Sunday, May 26, 2019

Ethernet bypassing RADIUS authentication

Hi all,

I have a RADIUS server set up, and it works properly with wireless devices(meaning it requires authentication before connecting). However with wired devices, a device wired straight to the router can get access without any authentication whatsoever. I am using freeRADIUS, and the router is set up as a client. Is this a parameter I can change? Or does RADIUS not work with Ethernet?



Networking advice

Hi everyone,

I wanted to take an advice from network professionals. I just shifted from help desk to network engineering after three years of experience. In order to become a succeful network engineer should you have experience in broadband technologies such as dsl, fiber optic, microwave systems, so you understand better how a network works before dealing only with routers, switches and firewall configurations and maintenance? Thank you.



Masters in networking

I need to convince my office(ISP) that I need to do my masters in networking and security, I am in the planning section of the org. I need to elaborate how this course will be beneficial. I can't think of any other reasons than to say that it will increase my knowledge and skills. Please help me out with some general ideas to add to the list of things I might be able to do after completing my masters.



Applying For My First AS Number

Hi guys,

I am in the process of starting up a WISP. I have never applied for an AS number before so bear with me. ARIN wants me to explain how am am multihomed or will be multihomed within 6 months of startup in order to get an AS number. We would have only 1 peering partner, our ISP. Is there any sort of loophole to getting your own AS number from ARIN without multihoming?



Palo Alto / mpls migration design help

Hi all, I've got a scenario I'm trying to overcome and struggling to see a simple solution.

I've got a cisco stack with a data vlan (1), a guest vlan(2),192.168.255.0/24.The svi's reside on the l3 switch. I then have a transit vlan(10). Let's say vlan 10 sits on the 10.10.10.0/24 subnet with an svi of 10.10.10.10.

Default route is 0.0.0.0 via vlan10 >>>>10.10.10.1 (l3 interface on Palo Alto stack). All other traffic has specific routes to our mpls via 10.10.10.254 (vrrp). The mpls is delivered/patched directly into our switch stack and does not touch the Palo for intervlan routing private subnets. Internet connectivity is delivered on an outside interface on the Palo via a dsl circuit via a 192.168.1.xxx/24 subnet. We also have an ASA connected directly to the Palo to provide anyconnect, so the upstream dsl router is providing port forwarding to the Palo outside interface. Static routes exist on the Palo that point back to the switch via the transit svi to reach private subnets on the mpls. We have static routes on the switch to point back to the annyconnect subnet hosted on the PA stack.

So to be clear, we have two separate circuits being delivered at two different ingress points. Most Internet bound traffic is actually proxied down the mpls so only very specific proxy pac routes go via 0.0.0.0 and the Palo Alto. All guest traffic is sent to 0.0.0.0.

The challenge I am facing is as follows. A new mpls/Internet provider is being provided as a merged circuit. So traffic intended for the Internet or mpls is presented now as a single ip address. Let's say it reuses the existing vrrp 10.10.10.254. I need to connect two physical uplinks to the mpls and www box. These cpe's have a ha link between them so if either box fails it still have connectivity to mpls or www.

It sounds simple enough but I'm concerned I'm missing something:

Should I just connect the 2 up links from the cpe directly into the Palo (as layer2) on vlan 10? Effectively all I do then is replicate one security zone for the additional interface.. Inline traffic traverses the PA to reach the transit svi and local branch subnet on vlan 1. Routing on switch just needs to point to 10.10.10.254 instead of 10.10.10.1.
With regards to guest traffic, this can traverse the same vlan but I'll just add additional security rules for any source or destination traffic on 192.168.255.0/24.
All NAT will be done via the cpe Internet interface.

In terms of current connectivity I'll provide a diagram shortly but I have a single uplink on vlan 10 for each PA. A single uplink to each mpls cpe on vlan 10 also but from the switches . The only change here is that the new cpe/www box will connect directly into the PA. I forgot to mention I'll need a layer 2 switch to account for the secondary standby PA.



What is AP Isolation?

What is AP Isolation and are there any performance benefits by having it enabled or disabled in a normal wireless environment?



Captive Portal for a Hotel

Greetings everyone, i have a little problem i would like to solve on my own. I'm hoping it's not rocket science what i am trying to do. So i went ahead and made a visual representation of the network that is currently in use in hotel. Nothing complicated but i can't seem to do what i want correctly so here i am.

Image at: https://ibb.co/99tdSBZ

Now where should i put, in this picture, the captive portal router? I was able to make it do a captive portal on the first wlan that emmits from the modem. I couldn't find the other wlan networks in the omada eap115, just the one from the modem. Floors were not present in eap115.

Please help me out, i know this is peanuts for you guys and rightly so. You probably invested years of hours in doing network stuff. The thing for csptive portal it just became a legal obligation at public places and hotels, so i have to setup one.



Xbox networking issue

Hi,

Sorry new to this and technologically useless(ish).

I bought a new xbox one s yesterday, got it home, connected to wireless fine, went to a mates, connected to their wireless fine.

This morning I am trying to connect again to my home network as the xbox does not remember previous networks, stupidly, and I am having some issues.

It appears to connect to my router but not fully to the broadband services. Wired works fine so Internet connectivity is there just not on WiFi through the xbox. All other wireless devices are working fine.

I have run through the xbox trouble shooting, and in doing so have tried setting up the MAC address as advised with no luck.

I have hard reset both router and xbox (running through the setup wizard and all that).

Any of you guys experienced this before? I have trawled through the various settings on the router but to no avail but then I am certainly not informed enough to say that I have tried everything.

Pls help...



Cisco ASA - ECMP over different interfaces?

I don't think this is supported, but I am hoping someone could say how else I can achieve the required end result.

We have active-active VPN gateways in azure. These used to terminate on an ASR. On the ASR we would have routes as below:

IP route 1.1.1.0 255.255.255.0 tunnel1 10

IP route 1.1.1.0 255.255.255.0 tunnel2 10

Which meant we would use either tunnel to reach azure.

I'm moving these vpns to a ha ASA cluster for resiliency, but it seems that ASA doesn't like route to the same destination over different interfaces, unless I specify a different metric.

Is there a way for me to utilize both tunnel interfaces as the route to the same destination with the same metric?



What is the required configuration for a web server to be able to run a site, such as network-tools.com, and what are the challenges?

No text found