Monday, February 22, 2021

N9K Power grid redundancy question

Hello guys,

I need help regarding PSU grid redundancy on the Nexus 9K platform (N9504 precisely).

According to Cisco's Power Calculator tool, it shows me that " Three N9K-PUV-3000W-B in Grid redundancy mode" as one of the possible PSU configurations.

But as far as I know, it's not possible to configure grid redundancy with an odd number of PSUs.

So is it just an error from Power Calculator or it's possible to configure 2+1 power grid redundancy?



Make Virtual Machines connect to internet without using Organizational Network

Hello, I work at a University Research Lab.

We have a wifi network and a LAN for the university. The LAN is most probably segmented into different portions, for each separate department.

I have a task to run some malwares ( ransomwares and others, that communicate with the internet ) on a Virtual Machine (VM1) and capture it's traffic on another Virtual Machine (VM2)

The challenge is, that i cannot risk running dangerous malware while connected to the University's LAN ( or even Wi-Fi ? ) .

Therefore, according to my understanding, i need to provide both the VMs with a static route to the University's gateway, which will connect the entire university to the Internet. ( I am not sure this is the most optimal method, feel free to add suggestions as you see fit )

I need your kind guidance in figuring out how to do the static routing of the VM's to the university's gateway

I am using VMware Workstation ( 16.1.0 build-17198959 ) for the VMs. The OS used in both VMs is Windows 10 64 bit downloaded from here, legally ( i selected the MSEdge on Win 10 x64 option there )

Any help, guidance or resources you can provide to help me would be greatly appreciated



Observium peer alert

So at the moment i need to make alerts to check when a S2S is down. The only condition i can use for a peer ip is bgppeerremoteaddr or bgppeeraddress.

But we are not using bgp, does it work with the bgp condition or is there any other condition i am overlooking

Cheers!!



Network Access Control Fingerprinting

Hello World,

Can someone guide me to a good reading about how NAC fingerprint a host... I am sure in the past it was maybe host name and Mac address but I am assuming new Gen networking devices use multiple artifacts..

I want to test if I have a fresh OS image and I keep changing artifacts will the NAC solution detect that it is the same host.



Fortinet VS Stormshield VS Palo Alto

Hi guys,

I will have to implement two new clusters on my network. At the moment I have narrowed down my list to these 3 vendors. I am currently using Check Point and Cisco mostly but we have been asked to change.

Aside from the different price ranges, what would be the strenghts/weaknesses of each of these 3 vendors ?

Thank you for your answers.



How to diagnose a problem like this?

Hi there,

I was writing more details then needed I think.

The problem is the following: in my company we have several headquarters and one of them is the main one, where we have the most part of our Informative Systems.

Some users connect to the main HQ on a Terminal Server using, of course, rdp.

Sometimes, randomly in term of time and in term of machine, they experiment disconnections of the rdp session.

In the meanwhile I check the connection with that system (the terminal server) using PRTG Network monitor (or other tools, like a ping) and I can't see any interruption.

If I remotely connect with the problematic client using Anydesk I'm suddenly disconnected at the same time of the rdp disconnection.

Now, ping is connection-less, I know, and this is probably because I can't see any disconnection. I think that something is breaking an active connection, but doesn't make the host unreacheable. I can't know how to diagnose, monitor and/or check this problem to have some data to analyze.

Anyone can help?



Daisy Chain Phones & PCs with Separate VLANs

Hey all, quick question. We are deploying about 60 new Poly phones and two Juniper switches. High level check config is below

-Phones are cloud based connected to BroadSoft -Converged network with seperate VLANS for voice and data

We will be deploying the new phones on the juipers and daisy chaining the PCs to the phone's switch port.

Each VLAN offers DHCP to the end point using seperate subents. My questions are....

-Will the PCs and phones be able to aquire their perspective IPs from the proper VLANs without any additional provisiong settings?

-When I configure the Junipers, do I tag the interfaces as trunk ports with both the Data and Voice VLAN?

Thank you all for taking the time to review.



Dell Force10 queuing and DSCP values

I was playing around with QoS management and prioritizing packets in a specific queue on Dell S6000 9.14(2.1). Adding policy-map on input port with "trust diffserv" specifies that packets with DSCP value of 10 go to queue 1. Everything works fine, however, i'd like to remove DSCP value before packets leave the switch environment. I found out that you can't have "trust diffserv" and DSCP value modifying rule on the same input policy-map.

Has anyone played around assigning packets to queues with DSCP value and then removing the DSCP value?



Sunday, February 21, 2021

Guest WiFi captive portal solutions

I'm setting up a network for a small restaurant that wants to offer guest WiFi access as a selling point, and use that to drive traffic to their social media sites.

I was wondering what kind of solutions are available for this task?

I'm currently testing with the Facebook WiFi option in Ubiquiti's Unifi line. I liked this because it gave customers the option of checking-in on facebook, which takes away the need to post up signs with the password or require staff to remember the password. But FB WiFi has a stipulation that guests can access the internet even without checking in, which kinda defeats the purpose.

There are other options using UniFi, but it got me thinking about what others are using.

I prefer the free/opensource route, or at least something that doesn't cost hundreds, or require bespoke hardware. The network solution at this place is simple with an ERX, Unifi AP, and an x86 mini PC running Debian.

Thank you.



Learning EVE-NG - Anyway to emulate L2 Switching without using Cisco IOS?

Hey All,

Playing around with EVE-NG to play around with some network topology designs, I've created templates for all relevant devices I need (Pfsense firewall, Windows Servers, Windows Clients) however I now need to implement some VLANs.

From everywhere I've read the only proper way to do this is to emulate Cisco IOS - However I've never touched cisco switches before, not too familiar with their CLI. So I either find a suitable replacement OR I just suck it up and learn?

Is Emulating IOS Devices the only way to do VLAN'ing properly in EVE-NG?