Wednesday, June 2, 2021

[Question] DSL help? 4-pair G.SHDSL card connecting to G.SHDSL? Wire splicing into RJ45 plug?

I'm trying to figure out DSL and there seems to be very little out there on it - specifically trying to make sense of this document: https://www.cisco.com/c/en/us/td/docs/routers/access/interfaces/software/feature/guide/GSHDSL_EFM_ATM_NIM.html#68879

If I have 2-pair copper running from a spoke to DSL hub, can I terminate (4) spokes on one hub using a NIM-4SHDSL-EA card (4 pair G.SHDSL) at the hub? Would I have to wire in 4 sets of 2-pair copper into the RJ45?



Clearing Solarwinds kiwi CatTools database

I'm currently using Kiwi CatTools 3.11 and I currently have a devices and activities list loaded but I need to swap to another set of devices and activities, previous version of Kiwi CatTools all I had to do was delete the KiwiDB-CatTools.kdb and it would wipe the database and I could start fresh to import the new lists.

The newer version does not allow me to do this by deleting the database file and will just add it to the existing list when I import the new list (thought it might work, you never know) .

I've tried searching through the manuals and Google but I'm at a loss, does anyone know how to clear the database on 3.11 without having to re-install CatTools?

Thanks.



Juniper MX map multiple inner tags to one outer tag

I have a Juniper MX in a lab terminating pppoe sessions. I'm using s-tag/c-tag setup.

s-tag = 175

c-tag = 900

set interfaces demux0 unit 175 vlan-tags outer 175 set interfaces demux0 unit 175 vlan-tags inner 900 set interfaces demux0 unit 175 demux-options underlying-interface ae10 set interfaces demux0 unit 175 family pppoe dynamic-profile BasicPppoeProfile 

This config above works fine.

How would I be able to map multiple c-tags (9xx) to one s-tag (175)? e.g. instead of just 900 I would have 900,901,902,203 etc. I've had some looking and I can see there is something called vlan-map. Not sure if I'm on the right track there. Does anybody have a working example of this?

Thanks



Weird ESXi HTTPS Issue

So we have 2 subnets behind a firewall: Production (.1) and Development (.2). We're accessing them both via an OpenVPN server in the following manner:

(1) Client connects to VPN server (192.168.1.10) with NAT'd IP address (1.1.1.10)

(2) Firewall does the NAT'ing

(3) Client establishes the tunnel to the VPN server which then provides access to 192.168.1.0/24 and 192.168.2.0/24

As a client, I can ping anything on both subnets. In terms of services, everything seems to be working fine. More specifically to this issue, I can access all services on both subnets that runs HTTPS, such as iDRAC, cameras, switches, routers, Splunk, etc. I can also access the ESXi web interfaces on the Production subnet. However, when I try to access on the Development subnet, the ESXi web interface loads endlessly.

Note that the same ESXi web interface is accessible immediately after reboot, but then "loses connectivity" after a couple of minutes. Also note that I can always ping and SSH into that same ESXi.

Been trying to wrap my head around this for a while. Some of our engineers would like to play with their own ESXi... The solution so far has been to spin up a VM on the development subnet, RDP into that VM and then access ESXi that way...

Any ideas?



Ciena Acquiring Juniper Case Study Help

Hey everyone! I recently got handed a case study to do for my MBA class. Ciena acquiring Juniper. However I'm a networking newb. I'm trying to get a handle on the ecosystem, where the two companies are strong, where they are weak, how they compete, and how one would compliment the other.

I know Ciena is super strong in optical transport network hardware and they have some software (Blue Planet) that helps with network automation. Juniper is strong in routing and switching products, SDWAN. Is that the main difference?

How do they interact with each other? And what software pieces does one do better than the other?

I've been doing research, but for a complete novice in this space it's a bit difficult to grasp. Also, I can't seem to find good information out there that shows the entire industry and where each player sits.

Thanks for any and all the help.



For those that HAVE to use Firepower...

It seems nobody would choose to run Cisco Firepower these days, but if you're one of those who would, or that decision's already been made for you...

Why not avoid the terrible GUI or terrible CLI, by using my terrible creatively-named Python library!

https://github.com/certanet/firepyer

It's a wrapper for the FTD API when running in FDM mode (not FMC).

It returns native Python objects (dicts, lists etc.) rather than modelling the API objects to custom classes and doesn't have major coverage, as I've only added the few endpoints I needed to use in my spare time, but if there's something missing that you need or have any feedback let me know!

Some docs and examples are here



What are common issues with enterprise switches at your job and how do you resolve them?

I’m trying to create a lab for myself. I will also use these resolutions and findings for work. It can be any model but Cisco has to be the make.



Viptela & Prisma Access

Greetings

I am working with my partner on deploying SD-WAN solution and we have offered Viptela to the end customer who is already using Prisma Access for cloud security.

The concern am facing is the integration between the two solutions.

I already found the integration document on the Internet : https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-integration/secure-sdwans-with-prisma-access/viptela-sdwan-solution-guide.html

What am looking for is real experience from people deployed such a setup to check if there is any restrictions or caveats related to this.

Appreciated.



Is -20dbm signal good for JioFibre FTTH having a single strand of fibre coming to home

So somehow I got my fibre cable broken in two halves and then used a field piece connector I cleaned the fibre and trimmed for straight cut then used the connector tho I’m getting the max speed what I’m paying for and the signal strength on meter is ranging in -20dbm just before the terminal point for ONT modem.



Cato Network quarterly report highlights cyber threats based on almost 200 billion network flows that passed through their cloud [PDF]

Link to the report: https://go.catonetworks.com/rs/245-RJK-441/images/Security%20Quarterly%20Report.pdf

Key Findings Highlight Risks and Key Applications

  • The most popular corporate applications on enterprise networks. Some applications, like Microsoft Office and Google, you will already know, but other applications that have been a source of significant vulnerabilities also lurk on many networks.
  • Is video–sharing consuming your network bandwidth? A popular video–sharing platform was surprisingly common on enterprise networks, generating even more flows than Google Mail and LinkedIn.
  • The most common exploits. The report identifies the most common Common Vulnerability and Exposures (CVEs); many were still found in essential enterprise software packages.
  • The source of most threats. While the news focuses on Russia and China, most threats originate closer to home. “Blocking network traffic to and from ‘the usual suspects may not necessarily make your organization more secure,” says Etay Maor, our senior director of security strategy.