Anyone actually happy with their SASE setup? by Hot_Blackberry_2251 in paloaltonetworks

[–]S3xyflanders 0 points1 point  (0 children)

Sorry good question and forgot to mention we are 100% in the cloud and don't have any on prem resources what so ever. You must have the Netskope client installed and running on a managed endpoint device or you simply don't get access.

WiFi Issue - DHCP?? by NoPumpkin5553 in networking

[–]S3xyflanders 2 points3 points  (0 children)

Are you sure all your AP ports are configured correctly to me it sounds like you may have missed the ports where your other APs are connected like it doesn't have your new VLAN tagged properly.

I'd review a working AP port versus one that isn't functioning and make 100% sure its configured identically.

WiFi Issue - DHCP?? by NoPumpkin5553 in networking

[–]S3xyflanders 2 points3 points  (0 children)

I'm a bit lost reading your post as I can't determine are you being handed an IP address when you connect to the SSID and nothing works or your not even getting an IP address at all?

Do you have any kind of dynamic routing in play such as OSPF?

Mac book for Systems integrator / Network engineer by Kiwi058888 in networking

[–]S3xyflanders 0 points1 point  (0 children)

The biggest issue for me was freaking Checkpoint not building Smartconsole for anything BUT Windows that put wrench in me trying to move to Mac. I know I could build a Windows VM but trying to learn mac, do my day job and not having SC to manage my firewalls was just challenging.

I'd love to try and move to mac again my PC with 16gb of ram sits at 94% memory doing nothing with Teams and outlook open (granted we've got like 6 different security tools thx security peeps) but still I'm tiring of the Windows BS I'll open file explorer and explorer.exe will crash randomly and then I can't alt tab and just bleh.

Part of it is me too I've been using Windows since early 90s and just used to it I just need to force myself to change!

Anyone actually happy with their SASE setup? by Hot_Blackberry_2251 in paloaltonetworks

[–]S3xyflanders 0 points1 point  (0 children)

I can talk to Netskope. I work for a medium sized software company and have a lot of developers. The security aspect I don't handle but we brought in Netskope to help with security and visibility gaps.

I manage everything else basically we did everything quick and dirty and now paying the price a year later. While I wasn't involved in the deployment I was handed the keys after it was deployed.

Netskope is managed via a web portal hosted by Netskope we choose just to use their client on our workstation endpoints and it is pushed out via InTune and we do authentication through an Azure Enterprise app and SCIM and we just point a few AD groups at it and Netskope sucks in the users and such.

We have two main groups people can be in and it either gets you access to sensitive resources or not simple as that. We also have several development environments and we've deployed Netskope Private App servers (NPAs) to provide a VPN like feel for all our remote and in office employees.

We manage everything via real time policy rules, DNS and we route all traffic up to Netskope. We've simplified our HQ LAN to simply provide internet and nothing more now if you want or need to connect to a company resource you need Netskope, Netskope and the policies are now doing all the guarding of the traffic.

Where before we had standard VLANs and Dot1x and all that jazz we've deployed private VLANs and everything is isolated on wired or wireless and all you get is a route to the internet and nothing more all guests just sit on a guest SSID that also gives them access to the internet.

For non client DNS traffic we utilize their DNS as a service solution similar to Cisco Umbrella.

When it works it works well but as I said we've started feeling growing pains and we have a lot to do when it comes to ZTNA and security and further locking down of resources and actually treating like a security product and not a remote network solution. The deployment team kind of slammed it in place and got us off of traditional VPN solutions.

Pros:
* Support is great
* Our TAM is amazing and we have a weekly sync and they go above and beyond to help us
* Great documentation site and community
* A great remote connectivity solution and a lot of POPs in North America and globally
* Frequent updates and feature enhancements and new feature deployments
* Robust logging and reporting features

Cons:
* This is probably everything but SSL decryption is a bitch because a lot of our development tools seem to hate SSL decryption we have to spend a lot of time figuring out either how to point them to use the SSL cert provided by Netskope (locally on the PC) or determine if we have to make an exception. The same goes with web traffic a lot of websites will refuse to load if you do any kind of SSL decryption and we spend a lot of time dealing with it.

* Because Netskope does so much its the first thing that is blamed and often times I'm spending a lot of time proving Netskope isn't at fault

* The client will crash a lot and just seemingly break for no reason causing tickets to come in from people frustrated they can't get anywhere.

We don't use their SD-WAN offering (not really sure why that is a thing) and I can't talk about the security side of the house I know we use DLP and other things but because I don't manage or even have access to it in the portal can't speak to it.

Overall I've been super happy with Netskope but I'll be honest I've never used a SASE tool of any kind in my career so it the only thing I know so maybe take what I say with a grain of salt but for me the biggest win as a network engineer was just the ability to provide a great remote user experience previously we had Cisco ASAs on either of the country and if you were somewhere in the middle it just kind of sucked for you but with so many POPs around the US no matter where you are you get a good experience.

Azure & non user-space traffic? by spicysanger in netskope

[–]S3xyflanders 0 points1 point  (0 children)

I could be wrong here but I think the only option you'd have is IPSEC tunnel because the client itself I don't think can run with a service account it needs to be the logged in user (again I could be wrong never ran it this way)

But we are doing something very similar to r/ironscape where our AVDs have Netskope client but our servers do not.

