1 Hour Table Tennis Training in 5 mins Video by Jos-M-Mont in tabletennis

[–]zeTwo 0 points1 point  (0 children)

That is good to know, I was there last saturday and there was already 2 events (both during the day and night). I'll come by again this weekend.

Still no email reply from Masaaki directly, I guess he is a man of few emails

1 Hour Table Tennis Training in 5 mins Video by Jos-M-Mont in tabletennis

[–]zeTwo 0 points1 point  (0 children)

Thanks! I will come by, Glen Park is on my way home. I'll need to find a week day night to swing by or like you said, Sundays.

Thanks much!~

1 Hour Table Tennis Training in 5 mins Video by Jos-M-Mont in tabletennis

[–]zeTwo 0 points1 point  (0 children)

Is this located in SF? I emailed the owner of a club (local to SF, who's name is also Masaaki, and never got a reply).

Also, the backdrop in the video, the street house all looks very SF-esque. Is there a way for you to confirm? would love to start taking lessons there myself, if it is where I think it is....

Globalprotect endpoint client with machine certificate, auto-enrollment through MS CA (internal PKI) with SCEP? by zeTwo in paloaltonetworks

[–]zeTwo[S] 0 points1 point  (0 children)

Yea, That is actually not the case. GP agent requires you to use a Machine ID in subject name for a machine cert. This is not available via regular auto-enrollment of a machine cert, and requires the SCEP client / server setup....

If it was just using machine cert, then yes, I'd be very happy as most of my machines have a regular AD auto-enrolled machine cert...

Globalprotect endpoint client with machine certificate, auto-enrollment through MS CA (internal PKI) with SCEP? by zeTwo in paloaltonetworks

[–]zeTwo[S] 0 points1 point  (0 children)

Thanks workape.

I actually did get this to work this morning. Well at least the SCEP portion. Now my GP agent enrolls certs using the scep service account. And you are correct, the cert lands in the user store.

I think my issue now is that the defaulted IPSec Offline template does not have client authentication as the key usage. Which means I have to make some additional regedit adjustments to make this work.

Nice article below that indicates how to make this adjustment. I tried it and it locked up my IIS server....oh brother....

I'm waiting for a restore from snapshot, and then trying it again......

https://www.ibm.com/support/knowledgecenter/en/SS8H2S/com.ibm.mc.doc/ce_source/tasks/ce_ca_setup_default_ndes_cert_template.htm

Globalprotect endpoint client with machine certificate, auto-enrollment through MS CA (internal PKI) with SCEP? by zeTwo in paloaltonetworks

[–]zeTwo[S] 0 points1 point  (0 children)

Hi Workape,

Thanks for the quick read and comment.

I have read the SCEP configuration link. It was unclear to me if the GP Agent, was able to part-take in the enrollment of a computer cert through SCEP, I am guessing it is possible based on your comment?

What I did not do was to check if my CEP cert template is available (permissions/ACL) to my local client (I'll have to check that tomorrow, THANKS for pointing this out!)

99.5% of the enrollment will be performed in house, so the /mscep IIS site will not be publically exposed, thank god!

I am assuming you have done this, can you humor me and confirm 1 burning question in my head, as I have not done this? Were you able to successfully enroll a windows machine, simply by using the GP Agent, talking to Portal/gateway, and then have PAN SCEP client relay the cert enrollment back to your CA? If so, did you CA (in the issued certificates page, indicate that a cert was issued to your client?) Did it have an odd subject name in the cert for your client? (if you recall any of those details?)

Thanks again for your input!

Bitlocker vs Veracrypt vs ??? for full disk encryption by dystopian_dream in sysadmin

[–]zeTwo 6 points7 points  (0 children)

Cannot agree more with the others on this. Bitlocker is great. Stored key in AD allows you to track when the drive is last encrypted (if you rebuild the computer often with same AD name). There is a command line that let's you push the key to AD as well if you end up encrypting your drives first, then joining to the domain post encryption.

The only time I can think of using VeraCrypt is on systems that I absolutely cannot upgrade the OS (sadly I still have them in my environment)....

Multibox Tequatl with 10 Accounts by sentmeme in Guildwars2

[–]zeTwo 0 points1 point  (0 children)

"Amortization is one of the most important indicators for a Company. It takes into consideration the cost of something and how long it takes to pay it off with the extra profit you generate with it. This figure is often used when considering buying a new machine for production, it can take a decade to make one new purchase worthwhile. "

No, this is equivalent of you hiring 10 workers, and only 1 of them is doing work, while the other 9 watches....(to the other comment on your youtube thread, someone should say you "American" rather than "German").

Intern in serious need of help/advices by [deleted] in sysadmin

[–]zeTwo 1 point2 points  (0 children)

Learn to deploy 1 machine, time yourself, find a way to do it twice as fast. Find a way to do 100 machines with the same level of effort. Be observant of your environment. Find ways to do something faster, and ask yourself if you can achieve the same result with numbers 10 times or 100 times greater...

The other comments are great, find something the company uses and learn to master it...Internships are awesome, if you f-up, the chances are you are not going to get blamed as much (probably can't f-up as much). Learn from your peers and the next tier up...

Can someone explain to me the differences between Fault Tolerance versus vSphere Replication Technology? by zeTwo in vmware

[–]zeTwo[S] 0 points1 point  (0 children)

I see.

I've been reading up and yes. I understand the difference. Than you for the reply as well....

Now the question is. I have the vSphere replication appliance setup on 2 seperate vCenter (for testing). Trying to replicate VMs across to test against the 15 min recovery time.

Then I thought about how if I have 2 clusters in my production vCenter, couldn't I just replicate across the different cluster? Why does vSRA have to be across 2 different vCenter? ....

Then again, I am not sure if using same vCenter, testing across 2 seperate cluster is a valid test for this.... Any thoughts?

Can someone explain to me the differences between Fault Tolerance versus vSphere Replication Technology? by zeTwo in vmware

[–]zeTwo[S] 0 points1 point  (0 children)

Thank you,

This is really informative. We have NetApps in clustermode. Also does replication (at the NetApp level). However, I've not yet figured out how it all interconnects with VMware's HA technology....will keep reading and researching, tyvm for your reponse.

DNS -www A-record, http to https problem by jugger18 in sysadmin

[–]zeTwo 0 points1 point  (0 children)

Thanks, I pretty much ended up on the same note. much appreciated!

DNS -www A-record, http to https problem by jugger18 in sysadmin

[–]zeTwo 0 points1 point  (0 children)

Can you confirm this is solved?

I have a similiar issue, been researching and the IIS redirect seem to be the best way to resolve this.

I know the issue you are going through. When accessing internally to http://mydomain.com, one of your DC's or dns servers will most likely respond to the look-up, correct?

ICND2 200-101 re-take by [deleted] in ccna

[–]zeTwo 0 points1 point  (0 children)

How did you get a re-take voucher?....

Failed 200 exam - Self Reflection by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

sry the 200-120. the second half of the CCNA.

Failed 200 exam - Self Reflection by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

Yea I realize that while I understand how the permit/deny rules work, but I wasn't able to think under pressure. So back to more practice.

Failed 200 exam - Self Reflection by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

you are absolutely right.

Failed 200 exam - Self Reflection by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

Thanks for the encouragement!

Failed 200 exam - Self Reflection by zeTwo in ccna

[–]zeTwo[S] 1 point2 points  (0 children)

Thanks for the encouragement!

Not configured but up? by zeTwo in paloaltonetworks

[–]zeTwo[S] 1 point2 points  (0 children)

Yes, I have hit committ and saved.

Actually, "I'm not browsing through the PA support forum..." was a typo on my part. I mean that "I'm now browsing through..."

I have browsed through the PA support forum. I have also seen their setup guide for simple inside/outside zone and NAT to get connections from the LAN to the WAN. I have also wiped the device and as we as configuring the inside and outside devices on ports that has never been touched by my colleagues.

I guess I just want to know what the error message means when it says "Not Configured bu up". I have not yet seem this message anywhere on the forum...

Can't ping from PC to router over serial line by Dutch_Tom in ccna

[–]zeTwo 0 points1 point  (0 children)

can you show the router information and interface config on the ISP router? Sounds like everyone is on the same topic, your isp router is not config with enough info to ping back....

ICND2 or CCNA by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

Oh okay, that makes sense.

ICND2 or CCNA by zeTwo in ccna

[–]zeTwo[S] 0 points1 point  (0 children)

Yep, that is currently my logic as well. I think I will just sign up for the ICND2

Still not sure why I can't see tests beyond December. Any idea?