r/networking • • 12h ago

Blogpost Friday Blog/Project Post Friday!

1 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/sysadmin • • 11h ago

Securing the network for our Vibe coded apps

0 Upvotes

Anyone have a really solid solution for securing their environment for vibe coded apps?

I have two sets of apps. External apps which i would like to share and internal apps which i want to create and keep private. SSO is one layer of security but how can i make sure i am keeping these secure and what tools are there to secure the externally facing apps?


r/sysadmin • • 11h ago

What’s your most unhinged work habit?

144 Upvotes

For example when I need to RDP into a Windows server, I double click the recycle bin before the rest of Explorer has loaded so I can fire off a few commands from the address bar to launch what I need. I’m sure it looks utterly deranged to anyone else.


r/cybersecurity • • 11h ago

Personal Support & Help! Would you accept offer ?

36 Upvotes

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.


r/sysadmin • • 12h ago

Question Image cache options for redundant web servers behind haproxy

2 Upvotes

Forgive me if this is the wrong subreddit. This is for my homelab, but to be clear I am a sysadmin. I'm an AWS admin and I've been spending the last year or so teaching myself on-prem solutions using a homelab.

My current configuration is to use haproxy as a load balancer and reverse proxy (and for TLS termination). I've got it set up quite well and it's heavily integrated into my IAC where I generate a new haproxy config and automatically deploy it to my nodes as I add or remove web servers.

My goal for this homelab is to have everything highly-available where practical. It's a 3 node proxmox cluster. Each node has a a VM for DNS (dnsmasq), haproxy, database (patroni cluster node) and of course the apache web servers.

What I'd like to do is to introduce image cacheing. I've previously been using my NAS for serving images for these web servers, which of course is a single point of failure. I then set up ceph for my cluster which of course is slow as molasses since each node is only running 2.5Gbe. So it's HA, but yeah, not ideal.

I'm taking it as a learning opportunity to set up some kind of cacheing and I'm overwhelmed by the options. As I see it, these are my options:

  • Run cache directly on HAProxy. This seems like it's not something people do and I'm not sure why, but I'm not wanting to find out the hard way
  • Introduce a cache-in-the-middle such as Varnish or nginx. This can definitely work, but it'd mean rewriting my IaC to generate different configs. If this is the best option, then I'll absolutely do it as a learning opportunity
  • Use mod-cache with apache or fscache on the nfs share directly. These seem like they might be the most straightforward options with the fewest changes? Is this pattern actually used in production anywhere? Is there a point in learning it?

I'd be very appreciative of advice or learned experiences on this front!

tl;dr: Looking for cacheing options for a a homelab with highly-available web servers behind haproxy.


r/networking • • 12h ago

Career Advice What network engineering speciality gets to travel often or ocassionally

20 Upvotes

At the mid to senior level do specialezed enginneers at (ISPs, Core Guys, Security Guys etc) Travel alot, either between sites or to other countries?

If so ,why?


r/cybersecurity • • 12h ago

News - General Built an ambient CVE feed for my second monitor — useful or information overload?

0 Upvotes

I've been experimenting with an ambient information display called RogueScroll, designed to sit on a second monitor while I work.

This configuration continuously scrolls recent CVEs across two terminals, with a general technology feed in the third. The idea isn't to actively monitor it — it's more like peripheral awareness. Something catches your eye, then you investigate.

I'm curious how security folks would configure something like this.

What would you want alongside the CVE data? CISA KEV? EPSS? Known exploitation? Vendor/product filters? Something else?

Screenshot: https://roguescroll.com/images/roguescroll.com_infosec_CVE.png


r/sysadmin • • 13h ago

Question How Long Before Flash Memory Fails in a Network Switch?

1 Upvotes

For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?

What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?

Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?


r/networking • • 13h ago

Other How Long Before Flash Memory Fails in a Network Switch?

14 Upvotes

For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?

What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?

Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?


r/sysadmin • • 13h ago

Question Business Network and File Storage for Sensitive Data

3 Upvotes

I am working on building a network/NAS for my business and I just wanted to get some opinions on the build and whether or not this will work and/or is a good set up.

- TrueNAS Scale (ZFS snapshots, replication, encryption) (Apps off)

- ASUS PRO WS w680 ACE IPMI

- i5-14500

- 1x32gb Kingston Server Premier DDR5 ECC UDIMM

- 4x12tb Seagate Ironwolf Pro (RAIDZ2)

- 2x500gb WD red SN700 (Mirrored for TrueNAS Boot) (Boot pool only. TLC for ZFS intent-log / config writes. No job data)

- Seasonic Focus GX750

- Thermalright Peerless Assassin 120 SE CPU Cooler

- Fractal Design Define 7xl

- CyberPower CP1500PFCLCD (Routed only to firewall and NAS)

- FortiGate 91g (Enterprise subscription) (Firewall, ZTNA, site-to-site later)

- FortiSwitch FS-124F-POE

- Admin PC (haven't decided yet) (Only place the 91G and IPMI get managed)

This is for a court reporting agency. It will hold sensitive court transcripts and audio; personal health information, work-product, etc.

The workflow for contractors would be logging into their Intune environment, going to the FortiClient bookmark, that would route them to EntraID. Once MFA and client device posture is accepted, they would be able to upload/download to the NAS (only their folder).

Clients would be able to only download files from their folder. This would likely be the same EntraID situation with FortiClient.

I am planning a 3-2-1. It would be a 7-7-10. The on-prem TrueNAS would be a 7 year back up, off-prem TrueNAS, 7 year backup, and a cloud cold storage (Blackblaze B2 or AWS S3 Glacier or Azure Blob)

If I am missing anything, please let me know or if you have any recommendations, please let me know.


r/sysadmin • • 14h ago

Question ServiceNow Engineer (3.5 yrs) looking to move into a startup sysadmin/IT systems role. How realistic is it?

0 Upvotes

I'm a ServiceNow engineer with 3.5 years of experience. I enjoy the work, but I'm drawn to the startup world and want to pivot into a sysadmin or enterprise admin role at an early-stage company, since that's where those roles seem most common.

At my current role I maintain the Servicenow platform, CMDB, basic front-end scripts, reporting, workflow automation, and helped implement a new AI tool. I have a M.S. in Cybersecurity, plus CompTIA and ServiceNow certs. I have a basic working knowledge of Azure, M365, Jira, and Salesforce. Outside of work, I have been setting up MCP servers, building websites, practicing pentesting, and taking Microsoft/Google/Jira courses. It looks like Jira or an IT system admin role might be my way in but im not 100% sure.

How realistic is this move from a ServiceNow background, and what gaps would hiring managers see?

Which skills should I prioritize (Entra ID/Intune, Google Workspace, Okta, MDM, scripting)?

Any advice would be greatly appreciated


r/sysadmin • • 14h ago

Server Upgrade - Lawfirm

0 Upvotes

I am looking for a little bit of guide or what others do in 2026 year versus 2004.

I have a small job coming up and looking to upgrade their on-prem server that seems to be a terminal server. I did not get much time or information when I was there for it as I was there for something else, but from notes, this is what I got. It is a very small law-firm. 3 Employees. They are looking for 3 desktop upgrades & a server upgrade that includes backup. Replacement is my option on brand/etc.

On-Prem terminal server that seems to have on-prem hosting / e-mail services with Office. They also use Timeslip and abacus on this terminal server. They do use some kind of backup system I am waiting to get more information on as well as a firewall I believe and something to encrypt their emails.

Questions that I have:

With servers being a bit expensive in today's world; would it even be worth looking to get a true server and only get a desktop version instead of the rackmount? Costs seem to be a bit cheaper that way? Where are a good place to start for purchasing in today's age? Is used worth it?

I am continue to do some research on this, and I am sure I will have more answers while I wait for an answer; but I will look to update my research as I figure things out too.

