i liked the chatbot feature when opening cases. Not too sure I understand AI vs Generative AI....
@AK-ql5vb10 күн бұрын
Thank you Bro!
@AVelez-zq5hf11 күн бұрын
but what if you do not want to do PAP? What if you want to do Microsoft MSCHAPv2? You need a Microsoft NPS Server so that your credentials are not sent over clear text.
@NetworkWizkid10 күн бұрын
See the following guide: help.duo.com/s/article/1014?language=en_US
@AVelez-zq5hf10 күн бұрын
@@NetworkWizkid yeah - but that doesn't help if attacker can do ssldecrypt/ssl inspection?
@NetworkWizkid10 күн бұрын
If an attacker can perform SSL/TLS decryption then I think you have a bigger problem than worry about whether you use PAP or MSCHAPv2 with Duo.
@AVelez-zq5hf10 күн бұрын
@@NetworkWizkid I agree with you - but there are several things that you cannot control outside of your environment if that makes sense. Most organizations do some form of deep packet inspection (At least I hope they do!!) It would be interesting to see a tutorial on how to get the UAG/DUO working with MSCHAPV2 along with a Microsoft NPS server. Not a lot of information out there and it would be the most secure way in my opinion.
@TechJedi00712 күн бұрын
How do you install this to 100's of machines? How does that process look?
@NetworkWizkid11 күн бұрын
Assuming those machines are Windows, you could look at using Group Policy
@NetworkWizkid16 күн бұрын
Here is an updated video of the tool here: kzbin.info/www/bejne/i4q1fqabZ6iUqNU
@DiegoFukayama20 күн бұрын
Do you play TTR? It's very cool
@kutalanota212226 күн бұрын
The explanation is clear and the demonstration is also excellent. As Transparent mode has so many limitations, I wonder if there are environments that actually use it?
@NetworkWizkid16 күн бұрын
Thank you as always, your support is amazing. To answer your question, working for Cisco I've seen and deployed transparent mode a few times and so it's definitely relevant.
@kutalanota212216 күн бұрын
@@NetworkWizkid Good to hear ☺
@kutalanota212226 күн бұрын
As always, your content is excellent and your explanations are clear.
@arturit0_27 күн бұрын
For a windows only needs to be a radius server besides the Duo for Authentication?
@NetworkWizkid16 күн бұрын
Your question is not clear, could you rephrase please?
@arturit0_27 күн бұрын
Quick question, something most being done on the AD for the radius authentication? I just did the same setup but using FDM and It give me login failed
@NetworkWizkid16 күн бұрын
No. Make sure you do have connectivity to AD and check your Auth proxy logs which may indicate your issue.
@kutalanota212228 күн бұрын
Thank you again Kelvin for such great content that you provide us with - I'm back again like I've never left. This is such an informative and useful video.
@NetworkWizkid16 күн бұрын
Anytime! Keep on studying ;-)
@kutalanota212228 күн бұрын
We're back at it again and using the same Lab Tracker. Thank you Kelvin and I'm glad I got an updated copy. 2025 will be our next attempt.
@NetworkWizkid16 күн бұрын
Excellent, good luck and keep me posted.
@debsmith7120Ай бұрын
Hello! Appreciate this series of videos! I do have a question that doesn't seem to be covered. On our FW, we have multiple Connection Profiles with associated Group Policies. We'd like to be able to control access so that, for example, a user that is a member of a particular AD group can ONLY log in to a particular Connection Profile on the FW. (Or possibly more than one. (depending on how many AD groups they are members of....) The point is that if a user is a member of Groups A and B (but not C) within AD, then on the FW they'll be able to connect on VPN to GRoups A and B, but not C. Is one or more of these flows best for that requirement? If more than one, which would you recommend as being best for not losing other capabilities (e.g., HA)? I am considering implementing ISE (instead of our current NPS), and wondering how best to implement it. Thank you!
@NetworkWizkid16 күн бұрын
Thank you for watching. To answer the first part of your question, this should be possible with ISE. To answer the last part of your question, that would likely require further consultation. Drop me an email [email protected].
@rashedenab431Ай бұрын
We are using cisco Umbrella in our environment. And I decided to share you some questions I have in mind Now, In the Umbrella Dashboard there are two tabs , one is called External Domains , which inspects the DNS traffic for the clients going to the listed domain and DO NOT inspect web traffic We add domains for websites that drops http/s connections from a proxy , somehow they detect it We also have another list called selective decryption list , the inspects DNS traffic , also web traffic , BUT DO NOT PERFORM deep inspection because the server somehow knows that the traffic is being read by an intermediate which is the Umbrella proxy. My question is , what if a user faced an issue with a domain or website because of Umbrella, how I can know where to add it first ? Any browser error indicates the cause? Thanks for the great content!
@NetworkWizkidАй бұрын
Thank you for watching. You can identify the rules that a affecting a user. Please take a look at the Cisco Umbrella documentation or go through this training which covers how you can find the policy. You can find the training here: networkwizkid.com/free-cisco-umbrella-course/
@rashedenab431Ай бұрын
@@NetworkWizkid Thanks , Any plans to make a course on Cisco Meraki ?
@1habeelАй бұрын
Hey! Im quite done with my security just gonna get done with ISE in a couple of days, what software are you using here? Im on eve-ng, i wanted to ask which one are you using?
@NetworkWizkidАй бұрын
I use a mix of virtual and physical software and nested EVE-NG within a virtual environment.
@MrKashifiqАй бұрын
First of thanks for sharing such a good video. I have found only 3 videos on NGIPS. Is there any other videos related with Cisco NGIPS or not? Regards
@NetworkWizkidАй бұрын
Thank you - I will be bringing some new content shortly. Keep notifications turned on so that you'll be notified when I release new content.
@itsame84702 ай бұрын
This is a great set of videos. Best ones on the topic. How would you handle your internal and external domains being the same? I can't find an answer to this. Our vendor changed networks and the proxy's public IP and now the website shows insecure. I've already had Cisco tell me that it's configured correctly. Is it because they're using the shortened domain version on the website?
@NetworkWizkidАй бұрын
To answer your first question, you either have Umbrella handle the DNS resolution or not. Without knowing the network and setup it difficult to answer the second question but I would speak to your vendor of Cisco support if you have any issues. Thank you for watching and I'm glad that you found these videos useful.
@trustprise2 ай бұрын
No one link works get message: We couldn't find the resource you're looking for. The course you're looking for may already be retired or obsolete. Try a new search or view available content for a subscription homepage. Go home
@InfoTech_Site2 ай бұрын
I have just passed the CC exam. Your video helped me a lot, followed the information you have provided. I have collected the most important questions from my preparation and created a video series on the CC exam with important questions here: kzbin.info/www/bejne/l5infIGmrt-sj8k
@NetworkWizkidАй бұрын
Thank you - I am glad this helped you pass and congratulations
@alifarsani24692 ай бұрын
it gives me error and does not like anything in the code
@metalsnake002 ай бұрын
why da hell will you get this if Microsoft have it all by there license
@funmemes59153 ай бұрын
Thanks, this work to me
@NetworkWizkid3 ай бұрын
Great! Thanks for watching.
@cezarkrs72873 ай бұрын
Everything will be more expensive this way including plumbers,electrician,taxi,etc. They will have to put this expense on your bill. A flat rate for vehicles with £0 road tax would work better.
@gabrielgarcia-xo5xy3 ай бұрын
Why was authentication failing even with 'open authentication' configured for that switchport?
@NetworkWizkid3 ай бұрын
Because there was no policy in place on ISE.
@gabrielgarcia-xo5xy3 ай бұрын
nvm I guess my question is, even though it's showing that it is failing... 'open authentication mode' allows the device to still access the network?
@NetworkWizkid3 ай бұрын
Correct
@mohammadaminulislam55583 ай бұрын
Video quality is not so good
@NetworkWizkid3 ай бұрын
Looks ok to me. Have you tried changing the video quality settings to 1080?
@rashedenab4313 ай бұрын
Studying on the CCNP security , this series is a banger , can't thank you enough for this you are a legend. btw , I'm thinking on obtaining the CCNP ISE , is it covered here ? and what do you think of the specialization? Again , you are a living legend
@rashedenab4313 ай бұрын
Also , would it be okay to explain the GRE over IPsec ?
@NetworkWizkid3 ай бұрын
Thank you for those kind words and thanks for watching. I do have some ISE content on here and will also be delivering more soon.
@NetworkWizkid3 ай бұрын
If I remember, I will try and cover it in a video
@rashedenab4313 ай бұрын
@@NetworkWizkidlooking forward to it!!
@Nezar0713 ай бұрын
What if i have two ISE nodes setup, do i need to integrate both to Azure AD ?
@NetworkWizkid3 ай бұрын
I'm assuming you are referring to a distributed deployment where you have x2 PANs?
@SurajSingh-o5i9s4 ай бұрын
Congratulations bro 🎉🎉
@NetworkWizkid3 ай бұрын
Thanks 🔥
@mohamedmowafy19084 ай бұрын
Thanks 👍
@NetworkWizkid4 ай бұрын
No problem, thank you for watching
@jjcrips49284 ай бұрын
Question: I have 2 VA's that were being used with a dashboard with an existing ISP. Since then, we have gone with a new ISP and part of the package of using it, we get Umbrella. With that being said, the old dashboard is no longer available. The new dashboard did not automatically populate / show the existing VA's even though they are working just fine. How do I get these existing VA's that were in the old dashboard (no longer available) to show in the new dashboard? Do they need to be re-registered or??? I appreciate any insight you can give me in advance. Thanks.
@NetworkWizkid4 ай бұрын
It sounds like you've got a new Umbrella tenant based on the new subscription. If that is the case, configuration from previous tenants are not transferrable and therefore that's why you cannot see the old VAs. The old VAs should be removed and you should configure new VAs for the new Umbrella subscription. I hope that provides some more clarity and thanks for watching.
@jjcrips49284 ай бұрын
Thanks for the response! Appreciate your time! Standing up new ones today!!
@antster74 ай бұрын
Can't you federate directly to Duo?
@NetworkWizkid4 ай бұрын
Duo isn't an IdP
@drifm4niac6624 ай бұрын
Nonsense the public transport it’s already overcrowded, this will only decrease the quality average life of the people ! And talking about funding if the government cared ,thy wouldn’t be sending money abroad to support wars and would instead focus on our country and our problems . Thoughts this was the whole point in the nonsense of leaving eu and making my shopping go from 250£ to 600£ 👏🏽
@sinade14 ай бұрын
This is informative. Thank you.
@NetworkWizkid4 ай бұрын
Glad it was helpful! Thank you.
@jonc53734 ай бұрын
Yes my brother. That really helped. liked and subscribed
@NetworkWizkid4 ай бұрын
Awesome, thank you and thanks for the sub!
@sleepyrasta4204 ай бұрын
I won't be paying per mile I'll just take the plate off my bike
@bolatan114 ай бұрын
Do you have the asa 9.0(4) image
@NetworkWizkid4 ай бұрын
Sorry, it's not permitted to share images. If you require the image, then please access software.cisco.com with a valid account that is capable of downloading software.
@bolatan114 ай бұрын
@@NetworkWizkid I know but the image is no longer on the cisco site as it is no longer supported
@NetworkWizkid4 ай бұрын
@@bolatan11 I see! I don't save the images unfortunately, sorry.
@NetworkWizkid4 ай бұрын
This tool has now been updated and includes 3 different options now.
@gavinbissell88474 ай бұрын
Looks like she needs the exercise
@aydnmahmudov67394 ай бұрын
Perfect worked for me on esxi 8.0. Thanks a LOT.
@NetworkWizkid4 ай бұрын
Good to hear, thank you for watching
@MarioRavellino4 ай бұрын
You're the master
@NetworkWizkid4 ай бұрын
Appreciate that, thank you :-)
@kutalanota21224 ай бұрын
Thanks for sharing as always and welcome back!!!
@NetworkWizkid4 ай бұрын
No problem and thank you...I had to recharge!!
@brambles00777777775 ай бұрын
Tax the drivers of the Q5's and X5's etc a fortune and make driving one up in a Chelsea tractor a premium cost.
@shaicruz1765 ай бұрын
I already pay per mile it’s called fuel duty. The more you drive the more you will pay. I will not comply to this law it’s inhumane.
@andrewstevens60055 ай бұрын
More ways of scamming drivers out of our hard earned money!
@dw55515 ай бұрын
Only hits the poor though. Rich will just keep driving.
@connorboyd66765 ай бұрын
So I gotta pay mandatory insurance, road tax, mot fees & this? I’m better off getting the bus
@ElenEmma884 ай бұрын
@@connorboyd6676 that’s what they want u to do ;)
@debeightonethree63465 ай бұрын
Pay per mile? Mate- that’s petrol. STFU with this.
@jamiearmstrong-vi9om5 ай бұрын
These "schemes" are not only unnecessary, they have virtually no support. Essentialy poorest are hardest hit....again
@NetworkWizkid5 ай бұрын
I think it's a ridiculous proposal - just another way to further tax motorists!
@Abdullah_khan3335 ай бұрын
brilliant... 👍👍
@NetworkWizkid5 ай бұрын
Thanks a lot 😊
@AlpiFirat5 ай бұрын
I dont have that cover thing for my Max hero 8. What Do I have to do?
@NetworkWizkid5 ай бұрын
Take a look at your manufacturers guide and they should highlight the correct process.