Monday, March 29, 2021

iBGP between locations using private link (fiber) which is used for internal vlans

Hi Guys,

I have currently two data centers inter-connected with dark fiber. Only one of them has ISP uplinks ( two separate BGP routers - each multihomed with 2 ISPs - we have AS and PI). Apart from 2 eBGP each router has iBGP between them and OSPF to propagate loopback routes and VRRP for redundancy from LAN side. LAN side has a default to VRRP VIP configured on Fortigate cluster in active-stanby mode.

As it comes to physical connections in DC1 both BGP routers have directly connected ISPs and behind them I have dedicated L2 switches to connect to Fortigate cluster.

I need to move one BGP router with one ISP to another location DC2 that is connected with private fiber with DC1. I want to move one Fortigate from the cluster as well. The problem is that I have only one core switch within DC2 which terminates this private link and we use this for internal vlans. I will have to connect BGP router and FW to that switch in DC2.

Now the question arises - I have several mainly safety concerns:

  • Is it safe to put iBGP vlan over the same L2 switch (physically the same aggregated link) between DC1 and DC2? I have only one private aggregated link.
  • What about traffic to FW from DC2 - I assume that only one Fortigate would be active (in DC1) and some traffic from BGP router in DC2 (even if not prefered) would also go to FW in DC1 over the same physical ports within aggregated link?


Measure Latency, Jitter, and Throughput Between Firewalls.

I'm doing some testing with various encryption algorithms, and I want to measure the latency, jitter, throughput by different encryption algorithms in a VPN.

I need an application, that can measure these stats and produce outputs in any standard format.



Question about ARP and NAT.

I spent so much time trying to find the answer. I hope I am forgiven if this is a fairly simple question.

If devices communicate on an internal LAN using Layer 2 (Data Link layer with MAC addresses) then how does NAT play into this equation? If our devices on an internal network are communicating using MAC addresses. Then why does each device need it's own internal private IP address using NAT?



Sunday, March 28, 2021

Port History?

Is it possible to find the history of when certain ports were closed and by whom? I’ve been tracing back why all my security cameras have gone down and everything points back to my ISP shutting down the ports used by the cameras for some reason. Just trying to see if I can find anything else on it before I call them up tomorrow.



Do you believe the pendulum will swing back?

Over the course of my time in IT (6 years now) I've seen how the industry has been trending away from insourcing to outsourcing, from centralized architectures to distributed architectures (i.e. CLOS, HCI), from on-prem to offsite, from private to public, from combined to separate data/control planes. I also have realized - from talking to old-timers - that technology and management trends tend to be cyclical. With that in mind - I'm curious to know if you think the trends we're seeing are here to stay, or if you believe the industry will course correct and start swinging in the opposite direction?

Sidenote: If you do think the pendulum will swing in the opposite direction, is it already starting to? Where do you think we are in this "cycle"?



Are Cisco 3750G compatible with SFP Optone or not?

I had installed Cisco 3750G and i had problem when i made interconnecting with Ubiquiti Edge Switch 24port Gigabit PoE - 250W using sfp optone SFP WDM SM 0220A and SFP WDM SM 0220B. Ubiquiti Edge Switch 24port Gigabit PoE - 250W can detecting sfp optone but Cisco 3750G cannot detect sfp optone at all and indicator lamp is down.

Please help me.



CWDM Issue.

I am hoping to get some extra suggestions on troubleshooting an strange CWDM issue.

Okay we recently had to move our uplink, and after the migration, we have noticed that one of our wavelengths in the 1510-1590 range that is having massive signal loss, we are seeing -37dbm or lower for a single wavelength. Prior to the migration there was a loopback installed on the Demarc for the provider who saw an expected signal across the complete range. This leads me to believe that the carrier side is alright. Once the CWDM was placed on this new link we lost the wavelength.

Things that were tested.

  • Swapped the fiber for the problematic wavelength.
  • Swapped Optical modules.
  • Swapped ports.
  • Installed a Loopback on the problematic wavelength.
  • Fiber cleaned.

Things I feel that might be an issue are possibly the CWDM, fiber attenutation.

Can anyone else, come with a suggestion.

I am sorry, I can't be more specific in information.



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.



Need some clarification on NAT?

The definitions are very convoluted and I THINK I have a decent grasp on what these all mean, can someone verify that my understanding is correct? Or if i'm totally off pleaseeee let me know lol

Inside global: The PUBLIC IP address as seen by other networks (if you're the host that is translating to a destination network - it would be the IP associated with your networks router?)

Inside local: The PRIVATE IP ADDRESS as seen by others on the network you're translating from (it's your PRIVATE IP address, but to other networks it is a public IP?)

Outside local: The PUBLIC IP address as seen by the network that is translating to this one (this is a HOST IP address?, meaning the opposite of inside local - a private IP to that host but it is PUBLIC to other networks)

Outside global: The PUBLIC IP address of the network you're translating to (This is the destination networks router?)

So in summary?

Inside global - Public IP - the router of the source network

Inside local - Private IP - the host that is sending the packet

Outside local - Public IP - the host that is receiving the packet

Outside global - Public IP - the router of the destination network

Sorry if this is a mess of a post. I'm trying to get this concept down before I sit for CCNA



Mobile hotspot 4g

Speedtesting my mobile's 4g speed shows a ping that ranges between 15-20. However when I connect my laptop to my phone's hotspot and do a speedtest, the ping goes up to 40-50. Both devices are next to each other.

What can i do to reduce ping on my pc?

thanks!