Saturday, July 13, 2019

Ethernet specs / separate VOIP network for small tech company?

Hi,

We’re looking at moving to a new office. As part of that effort we are re-cabling. We intend to use VOIP with a hosted provider. The phones and switches we’ve purchased are gigabit.

What Ethernet spec would you recommend? Right now we won’t be setup for more than 1 GB Ethernet but I’m wondering if it’s worth investing in Cat6A for the future?

Would you run a separate VOIP network? It would cost thousands more to cable for that and it seems like overkill but I don’t know what the current thinking is on that.

Thanks!



Eve-NG labs

I just found Eve-NG and threw it on my ESXi server. I like the idea that I can link nodes to a picture since I"m a network engineer and can throw the visio's down and it will be so much easier to lab. I also like what I might see on their forums but for some reason I have not been able to get the activation to any of my email addresses and no one contacted me back when emailing them :(....maybe they read this forum?

Anyone have labs they build with EVE-NG they would like to share? I use Cisco, don't know or have other images for other technologies.



Is there a L2 Host Isolation equivalent for non wireless networks?

Howdy All!

We use Ruckus for our clients and enable the host isolation on all networks we deploy, is there anything that's similar for non wireless networks? We already carve our networks into appropriate vLAN's (i.e dept based, printers, servers, vm's, etc) but I can see the benefits of having this implemented to help counter the spread of malware/crypto intra-vlan.

Any ideas or pointers?



If the default vlan on juniper is untagged, then wouldn't that make it the native vlan?

What I've read says that the default vlan is not tagged, but that junos does not have a default native vlan. But wouldn't the default vlan be the native vlan if it is untagged?



Only allow dropbox app

I have a computer at work which shouldn’t be granted internet access. However I need to access the files remotely. We currently use Dropbox for our other files. I was hoping to install the Dropbox app and block everything else from accessing the internet. System: windows 10

What kind of settings/software would I have to use on either the computer or router.

Many thanks for any advice or alternative solutions.



Port mirror to logical interface

Hello,

can you mirror a port to a logical interface? I need to run a tcpdump to troubleshoot pxe issues.

Its a generic 48p HP Switch with the usual set of features.

(All ports are used up and needed in the productive envoirement)

If you can do that, would it work giving that logical interface an ip address in a network that has a static route / default gw set to a machines interface that I can listen on?



Collapsed core recommendations

Pretty small setup - three small-ish buildings, total of about 10 switches. Daily throughput is laughably small, most switches are 48 port, but we aren't utilizing even half of that. We currently use a pair of stacked Cisco 3750 switches for a collapsed core and are looking to upgrade due to them being EoL. I'm thinking two Cisco 9200 switches would be a good replacement. The boss is looking at Aruba. Eventually we'll be replacing the access layer switches as well, and if we go Aruba for the core, we're probably going Aruba for everything. His biggest reason for non-Cisco is price and licensing, but the 9200s are fairly cheap, aren't they? That is, compared to Aruba's L3 aggregation switches. Haven't gotten price quotes, but from what I've seen online. The other issue with licensing I think is a non-issue that he's misread. The base license does everything we'd need.

I'm really not looking forward to reworking all of our configs, figuring out what hidden quirks and gotchas another vendor has, I'm hoping to stay in Cisco land. Anyone have any arguments in my favor? Or perhaps it's not such a horrible jump? Thoughts? Recommendations? Thanks.



Rerouting traffic for external site through a VPN

Hi Reddit,

We have a site with an IPSec VPN back to a Colo, the site cannot get to an external site they use due to a local isp routing issue. I know I can reroute the traffic for the local site through the VPN, can I do this just by adding the external IP into the VPN ACL on the remote site.



VPLS Default Route and Account Policy for Sap ?

Hello guys, first of all, thanks for many in this group in the past week you helped my a lot clarifying some questions about vpls, vprn and epipe, this one will be the last one and it is over my assignment.

1- I have a vpls working between 3 sites and an ies configured in the central office "one of the 3 sites" that allows this site to go to internet, my question is how I can do to the other two sites to go to internet using the IES in the central office if this 3 sites use a layer to vpn to communicate ?

2- I am trying to configure a account policy, something to the ISP control and billing this customer, i did the following configuration, makes sense ? and how could I apply this in a SAP or customer ? thanks a lot again.

file-id 1

description "ACCOUNT"

exit

file-id 3

description "INGRESS_PACKETS"

exit

accounting-policy 1

shutdown

description "Acount_Police"

record network-ingress-packets

default

exit

accounting-policy 4

shutdown

description "This is the default accounting policy."

record complete-service-ingress-egress

default

to file 1

exit

accounting-policy 5

shutdown

description "This is a test accounting policy."

record service-ingress-packets

to file 3

exit



Long distance transmission

Hi , i am searching for advice

I have to link two buildings for internet, with no cables

the distance is near 300 meters , but between them there is buildings , so no direct transmission

can you give me your advice for devices if we can do that

thank you



HomeLab Network Redesign: BGP over IGP

Posted a diagram over in r/homelab of my redesigned network. The initial response was quite a bit of confusion around peering iBGP sessions over an IGP, in my case OSPF. I realize iBGP isn't quite as popular as the typical leaf/spine eBGP architectures, but alas, what I'm limited to with a traditional 3-tier and NSX-T install base which only supports BGP.

Am I way off assuming that OSPF is still the preferred IGP to peer out loopback interfaces that establish BGP sessions? The importance of that was around always-up interfaces to allow multi-path selection in the event of a downed interface.



What is the best practise for monitoring latency, packet loss in a large enterprise system?

Hello, My workplace(a Govt. Org.) has a large IT network, with >100,000 Desktops, numerous routers/switches and about 10K local servers distributed across a large country (MPLS based).

While we do have a NoC with Solarwinds to monitor the entire network, it is manned by a vendor firm.

In the recent past (5-6 months), our firm has been noticing that customer complaints about network issues are rising, while the monitoring platform and the MIS provided atop the system are still painting a rosy picture.

Upon investigation, we realized that the NoC vendor had been acquired by one of our largest network providers last year.

This has understandably upset our management, since they weren't so much as intimated about the change. Nor were there public filings, as both firms are private, un-listed entities.

While management is separately undertaking an investigation into conflict of interest, and replacing the NOC vendor, we (an audit sub-group of the IT wing) have been asked to investigate deviations/mis-reporting by the vendor. We have a free hand to install software, monitor SNMP, etc., but not to touch solarwinds (A clause in the NOC contract allows them to inordinately delay providing us with data/access)

What would be the best way to go about monitoring the network, assuming that I can work with the end systems, but cannot touch the routers or solarwinds.

I apologise if this isnt the correct forum for such a question and request you to direct me to an appropriate place.



Replacement for Open Mesh who now has a subscription based model under Datto Networks?

So we have been using Open Mesh and I loved it for years. It was very affordable and had all the features I have ever needed. Their APs were reasonable and the service was free to manage online. This week I spoke with a Datto rep about their new subscription based product line up and at $7 per month per device monthly costs will change from zero to hundreds of dollars per month... This is not possible for WiFi for my customers and prices the Datto offer out of the question.

So, anyone have any suggestions for a replacement? I was used to finding 6 radio APs under $200 and 4 radio APs under $125 and no recurring costs to have up to 4 SSIDs, captive portal features if needed, VLAN support per SSID, central cloud management with APs that can work offline too. I'd love to see something similar to replace it but not sure who offers such things if at all anymore.

Edit: Datto bought Open Mesh... Hance this change and my ask here...



Anyone try to think of using RFC 6598 for private ip?

Hey all

Know the answer but wanted to get thoughts on using RFC 6598 (100.64.0.0/10) for private ip?



Anyone using InfraSensing?

Looking at expanding our environmental monitoring, since we have a lot of CO and field cabinet deployments. Lots of DC power plant that needs monitored A/B, battery levels, etc. Seems these would work, but of course you can only get pricing through quotes. Our current system is basically ping alerts and vauge syslog, I'm wanting something that has actual SNMP alert capabilities of info that I can trigger Solarwinds/PRTG to scream about instead.

https://infrasensing.com/sensors/sensor_list.asp



What network card should I buy

I recently upgraded to 1gb internet and need to buy a network card for my pc should I get a 1gb or a 10gb is 10 go overkill?



how are bus topologies implemented?

Bus topology are mentioned in networking literature, but I have never seen a description as to how it is implemented..

Bus topology diagram shows a main trunk with nodes connecting into the main trunk.. the question I have is how are they connecting into the main trunk?? Is it through a switch or some other method?



Sim card

I will be an exchange student in America, which sim card company I should choose, T mobile or straight talk??

I hope I can both surf the Net and call people.



Mapping label bindings to LSPs on P routers without LDP

Hey all,

I’m trying to figure something out. We have a big old MPLS network with a bunch of core/P/label transit routers in the middle of the network swapping labels for our PE routers that are passing traffic for LSPs that connect l2/l3vpns and other things like 6PE.

We export IPFIX with mpls templates from these guys, and we mostly get the whole label stack. But these mean nothing to our flow collection devices because they are literally ephemeral label stacks and have no context like “label 435 is heading out interface blah towards a.b.c.d/xx”. Since our collector isn’t on the same network, I don’t think we can get this from ldp (maybe I’m wrong?). Any suggestions for how I could “enrich” these flow records with lsp/label bindings?



Friday, July 12, 2019

IP Camera Gateway On Segregated Network

Hey Y’all,
So I’ve recently been promoted to a system programmer position at the security company I work for and I’m looking for some insight on gateways for IP cameras.
On typical installs where we provide all the equipment we usually plug our cameras into a a non-managed PoE switch which plugs into NIC1 of our NVR and then NIC2 of the NVR plugs into the customers switch which makes the NVR the only device on both networks.
In this scenario what should I set the Gateway address of the IP cameras to as they don’t communicate with a router directly? Normally we use the IP address of the NVR but I was wondering if this is technically correct or the best practice. Thanks for any input.



CISCO RANT - ISE ERS API

RANT:

Okay, so finally got my python script to work to add new devices to ISE with TACACS using the ERS API. So that is cool (thanks for anyone that helped in a previous post), and I decide to turn on CSRF Tokens for added security because you know security is important and what not (Also seemed like a good challenge to enhance my coding knowledge).

WELL:

I was able to get the CSRF token and have python parse for it and pass it from the dictionary into a variable. I used this variable to pass it in the HTTP header when using POST, because CUD(POST, UPDATE, DELETE) requires you to have the CSRF token to push the code to prevent a CSRF attack. Well turns out that this can't even work on the release we are on, and in fact Cisco does not even have a fix for the bug yet! Bug: CSCvp22075. This is now the second time where Cisco's API documentation was meh and it shows, but at least someone else ran into the bug on the community forms.

So that begs the question, when will Cisco get good with their ISE API? Oh well, I'll just use the script I originally made and turn off the CSRF option in ISE for ERS until the bug is addressed and a new patch comes out. On to automating some Nexus API stuff (God help me, the NX-OS API better be good) :)

For now, I am going to go get a slurpee and back to my NP Route studies..... Damn you Cisco for taking the satisfaction away from me.



Tool to open multiple tcp and udp sockets for testing

I am currently using Iperf to open TCP and UDP sockets for testing (client/server) but can only test one port a time.

Looking for a Windows tool that I could open multiple ports at once.

I found other nice tools but again only 1 port at a time.

Any suggestions?

Thanks

Edit: Needs to work on Windows.



DHCP and new WAP issue

So I’m setting up a new TPlink eap245 wireless access point. I’ve gone in and added added the static IP, ip mask, DG, and primary/secondary DNS. Changed the SSID, added password. I can connect to the WAP perfectly fine but it has no internet access. It’s currently connected to a switch.

I currently have DHCP disabled, and all the other (wired) desktops on the network are also manually set with a static ip and dns. Everything wired works fine. Do I need to enable DHCP for this WAP to work? If I enable dhcp, is that going to mess up the wired desktops that are currently working?



Need wireless training recommendations that are low cost.

Hello, I'm a relatively new network admin (20 years of tier 1 and tier 2 support, got my CCNA late last year) who just had a whole wireless network dropped in my lap. I'm trying to solve some interference and connectivity issues, and all I have is a bunch of info from the vendor itself. Can anyone recommend self study resources that hopefully don't cost much for wireless? I have learned there is a lot more about wireless frequencies, channels, and power level management that I thought there was.



VLAN id translation on Huawei

Hey all,

I have an interesting conundrum. I'm wanting to preform a VLAN id translation on a few switchports. I have a Huawei s6720 switch that should be translating VLAN ids. Both interfaces xg0/0/17 and xg0/0/18 are trunk ports and should only see their respective tagged VLAN traffic. I'm wanting to turn VLAN id 100 into VLAN id 1000 and vice versa on interface xg-0/0/17/18. The traffic has to be tagged

I can only see rapid STP BPDUs when port capturing on the connected interfaces. I also cannot see any ping packets from a host connected to xg0/0/17 or xg0/0/18 when capture packet on the Huawei switch.

Traffic Flow:

Inbound VLAN 1000 tagged -> XG0/0/18 >[VLAN translate] >XG0/0/17 -> Outbound VLAN 100 tagged

Inbound VLAN 100 tagged -> XG0/0/17 >[VLAN translate] >XG0/0/18 -> Outbound VLAN 1000 tagged

My Config:

traffic classifier TEST-VLAN operator or if-match vlan-id 100 traffic classifier TEST-VLAN-1000 operator or if-match vlan-id 1000 # traffic behavior TEST-VLAN remark vlan-id 1000 traffic behavior TEST-VLAN-1000 remark vlan-id 100 # traffic policy TEST-VLAN match-order config classifier TEST-VLAN behavior TEST-VLAN traffic policy TEST-VLAN-1000 match-order config classifier TEST-VLAN-1000 behavior TEST-VLAN-1000 # interface XGigabitEthernet0/0/17 description monitor port link-type trunk port trunk allow-pass vlan 100 traffic-policy TEST-VLAN inbound traffic-policy TEST-VLAN-1000 outbound # interface XGigabitEthernet0/0/18 description server1 port link-type trunk port trunk allow-pass vlan 1000 # 

I've tried putting the "traffic-policy TEST-VLAN-1000 outbound" on interface XGigabitEthernet0/0/18 with no success. I've read the document https://support.huawei.com/enterprise/en/doc/EDOC1000088746?section=j00d however I'm not not having any luck.

Huawei's code is very similar to H3C Comware and HPE Comware 7 - It being from the same code base.



Remote site goes offline every hour

I've got a remote site with a Router (c1111) and a switch (2960), with a 20MB mpls connection and broadband backup.

Every hour the devices will fail and then about 20-30 minutes later they will come back up and go green for data/voice.

I've believe that its some kind of power issue, but even after removing the UPS they were both connected to, we're still having issues. I've tried plugging them into a CyberPower surge protector and then also directly into the plug from the wall outlet.

I cant for the life of me figure out why these devices keep going on/offline.

Originally both devices were plugged into the Tripp Lite UPS_> CyberPower Surge Protector_>Wall outlet.

We removed the Tripp Lite because we thought it was a battery issue. Now we have the switch plugged into the wall and the router plugged into the surge protector from the same outlet.

I've verified with Cisco that the devices are good environment/config wise for both devices.

Help a lowly network engineer figure out this ongoing issue

Troubleshooting:

-Confirmed configs and environment settings with Cisco - Good

-Reached out to our provider to double check IPsec tunnels - Good

- We did see our IPsec tunnel was receiving invalid SA's. I cleared the SA's from the router and we no longer see the message in the logs.



vpn throughput/cpu usage question

I know this is basic, but I'm looking for validation of my understanding. When looking at a datasheet, the max VPN throughput is just for traffic that is sent through the tunnel correct? Traffic that is not sent through the tunnel should still be processed at higher rates? How much of a concern is added resource/CPU usage by having a site to site vpn configured on the firewall?



Fiber link not coming up.

I have a fiber p2p link that is not even showing the ports coming up, let alone the connection. What I find odd about it is that I am getting transmit and receive data on it from the transceivers. Would this possibly be an optic issue or am I just missing something completely? Do both sides show physical down if there is an issue with one? I was expecting TenGigabitEthernet2/0/1 is up, line protocol is down or something as I have tried multiple optics on this side. Just want to check options before I drive to the other side of town and change out an optic.

Switch 1 TenGigabitEthernet2/0/1 is down, line protocol is down (notconnect) interface TenGigabitEthernet2/0/1 no switchport ip address 192.168.105.1 255.255.255.252 end Port Power High A High W Low W Low A Transmit Te2/0/1 -6.2 -1.5 -3.0 -9.0 -10.5 Receive Te2/0/1 -21.2 1.0 -1.0 -26.0 -27.9 Switch 2 GigabitEthernet1/0/12 is down, line protocol is down (notconnect) interface GigabitEthernet1/0/12 no switchport ip address 192.168.105.2 255.255.255.252 end Port Power High A High W Low W Low A Transmit Gi1/0/12 -6.0 -1.5 -3.0 -9.0 -10.5 Receive Gi1/0/12 -22.7 -3.0 -5.0 -24.0 -26.0 

Edit: TenGig2/0/1 is a 1/10g port with a 1g optic in it. The esteemed fruit-loop /u/asdlkf 's suggestion of forcing the speed fixed the issue. Speed Nonegotiate on each side brought up each line and then they synced.



Is there a secure Remote Desktop solution that is relatively simple to set up?

I was using Chrome Remote Desktop last year, but I had reason to suspect I may have been hacked. I know little more than the average person about networking and security, so I’d like some advice before I proceed. If it makes a difference, the target is my home PC on a cable network. It’s running Windows 10.



How can this camera be accesed from WAN?

Hi,

Some time ago i tried to make my own server that could be accesed from outside of my LAN and failed because of the carrier grade NAT. I thought there was no other way around it other than getting a public ip. But recently, i have noticed that my WIFI camera can still be accesed when using mobile data. I didn't get public ip, i didn't even forward any ports. How can this be?

The only solution i see is that a company who made this camera also host a public ip server that acts as a middle man. Unfortunatly, i was unable to verify it, wireshark doesnt show me packets going in or out of the camera (if you know why i would like to hear about it too).

Thanks for all the help.



Power notifications in the field

Looking for thoughts/opinions. I manage about 170 warehouses throughout the country and have a staff of 7, most residing in our HQ. In these 170 massive buildings, my IDFs are located on the ceiling and can only be reached with a lift which most places don't have on hand (cost a few hundred to rent).

My main problem occurs when a switch goes offline in one of these IDFs, how do we figure out what the problem is. Sometimes it's power, sometimes it's the device itself. Either way it can take up to a week to get the answer. I'm thinking about putting a magnetic light on the IDF to tell me when the power is out. How much maintenance or false positives am I signing myself up for here?



Sources to keep up with industry trends?

I would like to keep more up-to-date with industry trends in networking, both in terms of technology as well as shifts in operational practices. What do you all use to keep up with developments?



Router device Limit

I have a network with 4 routers, 3 working strictly as access points and between 40-60 devices running on the network, some of my connections will connect but show no internet, it seems to be a failure of the main router to assign IP addresses, is this my issue?



Connect two branch locations over HQ using IPSec

Hello, r/networking

Hopefully the title makes sense what I am trying to do.

I have 3 Mikrotiks (I can also use 3 Cisco's ISR's as well) trying to configure a topology which replicates this:

PaloAlto how to connect two branch locations over HQ

The basic idea is to create two VPN tunnels: Site A <--vpn--> Site B <--vpn--> Site C; and have traffic going from Site A to Site C go over Site B (while being encrypted).

I have successfully created both tunnels between Site B and Site A and between Site B and Site C. The problem I have is that, when I try to add traffic from Site A going to Site C (and vice versa) in the IPsec configuration, I loose connectivity between both sides.

Also, there is no NAT between the local and "WAN" interface.

Any idea how to proceed? Googleing is starting to fail me at this point



Help IES

Hello guys, I finish a test, where I have a vpls working and to finish I decided configure a IES to simulate a internet connection, I configured my IES like that:

ies 2 customer 2 create

description "CUST_A"

interface "internet" create

address 10.0.0.13/30

sap 1/1/3:0 create

exit

exit

the port 1/1/3 is where my vpls is working:

vpls 111 customer 2 create

stp

shutdown

exit

sap 1/1/3:111 create

description "ACADEMIA"

exit

sap 1/1/3:222 create

description "ALUNOS"

exit

sap 1/1/3:333 create

description "DOCENTES"

My question is, i configured a default route in my CE point to 10.0.0.13, but what more should I configured in the CE side ? I tought in configure an IP in the CE side, but this port is a trunk port, so I cant configured...What I should do ? and to simulate the internet, I tought to put this 10.0.0.13 in the route protrocol that my mpls uses...just to simulate.. thanks a lot...



#On sale # for MPO/MTP Patch Cable #cheaper price with #Free shipping

#On sale # for any kind of MPO/MTP Patch Cable from Mpofibers.com



Work Wireless Network Woes

Hello all,

At work we have a wireless network composed of multiple access points with the same name and password. However, it seems that my iPhone has trouble letting one access point go and connecting to another.

Throughout the day my streaming music will stop and I notice I have no WiFi signal anymore as I’ve moved to a new part of the facility out of reach of the original access point. Now if I turn off the WiFi for a second and then turn it back on the iPhone will connect to the closer access point with full strength.

What is going on here? What settings can I change to make this better? Is this the fault of the way the network is configured? Thanks.



BGP Peering in I2 and in I1

Does it make sense to have a BGP peering with a provider in the regular Internet and another BGP peering with the another provider in Internet2?
Is this even consider multihomed?
We are not going to be a transit network between the regular Internet and Internet2.



Thursday, July 11, 2019

Palo Alto Decryption with Android

I have a palo alto that I am testing decryption on. I followed PA documentation, and I have it working on a Windows device, but my android phone does not trust the certificate. I export the certificate as pkcs12 since Android wont recognize any of the other export extensions, I download the file on my phone, go to security settings and click download from phone storage. It installs successfully, I see it in the "user certificates" but in multiple browsers, it shows untrusted certificate.

Is there anything specific that needs done for Android? One thing I noticed is it shows up under the user certificates, but not the security certificates. I am not sure if that is an issue, or how to resolve it.

Has anyone got this working, and what steps did you take?

Here is the document I was using for the certificate settings. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClmyCAC

Thanks



[N00b] PoE Injector for business IP cameras, do I really have to provide 1 data input for each data output?

Hi friends and thanks in advance for being awesome.

I bought this PoE injector, apparently thinking it was a PoE network switch:

WS-GPOE-16-48v240w Gigabit Passive PoE 16 Port Power Over Ethernet Injector for PoE Cameras, IP Phones, WiFi Access Points, Includes 48 Volt Power Supply 240 watts https://www.amazon.com/dp/B01H990ADQ/ref=cm_sw_r_cp_api_i_-p.jDbDW179C3

I’m trying to install/connect 8 IP cameras, a security alarm, router and 4 IP phones. I didn’t realize this until now, but it appears for every Power+Data connection OUT, the injector requires a data input.

My problem(s): 1. Holy spaghetti 2. How in the heck can I supply 16 data inputs off of the only 4 original modem outputs I have to work with?

All the blogs I’ve read/videos I’ve watched start with the assumption that I know how networking works, and maybe I’d be better posting this in r/ELI5?

Does anyone recommend a cleaner solution?

Thanks again!



Can Someone Please Explain to me What a LAN tap is?

No text found

Blogpost Friday!

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts

Feel free to submit your blog post and as well a nice description to this thread.



Unable to ping default gateway of a subnet in ASA firewall but able to ping it's subnet IP's. Why is this?

I am unable to ping default gateway of a subnet which is behind ASA firewall however i am able to ping all Ip's in it's subnet from other subnet connected to core & in other sites. Firewall access list rules allow 'icmp any any', so why am i not able to ping default gateway IP alone? I remember reading something like one cannot ping from end of ASA to other end however not sure if this is the reason.



Speed of Link Card In Primary Connection Point

What speed are Link Cards in the Broadband cabiniet capable of.Because they support a large number of connections which can go up to 350MB

So does anyone know what speed a Link Card can support I would imagine it is 10GB



Feeling dumb at work

This is not a technical question. Please forgive me if I am posting it in the wrong sub. I dont find a better place to ask this.

I am feeling very dumb at work. I did clear my interview honestly. It's a routing and switching job.

I am new to the job after 2 years of break, and my troubleshooting skills are not good enough. I get mocked by my colleagues and one guy even told me that I am dumb. I am feeling low and frustrated. Should I continue in this job ? Should I find another job ? Am I in a toxic environment or this is expected ? It feels like I cannot ask help if I am stuck with something.

Any suggestions or help is appreciated.

Thanks.



Trouble shooting internet as routing for webex

So I have and idea of whats going on with our issue I'm about to describe, but I'm out of my element on how to go about getting it resolved.

We have 2 carriers we peer with and advertise a /22

Att is one of the carriers.

Last night we turned up a new internet circuit with century link and shut off our us signal circuit.

Everything seemed fine following the cut, all our hosted sites were publicly accessible, various service we use seem to be fine as well. Well come this morning, and we can access webex. No ither reports have come in.

Doing some traceroutes, our last response comes from level 3.

We turned the us signal circuit back up, and we we're theb able to acces webex again.

Doing another traceroute, we take the same path, and the hop that we stopped reciving responses from turns out to be what looks like a peering point for level 3 and cisco systems.

For what ever reason we prefer a path out through the att connection rather than century link, which seems odd since century link owns level 3 now, but who know what the state of peering and bro oath selection looks like for that.

Anyways, it would appear to me that the cisco systems device does not have a valid path back to our prefix. I obviously have no way to see what their return path looks like either (unlesss they have a looking glass I'm not aware of)

Managment dosnt want me to take us down to just att or just century link for testing during buisness hours incase it causes more service disruptions.

Right now, we are running on all 3 carriers so that webex works.

I'm going to get a call in with century link, but the problem seems like who we really need to look at this is that cisco systems level3 hop owner.

Do I approach cisco and say, hey, your webex service seems to be having issues routing to our prefix, can you see what it lloks like on your end? Would I just call webex support?

I'm just not sure about who to contact to get this looked at properly and resolved. Ive never had to troubleshoot a specific service like this before, with multiple carriers involved. I'm not even sure how to go about finding out what carrier the return traffic may be trying to come back on.

Edit:

i forgot to mention that when we were "down", i could reach the destination if the ping/traceroute was sourced from the IP address we peer with either ATT or Centurylink on, but not when sourcing from our prefix. so its specific to how our prefix is advertised it would seem.

here is a truncated traceroute to take out identifying information

when it fails

8 5 ms 4 ms 4 ms 12.119.139.13

9 14 ms 14 ms 15 ms 12.123.35.130

10 15 ms 15 ms 14 ms cr1.cgcil.ip.att.net [12.122.152.37]

11 15 ms 15 ms 14 ms cgcil402igs.ip.att.net [12.122.133.161]

12 * * * Request timed out.

13 12 ms 12 ms 12 ms ae-2-3601.edge4.Chicago3.Level3.net [4.69.203.230]

14 * * * Request timed out.

when successful ( the extra hop is the router that terminates the other circuits hopping to the ATT terminating router)

9 13 ms 15 ms 14 ms 12.123.35.130

10 15 ms 21 ms 14 ms cr1.cgcil.ip.att.net [12.122.152.37]

11 14 ms 14 ms 14 ms cgcil402igs.ip.att.net [12.122.133.161]

12 * * * Request timed out.

13 12 ms 13 ms 12 ms ae-2-3601.edge4.Chicago3.Level3.net [4.69.203.230]

14 12 ms 12 ms 12 ms CISCO-SYSTE.edge4.Chicago3.Level3.net [4.53.98.74]

15 13 ms 13 ms 12 ms ord10-wxbb-crt01-bu60.webex.com [64.68.115.20]

16 33 ms 33 ms 33 ms iad02-wxbb-crt02-te0-6-0-1.webex.com [173.243.4.58]

17 30 ms 30 ms 30 ms iad02-wxbb-pe02-bu12.webex.com [64.68.117.194]

18 29 ms 29 ms 30 ms 64.68.118.55

19 33 ms 32 ms 33 ms iad02-wxp00-csw01-vl101.webex.com [64.68.115.101]

20 29 ms 29 ms 29 ms iad02-nebulaaa9.webex.com [64.68.105.103]



Looking for HTTP(S) to TCP reverse-proxy with customisable auth binary backend handshake.

Hi everyone,

I'm trying to implement something a bit different than usual. I'd like to deploy a reverse-proxy that accept HTTP(S) (SSL / TLS termination) on the frontend but with a TCP backend.

The twist is that I'd like keep a connection pool to the backend where the connection initialisation process requires a custom binary authentication handshake.

Also I'd like to be able to do some light processing (like modifying the request body and using the HTTP body as TCP body).

I had hopped to be able to use HAProxy for this but due to the following limitations I don't think it's feasible:

  • HAProxy doesn't allow mixing a HTTP frontend and a TCP backend
  • HAProxy doesn't allow modifying the body
  • HAProxy doesn't make it possible to initialise a TCP connections with some pre-determined binary authentication handshake

I looked around on the Internet, StackOverflow / StackExchange and the HAProxy subreddit but couldn't find any way to implement this.

Does anyone know of a high-performance open-source solution with sane defaults that full-fill these requirements?

Thanks a lot!



Easy way to test intrusion detection

I've finished an enterprise project installing network side and host side intrusion detection. What would be the absolutely easiest way to test this with as little effort as possible?

I know the rules are all 100% tested and work but I just want to make sure it intercepts an 'attack'. I don't want to pentest this I just want to set it off somehow for verification before I say it's finished.



Creating socks compatible hotspot wifi

We have a small company and we share internet to our mobiles via a hotspot. Now there is a need for us to apply socks on our internet so the mobile devices have same socks. We tried using proxifier, set all services and programs to socks. All programs on our system obey the rules, but the hotspot connection is not following it, meaning mobile devices still use the original IP. What can we do? Is there some modem or software that can help us achieve it? Also we are basic computing skills, we are not networking/ software experts.



E911 Inaccuracy (Telephony Question)

I have a site that has a SIP telephone number provisioned by SIP.us, and I have configured the TN with the proper street address. When I call 933 to verify the E911 address, it lists the proper address. When I call 911 to verify the address, I get a slightly different, incorrect address.

For example, 933 lists the following:

123 OAKBROOK CTR

911 lists the following:

123 OAKBROOK ROAD

Unfortunately, there is an actual nearby 123 OAKBROOK ROAD address, so I need to find some sort of way to resolve this, but I have no idea who to contact or what do it.

Has anyone ever seen a discrepancy between 933 and 911 like this? I always assumed that the pulled from the same database, but apparently not.



Theoretically a simple question....

I have two sites; one on fiber -site A (100meg), one on Comcast business cable modem - site B (300meg). Site A has about 50 employees, site B has about 40 employees and each site has the same type of functions so internet/intranet usage is about the same. There is a Cisco (5516x) site to site VPN between and in general all traffic from site B is routed through the VPN to site A. This is mainly done for security and sharing of resources located at site A. There is many times where I cannot run certain things as the tunnel gets flooded with traffic even though I have QoS on the tunnel.

Basically, I'm looking for a solution to improve traffic flow as my boss thinks throwing fiber at site B would help but I think that would be a waste of our budget and not really a solution in the first place.

TIA



Cisco Licensing | 'show license feature' Explanation Needed

Hi,

Can someone please clarify exactly what the headings below mean please? Just a short description? I have tried searching across forums but haven't seen anywhere that highlights it all in one place. I would appreciate if someone could fill in the gaps below please.

Enforcement -

Evaluation -

Subscription -

Enabled -

RightToUse -

What do they all mean exactly? As an example I have a HSEC license that is Enabled YES, RightToUse NO. Seems to contradict so I must be misunderstanding it somewhere.

Thanks in advance



Show ARP / Show Mac Address-Table - Not listing correct results

I'm not sure I'm doing something incorrectly, however, I'm not receiving the results I was hoping for.

I was recently in a situation trying to track down a rogue IP that was not listed in our documentation. We'll assume it was 10.0.0.10. I was able to ping the IP and verify that it was up.

I connected to the switch I assumed this device was on, which was a Cisco 2950G. If I type show arp, I see a small list of other IP addresses that are on the same network as the management IP for this switch.

The switch does have roughly 25 other VLANs configured on it. I next tried "sho arp vlan 123" in an attempt to list the arp contents for that VLAN, which did not work.

Does the sho arp command only work if the entire switch is on the same subnet?

Thanks



What's your favorite trick you used to solve a problem creatively?

Recently I solved a duplicate IP issue with static ARP, which I had heretofore never used, or even understood why it might be useful. Saved me a trip on-site, and cemented in my mind another piece of how L2/L3 works.

What's your rabbit-out-of-the-hat story?



Data Center/Comm Closet Environmental Monitoring Equipment

Do any of you guys use one of these systems? If so can you recommend any makes and models and/or share your experience with using them?



ACL weirdness with Aruba 5412Rzl2

Hey all - so I ran into a bit of weirdness recently with an ACL applied outbound on a VLAN interface on my core 5412Rzl2. The problem was that our DCs were unable to sync their time with our NTP servers. The DCs live in different subnets than the NTP servers. The cause of the problem turned out to be with the ACL applied outbound to the VLAN that the NTP servers reside in. However, that same ACL had permits allowing the DCs to the entire server subnet for ip. There is also another permit allowing UDP traffic from our internal networks into the subnet where the NTP servers live. There are no rules that would block this traffic before the allows in the ACL that I can see.

Removing the ACL from the VLAN interface resolved the issue, but of course that wasn't a true fix for the situation. I ended up having to add specific permits from the DCs to the NTP servers for udp/123 before the DCs could sync their time with the NTP servers. Given the other ACEs already in place I am not sure why this was necessary.

Below is the relevant portion of the outbound ACL in question. IPs have been changed to santize the ACL for a public forum. Also, a couple SNMP allow rules have been omitted for brevity. The ACL is actually much longer than what is presented here, but the rest isn't needed for troubleshooting this issue. Please note: This is the ACL after the specific NTP allows have been added. Omit any ACEs with "eq 123" and you'll have the ACL as it was originally applied where it was stopping NTP traffic from the DCs.

 remark "deny WiFi networks" deny ip 10.100.0.0 0.0.31.255 192.168.246.0 0.0.0.255 deny ip 10.103.0.0 0.0.31.255 192.168.246.0 0.0.0.255 remark "deny ping to broadcast" deny icmp 0.0.0.0 255.255.255.255 192.168.246.255 0.0.0.0 log remark "allow ping from internal networks" permit icmp 10.0.0.0 0.255.255.255 192.168.246.0 0.0.0.255 permit icmp 192.168.240.0 0.0.7.255 192.168.246.0 0.0.0.255 permit icmp 192.168.248.0 0.0.0.255 192.168.246.0 0.0.0.255 remark "allow NTP from DCs to NTP servers" permit udp 192.168.240.15 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.240.15 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.240.15 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 permit udp 192.168.240.16 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.240.16 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.240.16 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 permit udp 192.168.240.17 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.240.17 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.240.17 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 permit udp 192.168.248.12 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.248.12 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.248.12 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 permit udp 192.168.248.13 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.248.13 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.248.13 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 permit udp 192.168.248.14 0.0.0.0 192.168.246.50 0.0.0.0 eq 123 permit udp 192.168.248.14 0.0.0.0 192.168.246.101 0.0.0.0 eq 123 permit udp 192.168.248.14 0.0.0.0 192.168.246.130 0.0.0.0 eq 123 remark "allow all traffic from Domain Controllers" permit ip 192.168.240.15 0.0.0.0 192.168.246.0 0.0.0.255 permit ip 192.168.240.16 0.0.0.0 192.168.246.0 0.0.0.255 permit ip 192.168.240.17 0.0.0.0 192.168.246.0 0.0.0.255 permit ip 192.168.248.12 0.0.0.0 192.168.246.0 0.0.0.255 permit ip 192.168.248.13 0.0.0.0 192.168.246.0 0.0.0.255 permit ip 192.168.248.14 0.0.0.0 192.168.246.0 0.0.0.255 remark "Allow DMZ to Server Subnet unrestricted" permit ip 192.168.241.0 0.0.0.127 192.168.246.0 0.0.0.255 log remark "allow SNMP on Netsight-Server for management network" permit udp 172.18.0.0 0.0.255.255 192.168.246.150 0.0.0.0 range 161 162 remark "block SNMP from other networks" deny udp 0.0.0.0 255.255.255.255 192.168.246.0 0.0.0.255 range 161 162 log remark "allow UDP from internal networks" permit udp 10.0.0.0 0.255.255.255 192.168.246.0 0.0.0.255 permit udp 192.168.240.0 0.0.7.255 192.168.246.0 0.0.0.255 permit udp 192.168.248.0 0.0.0.255 192.168.246.0 0.0.0.255 permit udp 172.18.0.0 0.0.255.255 192.168.246.0 0.0.0.255 

The 5412Rzl2 is running KB.16.08.0001. Thanks in advance for any feedback.



Dumb Question about SD-WAN

Hi everyone! Tech noob here. I was doing some readings on SD-WAN and I am really confused with the term “Cloud-delivered SD-WAN” (VeloCloud’s offering). How is it exactly different from the regular SD-WAN and what part of it is delivered over the cloud?



Agile - Networking

Another agile post, I am sorry but just wondering if anyone that has worked in a network environment can explain to me if there is a design done at the start. My current workplace seems to think you have half of a design document, get everybody from different teams to build a POC and then run out of time and then go live.

Edit - Supporting it...optional.



Simple load balancing across Cisco port channel?

I don't tend to get too in-depth on Cisco stuff so knowledge is lacking there. We have a Cisco 2960 rack-switch with 2x 1Gbps uplinks to a Juniper MX gateway.

We have 3 devices on this switch running around 300Mbps up and down consistently, and many other devices with far lower traffic i.e. >10Mbps.

Inbound is fine and can burst to over 700Mbps but Outbound isn't doing so well and is mostly going over one port, causing other devices to suffer from low outbound speeds.

How can I get the outbound traffic balancing over the two ports better?

Only config relevant to the trunk ports below.

interface Port-channel1

switchport trunk allowed vlan *****

switchport trunk allowed vlan add *****

switchport mode trunk

spanning-tree bpdufilter enable

!

interface GigabitEthernet0/47

description po1

switchport trunk allowed vlan ***

switchport trunk allowed vlan add ***

switchport mode trunk

no cdp enable

channel-group 1 mode active

!

interface GigabitEthernet0/48

description po1

switchport trunk allowed vlan ***

switchport trunk allowed vlan add ***

switchport mode trunk

no cdp enable

channel-group 1 mode active

The two uplink ports below:

https://i.imgur.com/wS1gMZD.png

https://i.imgur.com/cTFjwxj.png

Thanks in advance!



User is not allowed to use gotomeeting in VM. how can we detect if he is using in vm

User is not allowed to use gotomeeting in VM. how can we detect if he is using in vm



Wednesday, July 10, 2019

Question for HPE/Aruba Networkers re management

Assume a network of mixed ProVision switches and Aruba APs.
You are only allowed one NMS tool, either IMC or Airwave. You will have to compromise.

So the question is, does IMC do a better job with Aruba APs, compared to the weak effort Airwave does with ProVision switches?



Juniper VLAN Interface vs IRB Interface

Hi All,

I'm still new to Juniper (I have a Cisco background though), and I'm trying to understand the difference between creating a VLAN interface, and attaching a VLAN to an IRB interface.

For example:

set interfaces vlan unit 10 family inet address 10.10.10.10/24; 

This appears to be the same as a Cisco SVI. This gives some layer-3 functionality to a VLAN.

On the other hand:

set interfaces irb unit 10 family inet address 10.10.10.10/24; set vlans NAME vlan-id 10; set vlans NAME l3-interface irb.10; 

This also appears to give a VLAN some layer-3 functionality.

So, I'm wondering what the difference between the two is. Is one for older versions and the other for newer versions? Are they different approaches to the same thing? Something else?

Thanks



RadB Summary/Prefix Alerts

Hi All,

Anyone have any experience with RadB? I recently set up some e-mailed reports for the following:

Prefix Alerts Summary Report and Host Reputation Summary Report

What do you do with this information? Should I re-act in anyway ?

Should I be looking for anything specific?

Most of the IP's I'm seeing are from my customer's customers several AS's downstream.

Thanks,



OSPF with HSRP

Hi engineers

I'm not sure if I'm overthinking but I have the piece of network shown here. I have one physical interface from the router going to two core switches that are doing HSRP and I'd like the router to choose the active one. The standby switch is configured with the higher IP address so OSPF is choosing that one.

I have read that forming adjacencies with the virtual IP won't work and I have also tried using a P2MP network type and assigning standby switch a higher cost using

router ospf 1

neighbor <standby switch> cost 10

neighbor <active switch> cost 1

However, I have a Peplink that also has to run OSPF and it only supports broadcast and P2P so even though the adjacencies form, I'm still missing routes. Is there a simple way to solve this problem that I am overlooking?



How can I see what is the API a website is using?

My school's library is using a ASPX website to facilitate room booking.

I am trying to figure out the API Endpoints and the API use to be able to make a script to book a room at a certain time (in the event I forget and someone else has booked it)

Is there any tutorials online on how to view the POST API endpoints and how the server is sending data to them?



ISP packet loss question/advice

Just built out a new internal network for a medium sized business in a rural part of the North East. Everything is working great, except general internet. Local ISP is small, but has a solid fiber network. However, we are getting nasty packet loss from the hop immediately after our ISP's boundary. And it isn't just our location. It is the entire town.

Pathping is clean out of the gate, but as soon as it hits the hop right after our small ISP (in this case, a series of Cogentco hops) we experience 2 to 10% packet loss.

We reached out to the small ISP with our data and got the ole "it's not our network" reply and "it's normal summer congestion." My questions for you fine folks...

  1. Am I wrong in thinking that they should have some relationship with the connection that they are passing their traffic off to? Wouldn't that be their upstream provider? And shouldn't they be able to reach out to them about this or escalate the issue? Or is that not how it works in situations like this?

  2. Any advice on how to approach this problem? It's totally up to our ISP to resolve, right? How would be the best way to get them to agree with that?



CCNA Security MegaLab | DHCP, Static NAT, PAT, VPN, Site to Site, ACL an...

58 minutes of pure configuration!

https://youtu.be/1EUgZGoaex4



TP-LINK TD w8961N iP QoS ?

So i was searching for the w8968 but i didn’t find it so I bought the w8961n thinking it also has the ip qos service to control bandwidth for connected users but unfortunately I don’t find it anywhere, quick search on google I didn’t find anything neither.. so i was asking does it support the ip qos or not and should i return it?



Routing 10GB traffic over L3 switch vs 1GB firewall

Hey guys,

We have an issue where certain applications like NFS, ISCSI, and Storage backups are currently routing through the firewall (Palo Alto) as it's router, limiting the bandwidth of the traffic to 1GB when everything else Layer 2 wise (servers, NAS, SAN) is 10GB+....trying to figure out the best way to route this traffic while still having insight to whats going on in the network with the Palo Alto traffic logs. The L3 switch is a cisco nexus 3k.

Any ideas or suggestions are appreciated!



Can I use a /30 for p2p trifecta (3 endpoint) the same way I can use a /31 for a p2p link?

I'm pretty sure the answer is no but I'm not sure what to Google to get the answer.

Thanks,

Edit: Answer

No

  • /31 only works thanks to RFC3021

  • If you try to assign a network or broadcast address to an interface, the OS will give you an error, saying you can't do that.



List of POE Switches?

Hello r/networking,

I work in the networking department of the university I attend and I need to find out which switches we use have POE and we switches we have do not have POE.

Is there a list anywhere I can use to figure it out? Or will I just have to google each individual switch?

There are 45 different Cisco switches in use.



Infrared LED or Laser for Line Of Sight Wireless - Experiences?

Anyone ever run into any Infrared LED or laser LOS products in their line of work?

Example

http://www.airlinx.com/products.cfm/product/19-0-0.htm



P2P wifi between buildings as a backup to fiber

We have a few buildings on campus, all within 1000', all with direct line of sight and all pulling less than 1Gbps of traffic. We have multiple fiber links to each building but they all run through the same conduit. It seems like having a point to point wireless connection between the buildings would be cheap secondary connection for insurance.

I'd want to run over the public spectrum so I dont have to deal with getting a license from the FCC. I see Ubiquiti makes some cheap products for under $100, their nanobeam and litebeam bridges. What am I overlooking here? This seems like a cheap and easy way to get connectivity but I don't hear of people doing it too often. Would there be any additional ways to secure this rather than the typical wifi practices?



Stratix switches - InterVLAN routing not working properly

I'm running into an interesting issue when I set up VLANs on a couple L2 switches.

I have one purely L2 switch (the Allen-Bradley Stratix 2500) that I configured one VLAN on and a Stratix 5700 that is capable of InterVLAN routing (which works if both devices are plugged into the switch, even if they're on different VLANs). [Btw, Stratix switches are made by Allen-Bradley and sold by Rockwell Automation and the 5700 runs full Cisco IOS BUT there is a web interface called the Device Manager that controls engineers will use, not CLI]

What I have set up: purely L2 managed switch, has an IP address of 10.10.10.90/24 on the default VLAN 1 and a device with IP address 10.10.25.100/24 on VLAN 25. VLAN 25 was added and given a description, but no IP address (SVI). There is a link that connects the 2500 to a 5700 via trunk ports (configured on both ends as Trunk with all VLANs allowed). The 5700 is a beefier switch that is not L3 but allows for InterVLAN routing, which works, like I said, when the devices are plugged straight into the 5700. On the 5700 side, I have a trunk port configured to allow all VLANs connected to the 2500, and configured a VLAN 25 with the same name as on the 2500, but I also added an interface IP for VLAN 25 of 10.10.25.1/24.

I have two devices on VLAN 25. The one that plugs directly into the 5700 has full visibility, including the 2500 default VLAN IP address (10.10.10.90) but not 10.10.25.100. The device plugged into the 2500 on VLAN 25 can't see anything.

The host configuration is as follows: the device that connects to the 5700 has IP 10.10.25.200/24 with gw 10.10.25.1 and the host that connects to the 2500 has IP 10.10.25.100/24 with gw of 10.10.25.1. <---- What should the gateway be for the device that connects to the 2500? There is no interface IP configured on the purely L2 switch, as I want the switch capable of InterVLAN routing to do those functions. Or do I still need a local interface IP for VLAN 25?

[[[ When I set up this topology in Packet Tracer w/ 2960 and 3650, I have full communication. The switches I am using are comparable to those models. Also, I can probably configure the topology through CLI but I want electricians and controls people to be able to do this through the web interface ]]]

Here is a sample topology: https://ibb.co/XJ0XJsW



Looking for New Layer2/3 SFP Switch

As the title suggests, I am looking for recommendations for a new Layer2/3 switch with at least 16 port SFP 1Gb ports and 2 or 4 10G SFP ports. I don't really have a brand loyalty just as long as it has some kind of enterprise support. I have been seriously looking into the Ciena 5142 because it is NEBS compliant which would be nice since these switches would be living in a none datacenter environment. But I don't know many people using the Ciena gear.



Breakdown of different Catalyst switch models?

So I need a 48-port 2960x with PoE. When I look online, there are a number of models that fit that need, all with different model numbers, but no real easy way to discern the differences. Does anybody have an easy breakdown of what the model numbers mean? For example, I've figured out the the "P" in "Catalyst 2960X-48LPS-L" represents that it is a PoE switch.



Mgig WANEM compatible PCIE NICs?

Hello Folks-

I am building a WAN sim for work, and the trashbin "atleast I have them" 4 port NICs I am using aren't working properly, and are not cooperating with my VM host.

With that said, I was wondering if anybody using WANEM has any advice on a usable 4 port mGig capable 1/2.5/5gbs PCIE card? The version of linux WANEM based off is a little old, so I am hesitant to just wing it with an Aquantia or something like that.

Thanks!

Thanks!



2960x switches lose lanbase license after software update.

In the process of updating the software on our 2960x's to Cisco's recommended release 15.2.4E8(MD). After the reload I've had 3 switches lose their lanbase license out of around 25. Once this happens it stops forwarding traffic, the management side works fine. Has anyone seen this behavior before? If so are there any indicators that would identify a switch that would be susceptible prior to an upgrade? I checked the licenses after the first two before going any further, yet had another fail last night even though it showed to have its license prior to the reload. TAC case is open with Cisco.

From the logs: %ILET-1-AUTHENTICATION_FAIL: This Switch may not have been manufactured by Cisco or with Cisco's authorization. This product may contain software that was copied in violation of Cisco's license terms. If your use of this product is the cause of a support issue, Cisco may deny operation of the product, support under your warranty or under a Cisco technical support program such as Smartnet. Please contact Cisco's Technical Assistance Center for more information.

On the failed switch show license Index 1 Feature: lanlite Period left: 0 minute 0 second Index 2 Feature: lanbase Period left: 0 minute 0 second

What it should show show license Index 1 Feature: lanlite Period left: 0 minute 0 second Index 2 Feature: lanbase Period left: Life time License Type: Permanent License State: Active, In Use License Priority: Medium License Count: Non-Counted



Cisco ASA design question disaster data center

Hi, I have the following setup. Site A with a running ASA HA cluster and Site B, that replicates alle the internal/external networks from site A over a 1gbit line (redundant). So network wise I'm all set.

My plan was to put two other ASA on site B, Site B becomes a member of Site A ASA cluster and if site A burns down, everything goes through site B.

So I cannot do this with the current HA setup. An active/active/active/active ASA cluster seems to be way out of line (iirc smth like 5gbit DCI) and I cannot control the traffic. Site B traffic should only receive traffic if A goes down.

So I was thinking about contexts, as the most reasonable solution. With i.e. Check Point I can have one or more "contexts". Have a fallback context and then a backup context (which in this case I would put at site B).

Is it possible to run a backup context to the HA context with a third or forth ASA? Or is there an even simpler solution for this?

Thanks



[Help] Cisco Multi-Path eBGP

Hi All,

So... I've done this before on older code, seem to be having some troubles getting it going on the 15 line (IOS).

I have 2 BGP peers advertising the same IP address (10.245.0.53) into a VRF (DMZ-VS)

# show ip bgp vpnv4 vrf DMZ-VS * 10.245.0.53/32 10.0.1.4 0 65004 ? *> 10.0.1.3 0 65003 ? 

I can't seem to figure out how to get both these installed into the routing table... it use to be max-path X import Y

It seems the import option was replaced with "import path" which I've applied to my BGP configuration, but it doesn't appear to be working.... possibly some missing syntax?

 address-family ipv4 vrf DMZ-VS import path selection all import path limit 4 redistribute connected neighbor 10.0.1.3 remote-as 65003 neighbor 10.0.1.3 activate neighbor 10.0.1.3 soft-reconfiguration inbound neighbor 10.0.1.3 route-map deny_all out neighbor 10.0.1.4 remote-as 65004 neighbor 10.0.1.4 activate neighbor 10.0.1.4 soft-reconfiguration inbound neighbor 10.0.1.4 route-map deny_all out maximum-paths eibgp 4 exit-address-family 

Routing table only has 1 entry:

#show ip route vrf DMZ-VS B 10.245.0.53/32 [20/0] via 10.0.1.3, 3w4d 

Thoughts?



OpenDNS now blocks all proxies. Use another DNS server.

It's all in the title really. They block/prevent you from accessing proxies, starting today. Any DNS server that does this I'll happily trash immediately.



Auto-summarization H/W question

So what is this fuckery that is confusing me?

A class C network: Network.network.network.node

If we have networks:

192.168.16.0 through 192.168.31.0 and we want to summarise them, well

  1. We look at the block size. In this case, it's 16 which fits nicely

  2. The summary network address is the first IP used, in this case 192.168.16.0

  3. The summary mask is 240 (256 - 16 = 240)

So, our it would be

192.168.16.0/255.255.240.0

Everything makes sense, except one thing.

When subnetting a class C address, shouldn't the 4th octet be manipulated, not the 3rd? Or am I misunderstanding something? Is this process different than "normal" subnetting?



Tuesday, July 9, 2019

RV320 & WAP 371

Thinking on picking up the RV320 VPN Router and WAP 371 AP. I was wondering how easy they are to setup and deploy a wireless network with VLANS and multiple WLANs. Are they CLI or web GUI?



Can someone guide me in acquiring and configuring a wireless router for an event?

I apologize if this is the wrong subreddit.

I’m launching a new mobile app and plan to have a launch event at an outdoor festival. The festival site has good service with Verizon and AT&T, but a sizable chunk of my target users have discount carriers without service at the site. What I want to do is share enough of a WiFi connection to allow people to download the app and try it out, as well as the normal things people do when they have an internet connection for the first time in a day.

Here’s my vision: public/open SSID, with a login page that forces them to download the app (or at least view the web page) before granting them access to the internet. Then they get a certain amount of bandwidth for a limited period of time. I see setups like this in places like airports all the time so I know it can be done, but I don’t know whether it can be done on a limited budget. Also, I need this router to have as much range as reasonably possible without running wires to multiple APs.

The other issue is acquiring the actual backbone connection. I haven’t figured that out yet. Verizon’s standard “unlimited” hotspot plans are definitely a no-go since they are all limited to 15 gigs per device and I expect that amount to run out in just an hour or two if the booth is popular. However I’m concerned that I may not be able to find a plan to just buy 100 gigabytes or so without committing to a very expensive ongoing plan. But I figure I need to evaluate the feasibility of the whole plan before getting into this detail.



TCP RTOs, Spurious Retransmissions, and unable to access cloud hosted application.

Ok, so I'm currently having an issue that we can't seem to solve. We have a application hosted on a 3rd party's server, which we access over the internet. This application is accessed by time clocks that automatically transmit data to the server, and by users over https via a web browser. Currently, no one LAN side can access the the web page, but time clocks have no issue sending data to the server. Both the web service and the time clocks talk to the same IP, via https. Despite numerous troubleshooting calls with the time clock vendor, our ISPs, and Palo Alto, (our edge firewalls), we have been unable to pinpoint where the issue lies.

Pcaps sourcing from the client and post-nat WAN show what you see in the title. We have had the vendor remove IP restrictions on their edge firewall. Outside our network, we are able to access the URL that redirects us to the application's web page. We have even had our ISP NAT to one of our public IP addresses, and they accessed the web page with no issue, bypassing our edge firewall. Really stuck on how to find out where the issue lies.

Everything was working until yesterday around noon. We had made no changes, but the vendor did make changes to IP restrictions. Apparently they have removed them since we have started troubleshooting.

Things we've tried so far: - Fail over to backup circuit. - Fail over firewalls - Verified, with Palo techs that firewalls are not blocking traffic. - Tested on machines that surpass their minimum requirements. - Verified routing. - Sent multiple Pcaps to vendor's network team.

Thanks for any advice, and I'm sure I'm leaving out important info, so please feel free to ask for clarification!



Why does my website ask for a username and password and say that my connection to the site is not private?

I tried to deploy my website on a raspberry pi just for fun but I can't access the content until I enter a username and password. I followed this tutorial but obviously, I messed something up. My website is izzyfro.com, all feedback is appreciated.

Please keep in mind I am new to web development and deployment.



Trying to create an Arista firmware upgrade script via Python. One issue...

Hey all. I was going to put this in r/Python but decided to try here first.

I have a script that calls in a JSON file which has a list of devices. I came across Kirk Byers ssh_autodetect.py script that will autodetect the code, which I think is perfect since we are a multivendor shop. I figured i'd make this it's own module and then import it into my main code. Problem is, I guess when it tries to unpack the list of devices, it can't find that variable name even though it's in the main script. It's like when it's run, it's running separately from my main script and any variables I have in my main script are invisible to it.

Is this possible? I imagine it is, but googling has not done much for me at this point. I hope the explanation is clear. Thanks



2000+ Device network 1 broadcast domain

I had a conversation last week with a senior engineer at a small ISP 2000+ customers.

My background is in guest networks and it came up that most of the time when a guest connects to our networks the broadcast domain is the guest and their gateway.

He countered with their entire network is 1 broadcast domain.

In the moment I gave a confused look and he just mentioned you'll learn a lot more about broadcast domains preparing for your CCNA. But now this is the thought that keeps me up at night.

I knew what a broadcast domain was but at the same time just a few short months ago I thought everything ISPs do was magic and completely different than what I'm doing.

So redditors that have experience in the ISP world. Is it true that ISP networks are just 1 broadcast domain. If so,

  1. How do you mitigate the effects of broadcast traffic on your network performance?
  2. I was always under the assumption that 500 devices was too many on a broadcast domain. Researching I came across the number of 1022 with a reference to 802.3, reading the latest revision I could get my hands on this appears to be absent from that document (it is hundreds of pages though). Are carrier devices just this good?

  3. But really, are you doing magic?

  4. Can a fiber ring network (they have many) even be in the same broadcast domain? I learned routers break up broadcast domains and you're jumping through multiple routers if you're in the middle.

I'm reaching back out to the person who had stated this but of course I need to get his number from someone else, but I'll update if I get a response.



Fortinet, ZScaler, GRE tunnels and the need to bypass

Hey all, I need your ideas please.

We’re a ZScaler customer for web filtering. We use IPSec tunnels from each branch to the closest tower for location based access rules. (also use ZScaler app locally for auth and offsite protection).

The IPSec tunnels terminate on a Fortinet firewall in each branch. We have a number of websites and systems that we need to break out locally rather than sending onwards to ZScaler. (mainly compatibility reasons – but can also be licensing etc.)

Currently this works nicely. The IPSec tunnels are tunnel mode, not interface mode.

The general topology looks something like: CoreSwitch -> Firewall ->TCP80+443-TunneltoZScaler -> Internet

ZScaler have a 200Mb/s limit on an IPSec tunnel. My head office is now hitting that limit and I need to change my traffic forwarding method. The recommendation is to move to a GRE tunnel as this supports 1Gb/s.

I’ve labbed this up and got it working.

The problem is that I can no longer bypass traffic easily as the GRE tunnel is an interface. Routing occurs before the policy lookup. (https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-life-of-packet-52/LoP-packet-flow.htm)

I know I can drop the tunnels completely and rely only on the ZScaler app but then I’ll lose the ability to have bandwidth control per site. (https://help.zscaler.com/zia/choosing-traffic-forwarding-methods)

I need to come up with a new solution. I need your ideas.

I need to do destination-based routing that supports the general IP addresses, FQDN’s and if possible the increasing need for wildcard FQDN’s. Ideally it will have a user friendly interface so my wider team can operate daily. (we have a high rate of change)

Has anyone else hit this? How have you approached this?

All help and ideas welcomed.

Cheers

Hkey.



Rant Wednesday!

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!



Who here is deploying WiFi 6 currently?

What brand/model are you using and how big is your deployment?

I have two buildings that are getting heavy renovations this year. All new everything, wiring, switches, APs. We are mostly going with the Aruba AP-515. Should be at least 200 new APs installed this year.



Smallest possible poe access point?

I'm looking for a smallest possible poe access point, preferably the size of a pen drive that can be plugged in directly into rj45 keystone without any additional cables.

PoE is a must and so is 2.4GHz b/g/n, 5.0GHz would be a nice addition.

I'm using UniFi so it would be good to be compatible.



Made a Python3 CDP neighbor to interface description script, all feedback welcome

Guys and girls I made this script, it is my second python project ever so please spare me https://github.com/TitsandAsses/CDPInterfaceDescriptions.git

i started this project so I could have generic interface description across all devices so I can easily filter the ones I need in our new monitoring tool (Zabbix, for those interested)

what you need: -Python 3 -pip install netmiko

what it does: -connect with ssh to each of the devices in devices.txt -run show cdp neighbor -give you an overview of the neighbors/interface mapping -option to delete certain entries if they are not needed/wrong

for now it has zero error handling and was tested on 2960s and 3750s any tips or advise on my code are welcome, if you want to contribute even better things i still want to add -LLDP support -Portchannel support -MAC based descriptions -...



Help with Cisco ACL on 4500 Switches

Looking for some quick help with an issue I am tasked with. I am used to our next gen firewall so creating ACL's is not really something I do. But I am tasked with creating some ACL's so a specific vlan can only talk to a few internal ips (one web server over 443 and DNS) It will also be allowed outbound for internet but blocked to all other internal traffic.

Essentially its a guest wired network. What I was hoping to do was create vlan 1200 give it a /64 network then apply an acl to just that network. Is it possible and is there any easy to read guide on this? Reading cisco documentation is not helping me.



Wireless APs and building codes?

Is anyone here versed in building codes (US-IL), particularly how it applies to wireless access points? I'm having a hard time believing our facilities guy saying that it's illegal to install an AP on the ceiling because it's an electrical device. Currently most are installed over the ceiling which greatly degrades the signal. TIA



Recently this Huawei equipment was installed on my building and I have no idea what is it. Can you identify this please, any ideas welcomed. Thank you very much



Cisco CUCM - Video Rate Issue

We have been having a hell of a problem with Webex lately. We have noticed in our troubleshooting that the video conferencing systems have been negotiating a 500kb rate instead of the configured 6000 that it should be using.

System version: 11.5.1.11900-26

We have checked Pipes and Bandwidth and neither of those are configured to rate limit anything.

We have escalated really high with Cisco, but they still can't find the cause. We can reproduce it, but no one seems to know why.

We use different room kits minis where it shows a troubleshooting screen and proved the room kits were only using 500k.

Anyone seen this issue before? If more details are needed I will submit, this stuff is not my strong suit.



Logging List issue on ASA

Hello.

I'm having an issue getting the logs set up the way I would like on an ASA 5515 on 9.6.4

I'm trying to send the syslogs to an Alienvault server for monitoring. However, a few events are quickly consuming our allowed monthly resources.

Stuff like %ASA-4-419002: Duplicate TCP SYN from inside:192.168.x.x/xxxxx to inside:192.168.x.x/xxxxx with different initial sequence number

This is engineering software that nobody understands, including the engineers. This makes me hesitant to think I could resolve this actual issue in a timely manner (I will pursue it later) but for the time being, I would like to keep it out of our logs. There are a few others like this as well. So I would like to just exclude this message from being sent to our syslog server (The Alienvault).

So in the ASDM, I went through the steps, I created a new syslog server, then went to logging filters and created a new one for syslogs filter. Made a new logging list to attach to that which I assumed? was how you can filter out logs you don't want to that host?

In the event list, I think this is where I might be going wrong? I have it set to all/notifications for severity and then put a list of events in the other side. Basicall 100000-419001 and then 419003-999999 (or whatever the max was). This to me means it should exclude 419002 but did I set it up to ONLY grab those notifications i'm trying to skip?

This is how the list actually looks in the console

logging list Syslog-Event-List level notifications logging list Syslog-Event-List message 101001-419001 logging list Syslog-Event-List message 419003-434001 logging list Syslog-Event-List message 434003-746015 logging list Syslog-Event-List message 746017-800000

So again, my goal is to exclude 419002. What am I doing wrong in this situation?

Thank you for any help!! Appreciated!



I can't understand where is sliding window flow control is used (transport or data link layer)

Hi, I have been trying to understand flow control for almost 12 hours, the information needed for window sliding flow control is stored in the segment at the transport layer, yet whenever I come across sliding window in resources it's explained under data link layer, I don't understand how the information is stored at transport layer but the implementation is at data link layer.

I would appreciate the help, if you can explain to me in detail i would be grateful, otherwise, just providing me with a good resources that explains them well would do.

I have an interview tomorrow and I need to understand TCP flow control very well.

Resources I used trying to understand:

Data and computer communications - book.

Introduction to computer networks and cyber security - book.

Google(Geeksforgeeks and others).

Youtube.

And this is the ABSOLUTE best resource I came across about the subject, thanks for whoever made it:here!

Edit: formatting & added a link.



Fortinet VM + vCloud & NSX

I’m newer in Fortinet and I have the opportunity to deploy Fortinet vm on my customer vdc based on VMware vCloud and nsx...I tried to find official documentation about the compatibility matrix but I don’t find a lot of docs only this https://www.fortinet.com/content/dam/fortinet/assets/solution-guides/SB-Fortinet-VMware-NFV.pdf

My customer want official documentation about the compatibility between Fortinet versions and vCloud before start

Thank A.



Network Speed Issue

Quick bit of background. Joined this company 3 months ago. Network is a mess and overly complex for the size. Our internet periodically goes extremely slow (1mbps down 0.2up) however it should be 100/20.

Checking the firewall there seems to be no issue with Bandwith and pings to Google DNS (8.8.8.8) are 1ms however, from our PC's it's over 1000ms.

Pings internally are okay between our devices and 3 switches however two out of the 3 also have the delay on pings to google.

Switches are Cisco and the subnet is 192.168.2.0/23

Any help would be appreciated.

Thanks



Cisco 1113P

Has anyone had any experience of using the 1113P? Particularly around the DSL modem, based on the specs it says it supports G.Fast, VDSL AND ADSL?

I can see this on the specs but it's not very clear. Basically looking at these devices for a wide spectrum replacement for the 897VA covering our xDSL, G.Fast and FTTP, it seems too good to be true!



Narrow Band IoT network Application layer protocols

I am working on project where I have Arduino with NB-IoT shield. I have http REST API configured. Should I program Arduino so that it directly sends http request to the server through NBiot or there should be some intermediate server of NBiot provider where I configure REST API server address?



Expand a VPLS Alcatel

Actual I have this vpls working fine...I can ping from customer A to customer B.... but know I would like to make bigger,

and decide to add a new site.

https://ibb.co/GTkswYy

1-To add this new site I will have to create a SDP for this site ? and do the mesh of this SDP ?and about the far-end could someone explain please, because now with two sites, one is the far-end of the other...

2- After I am think about to create new subnets for the all 3 sites, so I will need to create just new SAP and dot1q right ?

3- The last one :), after I was think to permit this sites to access the internet,so I will have to use Ies,anyone could share a example of config ?please..

thanks a lot



Monday, July 8, 2019

Hardware Choice for Home and or Business

I am a curious person and I am into networking and I was wondering what type of networking equipment you use at home and or work, and what made you go with that hardware.

For example: I have a UniFi setup with a USG, Switch 8, and AC-LR. The reason I went with this is because I read good reviews of it and it has an enterprise like setup with multiple SSIDs and VLANs which most homes probably don't have unless they into networking and or computers.



Creating a SSH/Telnet utility?

Hi, I would like to ask if possible to create a SSH utility. In where user can input just a hostname then translate to IP address using our internal tool then remote to the device?

Example:

rtr01 is equivalent to 1.1.1.1 recorded on our internal tool.

Target script: (to create a utility for example gossh)

user will just input 'gossh rtr01' and script will get the managed ip(our internal tool) and proceed in remoting and use the local user acct. in linux.

then the script will do this,

  1. get the mgmt ip of rtr01 using this command get rtr01 | grep IP
  2. then proceed in connecting 'ssh <localuser>@<x.x.x.x>'

Is this possible? should I do it on bash or in allias?

Thanks



best way to handle many wifi connections in a small or medium office environment?

Hello, I'm not that knowledgeable, would I be correct in believing that rather than a a single wireless router, what would be needed in this case would be like an ethernet router connected via ethernet to various wireless Access Points placed throughout an office and this would allow many wifi connections? Does the number of these connections increase with each Access Point placed or is it limited by the router itself ? Also what exactly is a mesh network? Does it let you switch seamlessly from one network to another or something like that ?



IPsec Redundancy

Does anyone know how to implement high avaliability for a pair ISRs that are going to be used to terminate VPNs ?



How to use IPv6 tunnel in EnGenius ESR600 router?

I'm using the Hurricane Electric Tunnelbroker service, I want to add their IPv6 tunnel to my EnGenius router - but all I get is "No Internet access" for my "IPv6 Connectivity" when I disable the IPv4 protocol in Widows.

I entered the info on IPv6 tunnel endpoints that I got from Tunnelbroker into my router settings for "Static IPv6":

  • "Server IPv6 address" as "IPv6 address"
  • "Client IPv6 address" as "Default gateway"
  • "Routed /64" as "LAN IPv6 address"
  • "Googles IPv6 DNS" as "Primary and Secondary DNS"

I'm using SLAAC+RDNSS, but I haven't setup anything on the Tunnelbroker site, is that a requirement - or should it work with the IPv6 DNS from Google?

What am I doing wrong? I appreciate any help I can get!



POST to ERS for ISE with JSON

Hey guys,

having some trouble. I am working on a script to automate Network Device and Network Device Groups creations using python with the requests module. I am trying to do this with using JSON to push the actually code to the ISE API. I am able to get a list of devices and device groups, as well as delete them, but when I use JSON in the requests.posts to actually create one, I usually get a 401 error... It makes no sense knowing that I can use this same account to delete and get using requests.get/delete.

Here is an example of my code:

import requests

import requests.auth

import getpass

import json

Username = input("Enter API Username:")

Password = getpass.getpass("Enter API Password:")

headers = {'Content-Type': 'application/json', 'Accept': 'application/json'}

ISE = requests.post("https://x.x.x.x:9060/ers/config/networkdevicegroup", verify=False, auth=(Username, Password), headers=headers, json={

"NetworkDeviceGroup" : {

"id" : "123456789",

"name" : "ERS Group",

"description" : "TEST ERS",

"othername" : "TEST"

}

})

print(ISE.status_code)

print(ISE.text)

I have even tried putting the json code into a variable and passing it that way and no luck..

If I try enough times it will get the 401 error, but if i recreate the ERS admin user and do it for the first time I get the following:

400

{

"ERSResponse" : {

"operation" : "POST-create-networkdevicegroup",

"messages" : [ {

"title" : "Validation Error - Illeagal values: [The name should have at least type and name, delimited by pound sign, The name's first part (before the first pound sign delimiter) should be equal to group's type provided.]",

"type" : "ERROR",

"code" : "Application resource validation exception"

} ],

"link" : {

"rel" : "related",

"href" : "https://x.x.x.x9060/ers/config/networkdevicegroup",

"type" : "application/xml"

}

}

}

Any help or suggestions would be highly appreciated.



CCIE Lab in Tokyo

Hey all,

Has anyone taken the CCIE Lab in Tokyo? I'm currently living in Japan and I don't have much of a choice but to take it in Tokyo. Do you all know how they keyboards are like there? Is it Japanese style keyboards? I've heard that the layout is a little different. So it might be of my best interest to pick up a Japanese keyboard and start practicing with that if thats the case.

Thanks



Port Forwarding Errors

Hey

I am tyring to open some ports on my router but when i check the ports it is all closed.

Everything worked fine until i added a second router in bridged mode to my network

Can anyone help

Thanks

Main Router - NF18AC



Ubuntu 16.04LTS DHCP Server issue

Been stuck on this issue for quite some time now and unsure how to fix this. Would there be a way to fix this? /etc/dhcp/dhcpd.conf: interface name too long (is 20)

  • /etc/default/isc-dhcp-server File:

# Defaults for isc-dhcp-server initscript # sourced by /etc/init.d/isc-dhcp-server # installed at /etc/default/isc-dhcp-server by the maintainer scripts # # This is a POSIX shell fragment # # Path to dhcpd's config file (default: /etc/dhcp/dhcpd.conf). #DHCPD_CONF=/etc/dhcp/dhcpd.conf # Path to dhcpd's PID file (default: /var/run/dhcpd.pid). #DHCPD_PID=/var/run/dhcpd.pid # Additional options to start dhcpd with. # Don't use options -cf or -pf here; use DHCPD_CONF/ DHCPD_PID instead #OPTIONS="" # On what interfaces should the DHCP server (dhcpd) serve DHCP requests? # Separate multiple interfaces with spaces, e.g. "eth0 eth1". INTERFACES="mgmt" 
  • /etc/dhcp/dhcp.conf File: (Note: Changed my DNS/Domain name here, but inputted my real one on my own config file)

ddns-update-style none; option domain-name "(MyDomainName.com)"; option domain-name-servers (DNS ADDRESS), (DNS ADDRESS); default-lease-time 600; max-lease-time 7200; authoritative; # Use this to send dhcp log messages to a different log file (you also # have to hack syslog.conf to complete the redirection). log-facility local7; # A slightly different configuration for an internal subnet. subnet 172.16.1.0 netmask 255.255.255.0 { range 172.16.1.10 172.16.1.50; option domain-name-servers (DNS ADDRESS), (DNS ADDRESS); option domain-name "(MYDomainNme.com)"; option subnet-mask 255.255.255.0; option routers 172.16.1.1; option broadcast-address 172.16.1.255; default-lease-time 600; max-lease-time 7200; } 
  • Restart/Status of DHCP

root@ubuntu:/# systemctl restart isc-dhcp-server.service root@ubuntu:/# systemctl status isc-dhcp-server.service ● isc-dhcp-server.service - ISC DHCP IPv4 server Loaded: loaded (/lib/systemd/system/isc-dhcp-server.service; enabled; vendor Active: failed (Result: exit-code) since Tue 2019-07-09 16:36:12 CST; 7s ago Docs: man:dhcpd(8) Process: 4079 ExecStart=/bin/sh -ec CONFIG_FILE=/etc/dhcp/dhcpd.conf; Main PID: 4079 (code=exited, status=1/FAILURE) Jul 09 16:36:12 ubuntu sh[4079]: Not configured to listen on any interfaces! Jul 09 16:36:12 ubuntu sh[4079]: If you think you have received this message due Jul 09 16:36:12 ubuntu sh[4079]: than a configuration issue please read the sect Jul 09 16:36:12 ubuntu sh[4079]: bugs on either our web page at www.isc.org or i Jul 09 16:36:12 ubuntu sh[4079]: before submitting a bug. These pages explain t Jul 09 16:36:12 ubuntu sh[4079]: process and the information we find helpful for Jul 09 16:36:12 ubuntu sh[4079]: exiting. Jul 09 16:36:12 ubuntu systemd[1]: isc-dhcp-server.service: Main process exited, Jul 09 16:36:12 ubuntu systemd[1]: isc-dhcp-server.service: Unit entered failed Jul 09 16:36:12 ubuntu systemd[1]: isc-dhcp-server.service: Failed with result ' 
  • Interface File

# The primary network interface auto mgmt iface mgmt inet static address 192.168.1.4 netmask 255.255.255.0 gateway 192.168.1.1 


IPSEC Redundancy

Hello all, does anyone know what the main difference between IPSEC VPN High availability with HSRP, or Interchassis High Availability is, when it comes to providing HA for a pair of VPN Headends (CISCO ROUTERS).



Can you use patch panels as joints in the physical network and is it good practise or not?

Having done simple network cable installs in the past, I find myself in a situation where my experience level is a little lacking. I'm upgrading the offices of a small air charter company (I'm one of the owner pilots) and the building is an old world war 2 RAF station so it's full of twists and turns and was never built with modern cabling requirements in mind. We are also limited in where we can make holes in walls, etc.

I am working with CAT 6A U/FTP solid and CAT6A S/FTP patch cable. Now as many of you will know, CAT 6A U/FTP is probably one of the most unbendable wires I've ever come across and I can see that trying to twist it through some of the bends and turns it is going to have to make is going to be a nightmare. I don't have the option to use more flexible cable like CAT5E due to tenancy restrictions.

Now in the past, I've only ever run structured network cabling in one continuous run from the port on the patch panel in the data cabinet where the switch resides to the keystone connector or RJ45 adaptor in the wall socket with no breaks in between. I really do not think this is going to be possible in this situation, some of the bends are going to be 90 degrees or more. To that end, can I run the cables between patch panels so they act as something akin to a 90 degree bend mechanism? If so, how detrimental is this likely to be to network speed (The longest run is 50 meters at most but most much less than that). Is there a better or more suitable component than a patch panel for negotiating these types of issues? I've googled but either my google fu is weak or I've not found it.

Many thanks for any assistance anyone can render.



Fuji or Everest? - ISR 4331

I'm trying to figure out whether we should upgrade all of our ISR 4331's to Fuji 16.09.03 or Everest 16.06.06.

The current IOS version on the 4331's is 15.5(3)S6. The current ROMMON version is 16.7(3r)

I've upgraded a lab 4331 directly to Everest 16.06.06 and it appears to be working fine. If I wanted to upgrade to Fuji 16.09.03, I would also need to upgrade the ROMMON in order to get Fuji to work.

Looking at this from a maintenance stand point, Everest seems to be the answer because it has one less step. Are there any significant feature sets in Fuji or Everest that differentiates the two? Is one of them more buggy than the other, in your experience? We will be upgrading about 30+ of them, so I want to make sure we take the right track.



"Enable Connectivity Monitor and Wireless Uplink" feature in UniFi causes bridging loops

I recently had the privilege of upgrading the office LAN at the small startup where I work from a hodgepodge of unmanaged switches to Cisco 2960s. We had been noting degraded performance and switches crashing for a number of weeks, and had been unable to rectify the issue.

When I upgraded the switches, I began seeing alerts from the STP system indicating bridge loops. After going through devices one-by-one at a downstream (still unmanaged) switch I was able to trace it to the UniFi access points.

There is a very misleadingly named option in the UniFi web UI: "Enable Connectivity Monitor and Wireless Uplink". The "Wireless Uplink" feature is what ended up failing us, by incorrectly determining that the uplink was malfunctioning, therefore creating a virtual bridge for all LAN traffic between the two APs.

Upon disabling this feature, all bridging loops disappeared and the network behaved normally.

Thanks Ubiquiti!



help finding a rugged cellular firewall/router with 8 ethernet ports

basically as the title suggests im going to be sticking some network gear in some pretty harsh/isolated environments, and i am trying to get the following features out of ONE Piece of hardware, I might settle for two (router + managed switch) .

  • Need Cellular with DUAL SIM (ATT/VERIZON)
  • Need VLAN support (obviously)
  • Need multiple DHCP Scopes support
  • Need VPN Support (IPSec, OVPN, GRE would be nice!)
  • Need an option for an ETHERNET WAN Port
  • Would LIKE to have 8 LAN ports (this can be deleted if needed and just add a switch + trunk to my purchase)

We already use cradlepoint but we only deploy it in an IP Passthrough type scenario to a meraki mx gateway, i know it has a ton of features, but i haven't really dug deep into the CP yet.

Solutions im currently looking at:

  • Cradlepoint COR IBR900 + Managed switch, this would probably be my go to, but i havent had to use any of the networking features of the cradlepoint yet, strictly IP Passthrough, would love input on this side!
  • C819HG-LTE-MNA-K9 + Managed switch, this looks good, but has anyone had much experience with using a firewall on these ? i currently deploy ISR4331's but just strictly as ROUTERS. Would love some real world input on securing these from a cellular perspective (with a dedicated static public ip address)
  • MOXA OnCell G3470A-LTE Series + Managed switch, Ive used moxa in some industrial spaces strictly as routers, would love some real world feedback if any exists on this sub reddit ?
  • God i would love for a rugged meraki with cellular built in so i could just deploy AutoVPN and be done, does anyone know if there is a roadmap for rugged?

I am open to any and all suggestions, thanks for the input ahead of time!.

-DR



Suggestions for DHCP server appliance that supports option82 leases?

So it turns out that the builtin DHCP server in Comware5 products is lacking the ability to hand out (lease) IP addresses based on option82 info.

Which means that I need some additional box for those sites to do this magic.

At first I was thinking of getting 1 (or 2 for redundancy) raspberry pi's with raspbian to use ISC DHCP, the drawback with this is that it takes some effort to get it as you want it to be specially if a less technical person are about to setup this.

That is I would prefer something like a "cisco" image + single conf-file ("startup-config") and thats it.

I have been digging through Google for options but most "DHCP server appliances" I have stumbled upon are just shitty so using the original idea of raspian would be less work to setup from scratch.

Any of you who might have some ideas other than raspbian that could deal with this scenario?

I was looking at https://zeroshell.org/ but that too went into the case of being way more work than just use raspbian.

Another thing I was considering was some ubiquity edgerouter but Im not sure if their builtin DHCP server will fully support leases based on option82 (anyone who have tested?).

My demands are simply:

  • DHCP server that can hand out leases based on option82 info.

  • One way or another rackmountable.

  • No EOL products, must have active updates - preferly without additional cost.

  • Easy to setup new devices/sites as in firmware + single conf without having to edit zillions of conf-files manually (think "cisco" firmware + running-config style).

  • And no cost (other than the hardware it will be runned on either some slim x86 or preferly raspberry pi or similar).

  • Also reliable would be nice since having the DHCP server available will be a single point of failure (if DHCP server goes poff and clients reboots they wont figure out which IP to use).

  • Bonus would be if the same DHCP server also supports DHCP6 and DHCP6-PD (because then I could remove the current DHCP6 config in the Comware5 devices and do everything from this single (per site, or 2 in a failover setup) DHCP server).

  • And then of course SSH, logging, syncing with external NTP etc.