Comments

  • Support finally called me back. We stopped the services for a few minutes, and then restarted them, the status eventually updated on the gateways page that it was installed, and then I was able to add my secondary GWs. I was also told there would be a statement from WG about this incident coming up.
  • So.. No change since last night, and no update from WG either. Ask me how impressed I am... Go ahead, ask me... I decided to completely delete the existing gateway (since it wasn't working anyways), and I created a new one. Now WG cloud still shows it as "Not Installed" under Gateways, but when I look at the logs in…
  • I'm not disputing that fact Tristan, and thanks for the updates (since WG isn't providing them)... Just frustrated at this point in the day and shit runs down hill, and I'm about half way down that hill right now with it being ankle deep. :-) I just turned off all the customer's infrastructure for the rest of the night and…
  • Tristan - I've restarted the services multiple times today without any change...
  • Well at least you guys are getting updates.. I'm only a 20+ year gold partner who only sells security products from WG, and I've heard squat... Err... Diddly squat... Over the past 11 hours, even though I've asked multiple times for updates... My customer doesn't care if it is Amazon's fault - they are paying WG for a…
  • Yes... I've got a customer who's been affected for over 10 hours now and is basically crippled... We called support and after an hour of waiting on hold to actually talk to someone, the call dropped. Called back and waited almost another hour. I also got the WG country manager involved. It's been over 7 hours now since we…
  • "deny.+udp" seems to stop the 50% CPU utilization and FSM having fits, yet still accomplishes the results I'm looking for. As was just explained to me by the WG sales engineer responsible for our Partner account: We do not have the “AND” operator but I usually do a search with the “anything” string between the 2 expression…
  • Yup - I saw the exact same results on my M370
  • Ah - that's much better. Thanks Matt! I sure wish there was more details on this in the documentation. I even went and watched the section in the current Fireware 12.7 network essentials training video this morning and it's not even mentioned. dcc
  • No - that didn't work. And I even tried switching it to (?=.deny)(?=.tcp) to double check.
  • No - I don't think AC will work. AFAIK, traffic coming out of these VPN and Tor nodes is just standard traffic without any markings in them.
  • Yeah - now that would be challenge!
  • I also don't see how this would be any different than steps in the documentation for deploying TDR in OS Image, the only difference here is the account is also being changed in addition to the UUID. Anyways - it may not be supported, but it still worked like a charm, and no after effects yet 3 weeks later. dcc
  • Gregg - I think maybe you misunderstood my ask (maybe I wasn't clear enough either)... O365 is O365 and has nothing to with that customer's M370 cluster, or my ask. Rather the BEC was a catalyst to prompt me to look at what we can do to protect services that we run on prem (not just at this client site, but all our other…
  • No - found it via Strings.exe (from the Sysinternals Suite)... Just dropped the output of "strings host_sensor.exe" to a text file and searched for clearSensorUUID (which is used when imaging machines), and from that found setAccountUUID. Know this exists, then did a Google on setAccountUUID and found this:…
  • I know I'm a little late in answering this, but I too was a long time Symantec Gold partner / reseller, and Phil is correct - Symantec and now Broadcom are now painful to deal with both as a reseller and a customer. As a partner, I'm not allow to sell licenses unless I specifically have a quote from them, which can take…