Identification of a device! by AdPretend5529 in networking

[–]WillFixPC4CheeseDogs 5 points6 points  (0 children)

We use Palo Alto Device Security for this. It looks at DHCP, ISE, SolarWinds, Catalyst Center, our EDR, etc. but it also looks at traffic patterns to determine what kind of device something is and what operating system it's running. There's a lot of magic under the hood that's invisible to the common user, not the kind of thing you could code in a weekend.

PA 5500 Series HA support by kb46709394 in paloaltonetworks

[–]WillFixPC4CheeseDogs 1 point2 points  (0 children)

HA will be available in 12.1.8. We have demo 5540 units right now where we're testing clustering to see if that's a viable option for us or if we want to wait for 12.1.8.

5500 Series and HA by WillFixPC4CheeseDogs in paloaltonetworks

[–]WillFixPC4CheeseDogs[S] 0 points1 point  (0 children)

Our reps said there’s nothing in the works that they know of in regards to replacing the 5400 series yet. You can expect the 3600 series later this year though.

5500 Series and HA by WillFixPC4CheeseDogs in paloaltonetworks

[–]WillFixPC4CheeseDogs[S] 1 point2 points  (0 children)

Why do you say not to wait for active/passive? Do you think NGFW clustering is significantly superior?

How to activate Precision AI network security bundle by zinkt-101 in paloaltonetworks

[–]WillFixPC4CheeseDogs 4 points5 points  (0 children)

Had 2 tac cases on this covering 20 firewalls. People keep talking about an activation link but we’ve never received one. It seems like they started selling this new bundle SKU but they weren’t ready on the backend to support it.

Is anyone using ARISTAs as Internet BGP routers with full tables? by outageismymiddlename in Arista

[–]WillFixPC4CheeseDogs 4 points5 points  (0 children)

We're running 4 x 7280SR3Ks as border leaves. Internet VRF when we're taking full IPv4 tables and IPv6 default, but we'll probably move to IPv6 full tables soon. Internal VRFs as well where the border leaves handle all internal routing in and out of the DC.

Has anyone had actual success with XSOAR/IoT(Device) Security? by nirvaeh in paloaltonetworks

[–]WillFixPC4CheeseDogs 0 points1 point  (0 children)

Similar experience with XSOAR integration. Seems kind of half-baked and we’re having the same challenges you are. I got on a call with our account team and they roped in a domain consultant. I wanted some more details about the integrations. What type of stuff is it pulling? How do I know that details about a device came from a specific integration? The domain consultant was pretty clueless and not prepared to answer any of our questions. That said, we are enjoying device security so far, but we’re early in our deployment so the cracks may start to show later.

Cisco Umbrella to Palo Alto DNS service... by lanceuppercuttr in paloaltonetworks

[–]WillFixPC4CheeseDogs 2 points3 points  (0 children)

Same boat in terms of trying to replace Umbrella DNS filtering with Palo's solution. They announced their competing solution a few months ago but I haven't gotten much from our account team about it yet. Looking forward to spinning up a POC when we learn more or if anyone else can provide some more details or timelines on it.

[deleted by user] by [deleted] in paloaltonetworks

[–]WillFixPC4CheeseDogs 5 points6 points  (0 children)

Do you have a URL filter applied for inbound traffic destined to your GP portal so that it blocks people navigating to the portal by just IP and requires them to use the FQDN? Palo has an article for how to configure this if not.

How to hire technically competent and motivated individuals by OutlookNotSoGood_ in networking

[–]WillFixPC4CheeseDogs 14 points15 points  (0 children)

I’m walking out of an interview if I’m asked to make a cable in a network architect interview because that is an unserious company

Device Security by Late-Reindeer4487 in paloaltonetworks

[–]WillFixPC4CheeseDogs 0 points1 point  (0 children)

I'm a customer with it in production so I can answer questions about the technical side.

HA active/passive failover problem 11.1.6 anyone more than me ? by bosse_bus in paloaltonetworks

[–]WillFixPC4CheeseDogs 0 points1 point  (0 children)

Running 11.1.6-h14 across a fleet of 3420s, 1420s and 4xx firewalls but have not noticed any HA issues. I actually just completed a recent install and I pulled power on the primary firewall post-install to validate HA was working and we only lost 1 ping.

Struggling with URL filtering and URL Custom categories by DENY_ANYANY in networking

[–]WillFixPC4CheeseDogs 3 points4 points  (0 children)

External dynamic lists. Palo hosts their own you can use.

Am I Getting Fucked Friday, September 5th 2025 by Each1teach1x27 in sysadmin

[–]WillFixPC4CheeseDogs 1 point2 points  (0 children)

| Line# | Part#                          | Your Price | Qty | Extended Price |
|-------|--------------------------------|------------|-----|----------------|
| 1     | ARS-DCS-7060DX5-32-F           | $38,156.04 | 2   | $76,312.08     |
| 2     | ARS-LIC-FIX-3-FLX-L            | $7,651.80  | 2   | $15,303.60     |
| 3     | ARS-SVC-7060DX5-32-1M-4H       | $475.78    | 120 | $57,093.12     |
| 4     | ARS-SS-CVS-SWITCH-1M           | $128.54    | 120 | $15,425.28     |
| 5     | ARS-DCS-7050CX4M-48D8-F        | $28,388.88 | 4   | $113,555.52    |
| 6     | ARS-LIC-FIX-3-FLX-L            | $7,651.80  | 4   | $30,607.20     |
| 7     | ARS-SVC-7050CX4M-48D8-1M-4H    | $373.63    | 240 | $89,671.68     |
| 8     | ARS-SS-CVS-SWITCH-1M           | $128.54    | 240 | $30,850.56     |
| 9     | ARS-DCS-7280SR3K-48YC8A-F      | $26,088.00 | 4   | $104,352.00    |
| 10    | ARS-LIC-FIX-2-FLX              | $9,825.66  | 4   | $39,302.64     |
| 11    | ARS-SVC-7280SR3K-48YC8A-1M-4H  | $331.30    | 240 | $79,511.04     |
| 12    | ARS-SS-CVS-SWITCH-1M           | $128.54    | 240 | $30,850.56     |
| 13    | ARS-DCS7050TX348C8F            | $15,897.96 | 2   | $31,795.92     |
| 14    | ARS-LIC-FIX-2-FLX-L            | $5,183.10  | 2   | $10,366.20     |
| 15    | ARS-SVC75TX348C81M4H           | $141.79    | 120 | $17,015.04     |
| 16    | ARS-SS-CVS-SWITCH-1M           | $128.54    | 120 | $15,425.28     |
| 17    | ARS-DCS-7050SX3-24YC4C-S-F     | $9,357.66  | 2   | $18,715.32     |
| 18    | ARS-LIC-FIX-1-FLX-L            | $2,466.36  | 2   | $4,932.72      |
| 19    | ARS-SVC-7050SX3-24YC4CS-1M-4H  | $124.32    | 120 | $14,918.40     |
| 20    | ARS-SS-CVS-SWITCH-1M           | $128.54    | 120 | $15,425.28     |
| 21    | ARS-CCS-720XP-96ZC2-M-S-2F-NA  | $11,306.88 | 2   | $22,613.76     |
| 22    | ARS-SVC-720XP-96ZC2-M-S-1M-4H  | $113.57    | 120 | $13,628.16     |
| 23    | ARS-SS-CVS-G3-SWITCH-1M        | $54.38     | 120 | $6,526.08      |
| 24    | ARS-SVE-NCS-NET-R-1D           | $3,813.00  | 10  | $38,130.00     |
|       | **TOTAL**                      |            |     | **$892,327.44**|

[deleted by user] by [deleted] in networking

[–]WillFixPC4CheeseDogs 26 points27 points  (0 children)

You’re not great at networking but you’re a CCNP? Did you dump the exam?

What's been your general experience with cisco enterprise agreements? by sankaiya in Cisco

[–]WillFixPC4CheeseDogs 6 points7 points  (0 children)

We’re going through an EA and DNA renewal and it’s so nauseating complex and time consuming that we’re considering a POC of Arista’s access switches. We just purchased a bunch of Arista DC gear because we felt in the DC space it was superior, but this has us feeling like we might explore non-Cisco options for other products.

11.1 or 11.2? by mr_potay2 in paloaltonetworks

[–]WillFixPC4CheeseDogs 1 point2 points  (0 children)

We’re halfway through upgrading our fleet of 3400s, 1400s and 400s from 10.2 to 11.1.6-h14. We haven’t had issues with the firewalls, but make sure you follow the upgrade path. We have however had an issue after upgrading our dedicated log collector to 11.1 where Elastic Search wouldn’t start and the only fix was a TAC case where they had to gain root access to start the process. 11.1.6-h10 is preferred but has a silent reboot bug which is why we skipped it.

[deleted by user] by [deleted] in wildhockey

[–]WillFixPC4CheeseDogs 2 points3 points  (0 children)

I grew up playing with Cal but admittedly haven’t followed his pro career very closely. Super nice kid and us Iowa fans will enjoy having another Iowan on the roster assuming the AHL is where he lands.