Wednesday, February 7, 2018

Does such a thing as as wireless switch exist?

So a hub has wired connections. When it receives something on one connection, it sends it to all other connections. A switch only sends something to it's intended destination.

A WAP is like a hub in the sense that everyone connected to it is on the same medium, so when a WAP receives something it sends it to all others, like a hub.

I was wondering, does there exist a switch that instead of clients connecting via Ethernet, they instead connect via different wireless channels. So that it's as if they have their own connection to the switch and the switch can send data only to the intended receiver.

Just wondering if something like this exists, I understand this doesn't really improve security or anything like that.



Cisco ASA vulnerability

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1#fixed

Looks like the previous fixed code of the ASA still has some security holes in it. :)



Does CAT6 cabling differ in quality?

Setting aside obvious cable standards such as Cat6a, and the type of cable UTP, STP, etc, I’m curious as to whether the quality of Cat6 can differ and in what way?

I’ve purchased some fairly cheap CAT6 UTP at 100m for 60 AUD, looking at electrical wholesalers it seems most of them charge around double this for around the same length and cable type - what am I missing out on going the cheaper cable? is there any reason not to go the cheaper one?

For reference the brand of cable is Anyware.

Let me know guys!



Why switchport port-security maximum should be enabled?

What good arguments can be used to convince a manager to activate this feature?

What is you have many sites already using cheap consumer grade switches connected to an access port. Activating this port security feature would disconnect them, so why should I activate this feature if it's going to cause some trouble for them?



Regular expression in Cisco Prime (3.3)

Hello!

Question in regards to Cisco Prime's Configuration Validation.

Fairly new user to Cisco Prime, as I have previously been using Nessus for auditing our networking devices for config validation.

I'm having trouble with figuring out how to properly make Regex work with building out a custom configuration audit policy/rule.

Currently, I have created a policy, and am adding a rule. For this particular one, I want to ensure that the enable password is encrypted.

What I have set:

  • Scope: Execution
  • Data Type: String
  • Input Required (Unchecked)
  • Is List of Values (Unchecked)
  • Accept Multiple Inputs (Unchecked)
  • Default Values: Blank
  • Max Length: Blank

For "Valid RegExp", I tried the following:

enable secret [^ ] enable secret [4|5] enable secret 4|5 

When I click preview, I get "Invalid Regular Expression".

Any help would be greatly appreciated.



Is it possible to pull wifi signal to a router to create an IDF so I can Ethernet wire everything?

Wherever the MDF is, it's not running an Ethernet line down to this strange basement area I'm working in. Currently, this business wants to use a netgear AC1750 router to supply a connection to all the switches. Is this even possible? The wifi connection is good enough, but how would I configure this wireless access point to act as this?

Seems nuts, but just because I haven't done this before. This is the basement of some school built in 1937.



Catalyst 3850 stack addition Q

This is probably a simple question, but I couldn't find a definitive yes or no (probably because it's assumed), and I haven't worked on a cisco stack in ages.

I have a 4 switch stack of 3850s. I need to add another switch. The data and power (stacked power) cables are connected as follows:

1-2

2-3

3-4

4-1

My understanding is that this is a full duplex stack because it's looped back. And show switch stack-ring speed verifies this.

Can I safely disconnect the cables (data and stacked power both) between switch 4 and 1 (break the ring), to bring in switch 5? It should just go into a half-duplex type condition where bandwidth drops and lose shared power but nothing goes offline. Right? As long as the switch is powered off when I connect it, I can then power it on and it will auto upgrade/downgrade to the correct version when added to the stack?

Is there any advantage to pre-provisioning it with the switch number it will have after addition to stack? Is there any need to do any configuration of the switch at all beforehand?

Thanks!



Chassis vs Stacks in IDFs

We typically do loaded 2 post racks with Cat 3k's in 4 or 6 member stacks. We used to do 2' cables and Neat Patches but lately have been doing 6" cables with no organizers (more dense, works pretty well, very easy to trace when vetting documentation). It get us about 6 switches per rack, 100% patched. There's an idea to do chassis based switches in the IDFs now (Cat9400) and I'm interested in hearing from folks on the contrast between the two. Seems like a lot of cables but we can always hire someone to do that. Which do you like more and why? If going chassis, what are some things to keep in mind or avoid?



Looking at NCCM

We recently went into a merger and we now have around 300 sites to manage with about 30k end users. Boss man seems to "finally" understand that we are a big shop now and says that we have budget for enterprise level tools.

The network is made up of different vendors (Cisco, Brocade, HP, etc.)

What do you guys recommend for NCCM (Network configuration and change management)?

In the past I've used Cisco Prime Infrastructure and liked it but that's not multi vendor better tools are possibly be out there.

I know of SolarWinds and ManageEngine solutions but I've been out of the loop since we never had the funds for these types of solutions.

What is out there and what do you recommend?



Cisco 7600 VPLS Configuration Help

At my shop we're trying to setup VPLS on our Cisco 7600 series (Yes they are EOL as fuck but support is still good and cheap spare parts are aplenty). We use OSPF for our MPLS core and already just do straight L2 xconnects so VPLS didn't seem that far off of a dream. Unfortunately that dream has seemed to died.

I'm setting up between three 7600's to create this tunnel with the following:

7600 1.1.1.1 l2 vfi Phones manual vpn id 231 neighbor 1.1.1.3 encapsulation mpls neighbor 1.1.1.6 encapsulation mpls 

7600 1.1.1.6 l2 vfi Phones manual vpn id 231 neighbor 1.1.1.3 encapsulation mpls neighbor 1.1.1.1 encapsulation mpls

7600 1.1.1.3 l2 vfi Phones manual vpn id 231 neighbor 1.1.1.1 encapsulation mpls neighbor 1.1.1.6 encapsulation mpls 

On each 7600 we have this in the interface VLAN config:

interface Vlan231 description Phones no ip address xconnect vfi Phones end 

Then we trunk that out to the ports needed as a standard VLAN. The Xconnect comes up and everything shows fine that I can diag.

1.1.1.1_7609#show mpls l2transport vc 231 Local intf Local circuit Dest address VC ID Status ------------ -------------------- --------------- ---------- ---------- VFI Phones VFI 1.1.1.3 231 UP VFI Phones VFI 1.1.1.6 231 UP 1.1.1.1_7609#show vfi name Phones Legend: RT=Route-target, S=Split-horizon, Y=Yes, N=No VFI name: Phones_DVS, state: up, type: multipoint VPN ID: 231 Local attachment circuits: Vlan231 Neighbors connected via pseudowires: Peer Address VC ID S 1.1.1.3 231 Y 1.1.1.6 231 Y 

Now on the switches at each location, we've tried running a ping between but getting failures. Also if I throw a VLAN on the int vlan on two of the 7600's, it fails to reach the other 7600.

Any ideas and suggestions would be appreciated, thank you!