Monday, September 20, 2021

DS-Lite VPN quirks

A few months ago, I had to use my company´s VPN in HomeOffice. At that time, I had a DS-Lite internet connection (4in6 tunneling).

For some reason, I was almost unable to work because primarily stuff, that would cause large package sizes (git push/pull, file transfer, etc.) would not work.

I went through long troubleshooting sessions with our IT-Department (I´m a software dev, but our IT-Department does most of the Ops stuff), but we didn´t find a solution.
After a few weeks, I found an article, that stated the IPv6 header size was a problem because the VPN didn´t account for that. It said, that the VPN expected a 20-byte IPv4 header instead of a 40-byte IPv6 header, which was used in the 4in6 tunneling step of my connection.
It also said, that because of this overhead, a few bytes of packet content would just be dropped, therefore making the packet invalid.

The solution was lowering the MTU of my tunnel interface to account for that overhead.

My problem is, that I don´t fully understand this behavior. In all my networking classes, I learned, that too large packets would just be split and receive a part number so that they can be reassembled in the right order. I never heard of packet content being just "cut off".

Can anyone explain this behavior to me?
Some of my colleagues had the same problems, and for now it´s just lowering the MTU and that´s it. But no one really understood why those packets won´t just get split.

​

Cheers and thanks in advance



What kind of cable is this? Marked "LL58"

My 4G wireless antenna has a cable that I hook into my modem that is marked LL58. I need to extend this cable by 5-10 meters and can't find much about it, or even parts for it on Aliexpress. Anyone have a clue?

Fact sheet: https://www.elfadistrelec.no/Web/Downloads/_t/ds/710123_eng_tds.pdf



WiFi spectrum analysis

I have been tasked with troubleshooting a network connection that is mobile. The farther we delve into the data, the more it looks like an issue between our two access points.

In order to get hard data about why the antenna's are struggling, I am looking to purchase a spectrum analyzer. I see that there are apps, SDR devices, and mobile equipment from $200 to many thousands of dollars.

What am I looking for when I compare these devices?
Can I GPS map across many miles or just a single building? Do dedicated devices work better, or is this my excuse to buy a HackRF?
Can I get away with just a free app, or does the dedicated hardware provide something my phone can't?



Do I need L3 for an iSCSI SAN? I have (2) Nexus 9300 switches (no licenses installed) for a 75 user SAN.

Firstly, I know very little about switches beyond the basics and I am still trying to hire someone to help me. I did manage to get management configured and I can log into it. It appears there are no licenses installed and that the switch is strictly L2. Cisco Part# N9K-C93180YC-FX at a cost of $10,000 each which I believe will give some indication of what they are in terms of licenses. I am within the return window and I can send them back. I plan to connect them to a Purestorage flash array and I need to be sure they will work for that with no additional licenses needed. I would appreciate any guidance. I pasted some of the license command output below.
Thanks

`show license usage` Feature Ins Lic Status Expiry Date Comments Count -------------------------------------------------------------------------------- N9K_LIC_1G No - Unused - VPN_FABRIC No - Unused - NXOS_OE_PKG No - Unused - FCOE_NPV_PKG No - Unused - SECURITY_PKG No - Unused - ACI-PREMIER-GF No - Unused - N9K_UPG_EX_10G No - Unused - TP_SERVICES_PKG No - Unused - NXOS_ADVANTAGE_GF No - Unused - NXOS_ADVANTAGE_M4 No - Unused - NXOS_ADVANTAGE_XF No - Unused - NXOS_ESSENTIALS_GF No - Unused - NXOS_ESSENTIALS_M4 No - Unused - NXOS_ESSENTIALS_XF No - Unused - NXOS_ESSENTIALS_XM No - Unused - SAN_ENTERPRISE_PKG No - Unused - PORT_ACTIVATION_PKG No 0 Unused - NETWORK_SERVICES_PKG No - Unused - NXOS_ADVANTAGE_M8-16 No - Unused - NXOS_ESSENTIALS_M8-16 No - Unused - FC_PORT_ACTIVATION_PKG No 0 Unused - LAN_ENTERPRISE_SERVICES_PKG No - Unused - -------------------------------------------------------------------------------- `show running-config license all` !Command: show running-config license all !Running configuration last done at: Sun Sep 19 18:10:43 2021 !Time: Sun Sep 19 18:29:51 2021 version 9.3(3) Bios:version 05.44 no license grace-period no feature license smart



Any good, central manageable host-firewall out there

Hi!

I do not really like the "microsoft-windows-firewall" and I am looking for any better manageable firewall software, that is working at "first-rule-matching" and not as limited as the ms-version.

Firewall should be able to use DNS-objects and should have a central management with AD-filters.

​

It would be great, but not needed, if also a linux-version would be available.

​

Are you aware of anything like that?

I did only find some limited "personal-firewalls" for consumer-use, but nothing in the mid-size or enterprise area...

​

Thank you for your thoughts

ITStril



Comcast business cable modem replacement that will provide QoS?

Helping out with a friend's church. They're doing live streaming of Sunday services and want to provision enough upstream bandwidth that the stream does not suffer in quality.

Current modem is a Technicolor CGA4131COM, and the setup looks like this;

[Cable Modem (1GB down, 35 up)] <---> [Ubiquiti Dream Machine Pro] <---> [Unifi Switches] / [Unifi APs] / Streaming Computer 

Now 35mbps *should* be plenty without worrying about QoS, but when you get hundreds of people in the building (including staff) there are a lot of question marks.

Unfortunately the DMP isn't able to provide any traffic shaping. At least not on the wired ports. So it seems like the easiest thing to do would be to find a cable modem capable of QoS and then hang the streaming computer off of one port and the DMP off the other. This might end up with the cable modem being the DHCP server (or just going double-NAT) but it is what it is.

First I'm just curious if there is a compatible modem that can give me QoS features.



AT&T is a dumpster fire of a company.

I've heard my coworkers jokes for years. I've heard the sighs and exasperated words from all corners of the office.

Well I've had to interact with them more in the last 3 months than ever before and it has been a truly awful experience.

  1. We had a circuit migration, and they installed a new ciena for it. They forgot to take the ports off testing modes and migrated the circuits anyways, then proceeded to tell us our equipment was bad, and that we didn't actually have the Ciena on property that we did. My boss was literally screaming the serial numbers at the tech that was calling us liars.

  2. Intermittent network connectivity to the outside was diagnosed as "our problem" when the technician sent 5 pings to a gateway and called it good. It was not our problem. I had to gather so much information just to prove it wasn't us.

  3. Both our circuits went out yesterday around 5pm and ARE STILL DOWN. It's been over 14 hours and ATT refuses to update us with anything other than "We don't know, we're actively testing, we will escalate". One of our 3 account managers finally got back to us, but had zero clue as to what was happening. Apparently a technician has finally been dispatched, but no one knows who or when.

I know even though we pay a yearly 6 figure fee for internet, we are still a small fish in the big ocean of ATT, but mother of god this is such bad customer service and technical support.



Aruba Cisco Spanning-tree

For some backstory I work for a small IT company, our client has a lot of aged Cisco kit throughout 4 sites. We won a contract to provide them with Aruba kit (which we have since outsourced to a 3rd party to configure and install - we will then support). In the meantime we provided them with an Aruba on one of their smaller sites to give added capacity.

The network is very small, 2x 48 port Cisco, 1x 8 port Cisco and now a 24 port Aruba2930F. The Cisco's run rapid pvst+.

At the moment not many devices are connected into the Aruba but there is a recurring issue where the Cisco blocks the uplink to the Aruba, when I run sh spanning tree on the Cisco I get "BKN4 P2P *LOOP_Inc for the port in question on VLAN 51.

We have seen the same issue in the past and have just manually shut the port off and on which tended to resolve it for maybe month or so but it doesn't seem to be resolving anymore.

I feel the cause may be because spanning tree has not been configured on the Aruba, in Aruba central under device\ interface\ Spanning-tree the only option is MSTP. From what I can see this is compatible with rapid pvst+ but Aruba central only seems to give me the option to enable and select a priority of 0-15, the rest of the config options are for each interface. I suppose I'm worried about root bridge election and what might happen, I don't want to bring the network down!

I'm wondering if anyone has any experience with Aruba central and if perhaps you have any tips on enabling spanning tree to work with Cisco, I have done a fair bit of searching and did find an interops guide but didn't go into a huge amount of detail, just to enable and create an instance for each vlan.

Training is going to be provided by the 3rd party we outsourced the work to but this will probably be in the new year, if anyone could send me in the right direction for now I'd hugely appreciate it!



Address calculating

Hi guys, can someone explain to me how to figure out the address's: network, broadcast, first and last usable host address's please

My example

ip address: 192.168.10.1

Subnetmask: 255.255.255.0

Max users: 50

Thanks in advance 👍



Cisco ASAv Syslog randomly stops sending

Hi, We have a Cisco ASAv which is sends syslog to an external syslog server. It works fine for a few days, and then it just randomly stops sending syslog (despite a capture on the ASAv seeming to indicate it is sending) and it takes a reboot or redeploy to fix it.

Has anyone else come across random issues with Cisco asa randomly stopping sending syslog?