Tuesday, January 1, 2019

Technical debt in networking?

Hello, I work on the image analysis side of remote sensing.

I got tasked with setting up a simple queueing messaging system. As such, in reading up and deepening my knowledge I started thinking about what technical debt there is accumulated in networking as a discipline. Such as IPv4 addresses running short. Most learning sources seem to show very graceful transition from early implementations (e.g. CSMA - CSMA/CD et.c.). What do you foresee will be the biggest issues in the near future in terms of limiting current implementations?



Is it possible to write an arpccess list cisco ios-xe?

There’s a customer owned device (Cisco isr Router) connected to one of our 3850’s that’s constantly answering arp requests for other devices on the same lan segment and stealing their arp both from other hosts and our firewall.

The customer will not turn proxy arp off and will not tell us what subnet mask they have configured on the interface. Basically they’re being a rude tenant.

This has caused a lot of outages for us over the past 20 days, the worst one got me called in on Holliday just this week that at least 3/4th the hosts on that segment had the tenants MAC address for almost every arp entry in their table WTF!

So we put a layer 2 pacl on the port to block arp. Now this broke the tenant because our firewall somehow lost arp for their router and didn’t get it back, so I got called New Year’s Eve last night just before midnight to work a priority one for the tenant being down!

So my question is there a way to write a better pacl that allows their router to arp reply for itself but not for anyone else? Call it... an arpccess list?

I know DAI is a commonly used solution but my understanding is that DAI requires dhcp snooping to work. Well we don’t use dhcp on that particular segment, so no dhcp snooping.

Thanks all!



Cisco ASA with egress and ingress netflow

I have an ASA5510 running version 8.2.5 and has netflow configured. It only captures outbound traffic netflows, i.e. egress on the outside interface.

​

In newer versions of say 8.3 or 9.X does netflow support both egress and ingress?

I know that's the case for older versions of IOS of core routers, earlier versions only did ingress, then later versions supported both egress and ingress. Unlike the IOS on routers, the netflow on the ASA is not configured to a specific interface, its global.

​

Thanks

John



3750g-24t-8 replacement?

My Cisco home lab switch that has served it purpose went belly up in the new year. As this is for my home lab instead of enterprise I will need to find another budget friendly replacement. Looking on eBay I’m leaning towards the same model. I need the routing capabilities and gig. Is there another model I should look at?



Source IP Address on DNS Forwarding Servers

Design: LAN -> Router -> Public DNS Forwarder -> Public DNS Resolver/Recursive

On this design, there’s no internal DNS service. Apparently when a client from the LAN asks for DNS response, it will be sourced by a public address from the Router via NAT/PAT.

My question: When our Public DNS Forwarder forwards the recursive queries to the public DNS Recursive servers, what will the source IP Address be? I suppose it would be the public IP Address of our Public Forwarder?

If it’ll help, Unbound will be the choice of DNS server software in this project.

If yes, to those who know, can I confirm that the traffic will be something like below: 1. Private Client to Public Forwarder Source IP: PAT Address of Router; Destination IP: Public Forwarder

  1. Public Forwarder to Public Recursive Source IP: Public IP Address of Forwarder; Destination IP: Public Recursive

  2. Public Recursive to Public Forwarder

  3. Public Forwarder to PAT’ed Address Source: Public Forwarder; Destination: Router Public Address

  4. Router PAT traffic to internal DNS client on LAN

Would just like to confirm the traffic esp. the addressing portions.

TIA!



Monday, December 31, 2018

Understanding how a wireless bridge works help.

I get what it dose... but I am a bit confused.

When we have a wireless bridge is everything on the same network. for example 192.168.1.0 /24?

​

or is this more like some kind of wireless routing? ie both routers would have be a separate networks

ie 192.168.1.0 and 192.168.2.0 with information being routing between them?

​

​



Rural ISP's robbing customers blind.

So I live in a very rural part of CA and only have access to satellite or point to point wireless. We all know the data limited story with satellite and I am grateful that I have the point to point as a second option but the cost these ISP's charge for the throughput speeds you get is just outrageous. I pay $300 a month for an unlimited point to point 30Mb/s down and 10Mb/s up connection when people are able to get gigabit for around $100 a month 30-45 min away. Now I get that living in a lovely rural area like I am comes at a cost and I should not expect city luxuries in a rural environment. But 3x the cost of a gigabit connection 30 min away at 3% of the speeds is just driving me insane. Even if I lived right in town and had Comcast business I could get 80-100Mb/s for around $150 a month. Is there something I am missing that justifies wireless ISP's charging these outrageous prices for such slow speeds? I hate the thought of moving for internet but it is starting to come to that point. I work in IT, am a heavy gamer and I'm tired of having a car payment for slow internet. Unless something major changes in the rural wireless internet game I don't think the situation out here is going to get any better any time soon. I apologize if this isn't the right place for this but I wanted others opinions and thought I might find some insight here.



IPSec vs IKEv2

Hello,

I am a high school junior working on my submission for a network design competition (don't have any significant certs yet only an MTA-hopefully I will have my CCNA by the end of high school as I have been self teaching myself networking). Instead of going for an Ethernet Private Line or leased line to connect up sites for this project, I figured using IPSec would be much more practical, cost efficient, and scalable. When I was doing some research, I stumbled upon something called IKEv2. Could someone clarify how IKEv2 is different from IPSec and when to use one over the other?

Thanks!



Urgent! please help.

Ok, so I need some advice. I'm a university student currently in the middle of an assignment where I have to create an ipv6 based network. In the scenario, I have been given a /48 prefix from the "ISP" but I'm unsure as to how I actually assign the IP addresses in my packet tracer implementation.

If I want to create a /56 subnet between two connections, what am I specifically inputting into the CLI for that subnet? would it look like this for example:

2000:DB8:2112:5100::1/56

or would it be assigned like this:

2000:DB8:2112:5100::1/64

From my understanding, the first way should be fine but later on down the road I have tried to assign a /60 subnet and it has given me an overlapping error; this error didn't happen when I tested out the second format. Help would be greatly appreciated as at the moment I cannot get much support from my lecturers about this issue due to it being the holidays.

This might seem like a basic issue to some but unfortunately, this topic hasn't been covered in detail as much as we had liked. The /60 prefix I tried to use looked a little like this if someone is wondering:

2000:DB8:2112:5110::1/60



DHCP / VLAN looking to tell me how this is working

Discovered something on my network today that has me a little confused. I have an unmanaged dell powerconnect 2848 (no vlan tagging) with a hypervisor+vms plugged into it that has a few virtual nics. The vNIC's have vlan tags for the network they are doing DHCP for. This powerconnect is connected to another managed switch that has devices requesting DHCP via a proper VLAN configuration on the ports. My question is, how the hell are the endpoints getting IPs if the switch is not passing vlan traffic? Wouldn't the broadcast traffic not make it to the proper interface considering the vNIC is tagged/switch doesn't know what it is?

also there is no helper or relay setup