Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
the spyder
Feb 18, 2011
Let me clarify:
1) This is starting fresh. IE: no one
2) IT is a strategic partner/service provider to the business, offering both internal and external services.
3) Huge push for better systems, new DC, cloudstack environment with a in house/EC2 connected cluster.
4) 15 offices, two HQ.
10) 10Mil budget.

I was thinking:

Desktop Systems Manager = oversee helpdesk, two tier 2 techs (one at each HQ) and a dedicated desktop admin.
DC/Infrastructure Manager = oversees Windows/Linux/Network/Security admins.

This is just for fun, I swear. Great replies thus far though, thank you!

Adbot
ADBOT LOVES YOU

Zero VGS
Aug 16, 2002
ASK ME ABOUT HOW HUMAN LIVES THAT MADE VIDEO GAME CONTROLLERS ARE WORTH MORE
Lipstick Apathy
I found out our building is wired for an all fiber-ISP called Cogent who's offering us 100/100mbps for $650 a month with a 3 year contract.

I asked the IT guys before me why they didn't go with that instead of the 80/40 for $1200 DSL contract we're in.

They said it was because it wouldn't be a reliable ISP due to all the peering disputes they have with Verizon/Comcast and VPN gets hosed up on it due to that.

I spent a while Googling this today and yeah Verizon hosed with their Netflix packets, and I guess that had a spat with another ISP called Level 3 and wound up getting them outright blocked for a bit. What do y'all think? I'm thinking if I set this up in a multi-homed dual-ISP BGP thingy, my routers will be able to sidestep any of that by rerouting through the other ISP... in theory.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
99% of the time vpn getting "hosed up" is a manager trying to use the hotel wifi network that has network monitoring on.

incoherent fucked around with this message at 23:40 on Nov 21, 2014

MC Fruit Stripe
Nov 26, 2002

around and around we go

DrAlexanderTobacco posted:

It's the worst feeling, isn't it? My work output remains mostly the same but you've always got this nagging feeling that you're just slacking off.
That's because I am. :ninja:

Roargasm
Oct 21, 2010

Hate to sound sleazy
But tease me
I don't want it if it's that easy
So your DCs are going to be on the cloud. Your productivity software is already there, as is your CRM. What's happening to the business every minute the ISP is down? The numbers are pretty easy to run because your revenue will be zero and you're paying all of your employees to play minesweeper. You should be looking at price as it relates to SLA, not as an expense

Roargasm fucked around with this message at 23:58 on Nov 21, 2014

GOOCHY
Sep 17, 2003

In an interstellar burst I'm back to save the universe!

Punc posted:

Continuing the resignation story: my boss lady (the same one who said I wouldn't be good enough for my next job) just begged me to stay on a month longer as my legal notice would be. I said I'd think about it, but I'm really not planning to stay that long. I just don't like her going all emo on me, it makes me feel like I really am a mercenary.
She also tried to bump up the notice to 4.5 months, saying it was the legal one. It isn't. It's "only" 3 months. Maybe I should be posting in things that piss you off.

Hi there, forums poster Punc. You work in IT. If you are smart you are a mercenary. Hope this helps.

Give her two weeks notice and cordially say goodbye to your fellow staff on the last day. The End.

Zero VGS
Aug 16, 2002
ASK ME ABOUT HOW HUMAN LIVES THAT MADE VIDEO GAME CONTROLLERS ARE WORTH MORE
Lipstick Apathy

incoherent posted:

99% of the time vpn getting "hosed up" is a manager trying to use the hotel wifi network that has network monitoring on.

I guess the other IT place wasn't totally full of poo poo, I just found this article: https://medium.com/backchannel/jammed-e474fc4925e4

Independent internet health monitoring firm confirming that VPN and VoIP packets from Cogent are super-low priority to Verizon no matter what they're for.

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

the spyder posted:

Desktop Systems Manager = oversee helpdesk, two tier 2 techs (one at each HQ) and a dedicated desktop admin.
DC/Infrastructure Manager = oversees Windows/Linux/Network/Security admins.
Depending on the staff, you might get better results from one actual manager of both of these teams and two team leads that perform day to day supervisory functions.

Che Delilas
Nov 23, 2009
FREE TIBET WEED

GOOCHY posted:

Hi there, forums poster Punc. You work in IT. If you are smart you are a mercenary. Hope this helps.

Give her two weeks notice and cordially say goodbye to your fellow staff on the last day. The End.

Pretty sure he mentioned that he's contractually obligated to give 3 months, which implies that he's in a country other than the U.S.

For the record, I would totally accept a required notice period in my own jobs if companies were bound by similar terms.

Che Delilas fucked around with this message at 03:32 on Nov 22, 2014

Picardy Beet
Feb 7, 2006

Singing in the summer.

GOOCHY posted:

Hi there, forums poster Punc. You work in IT. If you are smart you are a mercenary. Hope this helps.

Give her two weeks notice and cordially say goodbye to your fellow staff on the last day. The End.

This maybe look abrupt to you Punc, but it's probably the best advice you will ever have on this subject. And I can say this because the other option lead me dangerously close to depression.
You're dedicated to your job and it's a great quality. But it can also be a very powerful leverage to manipulate you. Believe me, I know what I'm talking about. Do your contractual three months before leaving and get the gently caress out.

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!
Be loyal to the people, not to the company.

My boss told me this.

Do what's best for your career. If your manager is more loyal to her people, she will understand and could be a great reference. If she's more loyal to the company, then she's a drone and it's not worth it.

evol262
Nov 30, 2010
#!/usr/bin/perl

Zero VGS posted:

I found out our building is wired for an all fiber-ISP called Cogent who's offering us 100/100mbps for $650 a month with a 3 year contract.

I asked the IT guys before me why they didn't go with that instead of the 80/40 for $1200 DSL contract we're in.

They said it was because it wouldn't be a reliable ISP due to all the peering disputes they have with Verizon/Comcast and VPN gets hosed up on it due to that.

I spent a while Googling this today and yeah Verizon hosed with their Netflix packets, and I guess that had a spat with another ISP called Level 3 and wound up getting them outright blocked for a bit. What do y'all think? I'm thinking if I set this up in a multi-homed dual-ISP BGP thingy, my routers will be able to sidestep any of that by rerouting through the other ISP... in theory.

They're idiots. Comcast is a tier 2 provider. Cogent is one of the big boys. They occasionally get into peering disputes with level 3 over bills, but so does sprint. Verizon fucks over everyone.

Go look at a health report every couple of days. They're fine.

The big issue for consumer broadband is basically transit fees. Comcast isn't a tier 1 provider, but they're big. They throw teenager tantrum about how they can just do straight peering, then run their egress points at capacity and give higher QoS to providers who pay them direct transit fees. Cogent in particular, since they carry a lot of Netflix. Cogent refuses, because this isn't how the internet works. Same goes for Verizon.

Cogent is fine. Cox uses them really, really heavily. 99% of the consumer traffic from Phoenix goes out on Cogent.

I'd take the fiber.

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

evol262 posted:

They're idiots. Comcast is a tier 2 provider. Cogent is one of the big boys. They occasionally get into peering disputes with level 3 over bills, but so does sprint. Verizon fucks over everyone.

Go look at a health report every couple of days. They're fine.

The big issue for consumer broadband is basically transit fees. Comcast isn't a tier 1 provider, but they're big. They throw teenager tantrum about how they can just do straight peering, then run their egress points at capacity and give higher QoS to providers who pay them direct transit fees. Cogent in particular, since they carry a lot of Netflix. Cogent refuses, because this isn't how the internet works. Same goes for Verizon.

Cogent is fine. Cox uses them really, really heavily. 99% of the consumer traffic from Phoenix goes out on Cogent.

I'd take the fiber.
In their defense, up until maybe 4 or so years ago, Cogent was basically the cheapest, shittiest connectivity you could possibly buy regardless of their widely-publicized peering disputes, and most web hosts advertised "Cogent bandwidth" and "non-Cogent bandwidth" in the specs for their colo and dedicated hosting plans because they were known to be incredibly unreliable across the board. They've improved steadily, though, and they're now ranked pretty well compared to most other transit providers.

That Keynote Internet Pulse site is an okay enough starting point to locate weird peering issues between ISPs, but it's far from the be-all end-all connectivity map that people push it as. It measures data between ten sources and nine destinations each.

Vulture Culture fucked around with this message at 17:59 on Nov 22, 2014

evol262
Nov 30, 2010
#!/usr/bin/perl

Misogynist posted:

That Keynote Internet Pulse site is an okay enough starting point to locate weird peering issues between ISPs, but it's far from the be-all end-all connectivity map that people push it as. It measures data between ten sources and nine destinations each.
There are much better places to go, including the internet traffic report, which isn't even that good. I just like this because is makings peering disputes/issues really glaring

dogstile
May 1, 2012

fucking clocks
how do they work?

Picardy Beet posted:

This maybe look abrupt to you Punc, but it's probably the best advice you will ever have on this subject. And I can say this because the other option lead me dangerously close to depression.
You're dedicated to your job and it's a great quality. But it can also be a very powerful leverage to manipulate you. Believe me, I know what I'm talking about. Do your contractual three months before leaving and get the gently caress out.

Not only that, but the three months in your contract (at least in the UK) will usually mean gently caress all if you negotiate leaving earlier if you can. This definitely works out in your benefit if you touch sensitive systems. I know that the required notice period for anyone at my workplace who has access to the admin passwords accounts for gently caress all. They get escorted off the premises as soon as they hand it in, get told not to come back in with full pay for the entire notice period.

Worth seeing what you can do.

Chickenwalker
Apr 21, 2011

by FactsAreUseless
.?

Chickenwalker fucked around with this message at 02:59 on Mar 1, 2019

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
Sonicwall Low end NSA $2,000 ish

Sonicpoint (the "light touch, no fuss" AP) 300-500/each. Does require BASIC vlan configuration or a straight shot cable ran from the sonicpoint to the sonicwall.

Its really heavily wizard driven so you dont have to do much.

Pockyless
Jun 6, 2004
With flaming Canadians and such :(
I've been using a server with some good gigabit nics and vyos (http://vyos.net/wiki/Main_Page) for my office router. I am super satisfied with it, but its CLI only for config.

BurgerQuest
Mar 17, 2009

by Jeffrey of YOSPOS

Pockyless posted:

I've been using a server with some good gigabit nics and vyos (http://vyos.net/wiki/Main_Page) for my office router. I am super satisfied with it, but its CLI only for config.

Pretty sure EdgeOS is just a fork of VyOS (not that this changes anything).

Chickenwalker
Apr 21, 2011

by FactsAreUseless
.

Chickenwalker fucked around with this message at 03:00 on Mar 1, 2019

Pudgygiant
Apr 8, 2004

Garnet and black? More like gold and blue or whatever the fuck colors these are

Chickenwalker posted:

We're running our network with around 150 people off of low-end Netgear routers and ancient 10/100 unmanaged switches going out to about a dozen Airports for Wi-Fi. The big bosses have gotten fed up with the intermittent outages that happen when clients aren't able to communicate with the DHCP server and end up with zeroconf IPs because the network isn't configured correctly.

I don't work in the office/internet side of IT but I got called in to assist on this. The boss wants a new router but we don't have the budget for an actual big boy enterprise router and the guy managing the internet doesn't know his way around anything without a GUI.

I suggested Ubiquiti's edgerouter pro for the price point vs features balance but there's big time apprehensions about using something without tech support to call up and hand hold you through setting up a vlan or configuring a subnet. If it were my baby to raise I wouldn't give a poo poo as long as I knew I could RMA it if it crapped out on me, but it's not. Anyone have any experience with using it in a business setting? Any suggestions for similarly configurable routers with SFPs in the sub $1000 range?

I'd grab a Cisco 1811 router and 2960 switch. They're both fairly long in the tooth (the 2960 has some pretty new variants, but the vanilla is getting old) but they'll easily handle what you need for under a grand. If you can get the budget though, a much more sane design would be a 3750 core switch with a few 2960's hanging off it. Probably could be done for 3 grand, 2 if you're willing to go used. That'll get you gig on every link with important features like as much redundancy as you want, the ability to actually manage anything, and for a bonus you'll be able to learn IOS.

syg
Mar 9, 2012

incoherent posted:

Sonicwall Low end NSA $2,000 ish

Sonicpoint (the "light touch, no fuss" AP) 300-500/each. Does require BASIC vlan configuration or a straight shot cable ran from the sonicpoint to the sonicwall.

Its really heavily wizard driven so you dont have to do much.

You can actually pre-configure them for Layer 3 management and they don't need L2 access to the sonicwall in that case.


Pudgygiant posted:

I'd grab a Cisco 1811 router and 2960 switch. They're both fairly long in the tooth (the 2960 has some pretty new variants, but the vanilla is getting old) but they'll easily handle what you need for under a grand. If you can get the budget though, a much more sane design would be a 3750 core switch with a few 2960's hanging off it. Probably could be done for 3 grand, 2 if you're willing to go used. That'll get you gig on every link with important features like as much redundancy as you want, the ability to actually manage anything, and for a bonus you'll be able to learn IOS.

You can get away without the router if you are trying to save cash. The 2960X with LAN base will do inter-vlan routing and you won't have any throughput concerns. Better plan might be Cisco SMB SG500 series though, they are cheap, have a great GUI, and can do L3 with lots of other features. If you need a firewall too, pair it with the aforementioned sonicwall and sonicpoints for wifi.

syg fucked around with this message at 13:12 on Nov 23, 2014

Thanks Ants
May 21, 2004

#essereFerrari


The SG500s have a 'fake' IOS CLI as well, so you can at least get comfortable with it.

Edit: I have no problem with Sonicwalls, but the Sonicpoints have caused me nothing but hassle.

Thanks Ants fucked around with this message at 13:54 on Nov 23, 2014

whaam
Mar 18, 2008
I haven't had great experience with sonic points either but they are a bit better with the latest firmware. We only started using them because we had de facto controllers everywhere already.

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

BurgerQuest posted:

Pretty sure EdgeOS is just a fork of VyOS (not that this changes anything).
Actually they are both forks of Vyatta. EdgeOS is forked from Vyatta Core 6.3 and VyOS is forked form Vyatta Core 6.6. EdgeOS has seen a lot of development toward a GUI, while VyOS has a much smaller developer pool and budget and mostly has seen a focus on bug fixes and a few new features.

Although I have found a few bugs in VyOS 1.1.0, I really recommend it for many use cases. I have 14 instances currently in use, including a few that constitute our core routing in two datacenters. Obviously it's not that great for this instance, since they need a gui and a vendor, but if you are comfortable with your in house expertise, you can save a lot of cash.

Bloodborne
Sep 24, 2008

CLAM DOWN posted:

Does anyone here use Tenables Security Centre?

Nessus? We have it and I log into it once in awhile to gently caress around in but I'm not a pen tester. What's up?

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

whaam posted:

I haven't had great experience with sonic points either but they are a bit better with the latest firmware. We only started using them because we had de facto controllers everywhere already.

the reboot on every configuration change is a bit annoying. Fortunately i'm not in there enough to an issue.

CLAM DOWN
Feb 13, 2007




internet jerk posted:

Nessus? We have it and I log into it once in awhile to gently caress around in but I'm not a pen tester. What's up?

I'm trying to figure out what kind of DB it runs so I can script some specific analysis things. Is it Postgres or SQLite? This isn't documented anywhere.

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin
Dear SA,

I never thought it could happen to me.

Today I got my first email of a PDF of a fax of a printout of a screenshot.

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!

Dr. Arbitrary posted:

Dear SA,

I never thought it could happen to me.

Today I got my first email of a PDF of a fax of a printout of a screenshot.

Inception at work.

We need to go deeper.

Picardy Beet
Feb 7, 2006

Singing in the summer.
Tomorrow I'll have the final interview for one of the two jobs offers I'm liking the most. It's more HR paper trail and money talks than everything else, but still, wish me luck. I've already prepared my resignation, only my signature is lacking.

Edit: and I just have received congratulations for getting the second one too. Can't complain to be spoilt for choice, specially after those past months. As I'll be in Belgium tomorrow regarding the paper trail, it's definitely :cheers: Chimay time :cheers:.

Picardy Beet fucked around with this message at 18:41 on Nov 24, 2014

BaseballPCHiker
Jan 16, 2006

Chickenwalker posted:

Does anyone have any experience with their hardware specifically?

Their hardware is rock solid. I wouldn't hesitate to recommend them. I used them for wireless bridges in some pretty harsh areas in the arctic and they held up well. The only real problem we had with them was delivery times. Seemed like a lot of their equipment was always on backorder.

Japanese Dating Sim
Nov 12, 2003

hehe
Lipstick Apathy
Today is so dead. I work at a college and it's Fall break, so no students are here, which means no faculty, which means almost no staff.

Patching my images and studying for certs at work, woo.

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!

Japanese Dating Sim posted:

Today is so dead. I work at a college and it's Fall break, so no students are here, which means no faculty, which means almost no staff.

Patching my images and studying for certs at work, woo.

The perks of being in IT

CloFan
Nov 6, 2004

I'm in the same boat as Japanese Dating Sim, a co-worker is bringing his WiiU with new super smash bros tomorrow. Hell yeah, holiday weeks!

Zero VGS
Aug 16, 2002
ASK ME ABOUT HOW HUMAN LIVES THAT MADE VIDEO GAME CONTROLLERS ARE WORTH MORE
Lipstick Apathy
Is this real? You'd think viruses that put creepy skeletons on your screen only happen in hollywood movies.

http://www.business2community.com/tech-gadgets/sony-pictures-hacked-gop-mean-01077919

Maybe someone got domain admin rights?

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Japanese Dating Sim posted:

Today is so dead. I work at a college and it's Fall break, so no students are here, which means no faculty, which means almost no staff.

Patching my images and studying for certs at work, woo.

We go into a change freeze after next week until the first of the year. Last year I watched 9 seasons of Supernatural during the downtime.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


skipdogg posted:

We go into a change freeze after next week until the first of the year. Last year I watched 9 seasons of Supernatural during the downtime.

That's best part about corporate IT.

My last gig turned into literal ghost town during the holidays. Every high-level manager was busy burning through their 5-weeks PTO and the rest of us just took it easy making sure everything was running smoothly.

Gucci Loafers fucked around with this message at 21:34 on Nov 24, 2014

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!

Zero VGS posted:

Is this real? You'd think viruses that put creepy skeletons on your screen only happen in hollywood movies.

http://www.business2community.com/tech-gadgets/sony-pictures-hacked-gop-mean-01077919

Maybe someone got domain admin rights?

Adbot
ADBOT LOVES YOU

FISHMANPET
Mar 3, 2007

Sweet 'N Sour
Can't
Melt
Steel Beams
Interview in 1 hour, bundle of nerves, etc etc.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply