Sunday, February 24, 2019

Juniper MX 10003 or Cisco NCS 5504?

I would like your thoughts on going with a Juniper MX10003 or Cisco NCS 5504 as a SP Edge Router Solution. We have been running down the pricing and they very close from a price/support perspective.

​

We can basically get 6-40Gb & 12-100Gbit ports with the MX 10003 & 24 100Gb ports with the NCS 5504 which is overkill for our current network design. We will be going with 4 edge routers in a redundant design with 4 different upstreams for DIA.

​

I will mention that we asked Cisco for a 9K solution, the cost was just not even comparable to the MX10003 for the port density. Also they have a per port license as well. The 100Gbit option made me fall out of my chair when we saw the quote. To even compete on price they started pitching the NCS series. Juniper came right out of the gate with the MX10003 for our design.

​

Also how is Cisco's CGNAT solution on an ASR 1K? Is it even comparable to an A10?

​

Any insight would be helpful.

​



Need help with networking assignment in college

First off, thank you for any help you guys can give me, this assignment is 'easy' but I'm just so lost and if I'm posting in the wrong subreddit please redirect me to another one. Antways I am tasked with making a small home office ip and subletting table and I need to make sure I am right before continuing. We have a table that we need to fill out as followed and I'm not sure I'm correct

SOHO IP address/mask: 192.168.33.1/ 255.255.255.128

Office subnet:192.168.33.0/25

Office subnet mask:255.255.255.0

Office gateway:192.168.33.1

Home subnet:192.168.33.128/25

Home subnet mask:255.255.255.128

Home gateway:192.168.33.129



GPON customer owned equipment

Is there any way possible to convince an ISP (specifically Frontier) to whitelist my own personal GPON "ONT" in the form of a SFP that plugs into my layer 3 Cisco switch? They use Calix equipment and I found out that this is supported with a Calix compatible SFP ONT. Just a matter of have them whitelist it and setting the right parameters. If not, does anyone here have an inside contact in Frontier that would be willing to help me out with this project?



Do bit rates on a single flow stay the same across many hops?

Say I have a 10Mbps egress shaper on an interface, and I start a large upload to a remote site out that interface.

The 10Mbps shaper smooths the traffic out not letting it burst above 10Mbps, and hopefully the flow control built into whatever protocol the upload is using should ensure the sending station slows down to 10Mbps, so it doesn’t over run the shaper and result in excessive buffering and drops.

At this point my flow should be an even, steady 10Mbps flow as I hand it off to my carrier.

Question: at the distant end which may be 2-3 autonomous systems away, and 30-40 router hops away, the packets arrive at my remote site.

Is that flow arriving in a steady even 10Mbps bit rate?

Measured at every single hop across that path, does the bit rate on that flow remain a steady even 10Mbps?

If not, what’s going on?



FTTH question: Should I run fiber or Ethernet to networking closet?

Just switched from Comcast cable to Frontier fiber. Love it so far. They came and spliced a fiber from the street to the back of my house. The fiber is then terminated into the Frontier supplied ONT. The ONT has an an Ethernet port that I will be directly connecting to my WiFi router in the house. I had planned to run CAT 6 from the ONT on the back of my house, up and into the attic, then down to my networking closet where the main router resides. Then I got to thinking: why not just continue the fiber on into the house and to the networking closet, moving the ONT there as well? I had really hoped to be able to skip the ONT all together and plug the fiber straight into a SFP GPON capable port on my Cisco, but Frontier won't whitelist customer owned equipment unfortunately. Should I run Ethernet or continue the fiber on? Any thoughts or suggestions?

Thanks.



Ok, this is the unreasonable wish thread. What unreasonable wish do you have for vendors/ISPs/enterprises that you know will never happen but it would make life so much easier?

No text found

Site-to-Site VPN (Raspberry Pi to pfSense)

Hello! I'm trying to do a site to site VPN, the server is on a Raspberry Pi, and the client is on a pfSense box. Right now, from the pfSense side I can access the network on the Raspberry Pi side, but not the other way round. It's the first time I'm tying to do this, I'm not sure what I'm missing.

10.0.0.0/24 to 192.168.1.0/24 works

192.168.1.0/24 to 10.0.0.0/24 doesn't work

  • 10.0.0.0/24(pfSense)
  • 10.8.0.0/24(TUN)
  • 192.168.1.0/24(Raspberry Pi)

Server Config

dev tun proto udp port 1194 ca /etc/openvpn/easy-rsa/pki/ca.crt cert /etc/openvpn/easy-rsa/pki/issued/server_b0kKByJ0t4CfspI8.crt key /etc/openvpn/easy-rsa/pki/private/server_b0kKByJ0t4CfspI8.key dh none topology subnet server 10.8.0.0 255.255.255.0 push "dhcp-option DNS 8.8.8.8" push "dhcp-option DNS 8.8.4.4" push "route 192.168.1.0 255.255.255.0" route 10.0.0.0 255.255.255.0 push "block-outside-dns" push "redirect-gateway def1" client-to-client keepalive 1800 3600 remote-cert-tls client tls-version-min 1.2 tls-crypt /etc/openvpn/easy-rsa/pki/ta.key cipher AES-256-CBC auth SHA256 user nobody group nogroup persist-key persist-tun crl-verify /etc/openvpn/crl.pem status /var/log/openvpn-status.log 20 status-version 3 syslog verb 3 

Client Config

dev ovpnc1 verb 1 dev-type tun dev-node /dev/tun1 writepid /var/run/openvpn_client1.pid #user nobody #group nobody script-security 3 daemon keepalive 10 60 ping-timer-rem persist-tun persist-key proto udp4 cipher AES-256-CBC auth SHA256 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local <my pfsesne box public ip> tls-client client lport 0 management /var/etc/openvpn/client1.sock unix remote <my server public ip> 1194 route 192.168.1.0 255.255.255.0 ca /var/etc/openvpn/client1.ca cert /var/etc/openvpn/client1.cert key /var/etc/openvpn/client1.key tls-crypt /var/etc/openvpn/client1.tls-crypt ncp-ciphers AES-128-GCM:AES-256-CBC:AES-256-GCM resolv-retry infinite 

Routing Tables pfSense

Routing tables Internet: Destination Gateway Flags Netif Expire 0.0.0.0/1 10.8.0.1 UGS ovpnc1 default core-campus-16.utc UGS re0 one.one.one.one core-campus-16.utc UGHS re0 one.one.one.one core-campus-16.utc UGHS re0 google-public-dns- 10.8.0.1 UGHS ovpnc1 10.0.0.0/24 link#11 U bridge0 pfSense link#11 UHS lo0 10.8.0.0/24 10.8.0.1 UGS ovpnc1 10.8.0.1 link#12 UH ovpnc1 10.8.0.2 link#12 UHS lo0 <my server public ip> core-campus-16.utc UGHS re0 <my server public ip>/32 core-campus-16.utc UGS re0 81.180.16.0/24 link#5 U re0 campus-16-002.utcb link#5 UHS lo0 campus-16-044.utcb link#6 UHS lo0 campus-16-254.utcb e8:de:27:41:4a:96 UHS re1 localhost link#8 UH lo0 128.0.0.0/1 10.8.0.1 UGS ovpnc1 192.168.1.0/24 10.8.0.1 UGS ovpnc1 cache.utcb.ro e8:de:27:41:4a:96 UHS re1 

Raspberry Pi routing tables

Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface default 192.168.1.1 0.0.0.0 UG 0 0 0 enxb827eb675bbf default 192.168.1.1 0.0.0.0 UG 0 0 0 wlan0 10.0.0.0 10.8.0.2 255.255.255.0 UG 0 0 0 tun0 10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0 192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 enxb827eb675bbf 192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 wlan0 


ok, talk me through BGP/IGP interaction one more time. I'm just not getting it

Alright,

So i'm getting ready for my CCNP route exam and the one thing i just can't get my head around still is how BGPs and IGPs interact.

Now, say I have an OSPF network in my AS, it's running all fine and dandy and the ASBR is also running eBGP out to the internet. How do i translate the route to the internet that BGP provides me into the OSPF area?

Obviously it's not redistribution in practice. I've read that BGP will distribute if it detects an identical IGP subnet on it's own routing table (syncronization). But obviously there are subnets that are _not_ going to be identical.

But is the correct process here to create a static route to point to the ASBR running eBGP? Is that the only way or is there a dynamic methodology that interacts between an IGP like OSPF/EIGRP and BGP?

​

​



VLAN Routing Netgear GS716Tv3

Hoping someone can point me in the right direction routing intervlan traffic on GS716TV3

​

Router IP: 192.168.1.1

Switch IP: 192.168.1.250

​

Wireless Network on: 192.168.10.0/24

​

I'm routing vlan traffic via the switch. Setting up the default route on the switch tells me

"Error! The specified Static Route Next Hop Router Address can't be in the same subnet as the service/network port"

​

Not quite sure where I go from here, any help would be greatly appreciated



Saturday, February 23, 2019

Tri-band Router Question!

Really not sure if this is the right place but I will ask anyway. I had a customer at work today who claimed to be a network engineer, ask me about one of the Tri-band routers we have but the question stumped me. He mentioned that they are falsely advertising the router because it is not possible for it to have a 2.4 ghz band and 2x 5 Ghz band. I tried to tell him that multiple manufacturers make them like this and he claimed the manufacturers were all lying. He said because he was a network engineer and understood how all this works that its not possible to have two 5 ghz bands at all. Is there any truth to this thinking? I haven’t used one of these routers myself so I just go by what the box and our website says.