Sunday, March 28, 2021

Palo Alto 3260 Install

 Palo Alto had a great firewall compared to the competition.  Below is another install as only an IPS box.  

Tuesday, February 2, 2021

PBR: Policy Based Routing On Aruba 3810

 Quick example that I did on an Aruba 3810 to force traffic out to another firewall.

============== Begin =====================

class ipv4 "Camera"

     10 ignore ip

     20 match ip


policy pbr "Camera"

     10 class ipv4 "Camera"

      action ip next-hop



vlan 10

   name "Camaras"

   untagged 1/10,2/10

   ip address

   service-policy "Camera" in


============ End ===================

As you all know, White Rhino Security does all vendor firewalls. For our small office, budget related customers,  we have been moving away from Sonicwall and are moving them to pfSense. We decided to make a pfSense blog page, with posts only related to pfSense and related items.  

Find it here at

Monday, October 5, 2020

Firewall Migration: Fortinet To Cisco

 It's a time consuming process, but manual moves of the configuration is just what you have to do.  Even if there was a migration tool, I've never seen anything that worked really great. 

Sunday, October 4, 2020

Wednesday, September 23, 2020

Can You Ping To A Certain Port Number?

 I had a phone conversation today with someone who said that they thought that they could ping to a certain port number.  I was walking them through using telnet to see if a port was open, when that statement was made.  Thats the quick way to see if a port is open, to just telnet to that port and see if you get a blinking light.  Easy enough, but can you ping to a certain port at the destination end?

Quick answer, No.  Here is why:

Notice above how there is not port number under layer 4 (Internet Control Message Protocol).  You can see Im pinging  But you dont see any port number involved.

Now, lets look at a UDP packet:

At layer 4, you do see port numbers.  Specifically a source and destination port number.  Same for TCP, but not ICMP.  

Always prove with a packet capture.