Monday, October 14, 2019

Aruba 8320 3rd Party Optics?

Hi

Has anyone has any luck with these? I know people have has issues with the FS.com ones previously. They are recommending:

https://www.fs.com/uk/products/11559.html

There are also these that I found - they claim to work with the 8320:

https://switchsfp.com/products/j9150d?_pos=1&_sid=3ec4013b6&_ss=r

Thanks

Huw



[Question] Cisco ISE - ldap/s to Azure AD without VPN.

Hi Reddit,

I have a client with Azure AD, but no on-prem AD. The client is planning an Cisco ISE installation and Cisco Meraki MX FW.
The MX FW does not natively support VPN to Azure, so ISE won't have a direct connection to AD.
We could run an Meraki vMX in Azure and then create a VPN, however I'm looking into alternatives due to saving $.

https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-configure-ldaps

What I'm considering is running ldap-secure over internet, with white-listed IP's of the locations.

Has anyone done this or something similar before? What was your experience?



Juniper EX Switches having hardware issues?

We just implimented a pair of EX2300 as TOR Switches. Last week I had one hard-lock and crash, console was inoperable. It came up after a power cycle.

Called up JTAC, both had SNMP Traps for fans that didn't exist being sent to syslog so they replaced both of them; the switch that crashed did not turn off when sent a request system power-off so that looks to be a hardware fault.

I change them both out out Saturday, find out one of the replacements rebooted into the loader screen and won't take firmware; it's giving me filesystem alignment errors so I'm guessing storage on the switch itself is toast. This is after it took firmware, loaded up fine, took a config, and was working.

We're up right now and I'm getting in early today to get back on the line with JTAC to continue troubleshooting and to make sure they have someone onsite in case another switch fails.

Am I just really unlucky or are they going through some hardware\supply problems right now? Juniper gear has always been rock solid for me once you get it in and all the bugs worked out.

Thank you.



How to terminate VPN tunnels for each client ?

Hello guys !

We have a new product that will be hosted in our Datacenter. This product is installed on a Windows VM that will have to be joined to the customer AD for various interactions, which is why a site-to-site VPN has to be established for every clients.

This is were it gets complicated for us, we've never had to set up dedicated tunnels over internet for clients, and we are now faced with the overlapping IPs issue : on both the clients LANs, and the VM IP addresses that will be chosen by the clients. Impossible for our firewall to be the tunnel endpoint for every clients, without a logical segmentation (VRF, VDOMs, etc...).

The throughput flowing through the tunnel will be very minimal, a few mbps (less than 3) at most for each client (50 are expected within a year).

Do you have a recommendation for a network design that could be implemented without the need for VRFs ? We have enough public IPs for assigning one per client if needed.

We could deploy a firewall VM per client which will terminate the tunnel. Is this a viable option ? What model would you chose to be just a tunnel gateway with the low traffic expected ?

If VRFs are the only option, what brand and models are you suggesting ? Fortinet and their VDOMs seems to be an industry standard for service provider. What about Juniper SRX and their virtual router ? The price point seems way lower than Fortinet, is there a reason ?

Thanks a lot for your help, I need some perspective here ;)



Dealing with Internal Attackers : Dealing with Liability??

I work at a uni, and regularly check what attacks happen on our network. In student season I always get a good couple of handfulls of machines on the network attacking other machines (usually over the internet). The problem is this: I have a report that I generate that tells me what username/source ip/dest ip/attack type/timestamp of the account/machine that was attacking the other people on the internet. However, how can I find a way to make them liable, or not liable for this kind of attack? They could easily claim that their machine had been hacked, and it was the hacker instantiating these further attacks. I worry because if nobody is ever liable for hacking/attacking other people then they can just get away with abuse/unlawful attacks scott free.



Network Emulation with EVE-NG

Hi All,

I am someone who feels very strongly that the best way to learn any new networking concept is to get hands-on experience on the subject. Now there are many people who already use network emulation software. I am just another person trying to help drive this as I feel there are not enough people in the network engineering space doing the effort to learn something new. I do not know if this is because of lack of financing where you believe you need to spend an excessive amount of capital on hardware when you can do the exact same type of labbing using virtual equipment and it can cost you ABSOLUTELY NOTHING!

So I have put some time aside to show you have to configure an EVE-NG Community edition server on VMWARE Workstation Player 15 in order to create your own labs.

https://youtu.be/uEH3IN1295k

I have also uploaded a video on how to import a MikroTik CHR with many more images to follow shortly!

https://youtu.be/kmJVScuCzIM

I really hope people take this to heart and join us in the emulation space where you can configure any network you can imagine and even if you break something in the virtual space it is no issue at all! You can even learn from those mistakes.

#EVENG #NetworkEmulation



Sunday, October 13, 2019

Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Curious about .0 IP addresses and poorly designed endpoints.

Hey all-

I recently had an embedded network-enabled device that refused to accept an address ending in .0 on a /21 subnet. This was clearly poor programming on the part of the device's programming team and we simply used another IP address, but it got me thinking. Have any of you ever experienced an issue trying to assign an IP address like 10.10.10.0/16 to an endpoint?



Networks not learnt over OSPF

Hi,

We are deploying a SDWAN in a customer premise environment with OSPF configured towards the LAN. This sdwan is connected to a cisco switch(L2 switch) which is connected to a cisco router. OSPF is configured in between the sdwan and the Cisco router with Area 0, I see the OSPF neighbor-ship to up in between both sdwan and cisco router.

My question here is, out of the 5 networks advertised by Cisco router, I see only one in the SD-WAN LAN routing instance. Is there a way to figure out why the other 4 networks are not being learnt by SD-WAN? Am I missing anything?

I do not have access to any other device except the SD-WAN.

Edit - no access policies on the cisco router

Help much appreciated. Thanks



Is there anyway to upload firmware from cisco 5505 WLC

Hello, I've been trying to get a customers WLCs in a HA pair and I according to the HA deployment guide the two WLCs must have matching code. Unfortunately the primary has a newer version, and these are out of support and EOL. Is there anyway to get the code off the primary and put it on the secondary? I realized also that the primary does have the old firmware still on it, maybe I could fall back to that version, do the HA pair and then push the code back onto it and it would sync. Thoughts?