Monday, July 6, 2020

What do you guys use for vulnerability management?

Vulnerability management can be a hassle, but it shouldn't be. Today there are thousands of ways one can successfully secure their organizations personal and private assets/data. But what really is the best option?

There are tons of solutions out there- I was introduced to a next-gen, all-in-one vulnerability management platform designed to help companies and organizations mitigate, and manage their software vulnerabilities. It is amazing, and time-saving.

The platform is based on real-time info, and has a force-field designed to help you patch-less when a patch isn't available, ridding all the hassle of protecting attacks with no patch. There are tons of benefits to this platform, and if you're having a hard time finding a solution for you- I invite you to check it out.

This amazing platform is TOPIA, offered by Vicarius.

Im interested, what other solutions do you guys use?

#vulnerabilitymanagement #patchmanagement #cybersecurity #binarythreats #CVEs #solutionsIT #itsolutions #vulnerabilityquestions #vulnerabilitymanagementsolutions #vulnerabilities #cyber #security #TOPIA #Vicarius



Packet reset issue, looking for some help/recommendations (Diagram included)

Let me get this out of the way, yes, Sonicwall. At this point, I'm not sure if this is part of the issue (I'm sure there will be jokes stating this is the issue) or if this would happen regardless of the router/firewall being used.

I will do my best to keep it as short as I can, but I do want to provide enough details and information.

Quick diagram, https://i.imgur.com/Yo3Lu0u.png

The Problem- PC1 is a windows 7 computer that runs a camera program that displays 10 cameras, 8 cameras are local to the PC1 network/LAN and 2 cameras are remote (same overall network, different subnet) from the same network which PC2 (windows 10) is connected to on the other side of the wireless bridge. The p2p bridge that links both buildings resets each night (soft reset.....radios reboot at 1am and 1:05am, respectively). The daily reboot is a recommendation from the manufacturer of the wireless bridge (EZ Bridge). Every time I log into PC1 (a remote connection using VNC) I see that only the 8 local cameras are being displayed and the 2 remote cameras show as disconnected/no video/etc.

At first I just assumed the link was bad/needed to be reset, but the other end of this link has VOIP traffic, internet/network/LAN file shares, printing, etc...each on their own VLAN. The remote building only has a couple of users who are not always in the office, not high volume traffic. I am able to successfully ping anything on the PC2 network from PC1 and anything from the PC1 network to PC2, the link is up, there are no other issues with this link other than the 2 cameras appear as disconnected.

This is what I do to get the 2 cameras back online on PC1 (which is in the main building and is being used to display all 10 cameras between both properties).

  • I leave the camera program running on PC1 and remote into PC2 and reboot PC2.
  • I wait for PC2 to reboot and one of two things happen, on PC1 the camera views come back online or sometimes I have to close the program running on PC1 and relaunch and then the cameras come back online, I've seen both scenarios. 90% of the time rebooting PC1 is all that is needed.

Here is what I am seeing when I perform a packet capture in the sonicwall

DROPPED, Drop Code 736 (Packet dropped - cache add cleanup drop the pkt), Module ID: 25 (network) 

Google takes me here, https://www.sonicwall.com/support/knowledge-base/how-can-i-resolve-drop-code-cache-add-cleanup/180118173647344/

The options on the page are as follows:

  1. Review the TCP conversation using the packet monitor. If the dropped packet is received after the connection was closed (FIN or RST Packet), the drop is legitimate. If so, you will need to find out why the connection was closed/reset before the end of it by checking the machine that is sending the FIN/RST packet.

  2. Try by disabling Enforce strict TCP compliance with RFC 793 and RFC 1122 in Firewall Settings | Flood Protection. CAUTION: This will reduce the security of your network.

  3. Make sure that the TCP Connection Timeout on the specific Access Rule or on Manage | Firewall Settings | Flood Protection is not too low (by default it is set to 15 minutes).

  4. Try to disable "Enable TCP sequence number randomization" from the diag page of the firewall (https://IP of the SonicWall/diag.html).

  5. If the dropped traffic is VPN, make sure that you have a public IP set on the WAN Interface: a double NAT condition may cause the firewall to drop the traffic as "Cache Add Cleanup" due to the change in the packet header.

