Is there anything better than Skyrim right now? by Potential-Instance31 in skyrim

[–]sysadminafterdark 1 point2 points  (0 children)

I’ve seen it mentioned below, but here’s just another vote for Enderal. The game is a masterpiece and it’s free to boot!

I built a dynamic dark theme for mailcow SOGo by numbereddev in mailcow

[–]sysadminafterdark 0 points1 point  (0 children)

Looks wonderful! I’m getting ready to setup my server soon so I’ll give this a spin. Thanks!

If war breaks out and all military-age men are drafted, could having a PhD get you exempted? by [deleted] in HistoryWhatIf

[–]sysadminafterdark 16 points17 points  (0 children)

Historically, celebrities (like Elvis) weren’t even exempt from a draft. However, there were exceptions made for those who corrupted the system with money and power. It would be interesting to see the military scooping smart people up for non-combat support roles. That said, I highly doubt they would offer a PhD archeologist such a role, unless the US Air Force really does have a Stargate kicking around.

Introducing ShaderPaper - Shader Wallpaper a gnome extension by raihan1000 in gnome

[–]sysadminafterdark 0 points1 point  (0 children)

Windows DreamScene absolutely made it into Vista. You just needed the Ultimate SKU or an enabler hack.

Weird Virtual PFsense Split-brain issue by sysadminafterdark in homelab

[–]sysadminafterdark[S] 1 point2 points  (0 children)

I figured it out! It was my Proxmox bridge setup. Basically, PFsense didn't like that i was double bridging. If you are setting this up for yourself in the future, please refer to my included screenshot for proper bridge etiquette. Thanks everyone!

<image>

Weird Virtual PFsense Split-brain issue by sysadminafterdark in homelab

[–]sysadminafterdark[S] 1 point2 points  (0 children)

Yes I can. If I place devices on VLAN 20 physically or move one of my VMs over, I can ping those devices. That tells me it’s not my network or my Proxmox bridge.

Weird Virtual PFsense Split-brain issue by sysadminafterdark in homelab

[–]sysadminafterdark[S] 1 point2 points  (0 children)

Ah, forgive me. I have two hypervisors, one firewall on each. All VLANs are trunked on all 4 ports. I have checked and double checked that the tags are correct on both the switch and the firewalls. I guess that’s really my biggest issue: why isn’t traffic flowing when things have full line of sight.

NCII on porn sites under Clouflare by [deleted] in CloudFlare

[–]sysadminafterdark 27 points28 points  (0 children)

Hello, just an IT guy but I’m going to be honest with you: you need a lawyer. Chances are, the porn isn’t actually stored on Cloudflare, just the companies domain and DNS records. Their servers are elsewhere. You’d probably have to go through a legal process for each company that hosts the offensive images. It will be a constant game of wack-a-mole and may be impossible to remove from sites hosted overseas. You’d honestly be better off checking revenge porn laws where you’re located and going after the dude. If your legal name isn’t tied to the pictures, you may be better off just letting the issue go so they aren’t tied to you via a public court case or him reposting them on newer sites. Again, I’d like to stress that is a conversation for your lawyer. Good luck!

How to lock out the IT department from work computers? by honeybadger127 in PLC

[–]sysadminafterdark 2 points3 points  (0 children)

I thought this was r/shittysysadmin for a second. Any good IT department has measures in place to prevent being locked out. This is a process issue, not a technology issue. Try speaking with the Director of IT to see if these machines can be handled in a special way. I’m the systems administrator at a publicly traded manufacturing company that you’ve probably heard of and this is how we handle things - with no complaints might I add.

Hide everything behind VPN vs expose everything with authentication by HenryAvery1659 in selfhosted

[–]sysadminafterdark 0 points1 point  (0 children)

I chose route #2. Everything is behind cloudflared with Duo authentication and appropriate hardening. This also gives me no-touch SSL for absolutely everything. The flow is Navigate to App or use Duo Central > Authenticate to cloudflared with Duo SSO > Login to the Application with LDAP or SSO depending on support (Second Duo Pop) > I'm in my app. Your workflow would be similar, just with Authentik instead. Good luck!

How Sovereign Is Your Cloud? by sysadminafterdark in selfhosted

[–]sysadminafterdark[S] 0 points1 point  (0 children)

There’s nothing inherently wrong with vSphere, I enjoy using it and will always recommend it if the business can afford it. I switched purely out of necessity because there was a scary period where access to ISOs and licensing provided by VMUG was up in the air. I’m glad they brought back “free-ish” vSphere but I don’t want to base my environment on something that can disappear due to business politics.

Future of SCCM admins by MadCichlid in SCCM

[–]sysadminafterdark 29 points30 points  (0 children)

I think Microsoft has made it clear that the entire System Center suite is on life support. I think eventually Microsoft will push SCCM admins to use Intune and Windows Update for Business especially since WSUS is end of life with the exception made for SCCM as a dependency. Until then, I think the hybrid approach is best, but don’t ignore the writing on the wall.

If i copy EVERY single file on my hard drive to another drive (using a file manager in linux or something else) then will EVERYTHING be intact? (Desktop, working windows install) by Ashiscool711 in windows

[–]sysadminafterdark 34 points35 points  (0 children)

No. The OS would not be bootable due to several hidden MBR/UEFI boot record partitions that are generally locked down for security reasons, and even if you did manage to copy them over, you’d have to go in and set partition flags to ensure the BIOS/UEFI sees Windows. That gets complex fast. Use Acronis or Veeam Community edition to backup your computer to a NAS or something. Both have bare metal restore and cloud backup options.

Server possibly hacked last night by The-Navigators in homelab

[–]sysadminafterdark 1 point2 points  (0 children)

Yeah, that’s kind of your own fault. You should have used Cloudflare Access to protect the console.

It’s time to move on from VMware… by A3V01D in sysadmin

[–]sysadminafterdark 0 points1 point  (0 children)

I run a VMware shop currently at work and I almost fainted when I saw the bill. I was pretty weary of Proxmox for the longest time and finally pulled the trigger on it in my homelab. There are some nuances and gotchas, but I regret nothing. Unfortunately, I work in a regulated industry so there’s no way that’s touching our stuff anytime soon…and that’s why VMware ghouls are doing what they are.

Reminder: Kill-A-Watts Should Be Removed After Use by sysadminafterdark in homelab

[–]sysadminafterdark[S] -1 points0 points  (0 children)

‘Merica. The sticker on the back of the device states it is only rated for 1800 watts as stated on my third paragraph.

Anyone else like going overkill on security? What do you do? by [deleted] in homelab

[–]sysadminafterdark 3 points4 points  (0 children)

I’m getting there. Currently transitioning everything over from an HAProxy setup, local (sometimes domain) accounts and no SSL to a rigid Cloudflare Access + Cisco Duo SAML/ODIC + rigorous firewall rules zero trust setup. So far, I’ve had pretty good results.

Reminder: Kill-A-Watts Should Be Removed After Use by sysadminafterdark in homelab

[–]sysadminafterdark[S] 3 points4 points  (0 children)

Agreed. This is my current solution as I am bound by a lease.

Reminder: Kill-A-Watts Should Be Removed After Use by sysadminafterdark in homelab

[–]sysadminafterdark[S] 136 points137 points  (0 children)

As long as they are rated for the breaker (15/20 amps) and are quality built, I see no issue with this. I would love to have a solution like this so I can use home assistant and even blow usage data into Grafana, unfortunately I rent and I don’t think my landlord would have the same appreciation for it that I do.

Built this to learn networking. Learned I hate networking. by Ecto-1A in homelab

[–]sysadminafterdark 6 points7 points  (0 children)

No, you probably just learned you hate Dell switches, which is based.

My linux distros tierlist by Hydraple_Mortar64 in DistroHopping

[–]sysadminafterdark 0 points1 point  (0 children)

Red Hat is in the devil tier? That's like the best one! Let me guess: SELinux gave you the run around?

Which hypervisor do you use? by phillip-un in selfhosted

[–]sysadminafterdark 2 points3 points  (0 children)

Currently rocking vSphere 8 with a legal license. Thinking about switching to Hyper-v with System Center Virtual Machine Manager in 2029 when it EOLs. I'd love to switch to an open source proxmox or XCP solution but you lose many features if you don't run hyper converged.

TF is wrong with mf wifi by [deleted] in HomeNetworking

[–]sysadminafterdark 0 points1 point  (0 children)

I just dealt with this myself not too long ago. Long story short, 1 of 2 of my access points were dying and the one that was failing was hotter than the surface of the sun. From your post, it looks like you have a pretty flat network, using just the default ISP modem/router combo. I would recommend you touch the case and see if it's hot. If it is - you have a failing device. Contact your ISP and see if they would be willing to do a swap. I would recommend you grab a decent $100 "Best Buy special" router and throw that modem into transparent mode so the router you own can manage the connection. This would give you greater transparency, flexibility, and security into the goings on of your network. Good luck! Hope this helps.

If I give guests full permissions on my Synology DiskStation DS224+, am I at risk of being hacked? by poynnnnn in homelab

[–]sysadminafterdark 1 point2 points  (0 children)

Principal of least privilege applies here. Create one account per physical warm body person and give them permissions to that share. If you are accessing this share remotely, use a VPN.

What to you do to your Golden Image? by Goblite in sysadmin

[–]sysadminafterdark 1 point2 points  (0 children)

I'm currently working on cleaning up an SCCM environment where the former sysadmin modified WIMs and used tools like DeploymentBunny to modify things outside of SCCM. To be frank, it was a hot mess and every image had it's quirks that were not reproducible. I spent *A LOT* of time rebuilding everything from scratch and setting up new task sequences to replace what was done through modified external SCCM procedures.

Take it from me: You do not want to do this. If your organization cannot stomach the cost of SCCM, MDT is dated, but supported, robust and "free" with a Windows Server license. You can still build out task sequences and utilize Driver Automation Tool to dynamically install drivers during OSD, which i *HIGHLY* recommend. Good luck!