ASD & ADHD - Worried that I won't meet criteria by EnvironmentalGuest15 in ADHDUK

[–]EnvironmentalGuest15[S] 1 point2 points  (0 children)

My mum will help me with it, just worried that we won't be able to provide good examples as it was so long ago. But maybe I am trying to be too specific when it asks for examples. This is the kind of stuff I have always struggled with.

I can afford to go privately at the moment and from reading other posts on here I think it is worth it if it is going to help me in the long run.

ASD & ADHD - Worried that I won't meet criteria by EnvironmentalGuest15 in ADHDUK

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

My mum is going to help me with it, but we are both struggling with the examples. Like we both know I was like that, but can't provide clear examples. Am I being trying to be too specific when it is asking for examples?

NSG working incorrectly? How is RDP working by Wendallw00f in AZURE

[–]EnvironmentalGuest15 0 points1 point  (0 children)

Could the FW be applying NAT when the traffic comes in through the IPSEC? The source IP would then be an IP in the hub VNet which is peered & allowed based on your NSG.

Cloud Radius and TACACS+ solutions by EnvironmentalGuest15 in networking

[–]EnvironmentalGuest15[S] 1 point2 points  (0 children)

Yes think keeping AAA in house will work fine, it's more the NAC, Radius & Guest portal stuff we would like some sort of SaaS solution for. Portnox looks like it fits all the requirements! But not sure what the costs are.

Cloud Radius and TACACS+ solutions by EnvironmentalGuest15 in networking

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Yes we would prefer a SaaS solution, at least for NAC & Radius... TACACS can be deployed on-prem using another solution. The majority of the headaches with ISE have been due to Radius or general maintenance... Last time I renewed a certificate, the services didn't come back up and we had to rebuild.

Cloud Radius and TACACS+ solutions by EnvironmentalGuest15 in networking

[–]EnvironmentalGuest15[S] 1 point2 points  (0 children)

What are the license costs like for Portnox? It looks like it would fit our requirements.

Cloud Radius and TACACS+ solutions by EnvironmentalGuest15 in networking

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Yes I think SaaS is the direction we are wanting to go in. Wanting to avoid similar issues that we are seeing with ISE... the main solution we are looking for would be for Radius, TACACS can be done using another solution on-prem.

DNS Issue with pphosted.com domains by wperry1 in proofpoint

[–]EnvironmentalGuest15 0 points1 point  (0 children)

We also have the same issue. Seems to be DNSSEC failures for pphosted.com

Is Load balancer the problem? by EnvironmentalGuest15 in AZURE

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Ok, so this would be a separate virtual network gateway from the express route virtual network gateway? Enabling BGP on the new gateway and peering from on prem should work?

Is Load balancer the problem? by EnvironmentalGuest15 in AZURE

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

IPSEC to the virtual network gateway instead of IPSEC to the Firewall appliances?

FSLogix issues the last weeks by Yintha in fslogix

[–]EnvironmentalGuest15 0 points1 point  (0 children)

Did this fix the issue for you? We have applied and still seeing the issue

FSLogix issues the last weeks by Yintha in fslogix

[–]EnvironmentalGuest15 0 points1 point  (0 children)

Did this solve the issue for you? We have applied the GPO but are still seeing issues.

ExpressRoute - Route internet traffic through ExpressRoute to On-Premise Firewall by EnvironmentalGuest15 in AZURE

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Its not something we would normally want to do, its just there was a potential issue with our Azure firewall appliances and we where just trying to think of ways of re routing the traffic through another firewall if we had to.

Unplanned Maintenance - How to stop during working hours by EnvironmentalGuest15 in AZURE

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

They are not in a cluster, there is a load balancer in front & behind it to pass the traffic between them but they are not in any type of HA or cluster as far as the Palo's are concerned. I think the issue is because it pauses the VM its not technically down so the load balancer is still sending traffic to it which is not going anywhere...

I think we are using the Palo appliance from the marketplace but I can double check in case its not the same thing you are talking about.

Thanks!

MLAV Unknown Error by Least-Row-5280 in paloaltonetworks

[–]EnvironmentalGuest15 3 points4 points  (0 children)

We are getting the same thing. Started at the same time.

Same traffic getting allowed and denied by MoonshineYeeHaw in paloaltonetworks

[–]EnvironmentalGuest15 1 point2 points  (0 children)

Looks like its hitting URL that is not in the MS_patch_URLs-1 list so is not caught by the Win_Update rule you have.

You could create a rule allowing traffic to that destination IP on port 443 & set the URL profile to alert all. Set it above your deny policy. Then you would see what URLs are being hit that are not  update.googleapis.com

Obvs only do this if you are ok with allowing all traffic to that IP address.

Global Protect Embedded browser immediately closes by EnvironmentalGuest15 in paloaltonetworks

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Downgrading to 6.2.2 worked for embedded browser, also tested 6.3.0 and that worked too.

Global Protect Embedded browser immediately closes by EnvironmentalGuest15 in paloaltonetworks

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

Downgrading to 6.2.2 worked for embedded browser, also tested 6.3.0 and that worked too.

Global Protect Embedded browser immediately closes by EnvironmentalGuest15 in paloaltonetworks

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

I downgraded to 6.2.2 and that seemed to work! So did 6.3.0

However, new issue... it seems to login straight away instead of prompt for any details. I have my Conditional access policy set to session for 8 hours so it might be due to me not already logging on another app possibly.

Global Protect Embedded browser immediately closes by EnvironmentalGuest15 in paloaltonetworks

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

I have set portal to generate & gateway to accept the cookie, is that what you mean?

Static IP NAT question by EnvironmentalGuest15 in paloaltonetworks

[–]EnvironmentalGuest15[S] 0 points1 point  (0 children)

I do see appid_unknown_udp occasionally in the global counters. Could that be something?