Monday, August 26, 2019

Azure VNET 2 OnPrem with or without Firewall

I have a feeling my company is going to be dipping their toe in Azure within the next 12 - 24 months. I'm trying to get ahead of what I don't know by doing some beginner research. I'm also betting that on-prem will be connected to the VNET out in Azure in some sort of capacity. I have seen a few network diagrams and tutorials on how to build a VPN tunnel using an Azure gateway but nowhere do I ever see a firewall between the gateway and the VNET within these diagrams. Am I to treat these gateways as security devices as well?

​

Edit: Specifically I'm talking about a firewall between the Azure Gateway and the Azure VNET



VPN Connectivity problems

Greetings! This is my first post here, so I apologize if this isn't in the spirit of the community, but I'm looking for some assistance, as I'm not too experienced in VPNs. My apologies if this isn't the place for this sort of inquiry.

About two weeks ago, all the VPN users for one of my clients stopped being able to connect. This is a new client so I'm still getting up to speed with their environment. They have a Cisco ASA and appear to be using IPSec/L2TP with local authentication.

Most of the users try to connect and get a spinning wheel (Windows 10). Some try and are told their username/password don't work.

I've been working on it and been getting weird results. I tried connecting with my phone and was able to connect to a network server and see the resources. It worked just fine. But Windows is giving me nothing but problems for all users.

I tried a registry tweak I found somewhere that adds a DWORD value to the PolicyAgent key. That let my laptop connect successfully, I think, but when I try to connect to anything on the local network Windows acts like it can't even find it, whether through host name or IP.

What's going on? Why on earth does everything work fine on iOS but not Windows?

Thanks for any help.



PVID on avaya switches

Hey everyone

I'm working on converting some avaya switches to juniper, and I'm trying to wrap my head around the various PVID tags, and figure out what PVID is. I'm not clear if it's a native vlan, or just tags frames outbound.

Does anyone here with any background on this have any helpful insight?

Untagpvidall, tagpvidall, etc... I've tried researching but getting conflicting information

Edit: thanks for down voting someone who's trying to ask a question, much appreciated! 🙂



Cisco FPR1010

Has anyone had the opportunity to interact with one of the new Cisco FPR1010 next gen firewalls? My rep is trying to sell me on these over the ASA 5506 but they kind of sound like Meraki where it's all cloud controlled. I'm not sure I'm ok with that.



Did you know Linux can do static routing out of the box?

You have to enable it first, but it works! It can even pass tagged VLANs if you connect it to a trunk port!

I'm reading through Network Programmability and Automation: Skills for the Next-Generation Network Engineer and it's blowing my mind thinking about networking in these new ways.

Any other out there network concepts you can think of?



Isolating wireless access from trusted network on Watchguard T35-W

I am testing a T35-W that we want to replace our existing Sonicwall TZ unit with. I've gotten pretty much everything else figured out but the built in wifi. While I had no problem getting Access Point 1 working within our trusted network as well as the internet, I am hitting a wall getting Access Point 2 configured for guests so as to block access to the trusted network while still giving it internet access. I enabled its DHCP server and assigned it an IP range on a different subnet than the wired trusted network. I left the default gateway setting as Use the interface IP Address. I created a policy that denies access from Guest Wifi to Trusted on all ports. In the end I am able to get internet access to work fine but I am unable to block it from the trusted network, even the IP to the Fireware login screen is still accessible. What am I missing?



Random sites, randomly trying to push POS traffic to our firewall

Scenario: we have a site that has a POS computer. It uses a program to complete transactions and sends it to a server internally in our network. We obviously use this for keeping track of sales and reporting, etc.

Randomly, the program goes down. Looking at our logs, our firewall is blocking the conversation between the POS and the server. The problem is that the conversation between the two should never be hitting the firewall to begin with.

This has happened 5 or 6 times in the last few months, and the only solution we’ve been able to remedy it with has been to change the IP address of the POS computer.

We’ve spoken to the people who make the program multiple times as well, and they’ve said repeatedly they don’t see anything wrong with the server as far as they can tell.

I’m just wondering if there’s something I’m missing here on a networking side of things. I can’t think of a reason for why seemingly random POS computers are trying to route through our firewall for an internal conversation.



Unable To Telnet/SSH Into ESXi Host/File Is Being Locked By a consumer on host.

I am unable to SSH or Telnet (Port 23). I can ping my ESXi host from my computer. The host is up and running. From Putty I am connecting to 192.168.125.xx using SSH. Port is set at 22. I get the error message: "Network Error: Connection Refused".

​

On the other question, I had an issue where I moved a VM from one datastore to another yesterday now I am not able to power it on. I get the error message: An error was received from the ESX host while powering on VM XXXX.

Failed to start the virtual machine.

Cannot open the disk '/vmfs/volumes/902099b8-c6eb93ef/ls3-odtdb02_1/ls3-odtdb02_3-000001.vmdk' or one of the snapshot disks it depends on.

Failed to lock the file

Cannot open the disk '/vmfs/volumes/902099b8-c6eb93ef/ls3-odtdb02_1/ls3-odtdb02_2-000001.vmdk' or one of the snapshot disks it depends on.

Failed to lock the file

File is being locked by a consumer on host _____________ with exclusive lock.

​

Any suggestions?

Thanks,



SD-WAN Scenario: One head-end with multiple "customers" connecting?

I'm trying to mentally process the feasibility of this scenario: One SD-WAN Head-end with multiple "customers" connecting to it.
(capacity may come into play such that I have multiple head-end devices, but there would still be multiple customers per head-end, so we'll keep the scenario one-to-many)

Hypothetical Backstory Context: I'm a device/service provider and my customers have their own networks but have to route my device/sensor data back to me from remote sites to be aggregated/processed. Currently all incoming customer data is whitelisted by IP (keeping it to only a few IPs per customer), meaning their multiple external-site data sources must be routed back to a central point before being sent my way.

Question at issue: Can I host a master head-end SD-WAN device(s) and have multiple customers' edge SD-WAN devices establish automagic dynamic VPN links back to it for the sensor data?
ie: Customers have the option to deploy edge devices of the same type as my selected head-end so they can talk directly to my head-end (for just the desired data) instead of having to route all that back through their own networks.

Security Concern: This must obviously not allow intra-customer traffic, but ACLs should cover that.



(Urgent) What is the job scope of a NTD-Wireless engineer?

Hey guys, I got an interview invitation for this position and honestly I can’t find any info regarding what is NTD actually. Does any of you gusy know what is the job scope and perhaps tips to ace this interview? Your help is much appreciated!