#networking

1 messages · Page 152 of 1

rocky badge
#

needs more 400Gbps, Lurick

thick minnow
#

Knowing how to set up ACLs is still a good skill to know.

waxen scroll
#

you only use ACLs on a router for traffic filtering if the router is direct connected to the internet

#

rocky badge
#

I like taking down the IoT network for a bit

#

lel

#

all of my shit freaks out and broadcasts their SSID

waxen scroll
#

i feel bad for blobs parents. its probably down all the time

rocky badge
#

lol

clear igloo
#

lol

rocky badge
#

I only took down one AP

#

the main network stays up

thick minnow
#

So you created separate VLAN's on one of your AP's(I assume you have more than one?) and those AP's are hooked up into your gateway/router?

#

Are you using a switch as well?

rocky badge
#

ER-X -> switch (US-8-60W) -> switch's 8th PoE port -> AP -> AP'S SSIDs using VLAN 5 and 10

#

PikaOh Got it

waxen scroll
#

i was too cheap and didnt want fans

rocky badge
#

guests can't see other guests

waxen scroll
#

no poe switch for me

clear igloo
#

I got all the PoE 😄

rocky badge
#

US-8-60W was like $99 and it has 0 fans

waxen scroll
#

i need 24-48 port, not 8

thick minnow
#

What is the ER-X your router?

rocky badge
#

yes

thick minnow
#

Is that the model?

rocky badge
#

then get the 24 port :p

#

yes

thick minnow
#

What brand of router ya got Blob?

rocky badge
#

Ubiquiti Networks

thick minnow
#

Neato, I've never heard of that brand before.

#

Alright, that's enough of me chatting. I have to get back to preparing for my Networking Midterm Exam.

#

Cya around guys.

waxen scroll
#

no exam here

#

if its broke they stare at me

rocky badge
#

lol

thick minnow
#

OOF

waxen scroll
#

if im wrong the business keeps losing money

thick minnow
#

It's like my parents calling me down this morning from bed because the "TV Isn't working.".

waxen scroll
#

millions of dollaz

#

an office full of people who cant work? sheeeeeet

clear igloo
#

@waxen scroll Just tell management they needed a break, you were watching out for their health 😛

waxen scroll
#

👽

#

blob doesnt even want to be a netadmin

clear igloo
#

That's sad kiichiMiyukisad

waxen scroll
#

i kno

#

@clear igloo i see r/sysadmin is finally becoming aware that jack of all trades is appreciated less and less

#

shits too complex now

#

people want specialists

clear igloo
#

Yup

rocky badge
hallow nimbus
#

Just a couple of servers

clear igloo
#

Is that your pr0n stash?

hallow nimbus
#

No its mine

rocky badge
#

😂

#

Dell R720xd 12 Bay LFF Two E5-2660 64GB 12x 4TB SATA+2x 146GB 15K SAS H710 2x PS

waxen scroll
#

Dooley: can we add p0rn to the censor?

rocky badge
#

reeee placement of label isn't uniform

waxen scroll
#

whoever did that blobby needs to be fired

#

thats too much for a skid

rocky badge
#

lmao

hallow nimbus
#

How much for 1 server 👀

rocky badge
#

$1.5k

hallow nimbus
#

Yikers

waxen scroll
#

the pallet jack must be crying

rocky badge
#

@hallow nimbus it's dual Xeon (8c/16t each) with 64GB of ram

hallow nimbus
#

Oh

#

I wil take 10

#

😂

rocky badge
#

and 12x 4TB SATA and 2x 146GB 15K RPM SAS with PERC H710

waxen scroll
#

srsly blob

#

what do you wanna do for a job

clear igloo
#

Blob gonna get him a sugar momma and live like king

rocky badge
#

uhhhhh

#

@clear igloo Hmm

waxen scroll
#

@clear igloo im about to go do my amazon basics oil change

#

xD

clear igloo
#

Let me know how that goes

waxen scroll
#

@rocky badge you better start wrenching now

rocky badge
#

🤔

waxen scroll
#

when you have money you might get a racing habit

rocky badge
#

oof

waxen scroll
#

learn young

#

IT people love cars

#

😄

little schooner
#

getting under a car without protection doesn't sound too much fun

#

if I had those lift things at the mechanic shop I would like to do the oil change

waxen scroll
#

No protection needed. I use ramps

rocky badge
#

lol

waxen scroll
#

i use these

#

they were the only ramps that didnt look sketchy AF at a price thats still ok

unreal wedge
#

@waxen scroll evasion of the "censored words" filter is an immediate and permanent ban.

#

I'll make the filter more intelligent later, it's not our top priority atm.

#

@hallow nimbus

hallow nimbus
#

Oh shits

unreal wedge
#

@rocky badge those HDD trays alone are worth a ton.

hallow nimbus
#

I am sorry mister dooley

rocky badge
#

yea

waxen scroll
#

HDD trays are gold. my old company bought knockoffs from china

#

cause dell over charges

#

actually no

#

the problem was dell didnt sell them

#

you HAD to buy it with an HDD

unreal wedge
#

I got legit ones from either ebay or newegg for cheap-ish

fresh copper
#

I’v 3D printed trays before. You usually can’t because they often have chips in them but sometimes it has worked

waxen scroll
#

this was 2012, so no chips.

unreal wedge
#

Dell SAS trays don't have "chips"

waxen scroll
#

ive never seen dell with chips. im not shocked if HP does

fresh copper
#

Maybe it was something else that I was doing wrong then

#

Either way, I only got it to work a few times

rocky badge
#

yeah, some of HP have chips

waxen scroll
#

hah hah. OF COURSE HP does

unreal wedge
#

HP aka money ho.

rocky badge
#

we used to have all HP Oof

waxen scroll
#

it pisses me off when people brag that they PREFER HP over dell

#

usually seen at HP server shops

rocky badge
#

We used to have HP ProLiants/ProCurve/etc

#

now it's all Extreme networks/Cisco/Dell

waxen scroll
#

i call them out on driver downloads and the fact that HP servers take twice as long to post

rocky badge
#

kek

#

Dell drivers and shit is SUPER NICE

waxen scroll
#

when you have an outage and a reboot will fix it, the HP posting is the worst

#

time stops

thick minnow
#

How would you guys get a 40gig connection without a fiber? I’m thinking about going eband but ...

waxen scroll
#

for a single connection or multiple?

#

i mean stream, not physical connection

fresh copper
#

That sounds very hard though I suppose that it is possible

waxen scroll
#

port channel

#

getting 10gb copper gear is gonna be more expensive than just doing fiber probably

fresh copper
#

He mentions E Band so I am assuming that he is looking for some form of wireless solution?

fickle wedge
#

I have a problem. My WAN light is on but my internet light isn’t. All the cables are plugged in the same way they have been for the last month. I unplugged my setup at the wall just like 30mins ago and now my internet isn’t working anymore

pine panther
#

try replugging

#

it

fickle wedge
#

Haha

#

What do you think I tried

#

Bro I tried everything that I know

pine panther
#

then that might be outta my reach i give this to other smarter people xd

fickle wedge
#

@smarter people than me

modern forge
#

Hi here, I'm trying to setup remote web access on windows server 2019 datacenter but when I try to connect to my public ip I get a time out error on chrome and an resource not found on ie. Connecting to local ip does work and everything is portforwarded correctly. Any ideas what is causing this?
(@ me)

modern forge
#

Can someone tell me which ports are exactly needed? Maybe I missed one

thick minnow
#

What port is your web server running on? 80,8080,8081,443?

#

Also, where does your webserver traffic get sent to?

modern forge
#

The standard ports, so 80 + 443

steady loom
#

@modern forge You need to forward ports in order to access it from outside of the network

#

also it's not always supported to use your external IP from inside the network. This is called a "hairpin turn" and not all routers support it

#

Also why are you using windows server? Unless you need active directory I wouldn't reccomend it

little schooner
#

@steady loom hairpin is funny same with hairpin nat

#

EdgeRouter supports it so you can NAT within the internal network which is strange but cool same time

steady loom
#

I try to avoid weird configurations like that

#

I'm working on setting up some kind of edgerouting / reverse proxying for a Nomad Cluster

little schooner
#

NAT please PAT SNAT

#

@steady loom reverse proxy is what again?

#

where connection comes in and. terminates?

#

and start a new connection using local ip?

unreal wedge
#

reverse proxy is where the connection comes in and it routed internally, without exposing the origins IP/port, only the proxy's.

steady loom
#

Kind of, it's when you basically have a proxy in front of backend services.

The situation is that I have a cluster of a few servers. And jobs that will be running on these servers. During the lifecycle of the jobs, it's possible for the server they are on to be abruptly terminated. If this happens, the scheduler will move the job to a different server in the cluster.

So I need a system where I can have one Nginx or HAProxy container that will route traffic to microservices to the correct cluster member that is currently running the job

little schooner
#

hmm seems useful

steady loom
#

Yeah, it's a fault tolerant system. With persistent storage. For example I ran a test database job. Added some test data, And then killed the server the database was running on. There was maybe 5 seconds of downtime while it rescheduled the job and moved it to another node

thick minnow
#

Redundancy is key in any newer modern network(s).

subtle glen
steady loom
#

Remote Authentication Dial-In User Service (RADIUS) is a networking protocol, operating on port 1812 that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service. RADIUS was developed by ...

subtle glen
#

and where do you find these info?

#

i mean, the radius key and stuff

steady loom
#

Are you running radius?

subtle glen
#

no

steady loom
#

You would get / configure the key during the configuration process

subtle glen
#

so you need to make a radius server first and then fill the RADIUS Server and Radius key spaces with the parameters you got during the configuration of the server?

steady loom
#

pretty much

subtle glen
#

ok

steady loom
#

Chances are you don't need radius though

subtle glen
#

so screw edgerouter VPN?

little schooner
#

@subtle glen I found pfsense was easier to set up

#

for VPN

rocky badge
#

use the CLI

#

4head

subtle glen
#

do you use pfsense as your main router @little schooner

#

@rocky badge uuuuh cli

rocky badge
#

CLI > webgui

subtle glen
#

PFFFF

modern forge
#

I'm using AD and I use my external ip before and it just worked fine with esxi. But now with windows server it does not. And as I said I already port forwarded it. @steady loom

little schooner
#

cli is also a luxury

#

Dell charges another grand or more for it

#

@subtle glen I don't but I NAT for VPN access

#

it goes Internet > NAT > WAN > PFsense > OpenVPN int

subtle glen
#

but then you would be on a separated subnet

little schooner
#

@subtle glen I am with two vlans, but the openvpn connection can access all the lans

#

if you push routes in your config

#

I have 10.0.0.0/8 route

subtle glen
#

this is getting more complicated than i expected

little schooner
#

if I were to do it again, I'd scrap EdgeRouter and put pfsense there instead

#

I just don't find affordable 10G

#

that uses tdp less than 25W

subtle glen
#

or use the edgerouter and PFSense as a transparent firewall

little schooner
#

no, that will only make it complicated for little to no benefit

#

I would do it over if I get the money again

#

The new build would cost around $570 with a 10G nic

#

but tdp is still problem

subtle glen
#

isnt pfsense bad for 10g

little schooner
#

who said that?

#

netgate even sells their 10g appliances

subtle glen
#

Ayyylias i think

little schooner
#

if you don't match hardware with capability, it won't hit 10g routing speeds

#

match it, it will be fine

#

like it requires quad core at minimum

#

don't know for boost speed but a fast Intel quad core from 8th Gen should do

steady loom
#

@subtle glen I run pfsense

subtle glen
#

any particular reason you went with pfsense?

steady loom
#

It's pretty powerful

thick minnow
#

That looks like the one my Networking professor has in the lab.

fresh copper
#

I’m not a big fan of PfSense as a router. It works well as a firewall and basic routing situations like NAT with two WANs and maybe a very small number of VLANs. No matter what machine you put it on, it has issues with too many interferences, especially too many IPSec interfaces (I’ve had it take 5 minutes just to save a single change to an IPSec interface because it wants to save them all). You can’t turn the firewall off without disabling NAT and trying to get allow all rules to work is very hard. Even a standard allow all rule does not block everything as it will block connections where it did not see the opening and it has issues with reverse pathing too. Sometimes, if you have a large number of firewall rules (like having many interfaces which each have an allow all rule), it won’t even properly apply the rules. It will save them but then it will still block packets even though you have an allow all, it can even show them as being blocked for rules that have been deleted. Reloading does not help at all and the only thing to do is make some other change to get it to re-save the rules.

thick minnow
#

Wall of text.

#

My eyes hurt.

subtle glen
#

it's been a long time since i turned on my cisco switch now that i think about it. Maybe it will blast dust out if i turn it on xD

little schooner
#

@subtle glen the best time to bring out the vacuum

subtle glen
#

true

zenith ridge
#

https://www.benl.ebay.be/itm/MIKROTIK-CRS326-24G-2S-RM-Cloud-Router-Switch-24xGbit-LAN-2xSFP-Rackmount/173223476825?hash=item2854ec7e59:g:c60AAOSwroZarqOe

I found a mikrotik router, with dual SFP+ ports
Never used RouterOs, only pfsense, can router OS do the same as pfsense? with a focus to dual wan/isp settings?

It's the best deal containing SFP+ ports i can find for a router

eBay

MIKROTIK CRS326-24G-2S+RM Cloud Router Switch, 24xGbit LAN, 2xSFP+, Rackmount | Computer & Netwerk, Bedrijfsnetwerk & Servers, Schakelaars & Hubs | eBay!

thick minnow
#

Looks interesting.

#

Layer 3 I assume since it has Router in its name? Is it a MLS?

zenith ridge
#

Layer: 3 is on the ebay page, but I really have no clue what that means, I just need a router, and I have a 14U server rack with at the moment 1x 4U server and a UPS, but I'd like to put 10G into the server, so this router would give me 10G option and more then enough ports for lan network

#

But I've never touched 10G network gear, and I'm not a networking guy, so

fresh copper
#

@zenith ridge the issue is that while it is a router, it routes much slower than it can switch. It has a switching throughput of about 46G but the routing throughput is only around 1.2G. Here is a photo from the Mikrotik page with their test results for routing. https://mikrotik.com/product/CRS326-24G-2SplusRM#fndtn-testresults

zenith ridge
#

Oh, so it's cheap because the 10G ports are rather useless as a router? Would you have a suggestion for a better option similar to this?

fresh copper
#

It's not really meant as a router which is why it has worse routing performance. It is a layer 3 switch which means that it's main job is as a switch with routing sort of tacked on and useful not as a main router but for inter-VLAN routing like maybe to allow normal devices to access an IOT VLAN but without letting the IOT escape to the internet. Routers that can actually handle 10G can get very expensive. The cheapest Mikrotik that can almost handle 10G is the RB4011iGS+RM (https://mikrotik.com/product/rb4011igs_rm). It has only one SFP+ port and 10 1G ports. It gets much more expensive if you want something with more than one SFP+ port. Here is Mikrotik's list of routers https://mikrotik.com/products/group/ethernet-routers. If you are ok with 10G copper ports then maybe the EdgeRouter 12 from Ubiquity would be the best.

little schooner
#

@fresh copper actually I never thought about the intervlan layer 3 switch usage that way

#

that's neat

zenith ridge
#

@fresh copper I see, thank you, I'll guess the search goes on, i don't need it as I'm still living at my parents, I would just like 10G and be ready to move out with my rack working and just plugging in the wan port znd power

fresh copper
#

It might be easier to just build a white box router with an SFP+ card

zenith ridge
#

@fresh copper Would you also happen to know some 'silent' 1u case with PSU options? I have 2x E5-2665 cpu's doing nothing, could use 1 or both of them in a pfsense box

though it will draw a lot more power

But making a server around those cpu's wont be to much of a waste, if i end up buying an actual router later i can still use it as a test server to play with or sell it as a full system

waxen scroll
#

hi ppl

fresh copper
#

I don’t have any good recommendations at the moment

pseudo blade
#

silent 1u You may pick one.

clear igloo
#

Dell R620, have both (up to about 70% CPU utilization) 😃

daring plover
#

Could someone help me with mysql

waxen scroll
#

lots of SERVER discussion in the NETWORK channel

#

maybe dooley needs to make #servers

cursive valve
#

@Tommeh#9804 what you need

waxen scroll
#

@unreal wedge since linus has been doing lots of server talk, maybe it makes sense to open #servers

daring plover
#

For some unknown reason whenever i install mysql, mysql -u root -p mysql returns : Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2)

waxen scroll
#

is there a flag to define "localhost" or the IP?

#

though if theres no socket, perhaps its not even running

daring plover
#

Well, how do i start it, i cannot find the name of its service

waxen scroll
#

its been years but mysqld ? sqld ?

daring plover
#

nope and nope

cursive valve
#

I haven't used MySQL since I found MSsql was free

waxen scroll
#

what is the OS?

daring plover
#

Centos 7.6

waxen scroll
#

you installed using yum?

daring plover
#

yep

waxen scroll
#

if you did yum, google says mysqld.... sudo systemctl start mysqld

daring plover
#

That's why i'm here, everything i can find doesn't work

waxen scroll
#

you checked /usr/lib/systemd/system/ ?

daring plover
#

Am i like missing an additional package or what

waxen scroll
#

if its not there, thats the extent of what i can help with. i havent had to run sql in years and systemd came out since ive used it

#

i stopped using linux for the most part before systemd hit, so :3

daring plover
#

I don't see any mysql services

waxen scroll
#

gotta go. bbl. all i can say is maybe try installing it again. maybe you only installed the sql client and not the server

daring plover
#

Tried already

#

Well, what would the darn package for it be

#

As i find the docs on this very bad

waxen scroll
#

sudo yum install mysql-server

#

should be that

daring plover
#

Doesn't exist

waxen scroll
#

you might need to add a repo

daring plover
#

How, we never did that

waxen scroll
#

this says you do

daring plover
#

I have already destroyed an entire machine trying to get this working

#

By using that exact doc even

#

It is an ipv6 machine btw

#

And last time i installed that it fucked everything up

#

The machine could no longer acces the internet or install any packages

#

Not even linux mint on ipv4 can get that file though

#

Oh, i broke that one aswell ffs

#

4th dead mint from trying to install mysql

little schooner
#

use snapshots and vm

daring plover
#

Broken for some reason

#

It must have some freaking package though

#

But i cannot find them anywhere

#

And i'm royally screwed if i cannot get mysql working again

little schooner
#

@daring plover yeah I'm not sure. Is this for a project or something?

daring plover
#

school

#

I'm fucked if i cannot get it to work

#

@little schooner

#

We were never told how to add repos and i cannot get it to work

#

MariaDB would also work

#

But somehow it doesn't

little schooner
#

yeah not sure. last time I used something with rpm was when I installed opensuse

daring plover
#

Well, i managed to finally find a valid package name for mariadb

#

But it denies acces for root

#

Nvm, finally got it working, thx anyways!

thick minnow
#

Hey, how’s it going folks?

subtle glen
#

pretty good thanks

little schooner
#

good I would say.

#

marketing class is coming up but the teacher keeps putting projector up and down

thick minnow
#

That’s good, I hope you all are dong well.

little schooner
#

I don't know what they're doing

thick minnow
#

I have my networking class midterm exam today.

little schooner
#

I wish you the best of luck on it

thick minnow
#

I should be fine, I’ve been binge watching Professor Messors CompTIA Network + Videos.

#

lol

#

I’ll just do the best I can.

little schooner
#

I remember that I never really studied for mine

#

I just came into class

#

seemed to stick, probably due to the professors explaining

thick minnow
#

Huh, interesting... I guess you have a good memory then.

#

The only reason I’m watching these videos is to just review the materials covered in class and from the chapters.

#

¯_(ツ)_/¯

subtle furnace
#

I have online networking classes, I always get to check my answers during finals because my professors don't bother setting up secured browsers for the tests

#

It's tough because I want to just breeze through and 100% everything but I want to learn it too because I'll be a worthless network admin without it

little schooner
#

I did the same thing for cisco practice tests. All I did was read the chapter and take the test within the next day or so

#

I was getting 88-97% on the tests

#

For datacomm II i was getting only 90%+

#

for datacomm IV, it started to drop to 85%

#

If I were to take notes, I would of been missing out on the examples the teacher was trying to explain in dumbed down version of what the slides had

#

and that what would end up sticking more

#

I guess the experience will vary for everyone but if you try giving me Trig math homework to memory, I will not do well

thick minnow
#

Same, the highest level math I ever did was Quadratic Equations.

#

Then I was like: "Yeah this is enough, I'm done."

little schooner
#

I am not doing too good in trig. I have a current grade average of 74%

thick minnow
#

I'm not that great when it comes to math as well.

#

I struggle sometimes even with basic math.

little schooner
#

All I need is just minimum D- for a credit

#

but im striving for better obviously

thick minnow
#

It's funny though because sometimes the more complicated math stuff is easier to me than the less complex math stuff.

#

My brain confuses me, and itself.

little schooner
#

And I spend a lot of time doing the homework but

#

cant seem to jab it in and stay in the noggin

#

I guess there are no neuron connections that could relate to the information to connect em

thick minnow
#

I have attention problem sometimes.

#

;/

little schooner
#

This semester cant be done soon enough. I want this math to be over

#

I still haven't done my core classes

#

I have a lot of generals to take

#

I am in a bachelors degree program

#

Somehow I managed to skip geometry, precalc and trig in grade school

glad prism
#

there is a lot of trig in Juniper networking

#

so you better brush up

thick minnow
#

I'm not even doing any math this semester.

#

But once I matriculate I'll need to take the Accuplacer Test which means that I need to brush up on my basic math skills and pre-algebra, algebra 1 math.

#

I don't even know why I'm saying this all to you guys.

#

¯_(ツ)_/¯

clear igloo
#

Everyone has their fair share of stupid errors 😛

little schooner
#

like how ubnt edgerouters don't properly remove firewall aliases when you delete some rules

#

and then when you upgrade it reboots itself because it detects broken config referencing something that doesn't exist

#

but somehow the old versions allowed this problematic config

#

yeah that's one dumb error

waxen scroll
#

ive met cyber security guys who didnt understand routing

clear igloo
#

Just put it all in a single L2 domain, it's fine

waxen scroll
#

no, like... the firewalls they manage were routing

#

but one of the team told me he didnt get it and tried to explain routing to me

#

was only half right

clear igloo
#

🤦

waxen scroll
#

that feel when dooley ignores you

#

😍

hallow nimbus
#

😂

unreal wedge
#

@waxen scroll I was busy.

waxen scroll
#

So can you moderate non-networking talk from now on?

#

👌

fresh copper
#

I've got 19.93 Mbps incoming on one of my servers right now. That's not a lot on its own but consider that that almost entirely NTP

cursive valve
#

@unreal wedge !slap

unreal wedge
#

@cursive valve !ban

cursive valve
#

😱

strange silo
#

@fresh copper I hope that's not NTP reflection attack traffic lol

fresh copper
#

@strange silo that’s 1/14th (or more) of all of the IPv4 NTP requests to the ntppool from China

#

The China pool has been failing really hard so we have added some non-China servers to the China pool so that the servers in China won’t be hit so hard and will hopefully recover from the state of having too low a score to be in the pool. Then maybe we can find a better solution (we don’t know exactly the best thing to do yet but we have been discussing it)

covert ibex
#

@fresh copper
All I'm going to mention would perhaps be disabling things you've probably already disabled. (Like disabling monlist)

fresh copper
#

@covert ibex absolutely nothing but the standard time commands are available, definitely not monlist. It’s not like monlist would even work. It’s supposed to return a list of 600 clients and I turned off logging clients so even if it was enabled, it would have nothing to return. I’ve done a ton of optimizations because handling that much traffic in very small packages is hard.

covert ibex
#

Could you just disable NTP on those servers?

zenith ridge
#

@fresh copper Sorry to bother you again

https://www.amazon.com/MikroTik-Ethernet-10-Port-RB4011iGS-RM/dp/B07HBW2NTR
I found this, but also read somewhere the SFP+ port is the WAN port, and 10x1Gbit are the LAN ports.

I would like to use the 10G for a server
And I would like to use 2x1G ports as WAN for load balancing

I think this should work for what I need (want), and I can still extend to the other 24port switch with 2x SFP+ if i need more 1G ports

Both would cost me less then 300$ combined, and a lot less watt usage then a pfsense box

thoughts?

pseudo blade
#

@zenith ridge You can use any combination of interfaces on the RB4011 as WAN or LAN (or any other setup you can imagine). Only real thing to keep in mind is that each bank of 5 gigabit ports has a 2.5gbps symmetric pipe to the CPU. (see the block diagram).

zenith ridge
#

I see, thank you! Guess that 2.5Gbps limit is why it's cheaper then other routers with a SFP+ port, but for home use, it should be alright, just going to save this one, but I think this will win because of the price and faster then 1G speeds (Most I have reached so far is 4Gb in a VM on the server the the drives, local, wont reach 10G speeds anytime soon

pseudo blade
#

The SFP+ port is 10gbps.

#

It's just not possible to leverage this using just the gigabit ethernet ports.

#

I quite like them for the price.

zenith ridge
#

Yea, but untill i need more ports i'm most likely just connecting the server with SFP+ port, and later add a switch with 2x SFP+ ports

#

the switch is about 150$ or so, 24ports 1G with 2 SFP+

#

Then I can connect router to the switch using fiber and server to the switch

pseudo blade
#

That works.

zenith ridge
#

Yea, and i can do this spread over few month, first the router untill i need more ports, instead of spending 1k on a router alone for just having SFP+ ports, even with limitations this is an amazing deal

#

Anyway, thank you, i was just a bit worried because of that 1 internet page telling SFP+ was WAN port 😅

pseudo blade
#

No problem.

thick minnow
#

How’s it going my Networking peeps?

median ore
#

Imagine you have to link 4 pc in 1 room to a Server in an other one ... how would you do that ? Run 4 CAT6 cables directly to the server room or an other way ?

clear igloo
#

Use a switch and run one cable from the switch to the server

median ore
#

Those are CAT6 cables ... going somewhere lol

waxen scroll
#

wow

thick minnow
#

Engineering 100

waxen scroll
#

thats how many offices do it

#

but they cover it up with plastic or metal

subtle glen
little schooner
#

@subtle glen whatt... no strap fasteners or cable tie love for those wires 😢

#

They might as well connect a console cable to the switch and let students access it

subtle glen
#

there is even worse

#

also no sites are blocked so you can access anything on the internet

little schooner
#

@median ore The seats look so hard.

#

@subtle glen is that a post-secondary school

subtle glen
#

i bet that switch doesnt even have a password

#

ehhh, i don't know how to translate that to italian xD

tawny seal
#

Lmao

#

I can't login to my school's router but I can access the page

subtle glen
#

me too

tawny seal
#

It's a Cisco meraki mx400

subtle glen
#

we are using some open source crap

tawny seal
#

10k router

#

It sells for around $10,000 I'm pretty sure

subtle glen
#

also the connection to that lab that has like 20 pc's still has a 100 mbps connection to the main router (or other switches in cascade, ikd)

little schooner
#

Were in the same situation

#

only a 100 mbps link

#

its stupid

tawny seal
#

Damn my school at least has 500mbps to the computer applications room using 5e

#

I got 1000mbps using a cat 7 cable of my own on a gigabit port on my laptop

subtle glen
#

and since my school is divided in 2 blocks (the labs where the routers and servers are located, and the classrooms) i am pretty sure that the classroom area (with access points, pc's and stuff is connected to the "server room" via 1 tiny ethernet cable

#

not even a fiber link or something like that

tawny seal
#

Everyone always days school internet is shit it's not honestly it's better then most kids internet at home

#

It just has a alot of web filtering

#

Making it slower

subtle glen
#

not mine xD

#

mine is slower cause it's a crappy physical network

#

not cause of firewall rules and stuff

tawny seal
#

I have the best internet where I live and it's only 100mbps

#

Well it's abit above

#

Other then business and fiber it's the best

subtle glen
#

my school has (in theory) 100 mbps but often it's around 30 mbps, and once we had to download a few MB software and it took one hour to do it

tawny seal
#

Jesus

#

Actually my school's upload is higher than download

#

We use old ass 2009 Macs

#

We could have got new windows computers for the entire school but nopw

#

We shitty Chromebooks

subtle glen
#

schools that fill up labs with MAC's really want to waste money

tawny seal
#

We did get new windows computers for computers applications room though

#

But it's Microsoft office

#

So you need windows computers

subtle glen
#

some pc's in labs still have 4 GB of ram, IDE hdd's, windows XP or 7

tawny seal
#

The middle school the IT director is my friends dad

#

So I'm gonna get like 2 Dell servers and 2 apple xserves and some more Cisco gear

#

This is what I got right now

subtle glen
#

those switches seems old

tawny seal
#

They are

subtle glen
#

like 100 mbps ones

tawny seal
#

They are

subtle glen
#

i have a couple of them too

waxen scroll
#

yeah, i trashed my entire cisco lab

tawny seal
#

Why

waxen scroll
#

im all virtual now

tawny seal
#

Damn I prefer physical

subtle glen
#

do you have a virtual switch

waxen scroll
#

yes

subtle glen
#

eww

tawny seal
#

I'm waiting to set up my proper lab

clear igloo
#

When you're labbing you don't need physical

tawny seal
#

Just ordered a 2811

waxen scroll
#

you only need physical if its a high performance lab

clear igloo
#

^

waxen scroll
#

none of us do that... i only do it at work

subtle glen
#

don't you wanna be high performance?

waxen scroll
#

no

clear igloo
#

Not at home, no

subtle glen
#

lol

waxen scroll
#

i do for work, not at home ;\

subtle glen
#

i prefer physical too

waxen scroll
#

yeah but thats all equipment you cant afford at home

#

i dont want to operate on equipment from 2001

#

virtual lab is all modern

clear igloo
#

Why use up all that space at home when you can virtualize a dozen routers into a single 1RU server

subtle glen
#

if you have the space (and money) to do it, why not

waxen scroll
#

i use a 2RU server and i dont keep it running 24/7 cause im an adult and pay the power bills

clear igloo
#

If you have money to throw away then just give it to me instead 😛

subtle glen
#

so that you can buy servers

waxen scroll
#

@clear igloo that feel when

clear igloo
#

lol

median ore
#

@little schooner those seats are soooo hard ... just pure wood 😐

waxen scroll
#

i tell TAC "only fix" all the time

little schooner
#

I am still figuring out how and when to sleep my server during the night without prompting me for bit locker password

waxen scroll
#

why dont you have a TPM chip

little schooner
#

@waxen scroll Hmm supermicro said I would have to buy it

#

it's a separate accessory

#

but I am thinking of switching to amd server first before buying it

#

because I will need a new board and a different supported module again

#

would the data be protected if they stole the server?

waxen scroll
#

its the same as a laptop

#

if the OS is vulnerable, they'll get the data

little schooner
#

say I enabled duo two factor login I addition to a difficult admin password

#

then if they try to break the UEFI, it should in theory lock out the drive right?

odd pasture
#

Hello, i have USB Internet connected as backup but anyhow it does not directly work if main internet goes down. Iam pretty sure a small thing could change a lot... like windows setting or smth? Thanks for your help ♥

tawny seal
#

What?

finite lagoon
#

^

#

if your network goes down what is the usb boi gonna connect to?

little schooner
#

I guess his 4G internet backup

finite lagoon
#

need more details for sure, lol

#

what's the main network, what is the USB internet? is it a wifi adapter or little 4G boi?

little schooner
#

details detayyuhls

finite lagoon
#

yos

#

g i b d e t a i l s pepeneedsafriendlyhug

subtle glen
#

hahahahahaha

pseudo blade
#

TIL: Mikrotik APs in Station mode that don't have an SSID set will connect to whatever open AP it sees first.

rocky badge
#

kek

thick minnow
#

Hey guys, sup?

glacial glacier
#

So errr. where can I get an LTE antenna? not for receiving, rather sending

little schooner
#

doesn't it do both?

glacial glacier
#

afaik not. basically I need to start a mini Telecom(LTE only) provider

subtle depot
#

Probably need to get a license for that

glacial glacier
#

Probably yes, but where do I even get the hardware?

subtle depot
#

Good question

#

Wouldn't equipment like that be basically made to order?

glacial glacier
#

Good question 😂

#

Honestly dont know

subtle depot
#

Try contacting the companies that make the components and make sure you at least have a registered business name so they take you seriously.

glacial glacier
#

I do have the business name, but what companies make them? Closest I could think of of finding that out is the Telecomproviders themselves

subtle depot
#

Sorry I have no idea. Maybe wikipedia can be of assistance. You could try climbing a cell tower and looking for logo's 😂

glacial glacier
#

If they wouldnt be fenced off, I would haha

subtle depot
#

Well good luck.

glacial glacier
#

going to need that haha

little schooner
glacial glacier
#

Oo will hve to look at that

glacial glacier
#

Apparently thats only for P2P connections 😦 mobile devices cant connect to it, and its all WiFi

subtle glen
waxen scroll
#

No need for command guide. Only Google and '?'

#

@clear igloo ...

clear igloo
#

Its still good to know basic commands 😛

waxen scroll
#

Wat

#

You'll just forget them

#

Speaking of basic commands.... BGP communities!

#

Co-worker put them in and didn't tell me

#

Found out during testing last night

#

🤔

clear igloo
#

lol

#

BGP surprises 😄

waxen scroll
#

It was over riding my local preference from another data center because I didn't put a community in

#

Had to dig deep to find it

#

Asr9k config is long and confusing

clear igloo
#

Nah, show run router bgp (AS) vrf (blah) 😄

waxen scroll
#

Wouldn't have helped

clear igloo
#

Ah, one of THOSE configs 😛

waxen scroll
#

Uh huh

clear igloo
#

Hire Blob to clean it up

waxen scroll
#

Exporting and importing routes, etc

#

Forget blob. I bet Xeon could do it

little schooner
#

that's a thick book on a concept like that

#

crazy

clear igloo
#

It's about 900 pages iirc

little schooner
#

crazy. There is a lot for me to still learn

#

😂

clear igloo
#

IS-IS is very interesting, I need to brush up on it again

#

Yah, BGP is another fun one 😃

#

Yup, and then you filter it all 😃

#

lol, I bet those calls are always fun to ignore....
I mean deal with very seriously >.>

#

Yup, need the proof at least

#

Ah, that's not too bad then

#

haha
"we were only a transit AS, please call the originator, kthx"

#

....and the origination was i O_O!!!

#

lol

#

I'm glad I don't have to deal with that
Instead I get management jumping on the call 20 minutes late asking questions about things we covered 15 minutes ago >.<*

#

Yah, thankfully the customer I deal with will just send emails for most of the questions they have but we do have weekly status calls about the various projects going on which can fluctuate a bit so the number of meetings varies throughout the year.

waxen scroll
#

i havent delt with end users in 5 years

remote kernel
#

Kind of an off topic question but does anyone have any pointers for running data cabling in an existing house?

hallow nimbus
#

Dont run it in the same pipe as ur powerlines

#

And dont hit any waterlines as ur drilling in to the wall

waxen scroll
#

and buy 4-8 boxes of 1000' cat6

#

running 8 at once speeds the job up

thick minnow
#

Working on a small business network diagram. (Not complete yet.)

#

It's for a project assignment for my college networking class.

#

I might need a little advice/tips from you guys.

#

There are 5 users in the organization. A server should be available for file sharing and a printer which should be network based. One of the rooms requires wireless connection to the network. There is a Firewall device on the perimeter and then that connects to the Internet. You must assign IP addresses, subnet masks and gateway IP address to all components that would need one.

#

I'm trying to keep this logical network topology diagram as simple as possible if I can.

waxen scroll
#

realistically, you probably would use home network equipment for this with /24 DHCP and some IP exclusions, but i cant say what the users are doing

#

the most important part is what is the user doing

#

it could be a 5 person animation shop with a render server

thick minnow
#

The project description says: A software development organization, which is planning to setup a small business network.

waxen scroll
#

yeah TBH i would use home network equipment, all in one, or similar

#

this is real world

#

your prof wont like that

#

lol

thick minnow
#

small business network?

waxen scroll
#

most small bis use a comcast modem

#

does the wifi and other shit

thick minnow
#

So what do I need to do then to the diagram?

#

Just add a gateway? Modem?

waxen scroll
#

we use these at tiny sites even

#

i dont want you to fail the assignment, but its important to note what real world is

#

do you think the prof wants a full blown broken out network?

thick minnow
#

I'm not really quite sure, he didn't really tell us what kind of LOD he wants in the topology. I assume the simpler the better. However, I am supposed to Include a written explanation of the diagram.

#

Don't worry the written explanation is on me. lol Shouldn't be too hard.

waxen scroll
#

based on what you told me, i personally would do an all in one device, keep everyone wireless if possible, put the server and printer on the wire

#

printer can also be wireless i guess

#

doesnt really matter

#

/24 for everything, no vlans

#

server and printer get static

#

@clear igloo Q?

thick minnow
#

Did you read the project desc. above? The printer should network based. The file server should be available for file sharing.

#

I assume network based means wired?

waxen scroll
#

yes

#

wired or wireless

#

both are network based

fresh copper
#

Network based means that it is not connected via USB

thick minnow
#

Yeah so in the diagram I have the printer wired in the ethernet.

waxen scroll
#

my reasoning for why i told you this is its 5 users, small site, dev work is not network intense

fresh copper
#

@thick minnow In the real world, I would use a combo router switch, maybe even the default one from the ISP. Might need an extra 8 port switch as most only have 4 ports. I would also go with 10.0.0.0/24, , router is 10.0.0.1/24, server is 10.0.0.8/24, printer is 10.0.0.9/24, rest are DHCP in range 10.0.0.128-10.0.0.254, then it is easy to add new computers or even wifi in the future.

What I would mention for your current diagram is that you assign the switch 10.0.0.0. I have two notes about this. You only need an unmanaged switch so the switch is not assigned any IP at all. Also, many devices still don't support being assigned the network IP or communicating with a device assigned the network IP. The network IP is the first IP in the subnet.

waxen scroll
#

if you think the prof wont accept that simple of an answer, you'll prob want to use that ^^^

thick minnow
#

I get your logic, I'm just trying to make sure that I do the correct thing here.

waxen scroll
#

sorry, optical isnt my strong point, pretty sure those should be negative numbers

#

do you need an attenuator? lol

thick minnow
#

You must assign IP addresses, subnet masks and gateway IP address to all components that would need one.

waxen scroll
#

yeah but theres such a thing as too much signal

#

are these long haul optics?

fresh copper
#

I would make sure to mention expandability somewhere as that network is very basic and they may need to upgrade sometime in the future, wifi would be the first thing, maybe some laptops.

#

@ancient vigil i'm not an optical guy either, I just know that it has something to do with total internal reflection.

waxen scroll
#

mux?

thick minnow
#

I'm little confused now, based on the project desc. saying I need to assign IP,Subnet Masks, and the Gateway IP. Doesn't that mean the devices are statically configured? Which In small business network would probably be ok.

waxen scroll
#

media converter?

#

amp

#

yeah i think thats a mux then

#

we have our own muxes and dark fiber at work but i never asked to be trained

#

so im a noob

fresh copper
#

Perhaps try some test data to see if it at least works

waxen scroll
#

@thick minnow you are right that means static

#

but i hope to god the computers dont go home at night

#

😂 🔫

fresh copper
#

Yea, I was saying what I would do in real life. I have no idea what you class teaches you so they may want a very formal, traditional setup rather than something more modern

thick minnow
#

So basically, I have to not use a CIDR subnet mask for my network devices, I'm using 255.255.255.240 currently. I would also have to put in an AP that is connected to the switch which is then connected to the router.

waxen scroll
#

huh?

#

255.255.255.240 is a subnet mask

#

o_o

thick minnow
#

CIDR Classes Inter Domain Routing.

#

IDK, I will work on my diagram tomorrow.

#

I need to think, take a rest.

waxen scroll
#

thats what happens when you ask people to help on your homework

thick minnow
#

I knew I would probably get varying answers. It's up to me how I want to build my diagram in the end.

#

I was just asking for some tips/input.

#

Thanks for the help guys, I appreciate it.

#

😃

fresh copper
#

You're welcome!

waxen scroll
#

its broke

#

no in

#

😄

#

@thick minnow you can impress him with BGP

fresh copper
#

That reminds me that I need to fix some of my peering connections. I lost a ton of peers recently

#

Also, my website is broken

waxen scroll
#

what do the peers do

fresh copper
#

You're the one that mentioned BGP

waxen scroll
#

i dont mean BGP terms, i mean why are you connecting to a bunch of peers whats their purpose

#

pretty sure you were running some non-work network

#

no.

unkempt crest
#

does anyone here know how to get unms working

#

it doesn't connect my ER-X

#

It see it

thick minnow
#

I’m probably making my diagram more complicated than it needs to be.
I’ll work on it more tomorrow, it’s 10:37PM ET where I am.

covert ibex
#

Any perticular reason anybody can think of why a DVR, or even my laptop won't get an IP from a router if I use a switch with mpr and dte ports in the line, but if I use literally the cheapest switch I could find, ($8 dlink switch), it works fine?..

clear igloo
#

@covert ibex What switch are you using that's causing the issue? Link?

fresh copper
#

Does it work if you configure an IP manually?

covert ibex
#

@fresh copper
No

#

@clear igloo
I'll tell you when I get to work. :p

fresh copper
#

Then maybe that switch does not work at all or is some form of managed switch that is configured incorrectly.

covert ibex
#

I don't recall it being managed, but I haven't looked at it that much.
Been fixing the work network and need 2 switches, and those are what I've got.
(They wont buy more. Cheap )

little schooner
#

@covert ibex maybe if they bought the wrong switches you can explain to them in a proposal or something why they need to purchase a new switch that better aligns with the companies needs, if the ones they bought are not doing what they initially wanted

#

but yes tell us the model when you get the chance

clear igloo
#

I don't even know of a switch with DTE ports. Like when I hear DTE I think DTE/DCE old style serial

covert ibex
#

8 port 10/100 nway switch.

#

Ns-08B

#

@little schooner
@clear igloo

clear igloo
#

WOW, that thing is OLD
Like so old there isn't any documentation in Google for it 😛

#

Like not even Alloy's own site shows anything

fresh copper
#

I would not be surprised it was just totally broken with it being so old

chrome hound
#

I bet thats not auto port sensing

fresh copper
#

Maybe it does not have auto-uplink and that was causing an issue somewhere

clear igloo
#

Yah, DTE makes me think it's some form of console port maybe or for clock signaling, maybe an early serial RJ45 port of some kind. I've never heard of MPR though and I'm not finding anything on it

fresh copper
#

Maybe it's related to multipoint relays?

#

But that would be a really weird thing to have on this switch

chrome hound
#

well a google brought up an Experts 123 page

#

MPR is where twisted pair connects and DTE is where workstation connect, so I am guessing cross over versa non cross over

covert ibex
#

So.. completely not relevant for 10 computers, some phones and a DVR?

chrome hound
#

well computer is interchangeable with network device really

stoic tendon
#

if someone could help a bit at tech support i would rly appreciate it

#

nvm

#

i found the solution

chrome hound
#

you could have a the possibility that your newer devices won't communicate at 100mb, do you get link? and that is really just pin matching up

#

for example I had an HP deskjet that only had a 10/100 card in it, my 10gb SFP to Cooper just wouldn't communicate with it, wouldn't go that slow, 1g was its min, so I had to toss in a netgear switch to use the printer on the network

covert ibex
#

Well the switch was picking up a connection to the router, and one of the pc's get a link when I plug it in, but still no data

#

Think I'm going to convince them to spend pocket change and buy some cheapo switches.

chrome hound
#

and you are not plugging in a cable to both DTE and MPR ports right?

covert ibex
#

Nope.

chrome hound
#

you can only use one of them

#

tbh yoru far better off to get something gig capable

covert ibex
#

Nothings been upgraded on this network in like 15 years

#

The "server" was running Windows 98 until I convinced them to upgrade it.

bright forge
#

trying to port forward a tcp port, and when i do, it doesnt seem to be working

covert ibex
#

@bright forge
Something bound to the port?

bright forge
#

its for this thing called Remotr

little schooner
#

@covert ibex so it might be that, just a very very old switch that needs replacing

bright forge
#

and to use it on a non local wifi your suppost to forward TCP port 8193

little schooner
#

older that it doesn't work with the new network connections your work has in place now

bright forge
#

i have a static ip and whatnot and i think i did it right too

#

this is how it should look like when port forwarding a single tcp port right?

stable spear
#

Yep

bright forge
#

idk why its not working

#

do i need to make a special rule for it in my firewall by chance?

little schooner
#

@bright forge no, did you try restarting the router to see if the rule will then take effect?

#

device ip should be the computer in your local network

#

your device should also have a firewall rule that opens said forwarded port, if it uses one

bright forge
#

okeh

eternal current
#

Weird question: Does anyone know if chromebooks have any packet analyzing software on them

#

Built in

fresh copper
#

If you have linux installed and enabled, it might come with some default tools like tcpdump but I am unsure. Other than that, I am not aware of anything built in. There is not a lot that can be done without installing new things

eternal current
#

I see, thanks for your helpm

#

.

unreal wedge
#

@bright forge Linksys ew

waxen scroll
#

even the mod is shitposting

unreal wedge
#

@waxen scroll banHammer

#

Was speaking with the ISP tech yesterday. He came to test our speed because he'd opened it up to 250Mb/s. Unfortunately, we were seeing 50Mb/s. After several hours of troubleshooting, it was our fucking Linksys router, which decided to cap itself, even after several reboots. Had to factory reset the fucker. Ended up replacing it last night either way.

waxen scroll
#

i could have told you that

unreal wedge
#

Yeah, right.

waxen scroll
#

had the same problem years ago

unreal wedge
#

It's not an old router.

little schooner
#

Linksys, linking to new problems

unreal wedge
#

Linksys used to be reliable, then they sold out to Belkin.

waxen scroll
#

i hope pol did his homework

little schooner
#

I wish there were ways to somehow achieve faster upload speeds for file sending without having to buy an expensive line

#

Its not like I can use a cloud VM because they will charge me money to use its resources to create vm, export it out and then time to send it to the destination

#

if only a line could be fooled into uploading faster :(

thick minnow
#

Still working on my project, I have until the 25th to submit it to my professor.

#

I’m not going to procrastinate though, I also have my programming 1 homework to do as well.

#

That moment when you join a channel and see 400+ messages. Pogey

#

It’s not surprising though, since this is a public Discord server.

little schooner
#

seriously, I dont like doing full time for school its so annoying

#

i hate going in 4 days a week because classes were already packed by the 2 day them being available

#

My networking courses were never selected like that

#

I miss networking...

thick minnow
#

It’s not surprising though, since this is a public Discord server.

covert ibex
#

@little schooner @clear igloo
All good now.
I convinced them to upgrade to NBN with wireless backup, so in turn, whole network is getting upgraded from 10/100 to 100/1000 as well as switches, PCI cards and new server.

20 years of no upgrades was apparently killing the office staff.

hallow nimbus
#

😂 😂

hardy kestrel
#

I have no Ethernet Wall thingy in my TV room and I the motherboard on my HTPC has no WiFi

pine panther
#

Anyone got 10gigabit internet yet

thick minnow
#

Linus does.

#

lmao

clear igloo
#

I've got 10Gigabit intranet 😄

waxen scroll
#

I don't

#

No need

#

I have 4x10G at work

median ore
hallow nimbus
#

👀

#

💦 💦 💦 💦

median ore
#

And they don't use them 🙂

#

But I can't take them 😐😐😐 and have fun all night in my house

clear igloo
#

@median ore If those are early gen 2950 servers then they are STUPID loud even at idle

thick minnow
#

Dell Power Edge R200 with Intel Xeon inside.

#

At least, that’s what I think I saw in the image.

#

The three bottom ones are 2950’s

median ore
#

@clear igloo why that ?

#

Yup there is Xeon but don't ask which ones 😅

clear igloo
#

The R200 isn't too bad but I had a 2950 and I could hear that thing downstairs when it was upstairs inside a closet with the door closed and sound dampening foam inside the closet

median ore
#

Well ... maybe just replace fans with quieter ones ?

clear igloo
#

You can't, they use proprietary connectors

median ore
#

For each version ? If you buy the same brand they should fit ?

carmine moss
#

It's probably better to buy a cheap server then hope you can get those as you can get more modern machines for cheap and they use less power

clear igloo
#

There aren't replacements, there is 1 model for the 2950 and that's it. You don't have "quiet" versions

#

Besides, as @carmine moss said, they suck up a ton of power. One will pull ~300 watts or so at idle iirc wheras a new server like the R620 is quieter and sips power by comparison, only hitting about 200 watts at about 50% load with more powerful CPUs inside

median ore
#

oh but they aren't cheap right ?

clear igloo
#

Depends but you can pick up an R620 with decent CPUs and RAM for about $400 to $500 on ebay

median ore
#

do you have any link ? the one i find are way more than 500

#

they are 1u ... aren't they louder than 2 or 4u ones ?

clear igloo
#

Compared to the 2950, no

#

I've got two running now in my closet and with the door closed I sleep without ever hearing them

median ore
#

hum ... yes ... so i think i will need to turn my server off over night if i want to sleep

chrome hound
#

@pine panther I have had 10gb for about 6 months now, will never go back

#

wait its been longer than that almost a 10 months

#

the hardest part about it is finding a speed test server that can really test at 10gb speeds

fresh copper
#

One of my servers has 10G but I have yet to figure out a way to actually generate that much traffic with it.

#

No local SpeedTest server is that fast

#

Maybe HE’s Iperf Server

little schooner
#

finding two 10G equipped servers over the internet sounds expensive

waxen scroll
#

I have an R710 and even that is going end of support for esxi

#

No way those other servers are supported

covert ibex
#

Cant DL a torrent with the most seeds and see what happens?

thick minnow
#

Ok so, in my diagram I'm using a Class C IPv4 Addressing. My router has an IP of 192.168.0.1 and a subnet mask of 255.255.255.224.

#

Do I need to add a gateway IP to my router? I would think not. Also since the network address is going to be 192.168.0.0 what do I assign to the switch?

rocky badge
#

those PE 2950s

#

OOOOOF

thick minnow
#

I really don't understand why I'm struggling so much which something that should be so simple.

#

It's literally 5 Desktop PC's(Wired) 1 File Server(Wired) and 1 Printer(Wired) and finally one wireless AP that connects to the network, and all that connect to the internet.

subtle glen
#

don't you assign the switch a random IP of your choice?

thick minnow
#

Because that wouldn't make sense. The devices on the local wired network need to be able to communicate to the router.

#

I can't just assign the switch an IP of 192.168.0.0 because that is the network address.(The physical network cable address that goes to the switch.)

subtle glen
#

is the router connected to a modem/media converter/ONT or something?

covert ibex
#

@thick minnow
Start from the start..

  1. Connection to internet happens where?
thick minnow
#

No, I'm supposed to have a firewall in the diagram that connects to the internet.

#

There are 5 users in the organization. A server should be available for file sharing and a printer which should be network based. One of the rooms requires wireless connection to the network. There is a Firewall device on the perimeter and then that connects to the Internet. You must assign IP addresses, subnet masks and gateway IP address to all components that would need one.

covert ibex
#

Why that subnet mask?

thick minnow
#
IP Address: 192.168.0.1
Network Address:    192.168.0.0
Usable Host IP Range:    192.168.0.1 - 192.168.0.30
Broadcast Address:    192.168.0.31
Total Number of Hosts:    32
Number of Usable Hosts:    30
Subnet Mask: 255.255.255.224
#

cidr mask /27

#

Does the router even need a subnet mask?

subtle glen
#

i specified a subnet when i configured my router, so i would say yes xD

thick minnow
#

So the one I have is ok?

subtle glen
thick minnow
#

So the router needs that, ok got it.

#

Except in my case it's 192.168.0.1/27

subtle glen
#

yep

covert ibex
#

If you have an internet connection through a firewall, why the router?

thick minnow
#

The diagram asks for a firewall

#

that firewall is hooked up the internet

subtle glen
#

the problem is that you don't have internet on the devices, right?

thick minnow
#

according to the instructions that I posted above.

#

This diagram is for a college homework project

subtle glen
#

as a gateway IP i would think of the IP of the modem or whatever interacts to the ISP internet connection

thick minnow
#

I figured I'd ask you guys from some help since you guys know a lot about this stuff.

subtle glen
#

there's definitely people in here that can help you 😄

thick minnow
#

I just feel so anxious right now because I just want to get this stupid diagram done and sent for grading to my professor but I can't because I'm not quite sure what is the simplest way of creating this diagram while making sense.

#

I feel very ashamed of myself for struggling on this very simple shit that is very difficult for me to figure out.

clear igloo
#

Why not just add a cloud, connect it to the firewall, and assign the firewall and cloud an IP address from a /30 network. Then you have your internal network gateway on the firewall or router, a /30 link between the two as well, and then a /28,/27, or /whatever for the internal subnet

#

If you REALLY want to show off you could use a /31 for the point to point links from router -- firewall and firewall -- cloud but it's not needed in this case

thick minnow
#

I want simple as possible, so : Cloud>Firewall(Assign the Firewall an IP?)>Gateway>Router>Switch(AP connected to Switch?)>Wired Network.

clear igloo
#

Cloud > Firewall > Router > Switch > AP and clients
Cloud > Firewall = /30
Firewall > router = /30
Router > Switch = Nothing
Router = Gateway + Subnet Mask
AP and each client = An IP in the subnet + Subnet Mask

#

Call the switch Layer 2 and don't put an IP on it

#

Or Router > Switch = /30
Gateway goes on the SVI on the switch then

covert ibex
#

So... Firewall - switch - Lan/wlan
Managed switch covers router config

Firewall - pfsence 1100
Switch - TL-SG116
Wireless network - Asus BRT-AC828

Rest you should be able to fill in.

thick minnow
#

Ok, I think I got it?

#

What do you mean by /30?

#

The CIDR is /27?

clear igloo
#

You use a different /30 network for each of the point to point links

thick minnow
#

I'm not hooking up multiple routers or routes here.

clear igloo
#

How are you going to route from Switch > Router > Firewall > Cloud then?

median ore
#

@rocky badge what does "OOOOF" mean 🤔

rocky badge
#

PowerEdge 2950 succc

#

Big succc

clear igloo
#

You need routed links since the router > firewall and firewall > cloud link is not going to be Layer 2, it's Layer 3

thick minnow
#

I understand what you're saying but the address of the connection between the Switch and Router would 192.168.0.0 as that is the network address yes?

median ore
#

@rocky badge oh ok

thick minnow
#

Are you saying that I should be using a different addressing scheme? The devices on the wired ethernet network are using a Class C CIDR addressing scheme.

clear igloo
#

What's the full address space you were given to use for this assignment?

thick minnow
#

I wasn't given one.

#

It just says: "You must assign IP address, Subnet Masks, and Gateway IP's to all devices that would need one."

clear igloo
#

Then do:
Cloud <----> Firewall
Cloud = 1.1.1.1/30
Firewall = 1.1.1.2/30

Firewall <----> Router
Firewall = 192.168.0.1/30
Router = 192.168.0.2/30

Router <----> Switch
Router = 192.168.1.1/24 (It would have a sub-interface to the switch which would have a trunk interface going to the router)
AP = 192.168.1.2/24 with a gateway of the router

thick minnow
#

Ok, but again there are no wireless devices on the network. It's all wired. The AP is there incase you just need to use it.

#

I just want simple answers man, I don't understand why such a small little network needs to be so complex.

#

Why can't it just be Ethernet Network>Switch>Gateway>Firewall>Internet?

#

and just have the AP connected to the Gateway?

clear igloo
#

Gateway is a term, not a device. You connect the AP to a switch

#

Sure a gateway can be equal to a router but that's what I just put up there

thick minnow
#

Why does the cloud have an IP address?

clear igloo
#

It's your ISP, you have a link from you to the ISP, you need an IP address to communicate between you and the ISP

thick minnow
#

Ah ok.

#

Instead of using 192.168.1.1/24 for the Router couldn't I just use 192.168.0.1/27 instead?

#

It would be a total of 30 host devices on that network address of 192.168.0.0

rocky badge
clear igloo
#

You can, yes, would just have to change the firewall <----> router to 1.1 and 1.2 instead

#

@rocky badge hush, it's all examples to help

#

😛

rocky badge
#

lel

thick minnow
#

Thanks for the help guys, I'll just do the best I can.

rocky badge
clear igloo
#

The reason you cannot have overlapping addresses on the point to point links comes down to subnetting itself, you can't have overlapping subnets on two different L3 interfaces

#

I mean, I could go into why and how you can do that, but that's not keeping it simple 😛

thick minnow
#

So what should the Firewall and Router address be again?

clear igloo
#

192.168.1.1/30 and 192.168.1.2/30

thick minnow
#

Ok got it.

#

So that 1.1.1.2 for that Firewall is the public IP yes?

clear igloo
#

yes

thick minnow
#

Ok

clear igloo
#

Yup, perfect

thick minnow
#

What about the connection to the router from the firewall should that also use a bolt?

clear igloo
#

you can, yah

thick minnow
#

k

waxen scroll
#

dat homework

thick minnow
#

Firewall <----> Router
Firewall = 192.168.0.1/30
Router = 192.168.0.2/30

Router <----> Switch
Router = 192.168.1.1/24

Why does it go from /30 to /24?

#

Do i need to add a second router?

waxen scroll
#

tell us why you think it shouldnt go to /24 first

rocky badge
#

lul

waxen scroll
#

not now blob

rocky badge
#

:(

thick minnow
#

/24 is ok. It's the default class C for private internal addressing right?

#

But what doe it mean from /30 to /24?

waxen scroll
#

it means nothing o_o

#

thats how routing works

#

@clear igloo you did a bad job at splainin

thick minnow
#

I get that the firewall needs an internal IP and the router as well. But if they're addressing the 192.168.0.1/30 and 192.168.0.3/30 respectively. Then why/how does it change to 192.168.1.1/24 for the router again?

waxen scroll
#

the router and firewall only need two addresses in your diagram to pass traffic between them. so in order not to be wasteful you use a /30... or even better a /31

#

you can run out of private space, so you dont want /24 on everything

thick minnow
#

So then everything internal uses /30 as the subnet mask?

#

Correct?

waxen scroll
#

if you have a direct link between two devices, its preferred to use /30 or /31

thick minnow
#

When you say direct you mean that bolt thing?

waxen scroll
#

yes

thick minnow
#

That uses /30 or 31?

waxen scroll
#

yes

#

were you taught routing yet?

thick minnow
#

Yes

waxen scroll
#

so you should understand why it has to be that way... next hop and all

thick minnow
#

But it's just that I didn't know you had to use a different routing subnet mask for public.

#

Is that because of PAT?

waxen scroll
#

you dont, but in the real world you need to save IP space

#

its highly unlikely you'll use anything higher than /30 or /31 (2 IPs) with a connection like that

#

you can use /24 if you really want

#

NAT/PAT is a whole other topic

thick minnow
#

Since I already have my diagram using /30 for ISP, Firewall, and Router I'll just keep it as is.

waxen scroll
#

yep

#

if only two devices can be connected on the one wire, thats what you do

#

if you want to add a switch in between for more routers and firewalls, thats when you go into /29

thick minnow
#

So I should address my switch the 192.168.1.1/24?

#

Should all be good?

waxen scroll
#

you dont address the switch at all technically.... you do in more advanced networks. 192.168.1.1/24 belongs to the router interface thats plugged into the switch

thick minnow
#

But in class my professor said that you can assign a switch an IP address?...

waxen scroll
#

you can for management reasons, but in your network the switch isnt participating in routing

thick minnow
#

So I don't need to assign the switch an IP in my network?

waxen scroll
#

not unless you want to manage it with SSH

#

if you want to manage it, perhaps .2

thick minnow
#

So what do I do then.

#

Just label it as Switch and that it?

waxen scroll
#

yep

thick minnow
#

Ok then.

waxen scroll
#

that powerpoint you linked us is exactly how it works for networking 101

clear igloo
#

@waxen scroll I'm usually not the best at splaining 😛

waxen scroll
#

should we tell him that most of my datacenter is using switches for routers

#

lol

clear igloo
#

Haha, I'll let you handle that for now 😛

waxen scroll
#

nah fam

#

tell him about vPC, VDC, VRFs

#

my one switch is actually 6 switches

clear igloo
#

vPC is when you love someone and someone else loves someone and you both love them together.
VDC is when you hate someone and divide them up
VRFs are when you hate yourself, everyone else, and want to not talk but still have to be near them

waxen scroll
#

is that a copypasta?

clear igloo
#

Nope

waxen scroll
#

nice job

#

i made a new tenant in our lab ACI today

#

no scripts. by hand

#

it was UGH

little schooner
#

My previous teacher wanted to keep his lab easy to manage so he asked for class c 192.168.1.0 network

clear igloo
#

Haha, what version are you on? 3.x or 4.x?

little schooner
#

I touched aci a little bit but just the theory on it @waxen scroll

#

the ACL simulation is nice

#

the mapping of network devices too. is good

waxen scroll
#

i havent been paying attention to the version, so dunno

little schooner
#

The same teacher requested to make an VM that has nested 2012 R2 VMs running in it

clear igloo
#

Ah, if it looks like crap then it's 2.x or less crap then 3.x but if it looks new and modern then it's probably 4.0

little schooner
#

it's possible but ram was like 9GB and 70GB storage

waxen scroll
#

it looks modern

little schooner
#

modern idrac is pretty too

#

modern like that is nice to play with

clear igloo
#

Nah, Java 1.6 is best 😄

waxen scroll
#

so i made all my shit, i didnt config from scratch, we have spine and leafs all configured... so now i need to build two VMs and run some cable to the host so i can test various things

#

its dizzy... the amount of things on the side you have to create and then link together

little schooner
#

yes it's a dizzying setup

clear igloo
#

Yah, my customer hasn't moved to ACI yet. They're just rolling out VxLAN eVPN now but I wouldn't be surprised if they made the jump in another year or so

thick minnow
clear igloo
#

They think they'll manage 500+ switches manually without any scripts, controllers, etc. XD

waxen scroll
#

my work does ghetto management too

clear igloo
#

Looks good @thick minnow

waxen scroll
#

old tools, etc

#

new tools just dont scale well and the licensing is outrageous

clear igloo
#

I understand classic LAN setups but when you need to have VLANs extended everywhere you need something, be it some crappy scripts or something to manage and deploy that stuff

waxen scroll
#

we have like 40,000 network devices

clear igloo
#

Do you use excel sheets for your config templates >.>

waxen scroll
#

yep

clear igloo
#

Haha, keeping it old school 😃

waxen scroll
#

for small deployments we do

#

we have a system to push large ones, but our stuff isnt standardized well

thick minnow
#

Do I assign anything to the Switch in my diagram? Because I'm supposed to write an explanation of my project as part of my assignment. What do I say about the switch?

waxen scroll
#

it only works in some chunks of network

clear igloo
#

You can say it's a layer 2 switch, it's just switching packets, the L3 gateway lives off a trunk port connected to the router

#

router on a stick 😃

thick minnow
#

I don't have a gateway in my diagram.

clear igloo
#

The gateway is the router's interface facing the LAN

waxen scroll
#

the company is so large that its not feasible to launch a standardization program because shittons of money will be needed and we would need to increase contractors

thick minnow
#

I also don't have any trunking ports/labels on my diagram do I need them?

clear igloo
#

@waxen scroll Money is always that factor that holds a lot of things back 😦

#

@thick minnow If you want to put them in, you can, but for just a simple setup I don't think you need to put it in there. Can call it VLAN 1 or VLAN 900, doesn't matter much in this case

thick minnow
#

Create a diagram showing the network and label all components and their IP addresses.

#

Well, in this case I'm not going to.

#

I'm trying to keep it as simple as possible here.

waxen scroll
#

built you a diagram

thick minnow
#

Uhh