Sunday, November 14, 2021

Unable to ping host until ARP is cleared yet MAC does not change

I have an active/standby firewall configuration that has been up and running for a number of years with no problem. Since today I am getting notifications that the standby is not available through our monitoring tools. Basically, this pings all the firewalls and sends alerts. The issue I appear to have is that I am unable to see anything on the outside interface until I clear arp cache, but then nothing appears to change;

asasov# show arp

outside 45.75.196.34 f4cc.55ac.892a 309

outside 45.75.196.35 f4cc.55ac.86ea 376

outside 45.75.196.33 0000.5e00.0106 2523

asasov# ping outside 45.75.196.34

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.34, timeout is 2 seconds:

?????

Success rate is 0 percent (0/5)

asasov# ping outside 45.75.196.35

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.35, timeout is 2 seconds:

?????

Success rate is 0 percent (0/5)

asasov# ping outside 45.75.196.33

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.33, timeout is 2 seconds:

?????

Success rate is 0 percent (0/5)

asasov# clear arp

asasov# ping outside 45.75.196.33

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.33, timeout is 2 seconds:

?!!!!

Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms

asasov# ping outside 45.75.196.34

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.34, timeout is 2 seconds:

?!!!!

Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms

asasov# ping outside 45.75.196.35

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 45.75.196.35, timeout is 2 seconds:

?!!!!

Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms

asasov# show arp

outside 45.75.196.35 f4cc.55ac.86ea 6

outside 45.75.196.34 f4cc.55ac.892a 11

outside 45.75.196.33 0000.5e00.0106 18

Before I raise this as an issue with my ISP, is there anything else I can check from my end. Nothing has changed in this setup for a long, long time and certainly not today.

Thanks



Different QoS markings for ingress/egress Voice packet

What are some likely noticeable problems if a voice packet is marked AF21 ingress to the switch interface (source) but the return traffic (egress) marked EF (46)?

I've found this in an existing voice environment. It will be fixed, however complaints about the quality of voice calls are few and far between. It would seem with the AF21 marking there would be more reported issues.



Cisco ACI Contracts

Hey Guys,

Just wanted to know something about ACI contracts. Let's say we have two application profile and each profile is has one EPG and multiple uEPG. Also Application profile == Bridge Domain (EPG vise).

Now if I apply vzAny contract for that VRF and contract is allow all with scope == Application Profile. Will that work. I'm aware that TCAM utilization will go high, butt wondering if it'll work.

what I need is Network Centric how a Firewall should work.

Traffic between EPG inside a BD should not be blocked but between two EPG from diff BD (Diff Subnet) should be.



When does DHCP Option-28 matter?

Option 28 specifies the broadcast address in use on the client's subnet, but I'm trying to figure out why/when to use it. I have a client device asking for the option and complaining when it doesn't receive it even though it seems to function on the LAN just fine. After some research it looks like some DHCP servers don't send this Option by default, but since most client devices don't seem to have an issue without it, it got me wondering: Shouldn't the device be able to figure that out on its own after receiving its IP & Subnet Mask? Is this something I should be ensuring is configured in my DHCP servers?



What is your good/bad experience with the TP-Link Omada product line?

I have bought a few cheap TP-Link wifi to ethernet devices in the past and I have been happy with them. Does any body have experience (not speculation) with the Omada product line? Seems like a low cost Meraki or Ubiquiti alternative.



Does QoS really matter when the bandwidth is never fully utilized?

We have encounter a problem when all of the device using Wi-Fi, some user said that the conversation will be lagged or disrupted while Zooming.

our vendor of the wifi said that apply QoS for online meeting will solve the problem. but in my concept, QoS is necessary when the bandwidth is limited. which our office's bandwidth never hit 50%.

So, does QoS really matter and improve Zooming latency?

PS: sorry for being noob



Error while installing CA cert for EAP-TLS

When trying to setup an EAP-TLS connection for my Wi-Fi authentication. I have to install CA cert and a user certificate in my device. This use to work perfectly fine until I upgraded my phone to android 11.
Now , my phone doesn't gets authenticated with radius server and in my radius logs it shows

 (26) eap_tls: ERROR: TLS Alert read:fatal:internal error (26) eap_tls: TLS_accept: Need to read more data: error (26) eap_tls: ERROR: Failed in __FUNCTION__ (SSL_read): error:14094438:SSL routines:ssl3_read_bytes:tlsv1 alert internal error (26) eap_tls: TLS - In Handshake Phase (26) eap_tls: TLS - Application data. (26) eap_tls: ERROR: TLS failed during operation (26) eap_tls: ERROR: [eaptls process] = fail (26) eap: ERROR: Failed continuing EAP TLS (13) session. EAP sub-module failed 

I have tested this with different phones and in all android 11 and above I get the same error, whereas it works perfectly fine for devices having android 10 and below.

Can anyone help me understand why am I getting this error and how do I overcome this?



I do not have loops with 4 interconnected switches, I would like to know why, that is, I do not have a blocked port

hello I would like to have your understanding on this problem solving I don’t speak much English but I’ll try to explain

I have two subnets here and two vlan that happens I know very well the STP ptotocolo but I observe that there are no loops and I have redudancia in the network and I see this and I say and because not there is a blocked port

data I have the interfaces in trunk and native mode because the one that is not colored is a vlan 99 for native traffic then what would be the cause of this problem that there are no loops



UTM Web Security Gateway and Umbrella DNS filtering

Hi Folks

We have UTM firewalls at the internet edge that has the inbuilt capability for URL filtering and web security. All the web traffic from LAN is sent to the firewalls using inline and explicit proxy modes. Currently, it has no DNS security or backend database to keep track of what’s good vs bad.

We are evaluating the Cisco umbrella solution.

From our perspective, ultimately we can have URL filtering on the UTM as long as it already has web security features and granularity such as SSL decryption and then we use umbrella solution for DNS security preventing internal hosts/servers from being able to do external name resolution for malicious sites from working

With that being said, I'm not sure if we are doing the right thing

What do you think?



Saturday, November 13, 2021

Trying to choose the right setup(router/firewall, switch)for a family member’s growing small business

Hello, first time poster here, I recently got asked if I could help out my aunt’s growing business she does tax prep and is moving to a new larger location, that is luckily already wired up, so she has all the wall drops she needs for her new onboards.

The location has a closet with patch panel all ready to go, but here is where I would need some help, since she is running the tax prep software on the server that emails and efiles thru the software, it basically installs clients to each computer for access thru a shared drive as it licensed, she never had any issues before with the router she was using from spectrum business plan, as she only had 2 computers wired in, the server and a network printer and it worked fine.

This new location has 8 total drops all running to a patch panel, and she is going to need all of them, so could she we connect a switch to the existing spectrum router and then connect to the patch panel? The bigger question is would the spectrum router be able to handle the traffic internet and server access all wired? Would we need a different type of router or switch? Any help would be greatly appreciated.

edit: if I should be posting this somewhere else please let me know, thank you