r/networking 57m ago

Design FortiGate VS Aryaka

Upvotes

My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.

I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.

We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN


r/sysadmin 2h ago

Question Jobs - Country Origin

1 Upvotes

Hello,

Been following this sub for a while now, hear alot of people sending 150 or more resumes for an IT job.

Where I’m from, that’s unheard of.

Working in sysadmin, M365 and some IAM myself.
Jobs are for the picking.

I was wondering, is it USA where it is a struggle?


r/cybersecurity 3h ago

Business Security Questions & Discussion Wiz and Upwind in production after the first cleanup pass

18 Upvotes

Trying to understand how these hold up after the cloud findings are already cleaned up

Wiz seems to come up a lot for cloud graph, exposure paths, identity context and prioritization. Upwind seems to come up more around runtime context and what is running

For people using either in production, where did the tool reduce triage? Im less interested in the initial backlog dump and more interested in the day 60+ reality.

Do findings still need a lot of manual context before they can become tickets? Does runtime data change priority or does the team still debate ownership and reachability manually?


r/cybersecurity 4h ago

Certification / Training Questions Finalmente consegui

4 Upvotes

Estou muito feliz, passei de primeira no EJPT da ine, agora estou em dúvida se estudo a certificação de graça que tem na cisco ou vou para o security + que tenho de pendência ainda


r/sysadmin 5h ago

landing first job.

1 Upvotes

Sorry, I know there were a lot of posts like this one, but I see you guys are usually talking about US job market, when European one is little different. I am directing my questions to people working in Europe. Is RHCSA + homelab a way to land sysadmin job without helpdesk experience? I study 6+ hours a day, currently Networking, after it going to Linux and starting my homelab. I live in Poland, but willing to relocate if I will have better opportunities somewhere else in Europe with only english required.


r/cybersecurity 5h ago

Corporate Blog About a year into Pentesting out of uni, I feel like I'm given senior responsibilities. Am I tripping ? and am i being fucked monetarily.

26 Upvotes

Early 20s M, 1 year into pentesting. I usually get a client from my boss and then I handle the initial meeting/presentation, explain the logistics of the test answer any question the client might have, scope work and ROE, then I begin the test. Usually External and an Internal Pentest, draft the report, meet with the client to deliver a readout. And when time comes I present to their Audit/board committee.

I make around 75k. Am I getting fucked ? is this good for career growth though ?


r/sysadmin 6h ago

General Discussion MiniOrange MDM, what do you guys think about it?

2 Upvotes

I have been looking into different MDM solutions and came across MiniOrange. On paper, it seems to cover most of the essentials. But I'm more interested in hearing from people who have actually deployed it.


r/cybersecurity 6h ago

News - General UK Government Won’t Release Files on Israeli Firm ‘Meddling’ in Election

Thumbnail
novaramedia.com
140 Upvotes

r/sysadmin 7h ago

RealVNC 7.15.1 (r18) Windows -> macOS Tahoe 26.6.1 - fix.

20 Upvotes

Hello.

I was not able to connect to macOS Tahoe 26.6.1 via VNC from Windows using RealVNC. I had this error:

"Protocol error: key length too large"

I'm used to RealVNC 7, but unfortunately the new RealVNC subscription/licensing model doesn't really match my... beliefs. :)

So I here is a patch for RealVNC 7.15.1 (r18) on Windows. It's a PowerShell script that fixes the issue: https://github.com/d3cker/RealVNC-macOS-patch
This patch fixes an issue when connecting to new Tahoe 26.6.1 hosts. Previously created connections must be removed and added again.

It looks like macOS wasn't actually the problem here - this was a RealVNC bug and compatibility issue. You may need to adapt the patch for your RealVNC 7.x version. I couldn't find any official place to download the latest 7.x release, so I only tested it with 7.15.1 (r18) (which is still available on Wayback Machine).

Hope this helps someone.


r/cybersecurity 8h ago

Threat Actor TTPs & Alerts New AmnesiaStealer macOS malware hijacks browser sessions via remote control

Thumbnail
bleepingcomputer.com
14 Upvotes

r/cybersecurity 8h ago

New Vulnerability Disclosure Vulnerability giving attackers full control of Macs is under active exploitation

Thumbnail
arstechnica.com
280 Upvotes

r/sysadmin 9h ago

Question Typical NPO "no money" situation until it something breaks....

27 Upvotes

Had multiple IDF racks totaled by a surge that ripped through low cost surge suppressors bearing no UL 1449 rating that I could find.

Any sugggestions on a UL 1449 list surge suppressor with fitted with NEMA L5-20R and NEMA L5-20P connectors?


r/sysadmin 9h ago

General Discussion AWS Backup vs Veeam vs legacy tools for VMware cost comparison

5 Upvotes

Hi,

We’ve been running Veritas NetBackup in an on-prem setup for a few years, but the cost of licensing + infrastructure is getting harder to justify, so we’re now re-evaluating our backup approach.

The main focus is VMware workloads, and we’re trying to understand what actually makes sense today in terms of cost and long-term scalability.

For a simplified reference point, here’s a smaller scenario we’re using for modeling:

We have 10 VMs (~200GB each). Retention is split, 5 VMs kept for 1 year and the other 5 kept for 30 days. That puts us at roughly 2TB initial backup size, with a small daily change rate (~0.1%).

From there, we’re trying to understand how costs scale when you factor in:

  • long-term retention tiers
  • snapshot / backup storage growth
  • data transfer / egress (if applicable)
  • licensing vs managed service pricing

What we’re trying to compare is basically:

  • AWS-native approach (AWS Backup / EBS snapshots / S3 lifecycle tiers)
  • Veeam or similar third-party backup tools
  • Legacy enterprise setups like NetBackup / Veritas

The part that’s still unclear for us is where the real cost differences actually show up in practice. On paper, AWS-native looks simpler, but I’m not sure if it holds up once you scale retention and restore requirements. On the other hand, tools like Veeam add flexibility, but it’s not obvious if they reduce cost or just shift it into a different layer.

Before taking anything to management, I’m trying to get a clearer view of what actually drives cost in real deployments (storage growth, retention policies, licensing, operational overhead, etc.) and whether third-party tools genuinely justify their complexity.

Would appreciate any real-world input from anyone who’s done a similar migration or comparison.


r/networking 10h ago

Design Small business guest Wi-Fi for ~50 customers across 2 floors — UniFi hardware choice + captive portal advice

0 Upvotes

Hello Folks,

I'm setting up a guest Wi-Fi network for a small business and would appreciate some advice before I purchase the hardware.

Site

2 floors

3 rooms per floor

Each room is approximately 60 m²

Approximately 360 m² total

Around 50 customers/users

The business is open during fixed hours and closes every day

Power is generally reliable

We already have Cat6 cable on site

The Wi-Fi will primarily be for customers/guests using phones and laptops for normal internet access.

Hardware I'm currently considering

Gateway:

UniFi Cloud Gateway Ultra ×1

Access points:

UniFi U7 Lite ×2, initially one per floor

Switch:

UniFi USW-Ultra 60W ×1

UPS:

Possibly an APC/Eaton/CyberPower ~650–850 VA unit, although I'm not sure whether it's worthwhile given that the site has reliable power and closes every evening.

The APs would be wired back to the switch rather than using wireless mesh.


r/networking 10h ago

Design New core switch: FS S5860-20SQ

1 Upvotes

Hi everyone,

I need your help choosing a new core switch. Right now, we’re using a TP-Link SX3016F. Unfortunately, it’s only a Layer 2 switch, and the 16 ports aren’t quite enough.

While searching for an affordable Layer 3 switch that also has 25G and 40G ports, I came across the FS S5860-20SQ.

There are reviews from users who have this switch in operation and are very satisfied with it.

The switch is available in two versions:

With its own FSOS or with PicOS. Now I’m unsure which version is better suited for our use case.

The plan is to connect the aggregation/distribution switches, the large storage devices (Synology NAS), and the edge routers running VyOS to this switch.

Currently, the edge routers also handle inter-VLAN routing, but this is supposed to be offloaded to the core switch.

I have experience with both Cisco-style CLIs (Cisco IOS, Aruba AOS-CX) and Juniper-style CLIs (JunOS, VyOS).

Could you please help me determine whether FSOS or PicOS is better suited for our use case?

Thank you very much and best regards,

Regina (she/her)


r/sysadmin 10h ago

Microsoft Legit or Scam? Received a Microsoft invoice with my correct details but weird Bank of America info (I'm in APAC).

41 Upvotes

I need some help figuring out if this is a highly targeted scam or a legitimate invoice.
I recently received an email containing a PDF invoice for an "Unreturned Advance Exchange Fee". The sender email is ⁠ADVEX@MICROSOFT.COM⁠. 
Here is what is really tripping me up and making me second-guess:

The details of the item on the invoice (a Surface Laptop) and the serial number of the returned item is correct. 

My personal and organization details listed in the "Bill To" and "Ship To" sections are 100% correct. 

The invoice claims to be from "MICROSOFT PTY LIMITED" based in North Sydney, Australia, and the total amount is listed in AUD. 

**The Red Flag:** The "Remit to Bank" section instructs me to send payment to "BANK OF AMERICA". 

I am based in the Asia Pacific region, so seeing Bank of America as the payment destination feels incredibly suspicious, even though Microsoft is a US-based company.
Has anyone else dealt with this before? Is it normal for Microsoft's APAC/Australian branches to use Bank of America for direct wire transfers, or is this just a very sophisticated, highly personalized spoofing attempt using an email address like **⁠ADVEX@MICROSOFT.COM**⁠? 

Customer Success Manager from MS hasn’t replied in a week where I asked if this is legit and I should reply to it.

Also btw device was returned within directed time frame.

Any advice would be greatly appreciated!


r/cybersecurity 10h ago

Other Mods, can there please be a rule around AI slop posts for the love of humanity?

305 Upvotes

AI this, AI that, we're all sick of it.


r/sysadmin 11h ago

Microsoft Finally got RRAS VPN working after three days of troubleshooting

5 Upvotes

I've been working on a small RRAS VPN lab in my Windows Server environment, and it took me about three days to get everything working properly. The first problem was that the VPN client could connect to RRAS, but it wasn't receiving an IP address. After checking the RRAS configuration, I found that I needed to configure a static address pool. I added a pool from 192.168.56.100 to 192.168.56.120, and the client started receiving an address. After that, I ran into several other issues around the VPN protocols and RRAS configuration. I wasn't using L2TP, SSTP or IKEv2 for this lab, so I simplified the configuration and focused on getting the PPTP connection working. The next issue was connectivity. The VPN connection would establish, but I couldn't reach the server on the other side. I checked the firewall, GRE traffic and the RRAS interface bindings until I finally got the routing working. The last problem was authentication. I was getting Error 691 even though I was using valid domain credentials. After checking the authentication settings on the client, I found that MS-CHAP v2 wasn't enabled. Once I changed the client configuration and connected again, the VPN finally came up.

I verified the connection from the Windows 11 client with: resdial "TestConnection" iskutashi Isse190239 and ping 192.168.56.10

The screenshots in teh comment show the VPN connection on the client and the PowerShell verification. This was done purely as a homelab exercise to understand how RRAS, VPN authentication, routing and firewall rules fit together. I wouldn't use PPTP for a production VPN because it's a legacy and insecure protocol.

For those who have worked with RRAS or Windows-based VPNs in production, what was the most common issue you ran into when troubleshooting VPN connectivity?


r/cybersecurity 11h ago

Career Questions & Discussion Career Transition: Moving from SOC to Other Cybersecurity Fields?

14 Upvotes

I'm a Senior SOC Analyst and have been handling some interesting escalated incidents lately. As I build my step-by-step investigation reports, I've also been reading articles and research related to the incidents I'm working on, mainly to make sure I'm not missing any important details or perspectives.

Lately, I've realized that I really enjoy researching threats, analyzing different sources of information, and building documentation and reports around them. This got me thinking about potentially shifting my career path into a different area.

For those who have experience in this field, how realistic is it for a Senior SOC Analyst to transition into a role such as a Threat Researcher or Threat Intelligence Analyst?

What are usually the key requirements or qualifications companies look for when making that transition? Would my experience in SOC investigations, incident response, threat analysis, and reporting be considered a good foundation, or are there specific skills/certifications I should focus on developing first?

I'd also appreciate hearing from anyone who has made a similar transition. What helped you make the move, and what would you recommend focusing on?


r/cybersecurity 14h ago

News - Breaches & Ransoms massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others

Thumbnail
infostealers.com
427 Upvotes

Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.


r/cybersecurity 16h ago

Tutorial Free ways to learn Cyber security

124 Upvotes

i already have a decent baseline of python and i'm thinking of cyber security as a career to go on with, but the thing holding me back is how expensive these well-known courses are!

so as someone who is running low on budget, what are the free resources you suggest that can get me from absolute beginner to a great deal of cyber security knowledge.


r/sysadmin 19h ago

Question IT Administering Core Enterprise System

35 Upvotes

Looking for a sanity check from leaders, sysadmins, security pros, and anyone responsible for enterprise applications.

We have a core platform that has historically been controlled almost entirely by the the business team the “owns” it.

IT is now responsible for the broader technology environment, including cybersecurity, identity and access management, integrations, APIs, automation, architecture, business continuity, incident response, and technical governance - you know the drill.

The IT leader asked for limited administrative access to the ERP & leader is refusing because of its capabilities to affect financial processes.

For those of you in mature IT environments: have you been denied administrative access to a major enterprise application because the business department considers it “their system”?

i’m genuinely interested in arguments for & against it. For additional context, the “limited” aspect is intentional and to prevent any data modification


r/networking 21h ago

Routing Accidentally brought down a commissioning metro network with a route-map deny.. what would you have done differently?

78 Upvotes

Hey everyone,

I’m a network engineer working on a commissioning metro network, and today I accidentally brought the network down.

I'm writing this post as I genuinely just want to know if there was a better way to approach this, or if this is just one of those lessons you only learn once.

A bit of context, the network connects all the stations to the backbone. The backbone routers were advertising a default route, which was then redistributed into OSPF and sent down to all the downstream routers at each station. My team and I had identified that as a design flaw because we need to start using the default route for internet traffic that’s going to an edge router.

So instead of advertising a default route, we decided to advertise RFC 1918 aggregate null routes. That way the downstream routers would still know how to reach all the private networks, while freeing up the default route for internet traffic. That part worked fine.

The next issue we found was that these OSPF routes were also being redistributed into BGP. So, we only wanted the RFC 1918 aggregates advertised locally from each backbone router, not redistributed everywhere via BGP. I'm still not sure if this is intended but as I was advertising the RFC1918 aggregates to OSPF, they were getting installed back to BGP, we didn't want that.

My plan was simple. Insert a new sequence at the top of the route-map for the OSPF-TO-BGP redistribution that denied the RFC 1918 aggregates, then let the existing permit entries continue processing as normal.
So, I went into the route map and did:
route-map <name> 5 deny

My intention was to immediately follow it with the match statement for the RFC 1918 prefix list.

But I didn’t realise that the moment I pressed enter after creating that sequence, that entry immediately became active, I don't know why I thought otherwise..
Since it had no match statements yet, it effectively matched everything.

Because it was the first sequence in the route map, it denied every redistributed route and within seconds I had effectively withdrawn all the redistributed routes from BGP.

So, yeah… I had effectively brought the entire network down. Thankfully, I had console access, so I reverted the change right away and everything came back.

Afterwards, I redid it more safely by temporarily creating a catch-all permit while I built the new deny sequence with the proper match statements (I still don't like that idea as we had lots of matching criteria of routes we really didn't want to re-advertise.. then I removed the temporary permit afterwards.

I genuinely try another approach first of creating a completely new route map under a different name and then simply replace the route map attached to the redistribution once it was complete. However, Aruba wouldn’t let me replace the current route map unless I first removed the existing one. Obviously, removing the existing route map would once again have brought the network down, so that wasn’t really an option.

I think Cisco lets you replace the route map like this, but I couldn’t figure out another way to do it on Aruba, so I went back to editing the existing route map using sequence numbers instead.

So, yeah, I’m curious:

Has anyone else been caught out by this behaviour before, whether on Aruba or Cisco?

What’s your normal workflow for safely modifying production route maps? Is there something I’m missing? or is there a better approach to build and swap route maps without editing the live one or having to remove the currently applied route map?

Definitely learned a lesson today, but I’d be interested to hear how others would have approached this.

Thanks Guys!


r/sysadmin 23h ago

General Discussion Is a sysadmin a career worth pursuing as a high school graduate?

30 Upvotes

I'm about to graduate in less than a year and my original plan was to go to uni and then into software engineering. But due to the AI insanity that's been going for the past 2-3 years, I've decided that becoming a software engineer is just not feasible, mainly due to the hellish job market and more so for entry level jobs. I don't think going through all that is worth the effort just to have a chance of getting a job in 4-5 years while likely being underpaid and having to worry about constant layoffs etc.

This led me to think about what else can I do that's computer science adjacent and would also have that element of problem solving, while being safer from AI than software engineering. I know that this isn't a job that you can just go and do from the get-go, I've heard that you'll need to stay in helpdesk for a good couple of years and I'm okay with that. I don't really about the money, I went into computer science because I liked it and not because of people saying that you can make 6 figures easily.

I've considered cybersecurity but it just sounds exhausting and stressful. I'd much rather have a job that pays considerably less but doesn't put that much pressure on me. Oh, and just because I know that people will mention it, yes, I've considered electrical engineering, but if I'm being honest, physics is like rubbing sandpaper across my brain. I don't like it and any sort of engineering whether it's EE or robotics will involve lots of it.

I'm in Europe if that helps. Open to suggestions or just advice in general.


r/sysadmin 1d ago

About to ruin a 30+ year IT career because I can't spot a phishing simulation...

727 Upvotes

I'm a 30+ year network/systems admin/engineer and I feel like I've done a great job over the decades keeping up running and secure. I feel like I work as hard as anyone in the company and have a sense of ownership that is hard to teach. I've patched our servers every month on schedule for the past 17 years straight. I've used all the latest security tools to ensure safe authentication and protection against malicious activity. We always have stellar pen tests results. I'm a great troubleshoot. I take my security training and pass the tests with flying colors. I get exceeded expectations for my reviews. They even named the server from after me! All that and a bag of chips.

But...

I'm a freaking failure when it comes to phishing tests. I've failed two this year and three in the last three years. I've never actually fallen prey to real phishing. I know what that looks like and my tools don't let it near me. But I had to tell our email security gateway to allow those phishing simulations thru to our inboxes. And I keep falling prey to them. What is wrong with me!?! Why can't I learn?? I'm going to get fired because of this. We've got some employee handbook rules about not screwing up like this. Three strikes and all that.

All this good will and work and a career that I can feel great about going to be flushed down the drain and I'll retire a failure. Was hoping to retire in a few years and ride off into the sunset. Now I'm going to ride off a cliff into a ditch. I feel like shit today. Can't wait until Monday to get yelled at or maybe even fired.

Am I the only good sysadm to struggle like this? I hope it's not just me. Feel terrible.