• Breaking News

    [Android][timeline][#f39c12]

    Saturday, February 8, 2020

    Fiber cut Seattle Networking

    Fiber cut Seattle Networking


    Fiber cut Seattle

    Posted: 08 Feb 2020 09:19 AM PST

    Anyone else have a ton of sites down in WA State? We have about 60 sites down, apparently a Zayo owned circuit was cut in Tukwila and I also heard about a cut between Walla Walla and Lagrande.

    This happened at about 8:00pm last night and still haven't restored service yet.

    submitted by /u/ParaglidingAssFungus
    [link] [comments]

    DANOS Project - early findings

    Posted: 08 Feb 2020 07:23 AM PST

    Hi networking,

    Just though I'd share some of my (very) basic findings toying around with the recently open-sourced AT&T project DANOS in case you're interested in giving it a spin.

    tl;dr; - don't make the same mistake I did trying to run it on Xen/xcp-ng.

    So far, my experience has been very positive, but by no means have I explored all the features available or have been able to stress it. For more information, here's a link to the project:

    https://www.danosproject.org/

    (If this isn't the correct place, please let me know where it would be more appropriate as I am relatively new to Reddit. I did have a peek at /r/NFV but that place seems to be dead)

    I'll start out with being able to install from the downloadable iso on various local hypervisors/clusters I have at my disposal:

    KVM - Xeon E5 W, Intel NICs, Local Storage, Centos 7
    oVirt - 3 Node, Xeon E5 W, Intel NICs, iSCSI, oVirt 4.3.7
    xcp-ng - 3 Node, Xeon E5 W, Intel NICs, NFS, xcp-ng 8.0.0
    ESXi - Xeon E5 W, Intel NICs, Local Storage, ESXi 6.7
    Hyper-V* - Core i7-7800X, Intel NIC, Local Storage, Windows 10 Pro

    *Sorry, out of real servers at home, and power budget :)

    These findings were based on 4 CPU, 4GB RAM, 10GB SSD VMs. I've found that the router likes at least 2 cores to run. My first inclination is that it uses a core for management while the rest are used for processing packets.

    Installed from ISO, booted from disk

    KVM - Pass
    oVirt - Pass
    xcp-ng - Pass
    ESXi - Pass
    Hyper-V - Pass

    Dataplane Up, Reachable (DHCP IP, Default Route, ICMP, SSH)

    KVM - Pass
    oVirt - Pass
    xcp-ng - FAIL
    ESXi - Pass
    Hyper-V - Pass

    The only system that the dataplane does not run on is the Xen based hypervisor, which is where I started. It will boot in HVM mode, but not in PV mode. But if the dataplane doesn't start, it's useless unless you want to have a peek at the CLI. I have tried everything I know with Xen and I couldn't get anywhere. I wasted a lot of time on this because I didn't RTFM like an idiot. Once I moved to other hypervisors, everything worked great.

    I *assume* since I've had a good experience with all the KVM testing I've done, that Proxmox would run DANOS just fine, but I've got a lot running in my clusters, so that will have to wait.

    FWIW, I've run VyOS on all of the above +Proxmox with much higher loads and more features running - no issues with dataplane on Xen. The dataplane itself is noticeably different from VyOS and that's where AT&T seems to have focused much of their work after the acquisition.

    I plan to run some performance tests with what I've got - basic routing protocols, specifically loading a few full internet tables, throughput, compatibility, IPSec etc.

    Today I will try all 3 major cloud providers and will follow up in this thread on how I make out. I suspect that since AWS is Xen-based, DANOS will not run on AWS on regular EC2 instances, but I'm interested to give it a shot on their new KVM-based Nitro hypervisor and might have better success there.

    Anyone else's experience with more advanced configurations or performance testing would be appreciated! I'll share whatever I find.

    submitted by /u/amaralarama
    [link] [comments]

    Juniper Open Learning - Free Certificate at Completion of Web Training

    Posted: 07 Feb 2020 10:27 PM PST

    https://learningportal.juniper.net/juniper/user_activity_info.aspx?id=10175

    Not at all associated with Juniper.

    Been waiting for this opportunity. Just sharing it here.

    Also, insights about the training would be helpful.

    Edit: Free exam voucher. Sorry for the misleading title.

    submitted by /u/rosemwrie_a
    [link] [comments]

    Do IGP protocols "touch" FECS at all?

    Posted: 08 Feb 2020 01:42 PM PST

    I'm learning about MPLS in school and a question on my midterm asked "how do interior gateway protocols deal with forwarding equivalency classes in comparison to link state paths?"

    But the thing is I'm pretty sure the IGPs are just there to lay the foundation for the LSPs (link state paths) instead and don't deal with fecs at all. The label bindings are exchanged on the data plane not the control plane. No?

    submitted by /u/InadequateUsername
    [link] [comments]

    Question ieee802.11 : Can an AP send probe requests ?

    Posted: 08 Feb 2020 07:31 AM PST

    I was wondering if an AP in infrastructure mode can send probe requests like client. I searched on internet and all I found was that "stations" can send probe requests, but does "stations" mean AP+client or just client ?

    Thanks ! :D

    submitted by /u/Dridact
    [link] [comments]

    Need help with port forwarding

    Posted: 08 Feb 2020 05:13 PM PST

    I am trying to port forward a Minecraft server. I have the port forwarding configured correctly, the only problem is it isn't working. I think the reason may be that i have another router behind an at&t provided router. I can't remove the at&t router as i won't receive an internet signal. I assume i need to forward the port again on the at&t router or set the at&t router to be a bridge with the second. Any advice would be greatly appreciated.

    submitted by /u/datcrqbwitlongassarm
    [link] [comments]

    Cisco 9500 ACLLOG Issue

    Posted: 08 Feb 2020 01:19 PM PST

    Has anyone had problems getting ACLLOG to work on a 9500's ACL. It works fine one my other NXOS switches, but for some reason I have no luck with the 9500.

    The show logging up access-list cache isn't always empty too.

    I have the log levels for ACLLOG and the log file set correctly. ACL with the log action is applied inbound on a vlan interface.

    submitted by /u/ciscoman5000
    [link] [comments]

    Latency path and BGP

    Posted: 08 Feb 2020 05:00 PM PST

    What is the impact of latency on BGP? Meaning if one way latency is say 50 ms and later it keeps hovering around 80. How does this impact BGP convergence or establishment etc?

    submitted by /u/dpex77
    [link] [comments]

    Configuring a router interface as a dhcp client using netmiko

    Posted: 08 Feb 2020 04:47 PM PST

    So I am fairly new to network automation. I am trying to configure a router's interface to be a dhcp client for a DHCP server on the same network. Now from what I know of netmiko, you have to specify the ip address of the device when referring to the device in the python code to be able to send configuration commands to it. But how would you specify the IP address if the device doesn't have an IP address as of yet. I am sorry if I am skipping some fundamental concept, I'm just really stuck on this. Help?

    submitted by /u/chaosandcolors
    [link] [comments]

    Cisco Firepower 2110's

    Posted: 08 Feb 2020 05:50 AM PST

    Hi All,

    I seem to be having a weird issue with some new Firepower 2110's we purchased.

    We have a total of 3 of them and on all 3 only the first 2 ports work. Ethernet 1/1 and 1/2. They are smart licensed with the ASA standard license but I can't get any of the other ports to work.

    Cisco TAC told me yesterday that it sounds like hardware failure but all three devices are acting the same way. I feel like I'm missing something, or I didn't set something up correctly.

    Ideas?

    submitted by /u/FunkyBuddha73
    [link] [comments]

    Cisco ASA 5520 - Remote Access VPN: Works, but no ping. Why?

    Posted: 08 Feb 2020 10:51 AM PST

    Hi All,

    I have an ASA 5520 in the US with remote access VPN capabilities via Cisco VPN Client. I have another site over in the UK that the US ASA has a site to site VPN to. In addition to that, the US ASA has site to site VPN's to about 140 other ASA's throughout the world. When connected to the remote access VPN, I can ping all of those sites, EXCEPT for this UK site...BUT....the actual services are accessible over this remote access VPN for the users in the US reaching out to the UK. I just can't ping the IP of the very same server that is successfully providing these users access, from the remote access VPN subnet. If I go to the US site and try to ping it (off the remote access VPN), it replies fine.

    Packet tracer shows ICMP is permitted in both directions on both of the ASA's. The sniffer shows this:

    An ICMP session is removed in the fast-path when stateful ICMP is enabled using the inspect icmp command

    Inspect ICMP is on the UK side, not the US side. Tried turning it off. Didn't matter.

    submitted by /u/TheFaytalist
    [link] [comments]

    Hands on Cisco ACI / DNAC possible?

    Posted: 08 Feb 2020 09:51 AM PST

    I want to gain experience / proficiency in these products to give me a fighting change in the job market - standing out against other lowly CCNAs

    Can they be used in GNS3 - if so are there any decent resources for learning the basics / day to day stuff?

    submitted by /u/VlcMackey
    [link] [comments]

    Looking for suggestions for a cable tone and probe kit

    Posted: 08 Feb 2020 08:53 AM PST

    Hey guys, I need a cable tone and probe kit and I'm looking for some suggestions. Anyone have one they can recommend? I don't mind paying a little extra as long as it's durable and trustworthy

    submitted by /u/Mr_Self_Eraser
    [link] [comments]

    Lower network latency for new-style TLDs? Are there any benchmarks or general insights?

    Posted: 08 Feb 2020 08:37 AM PST

    I'm wondering if any of the new / long-form TLDs have typically lower-latency than classic 'prime' TLDs of olde.

    I understand that some countries could have higher latency, if they've made all DNS bottleneck through the country. I don't really know how propogation happens across all/most/many of them. Which major DNS sign up for all TLDs, or which they defer (is that even right?)

    Is .xyz slower or faster than most? What about .bank, etc? Compared with .mk or .az?

    I'm sure there's tons of naivety in what i'm asking. Thanks for any bits you know, or bigger picture insight. (i've read the sidebar; i'm not asking for some homework or a test question.)

    submitted by /u/NewAlexandria
    [link] [comments]

    Lightweight Linux Distro for Networking Troubleshooting

    Posted: 07 Feb 2020 09:48 PM PST

    I am interested in creating a live Linux Distro for USB that would contain network troubleshooting software like Wireshark, Nmap, you name it. Would anyone have some good suggestions?

    submitted by /u/scoop263
    [link] [comments]

    Setting password for protocol usage in firewall

    Posted: 08 Feb 2020 03:41 AM PST

    Is there a way to set a password like for instance if I am trying to SSH into an endpoint? I am testing ideas to maximize security for a network. If I set a firewall rule that only a certain endpoint could SSH into a server or other resource, you could keep them safe even if that endpoint was compromised. You could even go a step further and setup MFA with this password. Is this possible?

    edit: Surely this has to be, sounds like an enterprise level firewall feature? Or perhaps there is a software that does this?

    submitted by /u/DreamBigLiveClassy
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel