Saturday, January 11, 2025

Resolve DNS Issue on Secondary Firewall in cluster

 


This is a permanent fix for DNS issue on Secondary Firewall Failing
 
$FWDIR/boot/modules/fwkern.conf
fwha_cluster_hide_active_only=0  (ADD)

Requires a reboot


validate 
fw ctl get int fwha_cluster_hide_active_only

Add on fly
fw ctl set int fwha_cluster_hide_active_only 0    

Friday, October 18, 2024

Palo Alto Architecting

 Strat Cloud Manager ( => move away from Panorama 

Prisma Access (Global Protect)
Commits

General Protection

  • Zone Protection profiles on all interfaces
  • Migrate to Application-based rules
  • Shared rules .. eg.  geoblocks, bad apps, cleanup
  • Criticality threshold, medium severity is common
  • Zero trust
  • External Dynamic List


Remote User /On-Prem Protection

  • Threat Protection
  • URL Filtering
  • SSL Forward Proxy (SSLD)
  • Global Protect VPN W/Full Tunnel & HIPs
  • User-ID
  • Data Redistribution

Responsiveness
  • Directional Clean up rulesHA configured locally, not in panorama
  • Link and path monitoring for hardare 
  • Baseline or referenece device group
  • use tags
  • Self-documentation configuration
  • Security profile group for different use case
  • Device group tiers and shared templates
Resilience
  • Automate update installation, config backups
  • Separate virtual router for secondary ISP
  • Use path monitoring (not PBF) for route failover
  • HA configured locally, not in Panorama
  • Link and path monitoring for Hardware failover
  • Use monitor profiles for all IPSec tunnels

Palo Alto
Prisma  Access - Associate Tenant
Prisma Access - Mobile Developer Tenant
Panorama Gateways

Sunday, August 25, 2024

Route

 netstat -rn | wc -l


34" MDF
11" Cut to accomidate 12" Speakers
All Joints are glued for sealed
Terminal Caps   
Rectangular Slotted port 1 15/16" Tall,  12 1/8" Wide and 13" Deep  (approx 1.5 Cubic Feet Volume)
Decrease the width lower the base frequency



Key Features
1.5 ft³ cabinet
Slotted port design
3/4" MDF construction
All joints glued and caulked
Black carpet covering


buffer flow 
x site scripting
sql injection 

Wednesday, July 10, 2024

Building a Checkpoint Firewall Cluster (Checklist)

 

Checklist to Build Cluster
1. Checkpoint Version R81.20
2. Checkpoint JumboHotFix JHF65 (or latest Checkpoint GA)
3. Hostname
4. DNS/NTP
5. Routes /Static/OSPF/Default Route/Route distribution
6. Add to Infoblox or your DNS server 
7. Interface Speed/Duplex
8. Integration with Cisco tacacs or Authentication Server
9. RSA Seed files if integration is needed for VPN
10. Serial Connection to Term Server
11. Monitoring
a. Add to SolarWinds
b. Add to Indeni 
12. Configure Firewall backup on Indeni  
13. Add to Firewall Management Servers
14. Apply Checkpoint License
15. Verify 
a. Logs on Logger
b. Policy is applied with software blades IPS/Identity Awareness
16. Configure Out-of-band LOM 



Special Configurations
1. Fix CP provided for the talk path issue 
/opt/CPsuite-R81.20/fw1/boot/modules/
Vi fwkern.conf
fwmultik_dispatcher_in_tap_mode=1

2. The core 0 CPU fix 
/opt/CPsuite-R81.20/fw1/boot/modules/
Vi fwkern.conf
fwmultik_sync_processing_enabled=0


Ref: https://support.checkpoint.com/results/sk/sk165853



a.