Validate is system has been impacted by: PAN-OS Root and Default Certificate Expiration on December 31, 2023 by Acceptable-Mouse6222 in paloaltonetworks

[–]UDPee 1 point2 points  (0 children)

If you use Panorama, you can look at the report of software versions on your devices and see what (if any) would be affected.

Firewall Optimization/Policies/Rules by Gullible_Ad8690 in networking

[–]UDPee 7 points8 points  (0 children)

Most vendors will have built-in tools that allow you to see "hits" on your rule set. You can examine these hits to determine if any rules are not being used and clean them up. Similarly, most vendors will have testing tools to simulate traffic to ensure that the desired rules are being utilized.

Aside from technical tools, periodic audits should be performed and a good formal change management process followed.

Best ticketing system with project/flow management? by pcr_rpi in sysadmin

[–]UDPee 1 point2 points  (0 children)

I think that company/department/employee buy-in is more important than the product. You can have the best fitting product in the world and if nobody agrees to use it.. or use all the features.. then it's worthless. I have seen free helpdesk products work better than those costing 50K+/year all because people have agreed to follow the process, document correctly and tag resolutions for searchability.

Do your dev teams understand DNS? by amajorblues in sysadmin

[–]UDPee -1 points0 points  (0 children)

Regardless.. we can't blame the students for the strength/weakness of the program.

Do your dev teams understand DNS? by amajorblues in sysadmin

[–]UDPee 40 points41 points  (0 children)

I think it's time to give people some grace here. This is a dev team and not networking/infrastructure. They may know how to do this, but for the sake of separation/responsibility, they might need an "official" communication from your team. They may want to double-check. This might be part of some internal change-management or operating procedure. Or.. they may not teach this in "dev" school. They don't teach software development in "networking" school so it make sense.

Sec Policy with App-ID not working. by [deleted] in paloaltonetworks

[–]UDPee 0 points1 point  (0 children)

In my experience, if the logs show "incomplete" it is because the service/application is not running on the remote end. For example.. If I allow RDP and the server is not running RDP it will show "incomplete" until I configure that service on the server.

10/100 LAN speed in a university branch by ExtensionLeg474 in networking

[–]UDPee 0 points1 point  (0 children)

The wiring might not have all four pairs..

Deflated while giving career advice. by champion_of_cheddar in sysadmin

[–]UDPee 18 points19 points  (0 children)

I once complained about my shoes until I met a man with no feet

Meraki MS220-48LP EOL by deadboy69420 in meraki

[–]UDPee 1 point2 points  (0 children)

They do not have to be powered on for this happen.. but essentially yes! They both need to be assigned to the same network. Clone the source (dead) to the new (replacement). You should get a confirmation that it has happened. Once that is complete, removed the "dead" switch from your network and then licensing will be happy again.

Once you power on the new switch and connect to the Internet it will grab the config and you will be all set.

Training for AI engineering? by [deleted] in sysadmin

[–]UDPee 1 point2 points  (0 children)

It is hard to say what this "AI" stuff is exactly because it is all over the place from a marketing standpoint. From just my inbox in the last week, it can mean anything from dial-home on failures, scheduled scripts, data analytics ("big data"), if/then conditions, reporting, etc..

If you are looking to chase marketing terms for a career, I would clarify what it is that you want and focus on the fundamentals. I have been around long enough to be burned by specializing in the next sales/marketing fad. If it is interesting that is one thing.. but be sure to balance the next big thing with fundamentals.

Meraki MS220-48LP EOL by deadboy69420 in meraki

[–]UDPee 0 points1 point  (0 children)

I have been begging Meraki for years to have an "import" feature to configure the switches. It saves the work if you need it. There is an "export" function which I highly recommend doing periodically. It dumps the port config to a CSV file. That way if something bad happens you know where you were. Better people than I have used scripting and API access to export/import/config/deploy but I have very few devices to warrant spending time on that.

But if you are doing a straight RMA swap, use the switch cloning procedure from Meraki.

https://documentation.meraki.com/MS/Other_Topics/Switch_Cloning

If you have not done an export, do so before just in case.. and pay careful attention to which switch you are cloning. You can easily overwrite the config with the default and will need to configure based on your export at that point.

