Sunday, January 6, 2019

Making an SD-WAN decision - When to use an MPLS with a DIA circuit as opposed to 2 x DIA circuits

Hi All

I would appreciate the communities thoughts on SD-WAN in relation to a recent chat I had. A customer who was looking at SD-WAN were most excited about the possibility of moving away from there MPLS network which could potentially give them more flexibility of circuit choice, and a possible cost savings by replacing there MPLS, in addition to some of the other benefits.

During the chat, I mentioned that SD-WAN is transport agnostic in that you can connect whatever circuit you want to it, whether that be an MPLS link or DIA. The customers made the statement ‘I would love to be able to go to the board and propose this solution and the risk needle to stay the same’. In this scenario, the customer wanted to move completely away from an MPLS network to having 2 DIA circuits at the site only.

This question in relation to the risk needle movement has occupied my thoughts for a few days as there are a few variables at play here and has driven me to find a more objective response and structured framework I can use to give a more honest, clearer response in future.

My response was that customers who want to guarantee that same level of performance or are perhaps more cautious often choose to have a hybrid setup with one link being MPLS and the other being a DIA. They can have peace of mind that the business critical performance traffic is sent on the MPLS, SLA backed circuit. With the flexibility to send non-critical traffic over the DIA.

The real heart of the question I am trying to answer is around when should a company choose a hybrid SD-WAN deployment and when can you move to an SD-WAN deployment with 2 x DIA circuits.

I appreciate that answering this question is specific to each and every customer. However, there is a grey area between the two solutions in my mind as to how and when you should choose one over the other. It would be interesting to hear how decision-makers have come to a conclusion and to understand their motivations. Not all organizations have the luxury of being able to compare the two solutions side by side before making a decision.

One argument I have heard is that you can get DIA circuits that perform at a level close to that of an MPLS link. If you have 2 x DIA that experience on average 1% loss then combined it would give you 99.99% uptime, which is a similar kind of guarantee on some MPLS links. As outlined in the article below

The two DIA circuits in combination with SD-WAN dynamically moving traffic between the best tunnels, and on top of that, the option to use packet duplication or FEC to me seems quite a solid offering. Where is the risk here that I might be missing?



Nortel 2526t POE not working - - ideas?

I just picked up an old 10/100 Nortel for $20 for my home camera system, but the POE is giving me issues.

I finally managed to get it connected with telnet (the serial adapter I bought isn't working for direct access), but the "no poe-shutdown" command is not working.

Here's what I do after connecting to telnet:

enable

config terminal

interface fastethernet 1-12

no poe-shutdown

ctrl+z

exit

Am I missing something? I don't get any POE. In an attempt to troubleshoot, I used a working POE switch and went:

[Test Camera] > {Working POE Switch} > {Nortel 2526t Port 6 (POE)}

And with that, I was able to get the camera working. So that determines the ports work, but POE isn't enabled.

Ideally, I'd just hard reset the switch, but (apparently) that's only possible with a direct COM port connection and I'm not able to get the DB9 to ethernet cable working (even with a crossover cable).

Any ideas?



DSLAM book

are there any book/books that explain how to configure a DSLAM, difference between atm and ip dslam like MSAN?



Affordable solution to manage small computer lab in classroom

Hi Guys, I have a small lab with 20 computers with Windows 10 on them. I need to set up an environment where I could manage centrally all computers in room. My requirements are:

  • domain management, each user has his account
  • management of software installed on users accounts
  • each user has 200MB space for his personal files
  • personal files needs to be accessible from outside (maybe NAS server ??)
  • "teacher" computer needs to have control over other PCs

Is there any other reddit to ask this question? Could you tell me some ideas how to start setting up this environment? Thank you guys! Sorry for my English.



Chinese Telecom NATing Our Traffic

I've had a hellish weekend after one of our VPN sites in Shanghai went down, I'll call it site A. Site A has a standard internet circuit provided by China Unicom and was originally set up with an IPSEC VPN to our Hong Kong data centre where it could utilize our global MPLS. We had latency problems with that VPN, so instead set up a new tunnel to another site in Shanghai, site B, which had its own MPLS feed and that worked great up until yesterday.

The WAN address we use at site A ends in .203, but since yesterday we were seeing ESP discards coming in from .205. I tried moving the VPN back to our DC in Hong Kong but were seeing ESP discards from .205 in the logs on the ASA at our Hong Kong DC. I turned NAT-T on, which didn't resolve the problem, but had this log entry on Site A:

Automatic NAT Detection Status: Remote end is NOT behind a NAT device **This end IS behind a NAT device** 

We hooked a laptop directly up to the ISP router and when doing a whatsmyip, found that it was different to the public IP we had statically configured on the laptop. Even if we changed the IP on the laptop to .205, it was NAT'd again to something else in the /29 they provided us.

China Unicom insist they are not NATing us, but we've tried an ASA and a direct laptop and are seeing a different IP everytime. Because of this we can't VPN anywhere, and this site is completely cut off from our MPLS.

Any suggestions on what we can do would be very helpful...



Asa SSL VPN logging

We have a pair of vpn asas with host scanning and rsa 2auth. Is there a way to log rejected or denied vpn logins? Our syslog servers receive permitted logins but not the failed attempts.



Any resources for discussing incoming MTU?

I recall seeing a post a longgggg time ago discussing incoming MTU at layer 2. Basically the gist was that setting the MTU doesn't necessarily always affect the incoming MTU as some implementations treat it differently.

Specifically in Windows I can confirm that even at layer 2 the host still accepts the high IP MTU packets, and outgoing it will fragment them.

For TCP they will of course negotiate the lowest MSS value and use that, so that traffic remains good.

​



Best router for under $100?

Parents are asking me this. I'm not to savvy on networking. We're a family of 3, I have 2 PC and a phone. Both of my parents have laptops and phones, plus TVs and Xbox.



Zscaler alternatives

Current situation: We have a few data centers and 40 offices. Each of these sites is on Velocloud SDWAN. Each of these sites has an IPSec tunnel to Zscaler. All traffic from users to internet is restricted via Zscaler proxy policies (e.g. no porn) and Zscalers firewall (e.g. no bittorrent). We do about 15 to 20TB per month.

The Issue: Our sites use applications in customers data centers. These customers have extreme security requirements, including all public IP addresses of clients need to be permitted in their firewall. Traffic is SSH, FTP and HTTP. Zscaler has a big pool of IPs that it uses for all clients. So at the moment, we cant give these IP addresses to our customers as it would then allow in Zscalers other customers. These applications number in the 50s and change monthly.

Question? What can we use? Requirements: Centralised firewall (can block outbound traffic on a port by port or protocol by protocol basis), centralised web proxy (block porn, gambling, whatever), can be used by users at home and at the office, uses a small set of IPs just for our users.

Any ideas?



Saturday, January 5, 2019

dhcp-snooping nuisance - unauthorized server 0.0.0.0

Hi

I am battling a nuisance on an HP core switch with dhcp snooping syslog messages indicating an unauthorized server 0.0.0.0

00854 dhcp-snoop: backplane: Unauthorized server 0.0.0.0 detected on port ...

I believe it's linked to a Windows 7 client problem described here: https://community.extremenetworks.com/extremeswitching-exos-223284/dhcp-snooping-false-positives-5899530 - basically a client is sending an offer packet rather than an acknowledgement/request.

There is no impact on the network as far as I can tell as no issues with IP assignment were reported.

Still it is my task to get it ironed out.

Now the complication is that the only information in the syslog is what port these packets are coming on - and these are trunks to distribution switches which have no dhcp snooping enabled so the trail stops there.

If that was on an access switch - the port information would allow me to identify the machines or some such. Sadly as it is it seems I need a "creative" solution to be able to track down machines which are doing this to get the IT to slap on a hotfix or some such. Hoping I'll find it here :-)

Cheers

​

​