Monday, August 19, 2019

Help deciding between a Cisco Meraki MX64W and a dedicated PfSense PC converted to router with multiple lan cards

Hello,

I am wondering what offers better performance for 50 heavy users between the Cisco Meraki MX64W and a PfSense computer converted to router with multiple gigabit lan cards.

We have a 200mbps dedicated connection from our ISP.

We would like to have firewall security, access control, bandwidth monitoring and website and application access control.

The vendor promises me that the Cisco Meraki is the way to go, but I have my doubts.

Thanks for the advice!



L3 switch - subinterfaced routed port not working but L3 SVI does?

Weird one. I put a stack of c9300's into service last week, did 'no switchport' on the uplinks to core routers, subinterfaced etc but only one of the uplink ports worked. These are 8x10g SFP modules.

I went back to site today and changed the uplinks to trunks, and put a L3 SVI on the switch instead and it worked first time.

Before that I changed the modules around, swapped the sfp's, changed fibres etc with no joy.

I know behind the scenes a routed port Vs a vlan svi is the same thing, but any ideas why this wouldn't work with subinterfaces?



Where do I need to look to find Elastiflow log information?

Hello, I installed Elastiflow following the steps outliner here:

https://www.catapultsystems.com/blogs/install-elastiflow-on-ubuntu-18-04-part-1/

​

I believe I have everything configured correctly but I am not seeing any data on the Elastiflow dashboards. I can't find the log file that shows the data being received by Elastiflow. Does anyone know what file I should be looking at to verify that traffic is at least being received?

​

Also, does anyone by chance have a better resource that goes over installing and configuring Elastiflow? I'm having a hard time figuring out what I'm missing, so any help is greatly appreciated!

​

thanks



Have you ever seen CDP send different IP info to different neighbors?

I'm working on some discovery/automation stuff for Catalysts, would like to know if it's reasonable to use the management address advertised by CDP as a key for uniquely identifying each switch.

I don't think I've ever seen a switch send different IP addresses to different neighbors. Have you?



Secure Remote Access architecture

Currently, our environment is using AnyConnect for remote access. We have an ASA at our perimeter which terminates the SSL connections. My company is starting to focus on updating and securing our enterprise architecture and are happy to put some money into it. I am brainstorming some solutions and just curious if there is a consensus on remote access design?

We are starting to implement Palo Alto's so my idea was to replace the ASA with the Palo and create a new remote access DMZ. I could then place an ASA or router for VPN termination and further restrict traffic.

Would it make sense to do SSL decryption and inspection on the Palo Alto sitting on the perimeter? Or is it best to use a dedicated appliance for this?

Would a Web Security Appliance be suitable here if I have a Palo Alto already doing the inspection/url filtering?

I've also seen designs where enterprises are utilizing dual firewalls (External/Internal). This seems it would be the most secure but I'm curious if anyone has any experience implementing this solution as it seems it could be more complex.



Question about replacing a 2U Patch Panel with a 1U Patch Panel

I've been tasked with replacing a 2U Patch panel with a 1U Patch panel and can't find information on if I will have to do punchdowns on the backside or not.

Is it as easy as unplugging cables, unscrewing the front of a patch panel, screwing in a new patch panel front, and then plugging cables back in?

I feel like it's not, and that I will need to unwire every cable on the backside, then re-punch them down.

Any insight on this would be very much appreciated!



Help Understanding HTTP(s) Request Latency through NLB to on Premise Server vs Directly through Firewall

I have the following scenarios (we are located in a data center in Chicago):

  1. AWS Network Load Balancer in US-EAST-1 listening on 443, forwarding traffic over port 8443 to an on-premise Nginx reverse proxy listening on 8443 (and 443). We have an AWS direct connection as well.

From my understanding (and verifying using packet captures), traffic goes... client (azure) -> aws-us-east-1-nlb:443 -> internal-reverse-proxy:8443 -> upstream server. response is the same but in reverse

  1. Firewall in our Data Center with static NAT enabled for our internal reverse proxy server for port 443.

traffic goes... client (azure) -> firewall NAT:443 -> internal-reverse-proxy:443 -> upstream server. response is the same but in reverse

I am using https://github.com/apigee/apib as my http(s) benchmarking tool, and the command I am running is:

apib -d 10 -c 50 -t application/json -H "Host: REDACTED" -H "Authorization: REDACTED" -x POST --csv-output --name "REDACTED" https://REDACTED 

Every single time I test, it doesn't matter the location of the client I am testing from, AWS always seems to win, and I just cannot understand how or why.

I used an Azure free-tier account to spin up an Ubuntu 18.04 server in US-SOUTH-CENTRAL location (Dallas, TX), and here were my results:

Client Server Throughput Avg. Latency Threads Connections Duration Completed Successful Errors Sockets Min. latency Max. latency 50% Latency 90% Latency 98% Latency 99% Latency Latency Std Dev
DallasTX FirewallDirect 166.039 594.611 2 100 30.029 4986 4986 0 100 174.797 921.127 592.297 692.909 794.512 855.213 85.196
DallasTX FirewallDirect 185.297 533.783 2 100 30.022 5563 5563 0 100 192.812 997.528 512.197 672.711 779.978 808.828 101.795
DallasTX FirewallDirect 203.451 487.400 2 100 30.027 6109 6109 0 100 173.641 1052.452 477.83 620.199 709.733 747.05 99.43
DallasTX AWS-US-EAST-1-NLB 194.637 508.742 2 100 30.025 5844 5844 0 100 272.026 832.814 492.759 650.240 716.850 732.909 95.55
DallasTX AWS-US-EAST-1-NLB 189.954 519.970 2 100 30.023 5703 5703 0 100 265.800 965.367 504.867 665.015 754.291 818.146 100.296
DallasTX AWS-US-EAST-1-NLB 183.496 541.257 2 100 30.022 5509 5509 0 100 310.584 933.735 522.065 673.488 794.933 835.227 94.65

Can someone help me understand if I am missing something when testing the above? I just do not see how AWS can have request/response latency that is, in some cases, better than making requests to our server directly through our firewall in Chicago when sourcing from a client in Dallas, TX. Is there something I am not understanding or failing to account for in this scenario? I know the firewall now has to process the NAT traffic but that should be failure trivial and we have a pretty powerful firewall fronting our services.

Traffic for using AWS would have to go.. 1. Dallas, TX -> 2. Northern Virginia -> 3. To Chicago -> 4. Over our Direct Connect -> 5. Get processed internally -> 6. Request gets sent out to AWS NLB and sent to client.

Traffic for using NAT on our Firwall would go... 1. Dallas, TX -> 3. Chicago Firewall -> 4. NAT'd to internal proxy and processed -> 5. Sent back out to client

The latency from Dallas to US-EAST-1 is about 29ms (taken from https://www.dotcom-tools.com/internet-backbone-latency.aspx) and the latency from Chicago to US-EAST-1 is about 42ms (taken from https://www.cloudping.info/, I am located in Chicago) giving a total latency of about 71ms in just travel time.

The latency from Dallas to Chicago is close to 39ms (pinging from my VM in Azure to our firewall).

Assuming time to process the data, I should see results where it is about 30-40 milliseconds quicker to use our Firewall directly for NAT instead of AWS in US-EAST-1 for a client located in Dallas.

Additionally, even testing using Azure NORTH-CENTRAL, I get the exact same results as above, the latency is the same for using US-EAST-1 and just using our Firewall directly (for NAT). Ping between Azure NORTH-CENTRAL and our Firewall is just 2 milliseconds, so I would expect to see using our Firewall directly for NAT to be about 70 milliseconds quicker, but its the same as AWS (average request time).

Can anyone help point out if there is something I am missing or not taking into account when doing these tests? I just don't see how my testing is showing AWS to be comparable or better than hitting our Firewall directly for NAT.

Thanks



Using SPAN/Port Mirroring for production

I recently came across an environment where there was permanent SPAN set up on switches to accommodate required features of a system they were running. Basically if the SPAN was turned off their records and billing system totally broke and assigned all their customers a $0 bill. They had a problem where some transactions weren’t being captured by their records and billing system, and the reason ended up being oversubscription of the SPAN output port.

Thinking this was surely some hucklebuck solution, I spoke to the vendor and confirmed this was their official way of doing it. They also required customers on purchase to buy their switches which were already pre-configured, but they finally admitted that other vendors were supported so long as you SPAN’ed the correct ports.

This was at a big name national company too, not some little mom and pop shop. The system they were running is quite old, but the vendor is keeping it in support and continues to update it exclusively for this customer.

Not really asking a question here, just thought I’d share since I hadn’t encountered this before.

What other examples of a “feature” like this have you guys ran into where a vendor used the network as a crutch?



Announcing same prefix out two different datacenters

Imagine the fairly common scenario quickly depicted here: https://imgur.com/N2wbwl2

​

I want to announce the same publicly assigned /16 out of two datacenters. The datacenters are connected with dark fiber and run OSPF as the IGP.

​

Do the two routers need to be connected to each other via a layer 2 link or a GRE tunnel for this to work (in addition to iBGP of course)?

​

I tried to convert a router to strictly layer 3 over the weekend with no L2 or tunnel between the two PE's and all heck broke loose. After doing some research, I believe it's because I broke the layer 2 connection between them (because I want to rid myself of all unnecessary layer 2 in the network).



IP log for mobile phones

Hello, we have an issue in our company that allowed a virus to sneak up on our smartphones. Is there an app to log the ip addresses the phone pings to so that we can investigate this further? Thank you for the help already.