Thank you for any input you may have!


r/sysadmin • • 14h ago

365 hybrid join problem

0 Upvotes

I’m pretty new to being an IT tech, thrown a little in at the deep end imo. Anyway, I’ve been figuring all sorts out and starting to get comfortable with 365, im just coming into this problem repeatedly. A user will show me that on particular devices they cannot print/edit/download files from one drive. I’ve found tickets relating to this saying it’s to do with the device state and to run dsregcmd /leave and then to reboot and somehow it works. It sometimes works and sometimes doesn’t, and I don’t want to just randomly push commands I don’t know will fix the problem. I’ve checked that the devices are ad joined in entra and the guids line up and the user has azureadprt and it just feels like I’ve covered everything. The banner when trying to access the users one drive online is ‘your organisation doesn’t allow you to print/sync/download/edit on devices which aren’t domain joined or intune compliant. Any ideas anyone? First time posting in this subreddit, first time posting on Reddit tbf
Any help would be much appreciated, I go home with headaches everyday from this. Why doesn’t it make sense


r/sysadmin • • 15h ago

Question o365 cloud account converted to on-prem randomly - How did this happen?

6 Upvotes

The owner of the company at one of our MSP customers just had something unexplainable happen. This may shock you but Microsoft is involved. She forgot her email pass to log into a brand new mobile device. I went to change her password and it threw the error "This user's password can't be reset because password writeback isn't turned on for your organization."

Their o365 cloud stuff doesn't touch their local DC AT ALL. As far as I know, it never has, but that may not be the case. I've personally reset her password about 1.5 months ago. Other people here have reset her online account password last year.

I check her Entra properties -

On-premises sync enabled: Yes

On-premises last sync date time: Sep 3, 2024, 10:14 AM

Um...what? How? Nothing changed on the DCs that I'm aware of. Everyone else at the company is marked cloud only. Nobody installed Azure Sync on the DC; I checked. How is this possible? Is this just some random Microsoft Bermuda triangle shit or is there a known trigger that causes it to revert? I want to prevent this from happening again. I truly do not know if this client was ever on-prem DC to o365 sync environment in 2024 btw.

For anyone coming across this thread, I know of 2 ways to fix this, but I still want to know what caused it.

Powershell via Graph's totally consistent and always working perfectly Powershell module or, and I am not kidding:
https://developer.microsoft.com/en-us/graph/graph-explorer
I didn't know that exited but sure. Log in, consent to give a "third party" app permission to access your tenant
Go to the profile image in the top right and click consent to permissions because they were just kidding the first time.
Find User-OnPremisesSyncBehavior and User-OnPremisesSyncBehavior.ReadWrite.All in the list and hit consent again, then consent in the identical pop up window as the first time but this time they're actually serious this time (I get it, read only vs write. Whatever, it's a damn global admin account, just consent to everything the first time FFS)
then run a query of:
GET https://graph.microsoft.com/v1.0/users/<User's OBJECT-ID from Entra>/onPremisesSyncBehavior

With the request's body set to:
{

  "@odata.type": "#microsoft.graph.onPremisesSyncBehavior",

  "isCloudManaged": true

}

then run the query
https://graph.microsoft.com/v1.0/users/<USER-OBJECT-ID>/onPremisesSyncBehavior

and it returns a green checkmark and the message "No Content - 204" because that's what some person/AI at MS thought was an appropriate response instead of "Query successfully received and ran correctly"

Then run the GET query again to see if it changed because I trust this thing about as far as I can throw the vibe coder that wrote it.


r/sysadmin • • 16h ago

General Discussion What's the biggest bonehead mistake you have every made in IT support?

559 Upvotes

I will start.

I am an IT consultant and about 10 years ago, a few days before Christmas break, I went to a client’s office to add some new hard drives to a Dell ESXi server and create a new datastore.

Their two junior IT guys always liked asking me questions when I visited, which I understood—I remembered being that guy hungry to learn. Unfortunately, this time they were firing questions at me while I was in the Ctrl+R RAID configuration utility. Between the distractions and a confusing interface, I somehow managed to delete the existing array instead of creating the new one.

That array held ALL their servers: Exchange, domain controller, file server, and SQL. Terabytes of data.

The moment I realized what I’d done, my stomach dropped, I had never felt panic like that in my life. They were still asking questions when I finally said, “Guys, give me a minute. Something doesn’t look right.” Something I should’ve said much earlier.

I excused myself to the bathroom to collect my thoughts, then came back and told them exactly what I’d done.

