Monday, October 15, 2018

As soon as DHCP Scope Vendor Option is set devices on HP 1820 get no DHCP offers

Hi,

first of all im no Network admin so if my problem is unclear im sorry in advance.

So we have Unify IP 35G HPA IP Phones on a seperate VLAN. The vendor gave us Scope Options for the Scope(Name,VLAN,DLS Server). These work fine unless the Phone is behind one of our HPE OfficeConnect Switch 1820 8G. As soon as i set the Scope Option the Phones wont renew their lease and cant reconnect - they work fine if they had a lease/reservation before that. Without the Option they work fine.

I would have understood this if it was the other way around(no scope Option - no vlan and no dhcp)

The thing is if the options are not set the autosetup of the phones wont work and i have to do it by hand.

Phones -> HP 1820 -> HP 2530-48G-PoE+-2SFP -> Core

Does anyone have an idea i could try?



DNS IP change in DHCP not applying on ER-8-PRO

https://ift.tt/2IX1Fm5

WatchGuard Internal to DMZ

Hello,

Maybe a stupid question but I am new to WatchGuard UI. We have an server running in the DMZ with an external IP assigned. If we try to ping it from inside the network it redirects to the external IP. Is it possible to set it up so if we try to access it from inside the network it resolves the internal IP?

Kind regards,



Importing custom snort rules into Firepower.

Does anyone have any idea how to do this?

I've gone to Policies -> Intrusion -> Intrusion Rules and tried to import a text file with the following rule in.

alert tcp any any <> any any (flow: established; msg: "APT28 - CompuTrace_Beacon_UserAgent"; content: "|0d0a|TagId|3a| "; fast_pattern; content: "POST / "; content:!"namequery.com"; content:!"Host: 209.53.113."; content:!"dnssearch.org"; content:!"Cookie:"; content:!"fnbcorporate.co.za"; content:!"207.6.98."; pcre: "/Mozilla\/[0-9]{1,2}.[0-9]{1,2} \(compatible\; MSIE [0-9]{1,2}.[0-9]{1,2}\;\)\x0d\x0a/";)

I get an error of "Failed to install rule update"

The documentation Cisco provides for this is terrible. I assume I might be missing GID or SID feilds etc , but not really sure.

r/https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/117924-technote-firesight-00.html

I did raise this with TAC, who were no help and insist they do not provide support for custom snort rules and redirected me to the above documentation. Not really helpful.

Cheers



XR L2transport question?

Hi Guys,

I have this scenario wherein I have 2 routers need to communicate and its passing thru l2vpn that is configured on XR. Now I would like to confirm the below setup and ask whether we can impose/tag a vlan on XR main-interface in ethernet portmode l2transport.

Scenario:

RTR1 ----XR9k1--l2vpn---XR9k2-----RTR2

RTR1 is directly connect to XR9k1 and l2vpn established towards to XR9k2 to RTR2.

Configuration:

RTR01:

int g0/0

ip address 1.1.1.1/30

XR9k1

interface GigE0/0

l2transport (is this allow all vlan?)

XR9k2

GigE0/1.100

encapsulation dot1q 100

rewrite ingress tag pop 1 symmetric

RTR02 (under sub-int)

int g0/0.100

encapsulation dot1q 100

ip address 1.1.1.1/30

Now my question is this a correct setup?

  1. Since RTR1 sending without any tag, when it reaches XR9k02, XR9k02 will tagged it as 100 and forward to RTR02.
  2. RTR02 will match the incoming traffic with tagged of 100, while the reply of RTR02 will have a tag.
  3. Reply from RTR02 will now pass to XR02 which then be process by match the encap, adding additional header for MPLS, Since i dont have "rewrite ingress tag pop 1 symmetric" on XR9k01 do you think it can reach RTR01 succesfully?

Thanks



Aside from certs, how can I keep my skillset relevant while going to school?

With all the gen ed work, I'm trying to avoid being sucked into a big vacuum, where I come out of it without relevant skills and knowledge. Also to note, I wouldn't mind shifting my focus to something like IA further down the road.



TE Tunnel is up but path and signaling has issue?

Hi Guys,

I'm having issue building a TE tunnel with path and signaling.

Output:

Name: R1_t0 (Tunnel0) Destination: 4.4.4.4

Status:

Admin: up Oper: down Path: not valid Signalling: Down

path option 1, type dynamic

Config Parameters:

Bandwidth: 0 kbps (Global) Priority: 7 7 Affinity: 0x0/0xFFFF

Metric Type: TE (default)

AutoRoute: disabled LockDown: disabled Loadshare: 0 bw-based

auto-bw: disabled

History:

Tunnel:

Time since created: 1 hours, 11 minutes

Number of LSP IDs (Tun_Instances) used: 150

Path Option 1:

Last Error: PCALC:: No path to destination, 0000.0000.0144.00

R1#sh mpls traffic-eng topology 4.4.4.4

IGP Id: 0000.0000.0144.00, MPLS TE Id:4.4.4.4 Router Node (isis level-2) id 15

link[0]: Broadcast, DR: 0000.0000.0144.04, nbr_node_id:16, gen:20

frag_id 0, Intf Address:10.3.13.2

TE metric:10, IGP metric:10, attribute flags:0x0

SRLGs: None

physical_bw: 100000 (kbps), max_reservable_bw_global: 75000 (kbps)

max_reservable_bw_sub: 0 (kbps)

Global Pool Sub Pool

Total Allocated Reservable Reservable

BW (kbps) BW (kbps) BW (kbps)

--------------- ----------- ----------

bw[0]: 0 75000 0

bw[1]: 0 75000 0

bw[2]: 0 75000 0

bw[3]: 0 75000 0

bw[4]: 0 75000 0

bw[5]: 0 75000 0

bw[6]: 0 75000 0

bw[7]: 0 75000 0

R1#sh mpls traffic-eng topology path destination 4.4.4.4

Query Parameters:

Destination: 4.4.4.4

Bandwidth: 0

Priorities: 0 (setup), 0 (hold)

Affinity: 0x0 (value), 0xFFFFFFFF (mask)

Query Results:

% No matching path to destination, 4.4.4.4 <-----

Debug output:

*Oct 15 14:11:47.567: TE-PCALC: Tunnel0 Path Setup [0000.0000.0144.00] 4.4.4.4: (isis level-2)

*Oct 15 14:11:47.567: TE-PCALC: bw 0, min_bw 0, metric: 0

*Oct 15 14:11:47.571: TE-PCALC: setup_pri 7, hold_pri 7

*Oct 15 14:11:47.571: TE-PCALC: affinity_bits 0x0, affinity_mask 0xFFFF

*Oct 15 14:11:47.571: TE-PCALC path type unidirectional

*Oct 15 14:11:47.571: TE-PCALC endpoint switching capability psc1, link encoding packet

*Oct 15 14:11:47.571: TE-PCALC transit switching capability psc1, link encoding packet

*Oct 15 14:11:47.575: TE-PCALC_PATH: No Path

Verified that all of the below path/rtr has mpls te enabled.

R1#trace 4.4.4.4

Type escape sequence to abort.

Tracing the route to 4.4.4.4

1 10.1.11.1 [MPLS: Label 24012 Exp 0] 8 msec 12 msec 32 msec <--- XR

2 10.11.12.2 [MPLS: Label 24003 Exp 0] 8 msec 56 msec 40 msec <-- XR

3 10.12.13.2 [MPLS: Label 24002 Exp 0] 12 msec 16 msec 60 msec <-- XR

4 10.3.13.2 64 msec 64 msec 56 msec <--- IOS

Thanks



Sunday, October 14, 2018

My own make believe ISP

https://ift.tt/2pQQEKi

Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Are there any MAC OSX VM hosting clouds that offer private network connectity like Express Route, Direct Connect or Cloud Connect?

Microsoft Azure has Express Route

Google Cloud has Cloud Connect

AWS has Direct Connect

Alibaba has Express Connect

However, none of these clouds can offer Mac OSX virtual machines, because OSX virtual machines can only run on a hypervisor running on Mac hardware.

There are many Mac hardware clouds:

xcloud.me

macstadium.com

virtualmacosx.com

(several others)

Do any of the mac hosting environments have a private networking connectivity option? If so, preferentially ones that have partnerships with Equinix Cloud Exchange?