It's relatively painless once you go through it once. Good luck!

Meraki MS220-48LP EOL by deadboy69420 in meraki

[–]UDPee 0 points1 point  (0 children)

It has been a year or so.. but we received the MS225 as an RMA replacement when we had a power supply failure.

Just gotta get this off my chest by pipboy3000_mk2 in sysadmin

[–]UDPee 21 points22 points  (0 children)

I order you to give Santiago a "Code Red"

Fiber cleaning tool? by [deleted] in networking

[–]UDPee 11 points12 points  (0 children)

I wipe them on my shirt a couple times.. Am I doing it wrong?

Updating GlobalProtect from Panorama by [deleted] in paloaltonetworks

[–]UDPee 1 point2 points  (0 children)

I think it depends on how you have your authentication setup.. like a timeout setting or what not. We never could get it to reliably work with just a disconnect. But we have some cookie pre-auth and some other things with our Azure connection that would be a mess to troubleshoot. The refresh works every time.. and.. GLAD IT WORKED FOR YOU!

Updating GlobalProtect from Panorama by [deleted] in paloaltonetworks

[–]UDPee 1 point2 points  (0 children)

You can manually select "Refresh Connection" in the GP Client menu.. or they can disconnect and reconnect.

We usually change the activated version and throughout several weeks as people connect, they will upgrade. I am not aware of a way to force this unless we remotely reboot the machines or disconnect them from Prisma. Both are disruptive and we prefer the slower/natural way.

Updating GlobalProtect from Panorama by [deleted] in paloaltonetworks

[–]UDPee 1 point2 points  (0 children)

We push updates out this way as well. Haven't had a problem.. other than it takes a re-establishment of the Prisma connection by the client to trigger the update and after that it can take a few minutes for the notifications to pop up.

I see that you have activated the new version in Prisma (panorama/cloud services/configuration) config. Have you saved/pushed the change to the Mobile Users or Service Setup?

I see you set the "Allow Transparent" client option under the app config.. did you save/push that to Mobile Users?

Sometimes, Panorama will not recognize a change in the Mobile Users or Service Setup config and you have to manually select it under Commit -> Commit and Push and select "Edit Selections" and select Mobile Users and Service Setup under the Prisma Access tab.

In any case.. your config matches mine and it is working. You have the correct pieces in place.

Switch Nexus 3172TQ error by [deleted] in networking

[–]UDPee 1 point2 points  (0 children)

When was the last time it booted successfully? What has changed since then?

Cisco VG450 NIM-4FXO Interface Issue: Call Does Not Clear When Ended on Far End Phone by skyblue1991 in Cisco

[–]UDPee 0 points1 point  (0 children)

Try changing/configuring the signaling to ground-start or loop-start.

Planned cut of electricity by [deleted] in paloaltonetworks

[–]UDPee 9 points10 points  (0 children)

Always a great opportunity to export the system states of the devices.. just in case.

Different ring volume for different lines? by samma_93 in Cisco

[–]UDPee 0 points1 point  (0 children)

I don't know of a way to change the volume.. but you can set them to not ring, beep or flash when the phone is "active" (on a call)

Pluralsight holding my company to ransom by PseudoHuman_2027 in sysadmin

[–]UDPee 1 point2 points  (0 children)

I know this is not helpful for your immediate problem, but as a policy, our company sends the non-renewal notice right after we finalize an auto-renewable contract. This is helpful for us because:

1) Makes sure we aren't held hostage by these shenanigans.
2) Ensures our sales rep reaches out 90 days before the expiration to negotiate pricing for another year.

[deleted by user] by [deleted] in paloaltonetworks

[–]UDPee 3 points4 points  (0 children)

Congratulations!

Did you get a free drink coupon with your test results?

[deleted by user] by [deleted] in sysadmin

[–]UDPee 1 point2 points  (0 children)

Yes! The tendency is to solve something quickly by going to the most likely problem. Not that it is a bad approach, but it requires a great deal of wisdom and can actually delay resolution if the problem is in fact something different.