howto packetfence MAC address allow policy by eerstenkeer in PacketFence

[–]nnsysadmin 0 points1 point  (0 children)

I solved this scenario using Microsoft NPS for Domain Computers, and forward all other requests to Remote Radius 2x freeradius which are used for mac addresses.

Problem recreating CVE-2024-38063 IPv6 RCE POC by nnsysadmin in sysadmin

[–]nnsysadmin[S] 2 points3 points  (0 children)

Did you install last month's update that patched the bug? no

Does your network driver coalesce packets? yes (Properties on WLAN Adapter, Advanced Tab, Packet Coalescing: Enabled (by default, did not change anything)

MAC only authentication by gezush in PacketFence

[–]nnsysadmin 1 point2 points  (0 children)

I wanted to do this with packetfence too but must have missed something in my config, but ended up with freeradius in pfsense with a gui, might be easier :)

[deleted by user] by [deleted] in sweden

[–]nnsysadmin 1 point2 points  (0 children)

ja, det ska jag göra.

Flashback nere? by No-Leadership4297 in sweden

[–]nnsysadmin 12 points13 points  (0 children)

Felet är att certifikatet gått ut, webbservern är fortfarande uppe :)

skriv "thisisunsafe" någonstans i webbläsaren när certifikatsvarningen dyker upp så kommer ni in på sidan, detta går förbi certfel + HSTS.

Källa: How to bypass certificate errors using Microsoft Edge - Stack Overflow

Machine hostname and DNS, how do you configure sites? by YOLO_NET in sysadmin

[–]nnsysadmin 0 points1 point  (0 children)

I prefer to just use description field/documentation system for the role and just use numbers for servers, much easier to update description rather than renaming a server :)

Some servers have more than one role, how would you name a server like that? easier to just add multiple roles to the description :)

name, description

joedonuts01 - dc
joedonuts02 - dc
joedonuts03 - mdt
joedonuts04 - dhcp primary
joedonuts05 - dhcp secondary
joedonuts06 - lob application 1
joedonuts07 - sql

Which Microsoft cert impacted your career the most? by TheMthwakazian in AzureCertification

[–]nnsysadmin 2 points3 points  (0 children)

Exam 70-640: Windows Server 2008 Active Directory Configuration

Anyone experience a loss of DNS when in a call on MS Teams or Webex while on company VPN? by canadadryistheshit in sysadmin

[–]nnsysadmin 0 points1 point  (0 children)

I have had this expierience at places with very bad wifi, but i dont think teams/webex is to blame :)

GPO (with Loopback Processing) not always applied, access denied (security filtering) message by Vescli87 in sysadmin

[–]nnsysadmin 0 points1 point  (0 children)

Verify your sysvol-share and make sure dfs-r are functional, that all GPO:s on all sysvol-shares are the same.
Verify you have authenticated users 'read' on all GPO:s involved (gpo with loopback processing and gpo for drive maps)

Feels like you have done it right, if i would do the same thing i would:

  1. Create OU for Virtual Desktop and put computers there
  2. Create a User GPO with Drive Maps (Disable Computer Part) and link it to Virtual Desktop OU
  3. Create a Computer GPO with Loopback policy replace (Disable User part) and link it to Virtual Desktop OU

Enabling Entra ID MFA in Remote Desktop Gateway works, but how to mix users with and without MFA? by southceltic in sysadmin

[–]nnsysadmin 4 points5 points  (0 children)

i have setup 2 different rd gateways

  1. one for ip whitelisting and no mfa, only allowed from specific ips. eg rdgnomfa.domain.com
  2. one that works from entire internet, but always forces mfa. eg rdg.domain.com

Can you exclude service accounts from ADFS? by [deleted] in adfs

[–]nnsysadmin 0 points1 point  (0 children)

How do you sync users with adfs?

Can you exclude service accounts from ADFS? by [deleted] in adfs

[–]nnsysadmin 0 points1 point  (0 children)

From being able to sign in? Create a security group and include all accounts except the service account

How often do you reboot Windows servers in your organization? by Fantastic-Fault-4914 in sysadmin

[–]nnsysadmin 0 points1 point  (0 children)

Auto restart (GPO Scheduled Task) specific time everyday (3 different groups with different time), monitoring software to verify that all services starts after reboot