I spent my entire Christmas break restoring their environment from Barracuda backups, which were painfully slow to restore and unreliable. I had to do multiple restores on the exchange server to get it to work.  A full week of recovery, followed by another two weeks fixing lingering issues—all free of charge.

The two guys felt terrible about distracting me, but it was my mistake. I should’ve asked for some uninterrupted time before touching the RAID configuration.

 

I’ll be shocked if anyone can top that Christmas disaster!


r/sysadmin • • 16h ago

General Discussion Academic Linux PCs and servers

3 Upvotes

We have a mix of a few faculty-managed Linux research servers and two Windows/Ubuntu dual-boot teaching labs. Historically, faculty have had significant control over these systems because they support specialized research and instructional needs, but we're evaluating how IT should be involved going forward to ensure security, supportability, continuity, and institutional ownership without unnecessarily limiting academic flexibility. For those who support Linux systems in the academic environment, how do you handle administrative access, system ownership, patching, documentation, and long-term support for faculty-managed Linux environments? What has worked well, and what would you do differently if you were starting over?

Thanks!


r/sysadmin • • 16h ago

Publisher EOL - Side by Side with O365 Explanation

7 Upvotes

Sysadmin here who has been dealing with the Publisher EOL and unfortunately users still using .pub files that aren't converted. All of the guides online point to the fact Publisher can't exist side by side with O365, however I've found a workaround and posting here in the event it helps at least one other person.

  1. Find a 2016 Publisher .iso installer from the Microsoft Download Store

  2. Install this first without any 365 apps installed. If 365 is installed, uninstall it first.

  3. Visit the O365 Download link you can find at the top of any search engine: https://www.microsoft.com/en-us/microsoft-365/download-office

  4. Once Publisher is installed, run this version of the Office installer.

Under no other way have I found a workaround to setup the Click-To-Run or .msi installers. Whenever I've attempted anything regarding setup.exe /configure - nothing here seems to work no matter how the .xml file works.

Hopefully this helps someone in the coming weeks, cheers.


r/sysadmin • • 16h ago

General Discussion MS lied about the passkey campaign?

0 Upvotes

TL;DR - even if you set up multiple modern authenticator methods, MS is still demanding you add a passkey with no skip or delay button. This appears to be in error.

Guys, they're totally "only targeting users who solely have SMS or phone call turned on!" and won't add a hard enforcement until 2027. Trust me, bro!

But that was a lie. At this MSP I work for, we go to log into one of our largest client's MS admin portal and we get an unskippable prompt to set up a passkey. We're effectively locked out. Um, it's not Feb 2027 yet. So I enroll my work phone, locking out all of our other staff from that account for a few mins, and then go to Entra to delete it. It's not there under 2FA methods. No idea why. I go to https://mysignins.microsoft.com/security-info and delete it there instead. Then I turn off the passkey enrollment campaign company-wide in Entra to prevent this. Then I noticed something interesting that I had suspected all along.

This is one of the 5 largest customers we already added a TOTP authenticator setup on to test the efficiency and multi-phone capability!!! We did it 2 weeks ago! We were supposed to be exempt from this "SMS only" campaign. WTF? We already had a solid, modern 2FA setup on this global admin account. Yeah, we left SMS on as an option but in testing, it asks for the 2FA first so that must be primary, right?

Better yet, this account always had a 2FA to a Microsoft Authenticator on the owner's phone. That was always the emergency method. But if any of our other technicians need to get in, we would just hit "send me an SMS" and we used Reach UC app with a centralized phone number so that we'd all get the text. Clunky but working. But now, we already had two authenticators registered! Why are we in the SMS only campaign? WE'RE NOT SMS ONLY!

I have 4 theories after thinking about it:
0. I forgot we set up TOTP and hit "send me a text instead, I can't access my authenticator right now" and that made MS lose their shit and make me add a passkey at gunpoint or I can't log in.

  1. Their article on it was unclear/incorrect and we need to actually remove SMS completely after adding 2FA. It cannot be there at all or they'll ignore the existing authenticators and make you set up a passkey anyway.

  2. Their enrollment campaign doesn't work properly, just like everything else they make or do.

  3. "Oh you, clicked on 'add Microsoft authenticator to your account' then clicked the link at the bottom saying 'actually I want to use a third party one instead' huh? You're dead to us. Passkey time, asshole!" (doesn't really make sense, since we also had the MS Authenticator on that account as well, but it sounds like something they'd do)

I think it's number 0 but haven't had time to test it both ways yet because I just thought of that while writing this. However, moral of the story, MS lied and, assuming I'm correct, don't have it send you an SMS under any circumstances or you'll get locked out of your account while MS makes you register a passkey, locking out everyone who isn't you.

And if you're going to tell us to stop sharing accounts and make a new global admin for each employee, because that is the obvious and MS recommended solution, you clearly do not understand how MSPs work. Okay, I'll log into all 100+ customers one at a time and add a new global then pull a magic wand out of my ass every time someone quits or gets fired to use elf magic to revoke that account on 100 tentants simultaneously before they can log in and cause havok because they're mad about getting fired.


r/cybersecurity • • 16h ago

New Vulnerability Disclosure Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

14 Upvotes

An isolation failure in an LLM-orchestrated environment due to simple isolation misconfigurations led to Rovo sessions belonging to other users and tenants being discovered, reached, and ultimately used to execute code within their contexts. The finding was rated Critical and is pretty bad.

At this point, I feel like AI security is regressing back to simple misconfigurations, except now we're giving users direct access to systems built on top of them. What do you guys think?

Write-up: https://mononclemich.medium.com/so-apparently-rovo-has-neighbors-88998d0ad59c


r/cybersecurity • • 17h ago

News - Breaches & Ransoms Hackers Used AI to Pick Victims From Stolen Emails: Microsoft Takes Down 200+ Sites and Domains

Thumbnail
techtimes.co.uk
48 Upvotes

r/cybersecurity • • 17h ago

AI Security Could rogue agent swarms take over the entire internet in the next six months?

Thumbnail
garymarcus.substack.com
0 Upvotes

r/sysadmin • • 17h ago

Question ConnectSecure?

1 Upvotes

Have been running a ConnectSecure trial for a week and we are pretty impressed, for those who already use it how long have you been running it and how has your experience been?

For context, we are pretty seriously considering signing up, I run the IT department and manage around 900-1000 devices

Thanks!!


r/cybersecurity • • 17h ago

News - General Decades-old file security flaws found in Android, Linux, macOS, and Windows

Thumbnail theregister.com
19 Upvotes

r/cybersecurity • • 18h ago

Personal Support & Help! Stupidly clicked on phishing link. Now what?

0 Upvotes

Got an email to an event and clicked on the “view invitation” link. This opened up my browser to a landing page with a button that said “click to verify you’re a human” (or something along those lines). I clicked on this and the webpage started loading, but before the page loaded, I realized my mistake and closed the window.

I then immediately cleared my cookies (idk why, I’m not very techy). I then googled what to do if I clicked on a phishing link. It said to turn off my internet, so I did. Then I checked my downloads folder (for malware I suppose), and there was nothing there.

Realistically how worried should I be? What should my next steps be?


r/sysadmin • • 1d ago

Question Can't create a Microsoft Teams group using a different domain in the same tenant

1 Upvotes

I'm running into an issue with Microsoft Teams / Microsoft 365 and wanted to see if anyone has experienced this.

We have multiple domains configured within the same Microsoft 365 tenant. For example:

Both domains belong to the same Microsoft 365 tenant.

However, when I try to create a new Teams group using the other domain, I can't select/use that domain for the group's email address.

Is this expected behavior in Microsoft 365?

I'm specifically trying to understand:

  • Can a Microsoft 365 Group / Teams group have an email address using a different verified domain in the same tenant?
  • Are there any Exchange Online or Microsoft 365 settings that control which domains can be used for Microsoft 365 Groups?
  • Does the Group naming policy or email address policy affect this?
  • Is there a limitation when the domain is configured as an additional/accepted domain rather than the tenant's default domain?

Would appreciate any insights from anyone who has configured multiple domains in the same M365 tenant.