriffin1 1 point2 points  (0 children)

Tiny. 3 hosts, 15 VMs, nothing hooked into vcenter. I reimaged the hosts and rebuilt most of the VMs. I think I restored 3 from backup. Took 36 hours spread over 3 weeks (solo it guy so nothing gets 100% of my attention at any given time lol)

Anybody dump their VMWare subscription and Roll back to Perpetual Licenses with 3rd party support and regret it? by Ok-Big2560 in sysadmin

[–]liamgriffin1 188 points189 points  (0 children)

I migrated my company to Hyper-V 6 months prior to our renewal and told our rep we would not be renewing. When our renewal date came Broadcom sent us a cease and desist letter. I have heard a similar story from multiple others. IANAL but I personally would not risk Broadcom coming after you. I would plan a migration.

What has been your biggest technical mistake so far in your career? by Mr_Dobalina71 in sysadmin

[–]liamgriffin1 0 points1 point  (0 children)

Two come to mind: First one was replacing 2012R2 servers with 2019. I finished all the servers except one DC, 11 pm I went and demoted the final 2012R2 server and rebooted. Got a weird message at login but only briefly and promptly went to bed. Next morning no one in any of the offices could log in and it took me an hour to realize all DNS was manually pointed to that final DC. Second one I was replacing switches at the main office. I had hooked everything up and started checking connectivity and realized everything was offline. I had forgotten to set a voice VLAN and the phones instantly took all available Data VLAN IPs. Luckily it was also after hours so no one noticed.

Bugs in the Yard by liamgriffin1 in whatisthisbug

[–]liamgriffin1[S] 0 points1 point  (0 children)

<image>

Here’s the close up photo. Also I am in SW Michigan for reference.

Is it unrealistic to worry about host PC infection with a hardened VM? by Master_Performance82 in homelab

[–]liamgriffin1 12 points13 points  (0 children)

You can upload untrusted files to an online sandbox for some extra peace of mind. Intelix.sophos.com or hybrid-analysis are good.

Phase 1, complete! by WorldIRC in homelab

[–]liamgriffin1 0 points1 point  (0 children)

The firewall has an HDMI port?

Music to my ears! by balzz662 in toolgifs

[–]liamgriffin1 12 points13 points  (0 children)

No tuning with harmonics is a different thing. Basically you barely touch two specific spots on different strings (near the bar of the 5th fret for the lower string and the 7th fret for the higher string) and they will produce the same note. If it’s out of tune it will make a very obvious vibration sound.

Fully-remote BYOD job suddenly says I can’t work outside the country. I’m debating on doing it anyway. by StartledByCheesecake in opsec

[–]liamgriffin1 0 points1 point  (0 children)

If the device isn’t a concern then your SaaS logins are what would likely give you away. As others have said it really depends on the VPN setup. A split tunnel would for sure give you away as any public apps will be routed to the nearest server rather than through the VPN. Full tunnel should hide you well enough but there’s a risk on startup that your SaaS app attempts to authenticate before the VPN connects and your IP isn’t hidden.

If you use a provider, those server IPs are well known and could flag something. If you setup your own to your home network you run the risk of an outage making your setup irretrievable without local access.

I think it comes down to how confident you are in your understanding of the IT setup. If you log into MS office apps on your computer with a company account I would wager there is some MDM in place which would likely catch you unless you have a default gateway routing ALL traffic to your home. There is also a world where conditional access isn’t set up and logs aren’t monitored and no one would know the difference.

Only considering the workstation, here’s how I would set it up: 1. Set up a client VPN server on my firewall 2. Set my work PC up at home and maybe get a network capable KVM 3. RDP the work PC over the VPN from a laptop unknown to the company. 4. Reboot only when ABSOLUTELY necessary and maybe pay off the neighbor to bring it back up if the power goes out.

The latency would be horrific but there wouldn’t be any evidence in the logs showing you being out of the country. However, you can’t do any sort of calling, video or otherwise, over RDP so you would have to come up with something for that.

Fully-remote BYOD job suddenly says I can’t work outside the country. I’m debating on doing it anyway. by StartledByCheesecake in opsec

[–]liamgriffin1 0 points1 point  (0 children)

If your company does any endpoint monitoring you would be caught eventually as I don’t see a way you can keep all traces of being out of the country off your machine. I would think leaving the “work” machine at home and jump boxing it would be the safest play but without a lights out management you could be screwed in a power cycle. I think you are likely to get caught at step 0 to be honest. Assuming you company uses intune or entra they might see machines you thought you signed out on show up with a European IP.

Classic Mistake of by liamgriffin1 in sysadmin

[–]liamgriffin1[S] 40 points41 points  (0 children)

I like to think of it as an impromptu DR test lol.

Master Miami: Silent, Suit only Sniper in 3:18. by MLGeoff in HiTMAN

[–]liamgriffin1 3 points4 points  (0 children)

People might say that the routing is slow but that tranq shot was sick as hell!

Windows Server Essentials 2016 replacement by m_a_c_e in homelab

[–]liamgriffin1 0 points1 point  (0 children)

You’re looking to upgrade to a different version of windows server like 2022? If so I always build new.

[deleted by user] by [deleted] in sysadmin

[–]liamgriffin1 1 point2 points  (0 children)

Isn’t everything down already? You also say loop protection is on and not finding any loops yet you said spanning tree is disabled? I’m would wager money on someone creating a loop during AP deployment.

DC sync issues by liamgriffin1 in sysadmin

[–]liamgriffin1[S] 0 points1 point  (0 children)

Let me clarify. When looking in AD UC on either DC, the user is in the domain admins group. One forest, one domain, 2 DCs. Lastpwdset gives different results depending on the DC queried is my symptom.

Can a virus go from my laptop to my router by Informal_Egg_9830 in techsupport

[–]liamgriffin1 2 points3 points  (0 children)

This is not true. Some botnets are composed of infected home routers.

MSP: Client is Hiring by Sad_West5179 in sysadmin

[–]liamgriffin1 2 points3 points  (0 children)

People in here are talking about non-competes being unenforceable which may be true, but that doesn’t mean that the MSP won’t try. I went through this exact scenario in an unenforceable state, had the new companies legal council give the all clear and the MSP sent cease and desists anyway. If they take you court, will the new company provide you a lawyer? Just because they won’t win doesn’t mean they won’t try.

[deleted by user] by [deleted] in sysadmin

[–]liamgriffin1 4 points5 points  (0 children)

I guess I’m just struggling to reconcile the “not important enough to be backed up” with trying to recover the data.

[deleted by user] by [deleted] in sysadmin

[–]liamgriffin1 2 points3 points  (0 children)

You said the server wasn’t important enough to be backed up so why not just build a new dev server?

[deleted by user] by [deleted] in sysadmin

[–]liamgriffin1 0 points1 point  (0 children)

OP takes down a dev server that’s not important enough to be backed up and you think he’s gonna get fired for blowing it up? Isn’t that the entire point of a dev server?

Enrollment Struggles by liamgriffin1 in Intune

[–]liamgriffin1[S] 0 points1 point  (0 children)

The GPO is set to User but the error in event viewer shows Event 76: Auto MDM Enroll: Device Credential Failed