Wednesday, March 13, 2019

Enterprise Hospital Network - UPS's

Good afternoon! I am curious how any other organizations support their edge/user switches with UPS's? What UPS do you use?

We support an enterprise hospital network with clinics and remote sites and are thinking of removing our UPS's from sites that have a single source of power (i.e no generator power) in an effort to reduce implementation/maintenance cost (UPS/battery refresh programs). We are using Juniper EX series switches with redundant power supplies.



Question on Identifying an IP range of a specific location

Hello! Disclosure: New here, and a noob but i did read the rules!

So here's the scoop:

I'm wondering what the best way to determine an IP range at a specific location, where an upcoming tradeshow will be held. We are trying to provide attendees with free access to our web service via an autologin based on IP of the wifi service at the venue.

Is this possible?

Happy to provide extra info! Thanks in advance!



Uk guy needs someone who has networking experience

I'm just putting this out there as I'm at the end of my tether , I've recently purchased a third party router ( netgear r7000) and separate modem ,done the research and it seemed an easy enough task even for a novice like me !!! How wrong I was !!!I now have equipment I can't set up and nobody to turn to for help ,isp obviously gave me username and password but that's where they stop , as you guess I've followed the netgear setup genie and keep hitting problems ,is there anyone out there willing to be patient and talk me through this headache, Thanks for reading people



Enable Port Mirroring at a Bank?

My client is a bank and today the CIO told me the ISP wants to configure port mirroring on the switch so they can monitor bandwidth. I explained this was a terrible idea but wanted to see if anyone else has heard of ISPs doing that for sensitive data such as bank or medical .



Cloud VPN?

Hello All,

I'm running into a situation that I need to plan for. We have two data centers...one production and the other fail-over. In our production data center, we have a about 20 vendors that terminate VPN tunnels on our main firewall. In the event of a disaster fail-over, we would need to swing those connections over to the secondary data center. What's the best option of accomplishing this, without calling each vendor and giving them a new ip to build their tunnel's to us? Is there a solution where I could have them terminate to a vpn concentrator that is extracted from on prem? I guess something like a global load balancer, just with vpn connectivity....



Tacacs+ and Windows AD

Hello my fellow network engineers...

So I'm running TACACS+ for our networking equipment in a Linux VM in our datacenter, and for the most part it works well and it's a good way to restrict access and provide logging info as far as what commands were entered and by whom. However, I was wondering if there is a way to integrate this with Active Directory. I've been looking online, and there seems to be a couple of ways of doing it, but all the guides basically instruct you to get the password of the user and then encrypt it using DES or MD5 and add that to the configuration file. However, I was wondering if there is a way to update this password automatically when the user changes his/her password in AD, instead of doing it manually.

Thoughts?



Need helping picking appropriate firewalls

I have a need to refresh about 10 firewalls in 10 facilities, the facilities currently are connected through IPSec site to site VPN, most have Cisco 5505 and it's all working fine , just getting up there in age.. I have little traffic between sites as there isn't much resource sharing.

I could go with cisco again, I just don't like the nickle & diming they do (like pay more to enable more than 3 interfaces, some of the 5505s had limited internal hosts etc.. the firepower lineup seems like a huge cost creep when you start adding services, SMARTnet is pretty pricey etc.. it turns into lot of gotchas now or later if you don't realize what cisco does that)

I get that you get what you pay for, but...

our budgets are very tight, I have no problem moving on from cisco if it saves some cash. My industry is very low tech to begin with, I just want reliability of the hardware.

are there any true SMB hardware providers to consider? I like GUI, I don't care about CLI as once we set them up they will sit alone for years on end (other than random change/reboot/updates). 100-200Mbps throughput would be plenty too.



python - device.send_command vs net_connect.send_command

Can someone clarify the difference for these two command options and when to use them? A link to the documentation (??) would be great. I searched all the 3.7.3 PDFs but no luck.

1) device.send_command

device=ConnectHandler(device_type=platform, ip='192.168.1.1', username=username, password=password)

com1='show vlan id 100'

output1 = device.send_command(com1)

2) net_connect_send

output = net_connect.send_command(command)

print(output)

net_connect.disconnect

Thank you,



using RJ45 SFP module only on one end

I have a CAT 4506e with a single 24 port SFP line card and a single 24 port ethernet line card. I'm running out of ethernet ports and rather than buying a new line card I'm wondering if I can instead use RJ45 SFP modules and utilize the numerous unused SFP ports on the other line card.

Has anyone done this?

Aside from SFP compatibility with the switch, is there anything else I'm missing? I would only have the SFP module on the end connected to the switch...the other end of the cable would be RJ45 into the endpoints.



Issues across multiple regions

Getting reports of issues across multiple regions and hearing others are seeing the same, anyone with additional information?

Edit: Seems to be a Facebook related issue: