4 ms·
Although I agree that some people shouldn't have an access to the machine room, this anecdote was caused due to the author's fault. It isn't reasonable to suspe
by Hitton 5y ago
Although I agree that some people shouldn't have an access to the machine room, this anecdote was caused due to the author's fault. It isn't reasonable to suspect that problem is with your machine when you can connect to one box in your network no problem and can't to another. That iptables rule shouldn't have stayed there so long - you can set cron to send yourself a monthly reminder whether the rule is still needed. So what really happened: "sysadmin" is causing their users problems and then makes pikachu face when users try to solve them when sysadmin isn't around.
- bravetraveler 5y agoI agree, both 'sides' to this story share a little responsibility You would think someone watching logs so diligently would also note the counters for dropped packets ceasing, and probably look to remove the rule Because well, they use DHCP. Those IPs by very nature of that environment are not static.. so rules dropping them shouldn't be either. Maybe just accept that services get unwanted traffic and QoS and structured logs exist for a reason. This is like early optimization, good intentions leading to holes in feet. I can look past it though for benefit of the story. The person flipping power had far more reasonable options at their disposal... Though I doubt they would expect a problem specifically with their source IP - a bit rigged