• Breaking News

    [Android][timeline][#f39c12]

    Monday, October 1, 2018

    I'm no longer a Network Engineer Networking

    I'm no longer a Network Engineer Networking


    I'm no longer a Network Engineer

    Posted: 01 Oct 2018 08:39 AM PDT

    Inspired by other recent posts.

    Years ago I was working towards CCIE and decided that taking a bunch of professional certs along the path was a good approach, so if I didn't get there then I'd still have something to show for it. Currently I hold 3 Cisco professional certs and have been getting a flood of e-mails to show they were expiring soon.

    I think they're useful for getting my CV up the pile but I'm seeing less value in infrastructure specific stuff and more in full stack knowledge or applications. To get mine back would be about 8 exams and it's always good to learn so decided to crack on anyway and spent the last few months of limited spare time working through the SWITCH subjects. The joys of spanning-tree that I'd managed to forget!

    Then I went to book the exam - £225, ouch! The cost of that has just tipped me over the edge, add that in with needing to take time off work, travel to the test centre, deal with the daft questions on obscure bits of the syllabus and go through all the general pain that Cisco exams entail. It doesn't sit well with me to try and profit from people who are basically ambassadors for your products.

    So I think that's it for me, I've been Cisco qualified for the last 15 years and in 12 days time that ends.

    And I have £225 towards my next guitar.

    submitted by /u/wombleh
    [link] [comments]

    What is this person trying to accomplish?

    Posted: 01 Oct 2018 07:38 AM PDT

    I had to set up some new firewall rules to kill sessions more quickly and auto-untrust anyone who decided to start a thousand sessions at once, because some mass spammer was flooding us with thousands of zombie sessions preventing anyone from accessing our site, but all from the same IP (though the IP does change from time to time).

    What even is their goal here? It's pretty easy to block, even automatically, so is it just to be a minor nuisance?

    submitted by /u/Kwahn
    [link] [comments]

    How long for CCIE written + lab?

    Posted: 01 Oct 2018 08:41 AM PDT

    Hey gang, I finally have the cycles to throw a few hours a day at studying for my CCIE-W. I am training with Jeff over at the Network Dojo and it got me thinking...

    I have been working through the material for about a month, but lets say that I study 20hrs/wk - when should I expect to be ready for my written?

    And outside of that, how long do you guys recommend spacing the lab after the written?

    My company is nice enough to pay for all this stuff and I work from home - so its a pretty sweet setup as I can just study anytime I am not doing billable work.

    submitted by /u/jetter23
    [link] [comments]

    Confirm please.. same Rackmount Ears for 9300, 3650 and 3850??

    Posted: 01 Oct 2018 10:50 AM PDT

    Some idiot tossed the box to our new 9300 series and I'm having trouble locating the rack mount ears.. can someone confirm that the 3650, 3850 and 9300 all share the same ears?

    submitted by /u/OnceUponNeverNever
    [link] [comments]

    (x-post from /r/cisco) Reminder: Cisco ASA's that are now End-of-Support

    Posted: 30 Sep 2018 09:35 PM PDT

    Looking for thoughts on connecting 3 buildings around town via leased fiber from local ISP

    Posted: 01 Oct 2018 10:54 AM PDT

    So we have 3 locations that we will be connecting via leased fiber from the local ISP (no ethernet/routing services from them, just a fiber port to connect to), and I am wondering about layer 2/3 on the remote sides. The main location (which is where the servers are that the remote locations need access to, and where the internet gateway is) has a layer 3 switch that we will use to connect the 2 remote buildings, but on the remote side do I NEED a layer 3 switch, or would I be just as well served by a layer 2 switch. These remote networks are flat - not vlans. I envision a VLANed port on the layer 3 switch at the main location for the fiber connection, and DHCP helper to get services to the remote buildings. If I should do a layer 3 switch at the other end, tell me why. Thanks.

    submitted by /u/gr33nmonk3y
    [link] [comments]

    Switch that can do wire speed static NAT

    Posted: 01 Oct 2018 11:11 AM PDT

    Hi, all, I am looking for a switch that can do wire speed static NAT (no ALG required), supports netconf, speaks BGP, can hold couple thousand IPv4 routes, what are my options?

    submitted by /u/oldcreek12
    [link] [comments]

    Charter/Spectrum WAN Connectivity (EPLAN)

    Posted: 01 Oct 2018 09:58 AM PDT

    Has anyone done any deployments in the recent past with Spectum. We have around ~70 locations in the new combined footprint and have always done a large amount of business with the legacy Charter & TWC sides. For the branch locations we had typically done just direct Internet/DIA in the past, but due to the lower cost of the EPLAN type product, we have began looking at feeding them that way and getting larger DIA circuits for at least 2 locations centrally (primary & backup for the branch).

    We currently have 3 corporate office locations and 2 branch offices on it and it works really well and we have been happy. However more recently we have been made aware of some limitations that are not great from a design perspective.

    • 5Gbps is the max circuit size in any legacy charter site or between any mix involving legacy TWC and legacy charter
    • Apparently legacy TWC network was more "advanced" and you could do 10gbps within the legacy TWC network
    • You can only do a max of 1gbps on a "backbone" location. For example we have a DR site in Phoenix and TWC has a presence at 120 E Vanburen, however because this is called a "backbone" site, you can only do 1gbps

    We had honestly looked at doing 10gbps in phoenix, but the one factor would limit that to 5gbps, and now the other factor they are saying with it being a backbone site would only allow 1gbps.

    Anyone else having WAN connectivity limitation issues with the new monster that is spectrum?

    submitted by /u/cooldude919
    [link] [comments]

    Application slowness over MPLS. Latency and bandwidth appear to be fine.

    Posted: 01 Oct 2018 12:22 PM PDT

    Hi, I've got a strange issue I was hoping someone could help me with because I cannot for the life of me figure it out. We have a new site with a 100Mbps MPLS circuit. This circuit is from Zayo Communications but the last mile carrier is CenturyLink. We're seeing application slowness with a few of our applications (GE CPS EHR, Biscom Faxing, others). Internet traffic, speed tests all seem just fine. These applications use a combination of HTTP, SMB, LDAP protocols. The slowness is anywhere from 5-10 seconds slower than all of our other sites and is consistent. This is the only circuit we have that routes through CenturyLink as the last mile. Consistent ping times range from 10-12 ms while our other circuits are closer to 2-5 ms back to our primary data center.

    I have tested bandwidth and we are receiving close to the 100Mbps. The slowness still occurs after hours with little traffic. I've verified our MTU settings, no errors (All Dell routers/switches), no fragmentation that I can see or test for.

    Any clues on what I should look for? I have a ticket open with Zayo and so far intrusive testing has not shown any issues with the circuit.

    Thanks for any insight!

    submitted by /u/Kg5o3
    [link] [comments]

    Cisco firepower alternatives

    Posted: 01 Oct 2018 07:51 AM PDT

    Hey guys! I am working on a project with one of my clients, to upgrade their firewalls. We are currently looking at the below models for Cisco:

    FPR2130-NGFW-K9 List Price $29,995 (4.75 Gbps)

    FPR2140-NGFW-K9 List Price $64,995 (8.5 Gbps)

    We'd like to explore some cheaper options - Palo Alto, Fortinet, Juniper... Anybody, with experience, have any suggestions as to some less expensive options? We are going to start with throughput, then examine other feature sets from there.

    submitted by /u/Connan23
    [link] [comments]

    ISE guest with internal users?

    Posted: 01 Oct 2018 01:12 PM PDT

    I need to set up sponsored or self registered guests on wireless in ISE, but I'm on a lab type network that doesn't have external identity sources available. Is this possible? It looks like they are required to authorize the portals, but I'm not sure I understand why internal users wouldn't be an option for that.

    Ideally, I want to run the SAW, and just have ISE and the WLC configured with minimal headache. What are my chances of that happening, lol?

    submitted by /u/on_the_nightshift
    [link] [comments]

    Security concept question...

    Posted: 01 Oct 2018 01:08 PM PDT

    What's the name of the security model that distinguishes the difference between denying all traffic and whitelisting acceptable traffic, or allowing all traffic and blacklisting unwanted traffic? I thought there was a term for it but can find it in my personal database...

    submitted by /u/nolannator
    [link] [comments]

    Amazon v. VAR for Cisco 3850s -- pro/con?

    Posted: 01 Oct 2018 01:03 PM PDT

    We need one Cisco 3850 48-port 1-gig PoE+ switch (WS-C3850-48P-S), and got a quote from a VAR for about $7400 for the base unit. My Accounting dept is understandably pushing back after finding some new C3850's for about $2900 on Amazon.

    How can I -- and should I -- justify nearly triple the cost by going through a reseller?

    Note that:

    - I'm personally sold on using a VAR, understand and explained all the benefits, but need to justify extra cost.

    - Amazon seller prices are all over the map, some as low as $2900, others over $8000. What's up with that?

    - We're not a volume buyer and this is a highly recommended VAR, plus all the presales support, getting every last cable right, registering serial #s with Cisco -- so I'm confident this is a decent value. Not going to shop VARs to squeeze down the VAR price and no VAR can match $2900 anyway.

    - Reports vary about if you can add SmartNet to equipment obtained off-channel / gray-market.

    - The moral angle of doing the "right thing" to support businesses will carry little weight with Accounting.

    - Our growth expectations don't support the scaling argument of buying tens of switches every quarter, it'll be a trickle at most for a few years, so some of the advantage of a VAR isn't there yet.

    This Reddit thread addresses the same question but it's 2 years old and nothing conclusive came from it.

    https://www.reddit.com/r/sysadmin/comments/3pdy2r/experiences_buying_cisco_from_amazon/

    I agree with the poster who says "I would be leery" -- but I need more than "leery" and "gray-market" to keep Accounting and the CFO from toasting our rear-ends when we ask for the extra G's.

    submitted by /u/certless
    [link] [comments]

    HP GbE2c Woes in the Homelab!

    Posted: 01 Oct 2018 10:53 AM PDT

    Hey r/networking,

    I've recently came up on a woe with the Gbe2c's that makes understanding tagging/untagging + pvid nearly damn impossible for me to grasp.

    I have the following networks uplinked to said switch:

    netBlock, vlanID, Appliance, uplinkInterfaceOnGbe2c

    192.168.1.0/24, VLAN 1 (DMZ), AT&T uVerse Gateway, /c/port 21

    10.0.5.0/29, VLAN 1, SonicWall NSA2400, /c/port 23

    10.13.37.0/24, VLAN 1337 (VM mgmt Traffic), SonicWall NSA2400, /c/port 23

    10.13.38.0/24, VLAN 1338 (Redundant ^^ mgmt), SonicWall NSA2400, /c/port 23

    Since I can't throw the uVerse box in bridge mode, I decided to use the appliance as a literal DMZ; all my devices and VMs sit behind the SonicWall beside my VPN server and IIS box (which while everything resides inside the BladeSystem Chassis, these blades have a direct link to the DMZ. As opposed to flowing external ingress traffic through the SonicWall.)

    So I discovered these Gbe2c's are Nortel based and I can't figure out its operation; hence me reaching out here ;). I'm used to Cisco and Ubnt.

    Here's a consolidated config that does NOT hand out 192.168.1 address's.

    /c/port 2 pvid 1 //pvid 1 is actually omitted from config dump. /c/port 23 tag ena /c/l2/vlan 1 ena name "uVerse" def 21 /c/l2/vlan 1337 ena name "VLAN 1337" def 1 3 4 5 6 7 8 23 /c/l2/vlan 1338 ena name "VLAN 1338" def 9 10 11 12 13 14 15 16 23 /c/l2/stp 1/clear /c/l2/stp 1/add 1 666 1337 1338 /c/l2/stp 1/port 21/off /c/l2/stp 1/port 23/off /c/l3/if 1 ena addr 192.168.1.253 broad 192.168.1.255 vlan 1 // also omitted from config dump. /c/l3/if 2 ena addr 10.13.37.253 mask 255.255.255.0 broad 10.13.37.255 vlan 1337 /c/l3/if 3 ena addr 10.13.38.253 mask 255.255.255.0 broad 10.13.38.255 vlan 1338 /c/l3/if 256 /* addr <dhcp> /* ena /c/l3/gw 1 ena addr 192.168.1.254 /c/l3/gw 2 ena addr 10.13.37.254 /c/l3/gw 3 ena addr 10.13.38.254 

    The only logical thing is that my /c/port 21 uplink to the uVerse box is not tagging vlan 1 due to tagging being disabled by default. I recall with my previous Cisco switches I was able to create a seperate vlan like 666 and segment the traffic from everything else as long as I didn't configure said VLAN inside my Router.

    Now I did discover the following: ( I have no clue what the difference is )

    >> Port 21# . .... tag - Enable/disable VLAN tagging for port tagpvid - Enable/disable tagging on pvid .... >> Port 21# tagpvid Current tag pvid support: enabled Enter new tag pvid support [d/e]: e >> Port 21# 

    I'll be ordering some Catalyst 3020's here soon to replace these things but in the meantime... I need some help!

    Thanks everyone.

    Hope your Mondays are going swell.

    Cheers,

    Dom.

    submitted by /u/tht1kidd_
    [link] [comments]

    F5 question

    Posted: 01 Oct 2018 10:52 AM PDT

    Let's say I have a pool with 4 members. only 1 member is currently active, but everyone says they never shutoff the other members...the servers are up though.

    Is their any way to tell in the GUI when a member was forced offline? Like date and time...

    submitted by /u/Leopard-Lifestyle
    [link] [comments]

    Hardware Advice Needed

    Posted: 01 Oct 2018 10:24 AM PDT

    Can someone help with a Cisco hardware recommendation?

    We are upgrading a Network to 10G from 1G.

    Currently, there are two stacks. The core is two stacked 3750X's connected to three 2960-S access switches by four 1G Ethernet trunk connections.

    What will work better... a single stack of SG550XG switches mixed and matched to provide all the ports we need, or a stack of 3560's, two SG550XG switches, and two 4500X switches?

    submitted by /u/Armourlink
    [link] [comments]

    Cellular Network Backup

    Posted: 01 Oct 2018 07:17 AM PDT

    I am running a Unifi Security Gateway (USG) and have 1 ISP (Spectrum) at a client location. During the spring, this place gets super busy and if their Internet goes out, I was thinking of using Cellular Backup. They mostly use the internet for credit card transactions and their cloud-POS. Can the USG auto-switch over to cellular if the connection goes down? That's my only other option in this location.

    submitted by /u/NCMarc
    [link] [comments]

    Failed attempt to become Network Engineer

    Posted: 01 Oct 2018 05:29 AM PDT

    I always wanted to share my story about attempting to become Network Engineer, how environment and consequences changed my mind.

    I've got my CCNA and CCNP at age 16 and 19, respectively. In between, I worked as an intern and then as a NOC engineer at local ISP. During that time I was studying at school and then I become student at local university.

    At first, I was really motivated to have CCIE knowledge, but my expectations slowly faded away due to inappropriate salary and low number of vacancies for Network engineers (Compared to developers) at my area (Caucasus) or at job searching platforms worldwide.

    Because of my naive childish mind, I thought that after spending so much time apart from family, friends and social activities, even if I had CCNP, I would have at least $80k yearly salary and it would be easier for me to relocate either to EU or NA, but it didn't happen after many unsuccessful attempts.

    At that time, I had significant amount of knowledge in Linux system administration, Network engineering and basic scripting, So I unconsciously started to shift to the DevOps role.

    I started new job as a QA/DevOps engineer at US startup that had an office in my country. With my team, I successfully completed several projects and moved to the new job at local Bank as a Automation/DevOps Engineer, where I am currently at age 21.

    Now, I don't dream about CCIE anymore, I agree that it is valuable knowledge to have, but I think it is better to focus my energy and time to somewhere else. As a DevOps engineer I've got much more perks and prospects ahead of me (I am getting offers from different countries without sending resumes, much more salary, feel more valuable, etc..).

    I am glad that I didn't stick to the certification career path due to my characteristic about finishing things to the end, even if it does have negative effects on me or does not have effect at all. I will see how it goes from now.

    submitted by /u/-nixx
    [link] [comments]

    OSPF on Aruba 3810M

    Posted: 01 Oct 2018 04:36 AM PDT

    I have some problems configuring Aruba 3810M to talk ospf to HPE A5800 (comware) It seems aruba gets only connected routes from A5800 while other device (mikrotik) connected to the same A5800 gets all routes? What I'm doing wrong?

    HPE to Aruba Interface config:

    interface Vlan-interface927 description aruba ip address 172.31.27.1 255.255.255.252 ospf cost 100 

    HPE to Mikrotik interface config:

    interface Vlan-interface804 description mikrotik ip address 172.31.120.13 255.255.255.252 ospf cost 100 

    Aruba confg:

    ip route 0.0.0.0 0.0.0.0 172.31.27.1 metric 60 ip router-id 172.31.1.1 ip routing router ospf area backbone enable exit interface loopback 0 ip address 172.31.99.1 ip ospf 172.31.99.1 area backbone exit vlan 927 name "VLAN927 uplink" untagged 1/48 ip address 172.31.27.2 255.255.255.252 ip ospf 172.31.27.2 area backbone ip ospf 172.31.27.2 cost 100 exit vlan 1097 name "VLAN1097 ospf network1" untagged 1/1 ip address 172.31.97.1 255.255.255.0 ip ospf 172.31.97.1 area backbone dhcp-server exit 
    submitted by /u/tommyd2
    [link] [comments]

    UK - Which internet provider does this building have?

    Posted: 01 Oct 2018 05:22 AM PDT

    Hi, is there any way to tell whether this building has a Virgin or a BT connection?

    There are photos of the external cables here: https://www.reddit.com/r/VirginMedia/comments/9k5unf/does_this_building_have_virgin/

    Thanks!

    submitted by /u/gooseodyssey
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel