Archive for Blog

Exiting ZTP Mode on a Palo Fails Partially

I just ran into a partially working Palo Alto firewall — a PA-1410 shipped with PAN-OS 11.0.3-h10 and ZTP (Zero-Touch Provisioning) enabled — as I exited ZTP mode to configure the firewall in standalone mode. However, this config shortcut did not work as expected. 🙁…

Continue reading →

Palo vs. PlayStation: How a Security Feature Blocked Our PlayStation Updates

For a few weeks, our PlayStation stopped downloading game updates. I figured it was just a temporary issue with the PS4. Since it didn’t affect me directly but only the kids, I didn’t pay much attention at first. I planned to wait for a firmware…

Continue reading →

Redundant VPN with Failover on a Palo NGFW

This goes out to anyone who uses more than one Site-to-Site VPN tunnel between two locations that are secured by firewalls from Palo Alto Networks. Using two (or even more) VPN tunnels, you need an automatic way to failover the traffic flow from one VPN…

Continue reading →

Wireshark Feature Added: Connecting ICMP Errors

It’s really just a small thing, but very practical for me: In Wireshark, a feature request I submitted has been implemented. Now, when you click on an ICMP error, the corresponding (original) packet is highlighted. Previously, clicking on a packet belonging to a flow would…

Continue reading →

Quiz resolution: troubleshooting using ICMP feedback

The troubleshooting in IP networks is not easy, because a network swallowing can be based on many causes. However, professional admins know ways to shorten the classic and mostly elaborate troubleshooting. For example, you can Sources of error based on ICMP feedback from … Source…

Continue reading →

CLOSE ICMP reports for troubleshooting on the network

You are admin and your network is ailing. Where do you start troubleshooting? Our tip: Top your network patients according to ICMP symptoms. Many lead directly to the cause. If you have to treat network swallowing, Wireshark is considered one of the favorite tools of…

Continue reading →

ICMP ‘Destination Unreachable’ Messages @ SharkFest’24 EU

I did a presentation at Sharkfest’24 Eu in Vienna, the “Wireshark Developer and User Conference“, about the topic: “Unveiling Network Errors – A Deep Dive into ICMP ‘Destination Unreachable’ Messages“. It covers the following: “Effective troubleshooting of network issues is a critical concern… Source link…

Continue reading →

Security-as-a-Podcast

It’s so far – My colleague Florian and I started a podcast! The Security-as-a-Podcast deals with network security-but not in the classic “We explain the RFCs” style, but rather from the perspective of two people who themselves … Source link Author: legendary Johannes Weber

Continue reading →

Page 1 of 8 1 2 3 4 5 ... Last →