Monday, September 13, 2021

Is this a WAN or LAN problem?

Hi all,

We've got a client who's been having irregular internet dropouts for a few months now. They've become more common in the last 2 weeks which is why I'm writing this post. At most, they'll happen 4 times a day. They have an AVD environment which makes this even more critical.

The method we know it drops out is when the remote session drops out and the continual ping the onsite IT guy has running to an external address and the gateway. The one to the external address will stop for around 10 seconds but the internal one to the gateway will continue. The gateway is a Watchguard M200. We've got a dimension server setup and we can see the VPN to Azure reastablishing but not a lot else. The WAN provider has assured us that it's not their problem as they've been out and replaced all of their equipment but they haven't been particularly helpful and I'm not confident in their monitoring. What steps would I take next? Is their any free tools I should look at that will help identify where this issue may lie?



Firewall comparisons/testimony (Checkpoint/Palo Alto/Fortinet)

TL/Dr; looking for rankings of firewall/security gateway products.

My organisation (10k staff users + 4k guest WiFi), is currently running a HA cluster of Checkpoint 13500's. They have served us well, but recently have run out of steam when we have tried to enable Identity Awareness and HTTPS inspection, and are at the end of their life, needing replacement.

In the last 18 months we have had significant issues with VPNs and Checkpoints implementation of IKEv2 (which an engineer let slip was non standard). Due to the VPN issues, the board have mandated that we consider additional vendors in the replacement tender, despite our teams experience and expertise is all Checkpoint-centric.

As is understandable, every vendor thinks their product is best, and it's hard to form a proper opinion from presales demos and discussions. So what I'm after is some objective comparisons between the brand's, such as those found at esecurityplanet.com, so that we can get a sense of how they compare to each other, notable benefits/pitfalls that are hard to judge at this stage, so that we can do our diligence and not just take the vendors word for how awesome they are, especially if they score similarly and need tie breakers that I can present as evidence either for or against.

The vendors that we are looking at are Palo Alto, Fortinet and Checkpoint.

So far I really like the look of Checkpoint's Maestro system, but concerned about the support we have had recently, and Palo Alto seem to be saying all of the right things that would make management weak at the knees.... But it could just be all presales banter!



Outdoor Event, Temporary Hotspot

Hello,

I need some recommendations for setting up an outdoor wi-fi hotspot for a one day event with 500-800 spectators. The purpose of the hotspot would be for the spectators to view the stream of two wireless cameras inside a building 50’ away. The people will be located in a 125’ x 200’ area.

Thanks



Adding VSF member into Aruba stack

Hello,

I have a new stack of Aruba 6300m CX line. Had some help with the initial setup but ended up needing to add an additional member to the stack. I have the DAC from member 8 to member 9 (the new one trying to add), then from member 9 back to member 1. Members 8 and 1 have the flashing Stk light

I have a case open but thought I would try here in the meantime since its not urgent. Here is the config.

Switch trying to add:

ssh server vrf default ssh server vrf mgmt vsf member 9 type jl661a link 1 9/1/51 link 2 9/1/52

existing stack:

ssh server vrf default ssh server vrf mgmt vsf secondary-member 2 vsf member 1 type jl658a link 1 1/1/27 link 2 1/1/28 vsf member 2 type jl658a link 1 2/1/27 link 2 2/1/28 vsf member 3 type jl661a link 1 3/1/51 link 2 3/1/52 vsf member 4 type jl661a link 1 4/1/51 link 2 4/1/52 vsf member 5 type jl661a link 1 5/1/51 link 2 5/1/52 vsf member 6 type jl661a link 1 6/1/51 link 2 6/1/52 vsf member 7 type jl661a link 1 7/1/51 link 2 7/1/52 vsf member 8 type jl661a link 1 8/1/51 link 2 8/1/52

I feel like I am just missing something very simple.

​

Thanks,



DHCP Snopping and DAI

Hello all!

Big networking noob here.

I would like to set up DHCP snooping and DAI on some switches, however I have many doubts on which ports to trust.

Right now DHCP snooping trusted ports are only the ones serving as uplinks between the switches and also the ones to which the DHCP server is connected. But, as far as I understand DAI trust should be given only to switches uplink ports (provided both sides are set with DAI)... what about the port leading to the DHCP server?

Should the DAI trust be assigned to that one as well?

For maximum security should I set up an ACL with a static IP and MAC of my DHCP server and scan the port against it?

Thanks!



SFP slow speed issue

slow data transfer speed(1Gbps) when testing with linux to linux but when i test with windows to windows i get good speed(7Gbps). i am using a dell fiber switch 8164f to connect a dell r720 with a dell m1000e chassis. i have tried setting MTU and play around with other settings no luck. i am stumped at this point and unsure what could be the issue. any help would be greatly appreciated. thanks



Unable to ping Beyond Tier 0 Gateway in NSX-T with

So I've got one physical adapter connected to a layer 3 switch as a trunk port. The host and edge transport nodes are both configured with a transport vlan of 10 and the layer 3 switch has an svi of 10.10.1.1/24 on vlan 10. This is the tep ip gateway and the tunnel status is showing up.There is also an svi for vlan 2 that is setup and has an ip address of 10.10.2.1/24. This forms an adjaceny with the tier 0 gateway and the state is showing full. I have a segment created for a test vm with a vlan id of 3 and it's in the overlay transport zone. Its ip10.10.3.1/24 and there is also a vlan created for it on the layer 3 switch with the svi 10.10.3.1. The MTU is set to 1600 everywhere and there's no firewalls blocking any routing. I'm still unable to route from the test vm to the physical network and am having issues with north/south bound connectivity. It can ping the tier 0 gateway, but that's it. The SVIs and interfaces are using OSPF in area 0. Any help would be greatly appreciated.



Block all the new devices connecting to the network

Hi there,

I work in an environment with over 700 assets, multiple switches (Alcatel-Lucent) and 3 different subnets.

All the assets are connected to a domain and have DHCP IPs.

I'm asked by my boss if there's a way to save the current assets connected to the network and block all the new ones, even if they're connected to the domain.

He asked if it is possible to do it via MAC address, allow the already existing ones and block the new ones.

I'm more of a HelpDesk than a Networking guy so I really need your help folks!



HPE Aruba JL682A resetting when loosing power

Hey folks.

I'm currently in the process of configuring six JL682A network switches and I've found something weird.

For reference: - I'm using local management. Not cloud. - Firmware is up to date, 1.0.5.0 - Bought them new, not used, arrived today

When you log in the first time with user admin and no password you have to change your credentials. So I've done that and I've also configured some things like the device name and so on. Then I unplugged the switch to bring it to the rack. After plugging it back in I noticed that my user was deleted, so I had to log in with no password again, and the device name as well as the clock where reset to.

So I'm wondering if this is the intended behavior. It seems like it because all of my six switches are doing this. But if this is in fact how the switch should perform I'll send all of them back asap.

Thanks in advance everyone!



HPE SN2010M - BGP Community Tagging

Hey there,

​

Has anyone had experience with setting up BGP community tagging on a HPE SN2010M switch?

We're running Onyx v3.8.2204 on them and we've got basic iBGP up and running, but our ISP is requiring us to add community tags to our routes. I've set up an IP prefix-list and attached that to a route-map, but when I try to add a community via the set community command the only option is 'set community none'

Any help appreciated here, I'm losing what's left of my mind over this...