Pinging from cli doesn't work but from gui works fine

I know it's very silly question to ask but I tried pinging a destination from the cli of Palo alto FW (pan os 11.2.5) and it is throwing me invalid syntax error.
admin@PA-1> ping source 12.1.1.1 host 23.1.1.1

Invalid syntax.

AND

admin@PA-1> ping host 23.1.1.1 source 12.1.1.1

Invalid syntax.

AND

ping logical-router virtual_router1 source 12.1.1.1 host 12.1.1.2 (since I made a new virtual router)

Cannot open network namespace "ns2": No such file or directory

However the ping works perfectly from the gui (troubleshooting tab)

reddit.com
u/Pothandev — 7 days ago

Where to get free ebooks to read and download

I want a free website so download free ebooks (networking books especially). Tried z-lib, annaarchive, etc.. Some books couldn't be found on those also.

reddit.com
u/Pothandev — 19 days ago

Need a book to learn more about BGP networking

I'm looking for a book to learn BGP but couldn't find it anywhere like zlib, libgen, anna's archive etc.. where should I look know?? coudn't give the name bcz of the policy here.

reddit.com
u/Pothandev — 20 days ago

A busineess or company email but not for a company

How can I get a business email, but not for any business. I want to access some course online but they require a company email hell knows why? How can I get one for myself without paying a penny. Surely I can use some temporary email sites for that but that ain't the right solution for long term.

reddit.com
u/Pothandev — 29 days ago

Resources to start learning Palo Alto NGFW

I'm a beginner to learning the NGFW. I want some good resources to make a strong foundation. I've already gain some experience with cisco ftd. I'm good with reading books but the only book I could get is the one by packt with which I'm having a little bit trouble in understanding. I also tried palo alto beacon but that also didn't help a lot yet.

reddit.com
u/Pothandev — 1 month ago

I n e content for free (atleast some of it)

I'm an networking enthusiast and I heard about I n e and watched some videos of those. It was quite helpful. When I saw the subscription plans my mind got frozen. First I thought to buy the fundamental plan but it doesn't offer a lot. Is there a way to get that content for free or any other workaround regarding those high price??

reddit.com
u/Pothandev — 1 month ago
▲ 1 r/ccna

Switch per port Collision

Can anyone explain what switch per port collision domain means. Because if a switch is connected to a pc with an ethernet cable then ofcourse the transmitting and receiving wires are always different withing an rj45 cable, so how on earth the collision gonna take place. And how it all relates to Half-Duplex setting only not in full duplex. Also what changes this same thing of wires with hub??

reddit.com
u/Pothandev — 2 months ago

Cisco Anyconnect Secure Gateway has rejected the connection

I tried to esablish a SSL Client VPN using Anyconnect on ASA, but I'm getting the errors:
cisco anyconnect the secure gateway has rejected the connection attempt
anyconnect was not able to establish a connection the specified secure gateway

ciscoasa(config)# sh run tunnel
tunnel-group aa type remote-access
tunnel-group aa general-attributes
address-pool ab
default-group-policy GroupPolicy_aa
tunnel-group aa webvpn-attributes
group-alias aa enable
ciscoasa(config)# sh run ip local pool
ip local pool ab 192.168.2.10-192.168.2.15 mask 255.255.255.0
ciscoasa(config)# sh int ip br
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 192.168.80.188 YES DHCP up up
GigabitEthernet0/1 192.168.1.1 YES CONFIG up up

reddit.com
u/Pothandev — 2 months ago
▲ 2 r/ccna

DHCPN NAK and ForceRenew Messaages using cisco IOS

I'm learning DHCP right now where I have a clear understanding of message like DORA, release and decline but some of the messages I couldn't understand are nak, inform and forcerenew.
So, I read somewhere that:

  • DHCPNAK : Sent by the server to reject a client’s request (e.g., if the client moves to a different subnet and tries to renew an invalid IP). I'm not sure how to achive that??
  • DHCPForceRenew which I'm not sure is a message itself but I read it mentioned in a book and also somewhere on the internet that it's used to renew the lease or even the ip from the dhcp server to the clients.
reddit.com
u/Pothandev — 2 months ago

DHCPN NAK and ForceRenew Messaages using cisco IOS

I'm learning DHCP right now where I have a clear understanding of message like DORA, release and decline but some of the messages I couldn't understand are nak, inform and forcerenew.
So, I read somewhere that:

  • DHCPNAK : Sent by the server to reject a client’s request (e.g., if the client moves to a different subnet and tries to renew an invalid IP). I'm not sure how to achive that??
  • DHCPForceRenew which I'm not sure is a message itself but I read it mentioned in a book and also somewhere on the internet that it's used to renew the lease or even the ip from the dhcp server to the clients.

Any ideas how to achieve these in eve-ng labs??

reddit.com
u/Pothandev — 2 months ago

DHCP GARP message

I was learning about dhcp recently with cisco ios in eve-ng. I found something very strange when I put a wireshark capture in place between the client and the server. The moment I ran "ip add dhcp" command on the client in interface configuration mode I found the client generated a GARP packet and the most interesting part of the packet is that the sender and target ip is 0.0.0.0 now the question arises that why does the client even needs to generate such GARP packet we know that their will be no device with such ip in the lan to check for duplicacy so why generate such GARP packet??

reddit.com
u/Pothandev — 2 months ago

High Availablility for FMC

Today, I'm working on the High Availability of Firepower Management Center in eve-ng. I've already done FTD HA which was quite easy to configure and verify, but HA for FMC is tough to get. I followed cisco's official documentation. The issue I found out with this is if my primary fmc fails then the secondary doesn't take over the role of primary. The secondary just shows that the acive management cener is failed but there is no switchover. It also makes a bit of sense since there is no dedicated failover link so if I connected two fmc's with a switch and then I turned off the interface of switch towards the primary fmc then how does the fmc2 gonna know what happened to the primary fmc. I'm not sure how things work here with FMC's HA and also that the switchover didn't happen till I checked maybe it takes more time which also makes very less sense. What am I missing here??

reddit.com
u/Pothandev — 2 months ago

GET VPN so called encrypted packet

So, as per cisco's configuration guide: 

The GDOI protocol is protected by an ISAKMP Phase 1 exchange. The GDOI key server and the GDOI group
member must have the same ISAKMP policy. This Phase 1 ISAKMP policy should be strong enough to
protect the GDOI protocol that follows. The GDOI protocol is a four-message exchange that follows the Phase
1 ISAKMP policy. The Phase 1 ISAKMP exchange can occur in main mode or aggressive mode.
The ISAKMP Phase 1 messages and the four GDOI protocol messages are referred to as the GDOI registration,
and the entire exchange that is shown is a unicast exchange between the group member and the key server.

Interestingly I did a packet capture between something weird their are no ISAKMP Messages and I know that all the data is being in the UDP payloads with the port 848 (GDOI), but why it works like this? I saw no packets with ISAKMP Header it's just plain udp with port 848 and the payload as plain data(in hex ofcours), I didn't get it what kind of encryption is this??

reddit.com
u/Pothandev — 2 months ago

DMVPN Phase 3

I was just doing a packet capture of DMVPN phase 3 on wireshark, and I found something very interesting. I saw when I try to communicate between two spokes, first spoke sends a nhrp resolution request to the hub and get a direct reply from the second spoke, which is fine. But the behavior I coudn't understand is why our second spoke also sends a resolution request to our first spoke?? I don't think their is a lot to share through the resolution request because the only viable think I could found out are the NBMA addresses are shared. Unlike in phase 2 where I captured a single resolution request from first spoke to the second spoke their was no follow up. Could anyone please explain me this behavior

reddit.com
u/Pothandev — 2 months ago

LLC vs Ethernet II in wireshark

I saw in my wireshark captures some packets like STP, CDP etc.. goes with the LLC headers whereas some other packets Like ARP only uses Ethernet II header. I want a clear distinction here.

reddit.com
u/Pothandev — 2 months ago

On Demand Routing

I was reading about CDP this morning when I came to know about On Demand Routing. I apply it with DMVPN since I'm learning about VPN in the weekdays. But I found it's just DMVPN phase 1 because the hub generates a default route. So it's not scalable anyhow. Is it still in use though or just a concept of textbooks??

reddit.com
u/Pothandev — 2 months ago

OSPF Rib Decision

I found it very strange when my ospf abr get's two similar subnets e.g. 1.1.1.0/24 from backbone and a non-backbone area it chooses the latter one which is quite strange for me atleast. If anyone has any idea about it please tell.

reddit.com
u/Pothandev — 2 months ago

DMVPN NHRP Resolution Request and Reply in Phase2 and 3

Recently I've been learning about DMVPN, and what troubles me understanding that in DMVPN phase2 and phase3 why does the resolution request packets needs to travel all the way from one spoke to another and that's too via the hub. If the hub has all the entries, then why don't just ask the hub and get those??

reddit.com
u/Pothandev — 2 months ago