• Breaking News

    [Android][timeline][#f39c12]

    Saturday, July 17, 2021

    Where to learn about peering types, internet exchanges, etc.. ? Networking

    Where to learn about peering types, internet exchanges, etc.. ? Networking


    Where to learn about peering types, internet exchanges, etc.. ?

    Posted: 17 Jul 2021 02:23 PM PDT

    I'm interested to learn as much as I can about BGP and peering on the Internet. I've learned how the BGP protocol works and is configured, but I don't have practical experience yet and there are many things I'm missing about how the economics work, what are the various types of peering that exists, how do internet exchanges work, etc...

    I've found "The 2014 Internet Peering Playbook: Connecting to the Core of the Internet" by William B. Norton, which was a very interesting read that I can recommend; but it's a bit dated at this point and it also mostly covers the economics and doesn't cover much technical details such as how IXPs are usually setup or how configuration is agreed between peers, etc...

    Is there some other resource/book/site that you would recommend as a read to learn more on this topic?

    Thank you

    submitted by /u/brogid
    [link] [comments]

    lab env getting the full route table.

    Posted: 17 Jul 2021 06:48 AM PDT

    One question brought up when I was conversation with a team mate, that I'm curious if we could simulate a router receiving the full routing table, without the lab router ever making a connection to our production routers.

    submitted by /u/scriptkeeper
    [link] [comments]

    Where did Checkpoint go wrong vs PANW? (Non Tech)

    Posted: 17 Jul 2021 12:02 AM PDT

    I have worked in IT Sales for a while right now.

    A common them in Firewalls is the preference of fortinet(if low budget) or PANW(if high budget).

    I see slower demand for Checkpoint - its been over a year since I sold one. PANW or Fortinet on the other hand, I keep getting inquiries and sales.

    Reps from PANW are always organizing meetings and pitching it to us, while Checkpoint staff has never contacted my team unless we bring a lead to them.

    I notice that Checkpoint is one of the apex cyber security companies but is it in a waning phase? like many legacy companies that started to bottleneck?

    Anyone with experience evaluating performance of Checkpoint vs PANW or FTD?

    submitted by /u/trickintown
    [link] [comments]

    Upgrading Network devices for small business - Advice?

    Posted: 17 Jul 2021 02:34 PM PDT

    Hello all,

    I came into a admin position for a smaller business a couple years back and since then its been mostly up keep. I upgraded our firewall to a SonicWALL, but everything else is pretty much what was there when implemented. What I'm wondering is, I'm looking for new devices and would like to stay uniform across the board if its better. Right now there are a wide variety of devices within this business. SonicWALL for the Router and Security, an old EOL Cisco Switch that has to be gotten rid of, a couple HP / Aruba 48 Port POE Switch that will probably be good for a couple more years, and then Small Cisco VPN Routers that connect certain aspects of the network to other parts. There is also a Unifi Wi-Fi setup. I know its all over the board.

    The cisco switch is going to be replaced very soon and before that happens I believe I will talk to the business about moving to one provider or something easier to keep up with. This business hosts around 50 years and 75 devices. I would like a system where I could easily create and manage VLANs. If there was some type of monitoring or dashboards built in that would be great but not required.

    Does anyone have any suggestions on hardware? I've looked through Aruba and Cisco's sites but you know how that is. They have a switch / router for any scenario and I'm starting to get a headache looking at all of them.

    Thanks!

    submitted by /u/moss728
    [link] [comments]

    Pricing circuit strategies

    Posted: 17 Jul 2021 09:09 AM PDT

    Does anyone here have experience or is responsible for ordering circuits from service providers? If so, could you share pricing strategies, discounts received, or general tips used when shopping around? Thanks in advance.

    submitted by /u/moneybags_921
    [link] [comments]

    Meraki Layer 3 Roaming With A Concentrator

    Posted: 17 Jul 2021 09:02 AM PDT

    I have a small campus type of environment: a bunch of buildings connected with fiber, several hundred users, maybe 50-100 APs when we are done. We are looking at migrating to Meraki and have been doing a pilot program. The buildings are connected with Layer 3 connections to the other buildings, so each building has its own voice VLAN, data VLAN, etc.

    One of the issues I have is that we have one "Staff LAN" SSID set up to authenticate users with RADIUS and place them on the appropriate subnet depending on which OU they are part of. There are three OUs of interest. I see that Meraki supports Layer 3 Roaming with A Concentrator. Apparently I would need to purchase a large enough concentrator to support multiple tunnels from each access point so that I can have the same subnet between any building for the proper OU. Has anyone used MX devices for this purpose? Did you find that there is a bottleneck within the MX device?

    I'm trying to wrap my head around a different way of designing our network to meet the security requirements between the wireless subnets, but change at this scale won't come easily. Tunneling everything through an MX seems like a band aid, especially because Meraki says that not many customers do this. We are currently using a Cisco WLC, which makes all of this easy....but we really like how much easier Meraki is to manage, especially on the guest Wi-Fi side of things.

    submitted by /u/ip_addr
    [link] [comments]

    HP printer on Wi-Fi continues to disconnect and reconnect randomly

    Posted: 17 Jul 2021 08:57 AM PDT

    I have an HP LaserJet M479fdw connected to Wi-Fi. Wi-Fi is provided by a Cisco Meraki MR33. The MR33 is plugged into an MS120-8P, which is then plugged into a Netgate SG-1100 (pfSense). The LaserJet is on its own wireless network (VLAN 530). Rules are in place to allow ICMP and printing from our access network. These rules work flawlessly when the printer is actually online. For the life of me, I can't figure out why, but the printer randomly goes offline for anywhere from 1 to 15/20 minutes and then comes back to life for another 1 to 15/20 minutes before randomly going offline again. I'm sitting in the same room as the printer with my iPhone and laptop both on wireless and we've had no issues, so I can't imagine it would anything signal related. Regardless, I've tried the following:

    • Disabling traffic shaping on the network.
    • Changing sleep mode on the printer to 1 hour.
    • Configuring 5GHz only and then back to 2.4GHz/5GHz with band steering.
    • Allowing all traffic to/from the printer from my VLAN (520) to the printer VLAN (530).
    • Enabling/disabling numerous services on the printer itself, including (but not limited to) WSD, NetBIOS, AirPrint, etc. At the moment, the only service in use is TCP 9100 for JetDirect printing, and this works perfectly fine when the printer is actually online.

    In the event logs on the Meraki, the following screenshot shows what's occurring. I do not know why the device is randomly disassociating. In the timestamp from 11:11 AM, for example, the printer deauthenticates and disassociates for an unknown reason (which the Meraki states typically occurs when the client moves out of range). It remains disconnected for 3ish minutes. At the present time, the printer has been offline since 11:19 and remains offline as of the writing of this post. The printer sleep mode settings were changed about 30 minutes ago, so there's absolutely no reason that sleep mode would be causing the printer to disregard traffic.

    When I just looked at the UI of the printer, https://imgur.com/KGTwQG9 was displayed. I wasn't expecting this, as usually this shows "Updating..." and shows 5GHz as the network. In diving deeper, it actually shows "Not Available" for the signal and channel. What's odd is that the printer IP is statically assigned, so I don't know if HP just uses the "IP Address" field as the status field while the printer isn't connected, but previously when it showed "Updating," the IP signal would show as 5GHz and the IP Address would show as 0.0.0.0. This was also odd, considering the IP is statically assigned. The DHCP server for this subnet/VLAN is disabled, which shouldn't matter anyways since it's statically assigned on the printer.

    I'm not really sure where to go from here. Up until a week or so ago, I had no issues printing on-demand to the printer, but that was before I had installed the pfSense and configured a VLAN for the printer. I'm not sure what I'm missing here, but I'll try anything at this point since I think I already have. Please help!

    EDIT: Some further odd behavior I just experienced: I made a change to the wireless bands on the Meraki about 10/15 minutes ago (re-enabling 2.4/5GHz again). After making the change, it seemed the printer came back to life (although I also toggled the 5GHz setting on the printer off and on again, so that could have done it, too). Right at 12:18, I got an email from the Meraki telling me that the band selection was changed. I thought I made this change 10/15 minutes ago, so I figured the email was delayed. But literally the exact second the email triggered on my phone, the printer web UI let me know that my sign-out was successful. On pinging the printer, it's inaccessible again... Coincidence? Who knows? I looked at the interface of the printer again and it's actually showing the correct IP and detecting that it's on the 5GHz network, but not replying to ICMP and not printing (via TCP/IP port 9100).

    EDIT2: After the latest lack of connectivity, I left the Meraki settings in place (dual band operation) and toggled the 5GHz slider on the printer again (from on to off, then back from off to on). After doing so, the printer began replying to pings again. I am not sure whether this setting forces the printer to use 5GHz or simply enables it to use 5GHz if available. Since both bands are available, this actually shouldn't have had any impact as the printer would have (should have) used 2.4GHz if 5GHz was disabled. My next step, since I haven't tried this yet, may be to force 2.4GHz and disable 5GHz entirely. Not sure why this would have any positive impact, but I'm also not sure why any of this behavior is occurring to begin with.

    submitted by /u/xyeLz
    [link] [comments]

    (HELP)Ipv6 address family didnt work.

    Posted: 17 Jul 2021 09:07 AM PDT

    Hey, I hope everybody is doing well.

    I am studying for cisco test , and I tried to do a lab of bgp address fammly.

    if anyone could give some clue about what I am doing wrong.

    My topology it is simple two routers directly connected: https://pt.imgbb.com/

    And I am trying to send the network 2002::1/128 over an ipv4 season, so I created a route-map "MYMAP" with a next route my ipv6 address.

    My R2 config:

    interface FastEthernet1/0

    ip address10.0.0.5 255.255.255.252

    duplex auto

    speed auto

    ipv6 address 2001:111::1/64

    interface Loopback20

    ip address20.20.20.1 255.255.255.0

    ipv6 address 2002::1/128

    end

    router bgp 2

    no bgp default ipv4-unicast

    bgp log-neighbor-changes

    neighbor1.1.1.1 remote-as 1

    neighbor1.1.1.1 ttl-security hops 2

    neighbor1.1.1.1 update-source Loopback1

    neighbor10.0.0.6 remote-as 3

    neighbor10.0.0.6 ttl-security hops 5

    neighbor10.0.0.6 password Cisco

    !

    address-family ipv4

    neighbor1.1.1.1 activate

    neighbor10.0.0.6 activate

    no auto-summary

    no synchronization

    network20.20.20.0 mask255.255.255.0

    exit-address-family

    !

    address-family ipv6

    neighbor10.0.0.6 activate

    neighbor10.0.0.6 route-map MYMAP out

    network 2002::1/128

    exit-address-family

    !

    route-map MYMAP permit 10

    set ipv6 next-hop 2001:111::1

    My router 3 config.

    interface FastEthernet1/0

    ip address10.0.0.6 255.255.255.252

    duplex auto

    speed auto

    ipv6 address 2001:111::2/64

    end

    router bgp 3

    no bgp default ipv4-unicast

    bgp log-neighbor-changes

    neighbor10.0.0.5 remote-as 2

    neighbor10.0.0.5 ttl-security hops 2

    neighbor10.0.0.5 password Cisco

    !

    address-family ipv4

    neighbor10.0.0.5 activate

    no auto-summary

    no synchronization

    exit-address-family

    !

    address-family ipv6

    neighbor10.0.0.5 activate

    neighbor10.0.0.5 route-map MYMAP out

    exit-address-family

    !

    route-map MYMAP permit 10

    set ipv6 next-hop 2001:111::2

    I can ping the ipv6 of both fast-ether, but I am not learning about my loopback ipv6 address. In a wireshark capture I can see the advertisement of my loopback ipv6 address point for the correct next-hop:

    https://ibb.co/NKJGjx7

    But in R3 route table I cant see this route:

