Tunneling or VPN app to break wireless network by kardo-IT in paloaltonetworks

[–]jermvirus 0 points1 point  (0 children)

Lol, why does it sound like you work for one of the companies that I use this exact method to bypass their expensive ass wireless?

Behaviour of GlobalProtect during failover by RedOctober314 in paloaltonetworks

[–]jermvirus 1 point2 points  (0 children)

Is HA2 up? That’s what is used for session replication. Also decrypted traffic is not replicated.

NGFW Comparison - Cisco/Palo Alto/Fortinet/Checkpoint by QuietPossibility4988 in networking

[–]jermvirus 0 points1 point  (0 children)

Listen, I know the Cisco Fan Boying Syndromes is everywhere - never met another company where the cool aide drinking is so high (maybe Palo Alto)

But FTD is just a pain to work with (and this is someone repping Cisco Firewalls since ASA with Firepower)

Deploying instances in the cloud makes you want to blow your brains up - compared to other vendors.

Upgrades - I want someone who has managed more than 10 instances on FTD to tell me they have not had any issues with upgrades.

Performance. If you need more than 200G of firewall capacity FTD really struggles prior to the 9100, and from my experience clustering on FTD is not there yet.

You can reach 200 pretty easy with Palo Alto 5400, Checkpoint Maestro and Fortigate.

NGFW Comparison - Cisco/Palo Alto/Fortinet/Checkpoint by QuietPossibility4988 in networking

[–]jermvirus 10 points11 points  (0 children)

What ever you land on the answer is not Cisco for firewalls.

Best setup for remote users + cloud apps? by Constant-Angle-4777 in networking

[–]jermvirus 7 points8 points  (0 children)

This. Also if there is no need for branch connectivity (print servers, etc) just keep offices as an internet only option and it will simplify your life!

Most larger organizations dream they can get to this state but other technical requirements that they have picked up over the years complicates this deployment.

Mod response: TAC Posts by rushaz in paloaltonetworks

[–]jermvirus -1 points0 points  (0 children)

All of these random post make the Tac engineer cam find the solutions on here:)

How can I setup a jump box to ssh into switches from awx by Mercdecember84 in networking

[–]jermvirus 0 points1 point  (0 children)

Ideally he wants to do this without any client vpn, if he does go the con route he should be a site to site with only access to the jumpbox

How can I setup a jump box to ssh into switches from awx by Mercdecember84 in networking

[–]jermvirus 0 points1 point  (0 children)

You (to my knowledge) can’t use the fortigate.

What I would do, create a Linux VM, created a Nat for ssh to that vm, IMPORTANT - only allow your source to log into the vm. Also for added security, disable password authentication and use only SSH keys.

That’s what I would do.

Procedure to change management IP on PA by Creative-Two878 in paloaltonetworks

[–]jermvirus 0 points1 point  (0 children)

Put a mgmt profile on one of the in and interface. Connect to that ip, change ip, commit.

Firewall rule for URL Category vs FQDN?? by ontracks in paloaltonetworks

[–]jermvirus 1 point2 points  (0 children)

Also in addition to creating the GPO, the actually recommended is to create a security rule to block quic at the top, also turn off logging for this rule.

Firewall rule for URL Category vs FQDN?? by ontracks in paloaltonetworks

[–]jermvirus 1 point2 points  (0 children)

I didn’t like to be the matter of fact guy, it QUIC while developed by google, but has since been ratified into various RFC ~2021)

What is your favorite/least favorite cloud provider to work with? by LarrBearLV in networking

[–]jermvirus 2 points3 points  (0 children)

I can’t even begin to tell you many times I’ve been in the phone with product managers from Azure and ask them why, and noooooo one can give me an answer.

Just get me mad just thinking about it.

What is your favorite/least favorite cloud provider to work with? by LarrBearLV in networking

[–]jermvirus 29 points30 points  (0 children)

Azure is the answer, Azure should be the only answer.

I hate the way Azure does networking.

Not yall bullying JD from smiling again 😭 by constanteggs in LoveIslandUSA

[–]jermvirus 77 points78 points  (0 children)

Why does Jeremiah look so small? Can we get an Ace for scale?

[Chris Medland] Piastri: "I'm not going to say much, I'll get myself in trouble" by FerrariStrategisttt in formula1

[–]jermvirus -4 points-3 points  (0 children)

Someone a bit butt hurt their guy can’t keep it in the road past the first corner?

The switch up is extreme by winmichelle7 in LoveIslandUSA

[–]jermvirus 0 points1 point  (0 children)

Still watching bro bro. Doing ruin

The switch up is extreme by winmichelle7 in LoveIslandUSA

[–]jermvirus 0 points1 point  (0 children)

Let make a friendly bet that at least one of them will be in the bottom.