Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Boywhiz88
Sep 11, 2005

floating 26" off da ground. BURR!
OK, got some troubleshooting. E-mails are not reaching Comcast addresses, message trace shows delivered. Verified functionality w/ a GMail address and a work address I have. I've submitted for a blocklist removal from Comcast, but I wanted to check here if there was anything I might be overlooking.

The messages don't show up in a spam folder either. Everything for the domain was setup from O365 importing from Network Solutions, and then updating its own MX records, SPF record, etc. So there's a good chance I'm missing something as well.

EDIT: confirmed not on blocklist either. Oh and Comcast e-mails reach them no problem.

And now a ton of bouncebacks from different domains citing bad sender, which was the original problem.

EDIT 3: Now into Restricted User stuff. Just trying to figure out what's triggering that flag.

Boywhiz88 fucked around with this message at 22:48 on Sep 12, 2019

Adbot
ADBOT LOVES YOU

EoRaptor
Sep 13, 2003

by Fluffdaddy

BonoMan posted:

I'm at home for the second so I'll get this all when I get back to the office but I should note that the ONLY thing they need access to is the files served on the very QNAP that is running the VPN. And that they won't "work" from it. Only pull files from time to time when they need a logo or reference to something we've done in the past. They don't need access to anything else on our network. Just the QNAP. Is the QVPN still a bad solution for that?

Basically "hey I need the Illustrator project for this" "oh it's on the client drive in their folder."

This is an outright lie. They are going to link that poo poo into InDesign and whine incessantly about how badly it performs and how much Indesign will lock up, because adobe products are extremely bad at dealing with slow network connections.

You need to cloud host these files. If you already have Creative Cloud, you should look at expanding the space there and putting them all online.

If you don’t use adobe products, any number of cloud + agent storage solutions like Dropbox/box/ etc will work a lot better and have way more features.

BonoMan
Feb 20, 2002

Jade Ear Joe

EoRaptor posted:

This is an outright lie. They are going to link that poo poo into InDesign and whine incessantly about how badly it performs and how much Indesign will lock up, because adobe products are extremely bad at dealing with slow network connections.

You need to cloud host these files. If you already have Creative Cloud, you should look at expanding the space there and putting them all online.

If you don’t use adobe products, any number of cloud + agent storage solutions like Dropbox/box/ etc will work a lot better and have way more features.

Ha thats probably true. People are stupid.

Honestly right now, until they pony up for a managed solution or dedicated employee we'll just use the file station web based solution for the QNAP. That way you can't work from it but can still download the files you need.

We just moved to CC for Teams *finally* so I'll check the hosting solutions there. Problem is that department demands every single project file/asset/whatever for every single client from 2009 til now be hosted and available.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
I'd push for a AWS appliance onsite with iSCSI drivers for caching frequently accessed files.

Boywhiz88
Sep 11, 2005

floating 26" off da ground. BURR!
I setup 2 CNAME entries per the article on DKIM. I just need to wait an hour or so for the entries to go through and be able to enable DKIM?

The 2 entries called for the custom domain and the initial domain. I don’t have to do anything more than that?

Edit: got home and was able to follow steps from MS to setup DKIM via power shell. It’s enabled but Comcast still isn’t receiving emails, and I verified the DKIM is good to go. At this point, should I consider DMARC?

EDIT 2: enabled DMARC! Hot dang, but still no luck. I pulled a couple DNS entries out that were pointing to old mail servers in case that could be affecting things and still no luck. I’m undeterred though! I know there’s gotta be one little thing I’m missing!

EDIT 3: looks like part of it is in Message Trace, e-mails sent to Comcast show being sorted via HRDP. Not sure what my next step is. Probably too late at this time. I’ve turned on Outbound Spam notifications tomsee if that might help as well. Any insight would be super appreciated!

The issue that precipitated this change was that domains like Comcast and AOL were rejecting or not delivering emails. The clients used to send out emails to huuuuge groups of people. Hundreds if not closer to 2,000. They later stepped it back to 100 at a time, but this is only once a year, not consistently or anything.



FINAL EDIT: the issue was on Comcast’s end! The client contacted them and got it resolved. Everything is good to go now! DKIM and DMARC should hopefully prevent this in the future. At this time, I’m trying to figure out what to charge. I didn’t really track my hours, but it’s definitely low double-digits. I was thinking $400-500. Too much? Too little? It was a learning experience for me so it wasn’t the smoothest transition for the client, but the issue is resolved and I feel like I was fairly proactive in my troubleshooting and resolution.

Boywhiz88 fucked around with this message at 15:17 on Sep 15, 2019

Ham Equity
Apr 16, 2013

i hosted a great goon meet and all i got was this lousy avatar
Grimey Drawer

BonoMan posted:

I'm at home for the second so I'll get this all when I get back to the office but I should note that the ONLY thing they need access to is the files served on the very QNAP that is running the VPN. And that they won't "work" from it. Only pull files from time to time when they need a logo or reference to something we've done in the past. They don't need access to anything else on our network. Just the QNAP. Is the QVPN still a bad solution for that?

