Monday, March 18, 2019

UK business opening up shop in the US, looking for ISP Advice

Hi all,

I work for a UK based retailer that are soon to be opening up shop in the US across the East Coast, and am hoping I can get some connectivity advice.

In the UK we take a wires only MPLS service (MPLS is cheap here), but from what I understand due to reach and costs across the US MPLS can become a quite expensive venture. From research it would suggest that SD-WAN is becoming a prevalent option and taking a number of locally available internet services to run this across is the way to go?

ISP wise who should we be engaging with for initial conversions into providing comms, and who should we avoid?

our UK setup is as follows, per retail store

  • 1 x FTTC or DSL
  • 1 x 4G
  • 1 x MPLS

Were very risk averse so usually have a least one hard line and one over the air line (incase lines get cut etc), with this in mind, what sort of technologies should we be looking at?

Thanks for you advice!

Alex



Short cables, yah or nay?

I would like to ask what is your opinion on short cables. I read conflicting reports on what is the minimum length a cat 6 should be.

My place is relocating soon and we will be getting new user access switches and brand new network cabinet.

To reduce cable clutter and cable slack, I was hoping to mount the patch panels and the switches one on top of another.

24p patch panel 48p switch 24p patch panel 24p patch panel 48p switch 24p patch panel (and so on...)

To achieve maximum tidiness, I was hoping to use 6” patch cables to connect the patch and the switch. Example below.

link

Would you be able advise if I should not be worried about the minimum length or perhaps I have to consider the length of the underlying cables behind the patch panel?

TIA



Can some some of you smart people take a look at my subnet and VLAN plan please? (Newbie looking for help)

Hey guys. I am still teaching myself how subneting and VLAN configuration works. And I know you see these questions over and over again, I just want to make sure my plan is sound before I start digging into the Cisco CLI and doing my very first config on my layer 3 3560 switch. Please excuse my ignorance.

I just built a pfSense box. I have its private IP statically set to 192.168.100.254 My plan is to send traffic out of its LAN port towards my Cisco Switch (which will have a number of VLANS on it).

On the Cisco switch....

VLAN 20 = Wired Ethernet devices. Subnet 192.168.20.0/24

VLAN 30 = Security cameras. Subnet 192.168.30.0/24

VLAN 40 = WiFi access point. Subnet 192.168.40.0/24

So now I am a bit confused about how I set up my LAN port on the pfSense box. I understand that this will be a trunk port, sending/receiving data from all VLANS on my switch.

I was thinking of tagging the pfSense LAN port with VLAN 10. Then on the layer 3 switch, I would set up a single switchport on VLAN 10. This would become my trunking port which, in the CLI, I can configure to pass traffic to VLAN 20, 30 and 40.

Does all this sound correct? Do my subnets all seem okay on paper?

One of the things I am confused about: Do I also have to set up the router LAN port with all those VLAN tags as well? Or can I just use VLAN 10 on the router, and let the switch do the multiple tagging?

Thanks so much! I hope this makes sense. Again, sorry about my bad terminology.

EDIT: Thanks so much to everyone who replied. The expertise in this sub is leaps and bounds better than the homenetworking sub for stuff like this. I am learning so much from you guys. Thanks again.



Bad Arp Entry ... I think

Having a weird issue that I can't seem to sort out, wondering if anyone might be able to send me in another direction.

I have 2 switches out of 40 that cannot be reached by Cisco Prime.

Switches are on VLAN42, Prime is on VLAN30, L2 Network routed through N7K cores.

When I check the ARP tables on the switches that won't communicate, they have entries for the Prime Server, on VLAN30.

They have the correct IP Address, correct MAC, and the VLAN that the Prime Server resides on.

When I clear the ARP cache, the switches can communicate for a few days, but eventually the bad ARP entry comes back and they lose connectivity again.

I've looked at the ARP tables leading back to the cores and nothing seems fishy, I'm not totally sure what I could be missing here.

Not looking for someone to solve my problem, just maybe light a fire in my troubleshooting.

Something seems off that there is an ARP entry for a device on a different VLAN, but I don't know if that is normal, I can't find much information on how ARP is handled when VLAN's are involved.

TIA!



Crazy Simple question

I'm doing some lab work for CCNP and I have one question based on something i read in a blog about 300-101.

Is there any way to see the age of an LSA without using "show ip ospf database"?

I had the thought that you could potentially look at the age of a prefix advertised in the routing table, if you have a fair idea where that prefix is from (asbr, abr, internal) then you could have a shot at figuring out, say a Type 3 LSA's age based on the prefix age.

Is there any other way or am i on the right track?



Going out to sea for 3 months, I want to create a wifi network for multiple devices.

Im going out to sea for three months, there is no WiFi and no cellphone signals in our Hold(Room) because were so low below deck. There are going to be something like 50 people in this hold and so outlet space is scarce, we are also not allowed laptops. There is a hard with 5 TB of movies/tv/porn. I was think of setting up a router with wifi so that me and my friends could stream content. I was wonder what set up would work best and how many people use it. The more the better obviously but my budge is around $200. I was looking up regular home routers. I also looked into putting together my own set up (Ubiquiti Networks UniFi AC LR AP Enterprise Wi-Fi System) so I could allow more people on, but Im not 100% on how to set it up. Any help would be much appreciated.

edit: we can have cellphones,and tablets



Sunday, March 17, 2019

Moving on from Networking Engineering - Career Advice

Hey ! So I’ve held a career as a Network Engineer for the better part of 7 years. A year ago, I took a job as a Solutions Engineer which helps design over all IT Solutions. So I touch everything from networking, PKI, identity management, etc.

I’ve recently been offered a job in Professional Services. My first client facing job. I think I eventually may want to pursue Pre Sale or Product but often struggle with these interviews with no client experience.

Interested in hearing from people who’ve made the switch from either direction. Why did you make the transition? What were some thing you wish you knew first?



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



What are some fun networking projects that use arduinos?

I have a bunch of arduinos lying around in my house, including an Arduino Yun which has a Wi-Fi chip and a Linux distrubtion on board (https://store.arduino.cc/arduino-yun).

Are there any projects I could do around the house with them?

I was thinking of setting up a VPN with the Yun but I think it does not have enough RAM -_-



802.1x computer base certificate issues

Hi,

We are currently rolling out 802.1x authentication using EAP-TLS and have noticed issues when some users have to re authenticate and they send their username with 'host/' prepended. The username/CN is made up of the [hostname@xx.com](mailto:hostname@xx.com) however when the reauth occurs some computers send through host/hostname@xx.com which our radius server (Cloudpath) will respond with a REJECT response. They will 5-10 minutes later attempt to re-authenticate again, and eventually will send through their username/CN correctly which any intervention.

Has anyone seen this issues before? currently the issues appear to be with random Windows 7 and 10 computers.

Thanks