• Breaking News

    [Android][timeline][#f39c12]

    Tuesday, August 6, 2019

    Is my new career becoming obsolete? Networking

    Is my new career becoming obsolete? Networking


    Is my new career becoming obsolete?

    Posted: 06 Aug 2019 06:04 AM PDT

    27/M - I started off as a network engineer for a service provider in the UK after graduating Uni (usual Cisco/juniper/mpls/bgp relating projects) before being offered a new role which came with a very good pay rise.

    Still within a service provider, I'm currently a tech lead overseeing changes on a transmission level. So now I'm basically specialising on a L1/L2 level, things like metro Ethernet/DWDM/fibre etc... however I've come to learn that my company may be shifting away from this in favour of Juniper/MPLS entirely.

    Did I make a mistake shifting to this new role? Or are these transmission skills still sought after anywhere?

    submitted by /u/spontanious9494
    [link] [comments]

    Cisco 3750G Stack with slowness issues in 1 switch

    Posted: 06 Aug 2019 02:34 PM PDT

    Any thoughts on what else I should look at?

    I have a stack of 9x 3750G switches and recently several endpoints are having connectivity issues. Issues include broken voice on the phone which uses voice vlan, and delays for IP connectivity on the PC ports. I have found the affected devices connected to interface gig3/0/13-gig3/0/16.

    All switches in the stack are running c3750-ipbasek9-mz.150-1.SE2.bin

    Before moving devices to another switch (where there are no issues after move), I tried rebooting the phones and running 'shut/no shut' on the port. When the phones booted, they did not receive the vlan assignment from CDP. Strange.

    I am not too familiar with MLS QOS and looking for some guidance. Here is our port config, and the MLS QOS settings. Last is CEF info. I am not familiar with what these results should look like. In this case, the stack has been up for 10 weeks, and just a few ports on 1 switch are impacted.

    mls qos map cos-dscp 0 8 16 24 32 46 48 56

    mls qos srr-queue input bandwidth 90 10

    mls qos srr-queue input threshold 1 8 16

    mls qos srr-queue input threshold 2 34 66

    mls qos srr-queue input buffers 67 33

    mls qos srr-queue input cos-map queue 1 threshold 2 1

    mls qos srr-queue input cos-map queue 1 threshold 3 0

    mls qos srr-queue input cos-map queue 2 threshold 1 2

    mls qos srr-queue input cos-map queue 2 threshold 2 4 6 7

    mls qos srr-queue input cos-map queue 2 threshold 3 3 5

    mls qos srr-queue input dscp-map queue 1 threshold 2 9 10 11 12 13 14 15

    mls qos srr-queue input dscp-map queue 1 threshold 3 0 1 2 3 4 5 6 7

    mls qos srr-queue input dscp-map queue 1 threshold 3 32

    mls qos srr-queue input dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23

    mls qos srr-queue input dscp-map queue 2 threshold 2 33 34 35 36 37 38 39 48

    mls qos srr-queue input dscp-map queue 2 threshold 2 49 50 51 52 53 54 55 56

    mls qos srr-queue input dscp-map queue 2 threshold 2 57 58 59 60 61 62 63

    mls qos srr-queue input dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31

    mls qos srr-queue input dscp-map queue 2 threshold 3 40 41 42 43 44 45 46 47

    mls qos srr-queue output cos-map queue 1 threshold 3 5

    mls qos srr-queue output cos-map queue 2 threshold 3 3 6 7

    mls qos srr-queue output cos-map queue 3 threshold 3 2 4

    mls qos srr-queue output cos-map queue 4 threshold 2 1

    mls qos srr-queue output cos-map queue 4 threshold 3 0

    mls qos srr-queue output dscp-map queue 1 threshold 3 40 41 42 43 44 45 46 47

    mls qos srr-queue output dscp-map queue 2 threshold 3 24 25 26 27 28 29 30 31

    mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55

    mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63

    mls qos srr-queue output dscp-map queue 3 threshold 3 16 17 18 19 20 21 22 23

    mls qos srr-queue output dscp-map queue 3 threshold 3 32 33 34 35 36 37 38 39

    mls qos srr-queue output dscp-map queue 4 threshold 1 8

    mls qos srr-queue output dscp-map queue 4 threshold 2 9 10 11 12 13 14 15

    mls qos srr-queue output dscp-map queue 4 threshold 3 0 1 2 3 4 5 6 7

    mls qos queue-set output 1 threshold 1 138 138 92 138

    mls qos queue-set output 1 threshold 2 138 138 92 400

    mls qos queue-set output 1 threshold 3 36 77 100 318

    mls qos queue-set output 1 threshold 4 20 50 67 400

    mls qos queue-set output 2 threshold 1 149 149 100 149

    mls qos queue-set output 2 threshold 2 118 118 100 235

    mls qos queue-set output 2 threshold 3 41 68 100 272

    mls qos queue-set output 2 threshold 4 42 72 100 242

    mls qos queue-set output 1 buffers 10 10 26 54

    mls qos queue-set output 2 buffers 16 6 17 61

    mls qos

    interface GigabitEthernet3/0/15

    switchport access vlan 30

    switchport mode access

    switchport voice vlan 50

    srr-queue bandwidth share 10 10 60 20

    queue-set 2

    priority-queue out

    mls qos trust dscp

    auto qos voip trust

    spanning-tree portfast

    !

    #show cef not-cef-switched

    % Command accepted but obsolete, see 'show (ip|ipv6) cef switching statistics [feature]'

    IPv4 CEF Packets passed on to next switching layer

    Slot No_adj No_encap Unsupp'ted Redirect Receive Options Access Frag

    RP 0 0 644 523 0 35 0 0

    2 0 0 0 0 0 0 0 0

    4 0 0 0 0 0 0 0 0

    7 0 0 0 0 0 0 0 0

    5 0 0 0 0 0 0 0 0

    3 0 0 0 0 0 0 0 0

    6 0 0 0 0 0 0 0 0

    8 0 0 0 0 0 0 0 0

    9 0 0 0 0 0 0 0 0

    #show ip cef switching statistics

    Reason Drop Punt Punt2Host

    RP LES No route 3 0 1

    RP LES No adjacency 18653013 0 0

    RP LES Incomplete adjacency 269131 0 0

    RP LES TTL expired 0 0 3

    RP LES IP options set 0 0 35

    RP LES Features 0 0 18

    RP LES IP redirects 0 0 523

    RP LES Neighbor resolution req 15797655 65 0

    RP LES Total 34719802 65 580

    All Total 34719802 65 580

    #

    submitted by /u/dcanter
    [link] [comments]

    GNI Planner FTTx

    Posted: 06 Aug 2019 12:02 PM PDT

    I have a post on their website but I figured I might ask here also.

    We are testing the GNI planner for a FTTH deployment but on step 1 we receive the error Error executing algorithm Refactor fields Evaluation error in expression ""full_id"": Column 'full_id' not found . Has anyone else hit this error and might know how to fix it?

    submitted by /u/WolfraiderNW
    [link] [comments]

    Nexus logs

    Posted: 06 Aug 2019 09:08 AM PDT

    Trying to find a way to limit the number of logs we keep on our Nexus devices and I can not find it. When I do show logging i get about two years worth of logs. If I remember on the Catalyst you could set a limit for logs but Nexus I am not having the same luck.

    Anyone have commands that are good outside of self truncating the logs when viewing?

    submitted by /u/wraithscrono
    [link] [comments]

    IDS python callback

    Posted: 06 Aug 2019 02:56 AM PDT

    Do you know any IDS (open source) that supports python code execution as callback to some rules? I want parse the packets myself and return some value to the IDS that will indicate what to do with this packet.

    submitted by /u/TomHatskevich
    [link] [comments]

    Best study material for CAP (ISC²) exam

    Posted: 06 Aug 2019 01:04 PM PDT

    Local Network, Users work off VPN < Printer

    Posted: 06 Aug 2019 03:34 PM PDT

    I have some users who work through a VPN in our office.

    these are terminals, basic dell. issue is, they cant access the printer on our network due to them being on the VPN

    if they need to pring they have to disconnect. and reconnecting takes a bit.

    im about to set up a print station - before i go that route any suggestions?

    submitted by /u/X4217
    [link] [comments]

    Is this type of routing possible?

    Posted: 06 Aug 2019 11:09 AM PDT

    Is it possible to have a setup which basically simulates multiple WANS?

    The final setup would have 7 devices with all of the same IP addresses and each will have its own gateway with different WANs.

    For a testing example, I would like to set up a router that would redirect:

    192.168.1.50 to 192.168.2.2 on Ethernet port 1. 192.168.1.51 to 192.168.2.2 on Ethernet port 2 192.168.1.52 to 192.168.2.2 on Ethernet port 3

    and so on.

    Can this be done with 1 router?

    submitted by /u/ottomobile1
    [link] [comments]

    Linux OSPF daemon for anycast advertising

    Posted: 06 Aug 2019 10:58 AM PDT

    I have two private IP addresses that I want to set up anycasting for internally. The idea is to have a VM with the anycasted IP addresses assigned to a loopback interface and then have the VM advertise a route to that IP directly so that I can just shut down one of the VMs and it'll just start using the other route to another VM advertising that IP. At this point I just need to set up an OSPF daemon on each VM to advertise it and it'll work, but I don't have too much experience working with OSPF running on a Linux VM. I don't actually need anything other than just advertising that one /32 route, so do I have any lightweight options or am I going to have to set up e.g. Quagga and have it calculating routes and running full OSPF? I'd prefer if there was a way to have the VMs not maintaining a link state database at all as they won't ever need to update any routes, just send out the occasional link status update.

    submitted by /u/MertsA
    [link] [comments]

    Cisco ISE - replacing Portal certificate

    Posted: 06 Aug 2019 03:02 AM PDT

    We have a two node ISE deployment running 2.2. I've looked at the Cisco documentation for replacing certificates, and it leaves a lot to be desired. We currently use a internal certificate and this means our guest portal doesn't work properly because clients without our internal root certificate cannot trust it, so need to use a publicly signed certificate.

    Has anyone done this before, and if so what SANs did you use, and what was the process for replacing the certificates on the ISE nodes?

    submitted by /u/NotSoStubbyUsername
    [link] [comments]

    Upgrade HPE 5130

    Posted: 06 Aug 2019 02:57 AM PDT

    Hi all,

    I inherited a stack of 4 HP 5130 which are running quite old software.
    HPE 5130-48G-4SFP+, running HPE Comware Software, Version 7.1.045, Release 3109P14

    I downloaded the latest software CMW710-R3506 and saved the config. Is it safe to upgrade the software using the web dashboard or do I need to install intermediate updates because the running software is almost four years old? Anything else I shoud consider? Thanks!

    submitted by /u/0815_argh
    [link] [comments]

    802.1X MAC auth : Dell N2048 switch reject EAP Accept

    Posted: 06 Aug 2019 06:38 AM PDT

    Hello everyone,

    I'm trying to set up MAC authorization (yes I know it's not ideal but it's a test) with 802.1X using FreeRADIUS, a Dell N2048 (DN OS6.3.3.9) switch as the authenticator and a Ubuntu machine as the supplicant. I've followed this guide for configuring FreeRADIUS : https://wiki.freeradius.org/guide/Mac-Auth#plain-mac-auth

    My FreeRADIUS config files looks like this (MAC addresses have been replaced) :

    $ sudo cat /etc/freeradius/3.0/sites-available/default listen { type = auth ipaddr = 10.0.180.100 port = 0 limit { max_connections = 16 lifetime = 0 idle_timeout = 30 } } authorize { preprocess rewrite_calling_station_id authorized_macs if (!ok) { reject } else { update control { Cleartext-Password := &Calling-Station-ID Auth-Type = Accept } } } $ sudo cat /etc/freeradius/3.0/mods-available/files files authorized_macs { key = "%{Calling-Station-ID}" usersfile = ${confdir}/authorized_macs } $ sudo cat /etc/freeradius/3.0/authorized_macs AA-BB-CC-DD-EE-FF Cleartext-Password := "AA-BB-CC-DD-EE-FF", User-Name := "AA-BB-CC-DD-EE-FF", Service-Type = Framed-User, Tunnel-Type = VLAN, Tunnel-Medium-Type = 6, Tunnel-Private-Group-id = 150, Reply-Message = "Device %{Calling-Station-ID} authorized" 

    The wpa_supplicant.conf on the Ubuntu client :

    ctrl_interface=/var/run/wpa_supplicant ctrl_interface_group=0 ap_scan=0 network={ key_mgmt=IEEE8021X eap=MD5 identity="AA-BB-CC-DD-EE-FF" password="AA-BB-CC-DD-EE-FF" eapol_flags=0 } 

    The switch dot1x config :

    ! dot1x system-auth-control aaa authentication dot1x default radius aaa authorization network default radius radius-server host auth 10.0.180.100 primary name "Default-RADIUS-Server" usage 802.1x key 7 "..." exit ! interface Gi1/0/1 switchport mode general dot1x port-control mac-based dot1x mac-auth-bypass exit ! 

    With this configuration everything is processed correctly, since the freeradius -X command is displaying that an Access-Accept message has been sent. The RADIUS server is authorizing the supplicant based on its MAC address. However, the switch refuse the EAP Access-Accept from the server. And I'm lost here. The only clue the switch gives me is that the EAP packet cannot be transmitted :

    <189> Aug 2 10:28:08 dell-n2048p-users-1-1 DOT1X[dot1xTask]: dot1x_radius.c(654) 58882 %% EAP message not received from server.RADIUS server did not send required EAP message. <189> Aug 2 10:27:08 dell-n2048p-users-1-1 DOT1X[dot1xTask]: dot1x_radius.c(654) 58879 %% EAP message not received from server.RADIUS server did not send required EAP message. <190> Aug 2 10:27:08 dell-n2048p-users-1-1 RADIUS[dot1xTask]: radius_api.c(1002) 58878 %% RADIUS: radiusAccessRequestMsgSend(): Updated Global radius server entry with ipaddr 10.0.180.100' 

    On the supplicant (Ubuntu machine), Wireshark is showing a "Request, Notification[Malformed Packet]" where the correct "Reply-Message" attribute is present. So I deducted it's actually the EAP Access-Accpet sent by the RADIUS server.

    I've tried using the supplicant MAC address as username and password, and making it a Framed-User but it doesn't change anything. I've added the MAC address as a Cleartext-Password into the EAP response message (Cleartext-Password := &Calling-Station-ID) in case this would be accepted but it doesn't change anything either. Enabling MAB doesn't seem to do anything, even by tweaking the dot1x timeouts.

    Am I missing something in the config ? What could make the EAP response being rejected by the switch ?

    Thanks

    Note : This is a repost of my topic at NetworkEngineering Stack Exchange.

    submitted by /u/a3ronoob
    [link] [comments]

    Major Internet speed degregation over wavelength circuit.

    Posted: 05 Aug 2019 04:22 PM PDT

    Hello all,

    First time posting on this sub-reddit (actually, posting on reddit at all). I've been banging my head on a bandwidth issue that we've been experiencing over a wavelength circuit here in the Seattle region. We're going on about 1.5 months of troubleshooting at this point (with our provider involved heavily and they're starting to get stumped). Here's our situation and a brief overview: we have rack-space at a colocation provider in the Lynnwood area (location A). At this rack, we are delivered a 1Gb/s symmetrical IP Transit circuit over 1310nm fiber going into our Juniper EX3400-48T with a fiber store optic (coded for Juniper). Local speedtests from this point, plugged into an RJ-45 port on the Juniper, to various servers show 750-940Mb/s down and almost always 940Mb/s-1000Mb/s up (on-net with ISP and off-net with other servers / providers peered with ISP). Seattle server latency is around 1-2ms. Also plugged into the Juniper's SPF+ slots is a 1310nm 10Gb optic (also fiber store, coded for Juniper) which is one end of our 10Gb wavelength circuit. This wavelength circuit is basically dormant at this point and is dedicated to the IP Transit, so theoretically, we have 9Gb/s of available headroom. This 1310nm fiber heads to the Westin in Seattle (Location B - approx. 17 miles South of location A) where it goes into the ISP DWDM equipment. From there, their DWDM bundle comes back up (~45 miles) to their other DWDM equipment which is about 13 miles from our HQ (Location C). This last leg of the wavelength circuit to our HQ is fed over 1550nm to another Juniper EX3400-48T. Plugging into that Juniper EX3400-48T at the HQ yields speedtests of approximately 200-400Mb/s down but occasionally, depending on server, reaching the max 940Mb/s of the IP Transit feed. Typical latency here is 4-5ms to Seattle servers. However, this gig speed is uncommon at HQ. Known facts and diagram for visual interpretation is below. I've looked up the bandwidth-delay product but I'm hesitant if that's what is playing a role in this situation since we are seeing conflicting results (some speeds are accurate at both locations despite latency). The ISP has been VERY helpful in helping us troubleshoot this but they're getting to their last straw of ideas. Any ideas or helpful points are GREATLY appreciated.

    • MTU on wavelength circuit is set to 9000 (have tried 1518).
    • Pings from HQ to the Juniper in our rack at colo is a steady 2ms.
    • We've completely swapped the Juniper switches at each end with Dell's (just for testing) with the same results.
    • We have NOT swapped the 1550nm optic at HQ but I'm hesitant that is the issue, still going to order one to test.
    • No framing errors on the switches for the corresponding ports in play.
    • The switches are doing pure layer 2 at this point. Very basic config, no QoS or anything. Two VLANs are involved but we removed them as being a possibility when we tested using the Dell switches (no VLANs on the Dell switch test).
    • Installed IIS (web server) on a server in our rack and tested downloads at HQ and consistently got ~90MB/s (720Mb/s).
    • ISP has validated the wavelength for 10Gb with an RFC test with various framing sizes.

    Diagram:

    https://imgur.com/hQ3pckc

    EDIT: Below are iPerf tests done between colo server (10.131.7.69) and PC running at HQ (10.131.7.66). Tests are also done in reverse. These tests are going to max at a gig since the computers involved only have 1Gb/s NICs.

    C:\Users\colo\Desktop\iperf-3.1.3-win64>iperf3.exe -c 10.131.7.66 Connecting to host 10.131.7.66, port 5201 [ 4] local 10.131.7.69 port 55796 connected to 10.131.7.66 port 5201 [ ID] Interval Transfer Bandwidth [ 4] 0.00-1.01 sec 60.0 MBytes 500 Mbits/sec [ 4] 1.01-2.00 sec 62.8 MBytes 529 Mbits/sec [ 4] 2.00-3.00 sec 64.2 MBytes 539 Mbits/sec [ 4] 3.00-4.00 sec 64.0 MBytes 537 Mbits/sec [ 4] 4.00-5.00 sec 63.8 MBytes 535 Mbits/sec [ 4] 5.00-6.00 sec 64.0 MBytes 536 Mbits/sec [ 4] 6.00-7.00 sec 63.8 MBytes 535 Mbits/sec [ 4] 7.00-8.00 sec 64.1 MBytes 537 Mbits/sec [ 4] 8.00-9.00 sec 63.6 MBytes 535 Mbits/sec [ 4] 9.00-10.00 sec 63.8 MBytes 534 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth [ 4] 0.00-10.00 sec 634 MBytes 532 Mbits/sec sender [ 4] 0.00-10.00 sec 634 MBytes 532 Mbits/sec receiver iperf Done. C:\Users\colo\Desktop\iperf-3.1.3-win64>iperf3.exe -c 10.131.7.66 -R Connecting to host 10.131.7.66, port 5201 Reverse mode, remote host 10.131.7.66 is sending [ 4] local 10.131.7.69 port 55801 connected to 10.131.7.66 port 5201 [ ID] Interval Transfer Bandwidth [ 4] 0.00-1.00 sec 59.5 MBytes 500 Mbits/sec [ 4] 1.00-2.00 sec 60.6 MBytes 508 Mbits/sec [ 4] 2.00-3.00 sec 59.7 MBytes 502 Mbits/sec [ 4] 3.00-4.00 sec 60.7 MBytes 509 Mbits/sec [ 4] 4.00-5.00 sec 59.6 MBytes 500 Mbits/sec [ 4] 5.00-6.00 sec 59.8 MBytes 502 Mbits/sec [ 4] 6.00-7.00 sec 60.4 MBytes 506 Mbits/sec [ 4] 7.00-8.00 sec 60.7 MBytes 509 Mbits/sec [ 4] 8.00-9.00 sec 60.1 MBytes 505 Mbits/sec [ 4] 9.00-10.00 sec 60.2 MBytes 505 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth [ 4] 0.00-10.00 sec 602 MBytes 505 Mbits/sec sender [ 4] 0.00-10.00 sec 602 MBytes 505 Mbits/sec receiver iperf Done. C:\Users\colo\Desktop\iperf-3.1.3-win64>iperf3.exe -c 10.131.7.66 -P4 Connecting to host 10.131.7.66, port 5201 [ 4] local 10.131.7.69 port 55805 connected to 10.131.7.66 port 5201 [ 6] local 10.131.7.69 port 55806 connected to 10.131.7.66 port 5201 [ 8] local 10.131.7.69 port 55807 connected to 10.131.7.66 port 5201 [ 10] local 10.131.7.69 port 55808 connected to 10.131.7.66 port 5201 [ ID] Interval Transfer Bandwidth [ 4] 0.00-1.00 sec 28.1 MBytes 236 Mbits/sec [ 6] 0.00-1.00 sec 28.0 MBytes 235 Mbits/sec [ 8] 0.00-1.00 sec 27.9 MBytes 234 Mbits/sec [ 10] 0.00-1.00 sec 27.9 MBytes 234 Mbits/sec [SUM] 0.00-1.00 sec 112 MBytes 938 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 1.00-2.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 1.00-2.00 sec 28.2 MBytes 237 Mbits/sec [ 8] 1.00-2.00 sec 28.1 MBytes 236 Mbits/sec [ 10] 1.00-2.00 sec 28.1 MBytes 236 Mbits/sec [SUM] 1.00-2.00 sec 113 MBytes 946 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 2.00-3.00 sec 28.4 MBytes 238 Mbits/sec [ 6] 2.00-3.00 sec 28.2 MBytes 237 Mbits/sec [ 8] 2.00-3.00 sec 28.1 MBytes 236 Mbits/sec [ 10] 2.00-3.00 sec 27.9 MBytes 234 Mbits/sec [SUM] 2.00-3.00 sec 113 MBytes 945 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 3.00-4.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 3.00-4.00 sec 28.2 MBytes 237 Mbits/sec [ 8] 3.00-4.00 sec 28.2 MBytes 237 Mbits/sec [ 10] 3.00-4.00 sec 28.2 MBytes 237 Mbits/sec [SUM] 3.00-4.00 sec 113 MBytes 948 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 4.00-5.00 sec 28.4 MBytes 238 Mbits/sec [ 6] 4.00-5.00 sec 28.2 MBytes 237 Mbits/sec [ 8] 4.00-5.00 sec 28.2 MBytes 237 Mbits/sec [ 10] 4.00-5.00 sec 28.1 MBytes 236 Mbits/sec [SUM] 4.00-5.00 sec 113 MBytes 948 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 5.00-6.00 sec 28.4 MBytes 238 Mbits/sec [ 6] 5.00-6.00 sec 28.2 MBytes 237 Mbits/sec [ 8] 5.00-6.00 sec 28.2 MBytes 237 Mbits/sec [ 10] 5.00-6.00 sec 28.0 MBytes 235 Mbits/sec [SUM] 5.00-6.00 sec 113 MBytes 946 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 6.00-7.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 6.00-7.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 6.00-7.00 sec 28.1 MBytes 236 Mbits/sec [ 10] 6.00-7.00 sec 28.0 MBytes 235 Mbits/sec [SUM] 6.00-7.00 sec 112 MBytes 944 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 7.00-8.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 7.00-8.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 7.00-8.00 sec 28.0 MBytes 235 Mbits/sec [ 10] 7.00-8.00 sec 27.9 MBytes 234 Mbits/sec [SUM] 7.00-8.00 sec 112 MBytes 941 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 8.00-9.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 8.00-9.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 8.00-9.00 sec 28.1 MBytes 236 Mbits/sec [ 10] 8.00-9.00 sec 28.1 MBytes 236 Mbits/sec [SUM] 8.00-9.00 sec 113 MBytes 945 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 9.00-10.00 sec 28.2 MBytes 237 Mbits/sec [ 6] 9.00-10.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 9.00-10.00 sec 28.1 MBytes 236 Mbits/sec [ 10] 9.00-10.00 sec 28.0 MBytes 235 Mbits/sec [SUM] 9.00-10.00 sec 112 MBytes 944 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth [ 4] 0.00-10.00 sec 283 MBytes 237 Mbits/sec sender [ 4] 0.00-10.00 sec 283 MBytes 237 Mbits/sec receiver [ 6] 0.00-10.00 sec 282 MBytes 236 Mbits/sec sender [ 6] 0.00-10.00 sec 282 MBytes 236 Mbits/sec receiver [ 8] 0.00-10.00 sec 281 MBytes 236 Mbits/sec sender [ 8] 0.00-10.00 sec 281 MBytes 236 Mbits/sec receiver [ 10] 0.00-10.00 sec 280 MBytes 235 Mbits/sec sender [ 10] 0.00-10.00 sec 280 MBytes 235 Mbits/sec receiver [SUM] 0.00-10.00 sec 1.10 GBytes 945 Mbits/sec sender [SUM] 0.00-10.00 sec 1.10 GBytes 944 Mbits/sec receiver iperf Done. C:\Users\colo\Desktop\iperf-3.1.3-win64>iperf3.exe -c 10.131.7.66 -P4 -R Connecting to host 10.131.7.66, port 5201 Reverse mode, remote host 10.131.7.66 is sending [ 4] local 10.131.7.69 port 55812 connected to 10.131.7.66 port 5201 [ 6] local 10.131.7.69 port 55813 connected to 10.131.7.66 port 5201 [ 8] local 10.131.7.69 port 55814 connected to 10.131.7.66 port 5201 [ 10] local 10.131.7.69 port 55815 connected to 10.131.7.66 port 5201 [ ID] Interval Transfer Bandwidth [ 4] 0.00-1.01 sec 28.4 MBytes 237 Mbits/sec [ 6] 0.00-1.01 sec 28.1 MBytes 234 Mbits/sec [ 8] 0.00-1.01 sec 28.0 MBytes 233 Mbits/sec [ 10] 0.00-1.01 sec 27.9 MBytes 232 Mbits/sec [SUM] 0.00-1.01 sec 112 MBytes 937 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 1.01-2.00 sec 27.9 MBytes 236 Mbits/sec [ 6] 1.01-2.00 sec 27.9 MBytes 235 Mbits/sec [ 8] 1.01-2.00 sec 27.7 MBytes 234 Mbits/sec [ 10] 1.01-2.00 sec 27.6 MBytes 233 Mbits/sec [SUM] 1.01-2.00 sec 111 MBytes 938 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 2.00-3.00 sec 28.0 MBytes 235 Mbits/sec [ 6] 2.00-3.00 sec 28.0 MBytes 235 Mbits/sec [ 8] 2.00-3.00 sec 27.9 MBytes 234 Mbits/sec [ 10] 2.00-3.00 sec 27.8 MBytes 233 Mbits/sec [SUM] 2.00-3.00 sec 112 MBytes 936 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 3.00-4.00 sec 28.0 MBytes 235 Mbits/sec [ 6] 3.00-4.00 sec 28.0 MBytes 235 Mbits/sec [ 8] 3.00-4.00 sec 27.8 MBytes 233 Mbits/sec [ 10] 3.00-4.00 sec 27.6 MBytes 232 Mbits/sec [SUM] 3.00-4.00 sec 111 MBytes 934 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 4.00-5.00 sec 28.1 MBytes 236 Mbits/sec [ 6] 4.00-5.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 4.00-5.00 sec 28.0 MBytes 235 Mbits/sec [ 10] 4.00-5.00 sec 27.8 MBytes 233 Mbits/sec [SUM] 4.00-5.00 sec 112 MBytes 939 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 5.00-6.00 sec 28.0 MBytes 235 Mbits/sec [ 6] 5.00-6.00 sec 27.8 MBytes 233 Mbits/sec [ 8] 5.00-6.00 sec 27.7 MBytes 232 Mbits/sec [ 10] 5.00-6.00 sec 27.7 MBytes 232 Mbits/sec [SUM] 5.00-6.00 sec 111 MBytes 932 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 6.00-7.00 sec 27.9 MBytes 234 Mbits/sec [ 6] 6.00-7.00 sec 28.0 MBytes 234 Mbits/sec [ 8] 6.00-7.00 sec 27.8 MBytes 233 Mbits/sec [ 10] 6.00-7.00 sec 27.8 MBytes 233 Mbits/sec [SUM] 6.00-7.00 sec 112 MBytes 935 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 7.00-8.00 sec 28.0 MBytes 235 Mbits/sec [ 6] 7.00-8.00 sec 27.9 MBytes 234 Mbits/sec [ 8] 7.00-8.00 sec 27.9 MBytes 234 Mbits/sec [ 10] 7.00-8.00 sec 27.8 MBytes 233 Mbits/sec [SUM] 7.00-8.00 sec 112 MBytes 935 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 8.00-9.00 sec 28.1 MBytes 236 Mbits/sec [ 6] 8.00-9.00 sec 28.0 MBytes 235 Mbits/sec [ 8] 8.00-9.00 sec 27.9 MBytes 234 Mbits/sec [ 10] 8.00-9.00 sec 28.0 MBytes 234 Mbits/sec [SUM] 8.00-9.00 sec 112 MBytes 939 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ 4] 9.00-10.00 sec 28.1 MBytes 236 Mbits/sec [ 6] 9.00-10.00 sec 28.1 MBytes 236 Mbits/sec [ 8] 9.00-10.00 sec 27.9 MBytes 234 Mbits/sec [ 10] 9.00-10.00 sec 27.8 MBytes 233 Mbits/sec [SUM] 9.00-10.00 sec 112 MBytes 939 Mbits/sec - - - - - - - - - - - - - - - - - - - - - - - - - [ ID] Interval Transfer Bandwidth [ 4] 0.00-10.00 sec 281 MBytes 236 Mbits/sec sender [ 4] 0.00-10.00 sec 281 MBytes 236 Mbits/sec receiver [ 6] 0.00-10.00 sec 280 MBytes 235 Mbits/sec sender [ 6] 0.00-10.00 sec 280 MBytes 235 Mbits/sec receiver [ 8] 0.00-10.00 sec 279 MBytes 234 Mbits/sec sender [ 8] 0.00-10.00 sec 279 MBytes 234 Mbits/sec receiver [ 10] 0.00-10.00 sec 278 MBytes 233 Mbits/sec sender [ 10] 0.00-10.00 sec 278 MBytes 233 Mbits/sec receiver [SUM] 0.00-10.00 sec 1.09 GBytes 937 Mbits/sec sender [SUM] 0.00-10.00 sec 1.09 GBytes 937 Mbits/sec receiver iperf Done. 

    Edit 2: Optical power levels, as requested by a few of you. ISP and I have looked into this but here are the results, maybe someone may catch something we missed. Colo switch is the first code block. Interface ge-0/2/3 is the ISP Internet uplink (1310nm). Interface xe-0/2/0 is the wavelength circuit.

    redacted@redacted> show interfaces diagnostics optics Physical interface: xe-0/2/0 Laser bias current : 35.298 mA Laser output power : 0.5360 mW / -2.71 dBm Module temperature : 25 degrees C / 77 degrees F Module voltage : 3.3470 V Laser receiver power : 0.3639 mW / -4.39 dBm Laser bias current high alarm : Off Laser bias current low alarm : Off Laser bias current high warning : Off Laser bias current low warning : Off Laser output power high alarm : Off Laser output power low alarm : Off Laser output power high warning : Off Laser output power low warning : Off Module temperature high alarm : Off Module temperature low alarm : Off Module temperature high warning : Off Module temperature low warning : Off Module voltage high alarm : Off Module voltage low alarm : Off Module voltage high warning : Off Module voltage low warning : Off Laser rx power high alarm : Off Laser rx power low alarm : Off Laser rx power high warning : Off Laser rx power low warning : Off Laser bias current high alarm threshold : 110.000 mA Laser bias current low alarm threshold : 1.000 mA Laser bias current high warning threshold : 100.000 mA Laser bias current low warning threshold : 1.000 mA Laser output power high alarm threshold : 2.2380 mW / 3.50 dBm Laser output power low alarm threshold : 0.0950 mW / -10.22 dBm Laser output power high warning threshold : 1.7780 mW / 2.50 dBm Laser output power low warning threshold : 0.1510 mW / -8.21 dBm Module temperature high alarm threshold : 100 degrees C / 212 degrees F Module temperature low alarm threshold : -50 degrees C / -58 degrees F Module temperature high warning threshold : 85 degrees C / 185 degrees F Module temperature low warning threshold : -40 degrees C / -40 degrees F Module voltage high alarm threshold : 3.630 V Module voltage low alarm threshold : 2.970 V Module voltage high warning threshold : 3.465 V Module voltage low warning threshold : 3.135 V Laser rx power high alarm threshold : 2.2387 mW / 3.50 dBm Laser rx power low alarm threshold : 0.0229 mW / -16.40 dBm Laser rx power high warning threshold : 1.7783 mW / 2.50 dBm Laser rx power low warning threshold : 0.0363 mW / -14.40 dBm Physical interface: ge-0/2/3 Laser bias current : 15.804 mA Laser output power : 0.2490 mW / -6.04 dBm Module temperature : 33 degrees C / 91 degrees F Module voltage : 3.2340 V Laser receiver power : 0.1629 mW / -7.88 dBm Laser bias current high alarm : Off Laser bias current low alarm : Off Laser bias current high warning : Off Laser bias current low warning : Off Laser output power high alarm : Off Laser output power low alarm : Off Laser output power high warning : Off Laser output power low warning : Off Module temperature high alarm : Off Module temperature low alarm : Off Module temperature high warning : Off Module temperature low warning : Off Module voltage high alarm : Off Module voltage low alarm : Off Module voltage high warning : Off Module voltage low warning : Off Laser rx power high alarm : Off Laser rx power low alarm : Off Laser rx power high warning : Off Laser rx power low warning : Off Laser bias current high alarm threshold : 100.000 mA Laser bias current low alarm threshold : 0.000 mA Laser bias current high warning threshold : 95.000 mA Laser bias current low warning threshold : 0.000 mA Laser output power high alarm threshold : 0.7070 mW / -1.51 dBm Laser output power low alarm threshold : 0.0890 mW / -10.51 dBm Laser output power high warning threshold : 0.6310 mW / -2.00 dBm Laser output power low warning threshold : 0.1000 mW / -10.00 dBm Module temperature high alarm threshold : 90 degrees C / 194 degrees F Module temperature low alarm threshold : -45 degrees C / -49 degrees F Module temperature high warning threshold : 85 degrees C / 185 degrees F Module temperature low warning threshold : -40 degrees C / -40 degrees F Module voltage high alarm threshold : 3.795 V Module voltage low alarm threshold : 2.805 V Module voltage high warning threshold : 3.465 V Module voltage low warning threshold : 3.135 V Laser rx power high alarm threshold : 0.7079 mW / -1.50 dBm Laser rx power low alarm threshold : 0.0022 mW / -26.58 dBm Laser rx power high warning threshold : 0.6310 mW / -2.00 dBm Laser rx power low warning threshold : 0.0025 mW / -26.02 dBm {master:0} 

    Here's the HQ switch with xe-0/2/0 as the wavelength uplink:

    redacted@redacted> show interfaces diagnostics optics Physical interface: xe-0/2/0 Laser bias current : 30.002 mA Laser output power : 1.1530 mW / 0.62 dBm Module temperature : 28 degrees C / 82 degrees F Module voltage : 3.4040 V Laser receiver power : 0.2127 mW / -6.72 dBm Laser bias current high alarm : Off Laser bias current low alarm : Off Laser bias current high warning : Off Laser bias current low warning : Off Laser output power high alarm : Off Laser output power low alarm : Off Laser output power high warning : Off Laser output power low warning : Off Module temperature high alarm : Off Module temperature low alarm : Off Module temperature high warning : Off Module temperature low warning : Off Module voltage high alarm : Off Module voltage low alarm : Off Module voltage high warning : Off Module voltage low warning : Off Laser rx power high alarm : Off Laser rx power low alarm : Off Laser rx power high warning : Off Laser rx power low warning : Off Laser bias current high alarm threshold : 100.000 mA Laser bias current low alarm threshold : 0.000 mA Laser bias current high warning threshold : 90.000 mA Laser bias current low warning threshold : 10.000 mA Laser output power high alarm threshold : 3.1620 mW / 5.00 dBm Laser output power low alarm threshold : 0.6310 mW / -2.00 dBm Laser output power high warning threshold : 2.5110 mW / 4.00 dBm Laser output power low warning threshold : 0.7940 mW / -1.00 dBm Module temperature high alarm threshold : 90 degrees C / 194 degrees F Module temperature low alarm threshold : -5 degrees C / 23 degrees F Module temperature high warning threshold : 85 degrees C / 185 degrees F Module temperature low warning threshold : 0 degrees C / 32 degrees F Module voltage high alarm threshold : 3.800 V Module voltage low alarm threshold : 2.700 V Module voltage high warning threshold : 3.700 V Module voltage low warning threshold : 2.800 V Laser rx power high alarm threshold : 1.2589 mW / 1.00 dBm Laser rx power low alarm threshold : 0.0200 mW / -16.99 dBm Laser rx power high warning threshold : 1.0000 mW / 0.00 dBm Laser rx power low warning threshold : 0.0251 mW / -16.00 dBm 
    submitted by /u/thetrevster9000
    [link] [comments]

    2 Locations, VPN Connecting them, 2 Different IP ranges, trying to figure out how to RDP between. Help?

    Posted: 06 Aug 2019 02:35 PM PDT

    So my company picked up a new account a couple months ago, and the client's setup was very antiquated. They got hit by Ransomware about a month or so ago right after we picked up the account. We have been able to get them cleared of it, purchased all new machines, servers, etc.

    The old IT company left the client 0 notes to anything on their entire infrastructure leaving me flying in the dark most of the time. We replaced their old Cisco routers which were acting as a VPN tunnel for a location that has 3 workstations and 2 avaya phones. We installed Fortinet routers at both locations and have a VPN connection established.

    Location 1: Main Store has an IP range of 192.168.0.X Location 2: Warehouse has an IP range of 192.168.10.X

    I need to have location 2 RDP to location 1, however because of the IP range difference this will not work.

    My boss mentioned something about something may be able to be done with the subnets but he wasn't too sure. Personally I would of put both locations on the same IP range since the routers are acting as a VPN and are talking to each other, but the boss didn't want that and I understand.

    So is there a way to get location 2 to RDP to location 1 with a different IP range?

    TL;DR: 2 Locations, 2 different IP ranges, need location 2 with an IP of 192.168.10.X to talk to location 1 with an IP of 192.168.0.X for RDP connections.

    I'm sorry if I missed any crucial information. Any help is appreciated, if any additional information is needed I will try my best to answer.

    submitted by /u/Thundernut
    [link] [comments]

    DHCP through MPLS problem and solution

    Posted: 06 Aug 2019 06:44 AM PDT

    Greetings,

    There is MPLS provided by our ISP. We only manage and service CPE routers on endpoints. There are cable and NDSL connections and certain NDSL connection end points have problem with getting DHCP packets. We confirmed DHCP packets entering and leaving CPE router at HQ, where the DHCP server is located, from/to that certain endpoint. We communicated this with the ISP and they told us it's their problem but won't do anything because it is some kind of new technology and they can't solve it.
    We came up with 3 ideas to solve this:

    1. Blame ISP, throw this problem on their shoulders and make them figure it out. (We don't like this idea)
    2. Make the end point CPE routers local DHCP servers. We need agreement with the ISP and customer but that isn't a problem. (We like this idea and are currently working on it)
    3. Make GRE Tunnels between the CPE router at HQ and the CPE routers of endpoints to encapsulate the DHCP packet. (We also don't like this idea since it is a hassle with all the DSL endpoints and possible change in future)

    Do you guys have different ideas or solutions?

    submitted by /u/LightSentinel
    [link] [comments]

    Translating HP Private-VLANing to Cisco Nexus

    Posted: 06 Aug 2019 01:46 AM PDT

    HP 1910-8G DHCP: Am I missing something or will this switch not work as a DHCP server?

    Posted: 06 Aug 2019 09:04 AM PDT

    We've been banging our heads. It looks like the only DHCP options are DHCP relay or DHCP Snooping. Does this mean that I can not set this up with different VLANs and have the VLANs provide a DHCP IPs?

    submitted by /u/tercra
    [link] [comments]

    Management port / IP on a Cisco switch stack?

    Posted: 06 Aug 2019 01:17 AM PDT

    How does the management port and management IP work on a stack of switches?

    This is the first time I've deployed a stack with the opportunity to use the management ports, usually we have a management vlan / svi.

    In a stack of 3 switches, would each switch share the IP? Or is it a Mgmt IP per switch?

    submitted by /u/LittleWanger
    [link] [comments]

    Open Server Root Servers, OpenNIC and ICANN

    Posted: 06 Aug 2019 08:08 AM PDT

    Please someone should further explain the working of Open Source Root Servers like OpenNIC, and how it's different from ICANN Root. What are the benefits and disadvantages of using Open Source Root Servers eg OpenNIC over ICANN? Why don't they stand the test of time? I also noticed you need to use different DNS from ICANN DNS to access domain names of OpenNIC eg: .oz, .neo, .o etc.

    submitted by /u/chrisbren
    [link] [comments]

    Storing/sharing admin password(s) best practices

    Posted: 06 Aug 2019 07:44 AM PDT

    I'm working at a small (ish) start up that is completely greenfield and hoping to start out on the right foot with some early decisions. Most of our infrastructure is in place / configured and working but set to scale out over the next 6 years. There's 2 admins on my team (including me) with a chance to hire 1-2 more eventually. We're working on configuring AAA for admin access where applicable. I'm curious what other folks are doing for storing/sharing local admin accounts for things like, vmware admin, local admin for routers/switches/shelves when AAA is not accessible or applicable. Currently we have about 12-13 different "boxes" that we're just verbally keeping up with these items but I could see this getting out of hand quickly. Are encrypted password managers safe? I've been in spots where there was one admin password for all systems and changing it/ managing it was a nightmare. Thanks!

    submitted by /u/budahsacman
    [link] [comments]

    Forcing Cisco Switches to use 3rd Party SFPs

    Posted: 06 Aug 2019 06:36 AM PDT

    We have an older Dell Powerconnect on its last leg so I wanted to swap in a spare Cisco 2960S and in preparation to do that I realize that Cisco does not like 3rd party SFP's (Dell in this case). We are going to order a few cisco SFP's today but it'll be a few days before they come in so I wanted to have the 2960S ready and working if the Powerconnect dies.

    I found a few commands to stop the errdisable but they don't seem to be taking, it accepts the command but still downs the port with errdisable. I did 'end' and 'write' after the command but no dice. The other end of this is a Cisco 3570, there is an uplink/SFP setup already that is live to the powerconnect but in the mindset of testing before I swapped the switch I used an free SFP port on the 3750 and popped another Dell SFP in so that I can test the switch before swapping it and ran into the same issue with 2960 and the Dell SFP (errdisable even with the commands run).

    *SW1(config)#*service unsupported-transceiver

    Warning: When Cisco determines that a fault or defect can be traced to

    the use of third-party transceivers installed by a customer or reseller,

    then, at Cisco's discretion, Cisco may withhold support under warranty or

    a Cisco support program. In the course of providing support for a Cisco

    networking product Cisco may require that the end user install Cisco

    transceivers if Cisco determines that removing third-party parts will

    assist Cisco in diagnosing the cause of a support issue.

    *SW1(config)#*no errdisable detect cause gbic-invalid

    SW1(config)#

    *******Yes I know this is not an ideal situation and one that I'd rather not implement but if it's either an unsupported configuration or downtime for a handful of uses I'll take the unsupported config (temporarily, until the new SFPs arrive). Ultimately I will swap in the Cisco SFPs in a downtime window once they arrive, but need a way to keep my users online.

    ***SOLVED! Thanks to u/Syde80 ! Had to reset the errdisabled state on the switches, once done I am able to get a connection (no more downed SFP interfaces)

    submitted by /u/wintelguy8088
    [link] [comments]

    Reset router. Default Gateway changed. Now entire office having connection issues. How do I change it back?

    Posted: 06 Aug 2019 09:59 AM PDT

    Hi all,

    Our office is having connection issues with Slack. Our internet provider is Virgin (UK) and the router is the Hitron CGNV4, and Virgin suggested that a reset using the button on the back of the router might help to resolve the issue.

    After pressing reset, the internet dropped out for about 5 minutes and then came back only sporadically. Everyone was having connection issues, staying connected with for a few minutes and then having to reconnect or not being able to connect entirely.

    What I think is causing the issue

    The Default Gateway since the reset has changed from 192.168.1.1 to 192.168.0.1. We have Ubiqiti UAP XG access points around the office to extend the signal from the router. If these are still configured to 192.168.1.1 are they now not able to connect? How can I change the router IP back to 192.168.1.1

    Apologies if this is a simple issue. I am new to this and worried that this is a bit out of my depth.

    Virgin have also reported outages in the area, so I also don't know if the issue might be to do with that. But the issues started occurring as soon as I reset the router.

    If this isn't the correct place to post this, I'd appreciate it if someone could point me to a more appropriate location.

    submitted by /u/anco_vinyl
    [link] [comments]

    ACI without hypervisor integration

    Posted: 05 Aug 2019 05:34 PM PDT

    Been given a project for which the design has already been done and hardware purchased. We've committed to Cisco ACI and a virtualisation platform that is not VMware, Hyper-V, Red Hat KVM or any of the other supported ones.

    I'm having a little bit of difficulty comprehending the documentation, at least on my first read through and am wondering what's lost without a supported hypervisor.

    submitted by /u/helpadumbo
    [link] [comments]

    Layer 1 Head Scratcher

    Posted: 06 Aug 2019 08:12 AM PDT

    I've got a bit of a head scratcher on my hands. We have a portable equipment rack with a few network devices in it. Each device connects directly to a corresponding device, which are each located in other racks, so there's 6 racks about 100 feet apart and about a dozen device-to-device "crossover" connections between devices in different racks. There is no connectivity within the racks between devices. The only network connections are the device-to-device connections running between racks. We've never had any issues with this setup until yesterday, when not a single network connection would come up. No link lights, nothing. A dozen simultaneous failures, with no single point of failure. They aren't running the same OS, so we can rule out driver issues. I'm having trouble coming up with an explanation for how this could have happened. The only theory I have is that it could be power-related, maybe a ground loop? We set it up again today and it's all working again.

    submitted by /u/albinotuba
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel