Sunday, September 26, 2021

CCNP Service Provider

Hello,

​

Apologies in advance if this topic has popped up before, I'm debating if I should take on the CCNP SPCOR 300-501 certification, although, it seems the lack of practice exams, centralized material, i.e., an OCG is lacking for this exam (or I am simply blind).

A nice article on the Cisco learning forum (https://learningnetwork.cisco.com/s/question/0D53i00000XA627CAD/what-would-be-the-recommended-cisco-press-books-for-350501-spcor-exam) suggested several books which I already have but if anyone out there has taken the exam and successfully passed if you don't mind sharing your resources and any advice I would be forever grateful.

I'm sure other service provider engineers would also appreciate the information as well :)



DNS resolve to backup/main static ips?

We have dual wan on our firewall/router.

WAN 1 = main

WAN 2 = backup

Both are static IP.

We have a camera server port forwarding to both.

We would like to setup a DNS record (houseNVR.domain.com) that will resolve to the main static IP, and if it can't reach it, it will resolve to the other backup static ip. I'm guessing it would need to ping the port or something to fail back and forth?

Does such a DNS service exist? We use AWS. Maybe route 53 has something like this?



Good choice for CCNP lab kit?

Hey guys,

It’s been about a year and a half since I got my CCNA and want to start studying for the CCNP (not sure which concentration yet).

Was interested in getting some hardware to set up an actual lab as opposed to a virtual one.

Trying to decide if this lab kit would be sufficient, it comes with:

3 x Cisco 1921 Routers 2 x Cisco 3560 Switches 1 x Cisco 2960 Switch Thoughts?



Switch MFA

Good morning,

I apologize in advance if this is a dumb question. I tried finding some information on this but I couldn’t get any good results.

Our insurance company is requiring that we have MFA on our switches. Is this a possibility?

In my mind, the web gui for some switches, and if it comes with a manager then sure. For example Aruba central. But for the CLI does it even have MFA?

If this does exist any insights would be helpful.

Right now we have Aruba 2920 48 port switches… I couldn’t find anything to do with MFA in the GUI.



dig terminal command in Linux turns up different IP address than using website ip detector ...thoughts?

Hi everyone, I have a basic question. I followed the guide on the following website https://www.cyberciti.biz/faq/how-to-find-my-public-ip-address-from-command-line-on-a-linux/

and used the dig +short myip.opendns.com @resolver1.opendns.com command. I was given an ip address 104.200.23.95 which seems to point to somewhere in Texas....

​

However when I use the IP detecting websites such as whatismyipaddress etc it returns me with another number, 94.x.x.x. which points to a seemingly valid location since the geolocation information displayed is accurate

can anyone tell me why I am getting 2 separate results, from a technical standpoint? I am just trying to understand this. ultimately my end goal is to create a proxy server on my computer so I can tunnel my traffic while I am traveling.

​

thank you!



Can a device randomly change its MAC address?

Can a device randomly change its MAC address while connected to a Wifi network?



Solution for resolving err-disabled

Will replacing a cat 5 cable with cat 5e and setting of full-duplex on the network adapter help with err-disabled?



dACLs and Config Management

Hi all.

We are currently looking at rolling out dACLs back by radius at work at the bequest of my director. First off, the documentation available for this is so minimal and has really sucked getting enough research done that I think I know how to implement.

The question, has anyone done downloadable ACLs with a config manager like rancid or oxidize? My understanding is that when a user traverses a switch it will swap in the required acl into the config. My concern is that this is just going to create a duck ton of revisions in our config management. Does anyone know a good work around for this?



How do you protect against ICMP tunneling

ICMP tunneling can be detected if you have deployed packet capture solution or Zeek (bro). But how do you protect say a user subnet against it? Well you could disable ICMP all together or limit it to certain ICMTP types. But totally disabling ICMP would result in operational inefficiencies. Do next NGFW (like PAN, Cisco etc.) protect against it by default or you need to enable something in the vulnerability profile?



Is there a system that that makes cloud based phone numbers that can create numbers for texts,and calls and also manage them ?

Am looking for a system or to make a system that can create phone numbers that can be used for text, call, Google, Facebook/social media MFA .Am looking to create 100+ phone numbers and also manage its calls. I have looked into Twilio and Google Voice as options but interested in what other might advice. Thanks