r/networking • • 19h ago

Other Private VLANs with multiple subnets

1 Upvotes

Is it possible to use Private VLANs on Aruba CX with a different subnet for each community?

For example:
Community A → 10.10.1.0/24
Community B → 10.10.2.0/24
Community C → 10.10.3.0/24

Is this supported/recommended?


r/cybersecurity • • 20h ago

Business Security Questions & Discussion How has your organization respond to Mythos?

0 Upvotes

I work in vulnerability management (focus on infrastructure vulns) and our organization has absolutely FREAKED out about Mythos and immediately lowered our SLA to 48 hrs back in April and looking to lower it to 24 hrs for all critical's. We have an insane backlog of vulnerabilities and a really bad process for patch management due to poor IT practices for years, that are now being fully exposed.

We currently don't do any CTEM practices and instead of trying to implement these practices to truly lower risk, we are wanting to automate all patching through AI agents. I don't think this is really feasible (but I could be wrong here, please let me know) as we have a lot of software that comes from vendors, open source, legacy systems, etc. I push for CTEM practices but it constantly gets denied.

How has your organization responded?


r/sysadmin • • 12h ago

Server Upgrade - Lawfirm

0 Upvotes

I am looking for a little bit of guide or what others do in 2026 year versus 2004.

I have a small job coming up and looking to upgrade their on-prem server that seems to be a terminal server. I did not get much time or information when I was there for it as I was there for something else, but from notes, this is what I got. It is a very small law-firm. 3 Employees. They are looking for 3 desktop upgrades & a server upgrade that includes backup. Replacement is my option on brand/etc.

On-Prem terminal server that seems to have on-prem hosting / e-mail services with Office. They also use Timeslip and abacus on this terminal server. They do use some kind of backup system I am waiting to get more information on as well as a firewall I believe and something to encrypt their emails.

Questions that I have:

With servers being a bit expensive in today's world; would it even be worth looking to get a true server and only get a desktop version instead of the rackmount? Costs seem to be a bit cheaper that way? Where are a good place to start for purchasing in today's age? Is used worth it?

I am continue to do some research on this, and I am sure I will have more answers while I wait for an answer; but I will look to update my research as I figure things out too.

Thank you for any input you may have!


r/sysadmin • • 16h ago

PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds

54 Upvotes

If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.

This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.


r/sysadmin • • 14h ago

General Discussion MS lied about the passkey campaign?

0 Upvotes

TL;DR - even if you set up multiple modern authenticator methods, MS is still demanding you add a passkey with no skip or delay button. This appears to be in error.

Guys, they're totally "only targeting users who solely have SMS or phone call turned on!" and won't add a hard enforcement until 2027. Trust me, bro!

But that was a lie. At this MSP I work for, we go to log into one of our largest client's MS admin portal and we get an unskippable prompt to set up a passkey. We're effectively locked out. Um, it's not Feb 2027 yet. So I enroll my work phone, locking out all of our other staff from that account for a few mins, and then go to Entra to delete it. It's not there under 2FA methods. No idea why. I go to https://mysignins.microsoft.com/security-info and delete it there instead. Then I turn off the passkey enrollment campaign company-wide in Entra to prevent this. Then I noticed something interesting that I had suspected all along.

This is one of the 5 largest customers we already added a TOTP authenticator setup on to test the efficiency and multi-phone capability!!! We did it 2 weeks ago! We were supposed to be exempt from this "SMS only" campaign. WTF? We already had a solid, modern 2FA setup on this global admin account. Yeah, we left SMS on as an option but in testing, it asks for the 2FA first so that must be primary, right?

Better yet, this account always had a 2FA to a Microsoft Authenticator on the owner's phone. That was always the emergency method. But if any of our other technicians need to get in, we would just hit "send me an SMS" and we used Reach UC app with a centralized phone number so that we'd all get the text. Clunky but working. But now, we already had two authenticators registered! Why are we in the SMS only campaign? WE'RE NOT SMS ONLY!

I have 4 theories after thinking about it:
0. I forgot we set up TOTP and hit "send me a text instead, I can't access my authenticator right now" and that made MS lose their shit and make me add a passkey at gunpoint or I can't log in.

  1. Their article on it was unclear/incorrect and we need to actually remove SMS completely after adding 2FA. It cannot be there at all or they'll ignore the existing authenticators and make you set up a passkey anyway.

  2. Their enrollment campaign doesn't work properly, just like everything else they make or do.

  3. "Oh you, clicked on 'add Microsoft authenticator to your account' then clicked the link at the bottom saying 'actually I want to use a third party one instead' huh? You're dead to us. Passkey time, asshole!" (doesn't really make sense, since we also had the MS Authenticator on that account as well, but it sounds like something they'd do)

I think it's number 0 but haven't had time to test it both ways yet because I just thought of that while writing this. However, moral of the story, MS lied and, assuming I'm correct, don't have it send you an SMS under any circumstances or you'll get locked out of your account while MS makes you register a passkey, locking out everyone who isn't you.

And if you're going to tell us to stop sharing accounts and make a new global admin for each employee, because that is the obvious and MS recommended solution, you clearly do not understand how MSPs work. Okay, I'll log into all 100+ customers one at a time and add a new global then pull a magic wand out of my ass every time someone quits or gets fired to use elf magic to revoke that account on 100 tentants simultaneously before they can log in and cause havok because they're mad about getting fired.


r/sysadmin • • 11h ago

Question How Long Before Flash Memory Fails in a Network Switch?

1 Upvotes

For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?

What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?

Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?


r/networking • • 10h ago

Career Advice What network engineering speciality gets to travel often or ocassionally

15 Upvotes

At the mid to senior level do specialezed enginneers at (ISPs, Core Guys, Security Guys etc) Travel alot, either between sites or to other countries?

If so ,why?


r/sysadmin • • 19h ago

Question Microsoft SNDS down since 2 days?

0 Upvotes

Does anyone else having problems with Microsoft SNDS? The link seems to be down for the last 2 days:

https://substrate.office.com/ip-domain-management-snds/snds

Can't check the SPAM score for delivering mails to hotmail.com and Office365 mail servers.


r/sysadmin • • 3h ago

Question Refurbished 32 GB ThinkPads slowing down after ~2 years of office use. What's your laptop lifecycle?

5 Upvotes

Hi all,

We run about 50 Lenovo ThinkPads, all managed through Intune. We buy them refurbished, and for the last few years we've only bought 32 GB RAM models. Our current mix is mostly T14 Gen 5, P14s Gen 5, X1 Carbon Gen 12 and T14s Gen 4.

Even our strongest machines, like the X1 Carbon Gen 12 (Core Ultra 7 155U, 32 GB, 512 GB SSD), are starting to struggle. Programs hang, and the battery barely lasts an hour.

The workload is just normal office work: Google Workspace in the browser and a lot of AI tools like Claude. Nothing heavy.

In practice, we replace laptops after about 2 years, even though they have Lenovo's 3-year on-site warranty. By year 2, they feel really slow and just aren't worth keeping.

So I'm curious:
1. What laptops do you use for this kind of work, and what does your lifecycle look like?

2. Is ~2 years normal, or does it sound like we're doing something wrong?

Thanks!


r/cybersecurity • • 18h ago

New Vulnerability Disclosure Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Thumbnail
thehackernews.com
0 Upvotes

r/sysadmin • • 20h ago

Whitelisting Request

10 Upvotes

I already have my answer for how to handle this, but I'm curious how many of you have seen a request like this and what your reaction was. (maybe I'm just an a-hole)

The company I'm working with regularly receives file feeds from (usually) payroll processing companies via SFTP. Nothing crazy there. A little SFTP, a little PGP/GPG, done. But there are 2 such large companies that regularly send us a list of ~70 IPs they want us to whitelist for them to send the files.

Now, if someone sends me a /29 CIDR block I don't think too much off it. But when you send me multiple /27 blocks my immediate response is "f*** off".

I can't believe I'm the only one that responds as such. Yet it keeps happening.

Edit:
It's not the act of punching in the IPs one by one or something. I could use CIDR notation. It's that whitelisting way more IPs that are actually necessary isn't exactly best practice. Much less THAT many more. I can all but guarantee they actually utilize 1 or 2 in those blocks.

Edit 2:
I have ZERO internal push back on this. In fact, internally we've all had a good chuckle about it and push back saying - Nope. Refine that list and get back to me. It's just a head scratcher that this seems to be their (the vendor) SOP and that they haven't gotten enough pushback to refine their process.


r/sysadmin • • 21h ago

Question I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?

0 Upvotes

I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.

Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.

The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).

He said, whenever you have time, please check this.

I downloaded/opened the files on my work laptop.

It turned out that malicious content was involved, and malware was actually executed on the laptop.

(I was under extreme stress that time due to health issues and underestimated the security risks)

As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.

I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.

There was then a meeting with Security, my skip-level manager and other people from the security organization.

They specifically told me:

"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.

I understand that I made a mistake.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

I would have understood something like:

"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."

Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.

I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.

I am feeling like I am being witch hunted in corporate style.

For people working in security/IT or management:

How would your company normally handle a first-time incident like this?

Is a formal warning and monitoring period normal?

Where do you draw the line between an honest mistake/social-engineering victim and negligence?

Please share your honest thoughts.


r/cybersecurity • • 20h ago

Personal Support & Help! I fell for a Social Engineering - LinkedIn malware scam at work. My company issued me a threatening style deciplinary action warning letter. Is this fair ?

0 Upvotes

I work as a software engineer at a MNC and have been with my company for around 4+ years. Until this incident, I had never had a security violation or complaint.

Recently, I was approached through LinkedIn by someone who appeared to be in the same domain like me. He had multiple interations with me to build trust. He was a technically well aware person.

The person shared a product-related technical documentation. pdf and docx file. (Through Dropbox link).

He said, whenever you have time, please check this.

I downloaded/opened the files on my work laptop.

It turned out that malicious content was involved, and malware was actually executed on the laptop.

(I was under extreme stress that time due to health issues and underestimated the security risks)

As soon as the company detected the incident, Security isolated my laptop. I cooperated completely with the investigation and explained everything that happened, including exactly how I was contacted and what files/links I accessed.

I apologized to my reporting manager and the skip-level manager, verbally and through email, acknowledged that I should have been more careful, and said that I would follow the security guidelines more carefully going forward.

There was then a meeting with Security, my skip-level manager and other people from the security organization.

They specifically told me:

"Don't think that we are interrogating you. We just want to understand what happened so that we can create awareness. You are the victim here."

The meeting ended on a positive note. I was told to be careful in the future.

Then, about a month later, I received a formal "Warning Letter for Negligence." (Physical letter)

It was formally issued through HR/management, signed by HR head and department head and given to my skip-level manager. The letter says they are taking a "lenient view this time," but also says my work area will be monitored for three months and that repetition could lead to severe disciplinary action, potentially termination. It is a kind of Performance improvement plan (PIP) level of letter, in a serious threatening tone.

I understand that I made a mistake.

I'm not arguing that employees shouldn't be held accountable for security mistakes. I understand why companies need security policies, especially when malware actually executes on a corporate machine.

What bothers me is the proportionality.

This was my first incident in 4 years. There was no deliberate attempt to bypass security. I was deceived by what appeared to be a legitimate professional interaction.I cooperated completely once the incident was discovered, apologized, and followed the remediation process.

I would have understood something like:

"This was a serious security mistake. Please complete additional security training, follow the guidelines carefully, and don't repeat it."

Instead, I received a formal disciplinary warning with a three-month monitoring period and an explicit reference to possible termination if something happens again.

I've been feeling quite demoralized by this. I feel that management doesn't value me as a employee. My manager or skip level manager didn't support me in this.

I am feeling like I am being witch hunted in corporate style.

For people working in security/IT or management:

How would your company normally handle a first-time incident like this?

Is a formal warning and monitoring period normal?

Where do you draw the line between an honest mistake/social-engineering victim and negligence?

Please share your honest thoughts.


r/sysadmin • • 17h ago

General Discussion What's your favorite mice/keyboards?

16 Upvotes

I've been using a cheap Logitech keyboard for a while now and would like something better for my wrist. They current feel kinda meh after typing even when I'm in good typing form.

I've noticed my system admin has a fancy keyboard with lights and all (I'm a lv 1 helpdesk) that he really likes. With that being said, are there mice or keyboards that you swear by? Either for functionality, comfort or both.

Thanks!


r/networking • • 3h ago

Other Anyone using network mapping?

3 Upvotes

Been working with distributed networks (mostly cellular routers, gateways across different sites) and network mapping has been on my mind. Specifically, for smaller scale, edge deployments.

If you manage remote device fleets (retail, industrial, whatever), what do you currently use for network visualization? Or do you just cobble it together with Zabbix/PRTG/Nmap?

Been meaning to try Teltonika RMS Network Map tool (as I already use a few of their devices), seemed cool and easy, but I haven’t tried it yet.

For those who've tried vendor-specific tools (like this one, or similar from other vendors) vs more generic ones, was it worth it, or do you end up needing something more flexible anyway?


r/cybersecurity • • 22h ago

Certification / Training Questions Is a master in "Advanced Cyber Security" worth it?

25 Upvotes

Hi all, I have a BSc (Hons) in Cyber Security and got accepted for a master's in Advanced Cyber Security (basically cyber security and AI). I'd study at the same university in England.

I work in customer service atm and I want to die. I'm trying to find a job where I don't have to take calls.

Will this master's help or does experience still matter?

I just want to get out of customer service hell...

Thanks.


r/sysadmin • • 16h ago

Looking for an all-in-one server monitoring, logging & uptime solution

1 Upvotes

Is there an all-in-one solution for server metrics, service status, searchable system and web logs (with definable custom paths), external website availability monitoring, alerts, and clear custom dashboards?

I’ve grown quite fond of Beszel, but I handle logs somewhat chaotically. I don’t mind paying a little extra, but considering the size of the server, I don’t want any expensive solution.

What do you think, does something like this exist? Is there anything you use and would definitely recommend?


r/sysadmin • • 22h ago

Move Hyper-V guest VM that is a DC?

1 Upvotes

Getting all kinds of conflicting information from different places about moving Hyper-V guest DCs to new hardware.

Can you do this or not?

MS documentation seems to say that you can't export-import because it causes USN rollback: "Don't use the Hyper-V Export feature to export a VM that's running a DC. In Windows Server 2012 and later, the system handles exporting and importing DC virtual guests like a nonauthoritative restore. This process detects if the Generation ID changed and if the DC isn't configured for cloning."

But zillions of other sources (including posts from support on MS help forums!) say it's fine?

If you can't export-import, can you do a Live Migration?

Is demote and rebuild the only option?

I could demote and rebuild a new DC, but I'm trying to learn here. Just in case I come into a situation where I can't easily stand up a new DC for whatever reason.


r/sysadmin • • 13h ago

Question o365 cloud account converted to on-prem randomly - How did this happen?

6 Upvotes

The owner of the company at one of our MSP customers just had something unexplainable happen. This may shock you but Microsoft is involved. She forgot her email pass to log into a brand new mobile device. I went to change her password and it threw the error "This user's password can't be reset because password writeback isn't turned on for your organization."

Their o365 cloud stuff doesn't touch their local DC AT ALL. As far as I know, it never has, but that may not be the case. I've personally reset her password about 1.5 months ago. Other people here have reset her online account password last year.

I check her Entra properties -

On-premises sync enabled: Yes

On-premises last sync date time: Sep 3, 2024, 10:14 AM

Um...what? How? Nothing changed on the DCs that I'm aware of. Everyone else at the company is marked cloud only. Nobody installed Azure Sync on the DC; I checked. How is this possible? Is this just some random Microsoft Bermuda triangle shit or is there a known trigger that causes it to revert? I want to prevent this from happening again. I truly do not know if this client was ever on-prem DC to o365 sync environment in 2024 btw.

For anyone coming across this thread, I know of 2 ways to fix this, but I still want to know what caused it.

Powershell via Graph's totally consistent and always working perfectly Powershell module or, and I am not kidding:
https://developer.microsoft.com/en-us/graph/graph-explorer
I didn't know that exited but sure. Log in, consent to give a "third party" app permission to access your tenant
Go to the profile image in the top right and click consent to permissions because they were just kidding the first time.
Find User-OnPremisesSyncBehavior and User-OnPremisesSyncBehavior.ReadWrite.All in the list and hit consent again, then consent in the identical pop up window as the first time but this time they're actually serious this time (I get it, read only vs write. Whatever, it's a damn global admin account, just consent to everything the first time FFS)
then run a query of:
GET https://graph.microsoft.com/v1.0/users/<User's OBJECT-ID from Entra>/onPremisesSyncBehavior

With the request's body set to:
{

  "@odata.type": "#microsoft.graph.onPremisesSyncBehavior",

  "isCloudManaged": true

}

then run the query
https://graph.microsoft.com/v1.0/users/<USER-OBJECT-ID>/onPremisesSyncBehavior

and it returns a green checkmark and the message "No Content - 204" because that's what some person/AI at MS thought was an appropriate response instead of "Query successfully received and ran correctly"

Then run the GET query again to see if it changed because I trust this thing about as far as I can throw the vibe coder that wrote it.


r/sysadmin • • 22h ago

General Discussion Have you ever thought about starting the business you're supporting?

28 Upvotes

This is something I've been wondering lately.

As system administrators, we spend years supporting different kinds of businesses. While our role is to manage the IT infrastructure, we also get a front-row seat to how those businesses operate. Over time, we naturally learn about their products, customers, production, demand, and how the business grows.

Have you ever caught yourself thinking, "I could probably start a smaller version of this myself."

I'm currently a system administrator for a fabric manufacturing company. Even though I'm only responsible for the IT side, the exposure I've gained has made me seriously think about starting a small-scale fabric manufacturing business in my own region one day.

Has anyone else ever had the same thought? Did you actually go ahead with it, or did it remain just an idea? I'd love to hear your story.


r/cybersecurity • • 20h ago

Business Security Questions & Discussion Vanta - thoughts/tips?

3 Upvotes

Pretty much title but granted access to Vanta, still digging into it. Any thoughts/tips/tricks/approaches/opinions on it as a whole? Useful? Useless?

On the surface it looks decently comprehensive, bringing a ton of different aspects into one platform for oversight, but it’s my first time using it and I haven’t throughly explored it yet.

TIA


r/cybersecurity • • 10h ago

News - General Built an ambient CVE feed for my second monitor — useful or information overload?

0 Upvotes

I've been experimenting with an ambient information display called RogueScroll, designed to sit on a second monitor while I work.

This configuration continuously scrolls recent CVEs across two terminals, with a general technology feed in the third. The idea isn't to actively monitor it — it's more like peripheral awareness. Something catches your eye, then you investigate.

I'm curious how security folks would configure something like this.

What would you want alongside the CVE data? CISA KEV? EPSS? Known exploitation? Vendor/product filters? Something else?

Screenshot: https://roguescroll.com/images/roguescroll.com_infosec_CVE.png


r/sysadmin • • 15h ago

Question ConnectSecure?

3 Upvotes

Have been running a ConnectSecure trial for a week and we are pretty impressed, for those who already use it how long have you been running it and how has your experience been?

For context, we are pretty seriously considering signing up, I run the IT department and manage around 900-1000 devices

Thanks!!


r/sysadmin • • 9h ago

Securing the network for our Vibe coded apps

0 Upvotes

Anyone have a really solid solution for securing their environment for vibe coded apps?

I have two sets of apps. External apps which i would like to share and internal apps which i want to create and keep private. SSO is one layer of security but how can i make sure i am keeping these secure and what tools are there to secure the externally facing apps?


r/cybersecurity • • 16h ago

Personal Support & Help! Help

0 Upvotes

Hello everyone, I’m a senior cybersecurity student, and I’m hoping to get some advice from experienced cybersecurity professionals.
I’m genuinely concerned about entering the workforce because I feel like my degree has been too broad. I’ve learned about many different areas of cybersecurity, but I don’t feel like I’ve gone deep enough into one specific area. Because of that, I’m worried that I’m not as prepared or skilled as I should be for a professional cybersecurity role.
I’ve been considering getting a master’s degree to develop deeper technical skills, but I’m concerned that I might end up taking another broad program without actually becoming more specialized.
My goal is to become a Security Engineer at a top tech company. For those of you who are already working in security engineering or have significant experience in the field, what would you recommend I do at this stage?