Wednesday, May 22, 2019

AF24 and Catalyst 3650

Hello,

I have done some searching on the subreddit and found this post: https://www.reddit.com/r/networking/comments/89ia2a/ubiquiti_airfiber_duplexspeed_issue/

It appears as though the solution was never posted. So I will ask again rather than cast raise dead on that thread.

We have a newly installed AF24 bridge that runs down to a 3650 on each side. One side is negotiating at 1000/full and working as expected. The other side is negotiating at 1000/full but I am getting tons of CRC errors and very low bandwidth. I have gone into this side of the bridge and set it to 100/full on the switchport and on the AF24 on this side and it works at 100Mbps. I searched around on ubnt.com and found a bunch of articles with people claiming this same problem: https://community.ubnt.com/t5/airFiber/AF24-CRC-errors/td-p/2524778

But alas, no answers. I am currently trying to replace all the layer 1 hardware as it was put in by a vendor who swears it's all good. But I am not sure what else to check. I might start with swapping the injector first actually.

Has anyone run into this? It seems that most people are just hard coding 100Mbps and operating at that speed. However, we need to the ability to get over the speed. Any tips or advice would be very helpful. Thanks for your time!



Random Multicast storms

In the past 12 hours from 8 PM to 8 AM, there are two entries in my router logs for Storms. One Multicast storm at 3:47 AM and a Broadcast storm at 5:12 AM. As far I know no one was in the building.

We have 5 access points. One port has only an access point connect, that port reported the Broadcast storm. (the other affected port has a switch and an access point connected to it. The switch does not have reporting. I am planning on upgrading it).

Does anyone have an idea what could be causing these isolated incidents?



Satellite internet questions

Hey. I need to do an emulation of a satellite link, to test an app I'm working on. I have found plenty of emulators and they also explain how to set up the network. But I can't find a good source that can help me know some of the specs I need to put in the emulator. In other words: where can I find the average packet loss, jitter, packet reordering, corruption and other specs that can help me setup the Simulator. I found the latency and bandwidth for the Geo and Leo sat but couldn't find the other specs.

Thanks for your help.



Inter area routing OSPF

Hi!

I'm trying to model an OSPF network and I'm not able tackle this issue.

Imagine that I have three areas: 1, 2 and backbone. Also that I have only two ABRs. One ABR-A belongs to the three areas and ABR-B to the backbone and area 2.

If I want the path between a router in area 1 to a router in area 2, is it possible that the path would be Router-1 - ABR-A - ABR-B - Router-2?

Thanks guys



Help! Nexus 9K VXLAN - VTEP Through SVI?

Hey folks, having an issue that doesn't seem like it should happen and wondering if this is a design requirement for VXLAN or a bug, hopefully someone has seen this before.

I have two Nexus 9Ks (N9K-C93108TC-EX) on NX-OS 9.2(3). This is a lab setup. I was doing a proof of concept of VXLAN through an ASA<->ASA IPsec tunnel and got everything working. I am using BGP as an underlay for L2VNI. Each N9K has a routed port on a VLAN behind an ASA, with the ASAs static routing the Loopback IP to the routed interface of the N9K. Then each N9K has the VXLAN network off an access port. I wanted to add something else into my lab environment (unrelated to VXLAN: BGP route-based IKEv2 tunnels and AnyConnect). The rub was I wanted to push another VLAN to one of my N9Ks and tried moving the routed port to an SVI and then trunking that VLAN. All of a sudden I lost end-to-end connectivity through VXLAN. Loopbacks can still hit each other, and I can even see the end devices advertised correctly in show l2route evpn mac-ip all. I ripped the config apart and also tried setting the port on the N9K as an access port to my SVI, still no dice. As soon as I change the access port to a routed port and move the IP from the SVI to the port I get connectivity again. It's bonkers because all of the control plane works for the underlay. Please tell me I'm missing one command somewhere.

