• Breaking News

    [Android][timeline][#f39c12]

    Monday, March 2, 2020

    Why does 25 GbE exist? Networking

    Why does 25 GbE exist? Networking


    Why does 25 GbE exist?

    Posted: 02 Mar 2020 09:56 AM PST

    I'm genuinely curious if I'm missing something, but I don't see the point of 25 GbE because 40 GbE was already established as a mature technology by the time they rolled it out. I can purchase 40 GbE ConnectX-3 gear all day long for around $40/card. Likewise, 40 GbE switching equipment is equally as cheap, I just picked up a Mellanox SX1036 for around $200.

    The sequence of progression doesn't make sense ether, 1, 2.5, 5, 10, 25, 40, 50, 100, 200, 400. What about all the gaps between 50 and 400? To me it seems like it would have made more sense to do periodic multiples of 40... 80, 120, 160, 200, 240, 280, 320, 360, 400. This would have allowed for linear scaling of fanout cables. i.g 80 GbE = 2x 40 GbE, 160 GbE = 2x 80 GbE or 4x 40 GbE.

    The transition between 50 and 100 is too large, the Linux software stack is struggling to push packets faster then 70 Gb/s... the ability to push packets in software vs hardware are highly divergent with regards to realized speed. If we would have set 80 GbE as the next target instead of 100 GbE the hardware vendors could have pushed out new equipment out the door faster and cheaper.

    This all strikes me as not being well thought out in advanced.

    submitted by /u/Hopperkin
    [link] [comments]

    Do you action ISP abuse emails?

    Posted: 02 Mar 2020 01:09 PM PST

    Probably a bit of a niche questions, but you folk who have own addresses space / ASN, and delegate some to customers, what do you do if you receive an email to your abuse inbox?

    We have a customer we have assigned a few IP addresses to, and over the last few months we have received numerous reports that their ip's are responsible for some nefarious activity. The reports have come via bitninja.

    Apart from contacting the customer and advising them, do you take any other action?

    submitted by /u/LittleWanger
    [link] [comments]

    Structured Networking - Shielded/Non Shielded

    Posted: 02 Mar 2020 04:12 AM PST

    Hi everyone,

    First of all, I work in the area of structured networking and I do understand most stuff, but there are some stuff that people suddenly start complaining that I just don't have any arguments against it because I just straight up think its dumb.

    Here's the deal, a customer of ours, some months ago started stating that even if you have, per example, CAT. 6A Shielded cable on your network, on the cabinet he claims that if the cabinet is well grounded you will not need shielded patch cords at all. I tried to argue with him because usually we advise everyone to buy all shielded or all unshielded cable/patch cords. But he stuck with his opinion and there is no changing his mindset.

    Not that it matters to me because the project is already with our brand, but I like to stay informed because the more I learn the more I can teach.

    I was wondering if, there is anything on the internet, that states that shielded networks do not need shielded patch cords. I know it's a simple thing, maybe even dumb to analyse, but I really need to understand why some people think this way.

    Thank you all in advance.

    submitted by /u/BolsoRoto
    [link] [comments]

    Cloudflare Access

    Posted: 02 Mar 2020 02:46 PM PST

    Does anyone have any experience with Cloudflare Access?

    My team is considering them as a VPN replacement internally, and am curious as to what folks' experience has been with this product.

    Thanks!

    submitted by /u/lalalainyourface
    [link] [comments]

    Auto transfer generator for back up power..?

    Posted: 02 Mar 2020 11:33 AM PST

    Hi All! Need some suggestions for back up power for one 20amp circuit. Site is remote and has multiple day outages with no power at all frequently. Would like the ability to remotely monitor generator (status, fuel, etc..) Most larger Generac sets have remote monitoring capabilities, however not for our smaller 3k watt requirement. Anyone have any thoughts on LPG powered, small smart gensets? Thanks! Edited for clarity.

    submitted by /u/Bamaged1
    [link] [comments]

    Questions about adding a 10Gb switch to an existing 1Gb network.

    Posted: 02 Mar 2020 08:26 AM PST

    First off, we're a small business and don't have an IT guy, I know a little, but it's not my job. We'll hire someone to do any necessary work but I'd like to understand what we can do first.

    Our network is currently composed of 3 Unifi us-24-250w switches providing PoE for some IP phones and gigabit connections to a few computers. There are also some Unifi wireless access points, I believe routing is being done by a SonicWall TZ400, as it's my default gateway (???).

    One part of our business involves a half dozen or so computers which are constantly moving large files over the network from a single storage server. Its a bottleneck in our production and I'm about to upgrade the server computer to have an SSD for those files, or get a NAS with RAID, But even in that case, our 1Gb network can only move 125MB/s and an SSD can do ~2000MB/s.

    I would like to upgrade these half dozen computers to a 10Gb network, just so they can communicate with each other and the file server more quickly, but I don't know if I need to upgrade anything else.

    The building is wired with Cat6 so I was looking at something with 10GBASE-T, either this QNAP QSW-1208-8C-US or to keep everything consistent, this Unifi US-16-XG, but I like that the QNAP has enough RJ45 ports. Then I'd get some 10Gb PCI-e cards for the PCs in question.

    Now to my actual questions:

    • Can I simply add a 10Gb switch to my existing 1Gb network?
    • Do I need a 10Gb router as well, to avoid that 1Gb bottleneck, or is it ok since all the 10Gb stuff is going through the one switch?
    • Is there a better way for a half dozen computers, all in the same room, to have 10Gb or similar speed to a file server?
    submitted by /u/unfinite
    [link] [comments]

    LACP Path / Port selection

    Posted: 02 Mar 2020 04:40 PM PST

    I have (2) Nexus 93180YC FX switches setup in VPC. I'm connecting the two Nexus core switches to a catalyst 2960X.

    I'm wondering if anyone knows how the Catalyst (or any switch for that matter) selects which port in a port-channel for traffic to exit on.

    Based off some wiresharking it looks like the traffic is leaving the catalyst on the lower switchport number consistently.

    Does LACP have a method for selecting a port to exit on?

    submitted by /u/gord1020
    [link] [comments]

    QSFP28 to 4x25G Breakout Fiber

    Posted: 02 Mar 2020 01:24 PM PST

    Good afternoon all!

    Does a QSFP28-4xSFP25G breakout fiber need 8 or twelve lanes on the MPO side?

    I've been searching part numbers on the web, but I haven't been able to find one that shows the mpo lane breakouts.

    submitted by /u/raddpuppyguest
    [link] [comments]

    Netflow on virtual interfaces

    Posted: 02 Mar 2020 01:17 PM PST

    In my company we use cisco routers with DMVPN to connect between sites, so a lot of our routers have 100 virutal access interfaces or more. With the current netflow configuration that we have, the routers specify the outgoing interface of the flow and most of the times it is a Virtual-interface.

    In solarwinds we do not manage virtual interfaces for obvious reasons, so solarwinds keeps giving me these errors: NetFlow Receiver Service [SERVER-NAME] is receiving NetFlow data from an unmanaged interface 'Virtual-Access32 - Vi32'

    Multiply that error for hundreds of routers and then for hunderds of interfaces. The events table is huge

    I could not find the option in Solarwinds to ignore this. Does anyone know how to do it? If not is there a way to do it the routers without removing the "collect interface output" command?

    submitted by /u/Eagle_1990
    [link] [comments]

    MPLS RSVP Configuration Management

    Posted: 02 Mar 2020 08:09 AM PST

    Been doing a lot of studying on RSVP for MPLS, specifically for Juniper. It's a very full-featured protocol with lots of options supported by Junos. But it sure seems like it carries a lot of configuration overhead. The company I work for has enough capacity to simply use LDP without need for MPLS traffic engineering (for now!). But it does look like there are some autoconfiguration mechanisms available which may simplify its use. Just curious for those who may use it in their networks - how does your company manage RSVP configuration? Manual configuration of LSPs or automated methods? What's your experience with it?

    submitted by /u/ruminative_vestige
    [link] [comments]

    Transition from Networking/IT Career to something else?

    Posted: 02 Mar 2020 08:58 AM PST

    Is there anyone here that has transitioned out of Networking or IT altogether and survived to tell us about it?

    The always on call/standby, denied vacation requests (with a large amount of vacation time accrued), Unflexible scheduling, long hours, etc. wear on people quickly. After being in several organizations it seems to be just a common theme across the IT industry. I know there are jobs/orgs where this isn't the norm, but those seem to be rare these days. The Network Admin/Engineer pay is hard to compete with in other career fields in the Southern US. What are some other career fields that may offer better work/life balance and comparable pay that wouldn't require starting from scratch? Has anyone here made a career switch that improved their quality of life? Has anyone made the switch and then ended up coming back? Curious to hear your thoughts and experiences.

    submitted by /u/sucksatservers
    [link] [comments]

    Trunk 2 switches with 10 Gb SPF+

    Posted: 02 Mar 2020 03:21 AM PST

    I am trying to connect 2 switches with a 10Gb SPF+ module we just bought.

