• Breaking News

    [Android][timeline][#f39c12]

    Wednesday, November 10, 2021

    Rant Wednesday! Networking

    Rant Wednesday! Networking


    Rant Wednesday!

    Posted: 09 Nov 2021 04:00 PM PST

    It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

    There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

    Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.

    submitted by /u/AutoModerator
    [link] [comments]

    HPE says hackers breached Aruba Central using stolen access key

    Posted: 10 Nov 2021 02:45 PM PST

    https://www.bleepingcomputer.com/news/security/hpe-says-hackers-breached-aruba-central-using-stolen-access-key/

    Just saw this from a blog, no word from our SE and account managers yet (and we spend millions with them). Have no idea what the extent is of the data breach. We're going to be engaging the SOC to see if there's anything that comes up in our logs. So note for all your central customers. We have a few hundred sites on our central platform.

    submitted by /u/arhombus
    [link] [comments]

    Whole IP Network Security Testing

    Posted: 10 Nov 2021 06:59 AM PST

    I'm looking at buying a network tester for my job. We have to verify problems for non-working security equipment that is connected by ethernet (mostly PoE) and fiber.

    I'm currently looking at the pro version of the following:

    https://www.idealnetworks.net/wp-content/uploads/2019/04/151844-NaviTEK-NT-Plus-Pro-Manual-English-Iss5.pdf

    It seems this is the most economical system out there, which is what I'm going for, that let's me at least do basic testing with the fiber. What is really crucial is the ability to identify switch and port# with the LLDP testing and the 30w PoE load testing. Most of our systems don't require more than 30w PoE.

    My question is:

    Are there any comparable systems that I am missing. I hate buying wrong.

    submitted by /u/Striking_Avocado3035
    [link] [comments]

    IOS image won’t boot to running config on 3560 switch.

    Posted: 10 Nov 2021 04:15 PM PST

    I've saved my config. I've made sure the boot statement was correct. Reload and the previous image is still running no matter what. I've been looking everywhere and can't find a way to change the register.

    It's currently set to 0xf.

    submitted by /u/PuzzleheadedSun3589
    [link] [comments]

    Cisco catalyst 3850 opinions

    Posted: 10 Nov 2021 07:13 AM PST

    We are looking to replace existing switches with something new. New in this context is new to us, not brand new equipment.

    Currently on Cisco SG300 which although a budget device has worked well but we now have a need for L3 VLAN routing.

    We also have 2 netgear XS716T which are used for vsan and not currently routed. I would add that to date these have had zero issues.

    We have looked at netgear M4300 and have gone as far as sourcing 2 of these, one new, one a year old. We have the option of returning these.

    I have since found a device which I believe will make our lives easier as we will be able to consolidate 4 switches into 2. The c3850 12x48 will give us both port types we need for access and vsan.

    I can get a pair of these for £2k with 3 years RTB warranty, so not any different to the netgear in terms of response. This could be backed up by smart net as well I believe. Current iOS version is 16.6.9 and the supplier is reputable and we have done business before.

    I have read a few stories about c3850 the same as most other switches and also about iOS issues that would also affect other devices.

    I'm looking for opinions as to whether I should absolutely not be using these or the opposite, any opinion is welcome.

    Thanks

    submitted by /u/officedg
    [link] [comments]

    BGP Redistribution - Static to BGP

    Posted: 10 Nov 2021 08:28 AM PST

    I have a Router 1 with static routes of RFC1918 with the Next Hop being the IP address of Router 2. R1 is redistributing these RFC1918 to BGP so Router 0 (Spoke Location) can learn about the RFC1918 and send them to R1 (Edge Router at the hub). If I don't use any Route Maps what will happen with the redistribution to Router 2 (Core Router/Switch)? Will it also receive these RFC1918 routes? If so, without using the next-hop-self command what will be the next-hop? Or will these RFC1918 Routes simply not show up on Router 2 ?

    More details:

    Router 0 (Spoke)------> Router 1 (Edge Hub Device) -----> Router 2 (Core at the hub)

    Router 0<---eBGPP--->Router 1 - Redistribution point Static to BGP<--->eBGP<---->Router 2

    Static Routes on R1: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 Next Hop Router 2

    submitted by /u/jguros
    [link] [comments]

    Software for Dell S4810-ON?

    Posted: 10 Nov 2021 05:09 PM PST

    I have 4 Siwtches DELL S4810-ON. They should use open Software like Cumulus or LightSwitch, But current version of Cumulus doesn't support the switch anymore, and LightSwitch doesn't exist anymore.I have been able to install ONL, but it doesn't recognize the interfaces.Someone can provide a working software for those switches?

    submitted by /u/Leonel_Toledo
    [link] [comments]

    Electrical Components of Network Circuitry

    Posted: 10 Nov 2021 05:07 PM PST

    I'm looking to do some deeper digging into how networks operate and how electrical engineering factors into network engineering. Are there any books that go into the science behind how electricity traverses a data communication circuit? I suppose books that cover the physics end of it would be just as important.

    Every book I've come across covers the physical layer briefly but doesn't delve deeper. I could tell you all the basics about how a T1 operates and how the twists per inch affect performance in Cat5 and 6 cables but I want to know the why.

    submitted by /u/network_wizard
    [link] [comments]

    BGP With Two Routers and Two Uplinks

    Posted: 10 Nov 2021 01:14 PM PST

    Hi All,

    I'm looking for some advice. Current scenario is an ASR1002-X with BGP config peering to two different handoffs going to the same place (geodiverse paths). One path is "preferred" and the other is a backup. We have our own ASN.

    Need to configure the 2nd ASR1002-X for redundancy. The preferred path will be on the first ASR, the backup on the second. How do I configure iBGP for the two routers to talk to each other and honor the preferences? We're just receiving a default route and routes for Internet 2. Any assistance is greatly appreciated!

    submitted by /u/mwagner_00
    [link] [comments]

    Firewall configuration Analysis tools

    Posted: 10 Nov 2021 07:11 AM PST

    Hi all,

    Currently I'm getting a lot of requests from customers about firewall configuration and security policy analysis, and while it's fun to dump it all out to CSV and txt files to comb through, I'm pretty sure there's an easier way.

    I've been looking at various analysis tools (Algosec, Firemon, Skybox, etc..) but they all seem to be almost a monitoring tool. (I could be wrong, haven't demo'd them yet)

    Are there any tools out there where you can throw a config file at it, and it will analysis it and generate a useful output?
    While I don't expect it to do my job for me, saving an hour or 2 here and there is never a bad thing.

    submitted by /u/bigbarruda
    [link] [comments]

    Benchmarking an App

    Posted: 10 Nov 2021 09:52 AM PST

    Hi All,

    My company develops an app that is used on Data primarily - I want to be able to gather the 'minimum requirements' and 'recommended requirements' in terms of internet speed/latency required in order to have a good experience on the app. What would any of you recommend in order to capture this?

    I'm looking for something to start from and understand there are LOTS of variables.

    Thanks!

    submitted by /u/platilostit
    [link] [comments]

    Detailed device WiFi antenna information

    Posted: 10 Nov 2021 06:39 AM PST

    I've been doing a lot of access point testing, measuring the maximum throughput on different model access points using different smart phones and tablets.

    I'm using some older access points that only have 2x2x2 MIMO and some that have 4x4x4 MU-MIMO. This information I can easily find in the spec sheet of the model.

    But for the different smart phones and tablets I have been using, I haven't been able to find a source for this, only information as to which WiFi generation they support. For example: I want to figure out how many WiFi antennas does a Samsung S7 have compared to a Samsung S21 - how many concurrent MIMO streams does the device support.

    Does anyone here know of an app that would be able to display this hardware information or how I would be able to find this info for various smart phones?

    submitted by /u/mreminemfan
    [link] [comments]

    Any Brocade FC experts in here? Will a POD license for the 5300 work on the 5100 series?

    Posted: 10 Nov 2021 07:54 AM PST

    The IT team 10 years ago didn't buy the POD license to expand past the 24 license cap and now I'm having trouble finding EOL licenses that are not $5000 (whoda thunk that?!) and I found the POD for the 5300 for ~500 but not sure if it will work.

    submitted by /u/RoutingFrames
    [link] [comments]

    Issues with routing in BGP Lab

    Posted: 09 Nov 2021 07:49 PM PST

    I am building a BGP demonstration lab, with four Autonomous Systems each with three routers. I am using VyOS for the routing, bringing up the routers with Vagrant and configuring them with Ansible. I have the routers set up and the BGP config somewhat working. I can see all the routes for all of the prefixes, but the actual routing table doesnt update. The next hop for the routes that aren't working are on subnets attached to the neighboring hosts, so it can see the route its just not making the connection.

    Here is an Imgur album with network diagram, IP/BGP tables, and router configuration. Any help with this is greatly appreciated, I've been trying to get this to work for a few days now and have been tearing my hair out. This is my first time using VyOS, I typically use OPNsense but wanted the script-ability of the VyOS CLI.

    submitted by /u/dmfiel
    [link] [comments]

    Question about trunking vs vlan participation

    Posted: 10 Nov 2021 11:01 AM PST

    I am in the middle of an epic saga in trying to get the enterprise network that I have inherited back in working order. Members of this community have already been immensely helpful to me in this project. Here's hoping you all can come to my rescue yet again.

