Monday, April 30, 2018

OSPF / EIGRP / Redistribution Question

Short story... EIGRP shop, have to convert to OSPF. Currently in a situation where we are standing up brand new 6880 VSS pair for Distribution layer... figured it was a good time to convert.

My Concern is we have two 7k's currently running EIGRP with redistributed static routes (bunch of 170 AD's). It won't be a hard cut EIGRP to OSPF but rather a rolling change as we are updating all access switches off an old 6500 to 6880's. So that means when we stand up OSPF between the 7k's and 6880 Distribution switches... we'll have to redistribute EIGRP into OSPF.

If I leave everything default, the redistributed EIGRP routes will have an AD of 110 pointing to the EIGRP instance running on the same 7k? will that cause routing loops since it'll overwrite all our DEX [170/XXX] routes? Should I just change the distance on the 7k's to say 180? And if so, is that just "(conf-rtr) distance #" and do that before redistribution or is it as simple as doing a default information originate on the two 7k's with no redistribution?

In the comments I've provided a basic topology



Cisco WLC causing strange behavior

I think, anyway.

Backstory - I'm in the middle of a migration between 2 wireless networks at a client - a large manufacturing facility. When I started, they had 2 5508s in a ghetto-HA setup with about 75 APs. I pulled one of the controllers from that group, set up a new SSID on it for their new network and started adding APs. At present, about 80% of their network is connecting to the new SSID on the new APs. The old network is still in use in some areas for at least a few more weeks.

Last wednesday, the controller on the old network started going offline briefly. It lasted about 90 seconds, all APs dissociate and the network interface in the controller does not respond to ping for about 60-90 seconds, then comes back up for 5 -10 seconds, then goes offline again for about another 20-30 seconds. This happens at least once per day, but it's not predictable. It doesn't generate any specific logs that suggest an error, that I've noticed, but I'll reply to this post with an excerpt of the logs I captured.

The really strange thing is that when this happens, at the exact same time, the other controller (we'll call it "new") - which shouldn't be talking to the "old" controller as I removed them from the RF group etc, also goes down for about 30 seconds. It responds to ping and does not lose its APs, but it does not pass any traffic for that time.

The "old" controller is running software 8.0.140 - The APs are 1130s, 1140s, 2602, 2702

The "new" controller is running software 8.3.133 and the APs are all 3802s and 2702s.

I've checked the stats on the switch ports that they're connected to and see nothing strange. Both WLCs have redundant GB uplinks to their switches.

Wireshark isn't showing any strange broadcasts or anything from either controller when it happens, and I don't notice anything else that might cause it. Wired network seems to be unaffected.

Anyone have a guess? Neither controller is under support currently, and new controllers aren't scheduled to be purchased until June. I'm guessing that the 2 WLCs are talking to each other for something and that's why it impacts both, but what it is and why is still a mystery.

The following is an excerpt from the message log on the "old" controller when the outage occurs.

*spamApTask0: Apr 25 08:07:30.232: %LWAPP-6-CAPWAP_SUPP_VER: spam_lrad.c:1874 Discarding discovery request in LWAPP from AP 00:1a:30:c2:ec:e0 supporting CAPWAP *spamApTask6: Apr 25 08:07:29.530: %DTLS-5-ESTABLISHED_TO_PEER: openssl_dtls.c:766 DTLS connection established to 10.1.100.124 *spamApTask0: Apr 25 08:07:27.399: %LWAPP-6-CAPWAP_SUPP_VER: spam_lrad.c:1874 Discarding discovery request in LWAPP from AP 00:1c:b1:07:04:b0 supporting CAPWAP *spamApTask0: Apr 25 08:07:27.399: %LOG-4-Q_IND: capwap_ac_sm.c:7983 The system detects an invalid AP(00:1c:b1:07:04:b0) event (Capwap_configuration_update_request) and state (Capwap_dtls_teardown) combination *spamReceiveTask: Apr 25 08:07:27.369: %CAPWAP-4-INVALID_STATE_EVENT: capwap_ac_sm.c:7983 The system detects an invalid AP(00:1c:b1:07:04:b0) event (Capwap_configuration_update_request) and state (Capwap_dtls_teardown) combination *spamApTask3: Apr 25 08:07:27.362: %CAPWAP-3-ECHO_ERR: capwap_ac_sm.c:7224 Did not receive heartbeat reply; AP: 00:1c:b1:07:04:b0 *spamApTask3: Apr 25 08:07:27.362: %LOG-4-Q_IND: spam_apf.c:290 The sytem is unable to find AP 00:a2:ee:57:5c:d0 entry in the database, could not process delete WLAN ALL MNs message *spamReceiveTask: Apr 25 08:07:26.169: %LWAPP-4-AP_DB_ERR1: spam_apf.c:290 The sytem is unable to find AP 00:a2:ee:57:5c:d0 entry in the database, could not process delete WLAN ALL MNs message *spamReceiveTask: Apr 25 08:07:26.169: %LOG-4-Q_IND: capwap_ac_sm.c:7983 The system detects an invalid AP(f8:0b:cb:b1:a2:00) event (Capwap_configuration_update_request) and state (Capwap_dtls_teardown) combination *spamReceiveTask: Apr 25 08:07:26.168: %CAPWAP-4-INVALID_STATE_EVENT: capwap_ac_sm.c:7983 The system detects an invalid AP(f8:0b:cb:b1:a2:00) event (Capwap_configuration_update_request) and state (Capwap_dtls_teardown) combination *spamApTask3: Apr 25 08:07:26.165: %CAPWAP-3-ECHO_ERR: capwap_ac_sm.c:7224 Did not receive heartbeat reply; AP: 00:a2:ee:57:5c:d0 *spamApTask1: Apr 25 08:07:26.162: %CAPWAP-3-ECHO_ERR: capwap_ac_sm.c:7224 Did not receive heartbeat reply; AP: f8:0b:cb:b1:a2:00 *spamApTask1: Apr 25 08:07:26.162: %LOG-4-Q_IND: spam_apf.c:290 The sytem is unable to find AP 00:21:d8:92:a7:00 entry in the database, could not process delete WLAN ALL MNs message *spamReceiveTask: Apr 25 08:07:25.971: %LWAPP-4-AP_DB_ERR1: spam_apf.c:290 The sytem is unable to find AP 00:21:d8:92:a7:00 entry in the database, could not process delete WLAN ALL MNs message *spamApTask0: Apr 25 08:07:25.962: %CAPWAP-3-ECHO_ERR: capwap_ac_sm.c:7224 Did not receive heartbeat reply; AP: 00:21:d8:92:a7:00 *spamApTask0: Apr 25 08:07:25.723: %LWAPP-6-CAPWAP_SUPP_VER: spam_lrad.c:1874 Discarding discovery request in LWAPP from AP 00:25:45:26:46:00 supporting CAPWAP *spamApTask0: Apr 25 08:07:25.723: %LOG-4-Q_IND: spam_apf.c:290 The sytem is unable to find AP 00:a2:ee:44:35:c0 entry in the database, could not process delete WLAN ALL MNs message *spamReceiveTask: Apr 25 08:07:23.966: %LWAPP-4-AP_DB_ERR1: spam_apf.c:290 The sytem is unable to find AP 00:a2:ee:44:35:c0 entry in the database, could not process delete WLAN ALL MNs message *spamApTask0: Apr 25 08:07:23.962: %CAPWAP-3-ECHO_ERR: capwap_ac_sm.c:7224 Did not receive heartbeat reply; AP: 00:a2:ee:44:35:c0 


WLC 5508 and 1562 outdoor APs still not joining after WLC upgrade

Over the weekend we upgraded our WLC to 8.3.133.10 because we have some outdoor ap models 1562 that weren't compatible with our current firmware. This was the version a Cisco tac recommended. He specifically attached this version because there is a bug in 8.3.113. and it's suppose to cover the 1562d models.

The weird thing is that the 1562d models get an ip address and you can ping them for about 2 minutes and then you get request timed out. Show cdp neighbors still shows them on the network and identified with their ip addresses. and on the WLC i see ap join requests with no failures but there is no attempt to join.

do you think the 1562ds have the wrong image? like maybe they were sent to us as standalone aps? I'm probably going to take one down and console into it. just wondered if anyone had any thoughts? thanks



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



What do the acronyms within a TID such as 1CW, 1AW, 1ZW mean?

What do they stand for? I get that 1CW is a router, but what about if it's 3CW. Any special meaning there or a dead giveaway on what the exact router is?



Spine and Leaf architecture questions

Folks, want to explore doing a spine and leaf DC with Cisco Nexus 9364 as Spines and Cisco Nexus 93180YC-FX as Leaf switches. I want to replicate this setup I'm planning at Primary Data Centre to the DR site. Now between the Primary DC and DR site I have DWDM that can provide 100Gb interfaces. Question is: Should I put another set of Cisco Nexus switches above the Spine switches for doing this "WAN/ DWDM" connection or is it ok to connect the Spines together using DWDM fibre and the route directly between the Primary DC and DR site?



Sunday, April 29, 2018

Help designing network, network security, and WAN connectivity

Hey guys I need help writing a paper and I'm hoping you can point me in the right direction. The project I'm working on is to design a network, network security, and WAN connectivity for the following situation:

Organization of 100 computer users in three locations

*Location one:two buildings, 25 users in each building. 50 total

*Location two: one building, 15 computer users

*Location three: one building 35 computer users

I need to document my as follows:

  1. intro to design explanation of equipment and software used
  2. diagram of entire network
  3. diagrams for each location
  4. explanation of security procedures
  5. explanation of WAN connection

I've read nearly the entire textbook that goes along with the subject and I don't feel like there's much to go off of. If you can just give me a nudge in the right direction I'd be super appreciative.

The three hypothetical locations aren't given any distances between them, so I just don't understand how to work it out.



About CAM lookup and how a frame is forwarded

I'm studying to take my CCNP Switch exam sometime soon, and am reading through the Cisco Press book. Only on chapter 2 so far, but I feel I've found an errata, or at least something that seems very misleading.

In my copy of the book, page 34 and listed as a key topic,

"Incoming frames also include the destination MAC address. Again, the switch looks up this address in the address table, hoping to find the switch port and VLAN where the destination address is attached. If found, the frame can be forwarded out the corresponding switch port."

And then on page 36,

"L2 forwarding table: The frame's destination MAC address is used as an index, or key, into the content-addressable memory (CAM), or address, table. If the address is found, the egress switch port and appropriate VLAN ID are read from the table."

To me, this reads as if the destination MAC address determines the VLAN that the frame will be forwarded on, which to the best of my knowledge is absolutely not the case. A switch with multiple VLANs should keep either a separate table for every VLAN, or (more likely) use the VLAN and destination MAC together as the key in the lookup.

I put together a lab in GNS3 that seems to support my understanding. I can share configs and more details if desired, but in short I have an IOSvL2 (layer 3 switch) node running without any SVIs (so just as a L2 switch) that is learning the same MAC address on 4 different VLANs across 4 different access ports, and I have no trouble forwarding either unicast or broadcast traffic within the correct VLAN, proving (in my mind) that the destination MAC does not have any influence on the VLAN.

I can accept that I might be nitpicking a bit about the few quoted statements, but I want to be sure my understanding is good. Specifically, that the VLAN and MAC are used together as the key for a CAM lookup.

If that understanding is not correct, is there any resource that gives more detail on what keeps a frame within its own VLAN in Cisco hardware?



Need assistance F5 GTM config .

Hey all,

I'm new to F5 and planning to install first F5 Big-ip LTM + GTM to load balance proxy traffic at two sites which will act as backup to each other. F5 is inline between users >> Proxy Servers >> Internet.

Here is the network diagram of two sites. https://imgur.com/a/sSN8Q1L

Goal is to set up LTM+GTM for traffic processing and failover as below: Normal operation: 1) When Site-A F5 receive DNS query from Site-A LDNS >> Send it to Site A Vip. When Site-A F5 receive DNS query from Site-B LDNS >> Send it to Site B Vip. 2) When Site-B F5 receive DNS query from Site-B LDNS >> Send it to Site B Vip. When Site-B F5 receive DNS query from Site-A LDNS >> Send it to Site A Vip Failover operation: 3) When Site-A F5 receive DNS Query >> If Site A Vip is Down >> Send it to Site-B Vip 4) When Site-B F5 Receive DNS Query >> If Site B Vip is Down >> Send it to Site-A Vip

Here are the ips for example: Site-A Virtual Server= 10.1.1.100 Real server =10.1.2.10 & 20
(10.1.1.100 =webproxy.technet.com 10.1.1.x = internal vlan 10.1.2.x=external vlan) Site-B Virtual Server= 10.2.1.100 Real server =10.2.2.10 & 20
(10.2.1.100 =webproxy.technet.com 10.2.1.x = internal vlan 10.2.2.x=external vlan)

I did the basic config for LTM like node, pool & virtual server. But I’m confused what ip to use for GTM and how to configure GTM to provide name resolution based on client DNS server and irules to divert traffic.

What config do I need on LTM + GTM?? LTM: 1) Configure Node – Real servers ( 10.1.2.10& 20) 2) Configure Pool – Proxy Server Pool ( Add node + port) 3) Config Virtual Server – (webproxy.technet.com/10.1.1.100)

GTM/DNS 1) Config Listener (Can I use Vip??? Or need new ip?? ) 2) Config Wide ip (Do I need different ip in same internal subnet 10.1.1.x??) Does the hostname should be webproxy.technet.com??) 3) Do I need GSLBPool?? What type, SRV, A, CNAME??? Which Member ip to add, wide ip of both site??? 4) Config Data Center- Site-A & site-B 5) Do I need GSLBServer?? Which server to add Vip or Real??? 6) Where do I apply rule to divert traffic?? Under Wide IP???

When user send DNS request for webproxy.technet.com which ip will resolve it Wide ip?? Or Vip??

Does anyone know hierarchy chart for GTM config? Like LTM (node >> pool >> Virtual server). Could someone provide a break down of the objects and config?

Thanks in advance.



Vendors are jerking us around, switch stacking help. (xpost /sysadmins)

I'm no hardware guy and I'm not sure if the answer is based on the brand, but 4 vendors are contradicting each other and I'm starting to lose hope in finding a correct answer.We're installing new switches in a 7 floor building, each floor has around 4 - 5 switches running in stack configuration to appear as a single virtual switch, those stacked switches will all connected to an aggregation switch eventually. Problem is no one seems to figure out what are the hardware requirements to connect those stacked switches to an aggregation switch, I know that we need 2 SPF ports to configure stacking in a loop configuration, but what is the correct way to connect them to the aggregation switch?

  1. One Vendor says that every physical switch needs 3 SPF ports, 2 for loop and 1 to be connected to the aggregation switch using a direct cable, which is totally crazy and goes against the goal of stacking.
  2. Another says that all switches in the stack need only 2 SPF ports, and that I can close the stacking loop by taking one of the SPF ports in the first and last switches and connect them on the aggregation switch.
  3. Another says that all switches in the stack need 2 SPF ports to close the loop, but the first and last switches in the stack needs 1 additional SPF port to connect them to the aggregation switch.
  4. the last one says that all switches in the stack need 2 SPF ports to close the loop, but the first and last switches in the stack needs 2 additional SPF port instead of 1 to connect them to the aggregation switch.

I'm leaning toward answer 4, but a confirmation from one the hardware masters here with a link that I can stick it to the vendor faces will be awesome.