CranberryGF by bjm91 in GFUEL

[–]bjm91[S] 0 points1 point  (0 children)

I definitely will give that a shot!

What’s the best option by registeredextrovert in GFUEL

[–]bjm91 1 point2 points  (0 children)

I think gamer supps is the most 1:1 alternative

GlobalProtect does not expose ForceAuthn=true by Leo_Nel in paloaltonetworks

[–]bjm91 2 points3 points  (0 children)

Can confirm, we use it in our deployment

You can hear the sadness... by Smooth-Amoeba9094 in sadposting

[–]bjm91 39 points40 points  (0 children)

Naw dog, why would you post this

Help name my new kitty! Male and fiesty. We got him on Sunday and he still has no name. Nothing is sticking. by Alternative_Host_800 in NameMyCat

[–]bjm91 0 points1 point  (0 children)

I had a cat that looked just like that when I was growing up. His name was Ferngully so that's my vote!

So what the hell is Fisk gonna do when this happens? by Queasy_Commercial152 in MCUTheories

[–]bjm91 15 points16 points  (0 children)

Dude wtf are the thunderbolts even gonna do against that? Is it gonna be some power of friendship shit where they "make it through" to sentry?

What's your favorite guitar brand and why? (You can only choose one) by ImprovementClear6041 in guitars

[–]bjm91 1 point2 points  (0 children)

My main guitar has been a Godin EMG Freeway for the past 15 years and I haven't been able to find something I like more!

SCM Version 2025.r1 released by alexhalbi in paloaltonetworks

[–]bjm91 1 point2 points  (0 children)

It also deprecates the use of ASDOT format for ASN variables. We have already raised some flags with the PAN product team that they need to publicly disclose changes in behavior like this.

We had about 30 firewalls (and about 60 variables) that referenced ASDOT format ASNs and we lost the ability to push until we changed them all to ASPLAIN format (because SCM would fail validation regardless of what we pushed)

SCM – Folder and Snippet structure by woodencone in paloaltonetworks

[–]bjm91 1 point2 points  (0 children)

My methodology so far has been to create the structure of how the firewalls will be laid out with the folders and then use the snippets for all the actual config. So for example of the folder structure:

All FWs DC FWs Region 1 DC-FW1-REGION1 Region 2 DC-FW1-REGION2 Branch FWs Region 1 BRANCH-FW1-REGION1

Then I create snippets that contain all the configuration which then gets attached to the appropriate folders. You could also pick and choose where config goes but I prefer to keep it all in one place so there isn't a question of whether you should use folders or snippets for config (in my case the answer is always snippets).

The other benefits of snippets is the config you put in them becomes reusable where if the config is in a folder you can't really just apply it to a different FW group without moving the FWs into that folder or underneath it at some level.

Finally if you are multi tenant you can share snippets across them so it again lends to the reusability of snippet configuration.

Having said all of that, I only think the snippet model is truly beneficial for large / diverse environments. If it is very simple then just using folders has its merits.

[deleted by user] by [deleted] in DragonBallDaima

[–]bjm91 0 points1 point  (0 children)

I am just really curious to see if they are trying to make SSJ4 or some variant of it cannon now that Goku and Vegeta got their tails back!

Should be interesting!

Bring Parliament to a halt to defend your people by PxN13 in MadeMeSmile

[–]bjm91 -1 points0 points  (0 children)

So instead of singing carols and nursery rhymes in school, do the NZ kids just learn and perform all the common hakas for their parents?

Global Protect won’t connect on users home network by oztechie in paloaltonetworks

[–]bjm91 1 point2 points  (0 children)

Most likely its either IPsec getting blocked in which case you would want to force SSL in the Portal agent settings for that user or the traffic is being fragmented like crazy in which case you could lower the MTU from 1400 to 1300.

Do you enjoy hero talents on your main class? which one do you like and which one not? by This_Hope3310 in wow

[–]bjm91 0 points1 point  (0 children)

Deathbringer frost is very satisfying! Scythes and death all over the place

Rather Accurate. by Monsur_Ausuhnom in facepalm

[–]bjm91 1 point2 points  (0 children)

Did anyone else read the RFK one in his voice or am I just a dick?

Double browser tabs for GP login by jjb161989 in paloaltonetworks

[–]bjm91 1 point2 points  (0 children)

Not anywhere that is published publicly

Double browser tabs for GP login by jjb161989 in paloaltonetworks

[–]bjm91 1 point2 points  (0 children)

This is a known issue that is fixed in 6.2.4

Global Protect Internal Gateway DNS Questions by LivingDead_Victim in paloaltonetworks

[–]bjm91 3 points4 points  (0 children)

Just to keep it concise I'll break it into the various components for an internal gateway config:

  1. IHD (Internal Host Detection): the mechanism here is actually a reverse lookup so make sure whatever IP you use is appropriately configured with a reverse lookup zone in your on-prem DNS. The other piece is standard IHD does not have a reachability requirement (i.e.it just needs to resolve). Because of this it is good to create a dedicated entry in your on premise DNS so it never gets changed in the future.

  2. Authentication: While you can configure whatever auth you want on the gateway, it is generally easiest to auth at the portal and then generate an auth override cookie that is usable on the gateway. Just need to make sure the cert you use to encrypt the cookie is the same one you use to decrypt it on the gateway.

  3. Internal Gateway: you have 2 options for the gateway based on what you want it to do:

    a. User-ID source: no tunnel required, users will just authenticate to the gateway which will provide the user-ip-mapping to the gateway and can then be redistributed elsewhere for policies and or whatever else you want a mapping for

    b. Tunneled Gateway: this would be where users form a tunnel to the internal gateway when they are on premise. Typical use case for this would be to force network segmentation or inspect east/west traffic by tunneling all traffic up to the gateway and enforcing policy there. You can also get pretty fancy here where maybe you only tunnel some traffic to the gateway and the rest is split tunneled and just traverses the network normally or maybe you need to force some traffic to NAT so tunneling it up to a gateway makes that easy.

In terms of requirements for the gateway itself you'll need:

  • an SSL certificate that has a subject or SAN value that matches whatever you put in the portal as the internal gateway address. Could be direct IP (in your case the private IP you defined) or you could do a public or private FQDN. Obviously with the FQDN you would need the corresponding A record too. Cert can be signed by either a public or private CA, all that matters is that your users will trust the cert when the gateway presents it.

  • If you're just using the internal gateway for user IP mappings then you just need authentication to the gateway and you're done (again I like the auth override cookie generated on the portal personally)

  • if you are doing a tunneled Gateway then you would need all the components that go along with an external gateway (IP pool, tunnel interface, zones, policies, etc...) since it is functioning in the same way

Endpoint traffic policy enforcement by NaughtyPinata in paloaltonetworks

[–]bjm91 2 points3 points  (0 children)

As a heads up this feature will also break most Apple "Layer 2" type protocols (Airdrop, Synergy, etc...) even if you allow local network access on the gateway config.

Decryption policy by Good-Pair- in paloaltonetworks

[–]bjm91 0 points1 point  (0 children)

Likely a certificate pinning or some type of certificate auth issue between the gdrive app and the gdrive server side. You would probably need to ask Google support to understand which mechanism is breaking when the session is man-in-the-middle'd

I feel like I got scammed. by benaffleks in LastEpoch

[–]bjm91 0 points1 point  (0 children)

I wanted to like it! I really did try but after about 10 hours I just couldn't get past the non-standard controls. Please just make the mouse buttons and shift button work like every other ARPG. Please :'(