Wednesday, October 10, 2018

Cisco Nexus 9000 QSFP to SFP+ 1470nm

We are buying a 10Gbit wavelength from our ISP and want connect that to our existing Nexus 9000-series switch. We have some QSFP ports on the Nexus switch that we wanna use. Is there any adapter sfp module that enables us to running 10G?

The ISP is are giving us 1470nm 40km on one side and 1310nm 20km on the other side. The speed is 10G.



Small Office Network. Netgear VLAN, HPE 1950-12XGT-4SFP+

I've recently joined small-ish company and now have the pleasure to also be partly responsible for our network, which is a pure Layer 2 network. We have a few Servers running with the usual services (smb, email, voip) but also provide 2 even smaller subcompanies with network intrastructure too (some shared services). The current network consists of mostly Netgear switches, which work reasonably well in this simple configuration, besides the occasional needed resets every few weeks/months.

I've been toying with the idea of improving our infrastructure to improve network availability and add some much needed separation. Am i correct in the assumption, that it would be best to add separate vlans for the services and look for a layer 2+/3 switch as our main switch for intra-vlan routing?

If we have a shared voice vlan, does this mean i have to hand over vlan trunk to their switch. We're also responsible for those, but it has happened in the past that people fiddled with them, so i'd like to make sure our internal network can no longer be easily influenced by any changes in the network topology at their end. Thinking about rogue dhcp servers, loop detection, etc. Any recommendations?

We have a Netgear GS724Tv4 which appears to support vlan routing as a L3 Feature. I know we should probably be looking for a more enterprise grade solution, but does anyone have experience with netgear VLAN routing, any known problems with those (i vagely remember reading about performance issues)?

As an alternative, i'm also considering the HPE 1950-12XGT-4SFP+ as a main switch , which peaked my interest because of it's 10G RJ45 capabilities for future upgrades (bandwidth increase to file server and access switches), does anyone have one of those running in a similar configuration?

I also remember reading that 10Gbit can be run over Cat 5e/6 for shorter runs, any oppinions or experiences in that department?



CiscoASA5505 - New WAN IP - Windows SBS DNS not working

Hello:

Today I had to install a new ISP into a Cisco 5505 for a remote office of ours...

Tunnel is up passing Phase1 and Phase2. I can SSH into the new external IP all looks good from a networking standpoint *I believe.

However DNS from a Windows SBS server is not working. It was not touched before this cutover so the only change was to the WAN IP on the 5505. We can ping 8.8.8.8 from the users PCs but unable to hit google.com etc.. We cannot ping 8.8.8.8 from the SBS server.

The SBS was setup with the DNS to point to itself inside its NIC then the forwarders were blank in the admin controls. Again nothing was changed other then the WAN IP on the firewall.

Any help guidance would be greatly appreciated.



Cradlepoint AER1600 LP6 module - does anyone have one they can rent to me for a week?

Got screwed over by a Cradlepoint vendor who shipped wrong item, then refused to replace in a timely manner. Have an out of town job for a week and I need the LP4 to LP6 upgrade module. PM me if you can help, thanks.



Cisco FirePower - High unmanaged disk usage

FMC is saying that one Firepower device has "High unmanaged disk usage on /Volume".

I've googled around but haven't found anything particularly useful about the message. Most of places tell you to check and clean out various directories on the drive, but I've done that and it is nowhere close to full. I thought maybe disk usage may refer to disk activity but I don't think it is.

I know it was a bug in 6.2.2 and below but I'm running 6.2.3 so in theory that shouldn't be the problem. I could upgrade it further but I don't have 5 years to spare right now.

One other thing, the device was unable to talk to FMC for a couple of weeks so maybe that has something to do with it. I thought maybe it buffered all its info in that period of time and it needs to be manually removed, but I can't find anything significant to remove.

Anyone dealt with this before?



Hpe switch Vlan understanding help!!

Coming from a cisco world with switch ports access and trunk, now in my new job found very difficult and struggle with hpe office connect switch 1910 and 1920. I have read a lot of guides but i cant understand the options tagged,untagged,access,hybrid,trunk,include,exclude per interface and per vlan options!! For example i have 3 vlan(1-native,5-voice,10-data) router connected to port 1 of switch and the ports 2-9 will be access and are only for data and only pc will be connected, 10-15 are for ip phones and after pc connected so access for the both vlans.Of course for the uplink (trunk)?? i need also all the vlans to be passed to the switch!!! Some ideas?? Thank you!!!



@Risk Technologies

Hello fellow IT people,

I was curious if anyone has any experience with using @Risk Tech for network monitoring. I work for a Transit Authority and part of our greater risk pool, they want us to implement this device to monitor traffic and send reports back. It takes north/south east/west netflow traffic having a few legs into the network.

We have Palo Alto 3020s in place as our FW and dont really see much of an added benefit to using this. Although we might be forced to use it for insurance reasons, I just wanted to see if anyone on here has any experience with them specifically.



Multiple Juniper security advisories

The whole list is here.

Happy upgrading!



Switch Cost Differences

I'm looking at different options for a new network stack for a SMB currently built on Cisco SG300's.

I'm a long time SMB admin, did some time at an MSP and have only ever really dealt with businesses between the 50-100 user mark. As such, I've seen a lot of lower end gear, and only at one larger client do I recall seeing something like a stack of Catalyst switches.

I've long made due with the small business grade equipment, and haven't really ever seen a need to upgrade.

Now at my current gig, I'm looking at implementing 10gig for our virtualization hosts and revisiting our whole stack. We don't have a lot of feature needs (at least I don't think we do).

In any case, I've been looking at every different vendor, from Ubiquiti to Aruba to Cisco..

My question: What is so much better about a $3000 switch than a $300 switch? How do businesses justify such a large expense?

I'm asking from a position of ignorance.. I honestly don't know.



Failure at the interview, career advice for next step

I work at one of the bigges telecom company as a Network Security Engineer. My main role is to maintain and update every single ACL in the whole company. It is about 100+ ACL for 100million user. Plus I do policy creations and updates in F5 Big-IQ and Juniper Space. And a little bit of VPN support. Mostly creating new VPN profiles(IKE1-2) in fortigate. I got CCNA, CCNA Sec, JNCIA, Linux+ project+, about to get Redhat admin. I want to get out of here to get a SDN or devop type of job. But looks like easier way out is Cisco or F5.

My previous role was similar except it was in Infrastructure security and all I was doing was completing MOPs by copy/paste. Now at least I am creating those for ACL and sometimes for routing updates for VPNs.

So I just had an interview for a Sr. Network Engineering Architect job. I was good with all BGP, OSPF and VPN questions. But, my weaknesses was scripting and SDN experience. I know SDN fundamentals, but didnt really get any expierence or hands on. And there are so much shit out there when it comes to SDN.

So enough of background. I am planning to get some more certs or just study on my weaknesses.

Path 1- Study CCNA-DC & CCNP and maybe squeeze CCNP-Arch since CCNP covers first 2 examp of this.

Path 2- Study Devops stuff Openstack, Ansible, Dockers jenkinsv and python/shell scripting etc...

Path 3- Go F5 load balancing & FW path. Get F5 101, 201, 301,302,303,304 certs(CCNP equivalent of F5). I can knock out 101 and 102 in 1-2 months all together, but others will take time.

Probably each path will take about 10-14 months to study and complete. I could do may be a little faster, but I got 6 years old kid and 8 months old baby.

What would get me a Sr level network/devops engineer job and bring at least $100K a year?