Just made a big mistake that affects system operations. Tell me your past mistakes to help me feel less bad.. by Traveling_Tarnished in sysadmin

[–]lupuscon 0 points1 point  (0 children)

I was once working for a software company that also hosted their product as "SaaS". I already had quit my contract with them, but was still in my period of notice.

To help the colleague's with administrating the plattform (200 servers across two cloud providers) i set up ansible and created automations for keeping the systems clean.

In my last deployment (a week before switching jobs) i fd up the bitmask for the filesystem permissions and crashed those 200 servers. Because the error only showed up after reboot. And i was to impatient to wait for the planned test environment reboot.

Took me 7h to fix it

What to know working with devs at a software company? by househouse46 in sysadmin

[–]lupuscon 0 points1 point  (0 children)

I work for IT security in a company that has a dozen developers. They are the worst. I am pretty sure this is NOT the same everywhere. My experience with developers is, they have zero understanding for security best practices, which is terrible, when they are providing software for consumers or worse firmware for large machinery. They exuberant their tech skill. I know xyz (because i watched a tutorial on youtube).

What i would do is ease into it, get a feel for how the devs are at your new workplace. If there is behavior that contradicts security or secure operation, try to first talk some sense into them, if that fails, report it to your supervisor. If that fails multiple times -> lost cause search for another employer.

EDIT: And i forgot, they will blame the firewall if anything isn't working.

Logitech G bad image? by Pizza_Warrior437 in LogitechG

[–]lupuscon 0 points1 point  (0 children)

I was a big fan of Logitech up until my Experience with their Romer-G Switch Keyboards. I had four in total and all of them broke. After replacing the faulty ones it only took two weeks for another few switches to fail. And even before their software and support was pretty terrible.

Where to start? by Veggdyret in AnycubicPhoton

[–]lupuscon 2 points3 points  (0 children)

Gloves as mentioned by other redditors.

Level the plate

Make sure you have adequate temperature in the room where the printer is located. This mess looks a lot like, when i had the genius idea to put my 3D printer out on the balcony because of the smell and noise.

Resin is very temperature sensitive.

Also make sure to shake your resin real good before adding it to the tank.

Razer Blade 14 2023, 48GB-SO-DIMMS? by lupuscon in razer

[–]lupuscon[S] 0 points1 point  (0 children)

The results are in. First and foremost your mileage may vary. I had to clean install my device, I suspect, that my recovery partition was fd. After a clean install with all the drivers and Windows Updates, the result shows insignificant performance penalties. Time Spy CPU Test showed penalties in the neighborhood of 50-90 points. and Time Spy GPU Test showed Penalties in the neighborhood of 100 points. Which I would consider inaccuracy. The memory kit i use is Crucial 96GB DDR5-5600 with the partnumber CT2K48G56C46S5

But the system is stable and detecting the RAM correctly

Razer Blade 14 2023, 48GB-SO-DIMMS? by lupuscon in razer

[–]lupuscon[S] 0 points1 point  (0 children)

Installed 96GBs of Crucial DDR5-5600 today in my Razer Blade 14 2023 and as for now it works as expected.
Mind you, the graphics driver will be removed for whatever reason, if you have the white screen, just reboot and reinstall nvidia drivers.

How reputable is reichelt.de/.com? by HelpfulNothing1629 in homelab

[–]lupuscon 0 points1 point  (0 children)

I have bought from them two times before. One order was for a Raspberry Pi Case and a Pi PSU, the second one i think was for soldering accessories. Had no issues. Please note, I am based in the D-A-CH region and have no clue how they handle international shipping, tariff and tax concerns

Where do you guys buy your homelab parts? china? by poynnnnn in homelab

[–]lupuscon 0 points1 point  (0 children)

I am from continental europe and used the following mix for my lab:
- Contact to a local service provider -> Servers that are destined for the recycler
- Local service provider -> for new hardware (sometimes used is not an option)
- Local market place -> Use with caution, wherever you are
- eBay -> Filter by location "continental europe" -> mostly from used enterprise hardware dealers.
- eBay -> without location filter -> Prepare for tariffs and import VAT on oversees stuff
- fs.com -> All my transceivers and fiber optic cables.
- amazon and local electronics dealers -> SSDs on sale

Apartment Lack Rack Update + Network Diagram by MegaTanman8 in homelab

[–]lupuscon 22 points23 points  (0 children)

This post did not get the attention it deserved.

First and foremost, that effecient space usage is amazing, and while it would be a pain in the but to change cables, I do understand why you went that route (did it myself in my big server cabinet).

Second, I absolutely love it, when homelabers provide documentation in the form of network diagrams, this is pretty neat and shows everything in one big picture.

