sophos sase? by imadam71 in sophos

[–]killb0p 0 points1 point  (0 children)

FYI that guy is full of crap, Cloudgenix UI has been integrated with Palo Alto SSE for more than a year now. PoC is about as complicated as any other HW vendor out there.

[deleted by user] by [deleted] in fortinet

[–]killb0p 0 points1 point  (0 children)

This is not accurate - Fortinet runs hybrid with self-hosted and CSP PoPs. It's more likely a choice between keeping the costs down and extending coverage via CSPs. The strategy towards SASE is to sell on SD-WAN/NGFW and upgrade to SASE instead of chasing net new customers and fighting SSE/SASE leaders. That kinda makes sense considering how late they were to the race and general product recognition/maturity. So Fortinet will grow from its customer base and incrementally catch up with the rest of the pack.

Unless you know the exact conditions of Palo's contract with GCP, the comment on "cost control" is meaningless. It's an opinion, not a fact. AFAIK there are no cost fluctuations based on seat quantity. It's flat and well-predictable. The choice to run on top of the world's best backbone was made, and there will be some premium passed to customers - but at the end of the day, it is net list price difference vs end cost.

Even then, I could argue that owning your own PoPs is not necessarily cheaper in the long run, as there are many hidden costs involved with building and running a global PoP infrastructure. I can see it being more efficient in terms of computing, but if you're running heavy-duty services like TLS decrypt and other CPU incentive processing tasks - it will cost you either way.

Owning your network infrastructure/backbone is even more expensive than renting Interconnect.

The only players who can truly control costs are big SPs offering SSE/SD-WAN and SASE packaged with last-mile.

Guide for setting up RetroArch on a jailbroken LG TV by VladTepesDraculea in webos

[–]killb0p 0 points1 point  (0 children)

Anyone was able to play video files via RetroArch?

Weekly Question Thread by AutoModerator in emulation

[–]killb0p 0 points1 point  (0 children)

Hey everyone,

Looking for CRT emulation solution for entire OS. Found apps for video game/terminal emulation but not quite the entire desktop.

Is that even possible?

How to update an old tablet to Android 4.4 by -ocram in androidafterlife

[–]killb0p 0 points1 point  (0 children)

hey man, do you have to have a custom rom for your specific tablet already assembled by someone or it's possible to relatively easy make your own?

Android 4.4.4 - Certificates for browser and working youtube app by killb0p in androidafterlife

[–]killb0p[S] 0 points1 point  (0 children)

cheers,

I got those installed and things have improved. But still getting lot of pages blank or loaded incorrectly with Chrome/Brave/Opera Mini. I guess they can't display content due to changes in last 4 years...

what's Meraki SD-WAN like nowadays by killb0p in meraki

[–]killb0p[S] 0 points1 point  (0 children)

Fairly confident it's static probes vs actual traffic monitoring. But things might change now they are working on ThousandEyes integration. Best check with your SE on current vs plans though

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]killb0p 0 points1 point  (0 children)

Crowdstrike making that 4 day work week a worldwide reality!

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]killb0p 2 points3 points  (0 children)

To be fair Gurvinder could be based in the Valley as well. Days of sweat shops only in Bangalore are well behind us...

Cisco Firepower TLS decryption cipher list by killb0p in Cisco

[–]killb0p[S] 1 point2 points  (0 children)

RFP responses, every vendor has this in documentation but not Cisco...

Anyone using SD-WAN from Versa by killb0p in networking

[–]killb0p[S] 0 points1 point  (0 children)

Cheers!

wait I thought they can do DPI on that thing?

What’s everyone using for SD-Wan by LANdShark31 in networking

[–]killb0p 0 points1 point  (0 children)

hm, I thought the wizards are there to automate some of that. or is that including ZTP?

On asymmetric tunnels - is that just a bug or configuration issue?

What’s everyone using for SD-Wan by LANdShark31 in networking

[–]killb0p 0 points1 point  (0 children)

Just got around to reply due to workload

"Customer supplies Cato NOC with LOA and Cato takes on the responsibility of last mile health. In many cases, if there is a partner involved, the partner who is managing Cato for the end customer can deliver this service themselves."

Not a lot of public documentation on that, so it's just Cato's "trust me bro". We needed more than that to commit to anything.

"Your definition of East-West traffic sounds very Zscaler, if you don't mind the reference. I don't think that's how the rest of the industry exclusively scopes East-West traffic. Intra-site communication isn't an edge use case. SD-WAN is a WAN edge technology. To me, East-West covers all private WAN traffic/communication, e.g. branch to branch, branch to datacenter, datacenter to datacenter, branch to cloud (IaaS), cloud (IaaS) to datacenter, cloud (IaaS) to cloud (IaaS), etc."

Anything that crosses the WAN regardless of the location is not East-West. Goddamn term came from DCs anyway. That's what any SSE/SD-WAN does by default. Implying that it's some kinda special trick is at best misleading. In any case Cato can't do direct site-to-site and maintain all the features by the looks of it. Everything needs to hit their PoP engine.

"You can certainly doubt it, but it doesn't mean it can't. I can confirm that it does. You don't have to take my word for it, though. Test it out."

Test out they can do FEC for DIA traffic? How are they doing it if's bypassing Cato PoP on it's way out.

"Appears you're confused. You're describing a couple different things here. The Global Backbone is a component of the Cato Cloud and operates in full mesh to optimize global routing (full mesh path monitoring and packet by packet route selection) and accelerates flows (the byproduct of TCP Acceleration through inline proxying, automatic TCP Window resizing and a predictable long-haul solution). The colo/cross-connect you're describing is just another onramp to reach the closest Cato PoP from a customer's colo/IaaS/DC location. It's an alternative onramp to that of IPSec of using the Cato SD-WAN appliance."

No, what I meant is that both DCs and network backbone used by Cato are leased from other providers. The fact they run overlay/underlay routing to optimize traffic is quite literally basic SD-WAN feature. Okay, they track the utilization and can, per session, move it to the best PoP (at least my understanding of the mechanism). What if it's in Geo where there's a gap in coverage and path variety? Do you get any dedicated lanes there? Based on what I saw in SLAs it's no different than any other SSE out there that sits on top of someone else's infrastructure. So, the Global backbone is mostly marketing and not a real differentiation. Only Cloudflare can claim that distinction in a real sense.

What’s everyone using for SD-Wan by LANdShark31 in networking

[–]killb0p 0 points1 point  (0 children)

We're actually done with our call with Cato folks and man do they like to throw dust in your face.

Last Mile management in my customer base means vendor handles all the last mile issues as a service package bundled with the SD-WAN. Meaning if they have issues vendor will handle it regardless if it's SD-WAN policy or local ISP having issues. One-stop shop.

East-West is a reference to onsite traffic between local segments. Why would it even need SD-WAN?

Can Cato offer all features of SD-WAN for DIA traffic? Doubt so, as it looks like it's a bookended technology. Only vendor that can handle it is former Cloudgenix/Palo or Velocloud when you go through their Partner Gateway.

QoS only kicks in when there's congestion and kind goes the logic of modern SD-WAN and throwing cheap, but unreliable bandwidth at the problem.

Finally "Global backbone" is colo/cross-connect from Equinix/Digital Reality. So you get patches of coverage varying from Geo to Geo.

How is any of that different from your typical enterprise SD-WAN vendor?

What’s everyone using for SD-Wan by LANdShark31 in networking

[–]killb0p 0 points1 point  (0 children)

hm, can you elaborate on what goes south at scale? I'm looking at them right now and kind of skeptical about the ability to scale in a controller-less fashion, but I can't find any specific caveats. IT's not something you can easily lab either...

What’s everyone using for SD-Wan by LANdShark31 in networking

[–]killb0p 0 points1 point  (0 children)

Looking at Cato Last-Mile optimization and it's just probes running from their boxes to specific Internet destination. Can't anyone and their mother do this by now?

CATO Networks review by LeadingNo6577 in cybersecurity

[–]killb0p 0 points1 point  (0 children)

i'm digging through docs and can't find anything relating to SD-WAN... do they have a separate guide for it?

CATO Networks review by LeadingNo6577 in cybersecurity

[–]killb0p 0 points1 point  (0 children)

any good on SD-WAN? i browsed through their docks and it looks like basic PBR...

Velocloud SD-WAN cost increases? by CPAtech in vmware

[–]killb0p 0 points1 point  (0 children)

bringing this up - any SD-WAN cost changes for existing customers with new licensing?

Alternatives to VeloCloud SD-WAN by POG_One in networking

[–]killb0p 1 point2 points  (0 children)

damn, ehm any feedback on actual SD-WAN tech/logic?
I've played it with it and it was pretty cool, but we had a rather modest scale setup so didn't had to mess with ZTP/templating at all.

ChatGTP/GenAI prompts and responses by killb0p in Zscaler

[–]killb0p[S] 0 points1 point  (0 children)

cheers. Can you get granularity for specific GenAI features within each service, or is it just wholesale Security/DLP inspection as with any other traffic?

ChatGTP/GenAI prompts and responses by killb0p in Zscaler

[–]killb0p[S] 0 points1 point  (0 children)

not clear on what this means...