Sunday, December 17, 2017

What differentiates the Expert versus the Enthusiast? Have you worked with enthusiasts before? What's the key to becoming the expert?

A soft question but it's been on my mind for a while.

I've worked with people before who have an enthusiast knowledge and attitude, they will learn "just enough" to get the job done and it seems to work most of the time. Sometimes they will ask me questions that make me concerned at their level of knowledge (i.e. a question you would expect a novice to ask, not a senior). I had a chat with a friend about this and he came up with the "Expert versus Enthusiast" idea as he's an Engineer and sees this a fair bit with friends who are Automotive Engineers vs. Automotive Enthusiasts.

Some questions:

  • Has anyone worked with an "Enthusiast" before?

  • How would you say that an Enthusiast differs from an Expert in our industry?

  • What's the key to becoming an "Expert" in the field? Is it a narrow focus on mastering the fundamentals? (TCP/IP for instance)

  • Is the "Just enough" attitude okay if used in moderation? (Learn just enough about say 'Technology X' to get the job done)

My personal question: I sometimes take the expert mentality into all of my pursuits. Which I'm starting to believe is negatively impacting me. I'm starting to think that's it's important to have that expert base of knowledge but to put on the "just enough" hat when dealing with day to day issues and problems. Sometimes you can invest an inordinate amount of time in learning something academically from the ground up, only to realize if you learnt the important parts only (the just enoughs) to get the job done you might never see it again and deeper commitment would have been wasted.

Is IT really a game of knowing the trunk of the knowledge intimately and learning the leaves of knowledge "just enough" to get the job done?

Does anyone have thoughts on this, I'd be curious to hear.



Router doesn't router.

Studying for CCNA. Homelab. Have network setup as so: http://ift.tt/2CNJeN0

EXCEPT - turned R1 into dhcp server on the 10.X/24 network, removing 10.1-10 addresses for gear. Also, removed CiscoNET wireless router and replaced with dual-nic Windows Server machine (hostname:Pingless).

House is a Linksys E1200 running DDWRT in repeater bridge mode connected to our Hughes router down the way. We live in the sticks.

Can ping all switches and router IPs on the .10.X/24 subnet from my laptop connected to House wireless network (.42.X/24). Can also ping all gear from SSH on the Cisco gear.

But can't ping Pingless (now appropriately named!) from House (SSH) or devices connected to House, nor RDP in of course. Any help would be welcome. Can post more info if need.



Mumble server dns issue

I just set up a mumble server at home on my raspberry pi 2. I think I may be having a dns issue. I tried three different ddns services, 2 free ones and one with my own domain being forwarded through Google. Most of my buddies have no issue joining my server with all 3 of the different ddns names but 2 of them cannot. The two that can't are able to join using the IP address but not the domain names that point to the IP address. What could be the issue here? Everything works fine but these two people can't connect with the domain names.



Does a TCP acknowledgment process guarantees that the data has been received by the end user?

No text found

Tool to check for throttling?

With Net Neutrality going down the drain I'd like a GUI tool to test specific protocols and domains for throttling. I can imagine this is fairly difficult as it depends on the server on the end, but must be possible. Anyone know of anything already out there like this?

My imagined use case is to provide push-button testing of connection to Netflix, Youtube, etc to begin collecting data on which ISPs are throttling and what domains/protocols are being affected.



VRF-lite vs ACLs for segmentation of internal campus networks

Hello fellow members of the networking community. I'm hoping to get some ideas on how you all handle segmentation of your campus networks across layer 3 boundaries. At most of our districts, inter-VLAN routing is handled by the firewall, but as more devices are connected to the network and more demands placed on it, I'm looking to route more often, either at the edge of a small building or even down to the IDF in larger buildings. Here's the example segments (VLANs) we have in place.

  • Private. Staff and students, RADIUS authenticated WiFi
  • Guest. PSK authenticated guest WiFi
  • Infrastructure. Access points, switch management, etc.
  • Security cameras
  • VoIP
  • HVAC
  • Door access control

And the differences I see between the two solutions.

VRF-lite

Just like a VLAN is a virtual switch, a VRF I see as a virtual router. Here's the advantages I'm seeing on this solution.

  • Scalable. As I add routers and VLANs to networks, it seems easier to me to add a new VLAN to an existing VRF than to create an ACL for an IP scheme that may or may not change and then change all the existing ACLs to include that new VLAN. Any IP scheme changes that may happen are automatically propagated through the network with OSPF as well.

  • Maintaining separation of device duties. As much as I can, I like to have routers routing, switches switching, and firewalls controlling traffic flow. With VRFs, I can control traffic flow between these segments with the edge firewall, which it is designed to do. I could even run UTM features on traffic flowing from a less trusted zone to a more trusted zone if I so wished.

ACLs on each layer 3 switch

  • More simple. I try to follow the KISS principle when appropriate, and ACLs would certainly solve the problem I have. Adding VRFs into my design would add more complexity that our more junior techs may not be able to solve, and I'm not a fan of designing networks only I can troubleshoot.

  • No support for VRF-lite on Aruba switches. We'd have to break our switch standard to get VRF-lite support, which adds to the learning curve for supporting the network. This isn't so much a budget cost but an operational/support cost that I think is important to consider.



Question about VPN and external access

I run PIA from my personal computer. I have RDP set to answer on a non-standard port. When PIA is active I can still RDP into my computer. Isn't all traffic to/from my computer encrypted via PIA and wouldn't it not respond to forward from the router?

Does PIA create a network inside of the 192.168.x.x network my personal computer is using?



Traffic Padding Systems for Packet Sniffing

I am doing a packet sniffing threat assessment/mitigation plan for one of my uni courses on information assurance. One of my proposed mitigations is a traffic padding system (I have read about them in my CISSP CBK book). I can't find a company who offers a traffic padding off the shelf system, but I need to find a typical price for the project. How should I approach this? The assessment is for a company with about 1000 End-Point devices.



Dual Routers (Am i being silly)

HI All,

I've just had an upgrade to my cable internet connection to 350mbit+ (it peaks around 400mbit).

My second connection is a DSL 35mbit.

My current router only supports up to 250mbit (a Meraki MX64) and uses both broadband connections, general internet connections are routed out over the fast connection whilst the slower connection has several fixed IP addresses allocated to it, which I port forward various ports such as web server, home automation kit etc, and manages all of the Meraki VPN connections to my customers.

I also have a pair of Dell N1524 L3 Lite switches, one of which provides my VLAN’s in the house, and I’d like to keep it that way.

I’ve just taken delivery of a Unifi Edgerouter Pro, which can apparently handle up to Gigabit speed connections, and seems to be working fine on the cable connection.

My question is:

Should I replace the Meraki MX64 with the Unifi router completely?

Or is there any reason, apart from setup being more complex, not to use the Meraki for VPN connections via the DSL and the Unifi for general internet browsing via the cable connection?

My plan would be to setup route commands for the IP addresses for my customer networks on the Dell switch, my only planned usage would be for vpn traffic using the DSL connection.

Look forward to hearing any ideas, or reasons not to do what I am planning.

Thanks in advance



Anyone using Segment Routing?

Curious to know what platform(s) and how/why you are using it. Any experience (MPLS, v6) shared is most welcomed!