• Breaking News

    [Android][timeline][#f39c12]

    Wednesday, April 3, 2019

    Rant Wednesday! Networking

    Rant Wednesday! Networking


    Rant Wednesday!

    Posted: 02 Apr 2019 05:04 PM PDT

    It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

    There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

    submitted by /u/AutoModerator
    [link] [comments]

    Need advice to setup university WiFi in rural Uganda

    Posted: 03 Apr 2019 06:18 AM PDT

    Hi! First time poster here. Not sure if this is the right sub for this question - if there is a better place to post this please let me know.

    So, the gist of it: I'm a computer scientist involved in a (social science) project to bring video-based e-learning to a remote university in Gulu, Northern Uganda.

    We want to offer the students of this university access to world class online video lectures, such as those from Stanford or other institutions. Many of these videos or courses are available online for free. The problem is that there's no inexpensive or reliable way for the students to get to these videos.

    There is (glass fiber!) internet at the university, but it ends in the "server room" (if you can call it that). There is no WiFi network. There are three or four computer labs with about 400 decaying Pentium 4's in total, all of which are running some ancient version of Windows. The university does not get all the potential bandwidth from the fiber connection (which was installed by Google), but they are paying for something like 20Mbit. They are considering to increase it to 30Mbit or 40Mbit. Perhaps unsurprisingly, the university administration itself has decent computers and good internet. Students typically have cheap Android phones, and they all have 3G (or 4G?) internet through a mobile provider, for which they obviously pay out of pocket.

    Within the university it's easiest to sell this project by using the flipped classroom approach: the video lectures don't replace the regular lectures, but they're given as homework.

    So, how do you get video lectures to these students?

    - They cannot use the decaying computers (because they're decaying and because you can only use them while on campus, and not at home as homework). Also, it's unclear if the university's limited internet connection would be enough for this.

    - They typically don't have laptops or computers themselves, so that's out of the question too

    - You can't ask them to watch these lectures on their phone, because they would have to download them using their mobile data bundle, and that's really expensive (especially for large video files) so you can't just demand that from them.

    So, the plan I came up with is to install a local mirror server that will download and host the video files, so that the university's internet connection only has to download the video once. Then, I want to install a proper WiFi network on campus so that students can connect to the university WiFi with their phones and download the video from the local video mirror server. I will probably have to develop a small app for that. Then, students can take the downloaded video file home at watch it as homework. Could work, no?

    However, I'm a programmer and not a network engineer, and I have no fucking clue where to start. I will go there in early May for one week and would be able to bring and install some hardware.

    The WiFi routers would be installed outside, in a humid and hot climate. I think it's possible to shelter them from the rain, if necessary. We have to assume the power can go out at any time (regular power cuts), and we cannot make assumptions about the skill level of the people who will end up maintaining them - so it needs to be as fool proof as possible. The routers itself can/will be connected to ethernet. Additionally there's a limitation as to how many devices we can take into the country: about 10 or so. Ideally we'd cover the whole campus, but if it's better (or more realistic) to only cover a part, that's fine. On good days there would be a few hundred students on campus at the same time (300 or 400 or so).

    Our budget for this is about €5000…. Do you think it's possible? Feasible, even?

    I'm grateful for any input you might have. If you think it's ridiculous, please say so. Do I need a higher budget? How would you approach this problem?

    submitted by /u/akie
    [link] [comments]

    Netalyzr is gone - anyone have ideas for a replacement?

    Posted: 03 Apr 2019 12:23 PM PDT

    I've been using ICSI Netalyzr for years to quickly check network quality. It seems that they've stopped development and took the app offline. I'm wondering if a similar tool exists?

    submitted by /u/OutdoorsLvr
    [link] [comments]

    Anyone have any design experience with Packetfence?

    Posted: 03 Apr 2019 02:07 PM PDT

    I've been keeping my eyes open for a NAC replacement... would potentially go with ISE but we don't have the licenses or money for it right now. We may pursue it in the future but I'm spending some time finding alternatives to what we have now that will allow us to continue moving forward with features. Packetfence has caught my eye.. I've been really impressed with the feature set and the number update schedule.

    We're using a RADIUS based NAC for both wired and wireless access in our Residence Halls (as well as our academic wireless and guest networks) currently but not doing full 802.1x. Mostly it is MAB with devices auto-classifying based on a combination of fingerprinting factors. Devices that don't get classified currently require a call to our support center at which point we manually register it. Wireless is all Cisco and wired is mostly Cisco with a few Dell 6248 switches.

    I'd like to move forward with 802.1x, MAB fallback with a portal sign-in page for devices that can't do 802.1x, and perhaps a self-registration portal so students can register devices that aren't capable of 802.1x and don't have a web browser. The goal would be for all devices to have a user-id associated with them and the ability for the students to self-manage their devices. I'd like to avoid requiring an install of a policy key on the end-user devices if possible. Also, I'm thinking a Layer 3 deployment would fit with our needs better so the Packetfence server would probably be on a DC network somewhere using our existing DNS and DHCP services. Ipv6 support would be great at some point as well.

    I'm wondering if anyone with Packetfence has experience with such a deployment? If so, is this a reasonable deployment plan or am I looking at it incorrectly or outside the feature set?

    Thanks in advance!

    submitted by /u/Dotren
    [link] [comments]

    EAP-TLS With IOS and ANDROID

    Posted: 03 Apr 2019 01:50 PM PDT

    Ready to pull my hair out cus this topic just doesn't sink in with me, but here goes:

    I'm looking into testing EAP-TLS on a wireless network with iphones and android devices as clients. As it stands, android will ignore certs presented to it, presumably because they are not trusted. iPhone will at least ask if you want to trust the cert. My first point of confusion is whether or not iphone and android need the full chain (root/intermediate/server) or just the root cert in order to trust.

    My next point of confusion is finding out how I can push profiles to iphones and androids that have the cert bundles they need and get them to trust them. I believe MDMs can do this, but can't force iphone and android devices to trust. Has anyone every successfully done this?

    Has anyone gotten EAP-TLS to work with Android/iPhone? What CA did you have to use? The server is going to be a Clear Pass Policy Manger. Thanks!

    submitted by /u/s1nsp4wn
    [link] [comments]

    What do you all use for enterprise level scripting?

    Posted: 03 Apr 2019 11:30 AM PDT

    So at my job we have an in-house application that is our only option for scripting of network tasks. It supports python but has limited input parameters and is not very user friendly for non-scripters.

    I was wondering what other enterprise-grade solutions you all use at your jobs, for things like automating tasks and config changes on multiple devices that meet certain conditions, etc. I don't really know what else is out there, open source or commercial (especially for very large networks). What are the favorite things about your scripting tool/s and what are the biggest drawbacks or things that you wish you could do?

    submitted by /u/dacv393
    [link] [comments]

    Monitor vMotion VM migrations from Nexus 9K

    Posted: 03 Apr 2019 01:07 PM PDT

    Hi,

    to keep it simple, I have 2 ESXi which are linked via Cisco Nexus 9K. What I'm looking forward to do is to trigger a script when virtual machines migrate from one ESXi to another (vMotion). I need to do it from the Nexus by tracking MAC addresses. I can't use syslog/logging, I need to send a notification to a web server when a MAC mouvement is detected (virtual machine migration). Can I achieve that with event handlers ? Thank you.

    submitted by /u/AntoineGJ
    [link] [comments]

    ISE 802.1x rollout to multiple sites - dACL vs Vlan and Vlan Groups

    Posted: 02 Apr 2019 09:19 PM PDT

    Currently for 802.1x and MAB with Cisco ISE I am using a dACL for unauthenticated domain machines along with some rules that use either different dACLs to allow traffic or a specific Vlan for certain machines. This is working well, but I need to roll this out to multiple sites and I have some concern as not all of the sites have uniform Vlan setups and have their own distributed servers for AD and such.

    Right now its easy to apply to any normal data vlan.

    Machines without domain certs get put in guest vlan and set to guest registration portal - VLAN redirect (MAB)

    Machines with a domain cert get a 'Domain Services Only' dACL. Allows AD auth and SCCM patching, certs, etc - dACL (802.1x)

    Domain users logging in via 802.1x with Domain machine cert and domain user cert get standard access accept - no dACL or VLAN (802.1x)

    Special case users get specific vlans by dept (HR, Finance, etc that are pre segmented) - VLAN redirect (802.1x)

    Works pretty good, except I only have 1 site so far. As I roll out I will have to add a ton more servers to the dACL (local AD, DNS, SCCM, and Cert servers) So I can see that dACL getting very large and applying to a lot of ports. I'm worried about the dACL overhead, is this typically an issue in large deployments?

    I'm also worried that the Vlans are not consistent throughout each site, so this may end up in resulting in a huge policy list providing proper Vlans.

    Theoretically I could use dACLs for all groups and simplify it a little bit, but that would mean a dACL applied to nearly every port, is this even feasible? Does anyone use this approach?

    The solution I thought to use to simplify this setup prior to rollout and making it easier to roll out would be to use a standard unauth Vlan and a standard set of vlans for a Vlan Group. It would be easy to carve aside a set of vlans I could deploy at every site and I could script it pretty quickly. I would have each site's individual 'Domain Services' ACL entries applied to the site's own Unauth Vlan and then a Vlan Group or two that I can name the same but customize at each site as needed. This would clean up my Policy rules and overal Vlan usage. It does require some more background maintenance though..

    My idea would look like:

    Machines without domain certs get put in guest Vlan and set to guest registration portal - VLAN redirect (MAB)

    Machines with a domain cert get put in standard Unauth Vlan. Allows AD auth and SCCM patching, certs, etc -VLAN redirect (802.1x)

    Domain users logging in via 802.1x with Domain machine cert and domain user cert get standard Vlan Group - VLAN load balance (802.1x)

    Special case users get specific Vlan Group by dept (HR, Finance, etc that are pre segmented) - VLAN load balance (802.1x)

    Does this seem like a better plan for a rollout? Has anyone used Vlan Groups and multiple Vlan redirects with 802.1x with success?

    Suggestions welcome!

    submitted by /u/supaflash
    [link] [comments]

    Aruba Wireless Network Issues (Lost)

    Posted: 03 Apr 2019 08:14 AM PDT

    We currently run Aruba Wireless on Campus. Running an Aruba 7220 wireless controller. We keep getting reports of people saying that are having major connectivity issues between 10pm and 1am every night. Sometimes they are even kicked completely off the Wi-Fi and others they have no bandwidth (0.05 down). I am at a loss, this issue does not present itself during the day. Does anyone with Aruba knowledge have any idea where I can even start looking into this? We do have Airwave and the AP that these people connect to are AP105s.

    Thanks!

    submitted by /u/caistTV
    [link] [comments]

    Multisite EVPN with Cisco BGWs

    Posted: 03 Apr 2019 03:33 PM PDT

    Hello,

    I'm working on EVPN Multisite solution based on Cisco Nexus 9k switches. Currently I have prepared one site with eBGP as under and overlay routing - 2x Spine in one AS and 2x vPC pair leaf switches in separated AS.

    This solution works fine for L2 EVPN and is full compliant with RFC - works with pair of Cumulus switches in clag as extra leaves.

    In next step I want to prepare mirrored site and connect them together by 2x BGWs and 1x SuperSpine layers/ per site.

    If found some documentation: https://www.cisco.com/c/en/us/products/collateral/switches/nexus-9000-series-switches/white-paper-c11-739942.html

    But in most important part they send me to "For more information" chapter without giving any answer :(

    Questions:

    • BGWs should be in different AS then SuperSpine and Spine switches?

    • BGWs should have full VNI base - sum of all VNI in same site/both sites?

    • Is iBGP session between BGWs necessary?

    • Do you seen any whitepapers or working deploymend?

    Sorry for my english - is not my native language. And of course thanks for answers.

    submitted by /u/pietrucha92
    [link] [comments]

    Best place for learning network service provisioning?

    Posted: 03 Apr 2019 11:33 AM PDT

    I would like to study concept of network service provisioning. Mostly about business related things such as peering, AS, transit network, QoE, VPN, etc. Things that an ISP should know. Any recommendations? Could be even a youtube channel if such exist.

    submitted by /u/tarttari
    [link] [comments]

    Specifying allowed subnets on BGP bird filter?

    Posted: 03 Apr 2019 05:59 AM PDT

    This is for internal BGP only for internal routing flexibility.

    Let's say the client owns 203.0.113.0/24 subnet and we want to allow him to announce various IP prefixes from within 203.0.113.0/24 subnet to route collecter which would deny or accept based on filter. How can I specify in the route collector filter to allow anything from 203.0.113.0/24 subnet to be accepted from that client? Which could possible involve prefixes like 203.0.113.64/27.

    I can allow prefix variation but not the network IP:

    filter client_filter{ if!(net ~ [203.0.113.0/24{24,32}]) then { reject; } accept; } 

    Maybe some kind of regex is possible?

    submitted by /u/OzschmOz
    [link] [comments]

    Observium PHP loadding issue

    Posted: 03 Apr 2019 12:47 PM PDT

    I have followed this doc to the letter {https://docs.observium.org/install_rhel7/}. I have Observium running and during a polling or discovery you can see that it did add devices and does see them. But when you try to go to the web page it loads in index.php file as text. Any idea what I have missed?

    submitted by /u/Brianbsi
    [link] [comments]

    Need a cheap, basic layer 3 device for a DMZ switch

    Posted: 03 Apr 2019 08:37 AM PDT

    I'm looking to pick up two layer 3 switches for a DMZ switches. We don't plug everything into our firewall and our existing DMZ switch runs at 100Mb and we need to get bigger pipe.

    One of our ISPs requires us to do some simple static routing on our end, so that's layer 3 is required.

    Someone here posted the FS S3900 switches awhile ago and for $280 they fit the bill on paper, but no one seems to have experience with them. Can anyone comment on that or suggest another slightly smarter than dumb switch? I'm not opposed to picking up a refurbed one either. Anything is probably better than the existing HP4000m we're rocking right now

    submitted by /u/byrontheconqueror
    [link] [comments]

    Wireless Guest Network, VLANs and ASA DHCP oh my.

    Posted: 03 Apr 2019 08:24 AM PDT

    Trying to set up a wireless guest network, Unifi APs, Cisco Switching, Cisco ASA, I cannot for the life of me get DHCP working in the properly layout

    Working Layout:

    AP (Guest VLAN 940)

    Switch A (MDF) AP Port Config:

    interface FastEthernet3/0/48

    description ===>AP Port

    switchport trunk encapsulation dot1q

    switchport trunk native vlan 110

    switchport trunk allowed vlan 110,220,229,940

    switchport autostate exclude

    switchport mode trunk

    srr-queue bandwidth share 1 75 25 5

    srr-queue bandwidth shape 30 0 0 0

    priority-queue out

    mls qos trust dscp

    spanning-tree portfast

    spanning-tree bpduguard enable

    ASA Port Config:

    interface GigabitEthernet1/0/16

    description => ASA Guest Wireless

    switchport trunk encapsulation dot1q switchport trunk allowed vlan 940 switchport mode trunk spanning-tree portfast spanning-tree bpduguard enable

    ASA Eth0/4-> Subinterface0/4.1 (VLAN940, DHCP Configured)

    Non-working Layout:

    AP (Guest VLAN 940)

    Switch A (MDF) AP Port Config:

    interface FastEthernet3/0/48

    description ===>AP Port

    switchport trunk encapsulation dot1q

    switchport trunk native vlan 110

    switchport trunk allowed vlan 110,220,229,940

    switchport autostate exclude

    switchport mode trunk

    srr-queue bandwidth share 1 75 25 5

    srr-queue bandwidth shape 30 0 0 0

    priority-queue out

    mls qos trust dscp

    spanning-tree portfast

    spanning-tree bpduguard enable

    Switch B (Core):

    description =>MDF to Core

    no switchport

    ip address 172.18.48.xxx 255.255.255.252

    ip pim sparse-mode

    srr-queue bandwidth share 1 70 25 5

    srr-queue bandwidth shape 30 0 0 0

    priority-queue out

    mls qos trust dscp

    description =>DS to Core

    no switchport

    ip address 172.18.48.xxx 255.255.255.252

    ip pim sparse-mode

    srr-queue bandwidth share 1 70 25 5

    srr-queue bandwidth shape 30 0 0 0

    priority-queue out

    mls qos trust dscp

    Switch C (DS):

    Description => Core to DS

    no switchport

    ip address 172.18.48.xxx 255.255.255.252

    ip pim sparse-mode

    srr-queue bandwidth share 1 70 25 5

    srr-queue bandwidth shape 30 0 0 0

    priority-queue out

    mls qos trust dscp

    ASA Port Config:

    description => ASA Guest Wireless

    switchport trunk encapsulation dot1q

    switchport trunk allowed vlan 940

    switchport mode trunk

    spanning-tree portfast

    spanning-tree bpduguard enable

    ASA Eth0/4-> Subinterface0/4.1 (VLAN940, DHCP Configured)

    VLAN 940 is defined:

    interface Vlan940 description => GuestWireless ip address 10.94.x.x 255.255.255.0 ip helper-address 10.94.x.y

    10.94.x.y being the interface on the ASA

    submitted by /u/inkarnata
    [link] [comments]

    Which collaboration tool?

    Posted: 03 Apr 2019 12:09 AM PDT

    Hi All, I'd like some advice on Telepresence / collaboration tools you use.I only have experience with Cisco SX20 product, which is nice but I see no replacement products right after the EoS advice on Jan2018 (please correct me if I'm wrong).So which systems do you use and you would recommend?Have a nice one!

    submitted by /u/tziupa
    [link] [comments]

    Aruba 2930F - Dynamic ARP protection and incomplete DHCP-snooping binding table, will it work?

    Posted: 03 Apr 2019 06:56 AM PDT

    I'm in the process of hardening an 8 port 2930F and I'm unsure what the effect of ARP protection would be in this instance:

    The switch currently has 6 Cicso phones attached to it and each phone has a laptop daisy chained from it. All phones and laptops are working fine and getting their DHCP addresses on their relevant VLANs.

    If I look at the dhcp-snooping binding table, only one port is showing two devices (phone and laptop; an entry for each) with all other ports only showing the phone. (No idea why only one port is showing the complete picture).

    If I enable ARP protection, considering that the dhcp binding table doesn't show the laptops, will it prevent ARP requests from reaching/leaving those laptops?

    (Side quest: Is there a resolution to the fact that not all ports are showing the complete info as above?)

    Many thanks

    submitted by /u/Findesiluer
    [link] [comments]

    Juniper VSTP Questions

    Posted: 03 Apr 2019 09:57 AM PDT

    Hey all - hopefully a quick question and it's just a matter of me missing something. My Google-Fu is turning up nothing on this.

    I have a virtual chassis of 9 x Juniper EX3400 48 port switches on 18.1R3.3 limited, running L2 to our aggregation layer. This stack has 12 VLANs on it, and because reasons (not greenfield), we are running VSTP. Not sure if it matters, but we are using dot1x mac authentication against RADIUS. When I try to configure VSTP on more than 11 VLANs, I get the following error when attempting to commit:

    user@stack# commit confirmed 5 [edit protocols] 'vstp' xSTP:Trying to configure too many interfaces for given protocol vports:[5173] error: configuration check-out failed 

    The Juniper docs that I've read indicate that VSTP can be applied to a limited number of ports, but I can't find what that limit is. The docs also specify a limit of 510 VLANs, which we are not even near. (https://www.juniper.net/documentation/en_US/junos/topics/concept/spanning-trees-ex-series-vstp-understanding.html)

    I've tried to discern what the [5173] in the error message might refer to. My current thinking is that 9 switches x 48 ports x 12 vlans, minus 1 port statically configured on a single VLAN puts us right at 5173. It seems to line up too well to be a coincidence. Maybe VSTP is limited to 4096 vports?

    I'm guessing that my only real option is to migrate to MSTP or RSTP. Can anyone confirm any of this or provide advice on the best way to proceed? Going full L3 is unfortunately not an option in the near future. MSTP or may not be a near-term solution, I'll have to do more research on it to see if our aggregation/core layer will play nicely.

    Thanks in advance!

    submitted by /u/havermyer
    [link] [comments]

    Hiding SSID Aruba WiFi

    Posted: 03 Apr 2019 09:26 AM PDT

    We have an old SSID we want to get rid of but unfortunately we still have thousands of users connecting to it. We are looking at ways to get users off this SSID and on to the new one and things we can do other than just emailing users (most will ignore) or just simply turning it off and letting users deal with it (management will never agree to that so please don't suggest this). The problem we have is we have hundreds if not thousands of new users every year and even with guidance a lot will still connect to our legacy SSID so the problem won't just go away over time.

    One thing we thought of doing was to look at hiding the old SSID so that existing users can still connect but no new users could see it and attempt to connect. I am aware it can easily be seen and connected to by anyone with a bit of knowledge but most new users on our sites will just connect to our new SSID and be done with it. I have tested hiding the legacy SSID whilst connected and find that while my devices stay connected once the SSID is hidden if I turn my WiFi off and on again it won't reconnect. If I forget the network then reconnect and auth to it while hidden then cycle my WiFi it is able to reconnect after. I presume there is a setting on the OS that specifies whether an SSID is hidden and whether to actively try and connect even if it isn't visible? I'm testing on OS X and IOS so I think these settings are not visible to the user and are only set when you setup your wireless connection while the SSID is hidden.

    Is there any way to lessen the pain of moving users off this legacy SSID or have we just got to suck it up and cause some pain?

    submitted by /u/humongouscrab
    [link] [comments]

    Is a demarcation box required to be outside or can the cable run straight from node to inside of building?

    Posted: 03 Apr 2019 09:19 AM PDT

    Hello there! Our office building is a commercial property. We currently have a demarcation box on top of our roof. I'd like new CATV cables to be ran inside so they don't sit outside exposed to weather elements.

    My question is, is there anything wrong with moving the demarcation box inside to the MDF? This way if a coax cable needs to be ran inside, it doesn't have to go outside to the demarcation box (an additional hole that's drilled). The ISP node is just a few feet away from the MDF, so could a cable be run underground from the node to inside the building? I'd imagine this is the setup for most commercial properties.

    I couldn't find any information related to my question online, any help would be appreciated.

    Thanks.

    submitted by /u/sarge-m
    [link] [comments]

    VPN management system

    Posted: 03 Apr 2019 08:52 AM PDT

    Hi, spending some money in headache pills, managing SSL VPN connections on FG.
    Clients that get stuck, unstable connections, poor debugging etc. Every once in a while situation get stable but then a windows update or solar storms make all your certainties so ephemeral.
    So I wanted to know from you wise friends, what are your VPN choices for employees/consultants/customers , and what's your ideal tool for manage them.
    Is IPSEC the cure? Are there any tools that prevent a man going nuts managing all that stuff? (not that much, speaking of about 30-50 concurrent VPN connections).

    Many thanks, have a wonderful day!

    submitted by /u/tziupa
    [link] [comments]

    Arista DCS-7048T-A-R

    Posted: 03 Apr 2019 08:04 AM PDT

    I just purchased an Arista DCS-7048T-A-R off of ebay for use in my home lab. I was trying to upgrade the EOS version on the switch from 4.6.3 to the last supported version of 4.15.10M. I created a login on arista's website, however when I go to www.arista.com/en/support/software-download all I see listed is cEOS-lab and vEOS-lab versions to download. I can't seem to find the EOS-4.15.10M.swi file for download. This is my first time working with a piece off Arista equipment and I'm confused on what I'm doing wrong.

    Thanks!

    submitted by /u/thenotrox
    [link] [comments]

    MM fiber to SM back to MM?

    Posted: 02 Apr 2019 08:08 PM PDT

    We have just moved our office into a new building, and I (company network admin) did not handle the ISP communications for the new site, or the inside wiring (my boss did that, and I answered his questions along the way.) So we moved into the new space, and it came time to turn up the new circuit, and I found that unlike our prior location where the ISP terminated their circuit in our data center, all the ISP circuits terminate in a office park MDF, and then the building's management co has an authorized inside wiring contractor extend the fiber into our suite (only that wiring contractor and the ISP techs are allowed into the MDF - no tenants.) So we had told our ISP to handoff on 1G MM fiber (LC connector), but it turns out that the inside wiring contractor ran single-mode fiber from the MDF to our suite, which I only found out when we went to turn up the circuit, even though my boss had also told them we needed MM. (When he called them to get them to change it, they told him that's the only way they do runs.)

    So now we have an ISP handoff on MM fiber, and our router (Cisco ISR4431) currently has a 1G MM SX SFP... What's the best way to deal with this situation without having the ISP have to make a change? The circuit turnup was supposed to happen yesterday, and now is rescheduled with the ISP for Thurs, which is delaying the office opening...

    Thanks!

    submitted by /u/wdennis
    [link] [comments]

    cisco ws-c2948g-ge-tx compatible with netgear gs316?

    Posted: 03 Apr 2019 07:06 AM PDT

    I have a client trying to connect a dummy netgear switch to a port on my cisco switch (see models in title).

    I have the port configured for the appropriate vlan.

    Connecting a single PC to the port will garner a proper IP address. My client wants to use the dummy switch to manage a set of laptops in a laptop cart.

    Any ideas?

    Thanks.

    submitted by /u/hokeythebandit
    [link] [comments]

    Combination of features on a Nexus 9K?

    Posted: 02 Apr 2019 08:06 PM PDT

    So I got it in my head to try to do some poor man's network segmentation in our DC. I've got two Nexus 9Ks running vPC with SVI's configured with HSRP pointed towards the servers. These SVI's have some older network ranges assigned on them and we're wanting to migrate to newer ones so I was thinking of using a secondary IP so that the server team can re-IP as they can without changing VLANs. I've also got dual-stack on these interfaces so the servers can be configured with IPv6 and the upstream connectivity is our Palo Alto firewalls with OSPF doing dynamic routing and high availability.

    To do the segmentation, I'm looking into PVLAN. The problem is, the Palo Alto's have no concept of that so the SVI for each network has to remain on the Nexus 9K. I don't really want to do ACLs, we currently use our firewall for that, so I was thinking of applying IPv4 and IPv6 policy-based routing to force traffic coming in from the PVLAN to the firewall at the next hop. Once approved at the firewall, return traffic would simply follow the dynamic routing path back.

    I've done basic research on this and it looks like all of the features are supported but I've run into issues with undocumented bugs on other Cisco platforms when combining things like this.

    Here is the list of everything I'm looking at implementing together:

    • IPv4 and IPv6 (so all other features have to work with both on the same SVI)
    • vPC
    • HSRP
    • OSPF
    • Secondary subnet to assist in migration to a different IPv4 range
    • Policy Based Routing
    • Private VLAN

    Anyone have any experience with using most of these together or see any reason it wouldn't work?

    submitted by /u/Dotren
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel