r/networking 5d ago

Blogpost Friday Blog/Project Post Friday!

14 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 21h ago

Rant Wednesday!

3 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 4h ago

Career Advice Network engineer journey to Cloud

16 Upvotes

Cloud engineers, wanted to get your experience... I'm a network engineer with 15 years of experience with all kinds of on-prem network technologies, from NX-OS, load balancers, proxies, VMware, ACI. I'm currently working with NSX and AVI LB for a major bank. But with the Broadcom aquisition, VMware/NSX doesn't seem so appealing anymore, VMware jobs are very rare. I feel that I'm a niche that will die eventually and it's time to make a change. I have experience with Terraform and CI/CD pipelines, did some automation with Python vibe coding.

There are a lot of Cloud-related jobs and I like public cloud, I like to learn new stuff in general. I started to learn AWS and Azure. I got the SAA-C03 AWS Solution Architect Associate certification and now I'm learning to get the AZ-700 Azure Networking speciality. I applied to Cloud Network Engineer jobs but got rejected, probably due to missing on-the-job experience. At my current job I can't get any Public Cloud exposure. I did put in my CV a project with Terraform standing up an AWS environment with ECS, load balancer, instances connecting over VPN to a VM in GCP.

How did you guys make it? It's the chicken and the egg... To get a job you need experience, but to get experience you need the job :)


r/networking 4h ago

Routing Total routes in your organization

7 Upvotes

Good morning all,

So how many routes do you folks have in your core router / core switch/ core firewall or whatever core device you use for routing.

Just curious.

We have like less than 300 so not that many so was just curious how many routes other folks who work in large enterprises have.

Thank you


r/networking 1h ago

Troubleshooting Follow-Up to previous post: VPN Tunnel Up, but specific subnets aren't passing traffic

Upvotes

About a month ago, I posted about Cisco APs that weren't able to join a WLC. Since then, I narrowed down the issue and think the APs/WLC are not the root cause. This looks more to be an issue with a VPN communication between subnets.

The two sites connect through Cisco ASA firewalls over a site-to-site VPN. The tunnel establishes successfully, Phase 1 and Phase 2 complete without issue, and multiple subnets traverse the tunnel normally. But then there are specific subnets that can't communicate across the VPN despite being included in the crypto ACLs and NAT exemption rules on both sides.

What strange is the traffic for other VPN networks works fine. In the IPsec SA counters, I can see traffic being decapsulated from the remote side, but I see no encapsulated traffic in return for the affected subnet. One side appears to be receiving traffic while the opposite side never properly sends traffic back across the tunnel. The tunnel itself remains up and stable the entire time.

I've rebuilt the tunnels, verified the crypto ACLs match on both sides, reviewed NAT exemption rules, confirmed routing, checked access-lists, and used packet-tracer. The subnet appears to match the VPN config, but traffic isn't flowing bidirectionally. The APs are able to obtain DHCP addresses and function locally but can't communicate with the WLC because the VPN connectivity for their subnet isn't working.

Any suggestions would be greatly appreciated. I've been chasing this for a while and feel like I'm missing something obvious.


r/networking 4h ago

Troubleshooting Ruckus One Port Flapping issues

2 Upvotes

Hi everyone. I'm fairly new to networking, especially with Ruckus devices. I get a port flapping alarm on Ruckus One every time a device is plugged into the switch. Whenever the alarm triggers, I check the port logs, and they look like this:

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, state down

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, state down

I've already checked the cabling and port statistics. The cables appear fine, and there are 0 CRC errors. Anyone ever having this issue ?


r/networking 13h ago

Other Adding ISE PSN to my current deployment

9 Upvotes

Cert is installed, DNS record is done,patched it to the require version,
As far as I know, all that’s left is registering it from the PAN and it should sync automatically ?
Am I missing anything?


r/networking 9h ago

Design Switch Recommendations/Worries

3 Upvotes

Hi All

We're looking to spin up a new DC as part of a large migration away from an MSP.
Initially we're installing a pair of 1G WAN links, which will head into a Forti of some flavour for security and routing.

I need some help with switching gear selection, some network context below:

  • As part of the migration we're bringing a hosted vCloud down on-prem with a Hyper-V cluster (3 nodes + SAN), so we're not only replicating the current setup which is all pretty much copper upto 10G but the new hypervisors will be 10/25G capable.
  • There are only around 15 other devices in the cabinet, most of which utilise 2 ports currently with 1G RJ45 and 8 of which are 10G, currently the LAN is all Meraki at this site but quite comfortable moving away.
  • I understand the discussion around not crossing SAN and LAN on the same gear but given the scale of the business, throughput (without hypervisor traffic) currently about 4Gbps peak we're erring on the side of a single stack of switches for the cabinet.
  • Vendors recommending things like Aruba CX8325's but this seems intensely overkill given it's capacity. They've also belied Catalyst for this use, and only recommended we use Nexus switches.
  • There's nothing uber complicated taking place in this network, a few VLANs at present and no unusual configs on the existing switches.
  • The hypervisor traffic at the moment, as far as we've analysed it in it's current form would not reach close to 10G.
  • We also have a pair of managed Aruba gig switches doing things like the WAN into the firewalls.

A few questions that I'd welcome feedback around, generally:

  • What sort of hardware realistically should we be looking at?
  • Are the vendors being greedy with these over-specced recommendations or am I being naive thinking enterprise grade switches would be perfectly fine?
  • I've been hugely tempted by FS switches, given their price compared to Juniper/HPE/Cisco, that said I've read mixed feedback
    • Given the simplicity of the network and our install not including them as a single point of failure, would this be an option?

r/networking 4h ago

Other Anyone familiar with Alkira as a SaaS IPSEC solution

1 Upvotes

We are considering on moving our whole IPSEC infrastructure to a cloud agnostic provider. Alkira was suggested, but I never heard of them. Has anyone encountered them on the field?

https://www.alkira.com/


r/networking 8h ago

Design Small Proxmox + OPNsense lab network design for apprenticeship test

2 Upvotes

Hello!

I am an IT apprentice preparing for my practical test, and I am building a small virtual lab in Proxmox to demonstrate basic business/office network design.

Everything is virtualized in Proxmox, except the physical NICs passed through to OPNsense. Proxmox management is outside the lab network.

My goal is not to build a perfect enterprise network, but a clean and understandable lab that shows I understand VLANs, routing, DHCP, DNS, AD, and basic firewall separation, because i have about 1 day on the test to set up the network.

Current plan:

Proxmox:

- Proxmox management stays outside the lab

- OPNsense is the router/firewall

- Internal VM traffic goes through a virtual bridge

OPNsense:

- WAN: physical NIC

- LAN/trunk: internal Proxmox bridge

Planned networks:

Admin/LAN untagged:

Subnet: 10.0.10.0/24

Gateway: 10.0.10.1

Use: admin client and management access

Server VLAN 20:

Subnet: 10.0.20.0/24

Gateway: 10.0.20.1

Static servers:

- DC01: 10.0.20.10

- DC02: 10.0.20.11

- File/print server: 10.0.20.12

- Entra Connect/sync server: 10.0.20.13

Client VLAN 30:

Subnet: 10.0.30.0/24

Gateway: 10.0.30.1

DHCP: 10.0.30.100-254

Use: domain-joined office clients

  1. Any practical tips for making this easier to document and explain?
  2. Is this VLAN/IP plan reasonable for a small lab that simulates a basic office network?
  3. Would you keep DHCP in OPNsense for this type of lab, or move DHCP to Windows Server?
  4. Any other network tips and tricks in general or for the use off OPNsense if you are familliar?

Thanks in advance for taking the time to read this, i appreciate any form for help. :D


r/networking 9h ago

Design ISP MPLS/L3VPN

1 Upvotes

I am ISP the network is very basic OSPF with one area most of my customers served an internet only, The bad thing is everything reach everything and this is so bad making ACL to each customer that's so old my network already mpls active with ldp protocol for L2 VPN (used it for customers needs transmission service )

I need to change it to be MPLS l3vpn

so all my customers (Public IPs) are just reach internet not my privet IPs (Backbone) not other customers B2B ips

I mad a LAB I stacked at how can I do a vrf for customer one by one to reach internet without cutting of the internet for others ???

the interface that face UpperISP needs to be in the vrf and that impossible for production environment

Any Advice ?

#ISP
#MPLS-L3VPN


r/networking 1d ago

Wireless How do you guys deal with rogue aps from end users?

44 Upvotes

So, large organization, thousands of users and several departments, Im constantly discovering that users are bringing routers to the work because they dont seem to think the current wifi policy access fits their daily routine, or they simply dont know how to request access to something, Im out sourced here so I dont have all the details.

How do you guys deal with the end users in terms of what is allowed and what is not?

Now we need to talk with the c-suite people about this situation. My thinking is that bringing an outside wireless equipment should be prohibited, I know theres avoidance mechanism for this kind of situation but having the ap changing channels in the middle of the day is also disruptive, spamming deauthentication frames also is going piss off someone.

Edit: to clarify something, those rogues are not connected to the infrastructure, they are simply there using a broadband connection that god knows why this customer thought it was a good idea to have solely for this little router, too close to their corporate aps and sometimes overlapping channels.


r/networking 13h ago

Troubleshooting POS connectivity issue

3 Upvotes

I am experiencing an issue on my business network where my Stripe WisePOS E reader and my laptop are both connected to the same SSID. The reader successfully connects and receives an IP address but my laptop cannot communicate with it. The reader works as expected on other networks and hotspots with this same laptop and this setup used to work on our Meraki/telus network with no issues. Just randomly decided to not be able to find one another on the network. Telus says there is no issue on their end and it is an issue with the devices but again they work fine on any other network except the one I need them to work on. Any insights would be greatly appreciated. Thanks


r/networking 1d ago

Other Anyone using Zscaler SDWAN

8 Upvotes

We are evaluating vendors for SDWAN replacement, currently on Velocloud. We did a POC on Cisco and Aruba SDWAN and they are a good product with some complexities.

I just did a quick lab for Zscaler Zero Trust SDWAN and I liked it. It's as simple as Velo. We currently use ZIA and ZPA, this looks like a perfect match. Anyone using them? What is your experience like?

Edit:

I am not looking for var's to help me with the solution. I am only looking to hear people's experience with zscaler sdwan.


r/networking 23h ago

Other Anyone paying for a dedicated technical success or advanced services offering?

3 Upvotes

We’re coming up on a renewal and using it as an opportunity to see what else is available before we sign again.

I’m looking at paid technical services that go beyond standard Support but aren’t quite a full consulting engagement. I’ve seen them called Technical Account Management, Advanced Services, Resident Engineering, or dedicated technical advisory services.

For anyone using something similar:

  • Which vendor and service are you using?
  • What do you actually get day to day?
  • Is the resource dedicated or shared?
  • How is it priced?
  • How is it different from regular Support?
  • Has it been worth the cost?
  • What has been the biggest benefit?
  • Anything you wish you had known before signing?

Named vendors, service names, and even broad pricing ranges would be really helpful. We’re mainly trying to understand what other options are out there before making a renewal decision.


r/networking 1d ago

Other Cato: Contract Renewals. Your experience?

4 Upvotes

Hi.

We are due to receive our renewal quote after our first year with Cato and the reseller has suggested a multi-year lock in as "Cato have YoY 20% subs increase". I expect prices to rise, but 20%/year seems high.

What are your experiences?


r/networking 1d ago

Design [Question] 169.254.0.0/16 In Routing Space

45 Upvotes

During my studies for CCNP, while learning the configuration of VPNs I came across use of 169.254.0.0 that I was not aware of. I know the range for APIPA, but the examples I saw used them for the point to point connection of the VPN. Looking into this further I found that this is somewhat common practice to use for VPNs, BGP, and cloud to on premises connections.

Discussions I found mentioned that occasionally people would use this space for point to point links on premises. Reading through the posts I was directed to RFC5735 which mentions the subnet as a communication between hosts on a single link. I read this as two connections on one link, or a point to point connection. This lines up with the uses I mentioned above.

   169.254.0.0/16 - This is the "link local" block.  As described in
   [RFC3927], it is allocated for communication between hosts on a
   single link.  Hosts obtain these addresses by auto-configuration,
   such as when a DHCP server cannot be found.

During my CCNP studies I have found that /31 subnet for routed point to point links is ideal. I learned this through some more discussions and from RFC3021.This was new to me as during my CCNA studies and even in the environments I work in currently they use /30 subnets for point to points. A /31 subnet would only allow two hosts on a single link, a point to point connection once again.

This leads to my question. If 169.254.0.0/16 is typically used outside of APIPA for point to point links would it not be possible to use it for a routing underlay in a network? From my limited knowledge in medium sized networks this feels like a good solution for routed connections within the distribution and core networks as most of them are essentially point to points that propagate through a dynamic routing table. It allows a divide between what is a known private network and routed network along with saving IP space.

Is this something that sounds good in theory but the practicality of it has flaws? I don't discussion for it's use in this context so perhaps there is something I missing. If it is something obvious please let me know.

EDIT: The responses to this post have been some great discussions and given me clarification both to my original question and to a better solution. I am going to look into IPv4 routes with IPv6 next hops as that seems to be the overall answer to the question I posed. I appreciate the deeply informative responses.


r/networking 1d ago

Switching service tag (mikrotik) and qfx problem

6 Upvotes

Hello everyone, I hope I am not violating any rules.

I am facing a rather unusual situation (please note that this is a lab environment).

The topology consists of three devices:

  • MikroTik CCR2004
  • Juniper QFX5110
  • Juniper MX204

The original configuration was working correctly with the following setup:

MikroTik CCR2004

/interface vlan
add interface=sfp-sfpplus2 name=vlan2000 vlan-id=2000
add interface=vlan2000 name=vlan10 vlan-id=10

/ip address
add address=10.10.10.1/24 comment="Test QFX" interface=vlan10 network=10.10.10.0

Juniper QFX5110

set interfaces xe-0/0/1 description "LINK TO CE-2 MX204"
set interfaces xe-0/0/1 flexible-vlan-tagging
set interfaces xe-0/0/1 encapsulation extended-vlan-bridge

set interfaces xe-0/0/1 unit 2000 description "Q-IN-Q TRANSPORT CE-2"
set interfaces xe-0/0/1 unit 2000 vlan-id-list 10
set interfaces xe-0/0/1 unit 2000 input-vlan-map push
set interfaces xe-0/0/1 unit 2000 output-vlan-map pop

set interfaces xe-0/0/2 description "LINK TO CE-1 MIKROTIK"
set interfaces xe-0/0/2 flexible-vlan-tagging
set interfaces xe-0/0/2 encapsulation extended-vlan-bridge

set interfaces xe-0/0/2 unit 2000 description "Q-IN-Q TRANSPORT CE-1"
set interfaces xe-0/0/2 unit 2000 vlan-id 2000

set vlans V2000 description "PROVIDER VLAN 2000"
set vlans V2000 interface xe-0/0/2.2000
set vlans V2000 interface xe-0/0/1.2000

Juniper MX204

set interfaces xe-0/1/1 description "LINK TO PE-1 QFX"
set interfaces xe-0/1/1 vlan-tagging

set interfaces xe-0/1/1 unit 10 description "L3 VLAN 10"
set interfaces xe-0/1/1 unit 10 vlan-id 10
set interfaces xe-0/1/1 unit 10 family inet address 10.10.10.2/24

With this configuration, the MikroTik and MX204 were able to communicate correctly.

However, the customer connected to the MikroTik side had to enable the use-service-tag option.

The MikroTik configuration was therefore changed to:

/interface vlan
add interface=sfp-sfpplus2 name=vlan2000 vlan-id=2000
add interface=vlan2000 name=vlan10 use-service-tag=yes vlan-id=10

/ip address
add address=10.10.10.1/24 comment="Test QFX" interface=vlan10 network=10.10.10.0

After this change, the MX204 and MikroTik are no longer able to communicate.

The QFX configuration has remained unchanged.

My question is:

How can I modify only the Juniper QFX5110 configuration to make the MikroTik and MX204 communicate again?

I suspect the issue is related to the different VLAN tagging behavior introduced by use-service-tag=yes on the MikroTik side (802.1Q vs 802.1ad/service tag handling), but I am unsure how to adapt the QFX QinQ configuration correctly.

Any advice or example configuration would be appreciated.

Thank you.


r/networking 2d ago

Switching Other Vendors with something similar to Cumulus LACP-Bypass?

19 Upvotes

I'm not to hardcore in networking, mostly worked with cumulus Linux. They have this great feature of LACP-Bypass (https://docs.nvidia.com/networking-ethernet-software/cumulus-linux-517/Layer-2/LACP-Bypass/) . You can configure LACP on the Switch side, but if the server just tries to send packets without the LACP-Frames, the switch just treats it as a regular Port for the time being with all the VLANs hat are configured for the LACP port. When the Device actually wants to do LCAP, it switches modes automatically.

This is amazing for PXE-booting, live images and various other things.

Does no other vendor have this, or something similar?


r/networking 1d ago

Security Wireless endpoint lockdown

0 Upvotes

Greetings Jedi counsel,

I need some advice.

Here is the setup

Firewall:

FGT40F

IP reservation on MAC address

Groups with devices, assigned to policy granting internet access

Network:

Unifi controller running as service on local pc(not my choice)

Unifi USW Pro 48 Port Poe switch

Unifi AP's

Wireless password for guests and corporate lan( has vlan)

Devices:

Entra Joined computers

BYOD android/iphone - unmanaged

No Intune enrollment on the devices

Identities:

Entra ID

Currently we are "locking down" the network based on ip reservation through mac. This is becoming cumbersome with devices using random mac, especially the phones. There are a ton of phones that needs internet connection.

We need to proper protect the network by not allowing unsolicited devices access or atleast put them in a zone not allowing them access to anything if they so happen to be able to connect wireless or wired.

I have tried FortiNAC in another environment and we had a ton of issues.

More or less 150 devices.

I am curious to see what you guys recommend.


r/networking 2d ago

Troubleshooting Cisco9300 stack lacp uplink flapping when 1 bad device is connected.

17 Upvotes

2 New switch stack of cisco 9300 switches with fiber uplink on each in active/active config. The uplinks were flapping constantly when 1 specific pc was connected. The pc was frozen and is no longer connected. On the older switch there was no problem on the 9300 as soon as the device was connected the uplinks started to drop. For my own sanity how can single windows device on an access port with broadcast and bpdu guard on cause issues with the uplink port?


r/networking 2d ago

Career Advice Best way to consistently find travel deployment contracts W2?

9 Upvotes

Hey everyone. Working on a nationwide contract with Teksystems for a client now. Rack and stack, switch installs, isr to mx cutovers, server decommissioning/installs. My contract ends in about 3 months.

I'm 32 and have been in corporate for roughly a decade. This is my first contract in this context, however. Have certs (CCNA Routing & Switching, CCNA Security, A+) and am looking for my next contract. Trying to expand in this deployment niche as I'm NOT open to go back to an office based or hybrid/remote role at this time.

I'm looking for a W-2 role through an agency/company. Travel based (nationwide preferable) multi-site variety, home most if not all weekends, overnight/deployment structure preferred. I prefer shorter 4–7-month contracts. Would rather switch clients sooner than sit in a bad fit for a year plus.

Posting because I'm running into issues finding any hits at all on this specific niche and wanted some guidance. I've looked on LinkedIn, Dice, Indeed and have not found a single role similar to what I'm doing now. I understand these roles are more recruiter/relationship based. I found out about this role via an email from a recruiter I'd worked with over the years. I've reached out to all of my recruiters across my different agency's I've worked with throughout the last decade, and nothing is available... I'm trying to avoid a lengthy gap of no work between contracts.

Can anyone with experience in this specific niche give me some pointers on how to actually find this type of work? Open to advice, DM's from anyone doing similar work etc... What has worked for you specifically?

Thanks in advance.


r/networking 2d ago

Moronic Monday Moronic Monday!

11 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking 2d ago

Design Questions on setting up networking for a 8500 sqft, 20 people office/lab space. I'm planning either FortiGate + UniFi + MSP vs Meter, need help!

2 Upvotes

Hi all,

I've been put on the task to help out the small company I'm at for setting up their networking for the new office (I do not have networking experience, trying to get it done scrappy).

  1. 8500 sqft, mix of office and lab
  2. ~20 users
  3. I think I've scoped out to use a FortiGate 70G firewall with UniFi switches and APs.
  4. We will need to write multi-TB/day to a local NAS via 10G locally, then NAS to our AWS S3 at 1G (our circuit ISP supports 1G).
  5. No SSL VPN (Tailscale), no VoIP.

I'm posting this to get some answers from people who have experience in this field, would appreciate it a lot!

The 2 options I think I've scoped down to is:

  1. FortiGate 70G + UniFi LAN, which is ~$4.5-5k once, plus a local MSP for setup/maintainence.
  2. Meter: they build and manage it, own the hardware, one bill, ~$1k/mo stack + circuit, 3 yr term.

I believe cost is roughly the same after I need to pay an MSP to run option 1.

I ideally won't want to self-manage, so it's really a comparison of people's experiences with Meter vs MSP and how much involvement I would need to do if I run my own setup.

Thanks!


r/networking 3d ago

Design Send Netflow over IPSec using same IP

8 Upvotes

Could anyone tell me if IOS-XE would complain if I configure Netflow to source it's feed from the same IP as my IPSec tunnel source (but different VRF).

What I mean is:

  • Netflow coming from Lo10 in vf-netflow
  • IPSec sourced from g0/0/0 in vf-internet
  • Both have same IP address, different VRFs

I'm expecting Netflow to be a one-way outbound UDP flow anyway, but IPsec would of course involve packets in both directions.

inter g0/0/0
  vrf forwarding vf-internet
  ip address *100.0.0.1* 255.255.255.252
inter Tun10
  vrf forwarding vf-netflow
  tunnel vrf vf-internet
  ip address 10.0.0.0 255.255.255.254
  tunnel source gi0/0/0
  tunnel destination 200.0.0.1
  tunnel mode ipsec ipv4
interface Lo10
  vrf vf-netflow
  ip address *100.0.0.1* 255.255.255.255
flow exporter NETFLOW
  source Lo10
  destination 200.0.0.10 vrf vf-netflow
ip route vf-netflow 200.0.0.10/32 Tu10 10.0.0.1 ! Imaginary next hop IP