Sunday, November 26, 2017

Fiber Termination DIY?

We have run some fiber through our business. These are all shorter runs of OM4 (300 ft-ish is the max) probably going to LC connectors. I got a quote to terminate the 96 ends for about $5k. I also checked with my local cable supplier and they can supply me pre polished connectors, and will rent me a kit (which includes a DC-30 cleaver) for $1250 give or take. They will give a quick training as well.

My question is, is DIY okay here? Never done terminations myself but watched a bunch of youtube vidoes. Seems like a quality cleaver is also a big part of the job and the DC-30 looks to be a quality cleaver that I can rent.

And I'm waiting for another quote to come in. I'm not sure if that $5k is a high quote.



Can I do L3 Port-Channel on 4500X?

Can I do this on Cisco 4500X-32 switch? Does it support layer3 port channels?

interface range Te1/1 - 2 no switchport channel-group 1 mode on no ip address no shutdown ! interface Po1 no shutdown no switchport ip address 1.1.1.1 255.255.255.252 


How to be a certified network cabling installer?

Hello!

My internship IT Networking department wants to take a training in being a Certified Network Cabling Installer (BISCI And/Or CNCI). We want to take our patching skills to a whole new level like those pictures you see at /r/cableporn. Where can we take training in the Netherlands?



New Enterprise Network Vendor

Hi, i am currently renew our Company Network and need your Help. Our current Network Hardware is from Huawei and my Goal is to change it to Juniper. But i need a comparative offer for the Juniper Hardware. Juniper Hardware is: - Juniper EX 4600 for the Optical Fiber Aggregiation Switch - Juniper EX3400 for Access and MGMT Switch But what is the equivalent at the Huawei Switches? CE6851-48S6Q-HI and S5720 ? Thanky for our help



Troubleshoot remote side phase 2?

I'm trying to get a tunnel up between a Checkpoint firewall and a ASR. I control the ASR, but I have no visibility into the Checkpoint (and frankly neither does my counterpoint on the other side - they have a contracting company running it).

I get phase 1 complete, but phase 2 fails with:

ISAKMP-ERROR: (1757):IPSec policy invalidated proposal with error 1024 ISAKMP-ERROR: (1757):phase 2 SA policy not acceptable! 

I believe this is probably an ACL mis-match. is there anyway to see what the Checkpoint is sending me for phase 2?

Is there anyway to look at the traffic and make my ACL match the Checkpoint side so that I can prove what is going on?

Thanks!



Designing a network

I have to design a network for a school project, I have to ask the client questions what questions could i ask the client?I have questions like backups, software, the network size what other questions could i ask



Best Practices for Managing Network Firewall - Deny All Rule...

Hi,

I always thought that "Deny All" should be at the bottom of the ACL, and all the "allow" exceptions above it. However, I was reading this article - http://ift.tt/2k0k1u0 where the author is advising to "Deny All" First and Then Add Exceptions... (?!)

I always thought if the rules are processed from the top to the bottom, "Deny All" will block everything regardless to what's below it.

Wrong example:

  1. deny ip any host (exchange server ip)
  2. permit tcp any host (exchange server ip) eq 80
  3. permit tcp any host (exchange server ip) eq 443

Correct example:

  1. permit tcp any host (exchange server ip) eq 80
  2. permit tcp any host (exchange server ip) eq 443
  3. deny ip any host (exchange server ip)

According to the article: "You'll most likely want to have a "Deny All" rule as your first firewall rule. This is the most important of the rules and its placement is also crucial... Once you have your "Deny All" rule in place in position #1, you can start to add your allow rules below it to let specific traffic in and out of your network (assuming your firewall processes rules from top to bottom)."

Is this a mistake or I misunderstood something?



What if... Networking was a game?

Hi /r/networking!

A lot of network specialists (and aspirants) have to learn continuously. There are always vendors, systems, and standards, and the rabbit hole runs deep.

Learning and staying fresh with networking almost always benefits from labs. Any lab - be it hardware, virtual machines or tutorial software (think PacketTracer), requires a lot of work to be comprehensive, and to have traffic generated. Let alone a compelling end goal.

Like many IT folks I like games! I know many of them have compelling goals and methods of presenting information. Kerbal and its physics. Anno and its logistics. FTL and its shifting challenges. What if this delivery style was leveraged to make a game for networking?

Your fictional company could have changing user capacity and requirements for access. Your projects and management demands could be tied to your budget for kit, and promotion goals. Learn about real RFCs. Fiddle with switches, routers, firewalls, load balancers, server farms, and third party services (real vendors or fictional). Set up dynamic routing protocols and VoIP brokers. Manipulate web traffic on the fly. Configure SSL VPN and multiple sites. Buy better gear, and get that cool SSO feature! Random events, and security scares! Surprise takeover! Ship all the staff to a hot standby location!

Tl;dr, games are fun. Create a game to make technology learning fun and challenging?



Cisco FirePower/FTD IPS - decryption of traffic?

Can anybody share experience with traffic decryption on IPS? As a best practice is it implemented? I'll place IPS in Internet Edge part of network and it will be as a second filter from different vendor for the main firewall. My question is - do you implemented traffic decryption in such situation? We'll have decryption on several other points - on the web proxy, on the email gateway, on the web application filter. We are looking at the Cisco FirePower/FTD appliances, working in interface pair inline deployment (without changes of L2 or L3).



Help understanding Route Aggregation! using binary, maybe decimal

hello guys, this is my first time posting here. I hope you guys can help me out with understanding route aggregation. My approach at the moment is using binary. So for this problem the third octet is the key. However, i am stuck at that. What are the next steps? and why? I know we should end up with two addresses. Are there any tips or things to look out for? HELP!

The addresses: 192.168.32.0 /23 : 00100000 192.168.34.0 /23 : 00100010 192.168.38.0 /23 : 00100110 192.168.40.0 /23 : 00101000 192.168.42.0 /23 : 00101010 192.168.44.0 /22 : 00101100