Thursday, February 8, 2018
Campus fabric for L2 adjacency over routed access
We have recently moved to a routed access design for our new campus buildings and it is working well, apart from some legacy BMS/BACnet systems that need L2 adjacency to function normally.
We want to avoid hooking up additional switches just to support these items so have been looking into campus fabric to create an overlay for this purpose. We manage all networking in-house and have modest CCNA/NP skillsets available but dont want to end up with a configuration that is difficult to manage.
Wondering if anyone else has set this up and how difficult it was to do?
RA network is cisco (C9500 cores, C3850 access, both on Everest code).
How do you handle OOB sim card access in EU?
We have several OpenGears in our EU locations and are looking at getting sim cards to insert into them to give us OOB access to our console servers. We're having trouble sourcing these and I was wondering how anyone else here handles this. What provider do you use? How did you procure them? Good/negative experiences with coverage?
At the moment all I can find locally are data sims at local shops that I have to provide my personal infomation for and then manually top-up with credit. This isn't practical or scale-able. I'd like to find some provider that can sell us a batch of SIM cards expressly for the purpose of OOB management of our devices that we can easily manage/pay for.
Suggestions?
Security Officer “recommend” constant upgrades
So we have a security office that was hired about a year ago and recently he’s been constantly pressuring us to “always have latest” firmware. We use mostly use cisco 800 routers (70+ routers, similar for cisco switches (they are internal only)), and right now we are on 15.4.3 m6. I’m not against upgrading but for example 15.4.3 m9 was released couple days ago and he’s already “recommending for upgrade”. I’ve tried explaining them that this isn’t like windows updates. Current m6 is stable with no issues. We normally upgrade if a special feature is needed or bugs or critical security issues.
Have you guys had to deal with something like this?
Need help on a possibly simple issue
Good morning/afternoon/evening r/networking.
Please bare with me if this gets a bit long. I just want to make sure I give enough information to you guys/gals.
I'm honestly stumped on this one, not sure what it could be. I've simulated this exact configuration and design, and it works fine on the simulation.
I have this network I'm helping to configure, it's a hub and spoke design, no redundant links, nothing fancy.
I have seven L3 3850 Cisco catalyst switches that are going to be connecting into a Cisco 4507, I'm literally configuring this setup as a router on a stick. Seven different IP schemes, one per 3850 with the 4507 acting as the router.
Each 3850 switch has a basic configuration; username and password, one configured VLAN with an IP address, and a switch default gateway, added nearly all my ports to the VLAN as access, SFP module uplink ports are configured as trunks with all VLAN access.
At the 4507, I have created all seven VLANs with the VLAN gateway ip addresses, enabled IP Routing (We're not doing dynamic routing at all.) I've configured the uplink ports to the 3850s as trunk ports as well with full VLAN access.
When it came to testing on the simulation, everything seemed to work fine. I did this in real hardware today, and I couldn't ping from one switch to the other.
When I went back to check my configurations on the 4507 using 'show run' I noticed that IP routing was not on the list, but if I enter command 'no IP routing', then 'no IP routing' shows up on the list. Google explains that this is normal on some Cisco switches.
I've tried to configure OSPFv2 after IP routing failed me, but then quickly discovered that the Cisco 3850s are missing this layer3 service.
Here's what I managed to write down. The IOS image on the Cisco 4507 is 'cat4500es8-universal.SPA.03.07.03.E.152-3.E3.bin'
Right now my only theory is that the Cisco 4507 is not routing, maybe due to the specific IOS image? Is there something simple that I'm just too numb to realize???
Unfortunately I am not able to show the configs since it's difficult to get a copy of at the moment, apologies for that.
Ask away any questions, and I'll answer them all. AND thank you in advance.
Edit:forgot to mention that at this moment, nothing is connected to the access ports on the edge switches, I'm simply just trying to ping other gateways on the 4507 and the other switches IP addresses.
Network design for a small engineering office
Hey all, I work in a small engineering office and I've been slowly grappling the IT responsibilities away from the senior engineer in the office.
Our current set up is a network of internet connected computers connected mostly via wireless to a router (1-2 computers each + phones). We have another air gapped network of 5 computers & 2 archival drives which is for the drafting stations and all our shared work. They are networked amongst each other but none are on the internet.
The problem is these isolated computers on the regular exchange USB drives with networked computers, and as they're not networked some are up to a year (or realistically more) behind in software / security updates. (These computers occasionally get disconnected from the offline network and connected to the internet for updates)
We make daily back-ups which are brought to an offsite location, the networked computers have antivirus & updates installed and generally people in the office aren't the type to open random email viruses.
Is there a better system we could be doing? I feel like we're living in the past and there's an obvious better solution. Any suggestions are welcomed.
Cheers
Looking for software that will let me monitor dozens of computers across multiple networks.
Im looking for software that will allow me to see dozens of computers with a small thumbnail live feed of whats happening on them across 3 different networks.
I own a small company with two branches. I want to monitor employees screens with software similar to veyon or tightvnc but from what I see I can only monitor computers that are on the same network. We have two branches so i would like to be able to monitor all computer screens when i need to from my office or from home.
For example.
I login from my home network and i see live thumbnails of computers from my two branches in a grid.
Wednesday, February 7, 2018
IPSec ESP Troubleshooting on the internet
I have a IPSec VPN issue.
I have a diagram that will help with this.
In my office, we have a VPN Firewall, connected to dual internet service providers.
At a remote site we have a VPN Firewall connected to just one ISP
-
If my traffic traverses ISP #1, I can Ping, SSH and HTTPs to the WAN IP no problem. My VPN establishes, but I get 60% packet loss if I try to ping across the VPN link. The VPN has IPs on both Ends.
-
If my traffic traverses ISP #2, I can Ping, SSH and HTTPs to the WAN IP no problem. My VPN establishes, and I get 0% packet loss across the VPN link.
-
If I try to ping the remote office, from my office. I see packets leaving my office to the remote office, but the packets never make it to the remote office's WAN interface.
-
If I try to ping my office from the remote office, I see packets arriving at my firewall and the responses. However the responses never arrive at the remote office.
So given what I see, if encrypted IPSec traffic leaves my office to the remote office through ISP #1, it fails. Through ISP #2 it works. All other traffic seems to work fine.
If this was a SSL VPN, I could just tcptraceroute and see where it fails, but I don't have an equivalent for IP Protocol 50.
I'm trying to figure out a way to show this to the ISP, because I know they are going to say PING/TRACEROUTE works, so everything else should work.
Has anyone else had a problem like this?
Newbie manager of a Ubiquiti UniFi network, how vital is it to replace EOL access points?
Hi, I've recently been put in charge of a network with several older access points that have been EOL'd by Ubiquiti. Not wanting to spend a lot of money at once to replace them, if I were to avoid updating the management software and firmware, how big of a risk would this be in terms of security, etc.? Could I expect them to function indefinitely as long as I don't update, so I could do rolling upgrade instead of a large purchase? Sorry if this is relatively basic.