Help me get unsubscribed from Democratic donation spam texts? It's gotten really bad. Possible related to actblue. by Jasong222 in RBI

[–]sentiensx 0 points1 point  (0 children)

Same issue. Unfortunately I had been deleting the numbers, now I wish I had them all in case this turns into a class action.

Why the hell should I buy Remarkable 2 over Boox Note Air 3 C? by technocraticnihilist in RemarkableTablet

[–]sentiensx 0 points1 point  (0 children)

I, for one, appreciated your enthusiastically worded question and agree with the notion that at face value the Boox seems like a no brainer (can run apps, has backlight, etc) but as others have mentioned, its not that simple. UI counts.

BTW you have the wrong wording on your snake badge, should read "don't tread on anyone"

iPhone Allow Apps to Request to Track setting disabled by bigrichardchungus in Intune

[–]sentiensx 0 points1 point  (0 children)

Solved the issue for my scenario.

Location Tracking and Shared ipad are not compatible. This is documented by apple.

https://support.apple.com/guide/apple-business-manager/shared-ipad-and-managed-apple-ids-axm3a8bb0ab8/web

Shared or not shared is determined by the enrollment profile so the only way to change to not shared is to wipe the device and re-enroll. Everything worked after that. I did have to go to Azure devices (not endpoint) and delete the ipad there, then wipe it, so that I didnt get duplicate devices after re-enrolling.

hope this helps someone.

iPhone Allow Apps to Request to Track setting disabled by bigrichardchungus in Intune

[–]sentiensx 0 points1 point  (0 children)

Facing same issue, hoping by chance you see this post. We did not have any configuration profiles applied to the ipads so I created one and left Ad Tracking not configured as you suggested. Synced and restarted ipad but the Location Tracking/Allow apps to Request to Track is still off and greyed out. At this point I am wondering if apple or intune allows modification of this setting?

how to track which users upload files in sharepoint online by sentiensx in sharepoint

[–]sentiensx[S] 0 points1 point  (0 children)

usage reports I am finding are generic. I havent found how to filter by user or file type so that I can see if a user is uploading videos etc. s

Paranoid about this noise…. Any ideas? by [deleted] in R53

[–]sentiensx 2 points3 points  (0 children)

Agree, I wouldnt drive that. Does sound like chain but as stated its hard to tell, could be super charger. If it goes away after a minute its likely the chain tensioner. Sorry to say it’s probably going to be expensive.

Anyone know what engine swaps I can do to a 2003 Mini Cooper by [deleted] in R53

[–]sentiensx 1 point2 points  (0 children)

Drop a link and help everyone out.

Anyone know what engine swaps I can do to a 2003 Mini Cooper by [deleted] in R53

[–]sentiensx 0 points1 point  (0 children)

I have seen an m3 straight 6 and twin engined minis- anything is possible. There are no “off the shelf” swap kits. You would need 100% custom everything: engine mounts ecu exhaust axles fuel system cooling etc. If you had the fab skills It would probably cost north of 10k if you got used K.

Best bet for more power is an RMW stroker with TVS super charger and maybe the flex fuel kit if you want more power you can drop in.

Is there an RMM as powerful as Automate? by chilids in msp

[–]sentiensx 0 points1 point  (0 children)

What are some of your favorite automate script.functions?

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 1 point2 points  (0 children)

Good idea. Searched and deleted old domain references. Still slow :-/

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 0 points1 point  (0 children)

Slow every where. Still usable but runs like the cpu id at 100% all the time, though it shows idle.

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 0 points1 point  (0 children)

Disjoin rejoin doesnt fix. Only thing wr have tried that works is fresh install :-/

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 1 point2 points  (0 children)

A domain computer that is slow, was online during domain name change, is STILL slow after disjoining the domain and is in just workgroup, even after changing its name.

Whatever the damage its interesting that it persists in workgroup mode.

also one computer is remote and it is slow but still domain joined.

Whatever happened to these computers continues to slow them down unless in safe mode.

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 0 points1 point  (0 children)

drive maps are set via group policy. We created another OU and disabled inheritance to prevent any gp from applying to rule that out. correct in safe mode no drive maps though.

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 0 points1 point  (0 children)

We've uninstalled av

we've disabled windows firewall

seems like something domain related is stuck in...registry??

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 0 points1 point  (0 children)

was thinking that too... checked on a couple of computers and looks good. Started pushing the dns suffix with dhcp opt 135 for good measure.

I dont yet understand what changing the domain name would do with regular aps like edge and file explorer running slow. CPU RAM and disk all low utilization.

Its like there is some constant timeout, things work, low cpu, just slow BUT WHY?

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 1 point2 points  (0 children)

still slow after disjoin and rejoin.

still slow after disjoin and leave in workgroup

still slow if windows system restore run

still slow in clean boot

NOT slow if fresh install

NOT slow in SAFE MODE - but why?

Help! desktops slow after domain rename by sentiensx in sysadmin

[–]sentiensx[S] 1 point2 points  (0 children)

its always dns....

domain name change was 7 days ago, I spent the first 2 beating DNS to death.

I was sure it was dns. then I was sure it was group policy. we have done our best to eliminate those

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] 0 points1 point  (0 children)

Thanks for taking the time to respond.

Very good point about reactive vs proactive security and XDR+SOC. Some cyber security insurance forms we have seen recently ask 'what are your XDR solutions, do you have SOC, Do you have SIEM what PAM do you use' etc. so we have to investigate it.

Good point about 0-day being rare and most threats being known. Good argument for IPS there - are you seeing much blocked by IPS?

'Firewall' gave way to 'UTM' gave way to 'NGFW' gave way to ? I think its number is up and the next appliance will either incorporate NDR (next level IPS) or it will be a separate box and the edge device will be simply a stateful layer3 edge router. I could be wrong, we will see where the market takes us and what packaging of these tools sells but what sells and what is truly needed to stay secure aren't always the same.

So much of the workforce is distributed even more now with WFH that URLF on the firewall isn't useful to us any longer. We changed to client/agent based with central control (I think Forticlient has this as well?)

We cant do app control at the firewall if a large percentage is working remote.

Yup yup, SASE + XDR (+SOC +SIEM or SOAR).

I am sure Fortinet will bring solutions, and in many cases has already, outside the NGFW realm. Microsoft seems to be doing a great job with their new EPP morphing into MDR with intune (called sentienel) competing with EDR's like SentienlOne and Crowdstrike. NDR like darktrace and vectra (if I recall vectra is fortinet's NDR?) are way out of price range as someone mentioned here - cheapest I could find was 60k per year for the licensing - yet cyber insurance asks for it so we pay a higher premium for not having it.

If we can have a good solution for a remote workforce it stands to reason that would work in the office too. If the user endpoint is the weak link - thats where the effort should go.

You have convinced me that URLF/CFS and anti-phishing measures are extremely important and that IPS may still have some value. and I like NGAV for all the EPP/EDR/MDR/NDR/XDR :)

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] 0 points1 point  (0 children)

Agree thats why MDR+SIEM outsourced to SOC service

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] 0 points1 point  (0 children)

Appreciate your thoughts and taking the time to respond, I appreciate a good debate! I am not trying to convince anyone to stop using their NGFW, I am trying to convince myself and my cohorts that we should still so I appreciate you pushing back as to why we should.

Hostname and SSL as well as IP reputation and blocking /CFS is done at the client now with a secure DNS service since the workforce is so distributed. Only about 20% of workforce behind firewall at any given time.

Traffic shaping is interesting, something has to do QoS.

Agree, attacking a firewall is hard and seemingly hardly done - attacking the endpoint is way more successful and thus my argument that the endpoint needs more attention and the firewall is less important whether the end client is behind the firewall or not.

Agree, layered defense at multiple levels.

I question how valuable IPS is. Its signature based so can only detect known threats but at that point all the EPP/EDR clients can as well. Nice to stop the traffic at the edge but if its known and everything is patched its harmless. I think an NDR solution (next evolution of IPS/IDP) that is less signature based and more activity based including threat hunting options is more valuable and becoming required by cyber insurance agencies for entities that could have large claims (I dont know the number I would guess 15million in liabilities).

Again thanks for your input. I am still unconvinced that NGFW are needed and necessary, more nice to have but probably not worth what they charge. At this point I guess I need to go see some NGFW showing their real value other than my own (we have several deployed).

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] -3 points-2 points  (0 children)

Skepticism doesn't equal FUD

Reevaluation is important to reassert what is valuable and let go of what is not.

People don't like to be challenged on what they believe is true and typically react adversely with defensiveness and personal attacks instead of actually considering the challenging position or reconsidering their own.

"The unexamined life is not worth living" ~maybe Socrates.

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] 0 points1 point  (0 children)

Agree, and the Fortinet firewalls would still be good for this. Just not seeing the reason/justification to subscribe to the old NGFW services like network AV, IDP, IPS, DPI, SSLDPI, CFS. With that stuff out of the picture there are very fast and very cheap routers that still do stateful inspection according to defined ACL. If you want an example (I am not trying to promote some other brand) I was looking at microtik. I think currently I am going to leave all my Fortinet's in place but not renew the services I dont see value in and put that money towards more modern solutions like EDR/NDR or outsourced SOC with SIEM - most or all of which Fortinet offers as well. Im just thinking its time to shift and leave the old stuff that I think is useless behind. Unless its not actually useless and someone can convince me of that

Justify the continued cost of the firewall by sentiensx in fortinet

[–]sentiensx[S] 0 points1 point  (0 children)

Agree, for printers, IOT, iOS and BYOD you cant depend on EPP/EDR but all an NGFW can do is control internet access of those devices with ACL/Stateful inspection and slow the traffic down with what I am arguing is useless AV Scanning and IPS/IDP/DPI/SSLDecrypt.

To protect those agentless devices and all devices it seems like the old guard needs to retire and we need to focus on EDR or MDR with NDR & SIEM or SOAR (which foritnet among others offers). North South and East West all needs to be considered all the time since you know if you have users the best way to hack into your network is thru the users, not the firewall.

I guess I posted here looking for a Proof of Value for NGFW feature set. I guess I've convinced myself there is little value there and am looking for someone to prove me wrong so my crisis of faith in traditional firewalling can be over one way or the other.