r/networking 6h ago

Career Advice Network engineer journey to Cloud

14 Upvotes

Cloud engineers, wanted to get your experience... I'm a network engineer with 15 years of experience with all kinds of on-prem network technologies, from NX-OS, load balancers, proxies, VMware, ACI. I'm currently working with NSX and AVI LB for a major bank. But with the Broadcom aquisition, VMware/NSX doesn't seem so appealing anymore, VMware jobs are very rare. I feel that I'm a niche that will die eventually and it's time to make a change. I have experience with Terraform and CI/CD pipelines, did some automation with Python vibe coding.

There are a lot of Cloud-related jobs and I like public cloud, I like to learn new stuff in general. I started to learn AWS and Azure. I got the SAA-C03 AWS Solution Architect Associate certification and now I'm learning to get the AZ-700 Azure Networking speciality. I applied to Cloud Network Engineer jobs but got rejected, probably due to missing on-the-job experience. At my current job I can't get any Public Cloud exposure. I did put in my CV a project with Terraform standing up an AWS environment with ECS, load balancer, instances connecting over VPN to a VM in GCP.

How did you guys make it? It's the chicken and the egg... To get a job you need experience, but to get experience you need the job :)


r/networking 6h ago

Routing Total routes in your organization

14 Upvotes

Good morning all,

So how many routes do you folks have in your core router / core switch/ core firewall or whatever core device you use for routing.

Just curious.

We have like less than 300 so not that many so was just curious how many routes other folks who work in large enterprises have.

Thank you


r/networking 15h ago

Other Adding ISE PSN to my current deployment

10 Upvotes

Cert is installed, DNS record is done,patched it to the require version,
As far as I know, all that’s left is registering it from the PAN and it should sync automatically ?
Am I missing anything?


r/networking 3h ago

Troubleshooting Follow-Up to previous post: VPN Tunnel Up, but specific subnets aren't passing traffic

3 Upvotes

About a month ago, I posted about Cisco APs that weren't able to join a WLC. Since then, I narrowed down the issue and think the APs/WLC are not the root cause. This looks more to be an issue with a VPN communication between subnets.

The two sites connect through Cisco ASA firewalls over a site-to-site VPN. The tunnel establishes successfully, Phase 1 and Phase 2 complete without issue, and multiple subnets traverse the tunnel normally. But then there are specific subnets that can't communicate across the VPN despite being included in the crypto ACLs and NAT exemption rules on both sides.

What strange is the traffic for other VPN networks works fine. In the IPsec SA counters, I can see traffic being decapsulated from the remote side, but I see no encapsulated traffic in return for the affected subnet. One side appears to be receiving traffic while the opposite side never properly sends traffic back across the tunnel. The tunnel itself remains up and stable the entire time.

I've rebuilt the tunnels, verified the crypto ACLs match on both sides, reviewed NAT exemption rules, confirmed routing, checked access-lists, and used packet-tracer. The subnet appears to match the VPN config, but traffic isn't flowing bidirectionally. The APs are able to obtain DHCP addresses and function locally but can't communicate with the WLC because the VPN connectivity for their subnet isn't working.

Any suggestions would be greatly appreciated. I've been chasing this for a while and feel like I'm missing something obvious.


r/networking 5h ago

Troubleshooting Ruckus One Port Flapping issues

3 Upvotes

Hi everyone. I'm fairly new to networking, especially with Ruckus devices. I get a port flapping alarm on Ruckus One every time a device is plugged into the switch. Whenever the alarm triggers, I check the port logs, and they look like this:

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, state down

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, state down

I've already checked the cabling and port statistics. The cables appear fine, and there are 0 CRC errors. Anyone ever having this issue ?


r/networking 11h ago

Design Switch Recommendations/Worries

3 Upvotes

Hi All

We're looking to spin up a new DC as part of a large migration away from an MSP.
Initially we're installing a pair of 1G WAN links, which will head into a Forti of some flavour for security and routing.

I need some help with switching gear selection, some network context below:

  • As part of the migration we're bringing a hosted vCloud down on-prem with a Hyper-V cluster (3 nodes + SAN), so we're not only replicating the current setup which is all pretty much copper upto 10G but the new hypervisors will be 10/25G capable.
  • There are only around 15 other devices in the cabinet, most of which utilise 2 ports currently with 1G RJ45 and 8 of which are 10G, currently the LAN is all Meraki at this site but quite comfortable moving away.
  • I understand the discussion around not crossing SAN and LAN on the same gear but given the scale of the business, throughput (without hypervisor traffic) currently about 4Gbps peak we're erring on the side of a single stack of switches for the cabinet.
  • Vendors recommending things like Aruba CX8325's but this seems intensely overkill given it's capacity. They've also belied Catalyst for this use, and only recommended we use Nexus switches.
  • There's nothing uber complicated taking place in this network, a few VLANs at present and no unusual configs on the existing switches.
  • The hypervisor traffic at the moment, as far as we've analysed it in it's current form would not reach close to 10G.
  • We also have a pair of managed Aruba gig switches doing things like the WAN into the firewalls.

A few questions that I'd welcome feedback around, generally:

  • What sort of hardware realistically should we be looking at?
  • Are the vendors being greedy with these over-specced recommendations or am I being naive thinking enterprise grade switches would be perfectly fine?
  • I've been hugely tempted by FS switches, given their price compared to Juniper/HPE/Cisco, that said I've read mixed feedback
    • Given the simplicity of the network and our install not including them as a single point of failure, would this be an option?

r/networking 15h ago

Troubleshooting POS connectivity issue

2 Upvotes

I am experiencing an issue on my business network where my Stripe WisePOS E reader and my laptop are both connected to the same SSID. The reader successfully connects and receives an IP address but my laptop cannot communicate with it. The reader works as expected on other networks and hotspots with this same laptop and this setup used to work on our Meraki/telus network with no issues. Just randomly decided to not be able to find one another on the network. Telus says there is no issue on their end and it is an issue with the devices but again they work fine on any other network except the one I need them to work on. Any insights would be greatly appreciated. Thanks


r/networking 23h ago

Rant Wednesday!

3 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 9h ago

Design Small Proxmox + OPNsense lab network design for apprenticeship test

2 Upvotes

Hello!

I am an IT apprentice preparing for my practical test, and I am building a small virtual lab in Proxmox to demonstrate basic business/office network design.

Everything is virtualized in Proxmox, except the physical NICs passed through to OPNsense. Proxmox management is outside the lab network.

My goal is not to build a perfect enterprise network, but a clean and understandable lab that shows I understand VLANs, routing, DHCP, DNS, AD, and basic firewall separation, because i have about 1 day on the test to set up the network.

Current plan:

Proxmox:

- Proxmox management stays outside the lab

- OPNsense is the router/firewall

- Internal VM traffic goes through a virtual bridge

OPNsense:

- WAN: physical NIC

- LAN/trunk: internal Proxmox bridge

Planned networks:

Admin/LAN untagged:

Subnet: 10.0.10.0/24

Gateway: 10.0.10.1

Use: admin client and management access

Server VLAN 20:

Subnet: 10.0.20.0/24

Gateway: 10.0.20.1

Static servers:

- DC01: 10.0.20.10

- DC02: 10.0.20.11

- File/print server: 10.0.20.12

- Entra Connect/sync server: 10.0.20.13

Client VLAN 30:

Subnet: 10.0.30.0/24

Gateway: 10.0.30.1

DHCP: 10.0.30.100-254

Use: domain-joined office clients

  1. Any practical tips for making this easier to document and explain?
  2. Is this VLAN/IP plan reasonable for a small lab that simulates a basic office network?
  3. Would you keep DHCP in OPNsense for this type of lab, or move DHCP to Windows Server?
  4. Any other network tips and tricks in general or for the use off OPNsense if you are familliar?

Thanks in advance for taking the time to read this, i appreciate any form for help. :D


r/networking 5h ago

Other Anyone familiar with Alkira as a SaaS IPSEC solution

1 Upvotes

We are considering on moving our whole IPSEC infrastructure to a cloud agnostic provider. Alkira was suggested, but I never heard of them. Has anyone encountered them on the field?

https://www.alkira.com/


r/networking 11h ago

Design ISP MPLS/L3VPN

3 Upvotes

I am ISP the network is very basic OSPF with one area most of my customers served an internet only, The bad thing is everything reach everything and this is so bad making ACL to each customer that's so old my network already mpls active with ldp protocol for L2 VPN (used it for customers needs transmission service )

I need to change it to be MPLS l3vpn

so all my customers (Public IPs) are just reach internet not my privet IPs (Backbone) not other customers B2B ips

I mad a LAB I stacked at how can I do a vrf for customer one by one to reach internet without cutting of the internet for others ???

the interface that face UpperISP needs to be in the vrf and that impossible for production environment

Any Advice ?

#ISP
#MPLS-L3VPN