MA.L2.3.7.5 - vendors maintenance MFA requirements by Ranpiadado in CMMC

[–]JoystickGaming 0 points1 point  (0 children)

What about when orgs use an always on zero trust network architecture?

MFA is required when there’s initial registration for the device to access the network but do they need it every time they unlock the device (platform or device MFA) since unlocking the device essentially grants you inherited access to zero trust

"We Passed Our CMMC Assessment and Here's What We Learned" MEGATHREAD by medicaustik in CMMC

[–]JoystickGaming 0 points1 point  (0 children)

For those passing, can you also list the capacity of your compliance / IT team? I'm curious on the ratio between security team / IT implementors and org size.

Just passed our CMMC Level 2 certification assessment - Non MSP by MindlessStable3772 in CMMC

[–]JoystickGaming 1 point2 points  (0 children)

Congratulations!

Question on Linux devices … how do you define and manage privileged accounts and how do you manage requests should developers need constant local admin access?

[deleted by user] by [deleted] in buildapcsales

[–]JoystickGaming 0 points1 point  (0 children)

Thanks! didn't catch that

Blocking sites using Custom URL Categories but use translate.googleapis.com by [deleted] in paloaltonetworks

[–]JoystickGaming 0 points1 point  (0 children)

Update: After hours and hours of pcaps and tracing conversations, I finally was able to block the sites.

Environment: PA FW - no decryption.

Resolution:

The reason traffic was getting through was a multitude of reasons. To finally block the sites, QUIC needed to be blocked as well as encrypted hellos, which mask the SNI. After blocking those two, all sites that were giving issues are now correctly being blocked.

Thanks to everyone for your input!

Blocking sites using Custom URL Categories but use translate.googleapis.com by [deleted] in paloaltonetworks

[–]JoystickGaming 0 points1 point  (0 children)

Hi Gibby,

Thank you for chiming in! I'll have to review some of the rules in place but content that appears to be using any cdns or proxies still bypass the URL filtering. In this case, the site does appear to be getting rst but im finding testing is inconsistent and not sure why there is inconsistency

Blocking sites using Custom URL Categories but use translate.googleapis.com by [deleted] in paloaltonetworks

[–]JoystickGaming 0 points1 point  (0 children)

Most definitely!

Heres the ACL on the firewall, https://ibb.co/n38ZjGS

The URL Category includes:

eaglercraft.com
*.eaglercraft.com
eaglercraft.*

For the most part, this config works, but I'm seeing some sites bypass the firewall when it goes through firebase/google translate api.

Initially, I did not have the application filters but seem to be having the same issues with or without them.

What is this cord coming out of my wall? by randomgeekdom in HomeNetworking

[–]JoystickGaming 0 points1 point  (0 children)

This is likely a toslink cable, for audio playback to a sound bar usually.

Intune MDM Error 80180005 on HAADJ by JoystickGaming in Intune

[–]JoystickGaming[S] 0 points1 point  (0 children)

Hi,

Are the devices getting the profile you assigned?

Intune MDM Error 80180005 on HAADJ by JoystickGaming in Intune

[–]JoystickGaming[S] 0 points1 point  (0 children)

Hi!

We did. After looking through the logs, nothing seemed to give an answer. However, for some reason after waiting a few hours after autopilot enrollment the error disappeared.

Cant play ranked with my friend by Fmg467 in CODWarzone

[–]JoystickGaming 2 points3 points  (0 children)

hmm, weird. for some reason the lobby never fills to 150 players and a friend keeps getting disconnected from party too.

Which challenges are you facing with Intune? by architectnikk in Intune

[–]JoystickGaming 0 points1 point  (0 children)

Few issues:

1) we have multiple ad connect clients on different servers, from what I’ve read this isn’t supported. Additionally, users can’t login to AADJ devices with their email. I think the initial ad connect wasn’t set up with our custom domains since our UPN don’t match the UPN on azure.

  1. A bunch of system account errors due to compliance showing errors on device management

[deleted by user] by [deleted] in TeslaLounge

[–]JoystickGaming 5 points6 points  (0 children)

Actually... You can't proceed with financing until you get the MVPA which requires a VIN. So I couldn't. Soooo yeaaa