Tuesday, April 28, 2020

MS510TX - 2.5gb and LAG ports only getting 100MBps

I am hoping someone can help me. I purchased a Netgear MS510TX switch with hopes of utilizing the 2.5gbps ports and setting up LAG ports. I configured everything and I am only getting 100-115MBps transfer speeds between all devices.

My setup: Orbi Router > MS510TX >
Ports 1&2 LAG LACP Windows Server 2012
Ports 3&4 LAG LACP Synology NAS
Port 5 Lenovo M910 2.5GBe Cable Creations USB eth adapter
Port 6 Netgear 1GB dumb switch
Port 9 Uplink to Orbi

Testing transfers between any of the devices server, nas or M910 desktop I only get 100-115MBps transfer speeds. Am I missing a configuration step somewhere? Any help would be greatly appreciated. Thank you!



I may have found the two generals problem solution ?

I assume you are familiar with the two general's problem. I came here after watching Tom Scott's video about it. Feel free to correct me if I'm wrong.

Both generals are aware of the strategy they will be using, because in a real world scenario where the generals are the client and the server, the developer creates both.

So, as far as I know, the two general's problem is all about sending acknowledgements to acknowledgements without knowing when to stop, because the one general may not receive the last acknowledgement and won't send his army, because he doesn't know if the other general received the previous one. so instead of stopping, the generals can say that if they manage to maintain an acknowledgement sending rate of approximately one acknowledgement per second for the hour that is one hour before the attack time. I say approximately because if the last acknowledgement is not recieved and the rate is 1 acknowledgement 1.000277778, the generals should still attack. How approximately ? approximately enough for the last acknowledgement to be allowed not to happen, but not enough for the last two to be allowed not to happen. So about a 1 / 3600 seconds tolerance.

What do you all think ? Do you see some case where this solution could fail ? (Not that it should be implemented in a real life scenario)

edit : I tried to reply to a comment, but reddit told me to try again, so I did, but then two comments appeared at once. its the case where the client sends a message to the server, but doesnt recieve the acknowledgement of the server. How funny is that !



Rant Wednesday!

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.



Redundant VPN appliance for ~700 users

Is there anything new or exciting that I should definitely look at before justifying the expense of a solid and redundant Juniper solution at this point? Basic remote access / potentially clientless for 600+ users.

Many thanks in advance!



Cisco ISE

Getting brand new 3615 appliance upgrading from Cisco ise 2.3. Which do you recommend 2.6 or 2.7? Should I transfer my 2.3 operating system and configuration to the new appliance and then upgrade? Or, start fresh with a new image?



Help getting wireless through houseboat

I've got a boat I'm trying to run wireless into. I've got the main hub ran into the helm and I need to have 1 run up toward the front with another 2 run toward the back and farther. I plan on wiring cat6 for each run if not daisy chaining the back runs together. I want to use wired access points for these but I'm unfamiliar with brand or requirements. What would you recommend?



Are there third-party alternatives to the Cisco SSD for Catalyst 9300s yet?

So, according to Cisco's document about installing SSDs into the Catalyst 9300:

"You must use only Cisco USB drives; non-Cisco USB drives are not supported."

Has anyone figured out how to, you know, ignore that, and use a disk that isn't the SSD-120G from Cisco, list price 1500 damn dollars? Like "service unsupported-transceiver" but for SSDs?



OpenSSL update - Red Hat

Can OpenSSH still be dependent on OpenSSL libraries? And could updating OpenSSL to the latest version affect applications using those libraries?



Free Fortinet Training - Yes FREE

So Fortinet just opened the doors to anyone to use their online training. Including labs!

If you are curious or need training, it is a good time.
https://training.fortinet.com/

https://www.reddit.com/r/fortinet/comments/g9rckx/fortinet_free_advanced_training_for_security/



Is it unreasonable to expect my ISP to provide an aggregate link from the fiber switch to my firewalls?

I have two different fiber connections delivering Spectrum internet to my facility. Each fiber runs into a fiber switch and comes out ethernet to my edge firewall. My edge firewalls are PAs running in an Active-Passive HA configuration, so I would love to have an aggregate link from their fiber switches with one link from each switch to the PA. That way there is redundancy. Currently, if my firewalls fail over, those uplinks will go down since they are no longer connected to the active firewall. They said they can't do that. I don't have much experience in what ISPs can and can't do, so is it unreasonable of me to think they should be able to?