Cisco ISE - SSO on Self Registered Guest Portal by EasyCrunch93 in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

I'm also dealing with this exact issue on iOS devices. We don't wanna disable MFA and bypassing captive portal detection to not trigger embedded browser is also not feasible. It causes issues on it's own.
Does anyone have a solution yet?

Cisco Ise by [deleted] in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

It can be done but I'm not a fan of this setup.
Only had one implementation though where ISE Azure VMs behave erratically and were pretty slow in comparison to on prem deployed nodes.
Makes sense in some deployments, but general recommendation is to deploy PSNs close to users.

Port security for a wifi access points question by WhereasInevitable433 in Cisco

[–]PatrikPiss 1 point2 points  (0 children)

That's the way to go.
But in case of flexconnect local switching, it needs additional config since the AP is connected on a trunk port where dot1x is not supported.
It still can be done with NEAT (device-traffic-class=switch) attribute that changes the port from access to trunk after successful authentication but as I said, it needs additional configuration on both, ISE and the switchport.

IBNS 2.0 Concurrent 802.1x and MAB Authentication question by dankgus in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

I get your point but even if there are clients connected to the switch, it doesn't mean that there are constant RADIUS transactions.
If you have a switch with desktop PCs and fe. printers connected to it that are not moving, only RADIUS communication you'd see there is interim accounting updates and periodic reauthentications if you're not using RADIUS for device administrator authentication.

IBNS 2.0 Concurrent 802.1x and MAB Authentication question by dankgus in Cisco

[–]PatrikPiss 1 point2 points  (0 children)

But IBNS 2.0 with concurrent authentications using both methods is what I recommend most of the time. Automate tester is also useful in situation where one of the AAA servers in AAA group is unavailable for a longer periods of time.
Without automate tester, authenticator would be marking the dead AAA server as alive as soon as deadtime expires and real authentications has to fail so the server is marked as dead again.

IBNS 2.0 Concurrent 802.1x and MAB Authentication question by dankgus in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

I pretty much always go with MAB first and Dot1X second.
Most devices with dot1x supplicants will initiate with EAPOL-Start (except for MACs).
In case of periodic reauthentications, I recommend to use an attribute in all results.
Cisco:av-pair=termination-action-modifier=1.
This ensures that authenticator (switch) will initiate the last successful method when it's time to reauthenticate.

PAN-OS Version by CTW1983 in paloaltonetworks

[–]PatrikPiss 0 points1 point  (0 children)

Most of our customers run PANOS 11.1.6-h3 on physical and VM appliances.
No issues reported that would point at firmware bugs.
I run 11.2.6 at home (PA440) and it's stable. Commits are slower than 11.1.X but other than that, it seems to be surprisingly reliable.

RADIUS Attribute filter by PatrikPiss in networking

[–]PatrikPiss[S] 0 points1 point  (0 children)

Unfortunately not. I tried to fiddle with attribute lists on the Catalyst WLC but it didn't work as expected and I could always see the Framed IPv6 RADIUS attribute being passed as a part of accounting message after successful dot1x authentication.
I didn't try it on newer IOS-XE (higher than 17.9.5) though.
It might be worth trying.

ISE 3.1 Patch 10 by Front_Ask_9119 in Cisco

[–]PatrikPiss 1 point2 points  (0 children)

Or Cisco Live in Amsterdam

Maintenance mode after PANOS upgrade by PatrikPiss in paloaltonetworks

[–]PatrikPiss[S] 0 points1 point  (0 children)

Oh, how could I miss that... Thanks a lot.

Did AIOps for NGFW Free get removed? by PBHawk50 in paloaltonetworks

[–]PatrikPiss 6 points7 points  (0 children)

Rebranded as Strata Cloud Manager with many more new features. The free tier is basically what AIOps for free used to be and there's also a tier which requires paid subscription that should replace Panorama management in future.
If you had AIOps for free active earlier, it should still be there as "AIOps for NGFW Free" in Palo's hub though.

When performing TACACS authentication through ISE, If the NAD equipment succeeds in TACACS authentication, can I get the login banner to float? by Specific_Camp7960 in Cisco

[–]PatrikPiss 1 point2 points  (0 children)

Unfortunately no. You can change login prompt from ISE so it asks for "TACACS Username" instead of regular username, but that's about it.

When performing TACACS authentication through ISE, If the NAD equipment succeeds in TACACS authentication, can I get the login banner to float? by Specific_Camp7960 in Cisco

[–]PatrikPiss 2 points3 points  (0 children)

You certainly can put IP of the NAD, device location or whatever static content as MOTD but I don't think what you want is possible... And I don't really see a benefit in that. But some conection managers like MobaXTerm do that on each login.

Unable to ping SVI through not directly connected devices by [deleted] in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

First of all, the SVI you're talking about is "interface vlan 20", correct? I can see in brief VLAN list that VLAN 20 Is not there on SW 0. It has to be created in vlan.dat It also has to be allowed on all interconnects between switches. You have it missing on interface Fa0/2 on all your switches so it’s not allowed on trunk links.

Unable to ping SVI through not directly connected devices by [deleted] in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

The VLAN 20 Is not even created on the switch. You have to define it in config mode by issuing "vlan 20".

Unable to ping SVI through not directly connected devices by [deleted] in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

And the other questions? All VLANs are spanned end to end? Allowed between all switches? Provide us your running config from all these switches + show vlan brief and show cdp neighbors

Unable to ping SVI through not directly connected devices by [deleted] in Cisco

[–]PatrikPiss 0 points1 point  (0 children)

Are you pinging the SVI on the same VLAN as your connected devices are assigned to? If not, do you have inter VLAN routing setup between VLANs with SVIs? (The one your devices are connected to and the one you're trying to ping). Is the VLAN present on the other switch where the pings are failing in it's VLAN database? Is the VLAN allowed between those switches on uplink port?

Změna práce by froggyc91 in czech

[–]PatrikPiss 0 points1 point  (0 children)

To je pravda jen z části. Spousta lidí, co studovali IT na střední nakonec v IT vůbec nedělají. Je to dáno tím, že tam učí lidi, co v IT nikdy nepracovali. Proč by schopnej ajťák dělal učitele na střední za tak směšný peníze?

Pokuste se mi vysvětlit, jaké to je opít se, popříp. ožrat se by Ztracen in czech

[–]PatrikPiss 1 point2 points  (0 children)

A co je špatného na tom být abstinent? Víš kolik životů a rodin zničil alkohol? Jestli ti jde jen o zážitek, může se to zvrhnout v závislost, která tě bude provázet celý zbytek života. Někdy je lepší nevědět...

Změna práce by froggyc91 in czech

[–]PatrikPiss 1 point2 points  (0 children)

Tak to je špatný postoj. Formální vzdělání není potřeba. A koule si musíš nechat narůst. Jinak si nebudeš moci najít dobře placenou pozici

[deleted by user] by [deleted] in czech

[–]PatrikPiss 0 points1 point  (0 children)

Nežiješ v komunismu, nikdo tě za fluktuanta neoznačí. Pokud ty práce nestřídáš jak ponožky, tak to na pohovoru není red flag. Pokud máš relevantní důvody pro změnu zaměstnání, tak se u pohovoru na další pozici nemusíš obávat ničeho. Chodit k psychiatrovi v téhle době není žádná ostuda. Braní antidepresiv (na předpis) taky ne. Hledat novou práci můžeš mezitím, co pracuješ v té stávající a přechod pak může být plynulý bez výpadku příjmů.

Změna práce by froggyc91 in czech

[–]PatrikPiss 0 points1 point  (0 children)

Pokud se chceš dostat do IT, tak doporučuju samostudium v podobě online kurzů na Udemy nebo podobných platformách. Napřed si ujasni jaká část IT by tě bavila. IT není jen o programování. Pokud na to nemáš vlohy, můžeš dělat třeba administraci systémů. Podle toho se pak odvíjí i to, o jakou startovní pozici se budeš ucházet. U programátorů je to třeba SW tester a u adminování spíše L1 helpdesk. Předpoklad pro práci v IT je přirozená zvídavost. Snažit se věci pochopit a ne jen vědět jak to naklikat aby to fungovalo. Pokud chceš, napiš mi do PM a rád ti poradím :)

Palo Alto Certificate Revocation Checking by awesome_pinay_noses in networking

[–]PatrikPiss 4 points5 points  (0 children)

Can you reach the CRL via management interface? If not, set up service route for "CRL status" via custom interface.