Monday, May 31, 2021

Multicast Question - Does a router always need to be present to handle Multicast traffic?

I'm trying to learn about multicast protocol and all the material I can find alludes to IGMP running at the router level. My confusion is, multicast groups have a unique MAC address, derived from the IP range that's a part of the group.

With the above in mind, for a local network (e.g., all devices on a single switch and on the same VLAN) does the Router need to be involved? Can't the switch itself run IGMP and use the Layer 2 MAC address to forward multicast packets to appropriate recipients?



Is there a place to download complete bgp peering data for ASNs?

Is there a place to download complete bgp peering data for ASNs updated daily?



Workaround to CIDR overlap using site-vpn between AWS and Cisco Meraki on DX?

We are trying to setup a site-to-site VPN from AWS to customer Data center running Cisco Meraki Gateway. This shouldn't be much of hassle setting up and getting the tunnels up, however the issue is we are both on overlapping subnet CIDR.

The problem is that AWS transit gateway/site-vpn setup doesn't allow SNAT/DNAT and in this case the customer gateway (Meraki) also doesn't support SNAT/DNAT as a workaround.

I looked up setting up Openswan to SNAT/DNAT but the https://aws.amazon.com/articles/connecting-cisco-asa-to-vpc-ec2-instance-ipsec/ mentions setting up NAT on the destination side as well.

What are the some of the workarounds I can do to get this tunnels up and running?



A subnet with two gateways.

I have some problems understanding a subnet with two gateways.

Let say we have a subnet 192.168.31.0/24. There is a computer (192.168.31.2), two gateways: a router port (192.168.31.1), anoter pc running gateway service (192.168.31.3) (in fact, I don't know what is a gateway service, does it like a http service? you also need a port and ip address to access it?).

When the computer access internet, the packet go to 192.168.31.3, then go to 192.168.31.1. So far, I have no problem.

What will happen when a packet come from internet to 192.168.31.2. Let's say I have a webserver running on 192.168.31.2:80. Please give me as more details as possible.

If 192.168.31.2 is connected to a switch then to a router. How the packet get to it?



Are bluecoat-like proxy devices becoming obsolete?

I work for an MSP, we do f5, palo alto, broadcom(symantec(bluecoat))) (lol) proxy stuff.

I have it on my career path /review plan thing to get the bluecoat proxy certifications.

So a conversation I once had came to my mind, about how most firewalls can URL filtering with just a simple license and how with unlimited bandwidth and cloud, proxy solutions are going to be history soon.

It made sense to me but I'm not so sure about it! Do you guys still use proxy solutions at your work?

Should I even get the cert or just go back to my boss and maybe talk about getting a Proofpoint email gateway cert or some cloud cert?



MAC Authentication Roles in Aruba Controller

Hello all, I am new here and don't know where should I post.

I have Aruba controller 7210 and I want enable MAC Authentication on one SSID. I enabled it and created role named "Deny_MAC-Auth" that is deny all and selected it as default role. then I selected the "Services" role as MAC Authentication role.

I added my clients to the internal database of the controller and selected "Services" as their roles.

when I trying to connect from my client, it can't get IP address.

Can anyone tell me what is the best roles should I choose to work well?



Question about Asynchronous transmission.

Hi, firstly id just like to say if this type of question is not allowed, please let me know and ill be happy to delete. Im just not sure where else to ask for help.

Im a first year student and im supposed to show the sequence of start, data and stop bits generated during an asynchronous transmission of the of a character string.

For example the letter L, ive said Start bit: 0

ASCII: 1001100

even parity: 1

Stop bit: 1

Is this correct or have i missed the mark here?



Computer network-Data link layer question

"If the average packet is broken up into say 10 frames and 20% of those frames are lost, it may take a very long time for the packets to get through. If individual frames are acknowledged and retransmitted, entire packets get through much faster"

I am trying to decode what is this text trying to say-:

1) We have 10 frames.

2) 20% of those frames are lost. i.e 2 frames are lost.

3) Entire packet takes long time to get through. WHY? (Is it because it has to retransmit the whole packet again)

In another case, 1) We acknowledge each frame and retransmit it.

2) Entire packets get through much faster. HOW?? (Is it because single frame goes faster than whole packet)?



Sunday, May 30, 2021

Firewall clustering across data center.

Hey,

I'm currently reviewing a vendor's design which includes single Fortigate firewalls clustered across multiple datacenters. Experience has taught me that this is a bad idea. In my engineering days, I saw entire stacks break due to:

  • DDOS filling up synced session tables
  • Software bugs and failed in-service software updates
  • Cut heartbeat connection resulting in split brain
  • Human error - an engineer shutting down a cluster by accident thinking it was a lab.

In my eyes, clustering of single firewalls no longer fulfils my requirement for redundancy since there is only 1 logical firewall across our data centers.

I've always thought this to be against best practice and I know the vendor will be asking for evidence of this. Does anyone have references to any vendor best practice, handbooks, whitepapers etc that covers this topic? Googling has brought up many forum discussions around this but nothing "official".

Thanks



I am a n00b will this OSPF design work in this network I'm building?

In addition to the OSPF 100 areas you see here, each LAN will be running OSPF 1 area 0 locally. Will this work or are there issues with this? Topology ----> https://imgur.com/YHrGo2b