Sunday, September 5, 2021

Port Mirror and GoFlow Collector

So I've got a port mirror on my switch connected to an ubuntu machine that is running the GoFlow docker container, its unclear to me how I might be able to have the packets coming in on that interface sent to the GoFlow collector. I'd love to be able to use GoFlow to monitor our networks with either a mirror or a tap.

I know the port mirror interface is working, TCPDump was seeing the appropriate packets coming through.

Any thoughts are be appreciated.

Thanks,
Jim



Optical fiber concealing

Hi guys. Is there any way to conceal an optical fiber cable inside building? Isps in my country(india) are hesitating to do concealing as they fear it might break the glass. Is there any cheap shielded optical fiber cable available in AliExpress which I can try doing concealing on my own?



BGP question

So usually when a router receives a prefix with its own AS in the AS-path, it will reject that route as part of a loop prevention mechanism.

So when a route reflector reflects routes to clients, are those prefixes accepted by the clients because its own AS is the most recent AS? When the route reflector reflects, I guess it doesn't prepend its own AS on (again) or make any changes from the received prefix?



Saturday, September 4, 2021

Why cant i use private DNS on mobile network?

I've tried everything to fix this, no matter what i change or override, it always uses no DNS or if i use automatic, it will use a random GOOGLE DNS. But i cant use CloudFlare no matter what i try. Does anyone know the reasoning behind this. Any help would be greatly appreciated.



Network Engineer Salary in Michigan

So I am having a hard time figuring out where I should be salary-wise. Let me explain...

I was in the Army until 2012; I was medically retired after a combat injury. I started going back to school in 2019 and have my BS in Network Security with a minor in Mathematics. My current employer is a reseller and channel partner for thousands of OEMs; as such, they ask a lot of their engineers.

Since working there, I have obtained my CCNP Security, Palo Alto PCNSA, Fortinet NSE 5, Aruba Clearpass ACCP, and other certifications from Ekahau, Dell, and HP.

My current title is Associate Regional Engineer, and my salary is 65,000 with the potential of up to 6500 in yearly bonuses.

I was fully prepared to start at the bottom, but I think the work I have put into learning, along with my employer sending me on solo projects, puts me above an Associate (entry-level) position. What I have trouble reconciling is that I literally just graduated, and I have less than a year of actual OTJ experience. While I am older than the majority of entry-level employees (38) and I have been working with IT personally for many years, on top of military leadership/project management experience.

I haven't worked in a civilian role since I was 19, so I just want to ensure I don't get taken advantage of.

thoughts / opinions?



Edgerouter-12 and SonicWall - Internet connectivity issue

Hi all,

I am running into an issue between a SonicWall and Edgerouter ER-12, ill try to be as specific as possible since the diagram isn't too detailed. Been knocking my head against the wall because this seems like it should be a no-brainer.

The Ciena SDS patches into the WAN X1 port on the SonicWall. The X1 interface is configured with a static IP from a /29 provided by the ISP.

The SonicWall X0 LAN interface connects to the WAN interface eth9 on the ER-12.

Interface eth0 is configured with several VLANs. eth0 connects to the trunk on the switch and connected devices on the access ports work as expected. Devices on VLANs configured with DHCP pickup their intended IP addresses. So no problems there.

The issue that is occurring is that the router is not passing internet traffic from eth9 WAN to eth0 LAN. I have plugged in directly from the X0 interface, assigned a static IP/DNS, and have full internet access. However, when connecting to any VLAN on the eth0 LAN port of the ER, I get no internet access. IP and DNS gets assigned via DHCP, but no internet.

I can ping to the eth9 interface (10.10.10.2/29) successfully from other VLANs on the eth0 LAN interface. I cannot ping the Interface X0 LAN (10.10.10.1/29).

However, when I set a static IP on my laptop and connect to another interface on the SonicWall (X2) that is in the same interface group as the LAN (X0) I can ping the ER interface eth9.

I don't have access to configs at the moment, but can try to post them later. However, I can provide more info if someone is willing to give advice. Thanks for any help.

Network diagram - https://imgur.com/QAdfQtY



Anyconnect VPN, granular access based on multiple AD group membership

Hi all!

The company I work for has the following setup:

  • ASA VPN
  • ISE
  • several subnets (/26-/30)
  • Azure AD
  • Integration between ASA and Azure AD via NPS server (MFA, AAA)

Each subnet is mapped to an Azure AD group via ISE (see SGT explanation below).

The business would like the anyconnect users to reach these subnets only when the user is member of the corresponding group, in a mix and match fashion. Example:

User 1 belongs to group A and B = can access both subnet A and B
User 2 belongs to group B = can only access B

(explained very similarly here)

SGT setup: In ISE, we map each subnet to its own SGT tag, and each AAD group to its own SGT tag. The ASA ruleset is therefore based on SGTs (src/dst) instead of IP/Subnet objects.

The big limitation in this approach is how the ASA sees the anyconnect user: when the user connects, it belongs to only one AAD group (SGT) at a time. This breaks the mix-and-match-multiple-groups requirement.

I have been searching for a solution to this need, and all I could find is the following:

I am afraid both of the above would not scale, as we are talking of hundreds of subnets/ad groups and consequently SGT tags.

Any idea? I am willing to radically review the approach. My knowledge of ASA and ISE is not so extensive, I am sure I am missing some bits.

Thanks!



Friday, September 3, 2021

VeloCloud Edges Disconnecting from Orchestrator and Enchanced HA Setup

Hi Team. I was wondering if any of you has experiencing this kind of issues on the VeloCloud Edges. I understand that there are certain configuration in the VeloCloud Edges that requires the device to reboot to take effect (even though minor configuration change-https://kb.vmware.com/s/article/60247), however we start seeing issues that the Edges are online as we can ping its external and internal ip addresses, but it is showing down from the Orchestrator. We have to manually unplug the edges from the power to reboot it, and regain connectivity back to the Orchestrator.

Another issue we experienced today while working with VeloCloud Support, the VC TAC started to perform debug and tcpdump on an GE2 interface as we are troubleshooting an SNMP issue, then suddenly the GE2 interface went down from the Orchestrator but we can ping its IP address.

Our set up looks like this -- Two VC Edges in Enchanced HA having two ISP connected on each Edge. What is your take on using Enchanced HA instead of Active-Passive HA? Echanced HA link -- https://docs.vmware.com/en/VMware-SD-WAN/3.3/velocloud-admin-guide-33/GUID-AD69349D-E008-4D11-9F08-550FE3AE9981.html

As you may notice I have a lot of questions, yes this is our first VC setup. So far its doing great in terms of its SDWAN performance, but we have issues on managing it, even making simple changes, and trusting its stability.



Help! Need to rewrite source address on Cisco ISR 1841

I did something very dumb and missed configuration of a default gateway on printer at remote site connected over MPLS through a Cisco 1841. There are no computers at the remote site I can remote into and big boss needs to be able to print to that remotely next week. I am quite rusty on my Cisco (I would know how to do this in a snap on a SonicWall). Is there a way to rewrite the source address of my port 80 traffic to the printer to an address on the inside interface so the printer doesn't have to use a gateway?

10.x.y.z (server in datacenter)

10.a.b.c (outside MPLS interface of router)

10.g.h.1 (inside interface of router)

10.g.h.107 (stupid printer)

Port 80 traffic destined to 10.g.h.107 gets intercepted by router and source rewritten to 10.g.h.1 and translated back out or port 80 to 10.a.b.c gets translated to 10.g.h.107 with source of 10.g.h.1 or something else?

Thanks for you help!!



EHWIC-4G-LTE-V on Verizon for home use

Have any of you managed to setup this Cisco(Verizon-LTE MC7750) card with a prepaid data plan?

When I try to activate this card on their prepaid website, I get this message after typing IMEI: "The phone associated with the Device ID you entered is not compatible with the Verizon Wireless network"

I tried the procedure on my existing cell phone service using the "Change Device" option. This is what I get when IMEI is entered: "We're Sorry! Unfortunately, we are unable to complete this request. You will not be able to change your device online at this time. Please call 888-294-6804 for further assistance."

My equipment is Cisco 1921 + EHWIC-4G-LTE-V

The signal is strong and the SIM card registers to the network without any problem.

Router#show cellular 0/0/0 network

Current System Time = Sun Aug 29 17:53:32 2021

Current Service Status = Normal

Current Service = Packet switched

Current Roaming Status = Home

Network Selection Mode = Automatic

Network = VZW

Mobile Country Code (MCC) = 311

Mobile Network Code (MNC) = 480

Packet switch domain(PS) state = Attached

Registration state(EMM) = Registered

EMM Sub State = Normal Service

Router#show cellular 0/0/0 radio

Radio power mode = ON

LTE Rx Channel Number = 3230

LTE Tx Channel Number = 23530

LTE Band = 13

LTE Bandwidth = 10 MHz

Current RSSI = -56 dBm

Current RSRP = -84 dBm

Current RSRQ = -11 dB

Current SNR = 8.8 dB

Radio Access Technology(RAT) Preference = LTE

Radio Access Technology(RAT) Selected = LTE