Sunday, October 20, 2019

How much details are enough to get justification for RIPE allocation?

Hi

I've been working with a company who is network-wise splitting itself off from its parent company and thus requested a business internet line with fixed IPs (technical and org-level reasons). Currently we have a /27 from the parent and make use of roughly ~17 public IPv4 addresses when I count DMZ and office NAT gateways together - hence why a /28 is already on the low side for us. If we were forced to we could likely squeeze more thing behind a IPv4 to IPv6 reverse proxy but some services won't be so easy.

On the cost side the difference between a /28 vs. /27 is not that high, thus our boss went safe and requested a /27. But now we got a form from the future ISP requesting pretty detailed information about our current actual use of IP addresses like

  • number of hosts with function, vendor, OS (the vendor surprised me a bit, most is virtualized)
  • network schema if you request more than a /28
  • Questions like whether we are returning currently-used IP space, and if not, why (no: since it's owned by the parent and will be reused internally there).

Anyone in the european space who could share similar experiences? Is there a tendency to only grant you the requested IPv4 subnet if you provide very exact data on the network? Is there a tendency to force you i.e. into a /28 instead of a /27 if you can currently justify let's say 18 IPs but not 25?

I should mention that the future ISP in question is one of the incumbents in the national market here and has definitely plenty of IPv4 address space available. Is this a normal procedure? To be honest I've only worked with ISPs where the company had maybe a /28 at most so this is the first time I've encountered such a form.

Looking forward to hear about some experiences. Oh and yes: One reason of getting independent is the question on IPv6 being unanswered by the current upstream for years.



FS.com QSFP-40G-LR modules failing. Anyone else?

We've decided to try out using some off-brand cheaper tranceivers to get away from how absurdly expensive name-brand tranceivers are, especially for 40G LR. However, we've only purchased 12 of these tranceivers and we've already had 2 failures out of the 8 we've deployed.

It wouldn't be so bad if it was the entire link dropping as everything is redundant, but instead it seems like only one of the 4 channels is failing resulting in the link dropping close to 25% of its packets but the switches still deciding to keep this link in the agg. A lot of people in this subreddit seem to recommend the FS tranceivers (and we have a mix of their 1G and 10G scattered around which haven't given us problems yet), so I would think that if these were that unreliable they wouldn't be recommended.

Did we just get a bad batch? Or is this a classic case of "You get what you pay for"?



Question on netbrain

https://ift.tt/2Buz1po

SP Static IPv6 Design

So I'm in the middle of designing and building out an IPv6 deployment. Currently having an issue with determine what is the best plan of configuration.

From what I can determine now, I'd have to set a static route for every block for a customer via a GUA. Is there anymore automatic method I can possibly configure or just apply on the SVI? One thought also is for a static GUA but then use DHCP reservation, but I could see that getting messy and enterprises not being a fan of that at all.

How are others building this out on their networks? Tips/tricks/etc? Doing DHCP was a breeze, so just static left until I can start production tests.



Wireless networking solutions for 160+ devices within ~1 metre area?

Hi!

I'm working on a device that uses 160+ stepper motors, each driven by an Arduino Pro Mini clone. Currently, communication between the Pro Minis occurs via a daisy-chained, wired serial solution. While simple to work with conceptually, this solution is a giant PITA when it comes to updating the code as we're required to take everything apart, individually re-flash each chip, re-assemble and re-wire everything.

I'm currently investigating the feasibility of running tiny wi-fi capable Linux boards instead of the Pro Minis in order to more easily update the software and remove the need for a lot of the wiring. That said, I'm weary that the WiFi protocol was not designed to run so many devices in such close proximity.

Is this a bad idea? Are there other more suitable/reliable kinds of close-proximity wireless communication? Are there other embedded wireless solutions that are more lightweight than running the entirety of Linux, that allow for swapping out software without re-flashing? Any advice appreciated!



PoE issue on Cisco 4500R+E w/ WS-X4748-RJ45V+E

I've got a weird issue that I'm wondering if anyone else has come across before. I've got some older PoE (Zebra MK500) devices that won't get power on the above switch. I've got other PoE devices (Cisco APs, MiTel Phones, MiTel DECT APs, etc) that all get PoE just fine, the issue seems specific to these Zebra devices. I'd say the issue is a problem on the MK500 and call it a day, however, my LinkRunner AT2000 won't test ports on these switches if I have the PoE test enabled. Which leads me back to suspecting the switch. The behavior of the LinkRunner with PoE tests enabled is that I get link for about 2 seconds, then it goes away for 5-10 seconds and repeats. As soon as I disable the PoE tests on the LinkRunner the port comes up as expected and I get the CDP info from the switch. We've tested these devices across numerous 4500s at this location with the same modules so I don't think it's bad hardware. We also have these devices running in a different location with the same hardware and software versions without issue. Unfortunately, no one at that other location has a LinkRunner so I can't test if that behavior is the same there or not. Interestingly enough, a LinkSprinter (the LinkRunners baby cousin) tests PoE without issue.

We also have some 3850 (MGig w/ UPOE) and 3560 switches at this location and the MK500 (and my Fluke) operate fine on those.

I'm at a loss as to what else might be wrong here. It's essentially a generic PoE configuration, we don't enable/disable poe on ports, no policing, etc. Has anyone seen PoE devices behave like this on these switches? Any ideas on where to go with it?



Port forwarding on IPv6?

Hello, i have a bit of a problem here. I have a Vodafone 1gbit connectiom that runs over the Ipv6 protocol. I want to host a headless client for a game server that only accepts ipv4 adresses and needs a few ports opened in the router. With ipv6 that is not possible. how do i solve this issue?



Stateful UDP filtering using Cisco ASR

I want to use a Cisco ASR 1001-X to do stateful UDP filtering (UDP connections should only originate from inside). What’s the best way to do this? I could use a reflective ACL, which seems very basic, or the ASRs firewall feature.



nslookup using Google DNS resolves to internal 10. IP addresses?

I’m a fairly new network analyst, so I’m not even sure I’m asking this question the right way. We have servers that host internal resources. Some of them are publicly accessible but others are all internal. How does Google DNS (or any DNS other than our own) know about our internal 10. addresses when doing a nslookup of one of our internal servers names?

I’m not sure if this is a security risk. But couldn’t someone basically map out a lot of our internal 10. architecture? I realize that’s only if they are behind our PNAC and know what they’re looking for but it makes me uncomfortable.



Is this impossible or am i retarded?

lo0 12.6.28.0 /25

lo1 x.x.x.x /24

lo2 12.6.30.0 /23

Wouldnt the network for lo1 be 12.6.28.128 - 12.6.29.128 or am i missing something? Everytime i try to place the ip for lo1 to 12.6.28.129/24 it says the network is overlapping with lo0. Any help will be greatly appreciated.