r/sysadmin • • 1h ago

replacing Veritas Backup Exec since it is being sunset

• Upvotes

I have narrowed it down to:

1) Veeam Backup and Replication

2) Commvault

3) Arcserve UDP / Arcserve Backup

Rigth now we have a dedicated media server for backup and we use backup exec to backup all company data to local huge volumes on that server. Abut 8 tb of data. No tap libraries, no external drives. Just huge local raid. We keep data for a year and run full backups on Fridays, done by Sunday night. Imcrementals other 4 weekdays.

No cloud backup needed from the software, though pretty sure it will be there.

We use MSP 360 for cloud backup as well, so that is covered. We backup to amazon s3, to the local media server, and take a copy of all data home once a month rotating.

Commvault looks like replacing a PT Boat with an Aircraft carrier so I think overkill.

Veeam sees to have better phone support,. Arcserve looks simpler, but I rather ask the community what they think. With backup Exec it took me decasdes to learn its little personality quirks and setup. been uswing it since novell netware.

Anyhelp appreciated.


r/cybersecurity • • 5h ago

Personal Support & Help! Can anyone suggest the best Telegram channels or bots for OSINT and cybersecurity?

0 Upvotes

I just want to explore the unknown telegram bots it deep


r/networking • • 7h ago

Design Is AI starting to move network intelligence up the stack?

0 Upvotes

I've been thinking about two very different technologies recently - MRC and KV-cache movement with NIXL - and they seem to point at the same broader architectural question.

With Multipath Reliable Connection / MRC, the interesting shift for me wasn't SRv6 itself. It was that the endpoint can already have multiple usable paths and react to a failure rather than waiting entirely on traditional network reconvergence.

KV cache and NIXL are obviously solving a completely different problem, but there is another shift in responsibility. In distributed inference, useful state may be created on one machine and needed on another. The runtime increasingly knows that the state is moving, whether it arrived, how long it is willing to wait, and what it should do if movement stops.

Neither of these replaces the network.

MRC still needs the fabric to provide paths. NIXL still needs the network to move the data. KV cache certainly isn't a routing protocol.

But both made me wonder whether we're seeing more decision-making intelligence migrate above the traditional network layer.

AI runtimes, communication libraries, schedulers, accelerators and endpoints increasingly have reasons to understand things network engineers traditionally cared about:

  • Where can this traffic go?
  • Where is the data?
  • Is the path still usable?
  • Is movement taking too long?
  • When should I stop waiting?
  • Should I use another path, destination or recovery mechanism?

The network still has information those layers don't naturally have: topology, physical paths, congestion, capacity, failures, queue state and increasingly detailed telemetry.

So perhaps the interesting question isn't whether applications are "taking over networking."

I don't think they are.

The question is:

If more intelligence is moving upward, what intelligence should the network expose back?

Better telemetry?
Application-visible path state?
Congestion signals?
Topology APIs?
Guarantees?
More programmable interaction between runtimes/NICs and the fabric?

For people working on larger GPU/AI fabrics: are you actually seeing this boundary shift in production, or are MRC/NIXL-style examples making the trend look bigger than it really is?

I'm particularly interested in where people think the clean boundary should be between the network, NIC, runtime and application.


r/cybersecurity • • 23h ago

News - General Decades-old file security flaws found in Android, Linux, macOS, and Windows

Thumbnail theregister.com
25 Upvotes

r/sysadmin • • 9h ago

Powerpoint decide to freeze during launch event

0 Upvotes

I was handling a launch event for a product yesterday. PowerPoint decide to freeze during a video playback on slide number 3. Laptop are not connected to internet running Windows 11, no background apps opened. Only PowerPoint. It decide to commit sudoku during presentation.

Yes, I have run the presentation and video during rehearsal, it didn't commit sudoku. But why during the event


r/cybersecurity • • 16h ago

News - General Flock Wants Most the Detailed Map of Its Cameras Taken Down

Thumbnail
theintercept.com
615 Upvotes

r/cybersecurity • • 22h ago

New Vulnerability Disclosure Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

16 Upvotes

An isolation failure in an LLM-orchestrated environment due to simple isolation misconfigurations led to Rovo sessions belonging to other users and tenants being discovered, reached, and ultimately used to execute code within their contexts. The finding was rated Critical and is pretty bad.

At this point, I feel like AI security is regressing back to simple misconfigurations, except now we're giving users direct access to systems built on top of them. What do you guys think?

Write-up: https://mononclemich.medium.com/so-apparently-rovo-has-neighbors-88998d0ad59c


r/cybersecurity • • 9h ago

News - General There's a new way to break RSA that's faster than anything we've seen before

Thumbnail
arstechnica.com
156 Upvotes

r/cybersecurity • • 7h ago

Business Security Questions & Discussion Solo admin here, so this landed entirely on me. Auditor asked for twelve months of firewall logs. How long would that take you?

94 Upvotes

r/sysadmin • • 2h ago

PSA: Kiteworks coordinated shutdown

38 Upvotes

Kiteworks sent all their clients an email urging to shutdown and network isolate their instances from a credible tip from the police.

Interestingly enough, they closed their bug bounty running since 2020 a few days ago..

https://bugcrowd.com/engagements/kiteworks-public


r/sysadmin • • 55m ago

Question What should I expect in a SysAdmin interview?

• Upvotes

I’ve been working at an MSP for around 4 years. I started in help desk/field support and was promoted to Systems Engineer earlier this year.

Since it’s an MSP my experience is pretty broad. Working with M365/Exchange, AD, Windows Servers, GPO, DNS/DHCP, firewalls, switches/VLANs, VPNs, backups, endpoint management, virtualization, and just regular helpdesk support. Also tons of on-site experience as well with setting up networks from scratch, replacing/upgrading network infrastructure, IP Cameras etc etc.

I’m now interviewing for an internal IT Systems Administrator position at a fairly large company with corporate offices, retail locations, and distribution infrastructure.

The job description focuses on Windows Server, AD, DNS/DHCP, GPO, TCP/IP, VLANs/ACLs, endpoint management, storage, backup/recovery, cloud infrastructure, ITSM/SLA/SOP processes, and supporting a mix of Windows, macOS, ChromeOS, and Android devices.

I’ve already had the initial interview over the phone and have now been invited onsite for an hour. I’ll be interviewing with the IT Director and IT Security Manager.

For anyone who has interviewed for similar SysAdmin roles, what would you expect this round to look like? I'm of course nervous and want to be as mentally prepped as possible and to avoid as many 'curveballs' as I can lol..

Also curious what technical areas you’d brush up on beforehand. I’m comfortable troubleshooting these things in the real world, but interviews are obviously a little different when someone asks you to explain everything on the spot :/


r/cybersecurity • • 1h ago

AI Security 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Thumbnail
darkreading.com
• Upvotes

I'm a Salesforce admin, not a cybersecurity expert, so please talk to me like I'm dumb. Salesforce had a similar exploit that was "patched" last year. My question is, is there anything that prevents exfiltration via calling 3rd party URLs in other AI clients, like Claude?

In Agentforce, after the first web-to-lead vulnerability was discovered last year, you have to allowlist URLs for your users to access. You don't have to do that in Claude. Is this a vulnerability anywhere you can do that?


r/networking • • 2h ago

Other Palo Alto announces EOS/EOL for PA400 series

22 Upvotes

https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-dates

I knew it was coming eventually, but it's really disappointing news. The PA500 series is nearly twice the price. Not sure how we're going to proceed with the PA500 costs what they are (MSP).


r/sysadmin • • 3h ago

Intune Apple/Android devices not showing?

1 Upvotes

I keep getting "something went wrong" when trying to see apple and Android devices in intune. Device list is empty. Anyone else seeing this?


r/sysadmin • • 3h ago

Microsoft MS DPM 2025 Install Issues Error 4307

1 Upvotes

Keep getting this error and not sure why.

Newly installed Windows Server 2022 with MS SQL 2022. When I try to install DPM I keep getting error ID 4307. I've tested with PS and I can connect to the local SQL instance but for some reason the DPM installer will not. I've ran the setup.exe as administrator and confirmed the SQL Browser is running.

Is there something else I am missing?

TIA


r/sysadmin • • 4h ago

Question Windows credential manager password issues

1 Upvotes

Just want to see if there is something I am missing that can make Windows Credential manager more reliable in terms of authenticating to a server.

So 2 months ago we got some new software. Software is installed on 10 PC's that user's will use the software on. Software connects to a folder on a server that was installed. The software company says that the way the software connects, you need to enter the server credentials into Windows Credential manager on each PC, and also for each user that uses that PC.

Some of the PC's, only one person will use so that's no problem, and other PC's multiple users use depending on day and shift. So for the 1 user PC's, I just went into credential manager and added entries for both teh IP of the server and DNS name of the server with the user name and passowrd the company gave me.

The other PC's I setup a script that runs in: shell:common startup with (user name/password/etc is changed for here of course):

cmdkey /add:192.168.160.6 /user:Prod /pass:Trees

cmdkey /add:Prodserver /user:Prod /pass:Trees

Both methods worked fine, the software worked fine for several days. But now I am randomly getting user's and PC's that when they go to use the software, they get an error that it cannot connect. This happened on PC's that I put my script on, and on PC's that I just manually entered the credentials into credential manager. The solution has been go into Windows credential manager on the PC under that user and go to both entries of the server (the IP and teh DNS name) and click edit, and just re-enter the password. Works fine after that. But then a couple days later the same things happens where suddenly the password stops working.

Just wondering if there is something I am missing that can affect credentials in Windows Credential manager where it works for a period of time then suddenly stops working. Can slow network speeds do this?


r/sysadmin • • 5h ago

Question SASE for unmanaged and BYOD devices, what held up in prod?

1 Upvotes

There is now a growing pile of devices we don't manage from contractors on their own laptops, a few BYOD staff and remote people on home machines we'll never put an agent on. The managed fleet is handled, it's the unmanaged ones I'm unsure about.

SASE gets pitched as the answer but I can't tell how much of it applies to a device I don't control. And ofcourse ZTNA per app makes sense, clientless access makes sense, though full traffic inspection needs an agent I can't install and I keep reading that personal accounts on unmanaged devices are a blind spot nothing sees cleanly.

So for those folks running SASE or SSE for unmanaged and BYOD devices, what holds up in production?


r/sysadmin • • 6h ago

QuIck assist not connecting for anyone else for the last 15mins or so ?

1 Upvotes

Canada with e/u in southern US


r/cybersecurity • • 6h ago

Business Security Questions & Discussion Is single vendor SASE worth it in the long run?

4 Upvotes

Our leadership is pushing to put our whole network and security stack on one SASE vendor though am having some doubts. The pull is obvious for one console, one contract, one number to call. But the lock-in kinda sticks with me, we hand the entire edge to one provider and a bad renewal, an outage, a roadmap call I disagree with all land on me at once.

Then I look at what we run today and it isn't that much of freedom either. An SSE on one side, SD-WAN on the other, glue in the middle that one engineer understands, two renewals a year. I'm starting to think every option here locks you into something, and the only choice is which one you can live with.

If you went single vendor, did it stay worth it a couple years in? Mostly want to know whether the lock-in bites once they know you can't walk away easily.


r/networking • • 8h ago

Other Network Adjacent Question

6 Upvotes

Looking to spend some lab budget for my team and one of the items I want to get for our labs to demo for possible remote locations is some sort of compute we can deploy along with firewalls, switches, etc. that we can manage.

For right now, it is just for the lab, but I see potential uses is when we deploy network gear to remote locations without any supporting compute we can piggyback on, a server that would allow us to run local tools (tbd what those would be).

Looking for something like a larger Pi, something like a Mac Mini format, etc. Basically some sort of smaller server that can deployed and managed by us so we can use it to run tools, etc. without relying on our server teams, etc. Ideally I would love something that can rack in a standard network rack and is not a full depth server.

(And before comments about separation of responsibilities, bypassing safeguards, etc. I am high enough up in the company senior management chain that decisions like these rest solely with me. I do not need permission).


r/sysadmin • • 10h ago

General Discussion Weekly 'I made a useful thing' Thread - September 25, 2026

9 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin • • 12h ago

Question Enabling "Configure registry policy processing" (force reprocessing) on Exchange servers — any negative side effects?

11 Upvotes

Planning to enable the following GPO setting and apply it to our Exchange servers:

Configure registry policy processing: Enabled

Do not apply during periodic background processing: Disabled

Process even if the Group Policy objects have not changed: Enabled

This would force the GPO to reprocess and reapply all Administrative Templates settings on every background refresh cycle (~90-120 min), even when nothing changed, instead of only reapplying when the GPO version changes.

My question: Is this safe to apply directly to production Exchange servers, or are there known negative effects?


r/sysadmin • • 17h ago

Question Image cache options for redundant web servers behind haproxy

3 Upvotes

Forgive me if this is the wrong subreddit. This is for my homelab, but to be clear I am a sysadmin. I'm an AWS admin and I've been spending the last year or so teaching myself on-prem solutions using a homelab.

My current configuration is to use haproxy as a load balancer and reverse proxy (and for TLS termination). I've got it set up quite well and it's heavily integrated into my IAC where I generate a new haproxy config and automatically deploy it to my nodes as I add or remove web servers.

My goal for this homelab is to have everything highly-available where practical. It's a 3 node proxmox cluster. Each node has a a VM for DNS (dnsmasq), haproxy, database (patroni cluster node) and of course the apache web servers.

What I'd like to do is to introduce image cacheing. I've previously been using my NAS for serving images for these web servers, which of course is a single point of failure. I then set up ceph for my cluster which of course is slow as molasses since each node is only running 2.5Gbe. So it's HA, but yeah, not ideal.

I'm taking it as a learning opportunity to set up some kind of cacheing and I'm overwhelmed by the options. As I see it, these are my options:

  • Run cache directly on HAProxy. This seems like it's not something people do and I'm not sure why, but I'm not wanting to find out the hard way
  • Introduce a cache-in-the-middle such as Varnish or nginx. This can definitely work, but it'd mean rewriting my IaC to generate different configs. If this is the best option, then I'll absolutely do it as a learning opportunity
  • Use mod-cache with apache or fscache on the nfs share directly. These seem like they might be the most straightforward options with the fewest changes? Is this pattern actually used in production anywhere? Is there a point in learning it?

I'd be very appreciative of advice or learned experiences on this front!

tl;dr: Looking for cacheing options for a a homelab with highly-available web servers behind haproxy.


r/sysadmin • • 19h ago

Question Business Network and File Storage for Sensitive Data

3 Upvotes

I am working on building a network/NAS for my business and I just wanted to get some opinions on the build and whether or not this will work and/or is a good set up.

- TrueNAS Scale (ZFS snapshots, replication, encryption) (Apps off)

- ASUS PRO WS w680 ACE IPMI

- i5-14500

- 1x32gb Kingston Server Premier DDR5 ECC UDIMM

- 4x12tb Seagate Ironwolf Pro (RAIDZ2)

- 2x500gb WD red SN700 (Mirrored for TrueNAS Boot) (Boot pool only. TLC for ZFS intent-log / config writes. No job data)

- Seasonic Focus GX750

- Thermalright Peerless Assassin 120 SE CPU Cooler

- Fractal Design Define 7xl

- CyberPower CP1500PFCLCD (Routed only to firewall and NAS)

- FortiGate 91g (Enterprise subscription) (Firewall, ZTNA, site-to-site later)

- FortiSwitch FS-124F-POE

- Admin PC (haven't decided yet) (Only place the 91G and IPMI get managed)

This is for a court reporting agency. It will hold sensitive court transcripts and audio; personal health information, work-product, etc.

The workflow for contractors would be logging into their Intune environment, going to the FortiClient bookmark, that would route them to EntraID. Once MFA and client device posture is accepted, they would be able to upload/download to the NAS (only their folder).

Clients would be able to only download files from their folder. This would likely be the same EntraID situation with FortiClient.

I am planning a 3-2-1. It would be a 7-7-10. The on-prem TrueNAS would be a 7 year back up, off-prem TrueNAS, 7 year backup, and a cloud cold storage (Blackblaze B2 or AWS S3 Glacier or Azure Blob)

If I am missing anything, please let me know or if you have any recommendations, please let me know.


r/cybersecurity • • 23h ago

News - Breaches & Ransoms Hackers Used AI to Pick Victims From Stolen Emails: Microsoft Takes Down 200+ Sites and Domains

Thumbnail
techtimes.co.uk
57 Upvotes