Monday, November 11, 2019

Residential DSL provider is terrible (CenturyLink). Need a modem that has strong diagnostics/metrics, thinking of Cisco ISR with VDSL WIC?

Hey folks, my ISP is terrible and I'm tired of not having good data on the quality of the line and DSL physical layer to use for troubleshooting/evidence that they need to fix things. Wondering if there are any modems out there that have really good diagnostics/line quality/monitoring capability. Presently i'm thinking either a Cisco router with a DSL WIC or some kind of DSL modem with an open source firmware that is able to do same.

Any recommendations?



IPv6: what are the practical benefits of implementing it over an IPv4-only network?

I’ve been told by very smart people that IPv6 is amazing and should be implemented everywhere. I’ve also been told by other really smart people that there’s no reason to implement it at all. I’ve also been told by slightly fewer smart people that it’s stupid and we shouldn’t support it. Those fewer smart people are the ones in charge. Because of them, there is no IPv6 support on our entire network. We even have policy to disable IPv6 kernel modules and AAAA record lookups.

Our WAN supports IPv6. Our equipment supports IPv6. We have our IPv4 /29, but we need more IPs. v6 seems like a perfect solution.

I feel like there’s something critical I’m missing. I understand the absolute basics of IPv6, but I’ve never seen an actual IPv6 network implemented anywhere I’ve worked. NAT and small address spaces has always been the preferred network.

Besides the gargantuan increase in address space, and the lack of need for NAT, there doesn’t seem to be much different between the two. The cost for a v6 block is low, and it would solve multiple problems we have.

Is there something IPv6 is doing that validates this concern, or is it just ‘I don’t know it so it’s bad’ mentality?

I can’t think of anything except more extensive IP blacklists, some minor performance hits on our hardware devices, and the labor needed to switch over or Dual-Stack.



termshark v2: a terminal UI for tshark - now with stream reassembly and dark mode!

Hi everyone - for those of you that use Wireshark regularly, I just published termshark v2 on github. Termshark is a terminal user-interface for tshark that copies Wireshark's layout - it tries to be Wireshark for the terminal. Termshark v2 is snappier than v1 and features dark mode, piped input, stream reassembly and more. You can see the ChangeLog via the website, https://termshark.io, and there are binaries on github at https://github.com/gcla/termshark. Hope you enjoy it, and I would love to hear if it's useful to you.



Wireless - Ekahau Sidekick Offset

Quick question for any wireless pro lurkers out here... what offset are you using with your sidekick? I was looking at -12, but that seems possibly a bit aggressive.

I do have old scanners in my environment, so perhaps I am on the right path.

Thoughts?



How do I assign an IPv6 address to a system?

I am working on assigning an static IPv6 address to a firewall.

If it was an IPv4 address, I can easily assign a static IP address like this:

If 10.10.10.13 is available in the 10.10.10.0/24 subnet then I can assign 10.10.10.13 to the system.

How would I select an IPv6 static IP address from an IPv6 subnet and assign it to the system?

Thank you.



PSA: Possible PearsonVue Breach

This morning I came into the office with email confirmations from StubHub for a concert and a college football game worth over $2,000. The only place I have ever used my work email for any sort of purchase was at PearsonVue for my CCNP and CWNA exams (I have to use my work email for exam reimbursements). I have never ordered anything else to be shipped to my office and the new StubHub account listed my office as my address and used my full legal name which I do not use outside of a professional setting (including other online ordering, etc). I also never store my credit cards on any site and I'm not even sure that's an option on Pearson's website but clearly they're keeping the information on the backend. Something else that was fishy was that they forced me to add "security questions" to my account this morning when I logged in to make sure my card wasn't stored there. Either that's a very strange coincidence or they know that there was a breach and haven't disclosed it yet but have increased security. I'm posting here because I figured you guys may want to check your credit card statements and change your PearsonVue passwords since a lot of you use PearsonVue for certifications.

Mods, if you want to remove this because it somehow violates sub rules that's fine, I just figured this would be informative to quite a few people here.



Network Automation/Scripting Use Cases?

Hi all,

I'm currently wanting to learn about networking automation/scripting through Python for Cisco IOS and wondered what sample use cases there could be that don't rely on DNA Centre? Ones that are more reliant on pulling information from existing configuration on devices like troubleshooting ospf?



What would happen if packet 4 in this trace was lost?

Hey everyone. I am learning on my own right now about TCP and SMTP. Here is a trace I generated https://www.cloudshark.org/captures/d37a26bda955.
The first three packets are for a TCP handshake. The 4th packet is a data packet sent from the server to the client. What would the next two packets be if this packet 4 were to be lost?
My current guess is that the server would resend the packet with the EXACT same payload, ACK, and SEQ, and then the client would just acknowledge that as usual.
Am I correct, or am I missing something special here?
Thanks!



Rebuilding Manufacturing Companies Network from the ground up. Name some Cons that I am not seeing.

Two years ago I started working for a manufacturing company who has in the past, used multiple MSP's for their networking needs. The network is convoluted and is a mess. My boss tasked me with recreating the network from the ground up to have a fresh start.

We have 3 sites which are all connected with wireless bridges with vpn failovers. Right now each site has a fortigate firewall which is used for routing but all traffic is routed through site A. The networks we need are

Main Lan

Cameras

Phones

Shop LAN

Wireless LAN

Wireless BYOD

Wireless Guest

The wireless bridges span A/B and A/C.

My thought is to connect sites B/C with another bridge then ditch the 2 firewalls at B and C. This way we can have redundancy if 1 set of bridges goes down.

I can create VLANS for the phones, cameras, and wireless networks then implement QoS. This would make it so I just have 1 large network to manage with easy routing. We would have 1 LAN and 6 VLANS.

The other option is to keep the 3 firewalls and create separate networks for LAN/Cam/Phone/ 3 wireless networks at each site. This would require 24 networks in total and lots of routing since VLANS cant pass over the routers.

This post isn't the cleanest so bear with me, I tried to make it straightforward and a short read. What problems do you see with my configuration? If you need any more information please don't hesitate to ask.



Material on Huawei u2000?

Hi everyone,

I've recently received a promotion where I would have to get familiar with the Huawei u2000.

I've been trying to find some learning material to get a jump start but besides the installation videos on YouTube I cant find any. I've also tried Huawei's website but it seems you must register the product which I dont have access to it right now.

Is there any material free/paid that is available at all?