Monday, October 15, 2018

Quick MLS QoS question

Say for example I have 1 port NOT configured for "mls qos trust dscp". Can a packet that came in (on a trusted port) and was properly written with DSCP egress this port with that same DSCP value? Meaning does it trust EGRESS and INGRESS dscp or just INGRESS?



Windows Server?

How many of you use Windows server in your line of work? After my CCNP I'm debating getting either the MCSA Server 2016 or the RHCSA certification. Based on job postings in my area it seems like Windows is in much more demand.



DHCP Spoofing

In order to demonstrate the value of DHCP Spoofing and Dynamic ARP inspection I'm labbing the vulnerabilities they defend. Using VirtualBox I have one client Windows 10 computer, another running OpenDHCP and Kali Linux all sharing a virtual network.

First I tried DHCP starvation with Yersinia and DHCPig originating from Kali targeting the OpenDHCP server. Thousands of DHCP Discover messages are generated and temporarily occupy resources of the DHCP server, but neither tool completes the DHCP transaction with DHCP Offer messages to confirm interest in the lease and finalize the handshake. The result is that when the flood of DHCP Discover messages ends the DHCP server resumes normal operation almost immediately instead of holding onto full leases for the duration of a full default lease to exhaust the scope. I can watch the traffic in WireShark and confirm that Discover messages are followed by Offers from the server, but again, no Requests and Acknowledge messages.

The other vulnerability through DHCP traffic spoofing I'd like to explore is DHCP Spoofing where Kali releases the lease that the client Windows 10 computer made with the OpenDHCP server. Yersinia and DHCPig are supposed to be able to exploit this also, but if I monitor WireShark traffic, no DHCP Release message is generated by Kali.

Are there other tools that I should be using? I’ve researched tutorials for these exploits and what I’m trying to accomplish is pretty basic as far as requirements from the tools. In other words default settings should be able adequate. Has anyone else tried to recreate these exploits?

Thanks in advance!



Where to learn?

I love computers and networking. I have a very basic knowledge of networking and the ability to get a basic LAN setup with network printers and other accessible devices.

I want to work in this field and make a career in networking. There are so many ways to "get certified". I don't know what's relevant and what's not. What are some good prerequisites for a good working knowledge of modern networks?

If this is in the wrong sub, I apologize but you all seem to know what you're talking about.



Time to Upgrade Data Center Networking Gear, How to Compare Different Options?

We're largely moving our data center operations to a colo facility, but we still have some that's going to hang around for a while. It is time to upgrade the networking gear. I'm looking for pizza box options (not chassis) and I'm having a hard time figuring out the differences between platforms.

Like, how is the QFX line different from the Nexus line? Should I be considering Arista as well?

This new core will be largely collapsed and catch all of our site-to-site connections (mostly dark fiber, some managed services) and will need to run OSPF to support these connections. It will also connect the new servers and new SANs. I'm pushing for using 10G SFP for the new servers and SANs, but we'll see. The new switches need to be 10G/1G capable in a potential mix of fiber and copper, multi and single mode. I specify the multi and single mode because I've noticed that some boxes seem to come with lc interfaces, and I'm not sure if they support one or both.

We're adding two servers and one SAN, and will need to support some legacy servers for a period of time.



Clearpass 802.1x deployment for wireless Question

I have my 802.1x for wireless pretty much completed and ready to roll out using clearpass. I had a question regarding the use of certificates. It seems that I may have misunderstood how the certificate on the clearpass was used. We are using EAP-PEAP so the cert is deployed only on the CPPM server. The Certificate is a publicly signed cert with the intermediate installed on the CPPM. When users join the wireless network using their phone (android or apple) they get a notification that the network is untrusted. In the iPhone it actually shows the cert with a small "untrusted" blurb underneath it. Is this the type of behavior expected out of phones when joining a new wireless network?



How many people join the Cisco certification exam every year?

No text found

As soon as DHCP Scope Vendor Option is set devices on HP 1820 get no DHCP offers

Hi,

first of all im no Network admin so if my problem is unclear im sorry in advance.

So we have Unify IP 35G HPA IP Phones on a seperate VLAN. The vendor gave us Scope Options for the Scope(Name,VLAN,DLS Server). These work fine unless the Phone is behind one of our HPE OfficeConnect Switch 1820 8G. As soon as i set the Scope Option the Phones wont renew their lease and cant reconnect - they work fine if they had a lease/reservation before that. Without the Option they work fine.

I would have understood this if it was the other way around(no scope Option - no vlan and no dhcp)

The thing is if the options are not set the autosetup of the phones wont work and i have to do it by hand.

Phones -> HP 1820 -> HP 2530-48G-PoE+-2SFP -> Core

Does anyone have an idea i could try?



DNS IP change in DHCP not applying on ER-8-PRO

https://ift.tt/2IX1Fm5

WatchGuard Internal to DMZ

Hello,

Maybe a stupid question but I am new to WatchGuard UI. We have an server running in the DMZ with an external IP assigned. If we try to ping it from inside the network it redirects to the external IP. Is it possible to set it up so if we try to access it from inside the network it resolves the internal IP?

Kind regards,