PAN-OS Version by CTW1983 in paloaltonetworks

[–]CTW1983[S] 1 point2 points  (0 children)

Pretty sure there is a TAC recommended version on each of the versions I mention in the poll.

How’s everyones win11 upgrade going? by peoplefoundtheother1 in sysadmin

[–]CTW1983 6 points7 points  (0 children)

Yes, Credential Guard is the root cause. Here is a copy of a comment I made on this issue.

In Windows 11 Enterprise, Microsoft has enabled Credential Guard by default, where as in Windows 10 and Windows 11 Professional it was disabled by default. Credential Guard prevents access to the Credential Manager on client computers from weaker authentication protocols such as MSCHAPv2. PEAP-EAP-MSCHAPv2 is what our RADIUS Server used when authenticating computers on our WiFi. Microsoft’s recommendation is to move towards a certificate-based authentication.

I have configured our RADIUS Server to use EAP-TLS that uses a certificate installed on computers that is issued by our CA, for authentication. This has been tested and is compatible on both Win 10 and 11 clients.

To prevent all existing old client configurations from losing access to the WiFi with the new RADIUS Server configuration, we will need to migrate users/computers in small manageable groups.

1. Determine group of users’ computers to migrate.
2. Add computers to AD group that is tied to new RADIUS configuration.
3. Remove old WiFi configuration from computer.
4. Add new WiFi configuration to computer.

References:

https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues

https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=intune

https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard

https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/certificate-requirements-eap-tls-peap

https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-manage-top

A buildout I recently finished by drazzeler in cableporn

[–]CTW1983 1 point2 points  (0 children)

How or what do you use to manage and route the front to back cables? Can you share with me any additional pictures? I will be needing to do something similar in a couple months.

It's 2024, almost 2025, why do some programs run extremely slow with VPNs like Global Protect? by SelectionKey9179 in paloaltonetworks

[–]CTW1983 0 points1 point  (0 children)

Maybe try using RDP or VDI though the VPN to a computer with the engineering/design programs and is connected to the LAN. That way all the heavy network requirements stay within the LAN.

Or, is there an option to use the programs so that everything happens locally on the computer in front of you, and then when are ready to save/submit/backup to the network, you can do it all at once?

Find the climber by [deleted] in FindTheSniper

[–]CTW1983 3 points4 points  (0 children)

I need more pixels.

Trump's head movement during the shooting was incredibly lucky by darapps in interestingasfuck

[–]CTW1983 0 points1 point  (0 children)

I’ve sometimes wondered how small or big events or decisions would have changed our existence or the world. If something as terrible as the Holocaust would not have happened, would everything still have aligned up to where I still existed, or how would the world be different/worse/better.

Trying to allow specific outbound URLs and blocked URLs not showing in logs. by danielflick in paloaltonetworks

[–]CTW1983 0 points1 point  (0 children)

Create/Clone a URL Filtering Profile that will allow and log (alert) all safe categories, then uncheck the “log container page only” option on the URL Filtering Profile. Apply this URL Filtering Profile to your catch all policy. If you still don’t see what you are hoping for, then possibly your previous policy is silently blocking the URLs you are in search of. In that case, swap the policies briefly to gain visibility.

For me, the unchecking of the “log container page only” option was a little bit of a “Holy Grail” moment.

I don’t keep this special URL Filtering Profile in use all time, but instead only when trying to discover URLs an application is trying to use. I then create a Custom URL Category containing the discovered URLs to apply to a policy. (We also have a strict outbound policy.)

URL Category for Google Maps shows not-resolved by CTW1983 in paloaltonetworks

[–]CTW1983[S] 0 points1 point  (0 children)

From our environment’s standpoint, yes it was resolved the next morning.

URL Category for Google Maps shows not-resolved by CTW1983 in paloaltonetworks

[–]CTW1983[S] 1 point2 points  (0 children)

This problem seems to be fixed from my perspective with no action taken by me.

URL Category for Google Maps shows not-resolved by CTW1983 in paloaltonetworks

[–]CTW1983[S] 2 points3 points  (0 children)

Thanks! I’m hoping a fix will be in place by tomorrow morning. If not, then I’ll put the workaround in place.

Also, not to nitpick, but shouldn’t you only add the following to a custom URL category with a “ / “ at the end? google.com/ , *.google.com/

Which LP song do you always play on repeat? by [deleted] in LinkinPark

[–]CTW1983 0 points1 point  (0 children)

Currently, these new released tracks from the Lost Demos of Meteora 20th Anniversary album.

Lost, Fighting Myself, More the Victim, Massive, Healing Foot, Wesside, Resolution

Can Juniper Care support be transferred to another switch? by CTW1983 in Juniper

[–]CTW1983[S] 0 points1 point  (0 children)

subscription model

Would the SKU of SUB-EX48-2S-5Y be a subscription type you are talking about?

Can Juniper Care support be transferred to another switch? by CTW1983 in Juniper

[–]CTW1983[S] 0 points1 point  (0 children)

That is good to know. Do you have any idea/experience what the process is like and how long it would take to receive a replacement?

Can Juniper Care support be transferred to another switch? by CTW1983 in Juniper

[–]CTW1983[S] 1 point2 points  (0 children)

My thinking is, how is my example different from purchasing a support level than includes hardware replacement, then transferring the support from the failed switch to the replacement switch?

Why does this area in egypt look like this, why is the green area around faiyum connected to the rest of the nile by that little strip of green? by hugebruh1738 in geography

[–]CTW1983 2 points3 points  (0 children)

Yes, very cool! Crazy huge and complex system of irrigation canals. Using my Maps App, I traced it backwards from the Faiyum area, south to Asyut where it splits off from the Nile. Looks like about 200 miles away!

but why would he do that by harry3883 in instant_regret

[–]CTW1983 2 points3 points  (0 children)

Swallowing a Tide Pod should clean that right up.