▲ 5 r/CMMC

S3 compatible storage for Veeam?

Looking for S3 compatible storage for Veeam off-site backups that have object lock for immutability. Using Backblaze now, but they are not even FedRAMP Ready. Was looking at Wasabi, but they are only READY and not Authorized.

Anyone have suggestions beyond going with AWS GovCloud of Microsoft Government? I looked at the FedRAMP Marketplace for storage - there were a lot and doesn't call out S3 storage as an offering in the quick blurbs.

Appreciate any nudges in the right direction. Thanks!

reddit.com
u/Mvalpreda — 11 days ago
▲ 133 r/pihole

Finally pulled the trigger - why did I wait so long?

I finally pulled the trigger on setting up pi-hole today....and I don't know why I waited so long!

Actually....I do know why. I'm an have Active Directory set up in my home lab with Windows for DHCP and DNS....and a wife that works from home. Last thing I wanted to do was mess her up since everything was working fine and I was comfortable with any troubleshooting.

Not sure what the catalyst was, but I said 'I'm setting this up today!' and I did. Little help for steps from Google (Gemini)...an Ubuntu VM on Hyper-V, quick pi-hole install, add HaGezi's Pro and FIT blocklists, add my conditional forwarders for internal AD.....and under and hour I was done.

Now I'm getting good insight on what and how much is being blocked. It's crazy to see how much is being blocked - especially from my TV(s)! Even have an app on my iPhone to monitor stats. It's a very impressive and polished offering. On top of that, browsing seems a little snappier - guessing since DNS is being served by something that only does DNS.

I raise a bourbon (well...maybe 3!) to pi-hole tonight. Glad to be a user.

reddit.com
u/Mvalpreda — 19 days ago

Using WSUS for Cluster-Aware Updates - stopped working a few months back....now what to use?

Been using WSUS on a 2022 Server just to do cluster-aware updating. Been using WSUS since we put our 3-node Server 2019 Hyper-V cluster in some years ago. Noticed in the last few months that there are no 'updates needed by computers' and there the last time my cluster nodes checked in was late April 2026.

The GPO has not changed, RSOP shows everything applying correctly. firewall showing the ports open, etc. If I manually approve the updates, CAU finds and installs them...does the whole drain/reboot/resume, then moves to the next cluster node.

I'm not seeing any blogs or post that changed with WSUS more than it being end of life. It does look like the ADMX for WSUS changed - shows some of the options I had set previously now showing under 'Legacy Policies' and some other new options....wondering if something in there is needed to get the machines to check in again.

I'm not opposed to moving to something else, just curious if there is something that is available that mimics the CAU.

Appreciate any nudges in the right direction!

reddit.com
u/Mvalpreda — 1 month ago

Bring app to the foreground? Trying to do some Teams shortcuts....

I'm looking to use my ActionRing N3 Macro Keypad to add some Teams functionality - mute, camera on/off, and leave the meeting. Mute works since it is a system-wide hotkey, but camera on/off and leave the meeting need Teams to be the focused application.

What can I do in VSD Craft to bring Teams to the foreground, and then do the camera on/off hotkey (Control + Shift + O) or leave the meeting (Control + Shift + H)?

Some of the AI responses I got tell me to do an Action Flow and launch %LOCALAPPDATA%\Microsoft\Teams\current\Teams.exe - which does not exist any longer.

Can someone nudge me in the right direction?

Thanks!

reddit.com
u/Mvalpreda — 1 month ago

When to use path monitoring vs. tunnel monitor?

Corp/data center with HA PA1410s and 2x ISPs and a warehouse with HA PA440s and 2x ISPs

Currently have 4x tunnels set up - each on their own tunnel interface. Each tunnel interface has a /30 and a management interface profile with only ping allowed.

  1. Corp primary to warehouse primary
  2. Corp primary to warehouse secondary
  3. Corp secondary to warehouse primary
  4. Corp secondary to warehouse secondary

Have static routes set up with increasing metrics (10/20/30/40) in the same order as above.

All tunnels are showing up in Network - IPSec Tunnels. Under each of the 4x tunnels in Network - IPSec Tunnels, I have Tunnel Monitor set up with monitor profile called 'FAILOVER' that has 'Fail Over' selected opposed to 'Wait Recover' with 5 second interval and 5 second threshold.

I can't say we've ever had an event where any of this would be put to the test. I tried shutting down the first tunnel, but the static route stayed active on the disabled tunnel. I was reading that using path monitoring might help with that - but not to use both at the same time. I don't know if if/when there is an ISP failure that the tunnel monitor would kick in and work as expected.

Was hoping to get a good understanding of this before I do a real failover test some weekend.

Appreciate any thoughts/input/criticism! There's no user flair for 'inherited this and know enough to be dangerous' ;)

reddit.com
u/Mvalpreda — 2 months ago

Constant battles with Macs and URL filtering - suggestions?

We have constant issues with our Macs and them not getting the correct URL filtering profiles we have set up. Trying to see what might be a better solution than rebooting the Mac and hoping it registers with the User-ID Agent - which doesn't always solve it.

User-ID Agent is running on a server and there is a decent number of entries in there. When someone cannot get to a site that they should be able to, find they are not showing in the User-ID Agent.

Is there any sort of trick to get the Macs to register more reliably? I did see a few mentions of using always-on GlobalProtect to an internal gateway that just registers the device, but doesn't encrypt any traffic. I'd be willing to try that if there is a document somewhere. I didn't have any luck, but I'm probably not using the correct terms.

Appreciate any pushes in the right direction.

reddit.com
u/Mvalpreda — 2 months ago

Bookings link showing me available at times I don't have in my work hours

Had someone book me for a 7am meeting on Friday and I wasn't sure how they were able to. I have my work hours as M 8-5, Tu 7-4, W 8-5, Th 8-5, and F 9-3.

If I go to my Bookings page as a guest, it shows me available at 7am nearly every day except Tuesday. On Friday, it shows I can be booked from 7am until 5pm. I checked each of my Bookings options and it says to use 'Use my regular meeting hours'.

Trying to figure out where it might be getting that 7am start time for meetings and/or why it is not adhering to my schedule.

reddit.com
u/Mvalpreda — 2 months ago
▲ 4 r/entra

Suggestions for conditional access policy for travelers with existing geoIP polices?

I have 4 groups of users - US, Canada, Australia, Ireland. I have 4x separate conditional access policies for each of the groups to only allow logins from their respective countries. Simple CAP with the group included, all resources, all networks included, selected network excluded, block access.

Have users that travel outside of their regions so I added a group called 'Travelers' as an exempted group in each of the CAPs, but does not seem to be working. Users that are travelling are getting blocked.

I'm wondering if there is a better approach to this or if I am missing something. Using P1 licenses.

[EDIT] The user stays in their respective location group, then is added to the 'Travelers' group.

reddit.com
u/Mvalpreda — 2 months ago

A sanity check on licenses - my reseller and reps are driving me bonkers.....

I don't think this should be so hard, but I don't feel like I'm getting the same answer twice. I

We have 3 sites

Site 1: Corp with 2x PA-1410 in HA
Site 2: Warehouse with 2x PA-440 in HA
Site 3: Small facility with 1x PA-440 standalone

I think this is what the licenses should look like:

3x PAN-SVC-PREM-440-3YR-R (3-year Premium Service renewal on PA-440)
1x PAN-PA-440-BND-PRECISIONAI-3YR-R (3-year PRECISIONAI software license renewal)
1x PAN-PA-440-BND-PRECISIONAI-3YR-HA2-R (3-year PRECISIONAI software license for PA-440 HA pair)

2x PAN-SVC-PREM-1410-3YR-R  (3-year Premium Service renewal on PA-1410)
1x PAN-PA-1410-BND-PRECISIONAI-3YR-HA2-R (3-year PRECISIONAI software license renewal for PA-1410 HA pair)
1x PAN-PA-1410-PAA-3YR-HA2-R (3-year software license for PAA/Global Protect)

Does this look right? The only thing I get mixed answers on is if the -HA2 needs to be quantity 1 or 2.

Appreciate anyone checking my work. I get different answers from ChatGPT and Gemini on the HA2!

reddit.com
u/Mvalpreda — 3 months ago
▲ 5 r/meraki

Anyone moved from Advanced Security to Secure SD-WAN Plus licenses?

Looking to see if we are going to get any value-add by going from Advanced Security to Secure SD-WAN Plus licensing.

  • 2x MX105 in HA at our Corp
    • Corp has ERP, internal web apps, file shares, AD, etc.
    • 2x 1Gb connections
    • 100-150 Cisco Secure VPN users
    • Hub for site-to-site
  • 2x MX75 in HA at our warehouse
    • No servers
    • 1x 1Gb and 1x 200x200 connections
    • Site-to-site back to Corp
  • 1x MX75 at a small production facility
    • No servers
    • 600x50 cable modem
    • Site-to-site back to Corp

Licenses are due for renewal soon and wondering if we would get benefit from going to Secure SD-WAN Plus. Looking for something that is not marketing fluff.

reddit.com
u/Mvalpreda — 3 months ago

Exchange SE Hybrid certificate renewed - mail stuck in queue

Exchange SE on Server 2025. Certificate expired and renewed it through GoDaddy. Ran through Hybrid Configuration Wizard again and updated to the new certificate. ECP is showing the certificate as valid, but emails that are relayed through that server are stuck. I am seeing a 421 4.2.1 Unable to connect -> SocketError with domain.mail.onmicrosoft.com

Direct Send is turned off, but we do have a connector at Exchange Online for our IP address. This has been working until the certificate was renewed.

I'm guessing I'm missing a step somewhere. Any points in the right direction would be most appreciated.

reddit.com
u/Mvalpreda — 3 months ago
▲ 3 r/ArubaInstantOn+1 crossposts

Anyone using the SG1004 yet? Few questions.....

I have a free license through Mearki CMNA for my MX67 that might be going away soon so I'm starting to look at other gateway devices. I already have an 8-port PoE and 24-port InstantOn switches, so going with the SG1004 made sense to stay in the same ecosystem. I just had a few questions and was seeing if anyone knows....

  1. Pretty sure it supports VLANs
  2. Does it include content filtering?
  3. How good is the IDS/IPS?
  4. Do the firewall rules have ACLs? (only allow incoming from certain IPs)
  5. Does it do port forwarding? (incoming on port X - translate to port Y)

Appreciate any input anyone may have. I'm sure someone is going to suggest PFSense, but I'd rather not build something myself.

reddit.com
u/Mvalpreda — 3 months ago
▲ 2 r/meraki

Different Geo-IP rules for outbound vs inbound?

Is there a way on the MX security appliances to only allow incoming connections from say the US, but allow outbound connections to all but a handful of locations?

Want to only allow US connections for client VPN. And yes, do have MFA on VPN (using SAML through Entra).

When I was looking at layer 7 rules, it says to/from on that rule, so I'm guessing it is going to block both ways including established outbound connections.

Appreciate any nudges in the right direction.

reddit.com
u/Mvalpreda — 3 months ago
▲ 0 r/aws

Move account/root user to new user/email address and add individual users?

Apologies as I have next to no experience with AWS, so I'll probably be using the incorrect terms.....

Have an AWS account accessing an S3 bucket that was set up by a user that has left. We do have access to the account and the MFA so it is not like we are locked out. Want to move that to a distribution list that is seen by multiple people. Is that as simple as updating the name and email address after logging in?

There are a couple of users that need access to the S3 bucket and are sharing the old user's login. I assume I need to set up new IAM users for those users, set up a policy for the bucket, add the users to that policy, then test.

Thanks for any nudges in the right direction.

reddit.com
u/Mvalpreda — 3 months ago
▲ 2 r/Veeam

Veeam B&R server is still domain-joined for now. Looking to best path forward to change that. For now, trying to get the permissions on the Veeam Service Account to as little as possible.

In reading https://helpcenter.veeam.com/archive/backup/120/vsphere/required_permissions.html#rptcb it says the Built-In Administators group. I removed all the groups for the service account, left 'Administrators domain.local/Builtin'. When I do that, I cannot successfully complete a guest credentials check, I have to put Domain Admins back in.

Is that expected? Or am I missing something?

Appreciate any nudges in the right direction.

u/Mvalpreda — 4 months ago

I am not afraid of a CLI, but I'm barely a Linux amateur. Been trying to do updates on our Ubuntu 22.04.5 system and running into issues. Also noticed our Site24x7 agent has not been checking in - showing down in their portal...even through everything is functional.

I used to just run
sudo apt update && sudo apt upgrade && sudo apt autoremove
and be on my way. Today that is not working at all. This is what I get:

Hit:1 https://repo.45drives.com/debian focal InRelease
Ign:2 http://ca.archive.ubuntu.com/ubuntu jammy InRelease
Ign:3 http://ca.archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:4 http://ca.archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:5 http://ca.archive.ubuntu.com/ubuntu jammy-security InRelease
Ign:2 http://ca.archive.ubuntu.com/ubuntu jammy InRelease
Ign:3 http://ca.archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:4 http://ca.archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:5 http://ca.archive.ubuntu.com/ubuntu jammy-security InRelease
Ign:2 http://ca.archive.ubuntu.com/ubuntu jammy InRelease
Ign:3 http://ca.archive.ubuntu.com/ubuntu jammy-updates InRelease
Ign:4 http://ca.archive.ubuntu.com/ubuntu jammy-backports InRelease
Ign:5 http://ca.archive.ubuntu.com/ubuntu jammy-security InRelease
Err:2 http://ca.archive.ubuntu.com/ubuntu jammy InRelease
Could not connect to ca.archive.ubuntu.com:80 (91.189.91.81), connection timed out Could not connect to ca.archive.ubuntu.com:80 (91.189.91.83), connection timed out Could not connect to ca.archive.ubuntu.com:80 (91.189.91.82), connection timed out
Err:3 http://ca.archive.ubuntu.com/ubuntu jammy-updates InRelease
Unable to connect to ca.archive.ubuntu.com:http:
Err:4 http://ca.archive.ubuntu.com/ubuntu jammy-backports InRelease
Unable to connect to ca.archive.ubuntu.com:http:
Err:5 http://ca.archive.ubuntu.com/ubuntu jammy-security InRelease
Unable to connect to ca.archive.ubuntu.com:http:
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done

87 packages can be upgraded. Run 'apt list --upgradable' to see them.

W: Failed to fetch http://ca.archive.ubuntu.com/ubuntu/dists/jammy/InRelease Could not connect to ca.archive.ubuntu.com:80 (91.189.91.81), connection timed out Could not connect to ca.archive.ubuntu.com:80 (91.189.91.83), connection timed out Could not connect to ca.archive.ubuntu.com:80 (91.189.91.82), connection timed out

Seeing what I might be able to do to get the updates working properly again. Or if there is maybe something going on with Ubuntu. I am located in the US (West coast) so not sure why I would be using the CA archive....but not sure how to change that.

Appreciate any points in the right direction!

EDIT - I'm good now. Used apt-mirror-updater and got a new mirror. Was able to update. Thanks all!

reddit.com
u/Mvalpreda — 4 months ago