Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # GOLINE SA: The idea behind GOLINE’s activity is to support the growth of modern, innovative companies whose focus is on the talents that can make a difference in devising the most appropriate solutions. We specialise in the creation of software for the logistic platforms used within the distribution chain of fresh products. ## Sitemaps [XML Sitemap](https://www.goline.ch/sitemap_index.xml): Includes all crawlable and indexable pages. ## Pages - [RoutePulse — NOC Wallboard](https://www.goline.ch/routepulse/routepulse-wallboard/): Back to RoutePulse Overview - [RoutePulse — NIS2 / DORA / AI-Act Compliance Dossier + WORM Audit Chain](https://www.goline.ch/routepulse/routepulse-compliance/): Back to RoutePulse Overview - [RoutePulse — CAD Compositional Anomaly Detector (90% noise reduction)](https://www.goline.ch/routepulse/routepulse-cad-anomalies/): Back to RoutePulse Overview - [RoutePulse — Incident Hub & 47 MITRE ATT&CK Playbooks](https://www.goline.ch/routepulse/routepulse-incidents/): Back to RoutePulse Overview - [RoutePulse — LoA Generator & Public QR-Scannable Verifier](https://www.goline.ch/routepulse/routepulse-loa-verifier/): Back to RoutePulse Overview - [RoutePulse — Settings & Configuration](https://www.goline.ch/routepulse/routepulse-settings/): Most SOC + NOC platforms ask you to edit YAML and SIGHUP a daemon — or worse, redeploy — for every threshold tweak. RoutePulse exposes **44 settings sub-pages** under `src/app/settings/` with over 130 configurable parameters, every one of them hot-reloaded into the running process. - [RoutePulse — ML Brain — 18-Model Machine Learning Pipeline](https://www.goline.ch/routepulse/routepulse-ml-brain/): Back to RoutePulse Overview - [RoutePulse — Peering Analytics & Session Monitoring](https://www.goline.ch/routepulse/routepulse-peering/): Back to RoutePulse Overview - [RoutePulse — RPKI Validation & ROA Coverage](https://www.goline.ch/routepulse/routepulse-rpki/): Route origin validation is no longer a nice-to-have. Major Tier-1 transit providers now drop RPKI-invalid prefixes by default, MANRS auditors require coverage scorecards, and route leaks remain the single most common cause of large-scale outages. - [RoutePulse — Autonomous System Explorer](https://www.goline.ch/routepulse/routepulse-as-explorer/): Back to RoutePulse Overview - [RoutePulse — Host Intelligence & Unified Threat Scoring](https://www.goline.ch/routepulse/routepulse-hosts/): Back to RoutePulse Overview - [RoutePulse — Capacity Planning & Bandwidth Forecasting](https://www.goline.ch/routepulse/routepulse-capacity/): Capacity Planning answers the only two questions transit procurement actually cares about: "what will my P95 be next quarter?" and "will I exceed my committed data rate before then?". - [RoutePulse — Infrastructure Map & Network Topology](https://www.goline.ch/routepulse/routepulse-map/): The Infrastructure Map answers two completely different questions on one screen. Where is the network physically — datacentres, IXP halls, transit POPs, cross-connect terminations? And how is the network topologically — which AS connects to which, via which provider, with what relationship (customer / peer / provider) and what backup path? The geog - [RoutePulse — Firewall & Network Edge Defense](https://www.goline.ch/routepulse/routepulse-firewall/): Policy zone and Virtual IP (VIP) context surfaces directly on every event row. SSH configuration scanning enables firewall rule auditing for policy compliance verification alongside operational monitoring. SD-WAN tunnel detection leverages FortiGate comment patterns with address-object resolution for accurate mapping. - [RoutePulse — Real-Time Flow Analyzer](https://www.goline.ch/routepulse/routepulse-flow-analyzer/): The Flow Analyzer is RoutePulse's ad-hoc investigation tool — Wireshark ergonomics applied to network-wide flow telemetry, not a packet capture on one wire. - [RoutePulse — Security Events & Alert Management](https://www.goline.ch/routepulse/routepulse-security-events/): Back to RoutePulse Overview - [RoutePulse — Traffic Analysis & Protocol Breakdown](https://www.goline.ch/routepulse/routepulse-traffic/): Traffic Analysis is the analytical backbone of RoutePulse — every flow record from every sFlow agent, every IPFIX template, every NetFlow v9 packet lands in a ClickHouse columnar store now running 44 tables (35 base + 9 materialized views) with 1.6 billion+ rows retained. - [RoutePulse — External BGP Visibility (DFZ Monitoring)](https://www.goline.ch/routepulse/routepulse-external-visibility/): Back to RoutePulse Overview - [RoutePulse — Unified Threat Intelligence Dashboard](https://www.goline.ch/routepulse/routepulse-cybersecurity/): SOC teams typically juggle four consoles: one for ML detections, one for threat feeds, one for SIEM, one for mitigation. RoutePulse's Unified Threat Intelligence Dashboard collapses them into a single 5-tab interface backed by Conviction Engine v2 (SPRT + Thompson Sampling + Conformal Prediction) and the Role Catalog (v4. - [RoutePulse — Transit Cost & Concentration Analysis](https://www.goline.ch/routepulse/routepulse-transit-costs/): Eight KPI cards: total monthly cost, blended cost-per-Mbps, CDR utilisation, burst overage spend, transit-vs-peering split, top provider by spend, top provider by Mbps, and the HHI concentration score itself. Per-provider rates are configured once (Mbps tiered, flat or stepped) in transit-cost-service. - [RoutePulse — Traffic Sankey Flow Visualization](https://www.goline.ch/routepulse/routepulse-sankey/): A traffic map that shows you 14 days of mean throughput as a bar chart is a coroner's report. The Sankey view is an X-ray: where does traffic enter, which AS-path does it traverse, which role-class of host does it land on, and how is the volume distributed across that topology *right now*. - [RoutePulse — BGP Anomaly Detection Engine](https://www.goline.ch/routepulse/routepulse-anomalies/): Back to RoutePulse Overview - [RoutePulse — AI Insights — Autonomous Network Intelligence Engine](https://www.goline.ch/routepulse/routepulse-ai-insights/): SOC teams drown in alerts because every detector hands them rows, not stories. ANIE — the Autonomous Network Intelligence Engine — turns every critical detection into a written forensic report with MITRE ATT&CK citations, evidence trail, and an explicit verdict (ESCALATE / MONITOR / DISMISS). - [RoutePulse — IRR Compliance Audit](https://www.goline.ch/routepulse/routepulse-irr-audit/): Back to RoutePulse Overview - [RoutePulse — AI-Powered Threat Mitigation & Blackholing](https://www.goline.ch/routepulse/routepulse-mitigations/): Back to RoutePulse Overview - [RoutePulse — BGP Analytics & Security Intelligence](https://www.goline.ch/routepulse/): 34 production dashboards, US English audio walkthrough. BGP analytics, ML brain, threat map, NIS2/DORA/AI-Act compliance dossier — the whole platform end-to-end. - [News Archive](https://www.goline.ch/goline-sa-news-partnerships-company-updates/): Stay informed about the most recent developments at GOLINE SA, a leading Swiss business partner known for building strong partnerships and fostering corporate growth. Our news archive provides insights into strategic collaborations, ambassador programs, company milestones, and events that highlight our leadership and engagement in Switzerland. For the latest updates, don't miss out on GOLINE SA news. - [NetApp](https://www.goline.ch/solutions/netapp/): In today’s data‑driven world, businesses need more than just storage—they need a platform that delivers performance, scale, security and flexibility. NetApp offers an intelligent data infrastructure that spans cloud, hybrid and on‑premises environments, enabling organisations to unlock the full potential of their data. (Discover NetApp’s mission and technology) - [Omnissa](https://www.goline.ch/solutions/omnissa/): In the modern workplace, delivering applications and desktops securely, efficiently and everywhere is no longer optional — it’s mandatory. Omnissa’s digital workspace platform empowers organisations with unified endpoint management, virtual desktops, application delivery, and robust security across devices and clouds. Discover the platform - [Cloudflare](https://www.goline.ch/solutions/cloudflare/): In today’s fast-paced digital world, your website needs a platform that combines speed, security, and resilience. Cloudflare is one of the world’s largest networks built to protect, accelerate, and make websites and applications more reliable. (Discover our solutions) - [Wazuh](https://www.goline.ch/solutions/wazuh/): Wazuh is a robust open-source security platform that unifies Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) capabilities into a single architecture. Designed for scalability and flexibility, it delivers comprehensive protection for endpoints, cloud workloads, and on-premises data centers worldwide. - [EaseUS®](https://www.goline.ch/solutions/easeus/): EaseUS, established in 2004, is a leading technology company dedicated to providing innovative software solutions for data recovery, including MS SQL Recovery, backup, and disk management. With a global presence, EaseUS serves over 10 million users worldwide, including both individuals and businesses. - [FileCloud®](https://www.goline.ch/solutions/filecloud/): Zero Trust File Sharing® is a system of “least privilege” where users only have access to the data they absolutely need, including services like FileCloud. This permission must be actively enabled or allowed. Industry-first set of capabilities that enable a Zero Trust security posture for collaboration and file sharing, including solutions. - [AbuseIPDB](https://www.goline.ch/support/report-ip-address-abuse/): AbuseIPDB is a leading platform that enables individuals and organizations to report IP address abuse quickly and effectively. In a world increasingly threatened by malicious activity, AbuseIPDB plays a critical role in maintaining cybersecurity by creating a shared database of abusive IP addresses. - [Ubibot®](https://www.goline.ch/solutions/ubibot/): UbiBot® offers a revolutionary way to monitor environmental conditions. Sensors sync with the UbiBot® IoT Platform via WiFi for easy access to data from anywhere via smartphone or web. - [PowerDMARC](https://www.goline.ch/services/powerdmarc-goline-email-security/): PowerDMARC Goline: Easy and Powerful DMARC Reporting - [AOMEI](https://www.goline.ch/solutions/aomei/): GOLINE SA is an authorized reseller and Premium Partner of AOMEI, one of the most important "Data Insurance Company". AOMEI offers insurance for data by providing “data backup" products. Founded in 2010, AOMEI has been committed for 14 years to keeping users' data safe from loss, offering reliable data protection and data backup solutions. - [Xmas 2023](https://www.goline.ch/xmas2023/) - [Speedtest](https://www.goline.ch/support/speedtest/): Speedtest Measure Your Network Performance in Real Time - [Termini e Condizioni GOPRESENCE](https://www.goline.ch/termini-e-condizioni-gopresence/): Termini e Condizioni del servizio GOPRESENCE di GOLINE SA. - [Autonomous System (AS202032) – IP Transits – Live Traffic, 1 Hour](https://www.goline.ch/support/autonomous-system-as202032-ip-transits-live-traffic-1-hour/): Autonomous System AS202032 IP Transit Live Traffic One Hour Overview - [Autonomous System (AS202032) – IXP – Live Traffic, 1 Hour](https://www.goline.ch/support/autonomous-system-as202032-ixp-live-traffic-1-hour/): Autonomous System AS202032 IXP Live Traffic One Hour Overview - [AS202032 peering policy](https://www.goline.ch/as202032-peering-policy/): GOLINE owns and operates an independent IP network identified as AS202032, designed to enhance global connectivity. Through direct interconnections with multiple ISPs, NSPs, and CSPs, our infrastructure ensures robust, secure, and resilient traffic flow across regions. - [Software Development](https://www.goline.ch/services/software-development/): Software Development at GOLINE SA is never one-size-fits-all. Every project is unique, and our mission is to develop personalized software solutions that fully support our partners' goals—ensuring efficiency, innovation, and scalability. - [AS202032 – LIVE TRAFFIC, 1 HOUR](https://www.goline.ch/support/as202032-live-traffic-1-hour/): The AS202032 Live Traffic report provides a real-time snapshot of network activity for Autonomous System AS202032 over the past hour. This data includes detailed information about IP transit and Internet exchange point (IXP) traffic patterns, bandwidth usage, and connection quality. - [Opportunities](https://www.goline.ch/opportunities/): GOLINE SA is seeking talented Full Stack Developers to work on both frontend and backend development. This role offers opportunities to grow, innovate, and contribute to cutting-edge web applications. - [Self Application](https://www.goline.ch/self-application/): Understanding the self application process is crucial for a seamless experience. - [Index](https://www.goline.ch/): We don't just design networks — we operate them. GOLINE runs its own Autonomous System (AS202032) with peering at major Internet Exchange Points. We design, deploy, and manage enterprise LAN/WAN, virtualisation platforms, hosting environments, and provide 24/7 operations. - [About Us](https://www.goline.ch/about-us/) - [Contact Us](https://www.goline.ch/contact-us/) - [FAQ](https://www.goline.ch/faq/) - [Virtualization](https://www.goline.ch/system-architecture/virtualization/): A hypervisor is a form of virtualization software used in Cloud hosting to divide and allocate the resources on various pieces of hardware. The program which provides partitioning, isolation, or abstraction is called a virtualization hypervisor. - [Telephony](https://www.goline.ch/system-architecture/telephony/): Cisco IP Communications offers a secure, 360° solution at application level (call-processing, multimedia streams, convergent applications) as well as at physical and network level. Sophisticated mechanisms of Quality of Service (QoS) and intelligent content management ensure the best voice and visual quality even in wireless environments. - [Security](https://www.goline.ch/system-architecture/security/): GOLINE SA delivers enterprise-grade IT security services designed to protect your digital infrastructure from evolving threats. Our mission is to ensure availability, confidentiality, and integrity of your systems — empowering your business to operate safely and efficiently in a connected world. - [Networking Services](https://www.goline.ch/system-architecture/networking/): We constantly evaluate new technologies and solutions from leading vendors such as Cisco, Juniper, Aruba, HP, Sophos, Ubiquiti, and Barracuda—all of which have awarded us with technical certifications. This ensures that we recommend only the most reliable and future-ready networking solutions. - [Domotics](https://www.goline.ch/system-architecture/domotics/): The word domotics originates from the Latin “Domus” (home) and the Greek suffix “-tics,” referring to applied sciences. It defines the interdisciplinary field focused on technologies that enhance quality of life in residential and commercial environments. - [Microsoft Dynamics 365 Business Central](https://www.goline.ch/solutions/microsoft-dynamics-nav/): Looking for a comprehensive and adaptable ERP solution? Microsoft Dynamics NAV is the ideal business management software for small to medium-sized enterprises and subsidiaries that require flexibility, international support, and ease of use. - [GoFresh Suite](https://www.goline.ch/solutions/gofresh-suite/): GoFresh is a suite of tools designed to support the day-to-day activity of logistic platforms. The automated processes integrated with the active and the passive cycle of the ERP system replace the manual operation of entering data by the operator, thus saving time and reducing the likelihood of human error. - [B2B-B2C Integration](https://www.goline.ch/solutions/b2b-b2c-integration/): The digital transformation of business processes has enabled the automation of inter-company communications and simplified transactions between organizations and end consumers. This evolution supports both B2B-B2C exchanges by enhancing connectivity, speed, and efficiency. - [Axtel Headsets](https://www.goline.ch/solutions/axtel-headsets/): The Elite MS is a professional headset from the UC series, characterized by crystal-clear HD sound. The outstanding sound noise-cancelling, intuitiveUSB connection and Plug&Play functionality make business communication easy, taking it to a higherlevel. - [Traceability](https://www.goline.ch/services/traceability/): Traceability is essential for ensuring transparency and control throughout the life cycle of a product. It enables businesses to track and share information at every stage of the supply chain—from production and packaging to distribution and final delivery to the consumer. - [Process Analysis](https://www.goline.ch/services/process-analysis/): In today’s dynamic business environment, improving operational efficiency often requires structured interventions across logistics, organization, and resource allocation. This is where Process Analysis plays a vital role. It enables companies to critically assess their internal processes, identify inefficiencies, and implement targeted solutions. - [IT Forensic](https://www.goline.ch/services/investigation-cybercrime-electronic-evidence/): In today’s highly digitized world, the investigation of cybercrime and electronic evidence has become a cornerstone of cybersecurity. As cyber threats continue to grow in sophistication, organizations must rely on digital forensic specialists to analyze, document, and respond to incidents effectively. - [cPanel Hosting](https://www.goline.ch/services/cpanel-hosting-goline-sa/): When launching or managing a website, the choice of hosting is crucial—and cPanel remains one of the most efficient and accessible platforms available. At GOLINE SA, we deliver hosting services that offer power, security, and simplicity, whether you're a beginner or a professional. - [Day to Day IT Support](https://www.goline.ch/services/7-days-it-support-tips-for-business/): In today’s fast-paced digital world, uninterrupted IT support is not a luxury—it's a necessity. At GOLINE IT Services, we provide 7-day, 24/7 IT support to ensure your operations stay online, productive, and protected at all times. ## Posts - [GOLINE SA Announces Strategic Partnership with NetApp](https://www.goline.ch/2025/11/07/goline-netapp-partnership/): GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. - [GOLINE SA Announces Partnership with Omnissa](https://www.goline.ch/2025/11/07/goline-omnissa-partnership/): GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. - [GOLINE SA partners with Cloudflare](https://www.goline.ch/2025/11/06/goline-sa-partners-with-cloudflare/): Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. - [Paolo Caparrelli – Wazuh ambassador](https://www.goline.ch/2025/10/09/paolo-caparrelli-wazuh-ambassador/): Mission as Wazuh Ambassador: advancing open-source security adoption through innovation, knowledge sharing, and proving that world-class cyber defense can be built on transparency, collaboration, and intelligent automation. - [SharePoint CVE-2025-53770 (ToolShell) Incident Response Guide](https://www.goline.ch/2025/07/21/sharepoint-cve-2024-38094-toolshell-incident-response-guide/): This comprehensive guide details the detection, analysis, and remediation of SharePoint Server compromises through CVE-2025-53770, also known as "ToolShell". This critical vulnerability allows unauthenticated remote code execution and has been actively exploited in the wild since July 2025. - [Automated Node.js Memory Leak Mitigation on FortiGate 50G: A Technical Case Study](https://www.goline.ch/2025/06/05/automated-node-js-memory-leak-mitigation-on-fortigate-50g-a-technical-case-study/): This article documents a critical memory management issue discovered on the FortiGate 50G model where the Node.js process exhibits uncontrolled RAM allocation without proper garbage collection. - [Workaround to Replace SSL Certificate on Cisco FTDv via Cisco FMC](https://www.goline.ch/2025/05/07/workaround-to-replace-ssl-certificate-on-cisco-ftdv-via-cisco-fmc/): This guide provides a detailed, technical walkthrough for replacing the SSL certificate on a Cisco Firepower Threat Defense Virtual (FTDv) device, using Cisco Firepower Management Center (FMC). - [GOLINE SA partners with EaseUs](https://www.goline.ch/2025/03/13/goline-sa-new-partnership-easeus/): New Partnership Between Goline and EaseUS: Technology and Innovation at Your Service. - [QNAP: disable TLS v1.0 and v1.1 (HTTPS)](https://www.goline.ch/2025/01/29/qnap-disable-tls-v1-0-and-v1-1-https/): Applied models:All modelsApplied Firmware:All versions - [PowerVault Manager ME5024 – Custom Certificates Creation and Installation](https://www.goline.ch/2024/12/03/powervault-manager-me5024-custom-certificates-creation-and-installation/): The first step is to generate the CSR, which will be displayed on the screen and can be copied into the Certificate Authority (CA) to request the certificate.Note: Avoid using CTRL+C, as the terminal may log out. - [How to renewal local certificate embedded on Fortigate Firewall](https://www.goline.ch/2024/10/24/how-to-renewal-local-certificate-embedded-on-fortigate-firewall/): This guide shows how to renewal all expired certificates embedded in the hardware at the factory of Fortigate Firewall. - [MiniO and Prometheus on QNAP Docker (Container)](https://www.goline.ch/2024/09/12/minio-and-prometheus-on-qnap-docker-container/): MiniO configuration & Installation - [Guide to Configuring FRR with OSPF on IPv4 and IPv6 (link-local) and CSF](https://www.goline.ch/2024/08/16/guide-to-configuring-frr-with-ospf-on-ipv4-and-ipv6-link-local-and-csf/): This guide explains how to configure FRR (Free Range Routing) on Ubuntu to manage OSPF for IPv4 and OSPFv3 for IPv6 using link-local addresses. It also covers CSF firewall adjustments to allow OSPF traffic. - [How to Disable PoE Logging on a Port of a Cisco Catalyst Switch](https://www.goline.ch/2024/06/13/how-to-disable-poe-logging-on-a-port-of-a-cisco-catalyst-switch/): Determine the interface on which you want to disable PoE logging. For example, if you want to disable PoE logging on GigabitEthernet 1/0/1, you would enter:        interface GigabitEthernet1/0/1 - [GOLINE SA partners with PowerDMARC](https://www.goline.ch/2024/04/24/goline-sa-partners-with-powerdmarc/): In the supply and logistics sectors, email communication is pivotal. However, organizations face threats like email fraud and phishing. GOLINE SA's clients struggled with configuring email authentication protocols manually. To address this challenge, GOLINE SA partners with PowerDMARC as an MSP Partner, collaborating to streamline implementation and management. - [Don’t install Security Update for Exchange Server 2019 Cumulative Update 14 (KB5036401)](https://www.goline.ch/2024/03/13/dont-install-security-update-for-exchange-server-2019-cumulative-update-14-kb5036401/): Be cautious about installing the KB5036401 update on Exchange Server 2019 CU 14 as it compromises many features as: - [Enable TLS 1.2 on Dell Unity-XT](https://www.goline.ch/2024/02/23/enable-tls-1-2-on-dell-unity-xt/): 4. Run the following command to set TLS to 1.2uemcli -u admin -password /sys/security set -tlsMode TLSv1.2  - [Cisco remediation COP files remain stuck](https://www.goline.ch/2024/01/26/the-cisco-remediation-cop-files-remain-stuck/): As usual, we immediately applied the patches through the COP files found on the Cisco website in the download section for each product. The installation was successfully completed, but the task on all Cisco products (CUCM, CUC, CUPS, UCCX) remains stuck. - [ADSelfService Plus – This site is not secure](https://www.goline.ch/2024/01/22/adselfservice-plus-this-site-is-not-secure/): ADSelfService Plus Please login with safe mode with networking to set the registry value to 'false' for the entry WindowsLogonTFA and RestrictBadCert. Also set 'true'' for  Bypass as shown below. You could also connect to remote registry to the server and do the changes. - [Windows KB5034439 and error “0x80070643”](https://www.goline.ch/2024/01/10/windows-kb5034439-and-error-0x80070643/): Recently, Microsoft released a KB update that has installation issues on Windows. We noticed this on a Windows Server 2019 where it was impossible to install KB5034439 because it reported an error during installation: 0x80070643. - [Domoticz – How to generate authentication token for Netatmo weather station](https://www.goline.ch/2023/12/18/domoticz-how-to-generate-authentication-token-for-netatmo-weather-station/): Preamble:1 - The following tutorial fix the authentication issue of Domoticz to authenticate Netatmo's devices.Below, you can see how the errors appears in the logs:2023-12-16 12:54:18.497 Error: Netatmo di : No Access granted, check username/password - [VMware Skyline Collector Password Reset](https://www.goline.ch/2023/12/12/vmware-skyline-collector-password-reset/): The root and/or admin account password of VMware Skyline Collector Appliance failsThe root and/or admin account of the VMware Skyline Collector Appliance is locked or password is expiredThe root and/or admin account password has been lost or forgotten - [Remove or disable unwanted plugins from vCenter Server Appliance](https://www.goline.ch/2023/12/12/remove-or-disable-unwanted-plugins-from-vcenter-server-appliance/): This article provides the steps to remove or disable any unwanted plug-ins from the vCenter Server or vCenter Server Appliance. - [Apache: Enabling OCSP Stapling on Your Server](https://www.goline.ch/2023/12/11/apache-enabling-ocsp-stapling-on-your-server/): For more information about the Online Certificate Status Protocol (OCSP) and the benefits of OCSP stapling, see Enable OCSP Stapling on Your Server. - [TeamViewer – How to change back to old GUI (Registry mode)](https://www.goline.ch/2023/12/06/teamviewer-how-to-change-back-to-old-gui-registry-mode/): Open REGEDIT, - [CloudLinux – Update MariaDB from 10.3 to 10.11](https://www.goline.ch/2023/11/23/cloudlinux-update-mariadb-from-10-3-to-10-11/): In order to update MariaDB on CloudLinux from 10.3 to 10.11, you need to perform the following tasks.  - [Cisco IP phones – How to remove or change admin password from devices?](https://www.goline.ch/2023/11/22/cisco-ip-phones-how-to-remove-or-change-admin-password-from-devices/): By default, no Administrative Passwords are set and anyone that has physical access to a phone can access the 'Administrator Settings' menu and change its settings. - [Synology NAS | How to disable disk compatibility check](https://www.goline.ch/2023/11/14/synology-nas-how-to-disable-disk-compatibility-check/): Nuova procedura: - [Cisco 88XX IP Phone – Factory reset procedure](https://www.goline.ch/2023/11/07/factory-reset-procedure-cisco-88xx-ip-phone/): How to factory reset a Cisco 8840 8841 8845 88XX - [SysAid Tomcat: redirect from http to https](https://www.goline.ch/2023/11/05/sysaid-tomcat-redirect-from-http-to-https/): Files to be edited\HELPDESKc$Program FilesSysAidServertomcatconfserver.xml\HELPDESKc$Program FilesSysAidServertomcatconfweb.xml - [VMware Horizon connection issue upgrading UAG from 2303 to 2309](https://www.goline.ch/2023/11/02/vmware-horizon-connection-issue-upgrading-uag-from-2303-to-2309/): Following the upgrade of the Unified Access Gateway and Horizon Connection Server from version 2303 to version 2306 or 2309, it may no longer be possible to establish a connection between the two servers. - [How to recovery/reset Cisco Nexus 7K/9K admin password](https://www.goline.ch/2023/10/10/how-to-recovery-reset-cisco-nexus-7k-9k-admin-password/): How to reset/recovery Cisco Nexus 7K/9K admin password  - [How to create and upload SSL certificate on Zerto Virtual Replication 10](https://www.goline.ch/2023/09/25/how-to-create-and-upload-ssl-certificate-on-zerto-virtual-replication-10/): Get more info about our society - [How to make PRTG custom icons](https://www.goline.ch/2023/09/04/how-to-make-prtg-custom-icons/): Creating new PRTG icons is very simple. The important thing is to follow these guidelines. To edit the files you can use any graphics software for resizing and that exports the images to PNG. You can find the logos of various vendors on Google. - [ManageEngine ADSelfService Plus – ADSelfService_Enroll.hta](https://www.goline.ch/2023/08/30/manageengine-adselfservice-plus-adselfservice-enroll-hta/): What is the Self-Enrollment process and how does it work? The Self-Enrollment process is an activity that allows users to register their mobile phone number and associate it with their profile. This will enable the user to perform password resets and/or profile unlocking directly from their smartphone through identity verification. - [Cisco ATA 190 does not register in CUCM 14.0.1.12900-161](https://www.goline.ch/2023/08/21/cisco-ata-190-does-not-register-in-cucm-14-0-1-12900-161/): After upgrading CUCM to version 14 we noticed a strange behavior with ATA 190s.Despite the option 150 in the DHCP informing which is the TFTP server and therefore the Call Manager, the ATA 190 fails to register properly. - [Network Configuration Manager | Cisco Catalyst 9800-CL Wireless Controller sync issue](https://www.goline.ch/2023/08/04/network-configuration-manager-cisco-catalyst-9800-cl-wireless-controller-sync-issue/): Following the reconfiguration of the Cisco Catalyst 9800-CL Wireless Controller tenant on NCM , the following post-backup error was returned: To solve the issue is necessary to go under Config Automation tab ⇾ Exclude criteria ⇾ Line exclude criteria and select the device model (Ex: Cisco Switch) and add the below criteria one by one and save:. - [Totally delete PHP 7.4 from Ubuntu](https://www.goline.ch/2023/08/04/totally-delete-php-7-4-from-ubuntu/): With this command you can see the installed PHP versions and select the one you want (in case there were more than one installed)#update-alternatives --config phpThen, to delete PHP 7.4 and all its components, you need to run these commands:#apt-get purge php7.*#apt-get autoclean#apt-get autoremove - [Changing the description of a PC using PowerShell scripts](https://www.goline.ch/2023/08/03/changing-the-description-of-a-pc-using-powershell-scripts/): Changing the description of a PC can be done via script directly from a Domain Controller. Below is the script to run: # Define the variables$DomainController = *INSERT DOMAIN CONTROLLER HERE* $PCName = "PC NAME" $Description = "DESCRIPTION"# Connect to Active DirectoryImport-Module ActiveDirectory# Check if the PC exists in Active Directory$PC = G - [How to install Dell DCISM or ISM on a VMware ESXi host](https://www.goline.ch/2023/07/19/how-to-install-dell-dcism-or-ism-on-a-vmware-esxi-host/): How to install DCISM or ISM on a VMware ESXi host1- Download ISM-Dell-Web-5.1.0.0-VIB-ESX7i-Live.zip or latest release from Dell Server iDRAC > iDRAC Service Module > Configure Service Module2- Upload this ZIP file to tmp on ESXi host3- Execute: esxcli software vib install -d "/tmp/ISM-Dell-Web-5.1.0.0-VIB-ESX7i-Live.zip"4- Delete ISM-Dell-Web-5.1. - [FIX: Change Windows PIN – Recovery procedure](https://www.goline.ch/2023/07/14/fix-change-windows-pin-recovery-procedure/): Solution 1Sign in with your password then do the following:Delete NGC folder and add a new PIN codeGo to C:WindowsServiceProfilesLocalServiceAppDataLocalMicrosoftNGC.In NGC folder delete all the files. To do so you must be logged as Administrator.delete the temp folder within the NGC folderNow go to Settings > Accounts > Sign-in Options. - [Disable SLAAC IPv6 Ad on Cisco Catalyst 3750](https://www.goline.ch/2023/06/30/disable-slaac-ipv6-ad-on-cisco-catalyst-3750/): To disable SLAAC IPv6 announcements on the VLAN 10 interface.Example on interface VLAN10interface Vlan10ipv6 nd prefix default 2592000 604800 no-autoconfig no-rtr-addressipv6 nd prefix 2A02:4460:1:2::/64 no-advertiseipv6 nd managed-config-flagipv6 nd other-config-flagipv6 nd ra suppress all - [Change hostname to VMware ESXi host](https://www.goline.ch/2023/06/27/change-hostname-to-vmware-esxi-host/): How to change hostname to VMware ESXi hostLogin with SSHesxcli system hostname set --host=esxi06.mydomain.localnano /etc/hostsadd your hostname with and without domain in a rowesxcli system hostname set --fqdn=esxi06.mydomain.local - [FortiNet FortiGate FGT40 hard reset for factory default](https://www.goline.ch/2023/06/15/fortinet-fortigate-fgt40-hard-reset-for-factory-default/): Did you get stuck on the FortiGate FGT40?Now I'll explain the reset procedure.... After sweating seven shirts :)There is a reset button behind it, but it should be pressed only in the correct sequence, otherwise the procedure does not work.1- Disconnect the power supply2- Prepare a paper clip or a pen with a fine point. - [SharePoint fails the GRT processing phase in Veritas Backup Exec](https://www.goline.ch/2023/06/10/sharepoint-fails-the-grt-processing-phase-in-veritas-backup-exec/): Sharepoint GRT backup fails with error 'The backup selection was not successfully processed for Granular Recovery Technology (GRT)'Error MessageV-79-57344-33967 - The backup selection 'SharePoint - 80Content-DB 1 (SQL2014WSS_Content)' was not successfully processed for Granular Recovery Technology (GRT). - [DELL Unity XT certificate renewal](https://www.goline.ch/2023/05/22/dell-unity-xt-certifica-renewal/): 1- Use a Linux machine with openssl   2- Generate RSA 2048bits key   openssl genrsa -out unity_05_23.pk 2048   3- Edit .cnf file (goline.cnf) with oppurtune values (only the fields below are needed)   DNS.1 = unity-xt DNS.2 = unity-xt.yourdomain.local   4- Run command for request generation   openssl req -new -key unity_05_23.pk -out unity_05_23. - [Create a local user account on first Windows boot](https://www.goline.ch/2023/05/17/create-a-local-user-account-on-first-windows-boot/): On latest versions of Windows 11, the installer no longer allows creation of local user account. - [Windows – Reset local administrator user](https://www.goline.ch/2023/05/17/windows-reset-password-dellamministratore-locale/): FAQ valid for both Windows Client and Windows Server - [VMware Horizon: cancellare gli Instant Clone](https://www.goline.ch/2023/04/20/vmware-horizon-cancellare-gli-instant-clone/): Quando il pol viene disabilitato, le repliche utilizzate dagli Instant Clone non vengono rimosse automaticamente da vSphere e sebbene non utilizzino risorse, consumano spazio. - [Installing iDRAC Service Module on VMware ESXi using CLI](https://www.goline.ch/2023/04/06/installing-idrac-service-module-on-vmware-esxi-using-cli/): Installing iDRAC Service Module on VMware ESXi using CLIiSM is available in a ZIP file for installing on systems running VMware ESXi. The ZIP file follows the naming convention ISM-Dell-Web-4.2.0.0-.VIB-i-Live.zip, where is the supported ESXi version.The ZIP files for the supported ESXi versions are:For VMware ESXi 7.x: ISM-Dell-Web-4.2.0.0-. - [Aggiornamento certificato STS VMware vCenter](https://www.goline.ch/2023/03/30/aggiornamento-certificato-sts-vmware-vcenter/): 1- Collegarsi in SSH con utenza di root sulla VCSA2- Creare una nuova folder in root con il seguente comando: - [Upgrade/Install ISM on a Dell PowerEdge Server](https://www.goline.ch/2023/03/13/upgrade-install-ism-on-a-dell-poweredge-server/): Upgrade/Install ISM on a Dell PowerEdge Server - [Fix for .bashrc not executing on startup in Ubuntu](https://www.goline.ch/2023/02/28/fix-for-bashrc-not-executing-on-startup-in-ubuntu/): There can be various reasons why the .bashrc file is not loaded at Ubuntu startup. Here are some possible causes and their solutions:The .bashrc file does not exist or has been accidentally renamed: Check that the .bashrc file exists in the user's home directory and that the file name is correct. - [How to Install Latest Curl Version on Ubuntu](https://www.goline.ch/2023/02/07/how-to-install-latest-curl-version/): Follow these steps to install the latest version of curl on your Ubuntu OS/server regardless of the version. (make sure that you are root by running the following command: sudo su) or add sudo in from the commands. - [Tesla car – Unable to pair RF remote control with HomeLink – Impossibile accoppiare radiocomando con HomeLink](https://www.goline.ch/2023/01/20/tesla-car-unable-to-pair-rf-remote-control-with-homelink-impossibile-accoppiare-radiocomando-con-homelink/): IssueYou have just bought and installed the HomeLink kit in your Tesla but you cannot pair it with the RF remote radio control or with the door opener RF control system.SolutionMany modern RF remote radio control works at 128 bit, while the HomeLink works at 64 bit. - [Cisco Call Manager – CUCM ungraceful shutdown error messages occur when Cisco CUCM servers are powered off without being shut down.](https://www.goline.ch/2023/01/12/cucm-ungraceful-shutdown-error-messages-occur-when-cisco-cucm-servers-are-powered-off-without-being-shut-down/): CUCM ungraceful shutdown error messages occur when Cisco CUCM servers are powered off without being shut down.In the latest updates to CUCM 12.5 and CUCM 14, Cisco has added unclean CUCM shutdown detection to CVOS/UC OS. - [Powershell Command Guide for Exchange Server](https://www.goline.ch/2022/11/26/powershell-command-guide-for-exchange-server/): #Visualizza le impostazioni dei servizi IMAP4 e POP3Get-PopSettings | format-listGet-ImapSettings | format-list - [Grafana update issue](https://www.goline.ch/2022/11/25/grafana-update-issue/): Grafana update reports this error:E: Repository 'https://packages.grafana.com/oss/deb stable InRelease' changed its 'Origin' value from 'grafana stable' to '. stable'E: Repository 'https://packages.grafana.com/oss/deb stable InRelease' changed its 'Label' value from 'grafana stable' to '. - [Enable Task Manager in Taskbar Context Menu on Windows 11](https://www.goline.ch/2022/11/04/enable-task-manager-in-taskbar-context-menu-on-windows-11/): Add Task Manager to the Right-Click Menu of the Taskbar in the RegistryRight-click the Start button and select Run from the menu.Type regedit in the Run box and and press Enter.In the Registry Editor, navigate to the HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlFeatureManagementOverrides4 key.Right-click the 4 subkey and select New > Key. - [How to disable Solarwinds NTA Interface Mapping](https://www.goline.ch/2022/11/04/how-to-disable-solarwinds-nta-interface-mapping/): How to disable Solarwinds NTA Interface MappingNavigate to Centralized Settings (http://localhost/Orion/Admin/AdvancedConfiguration/global.aspx ).2. Find and uncheck setting "InterfaceMappingEnabled"3. Restart NTA servicehttps://netflow/orion/admin/AdvancedConfiguration/global.aspx - [How to fix Cisco ASDM font size too small](https://www.goline.ch/2022/10/27/how-to-fix-cisco-asdm-font-size-too-small/): This happens because ASDM uses Swing which automatically tells Java that it is DPI aware.  Java passes this information along to Windows, so Windows doesn't scale it. - [Check .NET versions installed](https://www.goline.ch/2022/10/26/check-net-versions-installed/): Open Powershell and type this command:Get-ChildItem 'HKLM:SOFTWAREMicrosoftNET Framework SetupNDP' -Recurse | Get-ItemProperty -Name version -EA 0 | Where { $_.PSChildName -Match '^(?!S)p{L}'} | Select PSChildName, version - [Sharepoint – Timer Jobs do not point to all databases tables](https://www.goline.ch/2022/10/18/sharepoint-timer-jobs-do-not-point-to-all-databases-tables/): ISSUE:After a Sharepoint migration from version 2016 to 2019, it can happen that timer jobs, which are automatically scheduled, are not executed on all databases available for a web-application.In our case, the 'immediate alerts' no longer worked, as they pointed to the table 'Mysites' and not 'Intranet' (which is the main one). - [Enabling TLS on ProFTPd](https://www.goline.ch/2022/08/25/enabling-tls-on-proftpd/): IssueEnable secure FTP connection on ProFTPdFixapt install proftpd proftpd-mod-crypto Edit /etc/proftpd/proftpd.conf as followPassivePorts 30000 50000Include /etc/proftpd/tls.conf Edit /etc/proftpd/tls.conf and set:TLSEngine onTLSLog /var/log/proftpd/tls.logTLSProtocol SSLv23TLSRSACertificateFile /etc/ssl/star_goline_ch. - [Webmin upgrade bug: Can’t upgrade version 1.999 to 1.999-2 (Webmin)](https://www.goline.ch/2022/08/22/linux-bug-cant-upgrade-version-1-999-to-1-999-2-webmin/): PROBLEM:"Failed to upgrade from www.webmin.com : You are already running the latest version of Webmin"Even if you actually have the latest version installed.Run this command on SSH:miniservconffile=$(find / -wholename "*web*/miniserv. - [Unlock VMware esxi host root account (locked for 600 seconds)](https://www.goline.ch/2022/08/16/unlock-vmware-esxi-host-root-account-locked-for-600-seconds/): At the console press CTRL+ALT+F2 to get to the ESXi shell. If a login shows up continue with step 3, otherwise continue with step 2.Login to the DCUI (to enable the ESXi Shell if not already done)Login with root and the correct password. - [Brocade Switch – Access the console without Internet Explorer](https://www.goline.ch/2022/07/20/brocade-switch-access-the-console-without-internet-explorer/): ProblemYou want to access the Brocade administration page but Internet Explorer is deprecated - [VMware Horizon: Delete Instant-Clone Orphan VMs](https://www.goline.ch/2022/07/20/vmware-horizon-delete-instant-clone-orphan-vms/): ProblemWhen VMs remain "cp-instant-clone" or "cp.replica" cannot be deleted and the "Delete from disk" optione is greyed out. - [VMware Horizon: remove Desktop pool in “deleting” state](https://www.goline.ch/2022/07/20/vmware-horizon-remove-desktop-pool-in-deleting-state/): ProblemIn the Connection Center Horizon View when deleting a desktop it remains with "Deleting" status. - [Cisco Call Manager – Jabber Mobile cannot comunicate with the server](https://www.goline.ch/2022/07/16/cisco-jabber-mobile-cannot-comunicate-with-the-server/): ProblemWhen you open Cisco Jabber Mobile and try to login you receive an error"Cannot comunicate with the server. Diagnostic." - [Change the language to the interface of Backup Exec](https://www.goline.ch/2022/07/11/change-the-language-to-the-interface-of-backup-exec/): To modify the language Backup Exec 11.x to 2014 displays, create a Backup Exec registry key by doing the following: 1. Go to Start > Run >  RegeditWarning: Incorrect use of the Windows registry editor may prevent the operating system from functioning properly. Great care should be taken when making changes to a Windows registry. - [Veritas Backup Exec – ODBC access error. Possible lost connection to database or unsuccessful access to catalog index in the database.](https://www.goline.ch/2022/07/07/veritas-backup-exec-odbc-access-error-possible-lost-connection-to-database-or-unsuccessful-access-to-catalog-index-in-the-database/): This problem occurred following the migration of Veritas Backup Exec 21 to 22.The previous database was 32-bit and then during the upgrade was upgraded to 64-bit, creating ownership problems on some tables.The following two queries will definitely solve the problem.The Backup Exec console shows a lot of such errors:ODBC access error. - [ESET Agent: unable to install Agent](https://www.goline.ch/2022/06/29/eset-impossibile-installare-agente/): Seguire questa guida: - [WHMCS – Clear module queue](https://www.goline.ch/2022/06/29/whmcs-clear-module-queue/): Two tasks are being reported that even though they are set as "Mark Resolved", after a while they become visible again.How can we do to terminate them permanently and make them disappear from the list?I think they are old hanging tasks that are no longer needed.Run this query on the WHMCS database:UPDATE tblmodulequeue SET completed = 0 - [WSUS: Errori 0x8024401c e 0x80244022 durante la ricerca aggiornamenti in Windows Update](https://www.goline.ch/2022/06/22/wsus-errori-0x8024401c-e-0x80244022-durante-la-ricerca-aggiornamenti-in-windows-update/): ProblemaSul WSUS Server durante la ricerca degli update in Windows Update si blocca e restituisce errore "0x8024401c" o "0x80244022" - [WSUS: declinare gli update superseded](https://www.goline.ch/2022/06/22/wsus-declinare-gli-update-superseded/): ProblemaAprendo la console WSUS ci sono degli update che non si possono approvare perchè sono SuperSeded da un altro piu' recente.Ma non si riescono nemmeno a declinare e continuano a bloccarsi. - [Windows Task (Tasklist)](https://www.goline.ch/2022/06/22/windows-task-tasklist/): Windows stores scheduled tasks as XML files, AND in the registry. - [WinRM – Windows Remote Management (Enabling and permit hosts access)](https://www.goline.ch/2022/06/22/windows-remote-management-abilitazione/): # Enabling PowerShellEnable-PSRemoting -ForceTo enable all host:Set-Item wsman:localhostclienttrustedhosts *To enable a specific host:Set-Item wsman:localhostclienttrustedhosts prtg.goline. - [Windows DNS Server (tempo massimo cache)](https://www.goline.ch/2022/06/22/windows-dns-server-tempo-massimo-cache/): Crea questa chiave (di default non esiste)HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesDNSParametersREG_DWORD > MaxCacheTtlDefault= 0x15180 (86,400 seconds = 1 day) Riavvia il servizio DNS server - [Windows 2012 R2 DNS (Avoid spoofing – increase SocketPoolSize)](https://www.goline.ch/2022/06/22/windows-2012-r2-dns-avoid-spoofing-increase-socketpoolsize/):  Randomize your DNS source portsThere are some DNS attacks that can take advantage of the predictability of the source port for DNS responses a computer sends out. The predictability can allow the attacker to hijack a response to a DNS client and send the client to a site under the attacker’s control. - [Vulnerabilità Click Jacking su IIS e rimuovere il metodo OPTIONS](https://www.goline.ch/2022/06/22/vulnerabilita-click-jacking-su-iis-e-rimuovere-il-metodo-options/): Entrare sulla console di IISSelezionare HTTP Response Headers - [Visualizzare gli utenti di una OU e i gruppi a cui appartengono](https://www.goline.ch/2022/06/22/visualizzare-gli-utenti-di-una-ou-e-i-gruppi-a-cui-appartengono/): La funzione deve essere eseguita nella  PowerShell-----------------------Function GetADUser(){$ADUsers = dsquery user "ou=puntofresco,dc=buonvicini,dc=local" FOREACH ($ADUser in $ADUsers){If ($ADUser.Length -gt 3){$DN = $ADUser.split(",")$CN = $DN$UsrFriendlyName = $CN. - [MS Exchange: Utente autorizzato ad una Shared MailBox riceve ritorno mail (recapito non riuscitomancanza di autorizzazioni)](https://www.goline.ch/2022/06/22/ms-exchange-utente-autorizzato-ad-una-shared-mailbox-riceve-ritorno-mail-recapito-non-riuscitomancanza-di-autorizzazioni/): E' capitato che, creando una nuova Shared MailBox, gli utenti selezionando dalla rubrica l' inidirzzo "DA" e invando una mail ricevono un messaggio d' errore da Exchange.Il messaggio d' errore indica che l' utente non ha le autorizzazione anche se in realtà le ha. Si tratta di un problema di caching per Outlook. - [Uninstall Windows Defender Antivirus from Windows server 2016/ 2019](https://www.goline.ch/2022/06/22/uninstall-windows-defender-antivirus-from-windows-server-2016-2019/): Lanciare il seguente comando da Power ShellUninstall-WindowsFeature -Name Windows-Defender - [Unable to delete Active Directory user with ActiveSyncDevice](https://www.goline.ch/2022/06/22/unable-to-delete-active-directory-user-with-activesyncdevice/):  Su PowerShell di Exchange eseguire il seguente comando inserendo il cognome dell'utente da cancellarePer visualizzare : Get-ActiveSyncDevice | where {$_.userdisplayname –like “*tremolada”} Per rimuovere : Get-ActiveSyncDevice | where {$_. - [Trova CN di un utente in active directory](https://www.goline.ch/2022/06/22/trova-cn-di-un-utente-in-active-directory/): Get-ADUser -Properties DistinguishedName | Select-Object DistinguishedName - [Timeout for Sign out disconnected RDP session on RDP Server](https://www.goline.ch/2022/06/22/timeout-for-sign-out-disconnected-rdp-session-on-rdp-server/): Open "Run" and type "gpedit.msc" Go to "User Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Session Time Limits"Double Click on "Set time limit for disconnected sessions" and select enable then set time to "X minute" - [The trust relationship between this workstation and the primary domain failed.](https://www.goline.ch/2022/06/22/the-trust-relationship-between-this-workstation-and-the-primary-domain-failed/): Download netdom.exe. These two files have been exacted from KB958830. - [The system must be rebooted before installation can continue.](https://www.goline.ch/2022/06/22/the-system-must-be-rebooted-before-installation-can-continue/): Click Start > Run, type regedit, and click OK.Look for these registry keys:HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerPendingFileRenameOperationsHKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerFileRenameOperationsHKEY_LOCAL_MACHINESYSTEMControlSet001ControlSession ManagerPendingFileRenameOperationsHKEY_LOCAL_MACHI - [The Group Policy Client service failed the sign-in. The universal unique identifier (UUID) type is not supported.](https://www.goline.ch/2022/06/22/the-group-policy-client-service-failed-the-sign-in-br-the-universal-unique-identifier-uuid-type-is-not-supported/): There are two places to look in the registry:HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices this path should contain gpsvc key (a folder), which is responsible for service parameters and configuration.  I found that the key was intact, so, you do not touch anything here - just check that the key exists. - [SetACL rimuovere i SID orfani dalle cartelle condivise](https://www.goline.ch/2022/06/22/setacl-rimuovere-i-sid-orfani-dalle-cartelle-condivise/): ProblemaNell'arco degli anni si eliminano gli utenti da active directory, tuttavia nelle cartelle condivise rimangono i SID orfani di questi utenti eliminati.Ogni tanto è opportuno eliminarli o pulirli - [Server Manager: Under Manageability – Online- Data retrieval failures occurred](https://www.goline.ch/2022/06/22/server-manager-under-manageability-online-data-retrieval-failures-occurred/): Si presenta un errore nel Server Manager ma esiste un workaround per risolverlo.È necessario eliminare una serie di chiavi di registro e poi rifare il refresh nel Server Manager. - [rundll32.exe “Windows cannot access the specified device…” Error message when trying to open settings](https://www.goline.ch/2022/06/22/rundll32-exe-windows-cannot-access-the-specified-device-error-message-when-trying-to-open-settings/): Method 1:Solution through Group Policy:Open gpedit.msc (Group Policy Editor)Browse to Computer Configuration->Windows Settings->Security Settings->Local Policies->Security OptionsEnable “User Account Control: Admin Approval Mode for the Built-in Administrator account”,Restart workstation (Restart the computer)Method 2:Solution through registry:Open - [Ripristinare Microsoft Edge](https://www.goline.ch/2022/06/22/ripristinare-microsoft-edge/): Per ripristinare Microsoft Edge: - [Rimuovere Tastiera Chinese Simplified Microsoft Pinyin](https://www.goline.ch/2022/06/22/rimuovere-tastiera-chinese-simplified-microsoft-pinyin/): Per rimuovere la tastiera aggiuntiva (Chinese Simplified) che pare essere configurata di default in alcune versioni di Win10: - Aggiungere una nuova lingua a quella già esistente: Chinese Simplified (in automatico windows associa alla nuova lingua la tastiera Microsoft Pinyin)- Aggiungere una seconda tastiera alla lingua (una qualsiasi), quindi eli - [Rimuovere language QAA da Windows](https://www.goline.ch/2022/06/22/rimuovere-language-qaa-da-windows/): Entrare in PowerShell come amministratore ed eseguire queste righe di codice, poi riavviare.$LanguageList = Get-WinUserLanguageList$Language = $LanguageList | where LanguageTag -eq "qaa-Latn"$LanguageList.Remove($Language)Set-WinUserLanguageList $LanguageList -Force - [Riabilitare la visione delle Prestazioni dei dischi nel Task Manager](https://www.goline.ch/2022/06/22/riabilitare-la-visione-delle-prestazioni-dei-dischi-nel-task-manager/): Problema:Nelle nuove installazioni di Windows Server 2019 non si vedono le performance dei dischi sotto CTRL+ALT+CANC (Gestione attività) e Prestazioni. - [Resetting Administrator Password in Windows 2012](https://www.goline.ch/2022/06/22/resetting-administrator-password-in-windows-2012/):   - [Reinstallare Microsoft Store su Windows 10](https://www.goline.ch/2022/06/22/reinstallare-microsoft-store-su-windows-10/): Eseguire in Powershell con privilegi amministrativi:1 opzione di restore windows store:start->run->wsreset.exe2 optione di restore windows store:Get-AppxPackage -allusers Microsoft.WindowsStore | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)AppXManifest.xml"} - [Pulsante Siti greyed out nelle Opzioni Internet](https://www.goline.ch/2022/06/22/pulsante-siti-greyed-out-nelle-opzioni-internet/): ProblemaIl pulsante "Siti" è greyed out nelle Opzioni Internet - Sicurezza - zona - [Pulizia WinSXS su Windows 2012 e Windows 8.1](https://www.goline.ch/2022/06/22/pulizia-winsxs-su-windows-2012-e-windows-8-1/): In order to perform a WinSXS cleanup, you can remove any backup files created during the installation of a service pack by using the following command: - [PRTG – Launch an external batch](https://www.goline.ch/2022/06/22/prtg-launch-an-external-batch/):  PTF launcher is a Custom Notification that can launch external applications. PRTG Server runs as a service and therefore cannot start applications that interact with the desktop. With PTF Launcher, this is no longer an issue.The download includes two .exe files:Launch. - [Problema accesso con roaming profile Windows](https://www.goline.ch/2022/06/22/problema-accesso-con-roaming-profile-windows/):  Dopo aver cancellato il profilo utente e tutte le cartelle utente, eliminare la seguente chiave di registo dell'utente sotto:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionProfileListScorrere tutti gli UID e cercare il nome utente da eliminare nella chiave ProfileImagePath.Una volta identificato l'UID dell'utente cancellarlo.   - [Powershell – Get the user SID](https://www.goline.ch/2022/06/22/powershell-get-the-user-sid/): Get the SID for a local user account.$username='julian'$user = New-Object System.Security.Principal.NTAccount($username) $sid = $user.Translate() $sid.ValueGet the local username from a SID.$sid='S-1-5-21-5082059827-597078506-5194163137-1005'$osid = New-Object System.Security.Principal.SecurityIdentifier($sid)$user = $osid.Translate( )$user.Value - [Power Plan No Sync: event ID 4098 cannot find the file specified](https://www.goline.ch/2022/06/22/power-plan-no-sync-event-id-4098-cannot-find-the-file-specified/): Se i client non prendono la policy di powerplan è perchè i plan di default sono corrotti e non riesce ad applicarne altri.Bisogna far girare questo comando per riportare i power plan allo stato di default:powercfg -restoredefaultschemesda psexec:psexec \golapxx -s c:windowssystem32powercfg. - [Outlook non stampa e non fa l'anteprima](https://www.goline.ch/2022/06/22/outlook-non-stampa-e-non-fa-lanteprima/): Il problema capita di solito dopo un blocco improvviso di Outlook o dell’intero sistema Windows, l’effetto è quello che al successivo lancio di Outlook risulta impossibile sia stampare sia fare l’anteprima di stampa. - [Outlook tenta di autenticarsi su Microsoft 365 anzichè locale On-Premise](https://www.goline.ch/2022/06/22/outlook-tenta-di-autenticarsi-su-microsoft-365-anziche-locale-on-premise/): ProblemaAll'apertura di Outlook tenta di autenticarsi su Microsoft 365 in continuazione anzichè utilizzare i nostri server locali On-Premise - [Microsoft Office Online – sostituzione certificato wildcard](https://www.goline.ch/2022/06/22/microsoft-office-online-sostituzione-certificato-wildcard/): Dopo aver aggiornato il certificato WildCard *goline.ch e averlo bindato a tutti i siti in https è necessario eseguire il seguente comando:New-OfficeWebAppsFarm -InternalUrl "https://office.goline.ch" -ExternalUrl "https://office.goline.ch" -CertificateName "*.goline. - [Move a file share to a new server using Robocopy](https://www.goline.ch/2022/06/22/move-a-file-share-to-a-new-server-using-robocopy/): Robocopy is a command line tool that has been around for years, but is still really useful today. It is part of the Windows Server Resource Kit Tools. You will need to install these in order to use the robocopy command. - [MBR2GPT per convertire il disco in GPT per avviare Windows 10 con UEFI](https://www.goline.ch/2022/06/22/mbr2gpt-per-convertire-il-disco-in-gpt-per-avviare-windows-10-con-uefi/): Il programma MBR2GPT.EXE si trova nella cartella windowssystem32 nel disco dove è installato Windows 10. Esso può essere avviato con WindowsPE (Windows Preinstallation Environment) o direttamente da Windows stesso, però in questo caso bisogna aggiungere al comando la seguente opzione /allowFullOSIl disco da convertire deve essere un disco di sistem - [Impostazione permission per Home Directory](https://www.goline.ch/2022/06/22/impostazione-permission-per-home-directory/): La directory principale "Home" deve essere condivisa dando le seguenti permission:Oltre a Administrators e Domain admins impostare anche Domain Users in modo che non vengano generati avvisi di accessi non consentiti al momento del login. Le permission a Domain users devono essere date come "Read " e "This folder Only". - [Impostazione permission per cartella padre profili su Windows](https://www.goline.ch/2022/06/22/impostazione-permission-per-cartella-padre-profili-su-windows/): Impostare le seguenti permission - [HP WebJet Admin. Problem connecting after update](https://www.goline.ch/2022/06/22/hp-webjet-admin-problem-connecting-after-update/): http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c01625441 Error message: The service could not be contacted. Please make sure the service is started before running the client. When clients attach to HP Web Jetadmin, the software performs a redirect using the an IP address from the NIC that the application selected during startup. - [How to Disable Shutdown/Restart as Group Policy](https://www.goline.ch/2022/06/22/how-to-disable-shutdown-restart-as-group-policy/): How to Disable Shutdown/Restart as Group Policy1- Log in to your DC and right click at the OU node where you want the policy applied:2- Name the policy something like "Prevent Shutdown Display"3- Right click the newly created policy and select "Edit"4- Expand User Configuration -> Administrative Templates -> Start Menu and Taskbar:5- The right pane - [Gestione certificati e app IIS da Prompt](https://www.goline.ch/2022/06/22/gestione-certificati-e-app-iis-da-prompt/): ProblemaSi vuole cambiare il binding di un sito ad un certificato che non esiste piu'.Oppure si vuole eliminare il binding di un'app su di una porta per renderla utilizzabile. - [Fix for installing unsigned add-ons in Firefox](https://www.goline.ch/2022/06/22/fix-for-installing-unsigned-add-ons-in-firefox/): If you run a recent version of Firefox Dev or Nightly, and try to install an unsigned add-on, you may receive the error message that the browser prevented the operation from completing (... has prevented this site from installing an unverified add-on). - [File system error (-2147219196) con Microsoft Photos](https://www.goline.ch/2022/06/22/file-system-error-2147219196-con-microsoft-photos/): Eseguire con i privilegi amministrativi in PowerShell il seguente comando:Get-AppXPackage | Foreach {Add-AppxPackage -DisableDevelopmentMode -Register "$($_.InstallLocation)AppXManifest.xml"} - [Export Windows DNS zone to BIND](https://www.goline.ch/2022/06/22/export-windows-dns-zone-to-bind/): Login as Administrator, and load up a Powershell console: dnscmd YourDomainController.tld /ZoneExport YourDomain.fqdn.tld YourDmain.fqdn.tld.txt Then you can look in %windir%/system32/dns/* and find the txt files  containing your zone data. - [Escludere directories nel roaming profile](https://www.goline.ch/2022/06/22/escludere-directories-nel-roaming-profile/): Impostata nella "policy generale"User configuration >  Policy > Administrative templates > System > User Profiles > Exclude directories in roamin profilesEsempio sintassi: Videos;Music;Download;Dropbox;AppDataRoamingMicrosoftSearch;AppDataRoamingApple Computer;VirtualBox VM;AppDataRoamingMicrosoftTemplates - [Enable SNTP server on Windows Server out of domain](https://www.goline.ch/2022/06/22/enable-sntp-server-on-windows-server-out-of-domain/): Non si ricevono le informazioni via SNMP del time server (SNTP) di Windows su un server fuori dal dominio.Modificare le chiavi di registro qui sotto e riavviare il servizio: Windows Time.Enabling the NTP server service requires a quick registry modification. - [Eliminare file troppo lunghi da Windows](https://www.goline.ch/2022/06/22/eliminare-file-troppo-lunghi-da-windows/):   - [Downgrade di Edge](https://www.goline.ch/2022/06/22/downgrade-di-edge/): ProblemaLa nuova versione di Edge genera un problema con l' apertura dei PDF tramite visualizzarore integrato di Edge. (versione 92.0.902.55) - [Disattivare la registrazione DNS con più schede](https://www.goline.ch/2022/06/22/disattivare-la-registrazione-dns-con-piu-schede/): “HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParametersDNSRegisteredAdapters”  then that adapter will register in DNS unless you put a registry       “DisableDynamicUpdate” in  “TcpipParametersInterfaceGUID” key of       that adapter. - [Disabilitazione SMBv1 ed abilitazione Digital Signing](https://www.goline.ch/2022/06/22/disabilitazione-smbv1-ed-abilitazione-digital-signing/): ProblemaPer proteggere la rete da vulnerabilità come i ransomware si rende necessario disabilitare SMBv1 ed attivare il Digital Signing delle comunicazioni.Anche InsightVM segnala queste vulnerabilità. - [Delete a user profile from registry](https://www.goline.ch/2022/06/22/delete-a-user-profile-from-registry/): First, make sure the profile folder in C:Users was completely gone.Find the user’s SID (security identifier):From a command prompt type: wmic useraccount get name,sid  (type exactly as shown)In the registry, expand HKLMSoftwareMicrosoftWindowsNTCurrentVersionProfileList and find the key named with the SID of the desired user. - [Credenziali salvate e login falliti di Windows](https://www.goline.ch/2022/06/22/credenziali-salvate-e-login-falliti-di-windows/): Per risolvere il problema della credenziali salvate che generano innumerevoli login falliti si può seguire questa procedura.È necessario copiarsi in locale psexec di Sysinternals di Microsoft ed eseguirlo nella seguente modalità. - [Contare totale utenti AD (Active Directory)](https://www.goline.ch/2022/06/22/contare-totale-utenti-ad-active-directory/): Lanciare il seguente comando come amministratore:(Get-ADUser -Filter *).Count - [Configure Internet Explorer IE 11 Home Page](https://www.goline.ch/2022/06/22/configure-internet-explorer-ie-11-home-page/): 1) Open up Group Policy Management Console. Branch out until you get to the Group Policy Objects folder. Right click on it and click new. - [Come trovare la startup folder su Windows Server 2012](https://www.goline.ch/2022/06/22/come-trovare-la-startup-folder-su-windows-server-2012/): Click di destro sul menu di start e selezionare run. Scrivere: shell:startup A questo punto apparirà la cartella di avvio, nella quale è possibile inserire scorciatoie o applicazioni. Per trovare la cartella di avvio comune a tutti gli utenti: - [Comando per ricavare la versione del BIOS da DOS o PowerShell](https://www.goline.ch/2022/06/22/comando-per-ricavare-la-versione-del-bios-da-dos-o-powershell/): Da riga di comando (DOS o PowerShell) digitare la seguente stringa:wmic bios get smbiosbiosversion  - [Clear Offline Address Book Outlook](https://www.goline.ch/2022/06/22/clear-offline-address-book-outlook/):  Svuotare la cartella:C:Users%username%AppDataLocalMicrosoftOutlookOffline Address Books   - [Certificati root CA interne non riconosciuti da Chrome](https://www.goline.ch/2022/06/22/certificati-root-ca-interne-non-riconosciuti-da-chrome/):  Chiudi Chrome Powershell con amministratore   reg add HKEY_LOCAL_MACHINESOFTWAREPoliciesGoogleChrome /v EnableCommonNameFallbackForLocalAnchors /t REG_DWORD /d 1 /f  reg add HKEY_LOCAL_MACHINESOFTWAREPoliciesGoogleChrome /v EnableSha1ForLocalAnchors /t REG_DWORD /d 1 /f   Riapri Chrome - [Cannot rename this connection. A connection with the name you specified already exists. Specify a different name.](https://www.goline.ch/2022/06/22/cannot-rename-this-connection-a-connection-with-the-name-you-specified-already-exists-specify-a-different-name/): Apri il REGEDIT e sfoglia le chiavi sotto questo registro:HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}C'è un ID per ogni scheda ed espandendolo, in Connection, vedi il nome della scheda. - [Cancellare windows.old in Windows 8/8.1](https://www.goline.ch/2022/06/22/cancellare-windows-old-in-windows-8-8-1/): 1. Open an elevated command prompt.2. In the elevated command prompt, copy and paste the command below, and press Enter. (see screenshot below)NOTE: If you had another say windows.old.000 folder that you also wanted to delete, then you could repeat this command substituting that name instead of windows.old to also delete it.RD /S /Q %SystemDrive%windows.old  - [Cambiare descrizione PC via PowerShell in remoto](https://www.goline.ch/2022/06/22/cambiare-descrizione-pc-via-powershell-in-remoto/): Per cambiare da remoto la descrizione di un computer eseguire i seguenti comandi Powershell$PC = Get-WmiObject -class Win32_OperatingSystem -computername "GOPC075"$PC.Description = "Workstation di Coppolecchia Dino"$PC.Put() - [Backup Exec – Change deduplication device password](https://www.goline.ch/2022/06/22/backup-exec-change-deduplication-device-password/): When you specify a Backup Exec logon account for a deduplication disk storage device, an additional user account is created for the deduplication components with the same user name and password. However, if you change the credentials for the Backup Exec logon account, the credentials for the additional user account are not changed automatically. - [Azure DevOps TFS: Rinnovo certificato SSL](https://www.goline.ch/2022/06/22/azure-devops-tfs-rinnovo-certificato-ssl/): # Mostra certificati attuali bindati sulle porte, i thumbprint e application ID di DevOps TFSnetsh http show sslcert# Rimuove il binding da DevOps dei certificati vecchinetsh http delete sslcert ipport=0.0.0.0:443netsh http delete sslcert ipport=:443netsh http delete sslcert ipport=0.0.0. - [Autostart di programmi con Windows 11](https://www.goline.ch/2022/06/22/autostart-di-programmi-con-windows-11/): Autostart Windows 11Quando si vogliono far partire in automatico dei collegamenti ad applicazioni è necessario creare un link all'interno dello start menu di Windows, sotto ProgramsStartup.All'avvio del computer partirà automaticamente.Copiare il link dell'applicazione in questa cartella:%AppData%MicrosoftWindowsStart MenuProgramsStartup - [Amministratore di macchina locale non puo' eseguire come amministratore](https://www.goline.ch/2022/06/22/amministratore-di-macchina-locale-non-puo-eseguire-come-amministratore/): Procedere come segue:-Aprire le local policy-> Computer configuration - Windows Settings - Security Settings - Local policies - Security options.Individuare la seguente policy nel riquadro di destra:User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode -> Set its value to Elevate without promptIndividuare - [Aggiunta di un suffisso UPN a un insieme di strutture](https://www.goline.ch/2022/06/22/aggiunta-di-un-suffisso-upn-a-un-insieme-di-strutture/): Aggiunta di un suffisso UPN a un insieme di struttureAprire e trust di Active Directory Domains.Fare clic con il pulsante destro del mouse su Active Directory Domains and Trusts nel riquadro della finestra della struttura e quindi fare clic su Proprietà . - [Microsoft .NET 4.7 update problem on Windows 2012 R2](https://www.goline.ch/2022/06/22/microsoft-net-4-7-update-problem-on-windows-2012-r2/): The Fix To resolve this, we are going to download the updates MSU files from the Microsoft Update Catalog, and fully uninstall, then re-install the problematic updates. Please Note: Always make sure you have a full backup before making modifications to your servers. - [Problema Icone Windows 10 e ricerca non funzionante](https://www.goline.ch/2022/06/22/problema-icone-windows-10-e-ricerca-non-funzionante/): Problema noto di Windows 10 che, perde le icone e non sono ricercabili attraverso il search del sistema operativo.Risoluzione 1:Lanciare il seguente comando DOS come amministratoreDISM /Online /Cleanup-Image /RestoreHealthRisoluzione 2:Cambiare la seguente chiave di registro da 1 a 0HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExp - [WHMCS – Cleaning tables when DB grows too big](https://www.goline.ch/2022/06/22/whmcs-cleaning-tables-when-db-grows-too-big/): WHMCS - Table Cleanup via phpMySQLAdmin - [How To Change The Default Timezone In WHMCS](https://www.goline.ch/2022/06/22/how-to-change-the-default-timezone-in-whmcs/): We are often asked this question and here is the simple way to change your timezone in WHMCS so it is different from your server time. - [VMware ESXi: System logs are stored on non-persistent storage](https://www.goline.ch/2022/06/22/vmware-esxi-system-logs-are-stored-on-non-persistent-storage/): Problema:Dopo uno spegnimento o un riavvio di un ESXi viene visualizzato l'errore "System logs are stored on non-persistent storage"Risoluzione da SSHCheckvim-cmd hostsvc/advopt/view ScratchConfig.ConfiguredScratchLocationWritevim-cmd hostsvc/advopt/update ScratchConfig. - [VMware ESXi: Rimuovere floppy dalle VM](https://www.goline.ch/2022/06/22/vmware-esxi-rimuovere-floppy-dalle-vm/): ProblemaNonostante non compaia nelle periferiche, alcune VM continuano a mostrare l'unità Floppy A: connessa.RisoluzioneAccedere in SSH su uno degli ESXi a casoRecarsi nella cartella della VMAd esempiocd /vmfs/volumes/open-e DSS7/BUSE005 - Area 51/Spegnere la VM in questioneCon vi editare il file VMX (l'edit funziona solo con VM spenta):vi BUSE005 - [VMware vCenter: impossibile migrare una VM è grigio il comando “Migrate”](https://www.goline.ch/2022/06/22/vmware-vcenter-impossibile-migrare-una-vm-e-grigio-il-comando-migrate/): Problema - [VMware View Composer – View Composer agent initialization state error (16): Failed to activate license](https://www.goline.ch/2022/06/22/vmware-view-composer-view-composer-agent-initialization-state-error-16-failed-to-activate-license/): View Composer agent initialization state error (16): Failed to activate licenseRisoluzione:Sulla macchina template ufficiale entrare nel registro di configurazione:Editare questa chiave di registro e impostare SkipLicenseActivation a 1HKEY_LOCAL_MACHINESYSTEMControlset001Servicesvmware-viewcomposer-gaPoi è necessario rifare la snapshot per il linke - [VMware vCenter: update da SSH](https://www.goline.ch/2022/06/22/vmware-vcenter-update-da-ssh/): Problema:Durante l'aggiornamento di vCenter da pagina web compaiono errori o non viene effettuato l'aggiornamento. - [VMware: Controllo e rimozione VIB se si hanno problemi durante gli upgrade](https://www.goline.ch/2022/06/22/vmware-controllo-e-rimozione-vib-se-si-hanno-problemi-durante-gli-upgrade/): ProblemaDurante un upgrade di VMware ESXi vengono segnalati errori con VIB non compatibili e che andrebbero rimossi. - [VMware vCenter: reset database degli update](https://www.goline.ch/2022/06/22/vmware-vcenter-reset-database-degli-update/): ProblemaPer risolvere dei problemi si rende necessario resettare il DB degli upgrade - [VMware vCenter: pulizia LOG file per ottenere spazio disco](https://www.goline.ch/2022/06/22/vmware-vcenter-pulizia-log-file-per-ottenere-spazio-disco/): Getting an A+ on the Qualys SSL Test - Windows Edition - [VMware VM Template Update](https://www.goline.ch/2022/06/22/vmware-vm-template-update/): How to update a VMWare TemplateIssue: You need to install windows updates or make other changes to a Windows based VMWare Template.Solution: The following steps will convert the template back to a VM, allow you to apply any updates or changes and then sysprep the VMWare template and finally convert it back into a template. - [VMware vCenter Server Appliance on port 5480: Unable to login](https://www.goline.ch/2022/06/22/vmware-vcenter-server-appliance-on-port-5480-unable-to-login/): Here is how I resolved the issueLogin VCSA ssh consoleCheck which service did not start       # service-control --status      Found the most important one: applmgmt   3. Manual start the services which are missing     # service-control --start applmgmt   4. - [VMware Horizon: Task: Wipe a Flex-SE virtual disk Status: A general system error occurred: Wipe Disk failed: Failed to complete wipe operation.](https://www.goline.ch/2022/06/22/vmware-horizon-task-wipe-a-flex-se-virtual-disk-status-a-general-system-error-occurred-wipe-disk-failed-failed-to-complete-wipe-operation/): This issue occurs due to CBT enabled in the parent image:https://kb.vmware.com/kb/2047250 - [VMWare Horizon View – Cancellare instant clones corrotti manualmente](https://www.goline.ch/2022/06/22/vmware-horizon-view-cancellare-instant-clones-corrotti-manualmente/): Quando il pool è disabilitato, le repliche utilizzate dai cloni istantanei non vengono rimosse automaticamente da vSphere e, anche se non utilizzano risorse, consumano memoria. - [VMware Horizon Certificate for Composer self-made with Microsoft CA](https://www.goline.ch/2022/06/22/vmware-horizon-certificate-for-composer-self-made-with-microsoft-ca/): Generating a Horizon View SSL certificate request using the Microsoft Management Console (MMC) Certificates snap-in (2068666)PurposeThis article provides information on using the tools already installed on your Windows server (the MMC Certificates snap-in) to generate an SSL certificate request for View Connection Servers and View Security Servers. - [VMware ESXi drivers downgrade/install/list](https://www.goline.ch/2022/06/22/vmware-esxi-drivers-downgrade-install-list/): Emulex Corporation HP NC550SFP Dual Port 10GbE Server Adapter# visualizza i driver elxent installatiesxcli software vib list | grep elxnet>elxnet 10.2.309.6v-1vmw.600.0.0.2494585 VMware VMwareCertified 2015-10-01 emulex-esx-elxnetcli 10.2.309.6v-0.0. - [VMware vCenter Backup failed with error: Db health is UNHEALTHY, Backup Failed.Disable health check to take backup in current state.](https://www.goline.ch/2022/06/22/vmware-vcenter-backup-failed-with-error-db-health-is-unhealthy-backup-failed-disable-health-check-to-take-backup-in-current-state/): Execute this script to fix DB health on vCenter Server Appliance/usr/bin/dbcc -fbss embedded - [Unable to power off the virtual machine in a VMware ESXi host](https://www.goline.ch/2022/06/22/unable-to-power-off-the-virtual-machine-in-a-vmware-esxi-host/): Esegui questo comando sull'host per determinare il numero di world id della VM che non risponde#esxcli vm process listQuesto comando termina la macchina mettendola in shutdown#esxcli vm process kill --type=soft -w=601189 - [SOAP error in PRTG legato ad un host ESXi in VMware vCenter](https://www.goline.ch/2022/06/22/soap-error-in-prtg-legato-ad-un-host-esxi-in-vmware-vcenter/): ProblemaIn PRTG compare un errore "VMware Host Hardware Status (SOAP)" legato ad un host ESXi - [Abilitare SNMP su VMware ESXi modificando snmpd.xml](https://www.goline.ch/2022/06/22/abilitare-snmp-su-vmware-esxi-modificando-snmpd-xml/): Come primo passaggio bisogna modificare un file sotto /etc.Via SSH editare il file /etc/vmware/snmp.xml - [Rimuovere i plugin da VMware vCenter Server](https://www.goline.ch/2022/06/22/rimuovere-i-plugin-da-vmware-vcenter-server/): Removing unwanted plug-ins from vCenter Server (1025360)SymptomsYou are unable to remove plug-ins from the vSphere Client.You see the error:vCenter {Plugin Name} Disabled {Plugin Name} vCenter plugin The following error occurred while downloading the script plugin from https:///vmware/Plugin-NamePlugin. - [VMware vCenter: Previous MACHINE_SSL_CERT Subject Alternative Name does not match new MACHINE_SSL_CERTIFICATE Subject Alternative Name](https://www.goline.ch/2022/06/22/vmware-vcenter-previous-machine-ssl-cert-subject-alternative-name-does-not-match-new-machine-ssl-certificate-subject-alternative-name/):   First of all, you will need three certificates in the following format:  - [NTPd su VMware ESXi in shell](https://www.goline.ch/2022/06/22/ntpd-su-vmware-esxi-in-shell/): Per visualizzare se il daemon ntp sta funzionando correttamente su un server ESXi entrare in shell SSH e lanciare questo comando:~ # watch ntpq -p localhostEvery 2s: ntpq -p localhost                                                                               2014-10-22 16:32:09     remote           refid      st t when poll reach   delay   offse - [Monitorare e gestire un controller raid HP SmartArray da VMware ESXi](https://www.goline.ch/2022/06/22/monitorare-e-gestire-un-controller-raid-hp-smartarray-da-vmware-esxi/): Su un server HP, è necessario monitorare o gestire un controller RAID SmartArray. - [VMware: How to delete a vCenter Server advanced setting](https://www.goline.ch/2022/06/22/vmware-how-to-delete-a-vcenter-server-advanced-setting/): How to delete a vCenter Server advanced settingSSH to you vCenter Server.Go to the “shell”go to directory: /etc/vmware-vpx/Edit the file “vpxd.cfg”Simply find the entry and delete the entry (with “vi” you use “/” to search)Restart VPXD by running the following command service-control --restart vmware-vpxd. - [Eliminare vCLS orfane in VMware vCenter](https://www.goline.ch/2022/06/22/eliminare-vcls-orfane-in-vmware-vcenter/): Nostro dominio cluster: config.vcls.clusters.domain-c223823.enabledRetreat Mode stepsUsing the vSphere ClientLog in to the vSphere Client.Navigate to the cluster on which vCLS has to be disabled. Copy the cluster domain id from the URL of the browser. It should be similar to 'domain-c'.Notes: You only need to copy domain-c part of the URL. - [VMware ESXi: Configuring static routes for vmkernel ports on an ESXi host](https://www.goline.ch/2022/06/22/vmware-esxi-configuring-static-routes-for-vmkernel-ports-on-an-esxi-host/): #Add new gateway to routeesxcli network ip route ipv4 add --gateway 10.15.0.254 --network 10.15.0.0/24#List ip routeesxcli network ip route ipv4 list#Remove gateway esxcli network ip route ipv4 remove -n 10.15.0.0/24 -g 0.0.0.0 - [Backing up and restoring ESXi configuration using the vSphere](https://www.goline.ch/2022/06/22/backing-up-and-restoring-esxi-configuration-using-the-vsphere/): Note: From vSphere CLI for Windows, ensure you are executing the command from C:Program FilesVMwareVMware vSphere CLIbin - [Axis Camera Station – Problema RAM al 90%](https://www.goline.ch/2022/06/22/axis-camera-station-problema-ram-al-90/): Aggiornando il software Axis Camera Station è capitato che dopo circa 30 minuti la RAM andasse al 90%Per risolvere la problematica è necessario rimuovere il database di log e farlo rigenerare.I passi sono i seguenti.1 - Ritornare indietro con la snapshot (se esiste)2 - Fermare il servizio Axis camera station3 - Rimuovere o rinominare il DB di log. - [VMware Horizon UAG, unlock Root e indexing with mlocate](https://www.goline.ch/2022/06/22/vmware-horizon-uag-unlock-root-e-indexing-with-mlocate/): Se dovesse bloccarsi l' account Root su horizon-uag, procedere in questo modo:Eseguire i seguenti passaggi per ripristinare una password di root:1)Riavviare il server. Questo deve essere fatto dalla console di gestione di vsphere o Hyper-V.. - [Veeam Endpoint Backup. : Failed to create snapshot](https://www.goline.ch/2022/06/22/veeam-endpoint-backup-failed-to-create-snapshot/): Come risolvere il problema Error code: Visualizza lo shadow storageVssadmin list shadowstorageCancella tutte le snapshotvssadmin delete shadows /allAumenta lo spazio per la snapshotvssadmin resize shadowstorage /For=C: /On=C: /MaxSize=50GBAumentare il timeout delle snapshotRegeditHKLMSoftware\Microsoft\Windows NT\CurrentVersion\SPP\CreateTimeoutThe - [Veeam Endpoint Backup – VSS error](https://www.goline.ch/2022/06/22/veeam-endpoint-backup-vss-error/): Risolto questo errore:Creating VSS snapshot Error: Failed to create snapshot: Backup job failed. Cannot create a shadow copy of the volumes containing writer's data. VSS asynchronous operation is not completed. Operation: . Code: . c:> vssadmin Resize ShadowStorage /For=C: /On=D: /MaxSize=UNBOUNDED - [Veeam Backup & Replication: Unable to truncate Microsoft SQL transaction logs](https://www.goline.ch/2022/06/22/veeam-backup-replication-unable-to-truncate-microsoft-sql-transaction-logs/): Per risolvere l'errore a causa della mancanza di supporto TLS 1.2 di SQL Server. - [Veeam Backup & Replication – Can’t install console](https://www.goline.ch/2022/06/22/veeam-backup-replication-cant-install-console/): The Console cannot be removed through the installer or by using Add/Remove in Windows. With the following steps, you can properly remove the Console and all its components and cleanup the install if needed. - [Upgrade Veeam database](https://www.goline.ch/2022/06/22/upgrade-veeam-database/): Step-by-step process should look like this:1. Download SQL Express 2008 R2 installation package from Microsoft.2. Save it to your hard disk.3. Stop all Veeam services.4. Stop all running jobs, including restore jobs, SureBackup jobs and Instant VM Recovery sessions.5. Open a CMD-Shell.6. Go to the download directory.7. - [Debug ISDN Cisco Voice Gateway](https://www.goline.ch/2022/06/22/debug-isdn-cisco-voice-gateway/): Debug ISDN Voice GatewayAttivare:debug isdn q931ter monDisattivare:u all - [Cisco Unified CUCM HTTPS and Firefox (ssl_error_weak_server_ephemeral_dh_key)](https://www.goline.ch/2022/06/22/cisco-unified-cucm-https-and-firefox-ssl-error-weak-server-ephemeral-dh-key/):  Go to about:config (vuol dire fai copia e incolla nell’address di about:config)search for security.ssl3.dhe_rsa_aes_128_sha and security.ssl3.dhe_rsa_aes_256_shaSet them both to false. - [Cisco Unified CCX Administration – Sincronizzazione numeri pilota](https://www.goline.ch/2022/06/22/cisco-unified-ccx-administration-sincronizzazione-numeri-pilota/): Server https://cucxx.buonvicini.local/appadmin/main I numeri pilota vengono creati automaticamente da Cisco Unified CCX Administration sul Call Manager   Assegnazione del trigger          Nel caso rimangano dei numeri non assegnati sul Call Manager eseguire la procedura di "Data Check e Data Resync"    Nel caso alcuni numeri rimangono ancora non as - [Cisco UCCX (Upgrade VMware Tools)](https://www.goline.ch/2022/06/22/cisco-uccx-upgrade-vmware-tools/): CLI:admin: utils os secure permissiveadmin: utils vmtools refreshadmin: utils os secure enforceoppure:CallManager CLIadmin: utils os secure permissiveVMware ,right click on hostright click on guest, select Install Upgrade VMware tools, select interactive upgrade then OKCallManager CLIadmin: utils vmtools refreshAfter warning that vmware tools is ou - [Cisco UCCX – Visualizzazione e cancellazione vecchie licenze](https://www.goline.ch/2022/06/22/cisco-uccx-visualizzazione-e-cancellazione-vecchie-licenze/):  Mostra licenza attualmente configuratashow uccx licenseMoltra tutte le licenze installateutils uccx list license Cancella licenze obsoleteutils uccx delete license Licenze: \fileserver01SoftwareCiscoCisco Contact Center Express (UCCX)Licenza - [Cisco voice gateway translation rule per numero Mobility in uscita](https://www.goline.ch/2022/06/22/cisco-voice-gateway-translation-rule-per-numero-mobility-in-uscita/):  Sul VG-02 di Zurigo sono state inserite le seguenti translation roules per mostrare il numero del chiamante sul telefono mobile (per chi ha la mobility attivata).ZURIGO VG-02voice translation-rule 3 rule 1 /^1(..)$/ /91641711/ rule 2 /^2(..)$/ /91261621/ rule 3 /^6(5.)$/ /91260761/ rule 4 /^6(..)$/ /91641661/ rule 5 /^9(.. - [Cisco Call Manager – Unassigned DN](https://www.goline.ch/2022/06/22/cisco-call-manager-unassigned-dn/): Nel call manager, per visualizzare la sezione dove vanno inseriti tutti i numeri inutilizzati da cancellare, andare su "Call Rounting - "Route Plan Report" - [Cisco Call Manager – CUCM Numeri di gruppo (line group)](https://www.goline.ch/2022/06/22/call-manager-cucm-numeri-di-gruppo-line-group/): Procedura per la creazione dei numeri di gruppo su Call ManagerPer la creazione di un numero di gruppo sono da completare tre configurazioni1. Line Group2. Hunt list3. Hunt pilot - [Call diversion su Cisco Voice Gateway per mostrare il numero chiamante originale](https://www.goline.ch/2022/06/22/call-diversion-su-cisco-voice-gateway-per-mostrare-il-numero-chiamante-originale/): ProblemaCon il trunk COLT quando si inserisce la mobility ed arriva una chiamata da un numero non Svizzero, sul display dello smartphone compare il numero radice del centralino. - [SysAid Help Desk: utilizzo provider SMS personalizzato](https://www.goline.ch/2022/06/22/sysaid-help-desk-utilizzo-provider-sms-personalizzato/): Per attivare un provider SMS personalizzato è necessario modificare un file.\helpdeskc$Program FilesSysAidServerrootWEB-INFconfModificare il seguente file: CustomSMSProvider.groovy In SysAid, sotto integrazione > SMS, bisogna modificare questo campo:Classe provider: com.ilient.util.ClickatellProviderin :com.ilient.util. - [Rinominare categorie/sottocategorie in SysAid Help Desk](https://www.goline.ch/2022/06/22/rinominare-categorie-sottocategorie-in-sysaid-help-desk/): In SysAid è possibile modificare sia le categorie che le sottocategorie.Per eseguire il rename bisogna andare sotto "Impostazioni Help Desk" > "Categorie".Filtrare la categoria o sottocategoria nella casella "Cerca".Selezionare la categoria/sottocategoria e premere il bottone "Più azioni". - [SysAid Helpdesk – Redirect http to https](https://www.goline.ch/2022/06/22/sysaid-helpdesk-redirect-http-to-https/): il file da modificare è web.xml che si trova sotto:C:/Program Files/SysAidServer/tomcat/confAggiungere il codice sotto prima della chiusura dell'ultimo tag .   Protected Context /* CONFIDENTIAL Riavviare il servizio SysAid server - [SysAid Help Desk – Redirection from port 80 to 443](https://www.goline.ch/2022/06/22/sysaid-help-desk-redirection-from-port-80-to-443/): C:Program FilesSysAidServertomcatconfweb.xml Add this to bottom before Automatic SSL Forward /* CONFIDENTIAL I also can't remember if I enabled this in the server.xml file: - [Veritas Backup Exec – CRC on deduplication stop/start/check (crcontrol)](https://www.goline.ch/2022/06/22/veritas-backup-exec-crc-on-deduplication-stop-start-check-crcontrol/): Problema CPU / Disabilitare CRC sull'unità di deduplication di BE20 C:Program FilesVeritasBackup Execcrcontrol.exe --crccheckon--crccheckstate--crccheckoff - [Veritas Backup Exec: change display language](https://www.goline.ch/2022/06/22/veritas-backup-exec-change-display-language/): To change the display language in Backup Exec 2012 edit the REG_SZ value Language (set 'DE' for german or for example 'EN' for english) inHKLMSOFTWARESymantecBackup Exec For WindowsBackup Execand start Backup Exec GUI - [MS SSRS won’t bind HTTPS to new certificate — “We are unable to create the certificate binding”](https://www.goline.ch/2022/06/22/ms-ssrs-wont-bind-https-to-new-certificate-we-are-unable-to-create-the-certificate-binding/): SSRS won’t bind HTTPS to new certificate — “We are unable to create the certificate binding” This blog post is around the situation where you have SSRS setup to use HTTPS and thus using a certificate and the certificate expires (or just needs replacing). - [MS SQL Server Version, SP, CU](https://www.goline.ch/2022/06/22/ms-sql-server-version-sp-cu/): Per conoscere la versione di SQL Server, della Service Pack e della CU (Cumulative Update) installata sul server SQL, eseguire la seguente query:SELECTSERVERPROPERTY('ProductVersion') AS ProductVersion,SERVERPROPERTY('ProductMajorVersion') AS ProductMajorVersion,SERVERPROPERTY('ProductMinorVersion') AS ProductMinorVersion,SERVERPROPERTY('ProductBui - [MS SQL Server – Shrink tempdb database](https://www.goline.ch/2022/06/22/ms-sql-server-shrink-tempdb-database/): In SQL Server Manager selezionare il database da shrinkareTasks > Shrink > Files   Sotto File type Selezionare Data e impostare manualmente la dimensione del database.L'operazione può essere eseguita anche sul file di LOG (sotto File type)   - [MS SQL Server: sp_processi, estensione della sp_who](https://www.goline.ch/2022/06/22/ms-sql-server-sp-processi-estensione-della-sp-who/): La stored procedure sp_processi è un’estensione di sp_who. Serve per visualizzare informazioni più dettagliate sui processi attivi in SQL Server. - [MS SQL Server: Query di controllo per vedere quali processi stanno girando](https://www.goline.ch/2022/06/22/ms-sql-server-query-di-controllo-per-vedere-quali-processi-stanno-girando/): sp_who2 -- tutte le sessioni sql sp_who2 active -- solo le sessioni attiveSELECTLocks.request_session_id AS SessionID,Obj.Name AS LockedObjectName,DATEDIFF(second,ActTra.Transaction_begin_time, GETDATE()) AS Duration,ActTra.Transaction_begin_time,COUNT(*) AS LocksFROM sys.dm_tran_locks LocksJOIN sys.partitions Parti ON Parti.hobt_id = Locks. - [MS SQL-SERVER: Errore in fase di creazione db SQL](https://www.goline.ch/2022/06/22/ms-sql-server-errore-in-fase-di-creazione-db-sql/): Se si ottiene l'errore seguente in fase di creazione db:An exception occurred while executing a Transact-SQL statement or batch. (Microsoft.SqlServer.ConnectionInfo)Could not obtain exclusive lock on database 'model'. Retry the operation later.CREATE DATABASE failed. Some file names listed could not be created. Check related errors. - [Sophos UTM problems with rrdcached](https://www.goline.ch/2022/06/22/sophos-utm-problems-with-rrdcached/):  Finally, the error went away after the db re-initializing.  What I did was 1) issued rm /var/log/reporting/rrd/* 2) issued /etc/init.d/syslogng restart 3) issued /etc/init.d/rrdcache restart ... see another error about wrong time ("illegal attempt to update using time...") 4) issued /etc/init.d/postgresql92 rebuild 5) issued /etc/init. - [Sophos UTM: usefull shell commands](https://www.goline.ch/2022/06/22/sophos-utm-usefull-shell-commands/): Remember: - [Come monitorare lo stato di Sophos RED via SSH in PRTG](https://www.goline.ch/2022/06/22/come-monitorare-lo-stato-di-sophos-red-via-ssh-in-prtg/): All'interno della directory /var/sec/chroot-httpd/tmp/red/server ci sono alcuni file con l'ID dei dispositivi RED.-rw-r--r-- 1 root root 4705 Sep 16 16:25 red_config_A320086FD64F0F4-rw-r--r-- 1 root root 4701 Sep 16 16:25 red_config_A32009F3A854FF7-rw-r--r-- 1 root root 5671 Sep 16 16:25 red_config_A3200F4751D00F8-rw-r--r-- 1 root root 5704 Sep 16 - [Comandi PowerShell Skype for Business Server](https://www.goline.ch/2022/06/22/comandi-powershell-skype-for-business-server/): # forza lo spostamento in un pool Move-CsUser -Identity "Caparrelli Paolo" -Target "skype.buonvicini.local" -Force# disattiva un utente (specialmente membro Domain Admins)Disable-CsUser -Identity "Caparrelli Paolo"# abilita un utenteEnable-CsUser -Identity "Caparrelli Paolo" - RegistrarPool "skype.buonvicini.local" -SipAddress "sip:paolo. - [SharePoint: Workaround errore “TypeError: Unable to get property replace of undefined or null reference”](https://www.goline.ch/2022/06/22/sharepoint-workaround-errore-typeerror-unable-to-get-property-replace-of-undefined-or-null-reference/): Come ovviare all'errore “TypeError: Unable to get property 'replace' of undefined or null reference” dovuto all'installazione dell'update Microsoft KB3114503. - [Update Server Sharepoint 2016](https://www.goline.ch/2022/06/22/update-server-sharepoint-2016/): !!!Prima di cominciare eseguire una Snapshot del sistema!!!===================================================================================.Eseguire gli aggiornamenti in Windows Update che potranno andare ad aggiornare sia il S. - [SharePoint: problema: Accesso non consentito a pagina principale (Masterpage, Default site page)](https://www.goline.ch/2022/06/22/sharepoint-problema-accesso-non-consentito-a-pagina-principale-masterpage-default-site-page/): Verificare le permission utente nei seguenti punti: 1.2.Verificare le autorizzazioni delle cartelle che contengono la Master Page e la Default Site Page e degli stessi files (nel nostro caso seattle.html e Intranet.aspx) MasterPage: https://intranet.goline.ch/sites/intranet/_catalogs/masterpage   Default Site Page: https://intranet.goline. - [SharePoint2016: problema: File bloccato da un altro utente](https://www.goline.ch/2022/06/22/sharepoint2016-problema-file-bloccato-da-un-altro-utente/): La situazione non è ancora chiara e visto che il problema si è presentato una sola volta e non è stato possibile riprodurlo. È stata eseguita la seguente operazione: La procedura é sperimentale e deve ancora essere testata ulteriormente su casi reali. - [SharePoint2013: problema: Menù SP Espolorazione gestita non più visibile](https://www.goline.ch/2022/06/22/sharepoint2013-problema-menu-sp-espolorazione-gestita-non-piu-visibile/): Il menù in alto di SharePoint non è più visibile:       Workaround per mettere immediatamente a disposizione il sito SP:   Dal sito principale https://intranet.goline.ch/sites/intranet accedere alle impostazioni:             Selezionare la struttura classica e salvare         Fine. - [Sharepoint Error: CurrentSiteCount 0](https://www.goline.ch/2022/06/22/sharepoint-error-currentsitecount-0/): Lanciando un Get-SPContentDatabase, il site count di un sito risulta 0, quindi non si apre la pagina.Questo perchè la WebApp non ha il corretto puntamento al database. Questo il comando che risolve:Mount-SPContentDatabase "portal.b-horses.com" -DatabaseServer "SPP2016" -WebApplication https://portal.ettore.wine - [Search service SharePoint not working](https://www.goline.ch/2022/06/22/search-service-sharepoint-not-working/): Verificare il servizio    http://buse-spp01:8888/_admin/Server.aspx   Verificare se SharePoint Server Search é avviato   Accedere al Search service Application   http://buse-spp01:8888/searchadministration.aspx?appid=f45e2a1b-6e53-46ce-878e-2ded21ba5572   Verificare se ci sono errori   - [SharePoint Server: problema: File non caricabili in una cartella – visualizzare i file estratti (check out) in una DocLib di tutti gli utenti](https://www.goline.ch/2022/06/22/sharepoint-server-problema-file-non-caricabili-in-una-cartella-visualizzare-i-file-estratti-check-out-in-una-doclib-di-tutti-gli-utenti/): Selezionare > Gestisci file per cui non è disponibile una versione archiviata - [SharePoint : problema: un sottosito specifico non viene visualizzato (impossibile trovare pagina web)](https://www.goline.ch/2022/06/22/sharepoint-problema-un-sottosito-specifico-non-viene-visualizzato-impossibile-trovare-pagina-web/): Può capitare che un sottosito non venga visualizzato e dia l’errore “impossibile trovare pagina web”Questo si applica unicamente a un sottosito e non all’intero SP non funzionanteQuesta problematica può capitare se viene cancellato il file default.aspx che è contenuto in un sottosito. Ad esempio https://spp.goline. - [Rinominare Web App e URL in sharepoint](https://www.goline.ch/2022/06/22/rinominare-web-app-e-url-in-sharepoint/): Rinominare WebAPP:$webname = Get-SPWebApplication | Where {$_.Name -match "SharePoint - 443 - B-Horses Portal"} $webname.Name = "SharePoint - 443 - Ettore Wine Portal"  $webname.Update()Rinominare URL:Go to: Central Administration >> System Settings >> Configure alternate access mappings under Farm Management. Pick your web application and give a new URL to it. - [Binding tra Sharepoint e Office Online Service](https://www.goline.ch/2022/06/22/binding-tra-sharepoint-e-office-online-service/): Vademecum Office Online Server#Disconnect SP from OOS (remove binding to web office):Remove-SPWOPIBinding -All:$true#Per reimpostare il server Office OnlineNew-SPWOPIBinding -ServerName office.goline.chSet-SPWOPIZone -zone "external-https"#Per utilizzare la parte legacy dei documenti Office$Farm = Get-SPFarm$Farm.Properties. - [Utilizzo PGP (Creazioni chiavi – upload – revocation)](https://www.goline.ch/2022/06/22/utilizzo-pgp-creazioni-chiavi-upload-revocation/): Installazione del PGPInstallati il gpg4win che è freeware e si trova qui: https://www.gpg4win.org/L'interfaccia per creare i certificati OpenPGP si chiama Kleopatra ed è inserita nella distribution standard di gpg4win.Vai in > Settings > Directory Services e fai New (OpenPGP) - Ti metterà quello standard. - [SSL Error: ssl_error_weak_server_ephemeral_dh_key](https://www.goline.ch/2022/06/22/ssl-error-ssl-error-weak-server-ephemeral-dh-key/):  (1) In a new tab, type or paste about:config in the address bar and press Enter. Click the button promising to be careful.(2) In the search box above the list, type or paste dhe and pause while the list is filtered(3) Double-click the security.ssl3. - [Getting an A+ on the Qualys SSL Test – Windows Edition](https://www.goline.ch/2022/06/22/getting-an-a-on-the-qualys-ssl-test-windows-edition/): My previous article gained a lot of attention as a reference point on how to score the highest A+ rating on the Qualys SSL Test. - [Creazione certificato multi SAN per IPAM (OpUtils)](https://www.goline.ch/2022/06/22/creazione-certificato-multi-san-per-ipam-oputils/): Eliminare tutti i certificati precedenti dal file contenitore di IPAM C:Program FilesManageEngineOpUtilsconfserver.keystore   Creazione chiave privata locale Andare nella cartella C:Program FilesJavajre7bin in modalità DOS keytool -genkey -alias ipam -keyalg RSA -keysize 2048 -sigalg SHA256withRSA -keystore server.keystore -ext san=dns:ipam. - [Certificate conversion SSL/PFX/DER](https://www.goline.ch/2022/06/22/certificate-conversion-ssl-pfx-der/): How to convert a certificate into the appropriate formatSolutionIf your server/device requires a different certificate format other than Base64 encoded X.509, a third party tool such as OpenSSL can be used to convert the certificates into the appropriate format.For information on OpenSSL please visit: www.openssl. - [Ubiquiti UniFi AP-Pro: Incompatible Country Settings](https://www.goline.ch/2022/06/22/ubiquiti-unifi-ap-pro-incompatible-country-settings/): I assume you are using 5.6.18+ since that is when the warnings was implemented.  If you use the 5.5 series, it will not have it. If this is correct and no warnings, that would mean you have the correct version. To double check the version you have  Type this in CLI on each of your APs. grep regdmn /proc/ubnthal/system. - [UniFi – Evento EVT_conntrack_full su Access Point](https://www.goline.ch/2022/06/22/unifi-evento-evt-conntrack-full-su-access-point/): Nel caso si ricevea un altrt da UniFi con l'evento EVT_conntrack_full, vuol dire che c'é un client collegato al WiFI che fa una scansione degli IP. - [Ubiquiti UniFi Controller: problema della WiFi Guest che non mostra il captive portal](https://www.goline.ch/2022/06/22/ubiquiti-unifi-controller-problema-della-wifi-guest-che-non-mostra-il-captive-portal/): ProblemaQuando un client si collega alla rete Guest ottiene correttamente l'IP in DHCP ma non gli si apre la pagina di autenticazione Unifi Captive Portal - [Ubiquiti UniFi Controller – Aggiornamento su Ubuntu Server](https://www.goline.ch/2022/06/22/ubiquiti-unifi-controller-aggiornamento-su-ubuntu-server/): Metodo più praticoDownload direttamente dal controller del file .deb che poi va caricato sotto la tmp del server Ubuntu.Infine sudo dpkg -i path_to_deb_fileMostra installazione corrente:  apt-cache policy unifiDirectory di installazione:/usr/lib/unifiScript di instalazione: wget https://get.glennr.nl/unifi/update/unifi-update. - [SNMP Monitoring APC UPS – Useful OIDs](https://www.goline.ch/2022/06/22/snmp-monitoring-apc-ups-useful-oids/): Monitoring APC UPS - Useful OIDs Battery capacity1.3.6.1.4.1.318.1.1.1.2.2.1.0Value type Gauge FloatDivision = 1Value %Run Time Remaining1.3.6.1.4.1.318.1.1.1.2.2.3.0Value type Gauge IntegerDivision = 6000Value minutesBattery Temperature1.3.6.1.4.1.318.1.1.1.2.3.2.0Value type Gauge FloatDivision = 10Value °Battery Actual Voltage1.3.6.1.4.1.318.1.1. - [Windows IPv6 – Disabling router autodiscovery](https://www.goline.ch/2022/06/22/windows-ipv6-disabling-router-autodiscovery/): Quick mode:netsh int ipv6 set int "Ethernet" routerdiscovery=disablednetsh int ipv6 set int "Ethernet" managedaddress=disabled Visualizzare gli indici delle interfaccenetsh int ipv6 show intMostra i setting (compreso managedaddress)netsh int ipv6 show int Cancellare un IPnetsh int ipv6 delete address 17 2001:67c:13fc::1:2b9enetsh int ipv6 delete ad - [Hide DNS Software Version](https://www.goline.ch/2022/06/22/hide-dns-software-version/): Hide DNS Software VersionSometimes a new vulnerability is found in DNS software and script kiddies are scanning the Internet to exploit unpatched systems. It's a best practice to hide software version on your DNS servers, although this is not a real protection it just makes a little harder to find your servers via scanning. - [Exclude NETBIOS prefix registration of a NIC on machines in DMZ](https://www.goline.ch/2022/06/22/exclude-netbios-prefix-registration-of-a-nic-on-machines-in-dmz/): “HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpipParametersDNSRegisteredAdapters” then that adapter will register in DNS unless you put a registry      “DisableDynamicUpdate” in  “TcpipParametersInterfaceGUID” key of      that adapter. - [Enabling IPv6 on Barracuda Spam Firewall](https://www.goline.ch/2022/06/22/enabling-ipv6-on-barracuda-spam-firewall/): Aggiungere &expert=1 al URL della WebGUI in qualsiasi tab.Sotto Advanced tab apparirà "Expert Settings", un nuovo menù in rosso.Li dentro si può attivare l'IPv6. - [Disabilitare allarmi garanzia su UPS APC](https://www.goline.ch/2022/06/22/disabilitare-allarmi-garanzia-su-ups-apc/):  Premere un tasto per entrane nel menùSelezioanre LCMVerificare quali allarmi sono attiviEntrare in Set Allarmi e disabilitare l'allare "Garanzia scaduta"   - [Linux – Detecting DDOS Attacks (tcpdump)](https://www.goline.ch/2022/06/22/linux-detecting-ddos-attacks-tcpdump/):  # visualizza tutte le connessioni che comprendano l'host prtg.goline.chtcpdump -i ens160 host prtg.goline.ch# visualizza tutti i pacchetti syn in ingressotcpdump -i ens160 -n tcp == tcp-syn# visualizza tutti i pacchetti provenienti da uno specifico host come sorgente (src)tcpdump -i ens160 src host prtg.goline. - [Configuring w32tm on DC/GC Windows (ntp)](https://www.goline.ch/2022/06/22/configuring-w32tm-on-dc-gc-windows-ntp/):  w32tm /config /manualpeerlist:”ntp.goline.ch,ntp2.goline.ch” /reliable:yes /updatew32tm /config /manualpeerlist:,0x8 /syncfromflags:MANUAL The actual IP address of the NTP server or its host name must be entered instead of . - [Come aggiungere una rotta IPv6 su Windows](https://www.goline.ch/2022/06/22/come-aggiungere-una-rotta-ipv6-su-windows/): Come aggiungere una rotta IPv6 su WindowsSintassi:netsh interface ipv6 add route ipv6 address / integer string] ipv6 address] integer] Integer] {no | yes | immortal}] {Integer | infinite}] {integer | infinite}] {active | persistent}]Sintassi: netsh interface ipv6 add route store=persistentEsempio 1:netsh interface ipv6 add route 2a02:4460:1:1::/64 - [Apache2: Could not reliably determine the server's fully qualified domain name](https://www.goline.ch/2022/06/22/apache2-could-not-reliably-determine-the-servers-fully-qualified-domain-name/): Create: /etc/apache2/conf-available/fqdn.confAdd: ServerName wiki.goline.chThen execute this command:ln -s /etc/apache2/conf-available/fqdn.conf /etc/apache2/conf-enabled/fqdn.confand restart Apache2: service apache2 restart - [Abilitare IPv6 su Windows 10 in remoto](https://www.goline.ch/2022/06/22/abilitare-ipv6-su-windows-10-in-remoto/): Questo script abilita in PowerShell remoto l'IPv6 sulla scheda ethernetInvoke-Command -FilePath \buse005netlogonEnableIPv6.ps1 -ComputerName GOEM05Enable-NetAdapterBinding -Name "Ethernet" -ComponentID ms_tcpip6 - [MikroTik RouterOS – Utilizzare discover solo su’interfaccia specifica](https://www.goline.ch/2022/06/22/mikrotik-routeros-utilizzare-discover-solo-suinterfaccia-specifica/): Per evitare di avere disturbi sull'interfaccia pubblica degli IXP è meglio utilizzare la sola interfaccia interna.Questa guida spiega come creare una lista di interfacce chiamata only-sfp-sfpplus12, inserire l'interfaccia fisica come membro della lista ed attivare il discover MikroTik solo su quella. - [MikroTik Routerboard downgrade procedure](https://www.goline.ch/2022/06/22/mikrotik-routerboard-downgrade-procedure/): Yes, you can downgrade RouterOS, but only until the factory installed version, which you can check with this command: /system/routerboard/printThe factory-firmware is the oldest version supported by this device.Before contemplating a downgrade procedure, remember that older versions can contain bugs and security issues. - [Manage static routes on Mikrotik](https://www.goline.ch/2022/06/22/manage-static-routes-on-mikrotik/): Visualizzare la configurazione con il comando > exportPer aggiungere una rotta: ip routeadd distance=1 dst-address=185.54.81.0/24 gateway=185.54.80.30ipv6 routeadd distance=1 dst-address=2a02:4460:1::/48 gateway=2a02:4460::30Per rimuovere una rotta:/ip route remove Anche se restituisce l'errore: failure: can remove only static routes , la rotta vie - [Comandi basici BGP su MikroTik](https://www.goline.ch/2022/06/22/comandi-basici-bgp-su-mikrotik/): Visualizza received routes ip route print where received-from=ipv6 route print where received-from=ip route print where received-from=PEER_GGAMAUR_V4_1V7/ip/route/print where gateway="185.54.80.1"Visualizza GW per una routeip route print where dst-address in ipv6 route print where dst-address in ip route print where dst-address in 130.59.138. - [Aggiunta rotte statiche per le reti DMZ (MikroTik)](https://www.goline.ch/2022/06/22/aggiunta-rotte-statiche-per-le-reti-dmz-mikrotik/): #Aggiunge una destinazione per tutte le reti della DMZ /ip routeadd distance=1 dst-address=185.54.81.0/24 gateway=185.54.80.30add distance=1 dst-address=185.54.82.0/24 gateway=185.54.80.30add distance=1 dst-address=185.54.83.0/24 gateway=185.54.80.30/ipv6 routeadd distance=1 dst-address=2a02:4460:1::/48 gateway=2a02:4460::30 - [Libraesva ESG: Message contained password-protected archive (workaround)](https://www.goline.ch/2022/06/22/libraesva-esg-message-contained-password-protected-archive-workaround/): Problema:Per default gli archivi ZIP protetti da password vengono bloccati con messaggio "Message contained password-protected archive"Risoluzione:Aggiungere una regola di "Allow" in System - Content Analysis - Attachment Filters - Archive Check Rules - Password Protected Archives - [Yum remove old kernels (CentOS)](https://www.goline.ch/2022/06/22/yum-remove-old-kernels-centos/): 1. Check Installed Kernelsrpm -q kernelkernel-2.6.32-279.el6.x86_64kernel-2.6.32-279.2.1.el6.x86_64kernel-2.6.32-279.5.2.el6.x86_64kernel-2.6.32-279.9.1.el6.x86_642. - [Trova file (find) su Linux con ricerca stringa e sottodirectory](https://www.goline.ch/2022/06/22/trova-file-find-su-linux-con-ricerca-stringa-e-sottodirectory/): Trova tutti i file a partire dalla cartella /usr/share/pydio, comprese le sottodirectory, che contengono la stringra "ribrica"grep -R "ribrica" /usr/share/pydio/ - [Linux – Setting permissions to 755 dirs and 644 files (recursive)](https://www.goline.ch/2022/06/22/linux-setting-permissions-to-755-dirs-and-644-files-recursive/): #Setting permission to all directories and subdirectories to 755find /var/www -type d -print0 | xargs -0 chmod 755#Setting permission to all files in subdirectories to 644find /var/www -type f -print0 | xargs -0 chmod 644 - [Remote SSH root login with Ubuntu 12.04](https://www.goline.ch/2022/06/22/remote-ssh-root-login-with-ubuntu-12-04/): Enabling the root account to access ssh directly is a major security risk. However, you can enable it if you like to do so by doing the steps below:Edit the sshd_config file by sudo vi /etc/ssh/sshd_configFind the line PermitRootLogin no and change it to PermitRootLogin yes.Restart the ssh service by sudo /etc/init. - [Reinstall expired key of a Linux repo](https://www.goline.ch/2022/06/22/reinstall-expired-key-of-a-linux-repo/):  You don't need to reinstall the mongo packages, but just change the key as following:List the keys to confirm it is expired:apt-key list | grep "expired:"Replace the key:sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 0xd68fa50fea312927 - [Pulizia dei vecchi kernel su Ubuntu](https://www.goline.ch/2022/06/22/pulizia-dei-vecchi-kernel-su-ubuntu/):  Utilizzare il comando: apt-get autoremoveCon questo invece si può visualizzare la lista dei kernel installati:dpkg -l 'linux-*' | sed '/^ii/!d;/'"$(uname -r | sed "s/(.*)-(+)/1/")"'/d;s/^* * (*).*/1/;//!d' apt-get -y purge  NOTA: esegui un uname -r per evitare di cancellare il kernel in uso. - [PRTG: Monitorare singoli processi Linux](https://www.goline.ch/2022/06/22/prtg-monitorare-singoli-processi-linux/): ProblemaSi vogliono monitorare singoli processi Linux con PRTG ad esempio Unifi, cPanel, Exim - [ProFTPd with TLS support on Ubuntu](https://www.goline.ch/2022/06/22/proftpd-with-tls-support-on-ubuntu/): How to install ProFTPd with TLS support on Ubuntu 15.04On this page1 Preliminary Note2 Install ProFTPd and OpenSSL3 Create the SSL Certificate for TLS4 Enable TLS in ProFTPd5 Add an FTP user6 Configuring FileZilla for TLS7 LinksFTP is a very insecure protocol because all passwords and all data are transferred in clear text. - [OoklaServer – Speedtest server](https://www.goline.ch/2022/06/22/ooklaserver-speedtest-server/): Riavviare il servizio quando si è rootsudo -H -u ooklauser bash -c './ooklaserver.sh restart' - [MySQL – Password reset (#1045 – Access denied for user root@localhost (using password: YES))](https://www.goline.ch/2022/06/22/mysql-password-reset-1045-access-denied-for-user-rootlocalhost-using-password-yes/): Commandssudo /etc/init.d/mysql stopNow start up MySQL in safe mode, so you'll skip the privileges table:sudo mysqld_safe --skip-grant-tables &Login with root:mysql -urootAnd assign the DB that needs to be used:use mysql;Now all you have to do is reset your root password of the MySQL user and restart the MySQL service:update user set password=PASSWO - [Linux TTY resolution](https://www.goline.ch/2022/06/22/linux-tty-resolution/): Karmic Koala has switched to GRUB 2, and now the settings can be found in the file /etc/default/grubResolutions available to GRUB 2 can be displayed by typing vbeinfo in the GRUB 2 command line. The command line is accessed by typing "c" when the main GRUB 2 menu screen is displayed. - [Linux LVM Disk](https://www.goline.ch/2022/06/22/linux-lvm-disk/): Visualizzare i dischi fisici e le partizionifdisk -llsblkpvscan (mostra spazio libero) - [Linux – dischi pieni, ricerca delle cartelle e dei files che occupano il disco](https://www.goline.ch/2022/06/22/linux-dischi-pieni-ricerca-delle-cartelle-e-dei-files-che-occupano-il-disco/): Comandidf - report file system disk space usage  (Linux manual)du - estimate file space usage (Linux Manual) - [Kill a zombie process on Ubuntu](https://www.goline.ch/2022/06/22/kill-a-zombie-process-on-ubuntu/): To kill a zombie (process) you have to kill its parent process (just like real zombies!), but the question was how to find it.Find the zombie (The question answered this part):a@SERVER:~$ ps aux | grep 'Z'What you get is Zombies and anything else with a Z in it, so you will also get the grep:USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMANDuse - [Installing VMware Tools in an Ubuntu virtual machine](https://www.goline.ch/2022/06/22/installing-vmware-tools-in-an-ubuntu-virtual-machine/): To install VMware Tools, you must mount the VMware Tools CD image, extract the contents (VMware Tools), and then run the installer.To uninstall:  vmware-uninstall-tools.pl Note: If VMware Tools is already installed, these steps uninstall and then reinstall VMware Tools. - [Installare vsftpd su Ubuntu Server](https://www.goline.ch/2022/06/22/installare-vsftpd-su-ubuntu-server/): File Transfer Protocol (FTP) è un protocollo TCP per scaricare file tra computer: in passato è stato usato anche per il caricamento ma, considerato che questo metodo non utilizza la cifratura, sia le credenziali dell'utente che i dati sono trasferiti in chiaro e facilmente intercettati. - [Install Webmin and CSF on Linux Ubuntu](https://www.goline.ch/2022/06/22/install-webmin-and-csf-on-linux-ubuntu/): *.=info;*.=notice;*.=warn;auth,authpriv.none;cron,daemon.none;mail,news.none -/var/log/messages - [iftop – display bandwidth usage on an interface by host](https://www.goline.ch/2022/06/22/iftop-display-bandwidth-usage-on-an-interface-by-host/): Nameiftop - display bandwidth usage on an interface by hostSynopsisiftop -h | Description iftop listens to network traffic on a named interface, or on the first interface it can find which looks like an external interface if none is specified, and displays a table of current bandwidth usage by pairs of hosts. - [How do you empty the buffers and cache on a Linux system?](https://www.goline.ch/2022/06/22/how-do-you-empty-the-buffers-and-cache-on-a-linux-system/): If you ever want to empty it you can use this chain of commands.# free && sync && echo 3 > /proc/sys/vm/drop_caches && free# free && sync && echo 3 > /proc/sys/vm/drop_caches && free total used free shared buffers cachedMem: 1018916 980832 38084 0 46924 355764-/+ buffers/cache: 578144 440772Swap: 2064376 128 2064248 total used free shared buffers c - [Enable var/log/messages on Ubuntu](https://www.goline.ch/2022/06/22/enable-var-log-messages-on-ubuntu/): How to enable /var/log/messages in UbuntuIn this article we will show you how to enable Var Log  messages in Ubuntu.By default log messages are not written to the file /var/log/messages in Ubuntu. In order to enable this, we can do the following:Go to /etc/rsyslog.d. Open the file 50-default.conf and uncomment the following lines*.=info;*. - [Dump IPTABLES on Ubuntu](https://www.goline.ch/2022/06/22/dump-iptables-on-ubuntu/): Examines all traffic on the ens160 card and filters it by xxx#tcpdump -i ens160 -n | grep xxxExamine connections on the ens160 board that are not on port 22 or 10000#tcpdump -i ens160 port not 22 and port not 10000Review the log of connections blocked by IPTABLES#tail -f /var/log/kern.log - [Disable weak TLS and SSL on Apache2 e SSLHonorCipherOrder on. A+!!!!](https://www.goline.ch/2022/06/22/disable-weak-tls-and-ssl-on-apache2-e-sslhonorcipherorder-on-a/): Enable apache headers modulea2enmod headersApache2 configuration file (/etc/apache2/sites-available00-default.conf)ServerAdmin webmaster@localhostDocumentRoot /var/www/html AllowOverride AllSSLEngine onSSLCertificateFile /etc/ssl/star_goline_ch.crtSSLCertificateKeyFile /etc/ssl/server.keySSLCertificateChainFile /etc/ssl/DigiCertCA. - [Disabilitare IPv6 autoconfiguration su Ubuntu Server](https://www.goline.ch/2022/06/22/disabilitare-ipv6-autoconfiguration-su-ubuntu-server/):  # /etc/sysctl.conf - Configuration file for setting system variables# See /etc/sysctl.d/ for additional system variables.# See sysctl.conf (5) for information.net.ipv6.conf.all.accept_ra=0net.ipv6.conf.all. - [ConfigServer CSF command line](https://www.goline.ch/2022/06/22/configserver-csf-command-line/): This article covers some useful CSF SSH Command Line Commands in a “cheat sheet” format.CommandDescriptionExamplecsf -sStart the firewall rulesroot@server#csf -scsf -fFlush/Stop firewall rules (note: lfd may restart csf)root@server#csf -fcsf -rRestart the firewall rulesroot@server#csf -rcsf -a Allow an IP and add to /etc/csf/csf. - [Configurazione e aggiornamento di PHP su Apache2](https://www.goline.ch/2022/06/22/configurazione-e-aggiornamento-di-php-su-apache2/): # Pacchetti PHP installati nel sistemaapt list --installed | grep -i php# Per disinstallare tutti i componenti php5apt-get purge php5*# Sostituzione PHP in Apache2 dalla versione 7.1 alla 7.2a2dismod php7.1a2enmod php7.2service apache2 restartAggiunta della command Line:update-alternatives --set php /usr/bin/php7. - [Configure FTP (vsFTPd) to use TLS/SSL connections only.](https://www.goline.ch/2022/06/22/configurare-ftp-vsftpd-o-proftp-per-lutilizzo-esclusivo-di-connessioni-tls-ssl/): root@www05:~#cd /etc/ssl/privateroot@www05:/etc/ssl/private#openssl req -x509 -nodes -newkey rsa:1024 -keyout /etc/ssl/private/vsftpd.pem -out /etc/ssl/private/vsftpd.pemGenerating a 1024 bit RSA private key......++++++.......++++++writing new private key to '/etc/ssl/private/vsftpd. - [Comando logrotate su Linux](https://www.goline.ch/2022/06/22/comando-logrotate-su-linux/): #Rotazione log con il comando logrotateLe configurazioni singole dei rotate log sono nella cartella /etc/logrotate.dBisogna creare i file specificando nella prima riga su quale log file dovrà operare.Questo che segue è un esempio di script (file > /etc/logrotate.d/modsec)/var/log/apache2/modsec_audit. - [Change Ubuntu keymap and timezone](https://www.goline.ch/2022/06/22/change-ubuntu-keymap-and-timezone/): dpkg-reconfigure keyboard-configurationdpkg-reconfigure tzdata  - [SQL Server Mail Database Configuration](https://www.goline.ch/2022/06/22/sql-server-mail-database-configuration/): Steps to configure mail database on SQLSERVERConfigure Mail Database   If not already done, reopen the Mail Database configuration and set the Public and Private profiles  And enable public and private profiles    Entering SQL Server Agent Properties  In Alert System inserire Mail system e Mail profile  Create the operator  In the Job enter the ope - [Allow linux root user mysql root access without password](https://www.goline.ch/2022/06/22/allow-linux-root-user-mysql-root-access-without-password/):  Use e a client section of the ~/.my.cnf file, and add the credentials there.Set: chmod 600 ~/.my.cnfuser=rootpassword=somepassword - [Procedura (sperimentale) per creare un sensore sessione BGP IPv6 su PRTG per Juniper](https://www.goline.ch/2022/06/22/procedura-sperimentale-per-creare-un-sensore-sessione-bgp-ipv6-su-prtg-per-juniper/):   - [Zebra printer: Errore di fine carta](https://www.goline.ch/2022/06/22/zebra-printer-errore-di-fine-carta/): La Zebra ZT410 presenta un problema, quando si cambia tipo di ribbon va spenta e riaccesa per eseguire la calibrazione correttamente.Ogni 2-3 accensioni perde l'impostazione di "Tipo Di Sensore", al posto di "Riga Scura" torna ad "Interspazio".Bisogna quindi entrare nell'interfaccia web nella sezione "Configurazione Supporto di Stampa"->"Tipo di Sensore"->"Riga Scura". - [Stampanti Zebra: disabilitare SNMP e comandi SGD (Set-Get-Do Commands)](https://www.goline.ch/2022/06/22/stampanti-zebra-disabilitare-snmp-e-comandi-sgd-set-get-do-commands/): L'SNMP continua ad inviare trap in broadcast, ma la Zebra non ha nessun settaggi che gli dica di inviare gli Allarmi via SNMP. - [Reset errori su stampanti Canon imageRUNNER ir](https://www.goline.ch/2022/06/22/reset-errori-su-stampanti-canon-imagerunner-ir/): La seguente procedura viene utilizzata per eliminare l'errore che blocca le stampe. In determinate condizioni (tipo alta temperatura o altri errori) non c'è più la possibilità di stampante. Nemmeno riavviando la stampante funzionerà di nuovo.Con questa procedura è possibile sbloccare il meccanismo e riprendere a stampare. - [QNAP – What is “[SNMP] DoS detected” system log message?](https://www.goline.ch/2022/06/22/qnap-what-is-snmp-dos-detected-system-log-message/): This message will be generated when over 300 packets per second are received by the SNMP service.If you want to change this behaviour, there are 2 configurable fields in the section of uLinux.conf:EnableDetectDDoSMaxPacketPerSecondThe default value of EnableDetectDDoS is TRUE.The default value of MaxPacketPerSecond is 300.If you want to disable the DoS detection, then run the below command:# setcfg SNMP EnableDetectDDoS FALSEIf you want to increase the maximum number of packets, then run the below command (XXX is the maximum packets per second):# setcfg SNMP MaxPacketPerSecond XXXRemember to restart SNMP after changing these settings.# /etc/init.d/snmp restart  - [Changing default boot menu selection in DSS V7](https://www.goline.ch/2022/06/22/changing-default-boot-menu-selection-in-dss-v7/): When you manually copy files to USB pendrive or different boot medium a system will boot in installer mode by default.Best way to avoid it is to use installer to prepare boot drives, although if necessary changing default boot menu selection is also possible manually:Please mount USB key in Linux or Windows system and use text editor, which underst - [Fortinet Fortigate: URLs on ports 8008, 8011 and 8020 don’t work](https://www.goline.ch/2022/06/22/fortinet-fortigate-gli-url-sulle-porte-8008-8011-e-8020-non-funzionano/): Issue:When you open a site with ports 8008, 8011 and 8020, it will not openExample: Gesinflotweb - [FileAudit error during software update](https://www.goline.ch/2022/06/22/fileaudit-error-during-software-update/): If during the software update you get this error just after extracting the installation file, you should proceed as follows."Error applying transforms. Verify that the specified transform paths are valid"FIX:1. Open Run with the Windows key + R hotkey. 2. Enter ‘regedit’ in Run’s text box and press Return to open the Registry Editor.3. - [MS Exchange: Removes the specified email domain from all contacts in the OU](https://www.goline.ch/2022/06/22/ms-exchange-removes-the-specified-email-domain-from-all-contacts-in-the-ou/):  #Disable Address Policy on every contact in the OU (buonvicini.local/Exchange/Recipients External).Get-MailContact -OrganizationalUnit "myorg.org/Exchange/Recipients External" | Set-MailContact -EmailAddressPolicyEnabled:$false # Removes the specified email domain from all contacts in the OU (myorg.org/Exchange/Recipients External). - [Libraesva ESG: how to logout from Outlook/OWA ESG plugin](https://www.goline.ch/2022/06/22/libraesva-esg-how-to-logout-from-outlook-owa-esg-plugin/): IssueWhen you log into the Libraesva ESG plugin in Outlook or OWA, you can no longer log out. - [MS Exchange: managing certificates of connectors or auth server](https://www.goline.ch/2022/06/22/ms-exchange-managing-certificates-of-connectors-or-auth-server/): Issue:See/change certificates to Exchange connectors or AUTH serverGet all certificatesGet-ExchangeCertificateGet Microsoft Exchange Server Auth Certificate onlyGet-AuthConfig | fl(Get-AuthConfig). - [MS Exchange: changing the default mailbox database](https://www.goline.ch/2022/06/22/ms-exchange-changing-the-default-mailbox-database/): Displays the status of default provisioning of mailboxes:Get-MailboxDatabase -Server EXCHANGE19| select Name,ServerName,IsExcludedFromProvisioningSet a mailbox as excluded from provisioning by default:Set-MailboxDatabase "Public Folders Database 2019" -IsExcludedFromProvisioning $trueNote: even if excluded from default provisioning you can always s - [MS Exchange: increase the share of mailbox rules](https://www.goline.ch/2022/06/22/ms-exchange-increase-the-share-of-mailbox-rules/): set-mailbox -RulesQuota: 256KBRequires the inbox identity parameter: GUID or email or aliasValues from 32BK to 256KBhttp://technet.microsoft.com/it-it/library/bb123981.aspxDisplay the current quotaGet-Mailbox | ft DisplayName,RulesQuota - [MS Exchange Public Folder Quota: no mail forward](https://www.goline.ch/2022/06/22/ms-exchange-public-folder-quota-no-mail-forward/): When forwarding or folder rules no longer work (c.v. type with reply message) check this information:The public folder mailbox is like a user mailbox, so with limits on receiving and blocking send messages if a certain quota is reached. - [MS Exchange DAG Maintenance error (exiting from script)](https://www.goline.ch/2022/06/22/ms-exchange-dag-maintenance-error-exiting-from-script/): Today, on a DAG maintenance of an Exchange 2016, I ran into the problem that after executing the script StopDagServerMaintenance.ps1 a warning was displayed. - [MS Exchange – Search email event log](https://www.goline.ch/2022/06/22/ms-exchange-search-email-event-log/): Message log in Exchange - [MS Exchange: Dual SMTP email](https://www.goline.ch/2022/06/22/ms-exchange-dual-smtp-email/): If you have an Exchange account with multiple addresses assigned to it, the above methods will not work. The first method often doesn’t work because configuring your Exchange account as an additional POP3 account usually isn’t allowed. - [MS Exchange: Disable Read Receipts replies exiting our organization](https://www.goline.ch/2022/06/22/ms-exchange-disable-read-receipts-replies-exiting-our-organization/): Create a transport rule. So go into Organization Config ---> Hub Transport ---> Transport Rules tab On the right, click New Transport Rule Give it a name In the conditions scroll down and select "if the message type is Message Type" Change the message type to Read Receipt (add exception if you want) press Next scroll down to the bottom of Actions a - [MS Exchange: Check and recreate Exchange health mailboxes](https://www.goline.ch/2022/06/22/ms-exchange-check-and-recreate-exchange-health-mailboxes/): DAG databases keep switching servers by themselves is a new feature of Exchange 2016 CU2. If you have a pre-Exchange 2016 CU2 server and it’s switching over automatically, then there is another issue. What you need to do is to check the Exchange health mailboxes. - [MS Exchange: Add owner to distribution/security/dynamic groups](https://www.goline.ch/2022/06/22/ms-exchange-add-owner-to-distribution-security-dynamic-groups/): With the Set-DistributionGroup command and the pipe above, select all groups and then apply the property to AdministratorGet-DistributionGroup | Set-DistributionGroup -managedby "System Administrator"The next example, on the other hand, is much more selective:Get-DistributionGroup -Managedby "xxxx" | Set-DistributionGroup -managedby "xxxx"Finally, - [Microsoft Exchange GAL manual update](https://www.goline.ch/2022/06/22/microsoft-exchange-gal-manual-update/): Run this command with the Exchange PowerShellUpdate-GlobalAddressList -Identity "Default Global Address List" - [Enable an Exchange distribution group to forward to members with external email](https://www.goline.ch/2022/06/22/enable-an-exchange-distribution-group-to-forward-to-members-with-external-email/): To enable an Exchange distribution group to forward to members with addresses outside the organizationFrom Exchange Powershell:Set-DistributionGroup -Identity  -ReportToOriginatorEnabled $trueSet-DistributionGroup -Identity maha-service@restaurant-maha.ch -ReportToOriginatorEnabled $true - [Access MySQL as root or reset its password](https://www.goline.ch/2022/06/22/access-mysql-as-root-or-reset-its-password/): service mysql stopmysqld_safe --skip-grant-tables &mysql -u rootUSE mysqlUPDATE user SET Password = PASSWORD('password1234')WHERE Host = '%' AND User = 'root';FLUSH PRIVILEGES;service mysql startThen log in with root like this: mysql -pand write the passwordDB list via SQL: show databases;Delete a database via SQL: drop ;Create database via SQL: create database ; - [MySQL user management](https://www.goline.ch/2022/06/22/mysql-user-management/): MySQL user managementCreate a new user with password and set all permissionsCREATE USER 'newuser'@'localhost' IDENTIFIED BY 'password';GRANT ALL PRIVILEGES ON * . * TO 'newuser'@'localhost';FLUSH PRIVILEGES;How To Grant Different User PermissionsHere is a short list of other common possible permissions that users can enjoy. - [MySQL permission to login using Workbench from remote](https://www.goline.ch/2022/06/22/mysql-permission-to-login-using-workbench-from-remote/): mysql --password=xxxxxxxxxxxxxGRANT ALL PRIVILEGES ON *.* TO  root@192.168.221.5  IDENTIFIED  BY  'xxxxxxx';orGRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY 'xxxxxxxx'; Bind to all addresses:The easiest way is to comment out the line in your /etc/mysql/my.cnf file:#bind-address = 127.0.0.1 or 185.54.81. - [The cphulkd.login table seems corrupted (cPanel)](https://www.goline.ch/2022/06/22/the-cphulkd-login-table-seems-corrupted-cpanel/):  I now have an error message in cPHulk Brute Force Protection:The cphulkd.login table seems corrupted. Please contact your system administrator.Try to repair the cphulkd database using in your WHMHome >> SQL Services >> Repair a MySQL DatabaseSelect “cphulkd” from the list of DBs and click “repair database”. - [Terminate cPanel Restoration Queue](https://www.goline.ch/2022/06/22/terminate-cpanel-restoration-queue/):   > Review Transfers and RestoresAbort all jobsSSH>  /usr/local/cpanel/bin/backup_restore_manager state Then /usr/local/cpanel/bin/backup_restore_manager activate force it with: /usr/local/cpanel/bin/backup_restore_manager delete_all_regardless - [MariaDB can't be monitored in Service Manager](https://www.goline.ch/2022/06/22/mariadb-cant-be-monitored-in-service-manager/): FAILED ⛔: mysql (185.54.81.13)" coming from the chkservd service.Disable mysql to enable mariadb# systemctl stop mysql.service# systemctl disable mysql.servicemysql.service is not a native service, redirecting to /sbin/chkconfig.Executing /sbin/chkconfig mysql offEnable and start MariaDB# systemctl enable mariadb.service# /scripts/restartsrv_mysql --start - [Installazione SNMP su cPanel](https://www.goline.ch/2022/06/22/installazione-snmp-su-cpanel/): Installare l'SNMP ed opzionalmente anche le utilities#yum -y install net-snmp net-snmp-utilsRinominare il file di default di configurazione#mv /etc/snmp/snmpd.conf /etc/snmp/snmpd.conf.origEditare un nuovo file:#vi /etc/snmp/snmpd. - [How to fix cPanel Account Permissions](https://www.goline.ch/2022/06/22/how-to-fix-cpanel-account-permissions/): How to fix cPanel Account PermissionsFixing file and directory permission for a specific user.find /home/*/public_html/* -type f -exec chmod 644 {} ;find /home/*/public_html/* -type d -exec chmod 755 {} ;we can specify user by replace * with usenameTo fix the permission for all the websites.for i in `ls /var/cpanel/users` ; do chown -R $i.$i /home/$i/public_html/* ; done - [Fix Munin on cPanel](https://www.goline.ch/2022/06/22/fix-munin-on-cpanel/): #mkdir /var/run/munin#chmod 755 /var/run/munin//#chown munin.munin /var/run/munin//Then delete the messages in here: /home/munin/mail/newand possibly /home/munin/mail/cur - [Find Spammer on cPanel exim server](https://www.goline.ch/2022/06/22/find-spammer-on-cpanel-exim-server/): Top 5 users sending maximum emailsgrep ".*T=virtual_userdelivery|=>.*T=local_delivery)" /var/log/exim_mainlog | awk '{print $7}' | sort | uniq -c | sort -nr | head -5 eximstats /var/log/exim_mainlog | grep -A7 "Top 50 local destinations by message count" | tail -5 | awk '{print $1,$NF}'Script to check path for the script used for spammingawk '{ if - [Find out who is monopolizing or eating the CPUs](https://www.goline.ch/2022/06/22/find-out-who-is-monopolizing-or-eating-the-cpus/): Find out who is monopolizing or eating the CPUsFollowing command will displays the top 10 CPU users on the Linux system.# ps -eo pcpu,pid,user,args | sort -k 1 -r | head -10OR# ps -eo pcpu,pid,user,args | sort -r -k1 | lessOR# top cd1 - [ConfigServer cxs – Removing banned IPs](https://www.goline.ch/2022/06/22/configserver-cxs-removing-banned-ips/): # Check where the IP is bannedcsf -g 84.221.246.112# Adds IP to temporary list for 600 secondscsf -ta 84.221.246.112 600# Removal from cxs listscxs --Rrem 84.221.246.112  - [cPanel getting SSL A+ rating from SSL Labs](https://www.goline.ch/2022/06/22/cpanel-getting-ssl-a-rating-from-ssl-labs/):  I was able to get an A+ rating from ssllabs by using these simplified steps:At Home / Service Configuration / Apache Configuration / Global Configuration, I set:SSL Cipher Suite: ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSSSSL/TLS Protocols: All -SSLv2 -SSLv3 -TLSv1(f - [Add an additional super user (root) to cPanel WHM](https://www.goline.ch/2022/06/22/add-an-additional-super-user-root-to-cpanel-whm/): From the shell as root run the following commands: - [cPanel – Keeps asking for logins all the time using IPv6](https://www.goline.ch/2022/06/22/cpanel-keeps-asking-for-logins-all-the-time-using-ipv6/): ISSUEcPanel - Keeps asking for logins all the time - [cPanel – Run scheduled backup (in manual mode)](https://www.goline.ch/2022/06/22/cpanel-run-scheduled-backup-in-manual-mode/): cPanel offers you to schedule backup and retain backup of server and accounts. But if you need to run backup manually, you can do it from SSH. Login to your server as root via SSH and run following command. - [Copy cPanel Server configuration](https://www.goline.ch/2022/06/22/copy-cpanel-server-configuration/): Also, /usr/local/cpanel/bin/cpconftool will back up and restore the Exim configuration and Tweak Settings. The Tweak Settings are mostly stored in /var/cpanel/cpanel.config, so this does overlap some of the information I mentioned in my previous post, but I wanted to mention it because it could be helpful to you. Here is the usage: - [AutoSSL certificates from cPanel when used with CloudFlare](https://www.goline.ch/2022/06/22/autossl-certificates-from-cpanel-when-used-with-cloudflare/): There is a common issue of renewing AutoSSL Certificates while using Cloudflare for the domain. - [CentOS AutoFS](https://www.goline.ch/2022/06/22/centos-autofs/): yum install nfs-utils nfs-utils-lib /etc/sysconfig/autofs## Init syatem options## If the kernel supports using the autofs miscellanous device# and you wish to use it you must set this configuration option# to "yes" otherwise it will not be used. - [Cisco – BGP monitoring session (export full routing table w/no import)](https://www.goline.ch/2022/06/22/cisco-bgp-monitoring-session-export-full-routing-table-w-no-import/): Export the full routing table without receiving any prefixes!route-map MONITOR_IN_V4 deny 100!route-map MONITOR_IN_V6 deny 100!!route-map MONITOR_OUT_V4 permit 100!route-map MONITOR_OUT_V6 permit 100!router bgp 202032!template peer-policy MONITOR_V4_POLICY  route-map MONITOR_IN_V4 in  route-map MONITOR_OUT_V4 out exit-peer-policy ! template peer-po - [Cisco Call Manager – Root Access on Linux based UC CUCM/CUC/CUPS/UCCX](https://www.goline.ch/2022/06/22/root-access-on-linux-based-uc-appliances/): Assuming CUCM was already installed.  Boot the box with a Linux installation CD (e.g. RedHat).  Type "linux rescue" in the boot prompt. - [Reset Cisco Phone to factory default](https://www.goline.ch/2022/06/22/reset-cisco-phone-to-factory-default/): Staccare il cavo alimentazione o rete se PoE . Attendere un paio di secondi premere e tenere premuto il tasto # prima ti ricollegare la corrente.  Quando inizia a lampeggiare la cornetta o i led arancioni (dipende da l telefono) lasciare il tasto # e premere in sequenza: 123456789*0# - [Reset Cisco AP (Access Point) – WLC](https://www.goline.ch/2022/06/22/reset-cisco-ap-access-point-wlc/): Ripristino AP CiscoIn modalità console premere Esc quando richiesto prima del caricamento del firmware.Per entrarci premere il tasto MODE molto a lungo finché non appare:Ethernet speed is 100 Mb - FULL DuplexMode button pressed.Mode button held for at least 20 seconds.quando appare "ap:" eseguire i comandi set DEFAULT_ROUTER 172.16.30. - [Remove/Add client to Cisco WLC blocklist](https://www.goline.ch/2022/06/22/remove-add-client-to-cisco-wlc-blocklist/): You could use the WLC CLI to solve your problem... show exclusionlist  = shows all the blacklisted clientsconfig exclusionlist {add | delete | description} = add & remove clients - [How to reset Cisco Catalyst 2960 switch password without losing your configuration](https://www.goline.ch/2022/06/22/how-to-reset-cisco-catalyst-2960-switch-password-without-losing-your-configuration/): To reset your Cisco 2960 password, connect your console cable to the switch and open up your terminal emulator software.Power on the switch while holding the mode button.Release the mode button after you see the screen below in your terminal emulator software. - [Firmware Update/Recovery Cisco switch 2960](https://www.goline.ch/2022/06/22/firmware-update-recovery-cisco-switch-2960/): Aggiorna il firmware con la versione Web based dev manager e sostituisce il vecchio firmware.