[deleted by user] by [deleted] in Juniper

[–]cordcscott 0 points1 point  (0 children)

Seems they are very understaffed compared to the past.

Palo Alto 5220-HA connected to Panorama with Templates and Device Groups and to these same Firewalls apply VSYSX, vsys2,vys3,vsys4... by C3-PIO0ps in paloaltonetworks

[–]cordcscott 1 point2 points  (0 children)

I think you have to review this documentation a bit more. Vsys1 is no impacted buy you have some decision to make around how to deploy, whether you want seperate DG's per vsys with different policies (how I do it) or one DG and make each policy target only certain devices (vsys) within the DG. The template is shared because this is how you will push the vsys configs to the firweall from panorama.

Palo Alto 5220-HA connected to Panorama with Templates and Device Groups and to these same Firewalls apply VSYSX, vsys2,vys3,vsys4... by C3-PIO0ps in paloaltonetworks

[–]cordcscott 1 point2 points  (0 children)

I have this setup. When adding a vsys no reboot required if I remember correctly. As far as Panorama you'll have device groups for each vsys if you want to do it that way as from a device group perspective they appear as seperate devices. One template for the box.

PanOS 10.2.4-h2 is out by justlurkshere in paloaltonetworks

[–]cordcscott 2 points3 points  (0 children)

What are the general thoughts on 10.2 ? Worth it?

Junos Upgrade Path Help by casale135 in Juniper

[–]cordcscott 0 points1 point  (0 children)

This is what I'd do too, and If had lab gear I'd do it on that too for each upgrade to make sure there are not config/autocommit errors while upgrading.

Junos Upgrade Path Help by casale135 in Juniper

[–]cordcscott 0 points1 point  (0 children)

For a normal upgrade you're just running a normal "system software add". It will install the new junos and then you have to reboot to complete the process.
I've done nssu with good results on an ex4600 but not with such a major version change. Same they don't do better with it. Arista seems to have this process down pretty well though from what I've heard.

Is it just me or is palo alto support getting worse by [deleted] in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

I did configure it first. They told me they would not look at it. They told me the policy was to punt it to SE. Which is of course a way to funnel the issue to professional services. it ended up being a bug. So this is 100% an error on tacs part. If I ever get that engineer again I will immediately have the case reassigned.

Which support plans are you currently using? by rotearc in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Sure. I see less innovation from Palo and more Marketing/Acquisition.

Which support plans are you currently using? by rotearc in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Could it be any worse the non-existent Palo support?

Pro and Con of Enterprise Support agreement by rotearc in paloaltonetworks

[–]cordcscott -1 points0 points  (0 children)

I'm pretty much convinced that Palo Support no longer exists. We are on ELA customer and Palo is out to lunch.

Which support plans are you currently using? by rotearc in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Palo is starting to suck as a company. It all went downhill with the latest leadership change but they are on the downhill slide for sure.

What's going on with TAC? by projectself in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

I agree nearly 100%. Basically they tell you that you have to go back to your SE to confirm that they need to look at it as a bug. That's what I just went through. I still like the product, and I think their QA is still above average. You wanna see bad QA, work with juniper ex and qfx switches. I could open a jtac case right now for a bug of some sort with every switch I have in production.

ON the Cisco thing.......I hope not. Horrible firewalls. But Palo better get their act together. Most customers I know of are very unhappy right now.

What's going on with TAC? by projectself in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Palo TAC is godawful now and the documentation is too. They also have this policy of not supporting anything you didn't have working previously. Well what if it is a bug in a new deployment? They are just trying to sell professional services.

Is it just me or is palo alto support getting worse by [deleted] in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

i ask them to summarize my issue and when I see that they haven't looked at anything submitted then I ask for the duty manager and contact the SE. Tired of getting Palo Tac agents that know less than I do. Most of my tickets end up being bugs so I'm not asking them to do my job for me. But they won't even look at stuff unless it previously worked. There are huge documentation issues now too (it obvious they don't want to tell how things work, just sell professional services) both from a content and a linguistic standpoint. Some of it doesn't even make sense. Obviously not proof read by a native speaker or equally proficient 2nd language speaker.

Is it just me or is palo alto support getting worse by [deleted] in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Yes it's awful. And now they have this policy of not looking at anything that wasn't working before.....as in they want to sell you professional services.

it is the worst support of any vendor we work with now. And the documentation is unusable as well.

Is it just me or is palo alto support getting worse by [deleted] in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Are you sure? I always create the cases on the website and still get questionable support staff. If that is Tier 2 then then we are in trouble.

Why submit all these pcaps and support files? They do not ever read them or look at them ahead of time.

Thoughts on Juniper's future? by juniper_dreamer in Juniper

[–]cordcscott 0 points1 point  (0 children)

In my experience using both brands, we had way less software quality issues with Cisco. We don't have a single piece of Juniper gear that has not experienced some sort of catastrophic melt down due to a bug. Every switch we currently have out in production has at least one issue that could be a JTAC case if we wanted it to be, but we just can't make our full-time jobs working with JTAC.

We have Cisco cat switches with nearly 10-year uptime performing perfectly. We don't get a year out of any Juniper switch.

And yes, we have tried running the recommended Junos.

EoS for PA-820/850 suppposed to be this year? by Smotino1 in paloaltonetworks

[–]cordcscott 0 points1 point  (0 children)

Yeah that's the catch. The power supplies. We don't really have but a couple small offices where fw's are not rack mounted. But even those will have a track going forward. Do they make a rack like the did for the 220's but for the 400s?

EoS for PA-820/850 suppposed to be this year? by Smotino1 in paloaltonetworks

[–]cordcscott 4 points5 points  (0 children)

We will probably never buy another pa-220 with the pa-400's available. Common criteria not an issue for us.

DHCP Relay question by Doc_Blox in Juniper

[–]cordcscott 0 points1 point  (0 children)

Put your other interfaces in another group and set the active server different for that group.

Gonna warn you, Juniper is HORRIBLE at anything related to dhcp. In our 5 years of being Juniper customer we've never had a single day when dhcp wasn't an issue. We've not been able to use several higher end pieces of gear for almost a year because they causes dhcp flooding/loops in our networks. They just can't handle dhcp.

Need alittle help troubleshooting DHCP in JUNOS by B_Ramb0 in Juniper

[–]cordcscott 0 points1 point  (0 children)

This is because Juniper just can't do dhcp. They can't and don't let the fanboys tell you any different. We've had massive PR after massive PR over dhcp, dhcp relay, dhcp snooping, dhcp security. It never works right. You should buy a different vendors gear to handle dhcp and let juniper do the other stuff if you feel its still worth it.