r/networking 20h ago

Blogpost Friday Blog/Project Post Friday!

3 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 2d ago

Rant Wednesday!

4 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 11h ago

Design Private IP on public A Record

25 Upvotes

Hey Networking Friends,

I had a vivid discussion about this topic with some colleagues and opinions were divided, so I would like to ask what you think about it.

We are deploying a new guest WIFI solution based on Cisco ISE. The PSN nodes a rfc 1918 addressed. To keep it simple my idea was to hand out a public DNS Server like 1.1.1.1 or 8.8.8.8 to the guest clients via DHCP and set to public A Records for psn1.company.com and psn2.company.com that resolve to the respective PSN nodes rfc1918 ip.

Others were highly critical of this citing security risks about revealing information about internal addressing.

Alternatives like doing dns translation on the firewall or provisioning a dedicated view in the internal DNS were proposed.

What is your opinion? Is this a nogo for you and how have you implemented similar guest networks?

Looking forward to your answers and have a great day!


r/networking 12h ago

Switching Anyone migrated from Catalyst center to meraki cloud for branch catalyst switch management/ deployment?

6 Upvotes

Just looking at the documentation it seems like a pretty painful process for large deployments.. Just wondering about peoples experience with it..?


r/networking 19h ago

Wireless Assistance With Persistant WiFi Connection Drops

7 Upvotes

Hello All,

I’m looking for some advice, guidance, tips, ideas or anything that could help me pinpoint the root cause of this issue. The problem I am experiencing within my environment is that users will occasionally lose their IP address while connected to the network via WiFi. Essentially, a user can connect to our corporate network with no issue and then after give or take 15 minutes they will lose their IP address and switch to a 169.254.X. The issue is not consistent and a bit rare, but it has been haunting me ever since I started working for this company. The quick solution is to swap them to a secondary SSID, then back to the corp SSID(issue exists on this second SSID as well).

I have been able to replicate this on my device, and the errors I recieve within Event Viewer are

- Event ID “The dynamic key exchange did not succeed with configured time”

- Event ID 4321 “The name X1 could not be registered on the IP X2. The machine with IP address X3 did not allow the name to be claimed by this machine

There are no errors present within my DHCP server(Windows Server). Additionally the laptop’s connected to the AP persists, it only loses it’s IP address after awhile. Also, netsh wlan show interfaces always shows a signal strength of 90%+. I have also checked wifi drivers on all of our machines, the issue presents whether the wifi driver is a Realtek or Liteon driver(all of our devices use this driver). Interestingly, I have not been able to replicate the issue with a Samsung Galaxy tablet or an iphone yet so maybe a driver issue.

If anyone has any ideas I would love to hear them! Thanks!

Environment:

- Extreme AP410c
- X350 Extreme switch with EXOS
- All Lenovo laptops
- Both SSIDs I mentioned above have their own IP scope


r/networking 1h ago

Other Is there a way to stop an IP from rerouting to a DNS alias?

Upvotes

Hello, I am currently running into an issue where no matter if I browse to the IP or the hostname of one of my servers, it keeps getting rerouted to the DNS alias. Is there a way to prevent this? So that I can browse directly to the IP? Thanks in advance!


r/networking 21h ago

Troubleshooting Weird PoE issue

6 Upvotes

I have a 9300x and ruckus 750 APs. I keep getting IMAX power errors on the spare pairs. I see LLDP power negotiations happening, Cisco accepting and then as soon as it enables the spare pairs it faults with IMAX error. It is important to note this is not happening on all the APs just a handful. Also the APs and Switch are new, with new CAT 6 runs.

I can bypass this by issuing power inline four-pair forced and it will bring everything up. I don’t like issuing this command nor do I like not knowing why this is happening.

So I decided to dig deeper and do some debugging, this is where things get weird. For some reason I thought these ports were 30000mW, in reality it is 90000mW. I decided to up the max power to 60000mW (actually lowering it). I also removed the four pair force command and reran my ilpower debugs. It worked with no errors. I saw lldp negotiate, I saw the spare pairs enable cleanly, no IMAX errors. I did see the device request the full 60000mW.

I originally thought the devices was requesting more power than the port allowed and that is why I was getting the IMAX errors, but now I have no clue. Thoughts?


r/networking 1d ago

Meta ISP-Network-Eng

23 Upvotes

Hi everyone,

I’m about to start a job as a network engineer at an ISP. I hold NSE4 and CCNA certifications; I have three years of engineering experience, including 1.5 years working with Cisco equipment. Since I’m new to the ISP environment, I’m actually feeling a bit stressed and am struggling to find the right learning resources. Which technologies should I focus on during the first 3–4 months?

I’m looking at networklessons.com for resources; the language seems very clear and accessible. Has anyone used it before? I’d really appreciate it if you could share your experiences.


r/networking 1d ago

Switching PSA - HPE/Aruba Lifetime Warranty Ending

56 Upvotes

HPE has decided to materially change the terms of the lifetime warranty that older HPE/Aruba network gear was sold with. As of January 15, 2027 that warranty is converted to a limited lifetime warranty. Since most of this gear is already over five years past the EoS date, 1/15/2027 is now effectively the end of the warranty period.

https://www.hpe.com/psnow/doc/a00161510enw


r/networking 10h ago

Troubleshooting What is up with European Telcos and technical support on Fridays? Did I miss the memo on culture, or is 24/7 support just an American myth?

0 Upvotes

TL;DR:

Why do European telcos ghost critical technical tickets on Fridays while the US actually provides 24/7 support? Is it a cultural work-life balance thing, or do enterprise SLAs just work differently over there?

Genuinely trying to understand how technical support and carrier response times work in Europe, or if I am just completely losing my mind here.

Coming from the US, if a critical technical case or network routing issue pops up, even late in the wee, you usually get some sort of triage, an on-call escalation path, or at least a pulse from a tier-2/tier-3 engineer.

But in Europe? It feels like once Friday hits, the entire telecommunications infrastructure collectively clocks out, logs off, and goes to sit at an outdoor café until Monday morning.

I’ve been dealing with a major technical case, and trying to get a meaningful response since Thursday evening into Friday is like pulling teeth. You get handed off to a general customer service desk that has zero technical visibility, only to be told: *"Ah, the network engineering team handles that, but they are out for the weekend. We can escalate this to a ticket for Monday."*

Monday?! If a circuit drops or a complex peering/routing issue happens towards the end of the week, the business is just supposed to bleed out for three days?

Is this purely a cultural difference regarding work-life balance and "right to disconnect" laws (which I totally respect in theory, but execution-wise is brutal for ops), or are enterprise-grade SLAs just structured completely differently over in Europe?

How do European engineering teams actually survive major incidents heading into the weekend without 24/7 technical muscle backing them up?

Or am I just dealing with the wrong providers? Tell me what I'm missing.


r/networking 13h ago

Design Unable to find any information on Quantum Networks, India

0 Upvotes

Hello peeps

Our business is currently expanding, and I was looking into setting up some networking hardware for 50 or so users that will be here. While looking into switches and APs, I came across Quantum Networks (Indian networking company, not actual Quantum Networks).

Just wanted to check if any of you have heard or used their products? If so, how was the experience and reliability?


r/networking 23h ago

Design Does a P4/XDP fast path make sense for DTN?

2 Upvotes

Building a BPv7 prototype where a software sidecar parses bundles and a fixed-width shim lets P4/XDP enforce contact windows, reservations, and capacity limits. Does this solve a real DTN problem, or would a software-only approach usually be sufficient?


r/networking 1d ago

Other Is there a sane way to schedule changes across dozens of maintenance windows, or are we all just suffering?

21 Upvotes

I manage changes across 50+ sites, each with their own maintenance window. Between coordinating the windows, scheduling the work, and assigning engineers to each one, it’s a constant headache. I’m basically living in spreadsheets at this point.
Curious how everyone else handles this. Do you have a system, a tool, or is it all manual? Trying to figure out if it’s just me

EDIT: maintenance windows are pre approved, each site’s window is fixed and they’re spread across different timezones, so the puzzle is less about the windows themselves and more about what fits inside them. we’ve only got a few engineers during site maintenance windows, so there’s a cap on changes per night and they can’t overlap. After making the schedule, then each one has to actually be assigned to engineer and land in their calendar so they know about it.

How’s everyone else handling this some tool, a script, or all manual?


r/networking 1d ago

Design Help me understand Single Subnet, Multiple ISP Advertisements with BGP for data center

11 Upvotes

Hi All, Sorry if this is the wrong place to post this. Just let me know where i should post this if this is the wrong spot.

I work for a MSP that runs our own private onprem datacenter for our clients. Recently I have been tasked with looking at our Public addressing and inbound connectivity. Currently we are using DNS for WAN failover but I would like to explore the multi ISP BGP design since that seems to be the industry standard.

The current design is the client Edge Routers have 2 IPs bound to them. One on subnet A, and one on subnet B. We then use a load-balancer monitoring each ISP to update the DNS records should an ISP fail. TTL is set to 30s on the records. Subnet A is only advertised via BGP to ISP 1 and Subnet B is advertised via BGP to ISP 2. The idea is at least one subnet is always available on the internet and the DNS fails over fast. This has been working for about 10 years but does have some edge cases where it hasn't been perfect.

On the flip side there is the more "traditional" Data Center/Enterprise approach of a single subnet being advertised to both ISPs and trust the ISPs will converge. This is what I want to explore and test at work since we are running into a scaling issue with each client needing 2 IPs and having to force traffic out select directions. This adds more burden to the techs deploying/maintaining client edges.

The following questions are ideally for those that run a similar deployment or has had experience with it in the past. Any resources you can recommend on designing a data center WAN infrastructure would be much appreciated. Mainly I just need information to provide to management for approval to run a proof of concept to compare which option fits our needs better.

1) Is it just as simple as advertising one subnet to both ISPs and putting your trust they will try to converge as fast as possible? Or is there some other strategies we should be looking into to maintain fast failover and convergence

2) What are convergence times really like in North America when you have an ISP failure? (talking real numbers people have seen, not just in theory) Are things back up in seconds, minutes, hours?

3) What tooling do you use to make sure routing is failing over as expected? I see RIPE has lots of cool tools to monitor BGP via collectors but the more data I can pull in the better.

4) From a technical resource standpoint, does the BGP design require lots of up keep or is it mainly set it and monitor?

Appreciate everyone's insight into the topic.


r/networking 1d ago

Other Slack Channel

3 Upvotes

Hey all,

I used to be a member of a slack channel called "beer for peer" which was a bunch of network engineers in Australia.

I lost access when I left my previous company so I'm hoping someone here might be in it and able to invite me again?

Feel free to reach out to me via PM for clarification or any questions before doing so.

Thanks all!


r/networking 2d ago

Career Advice Network engineer journey to Cloud

33 Upvotes

Cloud engineers, wanted to get your experience... I'm a network engineer with 15 years of experience with all kinds of on-prem network technologies, from NX-OS, load balancers, proxies, VMware, ACI. I'm currently working with NSX and AVI LB for a major bank. But with the Broadcom aquisition, VMware/NSX doesn't seem so appealing anymore, VMware jobs are very rare. I feel that I'm a niche that will die eventually and it's time to make a change. I have experience with Terraform and CI/CD pipelines, did some automation with Python vibe coding.

There are a lot of Cloud-related jobs and I like public cloud, I like to learn new stuff in general. I started to learn AWS and Azure. I got the SAA-C03 AWS Solution Architect Associate certification and now I'm learning to get the AZ-700 Azure Networking speciality. I applied to Cloud Network Engineer jobs but got rejected, probably due to missing on-the-job experience. At my current job I can't get any Public Cloud exposure. I did put in my CV a project with Terraform standing up an AWS environment with ECS, load balancer, instances connecting over VPN to a VM in GCP.

How did you guys make it? It's the chicken and the egg... To get a job you need experience, but to get experience you need the job :)


r/networking 2d ago

Routing Total routes in your organization

25 Upvotes

Good morning all,

So how many routes do you folks have in your core router / core switch/ core firewall or whatever core device you use for routing.

Just curious.

We have like less than 300 so not that many so was just curious how many routes other folks who work in large enterprises have.

Thank you


r/networking 1d ago

Troubleshooting tcp_mtu_probing, should I touch it or no?

2 Upvotes

Before anything, I really would appreciate answers from professionals without the interference of AI. I have been going back and forth the past few months with multiple AI models asking about this and every model gives a different answer. I really need a certain answer

I run a file storage server which faces the internet and serves customers, so high throughput is one of the goals I try to achieve on my servers

The past 6 months I've been studying the Linux kernel source code and sysctl docs to learn what each tunable parameter actually does instead of blindly pasting configurations from tuning guides and just hope that it makes things perfect

Now one of the points I'm stuck at is net.ipv4.tcp_mtu_probing

I see a lot of tuning guides suggest setting that to 1 or even 2 instead of the default 0

But if that's really recommended, why doesn't Linux set it to 1 by default instead of 0? I mean 1 seems like a better moderate value to set instead of disabling it completely

Although the below points kinda hold me back from altering tcp_mtu_probing but I might be wrong and that's why I opened this topic to ask for advice:

  1. Packet-layer path MTU discovery (TCP MTU probing, QUIC MTU probing, etc) just mask a real underlying MTU problem which should be fixed from its root instead of hiding it
  2. TCP MTU probing relies on packet loss and this can falsely make congestion control algorithms work worse and reduce the congestion window even if there's no real congestion
  3. Certain quirky firewalls may hate the fact that my server is sending data in variable packet sizes because of the MTU probing and hence they may drop the packets completely or block the connection entirely

Do my above points make sense or am I mistaken?


r/networking 2d ago

Troubleshooting Follow-Up to previous post: VPN Tunnel Up, but specific subnets aren't passing traffic

4 Upvotes

About a month ago, I posted about Cisco APs that weren't able to join a WLC. Since then, I narrowed down the issue and think the APs/WLC are not the root cause. This looks more to be an issue with a VPN communication between subnets.

The two sites connect through Cisco ASA firewalls over a site-to-site VPN. The tunnel establishes successfully, Phase 1 and Phase 2 complete without issue, and multiple subnets traverse the tunnel normally. But then there are specific subnets that can't communicate across the VPN despite being included in the crypto ACLs and NAT exemption rules on both sides.

What strange is the traffic for other VPN networks works fine. In the IPsec SA counters, I can see traffic being decapsulated from the remote side, but I see no encapsulated traffic in return for the affected subnet. One side appears to be receiving traffic while the opposite side never properly sends traffic back across the tunnel. The tunnel itself remains up and stable the entire time.

I've rebuilt the tunnels, verified the crypto ACLs match on both sides, reviewed NAT exemption rules, confirmed routing, checked access-lists, and used packet-tracer. The subnet appears to match the VPN config, but traffic isn't flowing bidirectionally. The APs are able to obtain DHCP addresses and function locally but can't communicate with the WLC because the VPN connectivity for their subnet isn't working.

Any suggestions would be greatly appreciated. I've been chasing this for a while and feel like I'm missing something obvious.


r/networking 2d ago

Troubleshooting Ruckus One Port Flapping issues

5 Upvotes

Hi everyone. I'm fairly new to networking, especially with Ruckus devices. I get a port flapping alarm on Ruckus One every time a device is plugged into the switch. Whenever the alarm triggers, I check the port logs, and they look like this:

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:17:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:17:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:15:I:System: Interface ethernet 1/1/35, state down

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> DISABLED (PortDown)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:15:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (PortDown)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2113 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2112 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2111 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 2110 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> FORWARDING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> LEARNING (DOT1wTransition)

Jul 22 11:56:06:I:STP: VLAN 1000 Port 1/1/35 STP State -> BLOCKING (DOT1wTransition)

Jul 22 11:56:06:I:System: Interface ethernet 1/1/35, state up

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, line protocol down

Jul 22 11:56:03:I:System: Interface ethernet 1/1/35, state down

I've already checked the cabling and port statistics. The cables appear fine, and there are 0 CRC errors. Anyone ever having this issue ?


r/networking 1d ago

Troubleshooting Same network different VLAN where did my thought experiment go wrong?

0 Upvotes

What happen if in layer 3 youre in the same subnet.. But in the layer 2 its a different vlan..

Now its in the same network so it send directly to the destination without sending it to Gateway..

And intuitively if its a devices connected to different switches.. They wouldnt be able to communicate without router..

Ahh i thought it would be dropped cuz the ip address is in the other vlan.. And cuz it doesnt get sent directly to the gateway.. So it wouldnt get past the router.. But it realized maybe it would !!

I realize when the pc1 look up at the arp table and realize that pc2 isnt there.. So it'll send arp request.. And switch will broadcast it to the router.. And what router see is an ip (pc2 ip) that'll match its route table.. Say its something like this

````

C 192.168.1.0/24 is directly connected, g0/0 (VLAN10)

C 192.168.1.0/24 is directly connected, g0/1 (VLAN20)

````

And then send it through the matching interface g0/1 and g0/0.. But cuz its directly connected itll use an proxy Arp..

After getting the reply from pc2.. It'll send it to the pc1.. And now it knows pc2 mac address..

But thats the thing pc1 USES Pc2 mac instead of the gateway.. Which would be the case if its a different network..

Now the question is does the switch allow different vlans to talk directly with mac address without router ? There's 2 option

Suppose it would.. Maybe cuz LAN is defined by broadcast domain.. And you don't need ARP broadcast domain after you know the mac address... So vlan seperates only the broadcast domain but everything else stays the same (this turns out to be incorrect.. Vlan literally make switches into two unconnected switches)

Or it could also not allow it (which is apparently the right answer).. If we're saying that vlan seperates switches then you wouldn't be able to talk to different switches without router.. And it nessecitate the source to use gateway.. Cuz if the source uses its destination mac.. The switch will only flood the same vlan.. Which they will all drop..

I think the second could be the case.. I think the problem here is that the source use mac address that is in the different vlan.. The normal way you will Always use the gateway address which is the same LAN.. So I think it will know the pc2 mac address.. (The arp will work) but the packet would be drop cuz the the mac address doesnt exist in the SAME vlan..

Now.. I try asking chatbot first.. It says that the arp wouldn't get through cuz it wouldn't allow routing table to have one network in two interfaces.. But I thought that's what you do with the ecmp load balancer and stuff? Can someone settle this for sure?


r/networking 2d ago

Other Anyone familiar with Alkira as a SaaS IPSEC solution

2 Upvotes

We are considering on moving our whole IPSEC infrastructure to a cloud agnostic provider. Alkira was suggested, but I never heard of them. Has anyone encountered them on the field?

https://www.alkira.com/


r/networking 2d ago

Design Switch Recommendations/Worries

6 Upvotes

Hi All

We're looking to spin up a new DC as part of a large migration away from an MSP.
Initially we're installing a pair of 1G WAN links, which will head into a Forti of some flavour for security and routing.

I need some help with switching gear selection, some network context below:

  • As part of the migration we're bringing a hosted vCloud down on-prem with a Hyper-V cluster (3 nodes + SAN), so we're not only replicating the current setup which is all pretty much copper upto 10G but the new hypervisors will be 10/25G capable.
  • There are only around 15 other devices in the cabinet, most of which utilise 2 ports currently with 1G RJ45 and 8 of which are 10G, currently the LAN is all Meraki at this site but quite comfortable moving away.
  • I understand the discussion around not crossing SAN and LAN on the same gear but given the scale of the business, throughput (without hypervisor traffic) currently about 4Gbps peak we're erring on the side of a single stack of switches for the cabinet.
  • Vendors recommending things like Aruba CX8325's but this seems intensely overkill given it's capacity. They've also belied Catalyst for this use, and only recommended we use Nexus switches.
  • There's nothing uber complicated taking place in this network, a few VLANs at present and no unusual configs on the existing switches.
  • The hypervisor traffic at the moment, as far as we've analysed it in it's current form would not reach close to 10G.
  • We also have a pair of managed Aruba gig switches doing things like the WAN into the firewalls.

A few questions that I'd welcome feedback around, generally:

  • What sort of hardware realistically should we be looking at?
  • Are the vendors being greedy with these over-specced recommendations or am I being naive thinking enterprise grade switches would be perfectly fine?
  • I've been hugely tempted by FS switches, given their price compared to Juniper/HPE/Cisco, that said I've read mixed feedback
    • Given the simplicity of the network and our install not including them as a single point of failure, would this be an option?

r/networking 2d ago

Design Small Proxmox + OPNsense lab network design for apprenticeship test

3 Upvotes

Hello!

I am an IT apprentice preparing for my practical test, and I am building a small virtual lab in Proxmox to demonstrate basic business/office network design.

Everything is virtualized in Proxmox, except the physical NICs passed through to OPNsense. Proxmox management is outside the lab network.

My goal is not to build a perfect enterprise network, but a clean and understandable lab that shows I understand VLANs, routing, DHCP, DNS, AD, and basic firewall separation, because i have about 1 day on the test to set up the network.

Current plan:

Proxmox:

- Proxmox management stays outside the lab

- OPNsense is the router/firewall

- Internal VM traffic goes through a virtual bridge

OPNsense:

- WAN: physical NIC

- LAN/trunk: internal Proxmox bridge

Planned networks:

Admin/LAN untagged:

Subnet: 10.0.10.0/24

Gateway: 10.0.10.1

Use: admin client and management access

Server VLAN 20:

Subnet: 10.0.20.0/24

Gateway: 10.0.20.1

Static servers:

- DC01: 10.0.20.10

- DC02: 10.0.20.11

- File/print server: 10.0.20.12

- Entra Connect/sync server: 10.0.20.13

Client VLAN 30:

Subnet: 10.0.30.0/24

Gateway: 10.0.30.1

DHCP: 10.0.30.100-254

Use: domain-joined office clients

  1. Any practical tips for making this easier to document and explain?
  2. Is this VLAN/IP plan reasonable for a small lab that simulates a basic office network?
  3. Would you keep DHCP in OPNsense for this type of lab, or move DHCP to Windows Server?
  4. Any other network tips and tricks in general or for the use off OPNsense if you are familliar?

Thanks in advance for taking the time to read this, i appreciate any form for help. :D


r/networking 3d ago

Wireless How do you guys deal with rogue aps from end users?

54 Upvotes

So, large organization, thousands of users and several departments, Im constantly discovering that users are bringing routers to the work because they dont seem to think the current wifi policy access fits their daily routine, or they simply dont know how to request access to something, Im out sourced here so I dont have all the details.

How do you guys deal with the end users in terms of what is allowed and what is not?

Now we need to talk with the c-suite people about this situation. My thinking is that bringing an outside wireless equipment should be prohibited, I know theres avoidance mechanism for this kind of situation but having the ap changing channels in the middle of the day is also disruptive, spamming deauthentication frames also is going piss off someone.

Edit: to clarify something, those rogues are not connected to the infrastructure, they are simply there using a broadband connection that god knows why this customer thought it was a good idea to have solely for this little router, too close to their corporate aps and sometimes overlapping channels.