Tuesday, October 15, 2019

Disagreement in performance results

So we have two separate connections. An ethernet ATT 100/100 and a lab network provided by the enterprise which is part of a MPLS circuit that goes from our site to STL and then to charlotte to hit the internet. It’s 300Mbps to STL and supposedly 1Gbps to Charlotte.

We are having major discrepancies in performance and aren’t getting good answers from the enterprise. Anything we download from major provides on our ATT connection we get a static 100Mbps/100Mbps up down. So for example I’ll do a iperf to iperf.he.net and will get like 97Mbps.

Doing the same tests on the enterprise connection we will get anywhere between 2Mbps and 15Mbps. It will bounce all over the place.

I’ve tested multiple sources (softlayer, att, dslreports, google, etc). Every single one I’ll get around our 100Mbps on our att connection and then again on the enterprise connection it will be all over the place and jump from a couple Mbps to 20Mbps. Usually on average I’ll get 3-4Mbps.

I’ve told them that it’s basically unusable for us. They keep saying nothing is wrong and quote that our TCP windows are too small or they run a UDP test between their sites, get line rate and say nothing is wrong.

I’ve validated that the TCP windows aren’t the problem as I’ve checked it and it will be 1-2MB in size for the TCP window size and a RTT of 50-80ms. This would give a theoretical max of 150Mbps...which shouldn’t be limiting it to 3Mbps avg. As for the UDP testing i’ve told them it’s not apples to apples, isn’t a valid test and won’t explain why I’m having the issues I am.

Is there anything I can do on my end to push them into the right direction?



External 56k modem

Hello everyone,

Can you recommend some external 56k external modem model from some manufacturer that is not in End of Life?

Need: Connect a 56k line on external modem, with LAN output to connect to a Fortigate

Thank you.



NSX vxlan segmentation with ESG/DLR

Hi, Now you i'm going to try and ask here, since i did not recieve an answer over at vmware, so here it goes. So we run a basic datacenter setup, where each customer has their own firewall and a few vlans. So to make the things short, we want to run NSX with VXLAN and DLR/ESG. How do you guys make segmentation with VXLAN and DLR? I want to run BGP in the core, to route between the VTEPS and the ESG. But the only idea i can think of to keep each customer seperated, is to put each in their own VRF. What do you guys think, or is there even a better way to do this? Thanks!



What should I study next?

Hello guys, I am here hoping that someone is going to tell me which path is best for me to take.
First let me tell you, I am 24 year old guy, just finished college and got my first CompTIA Network+ certificate. I am working as a trainee (I am working and studying to become network engineer), my job for now is mostly "physical layer". I am setting up switches, routers, access points, testing connections, doing site surveys, creating heat maps, working on making data centers with my colleagues from scratch etc.

I already told you that I finished Network+ exam, and I liked it , theory is good and it is not an easy exam, but I want something more practical that would help me tommorow in my job. Let me say it like this, I dont care about certificate because I want to know how to configure routers, switches, access points when you put them on my table, and God know that in my 3 month work experience I saw a lot of people who have some CISCO certificates but If you tell them to go and configure that and that switch their faces would change color because they dont have any idea how to do that. I want to start studying something like Cisco Packet Tracer which would help me understanding more complex things etc.

So my question is, from your experience what should I take next? I was thinking to buy something on Udemy.com so I can study while I train in the same time? Any suggestions?

Btw sorry if I made some grammar mistakes, english is not my native language.



StrongSwan profile with cyberghost

I was wondering if anyone can give me a hand setting up a connection. I'm currently using cyberghost vpn and every time i try and put the server IP address I'm using to set up a stringSwan profile on the android app, it just constantly says error and keeps trying to connect. What am i doing wrong here?? There's another option to input a VPN host server name but I'm not exactly sure what that'd be.

I don't have a lot of experience with these kinds of things as you can already tell.



network scanner for default gateway of each device

Hello, I know there are many posts about network scanners. But I couldn't find one which gives me the default gateway of each device. Does something like this exist?



Access edge hardening - we got pwnd

Guys,

Large retail business with alot of public facing IT equipment in its branch sites.

We recently had an internal-pen test that involved social engineering and the full 9 yards - long story short the pen-test team managed to connect a rouge device to the network - packet-capture, harvest creds - elevate to domain admin (at multiple sites.)

We have actions coming out of this and I think one of the biggest weaknesses from a network standpoint we have is the lack of segmentation and switch-port access controls. We are already working on a piece of work to segment the network properly at these retail locations (currently we have third party's in vlans with corporate devices, high privilege vlans in public facing areas) its a real mess, luckily there is a focus on security now, hence the pen-testing.

I know there is no security silver bullet - but is there anything we should really look into to help us? 802.1x cetrificate based authentication at a switch-port level has been mentioned and is something we had on the back-burner for a while (although, alot of the equipment is public areas is third party equipment not on the domain - I know there is MAB etc) - sticky macs? automatic shutdown of unused switchports?

ideas appreciated



NSX

Hello all,

I am a new member and I would like to find out more about NSX does anyone has a good free materiel to do self study please?

Thank you for your help.

Regards,

Shahen



How to tell total tcp segment length.

I'm wondering how to know what the total segment length is without looking at the ip header. TCP only has a header length field and a maximum segment size. Say the maximum segment size is 1000 bytes. I can still send a payload size of 500 bytes, so then there would be no way (as far as I know) of telling the size of the data or total size of the TCP segment.



I was wondering why in the book Kurose and Ross computer networking Top-Down Approach they don't get into the Physical Layer ?

The book is very good in my opinion and gets into the other layers in details. So why The physical layer don't get that much attention ?