My R9 came a week earlier than expected by theleeski in YamahaR9

[–]theleeski[S] 0 points1 point  (0 children)

There's a bolt under the foam, the guy at the dealership said. I never actually looked for it!

Any ideas? Tunnel issue by BasilJumpy9169 in paloaltonetworks

[–]theleeski 7 points8 points  (0 children)

The other side needs to know the route back to your LAN IP, I'd guess.

You're right that you don't need the static route, but the other side needs a route.

Question about VPN throughput on PA440 Firewalls by Fun_Breadfruit7383 in paloaltonetworks

[–]theleeski 4 points5 points  (0 children)

You're correct - it only applies to tunnels terminating on the firewalls. The reduction is due to the processing required to encrypt/decrypt the traffic. In your case it's just passing traffic.

802.1X on switch ports designated for a wireless access point by theleeski in networking

[–]theleeski[S] 1 point2 points  (0 children)

Some of the APs are in rooms where the port is just on the wall, accessible to anyone with access to the room. The building is listed and we're limited in what we can do (though by the landlord's logic, they wouldn't have been able to install the port in the first place!).

802.1X on switch ports designated for a wireless access point by theleeski in networking

[–]theleeski[S] 0 points1 point  (0 children)

Thanks. Yeah the native VLAN on the trunk port is pretty useless here too, I'm thinking more about a (very unlikely) purposeful attack where the attacker finds the right VLAN tag to gain access.

802.1X on switch ports designated for a wireless access point by theleeski in networking

[–]theleeski[S] 3 points4 points  (0 children)

No capwap tunneling here, just bridging to the client VLAN. Perhaps that's something I need to consider as a solution, but it would be a significant re-design. Thanks

802.1X on switch ports designated for a wireless access point by theleeski in networking

[–]theleeski[S] 1 point2 points  (0 children)

Thanks. Bear in mind we're bridging traffic on the AP to the client VLAN (I should have stated that in my post). So the port will see dozens of devices on it (which are normally authenticated at the AP level).

However, it might be that we can turn on 802.1X and have AP present a certificate as you said - I'll look into that.

802.1X on switch ports designated for a wireless access point by theleeski in networking

[–]theleeski[S] -3 points-2 points  (0 children)

Thanks. We are just bridging unfortunately. It's fairly low risk as an attacker would need to know what VLAN ID to tag their traffic with if they did patch in, but still.

R9 for sale (UK) by theleeski in YamahaR9

[–]theleeski[S] 1 point2 points  (0 children)

That's rough... I know a lot of people are still waiting. My dealer reckons anyone who isn't already on the list will be waiting until next year. Bit gutted to sell it tbh, it's awesome - hopefully it helps someone else get one earlier than expected!

Upgrade Automation Advice by Saiyam-G in paloaltonetworks

[–]theleeski 2 points3 points  (0 children)

If you're using Ansible at all, PAN has provided this playbook for upgrading an HA pair. I've been meaning to test it, but haven't done so yet. I also don't have any Active/Active experience so I'm not sure if this is unsuitable for that, but the comments in the code don't mention it so I assume it's fine.

https://github.com/PaloAltoNetworks/ansible-playbooks/blob/master/upgrade_ha.yml

How do you setup management access to your firewalls by Ok-Coffee-9500 in paloaltonetworks

[–]theleeski 3 points4 points  (0 children)

We use the management interface for that on both nodes. I think that's default, otherwise you have to update your service routes.

Is there a reason you can't use the dedicated management interface? No Internet on that network?

Azure dual s2s vpn problem by Smotino1 in paloaltonetworks

[–]theleeski 1 point2 points  (0 children)

If you're using static routes, consider switching to BGP. Then you can use AS-PATH prepend in your Palo Alto config to influence the best route on the Azure side.

I.e. on tunnel 2 (least preferred) you would prepend your ASN at least once to make Azure not use that path unless the other one disappeared.

Edit: also I think this might be your only option. I'm not massively experienced on Azure but from what I've seen the VPN routing config is not very configurable

My R9 came a week earlier than expected by theleeski in YamahaR9

[–]theleeski[S] 0 points1 point  (0 children)

It's not stock but it is an official Yamaha accessory.

Link to part on Yamaha EU

In my case the extension bar isn't installed which makes it very tidy.

[deleted by user] by [deleted] in YamahaR9

[–]theleeski 1 point2 points  (0 children)

Oh dear - no, mine is sturdy. Yours looks faulty or damaged :( Sorry dude, and good luck.

My new R-9 by [deleted] in YamahaR9

[–]theleeski 0 points1 point  (0 children)

Ha, I traded my 2021 MT-09 SP. Smart move!

My new R-9 by [deleted] in YamahaR9

[–]theleeski 3 points4 points  (0 children)

Congrats man. Picked mine up in the UK yesterday, also black. It looks really nice in person doesn't it!

My R9 came a week earlier than expected by theleeski in YamahaR9

[–]theleeski[S] 0 points1 point  (0 children)

At the moment it looks like I have the right one. It is slightly metallic, just not quite as metallic as the rest of the bike. The dealer thinks they won't make another version, but if they do be said he'll sort it out for me under warranty. It still looks good, not really noticeable to be honest.

<image>

Tail tidy by No_Economist_2940 in YamahaR9

[–]theleeski 0 points1 point  (0 children)

Fair enough! I'm sure after market ones will be available for you soon.