Monday, June 28, 2021

Need a basic overview of how to begin with mapping/VLAN setup

So I just started a new job. I've worked with Cisco switches before (very lightly), but not HP. I've never setup VLANs before, but I have a basic idea. I got my Network+ in December.

This small business I'm at has everything on one .255 subnet, which the IT guy there wants to push to .254. However, from my reading it seems smart to put different departments on different VLANs, even for a small business, am I right?

I've never actually had to setup a VLAN from scratch, or worked on one that wasn't on a Cisco switch.

There's only like, 4 areas really. Should I combine HR, which only has a couple people, with the front office? Then do a VLAN for the other areas that only have like, a 24 port switch to them.. and one area that has a 48 + 24 port switch? Should I do the VLANs according to the switch area, or by department?

I'm assuming I setup the VLAN on the main switch in the MDF?

Also, I don't know how large the place will grow. Right now they are tight on addresses since they are all on just one .255, so I'm wondering how many addresses I should give each VLAN if I do do this.

Sorry for the noob questions. I've been doing IT for 20 years, but networking I've never been able to dive in this deep before, but whatever I need to do I'll catch on/read on real quick.

Edit: I've started a network diagram in yworks. They didn't have one before. I've basically just been putting down the hardware and what they are connected to. I assume I should somehow include the VLANs in the diagram once I get them up?



3750x access switch - Po/trunk - 6506-E Distro Switch

Hey all, trying to figure out what my distro switchports are going into err-disabled (channel-misconfig error) when the access switch uplinks are plugged in.

I have 2 3750xs connected to the same 6506-E. Below are their configs.

3750x / po11 work great. The second switch with po12 won't make a solid connection. As soon as the uplink is no shut, the distro switchport goes into err-disabled.

What stands out to me is the po12 switch doesn't have "switchport nonegotiate" on it. Could that cause the issue? Thanks for any insight!

3750x - access switch that works

!

Interface Port-channel11

Switchport trunk encapsulation dot1q

Switchport mode trunk

Switchport nonegotiate

!

Gi1/1/1

Switchport trunk encapsulation dot1q

Switchport mode trunk

Switchport nonegotiate

Channel-group 21 mode on

!

3750x - access switch that doesn't work

Interface Port-channel12

Switchport trunk encapsulation dot1q

Switchport mode trunk

!

Gi1/1/2

Switchport trunk encapsulation dot1q

Switchport mode trunk

Channel-group 12 mode on

!

6506-E - distribution switch

!

Interface Port-channel11

Switchport

Switchport trunk encapsulation dot1q

Switchport mode trunk

Spanning-tree guard root

!

Interface Port-channel12

Switchport

Switchport trunk encapsulation dot1q

Switchport mode trunk

Spanning-tree guard root

!

Interface Gi1/1/1 (working)

!

Switchport

Switchport trunk encapsulation dot1q

Switchport mode trunk

Channel-group 11 mode on

Spanning-tree guard root

!

Interface Gi1/1/2 (err-disables)

!

Switchport

Switchport trunk encapsulation dot1q

Switchport mode trunk

Channel-group 12 mode on

Spanning-tree guard root



Solo Racking Upgrade

Hello Everyone,

Looking to make my solo racking experience a better one. Been debating on switching up the traditional screwdriver. I have come up with three alternatives that could do the job and was looking for opinions, what would any of you use?

Bosch Pocket Driver: Amazon

Dewalt Cordless Screwdriver: Amazon

Ryobi Screwdriver: Home Depot

Any thoughts would be appreciated. Thank you



Very basic question about logging on ASA

I'm very new to networks and try to understand logging atm. Can someone explain to me what it means if "beginning" is disabled but "end" is enabled?
What exactly gets logged and what difference would it make if it was the other way around?

Logging Configuration
    DC                    : Enabled
      Beginning           : Disabled
      End                 : Enabled
      Files               : Disabled



Help With FortiGate Site-to-Site Connection

Hi All,

I am looking for some help with my company's current network setup.

We have two offices, one located in Texas and one located in New York.

We currently have a FortiGate 90D in the Texas office and 60D in the New York office.

We have a site-to-site connection setup between the two that was setup prior to my arrival at the company. I am not super familiar with FortiGate and have most of my experience with Cisco and Juniper devices.

The issue we are having is all the devices in the TX office are able to reach devices in the New York office without issue, ping, RDP, etc. These devices are also able to connect out to our Azure environment and VMs that we have.

But on the other side in the New York office, the FortiGate is not able to even ping the Texas FortiGate or any other Texas devices, devices connected to our TX VPN, or any of our Azure devices (including our DNS servers).

As far as I can tell it looks like everything is configured correctly on both sides and routing table includes routes to our Azure and Texas environments and looks like the access list is configured correctly to allow traffic to pass through.

Is there any other policies or anything that may be in place that I could check? I am unsure of why I can ping from Texas -> New York but not the other way around.

Any thoughts or suggestions? Any help appreciated! Thanks!



What could cause a Cisco switch of not learning the mac address of a PC/IP Phone?

I’ve been facing some problems at work lately and I would like some help. Sometimes a few users complain about not having internet access so when I checked the switchport that the pc is connected to, the interface was up and status was connected but when I did “sh mac address int x/x”, it was empty. Happened with a few other as well. The other problem I’m facing is, some users t even though everything looks fine and their pc has an ip address assigned etc can’t access the internet even though other users in the same subnet can access the internet normally. Our access switches are C3850. Any idea what could cause these 2 issues?



Guest WiFi using Umbrella for DNS/content filtering

Been working on migrating DNS for our guest wireless from an internal Umbrella VA to Umbrella Public DNS. For the most part, it works. Issue is devices get a cert error when they hit a blocked page. I'm being told this will be the behavior unless we install the Cisco Root CA cert on devices - obviously not possible since this is just meant to be a guest network.

Any suggestions on another DNS/content filtering solution that could leverage our existing Cisco WLC/AP deployment?



Switch Causing EERO downstream to lose connection to internet

I have a managed netgear switch (GS108PEv3) in a set up router->switch-> eero. The switch currently has port mirroring turned on and is mirroring to a different port. Over the past two days the eero's have lost connection to the internet two times while I can tell that the router still has the ability to connect devices to the web. Is there anything inherently wrong with this setup that could be causing this to happen.



Secure LAN To LAN gateway

Hello, please send me to the right place is I'm in the wrong one, I need some advice on reconfiguring an office network. We have a LAN, that is a labratory with many many different OS, microcontrollers, IOT devices, etc... I run a computer with DOS8, Win2000, XP, RHEL, Ubuntu, a few iPads, android devices and a lot of serial to IP gateway/device servers.

Our parent company has decided that we are a liability with so many old, unsupported and very unsecure devices.

I don't care if I have an connection to WAN from my lab network, but i need to transfer files (on the order of 10GB at a time) regularly to the main LAN on site (which is part of the company wide LAN and contains internet access and VPN to our other remote locations).

All my lab devices get time and lots of other updates from our on prem lab server as well as stream data from various test machines to a our central server. Our IT dept. claims there is no way this can be done. I feel like there must be a solution even if its not ideal. (and not hire an intern to run around our campus with an external hard drive)

Can anyone help me figure out what I should be searching for? Im out of my wheelhouse and I dont even know what i don't know. Security between the two LANs seems to be the penultimate requirement. I need to be able to transfer files from LAN to LAN but prevent all WAN from reaching the isolated LAN with old DOS machines etc. I hope that all makes sense, thanks for reading.



1G connection possible on 500-600 Meters of OM1 Multi-mode using Single Mode SFP 1000Base-LX and Mode Conditioning patch?

TLDR: I am looking for people's experience with getting long distance runs on OM1 using Single Mode SFP's and mode conditioning patch cables.

________________________________________________

So I picked up and abandoned project that I thought would be quick and easy, I made a couple assumptions, and that didn't go well. (Assuming the last guy knew what he was doing)

So, now that I have reassessed the situation and realized my assumptions were wrong.

I am left with 3-4 runs of OM1 that are well past the 275 Meter length for 1G.

Equipment being used:

  1. Unifi USW-Aggregation https://store.ui.com/collections/unifi-network-switching/products/unifi-switch-aggregation
  2. Unifi US-8-150w https://store.ui.com/collections/unifi-network-switching/products/unifi-switch-8-150w

So now I am going down the google \ reddit rabbit hole of making something work, with no possibility of changing out the cable runs anytime soon.

My thoughts so far:

  1. 100Base-FX... (AFAIK My switches won't support 100Base-FX SFP's)
  2. Media convertors (I am trying to avoid)
  3. 1000Base-LX Single mode SFP's and Mode conditioning patch cables? (just found this today)

So I am looking for feedback \ thoughts \ experience.

*I know this isn't ideal