• Breaking News

    [Android][timeline][#f39c12]

    Thursday, June 24, 2021

    Blogpost Friday! Networking

    Blogpost Friday! Networking


    Blogpost Friday!

    Posted: 24 Jun 2021 05:00 PM PDT

    It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts.

    Feel free to submit your blog post and as well a nice description to this thread.

    Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.

    submitted by /u/AutoModerator
    [link] [comments]

    Are the phone numbers for Cisco field offices in your area disconnected?

    Posted: 24 Jun 2021 07:02 AM PDT

    I am tried reaching out to my local Cisco office for help finding a very specific consulting need. The number pushed me straight through to headquarters, who couldn't understand what I wanted so they sent me to TAC. So I tried calling several other offices in my state and all of the numbers were disconnected. Seems strange.

    submitted by /u/elipseses
    [link] [comments]

    Oxidized Github inactivity

    Posted: 24 Jun 2021 01:06 PM PDT

    For those unaware, Oxidized is a backup tool for network devices.

    It seems that the Oxidized Github page is quite inactive. CI/CD pipeline failing due to outdated ruby version, last commit on master somewhere in Februari, owner seems inactive on Git, no responses on Issues etc.

    I'm thinking of implementing Oxidized as this backup solution because:

    • Its open source
    • Wide support of the community with many models
    • It being recommended widely on this subreddit and as replacement for RANCID.
    • Has an API
    • Does not use traditional scheduling (start a backup job with 300 devices at 02:00. Instead, spread them out over, let's say, 24 hours.)

    But now I'm debating due to the project being quite inactive. What do you all suggest / use? Is there an alternative that fulfills these needs or should I go for Oxidized regardless?

    submitted by /u/Yariva
    [link] [comments]

    Any Google Network Operations Engineers out there?

    Posted: 24 Jun 2021 09:00 AM PDT

    I have an interview with Google and I would like some feedback about the Network Operations Engineer position. The job description doesn't give too many details about what an NOE does at Google and I want to know some feedback and be prepared for my interview.

    What do you do as a NOE on Google?

    Is this an Entry/Mid/High-level position?

    Would you say close to CCNA/CCNP or CCIE?

    submitted by /u/Key-Size-8162
    [link] [comments]

    Secondary NTP Time Source Recommendations

    Posted: 24 Jun 2021 12:34 PM PDT

    I'm working on a project to setup a secondary time source in our environment.

    We currently have most stuff pointing at a Loopback on our Core Switch, which is acting as an NTP Master. The Core is synced to 4 public NTP servers and then everything points at the loopback.

    I would like to have a secondary source. My first thought is to replicate this setup in our DR site with another NTP source (we use pool.ntp.org in our primary site, I'm thinking the National Research Council [Canada] time servers for the DR site.)

    Thoughts and opinions welcome.

    submitted by /u/itguy9013
    [link] [comments]

    Cisco ASA 5508-X K9 replacement options

    Posted: 24 Jun 2021 04:24 AM PDT

    If this post should be in a different sub, please let me know.

    We are preparing for End of Life in a few years for the Cisco ASA 5500 series firewalls. What would be a good choice moving forward. I primarily work with Cisco Devices but I can learn just about anything. Does anyone have experience with the Firepower 1000 series devices?

    Edit: 90% of the devices we have now are Cisco ASA-5505-SEC-K9 and Cisco ASA-5508-K9, One company has 2900 series routers that are being replaced with new 5508-X firewalls. All Cisco switches

    submitted by /u/Sneakycyber
    [link] [comments]

    Meraki firewall

    Posted: 24 Jun 2021 03:34 AM PDT

    Hi All,

    Is there a Meraki guru out there that can confirm if the upstream firewall rules on the Meraki dashboard for cloud controller pushes policy to AP and if the AP then does the blocking of client traffic or does the client traffic still traverse the Lan to cloud controller before traffic is blocked there?

    submitted by /u/s1lentninja
    [link] [comments]

    Identifying RJ45 ends. Stranded vs Solid.

    Posted: 24 Jun 2021 07:20 AM PDT

    Is this type considered a solid, stranded or both.

    Two prong

    In school I was taught it was only for stranded. However, google search results say it is for both, or sometimes, just stranded.
    Just stranded

    Just stranded (see bottom of page)

    Can be used for both

    Thanks

    submitted by /u/jonathanovision
    [link] [comments]

    Wifi throughout an old industrial building

    Posted: 24 Jun 2021 09:57 AM PDT

    Hi there! Lurked and searched a little bit before asking this, so hopefully I'm not asking something that is already answered elsewhere. I found this post which feels a little similar https://www.reddit.com/r/networking/comments/hsq48p/a_routermesh_solution_for_a_friend/.

    I've been asked by a friend (much like in the linked post) to provide help getting decent wifi throughout an old industrial building he just purchased. Here are some details:

    • 5 floors
    • 8,000 sqft each
    • Almost entirely artist studios
    • Walls are usually thin and there's several feet of breathing room between the walls and the ceilings
    • No one needs to be streaming 4K Netflix, but consistent signal is needed since some are using this as a get-away-from-my-partner-and-kids pandemic solution

    My first thought was a switch on the first floor, wiring Cat 5 or 6 along the freight elevator, and connecting a simple mesh system on each floor.

    I did something similar at a previous job, but this was because that entire warehouse was already lined with miles and miles of networking cable and not a single employee had an ethernet input. We had wired mesh points wherever we could and properly meshed points where we couldn't.

    Here, we obviously have the flexibility to do it however we want... within reason (and budget).

    Thanks in advance for thoughts!

    submitted by /u/noforrealwhat
    [link] [comments]

    Juniper SRX PXE boot

    Posted: 24 Jun 2021 03:19 AM PDT

    I have an SRX which is working as a DHCP server for my user subnet. I want to send PXE requests from clients behind the firewall to the PXE server located in a different location in the network. What is the correct method to do this on the SRX?

    Is it with the dhcp-attributes line?

    set access address-assignment pool usr-pool family inet dhcp-attributes option 129 ip-address 1.1.1.1 

    Has anybody got a working example of this?

    I also see talk of a next-server

    https://www.juniper.net/documentation/us/en/software/junos/dhcp/topics/ref/statement/next-server-edit-system.html

    Is this required for PXE or not?

    Thanks

    submitted by /u/Tars-01
    [link] [comments]

    Black v Blue Colored 9pin RS232 cable

    Posted: 24 Jun 2021 02:16 AM PDT

    Another day, another stupid question from me to Reddit's networking community.

    I have two RS232 9 Pin Female-to-Female cables and an old style Cisco SG-300 console port in following pics:

    https://imgur.com/a/D8gSD2Y

    The blue one is a null modem cable I think. It doesn't work when I use it on an old type 9 pin Cisco SG-300 console port. The black one DOES WORK when you use it on the SG-300 console port.

    Whats the difference? Pinout obviously, but more importantly to me, I need to know what type of cable the black one is in order to buy another one identical to the black one that does work on SG-300's. I don't know what the difference is, or what type of cable that black one is I'm looking for.

    I'm thought it might be this below.. but on second look this looks more like a null modem cable like the blue one I already have:
    https://www.amazon.co.uk/dp/B002DEM02M/?coliid=I2B2WYUI0YK2J7&colid=FTPQIRXTI3LP&psc=1&ref_=lv_ov_lig_dp_it

    submitted by /u/smartiedude
    [link] [comments]

    At what point is a broadcast domain too big?

    Posted: 24 Jun 2021 08:39 AM PDT

    I'm running a /22 and a /23 for an office space. We're wanting to combine these into one VLAN for ISE, so we'd end up consolidating the networks into a /21. Realistically we'd never see a full 2000 users, but due to the way reservations are made, we need more addresses than a /22 can handle. So, would 1000 hosts on a broadcast domain cause issues? Also, how much broadcast traffic does an idle workstation that's on a domain send when it's not in use?

    submitted by /u/cokronk
    [link] [comments]

    Front Facing Web Server

    Posted: 24 Jun 2021 06:27 AM PDT

    Hey,

    Im about to migrate an internal web server to be opened to the internet. Just want to make sure if im being overkill on my setup

    LAN -> DMZ -> WAN

    ACL

    LAN -> DMZ

    Ports: 22, 443, 80 - ALLOW

    DMZ -> LAN Deny all except ICMP

    I feel like im being overkill restricting LAN to DMZ ports?

    submitted by /u/Hayabusa-Senpai
    [link] [comments]

    QoS in 2021

    Posted: 24 Jun 2021 09:30 AM PDT

    Hello!

    I've been told the other day by our senior network admins that QoS is not necessary in our network data environment because our phone system is on a separate network. They say we have more than enough bandwidth everywhere in our Campus/DC so QoS would be unnecessary.

    Is that true ?

    I've read a bit about QoS and for me I would implement it everywhere, I mean why not ? High bandwidth links with microbursts could cause congestion on slower links (10Gbits to 1Gbits).

    For our remote sites, let's say we have a 100Mbps ISP circuit. Don't we want to prioritize important traffic before let's say Netflix traffic when the 100Mbps is full ? I guess that's managed by L7 firewall rules and not QoS right ?

    Thanks

    submitted by /u/Jubacho
    [link] [comments]

    Planning to take bsnl air fiber franchise

    Posted: 24 Jun 2021 03:16 AM PDT

    Hi 👋

    I am planning to take bsnl (India ) airfiber franchise at my place. Right now we don't have any network providers at my location.

    So I started to think about it and contacted bsnl. BSNL will be giving space and powe but we need all other equipment for transmission.

    The equipment BSNL suggest costs around 75000.

    It would be hard for me to get 10 customer in next 3 months. I am thinking if you can suggest cheap alternative network design/devices.

    I am thinking of one sector antenna instead of 3 which reduces cost drastically. I know one person used to run network with just power beam and airgrids. Can someone suggest me cheap alternatives please? I am not trying to earn profit , I am just trying to provide connectivity 15 coastal border villages to help the children connect to online classes etc.

    I don't need any profit I just need network up and give a chance people to able to use it

    submitted by /u/v-ra
    [link] [comments]

    [Help] Cisco CBS350 stack switching capacity

    Posted: 24 Jun 2021 08:58 AM PDT

    Hello,

    I am planning to install 2 CBS350 as a stack with 2 twinax cables. I am wondering what the capacity on the fabric is considering there are 2 10Gbe composing the stack connection. Is it ~10Gb, ~20Gb, or something else entirely.

    I am having trouble finding the documentation that specifies this.

    Thank you

    submitted by /u/TSArc2019
    [link] [comments]

    CIS Dashboards for Network & Network Security

    Posted: 24 Jun 2021 08:48 AM PDT

    Has anyone here ever created dashboards around CIS Network controls before? There's tons of them and many doesn't make sense (or possible) to be tracked so looking for some general ideas from the people who might have done it earlier.

    submitted by /u/That_Firewall_Guy
    [link] [comments]

    How to calculate and assign minimum numbers of IP address based on the topology logical design?

    Posted: 24 Jun 2021 08:37 AM PDT

    Hello! Sorry for the most likely bad post because I haven't searched too much about this topic. I have an exam coming very soon and this type of exercise proves to be the hardest for me and my classmates because it's still not clear for us how to solve the problem.

    I have a topology given by it's Logical Mode Design and one IP address. I have to subnet the topology so that I have the minimum number of used IP addresses based on the given IP. Each device in the topology must have an IP address assigned.

    Here are some exemples ( exemple1, exemple2, exemple3 )

    Here me and my friends tried to solve the first two, but we aren't sure if it's correct ( solve_ex1, solve_ex2, the numbers and colors represent a network ).

    We are able to solve the simpler ones but the complex ones give us trouble ( exemple 3 ) and we have plenty more of these.

    The things we understood are:

    • each router interface must be on a different network;
    • everything connected to a switch must be on the same network;

    Are there any more rules that we don't know yet? What should I search for to learn more about this topic ? Any tips on completing this kind of exercises?

    Thanks for reading, have a good day!

    submitted by /u/Ionnier
    [link] [comments]

    Layer 0: Wall mounting IDFs in warehouses

    Posted: 24 Jun 2021 08:34 AM PDT

    I can't think of a better subreddit for this question, but let me know if there is. Got a brand new warehouse 150,000sqft (~3.5 acres) of enclosed space. Wall mounted IDFs every few hundred feet down the two outside walls.

    The walls are insulated with ~3" thick foam, and the cable contractor cut out the foam to mount the racks to the concrete. I had expected plywood to be mounted to the concrete through the foam, and the wall-mount rack to be mounted to the plywood.

    My concern is condensation along the back wall of the IDF, which is now in direct contact with the outside concrete wall. The warehouse is not temperature (or therefore humidity) controlled, aside from fans for circulation and heaters for the winter.

    Does anyone have a similar environment in their domain? Is this worry about nothing? I could put some R15 foam on the back if it becomes a problem perhaps?

    submitted by /u/porkchopnet
    [link] [comments]

    Seeking Brocade VDX firmware - help!

    Posted: 24 Jun 2021 08:23 AM PDT

    Hello! I just purchased a pair of Brocade VDX 6720-16-R switches to switch 10 Gbe iscsi traffic at a new DR site but they aren't running the same firmware (3.0.1 and 4.0.1 respectively.) Additionally, in order to stack/virtual chassis the switches it appears I may need Network OS 4.1.3x (?) If anyone can provide me with some ancient Brocade firmware I'll be very very grateful. Thank You!

    submitted by /u/tedwin1
    [link] [comments]

    BGP Selective Aggregation

    Posted: 24 Jun 2021 07:54 AM PDT

    Hello Redditors,

    I've got the following situation:

    • We have 2 exit points to the internet with multiple carriers, those exit points are located on different geographical places and each one has an Edge Router (Cisco ASR1004)
    • Due to the lack of IPv4 we basically provide downstream (to our equipment) /27 or /28 ranges
      • Those ranges are advertised via BGP back to our edges (we use OSPF for transit links and BGP for everything else)
      • Our Edge routers then just aggregate this and send the /24, /23, /22, etc. To our upstreams
      • This worked great because in the case one edge somehow lost connectivity to the main network, it stopped seeing the /27-/28 and didn't broadcast anything so our traffic went in using the next available Edge
    • We recently connected a couple of customers directly to the edge and we provided them with /30s in the PTP from one of our /27, our edge started sending this /27 via iBGP as all of the other equipment we have.
      • Then this specific edge lost connectivity to the main network
      • But this time it used the local /27 as an aggregation source and didn't stop advertising a specific /22, as such we kept receiving traffic for this /22 via the upstreams in this location, effectively blackholing a big part of our traffic

    So here comes the question, is there any way (in Cisco specifically) to aggregate ranges selectively, as in, tell the router "do not use/consider this range when trying to aggregate/summarize, just use these others", so we can avoid this situation again?

    I saw the different MAPs that we can use but they all seem to be related to adding parameters or inheriting parameters.

    Thank you all in advance.

    submitted by /u/shaoranrch
    [link] [comments]

    Hairpin two untagged vlans

    Posted: 24 Jun 2021 10:07 AM PDT

    Hi guys

    I have two untagged vlans that I need to pass through as untagged through a single interface and split up on the other side. switches are nightmare... Sorry Netgear smart managed switches.

    One vlan has public IP's the other is the local network.any ideas how I can do this?

    submitted by /u/retrogamer-999
    [link] [comments]

    Replace Cisco 1921 for 1Gbps Internet?

    Posted: 24 Jun 2021 05:30 AM PDT

    We recently upgraded our office to a 1Gbps fiber Internet connection. I am still using the Cisco 1921 router, which is not spec'd for those kinds of speeds. When a run a speed test, I get close to 900Mbps (so not too shabby) But I don't want this older router to be a bottleneck. What would be a good SMB replacement that can handle our faster connection?

    The router does not need to do anything other than route traffic to/from the Internet. All the other work (VPN, IDS/IPS, VLAN) is done by devices behind the router.

    submitted by /u/Catdaddyx2
    [link] [comments]

    Cisco ISE - iOS PEAP Authentication Invalid Credentials and AD lockouts

    Posted: 24 Jun 2021 05:23 AM PDT

    We have a wireless network that uses ISE for PEAP authentication (username/password). We started receiving reports of AD account lockouts for a few users. After digging into it we found that ISE was showing that the clients entered invalid passwords. This is where it gets weird.... We worked with the users to ensure they had the proper passwords. It seems that iOS devices specifically are having an issue where they are able to connect successfully initially but after some time the phones start sending invalid credentials. The phones will keep trying to authenticate and it eventually leads to a lockout in AD. Has anyone seen this time of issue specifically related to ISE, iOS, and PEAP?

    EDIT: At this point I don't think the phones have invalid credentials stored, it almost look as if they are abandoning their PEAP sessions which is causing the invalid password to trigger.

    submitted by /u/jacobt777
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel