Monday, August 26, 2019

(Urgent) What is the job scope of a NTD-Wireless engineer?

Hey guys, I got an interview invitation for this position and honestly I can’t find any info regarding what is NTD actually. Does any of you gusy know what is the job scope and perhaps tips to ace this interview? Your help is much appreciated!



Tp-link CPE210 configuration

Hi, quick question: I've got a tp-link cpe210 wifi antenna, and I'm trying to decide between two configurations; bridge and repeater. My question is, is it's set up as a bridge, can I access a server on my home local network by typing in its local ip (192.168...)?



Courses / certs that are SDN related?

exploring things such as controllers, SD-WAN etc.

How does one go about obtaining this knoweldge / skills, and what are the prereq?



Assigning Broadcast as a DNS address

Hey Guys,

Sorry if I should not be posting this here. Just a query (my networking skills are very rusty). A work collegue of mine was tasked with updating the address of the DNS servers. He accidently put 255 of the 4th octet of the IP address instead of 225.

I made him change them all there and then. However i was told by other collegues that I was over reacting and it could of waited.

What effect would this of had on a Production network, if 50 servers were using a broadcast address to resolve dns queries?

For clarification, its the DNS server setting when you configure IPv4 in Windows.



Bad quality peering from US to Netherlands?

A customer of ours is running Windows DFS and Veeam backups (Baremetal with the Veeam Agent) from five locations around the globe to our datacenter in the Netherlands.

DFS is used to synchronize company-wide information with every branch, the DFS namespace is only 14GB in size.

Every branch location has a Read-Only Domain Controller which is also the local Fileserver (DFS), there is a business-type Internet connection with usually 100Mbps up/down speeds. We use ASA 5506-X's to setup a full-mesh IPsec overlay over each location. In addition each location has a IPsec tunnel to our datacenter in the Netherlands which houses their central off-site backup server.

The data that is sent in day-to-day operations over the Branch to Branch IPsec overlay is Active Directory related traffic, and the DFS delta's, there doesn't need to be a lot of bandwidth available for this purpose.

The most important thing however is the IPsec tunnel for the Veeam Backup. The job contains the entire local filesystem that is differentially backed up over night and fully backed up every month.

The size of the dataset is around 1.5TB per location.

We are currently experiencing issues with the backup from a branch location in Portland, Oregon. Previously the branch had a Comcast Business connection (I believe Starter Internet with only 50/5Mbps bandwidth). Since they have upgraded to a Allstream Business Fiber 100/100Mbps connection.

The full backup isn't able to finish in time before the 180 hour job runtime limit passes. The max bandwidth that we are able to achieve from the US to the Netherlands is about 500kB/s which equates to about 4Mbps, at this rate the backup would need 834 hours (1.5TB / 500kB / 3600sec = 833.333333333 hr) to finish. The minimum amount of average bandwidth we would need is around (1.5TB / 180hr / 3600sec * 8bits = 18.5185185 Mbps) 20Mb/s, we would think this is way less than should be available over the 100Mbps up/down Fiber Internet connection and thus should be achievable.

The datacenter upstream ISP has a full 1Gbps connection available and has more than enough bandwidth available when the backup runs.

Other branches (they are all in Europe) have no problems running the same type of backup job.

We have run multiple tests over the IPsec overlays and we are not able to achieve more than 25Mbps throughput from Portland, OR to Amsterdam, NL. Withouth the IPsec overlay we are not able to achieve more than 27Mbps throughput over the same path.

We have checked the traceroutes and the carrier's BGP Looking glass and can't see a uneccessary long path end-to-end. Our upstream ISP also cannot find an issue with the BGP path.

Could this be a bad peering issue? Are there other tests/things we could try?, we have contacted Allstream but their support is useless and the techs we spoke to are only able to troubleshoot last-mile issues (ISP handoff port issues).

TL;DR:

Customer has branches around the world connected with business ISP's. There is a off-site backup server in the Netherlands. The North-American branch connected via Allstream Business Fiber 100/100Mbps is experiencing end-to-end bandwidth issues that compromises their backup operations (nightly differential, monthly full (1.5TB). Other European branches have no issue running the backup job. Could this be a bad peering issue?



Protocol Authentication

Edit: SOLVED. Protocol authentication uses HMAC, not the plain hash function. HMAC-MD5 will of course be less secure then HMAC-SHA3 but to this date has no known attacks.

I'm a total beginner so please excuse my ignorance.

I'm currently participating in a basic LAN networking course and have a security question. It seams that network protocols like VTP and HSRP have a password option that is hashed with the message to authenticate that the sender is part of the VTP domain or HSRP group. Everywhere I've read that these authentications use MD5 or SHA1, including on Cisco's site last updated in 2018; https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhp-xe-3s-book/fhp-hsrp-md5.html MD5 and SHA1 have been declared unsuitable for cryptographic use since 2012 and 2010 respectively. I couldn't find change-logs to the protocol that updated the hash function to an up to date cartographic protocol. Are we still using these outdated hashing protocols? Is there a way to manually upgrade the protocol on my own private network?



Sunday, August 25, 2019

Keeping up

Hi all,

New to actually being in a network engineering position and was wondering if the subreddit might be able to help out. What are some good resources, blogs, YouTube channels, or other things that you all use to try and stay current? Any advise on keeping up with the ever expanding technology?



Anycast IP plugin

Hi all,

I have been wondering for a while about the practicality of a software-solution I've developed - would appreciate your opinion and level of interest in this.

The issue is such - Active/Active load balancing is hard. Even if your service is a nice stateless UDP app, if you're using VRRP or similar solutions for high availability you're pretty limited as it requires L2 adjacency between all participating servers. Distributing an anycast IP is not fun, as it mixes underlay (for added static routes or directing the network to point at some servers for the same address) and overlay (the usual configuration of loopbacks and configuring non-local bind, routing and a bunch of other stuff).

What I'm suggesting is a nice Ansible playbook (or installable software, it's really the same) which configures the following:

  1. The anycast address on the servers, some LB software plus its configuration towards backend servers
  2. EXAbgp/BIRD used to peer with the ToR switch/Default gateway/Whatever BGP capable switch you choose (possible to use other routing protocols as well)
  3. An ACL/prefix-list on the switch which prevents the specific BGP peering from learning any IP address which is not the anycast address
  4. Keepalived used to monitor processes, status or whatever custom logic you want to apply and stop advertising the anycast IP as soon as the service is marked as down
  5. Basic monitoring showing the distribution of load across all servers, the status of BGP/LB/Keepalived services, configuration compliance etc.

What do you think? I've been looking for a solution which will do this all together, the closest I've found is Calico, MetalLB but of course that those are a partial match and are sort of an overkill.

Cheers.



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



GS108Tv2 not forwarding EAPOL

Hi,

​

Device: Netgear GS108Tv2

I have a 2 devices (ONT and a supplicant) in ports 1 and 2. Both on VLAN1 untagged (ports 3-8 are on VLAN4 and aren't messing in between). And packets aren't coming back (not sure if reaching as I can't debug the ONT.

Right now I have the following:

- IGMP Snooping enabled
- IGMP Snooping on VLAN1
- Port based authentication state and Guest VLAN ON
- Port G1 (ONT): forceauthenticated, EAP Flood ON
- Port G2 (server): auto, EAP flood on

​

Still, I see the EAPOL packets going out, but none coming back in. This works flawlessly with a dumb switch

​

Thanks in advance!