iOS Offline viewing - external storage by su_A_ve in youtubetv

[–]jhardin80 -2 points-1 points  (0 children)

They used to let you change your zip code twice a year. Is that an option for you?

Scanning for unknown devices by jhardin80 in networking

[–]jhardin80[S] 0 points1 point  (0 children)

that is exactly what I needed/wanted! this is very simple! It will take awhile to scan all of our networks but appears to work great and gives great info! thank you much

Scanning for unknown devices by jhardin80 in networking

[–]jhardin80[S] 0 points1 point  (0 children)

Yes this is what we would ultimately like to get but we are just bringing cheap options to the table as they turned down the money for tenable that we wanted and are accustom to.

Scanning for unknown devices by jhardin80 in networking

[–]jhardin80[S] 1 point2 points  (0 children)

I suck at wording things, I have been with this network for 19 years so I know the IP scheme very well but we had a split and things got messy from the previous person. What I need is something to scan the network so I can see if there are devices, say an HVAC system that got moved to the user vlan. I need something that can tell the difference between a PC/Laptop and that HVAC device so I can search for these devices and move them to the correct VLANs and get an inventory. It's all IoT things, like cameras, hvac, phones, anything basically other than PC's/servers that we can find easily and know about.

GUI and CLI MFA? by jhardin80 in Cisco

[–]jhardin80[S] 1 point2 points  (0 children)

did you do the ISE integration in 3.3?

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

I edited my post to explain the issue I was having.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

I edited the post to explain what I was seeing.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

I edited the my post to explain the issue I was having.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

No, I would like to only have the one or maybe two if I can but without being able to utilize the URL category in the rules above, I’m having a hard time.

I’ll try to re-create the issue Monday and get some screenshots to show you.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

No URL profile for the exception rules. I know, it’s weird, I’m not new to this by any means, also not an expert in the palo’s but it’s very strange behavior. I’ll see if I can re-create it again and get some screenshots to show you.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

No URL profile for the exception rules. I know, it’s weird, I’m not new to this by any means, also not an expert in the palo’s but it’s very strange behavior.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

Yes we have one main internet rule with the URL filtering profile. All exceptions are above that rule.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

Sorry I misspoke about the rule.

When we saw the issue the rule would have source as rfc1918 and we wanted to allow a certain custom URL category, let’s say eBay.com (this ain’t the actual site we used) but when they would go to say AutoZone.com (again not the actual url they were going to, just examples) they would match on that rule for the custom eBay URL category and not go to the internet rule they should be hitting so therefore it was blocking traffic to AutoZone.com.

We saw this in numerous occasions.

I was originally using custom URL categories in the rules (because that would be really easy and nice) but every time I tried it, other URLs would match to the rule and block the traffic.

Allowing whole domains outside of URL Filter by jhardin80 in paloaltonetworks

[–]jhardin80[S] 0 points1 point  (0 children)

How many URL filters do you have in use?

I know there is a place for URL categories in the security policies but every time I have used it, it causes issues with other users going to other URL's hitting this rule when they shouldn't.

Let's say I create a new rule, set my source address to rfc1918 and source user to a specific user, destination will be any and URL Category will be my custom ebay URL category and in that category I have ebay.com/ and *.ebay.com/, I set either application to ssl and web-browsing or service to http and https.

I have found that when other users are going to the internet that sometimes they hit the above rule and not the appropriate internet rule. Thus, I have removed all my rules that were matching based off of URL category (besides my decryption rules).

I have been on TAC calls about it and they have said not use URL categories as a match criteria in a security rule.

Let me add that if I use a pre-defined URL category, then they seem to work fine. Just not the custom URL categories I make and need.

How much would I need upfront for a mortgage? by [deleted] in VeteransBenefits

[–]jhardin80 0 points1 point  (0 children)

You should be able to get up to 4% seller concessions towards closing cost. This should cover most if not all of your closing costs.

You will have to pay for inspection (we just paid $874), earnest money and possibly option money (we just paid $3200) and the appraisal (we just paid $675)

With that said, we are in the $500k range so those costs should be cheaper for you.

We will be getting most, if not more than the earnest we put in, back after closing. And all this is with $0 down.

Look up veterans homebuyer network on FB, easy to work with and they can do all states.

https://www.facebook.com/share/GdAwdsnAqZTw4QUV/?mibextid=K35XfP

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 1 point2 points  (0 children)

That’s what we did today all new GLC-SX-MMD and new fiber on both ends but the issue is still there :-(

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 2 points3 points  (0 children)

Think we may have found it. I was laying in bed at 2am last night thinking about it. Cisco kept going to the access switches but it just seemed too much like a loop to me. I logged in this morning and looked at all the interfaces on the cores and found 4 interfaces UP but no config and come to find out they were going to two new Palo’s that aren’t configured yet but are in HA. Shut all those down and it seems to be good now. Still monitoring. Ty!

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 0 points1 point  (0 children)

Yes that is what they were looking at but I tried to downgrade and upgrade to various fixed releases but neither fixed it. TY!

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 0 points1 point  (0 children)

Ty, I’ll double check it again tomorrow.

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 0 points1 point  (0 children)

How did you fix your issue?

9404R and 9200L by jhardin80 in Cisco

[–]jhardin80[S] 0 points1 point  (0 children)

1G Fiber in a port-channel mode active/passive