{
    "version": "https://jsonfeed.org/version/1",
    "title": "altbrain.net",
    "description": "",
    "home_page_url": "https://altbrain.net",
    "feed_url": "https://altbrain.net/feed.json",
    "user_comment": "",
    "author": {
        "name": "Mike"
    },
    "items": [
        {
            "id": "https://altbrain.net/broken-data-domain-web-ui-2.html",
            "url": "https://altbrain.net/broken-data-domain-web-ui-2.html",
            "title": "Broken Data Domain Web UI",
            "summary": "I recently resurrected an EMC Data Domain as I have a new, potential use for it. It was offline for a while and the thought was to power it on, check out its health, the firmware version, and a few other things. As luck would&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">I recently resurrected an EMC Data Domain as I have a new, potential use for it. It was offline for a while and the thought was to power it on, check out its health, the firmware version, and a few other things. As luck would have it though, when attempting to log in using the web UI, the page wouldn’t load. After poking at it for a few and some additional Googling, I found that the self-signed certificate expired resulting in the web services not starting. In this post, I’ll share the steps that were taken to get the UI back up and running.</p>\n<h3 class=\"wp-block-heading\">Overview of Steps</h3>\n<ol class=\"wp-block-list\" start=\"1\">\n<li><strong>Verify</strong> the active hostname and inspect the current HTTPS certificate state.</li>\n<li><strong>Regenerate</strong> the local Certificate Authority (CA) and self-signed certificate.</li>\n<li><strong>Reset</strong> the local mutual trust for the hostname.</li>\n<li><strong>Bounce</strong> the Web UI services (<code>https</code> / <code>http</code>) to apply changes.</li>\n</ol>\n<h3 class=\"wp-block-heading\">Step-by-Step Procedure</h3>\n<h4 class=\"wp-block-heading\">1. Verify Hostname and Certificate Status</h4>\n<p class=\"wp-block-paragraph\">First, connect to the device via SSH, grab the FQDN of the Data Domain, and confirm whether an imported host certificate exists for the HTTPS application:</p>\n<pre class=\"wp-block-code\"><code>admin@datadomain# hostname\nThe Hostname is: datadomain.example.local\n\nadmin@datadomain# adminaccess certificate show imported-host application https\n**** There is no imported host certificate for application(s): https.</code></pre>\n<p class=\"wp-block-paragraph\">If no imported host certificate exists (or if it is invalid), proceed with regenerating the self-signed certificate.</p>\n<h4 class=\"wp-block-heading\">2. Regenerate Local CA and Self-Signed Certificates</h4>\n<p class=\"wp-block-paragraph\">Generate a fresh self-signed certificate and force a regeneration of the local Certificate Authority:</p>\n<pre class=\"wp-block-code\"><code>admin@datadomain# adminaccess certificate generate self-signed-cert regenerate-ca\n\n** WARNING: Regenerating local CA certificate will invalidate existing trust with external system(s).\n        Secure communication to trusted host(s) will be broken until mutual trust is reestablished.\n\n        Do you want to proceed? (yes|no) [no]: yes\nNew certificates have been generated.</code></pre>\n<h4 class=\"wp-block-heading\">3. Reset Local Mutual Trust</h4>\n<p class=\"wp-block-paragraph\">Next, tear down the stale mutual trust entry associated with the local hostname and re-add it using the newly generated CA fingerprint.</p>\n<p class=\"wp-block-paragraph\">Delete the old mutual trust entry:</p>\n<pre class=\"wp-block-code\"><code>admin@datadomain# adminaccess trust del host datadomain.example.local type mutual\nDeleting trust with ' datadomain.example.local ' may cause some management functions to stop working.\n        Are you sure? (yes|no) [no]: yes\n\nok, proceeding.</code></pre>\n<p class=\"wp-block-paragraph\">Re-add mutual trust for the local hostname:</p>\n<pre class=\"wp-block-code\"><code>admin@datadomain# adminaccess trust add host datadomain.example.local type mutual\nThe SHA1 fingerprint for the remote host's CA certificate is\nXX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX\nDo you want to trust this certificate? Are you sure? (yes|no) [no]: yes\n\nok, proceeding.\n\nFor adding the mutual trust with \" datadomain.example.local \", enter \" datadomain.example.local \" admin password:\nMutual Trust with host \" datadomain.example.local \" has been added.</code></pre>\n<h4 class=\"wp-block-heading\">4. Restart Web UI Services</h4>\n<p class=\"wp-block-paragraph\">Finally, cycle the HTTPS and HTTP admin services to bind the new SSL certificates:</p>\n<pre class=\"wp-block-code\"><code>admin@datadomain# adminaccess disable https\nHTTPS Access: disabled\n\nadmin@datadomain# adminaccess enable https\nHTTPS Access: enabled\n\nadmin@datadomain# adminaccess disable http\nHTTP Access: disabled\n\nadmin@datadomain# adminaccess enable http\nHTTP Access: enabled</code></pre>\n<h3 class=\"wp-block-heading\">Verification</h3>\n<p class=\"wp-block-paragraph\">Open a browser and navigate to <code>https://datadomain.example.local</code>. Accept the self-signed certificate warning, and the Data Domain System Manager login screen should load normally.</p>",
            "image": "https://altbrain.net/media/posts/47/datacenter-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Storage",
                   "SSL",
                   "Datacenter"
            ],
            "date_published": "2026-10-01T08:30:00-04:00",
            "date_modified": "2026-10-03T09:22:08-04:00"
        },
        {
            "id": "https://altbrain.net/docker-image-maintenance-2.html",
            "url": "https://altbrain.net/docker-image-maintenance-2.html",
            "title": "Docker Image Maintenance",
            "summary": "The other day, I was alerted to a storage space alarm on a Linux system that hosts a handful of Docker containers. Having had a few go arounds with Docker and logs filling up disks, I suspected that but logs weren’t to blame here. In&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">The other day, I was alerted to a storage space alarm on a Linux system that hosts a handful of Docker containers. Having had a few go arounds with Docker and logs filling up disks, I suspected that but logs weren’t to blame here. In this case, what was taking up considerable space was a decent collection of container images that accumulated over time. This post will review some basic troubleshooting and how to handle some basic Docker image maintenence.</p>\n<p class=\"wp-block-paragraph\">First, let’s talk about how you get to this point. When you build or pull a new version of an image to update a container, in the end, the old container image isn’t automatically deleted. Instead, it remains stored locally on disk. Over months of automated deployment or iterative testing, dozens or hundreds of gigabytes of stale images accumulate under /var/lib/docker.</p>\n<p class=\"wp-block-paragraph\">As always, take a snapshot or some other backup that you can rely on.</p>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Step 1: Check Storage Allocation Across Docker</strong></p>\n<p class=\"wp-block-paragraph\">Before running destructive commands, inspect how Docker is distributing disk usage across images, containers, local volumes, and build cache. The output will show you the amount of Images and the space the consume along with how much space is reclaimable. This also shows the same info for actual Containers, Local Volumes, and the Build Cache <br><br>docker system df</p>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Step 2: Inspect Active and Stopped Containers</strong></p>\n<p class=\"wp-block-paragraph\">Before purging images, or anything for that matter, verify which containers exist on the host so you don’t accidentally attempt to wipe an image tied to a stopped but vital service.<br><br>docker ps -a</p>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Step 3: List All Local Docker Images</strong></p>\n<p class=\"wp-block-paragraph\">Inspect all locally available images, including tags, Image IDs, and sizes. Take note of the Image ID, which you may use in the next step providing you want to delete specific images.</p>\n<p class=\"wp-block-paragraph\">docker image ls</p>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Step 3: Cleaning Up</strong></p>\n<p class=\"wp-block-paragraph\"><strong>Option 1</strong> – If you want to manually delete a specific, obsolete image by its ID</p>\n<p class=\"wp-block-paragraph\">docker image rm &lt;image_ID&gt;</p>\n<p class=\"wp-block-paragraph\">Note on Container Dependencies – If Docker prevents deletion with an error stating the image is referenced in a stopped container, you must either remove the stopped container first (docker rm ) or force removal (docker image rm -f )</p>\n<p class=\"wp-block-paragraph\"><strong>Option 2</strong> – Rather than deleting individual images by ID, to sweep away all untagged and dangling images safely, in that active and tagged images remain untouched</p>\n<p class=\"wp-block-paragraph\">docker image prune</p>\n<p class=\"wp-block-paragraph\"><strong>Option 3 (Full Cleanup)</strong> – If you want to fully delete all unused images AND stopped containers AND unused networks AND build caches in one sweep</p>\n<p class=\"wp-block-paragraph\">docker system prune -a</p>\n<p class=\"wp-block-paragraph\">When you’re all set, revisit Step 1 to see where you landed. Of course, you can also run below to see how the overall storage capacity has changed</p>\n<p class=\"wp-block-paragraph\">df -ah</p>",
            "image": "https://altbrain.net/media/posts/46/docker-img1-2.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Linux",
                   "Docker"
            ],
            "date_published": "2026-09-27T08:29:00-04:00",
            "date_modified": "2026-10-03T09:48:50-04:00"
        },
        {
            "id": "https://altbrain.net/openssl-generate-private-keys-and-csrs-2.html",
            "url": "https://altbrain.net/openssl-generate-private-keys-and-csrs-2.html",
            "title": "OpenSSL, Generate Private Keys and CSRs",
            "summary": "I’ve run into a handful of occasions where I’ve had to defer to OpenSSL to generate certificate signing requests (CSR), for signing by certificate authority (CA) like an internal CA server or a 3rd party issuer like Digicert. Sometimes, applications, network gear, or something else&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">I’ve run into a handful of occasions where I’ve had to defer to OpenSSL to generate certificate signing requests (CSR), for signing by certificate authority (CA) like an internal CA server or a 3rd party issuer like Digicert. Sometimes, applications, network gear, or something else you’re working with just don’t have the facilities or UI to pull this off but you need a SSL certificate. In these situations, my go to move is to hop on to a nearby Linux system and generate the private key and subsequent CSR from there. Then I take my CSR to to the CA for getting my signed SSL certificate.</p>\n<p class=\"wp-block-paragraph\">In this post, we’ll get right to it by displaying the steps below. I have added some brief comments to walk through this step by step. I have also added some additional details immediately below so check that out. If you feel that you want to just script this, then scroll way down to see the bash script there.</p>\n<pre class=\"wp-block-code\"><code><strong># Step 1 - Make a new folder for the certificate files, change directory to it</strong>\ncd /home/username/\nmkdir 2026-ssl-cert-renewal-appname\ncd 2026-ssl-cert-renewal-appname\n\n<strong># Step 2 - Create a 2048 bit private key\n</strong>openssl genrsa -out appname.example.com.key 2048\n\n<strong># Step 3 - Restrict key permissions\n</strong>chmod 600 appname.example.com.key\n\n<strong># Step 4 - Generate the CSR\n</strong>openssl req -new -key appname.example.com.key -out appname.example.com.csr -sha256 -subj \"/C=US/ST=Washington/L=Redmond/O=Org Name/CN=appname.example.com\" -addext \"subjectAltName=DNS:appname.example.com\"\n\n<strong># Step 5 - Before sending to your CA, validate:\n#  CN = appname.example.com\n#  Subject Alternative Name includes DNS:appname.example.com</strong>\nopenssl req -in appname.example.com.csr -noout -text\n\n<strong># Step 6 - Send CSR to your CA for processing</strong>\n</code></pre>\n<p class=\"wp-block-paragraph\">Below are some some additional details for each of the above steps.</p>\n<p class=\"wp-block-paragraph\"><strong>Step 1</strong><br>You’re essentially, changing directory <code>cd</code> to your home folder, creating a new folder <code>mkdir</code> to save the private key and CSR in, and the changing directory <code>cd</code> to the new folder you made.</p>\n<p class=\"wp-block-paragraph\"><strong>Step 2</strong><br>You’re generating the private key with <strong><code>openssl</code></strong>, in this case a 2048 bit RSA key.</p>\n<ul class=\"wp-block-list\">\n<li><strong><code>genrsa</code></strong>: This tells OpenSSL to use its RSA key generation tool. RSA is a commonly used algorithm used for securing web traffic.</li>\n<li><strong><code>-out appname.example.com.key</code></strong>: This specifies the destination and name of the file where the private key will be saved. In this case, it writes it to a file named <code>appname.example.com.key</code> in your current directory.</li>\n<li><strong><code>2048</code></strong>: This defines the key length in bits. 2048-bit is what we’re choosing here.</li>\n</ul>\n<p class=\"wp-block-paragraph\"><strong>Step 3</strong><br>You’re restricting the private key permissions, immediately after creation. Do it, it’s a solid security practice. By default, the private key file may be readable by others depending on their umask. Running <strong><code>chmod 600</code></strong> ensure that only owner can read the sensitive private key.</p>\n<p class=\"wp-block-paragraph\"><strong>Step 4</strong><br>You’re creating the CSR file in the current working directory using <strong><code>openssl</code></strong>.</p>\n<ul class=\"wp-block-list\">\n<li><strong><code>req -new</code></strong>: Tells OpenSSL that you want to create a new certificate request.</li>\n<li><strong><code>-key appname.example.com.key</code></strong>: Points OpenSSL to the private key you generated in the previous step.</li>\n<li><strong><code>-out appname.example.com.csr</code></strong>: Specifies the filename for the outputted CSR file. This is the text file you will bring to your CA for signing.</li>\n<li><strong><code>-sha256</code></strong>: Forces the request to use the SHA-256 hashing algorithm, to meet modern requirements.</li>\n<li><strong><code>-subj \"...\"</code></strong>: Bypasses interactive prompts by passing your organization’s identity details directly in a single line.</li>\n<li><strong><code>-addext \"subjectAltName=DNS:appname.example.com\"</code></strong>: Adds the Subject Alternative Name (SAN) extension. This is critical as modern web browsers ignore the Common Name (<code>CN</code>) for security verification and do look at the SAN list. Even if you only have one domain, it <em>must</em> be listed here as a SAN, or browsers will throw a “Not Secure” privacy error.</li>\n</ul>\n<p class=\"wp-block-paragraph\"><strong>Step 5</strong><br>You’re validating that your CSR is in good shape</p>\n<ul class=\"wp-block-list\">\n<li><strong><code>req</code></strong>: Tells OpenSSL you are working with a Certificate Signing Request tool.</li>\n<li><strong><code>-in appname.example.com.csr</code></strong>: Points OpenSSL to the specific CSR file you want to examine.</li>\n<li><strong><code>-noout</code></strong>: Suppresses the output of the raw, encoded text blocks (the <code>-----BEGIN CERTIFICATE REQUEST-----</code> clutter). You only want to see the decoded data, not the scrambled cryptographic text.</li>\n<li><strong><code>-text</code></strong>: Instructs OpenSSL to print the contents of the CSR in full, human-readable text format.</li>\n</ul>\n<p class=\"wp-block-paragraph\">Want a script that you can bend to your own will? Here’s a good starting point in <strong>bash</strong>:</p>\n<pre class=\"wp-block-code\"><code># Define your domain variable once\nDOMAIN=\"appname.example.com\"\n\n# Create the directory\nmkdir -p ~/certs/2026-${DOMAIN}-renewal\ncd ~/certs/2026-${DOMAIN}-renewal\n\n# Generate key and restrict permissions\nopenssl genrsa -out ${DOMAIN}.key 2048\nchmod 600 ${DOMAIN}.key\n\n# Generate the CSR using the variable\nopenssl req -new -key ${DOMAIN}.key -out ${DOMAIN}.csr -sha256 \\\n  -subj \"/C=US/ST=Washington/L=Redmond/O=Org Name/CN=${DOMAIN}\" \\\n  -addext \"subjectAltName=DNS:${DOMAIN}\"</code></pre>",
            "image": "https://altbrain.net/media/posts/45/security-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "SSL",
                   "Linux"
            ],
            "date_published": "2026-09-03T08:28:00-04:00",
            "date_modified": "2026-10-03T09:19:20-04:00"
        },
        {
            "id": "https://altbrain.net/decommissioning-a-domain-controller.html",
            "url": "https://altbrain.net/decommissioning-a-domain-controller.html",
            "title": "Decommissioning a Domain Controller",
            "summary": "Before getting into it, I want to raise some caution. Every environment is different and you really want to make sure that you’ve got your head wrapped around what removing a domain controller will impact in your specific environment. In this post, the idea is&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">Before getting into it, I want to raise some caution. Every environment is different and you really want to make sure that you’ve got your head wrapped around what removing a domain controller will impact in your specific environment. In this post, the idea is to provide a high level view of the general process, while presenting some things to consider that are sometimes missed. The general idea is to think before you do and to do as much as possible to get you to a successful outcome.</p>\n<h3 class=\"wp-block-heading\">Phase 0 – Prerequisites</h3>\n<ul class=\"wp-block-list\">\n<li>Run <code>repadmin /replsummary</code> and <code>repadmin /showrepl</code> to ensure Active Directory is replicating perfectly <em>before</em> you change the topology. Demoting a DC in an unhealthy forest can cause lingering objects.</li>\n<li>Run <code>netdom query fsmo</code> to see who holds the roles. If it’s this server, move them using PowerShell (<code>Move-ADDirectoryServerOperationMasterRole</code>).</li>\n<li>Check your DHCP scopes, member servers, and appliances (firewalls, switches). If they point to this DC’s IP for DNS, they will lose internet and domain connectivity the moment you pull the plug. Change client DNS settings days <em>before</em> the demotion to be safe.</li>\n<li>Check devices with static IP addresses, and resolve any future DNS problems by targeting a surviving DNS server.</li>\n<li>Review any AD integrated applications that may use this DC by name or IP in its configuration. Some applications leverage AD for authentication or authorization, where an admin needs to configure Active Directory or LDAP settings so that the application can enumerate users and groups and other AD object attributes. If you remove the DC, the application could break.</li>\n<li>Remember when you decided that it was a good idea to host printer and file shares on your DC (this is never a good idea)? If you did, you’ll have to deal with that first.</li>\n<li>Have an Active Directory backup. Not a VM snapshot, but an Active Directory, application-aware backup. It would be a dark day if you needed it, but make sure you have it.</li>\n</ul>\n<h3 class=\"wp-block-heading\">Phase 1 – Preparation (Days Before)</h3>\n<ol class=\"wp-block-list\" start=\"1\">\n<li>Point all client/server DNS settings away from this DC’s IP address.</li>\n<li>Verify AD health to confirm that everything has remained healthy since the prerequisite checks (<code>repadmin</code>).