We want to setup WAN connection between our sites, currently we are using mostly cisco devices switches for LAN sites and 2 routers with hsrp config to ISP using bgp protocol, i was wondering if we can use WAN switches and connect all sites together without isp, we might lease some dark fiber
Sunday, June 28, 2020
Rack space
In an ideal world, where money is no option, you decide to build a new lab and fill 3 racks. What devices do you put in your ideal rack space and why?
Http website to download files
Hi,
I'm searching for a http website to download files from to test content filtering since we are not using SSL decryption. I need to block exe, zip, etc files using SRX content filtering. Can somebody recommend a website.
Windows update out locally on a full tunnel?
Hey everyone,
I've got requirements that conflict against our capacities.
Oh the one hand, I've got regulatory requirements for full tunnels, always-on VPN, consistent patch remediation, and FIPS-validated crypto.
On the other, I've got 1500 WFH users who are actually in the habit of shutting down at night.
Which means their windows updates like to saturate my internets during business hours.
How can I make this work and still comply? FIPS-validated means I'm cornered into FortiOS 5.6. Can I poke MS servers out locally and still be in compliance and save some of my bandwidth? Could that even be done in 5.6?
802.1x/PEAP-MSCHAPv2 question: iOS 13.5 sending inner EAP username as outer identity?
I'm working in a lab on setting up EAP-MSCHAPv2 to authenticate Wi-Fi clients with FreeRADIUS 3.0. I've gotten it "mostly working," except that I'm trying to prevent the clients from exposing the inner identity during the outer EAP setup.
For most of my testing, I'm using Apple Configurator 2 to push a profile to an iPad that has a client cert+key and the CA cert for the server identity. The profile is set to WPA2 Enterprise and PEAP only. The outer identity is specified in the profile as "anonymous" but I can confirm in the FreeRADIUS logs and the AP logs that when the client attempts its first outer request, it is sending the inner identity username instead.
Has anyone run into this? I understand there was a bug in a much older version of iOS where they sent some 802.1x responses outside of the EAP tunnel once it was established, but Apple has long since fixed that bug years ago from what I've read.
OpenFlow Experimenter: Experimenter ID
Hi guys,
This is a pretty niche question that I couldn’t find an answer to online. Hoping someone here can share their expertise. For my SDN related masters thesis to work I need to make a substantial number of extensions to the southbound api protocol OpenFlow. These extensions are necessary to define new messages, actions etc sent between the controller and switches. In the OpenFlow documentation an “Experimenter ID” is needed which is either a vendors IEEE OUI or assigned by the ONF. As an MSc student I do not have a valid IEEE OUI to generate this ID from and am yet to receive a response from the ONF regarding assignment of my own ID. Would use of an “unofficial” Experimenter ID that I choose myself work or will a bad Experimenter error always be thrown? Should I try different ID’s until one works or is it better to cut my losses and change the focus of my masters? I need to find out if a work around is possible so I do not waste any more time on this. Thank you for any responses.
Where could I find VPN setup guides/simulators?
Hi, I am currently a lvl 1 tech support. I am looking to expand my networking skills. More specifically in VPN setups.
Could you guys recommend any study/guide materials. For VPN setups. Most of the devices we deal with in regards to setup of VPN are cisco devices so any Cisco CLI guides to setup a VPN would be awesome.
I have read about using packet tracer to try and simulate an environment is this a good way to learn to do this?
Cisco 1117-4p GB WAN
Not a a Cisco expert, so sorry for basic question
I have 2 ISPs that I use, ISP 1 is a 1gb circuit connected via a Cisco 1117-4p, engineer from ISP 2 has been to site today saying ISP 1 have mis sold us the 1117-4p as its not sized for a gb circuit.
I cannot find any throughput sizing for just L3 routing for this device, it does nothing else.
gNMI service map
Hi networkers,
Lately I’ve been involved in project that required quite a deep understanding of OpenConfig gRPC Network Management Interface (gNMI). Going over the gNMI specification multiple times made me realize that I can’t fully build a mental map of all the messages and encapsulations without having a visual representation of it. So I’ve made one - https://github.com/hellt/gnmi-map
Just wanted to share, maybe it will save quite some time for you getting through the deeply nested structures of the service.
Saturday, June 27, 2020
Cisco CML2 lab for ISE
Hello All,
I really want to learn how to use ISE since eventually we might get this solution at my work. If I wanted to lab this at home on CML2, how would I go about doing this?
I use CML2 with VMware Fusion.
So I went to Cisco software download and grabbed the ISE 2.7 trial ova file so I can put it onto a server. At this point I'm lost on how I can boot this image up in my CML2 lab so I can network it in my lab and start connecting switches to it. Would I need to start 2 different Virtual machines in VM ware fusion and somehow bridge the NICs so they can see eachother on the same network.
I'm not able to find much documentation on this, so if someone could point me in the right direction, I would really appreciate it. Thanks in advance