Sunday, November 4, 2018

How to "upgrade" DMVPN

Hey, Reddit!

For my final year of school project i chose to write about DMVPN, especially in connecting smaller branch networks.

My question is: This technology is kind of old. Can you suggest me any ways of making it more viable and/or more complex ( like integrating something ) ?

Thanks!

P.s: I am sorry if this post isnt for here or doesnt meet the guidelines. I will delete it ASAP if thats the case.



How does Link-Aggregation balance-xor exactly work?

I can't really put a grasp on what it exactly does, can somebody explain it to me?



Two post telecom racks

What are ya'll using for two post racks? I'm looking specifically for a two post with verticle cable management and the ability to add a verticle power strip on either side.



Packet dropping between switch and server - I'm out of my depth?

Hi all,

Basically I have been getting a lot of alerts from Netdata about packet drops on my server in my homelab.

net_packets.enp0s20f3 CHART inbound packets dropped ratio (was warning for 12 minutes) the ratio of inbound dropped packets vs the total number of received packets of the network interface, during the last 10 minutes ALARM enp0s20f3 FAMILY Recovered from WARNING SEVERITY 

It's a Proxmox 5.2-6 VM host on a Supermicro A1SRi 8-core Atom board. Two of ports (enp0s20f2 & enp0s20f2) are LACP bonded to form bond0. I am getting packet drop notifications on all enp0s20f2, enp0s20f2 & bond0 at different intervals (at least one email a day).

The main switch is a Ubiquiti UniFi US-24, again with aggregation configured.

The main communication from this server is to the FreeNAS server on the same switch. The NAS uses the same 8-core Atom board, and also with LACP configured in the same way.

Everything SEEMS normal to me with my general usage.

So my main question is - should I be worried? I guess I should?

And what/where should I start looking where the problem is? Unfortunately I have no clue, but am keen to learn.

Is the problem Netdata reporting too aggressively or incorrectly? NICs on the Proxmox or FreeNAS malfunctioning? The switch not aggregating correctly? Mis-configuration on the Proxmox or FreeNAS?

In the past I had a D-Link DGS-1210-28P and I didn't have as many packet drops as I have now. But the D-Link died a premature death.

Thanks.



TLS1.3 and DoH



Multihomed BGP: full tables or default route?

I am about to turn up a new eyeball network. ASN and IPs all sorted. Primary and secondary upstream selected. Local IXP with the usual suspects. More at a larger IXP less than 10 ms away.

Looking at routers it struck me: do I actually need full tables for this network?

Taking a default is simple. Simple is good. And I don't have to worry about routing table growth. Plus it doesn't hurt that this expands my options for edge routers and possibly lowers my price points.

The obvious cons are risk of asymmetric routing, no ASN information in flows and uRPF probably won't be as useful. The asymmetric routing issue is lessened by the fact that the IXP routes will take a good chunk of traffic and that the primary upstream would be the default choice for outgoing traffic most of the time anyway.

There are no BGP customers. For the sake of the argument, assume there won't ever be either.

What am I missing? I'm trying to let go of my preconceived notions and challenge my assumptions.



Keep up with WorldWide updates For Network Admins/SysAdmins

u/Kitosaki asked me to make this post so I hope this help people like u/letsgobaby. Please upvote this post if you find it useful so others can see it too. Thanks.

Subscribe to the following blogs;

Cisco blogs Security

https://blogs.cisco.com/security

Talos blog

https://blog.talosintelligence.com/

Naked security by Sophos

https://nakedsecurity.sophos.com/

Microsoft Security Update Guide

https://portal.msrc.microsoft.com/en-us/security-guidance

Apple Security updates

https://support.apple.com/en-au/HT201222

US-Cert

https://www.us-cert.gov/

Trend Micro

https://blog.trendmicro.com/trendlabs-security-intelligence/

Symantec

https://www.symantec.com/blogs/

VMware Security Advisory

https://www.vmware.com/au/security/advisories.html

Veeam forums

https://forums.veeam.com/

Digicert blog

https://www.digicert.com/blog/

G Suite update/blog

https://gsuiteupdates.googleblog.com/

O365 update/blog

https://blogs.technet.microsoft.com/o365guy/

The Hacker News

https://thehackernews.com/

Join Slack and follow below Slacks; bearing in mind that you need to be invited or request to join these channels. If you message me your slack I am happy to invite you to the below slack channels.

MacAdmins

Macadmins.slack.com

Windows Admins

Winadmins.slack.com

VMware

Vmwarecode.slack.com

Red Hat Linux Admins

Redhat-admins.slack.com

Tech Masters

Techmasters.slack.com

Android United

Android-united.slack.com

Android Chat

Androidchat.slack.com

Subscribe to the following subreddit;

https://www.reddit.com/r/apple/

https://www.reddit.com/r/Cisco/

https://www.reddit.com/r/CiscoNetworking/

https://www.reddit.com/r/ios/

https://www.reddit.com/r/linuxadmin/

https://www.reddit.com/r/macadmins/

https://www.reddit.com/r/mikrotik/

https://www.reddit.com/r/security/

https://www.reddit.com/r/sysadmin/

https://www.reddit.com/r/Veeam/

https://www.reddit.com/r/vmware/

https://www.reddit.com/r/windows/

https://www.reddit.com/r/windowsadmin/

https://www.reddit.com/r/HyperV/

https://www.reddit.com/r/NakedSecurity/

https://www.reddit.com/r/Ransomware/

Useful websites to bookmark

https://mxtoolbox.com/

https://www.ssllabs.com

https://www.ers.trendmicro.com/reputations

http://www1.commtouch.com/Site/resources/reputation_query/default3.aspx

https://toolbox.googleapps.com/apps/dig/#TXT/

Useful websites to bookmark Wi-Fi specific

https://www.adriangranados.com/blog

Cyberthreat “real time”

https://cybermap.kaspersky.com/

https://threatmap.checkpoint.com/ThreatPortal/livemap.html

https://www.talosintelligence.com/

If I have missed anything please comment below.



Change DNS outside router?

I'm running pihole (https://pi-hole.net) and would therefore want to change my DNS on my all my lan+wifi devices. But the router I got from my IPS doesn't allow me to change DNS and therefore I've set DNS manually in on my computer, phone, tv etc. But there are some devices that I don't know how to change DNS on. For example my wifi IR blaster and some smart wall outlets.

Is it somehow possible to change the DNS on these type of devices anyway?



Why is upload more expensive than download?

I don't get it. Network transit and cloud providers generally charge (a lot) more for upload vs. download traffic.

Why is this? Making a couple of assumptions, but surely at the network device level, the chips that send/receive traffic are almost identical. They are doing the same thing just in different directions, so why would one be more expensive than the other?

At the media level, I'd expect it to be the same. A piece of cable or fibre can send data either way and doesn't become more expensive to use in a certain direction.

I can't think of any extra costs that need to be passed on from handling upload traffic, other than you are then accepting more data into your core network and so need a better (more expensive) core, but then the same could be said for downloads?



Seeking interview suggestion for Network Engineer : Transport Dwdm lab.

I am pretty new in this field. I have a little experience on SDH and Dwdm. I was wondering what kind of questions I might be asked and in which topics I should be focusing on? Thank you.