Over three decades of Information Technology experience, specializing in High Performance Networks, Security Architecture, E-Commerce Engineering, Data Center Design, Implementation and Support
Tuesday, March 4, 2025
Saturday, January 11, 2025
Resolve DNS Issue on Secondary Firewall in cluster
This is a permanent fix for DNS issue on Secondary Firewall Failing
$FWDIR/boot/modules/fwkern.conf
fwha_cluster_hide_active_only=0 (ADD)
Requires a reboot
validate
fw ctl get int fwha_cluster_hide_active_only
Add on fly
fw ctl set int fwha_cluster_hide_active_only 0
Sunday, November 17, 2024
Friday, October 18, 2024
Palo Alto Architecting
Strat Cloud Manager ( => move away from Panorama
Prisma Access (Global Protect)
Commits
General Protection
- Zone Protection profiles on all interfaces
- Migrate to Application-based rules
- Shared rules .. eg. geoblocks, bad apps, cleanup
- Criticality threshold, medium severity is common
- Zero trust
- External Dynamic List
Remote User /On-Prem Protection
- Threat Protection
- URL Filtering
- SSL Forward Proxy (SSLD)
- Global Protect VPN W/Full Tunnel & HIPs
- User-ID
- Data Redistribution
- Directional Clean up rulesHA configured locally, not in panorama
- Link and path monitoring for hardare
- Baseline or referenece device group
- use tags
- Self-documentation configuration
- Security profile group for different use case
- Device group tiers and shared templates
- Automate update installation, config backups
- Separate virtual router for secondary ISP
- Use path monitoring (not PBF) for route failover
- HA configured locally, not in Panorama
- Link and path monitoring for Hardware failover
- Use monitor profiles for all IPSec tunnels
Sunday, September 8, 2024
Sunday, August 25, 2024
Route
netstat -rn | wc -l
34" MDF
11" Cut to accomidate 12" Speakers
All Joints are glued for sealed
Terminal Caps
Rectangular Slotted port 1 15/16" Tall, 12 1/8" Wide and 13" Deep (approx 1.5 Cubic Feet Volume)
Decrease the width lower the base frequency
Key Features
1.5 ft³ cabinet
Slotted port design
3/4" MDF construction
All joints glued and caulked
Black carpet covering
buffer flow
x site scripting
sql injection
Wednesday, July 10, 2024
Building a Checkpoint Firewall Cluster (Checklist)
Checklist to Build Cluster
1. Checkpoint Version R81.20
2. Checkpoint JumboHotFix JHF65 (or latest Checkpoint GA)
3. Hostname
4. DNS/NTP
5. Routes /Static/OSPF/Default Route/Route distribution
6. Add to Infoblox or your DNS server
7. Interface Speed/Duplex
8. Integration with Cisco tacacs or Authentication Server
9. RSA Seed files if integration is needed for VPN
10. Serial Connection to Term Server
11. Monitoring
a. Add to SolarWinds
b. Add to Indeni
12. Configure Firewall backup on Indeni
13. Add to Firewall Management Servers
14. Apply Checkpoint License
15. Verify
a. Logs on Logger
b. Policy is applied with software blades IPS/Identity Awareness
16. Configure Out-of-band LOM
Special Configurations
1. Fix CP provided for the talk path issue
/opt/CPsuite-R81.20/fw1/boot/modules/
Vi fwkern.conf
fwmultik_dispatcher_in_tap_mode=1
2. The core 0 CPU fix
/opt/CPsuite-R81.20/fw1/boot/modules/
Vi fwkern.conf
fwmultik_sync_processing_enabled=0
Ref: https://support.checkpoint.com/results/sk/sk165853
a.