r/networking 11h ago

Blogpost Friday Blog/Project Post Friday!

4 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 2d ago

Rant Wednesday!

15 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 45m ago

Other Is IPv6 actually going to take over private addressing?

Upvotes

So I am just a student in the networking field with no actual working experience. But in my studies everything I have learned has talked about how slowly IPv6 will take over the IP space. I can only imagine that it is going to make doing simple tasks that much more annoying due to their length such as subnetting and other things. Would it not just be easier to have a NAT/PAT that converted private IPv4 addresses to a public IPv6 address? I'm sure this is something that most seasoned people have an obvious answer to but I was just thinking about it.


r/networking 11h ago

Troubleshooting A few seconds of downtime

19 Upvotes

I inherited a VXLAN EVPN network and it has been pretty stable until recently. From time to time, the layer3 or at least the inter-vlan drops for a few seconds. It happened last week, yesterday and today.

For what I can tell, the layer2 is fine. The VLANs gateway is on the service leafs (vPC pair). We are using ePBR to force the inter-vlan to the firewall, which is connected to the service leafs, the firewall will route the traffic back to the service leafs.

This has been stable for several months and no network changes. At this point, I'm not sure if the Nexus pair (where the SVI with ePBR) is causing the network downtime or the firewall.

We recently migrated to OpenShift for virtualization and containers. This was a month or two ago.

The firewall has a static route to the 172.16.0.0/16 with the next-hop of the HSRP VIP of the vPC pair. The service leafs are learning the 172.16/16 from a Catalyst leaf. All the VLANs are stretched to the service leafs via L2VNI.

```

[Fw]---/29---[service leafs pair]---[spines]---[cat9k leaf]

```

I know the layer2 (or L2VNI) didn't fail because Zabbix is not reporting any ICMPloss between it and the hosts in the same VLAN. However, any subnets within the same VRF drops for a few seconds.

The leafs CPU utilization history is basically idle 1% - 3%. The firewall is the same thing. Network utilization wise, we are using less than 800Mbps of traffic and the network is 40Gbps links.

I'm trying to get some ideas what I should look for to identity the issue and what is causing it.

My nexus version is 10.5.4 and the Catalyst is 17.15.4b. The Palo Alto firewalls (active/passive) are version 11.14.0.

Thanks.


r/networking 9h ago

Career Advice New Network Environment - Little bit rusty!

6 Upvotes

Hi all,

I passed my Comptia Net+ in Jan of this year, but have yet to really use much of my skills and so my knowledge has dulled a bit. I want to change that and start to shift towards networking focused, in case I want to change jobs down the line and to be more of a help to the team.

I've just moved offices and have been shown around our server room, given a brief overview of equipment and the environment, shown the (little and outdated) diagrams and documents. I'd like to come up with a plan/steps of things to do to get my head around everything whilst also still doing work etc.

Currently, I am working on labelling cables and tracing the physical paths of everything, noting them down and I plan to try and redo the diagrams. I want to also do this logically, however any tips/advice on doing this would be appreciated as I've done generic help desk for months and need to read back up on everything.

Cheers :)


r/networking 6h ago

Design New ESXi Host - Copper vs SFP

5 Upvotes

I’m potentially replacing an older ESXi host with a Dell R570 and running into a networking design question.

The current host has a lot of physically separated networks, with many of them using their own dedicated 1Gb copper NIC. iSCSI also uses multiple physical links.

The problem is the R570 can’t be configured with enough 1Gb copper ports to recreate the existing layout one-for-one.

My options seem to be:

  1. Keep the existing copper switching and use a managed switch to aggregate the separate copper networks into VLANs, then hand them off to the R570 over SFP+ trunks. Keep dedicated high-speed ports for iSCSI.

  2. Configure the R570 with 8x 10Gb BASE-T and move to 10Gb copper switching. Use two ports as redundant VLAN trunks for normal VM/management traffic, two dedicated ports for iSCSI, and use the remaining ports for vMotion/FT, additional redundancy, or spares.

  3. Go with a different server platform that can still be configured with enough 1Gb copper ports to more closely replicate the current physical layout and avoid redesigning the networking right now.

The environment is already very copper-heavy, including the storage side, so I’m leaning toward the 10Gb BASE-T option.

For those running VMware in production today, how would you handle this? Is consolidating the normal networks onto redundant 10Gb trunks the standard approach now, or would you try to preserve more physical separation somehow?

I’m mostly trying to avoid forcing a new server into an old 1Gb-era design when the hardware doesn’t really support that layout anymore, but I also don’t want to redesign the network just for the sake of redesigning it.

Thanks in advance for any advice or real-world experience.


r/networking 13h ago

Other Please help me be better at my job

9 Upvotes

Hi guys,

I have a career in sales working for a VAR for about five years now. We provided new and preowned networking hardware globally- stocking mainly the major OEMs like Cisco, Dell, HPE, Juniper & Arista.

I talk to network engineers, managers & directors on a daily basis. I really want to become better at my job and truly understand how I can be helpful towards network engineers like yourselves.

My questions for you all - what do you value in your relationships with your hardware reps? How do they (if at all) truly make your day to day work easier?

What are examples of your hardware reps going above and beyond for you? And what are the things that you hate to deal with?

Any feedback is much appreciated. Working with you guys and building relationships enable me to feed my family at the end of the day, so thank you for dealing with us!!


r/networking 15h ago

Career Advice Systems Engineer

10 Upvotes

I am a new hire systems engineer for Arista Networks. I have been on the customer side for my entire career thus far, and recently got hired in this new role working on the vendor side of things. I am wondering from anyone at the major network vendors who went from customer to the vendor side, How long did it take you to feel comfortable enough and be a "contributor" where you work? I want to feel like I am adding something but I am having trouble getting past the initial shock of it all. I am loving things so far, but getting past the initial learning curves and being able to start adding value is a real struggle for me currently. For those who made the switch, how long did it take to start feeling like a contributing member of the team?


r/networking 1d ago

Career Advice Network Engineer Work Load

53 Upvotes

What’s the average workload like for network engineers in the enterprise side ? I worked at a telco for 11 years and I’m used to being busy and always having work to do. But move to a smaller enterprise last year, pace of work is slow a lot of the times. Literally don’t have anything to do sometimes. So interviewing at an energy company with more money and hopefully faster pace of work. Just wondering what everyone else’s experience like


r/networking 21h ago

Routing Dyndns and noip how to use if the service provider changed to CGNAT

5 Upvotes

A lot of my ISPs in my country have switched over / are switching over to CGNat IPs which makes dyndns and noip register the wrong ip address rendering it useless . Is the solution to fix this . We have 300 clients using either dyndns or noip to access our servers but now I servers won’t whitelist them as they getting misreported IPs


r/networking 20h ago

Design Automating Cisco Nexus ACLS in Atomic way

2 Upvotes

Hello,

I need to strenghten security via access-lists under (SVIs (interface vlans)) using automation tools for Nexus 9k switches.

I was always using Git, Ansible nxos_config module for that with no ip access-lists / ip access-list way. It was somehow working for non important SVIs. Nxos_acls is not good approach, because it does not support statistic enable command. Now i need to make it to use atomic fashion.

Cisco 9k supports that using configure session / commit method, but ansible doesnt provide models for that atomic fashion, i think i will need to remake it via nxos_config / nxos_command as i was using before. Also Ansible has AWX / Tower which is nice addition. Maybe i'm missing something ? Any other ways u would do it ?

Thanks


r/networking 1d ago

Other From Netscaler to HAProxy with Citrix VDI

10 Upvotes

Hi, I am a junior network administrator and have been tasked with evaluating whether it makes sense to migrate the Netscaler with a Citrix VDI setup to a different load balancer and implement the new solution if needed. Currently I am considering F5, HAProxy, Envoy and Kemp. Are there any limitations in functions which makes it not possible to change? The reason is, that we are unhappy with the last security incidents involving the Netscaler over the last few months and the upgrade from major 13.x to major 14.x would take some time.


r/networking 23h ago

Switching HPE Comware switch (JG963A) — xtd-cli-mode

1 Upvotes

Hi all,

I'm managing a small stack of HPE 5130-series switches (JG963A) running Comware software version 7.1.070, Release 3507P09. On most of these switches, the hidden xtd-cli-mode command (used to unlock the full/extended Comware CLI from the default simplified/restricted CLI) works fine — it prompts:

All commands can be displayed and executed in extended CLI mode. Switch to extended CLI mode? [Y/N]:y

Password:

Warning: Extended CLI mode is intended for developers to test the system. Before using commands in extended CLI mode, contact the Technical Support and make sure you know the potential impact on the device and the network.

and after entering the password, it drops me into the full CLI (system-view, display interface, etc.) as expected.

On one specific switch in the stack, though, xtd-cli-mode now just returns:

<SWITCH>xtd-cli-mode

Permission denied.

with no Y/N prompt at all — straight rejection.

What I've tried:

- Reconnecting fresh via SSH (telnet is disabled on this unit) — same result.

- Rebooting the switch entirely — same result, persists across reboot.

- The account I'm using is the local admin user with network-admin + network-operator roles assigned, service-type ssh enabled, and it authenticates fine for a normal SSH login — it's specifically the xtd-cli-mode command that's rejected.

- Restricted CLI at login only exposes display, exit, quit, no, show — no way to run display users, free user-interface, or check security-enhanced/lockout state from there.

Since this is a firmware "developer mode" feature with anti-abuse messaging built in ("contact Technical Support"), I suspect this might be some kind of persistent lockout counter stored in flash rather than a normal AAA/role permission issue — but I have no visibility into it and no way to reset it from the restricted CLI.


r/networking 1d ago

Other What is the usual Price for Dark fiber leasing?

7 Upvotes

I want to lease out unused dark fiber strands and would like to know the current market price per core per kilometer. I would appreciate it if someone could enlighten me on this matter. I am asking from the Philippines.


r/networking 1d ago

Routing NEF with Open5GS

1 Upvotes

Hi, I am looking for a way to integrate a Network Exposure Function (NEF) with Open5GS. I’m currently exploring the possibility of using an existing NEF implementation and adapting it to work with Open5GS.

OAI-CN5G has an NEF implementation, but it is designed to work with the OAI 5G Core Network:

https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-nef

I’m looking for a way to use this NEF or another open-source NEF implementation with Open5GS instead.

If anyone has successfully integrated an NEF with Open5GS or has any guidance, suggestions or ongoing work in this area. Please share


r/networking 1d ago

Career Advice Would you take a job that uses off brand equipment if the pay is good?

28 Upvotes

I was offered a job as a network engineer. The company uses primarily Ruckus switches and only a few Cisco switches in their data centers. Most of my day to day will be working with the Ruckus switches. Speaking long term, couldn’t this affect the types of jobs I can get in the future? I don’t really see any jobs looking for candidates with Ruckus experience. At the same time though they are paying really well. Would you take it?


r/networking 1d ago

Design Cogent or Lumen?

31 Upvotes

Have options to get a circuit from Cogent or Lumen in a datacenter, anyone have reasons why I should go with one or the other?

It’s just for a simple DIA service.

Thanks in advance.

Edit : The amount of folks saying Lumen is wild, that was the direction I was leaning too, interestingly enough, cogent did come in with a suspiciously cheap price, I’ll go with lumen, thanks for the input!


r/networking 1d ago

Career Advice Any HPE Networking SEs? Interview prep advice

8 Upvotes

Hi guys,

I have an SE interview coming up for HPE Networking. It's the first stage and wanted to know if there would be any other questions other than the standard behaviour/motivation questions. They've already asked me two technical questions and one commercial question in the screening call. I know Juniper Networks was recently acquired by HPE and is now part of the HPE Networking business segment. I don't have a ton of wireless experience but I'm reading up about Wireless theory contained in CCNP ENCOR OCG. Would I be involved in both HPE Juniper Networking and HPE Aruba Networking?

