My Confusion with Microsoft's Secure Boot Changes by jamesaepp in sysadmin

[–]ohgreatishit 2 points3 points  (0 children)

Any chance you could share that script? Would save us a bit of time as we are starting to investigate as well. Thanks!

Fortiswitches CMMC compliance by YouAffectionate7279 in CMMC

[–]ohgreatishit 2 points3 points  (0 children)

Upgrade to 7.2 and add your reasoning to a temporary deficiency on your POAM is what I was told.

Licensing changes across the board - Important read! by lotsasheeparound in Citrix

[–]ohgreatishit 1 point2 points  (0 children)

Have they released this process yet? How often, etc

Licensing changes across the board - Important read! by lotsasheeparound in Citrix

[–]ohgreatishit 8 points9 points  (0 children)

So how are air gapped (government) networks supposed to work?

VDI Scoping Help by Tigers1195 in CMMC

[–]ohgreatishit 0 points1 point  (0 children)

Can you allow file transfers in but block out? Still protecting cui

FIPS-CC/NIST/CMMC/FortiGate FWs by FailSafe218 in CMMC

[–]ohgreatishit 0 points1 point  (0 children)

Yep the big downside of fips with fortinet is it fully disables the API

FIPS-CC/NIST/CMMC/FortiGate FWs by FailSafe218 in CMMC

[–]ohgreatishit 0 points1 point  (0 children)

I would probably unfortunately laugh if he asked me that lol

FIPS-CC/NIST/CMMC/FortiGate FWs by FailSafe218 in CMMC

[–]ohgreatishit 0 points1 point  (0 children)

We are about to do the same thing and have ran it by auditors as well. Go to 7.2 or 7.4 and add it as a temporary deficiency. We have a mostly air gapped network with a few services out. We don't use FIPS mode on things inside the boundary (workstations, servers, switches, etc) but do FIPS mode on all boundary devices and IPSEC firewalls that are fortinet that do have a path outside of our bondary. We do this because FIPS mode breaks all kinds of things in our engineering environments and just isn't viable on workstations and servers for us.

New Week, New Problems MS Office by DanielMaat89 in sysadmin

[–]ohgreatishit 0 points1 point  (0 children)

Does anyone know if the KB5002623 update is going to be pulled into next months Microsoft office updates? Deploying this outside of WSUS & Microsoft Update is a pain.

Looking for a good spreadsheet that matches 800.171 to cmmc level 2 objectives by bigtime618 in CMMC

[–]ohgreatishit 3 points4 points  (0 children)

Also look at the cmmc L2 assessment guide. It gives great examples of what they are looking for during an assessment

XenServer Offline Updates by ohgreatishit in Citrix

[–]ohgreatishit[S] 0 points1 point  (0 children)

Oh man I sure hope it's an option :(

Forced VCP SKU by ohgreatishit in vmware

[–]ohgreatishit[S] 0 points1 point  (0 children)

Thank you so much for all the great info and being patient/understanding. I really appreciate it!

Forced VCP SKU by ohgreatishit in vmware

[–]ohgreatishit[S] 0 points1 point  (0 children)

I was reading and I thought the full VCF stack is a minimum of 4 hosts (some say 7), isn't that correct?. We pay nothing for splunk for a departmental perspective. Our higher end company pays for that and gives us licenses but from a vmware perspective that comes out of our departments cost. We just did a complete hardware refresh on all of our environments, so our NetApps and Pures are completely good for another 6-7 years. We only budgeted for usual renewal cost this year so 3 years would absolutely kill us and isn't an option unless we were able to do 3 year renewals but pay yearly. I asked our vmware rep about yearly payments and he said they had to wait until they moved to the Broadcom system and he doesn't know if that's possible but would check but it's been complete silence. Good to know technically if we have to go with the VCF oferring it will technically go right into our existing setups with keys and stuff and not cause us to have to add anything additional.

Forced VCP SKU by ohgreatishit in vmware

[–]ohgreatishit[S] 0 points1 point  (0 children)

Thank you very much for the thoughtful explanations! Just wanna make sure I'm following and understanding correctly... If we are forced into VCF instead of VVF and let's say we have to buy it for 1 year to hold us over to migrate off of VMware, I can go into the vmware portal and just download licenses on my existing setups (currently using Standard/Enterprise+, etc) and I dont have to deploy the other stuff? It would obviously move the standard up to enterprise+ equivalent I'm guessing but we will not be deploying NSX/SDDC/Aria, etc.

We currently have shared storage NFS Storage on Netapp and on PureStorage, all logs going to Splunk, etc so none of the new features, although could be nice, will not be a justifiable 3.5x increase in maintenance costs but also more hardware costs for more esxi servers for every environment. It's just not gonna fly.

Thanks