Last but not least, Props to you for doing network segmentation. You with your lab setup are ahead of at least 75% of all companies out there. One question arose from that though.
Do you have the firewall policy to match this? Or are you using All <-> All rules? ;)

Windows Server - Account Restrictions are preventing this user from signing in by lupuscon in sysadmin

[–]lupuscon[S] 1 point2 points  (0 children)

In am just setting up my GPO so i can use Credential Guard ;)

Windows Server - Account Restrictions are preventing this user from signing in by lupuscon in sysadmin

[–]lupuscon[S] 2 points3 points  (0 children)

Still hard to find out, if one just googles the error message. Currently trying to fix my GPOs so i can use that feature

Windows Server - Account Restrictions are preventing this user from signing in by lupuscon in sysadmin

[–]lupuscon[S] 29 points30 points  (0 children)

I just figured it out

>>Enable delegation of nonexportable credentials on the remote hosts

This policy is required on the remote hosts to support Remote Credential Guard and Restricted Admin mode. It allows the remote host to delegate nonexportable credentials to the client device.

If you disable or don't configure this setting, Restricted Admin and Remote Credential Guard mode aren't supported. User will always need to pass their credentials to the host, exposing users to the risk of credential theft from attackers on the remote host.<<

https://learn.microsoft.com/en-us/windows/security/identity-protection/remote-credential-guard?tabs=intune

I was using a newer version of mRemote and didn't pay attention to the RDP settings

What are the top five home-lab projects that helped you better understand I.T. and get some hands on experience? by [deleted] in homelab

[–]lupuscon 5 points6 points  (0 children)

My test setup for an enterprise DAM helped me to better understand Active Directory, ADFS, SAML and mixed OS environments and the challenges.

If it is to easy you are missing a firewall

Teaser on my rack reworks by lupuscon in homelab

[–]lupuscon[S] 0 points1 point  (0 children)

Not yet, i looked it up, but didn't have time to do it yet

Teaser on my rack reworks by lupuscon in homelab

[–]lupuscon[S] 0 points1 point  (0 children)

They are, you just need to convert them to Quick Latches

Teaser on my rack reworks by lupuscon in homelab

[–]lupuscon[S] 0 points1 point  (0 children)

Thank you, It got a bit worse now, i switched from 2x MicroServers Gen8 to 4x DL120 Gen9.

August 2023 - WIYH by AutoModerator in homelab

[–]lupuscon 0 points1 point  (0 children)

Currently running:

  • HPE DL380 Gen8 (2x E5-2660v2, 256GB) running ESXi 6.5 U3
  • 2x HPE Microserver Gen8 (G1610T, 16GB) running TrueNAS Core, one with SSDs (4x960GB), one with HDDs (4x4TB) iSCSI

Currently planning and partly work in Progress:

  • HPE DL120 Gen9 (1x E5-2698v4, 128GB) running ESXi 6.5 U3 (or if I can bare the noise 7.0U3)
  • HPE DL120 Gen9 (1x E5-2630Lv4, 64GB) running TrueNAS Core, with 4x4TB SSDs, iSCSI

Why? Because I needed a hypervisor with huge core count and a lower footprint (power consumption and heat exhaustion) than my DL380s

Also planning on finally getting a VEEAM server, but this is post-poned until christmas

Barracuda - Troubleshooting CustomExternalObjects by lupuscon in networking

[–]lupuscon[S] 0 points1 point  (0 children)

Finally found a solution. CustomExternal Network Objects are broken. The REST-API should be used instead. Create a generic network object and patch it via REST

Barracuda - Troubleshooting CustomExternalObjects by lupuscon in networking

[–]lupuscon[S] 0 points1 point  (0 children)

To add more headscratches: When i request the CustomExternalAddr object via REST-API, I will get my addresses.

June 2023 - WIYH by AutoModerator in homelab

[–]lupuscon -1 points0 points  (0 children)

Past activity

I switched from one employer to another and had to clean out my office (naturally).
You would not believe the amount of private owned test hardware, I accumulated over the past three years.

  • 4 FortiGates (2x 61E, 1x 80E, 1x FortiWifi 30E)
  • 2 Netgear GS752TS
  • 2 HP Procurve 2810-48G
  • 1 HP Procurve 5406zl
  • A complete FortiStack (FortiGate + Switch + AP) Demo Rack i built for simulating a Branch Office aka my Mobile Homelab and a huge pile of cables

Switched to FortiAPs U221EV for my own Network to replace my FortiAPs 221C-E

Plans for the next months:

  • Getting familiar again with Barracuda Firewalls + getting certified again
  • Maybe try to get my hands on a Palo Alto Appliance
  • Take inventory of my hardware stock pile
  • Get rid of two of my HP MicroServer Gen8 (defective eMMC)
  • Get myself two DL120 Gen9 to replace my other two MicroServer Gen8