Sunday, February 11, 2018

DO any of you actually turn the nerd knobs for QoS?

So I’ve been messing with QoS for a few months now, trying to fine tune it. I’ve had the most success with configuring one strict priority queue, and using “bandwidth remaining percent” on the other queues.

In that setup I’ll usually have zero drops on the priority queue, zero drops on a business critical queue, 0.001% drops on a interactive queue, and like 0.01% drops on best effort.

Stats are averaged over a 7 day period.

I tried using different combos of the nerd knob configs trying to eliminate the interactive drops too so only Best had drops. All my attempts usually made things worse causing drops to creep into the other queues. “Queue Buffer Ratio” especially made things worse.

By far my best results we’re leaving stuff bare bones basic stupid simple.

I think the biggest problem was probably not fully understanding what exactly the commands did, causing my trial and error to be more like error and error.

Is QoS one of those lost arts that no one really tunes? Or am I just bad?



Opinions / Suggestions on Cisco Network Refresh Design

We are in the midst of designing a network refresh to replace our aged pair of 6509 switches that support all functions, including the aggregation of older access switches. The following new design has been recommended by both our reseller and Cisco.

 

I'd like opinions and suggestions to the new design. So it is out there upfront, we've vetted other manufacturers but elected to stay with Cisco because we already have the skill set in-house, they have fantastic support (although you pay for it), and a number of other reasons. That said, we will be overlaying the core with VMware's NSX (software defined networking). The drive for a refresh is based on NSX (microsegmentation), VoIP, access layer POE, soon to be end of life Cisco products, and additional speed.

 

Requirements:
* 40 gb ports to our (10) VMware ESXi servers, (3) to our VMware VDI servers, and (1) to our backup server
* Most other physical servers services will be moved to vm's and any remaining will become 10g connections
* The core needs to be fast

 

The reseller and Cisco are recommending the following:
* (2) Nexus 93180LC and (2) 2248TP-E FEX’ for all Datacenter connections
* (2) Catalyst 9500 as the Core/Distribution switches
* IDF switches will be Catalyst 9300’s, stacked, connected back to the CAT9500

 

Notes:
* Non-datacenter services (i.e., Internet Firewall) terminate into the CAT9500
* VLANs will be defined on the CAT9500
* DHCP will be re-directed to DHCP server
* We have approximately (100) 1gb connections into a pair of 6509's currently, a good chunk are to the ESXi servers, and most of these are etherchanneled and/or are redundant connections.

 

Routing occurs at 3 areas:
* Datacenter. All subnets for the datacenter and all DC traffic is routed by the 9300’s.
* Core/Access/Edge. All subnets serving the access layer are routed by the 9500’s. The 9500’s also become the default way out of the network
* WAN. Use the existing ISR router
* Route distribution is handled by EIGRP processes running on the 9300+9500+ISR, so all internal routes are known. The ISR becomes the gateway of last resort.

 

The thought about using FEX's was that they will present themselves as essentially a line card out of the 93180LC and will be a staging place as we slowly move our traditional 1gb servers over to 10gb using breakout cables on the 93180. Once they have been migrated over, the FEX' can be used for server management (iLo, Drac, heartbeat, etc).

 

Thoughts?

 

Thank you!



Looking for guidance on a design with one subnet and multiple VLANs

Hi everyone,

I'm the system admin. at my company that is responsible for swapping Internet providers. We got ourselves a LAN 2 extension to connect our two facilities to our HQ. I'm struggling to come up with an elegant design that maximizes utilization of switches and minimizing changes to the network. My knowledge in networking is not strong (crashing through the Cisco CCNA ICND1 book to get up to speed) so I was hoping to ask for advice from this subreddit.

I've created a network diagram for reference that can be found here.

Some points:

  • Our ISP provides traffic coming from site #2 with VLAN 100 and traffic from site #3 with VLAN 200.
  • Switch SW-1 has one access port for VLAN 100 and one access port for VLAN 200. One port is trunked that goes to the ISP.
  • I'd like to maintain subnet 192.168.20.0/24 across all 3 facilities.
  • Presently we have majority of hosts connected to SW-Access. No VLAN tagging performed on this switch.

The problem I’m struggling is if frames coming from Site #2 destined to Site #3, it needs to be routed from VLAN 100 to VLAN 200. First thought that comes to mind is to use IP routing. However, if all 3 sites want to use the same subnet address, then in theory, this isn't possible.

The other option I thought was to create a physical link between the access ports on SW-1 to SW-Access. In theory, with ARP and layer 2 routing, this should work. The problem now is SW-1 is a 48-port switch. I'd like to connect more hosts (maximize utilization of switch) that are part of the same subnet. How could those hosts connected to SW-1 on VLAN 1 (native) ports communicate to the access VLAN ports (on the same switch)? In theory, I could create a physical link from SW-1 to SW-Access on VLAN 1 (native). But that seems inefficient to introduce one hop.

Any suggestions or advice is welcomed. Thanks everyone.



Social worker needs me to interview people in the field, any takers?

1.name and title of person you are interviewing

2.employers name and address

3.contact number and email

4.how did you get involved in this field

5.what type of education do you have?

6.what educational program is recommended as preparation?

7.what kinds of courses are most valuable in order to gain skills necessary for sucess in this occupation?

8.what are the duties performed during typical day? week? month? year?

9.Does he/she have a set routine?

10.what degree or certificate do employers look for?

11.what kind of work/internship experience would employers look for in a job applicant?

12.How can a person obtain this work experience

13.what are the important "key words" or "buzz words" to included in a resume or cover letter when job hunting in the field?

14.what are opportunities for advancement? to what postition? is an advanced degree needed?

15.which skills are most important to acquire (i.e. which skills do employers look for?)

16.what do you like most about your job and line of work?

17.what occupation did you wanted to be when you were growing up?

18.Does your job require you to go from one location to another frequently (driving)?

19.what inspires you or motivates you?

You can PM me your response too



IPSEC Tunnel only works if initiated from one side.

I have an issue that I can't really find a solution to.

I have an IPSEC tunnel between an ASA and Fortigate.

ASA side has two hosts, we'll call them 10.200.10.138 and 10.200.10.217

Fortigate side has one subnet in the tunnel, 10.9.10.0/24

The Fortigate side can initiate the tunnel and ping 10.200.10.217. However, the Fortigate side cannot hit 10.200.10.138 UNTIL 10.200.10.138 initiates a connection to the Fortigate side. After that point, everything works fine.

Until 10.200.10.138 initiates a connection to the Fortigate side, I get the following error in the log:

 The decapsulated inner packet doesn't match the negotiated policy in the SA. 

Usually I would suspect an ACL mismatch, but given the fact that the connection only works if initiated one way, what should I look for?



QoS queue limit with multipoint DMVPN

Hi all

We have quite a large number of branch sites in a hub-and-spoke DMVPN topology via mpls links. Recently we have experienced significant slowness to many of these sites along with packet drops on our hub interface. We are doing qos via our NHRP groups and are aware that there are quite a few limitations with this. Our branch sites have fairly low bandwidth links so we are frequently having to mess around with these in order to improve performance for one vlan at a branch site over another.

We've been recommended to increase our queue-limit on our hub from the default of 64 packets to 128 or 256, however I've tried doing this and it has informed me that this cannot be done on a multipoint tunnel interface. We are also limited to only using shape-average. Is there any other way we can tweak our policies/queues to reduce these packet drops we are experiencing? The obvious solution would be increasing our bandwidth at our tails however this is not really an option right now.



What are books similar to Network Warrior book that teaches CCNP R&S concepts in an easy to understand way?

I used network warrior book after completing CCNA R&S. I loved how the book explained complex concepts in a easy to understand way using simple language. I find cisco’s official guide filled with unnecessary & somewhat difficult to understand technical jargon. Is there any book that teaches CCNA security & CCNP R&S concepts in a easy to understand way similar to the way network warrior book teaches n/w concepts?



Dynamic IPv6 prefix from ISP, prefix delegation from firewall to layer 3 core switch (Cisco 3750G)

First of all, I'd like to say that this is a homelab environment, hence the outdated switch. I'd usually not ask questions regarding my homelab in this subreddit, but no other subreddit could properly answer me and the gear used is enterprise grade.

My ISP supplies a 56 bit prefix, allowing me to create 256 subnets.

Vlans and intervlan routing is all done on the layer 3 switch (3750g), which is currently IPv4 only. This switch is connected to a pfSense box via a layer 3 interface on the switch.

Now what I'd like to do is to delegate a slice of the 56 bit prefix, to the layer 3 switch, which is where the vlans are configured.

I've thought of one way to do this and would like to know if this is possible, or if there are better ways.

A DHCPv6 server on the firewall, which the layer 3 switch is connected to. Automatically configure the layer 3 interface on the switch with an IPv6 address and run a dhcpv6 client to obtain a slice of the 56 bit prefix (58 or 60 for example). This prefix would be used on the SVI's, combined with a prefix ID. This way, if my ISP supplies a new prefix, everything else will dynamically update.

Thanks in advance.



Juniper Certification Questions

Hi,

I recently got the JNCIS-ENT JN0-647 and I have CCNP R&S and some other CCNA (Wireless, Security), and planning to get a higher Juniper certs.

Pretty much all my experience are all on small/medium size Enterprise, and we usually just have a couple of firewalls that does routing and firewalling. We are not even doing BGP, so in regards to real world experience about BGP, I have none.

At this point, I am not sure if I should pursue the route/switch path or should I pivot to Security. My goal is to get to JNCIE level, but what would you do?



how are you doing captive portal for guest access?

its looking like ISE and sponsor portal is the norm for a cisco deployment. Other better options? Is there any best practice way to do this including approval/authentican process? I've already ready through ise admin guide for guest services.