#Copia via scparchive download-sw /imageonly /overwrite scp://cisco:stabio2010@192.168.222.5/c2960x-universalk9-tar.152-7.E10.tar#Copia via tftparchive download-sw /imageonly /overwrite tftp://tftp/c2960x-universalk9-tar.152-7.E10. - [Disabling “flapping” logging in Cisco switch](https://www.goline.ch/2022/06/22/disabling-flapping-logging-in-cisco-switch/): logging discriminator nolog msg-body drops flappinglogging buffered discriminator nologlogging console discriminator nologlogging monitor discriminator nologlogging host X.X.X.X discriminator nolog Per rimuoverlo:no logging buffered discriminator nologno logging console discriminator nolog no logging monitor discriminator nologno logging discriminator nolog - [Debug Cisco voice gateway 2911](https://www.goline.ch/2022/06/22/debug-cisco-voice-gateway-2911/): # Debug dei messagi SIP e VoIPdebug ccsip messagesdebug voip ccapi inout # Mostra le chiamate attiveshow call active voice compact - [Cisco Flexible NetFlow configuration example (Flow templates)](https://www.goline.ch/2022/06/22/cisco-flexible-netflow-configuration-example-flow-templates/): flow record ipv4_recordmatch ipv4 tosmatch ipv4 source addressmatch ipv4 destination addressmatch ipv4 protocolmatch transport source-portmatch transport destination-portmatch interface inputcollect interface outputcollect counter packetscollect counter bytescollect transport tcp source-portcollect transport tcp destination-portcollect transport tc - [Cisco WLC MIB oid for APs number and clients connected](https://www.goline.ch/2022/06/22/cisco-wlc-mib-oid-for-aps-number-and-clients-connected/): For those reading later.The MIB/OID to read out the number of AP is 1.3.6.1.4.1.9.9.618.1.8.4.0And the number of clients is 1.3.6.1.4.1.9.9.618.1.8.12.0 - [Cisco Unified Call Manager – Cisco Voice MIB](https://www.goline.ch/2022/06/22/cisco-unified-call-manager-cisco-voice-mib/): Cisco Voice GatewayISDN Active Calls -> 1.3.6.1.4.1.9.9.63.1.3.3.0Cisco Call Manager CUCMActive Phones -> 1.3.6.1.4.1.9.9.156.1.5.5.0Inactive Phones -> 1.3.6.1.4.1.9.9.156.1.5.6.0Rejected Phones -> 1.3.6.1.4.1.9.9.156.1.5.7.0 - [Cisco Switch CPU utilization (Catalyst and Nexus)](https://www.goline.ch/2022/06/22/cisco-switch-cpu-utilization-catalyst-and-nexus/): For Cisco Catalystshow processes cpu sorted | ex 0.00For Nexusshow processes cpu sort | ex 0.00 - [Cisco Switch – Find port using dal MAC Address](https://www.goline.ch/2022/06/22/cisco-switch-find-port-using-dal-mac-address/): Use this syntax xxxx.xxxx.xxxx.xxxxcsco-sw08-2960-bi#sh mac address-table | include fc5b.395c.d668  30    fc5b.395c.d668    DYNAMIC     Fa0/17or sh mac address-table address 746A.8900.4230 - [Cisco Router – Show interfaces index (MIB)](https://www.goline.ch/2022/06/22/cisco-router-show-interfaces-index-mib/):  csco-gw02#show snmp mib ifmib ifindexGigabitEthernet0/1: Ifindex = 5GigabitEthernet0/0/0: Ifindex = 1Backplane-GigabitEthernet0/3: Ifindex = 7GigabitEthernet0/1/0: Ifindex = 2Embedded-Service-Engine0/0: Ifindex = 3Null0: Ifindex = 8GigabitEthernet0/2: Ifindex = 6GigabitEthernet0/0: Ifindex = 4 - [Cisco Unified Call Manager – Cisco Phone Error: Host Not Found](https://www.goline.ch/2022/06/22/cisco-unified-call-manager-cisco-phone-error-host-not-found/): Error: Host Not FoundThe Host Not Found error message is received when you press the corporate directory on some 7945 and 9971 IP Phone models.SolutionThis issue can occur if you have changed the domain for the CUCM Publisher and Subscriber. In order to resolve this issue, you need to delete the ITL file from the phone. - [Cisco Nexus 3K configuration guide](https://www.goline.ch/2022/06/22/cisco-nexus-3k-configuration-guide/): Configuring Jumbo Frames Cisco Support   show policy-map system show policy-map interface   This example shows how to reset the system qos configuration:   configure terminal system qos service-policy type qos input default-in-policy service-policy type network-qos default-nq-policy service-policy type queuing output default-out-policy service-poli - [Cisco IOS – Create an access-list and apply to a interface](https://www.goline.ch/2022/06/22/cisco-ios-create-an-access-list-and-apply-to-a-interface/): First you have to create an access list:router(config)#access-list 100 permit icmp any any unreachablerouter(config)#access-list 100 permit icmp any any echo-replyrouter(config)#access-list 100 permit icmp any any time-exceededrouter(config)#access-list 100 permit icmp any any source-quenchrouter(config)#access-list 100 deny   icmp any any timestam - [Cisco IOS – Disable Telnet access (single host access)](https://www.goline.ch/2022/06/22/cisco-ios-disable-telnet-access-single-host-access/): Disattiva l'accesso telnet a tutti, tranne l'host specificato.#configure terminal(config)#ip access-list extended VTY_ACCESS(config-ext-nacl)#10 permit tcp host 185.54.81.23 any eq telnet (autorizza un host)(config-ext-nacl)#12 deny tcp host 202.85.221. - [Cisco IOS – Access-list resequence](https://www.goline.ch/2022/06/22/cisco-ios-access-list-resequence/): However, IOS includes a convenient command to resequence all entries in an ACL without a reboot and without recreating the ACL:Router(config)# ip access-list resequence Foo ? Starting Sequence NumberRouter(config)# ip access-list resequence Foo 10 ? Step to increment the sequence numberRouter(config)# ip access-list resequence Foo 10 10Router(confi - [Cisco ASDM can' t run on your PC](https://www.goline.ch/2022/06/22/cisco-asdm-can-t-run-on-your-pc/): Procedere come segue: - [Cisco ASR 1002-X router MIB for BGP connection state and Lookup values](https://www.goline.ch/2022/06/22/cisco-asr-1002-x-router-mib-for-bgp-connection-state-and-lookup-values/): Per aggiungere  i sensori delle sessioni BGP seguire la seguente procedura - [Cisco ASR 1002 – Upgrade ROMMON](https://www.goline.ch/2022/06/22/cisco-asr-1002-upgrade-rommon/): The hw-module slot slot reload command cannot be used to reload an active RP. If you must reload an active RP to complete a ROMmon upgrade, reload the RP using one of the following methods:- Run the reload command to reload the entire router. - [Cisco ASA SFR Module (Install/Uninstall)](https://www.goline.ch/2022/06/22/cisco-asa-sfr-module-install-uninstall/): Cisco ASA SFR Module (Install/Uninstall)ciscoasa# sw-module module sfr uninstallciscoasa# sw-module module sfr recover configure image disk0:/asasfr-5500x-boot-6.0.0-1005. - [Cisco 3750X (Environment and firware upgrade module 10G)](https://www.goline.ch/2022/06/22/cisco-3750x-environment-and-firware-upgrade-module-10g/): Mostra lo stato degli alimentatori e dell'hardware#show env all#show env stack (vedi anche le ventole)Reload del modulo 10G#switch 1 frulink reloadMostra lo stato dei moduli inseriti#sh switch service-modulesSwitch/Stack supports service module CPU version: 03.00. - [Cisco 2921 – Enable SNMP BGP messages](https://www.goline.ch/2022/06/22/cisco-2921-enable-snmp-bgp-messages/): #conf t#snmp-server enable traps bgp (versione 1)#snmp-server enable traps bgp cbgp2 (versione 2) - [Cisco 2921 ROM MONITOR upgrade](https://www.goline.ch/2022/06/22/cisco-2921-rom-monitor-upgrade/): System Bootstrap Upgrade procedureFirst download from Cisco.com a correct ROM MONITOR from (IOS ROMMON Software) section.NOTA: Non è necessario entrare nel ROMMON. Si fa da IOS.Then access to the router and execute upgrade rom-monitor command.The system will reboot after upgrading the ROM.Router# upgrade rom-monitor file flash:C1900_2900_RM2.srec. - [Cisco Call Manager – CUCM Cleanup before upgrade (watermark)](https://www.goline.ch/2022/06/22/cisco-unified-call-manager-cucm-cleanup-before-upgrade-watermark/):  Steps for clearing disk space by manipulating values of watermarks are described below:Open RTMT tool using the IP address of the Publisher. Inside RTMT click on 'Alert Central'.Select 'LogPartitionLowWaterMarkExceeded', right click and select 'Set Alert/Properties', click on next. - [Cisco 10Gbit Module C3KX-SM-10G for 3750-X – version-mismatch](https://www.goline.ch/2022/06/22/cisco-10gbit-module-c3kx-sm-10g-for-3750-x-version-mismatch/): Cisco 3750x FRULink 10G service module Errore mostrato%PLATFORM_SM10G-3-SW_VERSION_MISMATCH: The FRULink 10G Service Module (C3KX-SM-10G) in switch 1 has a software version that is incompatible with the IOS software version. Please update the software. Module is in pass-thru mode. - [Blackholing IP address on Cisco](https://www.goline.ch/2022/06/22/blackholing-ip-address-on-cisco/): Remotely-Triggered Black Hole (RTBH) routing is an interesting application of BGP as a security tool within service provider networks. One common use is mitigation of distributed denial of service (DDoS) attacks, as this article will explore. - [Fixes AnyConnect SSL certificate problem on Cisco ASA with failover](https://www.goline.ch/2022/06/22/fixes-anyconnect-ssl-certificate-problem-on-cisco-asa-with-failover/): Elliptic curve cryptography for SSL/TLS—When an elliptic curve-capable SSL VPN client connects to the ASA, the elliptic curve cipher suite will be negotiated, and the ASA will present the SSL VPN client with an elliptic curve certificate, even when the corresponding interface has been configured with an RSA-based trustpoint. - [Restoring Factory Defaults to the Cisco ASA5505 Firewall via the Console](https://www.goline.ch/2022/06/22/restoring-factory-defaults-to-the-cisco-asa5505-firewall-via-the-console/): If you are like me, you tend to click things just to see how they work. Sometimes they don’t work. At all. If you’ve mucked up the IP, vlan, etc settings and the Cisco ASDM can’t get into the device, it’s time for more desperate measures. If you can get into the ASDM, it is easier to Reset to Factory Defaults using the Cisco’s ASDM. - [Cisco ASA: web interface not working](https://www.goline.ch/2022/06/22/cisco-asa-web-interface-not-working/): I had to troubleshoot a Cisco ASA today, where the client wasn’t able to connect to the management web interface anymore via https. The customer didn’t install ASDM locally, but always starts the Java-based version. - [BGP – Border Gateway Protocol](https://www.goline.ch/2022/06/22/bgp-border-gateway-protocol/): BGP - Border Gateway ProtocolThe place of BGP in your routed worldEGP is the original External Gateway Protocol. The only EGP used now is BGP.For a corporate site, the main purpose of BGP is to make the Internet access redundant. : multi-homing. - [Brocade 300 SNMP (abilitare l'accesso da un host)](https://www.goline.ch/2022/06/22/brocade-300-snmp-abilitare-laccesso-da-un-host/): admin> snmpconfig --set accesscontrol SNMP access list configuration is the following:Access host subnet area : 15.220.105.51 Read/Write? (true, t, false, f): f Access host subnet area : 0.0.0.0 Read/Write? (true, t, false, f): Access host subnet area : 0.0.0.0 Read/Write? (true, t, false, f): Access host subnet area : 0.0.0. - [Juniper MIB BGP IPv6](https://www.goline.ch/2022/06/22/juniper-mib-bgp-ipv6/): Procedura Con la connessione BGP in stato attivoFare uno show snmp mib walk 1.3.6.1.4.1.2636.5.1.1.2.1.1.1.2 Esce la lista delle connessioni attive Disattivare la connessione con deactivate protocols bgp group XXXX_V6 Rifare uno show snmp mib walk 1.3.6.1.4.1.2636.5.1.1.2.1.1.1.2 e guardare la differenza. Vedere quale manca. - [Estendi una partizione con lo spazio non allocato (CentOS 7)](https://www.goline.ch/2022/06/22/estendi-una-partizione-con-lo-spazio-non-allocato-centos-7/): Estendere prima da VMware console.Reboot con inserito l'ISO di gparted ed espandere la partizione primaria con lo spazio aggiunto.Poi entrare in shell su Linux-> espande 20 GB alla partizione#lvextend -L+20G -r /dev/mapper/centos-root-> espande il 100% dello spazio non partizionato#lvextend -l 100%FREE -r /dev/mapper/centos-home Abbiamo riscontrato - [CSF (Install) – Attack monitoring on cPanel](https://www.goline.ch/2022/06/22/csf-install-attack-monitoring-on-cpanel/): # Detect if an attack is in progress...netstat -plant-- Filtra per IPnetstat -plant |grep -c 185.11.147.63-- Filtra per utente hostingps faux |grep paganico# Counts connections for IP netstat -anp |grep 'tcp|udp' | awk '{print $5}' | sed s/::ffff:// | cut -d: -f1 | sort | uniq -c | sort -n# Sessions count for IPnetstat -nA inet |awk '/^/{split($5,a - [Install cPanel & WHM](https://www.goline.ch/2022/06/22/install-cpanel-whm/): Install cPanel & WHMTo install cPanel & WHM, run the following command:cd /home && curl -o latest -L http://httpupdate.cpanel.net/latest && sh latestThis command changes your session to the home directory, downloads the latest version of cPanel & WHM, and runs the installation script.Warning:To install cPanel & WHM on a 5. - [Route RPKI validation](https://www.goline.ch/2022/04/01/rpki-validation/): RPKI is a security framework by which network owners can validate and secure the critical route updates or Border Gateway Protocol (BGP) announcements between public Internet networks. RPKI validation plays a crucial role in ensuring the security and authenticity of these updates. BGP is essentially the central nervous system of the Internet and one of its fundamental building blocks. - [RIPE – Atlas Anchor](https://www.goline.ch/2022/02/17/hosting-an-anchor-ripe-atlas-goline-sa-insights/): We are proud to be part of the RIPE Atlas project by hosting an anchor, a powerful device used to analyze Internet latency between networks (autonomous systems).By running an anchor, we not only gain deeper insight into Internet performance but also contribute valuable data to the global community of network operators. - [MANRS](https://www.goline.ch/2020/06/20/manrs/): GOLINE firmly believes in initiatives to protect networks, improve security and resilience of the global routing system. Therefore we decided to support the Mutually Agreed Norms for Routing Security (MANRS) project and join as participants. - [Looking Glass](https://www.goline.ch/2019/03/14/internet-looking-glass-enhancing-network-efficiency/): Typically, Looking Glass servers are run by autonomous systems like Internet service providers (ISPs), Network Service Providers (NSPs), and Internet exchange points (IXPs). - [Membership in MINAP IXP](https://www.goline.ch/2019/01/10/membership-in-minap/): MINAP is a distributed Internet Exchange Point established in 2008 in Milano in the Via Caldera 21 campus. - [Internet Autonomous System (AS202032)](https://www.goline.ch/2014/04/29/internet-autonomous-system-as202032/): On the Internet, an Internet Autonomous System (AS) is the unit of router policy, either a single network or a group of networks that is controlled by a common network administrator (or group of administrators) on behalf of a single administrative entity (such as a university, a business enterprise, or a business division). - [IPv6 implementation and Swiss IPv6 Council](https://www.goline.ch/2013/06/26/ipv6/): What is IPv6? ## Categories - [BGP](https://www.goline.ch/category/bgp/) - [Brocade](https://www.goline.ch/category/brocade/) - [Cisco](https://www.goline.ch/category/cisco/) - [Cisco ASA](https://www.goline.ch/category/cisco-asa/) - [cPanel](https://www.goline.ch/category/cpanel/) - [DBMS](https://www.goline.ch/category/dbms/) - [Exchange Server](https://www.goline.ch/category/exchange-server/) - [FileAudit](https://www.goline.ch/category/fileaudit/) - [FortiGate](https://www.goline.ch/category/fortigate/) - [Hardware](https://www.goline.ch/category/hardware/) - [Juniper](https://www.goline.ch/category/juniper/) - [Linux](https://www.goline.ch/category/linux/) - [Mail](https://www.goline.ch/category/mail/) - [Mikrotik](https://www.goline.ch/category/mikrotik/) - [Networking](https://www.goline.ch/category/networking/) - [News](https://www.goline.ch/category/news/) - [Security](https://www.goline.ch/category/security/) - [SharePoint](https://www.goline.ch/category/sharepoint/) - [Skype for Business Server](https://www.goline.ch/category/skype-for-business-server/) - [Sophos](https://www.goline.ch/category/sophos/) - [SQL Server](https://www.goline.ch/category/sql-server/) - [SysAid HelpDesk](https://www.goline.ch/category/sysaid-helpdesk/) - [Telefonia](https://www.goline.ch/category/telefonia/) - [Vademecum](https://www.goline.ch/category/vademecum/) - [Veeam](https://www.goline.ch/category/veeam/) - [Veritas Backup Exec](https://www.goline.ch/category/veritas-backup-exec/) - [Video sorveglianza](https://www.goline.ch/category/video-sorveglianza/) - [VMware](https://www.goline.ch/category/vmware/) - [WHMCS](https://www.goline.ch/category/whmcs/) - [Windows](https://www.goline.ch/category/windows/) ## About GOLINE SA GOLINE SA is a Swiss IT and Cybersecurity company (AS202032) headquartered in Stabio (Ticino), Switzerland. We design, implement, and manage advanced digital infrastructures and cyber defence systems for mid-to-large enterprises across Switzerland and Europe. Our expertise spans enterprise networking, system integration, software development, managed SOC (Security Operations Centre), data centre operations, and cloud hosting. ## Core Services - [Software Development](https://www.goline.ch/services/software-development/): Custom application development for logistics, supply chain, HR, biometrics, and business process automation. - [IT Consulting & System Integration](https://www.goline.ch/): End-to-end consulting, infrastructure design, virtualization, CRM/ERP deployment, cloud migration and managed services. - [Cybersecurity & SOC Services](https://www.goline.ch/system-architecture/security/): Continuous monitoring, incident response, vulnerability management, digital forensics and compliance (ISO 27001, GDPR, NIST). - [Networking & Infrastructure](https://www.goline.ch/system-architecture/networking/): High-performance network architectures (VXLAN, BGP, EVPN, multi-datacentre deployments, enterprise connectivity). - [Hosting & Cloud Services](https://www.goline.ch/services/cpanel-hosting-goline-sa/): Secure web and email hosting, domain management and cloud infrastructure for business-critical workloads. ## Technology, Distribution & Partner Ecosystem We collaborate with leading technology vendors and open-source solutions including Cisco, Fortinet, Juniper, NetApp, Wazuh, FileCloud and PowerDMARC. As an authorised **reseller and distributor**, GOLINE SA provides Swiss and European organisations with direct access to enterprise-grade hardware and software solutions from these vendors, ensuring genuine licensing, professional deployment and certified support. Our distribution activities combine technical expertise with a partner-centric approach to deliver high-value solutions that meet security and compliance requirements. ## Data Centres & Network Presence GOLINE operates its own network infrastructure (AS202032) with presence in Equinix Zürich, MIX-IT Milan and Stabio DC. Our backbone delivers redundant, low-latency connectivity with 24/7 managed infrastructure operations and real-time telemetry monitoring across all sites. ## Mission & Value Proposition Our mission is to empower modern organisations through innovation, security and operational excellence. We help companies transform IT infrastructure into a strategic asset, improving resilience, visibility and performance while reducing risk. We believe that robust security and strong architecture are the foundation of sustainable digital growth. ## Key Expertise & Differentiators - Deep domain knowledge in **logistics and fresh-food distribution software** platforms. - Hybrid competence combining enterprise network engineering with advanced cybersecurity operations and software development. - Multi-lingual support (Italian, German, English) for the Swiss and European markets. - Proven experience with VXLAN EVPN fabrics, iBGP over loopbacks, and high-MTU data-centre interconnects (MTU 9216). - Strong security-first culture: no RDP or SMBv1, all internal and external access over SSL, VPN with 2FA, Wazuh + Sysmon monitoring, ESET Protect, immutable Veeam backups (S3 copies), Suricata IDS. ## Certifications & Compliance GOLINE SA aligns its operations with international standards including ISO 27001, GDPR, NIST SP 800-53 and Zero Trust frameworks. We ensure all solutions delivered meet the highest levels of data protection, privacy and availability. Updated: 2025-10-29