Skip to content

Fortinet SD-WAN & BGP

Fortinet SD-WAN still requires proper routing. For small deployments, static routing is sufficient. For bigger deployments, OSPF or BGP can be used. For large-scale deployments, the recommended option is BGP because of its better scalability and other less obvious benefits. In the previous blog post, I described SD-WAN operations for traffic initiated from branches/spokes to… Read More »Fortinet SD-WAN & BGP

Expect unexpected #2

Some time ago, I described in a blog post the history of some interesting things. I’m working in the systems integrators environment for more than 12 years, so I have many more such unexpected stories. Let’s elaborate on the next one. Expect the Unexpected – Palo Alto Networks Logging Capabilities A Customer had an HA… Read More »Expect unexpected #2

DNS Sinkhole

Two weeks ago I wrote blog post about importance of DNS visibility – https://letsnet.eu/dns-over-tls-dns-over-https/. Let’s assume that DNS traffic is properly inspected, queries to malicious domains can be seen and you have capabilities to identify DNS tunneling and to block it as well. Is blocking a proper action to malicious DNS queries? Not really, let’s… Read More »DNS Sinkhole

Fortinet SD-WAN deep dive

As a engineer I would like to know in details what is happening behind the scene. Even, in my job it is mandatory, to have capability to troubleshoot some issues, during almost every implementation I’m facing some issue, this is real world, at the slides everything is perfect always 🙂 Fortinet SD-WAN configuration is quite… Read More »Fortinet SD-WAN deep dive

DNS over TLS/DNS over HTTPS

Visibility, visibility and visibility. Crucial and basic thing to secure infrastructure, if you cannot see something, than you cannot protect as well. DNS protocol is quite challenging from security perspective, it’s like phone book of Internet and cannot be blocked. DNS server has to have communications with external DNS server and that is enough to… Read More »DNS over TLS/DNS over HTTPS

Palo Alto Networks App-ID tips

App-ID, core Palo Alto Networks firewalls capability was elaborated at high level perspective on below blog post: Like mentioned above, all traffic flowing through the firewall is inspected by App-ID engine. Is NGFW able to identify every packets at layer 7? Of course not, what happening than and how knowledge about App-ID operations can be… Read More »Palo Alto Networks App-ID tips

Palo Alto Networks DUG/DAG

Automation out of the box, available directly on the firewall – Dynamic User Group and Dynamic Address Group. What it is about? Basically, using Palo Alto Networks firewall features, you can automatically add ip addresses or users to dynamic groups and enforce some actions, like blocking or allowing access to some resources. What are practical… Read More »Palo Alto Networks DUG/DAG

GlobalProtect OS Command Injection Vulnerability

PANW has published OS Command Injection Vulnerability in GlobalProtect, highest possible severity 10 – Critical. https://security.paloaltonetworks.com/CVE-2024-3400 At the time of publishing, no fixes were available, but if firewall was configured according best practises, mitigation was out of the box. How? Let’s go into details. Palo Alto Networks firewall has three types of security policies: Every… Read More »GlobalProtect OS Command Injection Vulnerability