Pages

Monday, December 25, 2023

Lessons learnt from COVID-19

I think this will be one of the major health disaster of the 21th century. It has shows that in our hyperconnected world, it would not be difficult to spread a virus.

No need of a some people (activist or terrorits) to spread it, as shown in the movie "12 Monkeys".

We just need a virus with a long incubation time to allow people with no symptoms to travel before being sick...

Anyway, let's get back to the topic of this post, the lessons learnt from this period.

1 - Appreciate simple things
Being confined at home gives you time to appreciate things you would not noticed in the "pre-COVID" lifestyle.

2 - Keep contacts with relatives, friends, colleagues.
Also, it was not possible to physically meet, you can message/call or do a visio to discuss. It is different, but it is better than being totally in lockdown.

3 - Do not keep in the same location, positive cases and negative cases
Unless you want the positive cases to contamine the negative ones. It is like having zombies in a building with non contaminated people ...if you watched World War Z, you have a lot of times this situation, like that one
Or for IT people, it is like leaving a compromised machine with a worm in the production network waiting all the machines get infected.

4 - Believe in a cure.
Eventually, scientists will find a cure.
Multiple vaccins are going to be released.

Sunday, August 13, 2023

More than a contributor on PANCast

Have you heard of Palo Alto Networks' PANCast?

It is a podcast made by TAC engineers (me included) to Palo Alto Networks products users.
Not a sale oriented stuff, really focused on the technology, and how to use 110% capabilities of the products.

The podcast covers all possible topics : from basic troubleshooting tools by TAC to protection of your containers with Azure Container Registry (Prisma Cloud) or discussing the informations you can find in your Cortex XDR logs.

So far, I did an episode on Panorama and its capabilities as logging solution. And we have some episodes pending to be published. I know that because I am scheduling the releases of the episodes :p

So stay tuned.

Patent granted

In case you are not following me on LinkedIn, I guess you are not aware the patent application done on March 2021 has ended, and the patent has been granted officially on 31 January 2023.

The patent details can be found here.

As you will see the patent owner is Palo Alto Networks, as I disclosed my invention to my employer in their patent program.
The invention is directly something PAN-OS can benefit in order to secure communiations, and the technical issue addressed by the invention is addressed in the PAN-OS feature App-ID Cloud Engine.
(Disclaimer : I am not aware if Palo Alto Networks has or has not use the invention)

So how big achievement is it?
1- Before Palo Alto Networks decided or not to apply for a patent, you need to convince a Patent Committe of your invention, the challenge addressed by the invention.
I submitted few others ideas and they were rejected.

2- I am the first inventor (through the Patent Progam of the company) in APAC region.

3- I am also the first one working in Palo Alto Networks TAC.

Sunday, June 4, 2023

Google - access to job application information

In 2011, when I was a fresh young graduate, I did some interviews for a network engineer role in Dublin.

Obviously, I did not make it.

I found recently that Google has a data access policy for the candidates (you can find it here). So I sent a mail to see what data was available after so many years.

It turns out, they did found the information about me : CV, different applications, and interview feedback.

Although it is a bit creepy to keep those data after so much time (Is there no retention period for those information?) , I found that those feedback were interesting : you do not see the questions asked / the interviewer, but you have the answers I provided and the feedback of the interviewer to the question / to the interview.

And today, I can safely say, that my application for the same role would end probably with the same outcome : rejected.

Conclusion : HR/recruiters, if you can spent 5min to provide feedback, do it.

Sunday, December 20, 2020

Packet Capture on PAN-OS

When you need to troubleshoot issues on the firewall, you will end with a packet capture if you did not solve it earlier with other checks.

To perform the packet capture on PAN-OS :
- define the filter
To define the traffic you want to capture. The purpose of the filter is to focus the capture on the relevant packets, and to save resources on the firewall.
- define the capture stage
The firewall capture packets in different stages : receive -  transmit - firewall - drop

The WebUI access is enough to define those 2 steps for most cases.

You will need the CLI for the following cases :
- the firewall has the hardware offloading, the traffic will hit the dataplane CPU only at the session setup, then it will be offloaded. Doing a capture with the traffic offload enabled will give the impression of lost packets (packets are missing).
In this case, you will need to disable the offloading so all the packets captured
set session offload no
- you want to have a subnet as a filter
It is not possible to define a subnet in the WebUI.
You have access to the keyword source-netmask and destination-netmask keywords for the filter definition.
For instance, the command below set a filter to match TCP traffic from 1.1.1.0/24
debug dataplane packet-diag set filter match source 1.1.1.0 source-netmask 255.255.255.0 protocol 6

- you want to see in real time the packets captured.
To check the filter configured is matching some traffic.
view-pcap follow yes

- you wish to capture specific packets only.

For reference, you can find the different protocol code from the protocol list on the IANA website