r/networking • • May 18 '24

Security Was this guy for real? Network security engineer

1.1k Upvotes

This network security engineer my company recently hired, he spends a good 2-3 hours daily staring at tcpdump on the external port on our four internet drain firewalls, no filter, just watching a rapidly scrolling screen of packets. Occasionally he click one of the putty’s, hits control + c, copies an ip to notepad, then hits up enter to start the dump again. He claims he can recognize certain malicious activity by watching the patterns of packets scroll by on the screen. He says once you’ve done the job long enough you can just tell when hinky stuff is happening, just by looking at tcpdump.

At the end of his shift he add all the IPs he copied to notepad to blacklist on the firewall.

r/networking • • 9d ago

Security Would you consider replacing Palo Alto and/or Fortinet with Juniper SRX?

84 Upvotes

Whenever the conversation on enterprise firewalls comes up on this group, I've noticed the discourse is always incredibly predictable:

"Palo Alto if you can afford it, Fortinet if you cannot. Honorable mention: Cisco FTD but we all hate those"

Juniper SRX? Never even mentioned in these topics.

I'm wondering why, though? What am I missing, or rather what are SRX missing to not be a major contender for enterprise NGFW consideration? It looks like SRX is more heavily used in Carrier & Telco networks versus enterprise networks.

Do you consider SRX a true "NGFW" firewall? Is it really as simple as "Palo and Fortinet have a nice GUI to manage and audit the security policy, and Juniper doesn't?"

r/networking • • Oct 17 '25

Security Which firewall vendors are actually keeping up with modern network demands?

208 Upvotes

I’m part of a mid-size enterprise that’s been slowly modernizing its network stack moving more workloads to the cloud, supporting hybrid teams and trying to unify security policies across data centers and remote users. We’ve used a mix of vendors over the years Fortinet, Check Point and a bit of Cisco ASA that just won’t die but lately we’ve been looking into newer, more integrated options that combine firewalling, zero trust and threat prevention under one roof. From what I’ve seen, every vendor claims to have “AI-powered” detection and “unified management” but the reality is often very different once you start scaling or integrating with identity systems. So for those of you managing large or complex environments, which firewall platforms have actually kept up with the shift toward hybrid and cloud-first networks? And which ones still feel stuck in the old appliance mindset?

r/networking • • 12h ago

Security How are you guys handling IP cameras on the network?

69 Upvotes

I want to know how other people are setting this up as camera counts start getting higher. Do you put cameras on their own VLAN and keep the NVR/VMS isolated or just treat them like any other IoT network? The part I’m most interested in is remote access. I’d rather not expose cameras directly to the internet but people still need to view footage remotely sometimes. What does your setup look like?

r/networking • • Aug 12 '26

Security CDP/LLDP

39 Upvotes

What are your thoughts on enabling CDP/LLDP everywhere except physical handoffs to untrusted /devices not managed by your org?

r/networking • • Aug 18 '26

Security Best firewall option for small nonprofit (<10)?

24 Upvotes

Hey everyone, I’m fairly new to the IT job field (about 1 year of experience) and have also been volunteering at this local nonprofit as IT Support on the side outside of my main help desk job. The President of the nonprofit has tasked me with finding a good firewall for them to use and I have no idea where to start.

For additional context, the nonprofit is very small (less than 10 people), they have hybrid work, and right now I’m the only IT person they have (they’ve been using a rotating cycle of volunteers). I do not know how to configure a firewall whatsoever so recommendations, as well as advice on how to configure and implement it would be much appreciated!

r/networking • • Aug 07 '26

Security Devices with public IP addresses

21 Upvotes

We sell network-attached devices for classroom use and we just noticed that a small number of customers seem to be allocating public IP addresses to them. We sell batches of devices, so this isn't just a single device sitting on their DMZ, in one instance there are 8 devices each with a real public IPV4 address that belongs to the organization. It also appears the ports are wide open.

Has anyone seen network admins do this before and if so why?

r/networking • • May 10 '26

Security Help me make an argument for Palo FW over Cisco FTD

45 Upvotes

Hi,

My company has a massive Cisco relationship which affords us some incredibly good pricing on all products. The vast majority of my company uses Cisco everything, including FTD and FMC.

We are living in a temporary facility right now for the next 1-2 years and using FTD/FMC.

It works fine and supports my needs, but to support everyone’s posts on here… it definitely feels like it’s barely hanging on as far as bugs, and forget it when you need to do upgrades… that’s a whole week burned because it never seems to go to plan. Also, Cisco documentation is a joke for FTD. Lastly, the OS is a mess of different CLIs glued together. It’s definitely Frankenstein like others have warned on here.

For our data center build coming up I want to potentially make the argument we should go with PA but it’s going to be massively more expensive as my company has basically no relationship with them.

That said, would Palo FWs actually make my network significantly more secure? If so, how?

My admins are of course begging for PA as they hate managing FTD, but that’s not an argument for leadership when I have to ask them for 500-700k for PA vs the pennies we’ll spend with Cisco. Plus the renewals!

Is Snort actually substantially inferior for to PA’s security features? Any data to quantity this somewhere? Any features that I can argue will actually make us more secure.

We’re an extremely lean network team so maybe I can make an argument that PA will give us more visibility? More security?

Thanks!

r/networking • • May 20 '26

Security Quic/HTTP3 ,How are you handling in Enterprise, in 2026

60 Upvotes

How are you handling Quic, DNS over TLS in your enterprise network, I see Palo Alto, Zscaler are recommending blocking it and falling back to HTTP/2,

But Chrome is aggressively pushing for adoption, and fallback mechanism is not mandatory, so soon enough , there is applications that will be broken by this blockage,

Appreciate your input rom experince.

r/networking • • Sep 01 '26

Security Checkpoint vs PAN/Fortinet

15 Upvotes

I'm evaluating Checkpoint Quantum and Quantum Spark. I come from Fortinet and Palo and have very little experience with Checkpoint by comparison. I'd like to hear some subjective opinions on the platform from people who have experience with it.

r/networking • • Dec 25 '25

Security NGFW Comparison - Cisco/Palo Alto/Fortinet/Checkpoint

84 Upvotes

Hey people,

Doing some documentation updates and looking at a possible NGFW refresh for our head-end and branch sites. I’ve mainly worked with Cisco gear, so I’d like some real-world pros/cons from people who’ve run these in actual network environments.

How have Cisco, Palo Alto, Check Point or Fortinet held up for you like performance, VPNs, routing, HA, day to day management, anything that stood out? And if you switched vendors, what made you pick the one you’re on now?

Thanks!

r/networking • • 11d ago

Security Emergency patch advisory: Cisco ISE CVE-2026-76460 (CVSS 10.0) — no workarounds, active exploitation

165 Upvotes

Heads up for anyone running ISE. CVE-2026-76460 is an unauthenticated API bypass that gives root on every ISE persona (admin, PSN, MnT, PxGrid). All supported versions affected. Already being exploited in the wild.

Cisco says there are no workarounds. Your options are patch or take ISE offline (which means shutting down network auth).

Practical steps: 1) inventory ALL ISE nodes, 2) schedule emergency maintenance this week, 3) check for compromise before patching (look for unexpected cron jobs, modified system files, unauthorized admin accounts), 4) restrict management interface access to a dedicated management segment, 5) if compromised, rotate ALL RADIUS shared secrets across every switch, AP, and WLC.

The management interface runs on 443 by default, same port as sponsor/mydevices portals. If any of those are internet-reachable, your ISE API is reachable.

r/networking • • Jul 16 '26

Security How can I force internal network traffic to pass through a firewall while keeping the core switch at Layer 3?

51 Upvotes

I'm new in the area and I have a network where a Layer 3 core switch currently acts as the gateway and routes traffic directly between multiple internal subnets and VLANs. Because the core switch knows all internal routes, traffic between internal networks is routed locally by the core and does not pass through the firewall. My goal is to make the firewall inspect and control east-west traffic between internal networks, not just Internet-bound traffic.

I would prefer to keep the core switch operating at Layer 3, since changing the entire core to Layer 2 would introduce significant risk and require major changes.

Some options I am considering are:

Placing an intermediate Layer 2 switch before the firewall

Running the firewall in transparent or bridge mode

Passing multiple VLANs through the firewall using trunks

Using VRFs to separate routing domains and force traffic through the firewall

Moving some gateway or routing functions to the firewall

I also need to apply policies between internal networks. For example, I may want to allow only TCP ports 80 and 4343 between certain subnets and block everything else.

My main concern is preventing the core switch, or any other Layer 3 device, from routing traffic through an alternate path that bypasses the firewall. Has anyone implemented a similar design while keeping the core switch at Layer 3? What architecture would you recommend?

r/networking • • Jan 19 '26

Security How do cybersecurity architects achieve full network visibility?

48 Upvotes

As someone in the cybersecurity field, I’m curious about how professionals get a “full picture” of a company’s network in order to secure it effectively. From an architecture perspective, where does the source of truth for the network usually come from, and how is it maintained?

r/networking • • Jun 20 '24

Security What firewall brand being used by a company to be kept secret?

169 Upvotes

Sorry, if this post is not revelant or breaks the community rules.

I went to interview today, the position is for IT system Infra. Anyway that one guy was asking me which firewall I am familiar with and bla bla. Then I was curious and asked what firewall are they using.. Being told he can't disclosed and even tells me I am a security guy, you know we cant disclosed. (yes I am infosec guy, changed from Infra)

I mean what the hell.. Technically telling what firewall they are using doesn't mean one can breached into their networks (yup yup understand in some cases specific models have CVE and one could somehow breached into) but then I was just asking the brand.

Any thoughts on this guys?

r/networking • • Jul 13 '26

Security OPNSense and alternatives

14 Upvotes

Hello everyone,

I've recently been thrown back into the networking part of IT (I used to be full Linux admin) and I was wondering some ideas and how viable they are.

The company I currently work for is using Sophos firewalls. However we have not been too up to speed with hardware EoL's and software EoL's (as all companies with suppliers are, I think).

I was recently exploring OPNSense on an old Sophos Firewall and these days it really looks nice!

So the question I am wondering. How viable is OPNSense in a company of like 200 people compared to Sophos of Sonicwall? Can it compete?

For homelabbing its obviously cool, but in a company?

r/networking • • Aug 07 '25

Security Why NOT to choose Fortinet?

56 Upvotes

Saw this posted a year ago and I would like to see updates or updated opinions. One of our teams is proposing a switch to Fortinet for remote access and broader network security.

Some people like the all in one platform and some like the fact its "proven" with long term support. Some are saying centralized VPNs (like Fortinet's) are adding more complexity and risk, especially as we move toward a Zero Trust model and support a more remote, distributed team.

What should we be wary of? Support, hardware quality, feature velocity, price gouging, vendor monopoly, subscription traps, single pane of glass, interoperability etc.

If you have chosen it are you happy/unhappy now?

Also want to know if anyone here has moved in a different direction to something more software-defined or identity based, that maybe leans on peer2peer rather than a centralized appliance stack. I read and hear that a different approach to Zero Trust is gaining ground, especially for teams that need better automation/IaC support/lower operational overhead

Trying to understand the real pros and cons in 2025. Appreciate any insights!

r/networking • • Aug 23 '25

Security Firepower - Still Awful?

49 Upvotes

My team had lunch with our Cisco SE today, and when discussing current projects, our Global Protect deployment on Palo VM-series firewalls came up. I don't have a great deal of love for the ASA platform, so I was honest saying none of us will miss AnyConnect once it's gone. He said something that for a Cisco rep is understandable, but as an engineer seemed like he hasn't touched another firewall. He said Firepower is a lot better than one would think, and he would put it head-to-head with any of our Palo Altos.

I've managed to avoid Firepower entirely for the last 6 years, other than us running some FP hardware in ASA mode for AnyConnect, so I'm pretty out of the loop. Is he saying this because it's his job and it is a device that moves packets in a configurable way and is something they sell? In a technical sense, I know the product works and there are several dozen deployed in the wild...somewhere. Having used Fortinet and Palo Alto for years now, I cannot imagine Cisco cleaned up their act enough to make it an enticing product compared to the more niche players.

Am I wrong to have ignored FP all these years in favor of Palo and Forti? Do I need to take one of our soon-to-be-decommissioned Firepowers and put it in a lab to brush up on it (probably gonna do this no matter what, free lab stuff).

r/networking • • Jan 21 '26

Security Firewall comparisons/testimony (Checkpoint/Palo Alto/Fortinet)

53 Upvotes

We’re planning a firewall refresh for an around 10k user environment (plus guest WiFi) and looking at options that can handle things like HTTPS inspection, identity integration and strong VPN capabilities ideally without killing performance.

We’re open to anything at this point Palo Alto, Fortinet, Checkpoint or others we might be missing. Just trying to cut through the sales pitches and hear what’s actually working for people in production. If you’ve had good (or bad) experiences with any platforms at scale, I’d really appreciate your thoughts!

r/networking • • Apr 19 '25

Security Fortigate Dropping SSL VPN

150 Upvotes

https://cybersecuritynews.com/fortinet-ends-ssl-vpn-support/

Am I wrong in thinking that this is a step backwards?

10 years ago, we were trying to move people from IPSec to SSL VPN to better support mobile/remote workers, as it was NAT safe, easier to support in hotel/airport scenarios... But now FortiNet is apparently doing the opposite. Am I taking crazy pills? Or am I just out of touch with enterprise security?

r/networking • • Aug 22 '26

Security DPI (Deep Packet Inspection)

42 Upvotes

So I am curious what others think about DPI? We run it on our UTM's but I kinda feel its more of a PITA then its worth. Looking to get feedback from others.

r/networking • • Oct 24 '24

Security Choosing a new firewall

53 Upvotes

Hello everyone,
I need your help in selecting a suitable firewall for our company's main site. Here are the key facts and requirements:

  1. Number of Users:
    • 130 internal users, typically 60-90 on-site.
    • Depending on the load, there are 105-160 devices (WiFi only) in the internal network (1.75 devices per user).
  2. Internet Bandwidth:
    • 1,000 Mbps (1 Gbps) for both download and upload.
  3. VPN Connections:
    • 9 Site-to-Site VPN connections: 6 sites and 3 services (two interfaces and one web application) are connected.
    • 70-110 simultaneous mobile VPN connections.
  4. Applications and Services:
    • VoIP, video conferencing via Teams, cloud services like Microsoft 365, web applications, internal web applications, regular internet access.
    • Internal servers (including file servers, application servers, database servers). These should be separated by network segmentation.
    • We do not publish any services to the internet.
  5. Throughput Requirements:
    • The internal infrastructure should perform well both internally and for VPN users (regardless of Site-to-Site or mobile VPN).
    • Traffic within the infrastructure (server to storage) should not pass through the firewall – this runs in an internal storage network.
    • Additionally, internet access from the main site should continue to perform well.
  6. Security Features:
    • Including IPS, anti-malware, application control, TLS/SSL inspection, network segmentation, and routing.
  7. High Availability:
    • Active-passive high availability solution desired.
  8. Conditions:
    • For future planning, I would like to account for an annual increase in traffic of 5-10%.
    • Additionally, we are looking for firewalls from the same manufacturer for the other sites. These sites do not have extensive infrastructure and need the firewalls mainly for local internet breakout and VPN connections to the main site.
    • We are looking for a manufacturer that offers a good price-performance ratio and can meet these requirements for the next five years.
    • A good VPN client for Windows and Android is very important to me. It must have good MFA integration.

It is particularly important to us that the firewall can provide both VPN throughput and throughput for all security features in parallel. Do you have any recommendations or experiences with specific models that could meet our requirements? Thank you in advance for your help!

r/networking • • Oct 11 '25

Security Anyone here actually happy with their SASE setup?

48 Upvotes

We’re running an RFP for a new SASE platform and honestly, all the vendors are starting to sound the same.

Everyone’s “cloud-native,” “unified,” and has a “single pane of glass”, but no one seems to agree on what that actually means once it’s deployed.

If you’ve been living with any of the big ones (Palo, Fortinet, Cisco, Zscaler, Netskope, Cato, whatever), what’s the real story?

  • Did integration go smoothly or was it a nightmare of agents and connectors?
  • How’s the day-to-day management, is it really unified, or just marketing slides?
  • Any weird costs or performance issues that caught you off guard?
  • And if you had to do it again, would you pick the same vendor?

We’re a global org (few thousand users, mix of remote and on-prem) trying to get this right the first time.

Appreciate any honest takes — the good, bad, and ugly.

r/networking • • Nov 07 '25

Security Turned on full decrypt in Zscaler and the helpdesk exploded. Do Netskope / Prisma / FortiSASE handle it any better?

31 Upvotes

We enabled SSL inspection company-wide and instantly got Teams lag, random timeouts, angry users. Zscaler support said “tune the bypass lists,” which feels like whack-a-mole.
Before I start re-architecting this, wondering if anyone’s had smoother luck with Netskope, Palo or even Cato’s SSE stack when everything’s decrypted.
Do any of them actually keep performance decent, or is this just the tax you pay for visibility?

r/networking • • Aug 28 '25

Security ClearPass replacement

29 Upvotes

Hi,

we are looking for NAC solution what is simpler to manage then ClearPass. Any recommendations?

BR.