Monday, November 30, 2020

Cisco ISE Setting for AV-PAIR for an ACL

I've configured Anyconnect on an FTD. Basically, my auth goes via ISE, and my ISE has a policy-set binding an AD group check to verify I'm a member of a group policy. If I am, then I've configured ISE to use the attribute below to assign me a pool (which is a pool configured on the FMC)

Cisco-VPN3000:CVPN3000/ASA/PIX7x-Address-Pools : POOL-XYZ-ON-FMC

So basically, I can assign different pools to people based on their group policy. What I want to do in addition to this (and I'm quite confident it will be a setting on this same page), is assign an access-list name that will be applied on this same group-policy check. It simply just needs to state: if authenticated, use an ACL named XYZ, which will be an ACL I have configured on the FMC (not an ACL I have configured on ISE). What is that option I need to find (what AV pair is it). I initially thought it would be the tick-box named "ACL (Filter-ID) " in the common tasks section of the authorisation profiles, this did not work. So I must just be needing to set this via an AV-PAIR.

The goal is simply to get an ACL that will be applied for a user based on their ISE auth, and either over-ride the existing ACL in the policy for that box, or get it to work in conjunction with the existing policy as an additional check.



Juniper Router on a Stick configuration

Hi Guys,

For another team -which has their own network- I need to offer some services in their logical network which can't pass our firewalls as we normally do. In order to do this I created a design where I create a new vrf with ACL's on our core switches (juniper qfx) and give them a layer 3 interface with subintefaces per switch and VRRP. Unfortunately, this isn't working. I'm used to Cisco and I'm pretty new to Juniper, so probably I am just missing something simple:

This is the configuration of the port on the HP (comware) side:
interface Ten-GigabitEthernet3/1/8
port link-mode bridge
description xxx
port link-type trunk
undo port trunk permit vlan 1
port trunk permit vlan 106
port trunk pvid vlan 2

And this is the juniper qfx config (in reality we have much more subinterfaces but we're troubleshooting on 106 at this moment):
set interfaces xe-0/0/5 description "Connection to xxx"
set interfaces xe-0/0/5 vlan-tagging
set interfaces xe-0/0/5 mtu 9216
set interfaces xe-0/0/5 unit 0 vlan-id 2
set interfaces xe-0/0/5 unit 106 vlan-id 106
set interfaces xe-0/0/5 unit 106 family inet address 10.26.253.67/26 vrrp-group 106 virtual-address 10.26.253.65
set interfaces xe-0/0/5 unit 106 family inet address 10.26.253.67/26 vrrp-group 106 priority 200
set interfaces xe-0/0/5 unit 106 family inet address 10.26.253.67/26 vrrp-group 106 accept-data
set policy-options policy-statement MY_VRF_NAME_redistribute_connected term accept-connected from protocol direct
set policy-options policy-statement MY_VRF_NAME_redistribute_connected term accept-connected then accept
set routing-instances MY_VRF_NAME instance-type virtual-router
set routing-instances MY_VRF_NAME interface xe-0/0/5.0
set routing-instances MY_VRF_NAME interface xe-0/0/5.106
set routing-instances MY_VRF_NAME interface irb.134
set routing-instances MY_VRF_NAME protocols ospf export MY_VRF_NAME_redistribute_connected
set routing-instances MY_VRF_NAME protocols ospf area 0.0.0.0 interface irb.134

What I can see is that I am receiving traffic when looking at the interface counters:

admin@exTAP-vc2-leibniz-NEW> show interfaces xe-0/0/5.106
Logical interface xe-0/0/5.106 (Index 604) (SNMP ifIndex 905)
Flags: Up SNMP-Traps 0x4000 VLAN-Tag [ 0x8100.106 ] Encapsulation: ENET2
Input packets : 82855
Output packets: 581289

And they do see my mac address learned in the correct interface. Also, when I send a ping, they see arp requests being broadcasted on their network so outbound traffic appears to be working just fine.

But, when I look at my mac address table, I learn nothing from them (although the input packet count is increasing!)
admin@switch> show ethernet-switching table interface xe-0/0/5
MAC database for interface xe-0/0/5
{master:0}
admin@switch> show ethernet-switching table instance MY_VRP_NAME
{master:0}
admin@switch> show ethernet-switching table interface xe-0/0/5.106
{master:0}

Does anyone know what I am missing here?

I am seeing this error message every commit, which might be related:
Nov 30 17:04:55 xxx l2ald[2075]: L2ALD_DEFAULT_VLAN_DISABLED: Internal vlan "default-switch/default" creation failed. User configured vlan with vlan-id 1 exist!

vlan 2 however does not exist (which I did not wan tto configure but I had to configure unit 0) so the error is somewhat off. I'm not entirely sure if it is related to my configuration but I haven't seen it before (I don't check the logs of this switch often so it could be there for months or even years)

Thanks in advance!



Has anyone used something similar to a Wacom Tablet for whiteboard?

I was working a problem the other day with an engineer from another group, and he started sketching up the problem using a Wacom tablet (using a whiteboard app) while we were on a teams call together. He said he's been doing this for a few years, and it was a pretty seamless transition.

Since almost every Network Architect I know usually ends up on a whiteboard at some point, and currently I don't have a whiteboard at my home office (The wife ixnay' d that one) has anyone else gone this route?

Specifically, has anyone tried to use an Android Table (I've got a Galaxy S4 with a pen just regulated to movie duty on car trips) to do this?

What other methods have you come up with to cope with a lack of whiteboard space?



Aruba NetEdit: Friend or foe?

Spent some time this weekend getting Aruba NetEdit working in eve-ng, really happy with all the IDE-like features doing CLI configs, whole writeup is at https://kd9cpb.com/netedit_eve-ng

I was wondering if anyone has successfully deployed NetEdit in a way that doesn't involve manually entering every AOS-CX switch? It feels like there's no way to automagically get devices in NetEdit without the seed addresses seeing the other AOS-CX switches via LLDP. If that's true, it's a big problem for those of us only running AOS-CX stuff at access layer, using other vendors for distribution/core switches.

Or if someone went with some IDE-like network config change tool other than NetEdit that has those cool commit/rollback/validate features, I'd be curious which tool you picked.



How to tag untagged traffic!

We have an office with a DIA circuit and MPLS circuit. The DIA will coming from Comcast as untagged and terminate on the collapsed-core cisco switch. From the Cisco core switch we need to tag it and bring it up to our sdwan appliance. Any thoughts on how to tag the DIA circuit? What is the cisco cli syntax?



ISE Guest with anchor mode

Hello guys,

I want to install ISE on my network, in addition to that, I am installing wireless anchor mode.

my question is that, should ISE be installed on the internal network and the authentication will be with the WLC that is installed on my internal network, or I should install 2 ISE nodes, one on the DMZ and one on the internal network?

thank you all.



How do Leased lines work in shared offices?

Just wondering how leased lines work (in the UK) if you have 3 businesses all wanting to use it? I get you could VLAN but if each business wants their own hardware setup?

Once the leased line is installed can the businesses each contact BT and get their own Modem and Public IP from them?



Unifi Configuring Custom DHCP Options

I can't seem to find the options where I can easily set my DHCP range. Due to that, I am stuck with the default of 192.168.1.0/24 This new UI change is welcomed but uncomfortable to find a lot of features.



Confine a device to the local network?

I want my NAS to be able to talk to other devices in the local network (as a NFS server) but not give access to the internet.

I have a double NAT, the NAS is in the inner network under a VPN and I want to keep it there (i.e. I don't want it to request the internet, or devices outside the innermost network).



Sunday, November 29, 2020

First hop out of LTE tracing to Google in Straya? and Strange Cellular Device Nets... a rabbit hole

I was playing around with NET-Toolbox on iOS (literally one of the only ios applications I've ever paid money for, have used, and would still highly recommend ~ non affiliated shilling over).

Shower thoughts: I was curious if my phone's public LTE IP was a local tower IP, and I'm actually NAT'd by their equipment or if my phone is literally getting a public address. Well, if I 'curl icanhazip.com' from my phone, it returns a public ipv4 address, so I sincerely doubt my phone is pulling out of some dhcp pool of public ipv4s. Plus traceroutes out are bouncing around a 10. range, so it looks like I'm hitting some internal equipment before routing out to the rest of the nets...

BUT WAIT, my phone actually says its "LAN" ip is 192.0.0.1 wtf...that's public space

Oh, that's neat... it's not, I've never heard of this "The IP range 192.0.0.0 - 192.0.0.7 is not a public IP block. This block is used for DS-LITE, a technology for sharing an single IPv4 address among multiple broadband customers by combining IP in IP and Network Address Translation. It was assigned by the IETF in the Standards Track document, RFC 6333"

So DS-Lite is doing some weird mutant NAT'ing and what not, I need to go read up on it...

Still, there's that ipv4 public address I'm curling that I now suspect is the DS-Lite gateway or something. I'd expect to hit that gateway on my traceroutes out, but that doesn't appear to happen. I don't know why... but I suspect I might find the answer in that RFC.

This is where the google.com trace comes in, my first hop out of the 10. range hits 72.14.242.140

The Net Toolbox tool is telling me this server is located in Australia, but a couple of geoIP and whois searches tell me it's a google owned address and returns Mountainview, so I don't know if it's just returning their corporate address, and Net-Toolbox is returning correct info, or if NetToolbox is wrong or what. There are 3 more hops after it, and those 3 are returning as US servers.

It's kind if unintuitive for a stateside trace to Google to bounce out to Straya, unless I slam on that tin foil hat and note that the Patriot Act allows for the unsolicited hoovering of any packets leaving US borders.

I figured I'd dump this here and see what yall think, gonna poke at it some more tomorrow.