Thursday, April 25, 2019

Trying to gently approach my Network Admins and tell them that the DMZ has quite a lot of problems. Any advice on how to argue?

Hey folks, I discovered that many of your VoIP Problems might be related to the timeouts and latency in our voice DMZ.The network admins already had to fix some firewall rules and disable features that caused similar problems, so they are naturally defensive.

I now analyzed the pings to certain devices in the DMZ and to one IP on the web to use as a reference.https://plot.ly/~perskes/22/#/

One of the devices makes incredible trouble (SBC01, most timeouts), tracert shows that the hop that takes the longest to respond is the firewall, behind the firewall the response time drops to normal levels.

Besides the timouts we also have a lot of delay in the ping (or latency) and I was wondering how to approach the team (as I said, they are defensive as hell right now). I am trying take as little of their time as possible and give them as much info as possible as well. What else can I check before I jump to conclusions?

Edit to clarify: Timouts are marked with a 1000ms ping, a timout does not response with a time, so I took a high value to show the spikes.



No comments:

Post a Comment