Topology:

https://i.imgur.com/vQ2TSXO.png



SFP Case

How do you guys store your SFPs? We have tons, and I'm looking for a better solution for storing them all rather than the plastic trays they're shipped in.

A hardened briefcase with little slots for them would be ideal, but I can't find anything of the sort.



ASA VPN: Configure VPN Settings per AD Value?

I'm trying to think in a security perspective how to separate my departments from having shared resources via VPN. In our LAN environment, certain subnets block certain actions. However our VPN pool has access to a every resource everyone needs. So network operations vs customer service is now the same routes available.

I noticed in our ASA I can assign LDAP attributes to ASA attributes. Is there a way I can say per OU department to specify what IP pool and route policy is sent to that device?

Ideally I'd put "The only thing allowed in/out of the VPN Pool is RDP to your desktop" but a lot of groups are going laptop-only and they take those stations home with them, so we're like 5% remote worker and 95% on-net now. I've tried to search (Maybe the wrong keywords) what this sort of thing would require. Any guidance would be appreciated!



Need Advice/Input (switch and mesh)

I am not used to Ubiquiti. I've just heard about it in the last few months from a friend who owns a telecommunications company and just switched from Netgear to Ubiquiti. I am not too familiar with networking, but know enough to set up things like a VPN, IP, Ports, etc.

I am switching jobs to a small company that currently has 1 router and a few extenders (no hard wire in any office). I am looking at getting a switch and run some CAT6 to some offices/rooms, and plan on adding a few IP cameras in the future so I'll need POE.

Right now, the budget is limited so the cheapest route to get what needs to be accomplished for the next few years (we can upgrade later if need to).

My friend recommended the 24-port POE 500W switch, but it's currently too expensive for us and overkill for what we have right now.

Our current need is/usage will be:

9-10 Rooms hard wired
Mesh Network (decided between Google Mesh or Linksys Velop) - so add 3 wired connections to this
Then whatever we have left for IP Cameras (it's not a big area)

So I'm thinking 16-port is plenty. I don't know if the wattage matters that much. We'll probably need managed.

With all that being said, I'm looking at the EdgeSwitch 16-Port Managed 150W.

Does the EdgeSwitch + Google Mesh/Linksys Velop sound like it'll get the job done? Or is there another switch that is cheaper and will do just as good of a job? Any thoughts on Google vs. Linksys? (The building has concrete walls in some places and two stories, but isn't very big.)



VLAN Question

I'm trying to get VLANs to work properly on the following equipment: WatchGuard T15 Firewall and Netgear Prosafe Manage switch (GS108PE)

VLANs are working correctly on the WatchGuard. I can plug directly into the Interface and program to any VLAN I want. The issue is trying to assign VLANs to the switch ports.

I believe the issue is with the Trunk. I am using port 8 for the Trunk.

VLAN Memberships:

VLAN ID Port Members
1 7, 8 (Port 7 is unused)
4001 1, 8
4002 2, 8
4003 3, 8
4004 4, 8
4005 5, 8
4006 4, 8

VLAN port is Untagged, Trunk is Tagged.

Firmware: V2.06.03EN

Also, when programming the PVIDs for the ports, I can only select 1 PVID per port. So I have Port 8 set to PVID 1 (Tried 4001 to no avail).

Is there something blatantly obvious that I am missing here? I spent a solid 3/4 of my work day yesterday trying to get this to work. Does my uplink/trunk need to be a part of every VLAN membership? Any help would be greatly appreciated!



Free OTP Servers?

Hi Guys,

Can anyone point me to any free radius servers I could deploy for OTP soft-tokens using the google authenticator algorithm ?

I know free-radius is available however this looks very cli driven - our service desk will be administering the creation of otp tokens and resets so Im looking for something a bit more web driven if possible for them?

Ideally I would be looking to deploy a proper enterprise grade, supported solution however some project budget "oversight" (nothing to do with me..) has forced us to look at leveraging free / open source software. - I've just been told to "get it working" :(