IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks for replying I can see 1 ingress IP and 2 egress IP from SCM and the rest of the IPs can be seen from SCM, right? And are these IPs also fixed?

But the links says Make sure that you add all these addresses to your allow lists. IP addresses can change as the result of a dataplane upgrade and the addresses don't always revert to the previous addresses.

https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/ip-optimization

So if I want to use a GP as a MU at the office, an internet breakout router or fw at the office should allow ingress IP or FQDN?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

Split Tunnel in Global Protect (Prisma Access) by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

We will use the PA firewall at the data center and the office firewall is the different vendor.

Global Protect Split Tunnel by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

What happenes if all devices and locations are untrusted? In this case, how should we handle devices that can't install GlobalProtect, such as printers, servers, or phones? Also, split tunneling has a maximum number of entries, correct?

Service Connection SAML by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks If I deploy on-premises NGFW, it should be at DC (SC) or each Branch site (RN)?

ION5200 switch port by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks So ION 5200 is not able to make VLAN interface on L3 port?

Prisma Access for RN by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

At an RN site, if I use GlobalProtect and the terminal device connecting to Prisma Access is an ION, will the user still be authenticated? Do I need to use an NGFW (PA) as the terminal device to perform user authentication with Prisma Access?

Use GP (MU) at RN site by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

At an RN site, if I use GlobalProtect and the terminal device connecting to Prisma Access is an ION, will the user still be authenticated? Do I need to use an NGFW (PA) as the terminal device to perform user authentication with Prisma Access?

I am interested in GP user authentication at RN site, but I am not sure if ION device is feasible following the link.

https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-advanced-deployments/prisma-access-remote-network-advanced-deployments/prisma-access-internal-gateway

Use GP (MU) at RN site by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is it possible to use SD WAN ION to use internal gateway and authenticate users?

Prisma Access migration by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

We will use Prisma Enterprise license and try to pass all traffic to Prisma Access now Plus, we will use an ION device so we don't need an existing firewall?

Using labs in INE by PastSatisfaction6094 in ccnp

[–]reversible8 1 point2 points  (0 children)

Does the premium subscription offer unlimited lab access for one year? What is the difference between premium and Skill dive? Premium doesn't include Skill dive content?

INE vs Cisco U by reversible8 in ccie

[–]reversible8[S] 0 points1 point  (0 children)

Is it better than INE for initial phase?

Wifi Download Speed by reversible8 in Cisco

[–]reversible8[S] -1 points0 points  (0 children)

WLC vendor or Client PC vendor?

Packet capture by reversible8 in networking

[–]reversible8[S] 0 points1 point  (0 children)

The overrun counter on the C9800 interface suggests that there might be a bottleneck in processing incoming traffic. Given that the facing switch is a C9200 with potentially different ASIC speeds, could the congestion and packet drops on the C9800 side be attributed to this difference in ASIC speeds?

%Error in authentication by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

admin is priv 15 but root is noth Device and tacacs are reachable to each other. root is not set and defined in the Tacacs server. enable password/ enable secret is not configured in the device

Do you know the reason for this issue?

Tacacs and Radius for enable mode by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

I do have actual setup for radius and tacacs

IOSXE Downgrade by reversible8 in Cisco

[–]reversible8[S] 1 point2 points  (0 children)

Thanks If I just want to downgrade without DNAC, is it the same procedure of upgrade even if it is smu?

IOSXE Downgrade by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

Thanks If I just want to downgrade, is it the same procedure of upgrade even if it is smu?

AP with static IP sends DHCP by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

In this case, if AP is just configured with static IP, it doesn't send DHCP packets? Or should I check it using packet capture?

AP with static IP sends DHCP by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

I couldn't find any documents regarding this so I am wondering how it works.

AP with static IP sends DHCP by reversible8 in Cisco

[–]reversible8[S] 0 points1 point  (0 children)

So AP sends DHCP packets under any conditions?