Monday, February 12, 2018

multicast when service provider does not support over mpls

We have a mpls network provided by our service provider. There is a requirement to have multicast between our remote sites, however our SP does not support multicast over the mpls. What creative options exist for us to tunnel multicast traffic over the mpls? This is a cisco network. IF the SP did provide multicast how would they be typically be doing it? mLDP?



Network discovery, what application are you using?

Many of us here work as consultants deployed onto customers networks to add equipment, solve an issue or advise on possible changes that could be made to improve the customers networks.

There is such a wide range of tools for network discovery these days, I have been using Advanced IP Scanner for a while that produces basic IP, hostname and service reports, and Nmap when I need a little more info.

But my question to /r/networking is.

You have been given permission onto a customers network, you sit down, plug in,

What is the first application you open to start your network discovery & reporting?

(And can it do SNMP info as well?)



Basic query on VLANS and IPHELPERS.

Hi All,

Have a layer 3 switch with VLAN 100 on it (for example) which has an IPHELPER pointing to the firewall for DHCP. Plugging a device into a port untagged on VLAN 100 gives me a DHCP address and all is happy with the world!

I want to connect a L2 switch to the L3 switch to add some more ports etc.

Will a device plugged into an access port in VLAN 100 on the L2 switch still get DHCP address by the fact the L3 switch has the IPHELPER on it? Or does the IPHELPER need to also be present on the switch the device is plugged into?



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Site to Site VPN

We have 2 sites for a client, all of the servers are hosted at Site1 and we have a site to site IPSEC VPN between netgear firewalls at each site. Occasionally at Site2, users won't be able to reach anything from Site1's network. This can normally be fixed by running ipconfig /flushdns or /registerdns. When running an NSLOOKUP at Site2 to servers at Site1, the addresses resolve correctly, but ping, web, and share access are unavailable. We've tried turning off netbios on the machines at Site2 and on the VPN, which made no difference. Adding the servers into the machines hosts file fixed the issue but isn't a permanent fix as all of the machines are laptops and frequently go offsite. The two sites are using different IP ranges, the IP address setup is as follows: Site1 has 2 public IP addresses, one for the hosted fiber line, one for the firewall. The firewall is open to WAN and has a private subnet of 125.1.X.X. Site2 has 1 public IP address to the modem. The modem then gives out a 192.168.0.X address to the firewall, which has it's own private IP range for the rest of the network of 192.168.10.X. The firewall is in the modem's DMZ. If you need anymore details please let me know.



Best Practices for network structures

Hello guys, I am a bit new to this subject and I really want to learn how I can use the knowledge I learned on a computer? I basically ask what is the best network learning practices?



check av database before authenticating via certificate / mac

is it somehow possible that the freeradius checks the database of the antivirus programm before accepting the client?

My system is running with a mix of MAC-addresses and certificates, but it should be advanced to trust the clients only if they have up-to-date databases on certain programms.

My first thoughts were maybe to do a systemcall and run a script to get the information even before checking for mac and/or certificates, but i honestly have no idea if this is possible.

I am also open for completely new systems (dont need to stick to radius), the most important thing is to check the database + certificates etc no matter what software / server does this.

thanks in advance



With dual home'd FEXes, how is a code upgrade handled?

If FEX1 is connected to SW1 and SW2, how does the FEX behave if SW1 or SW2 is upgraded? When does the FEX take in the new image, after both peers have the same software code? Or right after any switch has the image?



SCP Packet Captures directly to CloudShark

Hey All,

Not sure what experience you all have with CloudShark, but I found this new integration CouchDrop.io who lets you SCP pcaps directly to your CloudShark account.

Pretty useful and saves time moving files around.

https://couchdrophelp.zendesk.com/hc/en-us/articles/360000046415-Configuring-CloudShark-Integration



Sunday, February 11, 2018

I'm looking to broaden my skill set... $1800 for a class at a local college on Network+ cert. Crazy?

Tl;Dr truck driver with attention deficit issues seeks new avenues. Options? What should the classes cost?

Background first: My resume is all over the place. I can't sit still and I have a hard time with studying on my own. I have a liberal arts B.A. that has not been useful in the job search. I also have a CDL and years of experience as a truck driver, and it pays okay, but the hours are long and it is boring me to tears. I also have been playing/working with computers since the 80s. I can build PCs like Legos and I was once project manager on a new professional office (for a family member), and I wired a couple hundred feet of CAT6 through drywall etc and set up at least a dozen ethernet connections in all the rooms. I did a bunch of other computer stuff too. Later on I built a hardware firewall, though I couldn't be around to maintain it, so it didn't last. I still didn't really have a clue. This was all a few years ago.

In any case, a local adult education outfit, which has a decent reputation, is offering a Network+ certification class for $1,800. The A+ class is almost $2,000. Going to an actual class would help with my short attention span... but are those prices normal? Should I look instead for a CCNA class? Any other career suggestions?