Sunday, January 20, 2019

PEN Test and Intrusion Detection

Hi Guy's,

I have an IT company and would like to get in to the PEN Testing and Intrusion detection.

Lately read a lot about but would be curious if anybody would have any advise / opinion about?



IPAM, but for management interfaces

we currently have an excel spreadsheet full of management addresses for switches/routers/access points etc and i'm looking for alternatives as we cross the ~400 device barrier, we're also acquiring new companies like mad so we're getting more & more sites & devices on our network at a rapid pace and the excel file is becoming a little strained.

has anyone got any good solutions, pointers, recommendations or horror stories? would you just stick with a spreadsheet or are there legitimate solutions out there which can help with this? (like some kind of open source web interface thing that will automatically make clicky links for web interfaces?)

i started moving everything to a confluence document on friday but it just feels a bit clunky and i'm hitting that age old barrier of "how much info is too much info"

how do you folks do it? have you seen something that makes you go "that looks neat!" or even "this is the worst thing in the world, the network admin should be shot."

thanks!



Solution for 10 Gigabit Ethernet Connection

Hi all of Reddit,

I need your time and advice.

We have small graphics design business, which we want to upgrade to 10 Gigabit Ethernet.
This is because the bottleneck is the internal network speed.

We have 3 computers that we want to upgrade to 10 Gigabit Ethernet.
1x The Server, has a 4 TB SSD, HPE ProLiant MicroServer Gen10
2x Workstations, has 512 GB SSD

The workstations save and load Photoshop and InDesign files from the server.
Sometimes these are 10 or 20 GB.

I need, I think:
3 Network cards 10 Gigabit Ethernet
1 Switch with 3 GE ports that is located in the closet / server room
1 Switch with 3 GE ports that is located between the workstations

Can I use any 10 GE card? Or do I need specific ones?
I contacted several network suppliers and they all are $ 4000 or more.
I have the feeling this is too high, or am I wrong?

The network cards that they offer are $ 400 each.
The Asus XG-C100C is only $ 120, or is this one a very bad one ..?
Can I use CAT6 between the switches, or does it need to be fiber?

I have a good network knowledge, but have never had a project with 10 GE.

Thank you in advance for your time.



Small design studio – areas to improve network efficiency?

TL;DR Is my network setup below helping or hurting our LAN efficiency?

I own & run a small design studio (6 employees on high spec iMacs connecting to central file server). We work with lots of enormous files that often have to reference dozens of other files when open (ie Adobe InDesign publications, video projects, presentations, etc) so internal LAN efficiency is critical for us. While we’ve been operating fairly well on our current setup, we’ve been started seeing some pretty inconsistent performance over the past couple of months.

I’m definitely not a trained IT professional, but I’m a huge nerd with this kind of stuff and would consider myself a ‘prosumer’ in the space. But I have a nagging suspicion that my home networking skills have lead to a rookie setup in my studio. Looking for any advice on where I might be going about our setup the wrong way.

Here’s my current setup -

WAN: Spectrum Business 200 / 20Mbps w/ dedicated IP BMC cable modem with dedicated IP > Sonicwall Soho Firewall (DHCP server) > Mac Mini central file server (DNS server) >

LAN: Mac Server > Netgear ProSafe 16 port unmanaged switch > cat5e wiring to 4 hardwired workstations, 4 hardwired printers & plotters, 3 hardwired voip phones (service by Vonage)

WiFi: Apple AirPort Extreme (latest generation) hardwired to Netgear switch. Used by 2 mobile workstations and a dozen or so devices (phones, tablets, appletv, etc) Separate AirPort Extreme hardwired to SonicWall for isolated guest network

File Server: Mac Mini 2016 (top of the line spec at that time-8GB ram, core i7 processor) Mac OS High Sierra, up to date Main Storage: Thunderbolt 3 external raid 5 enclosure, 6TB Redundant backup: identical raid 5 external enclosure Offsite backup: Dropbox enterprise

I’ve been closely monitoring the health & services on our server to see if that’s the culprit of our speed inconsistency. I don’t see anything obvious, so I thought I would shift my focus to the network and see if our setup is appropriate for our size.

One thing I’m curious about is if I would benefit from a managed switch or if our network is too small to see any benefits.



BGP on ASA

Anyone use BGP on asa based VPN appliances as primary protocol? Any caveats? I think it's supported in 9.2 and up.



Is there a way to connect a LAN device to another device over the internet?

I'm not the most well versed in networking stuff, so this might be a stupid question.

In theory, couldn't you just connect the device to the network, forward the port, and have the other network do the same thing?

it would go something like: deviceA <-> networkA <-> networkB <-> deviceB

Security issues aside, couldn't this work? It probably wouldn't, I feel like it's too simple.



Owner of 17 Unit Boarding House - Sharing Wifi Connection

I am currently subscribed to a 15mb/s bulk service with a wifi router in each individual room. The service is very costly and I am considering purchasing one 300mb/s (unlimited transfer rate) service and sharing the password between tenants. The building is a 3 story house with shared kitchens and washrooms so it is not the size of a typical 3 story apartment.

What router would you recommend? Would 3 Google mesh routers handle the demands? What are the legalities of sharing internet with tenants? Technically I do require internet myself as I have wifi cameras in the building. I am located in Canada. Only about half the tenants use the internet and most are not streaming media.



Any help on this?

http://bit.ly/2CC3LoS

Translating (NAT'ing?) outbound IP addresses.

I can add way more information if needed but I was wondering if translating outbound traffic was something that could be handled in either a Layer 3 switch or ASA (Cisco equpment)?

EDIT 1: We currently have no Layer 3 switch and one ASA 5505 with two internet circuits (P1 and P2). The circuits are from different providers and P1 is way better than P2. P1 and P2 are different IP addresses and are static. For most of our VPN tunnels, the destination supports backup peer IP configuration so if we use P2 the VPN will continue to work.

We brought on a new destination that does not support backup peer IP. To allow for any type of connectivity to this dest while using P2, we've had to set up a separate VPN with the source IP as P2. The destination side has set up a VIP on their side. Assume that we access the machines using their IPs when using P1 (10.32.83.0/27 for example). When using P2 we need to use 100.98.255.0/27 and the VIP on the dest side will "translate" that to 10.32.83.0/27.

That solution is not good for a host of reasons so we're buying another ASA and giving it P2 (existing ASA will only have P1). We're also buying a Layer 3 switch to handle the IP SLA between the two ASAs (and hence two internet circuits). My networking group is telling me that once this is installed we'll need to have the destination remove the VIP so that we'll target 10.32.83.0/27 regardless of ASA/circuit. I want to only have to target one range but I also don't want to have the destination do anything that might screw something up (they've been awful up to this point). So I was hoping to simply have the new ASA w/ P2 take anything destined for 10.32.83.0/27 and DNAT it to 100.98.255.0/27. Once the destination gets it their VIP will de-DNAT it to 10.32.83.0/27.

Or is all of this a lot more trouble than it's worth?



Need help with ESXi dual homed to a pair of Nexus 9300 using vpc -can't get it working

What I want is to obtain an active active configuration

Here are the Nexus side settings

NX1 int e1/1 switchport mode trunk channel-group 100 no shutdown interface port-channel100 description "To ESXi" switchport mode trunk spanning-tree port type edge trunk # can't say I uderstand why this is needed;tried without it but no change vpc 100 

​

the other nexus is identical

VPC is correctly established

​

VMWARE -ESXi 6.5

using a vSwitch , the guest is in vlan 111, portgroup configured for this vlan ID

load balancing is IP hash based

Security for switch and ports: reject everything (promiscuous mode, MAC changes, forged packets)

​

If I remove the ports from vpc then it works but I think this is active -passive (have not tried to see if the traffic flows accros both links, I can't simulate traffic for now)