Tuesday, April 24, 2018

HyperV Network Virtualisation - VXLAN

I've recently started working at a MSP and the system's architect wants us to implement Microsoft HyperV Network Virtualisation as per microsoft's design guide below on a new platform:

https://docs.microsoft.com/en-us/windows-server/networking/sdn/plan/plan-a-software-defined-network-infrastructure

I'm not experienced with VXLAN but this solution seems to involve running the HyperV hosts as the 'VTEPs' rather than running the VTEPs on the network equipment, using BGP as an underlay. It seems to have a software based controller that determines if the frame needs to be encapsulated and sent to another VTEP (via the HNV VLAN) or if it's external traffic that should be forwarded directly to the (transit network) gateway with no VXLAN encapsulation.

If this is the case, what are the benefits of running VXLAN on our network equipment or is there something fundamental that I am misunderstanding here? I can see how microsoft solution may work within one DC but don't see how this would be scalable across two or more DCs. It would also need to communicate into a VMWare environment so i'm concerned about inter-op there.

I'm trying to put together a justification for buying VXLAN capable network equipment which is proving difficult as the system's architect is stating that it's too expensive and not worth the cost when we can run it on the hosts. Has anyone else run into these kind of arguments and how did you justify the expensive network kit to management?



Cisco Stratix Switches

Does anyone have any experience with Stratix switches? Looking at a config, it looks like they just run IOS. I'm curious if anyone has some feedback, good/bad/neutral, best practices, etc.



Are there any copper sfps that can handle 10g over a distance of 200 feet?

No text found

Cisco IOS MAB - How exactly does it learn the MAC addresses?

I know, the question sounds dumb - of course it learns the MAC addresses from the source MAC of the frames it receives. That's not quite what I'm asking.

I know that when the switch receives a frame, it records the source MAC address into the CAM table, for that port/VLAN. Got it.

When the MAB process is executing, it uses the known MAC address to authenticate. What source does MAB use to determine the MAC address? Does it look in the CAM table for the MAC addresses on that port? Or does it require an actual frame to enter the switch before it can begin the MAB process?


Consider this scenario:

  • 802.1x/MAB reauthentication timer is 1 hour.
  • MAC address inactivity timer is the default of 5 minutes.
  • MAB passed successfully at 4:00:00.
  • The device sends its last frame at 4:56:00, then goes to sleep for ten minutes
  • At 5:00:00, the switch begins reauthentication.

If the switch uses the CAM table, it still has an entry for the device, and can authenticate the device, and it will reauthenticate at 5:00:00 (+/- some seconds)

If the switch requires an actual frame, the port will unauthenticate at 5:00:00, and remain unauthenticated until 5:06:00 when the device sends its next frame. This means the device was 'down' for six minutes.


Thoughts?



Hijack of Amazon’s internet domain service used to reroute web traffic for two hours unnoticed

This originally looked like a DNS issue, then a route leak, and now it's thought to have been a man in the middle attack mounted from within an Equinix data center in Chicago. We had a lot of customers with issues this morning.

Here's an article on it with more information.



IP /24 Block monthly rental charge

Hi All,

I have a customer that we are going to rent 2 /24 blocks to in APAC until they can move to their own IP block. What would be a reasonable charge for this be?

Thanks



HPE 2920-24G switches to Watchguard multi wan - Dedicate Voice vlan to secondary External

Setup:

3 HP 2920-24G switches

2 Vlans - Voice and Data

Windows DHCP Server - hands out addresses to 10.x (Data) and 150.X (Voice)

I have the IP phones working as expected and hopping on the voice vlan, getting a new IP from the voice scope and working as expected. The only problem, is our main connection has a high latency route to the PBX location. Our copper connection (Secondary external) has a low latency route and I want to specifically force the voice vlan to use the secondary external to help with the delay problems being reported by users.

I've tried using policy based routing (override checkbox) and created both vlans within the watchguard. When I do this, the phones drop their IPs and no longer get an IP address at all. I've tried setting Send and receive tagged traffic for selected vlans on both vlans and vice versa in case I had everything backwards. I also tried setting send and receive untagged traffic for the data vlan. Data flows as it should, but the voice vlan just drops out. I know this has to be something simple I'm missing as I'm not much of a network admin, more sys admin than anything.

Watchguard info: Int type - VLAN

Vlan1 - data ipv4 address is the address of the watchguard

vlan10 - voice ipv4 address is the address of the switch with the route to the 10.x network

I've setup policies specifically for all mitel ip phone ports

From Any-external To Vlan10

From Vlan10 to Any-External

Both policies have PBR enabled for the T1 interfaces.

Thanks in advance!



Cisco Virl - 20 nodes. BY nodes, do they means 20 layer 3 interfaces? or 20 devices?

No text found

Configuring public static IP on LAN server

Hello,

Here is what we have:

  • DrayTek 2925 Vigor Router using a dynamic IP from ISP
  • switch connected to router via LAN1. And is used for a couple of servers, wifi routers, and hardwired computers.
  • ISP assigned single static IP, gateway, subnet mask, DNS(x2)

The two servers are Linux, if that matters (I've read that I should not configure the static IP on them but rather in the router). One should have outgoing connectivity, and connectivity with all other devices on LAN (serverX) and the other (serverY) needs to be accessible from outside the internal network via the static IP. For the life of me, I cannot get the server to respond via the static IP. I have contacted the router's support which had me doing things I had already tried (VLAN, IP Routed Subnet).

DrayTek

Switch

serverX - local access only
serverY - desired to have outside access via static IP
other devices

Questions:

  • Is what I am trying to do going about things wrong? If so, how should I be doing it?
  • Do I need to do anything on the serverY for the static setup?
  • Can I use a static IP on LAN even though the WAN connection is dynamic?

Other things:



Looking for opinion on Aruba configuration

I'm planning for a replacement of the switching in our main office. If it helps, the current setup (which was in place when I arrived) is a single Nexus 5548UP with six 2248TP fabric extenders providing all of the access. I'm aware this isn't a recommended config as the FEXes are meant for TOR and there should be a second 5548UP for redundancy. Here's what I'm planning so far.

Core 2 x Aruba 3810M (JL075)

Access 5x Aruba 2930M (JL321A) - basic 48-port 1G 1x Aruba 2930M (JL324A) - 24-port smart-rate

The plan for the core is to bring in our to-be-installed replacement three virtual hosts and new SAN, as well as two of our main file servers, all operating at 10G with redundant connections. The virtual hosts and SAN would be segregated to a separate iSCSI VLAN and redundant connections would go into each 3810M from all devices.
The plan would be to stack the 2930Ms and run 40G uplinks from either end of the stack to the 3810Ms. The JL324A is mixed into the JL321As because we wish to have the ability to run a portion of the client devices at speeds greater than 1G to improve Autodesk Revit shared model performance.

I've installed my share of Cisco gear, but this is my first foray into Aruba and I have a few questions about this design. 1. I believe it's the case (but I can't seem to find anything to definitively state it) that the JL324A can be added to a stack of JL321As. Can anyone confirm? 2. For Aruba stacked devices, when new firmware is released, does the stack as a whole get updated at once or is each device updated separately? 3. For the 3810M core, since my desire is for each switch to be fully redundant, would it make more sense to not stack them together? My thought is that during switch maintenance when updates to the switches are applied, the individual switches could be restarted without having to bring down anything such as the SAN or the virtual hosts.
I'm open to comments on the above or any other observations.