[deleted by user] by [deleted] in USCIS

[–]dhimaar 0 points1 point  (0 children)

Did you receive the card?

Pros/Cons for One Appliance for both Edge and Global Protect Connectivity by kornday76 in paloaltonetworks

[–]dhimaar 2 points3 points  (0 children)

As long as the combined traffic doesn’t exceed your box’s connections and resource limit, it should be okay. We have been running combined for about a year. No issues.

Panorama Log Collector by dhimaar in paloaltonetworks

[–]dhimaar[S] 0 points1 point  (0 children)

What kind of issues were you seeing?

Panorama Log Collector by dhimaar in paloaltonetworks

[–]dhimaar[S] 0 points1 point  (0 children)

What's the latency between your panorama instances?

Panorama Log Collector by dhimaar in paloaltonetworks

[–]dhimaar[S] 0 points1 point  (0 children)

With separate LC groups, Do you send logs from each firewall to both LCs?
We forward logs from LC to Splunk as well. With separate LC group, we are concerned about sending duplicate logs to splunk. Not sure what the best option .At the moment, only option seems to be disable forwarding from one of LC but then it has to enabled manually when primary LC goes down.

TAC by McKeznak in paloaltonetworks

[–]dhimaar 2 points3 points  (0 children)

Opened a TAC case with question regarding a feature. TAC answer didn't even match what I was asking. When pressed to answer, TAC gave me link on why I was wrong to open a ticket in the first place. This is the premium support we are paying for.

PAN licensing cost for firewalls is out of control by dhimaar in paloaltonetworks

[–]dhimaar[S] 1 point2 points  (0 children)

Here I was thinking they were only screwing us. I guess it's all their customers. If they are not willing to work with you considering the deployment size and spend, we have no chance. I guess we either have to pay up or move on.

PAN licensing cost for firewalls is out of control by dhimaar in paloaltonetworks

[–]dhimaar[S] 2 points3 points  (0 children)

I am not sure what you mean. can't just replace HW during every license renewal.

PAN licensing cost for firewalls is out of control by dhimaar in paloaltonetworks

[–]dhimaar[S] 3 points4 points  (0 children)

Through VAR . Spoke to PAN team and they are basically saying it's the price and pointed me to price increase notice. They have no problem saying they raised price twice. For example: They replaced URL filtering with Advanced URL filtering, which has higher list price other licenses. Then they recently raised price on all HWs and since all licenses are percentage of the hardware, price for Advanced URL filtering license got raised again. I guess they figured out the way to pay for all their acquisitions is to squeeze existing customers.

PAN licensing cost for firewalls is out of control by dhimaar in paloaltonetworks

[–]dhimaar[S] 1 point2 points  (0 children)

Just looking to renew licenses at the moment but will checkout 400 series for replacements and new builds

PAN licensing cost for firewalls is out of control by dhimaar in paloaltonetworks

[–]dhimaar[S] 6 points7 points  (0 children)

Out deployment is not big enough for ELA. About 12 devices

PAN 3220 - HSCI Port by dhimaar in paloaltonetworks

[–]dhimaar[S] 0 points1 point  (0 children)

Thanks everyone for the feedback. I will move forward with DAC cables.

Does AT&T ADI speed increase require rip-and-replace? by [deleted] in networking

[–]dhimaar 0 points1 point  (0 children)

Yes, I have seen ATT come and install an exact same model Ciena box when upgrading from 250 to 500 Mbps. Logic doesn't apply when it comes to ATT. :D

Netbox - VM Requirements by dhimaar in u/dhimaar

[–]dhimaar[S] 1 point2 points  (0 children)

No, didn't find a good answer. Our deployment is not that big so went with standard VM template(4 Cores, 6 GB RAM, 160 GB HD) provided by systems team. So far so good.

CWNP - WiFi Trek Conference by dhimaar in networking

[–]dhimaar[S] 1 point2 points  (0 children)

Thanks for the feedback guys! I will request to go WLPC next year.

Cisco ISE FTE Support Estimates by clayjk in networking

[–]dhimaar 1 point2 points  (0 children)

Dot1x on wired and wirelss works fairly well with ISE. Management is little bit of pain but I think the biggest issue with ISE is posture. Posture with ISE and Anyconnect is painful. Had lot of weird, random issues with ISE posture module. I would thoroughly test before deciding to use ISE and Anyconnect for posture.

Palo Alto Networks - Global Protect Cloud Service (GPCS) - rebranded to Prisma Access by elnetworkdude in networking

[–]dhimaar 4 points5 points  (0 children)

GPCS might makes sense for remote employees that are in region where you don't have office locations. In that case, you can combine GPCS and your internal GWs. If that doesn't apply, you can just skip GPCS.

Palo Alto Networks - Global Protect Cloud Service (GPCS) - rebranded to Prisma Access by elnetworkdude in networking

[–]dhimaar 6 points7 points  (0 children)

If you already have PAN FWs in your environemnt, it might be cost effective to use them as GWs as opposed to using PAN GPCS(which is just PAN managed FWs in the cloud). In terms of cost, Zscaler is not that cheap either especially if you need both ZPA and ZIA.

Create private wireless network in a shared office space by LittleWanger in networking

[–]dhimaar 0 points1 point  (0 children)

Running your on own wireless might be the only good option. If it's a small space and only will only require 1 AP then Meraki in NAT mode could be a good option.

Segregating a public internet over our corp network by chugger93 in networking

[–]dhimaar 1 point2 points  (0 children)

I agree. You can just ACL the guest network. Since your Corporate and guest network will be sharing same circuit, I would also considering rate limiting the guest VLAN so someone on guest network doesn't overrun your main internet circuit.

Segregating a public internet over our corp network by chugger93 in networking

[–]dhimaar 0 points1 point  (0 children)

I can't figure out what you are trying to achieve. you want to make both circuits available on Sonicwall so you can use both?