Wednesday, October 31, 2018

Client VPN with Azure AD support and Microsoft Authenticator.

https://ift.tt/2EWfXVH

Receiving Spam calls from our Cisco Phone system

Hey guys, maybe you can help me with this one.

I've been receiving spam phone calls coming from our Cisco phone system. When I checked the logs from our phone system I see that a call came into it from the spam company and came out to my cell phone and several other numbers.

How is this possible? Is there a vulnerability somewhere I am missing?

Our design:

\- 1 publisher at Data Center \- 1 Subscriber at HQ \- Voice Gateway at Data Center and at HQ both with 2 PRIs each \- ASA at data center used specifically for VPN connected phones. 

- Subscriber and publisher communicate over MPLS



Multicast on l3 switch stub

So I've come at a wall that I seem to not be able to get over. I've got a network where multicast traffic is pushed over the dmvpn. What I am having trouble is that I cannot seem to figure out how to get the phones on the l3 switches network to join the multicast RTP stream. So the multicast server does reach the phones with text and it preps the phone just no audio. I refrenced this https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipmulti_pim/configuration/15-s/imc-pim-15-s-book/imc_stub_routing.html as a guide to help me but it didn't work. Does anyone have an idea of where else I should look to solve this issue? As a reference multicast traffic is pushed over the DMVPN and this l3 switch route is pushed as a redistributed route from router its connected too.



End of Sale and End of Life

Hello Everyone. Happy Halloween.

How normal is it to have EoL/Eos devices running in your infrastructure some even playing the important role of critical device.

Currently, in my environment, we have a few ASAs5510-5585 and Cisco 4900/4948. Ok that's a lie its more than a few. Its quite a lot. We're talking about an entire DC running of these switches. Has anyone worked in such a network where the refusal to purchase new/supported equipment is resisted to the extent that they rather run of unsupported hardware?

Note that not everywhere in this network is bad but there is a crap ton of hardware like this that is EoL functioning as "Core routers".



Problems connecting to work network from home compared to other wireless networks.

Hello, I was recently hired for a company which provided me with a laptop and supports working from home on occasion. To connect to the internal work network, I must connect to the internet and use Pulse Secure.

For some reason, when connecting to my router (wireless or wired) from home, and then connecting via Pulse Secure, when I do a tracert on a work domain I get a 92.XX.XX.XX IP. After talking with my work, this is their 'external' gateway and has restrictions on what I can do. It will timeout trying to connect to databases, things like that.

If I hard wire directly into my Verizon modem and do the same tracert, I get a 10.XX.XX.XX IP, which is the correct internal gateway I need to use. I can do all my work with no issues this way.

I have a backup wireless router and tried both to replace my main router and saw the same issue on both. I even reset my bakup router to its factory defaults and saw the same issue.

Lastly, I went to Starbucks and connected to their wireless network and got the correct internal gateway, so I believe that narrows the issue down to my router.

I'm a novice at best when it comes to networking and how DNS lookups work. Anyone have any suggestions on how to correct this issue?

Thanks!



Cisco per IP Policing

Hello Redditors,

I've got the following situation.

Currently We have a situation where we have sets of IPs (that change over time, get bigger or smaller) that we need to police (rate-limit) when going through an specific interface, the catch here is that each IP must have assigned a maximum bandwidth (so we don't want to deal with shared values).

So, for instance we have:

1.- 10 IPs that must be limited at 10 mbps each

2.- 50 IPs that must be limited at 30 mbps each

Some times we have to move IPs from 2 to 1 or vice-versa, or just remove them altogether. We could achieve this using MQC, we kind of do it, but this means adding a class statement per IP, which is not something I want to do anymore (if possible), I'd like to have something like this:

policy-map IF\AA_OUT)

class class\10_mbps)

match ACL\01)

police each IP to 10 mbps

class class\30_mbps)

match ACL\02)

police each IP to 30 mbps

So adding, removing or changing bandwidth per IP would be a matter of just removing or adding entries to the ACLs. I've found something called flow micropolicer, but all the documentation refers to the Cisco 6500 (we need it to work on ASR1001-X and 7200), and also the documentation points that this can only be done in the ingress-direction, which won't work for us since we need to limit only outgoing traffic over one of the interfaces, not all.

Any help on this? doable? or stick at adding class statements per customer?



SDN networks. What do you know about it? Are someone working with it?

Recently I heard about this topic software-defined network(SDN) and I want opinions and real experiences with it.



ethernet-switching-options missing on EX4300 (v17.3)

Hi Guys, sorry for the noob question. I am trying to configure voice vlan on the Ex4300 and I am using the latest JTAC release. The switches are in a virtual-chassis. When I try go into edit mode and the try "set ethernet-switching-options" the command is not found at all. Any ideas on what I am doing wrong? Auto complete only shows event-options but nothing about ethernet-switching-options. I am wondering if it has anything to do with the cli layout changes on 17x or a different approach when inside a vc.

Thanks in advance.



Tuesday, October 30, 2018

Simple Open Source Asset Mgmt

Across our many tools we have a lot of drift/gap on the asset list. We manage around 1500 switches, routers, firewalls, load balancers etc and are looking for a very simple open source asset management tool that we can use as the single source of truth. We don't want any bells and whistles, just a simple snmp poll, store the information and an API that allows me to access the list from other tools.



Any idea whats wrong? Asked in one of the interviews

Dear Support, My virtual machine is talking to our on-premise Hadoop cluster and we have observed connections dropped by the VM after approximately 15 minutes after being established. We have tried tweaking our cluster and the VPN, but it did not work. We have also disabled any firewall or NAT: our cluster is connected directly to the Internet. We ran a TCP packet capture on one of our routers and we do see the following:

408 7.963058 178.124.133.65 172.16.72.34 TCP 66 http > 42867 [FIN, ACK] Seq=312 Ack=11 Win=14592 Len=0 TSval=3673141343 TSecr=234006479 409 7.963204 172.16.72.34 178.124.133.65 TCP 66 42867 > http [FIN, ACK] Seq=11 Ack=313 Win=15744 Len=0 TSval=234006482 TSecr=3673141343 410 7.995556 178.124.133.65 172.16.72.34 TCP 66 http > 42867 [ACK] Seq=313 Ack=12 Win=14592 Len=0 TSval=3673141351 TSecr=234006482

Please help, this is a fault in your network, I need a solution ASAP!

Customer, Inc.