Panorama SDWAN for Firewalls OOBM via internal and external DNS.

Hi guys, I am just wondering if this will work...We got Panorama SDWAN for years for several remote offices, all firewalls MGM are pointing to Panorama interface internal private IP via SDWAN tunnels..

Now I am thinking for some situations that I might need to have firewalls able to talk to Panorama via both SDWAn as well as external networks....

Thinking about getting panorama IP published via NAt with a public IP...and apply for dedicated public SSL certificate to Pano MGM interface, having both internal DNS mapping internal Pano IP and external DNS mapping Pano Public IP.. All firewall use Fqdn under Panorama MGM section instead its private IP. ...in this way, Firewall can talk to panorama via both internal and external network...is this common design for Enterprise Palo Infrastructure???

This will be useful, after upgraded our PanOS and SDWAN plugin, we might to push all to all devices at the same time, some devices in lower end hardware might be slow or shit itself to reboot without applying the new SDWAN config and dropped connections etc, later on it still can get he pushed config again from Panorama's Public IP...Anyone implement like this? Any issues?

Thanks John

reddit.com
u/Thegoogoodoll — 11 days ago

Cortex Upgrade to 5.1 Agents & LLM Experience.

Hi Guys,

Since we upgraded to Cortex XDR to 5.1. Our tenant is managed Unit 42 as well.

I noticed that we have these features available in my tenant "Agents & LLM Experience. " Should we enable it straight away? Any impact?

Thanks

reddit.com
u/Thegoogoodoll — 11 days ago
▲ 1 r/wifi

Products or solution recommendations for a guest wifi network..

Hi Guys,

Can anyone share if there is a solution for this scenario:

We are looking to deploy a Guest Wifi Network in a clients remote site for personal devices and general internet use for 100 ppl.

Some Basic requirements:

Wifi 6.

Three different SSID in different vlan firewalled.

Fast roaming among 20 APs.

A rock solid router and a POE switch can do dual internet links loading balancing and failover for two ISP, Maybe BGP dual homing depends on price.Also, allow us to remotely log in and manage from cloud...

Will need several Wifi SSID and VLANs, clients can do fast Roaming. Also, better support for Multicast Optimisation as there will be video calls and streaming at the same time...

Now we looking Ubiquiti. Seems it is more consumer level staff....Won't mind looking for a bit upper Enterprises solution, Like Cisco or HP Aruba combined with a firewall system like Fortinet for a a bit better security etc..

Thanks a lot for tips. John.

Any recommended productsh

reddit.com
u/Thegoogoodoll — 21 days ago

WAC Server SAML SSO with Azure confusions...

Hi Guys,

We have a local Windows Admin Center server managing all local Server Cluster VMs.

To enable Windows Admin Center server's MFA or SAML SSO function, I suppose I need to register our WAC tenant to Azure Arc?

Would it have any impact? Would it bring or publish the whole WAC to Azure Arc with all of our VMs? Dont think we need this feature yet,,..As we only want to have a SSO/MFA part for Admin Logins to WAC Web Admin for now.

Any solid guide that I can follow?

Thanks,

John

reddit.com
u/Thegoogoodoll — 27 days ago

MS Saml Certificate expiring for Palo GlobalProtect

Dear Palo Guys,

On our Palo Firewalls, I noticed that our Entra SAML Certificates for GlobalProtect Portal and Gateways "crt.Microsoft Entra GP Gateway SSO.shared" are about to expire in a few month time. What would I need to do to renew it, download the Saml Profile once again from MS entra? I suppose user wont be able to authenticate once expired? Any tips?

Thanks

John

reddit.com
u/Thegoogoodoll — 1 month ago

Set GP portal welcome page to none, somehow auth is broken

Hi Guys,

Not sure if anyone else is having this issue...I am trying to minimise the pages loaded when connecting VPN via GP agent...

I set two GP portal configs welcome page both to none, the first top one is checking HIP check for device cert for domain windows, the second config is for personal devices...somehow when I try to connect with a personal device (MacOs), it just constantly keeps loading the auth page, saying auth failed...but windows domain joined device seems fine, but the issue happens when personal devices trying to connect..Panos 11.1.4 hx, anyone noticed this? Is this known issue?

Thanks John.

reddit.com
u/Thegoogoodoll — 1 month ago
▲ 13 r/PKI

Renew RootCA cert in 2 Tier PKI plan

Dear Certificate Guys,

Our 10 years Enterprise root CA will expire soon in 1 month, it is in a 2 Tier PKI. RootCA always remain powered off. SubCA server issues certificates to all kind of things, internal Services, code signing, Wifi, VPN etc..

Now I am about to renew it, all certificate requests will try requesting from the new RootCA right once renewed? I wont need to renew with a new private key as the rootCA Server always remained off except CRL renew, sounds right?

My basic plan: renew rootCA, transfer rootCA, request file etc to subCA server following this guide: https://vmlabblog.com/2024/01/how-you-can-renew-the-certificates-of-a-two-tier-pki/

And export rootCA, deploy them via GPO and Intune to all clients and servers, and also load new rootCA and SubCA to Firewalls for VPN cert validation etc. Would SSL certificate (requested by demand) used by Services on Server, would I need to re-request them right?

So it is purely safe to do it now?

Thanks for the tip.

John

u/Thegoogoodoll — 1 month ago

Setting Up Two GP Gateways on two SDWAN Interfaces using the same tunnel interface, possible?

Dear Palo Guys,

We are running Palo Panorama SDWAN for several branches. In one of our branch, we already got a GP Portal and a Gateway. In this branch, I would like to configure one more GP Gateway on another SDWAN interface by using the same tunnel interface: tunnel.1 that is linking to the security zone "GPVPN". Is this supported? Or I have to create another tunnel interface tunnel.2 that is linked to the security zone "GPVPN"?

Thanks for the tip.

John

reddit.com
u/Thegoogoodoll — 1 month ago

Three DNS entries of three DC server for Windows Server VMs?

Hi Guys,

Long story short, we would like to increase more availability for our four domain services, five DC servers are at different locations on SDWAN tunnels. The main server cluster is in Site A. For all of our windows server VMs (None Domain Controller Servers) at Site A, can I put on three DNS instead of Primary and Secondary? So, we will put on for all VMs at Site A with three DNS server entries (Primary DC and Secondary DC are at Site A, and a Third DC is at a remote office via SDWAN tunnels with more latency). All VMs are pretty much on Windows server 2025 and 2022. Not sure if any of you tried there DNS entries on Windows Servers. Any input would be appreciated.

Thanks a lot

John

reddit.com
u/Thegoogoodoll — 1 month ago

SDWAN plugin, add a new route redistribution set all templates out of sync.

Dear Palo Guys,

Had a bit confusion today about Panorama SDWAN plugin 3.2.1 on PanOS 11.1.4-h33.

On Panorama SDWAN plugin, we got Full Mesh AutoVPN Cluster running for several years fine. Today, I got a bit confusion on this version..

On Panorama if I go Panorama -SDWAN - Devices, I am trying to add a new route to Prefix(es) to Redistribute to only one particular branch, so other branches can get this route that I defined here. My previous understanding is that it should not set all the Templates out of sync, should be only for that particular SDWAN template. As only that one branch site will redistribute this new route all other branches...

I upgraded SDWAN plugin from 3.1.2 to 3.2.1 last year. Also, all PanOS is running 11.1.4 - h33 now. Cannot see the known issues from SDWAN plugin and PanoS version.

Is this expected? Would I need to push to all branches? Any ideas?

Thanks a lot

John

reddit.com
u/Thegoogoodoll — 2 months ago

Migrate to ArubaOS MGM modules from old Chassis to new Chassis failed

Hi Guys,

My first time to work with single Chassis ArubaOS switch..We are trying migrate the old MGM modules from the old Chassis to the new Chassis. The new Chassis came with a MGM module which is the same mode with the old module..after I moved two old MGM modules to new Chassis, saying initialisating..it got stuck for 20 minutes anything .... The have to reboot manually.. The MGM status light on one module is red...all other lights are green.. I had a look the old MGM moduoe ArubaOS version on old Chassis is higher than the new M module on new Chassis..don't understand why it failed..does chassis have firmware that needs to be same with the old chassis? Any thoughts?

Thanks a lot John

reddit.com
u/Thegoogoodoll — 2 months ago

Opening MS project files are slow on IPsec with SMB sharing permissions set to Everyone Full Control Access

Hi Guys, I am working on a new file shares on our Brand new file 2025 server, having some performance issues when opening MS project files from a win11 computer on a remote office. Remote offices are connected with our AutoVPN IPsec tunnels. Network latency is around 34Ms..As tested, there is no network performance issue..

So, Long story short, when I configure SMB share permission as Everyone read only access for the file shares, the speed of opening project files is good. Takes about 5-7 seconds... Seems copying files directly is also good via SMB from a remote office...however once I set smb permission to everyone full Control or give Change rights, the performance of opening project files is degraded, opening the same Ms project file can take 30 seconds....I know the Ms project needs to have autosave etc can showhow affect performance..I wouldn't thought it degraded this much?

Tried SMB compressor didn't help with opening the project file..

Also, I noticed the performance was fine in the beginning after I created SMb share, after for sometimes, it is getting slow...I feel like there are some weird SMB caching somehow affect this performance....on the file shares, I already set no file caching under Advanced sharing options..

Any tips you can possibly share that I could give a try?

reddit.com
u/Thegoogoodoll — 2 months ago