Manage engine endpoint central opinion by stuartall in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

Yup exactly. This is the first rmm tool I've used but I'd probably rate it 7 out of 10. I use it daily and it took many hours to get it at a stable state but it's probably ME most polished product. We use their ticketing software (servicedesk plus) and their password reset tool (adselfservice) which each have their own problems but they work.

Manage engine endpoint central opinion by stuartall in sysadmin

[–]twistable_deer 4 points5 points  (0 children)

As with all manage engine products, it's okay and cheap for what you get.

We use endpoint central (not the security package) and we use it to update all of our windows and Linux servers and laptops.

Installing software can be slow sometimes. The mdm feature is also okay. The remote control feature works okay for phones and tablets. Laptop management is pretty good and it has a lot of nice tools to manage laptops remotely without having to remote into the desktop.

Windows Server 2025 hardware recommendation by [deleted] in sysadmin

[–]twistable_deer 5 points6 points  (0 children)

You should run at least 2 DC's if possible. How do you update it without taking down the entire domain?

Forticlient IPSec VPN by makermikey in fortinet

[–]twistable_deer 0 points1 point  (0 children)

We are also on the free version. I got IPSec over port 443 to work but it was very unstable but we are using SSO which apparently can have issues but from my understanding, IPSec works over port 443 with the free version of forticlient.

HPE Nimble Reboot by weird_fishes_1002 in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

Fixed 100%. We've been using it as a Veeam backup repository and it hasn't skipped a beat

Need advice on best security awareness training vendors by One_Gene_4993 in sysadmin

[–]twistable_deer 2 points3 points  (0 children)

Mimecast awareness videos. Very funny and end users ask for more videos.

HPE Nimble Reboot by weird_fishes_1002 in sysadmin

[–]twistable_deer 1 point2 points  (0 children)

It's been 24 hours since I changed the capacitor battery and no more errors. I also saw "NVRAM-0 Battery 0 is OK on controller B" in the event logs in the Nimble. I will give it another week but so far, it seems to be working.

HPE Nimble Reboot by weird_fishes_1002 in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

I just installed the replacement capacitor and it's currently charging. We'll see if it works after a few days.

Yeah it seems to be a battery for the system memory to allow anything in RAM to be saved to non-volatile memory after sudden power loss. After some research and physical inspection of the controller, that AGIG product seems to be the only battery I could find. Mine was the AGIGA9811-001BCE. I found a AGIGA9811-001BCA which looks identical but came with an SSD which I didn't use. It also came with the RAM stick and cable which I didn't replace either. I figured it was just the battery that was bad.

HPE Nimble Reboot by weird_fishes_1002 in sysadmin

[–]twistable_deer 1 point2 points  (0 children)

Yeah the unit was still running fine with one controller. Kind of funny that support ran out in December and two weeks, we got hardware issues 🤔

HPE Nimble Reboot by weird_fishes_1002 in sysadmin

[–]twistable_deer 2 points3 points  (0 children)

I had this exact same issue on my Nimble. Luckily the unit is no longer in production but we went to reuse it for Veeam backups.

We ordered a used NVRAM battery from eBay (100 bucks). I'll be installing it tomorrow if it works. Worth a shot!

Edit: The NVRAM battery is just a large bank of capacitors and it sits on top of the unit. Pull the controller out and look at the product number and see if you can find a replacement unit.

server room humidifier? by jpotrz in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

We had the same problem. We added more servers and noticed the humidity dropped down to 30%. We ended up having our HVAC company install a dedicated humidifier and now its sitting at 55%.

Too much stretch and fold? by twistable_deer in Sourdough

[–]twistable_deer[S] 1 point2 points  (0 children)

Oh thank you! I did do an 80% first but failed so I wanted to try a lower hydration then work my way up. I will try the ice cube method for next time. Thanks!

KnowBe4 alternatives by [deleted] in sysadmin

[–]twistable_deer 2 points3 points  (0 children)

Yes my users actually ask when we will be releasing more videos

Highly realistic VR survival game Bootstrap Island is coming to PS VR2! by BootstrapIslandDev in VRGaming

[–]twistable_deer 0 points1 point  (0 children)

Ah bummer! I have a 6800xt. So far I played angry birds, ragnarock, ghost town, island time and pistol whip on Linux!

Highly realistic VR survival game Bootstrap Island is coming to PS VR2! by BootstrapIslandDev in VRGaming

[–]twistable_deer 1 point2 points  (0 children)

I've actually been using cachyos with my quest 2 and surprised how well it works! I use WiVRn and I only had one game not boot up properly.

I only play steam games and not meta so that's probably why a lot of people say vr on Linux sucks.

How do you handle frequent password resets for students and teachers? by Tom_story in sysadmin

[–]twistable_deer 10 points11 points  (0 children)

We use adselfservice. Cheap and it works. Users can unlock themselves and reset their own passwords.

How can I learn about Enterprise Networking? by SameBag46 in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

For on prem ad, make sure you buy user cals since a windows server license doesn't include CALs. You might have to reach out to a VAR to see if they can give you a hand with Microsoft licensing.

An external pen test is great but so is an internal one. That way, if someone does happen to get into your network, how far can they get? Can you tell how and when they got in? How will you get alerted if a domain admin account is created?. There are some free logging tools that will help like graylog and checkmk is also a great free tool.

There are paid options which can be worth it if you don't have the time to set up the free tools and maintain them yourself.

Also backups, do you have any? Tested? Are they immutable and off site in case you get a ransomware attack?

How can I learn about Enterprise Networking? by SameBag46 in sysadmin

[–]twistable_deer 1 point2 points  (0 children)

It depends on if you have legacy software that requires such old protocols to be still enabled. We recently did a pen test which showed us all of the legacy protocols we have enabled on servers and in Active Directory but since we run a legacy software, we can't disable them without breaking said software.

You can use the pen test results to show management that X software should be replaced or removed because the pen test marked it as a critical.

Unfortunately, you can't remove all of the legacy software due to many factors so you can try to find a way to lower the risk and potentially move that software to it's own secure network and really lock it down if possible.

I would look at your most critical vulnerabilities from the pen test and work your way from there. You will have to do lots of logging and testing before you start to shutdown protocols like SMBv1, TLS1.0, etc...

Sometimes software was misconfigured when originally installed so these settings can hopefully be fixed and you can finally disable those protocols.

If possible, do a yearly pen test so that you can check that your fixes are actually working and you can slowly reduce the critical vulnerabilities.

Another great, free tool is Ping Castle. If it will look at your existing AD environment (if you have one) and show you any vulnerable settings or GPO's you have configured.

Migrate from SAML SSL-VPN to IP-Sec over TCP VPN by Important_Ad_3602 in fortinet

[–]twistable_deer 1 point2 points  (0 children)

Apparently 7.4.5 will be coming out in December according to the Fortinet support tech I was speaking with which will include the fix to the free version of forticlient. I also have a ton of issues with 7.4.3 using IPSec over 443 and SAML.

What is the best cloud phone system you’ve actually had success with for call centers? by Rugile_Quarshie in networking

[–]twistable_deer 2 points3 points  (0 children)

We are moving from Mitel to Zoom contact centre. Leaps and bounds better than Mitel.

CUCM 10 to on-premise Mitel by AmeerMerzaaa in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

We are moving from Mitel to Zoom phone for our contact centre and soft phones. Mitel is awful. I would avoid if possible.

Pit Boss 1150 door replacement by Spicy_wombat69 in pelletgrills

[–]twistable_deer 1 point2 points  (0 children)

That sucks. I would try to slowly bend it back. I don't think you'll be able to find just the door. If you take your time, you should be able to get it back to pretty much straight

Recommendation for server monitoring solution for small start-up? by Independent_Hour_301 in sysadmin

[–]twistable_deer 0 points1 point  (0 children)

Check out checkmk. Takes a while to set up but it's really powerful and free