    I have a ubiquiti edge switch, a layer 2 switch with multiple vlans that *should be* trunked back to a layer 3 core switch. The interface in question that connects to the layer 3 switch is not trunked. The configuration on the interface instead shows:

    vlan participation include 10,20,22

    vlan tagging 10 (phones)

    Will this accomplish the same thing as trunking? I would guess not. Could it be why I cannot ping the SVI gateway for vlan 22 on the layer 3 switch? What is the difference between vlan participation and trunking? How should the port be configured to allow me to use vlans 1,10, 20, 22 on this switch?

    Thanks for your help!

    submitted by /u/IslandTechVI
    [link] [comments]

    MPLS only network VeloCloud Edge activation

    Posted: 09 Nov 2021 08:28 PM PST

    Hello all,

    This question would have been asked already, but I did not find anything about it online.

    How do you activate VeloCloud Edge in a MPLS only branch site with no internet link?

    Do we have to provision the edge first in the VCO, configure Edge specific settings by creating user-defined overlay, enable Service Reachability in the WAN settings, and then send the activation email along with configuration to the site contact?

    because the normal approach shows an "VeloCloud Orchestrator Unreachable" error during activation.

    Thank you

    submitted by /u/MChethan7
    [link] [comments]

    Android devices get IPV6 address as primary DNS server. No IPV6 dhcp on network (Checked)

    Posted: 10 Nov 2021 01:01 AM PST

    Hi all

    I have some troubles triyin to resolve local dns names on the Android Wifi connected devices.

    Our installation:
    Firewall (that not provide DHCP) USG310 by Zyxel
    Windows 2019 DC with DHCP v4. No IPv6 Configured.
    Wifi Ruckus with ZD1200 Controller

    If i check the data assigned with DHCP:
    Get the IP for Our DC DHCP server.
    Primary DNS1: fe80::250:56ff:febe:f93d%wlan0
    DNS2: Primary DC DNS IP
    DNS3: Secondary DC DNS IP

    Trying to resolve dns that are created by us, failed randomly. because android device first try to resolve into internet dns prior to use the internals.

    Test already done:

    1. check my Firewall. No ipv6 configs here.
    2. check my DHCP, there are NO ipv6 config at all.
    3. iPhones, works good, get only ipv4 local dns.
    4. Check for rogue DHCP on network, not show anything
    5. Connect a windows laptop (wifi) with ipv6 enabled, not get any v6 config.
    6. Connect a windows laptop (WIF and LAN), with ONLY ipv6 protocol, not get any config.
    7. My ruckus controller, not show any ipv6 configuration that involve this protocol.
    8. This kind of IPV6 Address, locks that only local link address, and are not MAC Address vinculated to check the origin.
    9. IPv6 is disbled on the WIFI controller...

    I´m running out of ideas,Any help willbe appreciated.

    submitted by /u/Winter_Highlight4775
    [link] [comments]

    Netflow Ingress Only

    Posted: 09 Nov 2021 04:20 PM PST

    Hello,

    im currently using Cisco NCS 5500 and this only supports Netflow Ingress, in the past with ASR9000 i would enabled netflow on a interface and be able to see inbound and outbound traffic.

    But with NCS 5500 being capped to ingress only how im stuck with only inbound traffic, how can i check my outbound traffic flow ?

    Im currently generating flow from my NCS 5500 o my internet facing interface. Should i generate flow also on my core facing interface to be able to see the outbound traffic ?

    submitted by /u/devzeroo
    [link] [comments]

    Microwave links/PTP

    Posted: 09 Nov 2021 04:19 PM PST

    Hi All,

    Seeking some advice about microwave links.

    Rather than pay for a normal vpls/IPSEC over DIA etc I was wonder how feasible using a microwave link would be.

    Background

    We are based in small town centre in the UK.

    We are looking at taking the building next door which has clear line of sight and is 70meters/230ft away.

    Exisiting building has 300 users. The New Property is likely to have 150 users.

    Typical UK weather.

    Ideally low latency < 5ms and bandwidth of 10GB.

    Questions :

    1) can anyone advise what speeds you can get in "real life" I have seen 10GB but is that realistic in real world usage?

    2) I looked at this tech along time ago - 15 years ago - weather / birds etc are still gotcha's?

    3) Can you recommend a UK partner to work with?

    4) is there a "no brainer market leader in the uk"? Siklu? any to avoid?

    5) Link install is < 30 day ? You need a license?

    6) Typical costs? my assumption is cheaper than DIA-VPN/VPLS over 3 years...?

    7) any lessons from the field you can share?

    many thanks :)

    submitted by /u/ramraiderqtx
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel