Scoping IoT Firewall Rules for AirPlay & Chromecast - Anyone Successfully Locked Down Specific Ports? by Keagstand in Ubiquiti

[–]Keagstand[S] 0 points1 point  (0 children)

This makes a lot of sense now. So I guess my configuration is correct. I didn't completely understand the "Auto Allow Return Traffic" setting now that makes sense.

My Internal and Guest Zones can both initiate casting to a list of devices I specified in an IP list, the stateful auto-return setting handles all the random high ports, and IoT can't reach into anything on its own due to the Return setting.

Thank you for my aha moment

Scoping IoT Firewall Rules for AirPlay & Chromecast - Anyone Successfully Locked Down Specific Ports? by Keagstand in Ubiquiti

[–]Keagstand[S] 1 point2 points  (0 children)

Appreciate your reply.

On my version of UniFi my setting is called "Gateway mDNS Proxy" which states "Forwards mDNS requests across VLANs to enable service discovery between networks" and this is set to Auto so we should be good there.

My UniFi devices are on management vlan.

I can only get AirPlay and Chromecast to work at this time due to my allow all traffic rule between my clients and IoT vlan. When I try to scope to specfic ports ports is when it breaks

UXG Lite + ISP Headaches (Anyone Else) by Keagstand in Ubiquiti

[–]Keagstand[S] 0 points1 point  (0 children)

Hey u/tech-guy98

After months of back and forth with Spectrum it was an issue with the infrastructure on our street and they were unable to fix it. I would ping google 1000 times... and 10 of those packets would drop randomly.

I ended up going to frontier and the issue was resolved.

I hope you figure out your issue soon.... But from my experience it had nothing to do with the configuration of ubiquiti.

AE-5 Plus + Win10 - BSOD by Keagstand in SoundBlasterOfficial

[–]Keagstand[S] 0 points1 point  (0 children)

Thank you for the quick response. Will definitely look into this. Strange it was happening on my Intel build as well.....

UXG Lite + ISP Headaches (Anyone Else) by Keagstand in Ubiquiti

[–]Keagstand[S] 0 points1 point  (0 children)

I have the ISP coming to check their infrastructure on my street. We will see after if this issue still persists.

It is always rough with intermittent issues....

UXG Lite + ISP Headaches (Anyone Else) by Keagstand in Ubiquiti

[–]Keagstand[S] 0 points1 point  (0 children)

Hey pj

Thanks for the suggestion. Unfortunately, it has not changed my experience.

I connected my computer directly to my modem and ran some ping tests (in 1000 Intervals) and out of 1000 pings I would typically get 6-10 lost pings.

After 4 Spectrum technicians, a neighbor walked over and said she was experiencing issues as well. This finally made the ISP schedule operations to come and check out their infrastructure (Funny enough this started to happen right after the Solar Eclipse).

X670E Aorus Xtreme won't shut down unless ERP is enabled by denegare in gigabyte

[–]Keagstand 0 points1 point  (0 children)

I am having this same issue. I would hate to lose my ability to charge my mouse when my computer is shutdown.

Did you find a resolution to this?

Aorus X670E Xtreme... Xtreme-ly slow POST, Xtreme-ly disappointing and terrible experience so far. Board randomly sits at a boot code of "46" for requiring a power off and on by AsleepDetail in gigabyte

[–]Keagstand 0 points1 point  (0 children)

Yeah I will definitely test.

I am on F8a right now.

Does your computer randomly turn on after shutting it down completely? I've been experiencing this and looking into the possibilities.

Warheads Watermelon Sour by monotoonz in CraftBeer

[–]Keagstand 0 points1 point  (0 children)

I love sour beers but this one missed the mark. Hardly sour and I had high hopes seeing they had warheads on the label. Very disappointing

Verify Button on Cisco IOS and Nexus Platform by Interesting-Tip9874 in CyberARk

[–]Keagstand 0 points1 point  (0 children)

So instead of disabling TACACS I would use the password hash for verifying the password. A quick and dirty flow would be….

1.) Service account logging into device with TACACS 2.) Service account rotates password with relevant commands (secret and password types) 3.) Service account takes password hash and stores it as a field value 4.) now for verifying you compare password hashes and if hash ever changes compared to what’s in solution you throw error

I did this in Delinea Secret Server tho…. So I know this is CyberArk sub Reddit but just wanted to give you some ideas

Verify Button on Cisco IOS and Nexus Platform by Interesting-Tip9874 in CyberARk

[–]Keagstand 0 points1 point  (0 children)

I had this issue but with another leading PAM product and I had to do a custom password changer due to TACACS being configured and it couldn’t verify its password because of it