catsmate
No longer the 1
- Joined
- Apr 9, 2007
- Messages
- 34,783
Non-System disk or disk errorThat's what I said. You would not have gotten a prompt without someone leaving a boot floppy in it.![]()
Replace and press any key when ready.
Non-System disk or disk errorThat's what I said. You would not have gotten a prompt without someone leaving a boot floppy in it.![]()
Boot on LAN. That'll wake the up.Admin: I'm trying to remotely remove your software from 10 of our machines.
Me: What error are you getting?
Admin: None.
Me: Please describe what you're doing, what you expect, and what happens instead.
Admin: The 10 machines are powered down. They don't respond.
Me: You cannot remotely access a powered-down machine. It's not running.
Admin: But...
Me: No.
True, but for security reasons, this is usually disabled by "wise" PC configurationers.Boot on LAN. That'll wake it up.
Most corporates I've worked in use it as standard. It's quite possible to secure it.True, but for security reasons, this is usually disabled by "wise" PC configurationers.
Admin: I'm trying to remotely remove your software from 10 of our machines.
Me: What error are you getting?
Admin: None.
Me: Please describe what you're doing, what you expect, and what happens instead.
Admin: The 10 machines are powered down. They don't respond.
Me: You cannot remotely access a powered-down machine. It's not running.
Admin: But...
Me: No.
Boot on LAN. That'll wake the up.
True, but for security reasons, this is usually disabled by "wise" PC configurationers.
Most corporates I've worked in use it as standard. It's quite possible to secure it.
A lot of people were baffled by Windows at first, it's really not obvious how to use it when you were seeing it for the first time. Doubly so if no one had told you about double clicking.
I was absolutely convinced that Windows was just a fad and that nobody would like giving up their command lines.
I was absolutely convinced that Windows was just a fad and that nobody would like giving up their command lines.
No one who matters gave up their command lines.
That is indeed what you have to do to secure boot-on-LAN. But in locations like hospitals and universities which are fairly open to the public and even staff bringing their own gear (not to mention various departments building their own shadow IT operations), boot-on-LAN can be a gateway to unwitting drone and zombie machines, and also undesirable packet-sniffers which are security hazards.Catsmate beat me to it.
Computers sold for corporations generally come with some ILO software on the motherboard, that provides for remote access to the system, including power on/off and even sometimes access to the OS. They can also monitor hardware and firmware to provide for notices of updates, hardware problems, and similar things. We have the system in place at my business.
These are heavily restricted, password protected, encrypted, use certificate security to verify remote access, and run on a segregated, private network with limited access (only certain users/locations can get on that network, and it's not connected to any external network).
Same type of thing for servers, too.
No one who matters gave up their command lines.
Actually, it's making a big comeback in Windows administration. While batch files and command line has always remained in use, PowerShell is really bringing it back.
Pretty much, if it can be done on Windows, I can automate it via PowerShell. And usually in less than 10 lines of code
I have several automated tasks to generate various reports on all my assigned servers, perform reboots of groups of systems when necessary, collect software inventories, all sorts of stuff. Usually takes about 15 to 30 minutes to write (including look up syntax) and saves hours.
That is indeed what you have to do to secure boot-on-LAN. But in locations like hospitals and universities which are fairly open to the public and even staff bringing their own gear (not to mention various departments building their own shadow IT operations), boot-on-LAN can be a gateway to unwitting drone and zombie machines, and also undesirable packet-sniffers which are security hazards.
So it's very nice to have boot-on-LAN capability (in the past I used it to quickly bulk-reset classrooms full of training PCs and servers). But if you don't know who is going to do the booting and what they are booting or where it is then it is a problem
ETA: Not that I'm saying no iLO. We use real iLO all the time for servers, on a highly secure network.![]()
It really is good. I'd been waiting for ages for the bank to extract the finger and get a SCOM upgrade that would allow me to replace lots of expensive vendor software with direct management custom made for our needs. That went sideways when they let the real SCOM experts go and kept the script kiddies.
It certainly does. So any publicly-connected device can be booted (and thus accessed) from...anywhere, really. And what is running on that device? What is it doing with my network? FIIK!Well, the iLO network is what has boot-on-LAN capability, and that's a separate network from the public one, with certificate-based access and encryption controls. SO even if someone just walked in and plugged up whatever, it's only going to be on the regular network, not the iLO network. If that makes sense![]()
I've never had an eye for programming. I can follow a script to use a command line but I've never got the hang of actually writing code. I love my GUI.Command lines are awesome, and so are GUIs.
It certainly does. So any publicly-connected device can be booted (and thus accessed) from...anywhere, really. And what is running on that device? What is it doing with my network? FIIK!
ETA: Started life as a programmer decades ago, so I have no idea how many millions of lines of code I've written since then. Including all sorts of scripts on a variety of platforms.
I'm actually one of the few IT people I know that thinks the current balance of GUI for most all user interface function and GUI/Command Line for most system admin functions have actually struck a pretty fair balance.
I cut my teeth on commands lines but I don't want to go back to them for everything.
I completely agree. Those with the chops can do amazing things with a command line. For most functions, the GUI serves the rest of us extremely well.I'm actually one of the few IT people I know that thinks the current balance of GUI for most all user interface function and GUI/Command Line for most system admin functions have actually struck a pretty fair balance.
I cut my teeth on commands lines but I don't want to go back to them for everything.