</li>\n<li>Check and migrate FSMO roles (<code>netdom query fsmo</code>). You may ask yourself, why would I do this again as I checked it the other day??? I will tell you why. You should do this because it takes 5 seconds and because not everyone is a great communicator. Other people sometimes do stuff that you’re not aware about. Ask me how I know!</li>\n<li>Migrate DHCP or other secondary roles if applicable.</li>\n<li>Perform a “scream test” or whatever you call it. Don’t skip it. Disable the NIC for a few days to see what breaks and keep your ear to the ground. Make sure you re-enable the NIC and allow a day or so before advancing to the next phase.</li>\n</ol>\n<h3 class=\"wp-block-heading\">Phase 2 – Demoting the Server and Removing the AD DS and DNS roles</h3>\n<ol class=\"wp-block-list\" start=\"1\">\n<li>Check out the servers DNS configuration. If you find the loopback address configured for the primary or secondary DNS, lose it. Make the Primary DNS point to an alternate and healthy Domain Controller/DNS server in your environment. Make the Secondary DNS point to another surviving DC/DNS server. Make sure that you can resolve host names including the top level domain name (<code>ping YourDomainName.local</code>).</li>\n<li>Demote the DC via Server Manager (or PowerShell). If this is not the last DC in the environment, then don’t select the box that says “this is the last DC in the environment”. Enter and record the new local admin password. Monitor progress and wait until the server has been successfully demoted.</li>\n<li>Reboot. The server is now just a member server.</li>\n<li>Remove the AD DS and DNS Roles via Server Manager.</li>\n<li>Reboot again.</li>\n</ol>\n<h3 class=\"wp-block-heading\">Phase 3 – Cleanup &amp; Decommission</h3>\n<ol class=\"wp-block-list\" start=\"1\">\n<li>Verify the server automatically moved to the “Computers” OU in AD.</li>\n<li>Validate AD Sites and Services. A graceful demotion removes the NTDS Settings object from under the server in AD Sites and Services, but it does not automatically remove the top-level server object container itself. You may need to delete the empty server container manually.</li>\n<li>To completely retire the server, this would be a safe time to disjoin it from the domain and shut it down.</li>\n<li>If you do disjoin and are planning to nuke it, check out DNS Management, and remove any A or reverse pointers for this server that may be lingering.</li>\n<li>Update your asset and configuration management platforms to account for the changes.</li>\n</ol>",
            "image": "https://altbrain.net/media/posts/44/adds-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Windows Server",
                   "Active Directory"
            ],
            "date_published": "2026-08-15T08:27:00-04:00",
            "date_modified": "2026-10-03T09:49:19-04:00"
        },
        {
            "id": "https://altbrain.net/vsphere-cross-vcenter-migration.html",
            "url": "https://altbrain.net/vsphere-cross-vcenter-migration.html",
            "title": "vSphere Cross-vCenter Migration",
            "summary": "A vSphere cross-vCenter migration allows you to move virtual machines (VMs) between two different vCenter Server instances. This comes in handy for data center consolidations, hardware refreshes, or general workload balancing. It’s a native vCenter feature that you can use if the vCenters are in&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">A vSphere cross-vCenter migration allows you to move virtual machines (VMs) between two different vCenter Server instances. This comes in handy for data center consolidations, hardware refreshes, or general workload balancing. It’s a native vCenter feature that you can use if the vCenters are in the same SSO domain or if they are independent vCenters.</p>\n<p class=\"wp-block-paragraph\">For historic understanding and discussion, this cross vCenter migration capability was not baked into earlier versions of vCenter. Instead, it was available as a VMware Fling. Flings were the primary vehicle for rapid innovation, acting as a sandbox for features that eventually became foundational to vSphere. A lot of the Flings were rolled into final product releases, but in advance of that they were available to customers for download and for use “at your own risk”. Another example would be VMware PowerCLI. In my opinion, Flings came from a point in time when using VMware was exciting and the people who worked for VMware were excited and super innovative. This showed in their products and we benefited from their work, as a result. It’s a larger discussion, and maybe one for a future post, but it’ll be interesting to see if Broadcom looks and feels the same as their ongoing changes to the vSphere platform continue to evolve. What do you think?<br><br>In any case, as it relates to this write up, we will be working with 2 vCenter’s in 2 different SSO domains. We’ll be leveraging the Advanced Cross vCenter vMotion (XVM) method.</p>\n<p class=\"wp-block-paragraph\">There are a few prerequisites to consider.</p>\n<ul class=\"wp-block-list\">\n<li>Both the source and destination environments must have vSphere Enterprise Plus licensing (min).</li>\n<li>You’ll need network connectivity between the 2 vCenter’s. TCP 443, 902, and 8000.</li>\n<li>All vCenter’s should have valid NTP configurations with no or limited clock skew.</li>\n<li>Ideally, vCenter’s should be with the same major release or up or down 1 version, example Source at v7.0 and and target at 8.0.</li>\n<li>Consider EVC baselines and CPU generation compatibility.</li>\n</ul>\n<p class=\"wp-block-paragraph\">To get things moving along, you’ll need to do the following:</p>\n<ol class=\"wp-block-list\">\n<li>Connect to the Source vCenter and right-click the VM, select <strong>Migrate</strong>, then select <strong>Cross vCenter Server export</strong>. I would almost always recommend selecting to ‘<strong>Keep VMs on the source vCenter</strong>‘. This provides a safety net if the migration fails or if you need to roll back to the original host immediately.</li>\n<li>Provide the <strong>FQDN/IP</strong> of the target vCenter and <strong>administrative credentials</strong>. Accept the SSL certificate thumbprint, if prompted.</li>\n<li>Select the target <strong>Compute Resource</strong>, <strong>Storage</strong>, <strong>Folder</strong>, and map <strong>Networking</strong>, selecting <strong>Next</strong> at each step to move the wizard along.</li>\n<li>The system will run pre-checks. If any fail, you must resolve them before proceeding.</li>\n<li><strong>Execute</strong> the migration and monitor progress in the Tasks pane</li>\n</ol>\n<p class=\"wp-block-paragraph\">After the migration wraps up, review the following</p>\n<ol class=\"wp-block-list\">\n<li>Confirm that the VM is in the Inventory on the target vCenter and that the VM is running.</li>\n<li>If you moved the VM from another network, you’ll need to tend to its IP configuration and adjust as necessary so that it will function on the target network.</li>\n<li>Confirm that the VM is reachable by IP (ping) and its name (validate DNS).</li>\n<li>Confirm VMware Tools is running on the target version.</li>\n<li>Adjust backups or validate that the backup application will backup the VM.</li>\n</ol>\n<p class=\"wp-block-paragraph\">In summary, not overly exciting but useful when you need it.</p>",
            "image": "https://altbrain.net/media/posts/43/object-migrate-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Virtualization"
            ],
            "date_published": "2026-08-12T08:26:00-04:00",
            "date_modified": "2026-10-04T20:18:12-04:00"
        },
        {
            "id": "https://altbrain.net/monitoring-your-ups-and-pdu-gear.html",
            "url": "https://altbrain.net/monitoring-your-ups-and-pdu-gear.html",
            "title": "Monitoring your UPS and PDU Gear",
            "summary": "I wanted to post on this topic because the underlying UPS and PDU equipment that feeds our power thirsty server and network gear never seems to get much attention. These are the lowly, second hand citizens of our physical infrastructure. The good news is that&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">I wanted to post on this topic because the underlying UPS and PDU equipment that feeds our power thirsty server and network gear never seems to get much attention. These are the lowly, second hand citizens of our physical infrastructure. The good news is that we’re breaking the silence today! In this post, I’ll shed some insights on how to give these unsung heroes the love and care they deserve.</p>\n<p class=\"wp-block-paragraph\">To set the stage, we’re purely focusing on the management of Schneider Electric (APC) gear, and specifically devices with APC NMC (network management card), Smart Connect, or common management interface ports. I’m sure that other brands have similar management capabilities. If you support alternate brand gear like Eaton, please do read on but you’ll want to contact your Eaton rep or VAR to see what they offer.</p>\n<p class=\"wp-block-paragraph\">Generally speaking, if you have a couple UPSs and PDUs, you’ll probably get away with managing the stand-alone devices on an individual basis. All these devices have a browser based management UI that you can log into and use to configure, manage, operate, and maintain them. You can set up alerts, view power stats, assess health, and a bunch of other stuff. Again, it’s not a big lift to manage them individually if you have just a handful. However, this approach doesn’t scale well when you’ve got a lot of these devices in all kinds of network closets, server rooms, IDF’s, MDF’s, and data centers. Taking it a step further, if you sprinkle these devices at remote sites all over the globe, you’re going to need to think of a better way to tackle this growing problem.</p>\n<p class=\"wp-block-paragraph\">By now, and as you can probably imagine, things start to get super difficult to manage as your environment grows. Often times though, since these devices are generally set and forget until there’s a problem, I’ve seen a lot of admins just turn a blind eye to them. However, the reality is that these devices run embedded operating systems and they expose services to the networks they connect to. These assets do indeed require operational maintenance throughout their lifecycle. It is indeed important to keep their firmware updated, the devices secure from vulnerabilities, their batteries maintained in a healthy state, and their warranties in check. To accomplish all this, we need one, single pane of glass. We need a tool where all these devices are all linked to, from where you can manage all of them centrally. In the Schneider (APC) space, this solution is referred to as Datacenter Infrastructure Management (DCIM) tooling.</p>\n<p class=\"wp-block-paragraph\">Years ago, the preferred tool for this was called APC Data Center Expert. I’m not going to get into it here because I have a love hate relationship with it. It did certainly help manage a lot of distributed devices (loved it), but it was dated, cranky, and usually warranted a call to APC Support after every upgrade (hated it). It was a paid tool as well and just tossing that in here for general awareness.</p>\n<p class=\"wp-block-paragraph\">Fast forwarding to more recent times, Schneider Electric, probably recognizing that they needed a more modern solution, set out to deliver a reasonably good offering in <a href=\"https://www.se.com/us/en/product-range/65972-ecostruxure-it-expert/#overview\">Schneider Electric EcoStruxure IT Expert</a>. This is a modern, SaaS, cloud-based solution that enables monitoring and visibility into your IT physical infrastructure from anywhere. Also, for general awareness, this is not a free service but I would say that the juice is worth the squeeze, in my opinion. It delivers on the centralized, single pane of glass experience and does so with a fairly simple to deploy solution.</p>\n<p class=\"wp-block-paragraph\">Before we get into the solution architecture and high level deployment, let’s talk about what it can do for your distributed power infrastructure. Below is a list of the features and capabilities that I find most useful and you can check out the link above to further dig into any of this.</p>\n<ul class=\"wp-block-list\">\n<li>Inventory and asset management</li>\n<li>Configuration and day 2 management, including firmware upgrades</li>\n<li>Warranty and service information</li>\n<li>Instant visibility to critical infrastructure health, consumption and metrics, reporting</li>\n<li>Advanced remote monitoring via ExoStruxure IT mobile app</li>\n<li>Integrates with your Identity Provider</li>\n<li>Alarms, notification, and predictive maintenance</li>\n<li>Data driven insights and recommendations</li>\n</ul>\n<p class=\"wp-block-paragraph\">In terms of the solution architecture, it’s not a big deal or overly complicated. It pretty much consists of these main components:</p>\n<ul class=\"wp-block-list\">\n<li>SaaS web application (your tenant at se.com) that’s hosted in their cloud infrastructure</li>\n<li>Identity Provider like MS Entra is recommended, for user authentication</li>\n<li>A Linux or Windows based VM with line of sight to all the APC gear you want to monitor, for installing the IT Expert Eco (ITE) Gateway application</li>\n<li>IT Expert Eco (ITE) Gateway requires https (TCP, 443) to the SaaS web application</li>\n<li>Schneider Electric and/or APC gear with management interfaces, accessible from the IT Expert Eco (ITE) Gateway appliance using various ports and protocols</li>\n</ul>\n<p class=\"wp-block-paragraph\">To help frame out how all the pieces fit, this is it what it looks like :<br><strong>SaaS Web App at se.com</strong> &lt;—– TCP, 443 —– <strong>ITE Gateway VM</strong> &lt;—– various ports, protocols —–&gt; <strong>PDU and UPS Gear NMC/Smart Ports</strong></p>\n<p class=\"wp-block-paragraph\">With everything up to this point in mind, the remainder of the post is the basic step-by-step. Consider this a general guide though and not specifically tailored for your environment and all its nuances.</p>\n<h2 class=\"wp-block-heading\">Step 1: Pre-Configuring the APC Hardware and Networking</h2>\n<p class=\"wp-block-paragraph\">Log into your NMC web interfaces and ensure the basics are set:</p>\n<ul class=\"wp-block-list\">\n<li><strong>Identity &amp; Location:</strong> Set your unique device password on first logon and populate the Location ID (<strong>Configuration &gt; General &gt; Identification</strong>). ITE maps this location string straight to your cloud dashboard.</li>\n<li><strong>Network Identity:</strong> Assign your static IP, Mask, Gateway (<strong>Configuration &gt; Network &gt; TCP/IP &gt; IPv4</strong>) and your primary/secondary DNS (<strong>Configuration &gt; Network &gt; DNS</strong>).</li>\n<li><strong>Management Protocol:</strong> Enable SNMPv1 Access (<strong>Configuration &gt; Network &gt; SNMPv1 &gt; Access</strong>) and establish your community string in <strong>Access Control</strong>.</li>\n<li><strong>File Transfer and Firmware Protocol:</strong> Enable FTP (<strong>Configuration &gt; Network &gt; FTP &gt; Access</strong>)</li>\n</ul>\n<p class=\"wp-block-paragraph\"><em>If your security policy requires SNMPv3, ensure the encryption settings on the NMC match the Gateway. When configuring AES on the APC NMC, always select <strong>AES128</strong> in the ITE Gateway interfac</em>e. <em>If you have firewalls between your gear and the gateway appliance, you must account for that in any applicable </em>ACLs (see below)</p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td><strong>Source</strong></td>\n<td><strong>Destination</strong></td>\n<td><strong>Protocol</strong></td>\n<td><strong>Port(s)</strong></td>\n<td><strong>Description</strong></td>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>ITE Gateway IP</strong></td>\n<td><strong>Device or Device Subnet</strong></td>\n<td>UDP</td>\n<td><code>161</code></td>\n<td>SNMP Polling</td>\n</tr>\n<tr>\n<td><strong>ITE Gateway IP</strong></td>\n<td><strong>Device or Device Subnet</strong></td>\n<td>TCP</td>\n<td><code>21</code> and <code>22</code></td>\n<td>Firmware / Config File Transfer</td>\n</tr>\n<tr>\n<td><strong>Device or Device Subnet</strong></td>\n<td><strong>ITE Gateway IP</strong></td>\n<td>UDP</td>\n<td><code>162</code>, <code>1062</code></td>\n<td>Real-time SNMP Traps</td>\n</tr>\n</tbody>\n</table>\n</figure>\n<h2 class=\"wp-block-heading\">Step 2: Provisioning the IT Gateway</h2>\n<p class=\"wp-block-paragraph\">With your power gear ready to talk, it’s time to configure the ITE Gateway.</p>\n<p class=\"wp-block-paragraph\"><strong>Deploy and Access the Gateway Interface</strong> – Once the Gateway software is installed on your local Windows or Linux server, open a browser and navigate to <code>https://&lt;Gateway_IP_or_Hostname&gt;/gateway/index.html</code>. Establish your local ITE Gateway admin password.</p>\n<p class=\"wp-block-paragraph\"><strong>Define Device Credentials</strong> – Before scanning, you must tell the Gateway what strings to use. Go to <strong>Device Credentials</strong> and select <strong>New Credentials</strong>. Add your SNMPv1 community string (or SNMPv3 profiles) to match the settings you configured on the NMCs.</p>\n<p class=\"wp-block-paragraph\"><strong>Add File Transfer Credentials</strong> – Navigate to <strong>File Transfer Credentials</strong> and select <strong>FTP</strong> or <strong>SCP</strong>. Enter the management username and password for your APC cards. This allows ITE to push mass firmware updates directly from the cloud through the gateway.</p>\n<p class=\"wp-block-paragraph\"><strong>Run Device Discovery</strong> – Go to <strong>Discover Devices</strong>. Input the specific static IP addresses or the entire management subnet range of your UPS and PDU gear. Click <strong>Discover</strong>. The gateway will scan the range, match the credentials, and pull the hardware into the local pool.</p>\n<p class=\"wp-block-paragraph\"><strong>Register Gateway to the Cloud</strong> – Click the <strong>Register Gateway</strong> button. Log into your centralized EcoStruxure IT organization account. This binds the local gateway token to your cloud tenant, sending all discovered UPS and PDU data straight to your cloud console and mobile app.</p>\n<h2 class=\"wp-block-heading\">Step 3: Verifying Telemetry in the ITE Cloud Console</h2>\n<p class=\"wp-block-paragraph\">Once the sync completes, log into the EcoStruxure IT web portal or mobile app to verify your deployment:</p>\n<ul class=\"wp-block-list\">\n<li><strong>Inventory Validation:</strong> Check the <strong>Devices</strong> tab to ensure your Smart-UPS and Rack PDUs appear with their correct hostnames and location fields.</li>\n<li><strong>Sensor Check:</strong> Drill down into a PDU to verify that phase load, breaker states, and total power draw are updating in real time.</li>\n<li><strong>Threshold Tuning:</strong> Go to <strong>Configuration &gt; Thresholds</strong> to set up cloud-managed alert policies for critical events (such as low runtime or high current), bypassing the need to manage individual alert logic on every standalone endpoint.</li>\n</ul>\n<p class=\"wp-block-paragraph\">In summary, and hopefully as you can see, this is not a big deal and actually a project that’s worth it in my opinion. It solves some real challenges and helps you manage a lot of stuff with more efficiency while greatly improving visibility and overall management. It’s not going to break the bank either. Connect with your Schneider Electric rep for more information and start giving these devices the love they deserve!</p>",
            "image": "https://altbrain.net/media/posts/41/datacenter-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Datacenter"
            ],
            "date_published": "2026-07-24T08:25:00-04:00",
            "date_modified": "2026-10-03T09:49:41-04:00"
        },
        {
            "id": "https://altbrain.net/all-about-ethernet-cabling.html",
            "url": "https://altbrain.net/all-about-ethernet-cabling.html",
            "title": "All about Ethernet Cabling",
            "summary": "Ethernet cabling refers to the physical wires used to connect computers, routers, and switches within a Local Area Network (LAN). It transmits data as electrical pulses, providing a significantly more stable, secure, and faster internet connection than wireless networks like Wi-Fi. Not all cable is&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">Ethernet cabling refers to the physical wires used to connect computers, routers, and switches within a Local Area Network (LAN). It transmits data as electrical pulses, providing a significantly more stable, secure, and faster internet connection than wireless networks like Wi-Fi. Not all cable is considered equal and there’s quite a bit to consider when you’re deploying low-voltage infrastructure to support common local area networks.</p>\n<p class=\"wp-block-paragraph\">In this post, we’ll scratch the surface and I’ll point out some of the basics to help display the different types of Ethernet cabling. We’ll also lightly touch on how things interconnect using Ethernet cabling. Let’s get started! <br><br><strong>Ethernet Cable – Construction, Category, Data Rate, Bandwidth, Distance, and Common Usage</strong></p>\n<p class=\"wp-block-paragraph\">Immediately below is a cut-away image of a Cat5e Ethernet cable. Note the blue protective outer jacket, 4 twisted pairs (8 total conductors) that are twisted to reduce cross-talk of conductor wires, and a ripcord that’s used to slice open the outer jacket of the cable to expose the twisted pairs. The twisted pairs of conductor wires are color-coded: green, white-green / orange, white-orange / blue, white-blue / brown, white-brown. The conductor wires can be solid or stranded core. For what we’re talking about in this post, let’s run with solid core wiring.</p>\n<p class=\"wp-block-paragraph\">Each conductor wire serves a purpose, as displayed in chart below.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/cable-conductors.png\" alt=\"\" width=\"837\" height=\"647\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/cable-conductors-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/cable-conductors-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/cable-conductors-md.png 768w ,https://altbrain.net/media/posts/40/responsive/cable-conductors-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/cable-conductors-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/cable-conductors-2xl.png 1600w\"></figure>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<th class=\"has-text-align-center\" data-align=\"center\">Wire Pair</th>\n<th class=\"has-text-align-center\" data-align=\"center\">Pin Numbers</th>\n<th>Primary Function</th>\n</tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Orange/White &amp; Orange</strong></td>\n<td class=\"has-text-align-center\" data-align=\"center\">1 &amp; 2</td>\n<td><strong>Transmit Data</strong>: These wires carry outbound data (signals leaving your device).</td>\n</tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Green/White &amp; Green</strong></td>\n<td class=\"has-text-align-center\" data-align=\"center\">3 &amp; 6</td>\n<td><strong>Receive Data</strong>: These wires capture inbound data (signals coming from the internet or other devices).</td>\n</tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Blue &amp; Blue/White</strong></td>\n<td class=\"has-text-align-center\" data-align=\"center\">4 &amp; 5</td>\n<td><strong>Spare / PoE</strong>: In 10/100 Mbps networks, these are spare. In Gigabit+ networks, they are used for data transmission. They are also commonly used for <strong>Power over Ethernet (PoE)</strong> to supply electrical power to devices like security cameras or VoIP phones.</td>\n</tr>\n<tr>\n<td class=\"has-text-align-center\" data-align=\"center\"><strong>Brown &amp; Brown/White</strong></td>\n<td class=\"has-text-align-center\" data-align=\"center\">7 &amp; 8</td>\n<td><strong>Spare / PoE</strong>: Similar to the blue pair, these wires are used for additional data lanes in Gigabit and faster networks and help carry PoE power.</td>\n</tr>\n</tbody>\n</table>\n</figure>\n<p class=\"wp-block-paragraph\">Below is a reference chart displaying the various types (categories) of network cabling that everyone has most likely run across at some point. You can buy pre-made cables or boxed spools of cabling for larger projects. Every “Category” represents a generation of engineering. As the numbers go up, so do the the specs including tighter wire twists, better insulation, and optimized shielding. All of these improvements aim to reduce crosstalk (noisy signal interference between conductor wires) and try to buck EMI (Electro Magnetic Interference). Less noise allows data to travel at higher frequencies (measured in Megahertz, or MHz). These days, Cat5e and greater are what you’ll most often run into.</p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Cable Category Type</th>\n<th class=\"has-text-align-left\" data-align=\"left\">Maximum Data Rate</th>\n<th class=\"has-text-align-left\" data-align=\"left\">Bandwidth</th>\n<th class=\"has-text-align-left\" data-align=\"left\">Maximum Distance</th>\n<th class=\"has-text-align-left\" data-align=\"left\">Typical Usage</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Category 1</td>\n<td>1 Mbps</td>\n<td>0.4 MHz</td>\n<td> </td>\n<td>Telephone and modem lines</td>\n</tr>\n<tr>\n<td>Category 2</td>\n<td>4 Mbps</td>\n<td>4 MHz</td>\n<td> </td>\n<td>LocalTalk &amp; Telephone</td>\n</tr>\n<tr>\n<td>Category 3</td>\n<td>10 Mbps</td>\n<td>16 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>10BaseT Ethernet</td>\n</tr>\n<tr>\n<td>Category 4</td>\n<td>16 Mbps</td>\n<td>20 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>Token Ring</td>\n</tr>\n<tr>\n<td>Category 5</td>\n<td>100 Mbps</td>\n<td>100 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>100BaseT Ethernet</td>\n</tr>\n<tr>\n<td>Category 5e</td>\n<td>1 Gbps</td>\n<td>100 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>100BaseT Ethernet, residential homes</td>\n</tr>\n<tr>\n<td>Category 6</td>\n<td>1 Gbps</td>\n<td>250 MHz</td>\n<td>100 m (328 ft.)<br>10Gb at 37 m (121 ft.)</td>\n<td>Gigabit Ethernet, commercial buildings</td>\n</tr>\n<tr>\n<td>Category 6a</td>\n<td>10 Gbps</td>\n<td>500 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>Gigabit Ethernet in data centers and commercial buildings</td>\n</tr>\n<tr>\n<td>Category 7</td>\n<td>10 Gbps</td>\n<td>600 MHz</td>\n<td>100 m (328 ft.)</td>\n<td>10 Gbps Core Infrastructure</td>\n</tr>\n<tr>\n<td>Category 7a</td>\n<td>10 Gbps</td>\n<td>1000 MHz</td>\n<td>100 m (328 ft.)<br>40Gb at 50 m (164 ft.)</td>\n<td>10 Gbps Core Infrastructure</td>\n</tr>\n<tr>\n<td>Category 8</td>\n<td>25 Gbps (Cat8.1)<br>40 Gbps (Cat8.2)</td>\n<td>2000 MHz</td>\n<td>30 m (98 ft.)</td>\n<td>25 Gbps/40 Gbps Core Infrastructure</td>\n</tr>\n</tbody>\n</table>\n</figure>\n<p class=\"wp-block-paragraph\"><strong>Cable Shielding</strong></p>\n<p class=\"wp-block-paragraph\">The primary purpose of shielding in Ethernet cables is to protect data transmissions from Electromagnetic Interference (EMI) and Radio Frequency Interference (RFI). It ensures signal integrity and maintains high-speed performance in environments with heavy electronic activity. You would choose the cabling for your specific application. For example, if you install network cabling to a manufacturing environment that has a potential for a lot of interference, you’d want cabling with the appropriate shielding. Defer to your low-voltage professionals for direction on what to use for your application.</p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">ISO/IEC Designation</th>\n<th class=\"has-text-align-center\" data-align=\"center\">Common Abbreviation</th>\n<th class=\"has-text-align-center\" data-align=\"center\">Shielding – Conductor</th>\n<th class=\"has-text-align-center\" data-align=\"center\">Shielding – Cable</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>U/UTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">UTP or TPP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n</tr>\n<tr>\n<td>F/UTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">FTP or STP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n</tr>\n<tr>\n<td>S/UTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">STP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n</tr>\n<tr>\n<td>SF/UTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">SFTP or STP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding &amp; Foil</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n</tr>\n<tr>\n<td>U/FTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">STP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">None</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n</tr>\n<tr>\n<td>F/FTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">FFTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n</tr>\n<tr>\n<td>S/FTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">SFTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n</tr>\n<tr>\n<td>SF/FTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">SFTP or SSTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding &amp; Foil</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Foil</td>\n</tr>\n<tr>\n<td>S/STP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">SSTP</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding</td>\n<td class=\"has-text-align-center\" data-align=\"center\">Braiding</td>\n</tr>\n</tbody>\n</table>\n</figure>\n<p class=\"wp-block-paragraph\">In my last paragraph, I mentioned low voltage professionals. Find a good one and work with them when planning cabling projects. Up to this point, we’ve been zoning in on just the physical cabling and its characteristics. As you’re probably starting to realize, there’s a little more to this than some may think. For instance, there are low-voltage building codes, local codes and industry standards, and safety measures to consider. There are specific kinds of Ethernet cabling that are Plenum Rated. A plenum rated Ethernet cable is a networking cable specially designed with a fire-retardant jacket. It emits very little smoke and few toxic fumes when burned. You must use plenum rated cables when running wires through plenum spaces which are the hidden air-handling areas of a building such as the space above drop ceilings or below raised floors. There’s also a requirement to use fire stop sealant when passing cabling through fireproof walls. Fire stopping is required whenever cables penetrate a fire-rated wall or floor (such as firewalls, smoke barriers, or shaft enclosures). Its purpose is to seal the openings around the cables to maintain the structure’s original fire-resistance rating and prevent the spread of flames, smoke, and toxic gases. Again, you should always consult with a professional.</p>\n<p class=\"wp-block-paragraph\">Moving on from the network cabling, we’ll look at the other components that you’d commonly find on an Ethernet network.<br><br><strong>RJ45 Modular Cable Ends</strong></p>\n<p class=\"wp-block-paragraph\">The RJ45 Modular Plug (cable end) is the plastic, clip-like contraption that crimps on to each end of an Ethernet cable and ultimately inserts into a switch port, network device, patch panel, or wall jack. They look like the image below and require special tools to make the crimp connection. I have hand made and crimped a LOT of cables and I would challenge anyone to make one faster than me!</p>\n<p class=\"wp-block-paragraph\">This is what an RJ45 Modular Plug looks like:</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/rj45-cable-ends.png\" alt=\"\" width=\"493\" height=\"323\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-md.png 768w ,https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/rj45-cable-ends-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\">This is what a RJ45 Crimp Tool looks like:</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/crimp-tool.png\" alt=\"\" width=\"502\" height=\"226\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/crimp-tool-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/crimp-tool-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/crimp-tool-md.png 768w ,https://altbrain.net/media/posts/40/responsive/crimp-tool-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/crimp-tool-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/crimp-tool-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\">To crimp a cable end on to a network cable, you strip back the outer jacket to expose the 4 wire pairs. You untwist each pair as little as possible and line up the 8 conductors in the correct order (we will cover that next). At this time, it’s important to trim the wires down so that they are as short as reasonably possible to allow them to slip into the cable end slots. Make sure that the cable jacket is contained inside the RJ45 cable end. Afterwards, you grab your crimp tool and crimp the connector so that it’s permanently affixed to the network cable. This is what the finished product should look like.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/rj45-pin-out.png\" alt=\"\" width=\"502\" height=\"226\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/rj45-pin-out-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/rj45-pin-out-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/rj45-pin-out-md.png 768w ,https://altbrain.net/media/posts/40/responsive/rj45-pin-out-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/rj45-pin-out-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/rj45-pin-out-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\"><strong>Wiring Pin-Out</strong></p>\n<p>T568A and T568B are the two standards. The main difference between T56A and T56B is the color order of green and orange pairs. Most commonly, the RJ45 Modular Plugs are wired the same exact way on each end of a cable and this is known as a “straight-through” cable. Some applications call for a “cross-over” cable. This simply means that one side of the cable is wired in T56A and the other in T56B.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/t56a-t56b.png\" alt=\"\" width=\"494\" height=\"170\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/t56a-t56b-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/t56a-t56b-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/t56a-t56b-md.png 768w ,https://altbrain.net/media/posts/40/responsive/t56a-t56b-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/t56a-t56b-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/t56a-t56b-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\"><strong>Patch Panels</strong></p>\n<p class=\"wp-block-paragraph\">Ethernet Patch Panels are commonly found in MDF (Main Distribution Frame) and IDF (Intermediate Distribution Frame) rooms or closets. An Ethernet patch panel organizes and centralizes multiple network cable drops in a structured cabling system. Patch Panels provide a clean, mounted termination point for cable runs that originate from wall jacks and other places. From the Patch Panels in your network racks, you then “patch” them into a network switch. Pre-made Patch Cables are commonly used to link the ports on the front of the patch panel to nearby Ethernet switch ports. Immediately below is a high level view on where Patch Panels fit between your PC NIC and the destination Ethernet network switch.<br><br>Your PC NIC &lt;— Ethernet Patch Cable —&gt; Wall Jack — Hidden/Fixed Ethernet Cable Run —- <strong>Patch Panel </strong>&lt;— Ethernet Patch Cable —&gt; Ethernet Network Switch</p>\n<p class=\"wp-block-paragraph\">Below is what a common Ethernet Patch Panel looks like. The front view is on top and the rear view is on the bottom.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/patch-panel.png\" alt=\"\" width=\"444\" height=\"235\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/patch-panel-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/patch-panel-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/patch-panel-md.png 768w ,https://altbrain.net/media/posts/40/responsive/patch-panel-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/patch-panel-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/patch-panel-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\">To terminate an Ethernet cable run to the rear of the patch panel, and to the rear of your Ethernet wall jack, you require a special tool called an Ethernet Punch Down Tool. The tool is used to neatly shove the Ethernet cable conductor wires into their color-coded slots using the T56A or T56B pin-out standards. You can see the color-coded pin arrangement diagram on the rear view of the patch panel displayed above. As you push the conductor wires into the corresponding colored slot of the patch panel by putting pressure on the tool, the tool will ultimately “punch down” and trim off excess wiring leaving a neat wire termination behind; and not something that looks like a barbaric caveman installed it. Below is what a punch down tool looks like. Orient the tool the right way. Some lessons are worth learning the hard way so you’ll know what I mean if you don’t!</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/punchdown-tool.png\" alt=\"\" width=\"610\" height=\"440\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/punchdown-tool-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/punchdown-tool-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/punchdown-tool-md.png 768w ,https://altbrain.net/media/posts/40/responsive/punchdown-tool-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/punchdown-tool-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/punchdown-tool-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\">I briefly mentioned that Ethernet cabling is punched down to the rear side of a wall jack. On the wall jack side, the component the cabling is punched down to is often called a RJ45 Keystone Jack or RJ45 Quick Port. For those interested, this is the behind the scenes view of what’s going on behind the wall jack faceplate. The general procedure is to strip back the outer jacket from the cabling, line up the cable pairs to the Keystone Jack using the T56A or T56B standard, and then punching down the conductor wiring to the Keystone Jack. Then you simply snap the Keystone Jack into the faceplate and mount the faceplate to the wall. Below are pictures of a Keystone Jack with conductor wiring punched down to the component. Additionally, a fully assembled 2-port face plate with 2 RJ45 Keystone Jacks mounted to it is displayed below.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/keystone-jack.png\" alt=\"\" width=\"850\" height=\"723\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/keystone-jack-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/keystone-jack-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/keystone-jack-md.png 768w ,https://altbrain.net/media/posts/40/responsive/keystone-jack-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/keystone-jack-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/keystone-jack-2xl.png 1600w\"></figure>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/2port-faceplate.png\" alt=\"\" width=\"265\" height=\"323\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/2port-faceplate-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/2port-faceplate-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/2port-faceplate-md.png 768w ,https://altbrain.net/media/posts/40/responsive/2port-faceplate-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/2port-faceplate-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/2port-faceplate-2xl.png 1600w\"></figure>\n<p>Always use a label maker and label the faceplate so that you can identify it and know where the other end is. The information on the faceplate label needs to align to the patch panel port number on the other end. Use a naming convention like MDF1-P1-22. The MDF1 part identifies that this cable run goes to the MDF1 room. P1 identifies Patch Panel 1 in the MDF1 room. The number 22 lines up with port 22 on Patch Panel 1 in the MDF1 room. You get it.</p>\n<p class=\"wp-block-paragraph\">An Ethernet Patch Cable is commonly a shorter (3ft, 7ft, 14ft) cable that’s purchased and ready to use with RJ45 modular ends preinstalled. The cable connects a PC network interface card to the wall port, on the office side of the cable run. Back in the MDF or IDF, where the patch panels are located, another patch cable is used to link the patch panel port to a nearby switch. Patch cables look like this:</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/ethernet-patch.png\" alt=\"\" width=\"291\" height=\"173\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/ethernet-patch-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/ethernet-patch-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/ethernet-patch-md.png 768w ,https://altbrain.net/media/posts/40/responsive/ethernet-patch-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/ethernet-patch-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/ethernet-patch-2xl.png 1600w\"></figure>\n<p class=\"wp-block-paragraph\">In the end, if all the moons align and you’ve punched down and crimped everything right, you’ll be rewarded with the glorious green link light on both the computer NIC and the switch port! Job well done. If you don’t get a link light, you’ll need to get a cable tester and perform additional troubleshooting; which really leads me to my final point before wrapping up this post.</p>\n<p class=\"wp-block-paragraph\">Earlier in this post, I jokingly referenced something that “looks like a barbaric caveman installed it”. I want to elaborate on this. For those of you who know me, you’ll probably chuckle and probably don’t need to read too much further. For those of you who don’t know me, I am self-admittingly “that guy” when it comes to maintaining cabling order. I’ll make a few final points about my take on this and then ask you to look at the 2 photos below.</p>\n<ol class=\"wp-block-list\">\n<li>Do it once and do it right, or don’t do it at all</li>\n<li>Be kind to your future self, set yourself up for future success when troubleshooting or replacing network gear</li>\n<li>Use the same color cabling for similar use cases</li>\n<li>Always route cabling through rack channels, cable runners, organizers, and cable trays</li>\n<li>Don’t run cabling across the front of racks or lay cabling across ceiling tiles and lighting ballasts. Keep cable runs shorter than their maximum distance.</li>\n</ol>\n<p class=\"wp-block-paragraph\">Ask yourself, “In which environment would I want to troubleshoot a problem or replace a failed switch in?”. The choice is yours.</p>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/closet-messy.png\" alt=\"\" width=\"436\" height=\"576\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/closet-messy-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/closet-messy-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/closet-messy-md.png 768w ,https://altbrain.net/media/posts/40/responsive/closet-messy-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/closet-messy-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/closet-messy-2xl.png 1600w\"></figure>\n<figure class=\"post__image\"><img loading=\"lazy\"  src=\"https://altbrain.net/media/posts/40/closet-neat.png\" alt=\"\" width=\"460\" height=\"743\" sizes=\"(max-width: 48em) 100vw, 768px\" srcset=\"https://altbrain.net/media/posts/40/responsive/closet-neat-xs.png 300w ,https://altbrain.net/media/posts/40/responsive/closet-neat-sm.png 480w ,https://altbrain.net/media/posts/40/responsive/closet-neat-md.png 768w ,https://altbrain.net/media/posts/40/responsive/closet-neat-lg.png 1024w ,https://altbrain.net/media/posts/40/responsive/closet-neat-xl.png 1360w ,https://altbrain.net/media/posts/40/responsive/closet-neat-2xl.png 1600w\"></figure>",
            "image": "https://altbrain.net/media/posts/40/ethernet-cables-img1-2.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Network",
                   "Datacenter"
            ],
            "date_published": "2026-07-15T08:25:00-04:00",
            "date_modified": "2026-10-05T23:18:59-04:00"
        },
        {
            "id": "https://altbrain.net/get-down-with-winget.html",
            "url": "https://altbrain.net/get-down-with-winget.html",
            "title": "Get down with winget",
            "summary": "winget (the Windows Package Manager) is Microsoft’s answer to the classic Linux experience of apt or dnf. It allows you to discover, install, upgrade, and configure applications via the command line. This is ideal and arguably safer, as it helps avoid hunting for downloads from&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\"><strong>winget</strong> (the Windows Package Manager) is Microsoft’s answer to the classic Linux experience of apt or dnf. It allows you to discover, install, upgrade, and configure applications via the command line. This is ideal and arguably safer, as it helps avoid hunting for downloads from the Internet which could lead to problems should you run into a sketchy site with a mal intent.</p>\n<h3 class=\"wp-block-heading\">How It Works</h3>\n<p class=\"wp-block-paragraph\">Under the hood, <strong>winget</strong> is a client interface for a massive repository of community-vetted and developer-submitted software. While tools like apt and dnf manage software specifically packaged for a Linux distro, winget acts more like an orchestrator in Windows. It finds the installer for the app you want, downloads it, and runs it (often silently) with the proper arguments.</p>\n<h3 class=\"wp-block-heading\">Key Differences from apt/dnf</h3>\n<p class=\"wp-block-paragraph\">While the workflow feels familiar, there are some distinct Windows-specific nuances:</p>\n<ul class=\"wp-block-list\">\n<li><strong>Manifest-Based:</strong> Instead of repositories of binaries, winget relies on “manifests” (YAML files) that tell the tool exactly where the installer lives and how to run it.</li>\n<li><strong>System-Wide vs. User:</strong> winget can handle both, but since it’s Windows, it often has to navigate User Account Control (UAC) prompts if an installer requires administrative privileges.</li>\n<li><strong>Source Diversity:</strong> By default, it uses the Microsoft Community Repository, but it can also pull from the Microsoft Store. You can even add your own private repositories for internal tools.</li>\n</ul>\n<h3 class=\"wp-block-heading\">Useful Commands to Get Started</h3>\n<p class=\"wp-block-paragraph\">If you’re comfortable with Linux package managers like apt, these will feel like second nature:</p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td><strong>Action</strong></td>\n<td><strong>Winget Command</strong></td>\n<td><strong>apt Equivalent</strong></td>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>Search</strong></td>\n<td><code>winget search [app]</code></td>\n<td><code>apt search</code></td>\n</tr>\n<tr>\n<td><strong>Install</strong></td>\n<td><code>winget install [app]</code></td>\n<td><code>apt install</code></td>\n</tr>\n<tr>\n<td><strong>Upgrade All</strong></td>\n<td><code>winget upgrade --all</code></td>\n<td><code>apt upgrade</code></td>\n</tr>\n<tr>\n<td><strong>Uninstall</strong></td>\n<td><code>winget uninstall [app]</code></td>\n<td><code>apt remove</code></td>\n</tr>\n<tr>\n<td><strong>Check Info</strong></td>\n<td><code>winget show [app]</code></td>\n<td><code>apt show</code></td>\n</tr>\n<tr>\n<td><strong>List available updates</strong></td>\n<td><code>winget update</code></td>\n<td><code>apt update</code></td>\n</tr>\n</tbody>\n</table>\n</figure>\n<p class=\"wp-block-paragraph\">Below is an example of listing all available updates. You could then follow up with <strong>winget upgrade –all</strong>, to install all of them.</p>\n<pre class=\"wp-block-code\"><code>PS C:\\&gt; <strong>winget update</strong>\nName                                               Id                                Version       Available     Source\n-----------------------------------------------------------------------------------------------------------------------\nNotepad++ (64-bit x64)                             Notepad++.Notepad++               8.9.4         8.9.6.4       winget\nLibreOffice 26.2.3.2                               TheDocumentFoundation.LibreOffice 26.2.3.2      26.2.4.2      winget\nDell Command | Update for Windows Universal        Dell.CommandUpdate.Universal      5.4.0         5.7.0         winget\nMicrosoft Visual C++ 2010  x64 Redistributable - … Microsoft.VCRedist.2010.x64       10.0.30319    10.0.40219    winget\nMicrosoft Edge                                     Microsoft.Edge                    149.0.4022.62 149.0.4022.69 winget\nMicrosoft Visual C++ 2010  x86 Redistributable - … Microsoft.VCRedist.2010.x86       10.0.30319    10.0.40219    winget\nMicrosoft Windows Desktop Runtime - 6.0.12 (x64)   Microsoft.DotNet.DesktopRuntime.6 6.0.12        6.0.36        winget\nMicrosoft Visual C++ 2015 Redistributable (x86) -… Microsoft.VCRedist.2015+.x86      14.0.23026.0  14.51.36247.0 winget\nBrother iPrint&amp;Scan                                Brother.iPrintScan                10.5.0.74     15.2.0.11     winget\nMicrosoft Visual C++ 2015-2022 Redistributable (x… Microsoft.VCRedist.2015+.x64      14.44.35211.0 14.51.36247.0 winget\n10 upgrades available.\nPS C:\\&gt;</code></pre>",
            "image": "https://altbrain.net/media/posts/39/script-img2.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Windows Server",
                   "Windows"
            ],
            "date_published": "2026-07-01T08:23:00-04:00",
            "date_modified": "2026-10-05T22:41:43-04:00"
        },
        {
            "id": "https://altbrain.net/vmware-powercli-basics.html",
            "url": "https://altbrain.net/vmware-powercli-basics.html",
            "title": "VMware PowerCLI Basics",
            "summary": "If you are managing a VMware environment, doing everything through the vSphere client GUI can quickly become tedious. Enter PowerCLI, VMware’s powerful PowerShell module that allows you to automate almost any vSphere task. Whether you are spinning up a new automation pipeline or just need&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">If you are managing a VMware environment, doing everything through the vSphere client GUI can quickly become tedious. Enter <strong>PowerCLI</strong>, VMware’s powerful PowerShell module that allows you to automate almost any vSphere task.</p>\n<p class=\"wp-block-paragraph\">Whether you are spinning up a new automation pipeline or just need to quickly manage snapshots across your environment, having a few reliable go-to commands saves an immense amount of time. Below is a quick-start cheat sheet for installing PowerCLI, connecting to your vCenter, and managing VM snapshots.</p>\n<pre class=\"wp-block-code\"><code># Install the VMware PowerCLI module for the current user\nInstall-Module VMware.PowerCLI -Scope CurrentUser\n\n# Bypass untrusted SSL certificate warnings and connect to vCenter\nSet-PowerCLIConfiguration -InvalidCertificateAction Ignore -Confirm:$false\nConnect-VIServer vcenter.domain.local\n\n# List all virtual machines on this vCenter\nGet-VM\n\n# Create a new snapshot for a specific VM\nGet-VM \"servername\" | New-Snapshot -Name \"test snapshot\" -Description \"testing, hope it works\"\n\n# View all snapshots associated with a specific VM\nGet-VM \"servername\" | Get-Snapshot\n\n# Delete all snapshots for a specific VM (without prompting for confirmation)\nGet-VM \"servername\" | Get-Snapshot | Remove-Snapshot -Confirm:$false\n\n# List only the names of the snapshots on a specific VM\nGet-VM \"servername\" | Get-Snapshot | Select-Object Name\n\n# Find and delete a specific snapshot by its name\nGet-VM \"servername\" | Get-Snapshot -Name \"test snapshot\" | Remove-Snapshot -Confirm:$false</code></pre>\n<h3 class=\"wp-block-heading\">What’s Happening Under the Hood?</h3>\n<ul class=\"wp-block-list\">\n<li><strong>Installation &amp; Connection:</strong> The script starts by downloading PowerCLI directly from the PowerShell Gallery. It then suppresses self-signed certificate warnings, common in lab environments, before establishing a connection to the vCenter server.</li>\n<li><strong>The Power of the Pipeline:</strong> By using PowerShell’s pipeline (<code>|</code>), we can seamlessly pass a virtual machine object from Get-VM straight into snapshot management commands like New-Snapshot or Remove-Snapshot.</li>\n<li><strong>Automation-Friendly:</strong> By appending -Confirm:$false, the script bypasses interactive “Are you sure?” prompts, making these snippets perfect for embedding into larger, unattended automation scripts.</li>\n</ul>",
            "image": "https://altbrain.net/media/posts/38/script-img1.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Virtualization"
            ],
            "date_published": "2026-06-30T08:23:00-04:00",
            "date_modified": "2026-10-04T20:16:56-04:00"
        },
        {
            "id": "https://altbrain.net/managing-cisco-port-security.html",
            "url": "https://altbrain.net/managing-cisco-port-security.html",
            "title": "Managing Cisco Port Security",
            "summary": "I want to preface this by stating that although Port Security may still have a place, it’s a legacy approach, replaced with more modern standards like 802.1x &amp; RADIUS. I’d look at Cisco ISE, as a more enterprising way of managing who and what can&hellip;",
            "content_html": "<p class=\"wp-block-paragraph\">I want to preface this by stating that although Port Security may still have a place, it’s a legacy approach, replaced with more modern standards like 802.1x &amp; RADIUS. I’d look at Cisco ISE, as a more enterprising way of managing who and what can connect to the network. Nonetheless, for anyone specifically interested in Port Security, read on!<br><br>At its core, Port Security is a Layer 2 traffic filtering feature on Cisco switches that gives you control over exactly what can plug into a specific physical network port. It prevents rogue devices from establishing network connections. The feature looks at device MAC addresses, and based on the configuration of Port Security it will allow the connection of an allowed device, or potentially disable the port if a violation occurs. Some reasons to consider using it are:</p>\n<ol class=\"wp-block-list\">\n<li>Stops users from bringing in unauthorized home routers, wireless access points, or other network devices.</li>\n<li>Bad actors can use tools to flood a switch with millions of fake MAC addresses, blinding the switch and forcing it to broadcast all network traffic to every port. Port Security renders this attack useless.</li>\n<li>Ensures that critical wall jacks (like those in a reception area or conference room) can only be used by designated company hardware.</li>\n</ol>\n<p class=\"wp-block-paragraph\">Port Security relies on three main concepts:</p>\n<ol class=\"wp-block-list\">\n<li>Defining MAC addresses that are allowed to use the port. A switch can learn the MAC addresses a few ways.\n<ul class=\"wp-block-list\">\n<li>Statically – a switch ports running-config needs to be configured with MAC addresses.</li>\n<li>Dynamically – a switch port learns the device when first plugged in and only allows that device, the config is lost at switch reboot</li>\n<li>Sticky – the switch dynamically learns the MAC, saves it to the running-config and can survive a reboot if written to startup-config</li>\n</ul>\n</li>\n<li>Defining limits on how many MAC addresses can connect on a given port.</li>\n<li>Violation Modes determine what happens if a devices MAC is not on the “allowed to connect” list. The modes are:\n<ul class=\"wp-block-list\">\n<li>Protect – traffic from unauthorized MAC is dropped and valid traffic from approved devices pass</li>\n<li>Restrict – drops unauthorized traffic but logs the violation and increments the security violation counter</li>\n<li>Shutdown – this is the default behavior and places the port in an error/disabled state upon violation. The link is down until an admin resolves the port security violation.</li>\n</ul>\n</li>\n</ol>\n<p class=\"wp-block-paragraph\">An appropriate example here would be a scenario where a user (Jack) has 1 data port in his office. The upstream Cisco switch port has Port Security enabled and Port Security is set with a maximum limit of 2 MAC addresses remembered with the default Shutdown violation mode set. Connected to that wall port is an IP phone (unique MAC 1) and daisy chained to it is a desktop computer (unique MAC 2). At this point, all is good and everything is working normally for Jack. Later on, Jack finds a spare switch in an unused office and connects the 5 port unmanaged switch to his wall jack, to support more ports for connecting a printer and a laptop. Upon connecting the next device, the printer (unique MAC 3), Port Security senses that the limit has been exceeded resulting in a port security violation. The upstream switch port becomes disabled and now Jack has nothing.</p>\n<p class=\"wp-block-paragraph\">Now, if your curious to know what it’s like to manage this specific configuration (Sticky MAC, Limit=2, Violation Mode=Shutdown), specifically in offices where there’s constant people and equipment movement, it’s brutal so be warned. Decisions have consequences.</p>\n<p class=\"wp-block-paragraph\">Managing Port Security Violations (scenario is Sticky MAC, Limit=2, Violation Mode=Shutdown)</p>\n<p class=\"wp-block-paragraph\">First, you need to find out where the <strong>active</strong> Port Security violation is by reviewing the log. Using the scenario above, this is the port in Jack’s office where he plugged in the 5 port switch. Note the port number and MAC address that caused the violation.</p>\n<pre class=\"wp-block-code\"><code>show log</code></pre>\n<p class=\"wp-block-paragraph\">Next, find out if that MAC used to live on another port. This can be considered the<strong> abandoned</strong> port. Note that MAC addresses are case sensitive and Cisco’s MAC table stores them in lowercase format (example, 001a.2b3c.4d5e)</p>\n<pre class=\"wp-block-code\"><code>show port-security address | include [MAC address]</code></pre>\n<p class=\"wp-block-paragraph\">Now, let’s clear the port security violation on the abandoned port first so that it won’t become an issue later. Due to Violation Mode being set to shutdown, we have to down the abandoned port, clear port security on it, and then turn the port back on.</p>\n<pre class=\"wp-block-code\"><code>conf t\ninterface [abandoned_interface_name]\nshutdown\nexit\n\nclear port-security all interface [abandoned_interface_name]\n\nconf t\ninterface [abandoned_interface_name]\nno shutdown\nexit</code></pre>\n<p class=\"wp-block-paragraph\">Finally, we will clear the port security violation on the active port.</p>\n<pre class=\"wp-block-code\"><code>conf t\ninterface [active_interface_name]\nshutdown\nexit\n\nclear port-security all interface [active_interface_name]\n\nconf t\ninterface [active_interface_name]\nno shutdown\nexit</code></pre>\n<p class=\"wp-block-paragraph\">So we’re back to square one now, but Jack still needs that additional laptop and printer. To review, 2 additional MAC addresses are necessary for a total of 4 unique MAC address on the upstream switch port. Below is the configuration of a switch port that can meet the requirement.</p>\n<pre class=\"wp-block-code\"><code>interface GigabitEthernet1/0/12\n description Jack-Office Port with Port Security Enabled\n switchport mode access\n switchport access vlan 10\n switchport port-security\n switchport port-security maximum 4\n switchport port-security violation shutdown\n switchport port-security mac-address sticky</code></pre>",
            "image": "https://altbrain.net/media/posts/36/port-security.webp",
            "author": {
                "name": "Mike"
            },
            "tags": [
                   "Network",
                   "Cisco"
            ],
            "date_published": "2026-06-15T08:21:00-04:00",
            "date_modified": "2026-10-03T09:23:17-04:00"
        }
    ]
}
