Wednesday, February 7, 2018

'Reload in 10' gives erroneous, future time / date for reload

Hey all - I have a weird one for you - hope somebody has seen this before. Thanks in advance!

I found myself logged into a WS-C3560G (12.2(44)SE6) today and when I issue a 'reload in 10', the system informs me it will be reloading but not in 10 minutes as desired - rather 3 weeks and 8 hours and change into the future. I've included the commands issued, system response and relevant config.

I issue a 'sh clock' immediately before issuing 'reload in 10' to provide the current time to compare with the system's response to the reload command.

hostname# sh clock 15:53:45.383 CST Wed Feb 7 2018 

hostname# reload in 10 Reload scheduled for 23:10:44 CST Wed Feb 28 2018 (in 511 hours and 16 minutes) by redacted on vty0 (ip.ip.ip.ip) Proceed with reload? [confirm] hostname# reload cancel hostname# 

I have the clock and ntp configs and below we see that ntp is synched

hostname# sh run | i clock clock timezone CST -6 clock summer-time CDT recurring 3 Sun Mar 2:00 2 Sun Nov 2:00 

hostname# sh run | i ntp ntp source VlanBB ntp server ip.ip.ip.ip prefer ntp server ip.ip.ip.ip ntp server ip.ip.ip.ip 

hostname# sh ntp stat Clock is synchronized, stratum 2, reference is ip.ip.ip.ip. nominal freq is 119.2092 Hz, actual freq is 119.2079 Hz, precision is 2**18 reference time is DE25F281.95274A75 (15:57:26.582 CST Wed Feb 7 2018) clock offset is 9.4973 msec, root delay is 85.33 msec root dispersion is 41.31 msec, peer dispersion is 31.33 msec 


Setting up an IPSec(?) VPN for a Small Business

I work for a brick-and-mortar store as a technician and I've been attempting to setup a roaming VPN for a small business on-site.

The gateway is a D-Link DSR-500AC (one of the only gateways/routers that matched all the criteria he required that we sell). I followed this guide to set it up (with increases in the security algorithms): http://files.dlink.com.au/Products/DSR-500AC/REV_A/SetupGuides/How_to_setup_L2TP_VPN_Service_in_DSR-1000AC_500AC.pdf

I have the L2TP/IPSec server VPN setup. The only way I could get it to connect correctly was to set an L2TP secret AND an IPSec pre-shared key, with a username and password. The guide above mentions not using an L2TP secret. Windows' native client only allows setting the IPSec pre-shared key. So the first question: What's the difference between the two keys/secrets? Everything I can find online only ever implements one or the other, not both.

As of yet it works fine on Android's native client over LTE. On WiFi, it only worked once I enabled L2TP and IPSec pass through on my home router. So the second question: Is there any way to deal with the pass through issue for the employees that will undoubtedly not have VPN pass through on their home routers?

Thanks guys!



Network Tap Software

I'm looking into mirroring some ports on our LAN and hoping to keep about 1 week of pcaps. I know of Bro, but what other software are people using for this? Is this common?

Bonus feature would be to replay some PCAPs.

EDIT - to clarify, this would a continuously running service that would ingest 4-6 port mirrors and keep the packets on disk.



[Educational] Looking for some guidance on a semester long Networking Project with a Deliverable

Good Afternoon r/networking,

I have been offered an outside studies class by one of my faculty members for my MIS program. My interests, and his, lie in networking and cyber security.

The project is mostly research based but does require a deliverable. The deliverable doesn't have to be a unique or even new idea. The deliverable should demonstrate a semester (4 months) worth of research and work. For example, a deliverable could be submitting a paper to network world, regardless if they run it.

The purpose of this post is too get some ideas on where the future of Enterprise networking and enterprise network security are heading (e.g. SDN). I will do the research, I'm just looking for topics to research, and to see if anyone has ideas for a deliverable (logical model, submitted paper, demonstration via software etc).

I’m currently researching SDN and its security value for IOT and trying to think how I could demonstrate it.

So, does anyone have any ideas on good research topics or potential deliverables? Thank you all.



IPSec Site-to-Site tunnel issues between Europe and China

Since several months we have continues IPSec VPN issue with our Site-to-Site tunnels between our China and Europe sites via Internet. IKE traffic sent by some Europe sites is never arriving at the China site. All other traffic is arriving as usual.

Our china contact told us some of our public address spaces are on a kind of blacklist. We solved this by switching our public address spaces used for the tunnel establishment with our china sites on some important Europe sites. This works for now, but this might change ...

I spoke with some other colleagues i know from work. Most of them have the same behavior except those who are using MPLS lines to connect to Europe.

I heard that there is a way to "register" a company vpn to the chinese government in order to get not blocked by the great firewall. But i was not able to get any details yet.

You are/were faced with the same situation? How you solved it?



Anyone know what is going on with Meraki MR33s?

Over 2 months ago, we had all of our MR33s suddenly disconnect from the cloud controller and never connect back up no matter what we did. All other models worked fine on the network.

After over a month of being down, they finally released a beta firmware just for our MR33s and had us beta test for a week or two. Now they say that they'll roll the fixes into a general release, but it's been over a week since then.

Does anyone actually know wtf is going on? My rep is not helpful at all and support is giving me the ole run around about engineering not telling them anything. Hopefully someone with insider info can chime in.



Cisco AnyConnect filtering?

Hello all. Pardon my lack of knowledge in this department. We currently use Cisco Anyconnect (3.1.12020) for roughly 50 of our end users. We are trying to find ways to further lock it down to a device level. By this I mean, we really only want users connecting with it back to us via our devices, not their personal ones such as a home computer. Is there a way to do this? I am more or less asking on behalf of our Network Admin since he will be the one to make such changes but I thought I would get some advice from you guys!

Again, pardon my lack of knowledge in this area!



Motorola 7550 Modem/Router Woes

Howdy,

I've had two techs out in two days to investigate the issues we've been having with our home cable internet connection. The first tech removed some old amplifiers and splitters from years ago and that didn't fix anything. The tech that came out today didn't see any issues with downstream, upstream or SN ratio either from the drop or the modem.

However, as soon as they leave, this stuff starts right back up and it's super annoying, especially when you're trying to get homework done online!

I've tried to google the logs from my modem, which are annoyingly truncated and not showing the full message for each event, however, there seems to definitely be an issue. If anyone with experience with cable DOCSIS codes or just a general idea of what any of this means, that would be great to understand it. This is an example of the pattern that occurs a few times an hour. ============================================================ Tue Feb 06 17:12:23 2018 Error (4) Missing BP Configuration Setting TLV Type: 17.9;CM- MAC=00:40... Tue Feb 06 17:55:44 2018 Critical (3) Started Unicast Maintenance Ranging - No Response received -... Tue Feb 06 17:56:17 2018 Critical (3) Received Response to Broadcast Maintenance Request, But no U... Tue Feb 06 17:56:28 2018 Notice (6) Overriding MDD IP initialization parameters; IP provisioning... Tue Feb 06 17:56:36 2018 Error (4) Missing BP Configuration Setting TLV Type: 17.8;CM MAC=00:40... Tue Feb 06 17:56:36 2018 Error (4) Missing BP Configuration Setting TLV Type: 17.9;CM-MAC=00:40...

Other info: Ch LockStatus Mod CID Freq Pwr SNR Corrected Uncorrected 1 Locked QAM256 16 549.0 -6.2 39.6 0 0 2 Locked QAM256 10 513.0 -5.8 39.7 0 0 3 Locked QAM256 11 519.0 -5.9 39.7 0 0 4 Locked QAM256 12 525.0 -5.8 39.8 0 0 5 Locked QAM256 13 531.0 -6.0 39.7 0 0 6 Locked QAM256 14 537.0 -6.0 39.7 0 0 7 Locked QAM256 15 543.0 -6.1 39.7 0 0 8 Locked QAM256 9 507.0 -5.8 36.2 0 0 9 Locked QAM256 17 555.0 -6.3 39.5 0 0 10 Locked QAM256 18 561.0 -6.3 39.6 0 0 11 Locked QAM256 19 567.0 -6.3 39.6 0 0 12 Locked QAM256 20 573.0 -6.3 39.6 0 0 13 Locked QAM256 21 579.0 -6.3 39.6 0 0 14 Locked QAM256 22 585.0 -6.1 39.7 0 0 15 Locked QAM256 23 591.0 -6.1 39.7 0 0 16 Locked QAM256 24 597.0 -5.8 39.8 0 0 

Total 0 0

Ch LockStat ChanType CID SymbRate Freq. (MHz) Pwr (dBmV) 1 Locked ATDMA 3 5120 30.4 44.0 2 Locked ATDMA 2 5120 24.0 44.0 3 Locked TDMA 1 2560 19.2 42.8 4 Locked ATDMA 4 5120 36.8 44.8 


How deep should a Network Architect go into knowing a specific product or technology

In my view as network architect you need to understand the principles and you have to be able to create high level designs/architectures that will map business requirements to network functions. Then the design is refined by an engineer.

These days the network devices are quite complex they are capable of working with lots of technologies, some open standard some vendor specific, each vendor implementation of the above coming with its own limitations or specifics.

How deep does an architect need to know vendor products in order to be able to do proper high level designs. Let's not forget that most of the cases the companies become vendor shops and they stick with one vendor for most of the technologies they use (Ex: Juniper, Arista, HP etc). Do you need to know CLI and hardware specifics? Do you need to know about capacity limitations? What would you focus your learning on if you would hold such a position in your company?



Hi-Freq Trading/Financial Networks and Careers. Thoughts?

For some time I've been considering shifting from MSP to the Financial side (High-Freq/Low Latency). The opportunity may present itself and I need to make a quick decision at this point. I feel like I am diving into the unknown and may seriously regret the decision if I take it.

What can I expect? How stressful and hectic is the work environment? Is it a wise choice for progressing my career? Worth the money?

Forgive me if this falls into "Early Career Advice." I don't believe it does though. Strictly networking and coming up on 6 years in the industry.