Sunday, September 29, 2019

Open Source Traffic Logging/Visualization

I run a small DC at my school (roughly 500 IPs) with a Juniper edge router/distribution switch down to 5 access switches. OSPF up to my next hop. I want to be able to log and visualize data from hosts so I can see how active IPs are (mainly to see if I can shut them down). I'd like to see E/W traffic if possible, but N/S would do.

Anyone have any suggestions?



1-year-ago-me just saved my ass, aka "babbies first core switch failure"

tl;dr - Core switch died while I was halfway across the country. Due to how I built the network a year ago, there was no outage and I looked super cool and competent through my first major device failure.

Friday night I'm hanging out in the United club lounge at the airport waiting for my flight to start boarding when my phone lights up with texts from Solarwinds that some stuff has gone down, including a bunch of stuff (like our Edge switches) that made no sense.

So I VPN in, which was weird because if our edge switches were both down then I wouldn't have been able to connect to the VPN. I couldn't get to some devices through the regular network but I was still able to access them through our Cradle-point Out-Of-Band cellular backup network, and everything looked like it was still passing traffic just fine.

Initially I was thinking this was a Solarwinds freakout, but then after a couple of minutes of checking things I realized that one of the switches in our collapsed core (we have a pair of stacked C9300s that act as both Core and Distribution layer) had died.

But because I'd been neurotic about dual-homing all of our Access layer switches and server switches, and making sure that all other systems that connected to the core were as redundant as possible . . . no one noticed. There was some reduced bandwidth internally, but there was no downtime for anything and aside from us in the IT department, no one knew there was any sort of a problem.

By this time I'd boarded my flight, but I opened a TAC case from the in-flight wi-fi and once I got back on site Saturday morning I was able to sort out what happened.

It turns out that one of the switches in the core stack had experienced a spontaneous reboot for unknown reasons, but then it stayed down because the "Manual Boot" option was set. Once I was in the console and issued a Boot command, it came back up and everything was hunky-dory. I turned off the manual boot option, cycled in again and we're good.

Lessons learned:

  • Out-Of-Band management networks are super duper awesome and I'm so glad that I put it in place.
  • High-availability is super duper awesome and I'm so glad that I insisted we spend the money on it, rather than cheaping out and crossing our fingers that nothing goes wrong.
  • Some ethernet serial devices might be worth it so I can get into the console remotely, rather than just the management interface
  • Maybe I'm not as bad at my job as I'm always worried that I am.


Roaming with two different Controllers (5520 and 9800)

I was wondering if anyone in the subreddit has deployed a mixed environment with the 9800 controllers.

Im currently planning on deploying the 9800 with 9100/3800s but we currently have 3500s and 2600s which I need to keep them on 8.5 with the 5520. I'm planning getting the controllers in the same mobility group and rf group (i'm taking a bet with that is going to work) but these access points are also in flexconnect so i need to see how they roam in different flexconnect groups. This is just with PSK currently so I'm not very worried on issues ill have with 802.1x roaming at the moment (that is a later problem but hopefully those 3500s and 2600s will be replaced by them)

This is just a temporary problem which i have couple solutions such as just finding the money so that we dont have a mix environment or moving access points so they dont do inter-controller roaming..

Edit: If i can't get rf grouping to work well then i need to do static configurations.. which will be a pain. Add to the question... if you deployed it in this mix environment how does RRM/Cleanair react

Im just trying to see if anyone has faced this challenge and found a solution. I'll be testing this in a lab in the next couple weeks so we'll see.



Cisco ASA loop broadcast packet

I have small office where running cisco ASA ASA5506 and version 9.4(1)
and it's also configured for IPsec VPN tunnel, My LAN subnet is 10.1.1.0/24

So i have found very interesting things in LAN where if i ping 10.1.1.255
(broadcast address) it create nuclear reaction and my packet goes in loop and fill my LAN with traffic and my cisco ASA CPU goes 100%

This is how i stop strom, clearing conn in ASA

ASA# clear conn address <source_address_of_desktop> 

I believe cisco ASA participating to amplify this storm. here is the basic config snippets of ASA

same-security-traffic permit inter-interface same-security-traffic permit intra-interface 

Notes: I believe one of above option has something to do with this storm.

Routes

S* 0.0.0.0 0.0.0.0 [1/0] via 26.172.22.1, outside C 10.1.1.0 255.255.255.0 is directly connected, inside L 10.1.1.1 255.255.255.255 is directly connected, inside 


Networking question to reach an api server

I would like an app server "A" to reach the API server (located at Network C) via another network (network B). What is the best way to reach ? it must be a two way communication. Let me explain. Three networks are involved( Network A,B & C). What is the reliable way to design this infrastructure?

Network A [] > Network B [] and network C []

Here is what I am considering:

Create point to Site trust VPN relationship between A & B . There is Site to Site VPN between B & C that already existed . What is the reliable way App A located in Network "A" to have (port 443) two way communication to the API server in "Network C". Thank you for reading.



Cumulus Networks Certification (CCONP)?

Anyone researched or, better yet, taken the Cumulus Certified Open Networking Professional (CCONP) exam? I think this is a really interesting exam and am looking to see if anyone else has any thoughts on its value (for those who deploy Cumulus and general networking value). How did you go about studying for the exam? How was the online exam proctoring experience?



windows 10 Quality of Service or similar

Is there a way to enable QoS or something that allows me to prioritize for example streaming?



what is preemption in hsrp

i just learn how to config HSRP in router and in switch layer 3 , and i don't understund the preemption in hsrp

what is this preeption ?



Is this subnetting video incorrect? I don't get what he's doing here.

https://www.youtube.com/watch?time_continue=316&v=uyRtYUg6bnw

Is he doing some kind of "classful" subnetting? Because from what I've learned it's only CIDR that counts, classes have no meaning since 1993 (other than the private ranges). Also subnet calulcators online shows the results I would expect ie ignoring classes & just counting the mask. Or have I completely misunderstood everything?

This video has many views & high rating so what am I missing? What is he doing. Thanks



Network Administration Associate Degree

I'm currently in the Navy but I plan on getting out in the next 3 years. I have both experience and certs like Security + and CCNA R&S but I also want to strive for an Associates degree as well to make myself stand out more. Been looking into colleges like UMUC but I want to know if there if someone had advice for a good Associate's Degree for Network Administration.

Should I just go for an Information Technology degree w/ a specialization in Networking? Just wondering if anyone had an opinion or advice.