Monday, December 31, 2018

DHCP / VLAN looking to tell me how this is working

Discovered something on my network today that has me a little confused. I have an unmanaged dell powerconnect 2848 (no vlan tagging) with a hypervisor+vms plugged into it that has a few virtual nics. The vNIC's have vlan tags for the network they are doing DHCP for. This powerconnect is connected to another managed switch that has devices requesting DHCP via a proper VLAN configuration on the ports. My question is, how the hell are the endpoints getting IPs if the switch is not passing vlan traffic? Wouldn't the broadcast traffic not make it to the proper interface considering the vNIC is tagged/switch doesn't know what it is?

also there is no helper or relay setup



Site-to-site fully redundant (2+ ISP & LTE) mesh

Currently we have about 80 active locations connected by IPSEC tunnels; we're in the process of migrating them all to IKEv2, however some of them have relatively unreliable ISPs and therefor have multiple connections for failover - and many more are considering doing this, it seems to be a hot idea especially after the CenturyLink outage.

IKEv2 does not support this, though in some cases we have found a workaround using dynamic SNAT and multiple VPN configurations - another option would be route-based VPN meshing, though I worry about the complexity of maintaining that for 80+ locations.

Are there any better (simpler?) alternatives?

One that came to my mind would be to use WAN load balancing/failover, which seems to work fine, alongside something like a site-to-site OpenVPN tunnel. Less configuration, anyway. But I'm not sure if that would be more or less reliable than a full route-based VPN mesh.

Our main datacenter uses Cisco ASA on the edge, though we could also host whitebox software as an endpoint if needed, or get additional hardware. On the client-side, they run run either ASA, Fortigate, or Sonicwall, though we would be open to requiring additional hardware for the use of multiple ISP links. The SonicWalls support add-in cards with 4G, which we'd like to experiment with as well. In any case, we'd want our endpoints to be redundant as well (ASAs are in a HA cluster).



Inside wiring/low voltage in/near Bristol, IN

Looking on behalf of a customer. Warehouse/distribution center stuff.

Thanks!



Aruba IAP upgrades

I have a simple question that I can’t find online. I found the Aruba how to upgrade IAP with out airwave guide but it doesn’t state what happens to the cluster when I hit upgrade now.

Here what I think I should do.

  1. I log into the master VC AP.
  2. Backup configuration / certs
  3. go to maintenance > firmware > upgrade now Does this upgrade now button only do the current AP or the whole cluster. I would hate to log in 10 times to upgrade APs. Then would the VC only upgrade one at a time or does every AP at that moment. I know airwave has some slow roll out feature to limit WiFi downtime. I don’t know if the IAP do the same thing.


Multimode Fiber - OM5

Hey,

Once again I'm here to try to obtain some information, now about OM5.

​

Here is what I know now:

​

-OM5 will be part of TIA-492AAAE and are in ways of being published as IEC 60793-2-10

​

-OM5 supports OM4, aswell as OM3, meaning it is interconnectable

​

-OM5 is designed to support at least four low-cost wavelengths in the 850-950 nm range, enabling optimal support of emerging Shortwave Wavelength Division Multiplexing (SWDM) applications that reduce parallel fiber count by at least a factor of four to allow continued use of just two fibers (rather than eight) for transmitting 40 Gb/s and 100 Gb/s and reduced fiber counts for higher speeds

​

-OM5 color : Lime

​

- Support of 100GBASE-SR4 Ethernet and 32G Fibre Channel applications across the whole wavelength range

​

- When paired with single wavelength (i.e. λ = 850 nm) transceivers, e.g. 40GBASE-SR4 and 100GBASE-SR4 with an MPO interface, OM5 supports the same reach as OM4. In other words, OM5 parallel cabling does not have a clear advantage with these types of transceivers

​

So my question is, what exactly does OM5 have in advantage over OM4, and why is it something that a lot of people are giving such importance?

​

If you can help me please do.

​

Thank you all.

​



Sunday, December 30, 2018

Strange Issue on network and Hyper-V

If not allowed please delete.... and I apologize!

TL:DR: Looking for a Cisco/ASA/Hyper-V expert to assist me and my colleague remotely. Obviously, I will pay your rate.

I am not sure where else to turn for this, but I am pulling my hair out over this and am getting nowhere.

I have three Hyper-V servers sitting being a Cisco switched network. The original Network Engineer who designed this network put the hosts on the public net, VMs on the public net... etc... it is a total mess.

Well we were told to cutover to a new network... which includes adding those servers and NATting the DMZ...etc... There is no way we could make it happen due to the off-the-wall bindings in each host/vm.

So without trying to bore everyone to death... I am trying to find someone who is a Cisco/ASA/Hyper-V expert who would be willing to help me get things going again. I am willing to pay whatever hourly rate... Please remove/lock if this is not allowed but I am at a total loss.



Question about Management Network

Sup, r/networking?

So, I've been involved in a project which has the setup as illustrated here: https://i.imgur.com/WPpXWsO.png

Basically a Catalyst 3850 is gonna be the L3 boundary for the internal network (including the management network, as in all default gateways are on this switch) and the pair of PA acts as the Internet gateway, doing NAT and security stuff. SVI for VLAN 100 (TRANSIT), 101 and 102 (DATA) and 420 (MGMT) are created on the 3850.

Now all data networks are working fine, there's a transit VLAN used between the firewall and the 3850 (as the 3850 cannot have sub interface, I've reconfigured the existing link between them as a trunk, shown in the diagram) and all servers in VLAN 101 and 102 can manage to get to the outside.

The question is: The core switch is being managed using any possible IP on it. Now I want to restrict the management of the core switch only to the IP address that I assigned on the OOB management port (not SVI 420). Problem is, that port belongs to a separate, factory-created VRF which cannot be assigned to other interfaces. I've come up with this setup so that there's a path to the OOB management port and I personally think that since this is a L3 port, it shouldn't create L2 loop.

However, is this ever a good design in production environment? What's your opinion on this?



Sourcing outdoor CAT6a

Looking for outdoor rated CAT6a for some runs to new outdoor POE cameras being installed. Customer is kinda picky, so I was hoping to find white cable (so it doesn't stand out against the outside of their building). Some short bits will be underground, so rating for direct burial would be great. Monoprice was more limited in selection than I expected. Where do you guys source your cable?



CORE Network Emulator

Apologies if this is very common knowledge, but I just discovered CORE Network Emulator and I wanted to let you guys know that this exists.

Some background:

I don't have a huge complex network. It's pretty small with just a few sites, 6 or so WAN/BGP routers, and a bunch of ospf routers inside the data centers (we're doing a purely routed underlay with "routing on the host"). As we move away from bridged network designs and to all routed, I wanted a way to document everything well for the rest of the team, as well as a way to emulate the routing processes and test routing changes, review propagation/etc in the test environment before applying to production.

I was annoyed with GNS3 because it's pretty heavy for what I wanted to do. I really have no need to run full router OSes to test these things. I only needed to emulate the routing processes and configuration. I also didn't really want a bunch of VMs running on my laptop or to have to setup a dedicated server for this.

On the diagram note, I was using draw.io and gliffy and hated my life. So with the expectation that I'd have to compromise on some things, I began searching for solutions to these two problems, with the following (collective) requirements:

  • A network diagramming tool, but one where each device and link is an object to which I can add attributes and configuration details which are normally out of view, but available by clicking on an object.

  • Something free to use for personal or otherwise. Bonus for open source as well.

  • A routing protocol emulator or simulator of some sort, allowing me to create a configuration replica of our networks (don't really care the OS or syntax, just want to be able to functionally mock the protocol configurations) and test routing changes.

  • Preferably self contained, or at least not a bunch of VMs for which I need licenses and have to configure an entire OS for each device.

  • The diagrams or test configurations can be created and modified via both a GUI and text files, so I can version control them and make quick/scripted bulk edits.

  • Runs on Linux at least, bonus points if Mac as well.

So I came across CORE. I wasn't at all expecting to find something that met all these requirements in a single tool. But it does.

It runs on Linux, and spawns quagga inside LXC containers for the routers, and uses Linux bridges for switches. I believe the GUI can be run on Mac and talk to the daemon running on a remote Linux machine or in a headless VM. Since it's using containers, starting and stopping the emulation is extremely fast. Once it's running, you can get a shell inside the containers to observe or test live changes, and you can collect data about the whole setup with the built in tools. It's also scriptable in Python, so the whole [setup, generate fake traffic, monitor, teardown] process can be automated.

I don't think it's really intended to be a diagramming/documentation tool, but as far as I can tell so far, there's no reason it doesn't fit that purpose as well.

I'm thoroughly impressed so far. I'm curious to hear about anyone else's experience with using it.



Remote side jobs?

Does anyone know of any companies that are looking to recruit experienced network engineers for part time remote work to help supplement income on weekends or at night?

I have 10 years of experience supporting Enterprise networks and want to be able to leverage my time that I am not at work to earn extra money for the family. My current gig doesn't offer overtime pay and doesn't demand I work overtime. So something 2-4 hours for 2-3 days a week would be nice.

What I had in mind was supplementing existing operations teams that may be underwater with tickets and needs a hand. I don't know if that type of demand exists or not.