Wednesday 25 September 2024

whitelist domains on checkpoint firewall

 https://support.checkpoint.com/results/sk/sk173345


meraki local status pages to access from local LAN

MR - http://ap.meraki.com

MS - http://switch.meraki.com  

MX - http://mx.meraki.com or http://wired.meraki.com

MG - http://mg.meraki.com

Any - http://setup.meraki.com or http://my.meraki.com


https://documentation.meraki.com/General_Administration/Tools_and_Troubleshooting/Using_the_Cisco_Meraki_Device_Local_Status_Page

ISE-PIC

ISE-PIC requires a zero cost license which needs to be ordered from your usual disti.


Name: isepic

Product:Identity services engine

PID: ISE-VM-K9


Monday 23 September 2024

meraki MTU

 You need to call meraki support to check and get MTU changed.

WAN MTU is 1500 by default

Auto VPN MTU is 69 bytes less (1431 by default)

If you call meraki to change MTU it should create a blip, they said full reboot not needed


-20 for TCP

-20 for IP

-8 for PPPOE

Tuesday 10 September 2024

palo alto mtu

 https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/configurable-maximum-transmission-unit-for-globalprotect-connections


Thursday 5 September 2024

port scanner info

nmap - oldest and lots of documentation and help out there, script archive

rustscan - new (made in rust) very fast for scanning all ports

massscan - fast for scanning public IP blocks and /16s

Wednesday 4 September 2024

unable to upload secure client to FMC web interface

1. Open CLI to the FMC

a. expert

sudo su

vim +76 /usr/local/sf/htdocs/ddd/fileUpload.cgi


b. Enter in i on the keyboard to go to interactive mode on vim

c. Update the line by increasing the maxFileSizeMap


From: ANY_CONNECT_IMAGE => 100 * 1024 * 1024,

To: ANY_CONNECT_IMAGE => 200 * 1024 * 1024,


d. Save the file by entering in ESC then :wq


2. Upload the file again now