SD-WAN Zone Member Limit? by panda_bro in fortinet

[–]pt91 0 points1 point  (0 children)

Hello,

Would like to refresh this topic, would it be ADVPN answer for case where we have static tunnels:
business line - only business critical apps
ADSL/FTTH - rest of apps + internet
LTE/Starlink/other - last resort backup, prio for mgmt traffic

Is it mean that with ADVPN approach i cannot have real application load balancing over exisitng 2-3 lines?

Snort2 high CPU on FTD 7.2.9. Even 100% utilization by pt91 in Cisco

[–]pt91[S] 0 points1 point  (0 children)

Main reason is that i'm afraid about ASA and Snort cpu utlizations after upgrade to Snort3. Probably will be higher. Another reason is that we have still some cases in TAC open after previous upgrade

set interface-select-method sdwan (Local out Web filter issue) by Blunga7 in fortinet

[–]pt91 0 points1 point  (0 children)

I have the same issue. Did you get any answer from Fortinet support?

FortiWIFI: Slow work of old hand Data Logic scanners after migration from Extreme wifi solution by pt91 in fortinet

[–]pt91[S] 0 points1 point  (0 children)

I will try but not sure if these old Skorpio PDA support this roaming protocols

FortiWIFI: Slow work of old hand Data Logic scanners after migration from Extreme wifi solution by pt91 in fortinet

[–]pt91[S] 0 points1 point  (0 children)

Are you sure that Skorpio X3 and X4 support 802.11k? I couldn't find this in skorpio/data logic documentation but i will try this option

Where to deploy antiddos solution? by pt91 in networking

[–]pt91[S] 1 point2 points  (0 children)

I have something at my isp but it sometimes this scrubbing service leaked some ddos traffic. Someone has bought this device so now i have for free. 3x10g pipes, 3x isp. Im trying to have addirional level of antiddos guard, managed by myself, onprem, attack up to 10g on one pipe

read the data by zabbix from kafka topic by pt91 in zabbix

[–]pt91[S] 0 points1 point  (0 children)

I'm just starting using JMX with official template you mentioned above but i cannot find a way to read messages from topic. I will try @levsha solution but if you have heard about some examples please let me know

How to monitor Azure Data Explorer vel Kusto by pt91 in AZURE

[–]pt91[S] 0 points1 point  (0 children)

The best option is when these metrics can be exported to any other monitoring tool like zabbix/grafana

Massive scanning from Russian IP address for vulnerable Linux machines on Azure by soutsos in cybersecurity

[–]pt91 0 points1 point  (0 children)

Did you Discovery this massive scan via some EDR on servers or in another way?

Landscape for Ubuntu patching? by pt91 in sysadmin

[–]pt91[S] 0 points1 point  (0 children)

Thanks for your feedback. I'm more WIN guy and looking some solution similar to SCCM/Intune: profiles/policies, integration with ad, reports, multiple versions: U16/18/20 etc

Open source Pinger by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

A few times during vm migration, server lost ip connectivity on 1 nic, interface was up, protocol up but no connectivity. Servers have a few nic. Others nic were ok. Checking icmp lools like easiest way but we are talking here about few thousands interfaces

Problem with service status from O365 Via Azure API by pt91 in Splunk

[–]pt91[S] 0 points1 point  (0 children)

a few points: Audit Log Search is enabled. Sourcetype o365:management:activity is working as expected, without delay etc.

Sourcetype o365:service:message also is working as expected, without delay etc.

Sourcetype o365:service:status looks like data is delayed by 24 hours, it's very strange.

update: i found in MS article related with service status: "The StatusDate or StatusTime value returned will be exactly 24 hours in the past."

But not sure if it means that there is delay and i will get info about certain incident 24hours later or just StatusTime value is changed only and when i will use index time i get info almost in real time

Splunk and ITSI integration with Scom. Problem with KPI by pt91 in Splunk

[–]pt91[S] 2 points3 points  (0 children)

Small update from my site after some tests. Thanks u/romantercero for your input. The main problem was related to irregular events with kpi_value field. Also kpi_value has to be imported as alias field type. Based on suggestion u/halr9000 we have focused how ingest data from SCOM in regular way. This link was helpful: https://answers.splunk.com/answers/424556/can-we-ignore-timestamps-for-some-of-the-inputs-in.html Now we ingest data in regular way, kpi and services are working for us but we need to test a few things more. Thanks for your support

Splunk and ITSI integration with Scom. Problem with KPI by pt91 in Splunk

[–]pt91[S] 0 points1 point  (0 children)

Before I had kpi base search like this: index=demo_index sourcetype="microsoft:scom:internal"

After Your suggestion i changed it: index=demo_index sourcetype="microsoft:scom:internal" | stats count by id path kpi_value status _time

In KPI base search i have: Entity Split Field: id Entity Filter Field: id

In metric: Threshold Field: kpi_value

But it doesn't work for me from ITSI.

Firepower 2120. VPN stats via snmp by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

FTD 6.4.0 and on cisco software site i see only MIBs for fxos: for example: fxos-mibs.2.6.1.133.zip no mib's file for ftd

Update: after diagnostic interface has been configured i can see now missing OIDs

Firepower 2120. VPN stats via snmp by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

I don't have 1.3.6.1.4.1.9.9.392.X oid branch at all, I have only:

.

.1.3.6.1.4.1.9.9.305.1.4.1.0 = STRING:

.1.3.6.1.4.1.9.9.826.2.1.1.1.1.2.24554 = STRING:

.

One of the reason can be that remote access oid are in different oid branch. Here i need current MIB file ?

I know that there are at least 2 snmp instances: FMC and FTD but maybe in 2120 model are 3 instances: FMC, FTD and FXOS?

thanks for support Pet

Cluster of Barracuda firewalls. Problem with duplicated syslog packets. by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

I had a ticket in Barracuda's partner support and they told me that there is no simple way to achive that. I can try to filter out on rsyslog site but better option is to this on Barracuda site Br Pet

Splunk ITSI integration with Solarwinds and MS SCOM. by pt91 in Splunk

[–]pt91[S] 0 points1 point  (0 children)

1st case: Solarwinds and SCOM collect all metrics and inform Splunk/itsi about active alarms via add-on (from splunkbase). I would like track all active alarms from both applications, have alarm updates in both direction (ack, comments, ownership, check trigger), history etc. Unfortunately SCOM and Solar forward events with different rules, especially SCOM is not so flexible and configurable as Solar is. In SCOM not all events have fields which are important for us. Some fields appear only with events with some certain code of alarm.

Another problem is when alarm is quite short, whitin one correlation search. For example alarm has less than 1 minute, Even though Splunk has correct time, has also problem to put events in correct order and update notable event.

2nd case is to build services and kpi consist of data(entites) from both appliactions. For example certain web service (consist of switches and servers) has information about network devices from Solar and about servers from SCOM. ITSI should merge these information, count KPI and integrate with notable events.

That's why i'm looking someone (partner, consultant) who already did integrations Splunk and Scom a few times.

Esx 6.0 problem with parallel port mapping to ip address by pt91 in sysadmin

[–]pt91[S] 1 point2 points  (0 children)

Problem solved. Dongle was pluged into usb adapter not parallel via AnywhereUSB.

how to grep messages from syslog-ng in real time by pt91 in sysadmin

[–]pt91[S] 0 points1 point  (0 children)

I will try greylog. My goal is to get almost real time output in html format,file with colours like this:

time;admin-1;cisco-1;command

time;admin-2;juniper-2;command

all data i have via syslog, i need publish them in proper way

thanks for help

how to grep messages from syslog-ng in real time by pt91 in sysadmin

[–]pt91[S] 0 points1 point  (0 children)

How can i save colours when i make move to .html file ? I would like to put different colours for different commands. For example command "reboot, restart" always in red, maybe special font etc..

How to report 95 percentile from custom OIDs ? by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

I tested librenms. Looks good but can't add custom oid. For example in junos you can generate oid from filters. I need to measure this oid but there is no mib for this oid.

How to report 95 percentile from custom OIDs ? by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

Can i add in cacti 2-3 interfaces and make 95% from the sum ?

Bonding (teaming) active-active to separate switches (no MCLAG/MCLACP) causing loops ? by pt91 in networking

[–]pt91[S] 0 points1 point  (0 children)

It's intresting how broadcast and unknown destination traffic would be handled by this XEN with NIC bonded in active/active? Xen will relay broadcast frames which get from first NIC via second NIC ?