Monday, November 4, 2019

Troubleshooting Client connection (mac filtering enabled)?

Hi All, I'm troubleshooting a case in where Guest client can't access the portal from it browser, The AP is in local mode so traffic is passing thru capwap tunnel and we are filtering using external server ISE. Now, this setup works before then the issue pops up today that all client can't authenticate.

From client, we can able to get an IP and from AP and can resolve the portal address but can't fully access the portal and it has no display on guest client browser.

Note: this is Cisco WLC and APs.

Question:

  1. Can guest-client can ping the captive portal using the ip address given by the WLC?
  2. Should the WLC can ping the portal server using the interface of guest?
  3. What other this to check?

State is:

Client State..................................... Associated

Policy Manager State............................. CENTRAL_WEB_AUTH

AAA URL redirect................................. https:xxxxxxxxxxx

From Debug mac address client:

*Dot1x_NW_MsgTask_5: Nov 04 13:13:53.571: [PA] 1x: EAPOL frame with dst MAC 00:ea:bd:b1:71:20 and BSSID 00:ea:bd:ae:ab:40 discarded

*Dot1x_NW_MsgTask_4: Nov 04 13:17:24.185: [PA] 1x: EAPOL frame with dst MAC 00:ea:bd:a6:03:60 and BSSID 00:ea:bd:b1:84:e0 discarded

Thanks



Tagged or Untagged Ethernet Circuit

Just want to check with you guys if there are any advantages getting a circuit tagged instead of native. We have about 50 MPLS circuits and deliveries are not pretty consistent. Some ethernet circuits go native and some are configured with dot1q tag. The only thing i can think of using a tagged ethernet is the CoS field on L2 but our L3 ToS byte is being marked anyway. Getting the circuit tagged also adds 4 bytes additional header. Which is the better way to go for MPLS connectivity then just to keep things consistent moving forward? Thanks!



SYNFLOODs from AWS & other networks (Germany or hole Europe)?

Hi,

we are seeing on quite every public-facing machine in our globally routed network and some virtual machines in other networks in Germany not a small amount of syn floods (~100p/s per host) from mostly AWS (and some shady eastern europe) network(s) [1]. All requests are for now directed to 22, 80 and 443. The strange part is that I receive these "floods" also on my private (v)servers and my private internet connection.

Are you seeing the the same and has anybody information about these "flooding"?

best

xiconfjs

[1] some ips/nets (last 2 are the most active for us at the moment):

15.188.114.169 18.194.17.219 18.194.215.113 18.195.147.11 18.196.170.235 3.123.162.208 3.124.47.62 35.156.142.87 35.157.170.112 35.158.151.206 35.158.181.227 35.181.112.118 35.181.148.1 35.181.157.89 35.181.22.141 35.181.68.5 35.181.94.139 35.181.94.228 52.47.129.237 52.47.134.78 52.47.91.32 52.47.99.88 52.57.110.116 52.57.70.66 52.58.106.101 52.58.44.203 52.58.75.133 52.58.140.144 52.58.140.147 


Mesh WiFi

What’s the best Mesh Network system you can buy as of now? I hear Eero is the best. I know WiFi 6 is out there.



The JCAT Signature LAN – A $1,000 Ethernet Cable

Came across this article on the interwebz and I'm considering a move from enterprise to the audiophile networking business.

https://audiobacon.net/2019/11/02/the-jcat-signature-lan-a-1000-ethernet-cable/

Thought it was worth sharing on /r/networking :)



Ubiquity Firmware with mandatory device metrics

Since some people here might be using the products from Ubiquity for small installs / branch offices I wanted to share this, because the fact and the way ui handled this honestly shocked me.

Ubiquity has included a phone home "feature" in all their devices in their new firmware. This "feature" transmits all of the device metrics, including sensitive data like type and time of all connected devices, first 8 digits of the MAC addresses, transferred data amount and speed.

And no this is not optional or connected to the automatic firmware update feature. ALL devices with the current firmware do this! Eaven if you block the access points but still have a USG - it collects the data from them circumventing the firewall.

  • But the way this is handled by the company is even more horrendous:
  • They didn't post a note in the changelog sneaking this "feature" in
  • They made it mandatory ( no option to turn it off)

Here is a link to a thread detailing some of the ways they messed up

https://community.ui.com/questions/UI-official-urgent-please-answer/14259289-e4c3-4c5e-aaa0-02a5baa6cbbe?page=4

Honestly I don't trust the company any more and as a result will not use their product in any new installs.

Also I have to inform some people here that their new policy is not compatible with European data protection law and thus their network needs to be significantly - imagine their joy in that...

At least all be warned not to update to this firmware since downgrade is difficult and at the moment the only short term solution



Sunday, November 3, 2019

Is anyone selling their Cisco equipment? Message me

No text found

Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.



Aws vs ccnp

How it's difficult to switch your job as ccnp network engineer to as aws?. Confusion is that which is the best for the future?.



OOBM design brain fart. cant route.

Hello network gods.

building up a new greenfield and spending some time making a robust OOBM between two sites.

need guidance as to what i'm doing wrong..

Two sites, Two OOBM switches in each site. L2 and L3 within each site. L3 OSPF between sites.

Attached is a diagram of the design and current config.

Im having issues being able to route from one site to the other. Site 1 being 10.x.18.0/24 Site 2 being 10.x.19.0/24

Anyone able to point me in the right direction?

Diagram: https://imgur.com/a/9BP7lTO

IPN101 Config

!Command: show running-config version 7.0(3)I7(6) Bios:version 05.34 switchname IPN101 feature telnet feature nxapi feature ospf feature pim feature interface-vlan feature hsrp feature dhcp feature lldp vlan 1,4,1337 vlan 4 name IPN vlan 1337 name OOBM service dhcp ip dhcp relay no ipv6 dhcp relay vrf context OOBM interface Vlan1337 description VL for OOBM on IPN no shutdown vrf member OOBM ip address 10.x.18.2/24 ip ospf network point-to-point ip router ospf a2 area 1.1.1.1 hsrp version 2 hsrp 2 ip 10.x.18.1 interface Ethernet1/1-48 switchport access vlan 1337 interface Ethernet1/51.1 description OOBM interlink to IPN201 mtu 9150 encapsulation dot1q 1337 vrf member OOBM ip address 10.x.254.126/31 ip ospf network point-to-point ip router ospf a2 area 1.1.1.1 no shutdown interface Ethernet1/52.1 description OOBM interlink to IPN102 mtu 9150 encapsulation dot1q 1337 vrf member OOBM ip address 10.x.254.124/31 ip ospf network point-to-point ip router ospf a2 area 1.1.1.1 no shutdown interface mgmt0 vrf member management ip address 10.x.18.6/24 

show ip route vrf OOBM

IP Route Table for VRF "OOBM" '*' denotes best ucast next-hop '**' denotes best mcast next-hop '[x/y]' denotes [preference/metric] '%<string>' in via output denotes VRF <string> 10.x.18.0/24, ubest/mbest: 1/0, attached *via 10.x.18.2, Vlan1337, [0/0], 4d00h, direct 10.x.18.1/32, ubest/mbest: 1/0, attached *via 10.x.18.1, Vlan1337, [0/0], 3d22h, hsrp 10.x.18.2/32, ubest/mbest: 1/0, attached *via 10.x.18.2, Vlan1337, [0/0], 4d00h, local 10.x.19.0/24, ubest/mbest: 1/0 *via 10.x.254.127, Eth1/51.1, [110/44], 00:58:27, ospf-a2, intra 10.x.254.112/30, ubest/mbest: 1/0, attached *via 10.x.254.114, Eth1/47, [0/0], 3d21h, direct 10.x.254.114/32, ubest/mbest: 1/0, attached *via 10.x.254.114, Eth1/47, [0/0], 3d21h, local 10.x.254.116/30, ubest/mbest: 1/0 *via 10.x.254.125, Eth1/52.1, [110/44], 3d21h, ospf-a2, intra 10.x.254.120/31, ubest/mbest: 1/0 *via 10.x.254.127, Eth1/51.1, [110/8], 00:58:27, ospf-a2, intra 10.x.254.122/31, ubest/mbest: 1/0 *via 10.x.254.125, Eth1/52.1, [110/8], 00:58:36, ospf-a2, intra 10.x.254.124/31, ubest/mbest: 1/0, attached *via 10.x.254.124, Eth1/52.1, [0/0], 2w3d, direct 10.x.254.124/32, ubest/mbest: 1/0, attached *via 10.x.254.124, Eth1/52.1, [0/0], 2w3d, local 10.x.254.126/31, ubest/mbest: 1/0, attached *via 10.x.254.126, Eth1/51.1, [0/0], 00:58:40, direct 10.x.254.126/32, ubest/mbest: 1/0, attached *via 10.x.254.126, Eth1/51.1, [0/0], 00:58:40, local