Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cao Ni Ma
May 25, 2010



Paul ReiserFS posted:

You know in your heart it was “password”

Someone brought in two laptops to get reimaged today from a different org and the guy next to me was working on them. He went “ah gently caress these also have bios passwords. Ah poo poo your gotta be kidding me” I asked him if the password was password and he shushed me

Adbot
ADBOT LOVES YOU

Cao Ni Ma
May 25, 2010



Getting people to tell me the IP the VPN spits at them to help them troubleshoot issues adds like 30 minutes to each ticket that involves remote control.

Cao Ni Ma
May 25, 2010



Gabriel S. posted:

What in the hell is this guy talking about? Modern Auth is great.

I spent like 2 weeks trying to get some printers to recognize our ldap scheme so that customers could authenticate with their smart cards

To this day I still dont know which of the custom scripts were the ones that worked.

Cao Ni Ma
May 25, 2010



regulargonzalez posted:

Computer 1 : laptop on home connection, vpn'd into work network

Computer 2: work computer on the internal work network

Is there any way to get rdp or dameware to let computer 2 connect to computer 1? Doesn't seem possible.

I can do it from our network, but I cant use their hostname. I have to find their IP and then use it to dameware into the machine. I can remote directly from my work laptop while teleworking, or I RDP into my office workstation and then dameware into them.

The networking team doesn't provide us with access to the ASAs so we just use a powershell script to sweep the ASAs IP ranges and provide us who is using which IP so when they call in for support we already know which to remote into.

Cao Ni Ma
May 25, 2010



Via chat

supervisor- Are you inside the building today
me- Yes I am
Supervisor- did you look at the documents I sent you
me- Yes, but I dont know what I'm supposed to do with them, they are just some IPs
supervisor- ok let me explain

its been about an hour and he hasn't replied back

Cao Ni Ma
May 25, 2010



regulargonzalez posted:

Working remotely on vpn, I can dameware into about half the computers on the internet network and half the time it just can't connect, network error / can't find the remote machine. Can't seem to figure out why - it's not the client version of dameware, it's the same subnet, there's no rhyme or reason to it.

It's not a huge deal as I can just rdp into my workplace desktop and dameware from there but that's a bit laggier. Anyone theories on what's wrong?

I straight up cant use a hostname to remote into peoples machines with dameware when they are working from home. I have to use the IPs, and trying to have the networking team provide me access to the ASAs so I can see whos connected at the time is a pain in the rear end so I just wrote a script that sweeps the ASAs IP range and attaches the hostname and person currently logged into the ones that dont show up as unreachable.

Cao Ni Ma
May 25, 2010




Its already flipped on, I've worked now on like 5 different posts now in different geographical areas and its never worked right so I'm guessing its by design.

Cao Ni Ma
May 25, 2010



My boss just up and quit without any warning on us after weeks of him trying to push back on our regional HQ on getting a domain migration done asap. My supervisor called in everyone in the section to be present on monday in the office so thats like 7 people in a relatively small office. We are supposed to get like 1000 devices migrated to the new domain in 2 weeks and they pretty much have to be done without any major migration tools so I hope that our admin crew was able to at least get some of it automated through scripts to push through SCCM.

This was basically my wakeup call to not be picky with locations for my next move. I've applied to like 10 different positions and I'll jump ship with the first one that tells me if I'm interested in joining them.

Cao Ni Ma
May 25, 2010



GreenNight posted:

All of crypto is crashing.

Please President Xi, you can end the insanity right now.

anyways to bring this back into working IT. We are in week like 9 of a planned migration to another domain. Everyone is dragging their feet making everything harder than it should and I'm seriously starting to get pissed off. I think we have the right staff to do it, but our leadership just up and leaving right before it started kneecapped us.

Cao Ni Ma fucked around with this message at 17:16 on May 19, 2021

Cao Ni Ma
May 25, 2010



deedee megadoodoo posted:

One of my good friends basically failed upwards into a 6 figure IT job. He's all soft skills and knows how to get work done without actually doing any work himself. He has very minimal experience with what his actual job is and he's terrified that they are going to figure out that it's all a lie. And this isn't imposter syndrome. He literally doesn't know anything except how to creatively move work around.

I'm super proud of him.

One of my coworkers (before he got fired) was basically this. He was just one step bellow being a supervisor and a 6 figure job and knew jack poo poo about IT. He just sat on his computer doing absolutely nothing and only got fired because he failed the sec plus exam like 5 times.

skipdogg posted:

I've done 6 or 7 good sized domain migrations in my career and the biggest difference in the success of each one has been upper management buy in. Our best one was where senior leadership straight up told everyone "this is getting done, no excuses" The worst is when business units push back constantly because it'll make their life difficult and management lets them. Then I ended up supporting legacy domains that 20 people were using for a decade. I literally had to wait for a product line to die before I decommissioned one a couple years ago.

At my last job we were onboarding people in certain areas of the business with 4 separate AD accounts to access the resources they needed, all because the engineers couldn't be bothered to migrate their stuff.

Yeah it feels like the latter right now. There is no excuse but our supervisors are getting rolled over by other departments directors and since we don’t have a director of our own putting hard deadlines everything just keeps being put off.

We could have been done last month with just like 60 machines in the old domain waiting for a new sql server to be approved and stood up, instead over half our machines haven’t been migrated yet.

Cao Ni Ma
May 25, 2010



Its been a complete shitshow at work since last week with several systems being broken, a combination from a 365 migration and group policy probably caused outlook not to work anymore and the only way to fix it was by pushing an update into computers but the update system is broken too. Now our higher ups put a hard deadline on getting all the machines migrated which means I'm just flipping machines the moment I see them log into the network. We were getting a lot of pushback by some of the organizations that they weren't ready because of x y z and now any excuse they have is useless because either you migrate or your account gets disabled. If I was in charge I'd ask each of their directors for a memo for each of their machines that gets disabled thats going to need more work than just a re-image.

I got hired as customer support and the last 4-5 months Ive been doing mostly sysadmin stuff. Im afraid of logging into the ticketing system because its going to have like 80 unassigned tickets we are going to have to sort through

Cao Ni Ma
May 25, 2010



i am a moron posted:

How do you even gently caress a 365 migration up, either your coworkers or whoever you’re working with are complete failures

This is the army so everything is rear end backwards. The people that provide the email service are in a completely different organization than the people setting up the group policies for the domains in each region. So suddenly people that were migrated into the regions domain were starting to get a 365 pop up when trying to set up their email when they hadn't even been furnished with a 365 account yet.

I spent like an hour trying to troubleshoot the Department of Public Works director outlook and we couldn't figure out the problem, it looked like his entire mailbox had been nuked. Ended up being that he came in from the pentagon and they ran on their OWN system and they migrated earlier than the army. Its a clusterfuck

Cao Ni Ma
May 25, 2010



i am a moron posted:

Wait, like the US Army? Or the national guard? Cause i thought they migrated all the active duty orgs to hosted Exchange circa 2011 (was on a division staff at the time so my actual knowledge of what was happening easily could’ve been wrong). Which would make a 365 migration easy.

Edit: and the hosted exchange migration was like ‘hey here’s your new email you loving dipshit good luck logging in’ so sounds about par for the course lmao

Regular army. I was in the reserves when the shift happened to hosted exchange and we were furnished @mail.mil. Now its happening again and we are getting @usa.army.mil or something like that.

The whole thing has been messy, from the initial rollout of teams cvr and now the O365 change.


Sickening posted:

I was both in the US army and in Commo, so it doesn't surprise me how hosed up things still are.

I am sure the army still doesn't know what the gently caress to do about technology. They don't recruit technical people to do technical stuff, they recruit soldiers and ask them to sometimes do technical things. Its setup to fail from the start as few people with any of those skills are actually going to join and even less so that the few that do actually end up in the right place to make a difference. Military contractors in this space, in hopes to fill the gaps, also loving suck to the point of it all being laughable and stupid. I haven't met a miltary contractor working in tech that wasn't a bottom barrel worker who was sucking up a paycheck, hoping nobody would ask them to do anything. Somehow 10x as generate as the public sector could possible be!

They just won't let tradition get out of the way and realize that much like the air force, they need recruit passable people, teach them some basic skills, and let them focus on those things instead of trying to make them part time soldiers.

I was at a brigade S6 let me tell the vast majority of the 25 series we had in our battalions were not IT people, and we had a signal battalion under us. The only other guys that actually knew what they were doing were our warrant officers and a few of the officers that were dual personas that worked at the nec or commands IT office.

I decided not to reup when they had me be the sgt of the guard for an entire year while mobilized while a higher ranked less capable person manned the IT section. A year after my contract was done I was still getting whatsapp messages on how to fix poo poo that was breaking at the unit.

And not to bring service branches into the equation but the "Not hiring actual IT people" happens to all of them, you are a soldier first, a janitor second and whatever MOS you got third. When maria destroyed most comms on the island we had NG/ANG/AirForce/CoastGuard people come to our unit to use our network because we were literally the only ones in the area that were able to get them up and running on day 1 of the recovery efforts.

Cao Ni Ma fucked around with this message at 03:19 on Jun 6, 2021

Cao Ni Ma
May 25, 2010



Yeah, like were I'm at 99% of the networking staff dont know jack poo poo of things like AD and basic windows troubleshooting. On the other hand basically everything I knew about configuring a router is down a the toilet since its been a decade since I last touch one, I still know some of foundational knowledge thanks to working with MABs and NPSs though when troubleshooting things.

Cao Ni Ma
May 25, 2010



BaseballPCHiker posted:

Not contractors, full time employees. They made between $60-70K which I think is pretty good for help desk in the Twin Cities area. Awesome benefits too.

Definitely a case of getting what we paid for. I wish more employers would realize they could pay frontline support a bit more and make everyones life easier.

Yeah in the federal service you can definitely ride customer support till you are a supervisor making 100k+ a year. You have to be willing to move though, you can get there pretty quick if you aren't adverse to taking tours in Asia or Europe.

Cao Ni Ma
May 25, 2010



Just got done with an interview for a position. Dont know if the extra 4k and cheaper cost of living is worth being the team lead of 9 other people.

Cao Ni Ma
May 25, 2010



skipdogg posted:

4K for people managing? hell to the no

Honestly if I get the offer I might still say yes just to get the team lead part of my career done. I'll be significantly easier to promote to GS12 and 13 later which is the only way to get to 6 figgies in the federal government.

Cao Ni Ma
May 25, 2010



After 3 months of getting things migrated to the new domain the supervisor finally pulled the plug and disabled all objects that hadn't been migrated yet yesterday evening.

We got a call first thing in the morning that the print shop is dead in the water and they need to print a bunch of poo poo for the incoming cadet class by saturday :shepicide:

Cao Ni Ma
May 25, 2010



Migration was completed about 3 weeks ago and it feels like Im getting three times the tickets and calls I had during the thick of it now. Machines are getting updates that are essentially bricking the user because its locking them in a constant restart cycle, we haven't been able to image a machine in over two weeks, I still need to work on some departments that have some outstanding pre migration issues, our personnel are being shuffled around and we still dont have a new director so our morale is in the gutter.

I put in PTO for friday and it still hasn't been approved, I'm guessing its all going to depend on microsoft actually patching their vulnerability I guess.

Cao Ni Ma
May 25, 2010



Found out that mcafee's hips doesnt just stop you from installing things, it also blocks you from uninstalling things too :shepface:

I mean it sort of makes sense, but in the years working here it has never been an issue with uninstalling software, the logs didnt even make sense in this instance, but sure enough stripping the thing from the server and then trying again worked.

Cao Ni Ma
May 25, 2010



Just got a call from my supervisor that one of the relay towers is down so Im guessing we are hucking diesel cannisters up a hill.

Cao Ni Ma
May 25, 2010



Wibla posted:

That sounds like fun. How much power do one of those relay towers use?

We have to carry about 30-40 gallons every time the generator runs out of fuel. It usually has power through the grid but every time there is inclement weather theres a chance it can go down since its so remote. We normally have our aviation detachment come in with choppers and drop off the fuel but even they have issues landing on that rock. Trucks can only reach up to a point, after that you are carrying the 5gal jugs the rest of the way up.

Usually it can wait, but it being summer it means the cadets are on the field and that tower is very important for radio comms and keeping in touch with the aviation detachment, so if there is a medical emergency they need to get comms out immediately to get air lifted or whatever.

Cao Ni Ma
May 25, 2010



PrintNightmare has been, well a nightmare in our organization. Since July most of the printer fleet through the country have been unable to secure print or secure scan. We were spared for the most part because we are like the only place with most of the printers being Xerox but with the august update none of our customers can print through the server unless we manually remote in and install the drivers on their machines.

I was troubleshooting some issues with a konica minolta rep, since one of our tenants had a few of their printers with them when the july OOB hit and suddenly they couldn't secure scan/print. The vendor kept telling me it was up to microsoft to provide some relief, and microsofts answer was to release an optional patch that let printers fallback to 3DES, when he told me it was out I laughed at him. Told him it wasnt up to me to decide that and that the only for sure way it'll work would be for them to release a new firmware, he told me it would be ready at the earliest late september. A few days later I hear that the garrison was going to use konica to replace the xerox and I can already feel the aneurism coming.

I wrote a script so we can quickly install network printers onto the machines, bypassing the print server (because V4 drivers dont work on the printers, since its an optional feature that wasnt part of the contract!) until command comes up with a permanent solution. Someone above us scanned a system to see if it didnt run afoul with ACAS. Didnt trigger anything, told me to hold off from using it anyways since command is still writing a policy on what to do and they are just going to do what they tell them to do. So now we are back to manually remoting into machines :shepface:

Cao Ni Ma
May 25, 2010



Internet Explorer posted:

Does anyone use Tanium? Good lord is this poo poo garbage.

It and mcafee are the banes of my existence. The other day our regional sent in a code through tanium that knocked out like 10% of our computers ability to use smart cards to log in including a few of our servers.

Cao Ni Ma
May 25, 2010



Farking Bastage posted:

That PrintNightmare patch just loving exploded here. Everyone's already installed print drivers just started requiring elevation. This is why you shouldn't use the internal IT team as test subjects. Most, of not all have elevation privileges. :negative:

Yeah we are still dealing with the aftermath of printnightmare mitigations. We were completely blindsided by it because no one from regional told us they were pushing the patch or what to expect, we just started getting calls from people that they couldn't print anymore because they were getting admin credential prompts.

To make matters worse we couldn't get v4 drivers into the print server because 95% of our fleet doesnt have the xps function enabled on the printers (its extra money and the contract expires in a month)

The incoming printers were having issues authenticating to the domain controllers but luckily they fixed that via firmware recently.

Cao Ni Ma
May 25, 2010



Our printer nightmares continues. The lease for the old xerox is up and they are bringing Konica Minoltas to replace them. Up until like a month and half ago we couldn't get these to scan in our network (Because of print nightmare mitigations) but that got resolved. Problem is that the techs aren't loading the CA certificates on them that they need, so we have to go around and do that for each of them. And they haven't sent in a master list of mac addresses so we are having techs call in every 10 minutes for us to add them to the mab so they get an IP in the first place. Then we need to swap out the old printer ports to the new one on the server.

And we get to do that again on over 50-60 of them again in a few weeks because more than half of the printers they've sent us are temp ones because the chip shortage is affecting production and the ones they are sending dont meet the contracts specifications :shepface:

Cao Ni Ma
May 25, 2010



DropsySufferer posted:

How does a person like that get a C-level IT executive title with no hands on IT experience or knowledge? I really need to get into management...

What is their level of technical knowledge? I would think you could easily bullshit them and manipulate them if they were this incompetent.

Our old director didnt have a whole lot of experience with IT, he was just a people manager. How you can get an executive position while not knowing anything on the field AND not knowing how to manage people is beyond me though

Cao Ni Ma
May 25, 2010



Sickening posted:

I have just had my meeting with the CEO. Its time for all of you to buckle up.

:allears:

Cao Ni Ma
May 25, 2010



skipdogg posted:

I'm in the middle of change and release management hell right now.

We already have a change management process that is..... robust maybe is the right word. Not sure. Multiple sign offs, 1 to 3 CAB meetings depending on severity and impact, and once we get all those approvals, we can do our change.

Now we need to go through release management for all of our changes. Another set of approvals, release lead, release coordinator, etc.


I don't develop software, I'm in IT operations. Something like deploying a new GPO now takes me 2 to 5 hours of paperwork and meetings, so I can click a few buttons. Like I get it. I knew what I was getting into with working at a financial services company, but it's just... frustrating at this point. I seriously do maybe 1 to 2 hours of work a week. Thanks for letting me vent.

At least you can change your GPO. For us it would take about that many hours in paperwork and meetings with the higher ups and then them taking another 12 hours to push that information to their higher ups only to have it denied.

For 6 months now our security logs have been filling up one gig of data every day on each machine and its not overwriting the old data. So machines are literally breaking when the log gets full and the policy gets corrupted. We COULD fix it pretty easily but here we are waiting for it. I think we are going to push it locally on machines if the scans dont show any stig violations.

Cao Ni Ma fucked around with this message at 22:44 on Oct 15, 2021

Cao Ni Ma
May 25, 2010



Spring Heeled Jack posted:

Hey so uhh print nightmare, is it at all possible to mitigate the vulnerability and have network printers continue to work? Because I haven’t found it yet. These monthly CUs keep breaking things.

Use V4 drivers in the print server if you can. I know a lot of manufacturers have been sleeping on them (HP looking at you) but it'll allow users to install network printers without admin rights if they are loaded right. Also I've noticed the spoolers going down on users machines, so I have to flip them on manually.

If you dont have access to V4 drivers and you cant deal with login into each machine to load the drivers manually you can write a powershell script to load the printers into the machines. Thats what I initially did till they brought in new printers.

If you are using secure print/scan then your printers need to have new vendor firmwares for them to talk with the DC. Vendors are also sitting on their rear end with that, Ive got 120 konicas that need firmware updates and I'm still waiting for the manufacturer to send me the new firmware and they are in better shape than the ricohs the other locations have. Xerox was magically unaffected by print nightmare somehow. If secure print/scan is super important for your organization and your printers are having issues then you can back off the domain controllers print nightmare settings with some registry keys.

Cao Ni Ma
May 25, 2010



I went through like 3 interviews interviews since I got my current position 2 years ago. First interview was a bit technical, in a DoD video conference system but it wasnt actually on camera. Second interview wasnt technical at all, via phone for a position in Japan. Third interview was via teams fully vtc and very technical, lots of questions about different technologies, protocols and what if questions about day to day occurrences. Felt like I did worse the least technical the interviews were. The first and second position are still technically going through the hiring process since I havent received an email that I wasn't selected.

Just got an email that I'm tentatively selected for the third position and I'm loving stoked! Federal work doesnt get you much extra money whenever you promote but this position will let me promote 2 more times in place, so in 2-3 years I'll be pretty set. Couldn't ask for a better position when I'm mostly working in CS/SA.


AndyElusive posted:

Shiiiieeeet, I have two days before my A+ Certification expires.

So now I need to complete a CompTIA CertMaster CE for A+ Core Series with 349 Lessons & Videos and 149 Total Questions with a total of 7 Quizzes @ like $130 bucks

Ugggghhhhhhh. I had plans this weekend.

My current work mandates us have Sec+ and they have some CompTia trainings that count for like half the total CE amount for the 3 year period. We just knock that out and take a few hours to go through some other training and we are done for another 3 years.

Cao Ni Ma
May 25, 2010



The Iron Rose posted:

Why on earth would you bother renewing an A+ certification? I left it off my resume even before it expired the moment I could.

Some jobs DO require certs and for the employee to maintain them. I know the DoD mandates most IT people have Sec+ but the regulations do have positions that just need A+. Likewise more technical positions in cyber security will mandate you have CISSP or something like CASP or C|EH

Cao Ni Ma
May 25, 2010



Its stupid but I've seen people lapse their certs here (when sec+ was at like 301 or something) and have to retake the test (When the version is like 601 now) and fail. After enough failures you can get kicked out of the position because its a requirement. Sec+ has gotten tougher in the last few iterations now, I've seen newer hires flunk out over two times, then having to pay out of pocket for the test.

I wonder how much revenue Comptia gets out of the DoD. Must be their single biggest client.

Cao Ni Ma
May 25, 2010



jaegerx posted:

i hate you java, i truly do, i hate all apache products in fact.

I hate it too. So many of the of our old proprietary software use it and if sccm pushes updates to it suddenly it re-installs the 64 bit version and they all break. You get like 20 tickets coming in that they cant get into a website because it needs a jre plugin from 9 years ago or something and sure enough theres the 64 bit version on their machines.

Cao Ni Ma
May 25, 2010



Im almost done with the onboarding for the next job. Just need to go through a security screening and signing the final paperwork, should be fine I think. Its not really much of a pay increase from what I have right now the position is much higher scale so I'll break into the 6 figgies after 2 years. Pretty much a dream job, making 100k+ working essentially help desk for a not that big organization, without having to supervise, in a cheaper geographical area and with plenty of opportunity to TDY to say the capital or europe if needed

Cao Ni Ma
May 25, 2010



Only reason I'd do something like that is if I'm burning bridges and want him to inherit my position when I leave to a better place.

scott zoloft posted:

Nah someones aspergers relative i gotta babysit everyone knows the deal

Oh, thats fine then.

Cao Ni Ma
May 25, 2010



Boba Pearl posted:

There are businesses that use apple products??? Why????

Blackberry's where the go to phone product for our staff that got phones, then suddenly they were replaced with iphones when blackberry was no longer competitive many years ago. To this day I've never seen an issued android device despite the regulations being in place to purchase them since 2013 or something

Cao Ni Ma
May 25, 2010



So ever since print nightmare came out all the ricoh printers in our region have been down. They tried to do a few things to get them up and running but not a lot helped, apparently they came out with a tool to mass upgrade the firmware for the devices and it ended up frying hard drives so now they have techs coming in to replace the drives from the dead machines.

They brought in two new models for us to use at our place, first ones to try them out in the region. The tech was so relieved when they worked after we put in the domain info and root certs. All of this because of encryption, just a little toggle that says 3DES or AES256, bricked hundreds if not thousands of our printers.

Cao Ni Ma
May 25, 2010



The patches absolutely lit a fire on the manufacturers asses to get not only aes into printers for secure print and scan but also to get v4 drivers more reliably available.

HP went from “oh v4 drivers aren’t really necessary so we don’t provide them” to “our drivers are in beta because no one is going to bulk buy our printers if they have to have admins manually load them into each computer” a week after the patch hit.

Adbot
ADBOT LOVES YOU

Cao Ni Ma
May 25, 2010



Our work should be on a 3/2 schedule but its subject to the supervisors accepting it and setting up a proper schedule for each individual. It sure as hell feels like they dont want to implement it because the commands guidance on the issue has been known since like May and they are still having us come in. They made it seem like they were waiting for the new director to come in, well he's been here for a week already and nothing has happened. The networking team was pretty much told not to expect telework ever despite them being WFH fine for like a year.

I dont know what the situation will be in my next job but a good third of the questions involved authentication protocols and VPNing so I hope its better. I know that the one will likely have me travel more, I'm perfectly fine with that

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply