• Breaking News

    [Android][timeline][#f39c12]

    Monday, May 13, 2019

    Moronic Monday! Networking

    Moronic Monday! Networking


    Moronic Monday!

    Posted: 12 May 2019 06:04 PM PDT

    It's Monday, you've not yet had coffee and the week ahead is gonna suck. Lets open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarassed to ask!

    Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

    submitted by /u/AutoModerator
    [link] [comments]

    Need to perform my own wireless survey - Suggestions?

    Posted: 13 May 2019 12:25 PM PDT

    I have an environment that is currently running EoS 1142 APs, we however can not get the funding to pay for a proper wireless survey. Our goal is to find gaps in the 5ghz coverage and to identify 2.4ghz interference. When completed, I am submitting a quote for replacing all the EoS APs with newer models and extra to cover the gaps.

    I have been tasked to come up with a quote of equipment and software required to perform my own wireless survey. Has anyone here had to do this and to what success? What equipment and methodology did you use to complete the task? Any considerations I have to have going into the work?

    submitted by /u/NewTypeDilemna
    [link] [comments]

    10g InterVLAN Routing on Layer 3 switch

    Posted: 13 May 2019 11:12 AM PDT

    Right now we have all our InterVLAN routing done on the Firewall, but the I'm hoping to improve upon that now that our core switches are both 10gbe layer 3

    Our current network is daisy chained this way down 1gbe Firewall (Fortigate 200E) --> 1gbe link to 1gbe layer 2 switch (Cisco SG200-26) --> 1gbe link to 10gbe layer 3 switch (Netgear M4300)

    Now that I have another 10gbe Netgear M4300 to replace the Cisco with, I'm hoping to do the routing on the layer 3 switches, so that certain devices on different VLANs can talk to each other at 10gbe, and internet traffic can continue to go out through the Firewall at 1gbe.

    Is this achieved by something like static routes / ACLs?

    submitted by /u/codesyrup
    [link] [comments]

    Hands on experience with BGP and OSPF

    Posted: 12 May 2019 08:37 PM PDT

    Hi guys, I've been looking at a lot of the job vacancies around and they all seem to say a lot of experience required in BGP and OSPF. Now I have passed the CCNP route exam so I know the theory, though my current company only use EIGRP, so I've had to resort to GNS3 to build a small OSPF and BGP network to get any real life experience on it though it doesn't feel enough. Does anyone have any better ideas in order to gain valuable real life experience in these areas so I can progress in my career?

    submitted by /u/mbarnes008
    [link] [comments]

    O365 Tenant restriction

    Posted: 13 May 2019 07:20 AM PDT

    Anyone doing 0365 tenant restriction ( as in keep people from connecting to other tenants in O365)

    We were trying ForcePoint, not impressed

    Does Cisco WSA, Umbrella or combination do this ? Any other vendor suggestions ?

    submitted by /u/gizbri
    [link] [comments]

    Curious about different ways to connect to an internet exchange and what it might cost

    Posted: 13 May 2019 03:46 PM PDT

    As an overly ambitious project idea I have been wondering about connecting to the internet without an ISP, almost becoming my own, just as food for thought how much would a connection from an internet exchange to a house typically cost?

    submitted by /u/Benstockton
    [link] [comments]

    VG350

    Posted: 13 May 2019 03:17 PM PDT

    Hello,

    Doing a sanity check -

    We have some VG350s at my office, we noticed that none have dual power supplies and when we asked our vendor we are being told they do not support dual PSUs. However Cisco says they DO and show pictures of dual PSUs.

    Does anyone here have an idea of which is correct and IF they do support dual what might the model be of the PSU?

    (PSU = Power Supply Unit)

    submitted by /u/wraithscrono
    [link] [comments]

    Mellanox/Chelsio 3rd party 100G/40G optics

    Posted: 13 May 2019 03:02 PM PDT

    Hi,

    We are looking for a cheaper alternative for 100G/40G optics, and it seems that FS.com has generally a good reputation, but the majority of the posts I found are for SFP+, so I was wondering if anyone who have used their QSFP+/QSFP28 optics could share their experience with them? especially if you have used them with a Chelsio NIC, since they don't have Chelsio listed as a compatible vendor.

    Thanks.

    submitted by /u/MrFr1day
    [link] [comments]

    Should I use FTP to share local files remotely?

    Posted: 13 May 2019 03:00 PM PDT

    Background:

    The small business I work for uses an old Windows PC with a Shared folder to give access to all the employees access to documents. The internet is slow (satellite internet) and has a monthly data cap, so less downloading and uploading is preferred.

    Problem:

    We would like to be able to access our files from the Shared Drive remotely. Would running an FTP off that computer be a good solution? We also thought about connecting the folder OneDrive, but the computer needs to be upgraded to run OneDrive (currently running Windows Vista).

    Sorry, if this is not the right place to be asking this; I just thought I'd ask since I have a problem that is specific to our situation. I'm not a networking person, just someone with some technical knowledge and Google.

    submitted by /u/Vesper32
    [link] [comments]

    Opinions on new router for 300/300 fiber service and voip phones on a budget

    Posted: 13 May 2019 02:45 PM PDT

    Years ago a non-profit school I help with tech switched to a voip phone system and the Asus router they were using didn't prioritize the voip phones very well. The voip folks sold them an Adtran 3120. It helped. They are now upgrading their internet speeds from 75/75 to 300/300. The current Adtran 3120 tops out at 100M.

    So...I'm looking for a new router for them. They have 6-8 hard wired computers and about 30 laptops that come in over wifi. They have a computer lab with 16 desktops that seem to saturate the network from time to time when they are all visiting a busy site. Looking for a hardware router/firewall. Their budget is $300-$400 ish.

    Considering a WatchGuard T15, the T35 is a bit expensive for them.

    PF Sense SG-3100 firewall ( https://www.netgate.com/solutions/pfsense/sg-3100.html )

    Any others that should be on the shortlist? Thank you for any guidance.

    Sean

    submitted by /u/SeanVo
    [link] [comments]

    Cisco Python change running config

    Posted: 13 May 2019 01:12 AM PDT

    Hello guys,

    at work im in charge of several hundred of cisco switches. Because we are undergoing an infrastructure migration my boss wants me to check every single switch for unused ports and document it. You can imagine how i felt when i heard that. I was not amazed over the fact that i had to SSH into every single device, do following stuff:

    - sh int | inc line protocol is|Last input -> check which interfaces are not connected and where last input/output never

    - disable those interfaces

    show int status | count disable -> count the amount of interfaces which in the end are disabled and document in a excel file.

    I have little understanding of coding from school and after TSHOOT my next goal was to start with python, but with this assignment i will have to postpone my certification.

    So i spent whole day trying to figure out how to code it and the nearest ive come is this:

    - So in another pyfile (which i dont show you here) i SSH to a device, use the command: sh int | inc line protocol is|Last input and save the output in the file ASW2.cfg which we use here as reference.

    - I dont know if thats the optimal way to do this. In my opinion id like the code to SSH into the device, send the command sh int |... (save the output as a list?), if interface is unused, disable it, if not go to next interface. Sounds easy, right?

    device = ConnectHandler(device_type="cisco_ios_telnet", ip="192.168.170.129", port="32778", username="x", password="x") parse = CiscoConfParse('C:/Users/x/Desktop/ASW2.cfg') device.enable() def standardize_intfs(parse): for intf in parse.find_objects('Ethernet'): #Would like to pick an Object with "Ethernet" AND "not connected" in it? And i would like it to check if gigabit or #fastethernet port. last_input = intf.has_child_with ("Last input never") last_output = intf.has_child_with ("output never") if last_input and last_input: x = intf.text.split() print(x[0]) configcmds=["interface " + x[0], "shutdown"] device.send_config_set(configcmds) standardize_intfs(parse) count_disable = device.send_command("show int status | count disable") print (count_disable) 

    Ive almost made it work. It picks up Interfaces which are not connected but also those who are connected. Example:

    Ethernet1/1 is up, line protocol is up (connected)

    Last input never, output never, output hang never

    Thank you!

    submitted by /u/Skywal_id
    [link] [comments]

    Dell S4148F OS 10 Switches. Help with authentication methods?

    Posted: 13 May 2019 01:18 PM PDT

    Hey All

    Coming here for some help since DELL doesn't seem to have any idea (fruitless support case) They've asked me to email my questions to escalate to engineering........

    We recently bought some S4148F Switches, and here's what we're trying to do and questions I have - any help is appreciated:

     

    Goal: Configure RADIUS authentication for switch management

     

    Issue: Switch is remote to me, so if I configure my NPS server incorrectly, I won't be able to access it again without travelling a distance to physically access it.

     

    Questions:

    • Is RADIUS configuration an "all or nothing" type of configuration?
    • Can RADIUS be configured for TELNET separately from SSH? (IE. Configure RADIUS for TELNET while leaving SSH available for local login like HP switches can do?)
    • If RADIUS is configured, does LOCAL login (IE admin or manager accounts) still work remotely?
    • IF admin account still works remotely as asked above – can that local login be disabled?
    • What are the commands to do these things? Documentation is sparse, and the documentation for OS10 seems to not work anyways.

    Thanks!

    submitted by /u/sysadminmakesmecry
    [link] [comments]

    Anyone have Peplink 380 experience?

    Posted: 13 May 2019 11:23 AM PDT

    So I'm way more familiar with Cisco products, however my current network setup at the company I'm working for is using Peplink and I'm scurred to make changes without some info.

    The LAN ports, is this essentially a switchport module?

    I want to enable LACP on the router but I'm scurred. If I just plug some more cables into the LAN ports will they just plug and play? I want to setup an etherchannel but I need to make sure I don't bring down the network so just asking some general questions.

    submitted by /u/onequestion1168
    [link] [comments]

    Copying firmware from one switch to another?

    Posted: 13 May 2019 10:56 AM PDT

    I have a stack of cisco 2960x switches in production, and was just shipped a new 2960x to add to the stack. In the past I've had issues with adding a new switch to the stack if they weren't already running the same IOS.

    The stack is running a fairly current version of IOS, but the new switch is running a slightly newer version.

    Due to stupidity within my organization, my Director (who is currently on vacation of course) is the only one with a Cisco TAC login. So I can't simply hop on the web site and download the same image the others are running.

    So what I'm wondering is - can I simply log onto one of the switches in my stack and TFTP the .bin file off, put it on the new switch and rock and roll?

    My hesitation is that unlike the good old days when the IOS image was just a single .bin file, there are a ton of other files in the folder along with the .bin, like the files in the html subfolder.

    Is there a recommended way to get the files off the old switch and onto the new? USB drive maybe?

    Thanks in advance.

    submitted by /u/hiirogen
    [link] [comments]

    2 Links into a vpls - loop prevention?

    Posted: 13 May 2019 10:37 AM PDT

    We are soon to have a vpls solution delivered to us, to enable us to link our existing UK network and a couple of data centres and offices around the world.

    In each data centre we are having 2 links into the vpls, terminating on two different routers. The plan is to have a subnet linking up the DC's, run ospf, mp-bgp, and extend our existing mpls over it. So far sounds perfectly fine?

    Now, we also have a number of new offices coming into existence over the next year, and we want to use the vpls provider to provide tail circuits back to us. Original plan was to have 2 circuits to each office, one via the vpls provider and one via a different carrier.

    The powers that be have out it to me why don't we have two links from the vpls provider as it will save costs. Is this even possible without causing a loop?

    Our offices are set up a bit differently than DC's. Instead of having 2 routers/firewalls, we tend to run a active/standby pair of ASA's. My immediate thought is to place each vpls link at the offices into a separate vlan, and subinterface the vpls link on our core routers. Then we can run bgp from the offices, multipath, and let it choose it's own routes. Apart from that it would have to be one link into each firewall in the office and just run as active standby.

    Anyone able to pipe in with some other thoughts on this?

    Otherwise if both links in same vlan we would cause a loop

    submitted by /u/LittleWanger
    [link] [comments]

    EVE-ng how to change lab import size limit?

    Posted: 13 May 2019 06:26 AM PDT

    I'm trying to import a 1.7GB Lab into EvE-ng, and receiving an error every time I try to upload.

    When I check the php_errors.txt logs, I notice this entry which seems to correspond to every failed upload attempt:

    [13-May-2019 16:11:37 Europe/Helsinki] PHP Warning: POST Content-Length of 1727900618 bytes exceeds the limit of 209715200 bytes in Unknown on line 0

    This gives me reason to believe that a file size limit is being imposed, and is responsible for the error. Does anyone know how for Eve-ng, I would change this size limit?

    submitted by /u/times0
    [link] [comments]

    Disabling web UI on Aerohive access points

    Posted: 13 May 2019 02:35 AM PDT

    Hi guys,

    Currently trying to disable the web UI on individual Aerohive access points but the following commands don't seem to do anything as I can still browse to the IP of the access point and reach it there.

    no service http no service https 

    Is there any way to do this? I found no way through HiveManager either, but perhaps I'm overlooking a setting or such.

    Thanks!

    submitted by /u/LivelyZoey
    [link] [comments]

    Understanding goodput

    Posted: 13 May 2019 09:43 AM PDT

    On the wired side, I understand goodput as the bitrate of delivered data payload [source]. This excludes all encapsulation, headers, and retransmits.

    On the Aruba wireless side, my Mobility Master dashboard defines goodput as:

    ...the ratio of the total bytes transmitted or received in the network to the total air time required for transmitting or receiving the bytes. The air time includes the retransmission time taken for both successful and dropped frames.

    Suppose 1000 frames of 1500 bytes each are transmitted in the network as follows:

    50% of frames are transmitted successfully at MCS index 11 at 108 Mbps.

    25% of the frames were dropped in the 1st attempt at 108 Mbps but were successfully transmitted using MCS index 3 at 54 Mbps in the second attempt.

    The remaining 25% are dropped in both the attempts.

    Then the effective rate is calculated as: The total bits transmitted / the total air time. In this example: (500 * 1500 + 250 * 1500) * 8 / (total air time for 50% frames + total air time for 25 % frames retransmitted + total air time for 25% dropped frames) = 40.5 Mbps.

    Which, if either, are correct?

    submitted by /u/austindcc
    [link] [comments]

    Stable/safe IOS for Cisco 3650s?

    Posted: 13 May 2019 09:24 AM PDT

    Currently on 3.6.8E, but recently been having business-impacting issues with PoE not giving out power suddenly (possibly CSCvd46008 but still working with TAC as the are some differences).

    Does anyone have experience with a decent test bed of 3650s and an MD IOS that isn't buggy? 3.8.6E perhaps?

    submitted by /u/severance26
    [link] [comments]

    T568C ?

    Posted: 13 May 2019 08:14 AM PDT

    Hey all,

    Crimping some wires at work, I am able to get a LAN phone to power on and connect to ethernet with a small t568B cable, but the longer cables we are using for something else are T568C.2 and they will power-on the same LAN phone but not give any ethernet.

    Can barely find anything useful regarding this on Google and I am wondering if there is a different pinout or a length problem? (These wires are about 10 feet) and we are using them to connect a NAS to a switch (so am i using straight-through when I should use crossover?)

    Any information is helpful, thanks everyone!

    submitted by /u/MrMouse92
    [link] [comments]

    Migrating from one ASA to another

    Posted: 13 May 2019 07:49 AM PDT

    Is it possible to just copy a running config from one ASA to USB, move it to another via USB, run it and vwalla---it has everything including secret keys?

    edit: I don't know if by moving the config it'll turn the encrypted secret into plain "*"

    submitted by /u/networkguyhere
    [link] [comments]

    Router suggestions

    Posted: 12 May 2019 09:43 PM PDT

    Hi everyone,

    I put this on r/sysadmin, and I forgot r/networking existed (sorry).

    We are looking at replacing our existing infrastructure, and I wanted some advice on what we could use. We are due to start using SAP which is served with citrix and we are in the UK.

    We use clearos on a variety of old servers at the moment as our gateways. Head office has 25 users while the other depots have some people, possibly 20 people altogether, who need access to resources at head office. Head office uses a leased line and has a single mitel (save me) pbx server which the other depots use, there are no other pbx server in the company.

    The other 5 depots use the gateways as the DNS and DHCP server, and they connect back to the head office via VPN. All depots don't have failover WAN which I want to correct for at least head office as it's the most important. These clearos servers are very old and have a tendency to break so I'm looking to standardise the configurations together, so I was thinking at a edgerouter pro for each depot and head office.

    Does anyone have any good recommendations for what router(s) I could install for each depot? Or any other suggestions in general.

    submitted by /u/gibbonlake
    [link] [comments]

    Why SLA monitor failed ?

    Posted: 13 May 2019 07:48 AM PDT

    I have VPN tunnel setup between two location and every night here and here tunnel goes down may be because not enough interesting traffic in night time. so i am thinking to setup sla monitor to generate interesting traffic, this is what i am doing

    Local LAN: 10.0.10.0/24

    Remote LAN: 10.30.0.0/24

    Life is good, i can ping remote LAN ip.

    Local_ASA (config)# ping inside 10.30.0.10

    Type escape sequence to abort.

    Sending 5, 100-byte ICMP Echos to 10.30.0.10, timeout is 2 seconds:

    !!!!

    Success rate is 100 percent (5/5), round-trip min/avg/max = 10/16/20 ms

    This is my SLA monitor config:

    sla monitor 2

    type echo protocol ipIcmpEcho 10.30.0.10 interface inside

    num-packets 3

    sla monitor schedule 2 life forever start-time now

    Look like it doesn't like and it failed to ping.. WHY ?

    Local_ASA (config)# show sla monitor operational-state 2

    Entry number: 2

    Modification time: 03:56:40.393 EDT Mon May 13 2019

    Number of Octets Used by this Entry: 2056

    Number of operations attempted: 15

    Number of operations skipped: 0

    Current seconds left in Life: Forever

    Operational state of entry: Active

    Last time this entry was reset: Never

    Connection loss occurred: FALSE

    Timeout occurred: TRUE

    Over thresholds occurred: FALSE

    Latest RTT (milliseconds): NoConnection/Busy/Timeout

    Latest operation start time: 04:10:40.395 EDT Mon May 13 2019

    Latest operation return code: Timeout

    RTT Values:

    RTTAvg: 0 RTTMin: 0 RTTMax: 0

    NumOfRTT: 0 RTTSum: 0 RTTSum2: 0

    submitted by /u/satishdotpatel
    [link] [comments]

    Switch Suggestion: 18x Gbit + 2x 10Gbit Uplink Half Width (Managed)

    Posted: 13 May 2019 02:25 AM PDT

    Any Suggestions, I dont care which company. It seems there is no half width switch with these specs.
    I only found one from netgear with 10Gbit ports, but we need only Gbit.

    Thanks for helping.

    submitted by /u/j0hnnyclaymore
    [link] [comments]

    Vyos Hyper-V bridging

    Posted: 13 May 2019 07:27 AM PDT

    Is this possible with 2 physical nics? I can create the bridge and it will get a dhcp'd ip. But it wont pass traffic or dchp requests. Do I need a dhcp forwarder/relay?

    submitted by /u/Smithdude
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel