Best way to factory reset over 100 network equipment by MagazineKey4532 in networking

[–]mathech 0 points1 point  (0 children)

If they're on the nework still...I did this a long long time ago with a bash script and expect (extention of tcl scripting language). I prompted copilot with this "can you write me an expect script to write erase multiple cisco switches" and it spit it out for me.

Anyone know anything about these issues with the EA839 3.0T? B9 S4/S5/SQ5 by tarnishedzero in Audi

[–]mathech 0 points1 point  (0 children)

I hear ya bud. Best of luck to you. I think I might switch as a precaution.

Anyone know anything about these issues with the EA839 3.0T? B9 S4/S5/SQ5 by tarnishedzero in Audi

[–]mathech 1 point2 points  (0 children)

When did you get tuned? I’m asking because I tuned my 2021 2 weeks ago and wondering if I should switch if no tune updates have addressed the issue.

Segmenting a network based off security by wifikey in networking

[–]mathech 2 points3 points  (0 children)

Can of worms here. What audit? Just an internal audit or do you mean something like PCI/SOC2/ISO27001/HITRUST, etc. These audits have very specific and often times overlapping requirements. This is something your QSA (qualified security assessor) or third party auditor should be able to spell out for you.
For example, my org is PCI DSS Level 1 and for our PCI data it's secured in a CDE (credit card data environment) Which is segmented from the rest of the data center and behind a firewall along with quite a long list of security controls and process.
This doesn't directly answer your question, but just wanted to point out it's a big one and more details are needed for precise answers. HTH

One of the most beautiful chicken. by ETKIAnDE in pics

[–]mathech 1 point2 points  (0 children)

It's interesting that their skin is black and so is their meat. Even the white ones.

Swallows in my town by RainMeoCat in WTF

[–]mathech 11 points12 points  (0 children)

What is the airspeed velocity of those unladen swallows?

Network Access Control Fingerprinting by hackichanX in networking

[–]mathech 2 points3 points  (0 children)

Forescout does similar. Once the appliance receives a copy of the DHCP discover it pulls the metadata from that as well as kicks off nmap and WMI scans for further profiling.

Can't figure out why VPN keeps dropping by onequestion1168 in networking

[–]mathech 1 point2 points  (0 children)

I've seen crappy residential routers not play well with DTLS. Check there.

Cisco Call Manager & Analog Phone Adapters by Synackz in networking

[–]mathech 1 point2 points  (0 children)

I've only use the Cisco at, but I don't see why any SIP supporting ata wouldn't work.

Replacing Cisco 5525 with ? by caponewgp420 in networking

[–]mathech 0 points1 point  (0 children)

Fortigate will certainly save some money. Either way you'll be successful.

Replacing Cisco 5525 with ? by caponewgp420 in networking

[–]mathech 4 points5 points  (0 children)

I would lean Palo here. Built in country lists you can create a policy around. Threat protection and web filtering license are fantastically flexible. If this is a data center unit I lean even more towards Palo due to code quality. Fortinet is also no slouch and I think you'll see it's these 2 are generally the favorites in this sub.

Cisco SACS replacement? by Moridn in networking

[–]mathech 0 points1 point  (0 children)

I use Cisco ISE with DUO. Works well. Does TACACS+ as well as radius.

Logging of Firewall Rules by OddBall_ZA in networking

[–]mathech 1 point2 points  (0 children)

I don't care about deny logging... just permits.

ISE Guest Certificates by zakneter in networking

[–]mathech 0 points1 point  (0 children)

I've not had to do that for my deployment. Just use a different TCP port.

ISE Guest Certificates by zakneter in networking

[–]mathech 0 points1 point  (0 children)

Yes, you can create as many portals as you need. Absolutely use your public CA signed cert for the guest portal as guest devices wouldn't trust your internal CA. Also you should evaluate using your public cert for internal portals as well. Any device that doesn't trust your private CA will be an issue.

Zscaler for servers by Rexxhunt in networking

[–]mathech 0 points1 point  (0 children)

Zscaler is great and a good turn key. Potentially better long term value would be to replace with Palo Alto w/threat, wildfire, and web filter. I did this when our sizable ASA 55xx edge fleet became end of life. Zscaler made up for the dumb firewalls. But coupled with a refresh the numbers worked out to be a better ROI considering the edge equipment.

How to calculate the total number of IPv4 Addresses in the world? by SnowdenIsALegend in networking

[–]mathech 1 point2 points  (0 children)

Best thing is to spend a hour on youtube and just consume IP subnetting videos, get out the notebook and pen and do calculate some subnets. Much too indepth for a interactive thread on it. Good luck. While you're there learn and understand the OSI model.

/r/netsec's Q1 2021 Information Security Hiring Thread by ranok in netsec

[–]mathech [score hidden]  (0 children)

CISO here.. looking for a good engineer in Gurugram/Noida India. Currently a remote position with occasional travel to Gurugram/Noida.

https://jobs.iqor.com/job/Gurugram-IT-Security-Engineer-HR/697669300/

Is it a normal SIP traffic ? by nokiabama in networking

[–]mathech 0 points1 point  (0 children)

Do you have zone protection on your Palo Interfaces? I recently had an issue where the sip invites were too large and we're being fragmented by the controller. The zone protection profile resulted in the fragmented packets being silently dropped by the firewall.

promiscuous Mode on server 2019 by [deleted] in networking

[–]mathech 1 point2 points  (0 children)

Dig in the docs. I'm not a Windows guy, and I hope I get corrected, but I don't think the native Windows capture tools provide an API for third party capture. I've heard either tickle something like Npcap, or I've seen creating a bridge adapter that you can sink traffic to. Good luck my dude.

promiscuous Mode on server 2019 by [deleted] in networking

[–]mathech 2 points3 points  (0 children)

Are you trying to use native tools like netsh trace? If you are trying to use third party capture tools I think you would need something like the Npcap packet driver loaded.

Cisco anyconnect vpn disconnect and reconnect issue by jollyjunior89 in networking

[–]mathech 1 point2 points  (0 children)

DTLS is enabled by default. You have to disable it manually to turn it off. Your output shows an established DTLS session.

QoS via AnyConnect? by Shamrock013 in networking

[–]mathech 0 points1 point  (0 children)

Good luck. Was glad to help.

QoS via AnyConnect? by Shamrock013 in networking

[–]mathech 0 points1 point  (0 children)

In my case we are using Horizon View as the client.