Monday, September 14, 2020

I have a question about subnetting:

I have a question here about subnetting, it says "a host is configured with automatic IP-settings. What adress-space indicates the inability to communicate with a DHCP server? And I have these options, I know it's option C, but why is it option C?

Here are the options :

A: 169.254.0.X with netmask 255.255.255.0

B: 169.254.X.X with netmask 255.255.0.0

C: 169.254.X.X with netmask 255.255.255.0

D: 169.255.X.X with netmask 255.255.0.0



Different WiFi drivers and their roaming behavior?

Apple macOS has a good read on how their wifi driver behaves when roaming. (https://support.apple.com/en-us/HT206207). IOS is a little more aggressive in scanning threshold. But they do not mention physical modes when chosing roaming target. (https://support.apple.com/en-us/HT203068) Also, neither IOS or macOS article mentiones 802.11ax.

Since assumption is the mother of all f-ups....

Are there more info/blogs on this topic for apple/windows/linux drivers? Especially ones that are updated with 802.11ax information. I tried googling with not much luck.

I want to know how much more an 802.11ax station will prefer an 802.11ax AP over an 802.11ac AP, for instance.



Palo Alto transition from ASA- can ping across sites but cannot load services from some VLANs

We are in the midst of transitioning to Palo Alto firewalls from Cisco ASAs.

Set up is Active/Active HA with a 10GB link connecting the Palo Alto HA pair. Using our old ASA set up and just management ports on the Palo's connected to the network, I can ping and load HTTPS of the management interface of the Palo Alto without issue from the opposite side site (Site A->Site B; Site B->Site A).

Once we move production traffic from the ASAs to the Palo Altos, I can still ping the management interface of the opposite site Palo Alto, but cannot load HTTPS, receiving connection reset in the web browser. We see this issue across a few other VLANs as well.

HTTPS is allowed in the management profile and it clearly works when we just have PA management hooked to the network while still using the ASAs.

A diagram of the set up can be seen here: https://i.imgur.com/RrPFxq9.png

All traffic primarily goes over the 10GB link and spanning tree holds down the VLANs on our back up 500MB link. We have confirmed spanning tree is operating as expected (blocking cross-site port for all VLANs on the 500MB line) and traffic is flowing across the 10GB link.

I'm stumped at the moment as to where asymmetrical routing may be occurring, or if that is even part of the problem.



Where to go next - CCNP Enterprise

Hello everybody! Im not sure if here or in /r/CCNP i should post. Just delete it when on the wrong sub.

Soon im done with ENCORE, since sep. 10th the new enterprise design OCG is released - which seems very interesting.

BUT what would be better - go for the ENARSI and then for the design?

In my last role i was kind of network architect, making many designs and pocs for future decisions networkwise - like routed access and mpls to the edge with the 9300er.

But beginning Nov. I will start as a senior network security Engineer responsible for more zone designs, firewall setups, NAC with ISE and so on, so SECCORE could also be interesting.

I have now vacation till end of october so.. much time to study.



Network scanner that can automatically report results

Hi,

I'm searching for a network scanner tool which is able of scanning the network regularly and reporting the results to a server in whatever kind of format/way. Any suggestions? Thanks.



Infrastructure design question

Hi all,

I have come across a design proposal and I am trying to understand why WAN side and INTERNET side get differentiated.

WAN side: Cisco 4451-X Internet Routing Cluster

Internet Side: Fortinet Fortigate-1000D HA cluster + Cisco 4451-X Internet Routing Cluster

My confusion comes specially this site being standalone, no other offices will be connected to it, final topology being LAN, WAN and Internet

This might be very obvious for some of you, your words are very much appreciated

Thanks!



RUCKUS SmartZone Licensing

Hello, currently one of my customer is looking at Ruckus SmartZone, but my company doesn't sale Ruckus, and i want to compare Ruckus SmartZone to Cisco Meraki, here are several question i want to ask :

  1. Is RUCKUS SmartZone licensing is the same like Cisco Meraki or 1 time purchase? (Currently using the virtual SmartZone)

  2. Can RUCKUS SmartZone account can make several network for each office branch? In Cisco Meraki one organization can make one network per each branch.

  3. How Ruckus SmartZone compared to Cisco Meraki, the pros and cons.

Thank you before.



Packet Sniffing Stops My WiFi ?

Hi all, I just installed WireShark for one fo my courses on my Mac but every time I start capturing my WiFi gets dropped/stops working.

I tried the same on Wireless Diagnostics on the Mac but as soon as I start capturing it does the same thing.

I'm on my home wifi, does anyone know how to fix this issue and why it keeps happening? I've looked everywhere but can't find any information.



WLC8540: Error in creating disabled client

I’m trying to disable a specific client from accessing our wireless network, but there seems to be an issue in disabling that specific mac address. Not sure what’s the issue. I can disable any other mac but that one. Tried using gui and cli. Same issue. Could someone help me with this?



Sunday, September 13, 2020

Multi-Wan Networking Question

I have a networking scenario I am not sure if is possible and was looking for advice. I have tried looking at different hardware on the market and am hitting a brick wall.

I work for a small company which has always used a multi-wan router in failover mode for redundancy. Now we have a new fiber connection which is obviously our more stable, but is only a 10/10 line, and our copper is 100/10.

The scenario I would like is for people in the building surfing to go out over copper as their primary, and fiber as the failover. But anyone outside connecting in I would want to use fiber as the primary and copper as the failover.

Obviously this is not possible with our outdated Netgear SRX5308, but is there any equipment out there which can achieve this? And if not hardware solution, is this something which can be achieved by other means? Thank you to anyone with suggestions!

**Edit - Both providers are delivering service through an RJ45 connector, so I do not need any speciality converters; just treating as WAN1 / WAN2