    The 1st Switch of 2 switch ssack is the stack master, the 2nd switch is a stack member:

    Switch Ports Model SW Version SW Image


    • 1 28 WS-C3750G-24TS-1U 12.2(50)SE5 C3750-IPBASE-M

      2 28 WS-C3750G-24TS-1U 12.2(50)SE5 C3750-IPBASE-M

    Now I am trying to connect a 3rd switch from its SPF module to one of the 1st switch's (stack master) SPF module using this cable: https://www.fs.com/de-en/products/30862.html

    3rd switch:

    Cisco IOS Software, C2960X Software (C2960X-UNIVERSALK9-M), Version 15.2(7)E1, RELEASE SOFTWARE (fc4)

    Both SPF modules are currently down (err-disabled)

    submitted by /u/scoobydoobidoo420
    [link] [comments]

    VIRL IOSv Autoinstall

    Posted: 02 Mar 2020 01:11 PM PST

    I'm pretty sure it's not as I can't get it to work, but it does work on a CSR100v

    Any why to enable it on the IOSv devices?

    https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/fundamentals/configuration/15mt/fundamentals-15-mt-book/cf-autoinstall.html

    Thanks.

    submitted by /u/IndSolutionist
    [link] [comments]

    Best way to diagram shortest OSPF Cost Routes?

    Posted: 02 Mar 2020 10:04 AM PST

    I'm trying to figure out the west way to diagram the best routes of a network based on costs. Is there a program out there or an excel sheet or something where I put in the devices, connect all of them, put in the costs and it will tell me the route data will flow?

    Most importantly, I am looking for a feature where I can change costs of circuits and it will autoupdate and tell me the new best route, dependent on the new costs.

    Does anything like this exist? I'm a very visual person so my "ideal" program would be like

    Input box 1 : Starting Router

    Input box 2: Ending router

    Output: Router A -> Router C -> Router B - Cost: 11

    [Output Diagram of entire network, but the route taken is highlighted]

    Thanks!

    submitted by /u/Deose42
    [link] [comments]

    Help understanding Aruba controller + APs, and how it relates to IPv6 and also VLANs?

    Posted: 02 Mar 2020 02:27 AM PST

    1. IPv6

    Our ISP provides IPv6 through prefix delegation.

    The edge router is running pfSense 2.4.4-p3, and the switch is a Ruckus 7150. I have an Aruba 7030 mobility controller plugged into the switch, as well as Aruba APs. The controller communicates with a remote Aruba mobility master hosted offsite.

    For wired clients plugged into the Ruckus - they successfully get a IPv6 address - however, wifi clients do not. Is there something special I need to do on the controller to let it pass through IPv6 addresses to wifi clients?

    I vaguely remember there was a question in the controller full-setup, asking about whether I wanted an IPv6 address for it - not sure if related, but I believe I answered no at the time - is that related?

    2. VLANs

    I don't have VLANs configured in this network currently. However, I'd like to introduce them.

    The Aruba 7030 was configured just to use VLAN 1 - and I suspect that's what everything else is likely defaulted to.

    However, for wifi clients connected to the Aruba AP - how does VLAN-ing working here?

    Do the Aruba APs need to be connected to VLAN trunk ports? (I would have thought no, due to the GRE tunnel - but could be missing something here).

    Does the Aruba mobility controller need to be plugged into a trunk port?

    submitted by /u/victorhooi
    [link] [comments]

    Are there any online courses (free or paid) about the NEW Cisco certifications?

    Posted: 02 Mar 2020 03:24 PM PST

    Basically title,

    Searching in this subreddit and others, I find many people recommend some courses from Chris Bryant and Neil Anderson, and I'd like to do them after completing a free course from Stanford, but i'd want to know if they are more or less updated to the new certifications.

    Even if they arent updated, im sure that most of the old stuff will still be useful (even if it doesnt go into the new exam), but I'm asking just in case anybody knows.

    Also, please share your favorite courses that you would recommend on online platforms!

    submitted by /u/Aracubus
    [link] [comments]

    IRR invalid - parent route orgin mistmatch

    Posted: 02 Mar 2020 03:15 PM PST

    Hello,

    Does anyone know what this error means

    I asked my server provider to announce a subnet under my ASN, but https://bgp.he.net/ is showing IRR invalid - parent route orgin mismatch

    submitted by /u/snobbypanda
    [link] [comments]

    Aruba 2930F replace VSF member

    Posted: 02 Mar 2020 04:38 AM PST

    Hello,

    A member of our VSF stack of four HPE Aruba 2930F, failed last week. We have now the replacement from Aruba support, but I don't know exactly the replacement procedure.

    This is our vsf now:

    Mbr

    ID MAC Address Model Pri Status

    --- ------------- -------------------------------------- --- ---------------

    1 9cdc71-943a80 Aruba JL254A 2930F-48G-4SFP+ Switch 128 Standby

    2 f40343-71f8c0 Aruba JL256A 2930F-48G-PoE+-4SFP+ S... 128 Commander

    3 9cdc71-942a00 Aruba JL254A 2930F-48G-4SFP+ Switch 128 Member

    4 f40343-71b8c0 Aruba JL256A 2930F-48G-PoE+-4SFP+ S... 128 Missing

    And VSF config looks like this:

    vsf

    enable domain 1

    member 1

    type "JL254A" mac-address 9cdc71-943a80

    priority 128

    link 1 1/49

    link 1 name "I-Link1_1"

    link 2 1/50

    link 2 name "I-Link1_2"

    exit

    member 2

    type "JL256A" mac-address f40343-71f8c0

    priority 128

    link 1 2/49

    link 1 name "I-Link2_1"

    link 2 2/50

    link 2 name "I-Link2_2"

    exit

    member 3

    type "JL254A" mac-address 9cdc71-942a00

    priority 128

    link 1 3/49

    link 1 name "I-Link3_1"

    link 2 name "I-Link3_2"

    exit

    member 4

    type "JL256A" mac-address f40343-71b8c0

    priority 128

    link 1 4/49

    link 1 name "I-Link4_1"

    link 2 4/50

    link 2 name "I-Link4_2"

    exit

    port-speed 10g

    exit

    So.. it's better to delete member 4 or just replacing the mac on that line will be ok and it will take old conf?

    type "JL256A" mac-address f40343-71b8c0 <<- change for new mac?

    VSF is made by DAC Cable and it's a ring.

    submitted by /u/CopyRight90
    [link] [comments]

    Industry Needs - Open-Source

    Posted: 02 Mar 2020 02:10 PM PST

    Hey there!

    I'm looking for projects to fill my evenings with. By day, I'm a Network DevOps Engineer at an ISP. By night, I'm bored as hell.

    Does anyone know of any particularly under-developed areas in terms of network automation, monitoring, or related areas, which could benefit from a new open-source tool? I'd be interested in making something that could benefit ISPs (of any decent size), or large enterprises.

    I've got some ideas of my own having seen some of the struggles at my place of work, but I'd be interested in hearing about what you guys are experiencing and could use a bit of free help with. Hope this sort of post isn't too far from on-topic here!

    Thanks.

    submitted by /u/ANetworkEngineer
    [link] [comments]

    Need Wireless site survey outsourced

    Posted: 02 Mar 2020 07:37 AM PST

    Hey group been pretty swamped lately and I'm located in Canada and have 1 wireless site survey needed for a Ubiquiti network. It's not a blanket site survey but more of a assessment and troubleshooting day job. It's based in New York and they are considering switching over to Aruba HP aps. Someone please pm me or reach out to me on Sitesurveypros or see my YouTube page or LinkedIn. Also please only contact me if you have airmagnet or Ekahau with a spectrum analyzer.

    submitted by /u/rgesm
    [link] [comments]

    Keystone faceplate standards

    Posted: 02 Mar 2020 05:38 AM PST

    Does anyone have a resource they use to find out what type of jack fits into a specific faceplate?

    I have a bunch of bad jacks that look like this link https://imgur.com/cXwJkmW . The plastic is actually just deteriorating.

    The faceplates and jacks don't have a name on them. Are there standards or a way to look up what will fit what?

    Thank you.

    submitted by /u/budd313
    [link] [comments]

    Configure SRX Cluster without reth interfaces (Issue with failover)

    Posted: 02 Mar 2020 08:49 AM PST

    Hello,

    I have the attached design where the SRX cluster is connecting to standalone switches with one uplink. Hence i don't think i need reth interfaces. All the ports of the SRX will be trunk and the IPs will be on the irb.

    I'm facing an issue with the failover, it doesn't failover once i disconnect from ge-0/0/3. I found the issue with the cluster interface monitoring and the node priority for RG1 is showing zeros as shown below:

    Cluster ID: 1

    Node Priority Status Preempt Manual Monitor-failures

    Redundancy group: 0 , Failover count: 1

    node0 100 primary no no None

    node1 1 secondary no no None

    Redundancy group: 1 , Failover count: 3

    node0 0 primary yes no IF

    node1 0 secondary yes no IF

    Once I disable cluster interface monitoring the node priorities of RG1 become similar to RG0 which is supposed to be the case normally. I found my problem in this link but they proposed that the issue may be in the reth interface misconfiguration but i don't have reth in my configuration

    https://kb.juniper.net/InfoCenter/index?page=content&id=KB19431&actp=METADATA

    My questions are:

    1- Am i allowed to configure a cluster without reth interfaces

    2- Is there any workaround

    Below is the configuration:

    {primary:node0}[edit]

    root@SRX-Active# show chassis cluster

    reth-count 4;

    redundancy-group 0 {

    node 0 priority 100;

    node 1 priority 1;

    }

    redundancy-group 1 {

    node 0 priority 100;

    node 1 priority 1;

    preempt;

    interface-monitor {

    ge-0/0/3 weight 255;

    ge-5/0/3 weight 255;

    ge-0/0/4 weight 150;

    ge-5/0/4 weight 150;

    ge-0/0/5 weight 150;

    ge-5/0/5 weight 150;

    }

    }

    {primary:node0}[edit]

    root@SRX-Active# show interfaces

    ge-0/0/3 {

    unit 0 {

    description **Link-to-SW1-below**;

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/4 {

    unit 0 {

    description **Link-to-SW1-upper**;

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/5 {

    unit 0 {

    description **Link-to-SW2-upper**;

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/6 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/7 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/8 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/9 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/10 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/11 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/12 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/13 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/14 {

    unit 0 {

    family ethernet-switching {

    vlan {

    members vlan-trust;

    }

    }

    }

    }

    ge-0/0/15 {

    unit 0 {

    family inet {

    dhcp {

    vendor-id Juniper-srx345;

    }

    }

    }

    }

    cl-1/0/0 {

    dialer-options {

    pool 1 priority 100;

    }

    }

    ge-5/0/3 {

    unit 0 {

    description **Link-to-SW4-below**;

    }

    }

    ge-5/0/4 {

    unit 0 {

    description **Link-to-SW1-upper**;

    }

    }

    ge-5/0/5 {

    unit 0 {

    description **Link-to-SW2-upper**;

    }

    }

    dl0 {

    unit 0 {

    family inet {

    negotiate-address;

    }

    family inet6 {

    negotiate-address;

    }

    dialer-options {

    pool 1;

    dial-string 1234;

    always-on;

    }

    }

    }

    fab0 {

    fabric-options {

    member-interfaces {

    ge-0/0/2;

    }

    }

    }

    fab1 {

    fabric-options {

    member-interfaces {

    ge-5/0/2;

    }

    }

    }

    fxp0 {

    unit 0 {

    family inet {

    address 192.168.1.1/24;

    }

    }

    }

    irb {

    unit 0 {

    family inet {

    address 192.168.2.1/24;

    }

    }

    }

    submitted by /u/Hussam_Bay
    [link] [comments]

    Blocking Internet Connection if it hasn't resolved a dns query

    Posted: 01 Mar 2020 11:56 PM PST

    I am an IT Specialist and until now I've been monitoring dns queries made to my local server to prohibit non work related websites and prohibiting the use of other dns services.

    During a discussion with a much more senior specialist he gave the point that a tech savvy user could access the internet without using dns at all and advised me to not allow the users to connect to the internet if they don't use dns.

    The problem is I've been researching all weekend and haven't found anything. I'd appreciate even a high level description of how to make it work.

    EDIT: not ALL non-work-related websites, just notorious time killers like facebook, instagram, youtube etc.

    submitted by /u/0zeronegative
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel