Tuesday, April 2, 2019

MM fiber to SM back to MM?

We have just moved our office into a new building, and I (company network admin) did not handle the ISP communications for the new site, or the inside wiring (my boss did that, and I answered his questions along the way.) So we moved into the new space, and it came time to turn up the new circuit, and I found that unlike our prior location where the ISP terminated their circuit in our data center, all the ISP circuits terminate in a office park MDF, and then the building’s management co has an authorized inside wiring contractor extend the fiber into our suite (only that wiring contractor and the ISP techs are allowed into the MDF - no tenants.) So we had told our ISP to handoff on 1G MM fiber (LC connector), but it turns out that the inside wiring contractor ran single-mode fiber from the MDF to our suite, which I only found out when we went to turn up the circuit, even though my boss had also told them we needed MM. (When he called them to get them to change it, they told him that’s the only way they do runs.)

So now we have an ISP handoff on MM fiber, and our router (Cisco ISR4431) currently has a 1G MM SX SFP... What’s the best way to deal with this situation without having the ISP have to make a change? The circuit turnup was supposed to happen yesterday, and now is rescheduled with the ISP for Thurs, which is delaying the office opening...

Thanks!



ISE 802.1x rollout to multiple sites - dACL vs Vlan and Vlan Groups

Currently for 802.1x and MAB with Cisco ISE I am using a dACL for unauthenticated domain machines along with some rules that use either different dACLs to allow traffic or a specific Vlan for certain machines. This is working well, but I need to roll this out to multiple sites and I have some concern as not all of the sites have uniform Vlan setups and have their own distributed servers for AD and such.

Right now its easy to apply to any normal data vlan.

Machines without domain certs get put in guest vlan and set to guest registration portal - VLAN redirect (MAB)

Machines with a domain cert get a 'Domain Services Only' dACL. Allows AD auth and SCCM patching, certs, etc - dACL (802.1x)

Domain users logging in via 802.1x with Domain machine cert and domain user cert get standard access accept - no dACL or VLAN (802.1x)

Special case users get specific vlans by dept (HR, Finance, etc that are pre segmented) - VLAN redirect (802.1x)

Works pretty good, except I only have 1 site so far. As I roll out I will have to add a ton more servers to the dACL (local AD, DNS, SCCM, and Cert servers) So I can see that dACL getting very large and applying to a lot of ports. I'm worried about the dACL overhead, is this typically an issue in large deployments?

I'm also worried that the Vlans are not consistent throughout each site, so this may end up in resulting in a huge policy list providing proper Vlans.

Theoretically I could use dACLs for all groups and simplify it a little bit, but that would mean a dACL applied to nearly every port, is this even feasible? Does anyone use this approach?

The solution I thought to use to simplify this setup prior to rollout and making it easier to roll out would be to use a standard unauth Vlan and a standard set of vlans for a Vlan Group. It would be easy to carve aside a set of vlans I could deploy at every site and I could script it pretty quickly. I would have each site's individual 'Domain Services' ACL entries applied to the site's own Unauth Vlan and then a Vlan Group or two that I can name the same but customize at each site as needed. This would clean up my Policy rules and overal Vlan usage. It does require some more background maintenance though..

My idea would look like:

Machines without domain certs get put in guest Vlan and set to guest registration portal - VLAN redirect (MAB)

Machines with a domain cert get put in standard Unauth Vlan. Allows AD auth and SCCM patching, certs, etc -VLAN redirect (802.1x)

Domain users logging in via 802.1x with Domain machine cert and domain user cert get standard Vlan Group - VLAN load balance (802.1x)

Special case users get specific Vlan Group by dept (HR, Finance, etc that are pre segmented) - VLAN load balance (802.1x)

Does this seem like a better plan for a rollout? Has anyone used Vlan Groups and multiple Vlan redirects with 802.1x with success?

Suggestions welcome!



Combination of features on a Nexus 9K?

So I got it in my head to try to do some poor man's network segmentation in our DC. I've got two Nexus 9Ks running vPC with SVI's configured with HSRP pointed towards the servers. These SVI's have some older network ranges assigned on them and we're wanting to migrate to newer ones so I was thinking of using multinet so that the server team can re-IP as they can without changing VLANs. I've also got dual-stack on these interfaces so the servers can be configured with IPv6 and the upstream connectivity is our Palo Alto firewalls with OSPF doing dynamic routing and high availability.

To do the segmentation, I'm looking into PVLAN. The problem is, the Palo Alto's have no concept of that so the SVI for each network has to remain on the Nexus 9K. I don't really want to do ACLs, we currently use our firewall for that, so I was thinking of applying IPv4 and IPv6 policy-based routing to force traffic coming in from the PVLAN to the firewall at the next hop. Once approved at the firewall, return traffic would simply follow the dynamic routing path back.

I've done basic research on this and it looks like all of the features are supported but I've run into issues with undocumented bugs on other Cisco platforms when combining things like this.

Here is the list of everything I'm looking at implementing together:

  • IPv4 and IPv6 (so all other features have to work with both on the same SVI)
  • vPC
  • HSRP
  • OSPF
  • Multinet
  • Policy Based Routing
  • Private VLAN

Anyone have any experience with using most of these together or see any reason it wouldn't work?



Rant Wednesday!

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!



Dynamic Arp Inspection + Ip Source Guard (With Roaming)

Were running into an issue with a property where one of the wireless clients is static assigning the gateway IP. The problems we have is we must support Multicast in the same VLAN. Our first thought to prevent this type of IP theft was to implement dynamic ARP inspection for the router, and Ip Source guard on the switch ports towards the APs. The problem is roaming however, if a client moves from Port 1 to Port 2.. our thought is that this could enforce source guard to only allow on Port1.

Has anyone implemented such a security design where hosts must use DHCP creating a ip binding in the switch but allow roaming ?

if ip source guard supported DHCP LEASEQUERY which would allow lookups for moves the problem would be resolved but i don't see that feature set in the switch. (Cisco 2960X).



Q ref SD-WAN and Skype for Business externally hosted

Is anyone presently running the $subj scenario?

To be more specific - we are presently setup with a hosted Skype for Business provider (in a few of our outsourcer services data centers, distributed globally), which tie into our network utilizing our MPLS, in order to preserve the quality of service demand for voice and video conferencing.

We are contemplating deployment of SD-WAN, with SD-WAN devices being installed in each remote, replacing our routers. The challenge comes in the migration process, during which it seems that we may need to double up the MPLS connections in each Skype hosting data center, so that one is used "under" the SD-WAN overlay, for sites being migrated to SD-WAN, in need to use Skype, while the other MPLS leg is left for the still-to-be-migrated sites, for their Skype needs.

As this migration (few hundred sites, globally dispersed) is a long duration process, and it is hard to anticipate the pattern of traffic, we will probably end up supporting the MPLS dual connectivity for quite a while, unless we could somehow leverage Internet connectivity into some of the Skype hosting data centers ... ?!?

Extra challenge: MPLS is fully meshed. SD-WAN won't be (appliances in remotes won't support so many simultaneous tunnels), so a further regionalization of Skype access may be needed, but with some ability to still get multiple regions into the same conference calls, or having end points talk to each other across multiple regions (for which we think of having some hub-and-spoke with our data centers, from everywhere).

Anyone having run into this issue, and having some suggestions / recommended design patterns?



NETSH trace extra data

Hi everyone. I am attempting to capture some traffic on host using netsh trace and am running into an issue. The traffic I'm trying to capture is sporadic so I need to let the trace run, but also can't let it get too large. Here is the command I am using:

netsh trace start capture=yes Ethernet.Type=IPv4 IPv4.Address=x.x.x.x tracefile=<path>

While this is running, the trace file grows continuously, even when no traffic involving that address is ocurring. I let it run for approximately 5 hours yesterday, and it was filled with rows of "ETW" events. I don't want anything else except the traffic involving a specific address. Any help would be greatly appreciated.



Dynamic PAT : ASA, IOS legacy and NVI. So, what you gonna do with the source port?

https://ift.tt/2CPr4w0

Can't get faster than 500mb down/up

https://ift.tt/2CLSbYP

Static IP address Vs Dynamic DNS server

Hi all,

I'm setting up my own FTP server for me to access it online, I have changed my IP address from dynamic to a static IP address and opened the ports for my FTP server.

My question is I was told that even know my IP address is static meaning it will never change that I need a DynDns as well. I'm confused as to why I need to have a static IP and also have a dynamic DNS server.

Can someone please explain the difference because it sounds like the two are the exact same.

Static IP address keeps my IP address the same no matter if I have a power failure, so what is the purpose of me needing a dynamic DNS server?



Connect Intel XL710-qda2 to Cisco 40GB SR BIDI via LC connector

Networking has a couple of 40GBe switches and XL710 cards I can use. I would like to connect a bunch of servers to those switches.

Issue is that they want to use Cisco QSFP-40G-SR-BD adapters with LC connectors on their side and I can not find a compatible QSFP+ adapter for the Intel XL710 card.

Can anyone suggest which QSFP adapter to use with the Intel card?



Are we allowed to ask networking questions in here?

Do you get a performance increase by enabling sdm lanbase-routing or just leaving a Cisco switch at layer 2?



I have to update the IP on the loopback interface on 100+ access switches. Is there a way to automate this to get it done before the week ends?

No text found

Aruba releases datasheets on new 802.11ax APs, AP-535 & AP-555

https://www.arubanetworks.com/assets/ds/DS_AP530Series.pdf

https://www.arubanetworks.com/assets/ds/DS_AP550Series.pdf

Pretty interesting. The 555 looks to have more features than any of the other 8x8:8 APs on the market, tri-band and spectrum analyser. Both support UL and DL OFDMA.



NAT not working

This is probably something simple, but I am stuck, not a firewall expert.

I have, in my network, a firewall and behind it a network that doesn't interact with our main network save for a few IP. The topology is this:

(Inside Network 192.168.173.0/24 GW int 173.1 ) - [Mal-ASA] - Outside Int IP (192.168.66.10/24) the 192.168.66.0 is also an internal network behind a firewall that goes to the isp, the topology is:

[Mal-ASA] - Outside Int IP (192.168.66.10/24) trunk to L2 network switch to (Inside int 192.168.66.1) [ASA-Out] (public IP)

I am trying to NAT on the internal Mal-ASA from 192.168.173.5 to 192.168.66.12 on the outside interface of the Mal-ASA. For some reason it is completely unreachable and I am not seeing why. The ACL both ways are ip any any for now.

Thanks for any help.



Help with Ansible

Hi guys, I've been messing with Ansible for past two weeks and I'm simply amazed by its capabilties (maybe a part from super sensitive data format :D). I need a help with two things, I've been provisioning new switches and so far have done dns. vlans, ntp, acls etc all with Ansible. I need to configure hostnames for switches from a variable that share same naming convention. Let say I've got 10 switches in hosts file and I'd like to assign them name e.g. '501-MDF-SW1', '501-MDF-SW2', '501-MDF-SW3' etc. I think I've tried everything but no luck - is there even a way to do it?



Homework help regarding Zone transfers

Below is the question that I have to answer for some homework. My main question is if i'm going in the right direction or not. What I think is that this requires the creation of a secondary zone and a zone transfer from the csmpub.com to the DCs using a standard Refresh Interval. Steps would be to configure it in on the Zone Transfer Tab under properties dialog. I don't need a step by step here on each action. I have a description how to do this in my book.

Case Project 10-1 Resolving Names of Internet Resources

You have an Active Directory–integrated domain named csmtech.local with two DCs that are DNS servers.

You also have an Internet presence with its own domain name, csmpub.com, and a DNS server that’s not part of an Active Directory domain.

You want the DCs to be able to resolve the names of csmpub.com resources and to act as backup for the csmpub.com DNS database.

What can you do to achieve these goals? Describe the steps you would take.



Help determining if NAS will fit in a cabinet

I'm looking to install a cabinet and rackmount NAS for my small business. I'm new to rack mounted equipment and have a question about clearance and installation that hopefully someone can help me with!

I'm Currently looking at putting a QNAP TS-977XU-RP into this cabinet with these rails

QNAP NAS Dimensions:

(HxWxD) 1.7 × 19 × 19.9 inches

Cabinet Dimensions:

600mm overall depth (23.622"), dimensioning on website image shows a max rail depth of 20"

Rail Specs:

Mounting post width: ≥ 17.8"/451mm 
B. Panel width: ≥ 19.1"/485mm 
C. Mounting post depth: 18" ~ 32"/443mm~815mm
D. The distance between two rack posts is 18.3"/465mm (center-to-center)

So, it definitely seems to me that the NAS will fit, but I don't have the experience to know if it will leave me with enough clearance for cabling or anything else.

Side note, I was also considering the Synology RS1619xs+, but that definitely seems to me like it wouldn't fit, correct?

Thanks!



Cost per mile for installing fiber on telephone poles

I have an ILEC, a monopoly that is the only internet provider in the area. Over the last few decades they have done nothing without being bribed every step of the way. Right now, some neighbors finally snapped and said that we would pay for a fiber line to come out to us (we're currently on satellite.)

They bid the line at $45k/mile for 3.5 miles on empty telephone poles. My question is, how much would you expect to pay for 144 count ribbon fiber on telephone poles? Is there a calculator just to determine the cost of the line (I can't find the price of 144 ribbon online)?



Vlan hopping/ frames question?

I understand the idea behind vlan hopping, which is that someone can "gain access" to another vlan through sending the double tagged frame or switch spoofing, but what i dont understand is how sending a packet gives them that access? Why does VLAN 20 accepting a packet it shouldnt be receiving give the attacker anything? Wouldnt the vlan just accept the packet and that's that? Once the vlan accepts the packet, how does the attacker have access to the information? I feel like i dont have a proper understanding of what frames being sent across vlans are capable of. Could the frame contain a packet sniffing tool or something? Is that why? Sorry im still learning this stuff



China ISP recommendation

Looking for a new ISP in China to serve Asia countries, any suggestions? We are looking at Tata and PCCW atm, the budget preferring PCCW, however I never dealt with them and no idea about their cover/reliability... ? any help would be appreciated :slightly_smiling_face:

Hong-kong/10g circuit, full BGP table, 2g commit

Thx



Anyone have any experience setting up a (pfsense) VPN for Windows 10 connections?

What's the easiest way to do it if I don't care about security?

What's the easiest way to do it if I do care about security?



Cat6 termination cost

I know you guys probably see things like this all the time, but I am a minor(16) helping my dad renovate a place. I terminate the cat6 wires, and I want to know how much I should get for doing it. I am usually there like 2 hours per day 2/3 times per week, and I have done over 30 cables(and they work). I am the only guy who does it, and I have done everyone in the building. I want to ask for like 1/10th of the normal cost, (so if it would be like $50 per hour, I would ask for $5) because I just want a little bit of compensation. I also helped put the cables in place(I sat in a dark attic for an hour dragging the cables), and I test them as well. Also, let it be known that I am dumb, and I don't know the words for these things. Any info would be appreciated



AWS Transit Gateway designs

I'm looking into ways to connect VPC's in different regions together without having to manage VPC peering between all of them. AWS Transit Gateways sound nice, but based on all of their diagrams they seem to want you to connect all of your existing VPN connections to the TG itself, rather than to your local region VPC.

An example of what they seem to want you to do is on the right of the following image:

https://imgur.com/BVgb7M0

I'd like to continue to rely on our local IPSec tunnels to our regional VPC's to keep latency low while employing a TG somewhere to tie all the VPC's together over the AWS backbone. Is that something anyone else has done, or am I missing something?



Temenos t24 network

Hey guys does anyone manage the day to day operations of a network that hosts the Temenos core banking solution?

Do you guys host it on perm or on the cloud (azure) In my environment we have it hosted on a different continent which is over 250ms and we experience soo much slowness on a 25mb and even a 50mb DIA.

I was told by my directors that cloud is the way to go, however I told them most of our customers are in the country but they like cloud for some reason.

We had no Azure servers in our region that could host (apparently Temenos has to host it in azure for us)

Also we have no azure express route provider in the country so we probably need to pay a local ISP for transit and do BGP on our SRX 1500.

The cost is prob going to extremely expensive.



SD-WAN right for us?

We have 2 Head Offices in different parts of the country

60+ Retail branches spread throughout the country

Each site is making a site to site VPN connection to our data center.

Each branch site has a 5506 with 1 internet connection. Mix of fixed wireless, DSL, Cable

From my understanding, SD-WAN basically connects all branches to one location where all the QoS/Load Balancing etc.. is done.

For SD-WAN to be effective, I read I will also need a failover line as well.

Still trying to wrap around my head on SD-WAN and other benefits aside from management.



Network interface filtering question

Hey all!

I utilized a Nipper router config assessment tool on some perimeter routers.

Came up with a "Interfaces Were Configured With No Filtering" high risk however; the routers are utilizing Zone based policies.

Is this a false positive since Zone-based policies are implemented? Or am I missing something?



Amateur looking forward for feedback and a slight troubleshooting with a network design

Greetings. I am a student who has taken up on network design very recently and wanted to see if I'm going on the right track with this.

Now, in the diagram I present, the four areas represent four different departments within a single company (same building/physical location).

Here is my network diagram in the link below:

https://i.imgur.com/S0oj7o8.png

I wanted to get to know about the best practices to follow when designing such networks, keeping fault tolerance and scalability in mind.

I'm also open to any suggestions and tips that can help me to get familiar with and further improve upon network design.

On a side note, I'm also having issues connecting the server (in the diagram) to the rest of the network, if that is efficient at all.



Any useful networking powershell scripts out there?

Any scripts you use for automation? I have one I use with putty to ease the process of applying config changes to cisco switches, and 2 others that I use to automate changing my static IP and then changing it back to DHCP. Nothing too crazy, but I have recently jumped into it and just curious if anyone else out there uses powershell with networking and what you use it for?



Windows IPSec to FortiGates

Hi everyone,

Looking for some guidance. We have a Windows server up on AWS and I'm trying to use the built-in Windows VPN services. I have an IPSec tunnel setup on dual FortiGates in their SD-WAN configuration.

The Windows machine connects, FortiGate shows the tunnel being up, but then the Windows server never completes giving the error "The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer." Then the tunnel disconnects.

Any thoughts?

Thanks



CSR1000V on ESX: I keep getting bitten by vApp Options

I use a CSR1000V on ESX in rare occasions and have found (3 times now, because I keep forgetting) that my workflow is unsafe.

Generally speaking, that workflow looks like:

  • Grab the "for VMware" OVA bundle from Cisco.com
  • Attempt to deploy the OVA
  • Become enraged that the OVA includes an unrecognized interface type
  • Unwrap the OVA, fix the OVF within, fix the checksums, roll it back up
  • Deploy the fixed OVA, ignoring all of the pre-deploy configuration capabilities (I understand there's cool automation potential here, but I generally need just one or two routers for a quick task, this is not a automate-the-fleet situation)
  • Enable IP/SSH/AAA via the VMware console
  • Finish the job in the usual way over ssh

At this point, everything's fine, the configuration is saved, the router reloads, the configuration is getting vacuumed up by RANCID, etc...

Then weeks later, when there's a problem with the hypervisor (crash, power failure, etc...) I discover the "flash" and "nvram" of the virtual router have been wiped clean by the vApp Options checkbox.

The deployment guide mentions vApp Options, but only as a feature, not as the hazard that I've found it to be.

Am I doing something obviously wrong/stupid here?

Have the rest of you been through this?

Why have I been encountering the bogus interface type error for years, but the internet is virtually silent about it?

I'd like to improve my workflow, but it's not obvious to me where I've gone off the rails. I suspect it's early in the process because of the OVA incompatibility.

Remembering to uncheck the box is a strategy I can try to employ, but I'm guessing the problem runs deeper than that :)



Change DSCP Value on Layer2 N5k

So I been googling for two days and haven't found a clear answer. I find things that are way more complex than what I need. I am not a QOS guru.

Scenario: Traffic comes in port 1 from a router we do not control. When it comes in it will then switch to port 2 to one of our devices. When it arrives on our device it shows DSCP is 0. I need to have it changed to anything besides 0, but lets say 46/EF cause its voice. I control the switch, Nexus5548 running 5.1.3.N2.1b.

I have tried numerous ways but nothing is working for me. One of my limits is I can't do a service policy out put on port 2. This would lead me to apply in on port 1 (router). Its not that it is not working, its more that it will not take a full config of when I try. SO I know I am missing something. Here are some resources I been using:

https://www.netcraftsmen.com/testing-egress-marking-in-nx-os-qos/

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/qos/513_n2_1/b_Cisco_Nexus_5000_QoS_Config_Guide_513_N2_1/b_Cisco_Nexus_5000_QoS_Config_Guide_513_N2_1_chapter_0111.html

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/qos/513_n2_1/b_Cisco_Nexus_5000_QoS_Config_Guide_513_N2_1/b_Cisco_Nexus_5000_QoS_Config_Guide_513_N2_1_chapter_0100.html



Does a 4G amplifier amplify or just "move signal" from the antenna, inside?

Hi, i am trying to improve my home's 4g signal. I have found many $50-500$ 4G amplifiers an di would just like to understand if these signals are being amplified or just "moved" to a different location by that amplifier?

Thanks in advance.



How did the kids do this?

Saw this cross my newsfeed today:

https://www.nj.com/hudson/2019/04/2-students-at-a-nj-high-school-charged-with-jamming-schools-wi-fi-to-avoid-exams.html

And it was cited a few times that there was some app that would jam or flood the AP, killing signal in the process.

My question is, how could they have done this, so I can try and block this?



Recommended reading list?

I started reading "Top-Down Network Design" from Cisco and I wish I started reading this earlier. It`s very informative and adds to my general network knowledge.

What are other good books to add in my reading list that you would recommend (could also be programming related)?



NetFlow probe on servers

Hey guys

Our sysadmins are trying to move systems to aws and are trying to identify what the standard flows are for their systems (these guys never documented their architecture)

I am looking for any NetFlow agents they could install on their servers and send to a collector (graylog/Prtg, etc) that we have

I found them nProbe but it’s too espensive for them sigh

Anyone know or anything else that could do NetFlow or audit inbound/outbound on a host?



DHCP issue on Fortigate

Hi everyone! Experiencing a weird behavior on my Fortigate unit from yesterday. Please help!

So, basically we are setting up a new network of /25 for a client and I'm not able to get the DHCP IP for the client's machine. VLAN tagging is proper and I can ping the subinterface IP on my Fortigate unit from my access switch. So, traffic is flowing through Core, Distribution and access switch and the moment I connect client's laptop no IP gets assigned. Tried entering the IP manually and the best part is it doesn't even take the static IP, getting the APIPA range. Also, even VLAN interface on the switch is not getting an IP when I switched it to DHCP so can't tell it's end client machine issue.

Thanks in advance. Please help!



SSID visible to website servers?

My customer says that she can sort her websites visitors by their network SSID. She showed me statistic from her site that sorted visitors by “networ”. Is this really possible?

She wants a more anonymous SSID so she can’t be tracked.



While building smart buildings..

How does network segregation using VLANs impact the construction and design of a building? 



Monday, April 1, 2019

sflow sample rate for 60Gbps/40Mpps packet rate traffic

We have Cisco Nexus 9396PX switch and running 60Gbps traffic with 40 million packet per second rate on one trunk interfec. If I go ahead and enable sflow what would be the best sample rate I should use to not kill my switch and sflow collection



Centurylink/Level 3 - Can't provision Fiber

There's a site that I'm looking at that has an old Level 3 fiber circuit going to it. Since Centurylink bought Level 3 it took awhile for me to track down the correct department to inquire about activating the circuit and providing DIA or Transport to a POP.

After a week of waiting I got the following message back from the rep I've been speaking to about this location:

I truly do apologize as this process has been dragged for more than what I expected. According to my Engineering group the  “NATIONAL” fiber in this area is Long Haul fiber which looks like what that tower might have been connected to and we don’t provision customers on this Fiber.

Unfortunately there is no way for us to provide the Gig Fiber around the budget your provided me.

Does anyone have a good contact at Centurylink that could look into this for be ? For this location, Level 3 was the only fiber circuit brought to the address and to bring someone else in I'd have to pay to cut into another long haul fiber (if that's even possible and it would be in the tens of thousands to do it.). I feel like the last two sentences contradict each other as well. You don't provision customers on this fiber but in the next sentence you can't do it within my budget? I asked for a 1G DIA circuit and stated my budget was no more than $1500/m or I'd like transport back to the POP w/ colocation service because I felt that might have been cheaper.

I kinda feel like I'm getting dicked around or I'm still not talking to the right person. I've been dealing with this for the past two weeks now and I'm running out of time. What do I do in this situation ? Is there another department to speak to directly at Centurylink ? Someone had to have had service at this location before. I just don't know the history of it but this is a first for me so idk what to do now.



Small rack, do I need ups and psi?

I’m planning my home network rack. If I buy a UPS that has enough outlets to support all of my electronics (switch, router, modem) , should I purchase a PDU as well? I don’t think the PDU is necessary but would like some opinions. Thanks.



Avaya switch and dead vlans

Guys so standard avaya switches have more than just 48 ports right ? If I wanted to assign the other unused ones on it like the fiber to dead vlan and port security what would the commands be for those interfaces ?



Frontier Netgear B90 Gateway/Router wont push enough signal down 200ft of cat6?

Hey everyone! Here is my issue. I have a client who has rental getaway cabins out in bfe. Problem he is having is not having good internet. He is charged business line prices for not much better than 5 Mbps. It's PPPOE DSL and they supply these really old Neatgear B90 "all in one" deals. Oh and there are 8 of them strung about property, around 250 yards apart or sometimes less. My part solution to help him out a little was to delete every other service and run 2 cabins off one service. So went and got my 🐈 6 cable and started making runs. We got the first 2 done and I went to place a AP on the other end for the one cabin and nothing? My cable tester which runs off a 9v ran the less than 300 ft? And My laptop would work. But I had 4 different routers I hooked up and nothing? One Linksys router ( 3 of the 4 was all Linksys) seemed to start working. Lasted a day. Then stopped? I set it into bridge mode and that's about all you need to do? I have done this a million times but I have never worked with PPPOE type on internet. And there isn't anything on Google either. I can't be the first that ran into this issue lol. Frontier is the ISP. And they no nothing about anything. I would really like to understand why I can get way less then the minimum standard out of these routers?



GEO IP Database for firewalls

Is a there a free reliable geo IP database website that I can make API calls to? I want to setup a python script to mine the website for United States IPs and have the script import them into my watch guard firewall via cli.



IPS with encrypted traffic

How effected is IPS and anti-malware on a FW for SSL traffic with decryption on the FW not enabled?



RJ-45 Ends for Cat6 Direct Burial Cables (23AWG)

I've got a project that uses 23AWG solid/shielded CAT6 cabling. It's direct burial stuff, so the jacket is exceptionally thick as well. It seems that CAT5/6 RJ-45 plugs are designed for 24AWG--even ones that claim compatibility for 23AWG. Has anyone here had success finding plugs? If so, what brand/part works best? Did you need a special crimping tool for these plugs? Thanks in advance!



What's your opinion on connecting to a private IP via VPN on a third-party network?

I've been asked to set up a site-to-site tunnel for this but I've generally regarded it as poor practice, and most third-parties I've dealt with won't allow it anyway. It would a public IP on my end and private on the other. I don't really want to do it but it's not my call.



2960-x to 2960-s 1GB Fiber help.

We updated our auditorium and need a 24 port switch added. We have a extra 2960-s so that is what we are using.

We ran fiber from the new auditorium back to another closet to link to a 2960-x.

Since 2960-s is 1gb only we got two cisco GLC-LH-SM optics. We know the fiber works the company already tested the line they ran so it's not that.

I plugged each optic in and connected the fiber and I cannot even get the links to activate. Obviously I shut/ no shut on both. Here is some configs.

2960-x

interface GigabitEthernet2/0/49

description Uplink to CHS-AUD

switchport mode trunk

srr-queue bandwidth share 1 30 35 5

priority-queue out

mls qos trust dscp

auto qos trust dscp

2960-s

interface GigabitEthernet1/0/25

description Uplink to CHS-AUD

switchport mode trunk

srr-queue bandwidth share 1 30 35 5

priority-queue out

mls qos trust dscp

auto qos trust dscp

What could be stopping these links from even coming up? Am I missing something super obvious? They always say down/down but I type a Show Inventory and I can see both GBIC's so they are being recognized. Let me know if anyone needs more info. This seems like such a simple problem but it just won't connect.

I have also tried multiple GBIC's.



GlobalProtect and other VPN clients. How to secure host devices by not allowing them to change routing info.

Hello all,

I had an argument a couple of days ago whether its actually worth tunneling all internet traffic to the firewall vs split-tunneling. I always thought that the traditional approach would be best until I was told that this could be easily changed by adding a static route to the host device.

So I have tested it. I have configured a PA device without split tunneling and verified that I get internet trhough the Palo Alto firewall. Then I put a static route on my end host bypassing the tunnel which worked!

I was aware that sometime in the past this could not have been achieavable. What changed? Is there any vpn client that does not allow route manipulation?

TLDR: By using GlobalProtect someone can bypass the firewall by adding static routes on their workstation. Can this be avoided?



What exactly is MoCA?

Got a new modem today and I've got it set up but apparently it's got something called moca. Never saw it on my old modem so what is it and should I enable it?



Hiw private FTP?

Hi! My friend asking, if he'll theoretically will take some files from FTP of his friend, and some of these files might be(he can't figure out) copyright protected in the country of receiver, can he get busted, or FTP is private and data transferred can't be seen by monitoring companies? Thanks in advance for all replies!



Why might I get an 169.254.x.x address, but still get internet through that?

I was testing some ethernet jacks today to see if they could access the internet. I ended up with a few that gave me a 169.254.x.x address, but still provided internet. I didn't have internet access prior to plugging in so I'm sure it wasn't the wifi adapter and I kept checking through ipconfig, but it kept the same address.

There were a few other jacks that gave the same IP and no internet access which is what I would expect. I'm also 99% sure these jacks are hooked up to a normal network switch. Maybe I have a misunderstanding about the usage of that address space?



SDWAN and firewall positioning

Hello, I read a silverpeak article whichs recommends to put the SDWAN device inbetween 2 virtual routers on a palo alto firewall essentially making the PAN device the externally facing device. Is there a reason I wouldn't just put the silverpeak on the edge? Is it not secure enough to be an edge device?

https://www.silver-peak.com/sites/default/files/UserDocuments/PAN-Deploy-TopNav/content/edgeconnect_topics/service_chaining_to_an_edgeconnect_branch.htm



Watch guard April fools joke

Do people really think poorly of watchguard? I don’t know the most about firewalls and my company uses one.

Edit: disclaimer I did not setup this network, I am a junior tech here.



Cisco ASA 5500 LDAPS issue

I am new to Cisco, we used to have a Sonicwall. The problem is the anyconnect VPN, users cannot change their AD passwords through the VPN software. We have 50 plus users that never connect directly to the office and this is the only way for them to change their network passwords short of calling us to do so. Our old firewall did this, all you had to do was install the CA certificate from the AD server in the Firewall and enable TLS. I used to do all of the Firewall support, we now have outsourced the firewall support and they can't get this to work. They have the certificate installed on the ASA and have enabled use LDAP over SSL and it doesn't work. My AD server has this in the logs "The token supplied to the function is invalid ". To me that seems to mean the certificate is either not installed correctly or the Cisco is not using it. Any ideas on what we could be missing? My google searches have yielded no helpful results other than what we already have tried, and some others require a Cisco login with rights to access those articles.



ARP question

Hi guys,

today in my computer networking class, our professor asked the following question:

A router is connected to 2 different switches, each of them managing different networks. If the router has two ARP modules, each of them with its own ARP table. Is it posible that the same MAC address appears in both tables?

Somebody answered yes, but I didn't hear properly her argument and I couldn't ask after the class directly to the professor.

The reason would be that both tables are independent for each network?

Thanks is advance.



Can I force Windows to connect to a specific WAP?

I'm troubleshooting an intermittent wireless connectivity issue and think the issue is that 1 of the 70 WAPs is (for whatever reason) unable to pass traffic on to the rest of the network. The issue only affects one area of the building. I'd like to test my theory by connecting to each of the WAPs in the area and send pings out to the default gateway, but I can't find a way to force windows to connect to a specific WAP. It just connects to the one with the strongest signal. I would just wait for the issue to happen again, but it happens so infrequently and unpredictably that it could be a while. Any suggestions?

I should also mention that these are Aruba WAPs, there is no wireless controller, I don't have credentials for the WAPs, and I don't have a list of IPs assigned to the WAPs. I know I know, not my network, just happen to be the closest guy geographically to my former employer's newest client.



Local printer in events industry

Hi everyone.

I work in the event sector putting printers out for conferences among other things.

I tend to put out a printer connected to a switch so that a few PCs in an area can print to it.

However it's becoming more often that the PCs that they want to print to are on their own business VPN

So plugging up it would go

1 - Cable from venue to unmanaged switch

2 - Cables from switch to PCs

3 - Cable from switch to Printer

So when I set the printer to DHCP it gets the IP address from the venue (obviously).

And obviously their PCs get a DHCP address from the venue

But when they turn on their VPN and tunnel back to their offices, it doesn't talk to the local network any more.

The obvious way around it (to me) is to everytime they want to print they have to disconnect from their VPN to print locally but that isn't very efficient.

Is there a way to route the printer packets before it gets to the vpn, to go to the local network, rather than to the vpn?

Thanks in advance!



Targeting Cisco QoS over multiple remote links on AT&T Switched Ethernet Fiber

I'm working on creating/cleaning QoS policies for voice at my place of work but have run into a question on how to best accomplish what I'm trying to do. First off, we have about a dozen remote locations that are all connected via AT&T utilizing their Switched Ethernet Fiber product (Layer 2 connectivity). AT&T has a Ciena at our HQ and all remote locations. Most remote locations are connected with a 50Mbit link, some of the smaller locations at 10Mbit. Our link at the HQ is a 500Mbit link. I'm modeling after Cisco's AutoQoS. Normally I'd leave in the AutoQoS entries which classifies voice and control correctly, and provides 33% and 5% bandwidth respectively. But since I'm sending data over one single higher-bandwidth link at the HQ, these default rules do not work as we never hit the 500Mbit bandwidth statement, so QoS never is triggered. However, we are saturating some of the remote 50Mbit links at times which has generated complaints of voice not working properly.

I'm looking for a good way to set up QoS most effectively on the HQ router and though't I'd ask the hive mind. Right now my thought was to create 3 class maps per location that match-all on network ACLs and data class (voice, control, data) - following the Cisco AutoQoS. Then I'd have one big policy map that contains all 36 (12x3) classes with appropriate bandwidth statements. That won't work though as I mentioned earlier that we never hit the 500Mbit on the HQ router.

How can I get the one AT&T facing interface on our HQ router to recognize that traffic heading to one subnet should be accounted for separately as a lower-bandwidth link? For example, if traffic heading to 192.168.78.0/24 has surpassed the 50Mbit, start policing or shaping.

For good measure, here is a chunk of how I originally was thinking of setting things up:

class-map match-all Loc3Voice match access-group name Loc3VoiceSubnet match class-map voice class-map match-all Loc3Control match access-group name Loc3VoiceSubnet match class-map control class-map match-all Loc3Default match access-group name Loc3DataSubnets !Total BW to Loc3 = 50Mbit / 51200kbps policy-map AllRemotes class Loc3Voice bandwidth 16000 class Loc3Control bandwitdh 5000 class default fair-queue ... Repeat above 3 classes for all other locations 


How would you explain the meaning of an API to a network engineer?

Hi I am a developer and I have a friend who's a network engineer. Recently their company started using these new SD-WAN devices. As you all probably know, most of these devices expose RESTful web services. So the thing is that my friend's pretty old school and is struggling with understanding what an API is. I tried my best to explain it but it just wouldn't make any sense to him.

You y'all know any way in which I can help him understand the concept better?

I am not aware of what devices they use exactly.



1310nm vs 1550 nm

Im currently designing a dark fibre network, and am a bit confused.

What difference does 1310nm make vs 1550nm

Edit: it’s a 25km link



Network monitoring with raspberry pi

Hi, Do you know a program/distribution to monitoring network, collect logs and then show this logs on diagrams. It be good, if this can monitoring on WiFi and RJ45.

Thanks



Top 3 reasons WatchGuard firewalls are the best firewalls

  1. They are red (like a Ferrari, voooomm voomm)
  2. Users are respected as individuals. They are not just a number in the system, but a consumed per-user license (which is stuck at 50, and will require a reboot to clear - and hey there's never been more than 15 users onsite)
  3. They can never be replaced - new firewalls simply don't have a small display for monitoring


Is there any way to automate IPplan?

So the place I work uses IPplan for IP address management. I was wondering if there are any APIs available to automate the process of reserving an IP address and so on. Sadly they don't use DHCP.

Thanks guys!



Advice on a Layer 1 switch

Hello.

We have a lab for the network equipment and we need an L1 switch to automate the L1 connectivity between the devices. I've started googling the products and realised there's lots of them. Can you guys give me an advice on what companies/models to look at and what features to compare? Also, what is the usual approximate price for that kind of equipment?

Thanks!



Question regarding VPN

I have no experience using VNPs, however, I got curious about the American version of Netflix since it seems to offer A LOT more content than the one in my European country. My father currently lives in the US,and I was wondering if there is any way for me to use his IP as a VPN and from there access the content that is region locked?

I know Netflix has blocked a lot of the well known VPN services, therefore my question.



HP IMC Configuration Backup of Fortigate Firewalls (Or any other vendor for that matter)

Hi!

Has anyone got experience with this?
I'm new to the company. Configuration backup is already running on HPE and Juniper(Junos) switches and routers. So i don't know the basics of adding new devices to config backup.

As far as i can tell, the IMC gets the information of the device it needs, through the SNMP MIBs, that you need to import. Can anyone confirm this?
If correct, has anyone successfully imported the Fortigate MIBS, thereby gaining access to the configuration management tab, including config backup?

If i cant successfully get the MIBs to work, is there a way to make an custom SSH script in IMC to make it do the config backup?

Any pointers would be greatly appreaciated.



Sunday, March 31, 2019

Is Nornir Idempotent

I want to create an automation script using Nornir to update the vlan configuration on device interfaces. I want to have a version controlled file with something like:

int gig1/1:vlan10

int gig1/2:vlan10

Then when someone changes the file like to say int git1/2:vlan20 and successfully merges the file with a production branch of the file the config is implemented idempotently (So vlan1/1 is not affected even though its in the file that the script is being run against).

Can nornir do this? Easily?



Triangulating Wireless Access Points with Pings

Do you guys think it would be feasible to ping an access point while walking around in order to triangulate it's location?



Switching the WAN connection from ISP

So a parent company of a small shipping company wants to send us some black VPN box (ANIRA) and insists that it sits directly connected to the ISP and not behind the company Fortigate. They claim having sNAT both directions with a public IP is not good enough.

In our country we have an ISP and an infrastructure provider. These are 2 separate entities. infrastructure provider supplies the hardware (Alcatel fiber/Ethernet switch of some sorts) and the fiber line (p2p) going to the ISP, which in turns provides the public addressing and a connection to the Internet.

I talked to the ISP and they have no issue taking a /30 junk of an already routed range I have and letting me use that for this VPN device (network, endpoint, gateway, broadcast addresses). The infrastructure supplier is giving me a hard time though saying that they won't just make Ethernet port 2 switched with the port 1 (that porvides the connection to the ISP already) so far as saying we have to pay for another a dedicated connection to the ISP.

TL;DR: can i a plunk a switch at the WAN connection (port 1 from the infrastructure's Alcatel switch) and talk to the ISP to do the routing/gateway configuration skipping the infrastructure provider's involvement all together?



Inexplicable Network Problem

This problem has had me wanting to pull my hair out for days, so here goes.

First, let me describe my network set up in order to make this a bit more straight forward. We have two buildings on our property separated by a drive way. One of them acts as an office, one is the place we sleep. The office is where our Google Fiber comes in, and is also where our modem is housed. We have a 155 foot Cat6 line that runs from the modem, across the driveway, and into our house which connects directly into a Linksys dual band wireless router. There are 4 Ethernet ports in the basement of our house that are directly connected to this Linksys router as well.

So here is our issue. We have a variety of wireless devices and wired devices on our home network, but only some of them properly connect to the internet. The devices that don’t connect properly return a “IP address could not be obtained” error.

I can not figure out for the life of me what is the issue.

DHCP is turned on on both the modem and on the Linksys router. Does this matter? What other settings could cause this problem?

I was on the phone with the Linksys people for two hours troubleshooting to no avail.

If there are anymore questions you need answered, ask away! I am really really not having a good week because of this bullshit internet.

I should also note that we have had this same issue on 3 different routers, and the Google modem was replaced 4 days ago.



Redundancy Help

Hi

Thank you for reading

We have a three main sections currently of our network, and only have one location.

  1. Inbound connections- web, web services, ftp, etc
  2. Outbound connections- user connections, we have many departments come use basic internet and some use VPN to connect to certain resources, these vpns are not our resources (customers vpn to their network)
  3. Phone system- cloud based

We have three companies supply us fiber pipes for internet connections. Currently we only use one for all inbound, outbound and phone system. The phone system has an automated switching feature when the main pipe goes down to another available pipe.

We currently do not use the other two pipes for inbound and outbound connections. If the main pipe goes down, our inbound and outbound are offline.

We were pitched velocloud SDWan as a solve all solution. 100% uptime for inbound connections, outbound and phone system to ride this velocloud SDwan. Seems they said it will handle anything including all of our inbound redundancy. From whet they said, all of our traffic will go to their cloud and route from their. My concern is latency and route issues and if they have a hiccup then we are down until they resolve. All of our pipes would be managed by them at the edge.

I was looking at our own IP subnet and doing BGP, but they are convincing everyone that SDwan is the future and everyone is switching. I personally can see outbound with SDwan as a redundancy and but keep inbound and use BGP as we would have more control over routes and changes.

Let me know your thoughts or any possible solutions I haven't mentioned.



How to capture all wifi traffic

I am trying to monitor and capture traffic come across A Wi-Fi network( that I own) to do some troubleshooting on some Wifi only non open source IOT devices I have. I am knowledgeable with Wireshark however I am unable to capture any Wi-Fi packets that are not addressed to the capturing Workstation that is on the same Wi-Fi network has the devices in question. From what I understand this is because I am on Windows and Windows does not allow you to activate monitor mode which would enable you to listen for all Wi-Fi packets not just your workstation's is there a free work around that can get around this or will I have to just set up a linux vm on said Workstation? and will that even properly pass the network's traffic through?



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Viasat modem and NAT trouble

I tried to help a friend get his businesses network back online today. Their office moved and they were too far away for the two normal carriers here. They went with Viasat who provided a modem that won’t let us configure a dang thing about it. I called support who claimed no settings can be changed on it. He couldn’t get internet into his router and I told him about the double NAT. It’s probably not a good idea to let a $40 device run everything for their network. They have commercial switch and routing hardware. Is there any kind of clever way to use a VRF or static route so that the normal core router can route? Is this a fools errand? Should he ditch Viasat at all costs?



WiFi mesh in uk - which is the best?

I did a quick search across the group, but didn’t get a good answer. Simple question - in the UK which is the best mesh equipment for a large (5 bedroom and large garden 15 meters) house with the BT access at the front of the house - currently using sky with s TP-Link archer 3000 WiFi router - frequent drop outs and blind spots. Thank you



Unexplained Packet Loss (x-post r/Fortinet)

Hey, all! I am running out of things to check and thought I would give this a try to see if anyone could think of some other things I could try to track down my issue.

Problem:

At random times, on random days, my ends users at HQ will loose connectivity to multiple resources in Azure. Some of the traffic is sent IPSEC to a Fortigate-VM in Azure, the rest is Bomgar (also in Azure) via https over internet. All other traffic on the network, including internet, appears to be unphased and with no packet loss. Failures last 10-45 minutes at a time. During this time, neither FG recognizes a tunnel failure. Users connected to Bomgar have their sessions terminated and are unable to re-connect until failure clears.

Users outside the HQ building can access the resources with no issue mostly ruling out the Azure side of things.

My Network:

On HQ Side-

Access Layer (Cisco) -> Core (Cisco) -> Fortigate 100D (FW 6.0.4) -> Internet

On Azure side -

Servers -> Fortigate-VM (FW 6.0.4) -> Internet

Completed Troubleshooting Steps:

- Confirmed IPSEC configurations match on both sides of tunnel

- Set traffic shapers on HQ side (I see dropped packets on the FG side now, however not on the policy for the Azure resources)

- Upgraded 100D to 6.0.4 (also had issue on older FW)

- Confirmed with service provider that I am not over utilizing circuit

- My help desk onsite runs pings to multiple endpoints to see what traffic is loosing packets and confirms there is only loss on traffic to anything living in Azure

- Called FG support but there isn't much they can do since we are unable to replicate the issue

Has anyone else experienced something similar?



Help identifying this fiber optic connector?

We have a fiber service coming in, which then goes to a Huawei switch (S5300-10P-LI-AC0), and from there to the router.

I believe they're just using the Huawei switch as a media converter - there is a single fiber optic coming in to an SFP, then a single copper Ethernet cable that runs from there to the router.

I'm trying to identify the type of fiber connector this is?

https://i.imgur.com/eE2S0fd.jpg

https://i.imgur.com/poNwnqU.jpg

https://i.imgur.com/qrbi3jn.jpg

Does anybody know?

Secondly - the fiber comes in via a hole in the wall, and goes to this box:

https://i.imgur.com/5qDQlUp.jpg

We need to move the box to a different location - is there a safe way to disconnect the cable from the box, and reattach it afterwards?



** ANNOUNCEMENT: /r/networking is now secured by WatchGuard™ **

After much internal discussion, we are now migrating this subreddit to be secured by WatchGuard. This subreddit will be dedicated entirely for the design, deployment, and maintenance of your WatchGuard solutions. Now we know this won't be an easy change, but let's face it - WatchGuard makes award-winning solutions that are easy to deploy and manage, making enterprise-grade security accessible to any organization regardless of size or expertise.

We'll let other vendor posts on here until the end of the day, but starting tomorrow it will be all WatchGuard, all the time!



Juniper SFTP default directory

Does anyone know what is the default directory on a SRX where files are stored when using SFTP (if the directory is not specified when copying the file).



Using Grid Director Switch as normal switch?

Hi All,

Is it possible to use a Grid director Switch like the Voltaire Grid Director 4036 as a normal switch to connect servers and workstations together?

and What is the difference betwen a normal and a grid Director switch?



VRF Lite Question

I am working on a VRF Lite setup for a guest network at a branch office. I am unable to ping from the Branch VRF interface to the Edge or PA VRF interfaces.

ping vrf GUEST <IP of Edge VRF int>

I am seeing all of the routes in BGP for the VRF. Is this normal?

Network Map w/notes



CISCO RMA FIELD ENGINEER

Hello I work for a company that’s a Cisco shop. At times we need to RMA replacement routers to our customers or even request Cisco to dispatch a field engineer to our clients site to provide out of band access/swap hardware. How does one land a job like that, a Cisco Field Engineer?

Thank you.



fast convergence a multi-DMVPN clouds with multi-hub networks

hello all

i have 2 main sites (HUB)

and a bout 40 branches(Spokes) they are connected with multiple DMVPN clouds (3)

but when in a branch one link goes down i have to wait for NHRP to go down to switch to my second link it takes about 50 seconds to switch witch is a lot how can i fix this issue?



Network Automation - Keeping state

Hi folks,

I am trying to automate the process of creating VPN tunnels to AWS when a VPC is deployed. It's been very time consuming for me. Am thinking of the following structure:

* A page where the app teams will just input their info (like Account, VPC name, etc) - RBAC is not a problem, and there's a validation process in place.

* I have IPAM automation ready with Infoblox through their API - so this is solved too (or at least easily solvable, done it before)

* Am coming across this fundamental questions: how do I keep state (i.e. configuration state, you know like in Terraform?) of the routers and firewalls?

There are many ways of doing this, but it'd be nice if someone that's done something similar could chime in.

Anyone ever done something like this? What tools are you using? To what extent are you automating?



Network admin London

If that's you, and you know Windows server, message me.



Open Source Networking

Hi all,

Recently I've started exploring the world of open networking. I couldn't find any documentation on the following questions, so please forgive me if they're too obvious as I'm only making my first steps in this area...

1) I've read that the main advantage BIRD has over other BGP daemons is scalability. Are you aware of any published/publicly accessible benchmarks?

2) Does the network operating system (NOS) really matter, given that I run all routing/switching daemons separately? Does ONL, for example, have any advantages over Ubuntu, RHEL, or OpenSwitch?

3) As far as my exploration went into routing stacks, it seems that there is a variety of solutions - as long as you're using BGP only. The moment you start talking about more advanced features such as EVPN, advanced STP agents, MPLS, etc. your only option is FRR (or stitching a few other solutions). Is there any other solution that gives FRR a fare fight in all areas, or should I just focus on BGP mainly which will enrich my options list?

4) MCLAG (comparable to Cisco's vPC) - are you aware of any open source implementation? From what I saw on the internet, open source networking seems to be more concentrated around IP fabrics and therefore uses ECMP and not MCLAG for load sharing.

5) ONIE vs PXE - is there a good reason to use ONIE? If the whole point is to treat switches as servers, why not use a unified installation platform?

And finally - do you have any customer testimony/documentation/blog entries of people who have converted datacenters, WAN infrastructure or even LAN into open source?

Cheers.



Saturday, March 30, 2019

Automated Network Testing Framework

I read this great teaser post a few weeks ago...

https://packetpushers.net/exploring-robot-framework-for-automated-testing/

...and it got me scratching my chin about the possibilities of having automated network tests. The article references the robot framework...just wondering if anyone does this currently and any examples or references I could build on.



I have IP Static At & t u Verse (Sock5) for Sale, Expires in 2027 more info PM

No text found

Draft 802.11ax APs

Recently Cisco and Meraki have announced draft 802.11ax (WiFi 6) APs, the MR 45, MR55 and (Catalyst?!) 9115, 9117 APs.

My questions to everyone is, what's your experience deploying "pre-standard" APs? Is it worth it? Is it better sticking with tried and tested 802.11ac APs until the full 802.11ax standard is ratified or is there genuine benefit in jumping in feet first with this new gear?

For example, someone's deploying a brand new greenfield site next week, what's the best decision? No specific requirements, just want to know people's opinions.



Replacing an individual cable run in a bundle, Need Advice

I have about 30 workstations out of a 1000 that will not get a network connection. The remote networking people tell me the ports keep going into "err-disabled" mode after they're bounced. They say it's happening because a bad cable. I have replaced all cables, except the runs themselves. I have also replaced the desk/wall port. The only thing left is the cable run from the patch panel to the desk/wall port. These cables are bundled and some probably up to 250 - 300 feet. What is the best way to replace an individual cable in a bundle of them? Some go into the tiled ceiling, some go into the floor. Thanks for any and all help.



SonicWall FireWalls Education?

I've been working at a support desk for quite sometime and want to learn about the SonicWall firewalls since my company uses them for our various clients. Recently I was able to get handed a TZ 205w. While it's old itll probably be the best thing I can get my hands on. Where is a good place for me to learn the SonicWall GUI and stuff on firewalls in general?



Best way to connect 1 Main Branch and 5 Auxiliaries.

Hello! I’m fairly fresh to the I.T. networking realm (senior in high school) and wanted to ask on my current idea of creating a secure and functional network that would be put into place for a bank (educational project). I appreciate any advice given and fully expect to be wrong in some areas! The main branch has 6 departments with a total of 203 IoT devices in 100 machines, 100 phones, and 3 printers and the auxiliaries have 4 with a total of 42 IoT devices in 20 machines, 20 phones, and 2 printers. In doing this I’m also trying to allocate space for expandability but not at the price of security.
My current plan is to have it sub-netted by department with the main branch being a class B and the Auxiliaries class C. The class B is more difficult for me to determine as of now but for the class C I have it set as

192.168.1.0/26 (0-63) = tellers 192.168.1.64/26 (64-127) = New Account Reps And etc on to the next branch which becomes 192.168.2.0/26 (0-63)

Would a class B of 172.16.1.0/18 be acceptable for the main branch? The main thing I’m trying to keep intact here as well is the expandability of the network with good security as well.

ACL’s are my main plan to segregate the network and obviously shut down unused ports where needed.

Lastly I can’t figure out what would be a solid switch and router to use. L3 Switches perplex me because some say that they can be used as a router as well removing the need for one completely? Is this a legitimate enterprise practice? Sorry if the questions are very newbish and this maybe being a longer post but I sincerely appreciate any advice!



Possible Internet Issues

Hey guys,

I would like some advice,

Our current ISP is having issues which to me looks like route flapping if i do a traceroute from our router i get the following:

Hop 1: 1 host

Hop 2: 2 Hosts

Hop 3: 3 Hosts

Hop 4: 5 hosts

Hop 5: 3 hosts

Hop 6: 6 hosts

Hop 7: 4 Hosts including Final Destination in one of the hosts

Hop 8: 3 hosts no final Destination

Hop 9: 2 hosts including Final Destination

My thought around the current situation is that for some reason their core swtiching like possible BGP routing is fucked? i could be wrong

As when you do an MTR on the route surely there should only be 1 host for each hop as the route should be learnt?



Observium Alerts Device IP?

I work for a small WISP and we already have Observium monitoring our network ( I did not implement it). Currently our alerts only ID the devices using hostname, my boss wants the alerts to include the IPv4 address as well. So far I haven't been able to find anything in the Observium control panel, and google has not turned up any solutions either. Does anyone know if this is even possible?



Public network routed over private networks

Hello /r/networking!

I come to you today with a simple question that has been racking my brain:

Is it possible to route a public /24 network over a series of smaller /29 private networks?

Theoretically this setup would be done for a WISP via a handful of static routes, but I can't seem to answer my own question.



Physical-based ACLs?

Say I have two physically separate networks that share a common subnet and I wish for a management PC to be able to talk to both networks on layer 2 but not for the two networks to combine. There would be no duplicate IPs and the networks would still function if connected.

What I'm thinking is some form of ACL that permits traffic to and from physical ports 1 and 2, and 2 and 3, but not 1 and 3.

Any ideas? Am I missing something obvious?



How does a load-balancer handle too many connections, and how in case of websockets/SSE?

This isn't about whether one will ever need it. This is a general question, the answer of which I've been looking for as a curious CS grad.

Here's what I've learned from my research I have been doing for few days, after which I have by questions lined up.

PART 1 is about general load balancing with increasing number of connections

PART 2 is specific to persistent connections as websockets and Server-sent events

My concerns are in-particular to PART 2, so you can directly jump to that if you find it long.

PART 1 - general load balancing

Nginx is one of the many load-balancers available and is widely used. It can help in following ways:

- Small traffic, replicated servers for fault tolerance can be load balanced with servers referred by their IP address.

- Large traffic, multi-node/multi-server deployment where nginx handles the network requests and individual servers handle the CPU/DB operations.

However, there is a limitation on the number of connections which can be managed by the machine running the load balancer.

- RAM - this answer states that about 16GB RAM is required per million connections.

- Number of ports available - which can be handled by introducing virtual interfaces as the number of ports limit is 65535 per interface.

Still, this cannot handle large number of connections.

Another strategy is to have DNS based load-balancing which can region-wise distribute the traffic with the requirement of servers to be in sync and downtime as DNS cache update takes time.

Solutions like this one handle about a million clients on a single node, but I'm more concerned about a distributed system with enormous traffic.

What is the strategy services spanning multiple data-centers use to be available.?

PART 2 - for persistent connections

Persistent connections as SSE and websockets have redundant network operation on the load-balancer side as well as on the individual server. So I can think of two strategies

  1. Get entire traffic through the load balancer (however this seems to be redundant on part of network I/O on proxy and server).
  2. Pick a server for init request. The server returns it's canonical URL (say www1.domain.co) and then the client connects directly to the server, without nginx in between. This avoids duplicate network ops but removes location transparency.

How would you recommend to solve this problem?



Limiting ingress traffic rate ?

The association I work for passed a traffic contract with an ISP that has the usual burst limits, do you guys have a bandwith limitation in place for ingress traffic in your infrastructure ?



Permissions issue with RADIUS authentication on HPE 1920-24G-PoE switch

I've set up an HPE 1920-24G-PoE switch (JG926A) to authenticate against a Windows NPS server. Authentication is working fine, but authenticated users do not have manager permissions. I've set up a vendor-specific attribute as follows:

Vendor Code: 25506

Vendor-assigned attribute number: 29

Attribute format: Decimal

Attribute value: 3

Essentially the same NPS policy (aside from this vendor-specific attribute) works perfectly on my Procurve 26XX switches with aaa authentication login privilege-mode set.

Any ideas what's going on?



Guest VPN Networks

I apologise in advance if this isn’t the right sub for this. I’m completely new to networking bar replacing my ISP router with a separate modem and Ubiquiti Amplifi mesh setup so please excuse any misinformation or discrepancies in my post.

I’d planned an upgrade to the Ubiquiti SSG, gateway, switch, cloud controller and 2 nano AP’s however after trying to research my question online I don’t think these give me the functionality I’m looking for or whether it’s even possible.

I’ve done a little reading on VPN guest networks and can see in routers support DD-WRT that you can indeed have an ISP connection then a separate VPN connection.

Building in this, is this possible on the Ubiquiti platform?

Is there any home setup I could get that would allow numerous VPN guest networks? Ideally I’d like to have my ISP connection, a VPN connection based in the UK an another in the US and another based in Asia. However I’d be happy giving up the ISP / Asia connection and just having the 2 VPN connections if that’s possible?

Any help / purchasing advice is welcome. Based in the UK if that makes a difference.

I’m aware I could dedicate a VPN connection to a specific device but it would be easier if I wanted to change location to just connect to another network instead of going into each device to change the location, something very annoying on TV’s.



SMTP simple implementation guide

Hello everyone, I'm trying to implement SMTP protocol in java, a simple implementation. I've looked up some repos on github but all I've found were very large projects.

I wonder if you can guide me on what should I do? like a book suggestion or an online course? I want to be able to demonstrate my understanding of the protocol by writing a simple client and server that run on a local machine and send emails to each other.

thanks.



Dynamic vlan assignment with radius

Dear All!

How can i do this?

Radius with eap-tls so i create certificates for devices. But i would like that the switch automatically configure the proper predefined untagged vlan on the port for the device: for example: VOiP phones should be in vlan22 Printers in 23 Clients in 24

I can administer the macs i would connect to the network. For example create a group of mac address (or part of the mac) and i say this should be in the vlan 23 then i upload the precreated certificate onto the device and i connect to a switchport.

Can i do it with MS NPS? Or please suggest a solution to me.

Thanks



R850 mobile Hotspot looking to swap Sprint sim into beefier "modem/router" using band 41

I am on the Sprint network in a rural area and recently received a magic box gen 3. On the Pixel 2XL I am getting speeds of 70+ down. However on the R850 I am pulling 30 tops. I would like to move away from the R850 hotspot and dedicate the same sim card to a high powered modem/router. I am having trouble finding one that isn't priced above $200.

Are there any modems/routers that anyone has used to upgrade the reception of band 41?



Need Help with UniFi and FIOS

So, I just bought a new home and I wanted to start a server room. The first items I purchased were UniFi gateway, 24 port switch and a surge protector.

It took me a while to get the internet working but I did it by copying what I read on Google which was OTS > WAN on gateway > WAN2/LAN2 to FIOS model/router and Gateway LAN1 to port 1 of the 24 UniFi network switch.

Internet works great when connected and I was even able to setup my Google Mesh network. However, I’m noticing hiccups when trying to setup certain things, the voice commands no longer works on my FIOS cable (it says not available) and apps like Amazon video opens perfectly but Netflix hangs (can’t sure if maybe that’s TV suddenly but voice commands on cable don’t work either)

Also while internet is fine, the globe is red on the FIOS modem/router.

Did I connect something wrong? The gateway wouldn’t connect to the intent unless I configured it this way. Oh and yeah I did download the software, update the divided, adopted them and all that stuff via the UniFi software.



Friday, March 29, 2019

Stand alone access points

I was thinking of building a navigation system for a building. Obviously GPS cannot be a solution for such small distances. I was thinking maybe if I could place some stand alone access points which could be detected by my app to determine the present location of the person and help them get to a specific place maybe downstairs or on the right or left wing of the building. Is there a solution to this? Maybe a set of Bluetooth or other wireless APs which could be detected?

I couldn't manage to find a standalone AP. All links directed me to be using Raspberries but it would be costly to set up dozens of them. A few links on further information or direct links to products is what I'm basically looking for. We are not a huge organization and so cost really does matter. If an AP has a range of 50 meters, I'd need around 40 of them. So please consider the cost it would take.



Rsa keys

Do rsa keys require internet connection or can they ve deployed on an airgapped intranet



Stuck in a rut

So today I got rejected for an offer in a mid-size company as a network consultant. I am currently working in a large ISP as a network analyst/consultant and I feel like the progress is super slow, all the nice projects are given to the same people, mostly CCIE level people or just manager's ass-lickers. I'm not sure what should I do. Look for a smaller company and keep learning on my own, or stay there at the ISP because of the good benefits and salary.



Cellular emulation routing to internal network

So we all know about "stingray" type devices that are essentially man in the middle cell phone towers that attempt to get clients to connect so they can spy on them while relaying traffic through to a real tower. I read that these have to be registered with the carrier who owns the end tower in the US now in order to be legal.

I'm curious though, are there any legal issues with running a cell phone site that doesn't connect to any carriers?

Assuming that is legal, is it technically possible to run your own cell phone site that also routes traffic through an internal network including out to the internet?

There are two goals I have. One would be to get cell phones to connect to this site and then prevent them from routing out to the internet. Essentially a "jammer" that isn't actually interfering with anything and is following RF laws and protocols. The signal would be so low that only local cell phones would get a strong signal and therefore attempt connecting, in theory. I don't know how most clients deal with this, is an "on network" cell tower with low signal still favored over a much higher signal that is "off network" and potentially even unknown in terms of the operator?

The second goal is to take this idea further and still allow some internet or other network access while not allowing many other services like texting, certain sites like Facebook, etc.

How legal are these concepts and how technically challenging would it be to achieve for LTE as an example?

Is the main obstacle going to be legal transmission on these frequencies? I assume cell repeaters like you can buy from carriers are just amplifiers but these still transmit on the same frequency right? How is this legal, is there some amplification loophole?



Working with EVC and Routed Pseudowire | Unable to to reach from site A to B?

Hi, Would like to ask if why I cannot reach the site B SVI from A though I can learn its mac address completely?

Simple topology:

Site A(TAG 10) --------PE1(match10)------XCONNECT------PE2-----SW(ASR920)-------SITEB(SVI TAG 10)

https://imgur.com/4jfGtiZ -> diagram

From Site A, i can reach the Pe1 BVI and SW BDI (bidirectional) but Site B ip cant be reach from all test IP though mac address can be learn.

PE1 (Routed pweudowire to test the circuit): interface BVI99 vrf test ipv4 address 10.9.9.1 255.255.255.248 bridge group BGI10 bridge-domain BDI10 interface GigE0/2 neighbor 2.2.2.2 pw-id 1111 routed interface BVI10 

PE2 interface GigabitEthernet0/0.10 encapsulation dot1Q 941 xconnect 1.1.1.1 1111 encapsulation mpls mtu 1500 

SW port facing PE2 int g0/2 service instance trunk 100 ethernet encapsulation dot1q 2,941 rewrite ingress tag pop 1 symmetric bridge-domain from-encapsulation SW port facing Site B interface GigabitEthernet0/1 service instance 941 ethernet encapsulation default 

Only issue pinging site B 10.9.9.4

Thank you



CCNA Test Prep

What is a good Practice Exam for the CCNA cert? I have the Pearson Test Prep app, but I don't think it is particularly that good...



major fortnite packet loss. need help.

Im getting some major packet loss in just fortnite, everything else is good Wifi. I use ethernet but this happened without ethernet too. this all started at the beginning of season 8. I`m pretty sure the issue is Fortnite itself, and I`m not the only person with this exact 30 packet loss at least twice a minute. very annoying. Its unplayable and as a competitive player it does effect me largely. I have a video of it if you want to see I can dm.

I have tried everything ive found online, except get a new router. reply asking for more details if needed. thanks.

already posted in tech support 6 times got barely any responses. I`m tired of this internet issue and I need this shit fixed for future tournaments.



BGP Router + Subnetting

Hi all,

I have a /24 that I am announcing with Vultr. I am using BIRD on a Vultr instance to route the entire /24 to my instance.

I can easily add IP's from that prefix to my Vultr instance and ping them remotely.

Now, if I wanted to begin subnetting my /24 into smaller slices, what is the recommend method to do so on Ubuntu 16.04? For instance, if I wanted a /29 from that /24 I would need a network IP, gateway and broadcast IP in that /29. What is the proper methodology to do assign this on Ubuntu or even pfSense?

Thanks!



Learning Cisco IOS

Hi everyone,

I'm wondering if anyone has any resources for learning more about IOS. Not the networking aspect, but the OS and facilities aspect, like backing up your config, loading a config from a TFT server, etc. We barely touched these topics in my three years of college and I would like to have a better idea of what there is in IOS outside of the network configuration stuff.



remote hands?

We're running into more need for a consistent national (US) and sometimes international remote hands partner for SD-WAN endpoint placement, managed wifi/switch installs, MPLS and DIA CPE, demarc extensions, etc.

Back in the day I used to contract for https://www.fs24-7ltd.com/ but I don't know what this landscape looks like nowadays. I've reached out to the top handful of "remote hands" google searches as well, but I'm wondering if anyone here would be willing to share their experiences.



Is this connection possible?

https://ift.tt/2CM2tIz

Problem with Google maps after recent updates for Android based tablets?

Our company uses android tablets to track driver activity. Recently customers have been calling about navigation accuracy issues through 3rd party Maps app we use in our software. When this happens, the blue dot is miles from where the driver currently is and it keeps saying "searching for gps". Uninstalling latest updates to Maps sometimes corrects this but not always.



connecting server with 10Gbps CNA to tape with 8Gbps fiber Chanel

can anyone tell me if this direct connection is supported.

server has 10Gbps CNA network card and the tape drive supports up to 8Gbps fiber channel.

Can i make a direct connection from server to tape drive using SFP+ transceivers in the server and OM1 or OM2 optical patch cable?



Source locked port forwarding on Cisco asa 5506-x. What I’ve tried and hasn’t worked.

Hi all,

I have minimal experience with Cisco outside or reflashing APs and configuring them. Recently I landed a client and until we get them into a better firewall I have to administer their current one a Cisco asa-5506-x. It doesn’t have adsm enable and I can’t seem to find the image to enable it.

Anyways, I’ve scoured the net trying to find out to do a port forward that source locks to our office. I’ll list the players and someone can hopefully help I’m regards to how to make it work and I’ll list what I’ve done.

Our wan ip (not actual) 777.777.7.7 Their external IP 555.555.5.5 Internal server ip to RDP to 192.168.1.1 Desired external facing port 33891 Redirected port 3389

I’ve tried the following command with no luck

Access-list inbound extended permit tcp host 777.777.7.7 host 555.555.5.5 eq 33891

Then I tried the following command in config mode and exec mode and got incorrect parameters with the highlight carrot

Static (inside,outside) static (inside,outside) tcp interface 33891 192.168.1.1 3389 netmask 255.255.255

I entered that as a separate command and got the error.

Is there anyone out there who can help?

Thanks a million



This might be a dumb question, but I need a double check.

Say you have three separate layer 2 domains (Availability Zone 1, 2, and 3) with VLANs 0, 10, 20, and 30 in use on them. You have linux nodes in each domain tagging all packets, i.g. eth0 = VLAN 0, bond0 (eth1, eth2), and bond0.10, bond0.20, and bond0.30. The nodes in the three domains share the same IP address subnets, i.g. VLAN 0 = 10.0.0.0/24, VLAN 10 = 10.0.1.0/24, VLAN 20 = 10.0.2.0/24, and VLAN 30 = 10.0.3.0/24.

1) How do you send packets to one of the nodes in the other domain? Since they all share common subnets, how will Linux know to route packets through a gateway interface to the other domains? Furthermore, the ARP table for one domain won't have MAC addresses for IPs in the other domain... they won't share broadcast domains. So they can't talk to each other right?

2) If you are able to send packets to the nodes in the other domains, do the VLAN headers get stripped when they cross the gateway?

If I understand things correctly, we need VPLS to connect the three separate layer 2 domains into a single broadcast domain. Yes? Are there other ways, i.g. GRE or MPLS tunnels?, to join these into a single broadcast domain?



VPN Connection to AWS from Palo Alto

Looking for help from someone who has successfully got a site-to-site working with a PA firewall to AWS. I have been trying to get this to work for the better part of the week and just cannot get it working.

I can get the tunnel up but the traffic is not passing. I cannot ping the AWS server from corp network and from AWS cannot ping the corp network.



Cisco Nexus multilayer switches: Difference between checkpoints and exporting the running-config?

Cisco Nexus switches have a checkpoint feature that does not exist in CatOS and IOS to my knowledge... what's the difference between saving a checkpoint and exporting the running-config? When would I do one versus the other?

Probably it's best both save a checkpoint, and export the running config before making any changes you would think?



SDWAN input for basic requirements

We have ~10 branches behind cookie-cutter Cisco ISRs on IPsec to our hub PA appliance.

These are small offices of no more than 15 users with minimal traffic loads. Mostly HTTPS and SMB.

I don't need to turn 4 commodity links into an MPLS-quality connection at each site. I don't need sub-second failover or WAN optimization (strictly speaking--I could probably benefit from it, but it's not a hard requirement).

My main goal is to simplify deployment and management.

Also interested in adding link failover/diversity (e.g., LTE) where it would be cost-effective. Anything else is nice-to-have but not required.

I hear good things about Silverpeak and Cradlepoint, but I'm not sure if those represent deployments that need more features and horsepower than our use-case.

Should I consider some vendors over others, given our requirements?



F5 issuing TCP resets on high latency connection attempts

I have a standard VS profile that is an LB for a pool of workers inside a Kubernetes ingress point.

SSL terminations happen in K8S so this VS literally just listens on 443 and round robins to a pool of 5 workers.

Test connections to a minio server inside K8S work fine from one source test Mikrotik but not the other. Both MTKs sit in the same test datacenter and follow the exact path across the WAN to the VS. The only difference between the two is that the failing (connection timing out) test modem sits behind a device that artificially adds latency to the connection to simulate satellite connectivity.

TCP dumps on workers and F5 show the F5 is issuing TCP resets to this source host.

I'm not familiar enough with F5s to know exactly what needs to be tweaked to make this VS more tolerant to high latency connections. No http profile applied to this VS.

Any help would be appreciated.



Gigabit to Gigabit Per Second

Can someone tell me how this conversion works? I was reviewing alarm thresholds set by our network admin in PRTG and I saw his calculation for Gigabit per second to Kilobit per second was strange. It began to make me question my understanding of data rate and network speed.

He pointed me to this website http://endmemo.com/convert/data%20transfer.php and proved his point through this calculator. Of course, I still was not convinced since the conversion did not explain why/how it was calculated.

The website's result for a ethernet (10Gb) are as follows:

ethernet (gigabit): 10

gigabit/second (Gbps): 9.313226

kilobit/second (Kbps): 9,765,625

Please tell me im not crazy to think that a 10Gb circuit that our ISP is providing = 10Gbps = 10,000,000Kbps



Looking for opinions on switch monitoring

I'm hitting the tail end of rolling out a bunch of new Cisco SG250s and integrating some 2960s at 15 or so sites. We've also rolled out wired 802.1x. I'm in the process of re-thinking my monitoring, which has pretty much consisted of a few SNMP traps and ping alarms. I was wondering if I could get opinions on what you folks are using.

Basically I'm just looking to monitor changes on ports, unexpected MACs etc. We've had trouble with folks trying to plug in random junk in the past.

I'm currently evaluating ManageEngine OpUtils and have also evaluated PRTG. I'm not a huge fan of PRTG's per-sensor licensing model and visual aspect. Oputils seems to be more what I'm looking for. However I'm just playing pretend network admin since my company doesn't have one yet. I'd be grateful for any more seasoned opinions.



Route over IPSEC

Hi,

See this diagram: https://imgur.com/0xaL42N

I am not very good regarding IPSEC and routing between IPSEC.

The goal here is to eliminate the two IPSEC tunnels going to 10.0.51.0 and the 10.0.0.0 networks directly from the .168 network. We want to go through the .101 network and be routed from there to 10.0.0.0. The tunnels are all up already, except the .168 talk directly to 10.0.51.0 and 10.0.0.0.

I have not had any good experience with trying to route traffic over IPSEC that is coming from another IPSEC tunnel.

You guys have any good ideas how?

I have another idea to implement a IPVPN connection from .168 to .101 site instead. That way there will be no IPSEC to route over, just normal routing.

Thoughs, opinions?



ISAKMP ignoring interface MTU

Yesterday I was having trouble turning up an IPSec connection between R1 and R4 in this topology.

The issue was the certificate sent by R1 produced a ~2200 byte datagram fragmented into two packets of 1500 bytes and 700 bytes.

R3 had a bogus MTU[1] configured on its upstream Ethernet interface, was dropping "oversize" frames on ingress.

Eventually I managed to get R3's interface reconfigured, but before that was possible I decided to test by setting ip mtu 1400 on the relevant interfaces of R1 (IOS-XE 16.6.2) and R4 (IOS 15.6M). I expected this configuration to cause both of those routers to fragment their traffic differently (1400 bytes and 800 bytes), and the certificate exchange to survive the trip through R3.

That is not the behavior I observed. A sniffer near R2 still showed 1500 byte packets originated by both R1 and R4 after the change to their interface MTU.

Am I missing something obvious about the ip mtu interface directive and control plane traffic?

[1] Please don't bicker with me about MTU vs. MRU at R3. The device in question only has one lever and it's labeled MTU. Curiously, R3 had no problem transmitting R4's large packets, even with the small MTU configured. The MTU setting seemed to only make a difference in the receive direction. <shrug>



Cisco ASA 5505 died and I could use your help figuring out how we got the network back up.

This happened on Wednesday night and while everything is now back up and running, I’m going to have to explain why it took so long to restore and I genuinely don’t have the answers. The network guy is on vacation, so I had to step in and help. I used to call myself a network person, but I left that role about 10 years ago. Anyway, here’s what I know.

  1. We had a power surge which caused the firewall to go down, when power came back up none of the IPSec tunnels would reestablish. The debug gave me a “no proposal chosen” error. I examined the crypto statements and all the proposals were named correctly with AES256, 3DES, etc however they were all showing DES. I tried to change the proposal statements but it would not take. I got an error that said something along the lines of needing certificates. The IOS was asa921.ke version 9.2(1). This made me think that version of IOS didn’t have 3DES available, but it was working just fine several hours before this.

  2. Replaced the firewall with another 5505, running asa843.ke and got the crypto maps configured correctly, but the routing -while configured- wouldn’t show in the route tables. We couldn’t ping and errors indicated no established route.

  3. Instead of copy and pasting sections of the configurations we tried tftp using the ASDM. That worked; routes were there, crypto was there, the network came back up.

I have no idea why the VPNs were up and running before the outage if the IOS couldn’t support AES256 or needed certificates.

What’s different between copy/pasting text files v. tftp? Why would this method of moving the configuration work but copy/paste wouldn’t?

Any insight would be greatly appreciated!



Zero-Trust or Micro-Seg with PAN?

If I chose to use PAN products for my campus zero-trus or micro-seg, would it still be the perimeter-edge based filtering? What I mean is that I would implement a big PAN firewall and route every packet from user to the PAN for inspection and routing?



Teach me spanning tree

What I want to accomplish I believe should be simple.

I have 3 switches. 2 switches both currently trunk to an aggregate fiber switch. This fiber switch is currently the only way the other 2 switches can communicate between each other. I want to run 10G fiber between the switches, and only allow a couple VLANs to pass traffic through that 10G trunk instead of hauling all the way to the fiber aggregate switch and back down.

RSTP will simply nuke the other connection as soon as I link that fiber betwen the two switches....functioning as it should obviously. How do I configure it to play nice?