Main Menu

Recent posts

#1
Security / Re: RADIUS CoA
Last post by deanwebb - Yesterday at 06:35:04 PM
Yes, and most Windows won't notice the change without an agent. This is why agentless solutions have to hard-bounce the port to get the device to request a new IP address. Any dot1x solution works so much better with agents that replace the Windows supplicant.

I have evil things to say about Windows supplicants, if you would like to hear them...
#2
Security / Re: RADIUS CoA
Last post by config t - April 03, 2025, 12:04:46 PM
To answer my own question:

It depends on the equipment string. In this case a voip handset in-line with the PC was causing a failure to detect the network change so it wouldn't initiate DHCP. The answer for this scenario was installing the NAC agent.
#3
Security / RADIUS CoA
Last post by config t - April 03, 2025, 11:29:47 AM
When I impose a RADIUS CoA on a Windows box to maneuver it to an isolation VLAN should it detect the network change and DORA automatically? It seems as if it is failing to initiate DHCP unless the port is bounced.
#4
Forum Lobby / Re: Almost Famous
Last post by deanwebb - March 12, 2025, 03:51:39 PM
The more you do post-incident, the better your prep for the next one in terms of minimizing impact.
#5
Forum Lobby / Re: Almost Famous
Last post by Otanx - March 12, 2025, 09:06:37 AM
Welcome to the club. Not one you really want to be in, but it happens. I have not had to do a DDoS incident response yet, but have done a few incident response to other things that have made the news. I remember my first was in a medium sized town, company hit over the weekend. We got sent out and got to town late Monday. In the morning doing the hotel breakfast I see the company on the morning news. They were one of if not the largest employer in the town, and had sent everyone home Monday and didn't expect to recall anyone Tuesday.

If you haven't already document everything you remember. Especially anything you did to try to handle the incident if it worked or not. One is for identifying anything weird that shows up in the next few weeks from changes made during the incident. Two is for the next time it happens.

-Otanx


#6
Forum Lobby / Re: Almost Famous
Last post by deanwebb - March 11, 2025, 06:21:47 PM
Ooof, no, I missed that news, I was taking some easy time, recovering from a cold.
#7
Forum Lobby / Almost Famous
Last post by icecream-guy - March 08, 2025, 06:16:18 AM
Did you all see the NIH DDoS attack in the news from last weekend? It was a big deal, and happened on my watch.  I spent 25 hours between Sat/Sun battling that crap.
#8
Forum Lobby / Re: Concerned about BIG corpor...
Last post by deanwebb - February 19, 2025, 07:44:19 AM
Yeah, best to not run the EXE in case the forums are taken over by shill accounts. There's nothing really looking hard at AI development processes, so they are prime targets for supply chain attacks.
#9
Forum Lobby / Concerned about BIG corporate ...
Last post by icecream-guy - February 15, 2025, 01:00:25 PM
My brother turned me on to brighteon.ai, its a AI that is trying to preserve the "old ways" of doing and knowledge quote from the site it's a "set of critical human knowledge about food, nutrition, farming, permaculture, herbs, indigenous medicine, alternative medicine, off-grid survival, sustainability and other critical knowledge areas that have kept human civilization alive."

most interesting database of knowledge, Personally I couldn't get the self extracting .exe to run, so I downloaded the .gguf file and have successfully launched the .gguf in Ollma for windows 64bit. I Tried LM Studio, but my Norton AV said there was a virus in the LMstudio.exe, forums said it was a false alert, but I didn't want to take a chance.
#10
Routing and Switching / Re: IPv6 OSPv3 routing authent...
Last post by Otanx - February 07, 2025, 12:52:39 PM
I don't have an ASA anymore so I can't test, but I found this in the configuration guide. It looks pretty straight forward, but we all know how that goes.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa922/configuration/general/asa-922-general-config/route-ospf.html

-Otanx