Any advice and wisdom highly appreciated. Thanks


r/networking 1d ago

Troubleshooting Higher Latency WAN Sites slow AD/SMB Traffic

6 Upvotes

I am having a strange problem, and I'm not sure where to continue troubleshooting.

Our architecture is that we have all sites on a single MPLS provider. Most of these circuit are a direct connection with 5ms or less latency, however a few sites are involving a different last mile, with the highest latencies being 40-80ms. (Stable at each location, all latencies are constanly in the same 2-3ms range).

All of these sites have Cisco routers, and DMVPN tunnels back to our two hub datacenters (by weight, all traffic is to our main datacenter).

Even though all of these sites are 50mb - 100mb, any site with higher than 20-30ms of latency has very strange behavior involving seemingly any time of SMB traffic or group policy traffic. Copying one large file will hit full speed (eventually), and running an internet speedtest / iperf will show the appropriate speed. However, opening small files, or copying a folder full of small files, or applying group policy will be extremely slow. (to an extant that on the highest latency site, it was not uncommon to have group policy hit a 15 minute timeout, until we switched last mile providers to bring it under 15ms).

Looking at a Wireshark dump of a computer doing a gpupdate, the bandwidth graph shows less than 1kbps (compared with another location, 20Mbps). However, copying a large file, I was able to get 90mbps. I'm not sure what kind of troubleshooting I can do from here.


r/networking 1d ago

Meta WIndows WUDO in a semi ISP enviromnent

0 Upvotes

I started looking in random traffic patterns in our network (we have a small ISP-ish network, government) and I noticed that random computers from several non-related vendors and contractors in our network suddenly started exchanging data.

Turns out: it's windows WUDO service, some kind of weird p2p update system for pushing updates to seemingly random other windows devices.

This seems like a crypto-locker's wet dream if this service every get's compromised... (think wannacry).

Am I paranoid that we should lock this down? This seems like a terrible terrible idea to have servers and machines peer to peer update eachother when they are not even owned by the same contractor/supplier in our network...

From a networking perspective, is it sane for me to mandate that this WUDO server should be blocked globally?


r/networking 2d ago

Switching Is the QSFP-100G-SR1.2 Compatible with the QDD-400G-SR4.2?

1 Upvotes

Our team is upgrading part of our network from 100G to 400G, but we still need to keep several existing 100G switches in service.

The planned link is:

400G switch

→QDD-400G-SR4.2-BD

→MPO to 4×LC breakout

→4×QSFP-100G-SR1.2

The 400G port would be configured as 4×100G breakout.

Has anyone run this exact combination successfully?

The goal is to upgrade the 400G side first without replacing all existing 100G devices.

Would appreciate any real-world experience, especially on Cisco Nexus.

 


r/networking 2d ago

Design "Budget" LAN Refresh - HPE Instant On

9 Upvotes

Hi all,

Looking at a 50ish site LAN refresh (>300 switches) and I'm financially constrained.

Really doesn't need to be anything fancy, all VLAN's terminate on managed Forti SD-WAN appliance, so just need POE, some "visibility" (currently running Netgear "semi-managed" smart switches across the estate and I would very much like to set fire to them all) and the ability to support 802.1x in future would be a bonus (Will likely be a DIY NPS based solution!).

Looking at Instant On (Used the AP's in the past and had no issues with them) and looking for a bit of feedback from anyone that's using the platform.

- Is there a practical limit to the number of sites you can have? Have read about the 125 device limit but can't find any clear information on site limits...

- I would like to Cloud Manage them, however not averse to running them in local management mode to unlock the full feature set. What sort of visibility will I get from the Cloud Dashboard, is this the same basic client info you get on the Wireless dashboard?

- Are there any audit logs for users making changes when multiple users are setup? Current estate has a shared password that I'd like to get rid of. Depending on which mode I managed them in, I'm guessing I could achieve the same with local mgmt and RADIUS for Auth, but cloud console would be cleaner.

Any other low-cost solutions out there that I'm missing? Having come from several organization's where the answer is just throw Cisco/Meraki at it, this is a bit of a new challenge for me!

Please no Unifi, have been burnt in the past with issues to the point where I don't fancy using them beyond the home!


r/networking 2d ago

Design VeloCloud 720 + SonicWall — IPsec VPNs and port forwards on the same public IP

4 Upvotes

Looking for some advice on a VeloCloud/SonicWall setup.

Our topology is:

Dual ISP → VeloCloud 720 → SonicWall → Layer 3 core → LAN

We're adding VeloCloud 720s in front of our existing SonicWalls. The SonicWalls and network are staying in place; we're simply migrating the public IP termination from the SonicWall to the VeloCloud.

The SonicWall currently has several site-to-site IPsec VPNs as well as several port forwards. As part of the migration, we're configuring a dedicated VLAN/subinterface between the VeloCloud and SonicWall, with the SonicWall using that interface/IP to connect to the VeloCloud.

Our SD-WAN team says we can keep the existing VPNs working by using the remote VPN peer IPs defined in the SonicWall VPN policies as the source restrictions on the VeloCloud NAT/forwarding rules.

We tested this approach successfully at another location. The difference is that the public IP at that location didn't have any existing port forwards.

At this site, the public IP we're moving from the SonicWall to the VeloCloud currently has port forwards for:

  • TCP 722
  • UDP 21000
  • TCP 8080/8880

We also need the existing site-to-site VPNs to continue working with:

  • UDP 500/4500
  • ESP

So our main question is:

Can the VeloCloud 720 use the same public IP for the existing port forwards while also forwarding IPsec traffic from the specific remote VPN peer IPs to the SonicWall?

Has anyone deployed this type of setup?

We're mainly wondering if the peer-IP-restricted NAT/forwarding approach will coexist correctly with the existing port forwards on the same public IP, or if there are any NAT precedence, IPsec, or NAT-T gotchas we should be aware of.

Thanks!


r/networking 3d ago

Other Difficulty moving beyond the basics of Linux networking

26 Upvotes

I am studying Linux server networking in virtual machines, and I am still very much a beginner. There is an activity I was working on, but I can only manage (with some difficulty and delay) the IP addressing and connectivity testing, while the rest of the scenario seems way too complex for my level.

The practical tasks I need to resolve involve a multi-server architecture covering the following points:

  • Routing and NAT (PAT, port-forwarding, and static NAT) using nftables, with traffic blocking policies and logging.
  • Infrastructure services configuration, such as DHCP with automatic record updates and DNS servers with internal and external views.
  • Implementation of directory and authentication services using OpenLDAP and FreeRADIUS.
  • Remote access VPN configuration via OpenVPN.
  • Deployment of advanced services, including secure email (SMTPS/IMAPS), web servers with SSL/TLS certificates, directory-restricted FTP (jail), and monitoring with Cacti.

I don't know, it feels like for every small configuration multiple specific lines are required to achieve the goal, how can I learn more dynamically?


r/networking 3d ago

Switching MPLS FEC

6 Upvotes

Hi

I`m review now MPLS FEC topic.

 

R1----R2----R3----R4----R5----10/8,20/8

 

FEC is a group of packet one or more packet are treated the exact same way. Does that means if R1 received :

10.1.1.1,10.2.2.2,20.1.1.1,20.2.2.2

and these 4 packets are treated on R1 the exact same way

and on R2 are treated a different way, R3 another way,R4 another way. Does that mean each hop must treat these 4 packets as the exact same way like R1 in order to be on the same MPLS FEC ?

OR

It`s normal for each hop to treat them on a different way and still on the same MPLS FEC?

What i mean does the MPLS FEC is controlled on the ingress PE only ?

OR

MPLS FEC could be controlled on each hop and the FEC is locally significant?