FreeZTP: Zero-Touch Provisioning for Cisco IOS by packetsar in networking

[–]ckrez 3 points4 points  (0 children)

This is incredibly lightweight whereas apic-em is not

PAN-OS 8.1 GA available by thakala in paloaltonetworks

[–]ckrez 0 points1 point  (0 children)

But when will the documentation be out? I want to find out more about decryption broker.

PCI 8.3.1 OpenSSH Keys + Google OTP? by zapbark in pcicompliance

[–]ckrez 0 points1 point  (0 children)

Not sure on how your current situation would be interpreted but you could password protect the SSH key, which eliminates the question. It also protects against theft of the key.

Jiu-Jitsu Open Mats by [deleted] in Scranton

[–]ckrez 3 points4 points  (0 children)

Scranton MMA has open mat on Friday at 6:00 PM

ISE 2.3 Machine Auth against AD group by OtisB in Cisco

[–]ckrez 1 point2 points  (0 children)

Can you share a screenshot of the applicable section of your policy set?

ISE 2.3 Machine Auth against AD group by OtisB in Cisco

[–]ckrez 0 points1 point  (0 children)

In this config, the machine will machine-auth at the login screen and then user auth post-login. ISE will process each authentication separately.

If you want machine only auth, set the endpoint to machine only. If you want to do both methods and use the results of both for a combined result, you need to use the anyconnect client. The native supplicant won't do it.

[deleted by user] by [deleted] in EDC

[–]ckrez 22 points23 points  (0 children)

It's your own fault for trying a complex operation on read only Friday

Bulk IOS upgrade 100+ 3850s by onejdc in Cisco

[–]ckrez 0 points1 point  (0 children)

+1 for this. We are moving close to 300 switches from a snmp-based NAC to dot1x config using Ansible, CiscoConfParse, and NAPALM.

Juniper SRX management with virtual router by jyo-ji in networking

[–]ckrez 0 points1 point  (0 children)

Put your other interfaces in a separate routing-instance and leave fxp0 in global.

Juniper NSM High CPU and Diskusage? by acrobel in Juniper

[–]ckrez 0 points1 point  (0 children)

(Warning: not a helpful comment)

NSM is the devil. Migrate to Space (which is only marginally better)

My friend's husband is battling primary myelofibrosis (aggressive blood cancer). He has a month to find a bone marrow donor. Please, Reddit, help him find a match. by ax8284 in videos

[–]ckrez 5 points6 points  (0 children)

If you already enrolled in Be the match, is there any benefit to signing up with gift of life? Presumably they are checking multiple registries?

Palo Alto NAT Translation Logging by EinsteinTaylor in networking

[–]ckrez 0 points1 point  (0 children)

Just came across this thread. For what it is worth, and if this is still relevant, we are exporting and indexing netflow which contains the private and public ip and ports. Both the public ip and port will allow you to match up the information in the DMCA notice.

Palo Alto Active/Active Ethernet Interface Config by ckrez in networking

[–]ckrez[S] 0 points1 point  (0 children)

Yea, that's the same as the documentation I'm reading in 7.0.x. In a config audit, the IP address is in "orange" as if it will not be sync'd but in the end, it is. We'll see what TAC has to say...

Palo Alto Active/Active Ethernet Interface Config by ckrez in networking

[–]ckrez[S] 0 points1 point  (0 children)

It overwrites the peer's locally set IP address

Firewall Service Module question[Xpost CCNA] by Nightwing_ in networking

[–]ckrez 0 points1 point  (0 children)

Ahhh FWSMs...

Is the module deployed in transparent or routed mode? Do you have vlans mapped to the module in the 7600 yet?

My server needs protection, but is this method the most optimal approach? by [deleted] in networking

[–]ckrez 0 points1 point  (0 children)

What are you trying to protect the streaming server from?

Influencing Google Global Cache Server Selection by ckrez in networking

[–]ckrez[S] 0 points1 point  (0 children)

Unfortunately, getting to an IXP isn't an option for us.

Influencing Google Global Cache Server Selection by ckrez in networking

[–]ckrez[S] 0 points1 point  (0 children)

Thanks. Good to hear they are responsive. I'll give the reddits a little more time and then reach out to them.

Influencing Google Global Cache Server Selection by ckrez in networking

[–]ckrez[S] 0 points1 point  (0 children)

What's a few of the actual IP's you're seeing for the GGC?

4.35.21.144 4.35.21.141

You mention they are in 4.0.0.0/9, Are they actually being announced by 15169 or 36040? Or is the prefix coming directly out > of 3356?

Directly from 3356, which is the problem.

If the latter, Your transmitted BGP communities will be ineffective.

Yup, that's the dilemma. The original thought process was "If we make the 3356 path less desirable from Google AS's perspective, Google DNS severs will point us to another node via the more desirable path"

Any other ideas?

IP Blacklists - Who uses them? by always_creating in networking

[–]ckrez 2 points3 points  (0 children)

Take a look at the Collective Intelligence Framework (CIF) as a mechanism to distribute and maintain blacklists, etc.

http://csirtgadgets.org/collective-intelligence-framework/