Skip to content

Palo Alto Networks App-ID

What is application ID or application control? Firewalls vendors have different naming conventions. Normally, as match criteria in firewall access policies layers 3 and 4 can be used. So, access policies can be configured based on ip addresses and ports. Are there any issue with L3/L4 access policies? First example, let’s allow/block access to Facebook/Gmail/Netflix… Read More »Palo Alto Networks App-ID

Which solutions is the best?

Every products has its feature or characteristic. I always say to customers, that feature is really feature when it solves some problems or adds  new capabilities of IT infrastructure required by business. So, that’s why in my opinion we cannot say which one is the best, it depends on a lot of factors. Lets consider,… Read More »Which solutions is the best?

FortiGate troubleshooting methodology

What I like in FortiGate devices, is that troubleshooting is quite straightforward. Of course, knowledge is necessary about troubleshooting capabilities and functions. Basically, every firewall is about to block and allow traffic. So, how to troubleshoot communications issue, when probably FortiGate is blocking some traffic, but it shouldn’t. Lets’s analyze below scenario, quite specific actually:… Read More »FortiGate troubleshooting methodology

Being instructor benefits

As additional activities, apart from working for system integrator, I regularly deliver trainings from about 3 years. Usually I deliver around 10 trainings days per quarter. Are there any benefits of being a trainer? I wasn’t aware before, now I know there are plenty and I incorporate that benefits into my regular job. Soft skills… Read More »Being instructor benefits

Fortinet SD-WAN FortiOS 6.2 <-> 7.4

SD-WAN technologies are nowadays quite common solutions. Almost every distributed enterprise has a reasons to have it. Really good example are retails companies, one of the main reasons to deploy SD-WAN is to have stable card payments. As example retailers in Poland, most have it already or planning to deploy. I have deployed Fortinet SD-WAN… Read More »Fortinet SD-WAN FortiOS 6.2 <-> 7.4

GlobalProtect Pre-logon

GlobalProtect Pre-logon is a remote connection method based on machine certificate authentication. Practical use cases to deploy Pre-logon are: Configuration steps in detail are elaborated here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 Be aware of mandatory conditions to make it running, one of the following three must exist: Portal contains ‘certificate profile’ but ‘no’ auth cookiesPortal does ‘not’ contain ‘certificate… Read More »GlobalProtect Pre-logon

Certifications…

When you work for systems integrator or solution provider it usually means constant certifications, why? There are some requirements to be reseller of practically every network and security vendor. To be eligible to sell products and have partnership status with vendor some technical staff is necessary. Higher partnership status require more technical staff with some… Read More »Certifications…

Cortex XDR Management Tenant

Last time I was tasked to migrate my Customer Cortex XDR from Palo Alto Networks to new tenant. Cortex is purely SaaS software, about 5 years ago on-premise management console was decomissioned, previously Palo Alto Networks called it Traps. How to migrate? Simple when looking into documentation. Just configure new Cortex XDR tenant and migrate… Read More »Cortex XDR Management Tenant

FortiGate SSL VPN vulnerabilities

Again and again and again, Fortinet has published critical vulnerability in FortiOS for SSL VPN CVE-2024-21762: Let’s summarize last years: All above had high or critical severity, required immediate patching. SSL VPN is internet facing service usually and how dangerous it is, see below: https://therecord.media/dutch-find-chinese-hackers-networks-fortinet My advice… For remote access as protocol can be used… Read More »FortiGate SSL VPN vulnerabilities

Expect unexpected #1

Working for systems integrator means a lot of experience with different environments. Every infrastructure is different even when composed of similar ingredients. Every implementation is different, even when you deploy similar solution multiple times. Sometimes you can face really funny and horrible things at once. Expect unexpected – Master Key (Palo Alto Networks) Every firewall… Read More »Expect unexpected #1