Saturday, June 2, 2018

Getting FIN,ACK outside of a connection on Amazon Dot devices but not other devices.

I have used iptables to log the number of FIN,ACK's outside an existing connection. The FIN,ACK's only occur on my Amazon Dots and not on my Harmony Hubs or other devices.

Before I show the iptables -nvL FORWARD output I would like to mention that I am using a Raspberry Pi as a repeater for my home automation (HA) devices. In other works all of my HA devices are Wifi attached to the Raspbarry Pi, running Raspian Stretch, and the Pi is Ethernet port connected (i.e., hard wired) to my home router.

Here is a link to the iptables -nvL FORWARD list output:
https://drive.google.com/open?id=16w5U2_BkCapyf5aKO22hva7L2wS-PRNN
or
https://pastebin.com/fLuP1msU

Now, what I am going to say now should NOT be assumed to be 100% correct because,... well.... I make mistakes. I contend that the FIN,ACK's are outside of a valid connection because they are not picked up by previous rules in the iptables setup. The rule I contend that picks up the connection-less FIN,ACK's is nearly the last rule and starts with
3870 155K ACCEPT tcp -- wlan0 eth0

You will notice that, in this rule, I limit the rule to the address range of my Amazon Dot's which are defined in the first few rules.

So, am I interpreting correctly that my Amazon Dot's are attempting to respond with a FIN,ACK over a non-existent connection? If so, is there an issue with the Amazon servers or the Amazon Dot tcp stack? Also note that I do not see any of this connection less FIN,ACK on the other devices on the same Raspberyy Pi.

Thanks



Running Data Center replication and storage traffic across a stateful/IPS firewall

Having trouble finding case studies on this. I’m sure most are going to say “don’t” but I’m trying to do due diligence to find case studies or example of why not, or how bad it would be to do so.

The preamble is trying to eliminate private links and use the Internet as the sole inter-dc transport.



Any other Specifications Optimizing for 100G singlemode optical transceivers to fit data center requirement ?

100G single-mode transceivers are typically produced in lower volumes for the telecommunications market, which has a demanding set of performance requirements from utoptic.com :

Link lengths of 10 km and over.

DWDM and LAN-WDM require active cooling.

Support for a wide range of case temperature ranges

Service lifetimes, sometimes in excess of 20 years, that require hermetic packaging to withstand potential prolonged harsh environmental conditions.

Deep analyzing these factors, optimizing the specification to fit data center requirements by reducing the reach and link budget, decreasing the temperature range and lifetime warranty .

Any other Specifications Optimizing for 100G singlemode optical transceivers to fit data center requirement ?

Any insight will be appreciated !



Private address in trace to google DNS?

Hey all,

I'm pretty green, but I thought it was weird to see a private class A hop half way through my trace route.



Recommend

If you guys want to take a cisco products, i recommend you to choose 10gtek, which is a professional company established many years. i always take fiber optic there, not only cheaper but good service.



Friday, June 1, 2018

Is it breaking a rule to have RFC1918 IP addresses visible to the Internet? Here's a traceroute to a public IP address...

C:\Users\tomdzu>tracert 162.245.240.129

Tracing route to h240129.basinbroadband.ca [162.245.240.129] over a maximum of 30 hops:

1 2 ms 7 ms 3 ms 10.0.28.254

2 * * * Request timed out.

3 1 ms 1 ms 1 ms h72-2-59-114.columbiawireless.ca [72.2.59.114]

4 24 ms 6 ms 7 ms 172.27.15.138

5 8 ms 8 ms 7 ms 172.27.15.25

6 24 ms 24 ms 24 ms 172.27.9.186

7 24 ms 24 ms 24 ms 172.27.9.194

8 24 ms 24 ms 24 ms 172.27.9.202

9 24 ms 26 ms 24 ms 172.27.9.210

10 27 ms 27 ms 31 ms 172.27.9.218

11 24 ms 24 ms 29 ms 172.27.9.226

12 24 ms 24 ms 24 ms h240129.basinbroadband.ca [162.245.240.129]

Trace complete.

C:\Users\tomdzu>



/22 that bad for production networks?

We've traditionally used /23 subnets for our production networks and I see us needing a little more growth options moving into the coming years. I've split out many of our networks into additional /23 subnets, but am seriously contemplating bumping them to /22's as well. That would make things so much easier, but I'm a little hesitant as I've read you shouldn't go larger than a /23 or /22 in some circumstances.

If I use a /22 subnet in production, is it really the end of the world?



3 routers, 3 subnets with shortest path

I was trying to decide if this fit more in the home networking section, but the point of my experiment is to have a model of a more complex enterprise environment.

Here's a simple diagram: https://imgur.com/a/4vzL8JE

What I'm trying to set up is network that consists of 3 routers on 3 different subnets. I've picked up 3 WRT54GL v1.1 routers to try and do this on a budget. I have no problems getting devices on the 192.168.2.0 network to talk to the 192.168.3.0 devices via the 192.168.1.0 router. However, I can't figure out how to create the direct route between the 2 without going through 192.168.1.0. I was also hoping to find a way to make it resilient to a cable being disconnected, but maybe that's asking way too much from this consumer grade hardware?

Is this a limitation of using consumer level WRT54GL hardware? I was able to achieve the existing configuration by connecting the WAN ports on the 2 lower routers to the LAN ports on the upper one, and adding the routes to the routing table on 192.168.1.0. For that to work, routers 2 and 3 are both addressable on the 1 network. However, when connecting between the 2 LAN ports, I don't see a way to assign them the 2 IP addresses necessary for them to communicate directly.

If this isn't possible, what hardware should I be using? I feel like it's a simple scenario. I do have a few Cisco 3550s available if they would be better to use, but I'm not familiar with configuring them.

Sorry if this was too simple. I'm mostly trying to figure out if I need to go back to the drawing board or if it would be possible to use the 3550s to not have to buy new hardware.

Thank you!



Help me diagnose: some devices on wireless network have internet access while others don't

I'm stumped. My Archer C7 wireless is super-stable for my laptop, but my phone (a Pixel 2) sometimes has internet access, and sometimes doesn't. If I reboot the router, it'll get internet for a while, but eventually it stops. My wife's Pixel 2 *never* has internet access on this wireless network. All these devices can connect to the wireless network without any trouble at all, they just show as having no internet access.

Can anyone find a moment to offer me some troubleshooting steps to check out?



What is the aggregate time lost to IOS ip domain-lookup?

How old is this feature and at what point did Cisco Marketing's intent switch from benevolence to malevolence?