In reference to the sonciwall support article:

  1. I believe this is what is happening, I do see packets with the reset flag enabled, I think that the daily soft reboot is causing a TCP handshake issue since the network has to re-establish a link after the reboot is completed. However, I recall testing this by setting up the radios to not reboot for a couple of days and I believe the issue still happened. I've been having this issue for a while and have been too busy to focus on the problem and I don't remember what I've already tried, I have no problems testing this, again.

  2. This was already disabled, I don't think it is unchecked by default, but I am not the only one that logs into this firewall/router. However, since it is unchecked, I know it is not number 2.

  3. I believe the default time of 15 minutes should be fine, if it were changed to a very low value, I could change it, but this seems normal.

  4. I have not disabled 'TCP sequence number randomization'. When I looked into that setting, it says that it does not apply to packets over a L2 bridge, which is what these packets are passing.

  5. The dropped packets are not part of a VPN tunnel.

I did call sonicwall on this (months ago) and the packet capture shows that the packet comes in on x3 (normal) with a source IP of PC1 and shows a destination IP of PC2, but the egress column is blank and sonicwall says it should list the parent interface of x21 with the VLAN of PC2, which I agree is correct, but nothing shows up under egress. Sonicwall support states that this is the reason that the packet is being dropped because it doesn't know which interface to send the traffic to.

At this time, I'm not able to change building 2 to be a layer 3 connection, right now I'm simply extending my L2 networks. I'd like to set up another wireless link between the buildings to allow for some redundancy and/or test L3 connectivity with test equipment while keeping the L2 link online until everything can be converted to L3.

Another strange observation, Regardless if the traffic is VPN or not VPN, in another office (behind an ISP internet connection) I can connect to the cameras on PC2 (WAN and LAN connectivity is enabled for VPN traffic and non VPN traffic) and I can leave my computer connected for weeks at a time w/o the cameras dropping/disconnecting even with the daily wireless ptp bridge rebooting. I'm not understanding why the LOCAL PC1 connection is possibly being affected by the ptp reboot, but a computer over the internet (vpn or non vpn) is able to re-establish a connection. Unless of course this points back to the sonicwall locking up and not knowing what's going on with the traffic.

Hopefully I've included enough information to explain the problem, it would be great to get perspective from someone else. I'm not an expert and I don't have anyone else to bounce this off of, internally, the rest of the staff consists of programmers and help desk.

Thanks.



Who is using ExaBGP for their Anycast DNS deployments?

Greetings /r/networking,

I am gathering information for a proposal to deploy ExaBGP 4.0.8 on Debian 10.4 running Unbound 1.9.0 and IPTables to serve about a dozen DNS resolver IPs in an ISP network. I've got it running in a lab peering with ann ASR 9010 with the most basic health check script just to test the announcements and setting MED/Localpref. In production I would probably end up sending the announcements from each cache to our route reflectors but it would be helpful to hear from some folks that have used it in the real world.

Thanks in advance for your time. I really do appreciate anyone who takes the time to tell me about their setup and how it has worked for them.

-Mike



NEW NETWORK INSTALLATION

Hi,

We have some new networking equipments ( Routers, switches ...) being installed by a contractor. What are the different documents and assessments related to these new equipments and installation we should require the contractor to deliver ?

Thanks.



COVID-19 -> social distancing -> smart belts -> wireless interference?!?

Has anyone (network engineering) investigated the actual impact of using the so-called "smart belts" - like these ones - which seem to behave "like" APs (scan around and present itself as such), in the 2.4GHz band? It appears to me that this type of scanning and advertisement, in fairly high cadence, could add to the already noisy 2.4GHz, all around, but I have only seen ads about such.



Juniper link-protection feature

I was reading about this feature and I'm wondering if someone can educate me on why you'd use this:

https://www.juniper.net/documentation/en_US/junos/topics/topic-map/link-protection-aggregated-ethernet-interfaces.html#id-example-configuring-aggregated-ethernet-link-protection

If you had 2 physical interfaces in an ae interface, why would you consider using this feature? If I am reading right, does this then make it active/passive interfaces vs active/active? Trying to study and learn as many knobs as possible here in JunOS.

I suppose I could see this feature making sense if you were say, hooking up active/passive HA firewalls downstream, but wondering other uses for it?

TIA



How to connect to iSCSI target over Internet?

Hello everyone, I was wondering if someone can help me to connect to my iSCSI target that's in the different country? I know it's unsafe and not recommended but it's one of the performance tests I need to do (faculty).

Moreover, I know how to connect to iSCSI target when both the initiator and target are on the same network, but I fail to understand how to connect distant computers with different subnet.

Also, is there a way to make it at least a bit safer even though I'd be on VMs anyway?

Thanks a lot and I really appericiate your help!



scrapli - python sync/aysnc telnet/ssh/netconf driver

I've spent an obscene amount of time working on my project called scrapli -- a silly name that is "scrape cli" squished together. As the name/title implies, scrapli is a screen scraping library built in python, but theres a bit more to it than that, and as of this past weekend scrapli encompasses more than just "screen scraping" -- it also can handle NETCONF connections (get/get-config/edit-config/etc. -- though not 100% RFC support yet)!

TL;DR - scrapli is wicked fast, has zero requirements*, supports 100% of normal OpenSSH behavior*, is well typed/tested/documented, sync and asyncio with the same API, and provides a consistent look/feel across telnet/SSH/NETCONF (over SSH).

* if using "system" transport (you can ready about what that means in the README!)

Before going too deep into things, here are some links that may be useful:

I won't bother too much talking about what scrapli is and how its built as I've written extensively about it in the README on the GitHub page (first link above), as well as gone into tons of detail with Dmitry on his stream. Instead, I'll outline some reasons you may be interested in scrapli.

  • scrapli is super fast - it supports multiple different flavors of transports depending on your needs, so speed may vary a bit from transport to transport, but scrapli is fast with any of them! If you really feel the need for speed the ssh2-python (wrapper around libssh2 C library) plugin is about as fast as you'll get in python!
  • You care about typing! I know for me personally I really enjoy libraries with good type hinting -- its useful for IDE auto complete/Intellisense stuff, and being strict with typing can help stop problems before they rear their head (and has with scrapli!).
  • You enjoy long walks on the beach and reading ridiculously long README docs.
  • You want to write asyncio code. Not for everyone for sure, and I'm not advocating for asyncio necessarily, but "right tool for the right job" -- scrapli provides the exact same API for both sync and aysncio.
  • There is a nornir plugin for scrapli -- the current version on pypi works with nornir 2.x, but an improved version is ready to be pushed whenever nornir 3.x is "officially" released.
  • You have telnet/SSH and NETCONF devices that you interact with -- the NETCONF support is built right on top of scrapli "core", so you interact with scrapli in exactly the same way regardless of the type of connection you are making. Same host setup (the arguments you pass to scrapli to make a connection), same look and feel of the API, same result objects, etc.
  • You appreciate possibly too many tests. I have spent a goodly portion of that obscene amount of time making sure scrapli is well tested! There are of course unit tests, but there are also "functional" tests that run against virtual devices (and info in the README on how you can setup a lab to match if you wanted to test scrapli or contribute to it), as well as a mocked SSH server for ensuring that even without the "functional" tests scrapli can be tested in the most real way possible -- ensuring its doing what its supposed to do.
  • Additional platforms can easily be added by simply defining the privilege levels and on_open/on_close functions. I'm also working on a scrapli_community setup so that folks can add more device support. I am pretty adamant about not having a billion classes to maintain, and instead just having things be fairly pluggable by passing in args/callables to the "NetworkDriver" (or AsyncNetworkDriver of course)
  • There is seeming to be a lack of love for paramiko lately -- I don't want to get into any of that, but if you do want to get away from paramiko, you can use the system, ssh2, or asyncssh transport plugins in scrapli!
  • You, like me, don't really love ncclient, but want to NETCONF all the things. I personally find ncclient a bit obtuse, there is a fair bit of "magic" going on with dynamic attributes (getattr for vendor methods and things like that) and such that make it (at least for me) not super intutive. While scrapli_netconf is the latest addition to the scrapli family and does not have 100% feature parity with ncclient, it covers all the basics, and I am happy to add features if folks need them (and will over time anyway I'm sure!)

Why you may not want to use scrapli:

  • You are not working with one of the "core" platforms (IOSXE, IOSXR, Junos, NXOS, EOS) and aren't ready/interested to jump into a little bit of DIY (I promise its not hard!) to get your platform working (but you can still try out the GenericDriver which may be enough for whatever you've got going on!).
  • You are already doing all the things with RESTCONF or some other HTTP based thing -- yep, no need for scrapli then!
  • You are using Ansible/Salt/something else and don't really need/want to do low-level stuff like this because there are modules for that already.
  • ???

I may as well bring up the big question since I'm sure it will get asked: why not use netmiko? If netmiko is working for you then by all means keep on keepin' on! Kirk and I are friends and if it weren't for netmiko and all the amazing work Kirk has done for the community I wouldn't ever have built any of this anyway! To address the question though; asyncio is the most obvious differentiator. 100% of OpenSSH config support could be another big selling point to make a move to trying out scrapli (would mean using system transport). Not wanting to use paramiko (for whatever reasons), and lastly speed speed speed!

You probably would prefer to stick to using netmiko if you are a windows user (scrapli with ssh2/paramiko/telnet transports should work on windows but I don't windows so not sure whats up there), or you have non-core platforms and don't want to do a bit of DIY to make it work in scrapli (see above).

And now for a quick intro/example to scrapli!

from scrapli.driver.core import IOSXEDriver my_device = { "host": "172.31.254.1", "ssh_config_file": True, "auth_strict_key": False } with IOSXEDriver(**my_device) as conn: print("Gathering 'show run'!") show_run_response = conn.send_command(command="show run") print(f"Show run complete in {show_run_response.elapsed_time} seconds, successful: {not show_run_response.failed}") print("Gathering 'show tech'!") show_tech_response = conn.send_command(command="show tech") print(f"Show run complete in {show_tech_response.elapsed_time} seconds, successful: {not show_tech_response.failed}") print(f"Show tech was {len(show_tech_response.result.splitlines())} lines long!! AHHHHHHHH!!!!") 

And a quick asciinema example!

asciicast



Business Router

I am looking for advice on a new business router for my small(ish) business.

  1. We currently use an Orbi wireless network and use that router. It functions for us, but I notice that if the router resets it can take 5-10 minutes for the network to come back up. That seems excessive. I'd prefer to just move the Orbi into bridge and use a more business oriented router.
  2. I have about 50 wired connections, 20 wireless connections, 15 VOIP phones on our network. I don't currently have QOS setup for the phones.
  3. We currently have a 300/30 cable internet connections, but I am pending a dedicated fiber line that will be 100/100. I'm still undecided on if I should keep the cable internet after I get the Fiber installed. I would appreciate suggestions that would allow me a dual wan/failover option.
  4. Are my expectations out of line that the Orbi router takes FOREVER to boot up/reboot?
  5. I have a 19' rackmount, and plenty of room available.


Retro-tech question: what kind of regional, completely internal WAN options did an organization have before fiber or ISP WAN products?

I'm building an RPG setting that involves a plot point around some cinematic network hacking. Someone's connecting to an old 10BASE5 or other type of network that's part of a regional WAN for a megacorp. Since the setting is 2015, it's already long dead and gone by modern standards, but it's still in use for a separate plot point. It'd be a WAN, accessible by satellite offices from a central regional office, using VT-series terminals connecting to an IBM System/370 mainframe running APL. Cutting edge for its day, the kind of network that a graybeard BofH would be running through today because the company doesn't want to spend the money to migrate and the graybeard's the last person who knows how to run it.

Fully internal and private to the company, not available to the public - no dialup connectivity, owned and installed by the company (or its contractors). Buried cable, strung on power lines, some very well-configured packet radio sort of thing, etc.

What kind of network would a company use for this sort of setup? While it doesn't have to be perfectly accurate I'd really like to have the color text be "this place used to be a satellite office for FooCorp, but our guy on the inside confirmed there was no disconnect for the so-and-so node that was installed in '92 and deinstalled once they struck a nationwide deal with Kabletown."