Wednesday, March 6, 2019

Newb to Zabbix. Anybody have any suggestions to ease my way in?

I'm a junior net admin. The cyber-security guy in our organization has introduced Zabbix as a means of monitoring network and server stuff, but not only am I unfamiliar with this program, I'm almost completely unfamiliar with Linux in general. I'd like to download the program to mess around with it, and I've looked to do it on a VM running Ubuntu as well as my desktop on Windows 10, but with all the tarball and other Linux jargon I haven't gotten very far. Where do I start? and once I've gotten started, which aspects of the program should I look into for more of a network focus? If this is a retarded question. let me know if there's a better sub for it.

Thanks!



Why is Upload so slow? New 10G circuit

I have a new 10G circuit between two datacenters (primary and DR site). Server A is in the primary site, server B is in the DR site. Both servers are Windows Server, both are subject to the same network equipment. Using some LAN speed test software on either server the download speed is 200mb+ (Great!) and the upload is 50mb (not great!). It's a brand new link, no traffic is traversing this line besides my tests. Either direction the upload just sucks. Am I missing something here?



Small Network Design Question

Hello everyone -

I have a question on the best way to design this small network for optimal security and best practice.

We have a small network for our office. We have about 70 employees with plans to add 10 more this year, so not huge. We only have a couple on site servers for local stuff (ad, dns, etc.)

We have a layer 3 switch as the core. I have our internal networks set up on the layer 3 core and then the core has a default route to the firewall.

We are going to have a separate guest network and a few other networks that I want to lock down with ACLs so I want to do that on our firewall, rather than doing it with ACLs on the switch.

The firewall has two ten gig interfaces, one to the LAN core and one to the WAN/internet core.

Here's my question: do I add the "secure" VLANs to the 10 gig uplink to the firewall that is used for transporting traffic from the core or do I add a 2-port LAG or something from the core to the firewall that way I don't have layer 2 and layer 3 links on the same port.

We're using Extreme Networks switching VLANs on every port is how their stuff works, so typically we've been sharing our fiber links for Layer 3 transport of internal and layer 2 secure links on the same fiber. But I feel like we probably shouldn't be doing that and rather should be using one link for one purpose.

Here's kind of a simplified diagram of what I am talking about: https://imgur.com/a/95g6sO2

We're also going to be separating our guest traffic into a separate VDOM in the firewall so that would go over the same links as the other secured networks, just a different VLAN.

Thanks in advance for your suggestions!



What does a non-boundary subnet in ipv6 look like?

Obviously a 2000:1234:5678:9ABC on a /64 looks like 2000:1234:5678:9ABC:0001/64 but how does it work with like a /60 or /59?



Technical Interview for Sr Network Engineer

I have a technical interview tomorrow for a Sr Network Engineer position at a large company. I've had technical interviews in the past but always for smaller companies so I'm a little nervous about how this will go.

In the past the interviews I've had are more about how I would solve problems or maybe what something is (STP, BGP etc). This interview will be done by a third party called Derrico.

Has anyone heard of these guys? I've done some research and they seem to mostly be geared towards developers, networking seems to only be a tiny part of their offerings.

Also, for those of you who work for larger companies, how do the technical interviews normally go? What type of questions do they ask?

Thanks!



What's on your wiki front page? Or, how do you structure your wiki?

We recently bought new wiki software, and there's no way to import from the old to the new, so we'll need to re-create our documentation. Never been 100% happy with our current front page or wiki structure, so I'm curious what sorts of things other folks do.

Also, to whom do you give access to read your wiki pages? (Obviously, read-write is kept within the confines of the team.)

At the moment, we have a tree of links on our front page. Our main branches are:

  • $COMPANY network
  • NOC team (really just a list of provider contacts and portals)
  • Services we provide (we are an ISP, so Internet / MPLS / Managed Hardware / etc)
  • Processes and Procedures
  • Core devices we manage
  • Servers
  • Web Portals (mostly a restatement of bullet point #2)
  • "Documentation" (config snippets, technical descriptions of products, other administrivia)
  • Other Service Providers
  • Customers (mostly customer-specific configs)
  • Code and Programs we've written
  • Security issues and vulnerabilities
  • Processes internal to $COMPANY (mostly a repeat of bullet item #4)
  • Products we support
  • Technical Details (lists of our IP blocks, ASNs, etc)
  • Hardware configurations (more complete than the "Documentation" link)
  • Troubleshooting knowledge base

To me, the current wiki is a confusing mess of links, and to be honest I only use the search function. I don't ever try to navigate it.

TIA for any replies!



Automating forward and reverse DNS records for all L3 interfaces directly from NPM

Spent some time over the past few months looking at another aspect of network automation: DNS records management.

I started out looking to clean up our stale BIND9 zones, and ended up with a script that mostly automates the whole process, reading node/interface data from the SolarWinds NPM API and spitting out BIND9 zone/config files for both forward and reverse lookup zones.

My pings and traceroutes are much prettier now :)

$ ping example-router PING example-router-1g-te-1-1-8.example.net (10.250.20.66) 56(84) bytes of data. 64 bytes from example-router-1g-te-1-1-8.example.net (10.250.20.66): icmp_seq=1 ttl=252 time=1.69 ms 64 bytes from example-router-1g-te-1-1-8.example.net (10.250.20.66): icmp_seq=2 ttl=252 time=2.03 ms 64 bytes from example-router-1g-te-1-1-8.example.net (10.250.20.66): icmp_seq=3 ttl=252 time=1.92 ms 64 bytes from example-router-1g-te-1-1-8.example.net (10.250.20.66): icmp_seq=4 ttl=252 time=1.86 ms [austind@prod ~]$ traceroute 8.8.8.8 traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 60 byte packets 1 idf4-1g-v-10.example.net (172.16.32.1) 0.484 ms 0.547 ms 0.593 ms 2 agg1-10g-eth-2-48.example.net (10.250.20.6) 0.444 ms 0.549 ms 0.666 ms 3 pa-10g-eth-1-22.example.net (10.250.34.34) 0.616 ms 0.592 ms 0.578 ms 4 border-in-40g-hu-1-0-49.example.net (205.155.219.50) 0.872 ms 0.855 ms 0.779 ms 5 border-out-1-te-0-0-2-2.example.net (205.155.198.240) 1.504 ms 1.673 ms 1.650 ms 6 sac-agg2--but-coe-1-10g.cenic.net (137.164.50.236) 7.160 ms 6.515 ms 5.411 ms 7 oak-agg4--sac-agg4--100ge.cenic.net (137.164.46.34) 6.554 ms 7.099 ms 7.045 ms 8 74.125.48.172 (74.125.48.172) 7.528 ms 7.539 ms 7.516 ms 9 108.170.242.225 (108.170.242.225) 8.148 ms 108.170.242.81 (108.170.242.81) 7.972 ms 108.170.243.1 (108.170.243.1) 9.379 ms 10 209.85.240.169 (209.85.240.169) 7.957 ms 209.85.240.175 (209.85.240.175) 8.027 ms 108.170.232.69 (108.170.232.69) 8.049 ms 11 google-public-dns-a.google.com (8.8.8.8) 7.728 ms 7.787 ms 7.718 ms 

The codebase is premature and built around our environment (SolarWinds & BIND9), but I thought I'd share in case it's helpful.

github



10GBASE-T SFP+ Copper RJ-45 Problems

Hello community   I would love to hear you thoughts on 10G BASE-T SFP+ modules and any problems you may have experienced with them. Example module in the below link. https://www.fs.com/uk/products/66613.html?gclid=EAIaIQobChMI94aH06Xu4AIV9iCtBh04aAdDEAAYASAAEgKNA_D_BwE  

Cisco Systems do not sell them however you can purchase them from companies such as the one above who have very good reviews.  

From the reading I have done they may not be compliant to the SFP+ power specifications. 10GBASE-T solutions will consume around 4-6 Watts per port. Compared that to the 0.5-1 Watt for SFP+ based solutions.    

I have heard that these modules run very hot and was wondering what the gotchas were of using these as I’m sure Cisco would be selling them and making money from them if they could.  

My speculation is that if the modules require more power than the switch can offer you may run into situations when you have the switch fully loaded and some ports will suffer as they are not be getting there full allocation of the power. Potentially meaning that some of the ports cannot be used or because the necessary power to the 10G base T module cannot be achieved, you will have issues with the cable length you can use.

Cisco offer the 1Gb option and short 10gb twinax cables which fit within the power specification of SFP+ which reinforces my belief that the reason Cisco do not sell the modules is due to this power issue.  

Would be great to hear your stories



PacketFence...Love it or Hate it?

I am starting a packet fence eval and I am curious what people think about it?

What where the challenges with your implementation?

Would you consider using a different solution?



Force10 S60 issues

Sorry if this is in the wrong place, but I have a dell force10 S60 that I bought on ebay for $35. My plan was to reset it, program it to work with my home network, and all is good, but I am having some issues with it. I got a serial console cable, and connected to it. When I tried to log on, I typed what I found in the documentation to be a default admin name, Admin, and the previous user set a password on that account. So when I rebooted it, I interrupted the boot, and typed, I believe it was Erase All, and I think it wiped the SD card. I don't get anything on my terminal window, and the fans are staying at 100%, and doesn't boot. Is there anything I can do about this? or did I just make a glorified monitor stand?

Thanks