Sunday, August 25, 2019

GS108Tv2 not forwarding EAPOL

Hi,

​

Device: Netgear GS108Tv2

I have a 2 devices (ONT and a supplicant) in ports 1 and 2. Both on VLAN1 untagged (ports 3-8 are on VLAN4 and aren't messing in between). And packets aren't coming back (not sure if reaching as I can't debug the ONT.

Right now I have the following:

- IGMP Snooping enabled
- IGMP Snooping on VLAN1
- Port based authentication state and Guest VLAN ON
- Port G1 (ONT): forceauthenticated, EAP Flood ON
- Port G2 (server): auto, EAP flood on

​

Still, I see the EAPOL packets going out, but none coming back in. This works flawlessly with a dumb switch

​

Thanks in advance!



Recommend edge/switch/WAPs distributed small office

First post here.

We're a small TV/Film post-production group. We've been getting by with SoHo and consumer hardware, but I think we need to invest in some more enterprise-level infrastructure now for reasons of security, performance, and ease of management. I've read about many different brands and others' posted opinions, and it all leaves my head spinning. I'm trying to find what is right for us.

I realize there's a ton of "what do you recommend" posts already, but I feel like none of them quite fit our situation. I'll probably reveal how little I know with this post, but I've gone about as far as reading can take me without some human help.

Background

We work with intellectual property, so I've always been worried that our security isn't robust enough. Besides that, we're now adding some remote workers in other cities, and so we need to extend an always-on VPN to them with good performance and not compromise security in doing so. We also have team members traveling more, so want to have a good VPN solution they can take with them on the road.

Additionally, our customers have urged us to give them on-demand access to client data so they can help themselves to it, which would likely take the form of a self-hosted solution like NextCloud on premises, or else mirroring data to something like Backblaze.

We're self-supporting power users without an IT staff. I'm the savviest, with a background in IT as it was my first career (but from a long time ago - I've devolved into a glorified power user now). So it falls to me to design/build/deploy/maintain whatever our solution is. There's also a ton of reluctance to move away from this low overhead model, so costly integrators, support contracts, subscription fees, etc., are not likely to get a consensus nod. I know all the arguments about what our downtime is worth, etc., but I'm not the one to convince on that front. Our group is willing to make some up-front investment, but strongly dislike the commitment of ongoing fees unless it's something very modest (a few hundred a year is OK, but they are not going to spend thousands).

Current Setup

Main Office

  • 5 power users doing editing / color grading / VFX
  • Up to a dozen freelancers who sometimes come on to do additional VFX / editing
  • NAS and workstations connect over 10GbE to a Netgear X7S16T-100NES switch
  • Other clients and low bandwidth devices connect to a 1GbE Netgear M4100-D12G switch
  • 1Gb ISP connection
  • Asus RT-AC5300 is our edge router and WAP, with both switches connecting to it.
  • We run the firewall in the Asus, as well as that built-in to Windows on each client.
  • FTP is used to send/receive files to collaborators and clients, or we ship on a hard drive if it's >500GB or so
  • OpenVPN is used for remote connection

Remote Office (#1 and #2, both the same)

  • A couple of Windows workstations with Windows firewall turned on
  • DAS for a local cache of files
  • 1Gb ISP connection
  • Asus RT-AC5300 as gateway and WAP
  • OpenVPN (not always on, start it when needed)

What do we need?

I'm looking for a recommendation of the whole stack. The main edge device, the switches and WAPs, the remote Edge device / switch / WAP, whatever kit we might take with us while traveling and working remote (unless it's a software-only solution), etc. I'm OK throwing out what we've got, if that makes sense.

My "dream" solution, as far as I can determine, would be something like this:

  • User-friendly GUI interface, easy for me to understand, that integrates all the management into a single pane of glass.
  • Straight forward initial setup. I should be able to get it up and running in a week or less, including whatever necessary study, or else it's too complex.
  • Low maintenance. I don't want to spend more than an hour or so a week maintaining this.
  • Smart enough to stay updated against threats, proactively alert me, etc., without me having to be a security expert or monitor it constantly.
  • NGFW that could throughput 1Gb symmetrical performance from main office with VPN, DPI, IPS, and QOS all turned on (assuming I need all these to be secure?)
  • Upgrade path to higher performance (i.e. 10Gb) on the NGFW if/when we upgrade our ISP service
  • Dual ISP support (aggregate performance, QoS, high-availability, etc.)
  • 3-5 WAPs in main office
  • VPNs to separate IOTs, home, guest, general, production, and management networks.

Notions and Preconceptions

I have ideas, not sure if they're misguided.

  • Gateway/Firewall: Thought of building a PFsense or OPNsense box around a Xeon D-1500 platform, or maybe trying Sophos on it. But then it seems like a lot of tinkering, and that only multiplies when I think of how to manage the requisite box at the remote locations as well. Also thought of Sophos or Fortinet box with their requisite subscriptions. Sonicwall marketing makes their boxes sound like magic how you can mail it to a branch office and setup so easily, but there's a lot of hate for them online too. I have no first hand experience with any of them, so my head is spinning.
  • Cisco and some other enterprise gear seems too expensive, too much to master, and too CLI-oriented. I'm OK with command line, but if all else is equal I'd rather have a GUI for most functions and CLI for occasional advanced use.
  • WAPs: Thought of Ubiquity Unifi, throwing their management as a VM on the server.
  • Switches: Had though of just using our Netgear stuff unless it turns out we need more sophisticated switches, or that I'd get much easier management by putting it all in one brand.

Am I asking for the moon, or is there a product stack that would elegantly accomplish all this without breaking the bank / incurring high subscription fees?



I can connect to my work VPN via Cisco AnyConnect remotely; however, I can't access any of the intranet sites. Help?

Just as the title says. I've tried disabling my firewall and all antiviruses, flushing my DNS, releasing/renewing IPconfig, creating a new Windows user specifically for work, uninstalling/reinstalling Cisco...literally everything. The IT guys at my office can't figure it out either. I also cannot connect to my office's Remote Desktop.

For what it's worth, I could work remotely without issue (and connect to both intranet sites and the Remote Desktop) for literal years; then, starting in early February, it just...stopped.

I can still connect with my phone, my tablet, and different computer, so it has to be something specific to my machine. Does anyone have any ideas?



Unable to connect to VPN externally - Connects fine internally. Firewall seems to be configured properly?

Hello all, I'm having some issues with OpenVPN that I hope you can help me solve. I have a bit of a complicated setup to please let me try and explain.

On the outermost layer is an NGINX Reverse Proxy that sits on GCE. This proxy runs inside a Docker container on a small VM. My domain name, tjzimmerman.com, points at this proxy. This proxy then redirects all traffic to another domain name, tjzimmerman.dev, which points at the external IP of my house. Here are the firewall rules for this virtual machine. And here is the NGINX configuration.

There are two relevant sections, I'll comment on them here:

stream { server { proxy_connect_timeout 300s; proxy_timeout 300s; listen 9443; proxy_pass tjzimmerman.dev:9443; } server { proxy_connect_timeout 300s; proxy_timeout 300s; listen 1194 udp; proxy_pass tjzimmerman.dev:1194; } } 

This section takes incoming TCP packets directed to 9443 and UDP packets directed to 1194 and forwards them to tjzimmerman.dev:9443 and tjzimmerman.dev:1194 respectively.

 server { listen 443 ssl; server_name vpn.tjzimmerman.com; location / { proxy_pass https://tjzimmerman.dev:943; sub_filter </head> '<script language="javascript" src="/analytics.js"></script></head>'; sub_filter_once on; } } 

This section takes incoming requests to a subdomain, https://vpn.tjzimmerman.com, and redirects them to https://tjzimmerman.dev:943. As you can see, https://vpn.tjzimmerman.com is working without issue. The official NGINX Docker container is also compiled with the required modules to do proxy streaming, as you can see here:

$> 2>&1 nginx -V | tr -- - '\n' | grep -i stream stream stream_realip_module stream_ssl_module stream_ssl_preread_module 

Once the traffic hits my external IP, it goes through my router. Where I have port forwarded the required ports as you can see here.

My router sends the traffic to 192.168.10.10 which is the IP Address associated with the OpenVPN server. I am able to connect to the OpenVPN server via this IP Address, or it's associated hostname, without any issues. Here is an example of a successful connection.

However, if I attempt to connect to my VPN through my Reverse Proxy, or even my external IP Address, it fails and says that the connection was refused.

The only difference between these three OpenVPN profiles are the hostname/IP Addresses used via a search & replace. However, I have attached redacted versions of them here for you to see if you wish:

To make matters even more confusing, nmap always reports that the ports are closed or the host is down. Even though I can connect to the VPN via the internal hostname without any issues. And the ports are forwarded on my router.

$> nmap -p 943 192.168.10.10 Starting Nmap 7.70 ( https://nmap.org ) at 2019-08-25 12:01 PDT Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn Nmap done: 1 IP address (0 hosts up) scanned in 3.02 seconds $> nmap -p 943 24.18.133.202 Starting Nmap 7.70 ( https://nmap.org ) at 2019-08-25 12:04 PDT Nmap scan report for 24.18.133.202 Host is up (0.00044s latency). PORT STATE SERVICE 943/tcp closed unknown Nmap done: 1 IP address (1 host up) scanned in 0.02 seconds 

However, I'm able to connect to the internal IP via nc just fine. But, still not able to connect using my external IP despite the port being forwarded.

$> nc -v 192.168.10.10 943 192.168.10.10 943 open $>nc -v 24.18.133.202 9443 24.18.133.202 9443 (tungsten-https): Connection refused 

Anyone know what's going on here? As far as I can tell all of the firewall stuff is configured just fine. And I have confirmed with my ISP that they are not blocking ingress on 943/TCP or 1194/UDP.



NAT & Proxy

Welcome everybody! Can someone describe difference between NAT and Proxy? How they work together, if NAT behind Proxy and vice versa?



how stressed are you with your networking job?

No text found

SFP/SFP+

I'm replacing some equipment in my network rack. The router has SFP+ ports, and my switch has SFP. I'm fairly unversed on fiber connections and compatibilities. With this pose a problem or will this work? I know it would run at 1 Gbps and not 10Gbps. What modules and fiber will I need exactly?



Cisco WLC - FlexConnect/CAPWAP through ASA (Firewall Rules required)

Howdy,

I'm trying to setup a vWLC to sit behind a vASA using CAPWAP/FlexConnect AP's and only allow required ports inbound to the WLC (https://i.imgur.com/55bIOn0.png).

I'm referring the the document here:

https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113344-cuwn-ppm.html

However, when I lab this up - I can see the ports inbound using random UDP ports (the random one associated to each AP I assume). The only way I can get it to work is to allow the following:

UDP Ports 1024 - 65535

Is this right? Is there any other tidy ASA rule(s) than just allowing the UDP ports above else I get the below:
https://i.imgur.com/vL1C5v4.png

Has anybody had any previous experience of this before?

Thanks.



(ISP tech) How do you explain to customers when the issue is outside your network?

Jesus, that was a long rant...apologies.



ISP with odd "blackhole" issue.

Hi all,

I'm a shiny new Network Engineer though have a decent amount of background in IT and Networking. Earlier this year I started work at an ISP and everything was running smoothly. I was handed an issue about a month ago where traffic seems to mysteriously vanish for (as far as I can tell) all of our IP ranges, as if our AS is being rejected somewhere.

This only happens to certain destinations, though there is no pattern between the route, dest. AS, dest. IP, or Transit used.

We managed to resolve this for one destination network by peering with them directly at LINX.

What would you guys check here? So far I've attempted reaching out to the NOCs on the destination networks and seeing if they can contact their upstreams, but that's not yielded a lot of return and I'm unsure how else I can investigate this since it's outside of our network.

Look forward to hearing from you all.

Edit: Just thought I'd add - we're not on any blacklists per my exhaustive checks. I've probably checked a good 100 or so at least. Additionally we have had issues with IP Geolocation, where we're showing up as being in the Netherlands, but I don't see how this could prevent some customers for playing games, for example. We're in the UK.