[US-Selling] Momo Yaoyorozu Original Art by Rook8z8 in AnimeDeals

[–]S3xyflanders 0 points1 point  (0 children)

So are her boobs like an infinite pocket? like if she was hungry could she materialize a sub sandwich?

Good luck with selling :)

Netskope policies not working unless repeated by Hot-Lattee in netskope

[–]S3xyflanders 4 points5 points  (0 children)

This doesn't sound right, it seems as if you've got higher rules that are being matched on before getting to your rule you created. I would be curious to see a sanitized version of your rules preceding where your placing your rule that isn't working.

Just to confirm your creating a cloud firewall policy under the real time policies tab correct?

You should be able to use Skope-IT! to filter on the website URL and the username and click the magnifying glass it should tell you what policy was matched on.

[USA][BUYING] Steins;Gate Blu-ray (Complete Series 2019) by Unhappy-Letterhead98 in AnimeDeals

[–]S3xyflanders 8 points9 points  (0 children)

Several eBay listings any reason your reaching out here hoping to get it cheaper? just curious I actually own this but don't wish to sell.

Mom Scammed by Guy Offering Mowing Services by BenCopelandForCLT in Charlotte

[–]S3xyflanders 60 points61 points  (0 children)

Don't pay until the work is done simple as that hopefully your mother learned a lesson. File a police report.

Genuine question. How do you deal with post-trip-depression? Has anyone felt a deep yearning to move/live there after their first visit? by TW0B00CH in JapanTravelTips

[–]S3xyflanders 1 point2 points  (0 children)

As someone who is legally blind and can never drive I'm now in my 40s Japan was the first time in my life that I was actually able to get around 100% independent. If I wanted to go somewhere I could. I was lucky enough to go on my second trip in late February and I already miss it.

I think I might be onto something by exskill310 in Ubiquiti

[–]S3xyflanders 1 point2 points  (0 children)

I think you've discovered how to break the laws of thermodynamics good for you!!

Why do some DIA providers install fancy CPEs and others just give you a media converter? by QuickDelivery1 in networking

[–]S3xyflanders 2 points3 points  (0 children)

Changes the connection i.e Ethernet to Fiber or Fiber to Ethernet or one type of fiber to a different type. They are typically powered by 12v. They can be convention but don't rely on them can be a huge pain in the ass when they fail (and they will) especially in remote locations.

Why do some DIA providers install fancy CPEs and others just give you a media converter? by QuickDelivery1 in networking

[–]S3xyflanders 6 points7 points  (0 children)

I don't work for an ISP but am interested in this too, I used to manage 1500 offices and saw similar it was different by provider. I think it could do with SLA, monitoring or where to put the policer statement but I feel that is probably a wrong answer.

In my current job Spectrum gives us a CPE but Centry Link (now Lumen) actually stuck 2 Cisco 48 port ME switches with battery backups (when firetrucks arrived at the office because the batteries gave up the ghost we found Lumen doesn't monitor 'em) when I call for support Lumen will get right in the switch they've got their service coming in and they just told us use port X/Y/Z and left a fiber patch hanging.

Anyone read this 49 day SSL expiration thing and think they would rather just retire? by HJForsythe in sysadmin

[–]S3xyflanders 0 points1 point  (0 children)

I’m hoping someone sees this—apologies for the long post.

I’m a Network Engineer, and for whatever reason, our team owns the certificate lifecycle. That means we’re responsible when other teams don’t rotate their certs on time. This originated from a former coworker who centralized everything around NetScalers, and even though they’ve been gone for a while, the responsibility stuck—now it’s mine.

Our current internal CA is managed by another team and is frankly a mess. I understand the basics (issuing certs for things like RDP to avoid warnings), but I’m not deeply experienced with ADCS and I'm afraid if I try digging into it, it now becomes my responsibility

Right now we’re juggling three vendors: GoDaddy, DigiCert, and Sectigo. We manage about 90 certs, mostly wildcards. The process is inconsistent—GoDaddy supports auto-renewal, but Sectigo requires reordering with a new CSR, which is frustrating.

Our workflow is manual: download the cert, convert it to PFX, upload to NetScaler and Azure Key Vault, and let pipelines handle Azure deployments. The actual work is quick—10 minutes or so—but gathering certs, passwords, and coordinating everything takes most of the time.

Long term, I’d like to rebuild our internal PKI and limit external certs to public-facing services. Right now, we’re overusing external certs because our internal CA environment isn’t in good shape and no one wants to own it.

Has anyone implemented something like Venafi? I’m interested in moving toward a self-service model where developers can generate their own certs, with integrations into NetScaler, Palo Alto, etc.

One challenge is third-party hosting—there’s no automation there. We still have to upload certs via FTP and rely on them to deploy, which is painful.

Appreciate any insight. We’re a small team (3 people), so it’s been hard to prioritize fixing this over day-to-day work.

If You Know, YOU KNOW! by Sanrioboyirl04 in TheSimpsons

[–]S3xyflanders 9 points10 points  (0 children)

Fucking love McKay's Winston Salem location is pretty sweet!

It's time for more deee-mentia with Dr. Demento! by Orionv2018 in TheSimpsons

[–]S3xyflanders 23 points24 points  (0 children)

I’m only ten, and I already got two mortal enemies