Tuesday, April 24, 2018

Cisco Virl - 20 nodes. BY nodes, do they means 20 layer 3 interfaces? or 20 devices?

No text found

Configuring public static IP on LAN server

Hello,

Here is what we have:

  • DrayTek 2925 Vigor Router using a dynamic IP from ISP
  • switch connected to router via LAN1. And is used for a couple of servers, wifi routers, and hardwired computers.
  • ISP assigned single static IP, gateway, subnet mask, DNS(x2)

The two servers are Linux, if that matters (I've read that I should not configure the static IP on them but rather in the router). One should have outgoing connectivity, and connectivity with all other devices on LAN (serverX) and the other (serverY) needs to be accessible from outside the internal network via the static IP. For the life of me, I cannot get the server to respond via the static IP. I have contacted the router's support which had me doing things I had already tried (VLAN, IP Routed Subnet).

DrayTek

Switch

serverX - local access only
serverY - desired to have outside access via static IP
other devices

Questions:

  • Is what I am trying to do going about things wrong? If so, how should I be doing it?
  • Do I need to do anything on the serverY for the static setup?
  • Can I use a static IP on LAN even though the WAN connection is dynamic?

Other things:



Looking for opinion on Aruba configuration

I'm planning for a replacement of the switching in our main office. If it helps, the current setup (which was in place when I arrived) is a single Nexus 5548UP with six 2248TP fabric extenders providing all of the access. I'm aware this isn't a recommended config as the FEXes are meant for TOR and there should be a second 5548UP for redundancy. Here's what I'm planning so far.

Core 2 x Aruba 3810M (JL075)

Access 5x Aruba 2930M (JL321A) - basic 48-port 1G 1x Aruba 2930M (JL324A) - 24-port smart-rate

The plan for the core is to bring in our to-be-installed replacement three virtual hosts and new SAN, as well as two of our main file servers, all operating at 10G with redundant connections. The virtual hosts and SAN would be segregated to a separate iSCSI VLAN and redundant connections would go into each 3810M from all devices.
The plan would be to stack the 2930Ms and run 40G uplinks from either end of the stack to the 3810Ms. The JL324A is mixed into the JL321As because we wish to have the ability to run a portion of the client devices at speeds greater than 1G to improve Autodesk Revit shared model performance.

I've installed my share of Cisco gear, but this is my first foray into Aruba and I have a few questions about this design. 1. I believe it's the case (but I can't seem to find anything to definitively state it) that the JL324A can be added to a stack of JL321As. Can anyone confirm? 2. For Aruba stacked devices, when new firmware is released, does the stack as a whole get updated at once or is each device updated separately? 3. For the 3810M core, since my desire is for each switch to be fully redundant, would it make more sense to not stack them together? My thought is that during switch maintenance when updates to the switches are applied, the individual switches could be restarted without having to bring down anything such as the SAN or the virtual hosts.
I'm open to comments on the above or any other observations.



Estimating Network Traffic Load

Hello!

I am looking for some advice on estimating network traffic load. My organization currently has a 100Mbps Internet connection and will be upgrading to 1Gbps in a couple of months. We have a content filter in place that is capable of handling 150Mbps of traffic. On any given day the traffic load on the filter fluctuates between 50-100Mbps.

With the upcoming increase in bandwidth, I need to determine whether we need to upgrade our content filter hardware to handle the potential increase in traffic load. Is there a good way to get a rough estimate based on the number of users?

Thanks!



Cisco Live Customer Appreciation Event linup announced

Sam Hunt ... dangit ... didn't even know who that was ... looked him up ... just dangit ... not a fan
I am, however, stoked about Cake lol
No bigs, it's a still a free show :)



Using Palo Alto Virtual Wire to secure a DMZ?

Our Sysadmins are rolling out a server that requires an interface with a publicly routable address on it, accessible from the outside. We've got a /29 from our ISP so I've got the addresses to spare, but I've never designed a DMZ before and I'm interested in people's Best Practices for this kind of thing. I'm told by our sysadmins that they've heard a lot of anecdotal reports that even 1:1 NAT causes a lot of problems with this specific service and they need to be able to put the actual public address on the physical interface of the server.

After bouncing ideas around inside our department, my thought is to take an interface from our ISP distro VLAN on on external switch, and run it through a Virtual Wire on our Palo Alto 3020 firewalls to a null-routed VLAN on our server switch. As diagrammed here.

To my mind, this would give us full visibility into the traffic and ability to block based on all the factors, while still being totally transparent to the service and allowing a public address on the server's physical interface.

Am I crazy here? Is this a terrible idea, will I ruin the internet and accidentally kill kittens with it?



Shadow Vlans for service providers

Please see the article below that states that TTB has rolled out shadow vlans which in effect will re-route down interconnects keeping Ethernet services live.

https://commsbusiness.co.uk/news/talktalk-business-launches-shadow-vlan/

However after a bit of googling I cannot find any technical detail on how this is being done. Is anyone able to shed any light on this for me for example config of any kind ?



‘Boost’ internet?

Please excuse me if this doesn’t belong here.

My internet has been down for a few days and had an engineer out.

They stated ‘we had to boost your internet connection.’ I have a fibre line coming into my home.

I’ve only been in IT for three years but have never heard of that phrase.. is it possible? I have a feeling they’re pulling my leg.



Looking for recommendations on a new phone system for small office

There's a small office that asked me for help regarding their phone system. Currently, they have a few T7316 Digital Nortel phones and a Nortel CallPilot 150.

The owner says the system is dated and is looking for something newer. Now, there are 3 users there with these phones, but they aren't there full-time. They have an office number through Spectrum and he's hoping to keep the same number. He wondered if there is a way to just route calls to his (or co-workers) cell phones instead of having to be in the office and check voicemail.

Any recommendations? I'm NOT a phone system guy so let me know if any additional information is needed.



IPSec throughput speed

Hi Everyone,

Just a question on how to maximize throughput in IPSec tunneling. I have two Fortigate 200D devices utilizing IPSec site to site. Now I used iperf to see their speed and its a mix between 25-30 mbps to 10mbps at certain times. I checked the phase 1 and 2 protocols and even minimized the amount of encryption algorithms it would use to talk to one another. For these devices it says the maximum throughput should be 1.3 Gbps and the two locations these devices are in have 1GB pipes up and down. Now obviously it wont use the max 1GB pipe but I imagine that floating 25mbps is really slow in comparison to what the data sheet indicates.

Anyone have an idea what may be the issue? Also if anyone has had this similar situation before with similar devices? With the Cisco ASA's it was pretty straight forward so I'm a bit confused myself.