We are in the early planning stages of upgrading our AP infrastructure (around 400 APs in the environment). We are currently an Aruba shop and I generally like their hardware, but Aruba central can be a bit of a mess. What vendors/solutions should we be looking at to replace Aruba?
Monday, March 29, 2021
IP Geolocation issue
Hello,
I am a junior Network Analyst for an ISP in Canada/Quebec and a few of our customers can’t access certain websites because of a geolocalisation issue. For example, customer A can’t access a certain Canadian website because the website thinks he’s in the US, customer B can’t access his company Microsoft Teams...
The IP block my company uses for customers is correctly registered with ARIN, but some IPs shows up in the US on some geo IPs web databases. I am not sure how to solve that issue. Any kind of tip/advice is welcomed. thank you in advance
Edit I've already contacted the providers on this list https://thebrotherswisp.com/
When I have a remote client connected to my Juniper firewall VPN they lose Outlook / Internet access
Hi,
I have an remote VPN client service setup on a Juniper.
I trying to set up a split tunnel service on Window 10 machine so that:
Internet Traffic is sent outside VPN (for speed)
Certain Local IP is sent through the VPN tunnel
My question is : I've tried setting some static routes to force the traffic through the VPN tunnel. But no luck. is it possible routes to force the Internet / Outlook traffic outside VPN client without split-tunnel config on juniper ?
VPN defaut route like below on Windows 10 computer :
IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.136 25 0.0.0.0 0.0.0.0 172.16.10.0 192.168.1.136 280 0.0.0.0 0.0.0.0 on-link 10.186.100.10 1 (vpn ip address)
Thanks,
Using vlans into no managed switch
Hello,
Can we activate vlan on a not managable switch? If for exemple i have switch layer 3 and i have vlan student and vlan administration, can i make a not managable switch work with the vlan student only?
Thank you in advance for your reply.
Being overruled by leadership because of "familiarity" -- A rant
Just wanted to let this off my chest. This is not so much meant as a flame war between Cisco and Aruba. I think they're both are great.
I work for a small-medium sized college. We're in the process of upgrading our switches (under 200) and we're down to 2, Aruba and Cisco since we have both already in some shape or form. I made the presentation w/ quotes and pros and cons. Got quotes for 92-9300s for C and 2930+6300s for A. As some of you may guess, C's quote was significantly more!
I was surprised to find out that our leadership is leaning more towards C, mainly because we're also doing E911/CER and since they believe it'll be an easier transition/familiarity. Mind you there's basically 1 other person who works with me on networks. He happens to do the phones.
For one, our phone vlan scheme would have to be gutted regardless since it was created over a decade ago. Vlans are stretched between buildings and floors. Plus, there's no location info in any of them. I'm not a voip guy but from what i understand, going with C will allow port tracking capabilities for phones which i guess will help w/ overhead when someone moves locations. With 'A' tracking would have to be done via (new) subnets.
Going back to cost, we already pay up the nose w/ smartnet, licenses, etc. We also have several projects (such as e911) that would be funded if we choose A. Some of you in the public sector may have gotten some CARES act money. This is basically how we're affording all this. Being a small college we've gone thru our share of downsizing. We've also done our share of really dumb moves over the years.
I'm just frustrated. It's like you're trying to help but people are putting 'ease' over everything. Speaking of ease, I'm the one who will be using it! I know it's not my money to save but i've been there long enough to know that we'll have our lean years and that means cuts to budgets or worse, jobs.
/rant
Cisco WLC 3504 SSID Issue on legacy Devices
I have a WLC 3504 (v8.10.130.0) with AP's (C9115AXE-B) and they work great for newer devices but I have some old legacy Motorola Omnii XT PDA's (Windows CE) that I need to use for a project and they all show "__" as the SSID when trying to connect to these AP's. I have a clerical issue that is delaying my TAC case so in the interim I am lookin elsewhere for solutions. I even created a wide open SSID with a forced b/g only radio policy with the same results. Any ideas?
Setting up a anyconnect with certificate authentication
hey,
After days of struggling i still can't find any solutions to my problem.
We have several ASA and one of them is about to be decomissioned so i pulled its conf and put it into another new ASA that will exclusively be configured for VPNs.
At first we decided to use LDAP authentication but after all the fact that the AD users credential are free on the internet (still encrypted) we changed to a cert authentication.
And here is my problem i pulled the old certificate from the previous ASA this certificate isn't outdated and still up for 1 year i installed it both in the machine and in the Identity certificates of the ASA.
The cert is associated with a single trustpoint so far and whenever i try to log it throught the anyconnect client i instantly get a certificate validation failure.
Logs from anyconnect only show : No valid certificates available for authentication.
and logs from asdm :
6 Mar 29 2021 17:01:57 Device selects trust-point ASDM_TrustPoint4 for client WAN:10.x.x.x/19305 to 10.x.x.x/443
6 Mar 29 2021 17:01:58 10.x.x.x 19305 Device completed SSL handshake with client WAN:10.x.x.x/19305 to 10.x.x.x/443 for TLSv1.2 session
Note that any other way of authentication works ldap or regular local AAA
also the p12 file is imported in the workstation aswell.
Sorrento Networks Gigamux documentation/manuals
Hey all, I got some Sorrento Gigamux 3234 Chassis to manage. Unfortunalety i cannot just pull out the power plug and move to a newer plattform. And the worst is that there is no documentation at all about that dwdm plattform.
I got 4 GM 3234 with MPM2 management cards OCM10GF OCM2 OET MD100-40 8GFC
Sorrento Networks has no public documentation and it seems like that the contact form is dead.
Any guess where i can get some information about them? Does someone has some documentation for it?
How to change my IP so that my work VPN thinks I'm still in the US?
Hi everyone, I'm working for a fully remote company, and they're sticklers for employees being in the US. I'm actually a contractor and from a tax perspective there's no issue at all, I have LLCs open in both countries where I want to work and reside, I can pay the appropriate taxes in both, and have dual citizenship.
The issue is mainly the company procedures and guidelines which are pretty non sensical to me.
So, would it be possible to spoof my IP for the company VPN so that they think I'm still in the US?
If this sort of post isn't allowed pleased let me know, I read through the rules and didn't find any it would break.
Thanks!
iBGP between locations using private link (fiber) which is used for internal vlans
Hi Guys,
I have currently two data centers inter-connected with dark fiber. Only one of them has ISP uplinks ( two separate BGP routers - each multihomed with 2 ISPs - we have AS and PI). Apart from 2 eBGP each router has iBGP between them and OSPF to propagate loopback routes and VRRP for redundancy from LAN side. LAN side has a default to VRRP VIP configured on Fortigate cluster in active-stanby mode.
As it comes to physical connections in DC1 both BGP routers have directly connected ISPs and behind them I have dedicated L2 switches to connect to Fortigate cluster.
I need to move one BGP router with one ISP to another location DC2 that is connected with private fiber with DC1. I want to move one Fortigate from the cluster as well. The problem is that I have only one core switch within DC2 which terminates this private link and we use this for internal vlans. I will have to connect BGP router and FW to that switch in DC2.
Now the question arises - I have several mainly safety concerns:
- Is it safe to put iBGP vlan over the same L2 switch (physically the same aggregated link) between DC1 and DC2? I have only one private aggregated link.
- What about traffic to FW from DC2 - I assume that only one Fortigate would be active (in DC1) and some traffic from BGP router in DC2 (even if not prefered) would also go to FW in DC1 over the same physical ports within aggregated link?