Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


PremiumSupport posted:

The issue isn't so much that it uses a special port number to access the user's spam junkbox, I can handle that in my firewall/VPN routing rules. The problem is that web browsers have stopped allowing users to browse to a http resource that includes said port number. Users get a security warning page that basically says "you're not allowed to do this, goodbye." You can bypass the restriction by disabling the security in the browser, but I'm not going to tell all my staff to do this, and I'm certainly not going to do it for them.

The sane solution is to change the port number used to access the user control panel, but this sonicwall device is preventing this from happening for some reason. I've got a support case open, hopefully it's just a UI issue and there's some CLI string that can be executed on the device to force the change, but I'm not holding my breath.

Could you NAT the traffic as a workaround in the meantime?

Original:
source - $userIPs
destination - $junkboxIP
port - 80

Translated
source - $userIPs
destination - $junkboxIP
port - $nonstandardPort

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


star eater posted:

we got a 50 dollar off coupon for company merch for xmas :) cause that's what i want.... truly

We got $50 of cheers credits, our stupid achievers/recognition platform someone in HR has saddled us with. At least we can use the points on things like PlayStation or Best Buy gift cards

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Zil posted:

What you don't like the daily Home Depot emails telling you that you have won a free drill?

And DHL has tried to deliver something. I really don’t understand how those home depot and dhl ones get through.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Unexpected Raw Anime posted:

I've spent the last three weeks trying to work with Palo Alto Network's Client Management and Technical Support teams for the first time ever and I want to throw these loving firewalls out of a window

Bounced around between three different sales reps/client managers, tech support is just copy/pasting me paragraphs from articles I've found on my own, I have begged and pleaded and browbeat for escalation and it just doesn't go anywhere. I never thought I'd say this but I'd rather be dealing with freaking Sonicwall than these people at this point. Thankfully we've moved to Fortinet for basically our whole network stack now and I have had nothing but positive experiences with them so far.

Palo’s technical support has really poo poo the bed over the last couple of years. It’s a real pain for a lot of people.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


I’ve been hearing SWG pronounced as swig by people at my new job. 8 years of working at least adjacent to them and that’s a first.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Agrikk posted:

pfsense.

I have pfsense running in a VM and powered it off to do some maintenance on the host. When I powered it back on I cannot ping it from the LAN side, but pinging the LAN IP address from the far side of an IPsec tunnel works and I can manage it just fine.

PC_A <----lan_A---> pfsense_LAN--pfsense_WAN<------IPsec_tunnel--->Sonicwall<---lan_B<---PC_B

PC_A cannot ping the lan_A pfsense interface but PC_B can.

What the hell?

Does traffic from PC_A otherwise pass through pfsense ok? I saw you say you can manage it just fine but not sure if you manage it from PC_A. What does a tcpdump show? Dunno if pfsense logs traffic directed at interfaces but anything if so?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Agrikk posted:

No traffic from PC_A (or any other device on that side of the interface) leaves that LAN. Nor does the lan interface show any traffic passing though the any/any riles in the firewall for that interface. I can get to the management interface from PC_B.

and tcpdump only shows a bunch of arp who-has requests through that interface.

Well that’s interesting. Are the arp requests from pc_a for the firewall? No arp replies from the firewall? If it’s not arp requests from the pc, what does a packet capture on the pc show? Properly layer 2 addressed packets? Maybe try an arping from pfsense?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Hah, I was guessing some vlan or other layer 2 fuckery but wasn’t sure how a pfsense reboot could have caused it unless it lost a tag on the interface or something.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


TheParadigm posted:

Question about the contract to hire talk on the last page!

hows the pay differential work out? What about negotiating the different rates?

From what I understand of C2h, its 'you're a 1099 until we hire you, then you get to be an actual w-2 employee'. With 1099, rule of thumb is to charge more to cover taxes, expenses and the like.

Am I fundamentally misunderstanding it, and the grift is more or less seeing who doesn't negotiate and take the lowball offer?

The reason i ask is the first thing that popped into my mind was 'a lot of this could be solved with a contract competion bonus in writing as part' Ie, no 'to hire', they pay'.

But, I thought i'd ask for more information. Like, how do you negotiate your c2h pay if you WERE in that position? Two different rates, or cross the bridge later?

Because it seems to me like part of the whole scam is just danging the 'to hire' pay and getting contractors to agree to lesser rates and pretending one figure fits both shoes.

The one c2h position I had, I was technically the employee of a staffing company for 3 months and got a w-2 from them. I did get a higher hourly rate from them than the internal position supposedly due to the lack of any sort of benefits like pto or retirement, although I think I would have been eligible for health insurance if I had been there longer than that 3 months before converting. My company at the time had a blanket policy of only doing c2h for entry level positions, but I never saw anyone not be converted to full time after the 3 months. They eventually stopped doing it.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Sirotan posted:

Gmail flagged an email that I sent to myself as spam.

I get half a dozen of those "You've won a Yeti cooler!" and McAfee bill impersonation scam emails a day in my inbox, but this one goes to the spam folder. What a great product.

What does that say about the quality of your emails?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Thanks Ants posted:

That article still seems overly in praise of Elon

Yeah, doesn’t spend much time on why you might want to spend some time planning

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Would you care to guess what Palo’s XSIAM product addresses?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


devmd01 posted:

lmao rip zscaler. We were already looking at cutting back our licenses from company wide, especially once we turn on Okta fast pass and don’t need line of sight to the DCs for seamless SSO.

Yeah, there’s a reason their stock took a hit when the Entra stuff was announced. Palo also took a hit based on Prisma access I think but they at least have the “single pane of glass” “platform play” going for them if you’re a firewall customer.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


bull3964 posted:

Eh, I'm 44 and I can go a whole week+ without turning on my PC for something.

The instant I need to research something or do something like an even slightly complex travel itinerary, I'm heading straight to my PC.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


xzzy posted:

"zero trust" has leaked into my org and this has resulted in an end to some types of announcements being sent by email (because they can't trust email, even though we have to log in to it with 2fa). So instead they set up an internal website that we're supposed to check every day for announcements, and we have to log into that with 2fa. They want us to set it as our home page, ensuring we get constantly blasted with login prompts.

End result? People are starting to miss announcements because no one's cool with that bullshit.

I promise you people were missing those announcements before by ignoring the emails

Adbot
ADBOT LOVES YOU

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


guppy posted:

I am perfectly happy to configure firewall rules, and usually there is documentation, but I am sick to my teeth of vendors' documentation on what's required not matching what their devices actually do.

I worked at a MSSP for years, configuring firewalls for customers across a wide swath of industries. Constant battles of the customer providing vendor documentation for firewall rules fast forwarding to the application not working, to reviewing firewall logs and finding some blocked communication on a port nowhere in the documentation that is apparently critical to the functionality.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply