Monday, March 22, 2021

Wireless Lab Ideas

Is there a cheap alternative to a Cisco wireless controller and Cisco WAP? I was wondering id there was possibly a Linux alternative which would allow me to a set up a lab and assist me wireless study?



Any love for Juniper SRX?

Hi,

We are looking to replace an aging firewalling setup.

A little bit of background:
We are coming from a Cisco background, and have been impressed by Juniper in the routing field. So we are not uncommon with Juniper.
As for firewalls, we have still mainly been Cisco PIX and later ASA oriented. We looked at Firepower but were not impressed and put of by the horror stories, gave ASA with firepower a try, ran away.
Deployed pfSense, but are seeing weird problems from time to time, lost confidence. Gave Opnsense a try, but figured Opnsense and pfSense are beter for smaller or SOHO deployments.

The firewalls will be deployed in a datacenter, in front of servers. Obviously need HA support and we want IDS/IPS features. Traffic should be between a couple 100mbps to a max of 1gbps. There are multiple networks behind the devices, so we can split the networks over multiple firewalls and thus lower the amount of traffic per device. Some scenario's demand a dedicated anyway firewall, so we'll probably be managing multiple units anyhow in the end.

I see a lot of recommendations for Fortinet and Palo Alto.
But we've seen Fortinet at a client site, and were not impressed, we are fairly certain we don't want to deploy it in our datacenter.
As for PAN, there is not to much confidence, we don't know the systems and are hesitant to introduce a new, unknown system. Plus, some people are worried we might just be picking them because they are the lesser of 2 evils.

Intro Juniper SRX, a known platform (Junos), positive experience with them in the routing field, a nice range from small to big models for diverse deployments.
It's just that I can't find anything about any experiences with these devices.
Is everybody so happy about them that there is nobody actually talking about them?
Or did everyone ran away from Juniper firewalling after ScreenOS and is actually nobody using them?
We are currently looking at the SRX 340/345/380 devices.

Any experiences with these SRX devices?



Network Segmentation on a windows network

I have been tasked with implementing some network segmentation on our windows domain network. We already have the network segregated into VLANs and I just need to implement some ACLs (I think).

I am trying to figure out 2 main issues so far.

  1. I'm running server 2016 with a Server 2016 Domain functional level. Do i need to allow ports 137, 138, and 139 for netbios to leave the client VLAN?
  2. I know i need port 135 for RPC but do I also need to allow all high level ports 49152-65535 from the client or does this come under established communication during the RPC negotiation?

Any help would be greatly appreciated

Sources I'm looking at:

https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts

https://docs.microsoft.com/en-US/troubleshoot/windows-server/networking/service-overview-and-network-port-requirements



msp monitoring

hi

we are a MSP and currently looking for an alternative for our current infrastructure monitoring system

we are currentliy using nagios with a lot of custom plugins (mainly python scripts).

we are looking for a tool that already supports a lot of devices (cisco,paloalto,brocade,..), with a central management platform and some remote pollers at customer sites.

should support up to 100k hosts and 5k checks per second, with some sort of template-based check configuration for different device types.

a customer view and event management platform would also be nice, with some sort of reporting

Any suggestions/recommendations?

Currently looking at LogicMonitor, which looks quite promising.



Sunday, March 21, 2021

I've planned something for the office, and want to be sure everything is fine, can you confirm?

Hi! I'm working in an office where we do cinema/television post-prod. I've studied programmation back in college, so did a bit of networking, but it's been a long time.

Long story short, the network is shit. Old cables and hardware, bottlenecks because of how the switch are connected together, it's bad. Espacially since we are working with big files.

I decided that it was time for a change, so I started updating my knowledge on networks, and I came up with something.

Here's some info:

  • We have about 12 Mac Pros from 2013, with two 1Gb port each. They support lacp aggregation.
  • We also have a Qnap NAS, with four 1Gb ports, also supports lacp.
  • The office is separated in two sections, so we would like two switches, with 24 ports each.

What I want to do, is to run 2 cables for each computer to run them with LAG, and 4 for the NAS, with LAG too, to allow for faster file transfer everywhere. Half of the computers on each switch. I want to connect the switches with one or two 10Gb cables.

Here's what I though of:

2x S3900-24T4S Switches

2x or 4x Transceivers

1x or 2x Fiber Optic cable

Than a bunch of Cat6 cables to connect the rest.

Am I wrong? Is there something I don't know about that I should? Any advice? Will my idea with LAG work?

Thanks so much!



How are you handling Wi-Fi authentication for environments without an on-prem NPS server or Certificate Authority?

Title. There are some customers that are excellent fits for zero servers and all InTune in other areas, but this is a problem that we've run up against.

SecureW2 seems to be able to do it but I don't know their pricing and they've put it behind a "let's setup a quick call with a salesperson" wall so no thanks.

Azure AD DS and some NPS servers chilling in Azure is a method, but as an MSP I'm not sure how or if that could be mutli-tenant capable.

Pushing a long PSK-based profile via InTune isn't a great option because a simple one liner NETSH command can pull the PSK in 1 second.

Ideally, I'd love something that can replicate AD CS Automatic certificate enrollment + automatic Wi-Fi network join. The second part of that is simple enough to do with InTune, and InTune can even point devices as a SCEP-capable server.

Thoughts?



Setting up a wireless control network in a film studio

Hi all,

Probably fairly long post coming, so apologies for that, and big thanks for those who do read through and offer help!

I work as a lighting programmer, increasingly in film and TV. In studios/locations, there is a main Lighting Desk which does the processing, but a lot of the control is done roaming from a Tablet/Surface etc. Therefore, there needs to be a wireless network covering the studio - this will never connect to internet, it is simply providing a wireless interface for the handheld devices to talk to the lighting desk.

Previously, I have run a Ethernet cable from the desk to a TP Link router/AP, on a stand in the middle of the room. Tablet, desk and AP all in the same IP range, they talk to each other, there we go - that is about the extent of my networking knowledge.

However, I'm now increasingly working on bigger shoots, which means bigger studios and bigger locations. On my last shoot we were in a studio 200ft × 100ft, containing an apartment set (so often within wooden walls). There were also probably tens of other devices broadcasting WiFi signals and hundreds receiving (cameras, lights, sound gear etc). I originally assumed using 2.4ghz would be best because of the range, but I assume because it was so polluted with other devices, I found more luck on 5ghz

My existing basic setup struggled, and I've been recommended looking at setting a more professional multi AP system in the future (such as Ubiquiti; Ruckus; etc). What I imagine in my head is a number of access points, one connected to the lighting desk over cable, and the rest extending to each other - when I walk around the studio my device will automatically switch to the best signal AP giving me total coverage. Getting power to places is generally no hassle - running data cables would be more awkward, so ideally APs would connect to each other wirelessly.

Any and all recommendations of hardware, tips and tricks much appreciated. Budget is definitely of concern as well (all self funded) so where things can be avoided (ie a "brain" to manage everything makes it easier but not strictly necessary) I'll probably go that route, at least initially.

Cheers!



Moronic Monday!

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.



Fluke LANMeter software

I’ve been cleaning out our storage at work and reorganizing and came across a Fluke LANMeter 685. I cannot find the accessory pack (yet) but in reading up on it there appears to have been Windows software utilities and a firmware update available at one point from Fluke Networks. Alas, neither is available anymore from Fluke (and of course they want you to buy newer gear).

Would anyone happen to have a copy of the utilities and firmware floating around in your file storage? Yes, I know it’s an old device, but it can still be very useful to us with the right utilities available.

Thanks!



Dell PowerConnect 5548P - how to reenable a port?

Hey. Some of my ports got disabled by BPDU guard.

%STP-W-BPDUGRDPRTSUS: gi1/0/3 suspend by BPDU guard.     

Unfortunately, i dont know how to reenable those - port settings are showing that the port is Up and Active, but it doesnt work. Any advice please?