Sunday, October 6, 2019

Why the arrogance?

I don’t understand why a lot of the mods here on Reddit are so arrogant. I made a post yesterday and it was auto removed, so I requested permission to post it, My response was simply “nope” and then i was blocked for 72 hours... Like i get it, and i would have been fine not posting it.. But why the mute?

Inb4ban



Web filtering solution, help!!!

Hi guys,

I looking for some suggestions here about the best option for a web content filtering solution.

I want to implement it for a small congregation so they can block everything but their website, so as you might guess I'm doing it for free and that also mean I'm looking for the most cost effective solution. I don't mind paying for it but if it could be a free open source or something like that even better so I don't have to worry about it not working because I didn't pay for it for any given reason.

Basically I want to redirect any attend to access a website to a custom web page with a list of websites that guest users are allowed to browse, most users will try to access through mobile devices so it has to be mobile/WiFi friendly.

I have tried with PFSense/Squid (real nightmare), PFSense/Pfblockerng-devel and OpenDNS with no success so far. The easiest way so far has been OpenDNS but as with all of them HTTPS is a real pain, because of some websites like Facebook implement HSTS instead of getting the block page redirecting they get the SSL certificates error and that's not something you will want for your guest users plus I won't be able to redirect them to my custom block page, OpenDNS for this problem was the most effective by just installing the certificate in the computer but that would work in a home or business environment but not in a guest environment like a guest network.

I have been trying to do this for weeks now with no success so you could please give any suggestions I would really appreciate it.



Uncorrectables help

Sorry if this is not the right place for this. But, I'm having a lot of issues with internet stability. Took a look at my modem and noticed over 300,000 uncorrectables on CH. 16 and over 10,000 on CH. 2 after only 2 hours of uptime. The line coming in to my home is only a year old, and the one that is spliced to it that runs in to my wall is only 6 months old. Does anyone know why I have so many uncorrectables on these channels? Only thing I can find on this issue is possibly a cable issue but all of my cabling is pretty new. Any help is appreciated.



Recommendation for developing baseline firepower Access Control rules based ONLY on logs from Firepower Management Center (FMC)

Hi all, we recently deployed some firewalls in a client's network which was initally an "open" network.

Based on the design of these new firewalls put in place to implement proper segmentation, I have been tasked with developing baseline firewalls rules.

Because the network was initially open, there is no way I could possily use any existing rules. Plus getting the expected traffic flow information for each zone from the relevant teams of the client is not possible for unknown reasons. They do not have that sort of visibility.

So, the responsibility is all upon me to somehow develop this baseline firewall rules based on just looking at the traffic logs! You can imagine how this can be a humongous task.

Hence, I am wondering if there is any better, more efficient and faster way to do this ? I dont want to go through the logs line by line to determine what firewall rule should I create ?

Does anyone know if there's any such feature or dashboard/report in FMC where I can get the visibility of the high traffic patterns from all zones, which can eventually help me build this firewall policy ?

For e.g a list of traffic flows which tells me there is high amount of traffic between zone A to zone B and so on.



Networking Theory - Network+

I have over the last few months created a networking theory series which touch upon both home and enterprise topics. So far it has been a huge success on r/netsecstudentsso and on r/HomeNetworking so I decided that someone here could benefit from it as well. Feedback is very much appreciated as I'm currently studying for Network+ Cert.

Full playlist:

https://www.youtube.com/watch?v=rIZ61PyDkH8&list=PLR0bgGon_WTKY2irHaG_lNRZTrA7gAaCj

Individual lectures:

And many more.. For rest of the videos please use the full playlist link in the top.

Happy Learning!



Huawei switches - anyone?

Hello,

we're looking for new core and distribution switches for our routed access design. Currently we're using HPE switches running H3C Comware OS. So If it was HPE, we'd buy 5710 switches for core and distribution.

Now someone proposed Huawei switches (6720/6730) . Looking at the current CLI, those switches still seem to share a lot of commands with H3C (Huawei 3Com) from past. It seems Huawei sells licenses for activating ~full layer3 features...

Is anyone from here actually using current Huawei devices and can tell about his/her experience with the switches themselves or Huawei's support?



ASA HA pair mgmt ports on different subnets

Hey folks,

Configuring two ASA 5555x's in ha split across two sites, purely for anyconnect. when they are in a HA pair it won't let me have each device's mgmt port on different subnets.

Each site has a different subnet for OOBM so the plan was to configure each mgmt port on its respected subnet for mgmt.

no one wants to L2 there OOBM over two sites.

Anything im doing wrong here ?



Slow download speed when downloading

Hey, I have a problem with my download speed. When I am not downloading I get around 250 Mb/s but when I start downloading it drops to 10...

I use a orbi router with 2 acces points. One is even directly in to my computer with a cable.

Can someone help me please?



Saturday, October 5, 2019

Are there any good alternatives to Cisco Net Academy for a hands-on approach learning routing and switching?

During school I participated in a course called Cisco 1. This course taught me about the basics of the OSI model, TCP/IP stack, and enough to setup a simple network with routers, switches, and other hosts. However, I switched my degree and never ended up taking the other 3 Cisco courses that my school provided. Throughout most of my time in Cisco 1, we used their Network Academy and Packet Tracer to learn concepts before practicing them in a lab with real hardware. I don't really have any issues with Cisco, but I would prefer to learn about switching and routing with as little proprietary fluff and barriers as possible. Is their any good material out there I could use and practice with in a home lab environment using equipment such as Ubiquiti switches and routers?



VPN Handshake - where is it?

Hi

I've setup an OpenVPN connection to my home router (PfSense) as a demonstration for a school project. I need to show how VPN works under the hood with handshake, key exchange and so on.

When I inspect with Wireshark I can see a lot of OpenVPN packages, but not the key exchange. Is it possible to see it?

I was hoping some clever person here could point me in the right direction :)

Thank you in advance.