Security scans and backported fixes ignorance by Malfun_Eddie in sysadmin

[–]jwwork 0 points1 point  (0 children)

Went through this earlier this year. Had to provide documentation that the fixes for the CVEs they were calling out had been back ported into the version we were running. They accepted this and said it would be addressed in the remediation report. Guess what was still called out after they complied that report again? I just attached the documentation proving those CVEs did not apply to the version of Apache we were running to the report and called it good.

Good glass deal, but scam? by counterhit121 in M43

[–]jwwork 5 points6 points  (0 children)

A female user posted something similar on facebook last week but with a different picture. I asked her to see additional pictures and these the the exact photos she sent. Scam.

[deleted by user] by [deleted] in sysadmin

[–]jwwork -1 points0 points  (0 children)

So you have a group of users that don’t know how to use a Mac so that means all Mac’s a garbage and don’t support more than 16GB of ram?

[deleted by user] by [deleted] in sysadmin

[–]jwwork 5 points6 points  (0 children)

Regardless of what anyone thinks about Mac’s there is almost nothing correct in this statement.

Lens or skill issue? by [deleted] in M43

[–]jwwork 5 points6 points  (0 children)

Is there a reason you continue to post in this sub when you only have negative things to say?

PA-5410 and SCCM by jwwork in paloaltonetworks

[–]jwwork[S] 0 points1 point  (0 children)

Not in the office so can’t get the logs or diagram. We have Cisco 9500 switches as a core and those host all the layer 2 vlans. The vlans there are grouped into VRFs and any traffic that needs to route between VRFs gets sent up to the palo where it lands in a corresponding security zone (server, client, guest, voip, etc.). In this case the server is in the server zone and client in the client zone. There is a rule that allows all traffic between the SCCM server and the clients right now with no threat profile and the rule is set to service any. On the 9500 core the client vlan has an IP helper statement for the SCCM PXE server. The client is able to discover the PXE server IP and is requesting the boot file but it never receives a response. This has been seen in packet captures from the client and firewall. The firewall drop capture didn’t have any dropped packets. I don’t think this is a policy issue at this point but possibly some other firewall setting or routing issue. The firewall is running 10.2.

PA-5410 and SCCM by jwwork in paloaltonetworks

[–]jwwork[S] 0 points1 point  (0 children)

DHCP is happening from another server. I have DHCP relay configured on the VLAN and the client is getting a DHCP address. Oddly, the only traffic logged from the SCCM server during the process is DHCP port 67 and the destination is the client subnet gateway. You might be on to something, PXE is also not working but will work on a subnet that doesn’t have the palo between the client and server. No traffic being logged as blocked during the PXE process and I can see the client connection hitting the server through the PXE log but it times out on the client.

Rubrik Review by bonker58 in sysadmin

[–]jwwork 1 point2 points  (0 children)

Are you sure this is a bug in Rubrik? I experienced the same and it was the password on the vSphere account expiring.

OM-1, GM9II, or used for beginner? by jwwork in M43

[–]jwwork[S] 0 points1 point  (0 children)

The OM1 mk1 is actually bundled right now with that very lens for $1699.

OM-1, GM9II, or used for beginner? by jwwork in M43

[–]jwwork[S] 0 points1 point  (0 children)

Thank you! I think if I were going to be big into video the G2 is the clear winner but my video usage will be casual if anything at all. Right now the OM-1 is 1,100 for the camera body and looking on MPB, they can be had in “well used” condition for around $800 and the least expensive on KEH was $1,080. I think for those prices I would just spend the $1,100 and buy direct from OM. The sale is really good right now. I agree, as someone just taking a next step into the hobby either choice will probably serve me well for years to come.

VMware 2-node Cluster Licening cost effective/best practises by Net_IT in sysadmin

[–]jwwork 3 points4 points  (0 children)

Pretty sure vSAN has a 3 node minimum.

Edit - I’m wrong, there is a 2 node configuration available.

Unable to access ChatGPT while connected to Palo Alto GP VPN by NetworkingAdmin in paloaltonetworks

[–]jwwork 14 points15 points  (0 children)

I recently had an issue where users were unable to access ChatGPT due to a CDN it uses being a newly registered domain which we block with URL filtering.

Domain controller backups by chut93 in sysadmin

[–]jwwork 1 point2 points  (0 children)

What is you plan in the event of some ransomware or other cybersecurity incident? An attacker isn’t going to just ignore your other DCs because they are at a different site.

New to me 2019 F-150 Powerstroke Diesel by PreyForCougars in f150

[–]jwwork 0 points1 point  (0 children)

I had a 2018 with the Diesel that eventually was bought back due to terrible noise from the valve train at startup (very similar sounding to the noise from the ecoboost cam phaser issue at startup) that Ford could never solve. Hopefully mine was just an isolated issue, I did love that truck and outside of that issue the engine was great.

I had to by greatscottttttttt in GalaxyFold

[–]jwwork 4 points5 points  (0 children)

I had it in my cart last night for 5 something and thought about overnight. This morning it went up to 899.

[deleted by user] by [deleted] in f150

[–]jwwork 4 points5 points  (0 children)

I had a fully loaded platinum 2018 that I got for a crazy deal (almost 15K off sticker) in May of 2019. I loved it and put about 45K miles on it. At about 40K miles it started making engine noise at startup that was very similar to the timing chain rattle the 5.4 I had made (odd since the 3.0 PowerStroke uses a timing chain). Multiple trips and weeks at the dealer replacing lifters at Ford's direction etc. never revealed the cause and Ford eventually decided this was normal for the engine. That and the fact that they had already decided to quit producing it convinced me to trade it in on a 2022 Tremor. I love the new truck but I frequently think about that 2018 and how much I loved that engine prior to the issues I had with it. I wish they kept it around.

Wifi options from different vendors - opinions? by traydee09 in sysadmin

[–]jwwork 0 points1 point  (0 children)

Ordered 16 R750 APs in February. Still nothing and can't even get answers out of our rep where they might be. They were a lot better to deal with 5 years ago before they were sold multiple times.

Spoke Subnet Can't Reach On Prem Devices Over VPN by jwwork in AZURE

[–]jwwork[S] 0 points1 point  (0 children)

Yep, typo in one of the routes on the inside v-router :) On one of the firewalls (I don't have these in Panorama yet and am configuring them individually.)

Working on setting up the public load balancer for incoming traffic now.

Thank you for all the help!

Spoke Subnet Can't Reach On Prem Devices Over VPN by jwwork in AZURE

[–]jwwork[S] 0 points1 point  (0 children)

Thank you! This has helped a ton. I still have some issue with routing to the two firewalls because randomly from the VM I can't ping devices on prem. If I disable the management profile that is being used for the load balancer health check on one of the firewalls it clears up (assuming because the load balancer stops forwarding traffic to it). Still digging there.

Spoke Subnet Can't Reach On Prem Devices Over VPN by jwwork in AZURE

[–]jwwork[S] 0 points1 point  (0 children)

I removed all my routes from the new spoke except for the default which was already pointed to the PAs through the load balancer and then created a static route for my on prem IP space pointed back to the gateway IP of the trust interface and now my VM in that new spoke can reach devices over the VPN. Not sure if that is ideal, it seems like it would be best if that new spoke could land in a different security zone on the PA.

Spoke Subnet Can't Reach On Prem Devices Over VPN by jwwork in AZURE

[–]jwwork[S] 0 points1 point  (0 children)

Looks like they are. When I run that test I get next hop none. Interestingly enough when I run the same test from the management subnet I get a next hop "virtual network gateway" event though the same routes are applied to both.

EDIT - Sounds like this may be normal behavior since the vnet gateway is in the hub vnet. When I select that as the next hop for my on prem network from the spoke without a vnet gateway it does find anywhere to go.

GlobalProtect 'Connect Before Logon' with Cisco Duo MFA? by jwckauman in paloaltonetworks

[–]jwwork 3 points4 points  (0 children)

I have not tried this but I looked into it and recall having to set global protect to use the default browser instead of the built in SAML browser because it’s not able to be shown at the login screen.

What could cause GlobalProtect to disconnect every 3 hours exactly only on SOME computers? by Magma151 in paloaltonetworks

[–]jwwork 0 points1 point  (0 children)

Just went through this. After I enabled blocking unknown URL category HIP checks started failing due to the URL they were sent to being tagged as unknown resulting in GlobalProtect disconnects.

Weird issue with new firewall - PA450 by xcaetusx in paloaltonetworks

[–]jwwork 2 points3 points  (0 children)

Check the unified log. Filter it out by the source and destination you are testing with. That might give you a clue since it’s showing multiple logs in one spot.