Tuesday, June 1, 2021

Network design for new servers and switches. Design check and advice

Hi All, I've recently undertaken a project from an old IT system Admin in the company I work for with a few issues.

The main issue is that the guy i have taken over from as passed away taking with him a LOT of core system passwords as he setup a lot of these and did not write/document them or he did in an encrypted files that is basically useless to me.

I created a Rack diagram that's basic and is my rough idea of the layout so if you guys need an imager link or that kind i can provide that

Now I currently have 3 new servers on the way

2 x R440

1 x R540 - planning to run TrueNas - open to suggestions

3x power switchN2248X-ON

The Switches will be stacked connected via 40GBps uplinks.

each server will have dual SPF+ connections, 4 Gigabit NIC's and IDRAC enterprise

I plan to have four networks all class C ( 192.168.10.x, 192.168.15.x 192.168.20.x 192.168.200.x)

I plan to run ESXi on the servers however my CEO with the last System Admin preferred Hyper-V s i dislike the idea of a windows system running core of servers for their need to need to shutdown on the slightest update

1) are there other options besides EXSi//Hyper-V for enterprise? (ProxMox)?

2) these servers will be supporting around 200 users, is there any suggestions on the virtual setup of servers as currently i plan to have 2 VM's to run just DC's and authentication, 1 VM to run "Utilities" server for DNS, WSUS and the likes. Due to wireless access a Unifi controller must also be run on the servers

3) Management tools is another big area i am not so familiar with as I have really only assume this role for this project. Can anyone suggest management tools. We have used Spiceworks in the past However it has been buggy with AD authentication and the likes in the past and i would like to move away from it if possible can so any suggestions would be greatly appreciated

4) as for the router it is a FortiGate 60F with 4 LAN ports and 3 ISP/WAN ports and 1 DMZ that is currently unused

my question is does this topology currently sound like it will work fine as I have no one in my organisation to currently communicate this this off with the passing of my fellow IT member.

Any advice or suggestions would be great. Ive been doing networking for about 2 years now but its very different when you have to call the finial shots so thanks for any replies in advanced :D



Downstream switches not learning VRRP mac addresses for certain VLAN's

Hi,

We are having a fairly strange issue, it could be a very simple resolution but I can't seem to figure it out, just looking for some idea's to check that we might not have thought of.

We use pfsense as our main router, we have a Dell N4046F stack as our core, and multiple various Dell Edge switches hanging off them.

For some odd reason, the core and the first edge switches work correctly in that they learn the MAC of the VRRP for the specific VLAN. The problem is that switches below that don't, but only for certain VLAN's.

Because the switch doesn't learn the MAC, it spams the traffic out on all ports on that vlan and the trunk too. The next switch up, works correctly.

Any ideas?



Mass change password in switches - cisco, edgecore

Hello,
we have about 300 switches in our network. Cisco and edgecore. We need to change login to every device.

Any working solution for this? Will be thankful for working script maybe.

Thank you



What are some good python for network engineer courses, besides Kirk Byers?

Just want to see what other options are out there for training. My work pays for me to do training every year, so I think I am going to really focus on learning python. Just want to see what other reputable classes there are to take for beginners with no python experience. Not worried about price at all, there is really no limit on that.

I have taken boot camps in the past through global knowledge, infosec institute, and others, so was leaning towards something like that. I was considering looking into a course on the CCNP ENAUTO, but wasnt sure how deep that actually dives into python itself.



Cisco WLC - Inter-Controller Layer 3 Roaming

I have personally never set this up but am trying to solve a design issue.

Is it possible to use Layer 3 roaming to have a Guest Network SSID: GUEST on WLC1 and it's associated VLAN 100 on our downtown core switches.

I have a remote site that I really don't want to stretch VLAN100 across via layer 2 (but I do have that option). At the remote site with WLC2, how do I properly create the SSID and a VLAN so that it 'forwards' all that traffic to WLC1.

Is that just natively how it works? Is there a setting to mark one SSID/Interface the Anchor on WLC1 and then mark another one the 'foreign'. My hope is that when a user is at the remote site, and they try to join the same SSID, it just knows to forward all that traffic to the WLC1 without having to stretch that VLAN across my distribution switches.



Rant Wednesday!

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.



Way to manage on premise devices? Is my approach decent?

Hello there,

Im a software engineer and I'm deploying on-premise Jetson Nano devices for retail shops. I'd like to have a tool that allows me CI/CD and monitor said devices. I have a skim knowledge about way to achieve this.

The only thing that comese into my mind is setting up an OpenVPN server that allows me connect to devices via ssh and update them. Is this a good approach?

I dont know whether port forwarding will be possible by some clients so I'd like to have a solution that doesnt involve managing networking on client side .I'd like this to be seperated as much as possible.

Are there any other ways to achieve this? Can someone guide me if I'm naming my problem correctly?



Sharing radius keys securely with external entities

I'm curious what mechanism or method you use to communicate a new radius [or other shared key] key with an external vendor. I'm sure some folks have a portal that is meant for this very thing [Cisco etc] but for those who don't have something like that setup how are you securely sending sensitive information like shared secrets with your vendors?



Help me choose switches with these specifications! After reviewing a well-known brand, I was puzzled by the options number in the market Budget is $ 2,200 per switch

Switch Category: High End SMB to Enterprise entry level

Type: Managed

Layer: L3

Downlinks speed: 1Gb

Uplinks speed : 10Gb

Ports: 48 x 10/100/1000
+( 2 x 10GE copper/SFP+ combo + 2 x 10GE SFP+) or (4x 10GE SFP+)

Switching capacity: at least 175 Gb

Performance: at least 112 Mpps

PoE: PoE, PoE+ and 60W PoE

Enclosure type: Rack-mountable - 1U

Remote management
protocol

SNMP 1, RMON 1, RMON 2, RMON 3, RMON 9, Telnet, SNMP 3,
SNMP 2c, HTTP, HTTPS, TFTP, SSH, CLI



Cisco SG250 "Drop Events" on uplink port

Greetings

Sorry in advance if this isn't "enterprisey" enough but it's what we have in this office. If I should ask this somewhere else, let me know and I'll do that.

I have a Fortigate 60F (6.0.12) feeding into a Cisco SG250-50 (2.5.0.83), both of which are brand-new in the last 90 days. The Fortigate is plugged directly into an ISP-provided Hitron cable modem, attached to a 1G/50M service.

We are seeing inconsistence in our service. Speed tests can range anywhere from 50/5 to 950+/55. Days can go by without performance issues, and then we'll have days where the voip will get choppy/drop-happy/one-sided etc, and/or teams video will be laggy and choppy and freezy.

Speedtest issues do not correlate to the other issues.

Vendor support has been, so far, hopeless.

The only outlier that I can put my finger on, and that only inconsistently, is that when the speedtest results are bad, the switchport connected to the firewall LAN interface will sometimes accumulate RX Discards (called Drop Events in the web GUI) during the speedtest. As in, 10K to 15K packets per test run.

These results happen only when the speedtest is run through a web browser, connected to either speedtest.net or "whatever it is google uses when you search for speed test". If I use the win10 Speedtest.net App, it does not accumulate drop events, bad result or good.

Also, speedtest results are much less likely to be bad when run through the app.

Also, drop events do very slowly accumulate during non-speedtest use, but only in the order of a couple dozen per day.

My research suggests that drop events (InDiscards) indicate that the switch received a packet and did not forward the packet on -- due to ACLs (none active), QoS (default setting but the port shouldn't be triggering it) or a lack of resources on the switch -- ie buffer space. I can't rule out the last one, becuse I have been unable to find a guide to debug-mode on this switch (if debug-mode on the switch would even help diagnose something like this).

If I move the uplink port, the discards follow the move. So there's something about the way that this firewall talks to this switch.

Except, as I mentioned, both these devices are new in the last 90 days. The previous firewall, a FortiWifi 60D (6.0.8) was connected to an HP 1810G-24, and we saw the same kind of performance issues. I can't tell you if the "discard" symptom was showing because those HP switches don't export crap through SNMP. The intermediate combination, the FortiWiFi 60D connected to this Cisco SG250, also exhibited the same performance problems.

Every cable I can lay my hands on has been replaced. Both the switch and the firewall have been replaced. I can't see any evidence of ip conflicts or mac stealing. The only pre-existing "neworking" equipment still here are a pair of Aruba Instant Network things, and to simplify things I've turned them off while we work on fixing the wired network issues. And still.

Further upstream, the ISP has been in and replaced an open splitter on the input cable with a straight coupler. When they (or we) plug directly into the ISP device, the performance is always good.

I'm losing my mind here. At this point I'd welcome someone rolling up and saying the equivalent of "You idiot, have you set the [obvious parameter] from [broken] to [working]?" because it would just get this issue off my back.

What should I look at next?

Guidance gratefully appreciated. Thank you.