• Breaking News

    [Android][timeline][#f39c12]

    Saturday, November 27, 2021

    What actually happens if you forget to pay ARIN Networking

    What actually happens if you forget to pay ARIN Networking


    What actually happens if you forget to pay ARIN

    Posted: 27 Nov 2021 05:00 AM PST

    I had a client almost miss their arin payment for their AS and IP space.

    What would happen if that actually happened? It seems itd be difficult to reclaim the space and get someone to stop advertising. I guess IRR objects would be pulled, but would that be effective enough?

    (this is strictly a theoretical and I don't suggest not paying)

    submitted by /u/antleo1
    [link] [comments]

    SFP to SFP compatibility question

    Posted: 27 Nov 2021 12:42 PM PST

    I have a question regarding SFP+ compatibility when it comes to connecting, for example, a server to a switch.

    I know certain brand/vendor switches and network adapters prefer certain SFP+ modules but I would like to know if this applies to when you connect two devices together?

    For example let's say I have a nexus 9k series switch with Cisco SFP+ modules
    and an HP server with HP SFP+ modules. Both are 850nm but will the server be able to connect to the switch? Theoretically it should work but I've come across situations where a server doesn't connect at all unless the switch and server have the exact same modules.

    submitted by /u/Hank_ID94220
    [link] [comments]

    Arizona - DIA Build Times

    Posted: 27 Nov 2021 05:41 AM PST

    Here in my state we always give a 90-120 build time for carriers to deliver new DIA circuits. Even in metro areas.

    What is reasonable to expect in Arizona? Cox is the carrier if that is of any importance.

    I will say that permitting was VERY fast(less than 2 weeks) in Georgia, and it still took Spectrum and their contractors 90 days to complete a 100 foot build. So permitting windows alone may not be the best indicator of expectations.

    submitted by /u/ccagan
    [link] [comments]

    Wifi Router with Physical Lock

    Posted: 27 Nov 2021 05:30 AM PST

    For work related reasons I'm looking for a portable pocket router which I can carry around from plant to plant.
    On the plant I want to connect to the networkswitch so I can have acces to all the different devices over the network with wifi. (Robots, Applications, ...).

    Because almost everyone has a key to this networkswitch I want to be able to physically lock it. So that it cannot be stolen.
    https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcToEu0B1HOaSgbCyYd6vjLgi_nRIZZG8962Dp2d8XQuv8oDh1_P92qf7kTwg8kiaJkbtpc&usqp=CAU

    Anyone can point me out in a good direction on where to find routers that have this or just the locks on its own?
    Thanks!

    submitted by /u/blind_bob
    [link] [comments]

    NSX LAB misunderstanding of some concepts PLEASE HELP

    Posted: 27 Nov 2021 11:18 AM PST

    TOPOLOGY : https://ibb.co/9bFcXK0

    Hello Guys, Please this NSX-T will make me crazy, I manage a lab topology based on my understanding in order to do it as real lab and exercise, after doing the lab topology I found that I still have some misunderstanding regarding some pieces, Can you please check my lab topology and questions bellow please.

    Please if you can help refer your answer to my topology just to make it clear to me. Also mention the question number, Thank you <3

    - Please ignore the management interfaces, it's not yet in the diagram.

    1 - In which Step the the NVDS virtual uplinks are mapped to the Physical NIC ? And how to do it ?

    2 – What's the relationship/deference between uplink profile and transport node profile ? And where we are using each of them ?

    3 – I know that the Edge node should be connected to all transport zones (Overlay + VLAN) the TZ-Overlay will create a N-VDS in the edge host, right ? But the Edge VM ports will be connected to which segment? App or WEB ?

    4 - How to map the Physical ports the Transport + Edge nodes(ESXi) to the NVDS created by NSX ? :(

    5 - The TZ-Overlay will transport traffic generated by Web-Segment and App-Segment on Vlan 110 (based on my topology) is that correct ? or every segment should be in deferent vlan (means I should create a TZ for each segment :O ? and add this vlans to the physical switch and make the port between the physical switch and esxi a trunk port ?)

    6 - the vlan tagging is done logically on the Transport zone level or Segment level ?

    7 - I heard about TEP, should use a vlan for it ? but I should create a separate TZ for the TEP traffics ? a vlan on physical link a dedicated physical port on the ESXi edge and Physical switch ? where this TEP as an interface or tunnel or traffic is sitting

    8 - My design is correct ? any suggestions ?

    I really appreciate and need your help to proceed with this LAB.

    submitted by /u/cciex6
    [link] [comments]

    Lumen’s IRR was insecure

    Posted: 26 Nov 2021 01:36 PM PST

    And maybe they knew it, but didn't fix it for years because "because many of its customers still relied on it due to legacy systems."

    I guess Krebs publishing a story — about a proof of concept that could have removed the ~23% of the IPv4 prefixes which Lumen announces to the global table by deleting all those prefixes from IRR and thus removing them from BGP filters automatically built from that IRR data — was motivation enough to finally disable MAIL-FROM "authentication"

    https://krebsonsecurity.com/2021/11/the-internet-is-held-together-with-spit-baling-wire/

    submitted by /u/youfrickinguy
    [link] [comments]

    EAP-TLS Fragmentation over IPSec VPN Tunnels

    Posted: 26 Nov 2021 09:01 AM PST

    You guys are my last resort here. This is my third day on this and I'm pulling my hair out trying to figure out what is going wrong and where.

    We have a Windows 2016 NPS server acting as a RADIUS server for wifi traffic. When this guy was local in the office, it worked beautifully. Client machines have a cert, they authenticate to wifi, all is right with the world.

    The problems started when we moved this server up into the cloud last week with an IPSec Site to Site VPN connection.

    EAP-TLS packets are not being registered by the NPS server. I can see them make it through the VPN tunnel, but they are never registered in NPS logs (yes, I have advanced logging turned on). If i switch this to PEAP, things work fine - just EAP-TLS due to cert size, I am guessing.

    In testing MTU Thresholds over the VPN tunnel with a do-not-fragment ping switch, the max MTU that gets me a reply is 1472. 1473 fails with a message that it needs to be fragmented.

    I have NPS with a custom MTU rule set to 1344 (also tried this at 1400, no go).

    The IPSec Tunnel has an MTU of 1400 set on it (This is Barracuda <-> Pfsense).

    APs are Unifi, switches are Meraki (This client is not brand-loyal)

    Here is the output from a packet capture on the AP's switch port.

    16:11:25.931050 IP (tos 0x0, ttl 64, id 39144, offset 0, flags [+], proto UDP (17), length 1500) 172.16.1.242.60808 > 10.2.34.10.1812: RADIUS, length: 1472 Access-Request (1), id: 0xb5, Authenticator: 6649788cadda9431fdef46d132dcd5f2 User-Name Attribute (1), length: 9, Value: CENSORED NAS-Identifier Attribute (32), length: 14, Value: c6fbe4c25386 Called-Station-Id Attribute (30), length: 23, Value: C6-FB-E4-C9-51-87:CORPORATE NAS-Port-Type Attribute (61), length: 6, Value: Wireless - IEEE 802.11 Service-Type Attribute (6), length: 6, Value: Framed Calling-Station-Id Attribute (31), length: 19, Value: 64-5D-86-46-6D-C8 Connect-Info Attribute (77), length: 23, Value: CONNECT 0Mbps 802.11b Acct-Session-Id Attribute (44), length: 18, Value: DC46B5523AE7683F Acct-Multi-Session-Id Attribute (50), length: 18, Value: 73D2557C01ED5ED7 Unknown Attribute (186), length: 6, Value: Unknown Attribute (187), length: 6, Value: Unknown Attribute (188), length: 6, Value: Framed-MTU Attribute (12), length: 6, Value: 1400 EAP-Message Attribute (79), length: 255, Value: [|radius] EAP-Message Attribute (79), length: 255, Value: [|radius] EAP-Message Attribute (79), length: 255, Value: [|radius] EAP-Message Attribute (79), length: 255, Value: [|radius] EAP-Message Attribute (79), length: 255, Value: [|radius] EAP-Message Attribute (79), length: 229 (bogus, goes past end of packet) 16:11:25.931091 IP (tos 0x0, ttl 64, id 39144, offset 1480, flags [none], proto UDP (17), length 288) 

    And from Wireshark opening the PCAP file -

    [2 IPv4 Fragments (1748 bytes): #23(1480), #24(268)] [Frame: 23, payload: 0-1479 (1480 bytes)] [Frame: 24, payload: 1480-1747 (268 bytes)] [Fragment count: 2] [Reassembled IPv4 length: 1748] [Reassembled IPv4 data: e9ea071406d46e99012c06ccf4bc3bbf4d09625bbf3f83ed5e236a270109616365746563…] 

    I need this first frame to be under 1472 bytes in size - I don't know where else I'd need to configure this MTU to get the packets fragmented correctly.

    submitted by /u/SysTerra80
    [link] [comments]

    Trying to learn more about networking SONET MPLS-TP

    Posted: 26 Nov 2021 11:45 AM PST

    So I'm a junior engineer and trying to learn more about networking, i really just know the basis, well my boss is on vacation till December, so I don't have much to do these days. So in my free time I'm trying to learn more, I was checking the new projects. The clients wants us to replicate one of their networks in a different location but this old one uses SONET/Sdh, but they want to start using MPLS-TP. I realized their old site has a MUX(Junglemux), would the new site need a mux. Are all router and switches compatible with Mpls-Tp is that sometime to consider.

    submitted by /u/jagarez
    [link] [comments]

    Adtran TA5000 refurbished equipment?

    Posted: 26 Nov 2021 06:17 PM PST

    I know that there are many companies that deal in used Cisco and Juniper equipment and have both bought and sold from them. We have quite a bit of Adtran TA5000 series gear and I'm looking for a source for used equipment as well as to offload some kit that we no longer need. Does anyone have recommendations beyond Ebay?

    submitted by /u/niceandsane
    [link] [comments]

    Looking for help. Need a service that allows guests to upgrade their internet speed/data allowance. (please let me know if this is the wrong place)

    Posted: 26 Nov 2021 03:02 PM PST

    Background

    I have charter boats that need a WiFi service. Guests spend weeks at a time at sea (in cellular range), and I need to provide them with a minimal service for free. The problem is I need to charge extra if they want to stream or do heavy interneting. So I would like for them to be able to log into a portal, and pay to upgrade.

    Hoping there is a cellular router and online service that will communicate with each other, to allow guests to pay, and upgrade the routers speed and/or daily data allotment.

    I am in the Caribbean.

    Routers need to be able to run on usb power

    LTE is the fastest speed available (no 5g)

    Please let me know if this is the wrong place for this question, im very new to this. Any help pointing me in the right direction is greatly appreciated.

    submitted by /u/MrMoth
    [link] [comments]

    Recomendation for SOHO Mesh Device, that actuallly use our network range, not own mesh ip range.

    Posted: 26 Nov 2021 10:33 AM PST

    Hi all.

    A lot of SOHO wireless device create its own ip range on the mesh wifi SSID.

    For example our offices have the range 192.168.1.0-254 and the mesh devices give to the clients 10.0.0.1-254 .

    We need that the wireless clients are on the same network.

    My investigation:
    Ubnt devices works fine. Use the same ip range that our network.
    Ruckus devices too, but are dseinged for big enterprise and are too expensive.

    Could you tell me other options/recomendations that works on the same way?Regards.

    submitted by /u/Txurrispo
    [link] [comments]

    Juniper QFX <-> Linux server BGP over GRE not working

    Posted: 26 Nov 2021 12:38 AM PST

    I have a QFX 5100 and a Linux server running Debian 11 (kernel 5.10.70). I set up a GRE tunnel with 192.168.0.0/31 as the subnet, the QFX is .0 and the server is .1.

    I can ping the other end from each side, so no connectivity issues. I can telnet and connect on TCP port 179 on each side, so no firewall issues that I can think of.

    However, when I try to BGP peer (the server is running GoBGP) them the sessions are stuck in OpenSent/OpenConfirm, eventually the hold timer expires and then the cycle repeats. I captured a pcap on the server and found a bunch of retransmits for keepalive packets sent by the server, so figured that it might be a MTU/MSS issue.

    Things I've tried that haven't seemed to fix it:
    - Clamped MSS on both sides to 1300 bytes, I've been able to get (at maximum) 1456 byte IP+ICMP packets with the DF bit set through with no issue
    - Lowered the MTU on both sides to 1400, did not help so reverted

    Configuration on QFX:

    interfaces { gr-0/0/0 { tunnel { source <snip>; destination <snip>; } family inet { address 192.168.78.0/31; } } } ... group HOME { accept-remote-nexthop; local-address 192.168.78.0; hold-time 300; mtu-discovery; import DEV-IN; export DEV-OUT; peer-as 64599; local-as <snip>; tcp-mss 1300; neighbor 192.168.78.1; } 

    Configuration on the Linux server:

    $ ip route | grep gre1 192.168.78.0/31 dev gre1 proto kernel scope link src 192.168.78.1 advmss 1300 $ cat /etc/gobgp/gobgpd.conf [global.config] as = 64599 router-id = "192.168.78.1" port = 179 [[neighbors]] [neighbors.config] neighbor-address = "192.168.78.0" peer-as = "<snip>" [neighbors.timers.config] hold-time = 300 

    Has anyone run into this before?

    Thanks!

    submitted by /u/az_6
    [link] [comments]

    How to Set the priority of traffic on a gateway having two gateways for upstream?

    Posted: 26 Nov 2021 01:22 AM PST

    I will have two upstream one is in Delhi (nearest to me) and another is in Mumbai. Will get 1 gig of bandwidth from Delhi if I found a solution and 3 gigs is ongoing from Mumbai (Two different ISPs). I currently have near 2000 users. What I want to do is set priority to Mumbai Bandwidth port so that if it gets near full usage then users will start getting speed from Delhi port. I don't want to move users to any single port. Is it possible to set a priority? Currently, I am using Mikrotik CHR as a router.

    submitted by /u/jtnrao7
    [link] [comments]

    No comments:

    Post a Comment

    Fashion

    Beauty

    Travel