Monday, April 27, 2020

Hardware Recommendations - Gateway/Firewall low-mid budget.

We're currently using an MSP for our firewalls (USG 4P at both locations), utilizing a site-to-site VPN. The two offices are about 1000mi/1609km apart. We have some physical servers (storage and application) at both locations but favoring one locations (location A) over the other (B). We also have some AWS virtual servers in the mix. To add to it, we also have the need (especially currently) for VPN connections for working from home.

My experience is with older Cisco ASA (not certified), SonicWall firewalls, and USG. I've done a little with Cisco Meraki, WatchGuard, and Palo-Alto.

My question(s): should we stick with the UniFi or replace with something a bit more sophisticated? I haven't done much with SD-WAN but the research I've done looks like it might be a great replacement for the site-to-site. I've been considering getting a Meraki at each location and setting up SD-WAN but since my experience with it limited I'm not sure if it'll fill all our requirements. Would we still utilize VPN for individual users working remotely? Is there some sort of SD-WAN equivalent? Would we offload that to a software solution instead? Is Meraki worth it or would I be better served going SonicWall? Is there another product within the same price range that I'm maybe overlooking?



SFPs for Avaya/Nortel Baystack 5520?

I've been searching for a listing of commonly available SFPs compatible with Avaya/Nortel BayStack 5520-48T-PWR switch, preferably Multi-Mode 850nm 1.25 Gbps SFP (to uplink with to an Ubiquiti UF-MM-1G SFP). Google searches have turned up SFPs from unrecognizeable companies that I'm weary of purchasing from and hoping for a suggestion from a reliable brand and/or vendor.



Should I get a modem-router combo or a separate modem and router for true 1 gig internet

we are switching are internet providers cause we get 20mbps for 55 dollars a month



Cisco LIVE 2020 - Registration Opens (Free to All)

Hi Everyone, Just wanted to share that Cisco Live 2020 is be 100% virtual and registration is now open.

​

Registration Link



Enterprise/Commercial grade router

Hey guys I am looking for some feedback on our office building setup. So we just built and moved to a new office and essentially combined 11 smaller buildings into 1 large factory and office. I went with ubiquity switches and 10 ubiquity wireless access points through out the building with fiber connecting the 5 IDFs (250,000 sq ft facility). Everything seems to work well for the most part but occasionally I am having problems getting devices to connect to the wifi. I am still using the router provided from my ISP (Nortex 1GB fiber) to do DHCP. There are roughly 200 devices on our network and I dont feel like that provided router is capable, if I reboot it then the devices I was having problems with will connect and work great for a few days and then I will have the same problem. Am I on the right track in replacing this with a commercial/enterprise grade router? If so is there a particular brand or model you would suggest? I am by no means a network engineer, my knowledge is pretty basic. I appreciate any feedback or suggestions



BGP scan-time

Hi

As far as I understand, BGP scan-time is a feature that goes through the routing table every <X> time in order to evaluate next-hop reachability.

If I have R1 (AS1) -------------- R2 (AS23) -- R3 (AS23):

- bgp scan-time set to 5 secs on R3

- from R3 I can reach R1 loopback via R2 IP address (192.168.23.2) / BGP route

- R2 and R3 running OSPF

- if I shutdown R2 interface towards R3, shouldnt R3 remove the BGP route towards 1.1.1.1 from the routing table after 5secs?

​

Let me know if the above assumption is correct or not. Also because I found something as next-hop trigger and couldnt really understand the diference compared with scan-time, it looks like its same thing...

​

Thanks!



How to achieve network redundancy with dual Aruba core switches?

This question is inspired by "we take down the network 4 times a year..." post.

Let's say you have two 6300M core switches. How would you configure them to be redundant with no down time but still allow firmware upgrades?

How do you design a network to be full redundant like many of the replies state, but still allow firmware upgrades?



How to abolish IPv4?

IPv4 is fine. The workaround hacks to make it work in the modern world are the problem. In reality, IP exhaustion is the true problem. The headaches are CGNAT, NAT, PAT, etc...

Doing away with IPv4 entirely seems like a good way forward. How would we go about deprecating IPv4?



TFTP Server for macOS

Ok, I've dealt with this issue for years now and was wondering if anyone has any suggestions. I'm looking for a good little app to use for TFTP on for macOS. Yes, I know about the CLI and the OS having TFTP built in, but I would much prefer an app that would show TFTP progress. I'm a network engineer and sometimes need to move and upgrade the code on various network devices. Any suggestions would be much appreciated!



Routers

I'm looking to possibly replace my AP with a solid router I have a 500gb download speed any good brands out there ? I was looking into a Linksys..