Sunday, September 20, 2020

I still haven’t gotten the answer I’m looking for. Help?

So i have asking around and it seems everywhere people misunderstand me or cannot answer the question i have. My questions are: 1. Is it possible for me ( as a mobille network operator with an accompanying mobile phone application) to give my users access to said app and use it without any sort of internet connection, Wether cellular or wifi??

2. Depending on the answer to question 1, Is it possible to give the users access to my app even when they’re out of data but cellular is on?

Thanks, i hope you understand.



Best way to wirelessly extend WiFi coverage into backyard

I have small one story house. About 1500sq ft. I also have a shop about 80 ft away from the house.

I’m thinking to buy a 3 puck mesh system and place a puck at the window and another one at the shop window.

I’m currently looking at the TP-Link Deco M9 and they recommend to place the pucks no further than 50 feet away but since this would be open air (minus two panes of glass), do you think I can get away with 80 feet?

Any suggestions? I really want to avoid a long cable in the backyard.



Is there any way to see how my computer's packets move geographically?

Say I am in Dubai and play a game on a server which is in America, I would like to see what geographical path my data packets took to travel to NA from my home, for example.

It would be pretty cool to see.



White Paper for Network Installation/Upgrade Best Practices

Hello all! I'm currently working on a paper for school in which my fictional company is being hired to upgrade a fictional network. I'm trying to find a document that details what steps are necessary for a successful upgrade. I know them in my head (stage equipment, prepare an authorized service interruption, install, followup etc etc) but I need a reference to "qualify" my knowledge. A half hour of googling discovered physical installation guides and IOS upgrades, but nothing that would serve my interests.

If it matters, the proposed network utilizes Cisco devices. Thanks in advance for any help!



802.1X authentication: working in windows enviorment, but in linux?

Hi!

I've setup a freeradius server on a virtual machine in ubuntu enviorment, and i'm using a cisco SG350-10-K9 Switch. I've got 802.1x authentication working on 2 different PC:s in windows enviorment. But when i setup linux VM:s i those and try to use that i get to enter my password, then i have to reenter it a couple of times before it turns off the network interface.

I've check the logs in both the switch and in the server. The switch gets the requests and the server shows nothing.

So, is there a know issue that it doesn't work in Linux? (although i googled it and couldn't find anything) or do i have to do something special?



Is it possible to split the POE OUT of a POE+ injector to power 2 devices?

At my desk I have a 30W POE+ injector with a single POE OUT port that powers my Cisco IP phone with networking coming in from a non-POE switch. I just got a 5 port switch (Unifi Flex Mini) that can be powered via POE or USB-C. I dont have too many electrical outlets under my desk so will need to get an extension cable but it made me wonder if there was a Y cable out there that would allow me to split the POE OUT port of the injector so I could power both the phone and the switch? The injector itself would have plenty of juice to power both.



Cisco WLC/ISE radius authentication behavior

I was troubleshooting an issue with Cisco this past week involving an issue with the guest wireless solution we have which is Cisco based. We have the foreign controller in the data center along with the anchor in the internet DMZ. We also then have regional ISE clusters [two ISE nodes behind a load-balancer] which the WLC would use to determine if they entered the correct credentials.

As we are troubleshooting I saw a behavior that I had seen in the past which is that in ISE I can see these authentications coming in from ISE nodes around the globe. You would think that the WLC would stick with the primary radius server and NOT leave it unless it would go down. In order for the primary radius server to go down the load balancer would have to fail or both ISE nodes would have to fail in the local data center.

Why the hell is the WLC bothering with radius servers half way across the globe??? I posed this question to the Cisco engineer and they said "yeah unfortunately there's no way to force it to just one radius server...". So we had to sit there and run debugs waiting for the connection attempt to come through the nodes we were monitoring.

This seems a bit asinine to me honestly. There isn't a way to tell the WLC to ONLY use the local ISE nodes for radius and NOT the ones in Europe UNLESS the local one's go down hard?



Understanding computer networks by analogy

I'm writing a series of posts to help me and help some of my friends to understand a little bit better computer networks by using analogies.

I'm going to start with networks, subnets and devices but I want to expand to more topics like switches, routers, internet, SDN, etc.

What do you think? Do you have any feedback?

Part 1 Part 2



Why is my server attempting LDAP connections to another domain's DCs

Hey al,

Something that has kind of been plaguing me and I want to understand what specifically is going on. My network at work is separated from our corporate network. If this is of importance, we do have a one-way incoming trust with them. There is a firewall between our site and the corporate network.

I'm using our maintenance / patching server (Ivanti Security Controls, but udp/389 is not a requirement), which at the current moment is attempting to scan machines in the corporate network that we still maintain. While investigating things, I do see that there are numerous requests on UDP/389 going to various domain controllers in the corporate environment..

  • What is happening that this server is attempting to reach out to various domain controllers?
  • If this connectivity is required, is it possible to limit which domain controllers that this specific machine will attempt to access udp/389?

Thanks for helping me learn. :)



Saturday, September 19, 2020

Easy Subnetting question

How many subnets can I create with four masked bits on a Class C address?. It's 16 right?