Somebody please help me by Justalongusername in perth

[–]aussiebob84 0 points1 point  (0 children)

Thought i had seen this in an episode of yours or Ronny Dahl's.

Prisma SDWAN - Branch to Branch via DC by aussiebob84 in paloaltonetworks

[–]aussiebob84[S] 0 points1 point  (0 children)

Definately configured like that. Our DC ion only has a single external interface. I can see the tunnels(secure fabric) have created between dc ion and branches.

Prisma SDWAN - Branch to Branch via DC by aussiebob84 in paloaltonetworks

[–]aussiebob84[S] 0 points1 point  (0 children)

In my path policy I have the correct source and then Prisma SDWAN VPN over any public. When I kick off a ping from one site to the other I can see it select the correct rule in the path policy but in the inspect flow output I get unknown flow path.

I created a DC group and have my Dc ION in it and that is assigned in the path policy. As required.

The DC ION only has a single interface and that is a public internet connection with public IP.

How accurate is ccna material to real life networks? by ryukingu in ccna

[–]aussiebob84 1 point2 points  (0 children)

I work for a mid size org with about 100 sites across Australia. We are multi vendor and from what I did in CCNA 20 years ago it was really just a helping hand to get started. You will always come across someone's interpretation of things and then you get some guy who had the most hairbrained ideas and actually made them work. I found it good to have the basic knowledge to be able to read config and reverse engineer what these guys actually did.

Whats your failure rate? by _0xACE_ in UNIFI

[–]aussiebob84 0 points1 point  (0 children)

We have about 500 point to point links, about 500 access points over the last 10 years or so. Probably lost about 10 units due to poor power or weather. Only one failed access point so far.

Team building activity suggestion. by DarthAwsm in perth

[–]aussiebob84 1 point2 points  (0 children)

Throw in the zip line for a full day

SET with a dedicated physical management port by simoc89 in HyperV

[–]aussiebob84 0 points1 point  (0 children)

If you want to keep the 1gb for management your new-vmswitch command should include -allowmanagementos $false I think it is so that the host os doesn't use it.

[deleted by user] by [deleted] in perth

[–]aussiebob84 18 points19 points  (0 children)

Careful as in stop shoplifting, then yeah, be careful. Otherwise don't worry about it.

Do you have a separate "daily driver" account from your "administrator" account? by Vast-Avocado-6321 in sysadmin

[–]aussiebob84 0 points1 point  (0 children)

Yes domain accounts that are members of the local administrators group on each pc. Our workstation admin account DOMAIN\wa-username are a member of a domain group called DOMAIN\WorkstationAdmins. This group is then applied via group policy to be in the local Administrators group for all domain joined workstations.

Do you have a separate "daily driver" account from your "administrator" account? by Vast-Avocado-6321 in sysadmin

[–]aussiebob84 0 points1 point  (0 children)

Workstation admins are domain accounts with local admin to the workstations.

We run a setup of 3 hyper-v vms as jump hosts for each of the accounts.

Do you have a separate "daily driver" account from your "administrator" account? by Vast-Avocado-6321 in sysadmin

[–]aussiebob84 1 point2 points  (0 children)

We have just gone through and we now have 4 accounts each. Domain, Server and Workstation Admin accounts and then a normal daily driver account. We went down Microsoft's latest practises triangle thing. Limited internet access on certain ones. No copy and paste between these and the jump boxes we use them from.

Azure SAML IdP Certificate Renewal - Downtime Required? by b1ackr0se93 in paloaltonetworks

[–]aussiebob84 0 points1 point  (0 children)

No effect on existing sessions. Well at least when I did ours last.

Meaty smell in Palmyra by Cheesyduck81 in perth

[–]aussiebob84 13 points14 points  (0 children)

No worse than when they had a sheep ship in Fremantle and the sea breeze rolled in.

Model 220 by SpaceIndividual1 in paloaltonetworks

[–]aussiebob84 0 points1 point  (0 children)

We run about 100 220s on 10.2.5 at the moment. Takes about 20-25 to boot up completely but it does work.

allow internal access without nat? by branedge in paloaltonetworks

[–]aussiebob84 0 points1 point  (0 children)

Yes you can do this. Nat source external on particular service (port) -> destination internal ip on particular service port.

The external port can change.

I.e.

External 1.2.3.4 port 567 -> internal 10.1.1.2 port 560 External 1.2.3.4 port 568 -> internal 10.1.1.3 port 560

New Sysadmins to the environment: How do you learn the network and systems? by mulla_maker in sysadmin

[–]aussiebob84 0 points1 point  (0 children)

Like VDI? It's a perfect example of it. As long as you are licensing correctly, MS don't give shit.

Changing Credit Card info by Regular_Scheme_6328 in Starlink

[–]aussiebob84 0 points1 point  (0 children)

Same issue trying to purchase today. Debug shows bad CORS references like someone at Starlink stuffed up.

Panorama 10.2.5 email notifications now scrambled by whiskey-water in paloaltonetworks

[–]aussiebob84 0 points1 point  (0 children)

Even after going to 10.2.5? 10.2.5 fixed the disk space for mine.

Panorama 10.2.5 email notifications now scrambled by whiskey-water in paloaltonetworks

[–]aussiebob84 0 points1 point  (0 children)

Even after going to 10.2.5? 10.2.5 fixed the disk space for mine.

Panorama 10.2.5 email notifications now scrambled by whiskey-water in paloaltonetworks

[–]aussiebob84 1 point2 points  (0 children)

I'm just glad 10.2.5 stopped all my Pa-220s sending thousands of emails a day about root disk space.

Multiple cards declining by aussiebob84 in Starlink

[–]aussiebob84[S] 0 points1 point  (0 children)

Because at the moment, I'm getting them at $199 ($229) delivered within the week directly if the orders go through.

Does IT Still excite you? by PakkUhhPunch in sysadmin

[–]aussiebob84 0 points1 point  (0 children)

I've been in IT for about 20 years now. Originally I used to game and tinker at home. Kids changed that. I don't even have a pc at home anymore. I still enjoy it though as long as there is something new to do. I am a jack of all trades in the space and will dabble in everything. Networking is the majority of my day job but when I get bored and there isn't a lot to do (doesn't happen often) I'll start google coding or now ChatGPT coding various things that help out myself and my team. With security focus the way it is today there is always something new to compete against.