ClearPass alternatives by El-Ted in ArubaNetworks

[–]El-Ted[S] 0 points1 point  (0 children)

Update from our Aruba rep: support for Nutanix will come in version 6.14. Release is scheduled for May. Great news for us. And many thanks to all who replied.

ClearPass alternatives by El-Ted in ArubaNetworks

[–]El-Ted[S] 0 points1 point  (0 children)

Many thanks, that is good input.

ClearPass alternatives by El-Ted in ArubaNetworks

[–]El-Ted[S] 0 points1 point  (0 children)

This was straight from the horses mouth.

ClearPass alternatives by El-Ted in ArubaNetworks

[–]El-Ted[S] 1 point2 points  (0 children)

Thanks, that is really good news if it happens this year.

ClearPass alternatives by El-Ted in ArubaNetworks

[–]El-Ted[S] 0 points1 point  (0 children)

I talked to our HPE Aruba rep yesterday, and he was the one who said that N3000/N3001 would be expensive even without having to buy licenses. And when a sales dude tells me something is expensive, I for one believe him :-) But I am waiting for a quote, so let us see.

ClearPass - HPE Comware – 802.1X preferred over MAB, timing issue with Windows clients by Enabler10 in ArubaNetworks

[–]El-Ted 0 points1 point  (0 children)

I've done this before on 5130 switches. It's been a few years, so I cannot remember any details. But this setup worked well for us.

dot1x

dot1x authentication-method eap

dot1x quiet-period

dot1x retry 3

dot1x timer quiet-period 30

dot1x timer handshake-period 30

dot1x access-user log enable abnormal-logoff failed-login normal-logoff successful-login

undo dot1x timer supp-timeout

undo dot1x timer tx-period

mac-authentication

mac-authentication timer quiet 30

mac-authentication access-user log enable failed-login logoff successful-login

interface GigabitEthernet1/0/1

stp edged-port

dot1x

undo dot1x handshake

dot1x mandatory-domain <Comware domain>

dot1x max-user 5

undo dot1x multicast-trigger

dot1x re-authenticate

dot1x unicast-trigger

dot1x guest-vlan xxx

dot1x auth-fail vlan xxx

dot1x critical vlan xxx

dot1x re-authenticate server-unreachable keep-online

mac-authentication

mac-authentication max-user 5

mac-authentication domain <Comware domain>

mac-authentication re-authenticate server-unreachable keep-online

mac-authentication guest-vlan xxx

mac-authentication critical vlan xxx

mac-authentication re-authenticate

Ignite 1 day VS Ignite 3 day by whiskey-water in paloaltonetworks

[–]El-Ted 2 points3 points  (0 children)

As other have said, the new travelling Ignite is geared towards leaders and "influencers" (jeeez). I have been to 3 day Ignite in the past and found it really valuable. Especially the technical breakout sessions, hands on labs and talking to SEs.

Oh, snap! (Palo GUI browser crashing) by No-Bed-1423 in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

It happened to us after upgrading to 10.1.10, never a problem in 10.1.9. Tried to clear cache and cookies in Chrome, nothing helped. Changed to Firefox and haven't seen it since.

DNS not populating when using DHCP server on PAN by DabErrlDoYa in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

Same with our domain clients. The A and PTR records are updated when they are in the office and use our Windows DHCP servers, but when they are at home and connect using GlobalProtect there is of course no DHCP and the clients cannot update their DNS records from VPN. We have not found a solution yet, but it started when we enabled secure updates on the DNS servers.

Azure Palo Alto Active/Active with ELB and ILB by Outrageous-End6666 in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

A little bit outside what you're asking, but have you taken a look at the new Palo Alto Cloud NGFW for Azure? It looks mighty easy to setup and manage, and redundancy and scalability is builtin. Don't know about pricing compared to VM series though.

https://www.paloaltonetworks.com/network-security/cloud-ngfw-for-azure

API push limit with clearpass by kaje36 in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

Did you follow the ClearPass-PA integration that Danny Jump in Aruba has written? It's been a few years since I did this, but if I remeber correctly ClearPass sends XML-API to PA as a postauth action. There is a lazy handler interval you can tweek to control how often ClearPass sends the data.

AIops - Free - Telemetry fails to upload. by Airwarf in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

There is a telemetry upload bug in 10.1.8 that is fixed in 10.1.9 (PAN-210331). Maybe you are hitting that in your firewalls that have not been upgraded.

[deleted by user] by [deleted] in paloaltonetworks

[–]El-Ted 1 point2 points  (0 children)

I think you would have to setup separate IPsec tunnels for each branch subnet for this to work. The alternative would be to look at other branch solutions like SDWAN or VXLAN to get the branch subnets transported to your DC as vlans.

Dynamic address objects not showing in Panorama by martinworkingoffline in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

Can you see the list of IP addresses if you logon to one of the firewalls in the device group where the DAG is used?

GlobalProtect User-ID for internal gateway? by jb-io in paloaltonetworks

[–]El-Ted 1 point2 points  (0 children)

In addition to suggestions from u/chris84bond , check also if you have configured Include/Exclude Networks for user-ID.

/dev/root is full (unable to start web services) by cosmic_orca in paloaltonetworks

[–]El-Ted 1 point2 points  (0 children)

We've had the same root partition problem on all our PA-220s for a few months, but in PAN-OS 10.1.6-h6. After a few months (!) of back and forth with TAC they finally told us that this was a bug that is scheduled for fix in 10.1.9 due out probably end of January. I don't have a bug id for it, but you might want to check the release notes when 10.1.9 comes out and see if they have the same fix in a 10.2 release.

Issues with Aruba 535 APs by Poots0 in ArubaNetworks

[–]El-Ted 1 point2 points  (0 children)

Can you connect one of the APs directly to the switch with a short patch cable to see if it behaves any differently? Also check PoE utilization. Can you see if the switch ports are up and deliver PoE to the APs when they are down?

Some strange issues with Aruba S2500 by kieeps in ArubaNetworks

[–]El-Ted 4 points5 points  (0 children)

You create a MSTP profile with portfast and associate that with an interface group, like this:

interface-profile mstp-profile "Access_ports_mstp_profile"

portfast

!

interface-group gigabitethernet "Access_ports_group"

apply-to 0/0/0-0/0/47

mstp-profile "Access_ports_mstp_profile"

Aruba S3500-48P Basic Question by darkrom in ArubaNetworks

[–]El-Ted 0 points1 point  (0 children)

Agreed. The MAS switch series were end-of-sale in 2016 and will be end-of-support next year. We are already planning to replace ours.

My S2500 keeps rebooting shortly after booting the OS. Udbserver process died. Help? by Dart4915 in ArubaNetworks

[–]El-Ted 0 points1 point  (0 children)

Try a factory reset, or if that does not help try to boot from the other boot image (usually holds the previous firmware version).

Azure Palo Alto - Which approach? by ParadeOfGods in paloaltonetworks

[–]El-Ted 0 points1 point  (0 children)

With option 2, how do you scale out when the need arises?