Hi people out there. In our Network we daily have some or the other access-points which get rebooted. Basically uptime less than 24hrs. Can't exactly tell what's causing it. Managing from remote location is another challenge in capturing logs and stuff. Any suggestions.
Monday, November 11, 2019
BGP next hop self
I am currently a student and we are learning about the topic BGP. Now we have been told to always use next hop self between iBGP routers. Now i ask myself is there any reason why I shouldnt use next hop self and when not why isnt it a default value?
bittorrents increase internet speed!!
i guys i have some weird situation here there is trouble in my country. So the internet is partly work and some sites banned internet speed is so bad. But when i start bittorrent speed is back to normal before the ban for 15 min and i need to restart bittorrent over and over what happens here? is it port related?
DLINK AX6000 - Monster Router Review
Hi Guys, I just did a review after using the router for two weeks. The thing is a wi-fi-6 beast... and a conversation piece :D
https://www.fibretiger.co.za/article/dlink-ax6000-router-review
Single uplink cable to switch or all patches to the place where uplink is?
Sorry for the confusing title. Basically my question is what is a good idea. That a single up link cable(from the firewall) be taken all the way up to another department to the unmanaged 8 port switch there, or get all the patch panel LAN cables all the way to the main switch room and have them connected to the switch there?
I assume having all patch panels cabled so distantly to the switch would increase latency on each patch panel and is plain stupid instead of pulling one single up link cable to the desired place/department.
Actually what has happened, I gave task of setting up another departments wiring job to a networking service provider. And when I came to the site today, I found out they have been wiring patch panels all the way from another department to our switch room. Thus increasing the cost and effort as well. I'm really in a fix at the moment as to what has just occurred.
Seeking recommendation for a Lab Server to host a HomeLab.
I am looking to build a homelab for networking and programming study.
OS: EXSI 6.0
OVA: ASR9kv, CSR1000v, ASAv, F5, N9Kv,
OS: Ubuntu, Centos
Host: 14-CSR, 4-ASRs, 2-ASAv, 2-F5, 2-Centos, 1-Ubuntu.
I was looking at a HP Z620 Workstation E5-2680 2.7ghz 8-Core / 1TB / 64GB / Quadro 600 / Win10 Pro.
HP 2530-48G-PoEP (J9772A) partial loss of connectivity
First, sorry for my English, as it's not my first language. Also, networking is not my specialty, we're a small enough business to go by with only one IT guy and I'm supposed to "know it all".
I'm having weird issues with our HQ local "core" switch. Every now and then some (random) parts of network traffic stops flowing. I'd understand this better if everything would just stop working, but no, some users (even in the same access switch) may be able to do work as usual, while some have nothing, no Internet, no access to servers. Some have reported to have access to Internet, but not servers. Whether they had connections open prior the issue begins or not doesn't seem to matter.
Our local network consist of operator CPE, which WAN is connected to MPLS (to our branch offices, Internet) and LAN to the problematic 2530. GW and routing are done by the operator. The eight access switches we have (more 2530 series ones, old ProCurves and one HP OfficeConnect), Hyper-V server with NIC Teaming and some misc. security devices are connected to the "core" 2530. There are 9 VLANs. The issue spans over different VLANs as not only workstations lose connectivity, but equipment in the other VLANs also goes down. This for example causes some of our doors to stop functioning, but again, not all of them. Access from MPLS to our servers is compromised as well.
All issues do go away for couple of weeks to even months by restarting the "core" switch.
We're currently running YA.16.02.0027 on the "core". Access switches have varying firmwares. Spanning Tree is turned on on all of the switches. There's nothing on the switch alert log, nor is there excessive amounts of errors logged.
We had similar issues two years ago and then I replaced the "core" switch with a new one and the issue seemed to go away, until this year. Do you guys have any idea what to look at and if I'm to replace the switch again, what switch would you recommend? I'd rather stick with HP as almost everything else we have is HP gear.
802.1x Multi-Domian Authentication - Not Working Juniper .
Hello Guys,
I'm looking at setting up 802.1x PNAC on our Juniper EX2300's running 18.3.R1 - Handing off to NPS for radius.
Devices with machine certificates authenticate fine. I am having an issue with VOIP phones, the phones do not have certificates or are domain joined devices so I have enabled MAC-Radius (not secure I know) on the switch-port. The phones authenticate fine as stand alone devices with mac-radius - phones register to the call manager platform.
The issue I am running into is when the PC's are piggybacked through the Phones, I have enabled multi-domain authentication
My dot1x configuration is below:-
set protocols dot1x authenticator authentication-profile-name WIRED_ACCESS set protocols dot1x authenticator interface ge-0/0/4.0 supplicant multiple set protocols dot1x authenticator interface ge-0/0/4.0 transmit-period 2 set protocols dot1x authenticator interface ge-0/0/4.0 multi-domain max-data-session 2 set protocols dot1x authenticator interface ge-0/0/4.0 mac-radius set protocols dot1x authenticator interface ge-0/0/4.0 reauthentication 60 set protocols dot1x authenticator interface ge-0/0/4.0 supplicant-timeout 60 set protocols dot1x authenticator interface ge-0/0/4.0 server-timeout 60 set protocols dot1x authenticator interface ge-0/0/4.0 maximum-requests 3
However in the output I see that the phone (supplicant f8a5c5ea3fa3 is in the data domain, not the voice domain) this is causing issues and the phones are unable to register.
I am using a cisco 8845 - has anyone experienced anything like this before?
root@dot1x_switch> show dot1x interface detail ge-0/0/4.0 Role: Authenticator Administrative state: Auto Supplicant mode: Multiple Number of retries: 3 Quiet period: 60 seconds Transmit period: 2 seconds Mac Radius: Enabled Mac Radius Restrict: Disabled Mac Radius Authentication Protocol: EAP-MD5 Reauthentication: Enabled Reauthentication interval: 60 seconds Supplicant timeout: 60 seconds Server timeout: 60 seconds Maximum EAPOL requests: 3 Guest VLAN member: not configured Multi Domain Data Session Count: 2 Number of connected supplicants: 2 Supplicant: host/LAPTOP1.thedomain.co.uk, B8:6B:23:08:62:CE Operational state: Authenticated Backend Authentication state: Idle Authentication method: Radius Authenticated VLAN: VLAN_USER_248 Session Reauth interval: 60 seconds Reauthentication due in 18 seconds Eapol-Block: Not In Effect Domain: Data Supplicant: f8a5c5ea3fa3, F8:A5:C5:EA:3F:A3 Operational state: Authenticated Backend Authentication state: Idle Authentication method: Mac Radius Authenticated VLAN: VLAN_USER_248 Session Reauth interval: 60 seconds Reauthentication due in 26 seconds Eapol-Block: Not In Effect Domain: Data Sunday, November 10, 2019
Networking Field Guide?
So, I'm wanting to find some type of field guide that I can consult - not a full book on how networking works, just something well packaged and easily traversable when I want quick information.
You may argue that if I have an issue, I should just Google my problems and dig around for the answer - and that would be a reasonable response, but just in case someone knows of something like this I can find/buy, I would appreciate it. I haven't had much luck besides this one article I found.
Thanks in advance.
Dead NSA ?
Hey guys- strange thing is happening- hopefully someone can offer some quick suggestions for me to try:
- pre-owned NSA3600. purchased on eBay a few months ago. never tried to use it till couple of days ago.
- tried to reset using the reset button, and access using IP (192.168.168.168 etc...) - i can the login screen but no password is available to us.
- moved in to the next step - Console cable. Connected to TWO different computers , set up COM1 with 115200 and the rest of the settings - i can get putty to open the console window, but it's completely blank. nothing happens when i click anything in the window.
- i thought it's a bad console cable- tried another one (actually , 2 others) on another PC. outcome is the same.
- tried to hold the reset button for 15 seconds as i turn on the device. tried to reset using normal 15 seconds reset button push, tried everything except sledge hammer :)
- i'm able to see the SSH window / login screen, but obviously i don't have those credentials...
putty screenshot: https://i.imgur.com/Om0zWv4.png
console window: https://i.imgur.com/7XVnGcA.png
Thanks guys!