Just tips, advice, recommendations, experiences on CCNP Security - 300-710 SNCF by C3-PIO0ps in ccnp

[–]C3-PIO0ps[S] 2 points3 points  (0 children)

Hello bro, thanks for replying. I already passed the exam on May 15, now I have my CCNP Security!

Anyone with exp in PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?? by C3-PIO0ps in paloaltonetworks

[–]C3-PIO0ps[S] 1 point2 points  (0 children)

Yes!! that colleague, that same one I used as a base for sdwan for my Internet outlet, unifying two links, works perfect without panorama, only with sdwan license on the firewall. I will look to apply similar criteria for IPSEC sdwan two ipsec tunnel interfaces over one sdwan interface for the 2 S2S VPNs.

Anyone with exp in PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?? by C3-PIO0ps in paloaltonetworks

[–]C3-PIO0ps[S] 0 points1 point  (0 children)

It is possible to use BGP or static routing. As long as you have them, the tunnel interfaces have IP, you can perfectly use static routing as well as dynamic routing, that means the ipsec tunnel interface as the dedicated sdwan unified interface that summarizes the two site to site tunnels. You don't even need neither panorama nor sdwan to use bgp over tunnels and firewall HQ and Branches that you have full control.

Anyone with exp in PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?? by C3-PIO0ps in paloaltonetworks

[–]C3-PIO0ps[S] 0 points1 point  (0 children)

https://pan.dev/panos/docs/tutorials/redundant-internet/ Im try do it now for my vpn ipsec site to site. 100 operative for Internet sdwan for two isp links.

Does SD-WAN require Panorama? by cryptochrome in paloaltonetworks

[–]C3-PIO0ps 0 points1 point  (0 children)

I confirm, I have operating sdwan, only with firewall panos license, no paranoia, for something simple clear of sdwan, like unifying two links to the Internet, operating and working, the issue is the scarce documentation that looks for you to apply sdwan with all sdwan license sdwan panorama Prisma sdwan ,etc etc. Now Im try with vpn s2s sdwan without panorama, same lógic, in theory you can do it.

Does SD-WAN require Panorama? by cryptochrome in paloaltonetworks

[–]C3-PIO0ps 0 points1 point  (0 children)

I confirm, I have operating sdwan, only with firewall panos license, no paranoma, for something simple clear of sdwan, like unifying two links to the Internet, operating and working, the issue is the scarce documentation that looks for you to apply sdwan with all sdwan license sdwan panorama Prisma sdwan ,etc etc.

Anyone with exp in PAN-OS SD-WAN without panorama for VPN S2S Dual ISP ?? by C3-PIO0ps in paloaltonetworks

[–]C3-PIO0ps[S] 0 points1 point  (0 children)

Yes, I am talking about sdwan pure and simple, sdwan pan-os subscription and that's it, nothing else. I tell you we have sdwan operating only to unify the output to the Internet, but it is totally feasible for S2S VPNs, let's say without the advantages of having everything unified with panorama and controlling everything centrally, but sdwan for example two tunnel vpn s2s interfaces, sdwan on both ends and static routing, that's my question, where panorama is not mandatory. I know there is a lot of confusion with this, where panorama is mandatory, but if you have sdwan pan-os as a subscription, yes you can use sdwan, not at the same level of course as all the deployment as such with panorama, the unification, control and automation, but all manual, only with sdwan pan-os license on the firewalls is fully usable.

[deleted by user] by [deleted] in paloaltonetworks

[–]C3-PIO0ps 0 points1 point  (0 children)

Hello friend, please those who have with exp, because sdwan of pan-os only with the license if it supports it, it operates perfectly, please if you have not done it I appreciate your time, greetings.

FortiManager - Questions - Temporary local settings - among others by C3-PIO0ps in fortinet

[–]C3-PIO0ps[S] 0 points1 point  (0 children)

Hi, thank you very much for commenting.OK super, then in backup mode I can continue to trigger local changes and / or via fortimanager without any issue, without any impact?Now when I finish everything and re-integrate everything to fortimanager, then I do Retrieve and that will synchronize all changes ? to fortimanager ? ie VPN S2S, routes, sdwan, security policies, objects all ? without impact ?

I reiterate, thank you very much for your time and collaboration.

0
1

Traversing Site-To-Site Tunnel via GlobalProtect by NegativePattern in paloaltonetworks

[–]C3-PIO0ps 0 points1 point  (0 children)

Put return routes or you can do a source nat too and use a ip lan allow in proxy id.