• Breaking News

    [Android][timeline][#f39c12]

    Saturday, May 2, 2020

    Free Certifications and IT Conference Registrations (where they usually give out codes for more free certifications) Networking

    Free Certifications and IT Conference Registrations (where they usually give out codes for more free certifications) Networking


    Free Certifications and IT Conference Registrations (where they usually give out codes for more free certifications)

    Posted: 02 May 2020 01:55 AM PDT

    CCIEs of reddit: how long was your average read/day?

    Posted: 02 May 2020 02:22 PM PDT

    Hi everyone.

    I struggle. I have always struggled. I do not know whether I am too lazy or borderline ADHD. But my max. concentration study time is 2 hours/day. After that my brain cannot absorb anything else and I would just stare at the void as I am unable to store any new information.

    Should I just quit my dream target or is there a trick to it?

    submitted by /u/nicolaidesnikos
    [link] [comments]

    why TCP BBR throughput still significantly affected by packet loss.

    Posted: 02 May 2020 10:45 AM PDT

    After reading this medium post [1] about BBR, where they simulate packet loss using the following command :

    sudo tc qdisc add dev eth0 root netem loss 1.5%

    But throughput drop from 8.55 Gbits/sec to 2.49 Gbits/sec with TCP BBR.

    Since BBR is designed to respond only to actual congestion by modeling the real available bandwidth I don't understand why the throughput is reduced this much.

    Is it because the model still assume the available bandwidth is this small ?

    [1] https://medium.com/google-cloud/tcp-bbr-magic-dust-for-network-performance-57a5f1ccf437

    submitted by /u/skyde
    [link] [comments]

    New Data Center - ToR Singlemode or Multimode?

    Posted: 02 May 2020 03:22 PM PDT

    I'm trying to build a cable plant design for a new data center. I have to spec out a lot of multimode fiber for the server folks who insist on using fibrechannel for storage, but for regular ethernet traffic should I also stick to multimode or should I go with singlemode? As speeds push to 100Gb and 400Gb is multimode no longer a viable option? I'm just getting up to speed on 400Gb now, but it seems like there is no bidi option for multimode but instead requires a full MPO24(!)

    Any thoughts from data center folks?

    submitted by /u/imodey
    [link] [comments]

    Juniper:EVPN:VXLAN - Router id mismatch with source vtep

    Posted: 02 May 2020 11:00 AM PDT

    Dear, I hope you guys doing well and safe!

    Juniper noob here trying to learn EVPN VXLAN

    after loads and loads some digging, I arrived to the config shown below, but really I can not find why my commit fails, with the following error

    Router id mismatch with source vtep: router-id:0.0.0.0 lo0.0:10.100.100.1 error: configuration check-out failed 

    This is the config I have on one of lab MX

    jcluser@vMX1# edit routing-instances [edit routing-instances] jcluser@vMX1# show EVPN { protocols { evpn { encapsulation vxlan; extended-vni-list 34; multicast-mode ingress-replication; } } vtep-source-interface lo0.0; instance-type virtual-switch; bridge-domains { BD { vlan-id 34; routing-interface irb.34; vxlan { vni 34; ingress-node-replication; } } } route-distinguisher 10.100.100.1:34; vrf-target target:1212:34; } [edit routing-instances] jcluser@vMX1# top edit interfaces lo0 [edit interfaces lo0] jcluser@vMX1# show unit 0 { family inet { address 10.100.100.1/32; } family iso { address 49.0001.1010.0100.0000; address 49.0001.1010.0100.0001.00; } } [edit interfaces lo0] jcluser@vMX1# commit [edit routing-instances] 'EVPN' Router id mismatch with source vtep: router-id:0.0.0.0 lo0.0:10.100.100.1 error: configuration check-out failed [edit interfaces lo0] jcluser@vMX1# 

    Why oh why!!

    Have you seen this before?

    Is there any easy to follow one workbook for learning EVPN / VXLAN?

    I appreciate your comments and directions

    ppacv

    submitted by /u/ppacv
    [link] [comments]

    New FTTH connection, problems with SSL VPN, slow file opening

    Posted: 02 May 2020 03:23 AM PDT

    Hi,

    i'm here to ask help to identify the root cause of a FTTH connection that is acting very poorly to open files via SSL VPN.

    Here the spec:

    • 60 mbit up/down symmetic FTTH Connection. Is a business grade one with bandwidth reservation (600€/month)
    • Zywall USG 210 Router Firewall.
    • The server on i'm opening the files is a Windows 2016 file server VM, full patched, 4 core, 6 gb RAM.
    • The infrastracture in new: 2 HP DL380 Gen10, 10 gbit networking between the 2 esxi host and principal switch

    Previusly, we had a RDSL 15 mbit download and 3 mbit up at that site and opening a file took actually less time.

    What i'm seeing: when i'm connected via SSL VPN (provided by the Zywall) to that server, if i try to open a 3 Mbyte excel file i get Excel freezing for about 10 second, then i see that excel is actually opening the file, i see the progress about at 15% increments, each one last about 3/4 second.

    Total time to open a 3 mbyte file is about 40 second. This doesn't change if i use my workstation or another, or if i have Excel already opened or not.

    What i've done until now:

    • Tested bandwidth: i have a full 60 mbit down/60 mbit up with 2/3 msec ping from a speedtest
    • I've adjust the MTU of the wan port to 1490, as i see it started to fragment at 1464 size and does not at 1462
    • Running iperf from my home connection using VPN i get transfer speed about 12/15 Mbits. I have a 100/20 mbit connection at home and it was not loaded with other tasks at the moment (netflix,ecc)
    • The problem does not occupr on local Lan
    • Running Wireshark at my point. I get some TCP Spurios Rentransmission error and TCP Dup ACK error repeatly.

    In wireshark i tried to get some data (this data has been created today, when the performance seems a little better but i'm the only one connected today, yesterday with 5 people via VPN the opening time in SMB2 report was 23 seconds)

    https://imgur.com/a/2twMyA9

    SMB2 Service Response Time Statistics - Ethernet 2:

    Index Procedure Calls Min SRT (s) Max SRT (s) Avg SRT (s) Sum SRT (s)

    ---------------------------------------------------------------------------

    SMB2

    Close 6 208 0.017751 0.123955 0.027319 5.682350

    Create 5 205 0.018134 0.123470 0.030133 6.177226

    Find 14 30 0.050237 0.087804 0.056980 1.709402

    GetInfo 16 92 0.018054 0.104919 0.025832 2.376504

    Ioctl 11 16 0.018615 0.057483 0.025317 0.405076

    Read 8 54 0.018147 1.829909 0.245593 13.262049

    Tree Connect 3 6 0.018539 0.022023 0.019451 0.116708

    Write 9 12 0.018514 0.066883 0.023869 0.286423

    SMB2

    ---------------------------------------------------------------------------

    submitted by /u/execcr
    [link] [comments]

    Juniper Campus EVPN-VXLAN Fabric

    Posted: 02 May 2020 04:51 AM PDT

    Has anyone here used Junipers campus EVPN fabric? I am looking at different solutions for VXLAN overlays to allow layer 2 connectivity across a fabric without creating a huge L2 domain like I have today. This is required for different vendors that have statically assigned mobile devices and cant do DHCP.

    Has anyone used the Juniper solution on their EX series switches, creating a spine/leaf architecture? Most the info I have found from an end user perspective is their data center solution. Does anyone have experience with the campus solution? How stable has it been? Have you ran into any issues? How easy is it to configure and maintain? Have you used this with multiple routing instances (VRFs)?

    Thanks

    submitted by /u/drummerboy988
    [link] [comments]

    upgrade to FGT 6.2.3 and issues with an office reaching our EMR and VMware View

    Posted: 02 May 2020 04:24 AM PDT

    Hi - we are a small hospital that recently upgraded our Fortigate firewall from 5.6.11 to 6.2.3 per their recommendations. The upgrade went smoothly, albeit a couple minor issues, one being that our SSLVPN users couldn't reach our internal ADFS / SSO server due to a caveat in the new code, which tech support was able to remedy by enabling auxiliary session (https://docs.fortinet.com/document/fortigate/6.2.3/technical-tip-enabling-auxiliary-session-with-ecmp-or-sd-wan/19/fd47765)

    However, one issue remains, and that is that a healthcare org that we closely work with is no longer able to reach our EMR (which is publicly accessible via a pub DNS record and SSL cert), as well as our VMware View connection server. Both of these should be reachable over 443, and from our firewall rules should be allowed in. I've confirmed I am able to publicly hit both from the internet, regardless of where I am, can access both on my smartphone for example, AND I can successfully access both via this healthcare org's PUBLIC wifi (seperate network).

    But this healthcare org it seems to be timing out when navigating via https while on their wired and secure wifi network - the telnet port tests show connectivity over 443, but to me it seems like a TLS issue - their web browsers are showing "Cannot connect to this site securely". I don't have any control over this org but as far as their IE Security options go, they allow TLS 1.0, 1.1, and 1.2, but they're all grayed out due to GPO policy that I can't edit. They say they are allowing all 3 and I believe them based on what I see, but why can't they then hit our 2 sites on 443 securely?

    The POC I worked with Friday said he whitelisted our domains with wildcard entries for our domain name on their webfilter, but I'm still skeptical. If I can reach these sites right now from my home machine, what would make this "our issue"? And I don't doubt that we have some part to play in it; the issue occurred following our firewall upgrade, so I am open to any insight or suggestions. Thanks!

    submitted by /u/iamboblazar
    [link] [comments]

    Why can i manage a domain on multiple platforms?

    Posted: 01 May 2020 11:59 PM PDT

    Hi all,

    I'm a sysadmin for a while now and I study hard to keep up and keep learning new things. I am by no means a networking expert. Today I ran into something that was really weird in my opinion. We host one of our domains at a Dutch supplier. We manually add and modify records and it's all fine.

    Because of some certificate issues in a webserver hosted at AWS, I was involved in that environment for the first time, and a colleague showed me around. Then, I noticed that they have multiple records for the same domain I host at my Dutch supplier, I only saw local records though. So, to the DNS guru's out there: how is it possible that one single domain has records at multiple domain hosters?

    submitted by /u/TemporaryFigure
    [link] [comments]

    Am I missing something ? /32 subnet mask for PPPoE

    Posted: 02 May 2020 05:21 AM PDT

    Hey fellas,

    First post ever, so go easy on me.

    So I got my CCNA and got my first networking job. We have a small customer who bought a router from us and wishes to use it with their existing pppoe connection. They don't have their own IT, just a 3rd party support, and we asked them for the connection type so that we can pre-configure the router prior shipping.

    So according to them we need to set a static IP on the PPPoE interface but with the subnet mask of /32..?

    Since I'm a newbie , I did not want to question their network engineer, but even my colleagues were surprised (they are located in the US, so they are not really familiar with this type of "old connection").

    Is there a gap in my knowledge regarding any speciality with pppoe or did the guy just made a typo and he wanted to write /30 for p2p connection ?

    Any comments are highly appreciated, thanks

    submitted by /u/invii03
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel