Monday, April 27, 2020

We take down the network 4 times a year. Does your enterprise also batch up disruptive changes like this?

Like the title says, we arrange with our business customers for their applications and services to be unavailable for several hours over a weekend, 4 times a year. We pay so much for redundant networking gear that I feel like this is a backwards way of doing things.

One reason we do such a broad impact at one time is because we can’t seem to figure out exactly which applications/services will be impacted. Another reason is that many of our big applications are “sensitive” to losing the network. I.e. if they lose connectivity for 20s they start rebooting, or pull themselves out of the available pool for a service, etc. therefore, the support teams for those applications prefer to shut down the application for many hours just so it’s graceful, even if our impact to them might only be 30 mins.

How do you schedule disruptive work at your enterprise?



VTI Site-to-Site VPN help needed!

Greetings everyone,

I am having some problems with setting up the VTI configs between my 2 routers (R1 and R3)

IPsec phase 1 and 2 comes up everything works like a charm.

However, the whole reason we use VTI for is that we can have separate policies between encrypted and un-encrypted traffic.

So my problem is:

I wrote the following Policies (One for the VTI interface and one for the physical interface):

R3:
conf t

!
class-map match-all VTI-CLASS

match any

exit

policy-map VTI-MAP

class VTI-CLASS

set precedence 2

exit

interface tunnel1

service-policy output VTI-MAP

exit

!

!

class-map match-all Physical-CLASS

match any

exit

policy-map Physical-MAP

class Physical-CLASS

set precedence 4

exit

interface ethernet1/0

service-policy output Physical-MAP

exit

!

---------------------------------------------------------------------

I have done a packet capture in wireshark and I see that every single traffic leaving the router (R3) is having the QoS value "Precedence 4"

But packets going through the VTI tunnel interface also have "precedence 4" QoS markings (But it supposed to be having "precedence 2" markings.

As soon as I give out:
interface ethernet1/0
no service-policy output Physical-MAP
exit
!

So basicly removing the physical policy, traffic going through the VTI tunnel instantly turns into "precedence 2" marked QoS values.

But for some reason, if both policies are applied the physical interface policy simply overwrites the VTI tunnel policy.

--------------------------

Just to buy some time I will also post my Ipsec config aswell: (Which is mirrored in both routers):

R1:

conf t

interface loopback0

ip address 1.1.1.1 255.255.255.255

exit

!

!

!

crypto isakmp policy 5

encryption aes 256

authentication pre-share

group 14

exit

crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0

crypto ipsec transform-set P2P-SET esp-aes 256 esp-sha-hmac

mode tunnel

exit

crypto ipsec profile P2P-PROFILE

set transform-set P2P-SET

exit

interface tunnel1

ip unnumbered loopback0

tunnel source ethernet 1/0

tunnel destination 35.0.0.3

tunnel mode ipsec ipv4

tunnel protection ipsec profile P2P-PROFILE

exit

-------------------------------------------------------------

Might this be a bug with my GNS3 IOU images? Or with Wireshark?

Or is this working as intended and I screwed up something?

Thanks for the answer in advance.



Sunday, April 26, 2020

IPAM During Covid

I just got a /40 from ARIN. And I have no money for a paid IPAM solution.

I got a Netbox dev box up, and it looks pretty good. I've been a fan of Stretch for years, so seemed like a good place to start.

What else should I check out?

I have Solarwinds as a NMS, so that's not needed.

And just to reiterate I've got nothing to spend.

Thanks!



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.



Sophos XG Firmware Updates

Are there any other XG users here who are as nervous as me when it comes to updating firmware?

Maybe I've just been unlucky but we've had two different XG210 rev3 units "shit the bed" when it comes to updating them over the past 12 months.

One occured on Tuesday last week, rebooted the unit so it had a fresh boot and then downloaded the firmware within the management interface and told it to apply and reboot. Well it never came back, and after waiting two days on Sophos support we finally got an RMA agreed and a new unit is going to be with us some time next week - that in itself is a bit frustrating given we have the all bells and whistles support. Just so happens we had spare kit available at this site because we can't seem to rely on Sophos turning things around quickly.

I've got another to update this week, just nervous to push the button. I probably manage close to 50 firewalls and they're a mixture of vendors but I've never seen such issues with other vendors equipment.



P2P with POE Passthrough

Does anyone have a recommendation for a good, solid Point to Point device w/ POE Pass-through to go less than 1 Mile? My go-to is Cambium, but they don't have anything other than 250Km P2P devices from what I can tell. Ubiquiti is a bit "consumer-grade" in this department.

On the pass-through, POE 802.3at Class 3 (11.0w) is possible, but Class 4 (17.0w) is preferred.



What information do you out in your exec banners?

We all know about MOTD/login banners and the legal notices that usually go in there. But I’ve actually never used the third banner; exec.

The only information that I’ve come up with that you could put in are: * Connected devices - Saves you from looking at CDP/LLDP neighbors. * Important uplinks on the device. * Jokes

What information do you put in your exec-banners?



Why 192.168.x.x or 10.x.x.x

Whats the reason for these ranges specifically to be private? (Shoutout to 172.x.x.x)



WatchGuard firewall — what are the benefits of Secondary IPs used in (External) Interface

I’m moving (replicating) the server/RDS from one site to another. Both sites have a WatchGuard firewall, but only one has secondary IPs added to one of the external interfaces (leased line).

All this was configured by someone before my time and I’m learning from back to front 😋😎

Different things such as BOVPNs use different IP and not the primary IP. I use the primary IP for the management.

At the new site, can I assign the primary IP to everything? (Not like I have a choice)

I guess I’m just not 100% sure about the benefits of having additional external IPs other than separating traffic.

Also, can I just move all those additional IPs from one watchguard to another? The first watchguard won’t need them anymore. Not sure how that works with the ISP provider either... both sites have a leased line provided by the same ISP.



[Trade] - Network Brilliance - Andrew Tate

I got a decent course by Andrew Tate about networking and connecting with high status people and advancing in your life relationships with such people. If you are interested, drop me a DM.