    IPv6 Routing Table - 4 entries

    Codes: C - Connected, L - Local, S - Static, R - RIP, B - BGP

    U - Per-user Static route

    I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary

    O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2

    ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2

    C 2001:111::/64 [0/0]

    via ::, FastEthernet1/0

    L 2001:111::2/128 [0/0]

    via ::, FastEthernet1/0

    L FE80::/10 [0/0]

    via ::, Null0

    L FF00::/8 [0/0]

    via ::, Null0

    thanks for any help .

    submitted by /u/raikone51
    [link] [comments]

    DHCP issues only on one SSID and on one AP

    Posted: 17 Jul 2021 12:19 AM PDT

    APs: Unifi AC Pro. Unifi Switch: US-24 layer 2. Aruba Switch: 2930m layer 3. Unifi controller: VM on Windows server. DHCP server: Windows Server domain controller

    Hey. We're experiencing an issue were devices connected to one particular VLAN/ SSID can't get a DHCP IP and instead assign themselves APIPA 169.254 addresses. The strangest thing about this is it's seemingly isolated to only one AP in the business - when the same devices connect to the same SSID/ VLAN on different APs in the building they get an IP via DHCP.

    Even more stranger and confussing is that devices can SOMETIMES get an IP via the problem AP whilst connected to the problem VLAN - it's seemingly intermittent. At first I thought maybe the problem VLAN has been incorrectly configured on one of the switches between the AP and the DHCP server but, if this was the case, surely the issue wouldn't be intermittent?

    I've checked the DHCP server, which is running on our Windows domain controller, and there aren't any errors so it seems like the DHCP requests travelling via the problem AP whilst connected on the problem VLAN aren't even reaching the DHCP server.

    I'm not even sure where to start looking from here as no one in the IT department has been at this company for more than 6 months and VERY little has been documented. It seems like the problem AP is able to handle traffic fine for the other VLANs/SSIDs, so other than it being poorly configured to channel 8 on 2.4Ghz radio, the AP seems ok and the DHCP server seems ok as it's able to dish out IPs error free for every other VLANs and even for the problem VLAN so long as devices aren't connected to the problem AP.

    Could it be that somehow the DHCP broadcast isn't being relayed between the VLANs on the switches? But if so why would it be intermittent?

    If you need more information then please let me know!! I'm happy to elaborate on anything you need me to.

    submitted by /u/wutanglan90
    [link] [comments]

    Looking for new datacenter core router

    Posted: 16 Jul 2021 05:24 PM PDT

    I'm hunting for a new datacenter core router for a new PoP. Right now we'll only be handling two 10GE uplinks from tier-1's, and within a few weeks we'll be linking a 10GE local IX connection.

    That being said, here's our minimum requirements:

    • 4x10GE ports
    • handle default routes
    • line-rate regardless of features enabled (within reason)

    Some preferences sit around the BGP, namely we'd love to handle two full tables but I'm doubtful we'll find anything within our budget. Management has crossed-off an MX204 and a few other "nicer" routers.

    I've contemplated setting up an Arista 7124 or 7050 to be the BGP "router" and then terminate it to other switches/nodes directly, but I believe that won't handle the full tables (which is somewhat of a shame).

    All said, what would you recommend?

    submitted by /u/thegeekbin
    [link] [comments]

    Any good books/resources for Network Sales Engineers more geared towards business and less technical?

    Posted: 16 Jul 2021 06:13 PM PDT

    Hello fellow network people ! I've recently took my career towards the sales side and I'm looking for a good resource for a Sales Engineer. Most of the books from Cisco and other vendors do a good job of the technical execution of design, but seem to lack high level business use cases. I need to learn what gear to use for certain situations. Current business needs in the networking world. A general guide for upgrading older networks. Comparing and contrasting different vendors and price points. Being cost effective. Any help or guidance is much appreciated! Thanks.

    submitted by /u/MattwillYums
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel