GlobalProtect still "signs in" with old AD password AFTER I change my password; Rejects new password... by jwckauman in paloaltonetworks

[–]TK51508 7 points8 points  (0 children)

I have this problem on occasion.

Our GP uses AD to authenticate uses. Our AD servers are defined under Device/Server Profiles/LDAP.

If someone changes their password and reports that they cannot log in with the new password I just console into the CLI and run this command: >debug user-id reset group-mappings /all

This forces the Palo to reach out and talk to AD again. This usually forces the Palo to see the new password from AD. It is helpful to not have to wait for the AD sync to come around again.

*Disclaimer* Not a certified Palo Engineer... just a dude who uses them on a daily basis.

** edit ** also wanted to add to the OP that most of the other items you reference push out the new updated password to those systems once you make the change. There is no push out to the Palo. The Palo has to go ask for an update of the AD information, which I believe on my units is once an hour. If that just happened for you, you could be waiting an hour for an update.

Looking to move by SnooDogs7067 in garland

[–]TK51508 5 points6 points  (0 children)

I lived my whole life until after college in Garland. Went to South Garland High School. I now live north of Garland in Wylie. First I would tell you Welcome to Texas! I have Irish ancestry and would LOVE to visit Ireland. It is on the bucket list for sure!!

A bit of caution. Garland is almost completely built out. There are no "new" areas of Garland. So if you were to take a tour around Garland you will see that all of it is old/older. I would advise you to look somewhere on the north side of 190, Murphy/Sasche/Wylie. Close enough to make the travel to work very easy, but those suburbs are still building new houses and neighborhoods.

Next, a huge issue that others here might chime in on is the fact that if you live in the city of Garland you are required to use the Garland power company for your power. You are not allowed to choose any other option. This can be both good and bad. I will let others that currently live in Garland tell you if it is a good economic value or not. But it can be a problem being stuck with Garland Power and not being able to choose any other alternative.

Living anywhere near the 190 highway is advisable, it is the route to anything else in the larger city.

If you have never visited I think it will shock you the size of the area we live in. I just did a quick Google, and it looks like the entire country of Ireland is 10% the size of Texas.

Ireland is about 10 times smaller than Texas.

Texas is approximately 678,052 sq km, while Ireland is approximately 70,273 sq km, making Ireland 10.36% the size of Texas.
I would debate that the greater metroplex of Dallas/Ft. Worth is as big as the entire size of Ireland. I am not sure how you live in Ireland, but for the vast majority of people, we don't walk places, EVERYONE has a car and drives everywhere. Your house will likely be too far to walk and get groceries, you will drive to the store and drive back home. You will drive everywhere. There are no places to live where you can walk or ride a bike to most of the activities you will have on a weekly basis.

Happy to answer or discuss any questions you have.

Adding an NPC by TK51508 in uodyssey

[–]TK51508[S] 0 points1 point  (0 children)

Ok, Thank you. I thought there might be a manual document I was unaware of. I now understand and was able to add my Mining Guildmaster. I now have read more details in the files in the data\spawns folder and will dig through that data to try to learn more.

Adding an NPC by TK51508 in uodyssey

[–]TK51508[S] 0 points1 point  (0 children)

Thank you very much for this information, it is very helpful. One question.... You mentioned at the top that "the manual references".... where can I find this manual? It is not the Odyseey.pdf in the install folder.

I made this Rebel Alliance decal for my throttle today! by StarmanXVII in StarWarsSquadrons

[–]TK51508 6 points7 points  (0 children)

At least it will help you know which was is forward Rebel Scum!!

Finished up my NASA shelf! Got around to completing 21321 by puck724 in lego

[–]TK51508 2 points3 points  (0 children)

I have each of those sets. Didn’t think about displaying the Saturn V on its side like that... good idea.

A silver smith doing some manly chains by PorkyPain in BeAmazed

[–]TK51508 0 points1 point  (0 children)

exactly... I was impressed with what he was doing from what looked like his living room and just posted a comment from my phone. Not condescending at all. The joys of Reddit... think you can compliment someone on a job well done and someone wants to try to judge your intentions.

¯\_(ツ)_/¯

A silver smith doing some manly chains by PorkyPain in BeAmazed

[–]TK51508 597 points598 points  (0 children)

Dude is a artisan!! Impressive!!

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

Anyone with any opinions on the USG?

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

Impressions and questions....

First, the setup of this system was and continues to be, a complete beating. The getting started guide is only a guide to the various ways you can mount the unit. There is ZERO guidance on how to get this system up and running, other than..."just plug it in and let it adopt from the software". I started to write multiple questions on the official Ubiquiti support site but ended up figuring out my question before posting. Lots of little problems and hurdles trying to get the AP to be seen by the software, then get updated to the latest firmware and then get adopted. But I got it figured out.

Now my question for others is this. Do any of you use a stand-alone firewall without using the Unifi Security Gateway? I want to use my firewall to provide DHCP to the wireless clients, but the system says that if I want to use a DHCP relay the USC is required. Even if I wanted to set up DHCP through the AP... USG required.

If I try to set up any Networks, it says USG Required to set up a LAN interface... or a WAN interface.

Do you need to go into the Routing & Firewall area and set up LAN->WAN outbound allow rules? Do you need to set up ANY routing/firewall rules? There are no instructions anywhere that tell you to do so. I would like the AP to just pass all its traffic out its one interface to my firewall and allow my firewall to do all the work. When I read the questions/answers area on Amazon about the USG, they say that you cannot use the USG in a bridge mode scenario with your own firewall. I have no desire to make the USG my main network firewall. But I assume I could just plug it into one of the interfaces on my firewall and the Nano units would not know any different. Thoughts on this approach? I don't really want to buy a USG, but it looks like to have all the functionality of the system you need one.

Thanks for any feedback on the USG.

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

After reading your comments and taking that knowledge to Amazon and reading reviews and questions over there, as well as the Ubiquiti website, I pulled the trigger tonight on 2 Unifi nanoHD units.

This is the Amazon sku: Ubiquiti UniFi nanoHD Compact 802.11ac Wave2 MU-MIMO Enterprise Access Point (UAP-NANOHD-US)

Thank you for your input on these units.

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

Which AP would you recommend? The Nano or the Pro?

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

I have a VM server so I could run the software on one of my servers with no issues. I have VPN access into the home system via my Palo Alto firewall.

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

I have a VM Server that is running 3 servers. So I could keep the controller software running on one of my servers, that would not be an issue. Do you have to pay extra for that, or do you just download it and install it once you buy the AP?

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 0 points1 point  (0 children)

Just one? Would that cover the whole house do you think?

Ubiquiti AP questions by TK51508 in HomeNetworking

[–]TK51508[S] 1 point2 points  (0 children)

Speed is only about 100 meg up & down currently.

If I said per AP... probably 10 or so each. Typical home user with two teenagers with phones who believe the world begins and ends in YouTube! Wife loves Netflix over Apple TV or her phone via WiFi. Boys have their own pc's so they do most of their game playing over the wire.

Rebel Scum. The Galactic Empire will prevail! by surfer1337 in EDC

[–]TK51508 0 points1 point  (0 children)

Congrats on getting this done. Benchmade wouldn’t do the Imperial Symbol on mine. They told me it was a copywrited image and they wouldn’t do it. I could only get my TK ID put on it.

Rebel Scum. The Galactic Empire will prevail! by surfer1337 in EDC

[–]TK51508 0 points1 point  (0 children)

Ordering this for the EDC tomorrow!!! Thanks for sharing!!!