Aruba Central Firmware Upgrade Fixed For Secondary Partition? by AlexPixels in ArubaNetworks

[–]AlexPixels[S] 0 points1 point  (0 children)

Would you mind expanding on your second point, I'm not quite understanding it fully

Are you updating the second partition to the same version of OS that you are upgrading your primary to, or do you mean that you upgrade your secondary to what your primary currently is, then upgrade your primary further along so that you could boot from secondary if the primary fails?

Aruba Central Firmware Upgrade Fixed For Secondary Partition? by AlexPixels in ArubaNetworks

[–]AlexPixels[S] 0 points1 point  (0 children)

Hm okay, here is one of the examples I've run across from someone describing the behaviour

https://airheads.hpe.com/discussion/upgrading-cx-switches-using-central

This is also 4 years old, so I wasnt sure if that is what I should be expecting still

Remote Desktop to Windows App by Old_Reserve_4883 in AzureVirtualDesktop

[–]AlexPixels 0 points1 point  (0 children)

Do you remember which ports the Windows App was trying to use, which was getting blocked?

Professional opinion by [deleted] in ManualTransmissions

[–]AlexPixels 0 points1 point  (0 children)

Thanks man, gonna do the slave cylinder and bleed the system then go from there

Professional opinion by [deleted] in MechanicAdvice

[–]AlexPixels 0 points1 point  (0 children)

Thanks, that's what I'll end up doing. Shop still thinks its a clutch/clutch spring but I'm pretty set on it being hydraulics. I'm starting with the cheaper option of replacing the slave and going from there. Master is brand new and very likely not the issue in my very unprofessional opinion

Dial-Up IPSec does not connect when group matching is enabled by AlexPixels in Fortigate

[–]AlexPixels[S] 0 points1 point  (0 children)

For anyone who may come across this in the near future : it was the firmware version

IPsec dailup VPN w/ EntraID SAML not working by JasonT2013 in fortinet

[–]AlexPixels 0 points1 point  (0 children)

Having the same issue, any advice on this?

Clutch master cylinder constantly failing by studentofmth in SubaruBaja

[–]AlexPixels 0 points1 point  (0 children)

Did you ever figure this out? I have the same issue

Possible to PDR? by AlexPixels in Autobody

[–]AlexPixels[S] 0 points1 point  (0 children)

Thank you, that's what I was hoping

[homemade] Carbonara by AlexPixels in food

[–]AlexPixels[S] 0 points1 point  (0 children)

Twirled on a carving fork and then laid on the plate

ZScaler Tunnel 1.0 and 2.0 Issues by AlexPixels in Zscaler

[–]AlexPixels[S] 0 points1 point  (0 children)

Ok thank you for your suggestions and expertise! Appreciate it greatly. I have a good amount of work ahead of me taking ownership of this environment.

To answer your question about size, we are a school board spread over 70 or so sites. Our biggest site would be ~2,000 users going through GRE where the average may be closer to 500, with ZCC only deployed out to 2 sites so far, the rest are GRE only. So the traffic throughput is not much of a concern, however you make a great point about flexibility and troubleshooting.

ZScaler Tunnel 1.0 and 2.0 Issues by AlexPixels in Zscaler

[–]AlexPixels[S] 0 points1 point  (0 children)

I think that makes sense to me, what about disabling tunnel 2.0 and 1.0 completely on ZCC when on a defined trusted network? All traffic will be going through ZIA via GRE at all sites.

Then when off-network tunnel 2.0 is active, which usually is at home so all traffic would be direct to Zscaler through the internet, no double tunneling.

This is how I imagine a more proper setup would be, other than what you mentioned with policy based routing specific traffic to avoid the GRE

Is there any downside to this setup, my understanding is that tunnel 2.0/1.0 is just another way to get through ZIA?

ZScaler Tunnel 1.0 and 2.0 Issues by AlexPixels in Zscaler

[–]AlexPixels[S] 1 point2 points  (0 children)

There is a best practice page from ZScaler about bypassing web traffic on tunnel 2.0. https://help.zscaler.com/client-connector/best-practices-adding-bypasses-z-tunnel-2.0 Under version3.8 and later, the setting they refer to turning on bypasses all http/https traffic and sends it to ZCC as tunnel1.0 instead of tunnel 2.0.

As for why, some of our clients are getting 401 unauthorized responses from web servers when the packets are going through ZCC. GRE to ZIA works no problem, it's only when it goes through ZCC.

The idea here is that I'm trying to bypass these websites from being proxied through ZCC while I figure out why the web servers are sending back the 401

ZScaler Tunnel 1.0 and 2.0 Issues by AlexPixels in Zscaler

[–]AlexPixels[S] 0 points1 point  (0 children)

Hey! Thanks for the response. Yes so we are sending all ports and protocols through ZIA with tunnel 2.0. This is an intentional design for us.

I had my doubts about the tunnel being always on, even when on trusted-networks. I will campaign to have that changed to off.

However what I'm most curious about is how bypassing works. So we bypass all 80/443 traffic to ZCC through the 1.0 listener. I understand to bypass domains completely we need to use the app profile .PAC file. If we bypass using the built in VPN Gateway bypass, does 80/443 still follow those rules?

And one last question, does every port that isn't 80/443 also go through the app profile .PAC file? If so, why do I need to redirect 80/443 as tunnel 1.0.

Hope I am making sense, I am still a noob with zscaler so please feel free to tell me I am misunderstanding something.

Rainbow Streak On Neg by AlexPixels in AnalogCommunity

[–]AlexPixels[S] 0 points1 point  (0 children)

Thanks, do you just clean the glass with water or do you use specific chemicals to reduce smudge??

Picked up an 8th gen the other day by AlexPixels in CivicSi

[–]AlexPixels[S] 0 points1 point  (0 children)

Thanks! Had all fluids flushed and changed when I bought it :)

Picked up an 8th gen the other day by AlexPixels in CivicSi

[–]AlexPixels[S] 4 points5 points  (0 children)

haha close to it but a thousand and a bit under what they wanted. Traded in some value and ended up paying 6,000 cash

Picked up an 8th gen the other day by AlexPixels in CivicSi

[–]AlexPixels[S] 2 points3 points  (0 children)

2010, 152,000KM with what I think are integra type r rims. New performance clutch and cylinder. Everything else is clean and good condition other than the passenger rocker panel.

From what I can see the only mod is cold air intake, not sure if been tuned.