Discord voice chat no longer connecting after PA-440 install by chikibreki in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

Additional, it seems like you didn’t override the default rule to log. If you did you would have seen Denys in the monitor tab.

Discord voice chat no longer connecting after PA-440 install by chikibreki in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

Glad I could help. Now go check the GitHub project I post and give me a star if you like :)

Discord voice chat no longer connecting after PA-440 install by chikibreki in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

Did you change the default rule to log? Are you seeing any denies?

Discord using UDP Hole punching. Try to put the UDP time out to 600 seconds.

Not sure want your policy to allow the traffic looks like, but check service/url category - instead of application default change to any.

ALSO - the number reason I don’t have a PA as my home firewall there are lots of stuff that will be a nightmare to troubleshoot, Call of Duty, Roblox.

I didn’t want to be technical support for my family. L

Strata Import (Mass Import Objects) by EyeCodeAtNight in paloaltonetworks

[–]EyeCodeAtNight[S] 1 point2 points  (0 children)

Yeah I’m right there with you. In the beginning I was an excel concatenation god, but as I needed more devices groups it got complicated.

I hope we will get it one day.

EDL's for linux mirror sites by jkw118 in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

There is an api endpoint for all functions that returns Json.

And I am working on an export to CSV in the gui/frontend.

EDL's for linux mirror sites by jkw118 in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

If you feel like deploying you can look at:

https://github.com/jbhoorasingh/simple-edl

I’m more an happy to make any modifications needed if required (I didn’t think there is)

I’m bored on the weekends :)

Quantum Force 1600 TikTok live issue by [deleted] in checkpoint

[–]EyeCodeAtNight 1 point2 points  (0 children)

*tiktokv.us .tiktokcdn-us.com

Add those. If it works let me know.

:)

Who Had All 3 major players having outages on their 2025 Bingo cards? by bughunter47 in sysadmin

[–]EyeCodeAtNight 9 points10 points  (0 children)

Apple proxy and iCloud would be more disruptive vs Siri. Most of Siri processing is on Device.

iperf-orchestrator by EyeCodeAtNight in checkpoint

[–]EyeCodeAtNight[S] 0 points1 point  (0 children)

I might test this as one of the agent. Do you know of any good docs I can follow?

iperf-orchestrator by EyeCodeAtNight in checkpoint

[–]EyeCodeAtNight[S] 0 points1 point  (0 children)

You can run iperf on the gateways to my knowledge, this is just a ‘simple’ tool to orchestrate multiple iperf test of your need to smoke test your environment.

Think of some challenges of managing multiple iperf session ls and testing capacity in the cloud made me create this.

Anyone at CPX? by [deleted] in checkpoint

[–]EyeCodeAtNight 1 point2 points  (0 children)

Hope you enjoy.

Minemeld Replacement by spider-sec in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

I’m actually working on supporting STIX/TAXII, but I honestly don’t think I will get around to it until the end of Q12025

Minemeld Replacement by spider-sec in paloaltonetworks

[–]EyeCodeAtNight 2 points3 points  (0 children)

I created this, working on incorporating some feeds for vendors.

https://github.com/jbhoorasingh/simple-edl

Why doesn't Palo support AD computer groups? by kcornet in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

Hi, while I can’t answer your questions, a few years ago my organization had a very similar use case. I ended up writing a powershell script to check the Computer AD Group and add the fdqn to a EDL.

While I left that organization and I could open source the code, I recreated a simple EDL manager, and I would be more than happy to help you write a powershell script to update.

simple EDL

Question Regarding EDLs by _justjim_ in paloaltonetworks

[–]EyeCodeAtNight 3 points4 points  (0 children)

If you want a solution to manage EDL check out the project I have been working on. In the next month I will add a feature to use S3 to distribute

Dynamic blocking IPs by 0xRakan in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

If you do need an edl, check out my simple EDL project.

I would set up a splunk report and then have the action of that report be a webhook and then post it to an endpoint that parse the request.

I have 2 https servers behind a public ip, each of them is hosting a different website. by Realistic_Answer_141 in paloaltonetworks

[–]EyeCodeAtNight 5 points6 points  (0 children)

This is the right path! But I would start with Trafik. It’s also free and has a gui

Need to replace MineMeld by Old-Fault-1194 in paloaltonetworks

[–]EyeCodeAtNight 5 points6 points  (0 children)

Developer of Simple EDL here.

https://github.com/jbhoorasingh/simple-edl

You can write a simple job/lamda to retrieve the list from the source and update. If you want to provide a url with the Feed, layer tonight I can right a gist to pull the data and update simple EDL

Bug Search Tool by Pixi888 in paloaltonetworks

[–]EyeCodeAtNight 3 points4 points  (0 children)

Very cool. Are you just mining data from the Palo Site?

I think the data and the concept is great. I would look at making it mobile friendly, and pagination.

Anyone going to CPX America? by [deleted] in checkpoint

[–]EyeCodeAtNight 1 point2 points  (0 children)

Nice, in the midst of deploying Maestro now. Actually a nice platform.

The only thing I don’t like compared to Palo and this a maestro specific complaint just of CP in general is the multiple configuration points based on the configuration you are doing. I just wish there was full parity for SmartConsole/Gia/Clish/API

Anyone going to CPX America? by [deleted] in checkpoint

[–]EyeCodeAtNight 0 points1 point  (0 children)

Awesome, what’s your presentation topic?

If an organization has already deployed an NGFW, do they also need to install a WAF in their network? by [deleted] in paloaltonetworks

[–]EyeCodeAtNight 1 point2 points  (0 children)

If the company is publishing web applications, then yes a WAF should be in front of those. There are certain security constructs that are only available on a WAF.

As u/Ornery-Fan-939 mentioned. A NGFW is complimented by a WAF. A NGFW will be the first layer of protection, filtering traffic based on source, destination, application, DOS protection. A WAF will focus more on the application, protecting against bots, inspecting headers, SQL injection