• Breaking News

    [Android][timeline][#f39c12]

    Tuesday, July 31, 2018

    Old Telecom Folks, did your peers talk about VoIP the same way that network engineers in this sub are talking about SDN? Networking

    Old Telecom Folks, did your peers talk about VoIP the same way that network engineers in this sub are talking about SDN? Networking


    Old Telecom Folks, did your peers talk about VoIP the same way that network engineers in this sub are talking about SDN?

    Posted: 31 Jul 2018 06:18 AM PDT

    Ex: "It's overrated/a mess/just a buzzword/poorly defined/not happening anytime soon/not a good fit for my enterprise/I don't give a shit" (Ex 2:https://www.reddit.com/r/networking/comments/6fy2pe/sdn_do_you_give_a_shit/)

    It seems like there are a lot of these sentiments in this subreddit, and I'm just wondering if the old voice engineers felt similarily around the time that VoIP was starting to compete against the traditional PBX systems.

    Side Note: Do you know any telecom engineers that didn't adapt well to the changing technology? If so, what are they doing now?

    submitted by /u/Fiveby21
    [link] [comments]

    How buggy is the firmware on these damn cisco sg300x small business switches?

    Posted: 31 Jul 2018 01:37 PM PDT

    I'm trying to configure ACL's and bind to all my vlans here and I am getting fed up with the inconsistency as far as allowing my rules to go through. One minute, the ACL works fine, then just starts blocking traffic it was just allowing a little while ago.

    Also, once I bind 2 or 3 ACL's to interfaces, it won't allow me to bind any more. I get a "Cannot apply - TCP/UDP port range ingress amount exceeded." This happened to me on the same exact ACL I successfully binded before without changing anything. I literally added a deny rule at the end to log anything I may have been missing and it wouldn't allow it all of a sudden. When I removed that deny rule and put it back the way it was, I get the ingress port error...but it had no problems accepting that same list 2 minutes ago!!

    This is beyond bad. Has anyone else experienced similar results when dealing with these shitty switches? I tried to push for the catalyst switches but my boss wanted an easier gui to work with, so here I am, stuck trying to get these to work now.

    submitted by /u/jayleel98
    [link] [comments]

    FS Box - Real-time reconfiguration for SFP/SFP+/XFP/QSFP+/QSFP28 transceivers and cables

    Posted: 31 Jul 2018 06:07 AM PDT

    FS Box is designed to help not only optical network engineers to solve real-time problems but also distributors to break free from massive stocking optimizingresources allocation. As for hardware installation, it only requires a FS Box, a Computer and an USB cable to set up and operate. What's more, one-stop coding iscarried out on cloud platform (cloud.fs.com) with clear instructions which could be done in seconds.

    https://www.fs.com/specials/fs_box_beta-58.html

    https://www.fs.com/products/73321.html

    submitted by /u/fireshroom
    [link] [comments]

    = or >60km 40/100Gbps optics

    Posted: 31 Jul 2018 11:05 AM PDT

    Is anyone aware of a company that offers a QSFP+/28 optic @ 40 or 100Gbps that can reach out to 60km or more, without the use of an amplifier, or additional intermediate WDM equipment. I understand that 40Gbase-ER4 (40K), and 100Gbase-ER4 optics are available per ratified standard. However, I'm curious if there is a company out there that are producing, or planning to produce a transceiver that can make it further than 40km. Thanks!

    submitted by /u/jrnoc
    [link] [comments]

    Shot in the dark: anyone here have experience using SEL Software Defined Networking? SEL-5056 and SEL-2740S

    Posted: 31 Jul 2018 07:46 AM PDT

    Electric utility industry focused stuff. Not your typical SDN application.

    submitted by /u/phantom_mood
    [link] [comments]

    Cisco ASA Dynamic to Static VPN with same remote network subnet

    Posted: 31 Jul 2018 08:33 AM PDT

    I have several Cradlepoint devices that will be establishing a S2S VPN connection via 4G back to a Cisco 5520 headend. The Cradlepoint will have dynamic ip addresses, and the 5520 is static. So it will be a dynamic crypto map - DefaultL2LGroup. My question is do all of these Cradlepoints have to have different local subnets (remote from the ASA's perspective) in order for this to work?

    Reason I ask is I have the clients behind the Cradlepoints receiving their DHCP from our DHCP system in the same data center as the ASA. Basically I've created one subnet for all clients behind different cradlepoints to use. So Cradlepoint01-Client01 might get 10.10.3.25 and Cradlepoint02-Client01 might get 10.10.3.26. The configuration on each CP is basically identical, and crypto map on the ASA set for 10.10.3.0/24 as the remote network. One tunnel is working fine, when I bring up 2 it introduces problems, some type of conflict and it's not working.

    submitted by /u/Vontech615
    [link] [comments]

    DHCP Option 124/125 for UBEE DDW36C

    Posted: 31 Jul 2018 11:57 AM PDT

    I am working on getting a ubee ddw36c smart cable modems connected to a GenieACS server. I am trying to pass the acs servers URL through DHCP using option 125 as suggested by the manufacturer. If anyone is currently doing this can you provide a example of how your option 125 looks or what you had to do to get it working. I have spent days on this so any suggestions would be appreciated. Below is the model of device

    http://www.ubeeinteractive.com/products/cable/wireless-gateways/ddw36c-advanced-wireless-gateway

    Thanks

    submitted by /u/lnltechnologies
    [link] [comments]

    Suggestions on a weird ospf setup

    Posted: 31 Jul 2018 01:48 PM PDT

    So I'm trying to work out a solution for ospf in my environment. It's government work, so as always it is a little strange. I have a firewall running as my default gateway. Down below I have about 30 virtual routers in front of different clouds.

    I want my firewall to have ospf relationship with every router, easy. But I also don't want any of those routers to neighbor with eachother and route directly to eachother. Essentially I don't want anything to leave those without hitting the firewall first.

    Now I could setup a different area with each router, but that seems like a very crappy way to go forward. It seems possible to do BGP, but that seems also like a very imperfect solution.

    As far as practical application I'm not great with OSPF so I'm sure there are things I'm missing. Is there are better solution for this? Thanks!

    submitted by /u/cylemmulo
    [link] [comments]

    Need to supply internet to 8 endpoints using coax and isolate each endpoint a la VLAN

    Posted: 31 Jul 2018 11:58 AM PDT

    My initial plan was to drop ethernet to each workspace where the tenant could plug in whatever switch/AP they wanted, with each endpoint switch/AP being supplied a signal by separate port on a managed switch of mine with port-based VLAN turned on to segregate each endpoint. Then I discovered that it's not possible to get ethernet into each space....

    Now I'm looking at the Coax lines. Each space already has coax and it's not being used for anything. I've tested and confirmed that the coax lines can handle 100mbps. I was looking at using MoCA, but now comes the complication... I only have ONE Coax jack in the network closet, which connects via 8-way splitter downstream to each workspace's coax jack. I've read plenty about MoCA and am confident this would be easy if I didn't need each endpoint to be invisible to all the others. I've never deployed 802.1q VLANs, but if I understand correctly I would have to have a managed switch at each endpoint which I can't do. Now my infantile brain is out of ideas so here I am..

    TL;DR - how can I take a single switch port, push internet from one to 8 already-live coax jacks using MoCA, and then segregate each of the 8 endpoints so they're all invisible to each other?

    TIA

    submitted by /u/razorvolt
    [link] [comments]

    Meraki Switches as an Enterprise Solution?

    Posted: 31 Jul 2018 07:17 AM PDT

    I'm wondering if there is anyone out there that has used Meraki's switch platform as an enterprise solution? Ideally, I'd love to hear from someone with multiple campuses and at least 150+ access switches per campus.

    The back story on this centers around a comm closet refresh. Currently, we run a mix of 3750s and 3850s, originally the plan was to refresh to all 3850s but we've had nothing but problems with that platform. Next, the plan was to go with the new Cat9Ks but someone saw the price tag on Meraki 350m series and now there is a lot of conversation on that side of the isle.

    If anyone has worked with both Cat9Ks and Merakis I'd love to hear from you. I'm very interested in all things orchestration related, specifically pushing QoS and 802.1x configs from a central management server. I really like encrypted thread analytics and SDA on the Cat9Ks but I'm hearing that these features 'just aren't there yet'.

    Our typical comm room refresh rate is 10-12 years so I see more long term potential with the Cat9Ks.

    Let me know what you think...thanks!

    submitted by /u/cap-n-dash
    [link] [comments]

    CWDM MUX instead of chaining switches?

    Posted: 31 Jul 2018 02:42 PM PDT

    https://snag.gy/qOb7aR.jpg

    We have few different campuses, currently done like in the upper part of the pic. Switches are connected to switches and to other switches etc. So if one fails, a lot switches behind that switch fail too. (Some buildings have more layers but I was lazy with paint...)

    As we don't have enough fibers from distribution switch to all access switches, I was thinking of getting CWDM MUXes and chaining them, and dropping some wavelengths on the way to switches. And hopefully in the end all the access switches are logically connected to the distribution switch by just one wavelength.

    Would this work? Do I need amplifiers anywhere (all the switches are withing few kilometers)? Any other thoughts? Would be something from fs.com....

    Thanks!

    submitted by /u/PublicSectorJohnDoe
    [link] [comments]

    Help with EEM/TCL script to run IOS-XE package clean command...

    Posted: 31 Jul 2018 02:40 PM PDT

    Simply, I need a script to run the command request platform software package clean switch all which scans the root of flash: for unused .bin and .pkg files.

    • If there are packages to clean if the switch prompts Do you want to proceed? [y/n] and awaits user input.
    • If there are no packages to clean the switch presents a message SUCCESS: No extra package or provisioning files found on media. Nothing to clean. and then returns to the exec prompt hostname#.

    Platform: 3650/3850 running IOS-XE 16.3.6

    I tried an EEM applet to that watches the switch log for %SYS-5-RESTART, then;

    1. Runs the pkg_clean.tcl script.
      1. Reconfigures int gi1/0/48; removes description.\\**
      2. Performs the "software package clean" command, with typeahead "y".
    2. Deletes SVI for vlan 2.
    3. Deletes itself (the applet).
    4. Writes the config.

    \\** I only put the Gi1/0/48 command in the tcl script so I could see the %SYS-5-CONFIG_I syslog message in debug since TCL does not print to syslog. This tells me that at least the ios_config line from the tcl script successfully ran.

    EEM Applet

    event manager applet pkg_clean event syslog occurs 1 pattern "%SYS-5-RESTART: System restarted" maxrun 60 action 001 cli command "enable" action 002 cli command "tclsh flash:pkg_clean.tcl" action 005 cli command "conf t" action 006 cli command "no int vlan 2" action 007 cli command "no event man app pkg_clean" action 008 cli command "end" action 009 cli command "write mem" action 010 cli command "" action 011 syslog msg "\n ##Old .bin and .pkg files cleaned from flash:, temporary interface vlan 2 deleted, wrote startup-config." 

    pkg_clean.tcl

    ios_config "int gi1/0/48" "no desc" typeahead "y" exec "req plat soft pack clean sw all" 

    Result... The EEM applet hits the 60 second maxrun timer and then dies.

    switch#debug event man act cli switch#event man run pkg_clean *Jul 31 2018 14:13:38.181 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : CTL : cli_open called. *Jul 31 2018 14:13:38.183 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : OUT : switch> *Jul 31 2018 14:13:38.183 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : IN : switch>enable *Jul 31 2018 14:13:38.295 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : OUT : switch# *Jul 31 2018 14:13:38.508 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : IN : switch#tclsh flash:pkg_clean.tcl *Jul 31 2018 14:13:38.551 PDT: %SYS-5-CONFIG_I: Configured from console by on vty0 (EEM:pkg_clean) switch# *Jul 31 2018 14:14:38.223 PDT: %HA_EM-6-LOG: pkg_clean : DEBUG(cli_lib) : : CTL : cli_close called. *Jul 31 2018 14:14:38.228 PDT: *Jul 31 2018 14:14:38.228 PDT: tty is now going through its death sequence 

    If I run it manually, it only takes about 15 seconds to prompt with [y/n].

    switch#show clock *14:41:47.006 PDT Tue Jul 31 2018 switch#req plat soft pack clean sw all Running command on switch 1 Cleaning up unnecessary package files No path specified, will use booted path flash:packages.conf Cleaning flash: Scanning boot directory for packages ... done. Preparing packages list to delete ... cat3k_caa-guestshell.16.03.06.SPA.pkg File is in use, will not delete. cat3k_caa-rpbase.16.03.06.SPA.pkg File is in use, will not delete. cat3k_caa-rpcore.16.03.06.SPA.pkg File is in use, will not delete. cat3k_caa-srdriver.16.03.06.SPA.pkg File is in use, will not delete. cat3k_caa-wcm.16.03.06.SPA.pkg File is in use, will not delete. cat3k_caa-webui.16.03.06.SPA.pkg File is in use, will not delete. packages.conf File is in use, will not delete. done. The following files will be deleted: [1]: /flash/cat3k_caa-guestshell.16.03.03.SPA.pkg Do you want to proceed? [y/n]n switch# switch#show clock *14:42:01.748 PDT Tue Jul 31 2018 
    submitted by /u/derek
    [link] [comments]

    802.1x and Shoretel IP Phones

    Posted: 31 Jul 2018 09:48 AM PDT

    I am testing 802.1x on my network. I am using Windows Server 2008 R2 NPS as my RADIUS and Cisco switches. Domain computers are authenticating fine. Endpoints that require mab are authenticating fine. The problem is my IP phones are not. The phone that I am testing with has had an AD account created for the mac so that mab will work. In fact if i run show auth sessions I see the phone is authenticated by mab. However it is in the data domain making the authentication host-mode multi-domain useless! Finding anything from shoretel is like finding a needle in a haystack. I found a couple cisco forum posts without answers. I can't figure out how to make it use the voice domain so the pc behind it can authenticate.

    submitted by /u/Zombiehotel
    [link] [comments]

    Site to Site solutions

    Posted: 31 Jul 2018 12:40 PM PDT

    Folks, I'm looking at connecting 5 sites together. I believe I'm going to use 5 Ubiquity Edge X routers and configure their site to site vpns.
    We're a small business. about 150 employees.
    What do you use for site to site connectivity and why?

    submitted by /u/VenomXII
    [link] [comments]

    File Storage (Isilon) and a Cisco Fex?

    Posted: 31 Jul 2018 08:32 AM PDT

    Anyone had to deploy this setup? In the past I guess there was some port buffering issue with having the Isilon attached to the FEX(C2232TM/2232PP) so they were instead attached directly to the 5Ks.

    From what I can tell it was just due to those models not being adequate for bursty traffic.

    Just trying to see if anyone ran into this situation and if there is an 2K that can handle it. Right now the storage guy is wanting us to buy another 5K just for it

    submitted by /u/_Justified_
    [link] [comments]

    CCNA Bootcamp Washington D.C?

    Posted: 31 Jul 2018 06:48 AM PDT

    I recently failed my CCNP switch and let my CCNA expire. I would like to do a CCNA boot-camp and start fresh. Anyone know of any of any good boot-camps that might be available in the DMV? Preferably in dc since that's where I work or somewhere in Arlington (where I live). I plan on using my GI bill so hopefully any recommended places might take that method of payment.

    submitted by /u/mongoooooose
    [link] [comments]

    OSPF Config

    Posted: 31 Jul 2018 09:58 AM PDT

    A previous team member setup OSPF and I'm in the process cleaning up and documenting configs in preparation for replacing equipment. He choose 172.255.x.x for the loopback and Router ID. I know the Router ID doesn't matter, but shouldn't the loopback be in a private address space? We've never had any issues, but it just looks wrong to me.

    Thank you

    submitted by /u/F1adrif
    [link] [comments]

    VPN across different service providers

    Posted: 31 Jul 2018 05:55 AM PDT

    I have about 60 machines in different data centers across the globe. I use two main service providers: Linode and DigitalOcean, as well as nodes at several customer sites. Currently, I am using tinc (r/https://tinc-vpn.org) to provide connectivity between our nodes, but I believe that I may be reaching the limits of its scalability. In addition, I want to connect our office network to this cloud network, and tinc is not readily available in most commercial firewall solutions. I have been looking into IPSec, but to be honest, I am not sure if this is the right solution either. I suspect someone has done something similar, and if so, I would really appreciate any expertise you could share with me.

    submitted by /u/tebrown
    [link] [comments]

    Teleworker gateway device similar to Cisco OEAP?

    Posted: 31 Jul 2018 09:01 AM PDT

    After deliberating on what to purchase- I am deliberating again.

    I have a user who needs a remote gateway device so that they can connect a physical IP Phone and their laptop into it and have access to our network. Currently- they use AnyConnect to remote in and the physical phone no longer works due to security upgrades.

    Cisco OEAP 1810 seemed like the ideal solution until I saw that it needed a controller. Aironet 1815t also seemed good until it needed the controller.

    What else are my options? I was going to try to shoehorn a USG IPSEC tunnel, but it gets too complicated if it isn't the main router.

    Anything would be wonderful.

    Thank you.

    submitted by /u/THEMCV
    [link] [comments]

    Weirdest Networking Issue I've Ever Seen

    Posted: 31 Jul 2018 08:02 AM PDT

    Wanted to bring this up to the community because I'm at a total loss for how to proceed. Has anyone else seen an issue remotely like this?

    Background: Running two Cisco 4500-X switches as a VSS to provide connectivity to the wiring closets in one of our buildings and also to other nearby buildings. There are primary and secondary layer 3 links to this VSS from our core sites using EIGRP to provide redundant connections to this particular location. The primary uplink connects to the active 4500 while the secondary connects to the standby 4500.

    Scenario: First noticed the issue shortly after initial installation where two-way voice traffic was not functioning properly on VoIP phones. After extensive troubleshooting we discovered that shutting down one of the links on the port-channel to these downstream switches fixed the issue. As soon as the etherchannel bundle was restored the problem resurfaced. This occurred on either link going back to one of the 4500s, not only on the active or only on the standby switch

    We also soon discovered that the secondary route would not function properly when the primary failed. The secondary still shows up as an EIGRP neighbor and weirdly enough I can still ping/ssh to other devices in our network but hardware routing seems to fail completely and devices can't actually connect to the internet. Problem is fixed as soon as the primary route is restored.

    Troubleshooting: We've replaced cables, tested fiber, replaced transcievers, ect. We checked the configuration multiple times but found it is essentially identical to other locations that are working just fine. One of our other buildings is so similar it even has the same floorplan and an identical network design and the configurations match; this other location has never had a problem. Before anyone suggests I double-check this: the config is not the issue.

    We broke VSS functionality on these switches and tried rebuilding it from the ground up. We switched the active and standby around. We tried replacing the active with a spare 4500. We replacing the standby with a spare 4500. Nothing has worked. The only thing left I haven't done is try replacing both switches in case hardware on both have happened to fail. We only have one spare 4500 so I have yet to do a full replacement to see if that fixes the issue. While there is a limited lifetime warranty on all 4500-X's I'd rather exhaust every potential solution before going through the RMA process. Plus if I performed a full replacement and the issue was still there I'd feel like a real asshole.

    Has anyone ever seen an issue like this? I've been in networking over ten years and never encountered any problem like it.

    submitted by /u/sympathyfortheball
    [link] [comments]

    Best practices for enabling SSH on network equipment?

    Posted: 31 Jul 2018 07:07 AM PDT

    A large majority of our corporate networking equipment does not have SSH enabled. Makes it very annoying having to physically console in everytime I need to make a change. I inherited this network from someone who never bothered to enable it because he rarely made config changes (he sucked in a lot of ways).

    I know that SSH is secure, but are there any risks of enabling it? And does anyone have any best practices in mind for enabling SSH? Just want to make sure. And for the record, this will NOT be port forwarded out of our router. Only local access. I'm still relatively new to networking so any help is appreciated!

    submitted by /u/eeza465
    [link] [comments]

    running out of internal IP addresses

    Posted: 31 Jul 2018 08:05 AM PDT

    Hey, we're currently using the standard 192.168.1.0/24 address range. 254 Usable IPs and they filling up soon. Simple company nothing too complex or require any type of strict regulation. What is the best way to expand our usable IPs? Increase the subnet mask to /22 to expand our IPs range from 192.168.0.0 - 192.168.3.255 or VLANs? Expanding the subnet seems to be the easiest way.

    submitted by /u/eternelize
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel