Monday, July 5, 2021

Switching from programming to network admin in power utility

I’m currently in need of a job and don’t want to sway away from tech related roles. I was a “software developer” for 3 years since I graduated college with a computer engineering degree, but I mostly did some automation and app maintenance. So not much real software development and that’s hindered me a lot from finding a software dev role — even at the entry/junior level is a struggle.

However, I’m currently in my small hometown where I might have a good shot at becoming a network administrator with an emphasis in security at our local power utility co-op with plenty of training and education opportunities that they will pay for (this is great because I haven’t been lucky in getting any mentorship as a dev).

Overall, I like tech. I would love to learn as much as possible in this role and I assume I’m not shooting myself in the foot by entering an “old-school” IT role. I’m pretty new to the whole IT side of things but I find it very interesting. My question is — what career prospects do I have entering this network admin opportunity with an emphasis in security? I say this because down the line I may want to specialize or pivot into something else where I can use my “old-school” network admin experience. Thanks all I’m advance!



Has anyone done business with 313 technology before?

I was looking into sourcing some refurbished equipment from them however I cant find any credible reviews online.



How to Lower Network Team Stress?

What should managers do to lower team stress, anxiety, and the resulting burn out?

The fantasy answer is double or triple the team size, give everyone raises, reduce on-call, etc., but what specific changes would you ask your manager for, that are things that are reasonably possible?



Juniper ACX1100 remote management

Hi there, I have the following setup and unsure how to implement any kind of remote management solution for my ACX 1100 router in this constellation. To prevent any confirmation bias I‘m not mentioning my previous ideas and hope for your creativity.

I am using the ACX to provide Internet services to 3 costumers. My outbound connection is a symmetric 1G internet connection, as a private ethernet line in this location was more expensive.

Internet — ISP public subnet A /29 — ACX1100 public subnet /28 — costumers with public IP

My problem is that I have no private connection to my datacenter infrastructure on which I can use my management VLAN to access the ACX. As it supports only telnet, I‘m concerned to access it via the public network.

Looking forward to your ideas!



Wireless point to point failover suggestion.

Good day. I need some advice on a setup I have at work. We’ve got two building about 400 feet apart and we have a fiber link between them. Not long ago there was some construction in the area and our fiber like was physically cut. We were down for about 2 days while the repairs took place and in the meantime. I configured a P2P wireless bridge between the buildings with some Aruba gear. What would be the recommended best practice for creating an auto-failover to the wireless link in the even the fiber went down again? Part of me was thinking of getting both links up and letting spanning-tree deal with the loop but I don’t know, that just seems like a recipe for disaster. Thoughts? Suggestions?



What's your 5(ish) year career plan?

Hello /r/networking

We've had an influx of posts about the future of networking etc etc since, well, AWS became a reality for outsourced infra (Well over a decade, that is to say). I'd rather not dig up that topic as it's strongly polarised and brings nothing new to the table.

However today I wanted to open up a conversation with you all about your actual 5 year career plans, hopes and goals. What are they?

I can start and say my current 5 year arc includes mastering go, switching to SRE job title and owning more systems, rather than individual classes of devices. I dont expect to leave the networking field, but I do want to leverage tooling and systems more than mashing a CLI.



Layer 2 Data X 2 with Failover and PBR

I am looking to manage my 2 layer 2 data links with failover on Mikrotik primary link is Fiber 40mbps and Seconday link is wireless 250mbps .Further I willing to route surveillance traffic permanently on wirless bridge from each side



MLAG and VPC

hello. I'm struggling to understand how to create redundant aggregated links between a pair of Extreme Switches and some Cisco 5k's.

Here is the physical topology in essence: https://imgur.com/a/YbkzP9T

The hosts are connecting to the EX switches via mlag ports.

From the EX (lets assume S3 and S4 in that diagram) which are connected to the upstream 5k switches (S1 and S2). Actually there is also an ISC between SW03 and SW04.

My plan was to create a VPC connection on the 5ks to the ex's, and LACP enabled MLAGs on the exs'.

In terms of the VPC, I create a port-channel between the

SW01

interface Port-channel 100 description VPC 100 switchport mode trunk switchport trunk allowed vlan 100,101 vpc 100 interface Port-channel 100 description VPC 101 switchport mode trunk switchport trunk allowed vlan 100,101 vpc 100 #connected to SW03 P13 interface ethernet 1/21 channel-group 100 channel-group 100 mode active #connected to SW04 P13 interface ethernet 1/22 channel-group 101 channel-group 101 mode active 

SW02

interface Port-channel 100 description VPC 100 switchport mode trunk switchport trunk allowed vlan 100,101 vpc 100 interface Port-channel 100 description VPC 101 switchport mode trunk switchport trunk allowed vlan 100,101 vpc 100 #connected to sw03 P14 interface ethernet 1/21 channel-group 100 channel-group 100 mode active #connected to sw04 P14 interface ethernet 1/22 channel-group 101 channel-group 101 mode active 

Is this correct?

From this article (https://extremeportal.force.com/ExtrArticleDetail?an=000082635), it seems you only need to enable one port on each EX switch as the mlag port and then enable lacp lag between the ports connected between the two upstream switches.

On the EX side,

SW03

enable sharing 13 grouping 13,14 address-based L3_L4 LACP enable mlag 13 peer sw04 id 101 

SW04

enable sharing 13 grouping 13,14 address-based L3_L4 LACP enable mlag 13 peer sw03 id 101 


Serial Console over RJ45 Ethernet-Patchpanels / RS232-Ethernet-Pinout?

Hello Guys,

we recently purchased an Avocent ACS8000 terminal server/console server for an OOBM for one of our customers, to have remote connections to local devices serial console ports. (mainly Cisco switches)

http://42u.com/pdf/Manual_Avocent-ACS-8000_userguide_501a.pdf

We also have to reach switches in a different fire compartment. Therefor we have to use standard Ethernet patchpanels. So now we are wondering how to cable it up!?

The Avocent terminal server has RJ45 ports with RS232 pinout.

The Cisco switches also have RJ45console ports, which are supposed to be rollover?

Page 5: https://www.cisco.com/c/en/us/td/docs/security/asa/hw/maintenance/5585guide/5585Xhw/pinouts.pdf

So now I am wondering, do we just use rollover cables?

[Cisco Console Port] - [rollover cable] - [RS232 port on Avocent terminal server]

[Cisco Console Port] - [rollover cable] - [Ethernet patchpanel] - [Ethernet cable] - [RS232 port on Avocent terminal server]

Or do I use the included Cisco RJ45-DB9 console cable (which is supposed to be doing a rollover already) on the switches and then a DB9(male)-RJ45 adapter.

[Cisco Console Port] - [Cisco console adapter RJ45-DB9] - [DB9-RJ45 adapter] - [Ethernet cable] - [RS232 port on Avocent terminal server]

[Cisco Console Port] - [Cisco console adapter RJ45-DB9] - [DB9-RJ45 adapter] - [Ethernet cable] - [Ethernet patchpanel] - [Ethernet cable] - [RS232 port on Avocent terminal server]

I am sure, I am not the first with this question, so there has to be an answer for that somewhere out there, so I hope someone can me poke into the right direction.



[help] Junos ezpy does not connect regardless of ssh setup....

Hi Everyone,

I need help... :'(

When referring to:

https://www.juniper.net/documentation/en_US/junos-pyez/topics/topic-map/junos-pyez-authentication.html#id-authenticating-the-user-using-an-ssh-key-agent-with-actively-loaded-keys

I should be able to just specify the device name and connect so I started with ansible and built out a simple playbook to tell me the device version but the connections always failed.

Then I moved my troubleshooting to the python module itself as I can connect on ssh and the netconf port with no issue in Ubuntu and the keys were loaded in memory.

Notes

  1. Fresh Ubuntu 20.04 LTS environment from the Windows store.
  2. Network devices username is configured in ~/.ssh/config
  3. Our environment is ssh keys only (no password auth)
  4. SSH works directly with key loaded in memory
  5. netconf is running and can connect with :

ssh  -p 830 -s netconf 

Version Info

  • OS: Ubuntu 20.04 on WSL2
  • Python: 3.8.10 (Default with distro)
  • PIP: 21.1.3
  • Ansible: 2.10.11
  • junos-eznc: 2.6.1

PIP Packages Installed

# python3 -m pip list

# Note: all installed with --user

Package Version ---------------------- -------------------- ansible 2.10.7 ansible-base 2.10.11 asn1crypto 1.4.0 attrs 19.3.0 Automat 0.8.0 bcrypt 3.2.0 blinker 1.4 certifi 2019.11.28 cffi 1.14.5 chardet 3.0.4 Click 7.0 cloud-init 21.2 colorama 0.4.3 command-not-found 0.3 configobj 5.0.6 constantly 15.1.0 cryptography 2.8 dbus-python 1.2.16 diceware 0.9.6 distro 1.4.0 distro-info 0.23ubuntu1 entrypoints 0.3 enum34 1.1.10 httplib2 0.14.0 hyperlink 19.0.0 idna 2.8 importlib-metadata 1.5.0 incremental 16.10.1 ipaddress 1.0.23 Jinja2 2.10.1 jsonpatch 1.22 jsonpointer 2.0 jsonschema 3.2.0 junos-eznc 2.6.1 jxmlease 1.0.3 keyring 18.0.1 language-selector 0.1 launchpadlib 1.10.13 lazr.restfulclient 0.14.2 lazr.uri 1.0.3 lxml 4.6.3 MarkupSafe 1.1.0 monotonic 1.6 more-itertools 4.2.0 ncclient 0.6.9 netaddr 0.8.0 netconf 2.1.0 netifaces 0.10.4 oauthlib 3.1.0 packaging 21.0 paramiko 2.7.2 pexpect 4.6.0 pip 21.1.3 pyasn1 0.4.2 pyasn1-modules 0.2.1 pycparser 2.20 PyGObject 3.36.0 PyHamcrest 1.9.0 PyJWT 1.7.1 pymacaroons 0.13.0 PyNaCl 1.3.0 pyOpenSSL 19.0.0 pyparsing 2.4.7 pyrsistent 0.15.5 pyserial 3.4 python-apt 2.0.0+ubuntu0.20.4.5 python-debian 0.1.36ubuntu1 pytils 0.3 PyYAML 5.3.1 requests 2.22.0 requests-unixsocket 0.2.0 scp 0.13.5 SecretStorage 2.3.1 selectors 0.0.14 service-identity 18.1.0 setuptools 45.2.0 simplejson 3.16.0 six 1.14.0 sos 4.1 ssh-import-id 5.10 sshutil 1.5.0 systemd-python 234 transitions 0.8.8 Twisted 18.9.0 ubuntu-advantage-tools 27.0 ufw 0.36 unattended-upgrades 0.1 urllib3 1.25.8 user-agent 0.1.9 wadllib 1.3.3 weblib 0.1.30 wheel 0.34.2 xmltodict 0.12.0 yamlordereddictloader 0.4.0 zipp 1.0.0 zope.interface 4.7.1 

Environment Setup Notes

python3 -m pip install --upgrade pip python3 -m pip install --user \ ansible==2.10.7 \ paramiko \ junos-eznc \ xmltodict \ asn1crypto \ bcrypt \ cffi \ cryptography \ enum34 \ idna \ ipaddress \ Jinja2 \ jxmlease \ lxml \ MarkupSafe \ ncclient \ netaddr \ pyasn1 \ pycparser \ PyNaCl \ pyserial \ PyYAML \ scp \ selectors \ six \ netconf ansible-galaxy collection install \ juniper.device \ junipernetworks.junos 

However when running a simple script:

# Python 3 from jnpr.junos import Device from getpass import getpass import sys import jnpr.junos.exception hostname = input("Device hostname: ") try: # NETCONF session over SSH with Device(host=hostname) as dev: print (dev.facts) except Exception as err: print (err) sys.exit(1) 

I get this error and it doesn't seem to matter if I specify user, pass, keyfile, etc the results are always the same. This is the same error I receive on Ansible even I use the connection as 'local'.

ConnectAuthError 

When I force specify the variables still no luck and get the same error.

Device(host=hostname, key_password='pass', user='username', ssh_private_key_file='/home/user/id_rsa') 

I feel like I'm missing something very simple but I've hit a wall... If anyone might know it would be a huge help.

In the meantime this has given me a great challenge so far so I will keep bashing away at this and if I find the solution I will be sure to reply encase it can help others unless someone can push me in the right direction.

Thanks everyone!