Basically "hey I need the Illustrator project for this" "oh it's on the client drive in their folder."

That kinda thing.



See above. It's generally just for file grabs when they need some work we've done in the past.

I'm inquiring about the internet at the new office (it's literally in the process of being setup) and here we have AT&T fiber at 50/50.

There will be 2 or 3 users that will need to access everything.

edit: OH hey a pertinent piece of information I posted in the other thread but not here:

This feels like a good use case for carrier pigeon (the fastest site-to-site file transfer system available). Take a hard drive, copy all the files to the hard drive, take it to the new site. Because it sounds like you don't need the data to be accurate in an up-to-the-minute kind of way. Every couple of months, someone copies down the files to a new hard drive, and runs it to the remote site.

Moey
Oct 22, 2010

I LIKE TO MOVE IT

Thanatosian posted:

This feels like a good use case for carrier pigeon (the fastest site-to-site file transfer system available). Take a hard drive, copy all the files to the hard drive, take it to the new site. Because it sounds like you don't need the data to be accurate in an up-to-the-minute kind of way. Every couple of months, someone copies down the files to a new hard drive, and runs it to the remote site.

Sneakernet

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.
Station wagon full of hard drives barreling down the freeway, etc

Dans Macabre
Apr 24, 2004


Have someone memorize all the data every now and then.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Encrypted off-site backups.

Right now, my boss mounts a USB external hard drive where he has a truecrypt volume that basically takes up the entire drive. He then copies stuff over to this drive and takes it off site.

He always complains about how every so often the drive gets 'fragemented' and it takes 3 weeks to defrag it.

I haven't researched drive encryption much but it seems like there's a better way.

Don't SSD's have built-in encryption? Is that something you can activate when you use it in an external enclosure? It seems like that would be more transparent and probably perform better.

The Fool
Oct 16, 2003


Lots of external enclosures have hardware encryption in the controller.

A bunch of sad manufacturers also make drives that self encrypt, but there was a flaw found last year: https://www.ru.nl/publish/pages/909275/draft-paper_1.pdf


Also, there’s bitlocker, but that will be windows only.

For a mixed environment I’d probably try to find a reliable drive with encryption on the controller, but you will lose the contents of that drive if the controller breaks.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
LVM with Encryption is an option.

Rick
Feb 23, 2004
When I was 17, my father was so stupid, I didn't want to be seen with him in public. When I was 24, I was amazed at how much the old man had learned in just 7 years.
A while back here someone posted some Bomgar alternatives but I can't find the post for the life of me. Anyone still have other remote control software they're using?

The Fool
Oct 16, 2003


We’re using Dameware.

Just don’t use teamviewer.

redeyes
Sep 14, 2002

by Fluffdaddy
Doesn't windows have a remote help feature by now?! I swear I read something.

The Fool
Oct 16, 2003


It does, but you still can’t do uac escalation through it.


So if your users have local admin and you can trust them to click on the right button at the right time it’ll work just fine.

Thanks Ants
May 21, 2004

#essereFerrari


It's called Quick Assist and it's pretty great

wolrah
May 8, 2006
what?
We are trialing MeshCentral as a self-hosted option. Definitely rough around the edges in a lot of areas and very basic compared to the commercial alternatives, but if your main priority is remote control and not policy enforcement or system management it looks pretty decent so far. The price is definitely right.

It supports agent-based connections to basically any major OS, GUI or CLI, and agentless connections to Intel AMT equipped machines.

Rick
Feb 23, 2004
When I was 17, my father was so stupid, I didn't want to be seen with him in public. When I was 24, I was amazed at how much the old man had learned in just 7 years.

Thanks Ants posted:

It's called Quick Assist and it's pretty great

This is cool!

E: Well it will be cool in 8-10 months when all of our Windows 7 machines are finally retired.

The Fool
Oct 16, 2003


Rick posted:

This is cool!

Still doesn't do UAC

Rick
Feb 23, 2004
When I was 17, my father was so stupid, I didn't want to be seen with him in public. When I was 24, I was amazed at how much the old man had learned in just 7 years.

The Fool posted:

Still doesn't do UAC

Ah, then way less cool.

The Fool
Oct 16, 2003


I should be clear. It's not like it breaks on UAC like some older screensharing programs did when Vista came out.

MS made a design decision to block the remote user when a UAC prompt comes up, expecting the local user to proceed through the prompt, then the session resumes.

This actually makes a lot of sense because you don't want a support scammer calling grandma and him being able to bypass UAC and installing his malware just because he tricked her into launching QuickAssist.

This however is a non-starter when supporting users that don't have local admin.

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


Is there a reason why VPNing to the site and then using VNC (such as tight VNC) isn't a good option? VNC will let you verify UAC prompts and everything. Hell you can pull up the login screen and login if no one is at the computer. It's as good as sitting in from that that machine.

Dans Macabre
Apr 24, 2004


pixaal posted:

Is there a reason why VPNing to the site and then using VNC (such as tight VNC) isn't a good option? VNC will let you verify UAC prompts and everything. Hell you can pull up the login screen and login if no one is at the computer. It's as good as sitting in from that that machine.

