Wednesday, March 20, 2019

Isolating & Determing VPN's Negative Effect on Internet Connection

Hi, I am doing research into if using a VPN on cellular data is beneficial to the content-based ISP throttling. I have an effective way of speed testing CONTENT not just internet speed...

The problem I am having is I don't know how to accurately determine a definitive value on the negative effects a VPN would have on my data as a whole. The reason I need this is so I can subtract the VPN's negative effects from my estimates on ISP throttles.

Would it be practical/accurate , alone on my network, do 100 content-based speed tests without a VPN, then with the VPN, and graph the difference and form an equation? VPN speeds aren't consistent so I am unable to tell if it may have been a busy hour.



Twice Nat to a smaller subnet

Hi All,

I'm trying to create a site to site VPN between 2 ASA to a company that is requesting we NAT our local subnet to a 192.168.192.x/28. They have a lot of customers VPN into them so they provide these /28 subnets to everyone.

My inside address range is /24, I keep getting the error that the subnets must match when trying to setup the double natting. I only have 5 addresses that need to use the VPN, how can I get this NAT statement to work? Can I create 5 different static twice NAT statements to give my inside host something in 192.168.192.x range?



Eset detects duplicate IP addresses on Network, but no evidence of it?

Hey all. Entry level Networker here so excuse me for what may seem like an obvious or basic question.

I have a site using Eset antivirus, which is flagging up that there are duplicate addresses and could potentially be an ARP attack. I've logged onto the Router (MikroTik) which is providing DHCP, however there are no duplicate leases. I asked a user to send me the ESET logs, some of which is below.

-<RECORD>

Time">09/02/2019 09:10:04

Event">ARP Cache Poisoning attack

Action">Blocked

"Source">10.1.1.111 [80:2b:f9:XX:XX:XX] (Client address)

Target">10.1.1.111 [AA:AA:AA:AA:AA:AA] (Routers MAC address)

Protocol">ARP

Rule/worm name"/>

Application"/>

User"/>

-<RECORD>

Time">09/02/2019 10:57:04

Event">Duplicate IP addresses on network>

Action">Blocked

Source">10.1.1.193 [a4:77:33:XX:XX:XX] (Client address)

Target">10.1.1.193 [AA:AA:AA:AA:AA:AA] (Routers MAC address)

Protocol">ARP

Rule/worm name"/>

Application"/>

User"/>

This has happened on a few different devices, but only flags up in Eset.. Not Windows.

Does anyone have any idea why Eset may report that Router is being given the same IP address as the client?



LTE routers with good central management (also on prem?)

Hi,

Dealing with IoT stuff and mobile LTE routers a lot, and I wonder if people have good experience of central management solutions for these routers that can also be run as an on-prem solution? I've mostly experience with advantech solutions but we've also tried some other brands (sierra, option to name a few). Many seem to have a cloud-only management and I don't think I've seen a single one that has properly accounted for certificate management with integrations to VPN functionality.

Does anyone have experience of central management solutions for routers that properly deal with certificate distribution? Or even experience of central management solutions that scale well into thousands of routers in general?

People here seem to mention cradlepoint a lot, but does the central management run on-prem or only in the cloud? How big deployments do you people with cradlepoints run?



Support/maintenance contract management?

Do you guys have any solutions for tracking and managing maintenance contracts other than a spreadsheet? Before we try to create one, I was hoping to find a simple opensource tool that would let us enter contract details and set a reminder for upcoming renewals, especially the ones that require a lot of data collection about current inventory (looking at you smartnet.)



QoS on a router vs switch

If i am using a layer 3 switch instead of a router to connect a branch office to a private mpls wan am i losing any capabilities in qos? I need to ensure voice is prioritized outbound to the mpls network. The phones insert the qos markings as packets leave the handset. Why would i need to put in a router as well? Would i need a router for any reason?



Solarwinds alternatives

Hi All,

What other product you would recommend instead of solarwinds to perform network monitoring. Main requirements are: NetFlow Monitoring links and devices Configuration backup

Does anyone use Kaseya if so what is your view about this product



Rookie question : networking with multiples Routers / Gws

Hi,

(what i would like : https://i.imgur.com/UXiJifK.jpg )

I would like to optimize my MPLS network with our branch office : connect RTR MPLS directly to our ASA (which is our router on a stick) without passing by a switch.

- I focus on ToIP vlan since Data vlan works fine with both configurations

- when RTR-MPLS is connected on switch, the ipPhone reaches the IPBX easily since it's on same network : no re-routing

I know our config is a little bit weird (especially GWs ) :p

So the question is : when the packet is coming from branch, is the mainOffice RTRMPLS capable of "pushing" the packet trough ASA different interfaces and be able to reach IPBX ?

Maybe ACLs ?



Google Stadia - private network?

If anyone watched the announcement of Google’s new game streaming service Stadia, there was an interesting part where they described thousands of ‘nodes’ around the world connected directly to users but ‘not via the public internet’.

This suggests a physical private network between google servers and users ISPs... Does anyone have any idea how this might be achieved?

Game streaming requires low latency and so I can understand the concept of wanting to have dedicated network routes from Google’s servers to customers, but how is this avoiding the ‘public internet’ all over the world?

Surely even Google can not afford to install dedicated physical network connections between its data centres directly to end points within every ISPs?

Is it more likely that they have made arrangements with existing internet infrastructure companies to allocate a certain amount of private tunnelled traffic / throughout over existing fibre that is in fact used in the public internet.

Basically is Google’s claim of the connection not going over the ‘public internet’ accurate or just marketing speak? Or could it be technically true but still using the same physical fibre as normal internet traffic?



public datacentre/cloud security breaches

Hi Folks,

I'm writing a report and I'm trying to find examples where a public datacentre such as AWS/Microsoft Azure were breached which resulted in the data that companies were storing in these datacentres being stolen.

I'm not talking about say a single AWS EC2 machine being compromised but the entire datacentre as a whole.

So lets say 'Company A' were running their infrastructure in AWS, and 'Company B', C, and so on were doing the same. The AWS datacentre gets breached and all companies are affected by this.

Obviously it doesn't have to be AWS and can certainly be a lesser known public cloud platform.

Thanks for you time!