Monday, February 22, 2021

Meta: Would you be interested in someone opening a r/NetworkingRelaxed subreddit?

Hello, I am just wondering if you would be interested in someone creating a r/networkingrelaxed sub?

Personally I like this sub, but sometimes the rules here are just too tight for what I want. There is also r/networkingmemes but that doesn't allow for text posts and is mostly memes anyways.

What I would most like to do on such a sub is talk about weird stories that have happened in my noc life(#noclife), PoPs in both literal and figurative barns, 'interesting' client stories, interesting places I visited and stuff I did related to networking, the 'politics' of working at an ISP, etc...



DHCP Scope Organization

Hello,

I have a question regarding DHCP reservation for Network Appliances and Servers. Let's say I picked a subnet of 10.100.0.0 and Mask of 255.255.254.0. Is it okay to set the Server as 10.100.0.10 and then all the network appliances from 10.100.0.1-9? /Or would it be better to reserve 10.100.0.2 for the server?



CISCO PT Switch ACL not working

I am attempting to configure an ACL on my CISCO 2960 switch in packet tracer. I am following the guidance from CISCOs website. However, I keep getting the error below:

https://imgur.com/a/gmBM3fX

I would be very grateful if anyone could offer some suggestions as to why this might be happening or ways around it.

Thanks in advanced!



Why would I receive dozens of RST/ACK packets without any other packets in the normal TCP handshake?

Over the span of a few days I have noticed dozens of RST/ACK packets all originating from different IP addresses and directed towards all different IP addresses on my network. There were no initial requests by my network to these unknown IP addresses. They are all coming from, and going to what seem like completely random ports (not just ephemeral though, a mixture of low/high source ports and low/high destination ports).

Is there some sort RST/ACK attack or scanning technique going on here? I'm not sure about scanning since I don't believe an IP address would respond to a random RST/ACK but I could be wrong. Googling it hasn't been helpful so I'm interested in any additional insight someone on here might be able to provide.



Visio mass select question

I’m trying to find a way to select all instances of a certain word (i.e. AIR-CAP2802l) in order to change the font color. It’s so time consuming to go through a Visio for a massive site and highlight every instance of the word manually. We use Visio 2016 professional.



Configuring VPN between a very old PIX and an ASA

Hi all! My company acquired another small company which currently has a very old PIX. I need to configure a temporary VPN connection between one of our ASA's and the PIX. I have the VPN in place but am not seeing any traffic from the PIX to our ASA. I do see traffic to the PIX.

I think it is an issue with the nat rule but, due to the age, the syntax is different.

I need to have traffic from the 'VOIP' interface on the PIX route to the 'inside' interface on the ASA.

Any help is greatly appreciated!

ASA

(inside) 10.10.12.1

PIX

(VOIP) 192.168.1.1

PIX NAT Statement:

access-list ASA-PIX-ACL extended permit ip VOIP_LAN 255.255.255.0 10.10.12.0 255.255.255.0 nat (VOIP) 0 access-list ASA-PIX-ACL 


Multi WAN combined (not only load balancing)

Hey guys,

If I would want to use a normal internet (DSL) Connection and combine it with a LTE connection to get the combined upload and download speeds. How would I do that?

The idea was to use two servers. One in my own network with both Ethernet connections attached and one rent by a online provider with a better bandwidth. Then use both Ethernet connections to Transfer everything between these servers. Something like a VPN over two wan connections.

I hope you get the idea? How would you do that? (If it's possible) and if not, how could it be done. The goal is to use multiple Ethernet connections to combine upload and download speeds.

Greetings from Germany :)

P.S. i asked that already in r/sysadmin Here



Working on getting a UDM Pro to Site to Site VPN a /32 Address

I followed this guide:

https://www.reddit.com/r/Ubiquiti/comments/ksrbra/how_to_set_up_sitetosite_with_32_subnet_with/

Basically, we are trying to setup a temporary site to site VPN so one user can work with the emr vendor to build out the cloud based version of the emr software, once that is completed the site to site VPN is no longer needed.

Unifi uses swanctl to do ipsec VPNS, but does not allow you to create a remote subnet above a /30. The EMR Vendor has a few /32 subnets. I tried transitioning them to /24, which will not create a tunnel. I have also tried manually configuring the static routes for each subnet, which also does not work.

Using the above guide, I was able to get a tunnel established, but it does not appear to be routing traffic. I have asked for some logs on their end, but they are very slow to respond.

As far as I can tell, it is setup exactly like my two other working VPNS, so I am unsure where the issue could be.

What I did was create a Site to Site for each subnet, as it will only read the 1st route in the config file, and manually edit the files for the tunnels with the correct information using winscp. Then I restarted ipsec to establish the links.

It also doesn't help that icmp request are blocked, so I only have a URL to test through google chrome.



Do you log known blocked traffic?

Afternoon oh wise ones

Wondering whats peoples opinions on this cause I'm beginning to lean towards no.

Background wise, I'm on a network cleanup since there's been a a huge amount of change over the last couple of years with all the focus being on next new project instead of proper configuration and monitoring of the everything that's just been put in (basically the get it works and deal with the rest never attitude).

As a result, the amount of traffic being blocked at the firewall generated by every application, OS, IoT device etc trying to dial home/get updates/god knows what else is making a proper baseline really difficult.

I've started going through it all to see what exactly is causing it all and will hopefully be able to solve the majority at the application level but stuff I can't (or the owner wont) I'm leaning towards an explicit block rule with logging disabled so we can focus on actual new behaviors.

How do you all approach this?



Do you log known blocked traffic?

Afternoon oh wise ones

Wondering whats peoples opinions on this cause I'm beginning to lean towards no.

Background wise, I'm on a network cleanup since there's been a a huge amount of change over the last couple of years with all the focus being on next new project instead of proper configuration and monitoring of the everything that's just been put in (basically the get it works and deal with the rest never attitude).

As a result, the amount of traffic being blocked at the firewall generated by every application, OS, IoT device etc trying to dial home/get updates/god knows what else is making a proper baseline really difficult.

I've started going through it all to see what exactly is causing it all and will hopefully be able to solve the majority at the application level but stuff I can't (or the owner wont) I'm leaning towards an explicit block rule with logging disabled so we can focus on actual new behaviors.

How do you all approach this?