Sunday, April 29, 2018

How much experience would you expect from a CCIE?

Firstly I apologise if this is against the rules. It's not really an early career question however I can see how it might not be permitted for the same reason

I'm about to begin to pursue CCNP R&S exams having been operating at that level for a while in my career and having completed CCNP Route/Switch courses. I have about 8 years of Sysadmin experience and 5 really focused on networking. After this I'm planning to move jobs to get something more network focused (currently have a 50/50 split).

What I'm trying to gauge is if I should be thinking about CCIE after acheiving the NP? The CCNP is the logical next step from the CCNA but is the IE the same for the NP? Or is it accepted that most don't go on to the IE and those that do should have more years under their belts?

I have had dealings with a few CCIEs (especially security ones) where they've got some gaps in their general knowledge in networking and I've honestly been a bit disappointed.



Libreswan to ASA 5500 Config

I have to create an IPSec tunnel from amazon to an ASA 5500. Below is the info I was provided on the ASA config:

Support Key Exchanged for Subnets: ON IKE Encryption Method: AES256 SHA IKE Diffie-Hellman Groups for Phase 1: Group 2 (1024 bit) IKE (Phase-1) Timeout: 1440 Min IPSEC Encryption Method: AES256 SHA IPSEC (Phase-2) Timeout: 3600 Sec PFS (Perfect Forward Secrecy): Disabled Keepalive: Disabled 

I setup libreswan on a centos 7 ec2 instance. This is what I have for Libreswan connection config:

conn ipsec type=tunnel authby=secret remote_peer_type=cisco initial-contact=yes rekey=yes pfs=no ikelifetime=1440m salifetime=60m ike=aes256-sha1;dh2 phase2alg=aes256-sha1;modp1024 aggrmode=no 

I've successfully created a tunnel to another libreswan instance in a separate aws vpn and can pass traffic but when I point to the ASA, I don't seem to be even getting past the IKE phase. based on this ipsec status:

000 Total IPsec connections: loaded 1, active 0 000 000 State Information: DDoS cookies not required, Accepting new IKE connections 000 IKE SAs: total(1), half-open(0), open(1), authenticated(0), anonymous(0) 000 IPsec SAs: total(0), authenticated(0), anonymous(0) 000 000 #1: "ipsec":4500 STATE_MAIN_I3 (sent MI3, expecting MR3); EVENT_v1_RETRANSMIT in 12s; nodpd; idle; import:admin initiate 1: pending Phase 2 for "ipsec" replacing #0 

I know the preshared key is correct but I'm at a loss. For starters, do I at least have the correct libreswan config based the ASA config?

I'm banging my head against the wall here and am willing to pay if someone knowledgeable can give some direction.



Cisco 9300 - Stackwise Virtual vs Stackwise 480

We are deploying 2 pairs of Catalyst 9300 as a Collapsed Core in 2 Regional Offices, replacing HP 3500yl. We are licensed for Network Essentials.

Wondering what people's experience is with Stackwise Virtual. I've dealt with traditional Stackwise on 3750/X/3850 and VSS on 4500X, but haven't deployed Stackwise Virtual yet. We have purchased the 8x10G expansion modules for these switches as well, and will use Twinax to interconnect with new Access Switches (unsure if Meraki or Catalyst yet).

For context, there isn't a lot of gear in these Offices:

  • 2-4AP's (Meraki MR32)
  • 1 WAN Circuit
  • 1 Audiocodes Telephony Gateway hosting 1 PRI
  • 1 Fortigate Firewall for Local Internet.
  • 1 UPS
  • 1 VM Host hosting File/Print, DC and SfB Survivable Branch Server


HP Procurve DHCP Server Comnection Issues

Hey All,

I have a question about an HP Procurve 2824 switch. Anything that is not in the same subnet as the DHCP server is unable to connect to it. I have the IP helper address set as the DHCP server address. What else is needed to get it to connect to it?



Which networking certs are the most relevant today?

Hello everyone,

I work at a software company that's growing at a rapid rate so there's always new positions opening up for all departments. I'm currently part of the IT team for the office just general tier 1/tier 2 support. I want to work towards getting the skills to be able to apply for a network or system admin role at my company. Which certs are the most relevant these days when it comes to Network Admin related work? Is it still CCNA? I hear a lot about AWS certs these days.

Which certs should I work towards?



Undersea cable outage tracker?

Anyone know of a website that tracks the status of undersea cabling? Seems like there is always a few undersea cables down due to negligent fishermen or whatever.

I know that sites like cablemap.info which list all the cables but it doesn’t show anything about their current status.



Stumped! 3 Routers to 1 Switch

Looking to setup 3 Routers to 1 Switch which will be segmented via VLANs. I was kinda looking NOT to use trunking from the routers is this possible or was that the whole point of VLANing to cut down on all the HW needed todo such things



I just got a toiletpaperlink ipsec vpn working with a fortigate AMA

It only took me 5 or 6 hours of messing with it. (including setting it up on pfsense just to make sure it wasn't an issue between the 2 locations)

I spent 3 hours messing with it, decided it might just be something between the 2 points so I loaded up a pfsense instance and in 10 minutes it was working. Whoever wrote the interface and manual for toiletpaper link should be shot. I don't how you would shoot google translate though...

It was so bad and there is such a lack of documentation examples out there I might just make an ebook and sell it for a dollar /s

I had never been in a tp link until today, I heard they were bad... wow. The logs are horrible, the interface is almost worse.

The thruput isn't as bad as I thought it would be... was getting 2.5MB/s over the vpn with pfsense. around 1.3MB/s on the 2 ply.



What's new in Network Monitoring in the last 12 months?

I would like to hear what people have to say about these network monitoring topics:

  1. New useful features and capabilities in PRTG, Solarwinds, and other monitoring tools in the last 12 months
  2. New monitoring tools that did not exist before the last 12 months
  3. What is one useful thing YOU have learned in network monitoring in the last 12 months (doesn't have to a be a new technology or feature).
  4. What's else has changed about network monitoring in 2018, versus say 2014 or 2015, if anything?


Saturday, April 28, 2018

Issue connecting to SQL server.

I'm having an issue connecting to a MySQL database hosted on amazon AWS via MySQL Workbench.

I can connect fine when i use my mobile network tethered to my PC. However when i try to connect via any PC in my house, i get error 10060. I've temporarily disabled both the firewall on my PC as well as the firewall on my router. I've also temporarily forwarded every port (TCP/UDP from 1-65535) in my router. Ontop of this i have set my PC to the DMZ.

In MySQL Workbench i'm connecting via Standard (TCP/IP), This works on my friends computer in his house (he is using the same model of router and same ISP) - I am able to connect via my mobile network tether. Is there anything that i can still try?