• Breaking News

    [Android][timeline][#f39c12]

    Friday, March 30, 2018

    Blogpost Friday! Networking

    Blogpost Friday! Networking


    Blogpost Friday!

    Posted: 29 Mar 2018 11:08 PM PDT

    It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts

    Feel free to submit your blog post and as well a nice description to this thread.

    submitted by /u/AutoModerator
    [link] [comments]

    Cloudflare Announcing 1.1.1.1 & 1.0.0.1 DNS Resolvers

    Posted: 30 Mar 2018 10:14 AM PDT

    A heads up since I know a lot of people like to treat 1.0.0.0/8 like private space - it seems like Cloudflare and APNIC teamed up to start offering DNS service on 1.1.1.1 and 1.0.0.1. The announcement isn't "official" yet but the service is already running.

    On the plus side the resolver is fast as lightning (probably because nobody is using it yet). The IPv6 addresses are 2001:2001:: and 2001:2001:2001::

    Edit: Google cache of the page went away, switched to a less accurate but still existing Wayback Machine version.

    submitted by /u/zamadatix
    [link] [comments]

    Cisco WLC Question... trying to improve 2.4ghz on my campus

    Posted: 30 Mar 2018 07:07 AM PDT

    Greetings all,

    Still working on trying to improve our wireless on our campus. I've gone through multiple rounds with VARs and Cisco Wireless Experts and we've made quite a few adjustments for our residence halls in particular but I'm still getting complaints. I think some of this is simply due to interferers... in some areas I'm seeing 80%+ channel utilization with less than 5% tx and rx on the AP and it's neighbors and with a number of unknown interferers in the area with unknown effect and duty cycles. We won't know for sure until this summer when we can go in with a spectrum analyzer and disable our radios for a clean survey of the air space. Since most of our residence hall APs are in a hallway covering rooms on both sides (not great, I know, but this can't be changed anytime soon), they can see each other as neighbors fairly easily.

     

    We don't support 802.11b anymore and that helped, particularly with roaming. A lot of complaints in the residence halls don't really involve a roaming situation though. Our engagements with the experts have indicated the following data rates for 2.4ghz:

     

    Data Rate Support
    1 Mbps Disabled
    2 Mbps Disabled
    5.5 Mbps Disabled
    6 Mbps Disabled
    9 Mbps Disabled
    11 Mbps Supported
    12 Mbps Mandatory
    18 Mbps Supported
    24 Mbps Supported
    36 Mbps Mandatory
    48 Mbps Supported
    54 Mbps Supported

     

    Recent attempts to improve the situation have involved reducing the 2.4ghz cell size by modifying the RRM Power Threshold v2 trigger and Maximum Power Level Assignment. I believe, judging by feedback, this had a small positive affect but it wasn't enough yet. We also enabled a 5ghz only SSID but I've already gotten a complaint about that network as well.

     

    My second attempt involved adjusting those settings again, this time to increase 2.4ghz cell size, and disable the 2.4ghz radio on every other AP (staggering between floors). We're in the process of seeing how this one plays out although RRM is still keeping the radios power level down so I started looking in to other possibilities.

     

    I'd like to disable the 11 Mbps data rate... advice we got previously was to leave it on so clients could drop down to it if necessary but I'm wondering if this isn't part of the issue since as I've read this could be causing a larger cell size for AP neighbor detection. I did try to disable it on one RF profile but got an error saying "Failed to update 11b data rate as 802.11b network is operational"... do I need to disable this data rate in Wireless->802.11b/g/n->Network" first?

     

    This is a BYOD environment so I have to support as much as possible, within reason (#sorrynotsorry802.11b). When I look up device info in Prime Infrastructure on some of the tickets I've gotten, connectivity/data rates/SNR/etc usually looks pretty good for the most part. Anyone have any similar experiences or thoughts on this?

     

    edit Update to include some additional information... all of our residence halls are utilizing a main SSID broadcasting both 2.4ghz and 5ghz with Band Select enabled (the two residence halls I'm using to test are also broadcasting the second 5ghz only SSID I mentioned above). AP units consist of Cisco 2702i APs and some 702w/1801w deployed where we had to.

    submitted by /u/Dotren
    [link] [comments]

    Cisco 3750G flash/nvram free space and filesystem geometry

    Posted: 30 Mar 2018 01:51 PM PDT

    I'm trying to copy a file to a 3750G's nvram: that is smaller in bytes than the filesystem's listed free space in bytes. However, the transfer aborts with:
    %Error writing nvram:blah (No space left on device)
    I assume this is because the free space does not indicate unallocated free space, just filesystem capacity minus straight used space (so if it's a 524288 byte filesystem with 2k blocks, and I have two 100-byte files, it would show 524088 bytes free but I couldn't actually put anything larger than 520192 bytes).
    Is there a way to find more details on the flash/nvram filesystems in these switches? Either through Cisco documentation or a CLI command to show filesystem geometry? Something that could show me actual usable space would be fantastic.
    FYI right now the nvram: filesystem has two files of 0 bytes, is showing a capacity of 524288 bytes, with 524236 bytes free.

    submitted by /u/ExplodingLemur
    [link] [comments]

    INE Is Getting Just As Bad As Solarwinds

    Posted: 30 Mar 2018 03:19 PM PDT

    We spent some $$$ for an AAP for multiple team members and a good chunk on tokens and now I'm being spammed to death. https://imgur.com/dTPXi4Z starting to feel just as bad as Solarwinds.

    submitted by /u/S3xyflanders
    [link] [comments]

    AS Path Filter list contains ^$

    Posted: 30 Mar 2018 06:14 AM PDT

    Just want to confirm what this means. Here is the config output

    ROUTER#show ip as-path-access-list 10

    AS path access list 10

     permit ^$ 
    submitted by /u/Digital_Native_
    [link] [comments]

    WLC Krack - Stable Versions of Code

    Posted: 30 Mar 2018 08:42 AM PDT

    Anybody get this stable yet? Finally got all my legacy ap's out of the environment and will probably pull the trigger.

    submitted by /u/longlurcker
    [link] [comments]

    DHCP Issue stumping me

    Posted: 30 Mar 2018 03:20 PM PDT

    Hello friends,

    I have been working with a colleague to try and figure out this issue but have run into some confusion which will probably seem completely academic to you.

    We have a device in question which is a hardware controller (http://www.wiznet.io/product-item/wiz550io) . This controller is set to allow for dhcp, and has a default IP of 192.168.1.2.

    In our main office, which has DHCP running on a windows 2012r2 server, it is able to connect properly and go through the standard handshake process.

    When I take the same device to our other office down the street, which has DHCP running off of our firewall (fortigate 60e) it fails. port mirroring and wireshark shows the device constantly sending out the discovery broadcast but never receiving a response. Other devices can get addresses just fine on this same port.

    The wireshark capture shows that the source is the 192.168.1.2 (default address) and destination is the broadcast domain 255.255.255.255. I wagered that this was probably the issue but was stumped by how it was then able to work in our other location with a Windows DHCP server. note that we do not have a 192.168.1.0/x subnet in either location.

    Before submitting this post, my colleague confirmed that once he set the default ip to 0.0.0.0 it was able to successfully obtain an address in our remote office

    submitted by /u/Saidin86
    [link] [comments]

    Server to host video streaming for nationwide company

    Posted: 30 Mar 2018 02:04 PM PDT

    Hi all,

    I work for a company that has stores nationwide. In each store we have a Samsung TV that we use to stream information pertaining to the job. I've been with this company for a year now and recently have been in charge of maintaining the TV's in each location as a side project to my normal networking tasks.

    We host our playlists on a seperate server that we pay for but I've been wanting to find a way to host these TV's playlists and maintain them on a server of our own so we don't have to pay for the licensees through a third party company. The only issue being I have never attempted something like this before.

    Does anybody here have any insight or previous knowledge/know how on this kind of thing and could point me in the right direction to get started? I really feel like this could save my company thousands of dollars every year if I could pull this off.

    Thank you for reading!

    submitted by /u/WastedTurtl
    [link] [comments]

    Cisco router for 350Mbps Internet?

    Posted: 30 Mar 2018 05:22 AM PDT

    Hi all, need some advice please!

    We recently upgraded our VirginMedia service from 152Mpbs to 350Mpbs (with static IPs and SLA). We go through a Cisco892 ISR, so we can use WAN failover (to an old ADSL line) and other features. I used to get 152Mbps fine with our old connection, but since the upgrade it's actually slower (100Mbps max download on speed-tests). When I connect directly to the Virgin router I get nearly 400Mbps, so clearly the problem is with our Cisco configuration. I found that by removing IPS from the WAN interface, it now maxes out at about 180Mbps, so nearly a 100% increase. I've determined that the general issue is that I'm maxing out the capability of the CPU on the Cisco router. Doing a "show processes cpu history" command in the CLI confirms that it is indeed struggling.

    A few questions:

    1. Why is the relatively-expensive Cisco892 router so much slower than the relatively-cheap Virgin router? I assume this is because the Cisco box is doing everything through the processor and offering more services/inspection at the cost of performance?

    2. Is there a quick-fire solution to improving this speed, i.e. anything else I can disable on the router? The only things I'm using now that could be using CPU is the general firewall (access-group in) and the SLA for failover so I don't think there is...

    3. What would be a good upgrade for my situation? I want to stick with Cisco preferably. Something that's going to do 400Mbps without killing the CPU, but not too overkill!

    Many thanks in advance!

    submitted by /u/AndyM_LVB
    [link] [comments]

    Troubleshooting Cloud Application - Bandwidth Being Blamed

    Posted: 30 Mar 2018 08:44 AM PDT

    I have a client that uses a cloud application and the users are complaining about sporadic performance problems during certain operations within the program. Using all the bandwidth and network traffic monitoring that we have in place there are no obvious issues with the Internet connection. In fact, it appears they aren't using anywhere close to all the bandwidth, especially in this application. The cloud provider has a speed test that can be run to test the connection between us and their data center. When the users are experiencing the performance issues, I have them run the speedtest. The results the users are getting back are showing a very healthy connection; always 25ms or less of latency and greater than 50Mbps upload and download. In addition to this, I have made packet captures of the cloud application (during times where no performance issues are noticed) and I have seen that these operations involve very little data transfer. In most cases it is less than 3MB in total data for an operation that when the performance problem is present is taking as long as 5 minutes to complete. In many cases the users are even having to "end task" on the cloud application because, from what they tell me, it looks as if the application is locked up.

    Currently we seem to be stuck in finger pointing mode in that the cloud provider (and some users) are just blaming our "bandwidth" as the problem. I feel like the results that the users are getting from the speedtests they are running while the problem is occurring are conclusive proof that there isn't an issue with bandwidth/connectivity but I am still struggling to get traction with the cloud provider.

    Does anyone else have any suggestions on what I can do to isolate the problem and/or prove make quality progress on getting the issue worked on in a quality way by the cloud provider?

    Any suggestions are greatly appreciated and please let me know if you need more info from me on this.

    submitted by /u/tbonejackson81
    [link] [comments]

    Using “public IPs” on private networks

    Posted: 30 Mar 2018 11:40 AM PDT

    I have a question I've wondered for a few weeks. Is there anything stopping anyone from using public ip ranges within their own LAN... for example, can I make my dhcp range for WiFi a 78.78.78.1 - 78.78.78.255.. we can assume this is a typical setup from a ISP were they provide you a public IP gateway

    submitted by /u/fecal_destruction
    [link] [comments]

    Port Security

    Posted: 30 Mar 2018 07:15 AM PDT

    Ok, so to preface this question, I am new to networking. I understand the basics and am working towards my CCNA, but I definitely have to consult Google every single day still. I tried googling this question, and asking my coworkers, but no one had an answer.

    So I'm bringing a new VoIP phone online for a customer. We use port security and sticky MAC-addresses for the network, so I SSH into the switch to clear the port and make sure the interface has the right vlans. However, I can't clear port security. I type in clear port-sec ? and it only shows dynamic as the next choice. Normally, I type clear port-sec sticky interface interface. But all, configured, and sticky don't show up as logical next steps when I use the ?. Ultimately I just removed the configuration for port security and added it back, but I was curious as to why clear port-sec sticky wouldn't work.

    submitted by /u/njandersen97
    [link] [comments]

    Cisco Firepower email alerts

    Posted: 30 Mar 2018 10:58 AM PDT

    I'm trying to more effectively monitor a Cisco Firewall on my cell phone.

    Can you help me configure alerts so they don't come as attachments to email, but are inserted in the body of the email instead?

    Connection oriented alerts come as plain text in the body of the email titled "Auto Generated Email, [yay, this is helpful]

    but the vast majority of my other alerts are titled "Emailed Report" and require downloading and opening a text file [e.g. JobSFMail-20180330163002.e276abec-e0f2-11e3-8169-6d9ed49b625f.txt] before I can see the message. [boo, this prevents me from seeing at a glance on my phone if the alert is important or not].

    submitted by /u/SudoMoniker
    [link] [comments]

    Using VLAN to separate traffic from different WiFi networks?

    Posted: 30 Mar 2018 08:32 AM PDT

    I'm hoping someone has an idea of how to help me understand/implement this. We have a good number of guests in and out of our office. We want them to be able to connect to our WiFi in the building and get to the Internet, but:

    • We don't want them to be "on the same network" as our employee servers where they could get into our staff drives or communicate directly with any of our machines, and

    • We don't want connections coming in from the guest WiFi to get DPI-SSL through our firewall, because if you don't have a special certificate installed on your machine, you're not able to get to any secure websites. This is fine for our machines because we push the certificate out, but for guests it's a pain to download and install the certificate every time, and often they're not really OK with us installing stuff on their personal computers to begin with.

    My boss has this idea that we can use VLANs and tagging to set it up so that guests get DHCP from the wifi routers and are placed on a separate VLAN with a different IP range, and we can then apply different rules to that range using the firewall. The problem is, there are only 3 of us in the department (including boss) and none of us has any experience with VLAN and we're collectively banging our heads against the wall trying to get our minds around this problem.

    In an ideal world, this is how the setup would function:

    1. The (Aruba) wifi access points have 2 networks broadcasting: Internal and Guest. When you connect to Guest, you get DHCP and it assigns you an IP in a range that's different from the one we use internally.

    2. The Aruba is configured to add VLAN tags to traffic packets on both networks. For example, let's say it tags traffic on the Internal wifi as 10 and the Guest wifi as 20.

    3. The packets are passed on to a (Netgear GS748T) smart switch, which is configured to separate the traffic onto the 2 VLANs and then pass the packets on to the firewall with the tags left intact.

    4. The firewall (SonicWall NSA 2650) is configured to apply different rules to packets with different VLAN tags. It receives the tagged packets and applies DPI-SSL to packets tagged 10/Internal and does not apply DPI-SSL to packets tagged 20/Guest.

    I haven't been able to find any documentation in the switch manual or online about how to potentially set this up, or whether it's even possible in that configuration. If there are any VLAN gurus around here who want to help me work through this problem, or can even send me some links to good resources to help me sink my teeth into VLAN as a topic, I'd be eternally grateful.

    submitted by /u/STEM_Special
    [link] [comments]

    VLAN Question

    Posted: 30 Mar 2018 07:49 AM PDT

    I'll start off saying I'm new VLANing. I have a SonicWall TZ400 and an HP OfficeConnect 1920S. I have VLAN ID 3 configured on SonicWall X0:V3 and VLAN ID 3 configured for POS system on the switch. I have Port 5 on the switch that will be the end user device (DHCP preferably). On the Switch:

    I currently have Port 5 (End user) configured to include and tag VLAN ID 3. I also have VLAN ID 1 exclude and untagged.

    I have Port configured as a trunk (TRK1) on the switch which plugs into X0 on the SonicWall. TRK1 is currently untagged and include in VLAN 1 & 3.

    My goal is to have Port 5 (POS end user) go out to the internet without any communication to the rest of the network with VLAN 3.

    As I said I am very new VLAN and still learning, I am sorry if I seem confused at first and have questions.

    Thank you for your help in advance.

    submitted by /u/sdonohue1994
    [link] [comments]

    Looking for a specific Media converter

    Posted: 29 Mar 2018 06:47 PM PDT

    So a while back in one of the media convert posts. Someone had an sfp to copper converter that they said was comparable in price to a FS.com one, but was wall mountable and had space inside a cover to coil the patch cord. It was white in color.

    I can't seem to find the post. Anyone have any ideas?

    submitted by /u/stazy
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel