Monday, November 15, 2021

Option 82

What Metro Ethernet demarc device do you recommend that supports DHCP option 82?



Gigabit switch not handing out IP while Megabit switch is

Hi guys,

I’m farly new in networking (basic knowledge) and english is not my mother toung so i apologize for any mistakes.

I’ve been hired as an intern at this company since their IT quitted and i was hired as “junior IT for basic things” . This month has hell for me since we had a lot of issues with our internet connection. Long story short our AP were not handing out IP (We have a DHCP server installed on a server in HyperV). These AP we connected to a gigabit switch and when hell came loose i went to the server room and tried to connect to the gigabit switch so i can be on the same VLAN as the AP and reboot them, that switch did not give me an IP but the megabit one did. To reslove the issue i went at work on saturday created a new VLAN and at the DHCP server i created a new IP range /22 and connected all the AP to that switch. Can anyone give me a hand here and tell me why the switch wont hand out IP’s?

Thank you



Private Cloud firewall cluster, redundant across multiple AZ in AWS. Is anybody doing this for production?

We currently have Checkpoint cluster in a single AZ, and if you use IPsec tunnels, you can’t deploy Checkpoint cluster in two AZ, unless you don’t use IPsec. We have around 300 VM’s there in different VPC’s isolated with TransitGateway quite a bit traffic going on there. Just wondered, what other people are using out there?



STP taking down my firewalls or my config is just plain wrong

In the last day or so, I have had an issue with my firewalls and the secondary kept dropping offline. I have been on site for the last 4 hours and I could not see any reason for there to be an issue until I had a thought about STP and it appears that this is what was causing the issue, one of the ports on my switch was being blocked. I have disabled STP on both switches for a single port, that port is a trunk on VLAN 2 between my 2 switches. There are 2 other connection in the same VLAN on each switch and those being the outside interface of a firewall and the connection to my provider.

This doesn't feel right, but it also makes sense as to why I have been having issues. I am also not sure why this suddenly started happening yesterday with no changes from my end.

I am trying to understand if I just happened to have made it work when it should not or I actually fixed the problem and have not introduced a horrible issue somewhere.

The connections from my provider are running HSRP I believe. From what I can see, only 1 of my links is active at any time.

So with STP active, it appears it was blocking one of the ports and stopping both of the firewalls being able to see the active uplink so only the firewall on the same switch as the active connection from my provider would work. If I swapped the active firewall at this point, the active provider link was on the other switch and not until I disconnected the provider link in the other switch would it work.

After disabling STP, I can failover the firewalls however I want and because they both have access to the active provider link, they both work.

My concern is that I have had to disable STP on these ports and what is the impact of that. I had also expected the firewalls to know something was up but it seems that only occurs when the provider link goes down.

What gives!



secondary vlan ip on EVPN-VxLAN network

I have working EVPN-VxLAN fabric and life is good but now i need more public address so i am planning to add new public IP subnet in existing public VLAN interface on all border-leaf and my other leaf switches. does following work and any other complication for future?

currently i have following config for public VLAN

interface Vlan100 description ** Anycast Gateway For Public ** no shutdown mtu 9216 vrf member CUST1 no ip redirects ip address 69.xx.xxx.1/24 ipv6 address 2600:c04:3111::1/64 ipv6 nd prefix default no-advertise ipv6 nd ra route suppress no ipv6 redirects fabric forwarding mode anycast-gateway 

I want to add new public subnet Ex: 70.xx.xxx.1/24

so can i do following, just add secondary ip?

interface Vlan100 ip address 70.xx.xxx.1/24 secondary 


Barracuda Firewall Backup PAR file - Is it a text file?

Hi, getting ready to do some analysis on Barracuda F600 and F400 devices. Manual mentions that a backup creates a PAR file. I don't have access to these devices yet, does anyone know if the PAR file is plain text? Can I open with notepad++ ? If not, is there a way to export config to csv? TIA!

https://campus.barracuda.com/product/cloudgenfirewall/doc/72515937/how-to-back-up-and-restore-firewall-configurations



Need help with the Design of a University Classroom

Hey guys,

a friend of mine asked me to help him and his professor with the design of the network infrastrucsture in their new classroom. I recently finished my CCNA so my knowledge isn't very deep especially when it comes to networking hardware so please don't go too hard on me ;)

The task is the following:

-1 autotracking camera focused on the presenter

-1 camera that works with a microphone to identify different zones in the room and to focus on those zones

-1 microphone on the ceiling of the room able identify the beforementioned zones

-1 TV

-1 SmartBoard

-1 Computer/Control desk

-1 Tablet to connect and control the computer

The idea is that other students who can't attend the class and are studying from home can still see both the presenter/teacher and the people speaking in the classroom. The camera together with the ceiling microphone will communicate and focus on the speaking student in the classroom (the microphone tells the camera in what kind of "zone" the talking student is, after that the camera focuses on that zone). At the same time the other camera is constantly tracking the talking and presenting teacher in the front of the classroom.

From my understanding right now the microphone and the cameras will be connected through USB cables to the computer and will communicate through some software on the computer. Since I'm not very familiar with transmitting multimedia over the LAN my question would be if I can CONTROL the cameras and microphone over USB but getting the video output over the LAN and import it into something like OBS (the specifications say that the camera supports IP streaming like RTSP and RTMP and do I need a speacial Switch/Router that support those protocols)?

The next problem is the network where all this devices should be. Since transmitting livestreaming information(tablet connecting to pc, cameras, microphones connecting to pc etc) over the university-network is rather problematic (needing to reconnect, connecting the camera can also be problematic since the admin has to add them etc. etc.) I was thinking of creating a private network for the classroom. The professor says last time he tried to do something simillar and far simpler in some other classroom and talked to the IT staff of the uni it took them months until they did something and even that was wrong so he doesn't want to rely on them again... Right now there are around 6 LAN ports in the room that each have a static public IP address. Basically I thought about connecting a router to one or two of the ports and impelementing NAT for all the devices that will be connected to the router (see above).

The are a few requirements:

-At least 8 ports (10 would be better)

-There should be at least 3 PoE+ ports for the microphone and the cameras

-Wireless Access Point (needed to connect the Tablet to the Computer and eventually to connect the devices of the students to the computer)

I didn't find a device like that online. Best I found were these 2 routers:

The RV260P VPN with PoE Router which has no WiFi and only PoE which from my understanding isn't enough since the devices need PoE+.

And the RV260W VPN with Wireless Router which has no PoE at all.

Since I didn't find anything better I thought of getting the RV260W and a simple Layer 2 Switch that has PoE+. Then connect the Router to the wall LAN port, the Switch to the Router and all the devices to the Switch (Or the Access Point of the Router). I also thought about getting a Router and putting PoE+ and a wirelless modules inside but didn't find anything appropriate either.

I really hope someone could give a recommendation for a Router, Interface Cards + Router or Switch + Router. And probably show me some of the red flags I missed in this setup.

Thank you very much in advance

PS.: The Professor said that ordering and receiving those items would take up to 3 months (German burecruacy) and he wants to get all the needed hardware as soon as possible. Meaning reordering is not really an option.

PPS.: On the Cisco website it only says that this router (RV260W) only supports 802.11ac however on this website (just scroll down) it says that this router supports many different wireless standards. Does Cisco just omit mentioning all the other standards?

PPPS.: The price doesn't really matter. The prof would rather pay $1200 than waiting another 3 months for the additional hardware. He just wants a solution that works and doesn't involve the Uni-staff.

Edit1:

I’m sorry I forgot to mention it but I already found some mics and cameras that do exactly that (can communicating with mic etc). There are those shure mics that you attach to the ceiling. And this Aber Camera that can focus on those zones. The other camera looking on the presenter uses “basic” ai auto tracking.

What do you think about the Router/Switch networking problem?



Wireless Topologies - Star, Infrastructure, service sets (ESS) - All or some?

This is for an educational project to build a network for a company. Currently, my wheels have been spinning trying to iron out this detail. Any help would be appreciated so I can move on with the project. I'm currently in my first networking class so I'm very new to this information.

I will be posting links to what sources I've read to try and determine the answer for myself. There is a rule against re-direction, but I must show the effort I've been attempting to locate the solution.

The questions I need to be answered: For a large multi-user business on a WLAN, would the topology in this network use an infrastructure topology, star, and/or ESS(extended service set)? Which are physical/logical?

Note: This is a question I wrote and not something directly from the project.

Infrastructure Topology

I'm currently using the uCertify course materials. I understand the difference between physical and logical topologies. According to uCertify wireless networks use the three wireless topologies: Ad Hoc, Infrastructure, or Mesh. (I would link to the text, but since it's paid material, that's probably a nono.)

From the point above, I'm reasonably confident the WLAN I'm crafting will use infrastructure topology.

Infrastructure topology appears to be physical since it extends a wired LAN to include wireless devices.

link: http://www.idc-online.com/technical_references/pdfs/data_communications/Wireless_Network_Topologies.pdf

Star Topology

Star topology appears to be the logical topology I would be using. However, the uCertify material seems not to mention star being used with wireless.

Tom's Hardware agrees: https://www.tomshardware.com/reviews/local-area-network-gigabit-ethernet,3035-7.html#:~:text=Wireless%20networks%20have%20different%20topologies,use%20only%20two%20logical%20topologies%3A&text=Point%2Dto%2Dpoint%E2%80%94Bluetooth,point%2Dto%2Dpoint%20topology.

Here is another source with diagrams showing star topology being used as the logical topology component fire wireless networks specifically:

https://www.emerson.com/documents/automation/training-wireless-topologies-en-41144.pdf

Extended Service Set(ESS)

According to uCertify ESS operates within an infrastructure topology. The link below, which is another education program, labels ESS as a topology in itself:

https://networklessons.com/cisco/ccna-200-301/wireless-lan-802-11-service-sets

ESS is the connection between more than one Basic Service Set (BSS); any google search should confirm this since it's a definition. Due to this definition, this topology sounds physical as well.

Conclusion

My answer to this question would be the WLAN would use all three: a physical infrastructure topology with a physical ESS topology within along with a logical star topology.

Edit: fixed the duplicated links to reflect the appropriate ones



Network automation - Netmiko, Pexpect, or both?

Hi!

While I have like 15 years of networking experience, I'm fairly new to automation and I'd love to learn more. I'm not sure I get it, so I hope you can explain.

I've recently started automation via expect, and found it pretty simple to learn but also limited in what it can do (or at least, some things are HARD in expect). So I heard Python is the stuff! I've studied the basics of Python, but I find myself having a hard time with all programming until I have a concrete goal. So I figured I might as well start scripting, and try to translate my old expect scripts.

What I don't get is the relationship between Netmiko and Pexpect. Are they totally different modules made to be used separately? Or can you use both and do a bit as you like?

I've tested a few things with Netmiko, but found it really hard since I'm used to Expect. Netmiko felt a bit "blind", I wasn't sure if it was working until I printed output from a command. Maybe Pexpect is run a bit more like Expect - with a live output? Or how do you use them? Is one better than the other or do they only do different things? How should I go about this and maybe you can recommend some good place to learn more?

Appreciate your input! Thanks!



Option 82

What Metro Ethernet demarc device do you recommend that supports DHCP option 82?