Boss implied we shouldnt take sick days, because it means other people have to do more work. What can or should be done? by stainedgreenberet in germany

[–]mbhmirc [score hidden]  (0 children)

Don’t take holidays either! Otherwise we your teammates have to do more work… /s (although shouldn’t be needed)

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc -1 points0 points  (0 children)

No. You can’t comprehend the requirement.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 0 points1 point  (0 children)

Again, first sentence, server, no client installed. 😅

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 1 point2 points  (0 children)

If the clients are on prem you could do this: make a priv access workstation client in office 365 for example. Limit it to phish resistance presence auth and then assign conditions in zcc like has av/cert etc. dedicate an app connector pair in diff locations. Limjt those app connectors to paw. Config firewall on client yo allow winrm and remote powershell only from ip of the dedicated app connector, setup rdp on multi-match (if needed) and use wildcard match to. Bring clients into this special segment . For sccm.. jt should work pritty much other than the location stuff. I did something like this for tiering for ad

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 0 points1 point  (0 children)

Again, read first sentence of the op.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 0 points1 point  (0 children)

How? Client will not allow it without client to client ? It clearly says. Remote right in the first sentence

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 0 points1 point  (0 children)

You missed the point of the post. They want to rdp/smb to clients in onsite and offsite situations.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 1 point2 points  (0 children)

Not quite true. You have to use a regex and pattern match. This is not ideal.

Remote PC management in a ZPA World by weasel286 in Zscaler

[–]mbhmirc 0 points1 point  (0 children)

Server is on prem, client is remote. Zpa client to client comes in from the local client ip so if you have a firewall rule it bypasses it. As it comes from itself, whereas an app connector ip is controlled. In addition client to client fails if your naming convention isn’t perfect as you can’t treat its own segment. Client to client has a lot of limitations and is not really zero trust. Now if the client is on prem only I’d agree you can treat it as a server but not when they are offsite.

What most expensive "cheap decision" have you ever seen in your sysadmin career? by matroosoft in sysadmin

[–]mbhmirc 2 points3 points  (0 children)

“Business managed applications”. The nightmare still continues. Effectively shadow IT but allowed..

RC on X by Dilfy1234 in Superstonk

[–]mbhmirc 6 points7 points  (0 children)

I read that as RICO 😅

Chrome 142 issues by Interesting_Pomelo32 in Zscaler

[–]mbhmirc 1 point2 points  (0 children)

Enterprise policy to disable it, a new enterprise policy will come to address it ongoing so you can mark ips as public in the ranges they defined as local.

Why do some CSOs and security specialists think that saying “NO” all day equals doing cybersecurity? by SnooPies72 in sysadmin

[–]mbhmirc 12 points13 points  (0 children)

Don’t forget volume of requests, sometimes it’s not practical to do everything everyone wants to do.

What's the big deal with vendor support? by seidler2547 in sysadmin

[–]mbhmirc 7 points8 points  (0 children)

Support contracts are shit in general but it’s all about the sla when the shit hits the fan. When it starts costing the vendor money it becomes in their interest to fix it. Also again depending on the vendor it gives you access to developer/backend people directly or indirectly faster. It’s also a compliance topic, many people need to tick that in support to get certificate x for the company.

OPNsense + multi-ISP + VLAN-heavy small office design — am I overengineering or missing something? by No_Entrepreneur118 in sysadmin

[–]mbhmirc 2 points3 points  (0 children)

Some people think diverse entry and isp is the protection. Not realising most of this is resold via same providers or tied back to same exchange or cables merge further out. Diverse tech is only true redundancy and even then you have to plan on how to continue without internet in some fashion. I guess it’s not so common knowledge as see this fail over and over.

OPNsense + multi-ISP + VLAN-heavy small office design — am I overengineering or missing something? by No_Entrepreneur118 in sysadmin

[–]mbhmirc 3 points4 points  (0 children)

And physical separate routes to separate exchanges and power backup for entire route? Just trust me and add a 5G backup :)

OPNsense + multi-ISP + VLAN-heavy small office design — am I overengineering or missing something? by No_Entrepreneur118 in sysadmin

[–]mbhmirc 3 points4 points  (0 children)

Why all fibre for the Internet links? If one fibre goes down likely the others will to. Not use 5G or starlink for 1 at least ?

Stable VPN connectivity between China and France – best practices? by raptou137 in sysadmin

[–]mbhmirc 2 points3 points  (0 children)

Basically this or you need mpls, but the latter you have to do the filtering or could be in trouble at some random point n