• Breaking News

    [Android][timeline][#f39c12]

    Thursday, July 4, 2019

    call-home in cisco Networking

    call-home in cisco Networking


    call-home in cisco

    Posted: 04 Jul 2019 01:55 PM PDT

    I see you can specify a custom HTTP for the call-home feature in Cisco's. Never used it. Anyone used the call-home to custom PHP scripts or anything like that? I don't plan on usign "call-home", but I am interested if other people use it.

    Currently, we use SNMP, SYSLOG, and SSH to automate our management/monitoring.

    https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_call_home/book/SCH31_Ch2.html

    submitted by /u/sfxsf
    [link] [comments]

    Do Cisco SG350 RSPANs actually work?

    Posted: 04 Jul 2019 10:52 AM PDT

    I have two SG350-20s where I'd like to do an RSPAN. I've followed Cisco's instructions to the tee, though the information on the "reflector-port" is ambiguous - does it need to be connected? I never see any of the RSPAN traffic on the destination. "sh monitor session" and "sh vlan remote-span" seem to indicate everything is correct, so I'm at a loss. The firmware release notes seem to indicate RSPANs have a bug, but I'm not sure if that applies in my situation.

    Here's a quick pseudo config on switch1 (source):

     conf t vlan 333 remote-span exit int gi20 switchport mode trunk switchport trunk allowed vlan add 333 exit monitor session 1 source interface gi1 both monitor session 1 destination remote vlan 333 reflector-port gi2 network exit 

    The switch CLI forces me to specify "network" for the reflector. The reflector port is not connected to anything and is "down" but not "shutdown."

    And now switch2 (final destination):

     conf t vlan 333 remote-span exit int gi20 switchport mode trunk switchport trunk allowed vlan add 333 exit monitor session 1 source remote vlan 333 monitor session 1 destination interface gi1 exit 

    Any insights, comments, etc. are welcome! This really has me scratching my head.

    submitted by /u/lethaldevotion
    [link] [comments]

    Technical Interview at Cisco

    Posted: 03 Jul 2019 08:12 PM PDT

    I have started the interview process for a Technical Consulting Engineer - Data Center Routing & Switching position at Cisco and have a technical interview on Friday over Webex. I was told in an email that it will only be 10 to 20 questions. Does anyone know what to expect? I was surprised it's only a few questions so I assume this is just the initial screening.

    This isn't through a recruiter (if that matters).

    Thanks!

    submitted by /u/dotson83
    [link] [comments]

    Is optical SFP DDM/diagnostics monitoring using SNMP useful?

    Posted: 04 Jul 2019 12:29 AM PDT

    It seemed to me that monitoring SFP DDM/diagnostic values (TX/RX power, voltage, temperature) would be a good practice for preventive maintenance. Having recently spent over a week troubleshooting problems in an optical link, I thought maybe looking at SNMP-DDM graphs would prevent end user complaints next time.

    When looking for a switch with 8-16 SFP ports, I was very surprised to find that monitoring SFP DDM is not supported over SNMP.

    SFP DDM is widespread, which has to mean it's useful, right? Yet the data can be only accessed manually using CLI or browser, is not available automatically using SNMP.

    Does it mean continuous values tracking / graphs are actually not used in practice and alerting is implemented within switch using Warning/Alarm thresholds and SNMP traps?

    submitted by /u/lux44
    [link] [comments]

    Lenovo RackSwitch - Scheduler? Kron? Cron? Nothing???

    Posted: 04 Jul 2019 05:27 AM PDT

    Morning all,

    I've been poking around in the CLI of my RackSwitch, trying to figure out how to automate some things (eg: turn a port on/off at a specified day/time).

    However... I can't for the life of me find any type of scheduling functionality on the switch itself. Am I going crazy, or, is this an unrealistic expectation?

    I'm pretty sure most Cisco devices had kron... but again, could be crazy too.

    Thanks!

    submitted by /u/furay10
    [link] [comments]

    What work should I be consulting out as the only network guy?

    Posted: 03 Jul 2019 07:41 PM PDT

    Spread pretty thin lately and I'm starting to wonder what I can outsource without creating even more work for myself later.

    submitted by /u/deafultadmin222
    [link] [comments]

    Is it worth it to switch to IMS from Softswitch?

    Posted: 03 Jul 2019 08:14 PM PDT

    My company uses soft switch for fix core, Is it worth like saves money or it gives better service to switch to IMS from old soft switch?

    submitted by /u/Janec201
    [link] [comments]

    Windows 10 with DOT1X and MAB, MAB fallback not working

    Posted: 04 Jul 2019 12:18 AM PDT

    Hello everyone,

    trying to get a windows 10 VM working with a VIOS as a NAD, flexauth is configured on the NAD for the sequence dot1x and as a next-method MAB.

    A problem that occurs is that when dot1x fails, the windows 10 vm has decided that authentication failed, which causes the green light for the MAB check from the NAD ,which occurs with changed timers around 10 sec later, to be not working

    Has anyone successfully managed to get windows 10 or any other OS working with flexauth where MAB is a next-method and also does anyone know where the issue could be?

    any info is appreciated.

    submitted by /u/ll9050
    [link] [comments]

    IKEv2 Linux Server (VPS) to Windows Client

    Posted: 04 Jul 2019 11:59 AM PDT

    I am trying to setup a road warrior VPN to my VPS on a CentOS 6.10 box and Libreswan

    Following all instructions, I have successfully created and can log into my VPS using Windows VPN client with a 509 and IKEv2. I get an IP address from the IP pool and all is good.

    However, I need to be able to configure the VPN so that all traffic can route through my VPS and a whatismyip will show my VPS's IP address.

    As well, I have given my VPS an internal IP address which I cannot ping once connected.

    Any advise would be appreciated

    Server Config

    conn ikev2

     left=%defaultroute leftcert=X.X.X.X leftid=X.X.X.X leftsendcert=always leftsubnet=192.168.103.0/24 leftsourceip=192.168.103.1 leftrsasigkey=%cert right=%any rightid=%fromcert rightaddresspool=192.168.44.10-192.168.44.250 rightca=%same rightrsasigkey=%cert narrowing=yes dpddelay=30 dpdtimeout=120 dpdaction=clear auto=add ikev2=insist rekey=no pfs=no ike-frag=yes ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024 

    ,aes128-sha1;modp1024 phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes128-sha2,aes256-sha2 modecfgdns="8.8.8.8 8.8.4.4" encapsulation=yes mobike=yes

    when I connect:

    PPP adapter VPN:

    Connection-specific DNS Suffix . : IPv4 Address. . . . . . . . . . . : 192.168.44.10 Subnet Mask . . . . . . . . . . . : 255.255.255.255 Default Gateway . . . . . . . . . :

    I noticed on my PPP adapter, there is no default gateway, which I am guessing is an issue but not too sure how to proceed

    thank you

    submitted by /u/eternal_peril
    [link] [comments]

    Internet2 peerage and bandwidth shaping in Palo.

    Posted: 03 Jul 2019 05:52 PM PDT

    I have an interesting case. We are a main interconnect for our ISP and currently interface two 10g connections. We (they) are also Internet2 (I2) members, so much of our campus traffic can freely flow to those exchange peers without incurring a hit on our "ISP provisioned rate."

    We are also peered with other sites on our ISP ring, we pass a lot of traffic back and forth as we are each other's DR. Any traffic between these sites also does not incur a count against our provisioned rate. Thus, only Internet1 (I1) destined traffic is subject to the rate.

    The ISP does not throttle, shape or QoS. It is left to us to comply, which we've done well with thus far. They basically just ding us on overage rates sustained above 95% of the provisioned rate, which I don't believe has ever happened. And also, it is only on egress I1. Ingress I1 does not incur the same limit restrictions.

    However, I just discovered that the Palo links to the edge have an egress QoS value set at our provisioned limited rate as the Max for all classes, thereby impacting all interconnect traffic, I2 and I1 equally. Palo does not let you create QoS egress exceptions based on subnet destinations in the Network QoS profile; you can create exceptions to the profile based on source networks.

    What would be your ideal method of chopping up this traffic by destination and rate limit only the I1 stuff for egress? I am pretty sure I figured it out, but would be curious if I'm not so unique in my specific quandary and could take some pointers from other I2 member engineers.

    submitted by /u/CryptoFascistZoology
    [link] [comments]

    SNAT Server Sanity Check

    Posted: 04 Jul 2019 06:01 AM PDT

    I need a quick sanity check on my iptables config for SNAT. I've a bunch of servers in a private IP space with no external access 10.0.10.0/24 that I'd like to have access out to the internet when needed.

    I've a CentOS box that has firewalld disabled and the below iptables rules added after clearing everything out. I believe this should allow anything within that network to set it's gateway to my CentOS box and get access out. I'm confident that only computers in the defined range can go in through the SNAT internally, I'm just concerned I'm opening up the public side of the SNAT to allow stuff in to my internal side. Or some other security issues I'm totally missing.

    There just doesn't seem to be a whole lot written about implementing SNATs!

    ```

    ens6 internal

    ens9 external

    -P INPUT DROP -P FORWARD DROP -P OUTPUT ACCEPT

    -A INPUT -i lo -j ACCEPT -A INPUT -s 10.0.10.0/24 -i ens6 -j ACCEPT

    -A INPUT -p tcp -m tcp --sport 53 -m state --state ESTABLISHED -j ACCEPT -A INPUT -p udp -m udp --sport 53 -m state --state ESTABLISHED -j ACCEPT -A INPUT -p tcp -m tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT -A INPUT -p udp -m udp --sport 80 -m state --state ESTABLISHED -j ACCEPT -A INPUT -p tcp -m tcp --sport 443 -m state --state ESTABLISHED -j ACCEPT -A INPUT -p udp -m udp --sport 443 -m state --state ESTABLISHED -j ACCEPT

    -A FORWARD -i ens9 -o ens6 -m state --state RELATED,ESTABLISHED -j ACCEPT -A FORWARD -s 10.0.10.0/24 -i ens6 -o ens9 -j ACCEPT ```

    submitted by /u/lokenx
    [link] [comments]

    SPAN/MIRROR flow generator recommendations

    Posted: 03 Jul 2019 11:22 PM PDT

    Hi all,

    I'm looking for some recommendations on a *flow generator (preferably netflow) which will receive traffic from a SPAN or Mirrored port as well as a analyzer.

    I really just want to know the source ip/dest ip/dest port that is coming over the wire and have this data available in a CSV or similar.

    submitted by /u/scriptersx
    [link] [comments]

    When do you consider Cisco gear EoL?

    Posted: 03 Jul 2019 05:53 PM PDT

    Thinking of an access switch on an internal company network, do you use the last day of vulnerability/security support, or the last day of HW support as your "EoL" date for equipment?

    submitted by /u/JamMan23
    [link] [comments]

    Can you daisy chain CWDM passive mux/demux ?

    Posted: 03 Jul 2019 04:33 PM PDT

    Want to make sure I understand the way the "Line" port and "Expansion" port work on a passive mux. Can they be daisy chained like:

    M/D #1 Line <-----> Expansion port of M/D #2 Line <----->Expansion port of M/D #3 Line <------> Expansion port of M/D #4 ? I realize that I can not duplicate any wavelengths along the chain but I've never tried daisy chaining them. Seems like it should work.

    submitted by /u/endmatter
    [link] [comments]

    Enterasys E7

    Posted: 04 Jul 2019 03:18 AM PDT

    Hi Everybody, anybody here know much about Enterasys E7 Chassis switches. I'm trying to fit a line card to the chassis to increase capacity but I'm hit with the log of a version mismatch. Anybody know the process to upgrade versions of this linecard or generally any linecard ?

    submitted by /u/joeyscottyzazu
    [link] [comments]

    Need help with a routine package installation that broke my clusters network connection

    Posted: 03 Jul 2019 06:02 PM PDT

    Hello,

    I have an older High Performance Cluster running Centos7 that had a very strange problem today. I was installing some prerequisite packages for python 3.7. They installed fine on the head node, and then it failed on the child nodes due to the hostname resolution failing. I figured it was a DNS issue, so I checked the network status. It was running fine on each node, but no DNS. So, I elected to restart the nodes. That didn't fix anything. After some more troubleshooting I restarted the head node, and now the network interface that handles ssh and other public connections is not detected on the network. Instead, the local interface to handle communication between the nodes seems to be multi casting on the network. Perhaps this was an issue before I installed these packages, but things were working fine the last time I did this for a server maintenance just a few weeks ago. The network interfaces are both up and running well since I can ping both IPs. The problem is that I just can't ping or connect to anything else. It's all unreachable.

    Im quite new to HPC, and am at a loss. I haven't changed anything to this system and neither has the Networking team Any suggestions on what to look for to fix this issue would be wonderful.

    Thanks!

    submitted by /u/bradjac2
    [link] [comments]

    Fluctuations in dBm sensor values

    Posted: 04 Jul 2019 06:59 AM PDT

    Hi,

    I've been thinking about this for quite some time. We are monitoring all our SFP core ports in Observium and I can see Fluctuations on TX/RX one some interfaces, its not a lot (0.1db) but one other interfaces its really stable. Seems to be more of an issue on fibers internally (both SM and MM) but not so much on dark fiber exiting the building.

    I know interference can be a thing but should it Fluctuate at all?

    submitted by /u/studiox_swe
    [link] [comments]

    Troubleshooting script in python?

    Posted: 04 Jul 2019 04:59 AM PDT

    Hi Guys,

    just want to ask if any here currently using or developing a script that conduct a pre-checks and simple troubleshooting on multiple device? Can you share the details of your tool and the user representation(output)?

    Currently I'm building a simple one and it's a CLI output that summarize the output from my pre-checks command. Just want to gather some idea on how to create a better one. thanks

    submitted by /u/1searching
    [link] [comments]

    Not qualified SFP module Arista DCS-7124S EOS 4.2.2

    Posted: 03 Jul 2019 06:45 PM PDT

    Context/Info:

    Hello, first off, my boss bought these discounted switches and we are struggling because the sfp modules we have are not supported by the switch.

    The switch is an Arista DCS-7124S as the title says, and is version 4.2.2 of EOS. Everything is running fine if I use Arista sfp modules or even a couple other brands I have available, the thing is, I can't find the blessed code for this switch to allow third party sfp regardless of qualification.

    I already tried service unsupported-transceiver wiprolabs f5047577 but no luck, the command is not even recognized. Also tried touch /mnt/flash/enable3px, but this version does not accept touch as a command, let alone create the file.

    For the record, my sfp modules are shown with status "errdisabled", although displayed -correctly- as "10GBASE-LR".

       

    Actual question:

    Has anyone here managed to make this switch/version able to use third party sfp modules? Anyone with the magic code?

       

    Any help is highly appreciated, thanks in advance.

    submitted by /u/harmancasvi
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel