holzman_tweed: (Default)
[personal profile] holzman_tweed
Dear Systems Administrator,

Please understand that IP addresses in an Internet-facing DMZ are not merely convenient placeholders for the interface to make the Winbloze dialog close, they actually mean something. If you assign IP addresses from a space that belongs to me, particularly without understanding why I've subnetted the Class C you're playing with in a certain way, you're likely to do something like give a machine an address that implies the machine is behind firewall B when it's supposed to be firewall A.

This can get confusing when we're trying to deploy your server benind firewall B.

So pretty please with sugar on top. Ask me for a fucking IP address.

(no subject)

Date: 2003-08-29 01:03 pm (UTC)
From: [identity profile] marnanel.livejournal.com
I had a job once where the new sysadmin installed DHCP one day, and blithely gave away the static rfc1918 address I'd been assigned for my desktop machine (and had been using for the past two years) to some random laptop. I didn't get much work done that day. Most of it was spent tracking down the new sysadmin and explaining his job to him :(

(no subject)

Date: 2003-08-29 06:46 pm (UTC)
From: [identity profile] docstrange.livejournal.com
Ick. But then, there's: When deploying a new host, don't take a box that has been off and idle for a year, put the two latest patches on it, deploy it in place of another host you've secretly retired on the public-facing DMZ, and act surprised when it gets backdoored through a WebDAV hole using KaHT two hours later.

Then don't be surprised when you're asked to send the drive to corporate HQ so forensics can figure out how many other hosts your lazy action may have compromised.

(no subject)

Date: 2003-08-29 07:42 pm (UTC)
From: [identity profile] holzman.livejournal.com
Five years ago, I never would have dreamed that Systems Administrators would be the bane of my existence.

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags