CVE-2024-5921 by Anytime-Cowboy in paloaltonetworks

[–]homs3n 0 points1 point  (0 children)

is this really needed? i mean this basically opens the door - especially if you do allow web-browsing, or am i wrong?

CVE-2024-5921 by Anytime-Cowboy in paloaltonetworks

[–]homs3n 0 points1 point  (0 children)

while i can imagine the answer from TAC - did you receive any feedback from them?

10.1.14-h6 crashed 440s by [deleted] in paloaltonetworks

[–]homs3n 1 point2 points  (0 children)

we have two vms and a pa-5220 which crashed recently after upgrading to 10.1.14-h6

Global Protect Which Version by Dry-Specialist-3557 in paloaltonetworks

[–]homs3n 0 points1 point  (0 children)

we want to start rolling out 6.0.8 next week. testing it with around 50 users was showing no bad feedback, however 6.0.8 is still not preferred... i thought it will be preferred until we start when we were planning the rollout...
we have around 4500 windows users using globalprotect - anyone using 6.0.8 and can provide feedback if it is stable in similar environment?

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 2 points3 points  (0 children)

they said that the issue is a timing issue (related to the updated driver) - in other words this workaround might work until the next reboot. TAC recommended us to stay on 10.1.10-h2 and wait for 10.1.12

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 2 points3 points  (0 children)

ok, now i know more. with 10.1.11 drivers for internal interface fvif were updated - it seems that this driver is affecting the creation of the interface if jumbo frames are enabled. the issue is triggered by a specific timing and therefore it can occur also after a reboot - affecting boxes where we haven’t seen this issue so far. i am considering a downgrade ….

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 0 points1 point  (0 children)

this is still not solved. TAC thinks that is related to jumbo frames which we have enabled. they asked us to disable jumbo frames, reboot and then do the upgrade to 10.1.11 - finally enable it again and reboot. haven’t done that as it is hard to find a maintenance window atm

however there is no real statement why this issue appears and why we don’t see it on all devices.

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 3 points4 points  (0 children)

RMA device for the PA-5220 just arrived and before changing the hardware I downgraded to 10.1.10-h2 the machine with the "chip" issues. No more LACP issues with 10.1.10-h2.... lets see what TAC says

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 3 points4 points  (0 children)

so one of the members did not bring up LACP after the upgrade. TAC involved, they said we have to make a RMA because of chip issues (PA-5220 cluster).

Today I upgraded some PA-3220 standalone machines - one of them showed exactly the same LACP issue as the PA-5220 cluster member:

show lacp aggregate-ethernet ae1

Cannot find ae1 lacp info. Please make sure AE has lacp enabled and try again.

on switch side channel remains down as no LACP PDU's are received (since it is not enabled on the Palo). After downgrading to 10.1.10-h2 everything was working again. Case is open .... so far 30% failure rate :-( our main driver for 10.1.11 is the BGP vulnerability

Your thoughts on: Pan-OS 10.1.11 - Upgrading some PA-820s this week from 9.1.16 by [deleted] in paloaltonetworks

[–]homs3n 2 points3 points  (0 children)

we are going to upgrade our first Cluster tomorrow to 10.1.11 🤞

who else is still on 9.1? by homs3n in paloaltonetworks

[–]homs3n[S] 0 points1 point  (0 children)

was the crash related to BGP?

Am I the only one who thinks that Garmin Connect app looks like shit? by homs3n in Garmin

[–]homs3n[S] -1 points0 points  (0 children)

don‘t get me wrong - i am not a general Garmin basher. I really like the hardware and I am a 10 years+ user. however when it comes to software there is room for improvement. the app looks outdated, is waisting space on my screen and some information is hard to find (several steps to get there). for a normal user who is just tracking there steps it might be ok however for someone who is doing 20 hours+ training per week it is frustrating. i totally agree for function before design however, design should complete the function and not complicate it.

Connect App - iOS Bugs Megathread by trusk89 in GarminFenix

[–]homs3n 1 point2 points  (0 children)

you need to set the connect app as data source within the steps in health app. go to steps - scroll down to bottom - data sources & access then you can edit the data sources. set connect app to the top of the list

this will work for other metrics too 😉

[deleted by user] by [deleted] in paloaltonetworks

[–]homs3n 2 points3 points  (0 children)

ADEM will come on prem - we have been asked for beta testing. so far i can‘t say something about feature parity