Recently I heard about this topic software-defined network(SDN) and I want opinions and real experiences with it.
Wednesday, October 31, 2018
ethernet-switching-options missing on EX4300 (v17.3)
Hi Guys, sorry for the noob question. I am trying to configure voice vlan on the Ex4300 and I am using the latest JTAC release. The switches are in a virtual-chassis. When I try go into edit mode and the try "set ethernet-switching-options" the command is not found at all. Any ideas on what I am doing wrong? Auto complete only shows event-options but nothing about ethernet-switching-options. I am wondering if it has anything to do with the cli layout changes on 17x or a different approach when inside a vc.
Thanks in advance.
Tuesday, October 30, 2018
Simple Open Source Asset Mgmt
Across our many tools we have a lot of drift/gap on the asset list. We manage around 1500 switches, routers, firewalls, load balancers etc and are looking for a very simple open source asset management tool that we can use as the single source of truth. We don't want any bells and whistles, just a simple snmp poll, store the information and an API that allows me to access the list from other tools.
Any idea whats wrong? Asked in one of the interviews
Dear Support, My virtual machine is talking to our on-premise Hadoop cluster and we have observed connections dropped by the VM after approximately 15 minutes after being established. We have tried tweaking our cluster and the VPN, but it did not work. We have also disabled any firewall or NAT: our cluster is connected directly to the Internet. We ran a TCP packet capture on one of our routers and we do see the following:
408 7.963058 178.124.133.65 172.16.72.34 TCP 66 http > 42867 [FIN, ACK] Seq=312 Ack=11 Win=14592 Len=0 TSval=3673141343 TSecr=234006479 409 7.963204 172.16.72.34 178.124.133.65 TCP 66 42867 > http [FIN, ACK] Seq=11 Ack=313 Win=15744 Len=0 TSval=234006482 TSecr=3673141343 410 7.995556 178.124.133.65 172.16.72.34 TCP 66 http > 42867 [ACK] Seq=313 Ack=12 Win=14592 Len=0 TSval=3673141351 TSecr=234006482
Please help, this is a fault in your network, I need a solution ASAP!
Customer, Inc.
Modular Patch Panel suggestions.
So I am in the market for patch panels. We already have some Monoprice PN 310 toolless keystone jacks, but from what I am reading you can't fully fill a 24port modular patch panel from Monoprice, due to the width of the jacks.
We have a few panduits, but we want to get away from them, since they cost an arm and a leg.
Do you all have any suggestions? What about the vertical cable 24 port blank patch panel that firefold sells?
VPN behind Double NAT issues
Been breaking my head over this one for a few days now, so figured I'd ask here as there seem to be quite a few knowledgeable people on here.
A brief explanation on the topic at hand. Due to the way the "ONLY" ISP around configures their switches we're having to run our VPN behind a double NAT.
The server side has 100/20 VDSL The client side used for testing has 80/20 VDSL but problems occur on fiber networks all the same. Ping is low (~10) at all times
The modem is serving 192.168.2.x whilst the server behind which is the internal network is serving 10.0.0.x. There's no way to configure the modem in bridge mode because some equipment used for IP phones is also ran off there. Reason it's not behind the internal network has to do with some external management functionality that the ISP desperately doesn't want to give up on and seems to depend on the modem being in the state that it is, so there's not much room to wiggle there.
Initially (about a year and half ago) this worked fine with proper port forwarding, etc. But about a month or two ago the modem was replaced and the external IP address changed. Ever since then it's been very problematic and downright awful.
VPN is provided by good old Windows Server 2016. It's just a basic L2TP VPN with nothing fancy. Something that like I said, has worked well for a substantial period of time.
Now I've isolated the problem down to the NAT interface in RRAS, without that configured the VPN is blazing and browsing through folders on network shares is a breeze. Opening files works like the server was right next to you.
Obviously without NAT configured (the server has two physical NICs) there would be no internet access on the internal 10.0.0.x network so that simply has to run. But once I add the NAT interface the file browsing just stops dead in its tracks. Browsing the internet, watching youtube, etc. all works flawlessy (using the external gateway) but it takes well over a minute to open any folder on the remote network. Whilst opening a folder and waiting for it, the internet in the background continues to work flawlessly.
Remove the NAT interface from RRAS and everything is all fine and dandy again.
Now I'm aware that a VPN behind a double NAT will never work perfectly but this is a bit much isn't it?
I've played with MTU sizes, tried a different protocol (PPTP), went as far as completely reconfiguring the on premise networking side of things (which means I'll now have to sacrifice a weekend to reconfigure part of the server..) all to no avail. Am I missing something blatantly obvious here or what gives?
I should probably mention the server runs on VMware and as such is virtual.
IT Mgr Transition to Network Engineer ?
Currently I'm an IT manager for small business. (1 man shop, yours truly and an MSP doing L1 help desk stuff) we have 700+ employees. I have been in the IT world as a SysAdmin and IT manager for the last 8 years, here over a year. My last employer was 10x the size and had much more networking, which I really enjoy and find fascinating. We had UCS's, Data Center, lots of route/switch etc... Here it's so simple its just plain boring...while the company is growing its not at a rate that will change my career path and there are very limited technical opportunities here. I hold a current CISSP and CCNA R&S cert, make decent money, $95k/yr, no bonus, no 401k in a moderate cost of living are - not complaining just making a note :)
I'm a bit burnt on the one man show thing....
Does $95k/yr (no bonus/401k) seem reasonable in my current role?
Is it realistic for me to expect to be able to transition into a network/systems engineer/consulting type role (with a VAR\big4 etc) making similar $ (or more) money if I pick up CCNP ?
Any other thoughts or recommendations ?
Has anyone out there done this - moved from management to technical ?
Thank You!
Nexus 3k vPC Redundancy Help
What I've got today:
I am coming from a pair of 5548s with a bunch of 2K FEXs as my ToR. The FEXs are currently multihomed to each 5k, and I add a server into each of the 2 FEXs at the top of a rack and create a vPC for redundancy. vPCs are extremely self-explanatory with that gear.
Proposed diagram: https://i.imgur.com/S0BPWM4.png
So... it's almost 2019 and it's beyond time for a 40gb core and 10gb ToR. New switches here I come.
I know I can do a vPC from the server to each 3172. What I am unsure of, is can (should) I do a vPC from a 3172 to each 3132 in the core? I would like to avoid layer 3 between core and ToR, since my VLANs are spread amongst many racks.
Thanks.
Rant Wednesday!
It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.
There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!
Last Input on [HPE Switch]
Is there an equivalent command to Cisco's "sho int <port>|Last Input" on an HP switch? I'm needing to find 3 unused ports on a full HP switch and, for the life of me, can't find (google) the command on how to see when the last input on a port was.