Vnc isn’t really secure out of the box, and useless if the user is not on your lan

Maneki Neko
Oct 27, 2000

ConnectWise Control (aka ScreenConnect) is really nice as a remote control tool.

stevewm
May 10, 2005

pixaal posted:

VNC will let you verify UAC prompts and everything. Hell you can pull up the login screen and login if no one is at the computer. It's as good as sitting in from that that machine.

This is why we use VNC internally (with encryption and certificate based auth features that ultravnc has)

Sheep
Jul 24, 2003

Maneki Neko posted:

ConnectWise Control (aka ScreenConnect) is really nice as a remote control tool.

The on premises version is also a single, non-subscription payment which is something of a rarity these days.

Digital_Jesus
Feb 10, 2011

Sheep posted:

The on premises version is also a single, non-subscription payment which is something of a rarity these days.

Can confirm I deployed the on-prem option at multiple past jobs and it does a great job. Its a good product.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Standing up some new hosts and a SAN for a client, they are currently on ESXi 6.5u3 on their older equipment.

I have not worked with vmware stuff much other than admining a couple already running clusters; most of my clients have used hyper-v.

The plan is to merely move the VMs to the new storage/cluster and then rebuild some of the VMs afterwards (not my choice but it is what it is).

If I install 6.7u3 onto the new hosts, is it going to cause problems for importing the VMs?

Should I build a new ESXi cluster (datacenter whatever vmware calls it) or can clusters run mixed versions?

Any other gotchas/stuff I should look out for?

Count Thrashula
Jun 1, 2003

Death is nothing compared to vindication.
Buglord

MF_James posted:

Standing up some new hosts and a SAN for a client, they are currently on ESXi 6.5u3 on their older equipment.

I have not worked with vmware stuff much other than admining a couple already running clusters; most of my clients have used hyper-v.

The plan is to merely move the VMs to the new storage/cluster and then rebuild some of the VMs afterwards (not my choice but it is what it is).

If I install 6.7u3 onto the new hosts, is it going to cause problems for importing the VMs?

Should I build a new ESXi cluster (datacenter whatever vmware calls it) or can clusters run mixed versions?

Any other gotchas/stuff I should look out for?

Not really between ESXi versions, I just did a big 6.5->6.7 upgrade and migrated hundreds of VMs between the two versions no problem.

If you're upgrading vCenter from 6.5 to 6.7, that's a bigger deal, but if it's just ESXi, you're fine.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

COOL CORN posted:

Not really between ESXi versions, I just did a big 6.5->6.7 upgrade and migrated hundreds of VMs between the two versions no problem.

If you're upgrading vCenter from 6.5 to 6.7, that's a bigger deal, but if it's just ESXi, you're fine.

I will probably just build a new vcenter server since the old one is server 2012r2 anyway.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

MF_James posted:

I will probably just build a new vcenter server since the old one is server 2012r2 anyway.

Just use the new vcenter virtual appliance.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Looks like 6.7 deprecates the windows version anyway.

Dans Macabre
Apr 24, 2004


Maneki Neko posted:

ConnectWise Control (aka ScreenConnect) is really nice as a remote control tool.

speaking of connectwise, they bought continuum, anyone got the scoop on how that's gonna work vs. labtech which they also bought

Internet Explorer
Jun 1, 2005





Prices are going to go up. That's how it's going to work.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Oh connectwise bought continuum? I thought it was the other way around.

Yeah my assumption is prices will go up in the next 6-12 months, service quality will go down; how it can go down further I don't know because Continuum's NOC is terrible and their monitoring is dog poo poo.

Actuarial Fables
Jul 29, 2014

Taco Defender
My old boss just finished migrating everyone off of labtech and onto continuum a few days before the announcement. Glad I don't have to worry about it anymore (but I might because rent is expensive and he offered me part-time employment :()

Internet Explorer posted:

Prices are going to go up. That's how it's going to work.

I was told 10% price increase annually, but that might just be grumbling.

Moey
Oct 22, 2010

I LIKE TO MOVE IT

Actuarial Fables posted:

I was told 10% price increase annually, but that might just be grumbling.

I budget for a 10-20% price increase annually for services. It has never bite in the rear end. Or hasn't yet......

Maneki Neko
Oct 27, 2000

NevergirlsOFFICIAL posted:

speaking of connectwise, they bought continuum, anyone got the scoop on how that's gonna work vs. labtech which they also bought

All the chat I’ve heard is they feel there’s enough difference in audience between the two that they’ll keep one for MSPS that can do it all in house and one for folks that want to outsource helpdesk, NOC, SOC, etc.

Adbot
ADBOT LOVES YOU

Revalis Enai
Apr 21, 2003
<img src="https://fi.somethingawful.com/customtitles/title-revalis_enai.gif"><br>Wait, what's my phone number again?
Fun Shoe
Any recommendation for touchscreen monitors good for POS? I have a spare ITX PC I'm thinking about using it for one of our POS system. I'm getting sick of having to deal with the old rear end Casio-9100s.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply