Sunday, February 28, 2021

Question: Switches Cisco vs HPE

I am in the process of upgrading our branch office with new infrastructure and am looking to replace the current HPE switches (1620 48 port, 1920s 24 Port POE). I am looking at going to just 2 48 port POE.

I am looking at upgrading to either newer HPE or moving to Cisco (for familiarity as our controls team uses Cisco based Allen Bradley devices and they ask me questions quite often).

My few questions are:

1) What's a comparable model of Cisco and what are some considerations that I may not have insight on?

2) I am thinking going 2 48 port POE as I stated - Whats the incentive to go non POE if any? Is there any real reason to go non POE anymore?

Current we have 3 simple vlan for our main, wifi, and engineering devices. There are just a few ports on each switch tagged for these. If I move to Cisco how easy is the creation of these vlans from the GUI as I'm not familiar with their CLI at this point?

Thanks



Telephone and Cat5 pin comparison

i know the cables are different, i also know there are more strands in Cat5 than in telephone cabling. but i want to replace all telephone cabling to cat5 so when the eventual new owners of the building that i am renovating decide why they want, they can either continue using POTS, or they have the option of connecting smart gadgets and repeaters with little extra work.

so i am looking for what pins go where from telephones to the cat5 wire so i can get it right.



VyOS 1.3-rc1 released

The VyOS team has been very active, and they just released the first release candidate for version 1.3.

I have been running 1.2.x in production for many years, and seeing the pace of development on 1.3 is very exciting. Version 1.3 has loads of bug fixes, more features and a lot of the code has been rewritten to python. This will make VyOS usable with an API, and even more enterprise ready.

So, I just want to bring some attention to the project, and hopefully more people can join in and contribute/test!

Read more on their blog and direct link to the new images.



Stuck in Rommon mode!

Hey guys so after trying everything I know, I'm coming here to get some help

I have a 1921 router and it was working just fine, by mistake I formatted the USBFLASH0: (I thought it was the usb driver that I inserted) but not it was the actual flash of the router

so now I'm stuck in rommon mode and I have a good image but no solution yet, I try to boot from USBFLASH1: and I got this message

rommon 12 > dir usbflash1:

program load complete, entry point: 0x80903000, size: 0x4c4a0

Directory of usbflash1:

5 68923232 -rw- c1900-universalk9-mz.SPA.152-4.M5.bin

134622 8959 -rw- 1921 config.txt

134640 1500 -rw- config.txt

rommon 13 > boot c1900-universalk9-mz.SPA.152-4.M5.bin

program load complete, entry point: 0x80903000, size: 0x4c4a0

an alternate boot helper program is not specified

(monitor variable "BOOTLDR" is not set)

and unable to determine first file in bootflash

loadprog: error - on file open

boot: cannot load "c1900-universalk9-mz.SPA.152-4.M5.bin"

---------------------

any help would be more than welcome



Aruba-OSX Help

We are replacing all of our current Aruba networking equipment (aruba 2930) with the new aruba 6200f and for our core switches from 5400z to 6400 series.

So far I have not had any issues replacing the switches. I am now to a point where the main switch in the IDF cabinet that connects back to the 5400z series switch will not work.

The current Aruba 2930f switch connects back to the 5400z with a vlan 900 untagged port. I tried to replicate this scenario on the 6200f but i can't ping the ip address i assigned to the int vlan 30. That did not work. Now in each IDF cabinet there are additional switches. They all uses trunk ports to connect back to the IDFXsw1. I was able to configure them and connect back to the idfsw1 switch with no issues. I am solely having issues getting the main switch in the IDF cabinet to connect back to the 5400 series switch. I believe it's the way the vlan 900 is setup and the untagged port on each side. On the MDF switch all the vlans have the ports that connect to the IDF switches tagged. What do I need to do to get the 6200 series switch to work in this scenario?

idf1sw1 - aruba 2930


interface 16

name "WIALPAP3"

exit

interface 17

name "WIALPAP4"

exit

interface 18

name "WIALPAP5"

exit

interface 19

name "WIALPAP6"

exit

interface 20

name "WIALPAP7"

exit

interface 23

name "WIALPMDF1SW1-D24"

exit

interface 24

name "WIALPMDF1SW2-D24"

exit

vlan 1

name "OLD_Data"

exit

vlan 5

name "Client"

untagged 1-15

tagged 16-20,23-24

vlan 30

name "Prod_Manage-VL30"

tagged 23-24

ip address 10.10.30.35 255.255.255.0

exit

vlan 31

name "WiFi_Manage-VL31"

untagged 16-20

tagged 23-24

no ip address

exit

vlan 900

name "InterSwitch-VL900"

untagged 14,23-24

no ip address

exit


aruba 6200f


vlan 1

vlan 5

name Client 

vlan 30

name Prod_Manage 

vlan 31

name WiFi_Manage 

vlan 900

name Interswitch 

int 1/1/1-1/1/40

no shutdown

vlan access 5

int 1/1/52

vlan access 900

int vlan 30

ip address 10.10.30.8/24



How do I make it so a user can only access certain network devices rather than every device on the network through Cisco ISE?

Not talking about access list. For example there's a switch on the network that I want someone to be able to access so they can change configs remotely, but I don't want them to be authorized on any other device.

I can see how I can I can assign nodes to groups, but I start getting a bit lost when it comes to how to set up policies and how to give a user or user group access to node groups, if that makes sense. I messed around with it a bit but couldn't figure it out.



Configuring network so all VLANs can ping on OSPF

Configure the network so that all Vlans can ping each other. FTP server should be accessible only from the support Vlan. All three routers could only be be telnetted from the support Vlan. Routing on the network is OSPF."

Thank you guys. Ive been trying for hours.



Would you buy a router or modem from craigslist?

Just the title. Any thoughts?



Saturday, February 27, 2021

Multiple Firewalls at the edge of the network?

Hey Guys,

We have a small business of a few hundred people, they are protected with a Sonicwall 4600 series firewall.

Our ISP has given us about 15 static public IPs to use its fiber 1 gig service.

We have a very specific workflow and we need to add a Palo Alto to our network for performance improvements.

I know that our ISP has a juniper switch installed and then a device with about 5 Ethernet ports and a few SFPs.

I’m wondering if it would be possible to have both a sonicwall and a Palo Alto at the edge of each of their respective networks?

The idea would be to use a separate static IP for the Palo Alto and just install it side by side next to the sonicwall. Then go directly to the ISP device. That way the Palo Alto doesn’t have to sit behind the sonicwall.

I want to put a select few computers behind the Palo Alto because it has better performance. I don’t want to put the Palo Alto behind the sonicwall because I need real time Site to site video playback. The Palo alto handles this type of real time playback better than the sonicwall.

We dont have the budget to replace the sonicwall with an adequate size Palo Alto. So we just want to use a mini Palo Alto side by side next to the sonicwall.

Is my idea possible?



Is Starlink a WISP Killer?

I have a close friend who's thinking about working a Networking job for a mid tier WISP. He has a few other offers on the table. I've advised him that WiSPs are direct competitors to Starlink and will likely go the way of the horse and buggy over the next 12-36 months. He's on the fence, but it's a tantalizing offer. Obviously he doesn't want to get a start headed down a dead end road.

So what do y'all think? Is Starlink going to get rid of WISPs? It seems like they plan competing within the same market. Also, is Starlink a threat to traditional ISPs like Spectrum or Charter?