Тёмный

Network Admin Life - Building a Tunnel 

Network Admin Life
Подписаться 13 тыс.
Просмотров 1,5 тыс.
50% 1

Опубликовано:

 

1 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 27   
@johng.1703
@johng.1703 5 месяцев назад
CBC (Cipher Block Chaining) is encrypted but not authenticated whereas GCM (Galois/Counter Mode) is encrypted and authenticated. and Cipher block chaining - message authentication code (CCM) mode is an authenticated encryption algorithm designed to provide both authentication and confidentiality during data transfer.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Thanks for the info! God bless!
@Arcadier
@Arcadier 5 месяцев назад
NAT-T is a procedure wich is able to recognize if there is a router using NAT on its connection all the way of the ipsec tunnel you established. So needed packages are going to be encapsulated and UDP is going to be used. Thats it in a very short term. its a payload encapsulation over all .
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Thanks for that. That's not how the Palo Alto support tech explained it. But he also said he has seen situations where NAT traversal just "doesn't work." Um... okay. God bless!
@Mitchell7790
@Mitchell7790 5 месяцев назад
Both CBC and GCM are pretty secure however GCM also provides authentication which removes the need for an HMAC SHA hashing function. It is slightly faster compared to CBC because it can take advantage of hardware acceleration. If the hardware at both sides of the tunnel can support it and can make use of hardware-based acceleration then definitely use GCM for best performance.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Okay, that may be why I was advised to use CBC. We don't know that the peer firewall has hardware acceleration. God bless!
@keithsauer3574
@keithsauer3574 5 месяцев назад
I think the route interface shows up after you commit. It doesn’t exist yet. Commit, then it exists and you can use it in the route tables and commit again. We do this too many tunnels to vendors. PA-3220’s PA-1420’s and PA-460’s. We also do this for site to site vpn over internet and use ospf with a higher cost. It the metro Ethernet is down, it fails over in a second to cable modem vpn tunnel. BFD and OSPF make it magic… poor mans SD-WAN without paying for all the licenses!
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Yeah, that's a PAN unit that's not connected to anything so it wasn't the greatest demo platform. But better than my production unit! God bless!
@212helpdesk
@212helpdesk 5 месяцев назад
Fun, I used to do some of this. That employer was big on selling Sonicwall. I never really understood it. Fortunately that wasn't why I was hired. Instead I primarily did onsite voip servers (back in the day) and switching (Adtran/ Cisco). Luv'd L3/ L2 switching and routing. Pretty cool watching you, thanks! Now I just rack/ stack & idrac monster EMC servers. I'm just a gorilla with some config on occasion.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Seems like at my last two jobs, they had just decommissioned a Sonicwall just before I hired in. So for years I've "almost had" Sonicwall experience. LoL! God bless!
@OldePhart
@OldePhart 5 месяцев назад
Isn't NAT traversal the ability to VPN from private IPs over the public internet ? Like work from home folks have to do when their home IP is a 192 address? and I can relate to that mental block on a specific subject. I can learn everything around it but that one topic just puts me to sleep. Subnetting is a good example. I can do it, but I can't sit through a class that teaches it.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
As I know understand it, NAT-T just encapsulates the entire packet so that address information in the source address, and data payload will match end to end. In the case of the data passing through an intermediate router that also does NAT, this can cause the source address and the source address in the message payload to not match, causing the data to be dropped. It's still confusing as all get out. I'm just pressing the "I believe" button for now. God bless!
@xarop3e
@xarop3e 5 месяцев назад
IT is learned from life not courses
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Sounds like something Yoda would say. But true! God bless!
@Solkre82
@Solkre82 5 месяцев назад
I had to learn GlobalProtect on the fly as well. Funny enough I left that job 3 months ago and where I'm at now it's not my job to touch firewall. Can't if I wanted to.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Yeah, funny how life works out sometimes. God bless!
@johng.1703
@johng.1703 5 месяцев назад
you didn't set up an interface, you set it up on the loopback.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
There are no connected network interfaces on the firewall. Using the loopback was just an expediency. God bless!
@bryanb30
@bryanb30 5 месяцев назад
4:57 That’s awesome 👍🏿
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
All I can say is, don't ever get old. God bless!
@captjack5169
@captjack5169 5 месяцев назад
Anyone who is calling you stupid lacks humility and forgets they used to be noobs too. No one knows it all. Thank you for sharing the video.
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Thank you brother! God bless!
@justinmiller7841
@justinmiller7841 5 месяцев назад
What headset are you using?
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
Logitech Zone Wireless. God bless!
@damronthumsuansano7900
@damronthumsuansano7900 5 месяцев назад
wow Thank vdio
@NetworkAdminLife
@NetworkAdminLife 5 месяцев назад
You're welcome! God bless!
Далее
Network Admin Life - Surgery Clinic Switch
13:40
Просмотров 2,3 тыс.
I Took An iPhone 16 From A POSTER! 😱📱 #shorts
00:18
Лучше одной, чем с такими
00:54
Просмотров 341 тыс.
Network Admin Life - Store Room Clean Up
8:54
Просмотров 1,3 тыс.
Network Admin Life - Chasing Down Fiber Problems
18:28
Просмотров 2,7 тыс.
Network Admin Life - Just Another Wednesday
12:50
Просмотров 1,5 тыс.
The Value of Source Code
17:46
Просмотров 28 тыс.
Network Admin Life - Cleaning Fibers
18:50
Просмотров 2,3 тыс.
Network Admin Life - Firmware update problem
19:29
Просмотров 2,2 тыс.
Network admin life- oops a Daisy
11:24
Просмотров 2,2 тыс.
Day in the life of a sysadmin: Day full of meetings
8:03