#networking

1 messages ยท Page 156 of 1

pseudo blade
#

Could be for a smartboard, but even then I'd want it offset.

pseudo blade
#

loopback plug on 40km optics Crispy.

unreal wedge
#

@thick minnow ๐Ÿ‘€

thick minnow
#

@unreal wedge Sup?

little schooner
#

@pseudo blade is there such thing as an affordable 24 rj45 port, full poe af/at with 2 or 4 sfp+?

hollow marlin
#

@little schooner Mikrotik CRS328-24p4s

little schooner
#

@hollow marlin thanks. I'm happy it is all wire speed too

#

That's like awesome

#

I noticed it mentions sending power on the B pins. What is that supposed to mean?

#

That it doesn't support type A devices?

#

Or that doesn't matter as long as the device itself supports the true 802.3af/at?

hollow marlin
#

It's all after negotiation. Auto MDI-x will handle type A/b then PoE takes it's turn

little schooner
#

Alright thanks @hollow marlin

hollow marlin
#

No probs

outer nexus
#

Can someone tell me if it is these squares or one up i am supposed to use... 1 of 3 parts wont fit this way, rest fit perfectly... :/

clear igloo
#

It's every 3 = 1 RU so if it's like that then it's correct

hollow marlin
#

Also make sure they are spaced every 3 from the top. There are spacing differences throughout. This could lead to alignment issues too

outer nexus
#

Thanks both. Will take it apart again. Hopefully getting it right 3rd time ๐Ÿ˜„

clear igloo
#

One thing I found out when I did my rack, getting the screw holes in when the tabs went up down was much harder than if they went left right, just something to try if you have issues with yours ๐Ÿ˜ƒ

hollow marlin
#

@clear igloo I still want an explanation on why that is true. Perfect squares and they plop in so easily left to right.

outer nexus
#

@clear igloo ... that fixed the new issue ๐Ÿ˜„ It doesnt fit when they are up / down ๐Ÿ˜„

#

best place to get help is here ๐Ÿ˜„ โค

clear igloo
#

That's bizarre that it doesn't fit that way but it works so yay ๐Ÿ˜„

#

@hollow marlin Yah, I've always been puzzled by that, I wonder if it's because the nut shifts a bit and gets in the way of the tab bending back as easy

outer nexus
#

They small metal part hits ot one above here when they where up/down. Making the screws go in at an angle.

#

everything moved in minutes. So much easier now ๐Ÿ˜›

clear igloo
#

Nice!

outer nexus
hollow marlin
#

Looking good. What switches?

outer nexus
#

D-Link DGS-1100-08P Smart Switch PoE and a Linksys LGS105

The Dlink is not the one i wanted, but ordered wrong one (Too many tabs opened so i clicked the wrong one) ๐Ÿ˜„ and the linksys is just extra. @hollow marlin

green sphinx
green sphinx
#

I mean, I don't even want to do cable management like that. Sure I want to keep check if what cable goes where etc but I don't want to zip tie it etc for example when adding a Ethernet cable or removing one

outer nexus
#

@green sphinx You could use the fabric style "zip ties" , then you can reuse them when adding more cables ๐Ÿ˜ƒ

green sphinx
#

Oh yeah, but should I really just hide the cables? Can't I just show them but sort them better etc?

covert ibex
#

4 cisco 1841 routers for $150.
Good/bad?

#

@green sphinx
Could use something like this, and flex self sealing wraps to run above the sideskirts.
Wouldnt look bad.
Chuck some led lines to space them and it'll look sick for home.

fresh copper
#

I like those

covert ibex
#

Can't decide if I wanna visually and properly hardware setup my home network, or demolish my house, build a new one and dedicate a room for server stuff, fiber the house and be done with it..

vast coral
#

Hey Guys,

I'm trying to pass port 9091 over my PIA VPN instance, but for some reason, I can't get it to route traffic from that port over the VPN.

I've tried creating an alias, and passing that through a lan rule with the gateway set as the VPN but it just won't happen.

Could someone please guide me, or link me to an article which I could follow. My google-fu is not helping, as all the articles show how to route entire IP over the VPN, and not just the specific port from an IP.

#

Im using pfsense, since I forgot to mention it above

thick minnow
#

nice pfsense is great

#

took like 5min to setup ipsec

vast coral
#

Yeah, it's pretty good

#

But this one thing has gotten me stuck

#

I'm not pfsense master, but I thought it would simple enough. Guess I was wrong

outer nexus
#

@naive meadow ๐Ÿ˜ฎ

naive meadow
#

sorry just saw it contained private info

outer nexus
#

did it?

naive meadow
#

like where I live

outer nexus
#

ah

hallow nimbus
#

That aint no problem to share here ๐Ÿ˜‚ ๐Ÿ˜‚

outer nexus
#

๐Ÿ˜›

clear igloo
#

@covert ibex If you can get them for less, I would try to pay no more than $100 for 4 of them

pine panther
#

my question is whats consiedered a fine line between good and bad internet

#

id say between 30mbps down 5-10up and 50mbps down and 10up

#

since mine is 20 down and 1 up its big big big shit

hollow marlin
#

@pine panther 30 is the border line and 100 is the sweet spot as 99% of people never sustain even 100mbps.

steady loom
#

@vast coral You just want to route traffic for the remote network over the vpn right? not all internet traffic of the client?

pseudo blade
#

@covert ibex 1841's throughput is pretty trash (~40mbps/75kpps with 64 byte packets and literally no features in use, even NAT) and Cisco have obsoleted them.

#

At work they seem to handle our 50mbps NAT, VLANs and ACLs with real-world use (it's kinda pushing it, so I couldn't recommend them for anything faster), and their lack of support makes them a hard sell for training also.

vast coral
#

@steady loom yes, thats exactly what i wanted to do

#

i pretty much gave up on that, and just got the transmission-vpn docker file

steady loom
#

That's called "split tunneling"

vast coral
#

but im wondering how i could have done it throiugh pfsense

steady loom
#

it's pretty easy to set up

#

I haven't setup openvpn through pfsense, but basically for split tunelling you make sure that the redirect-gateway line isn't in the server config.

and then with the server config you push your lan as a route

#

and then the client will be able to talk to the remote lan through the tunnel

vast coral
#

but wouldnt that route all traffic from that IP over the said route?

naive meadow
#

my best speeds for up and down each on a different test are 493.46 down and 444.07 up

#

wireless

agile verge
#

Hey guys, I don't know where else to ask this since I'm a tech noob so

#

Can anyone help me out with a hosting solution for wordpress
Reading tons of negative reviews about bluehost and am really confused what to go with, since it's my first time creating a website

#

I'm a student so the hosting services which don't cost a fortune would be appreciated since this is just a side project

radiant shell
#

@agile verge It depends on what you are using wordpress for

agile verge
#

It's basically for educational purposes as in helping with what school you wanna go to

radiant shell
#

so you are wanting it as a static website and not a blog?

agile verge
#

Sorry but irdk what's the difference between them

radiant shell
#

Static: homepage with menu bar to take you to different sections/pages
Blog: typically one page with links to stories/entries

agile verge
#

I think it'd be a lil more comprehensive

#

kinda like makemytrip's interface

radiant shell
#

that would be considered a static website

agile verge
#

ohk then

radiant shell
agile verge
#

nah def not a blog

radiant shell
#

generally for wordpress hosting it just comes down to the amount of storage and traffic you need. personally i have used namecheap in the past without any problems

agile verge
#

This would be a new website altogether, so I assume not many people would come through as first

#

Does namecheap give you host with domain too?

radiant shell
#

if you go shared hosting they give you a free .website domain

#

it just comes down to the features for small websites majority of hosts will be fine

agile verge
#

Does that fall under the EIG group or should I just stay away from all hosting services under EIG

radiant shell
#

tbh ive never used any of the hosts under the EIG group ive used Domain.com and namecheap both without any issues before which i currently have 7 domains between them. the problem is no matter who you go with to a degree. the average person/site will all be fine. when you start getting to a 1,000+ viewers a day then you start to worry about the host a little more

#

scratch that domain.com is in the group so yes i have but i dont notice it

agile verge
#

oooh

#

someone recommended siteground to me for this too

#

Anyway, thanks for all the help man really appreciate it

radiant shell
#

yea for the size your site just find a cheap host with good features that looks respectable

agile verge
#

Will do

covert ibex
#

Or rent an Indian VM for $2 a month, and a DNS name for $30 a year, and host your own. :P

radiant shell
#

^ thats one way to learn

pseudo blade
#

Amazon Lightsail starts at $3.50/month and is quite good if you can handle patching your own Wordpress box, technical people might find lowendbox deals interesting, but if so caveat emptor applies, do your own research.

#

Alternatively, Wordpress themselves offer hosting.

agile verge
#

think domain from godaddy and siteground would prolly work fine tho lets see

glacial glacier
#

For my wordpress site, I use XAMPP on a Ubuntu server, a domain purchased from Cloudflare

#

On xampp I have the MySQL and Apache module enabled

radiant shell
#

i never realised how many radio towers there actually are around my area, they blend in really well

pseudo blade
#

@agile verge Most people who would consider managed Wordpress aren't super technical and the service is more performant than many of the dodgier hosts out there.

#

And I'd rather someone use Wordpress.com than spin up/get provided yet another unpatched/secured instance to have hacked later.

agile verge
#

ohk thanks for the info

pseudo blade
#

If you know your stuff host your own.

agile verge
#

are namecheap and siteground considered in the dodgier hosts

#

nah I'm just starting out so don't have much know how

pseudo blade
#

Namecheap are good for domain hosting, I know little of Siteground.

#

My stuff all lives in AWS.

agile verge
#

ah amz

pseudo blade
#

I use static hosting wherever possible for performance, cost and maintenance reasons, but none of my stuff needs to look pretty.

little schooner
#

@pseudo blade static hosting meaning its not dynamic ip and stuff?

remote kernel
#

I am considering going with UniFi cat6 cable

#

Am i losing much using cat6 instead of cat6a?

#

Ive read cat6a is much harder to install

covert ibex
#

Just takes a little bit longer that's all.
@remote kernel
Not really a difference under around 30m lines if I remember

#

@little schooner
Yes.

remote kernel
#

so would you go cat6 utp or cat6a s/ftp?

covert ibex
#

Well if you have heavy interference, shielded. Otherwise, unshielded is fine.

thick minnow
#

Who can help me with a networking problem?

ornate jungle
#

Many people are plenty capable of helping, however, it's better to actually be specific about your question or inquiry so we know what we're helping with in case it something out of our support scope. Can you clarify?

pine panther
#

okay how braindead are u actually @thick minnow

thick minnow
#

uh, really

#

Thanks for asking

#

Anyway, I need help with VDSL.

pine panther
#

it was said so many times even a dog would remmember it specify a damn problem..

thick minnow
#

I just did

ornate jungle
#

k.... c'mon now. letsa be nice-sa. What about VDSL do you need help with?

thick minnow
#

Okay, so we just upgraded to VDSL last week and I have noticed that download speed is actually worse than what it was with ADSL. (Also, I can't get fibre down my street)

#

So I was wondering, isn't VDSL meant to be faster than ADSL?

#

And please, dumb the answer down a bit so I understand

ornate jungle
#

Apparently, it is according to Wikipedia https://en.wikipedia.org/wiki/VDSL

Very high speed digital subscriber line (VDSL) and very high speed digital subscriber line 2 (VDSL2) are digital subscriber line (DSL) technologies providing data transmission faster than asymmetric digital subscriber line (ADSL).
VDSL offers speeds of up to 52 Mbit/s downstr...

pine panther
#

probably a ISP problem

#

contact them

ornate jungle
#

Unfortunately, I know little of DSL because I only accept FTTP or DOCSIS 3.1 compatible modems. All other modems are burned on site in my house.

thick minnow
#

Yeah I got 10mbs on ADSL and I get 9mbs on VDSL.

pine panther
#

thast still pretty bad lol

ornate jungle
#

Agreed, I would be contacting your ISPs support department to have them check things remotely, especially if your DSL equipment has changed, and verify speeds. However, when you upgraded to VDSL, did you speed plan change? And what speed are you supposedly paying for?

pine panther
#

mines really bad and its 20mbps and im upgrading to 30mbps

#

resolve it with contacting ISP and see what can they do

thick minnow
#

The speed wasn't specific, only that it was unlimited data usage

#

On Ethernet the speed is 20mbs

ornate jungle
#

So... your ISP doesn't even tell you the "up to" speed you're paying for or....? Oh, so it's possibly a WiFi related problem then - don't test speeds over WiFi to find out your line speed. Always ethernet.

thick minnow
#

I have

#

It's still somehow slower

#

20mbps ADSL, Close to 20 Mbps VDSL

#

And that's with a 'super speed' modem.

ornate jungle
#

Gotcha, so yeah first steps are find out what speeds your plan offers you, and keep in mind these are always advertised as "up to" this amount. If your plan hasn't changed, then there's no reason for your modem to receive a higher provisioned speed rating just because it's been upgraded to VDSL.

thick minnow
#

Okay

#

Let me check

ornate jungle
#

That would be like all the old people around here paying for 15mbps down from the old DOCSIS 1.x days suddenly expecting to receive 150mbps down for free just because the ISP gave them a DOCSIS 3.0 modem.... that's not how that works. Speed increases can be sold for profit so....

#

Who's your ISP?

thick minnow
#

Telstra Australia

#

They don't tell you a lot about the speed.

ornate jungle
#

Ah, alrighty, let me just get my running boots because I'm nope.jpg-ing right out of this conversation now. /s But really.... from everything I hear, unless you live in a highly populated area where Cable or FTTP is available, AUS has shit internet because nbnโ„ข network is "best" network. ๐Ÿ˜ฆ

#

Do you know if you're on the nbnโ„ข network, or actual xDSL?

thick minnow
#

Uh

#

nbn I think

#

Sorry

#

Not VDSL

#

Im really sorry

#

I thought it was

#

I don't know a lot about internet.

ornate jungle
#

no no its fine. I've seen some of the shit that AUS ISPs advertise as their "marketing" materials down there - they REALLY DO INDEED not want people knowing jack about how the connection comes to their home, because they know they can't even come close to advertised speeds in many cases.

thick minnow
#

I live in Melbourne

#

By the way

ornate jungle
#

Go here and click on More about nbnโ„ข speeds then scroll down and click on the links under the Got a question? See our FAQs text, then call your ISP and ask to have them run speedtests with you to determine a baseline speed, then ask them to either improve it or switch ISPs.... although other ISPs will be limited by the same nbnโ„ข network most likely. https://www.telstra.com.au/internet

thick minnow
#

Okay

#

Wow that is slow

#

So there's no VDSL in AU?

#

At all?

ornate jungle
#

No idea, I don't live there, you'd want to check with Telstra to confirm the exact service they're supposedly providing.

thick minnow
#

Oh...

#

Sorry

#

Are you in USA?

ornate jungle
#

I will say this is pretty damn awesome though:
Your Smart Modem switches to the 4G mobile network if there's an internet dropout.

#

Wish we had that in western Canada, but alas, we don't.

thick minnow
#

Yeah I have noticed that.

#

Oh.. Canada...

#

Okay

#

Thank you for your help

ornate jungle
thick minnow
#

Okay

ornate jungle
#

I'ma go sleepy now because its 230am ๐Ÿ˜› Hopefully they can get you sorted out.

thick minnow
#

Okay

#

Thank you

#

My friend in NZ gets 5gb a second lol

#

And compared to me

#

Oof

covert ibex
#

@thick minnow
Aus has xdsl, with 4g backup as the fastest public plans available.

Fastest home connections are 78mbps down - 30mbps upload.

pseudo blade
#

Wh-5gbps? I assume your firstborn gets you your first week paid for?

hollow marlin
#

I would assume the 5gig is his work's connection?

clear igloo
#

I've got 5gig connections......
To my APs ๐Ÿ˜„

hollow marlin
#

With the Catalyst 9k?

clear igloo
#

Yah, lol

hollow marlin
#

I really want to get my hands on a 9300 or 9500 for testing...and the new fancy pants APs

clear igloo
#

Yah, I don't get my Catalyst 9100 APs until mid-June ๐Ÿ˜ฆ

#

I'm wondering if I'll be doing any Catalyst 9600 testing or if the customer I deal with will pass on those. I doubt they'll go that route though but never know if they'll have a need somewhere

hollow marlin
#

@@clear igloo Do you work at a VAR ?

clear igloo
#

I do not

thick minnow
#

Good day everyone, how are you all doing?

clear igloo
#

Good, how about you?

thick minnow
#

Decent, finals are fast approaching.

#

I have to brush up on previous course textbook chapters and course materials.

#

news โ„ข

clear igloo
#

Fun

deft pasture
#

would spanning-tree bpdugaurd enable shut the port if an AP was plugged in to it?

#

I'm on a cisco switch

#

I would hate to ping anthony but I feel like he would know

clear igloo
#

Yes, I believe it will until the AP gets it's image from the controller

deft pasture
#

The only reason I'm asking is because at my propery I manage I didn't set up the switches. One of them allowed me to hook up a crappy linksys in AP mode while the other immediately shut the port. Comparing both configs I see that bpduguard is the only thing enabled differently

#

I thought it had something to do with port-security

clear igloo
#

Yah, if the AP is spending out BPDUs then it will shut down. Depends on the device but if I remember correctly most APs will (or should) send out a BPDU at least until configured otherwise

deft pasture
#

so if i remove that line from the interface it shouldn't have an issue with future AP's being hooked up?

clear igloo
#

Correct

deft pasture
#

thank you!

remote kernel
#

So i found a dell powervault on ebay

#

What do i need to use it?

#

And do dell servers have sas ports

clear igloo
#

Depends on the model @remote kernel

remote kernel
#

Its a MD1000

#

@clear igloo

clear igloo
#

You need a compatible server then, it's Direct Attach Storage so it's supposed to connect directly to a a Dell server

remote kernel
#

Is there a list somewhere of compatible servers?

#

PowerVault MD1000 to PowerEdge R910

clear igloo
#

Anything that supports a PERC5/E or PERC6/E RAID card will work

thick minnow
#

He gets a 5gb connection to his work.

#

Or his school

#

Idk

remote kernel
#

So to do a storage array i need to buy:

#

A server (R910)

#

A PowerVault (MD1000)

#

A Perc 6 card

#

2 SAS cables

#

Correct?

outer nexus
#

@remote kernel Sounds correct to me. But note you can only use 2tb drives in the MD1000 with a perc6

remote kernel
#

Oh, what should I use if i want more storage per drive?

outer nexus
#

@remote kernel MD1400 can handle 4TB if i remember correctly.

green sphinx
#

help with what?

hardy kestrel
#

His "Bitcoin Generator" hahahahahahaha

outer nexus
#

That cable management ๐Ÿ˜ฎ

native seal
#

mapped network drives are a thing

but can I map a disk drive? I wish to be able to access a CD in my NAS from another machine

fresh copper
#

Itโ€™s possible but I canโ€™t say how to do it as it highly depends on the NAS

native seal
#

i think i've worked it out actually

#

just grabbing some disks to test with

#

I made a shortcut to the drive and then mapped that lmao

#

it works i guess

#

ยฏ_(ใƒ„)_/ยฏ

little schooner
#

@native seal change the share name in Advanced sharing properties window

#

If you right click CD > properties > sharing > advanced it will have a place where you can add a share name

native seal
#

ayyy thanks dude

#

@little schooner <3

little schooner
#

No problem happy to help

#

Though I have been feeling a little stressed out by school... In the final stretch lol

waxen scroll
#

I want to know what grade @thick minnow got on his diagram

covert ibex
#

Same.

clear igloo
#

Yup, we must know @thick minnow

formal fossil
#

Hi. Do you have CCTV ? I would like a software that runs on a Linux server (Debian) to interact with my IP cameras. Do you guys know / use one ?

clear igloo
#

Do you want to just store the camera data, just view it from a linux server or both?

#

@formal fossil

formal fossil
#

Both

clear igloo
#

You can do that with ZoneMinder or you could just have the footage store on the server via FTP and then view live footage with something like Home Assistant and the appropriate plugin for your cameras. The section option is less clean and you don't have a way to scrub footage though so ZoneMinder is probably your best bet

outer nexus
#

@clear igloo Is ZoneMinder an OS ? Cant really see what it is. My NVR is **** (cant even download recordings) and have tried to find something else for it.

clear igloo
#

@outer nexus It's not, it goes on top of a Linux OS. One thing I've seen is that you need to get the packages from zoneminder.com and not use the native OS repos as they seem to be out of date

outer nexus
#

@clear igloo thanks! Good to hear. Then ican try it on my PI and see how it works.

thick minnow
#

@waxen scroll @clear igloo Got an A. or 100/100 on BB.

clear igloo
#

Nice!

thick minnow
#

Yup.

chrome raptor
#

can i talk here about some vm labbing ?

#

i mean network labbing

clear igloo
#

No, no networking talk here ๐Ÿ˜›

#

kidding, yes, ask away or chat away

thick minnow
#

Only Nerdโ„ข talk is allowed here.

#

๐Ÿ…ฑ๐Ÿ…พโ„นโ„ข

#

โ„ขโ„ขโ„ข

#

I trademarked my trademark thatโ€™s been trademarked.

#

๐Ÿค”

hollow marlin
#

@thick minnow congrats dude

thick minnow
#

Thanks

chrome raptor
#

So can somebody explain to me how can i make PfSense VM to only filtter traffic and not make any subnets?

#

Like i client machines should receive ip from router dhcp or switch but traffic from that would go trough pfsense

#

is it even possible?

clear igloo
#

Not sure if pfSense supports bridged L2 mode but I would search around. Maybe they call it passthrough or something as well

chrome raptor
#

well i found some guides for transparent brigde/firewall but it doesnt work or i am dumb

#

like one VM acts as default router (Wan is in brigde mode with host, Lan is internal network) another VM has wan on that internal network and has another interface that creates another network, third VM is connected to that 2nd internal network (ofc in Wan) and has its own lan (which i am not sure that giving it different address than first machine gives via DHCP is good idea)

#

all of the Machines are using Pfsense

#

yet after creating brigde and removing types in WAN and LAN for 2nd machine i lose access to that Pfsense webGUI (even tho i gave some address to that brigde interface to access it)

#

and the traffic is not on the 3rd machine (doesnt get even addres on WAN)

#

@clear igloo

#

although my production setup will be different. like i will buy some nuc to install pfsense on it and get some man switch (unless i get some netgate gear here but i doubt it)

clear igloo
#

Hmmmm, that all sounds right, been a while since I messed with bridge mode for a firewall but the bridge interface should allow it to be accessible unless the side the second machine is on is considered "untrusted" and has a different security level that's lower OR you're not allow intra or inter interface communication for the different or same security levels

chrome raptor
#

so its better to drop brigde ?

#

hmm

#

okay now question regarding my true production setup i want

#

how can i set a nuc with pfsense with 1 NIC + man switch with VLANs to work?

#

like thats one advice i got if i want pfsense on 1 NIC device anyway

clear igloo
#

You'd need to do a router on a stick style setup in that case

chrome raptor
#

?

clear igloo
#

You could do multiple sub-interfaces on the pfsense box and a trunk port on the switch port. Have the default gateway for each VLAN on the pfsense box and then a default route off the pfsense box out it's own VLAN pointed to the external gateway or a L3 sub-interface in the same subnet as the external gateway's internal facing interface

#

Really haven't dealt with single ingress/egress interface in a while, I usually deal with L2 stitching or passthrough mode at least. I might be missing something though

chrome raptor
#

oookkkaaayy...well my network knowlegde doesnt comprehand this

#

xd

#

how can i make multiple sub-interfaces

clear igloo
#

Search up "router on a stick", should give you a good graphical representation of what it looks like

chrome raptor
#

on nuc that has only one NIC

clear igloo
#

I haven't ever done anything with pfsense so I'm not sure of the exact commands but you're basically breaking one interface into several logical interfaces

chrome raptor
#

oh

#

pfsense doesnt do much with commands

#

webGUI is mostly used

#

i take it back

#

pfsense has command line and PHP shell

#

hmm i have different question. Router will give LAN access to the switch (because now i have modem -> router -> clients and i dont want to mess our family network with putting pfsense between them)

#

how pfsense will know that it has Wan from that port and gives Lan to others??

hollow marlin
#

Thats where you begin assigning trusted/untrusted interface or what the PFsense equivalent is. Like Lurik I havent toyed around with PFsense in a while but you assigned trusted zones (LAN) to certain ports

chrome raptor
#

you can do that even with one ethernet port?

#

because thats how many nuc will have

hollow marlin
#

If you are able to create sub interfaces, yes. If not, no.

#

This isnt include a ton of configuration on a managed switch if you dont have one already

chrome raptor
#

okay serious question now.. is there a way to simulate such switch on VM or in Virtualbox?

#

so that i just buy stuff, make little adjustments to what i did in VMs, and go live?

hollow marlin
#

Technically yes but not for production use. Its used in lab applications like GNS3 and EVE-NG. Switching is the hardest thing to emulate because how much it relies on hardware.

#

Its why PFsense lack so much L2

thick minnow
#

Why was LTT server down? Maintenance I assume?

thick minnow
#

Yup, makes sense.

#

Next server outage: soontm

chrome raptor
#

Btw where can i seek more help with networking stuff except here?

little schooner
#

LTT discord is always the first one down for some reason

#

I've seen at least 7 outages when I tried to login to discord

#

And it's always LTT down

#

It's so annoying

ornate jungle
#

The more members a Discord Server has on it, the higher chances there are for it to become unreachable at times. Good thing Discord is still a free service though.

thick minnow
#

I need to order 50-100 ft of Cat 6 to run at my parents house..... Amazon's pricing is crazy cheap - getting cat 7 isn't much more - confirm to me that there is zero gain by integrating cat7 wiring for a portion of this house while the rest/majority of the infrastructure balances between cat5e and cat6

#
#

ugh the reviews are cringeworthy

#

"Thin and easy to set up, CAT7 fixed my Netflix/Amazon Prime performance issues on my smart TV."

little schooner
#

@thick minnow CAT 6a is good enough yeah

thick minnow
#

I've heard that when people try and market networking cables as CAT6E that it's a lie and that it's probably just 6a?

clear igloo
#

Cat6e is like Cat7, junk with only an ISO standard and no electrical standard to follow

little schooner
#

@clear igloo how come some people market some CAT 6a cables that look like CAT 7?

#

They have shielding and all that good stuff around the connector and inside

clear igloo
#

Depends on the seller and how much they care about adhering to the spec, some will use CCA or other crap cable and not adhere to the official standards as much. Unfortunately Amazon and other sellers aren't going to test and verify every cable is up to par

thick minnow
#

Makes sense, why should Amazon check? It's up too you as the buyer to check and do your research, not the sellers.

hollow marlin
#

@thick minnow Because in order for you to check you need to purchase the cable. You can only do so much research with the plethora of vendors. Its the sellers responsibility

thick minnow
#

Maybe, but it's mostly on the buyer.

#

It's primarily up to the Buyer NOT the seller to do the research.

hollow marlin
#

I get that but the seller is also responsible for selling the actual product they are advertising.

#

Again there is only so much research you can do especially on a niche of little reviews, even less of that properly test the wires

little schooner
#

@hollow marlin on ebay, if you arent responsibly representing the product you are seller, that is grounds for a eBay buyer case. So yes I agree, it's the seller responsibility to make sure the item is described accurately

#

The same should apply on Amazon but they are more lienent

wraith plank
#

Sooo i have a question. Im currently taking a course in programming and management of informatic systems and in my networks of communication class the teacher is saying that wireless networks are more secure are more noise immune that wired ones.i think this is false but i can't argue with him because these "facts" are in the "book" that we are using at class. So is it true or false??

stoic moon
#

Wireless sucks ๐Ÿ˜ฌ

covert ibex
#

More secure maybe unless somebody with Kali, nethunter or any other of the distros are in range..

native seal
#

or a WiFi pineapple lmao

#

u can pull anything with that

covert ibex
#

@wraith plank
I'd love to hear the points why a wireless network would be more secure than an ethernet network..

Wpa3 has been out publicly for a few months and theirs already PoC vulns that work...

stoic moon
#

Because our teacher is God

#

And no one can say anything agains him

wraith plank
#

@covert ibex the problem is that he says that because it is in the book its correct and doesn't even bother with justifying it

stoic moon
#

Or he will be mad ๐Ÿ˜‚

covert ibex
#

Books can be wrong. Throw a Bible at him.

stoic moon
#

He makes us watch yt videos about classes...

#

Brazilian videos

#

Nope

covert ibex
#

Nvm. :P

wraith plank
#

Nop

stoic moon
#

It's Delgado

#

Something similar

wraith plank
#

Were portuguese and he makes us watch videos

stoic moon
#

It's just a weird ass name

covert ibex
#

Well, he's wrong.
As long as you's understand that, don't worry about it.

wraith plank
#

K thnks

stoic moon
#

Yeah, but we need to say that wireless is safer on the exam..

#

The struggle it real

outer nexus
#

@wraith plank @stoic moon Don't your teacher explain why he thinks its safer?

slow pivot
#

Doesnโ€™t sound like that teacher is all that good at teaching, or networking. Just get through the exam and get on with life. Education is like that a lot of the time unfortunately.

native seal
#

yea :P in electrical installations were told alot of stuff which is rather irrelevant on actual construction sites

thick minnow
#

id say if an attacker has physical access to wired ports in an environment where properly designed and executed vlans/subnets and 802.1x isnt implemented, WPA protected wlan is more secure. because at that point, you at least need a password to get in. If you want to compare a more apples to apples approach, open wireless is more secure than open wireless because you have "protection" by default because you have physical control over where the ports are. But almost nobody does open wifi anymore. Tons of places run unauthenticated wired networks. Even less do firewalled vlans and subnetting properly if at all.

stoic moon
#

@outer nexus nope, he says "go search it.."
Or he kick out of the class

outer nexus
#

๐Ÿ˜ฎ

#

great teacher .... lol

clear igloo
#

lol, that's a horrible teacher

stoic moon
#

He doesn't even know to check the tests

#

I think that he sees the answer and be like: "this is 4 points, that one 0, that one 3"...

#

Because he doesn't know shit about this

clear igloo
#

๐Ÿ˜ฆ that makes me sad

stoic moon
#

I'm going to fill a complaint

outer nexus
#

yes do that.

stoic moon
#

He's really rude too

clear igloo
#

Probably knows he doesn't know jack and just hopes he can bully people to be quiet

stoic moon
#

You can't even ask what a word means

#

Or u get out

clear igloo
#

Yah, he needs to go =/

stoic moon
#

He's on this school for 20 years I think

#

Or 15

clear igloo
#

ah, one of those "I've been here forever so I deserve to not care"

stoic moon
#

He needs some VACation

clear igloo
#

Needs a learning vacation ๐Ÿ˜›

stoic moon
#

๐Ÿ˜‚

thick minnow
#

meh, ive had teachers like that. just nod, smile, and then move on with your life.

#

its not worth the stress

#

teachers, customers, employers

#

smile, move on, and forget the bullshit. you cant fix people on a power trip

clear igloo
#

What annoys me about those teachers is then you move to a higher level class without the proper knowledge to succeed there =/

thick minnow
#

the thing is stuff is changing super fast. youre even going to run into official documentation for things you are tasked with implementing in the future that is entirely wrong

#

if you keep on your game, youre even going to end up fixing products that the developers own specialists didnt understand well enough to implement correctly

#

my recommendation if you really want to understand what you are learning is to build a lab to implement, break, and fix the things you are learning

#

most linux stuff is free, microsoft gives out 180 day licenses to their products, there are cisco emulators for network stuff

#

use your education to supplement your actual learning by doing

#

ask teachers for guidance, and stick around the teachers that really know their stuff and the ones that really listen and want to learn with you

#

use the ones that wont as a lesson in dealing with beaurocracy

covert ibex
#

Also, if you ask nicely, and don't pester them too much, your school I.T guys will more than likely answer questions too.

wraith plank
#

@thick minnow i do agree with u. My favourite subject of technology is networking and this is kind of a let down for me.

radiant crane
#

@covert ibex Can confirm, am IT guy at a college

covert ibex
#

@radiant crane
Can confirm, was one for 4 years. :P

#

And if i was given the option, would happily do it again.

radiant crane
#

Yeah, it's gonna take a pretty big pay bump to make me leave lol

wraith plank
#

He(the teacher) could do much more in terms of pratical stuff like making networks and simulating real cases like debugging a network, the school has the everything we need to do that. And he just sticks with powerpoints and pdf of written stuff

thick minnow
#

@wraith plank I understand, I had classes like that too. But remember, there is still good information in these classes, and sometimes the teacher is even bound by some preset curriculum they have no control over

radiant crane
#

@wraith plank You mess around with a virtual lab? VIRL and GNS3 are both free

#

Oh and packet tracer

wraith plank
#

We've worked with a packet tracer a operating systems class. Never tried virtual lab though

radiant crane
#

You could get a book for the CCENT and do labs in Packet Tracer. That could satisfy that networking itch, plus CCENT is a great cert to have on your resume

covert ibex
#

My introduction to VM's was my second I.T teacher giving an IP range, credentials and a task for us to connect to a telnet server on his pc, without connecting directly to his pc.

Little guidance besides "see google for help" written on the whiteboard.

thick minnow
#

its hard to go wrong in the networking profession with any sort of cisco cert

wraith plank
#

@thick minnow and by the way he does have control over the curriculum. supposedly next chapter should be "advanced networking" but he has already confirmed that hes going to teach us html css and php... Makes sense doesn't it??

clear igloo
#

Yah, if you want to go further (CCNA and CCNP) then VIRL is great as well for the more advanced stuff

#

Even some CCIE studies VIRL is good for

wraith plank
#

@clear igloo @thick minnow @covert ibex @radiant crane btw thanks for the advice guys

radiant crane
#

Yeah no probs!

thick minnow
#

@wraith plank is this a web development class?

#

also yeah, no worries

wraith plank
#

No its the same teacher same class:"networks of communicatio"

radiant crane
#

Sounds like it's more of an overview course, just to give you an idea how websites and computers work on a network

thick minnow
#

i was thinking the same

wraith plank
#

I just now that next year he is going to give us the same stuff html css php

thick minnow
#

im trying to think of the last time i heard a web developer use the word "packet"

wraith plank
#

Meanwhile were doing other stuff on other classes. C# in programming
Raspberry pi and Arduino in computer architecture
Windows server ubunto server and debian command line in operating systems

radiant crane
#

@thick minnow I have a dev say "VLAN" to me and I was shook

thick minnow
#

@radiant crane I have to be careful, where I live "VLAN" and WLAN" are pronounced the same

radiant crane
#

lmao

#

What a problem to have

stoic moon
#

@thick minnow yeah, but the grades go down as hell

#

he fucks up all the grades, and that sucks, cuz we want to get into Uni

thick minnow
#

@stoic moon I think eivarin at least has a better idea now about the topic than before. Just because they have more input from the community doesn't mean they still cant write whatever the teacher wants on homework or a test to placate them.

stoic moon
#

hm

thick minnow
#

The, people around you, other professionals, the internet, even official documentation is filled with bad or sometimes completely wrong information.

stoic moon
#

yeah

wraith plank
#

I do understand that and that's why i asked here just to be sure @thick minnow.

stoic moon
#

yeah, we were like "wtf"

#

how the hell is wireless safer..

radiant crane
#

Well you can auth with wireless

thick minnow
#

easily and cheaply at that

#

WLAN is not at secure as LAN.

#

Or just Wireless APs in general.

stoic moon
#

exactly

#

i think

thick minnow
#

If implemented correctly, and configured properly WLAN has the potential to be safe-ish.

#

I guess we have to clearly define "secure" to give a definitive answer

radiant crane
#

^ +1

thick minnow
#

and then figure out what assumptions we are making about the default wireless and wired connection

hollow marlin
#

WLAN is not secure. All traffic is broadcast.

thick minnow
#

Anything thatโ€™s โ€œwirelessโ€gets transmitted over the air, so as long as someone even has just a standard laptop wireless NIC in monitor mode it can be bad news bears.

stoic moon
#

exaclty, wlan cant be totally secure, because its a broadcast, its just...impossible to secure it?

thick minnow
#

That AND Wi-Fi is a shared resource. So the more people connect to the AP the more devices are sharing the bandwidth.

#

how does that differ from wired networks?

hollow marlin
#

It is secured but its such weak encryption it can be easily broke. Not including how easy it is to just do a man in the middle

thick minnow
#

^

#

Iโ€™ve cracked my own home router in like < 5 minutes

#

Thanks Comcast.

stoic moon
#

O-Oยด

radiant crane
#

What was it using? WEP or WPA2?

stoic moon
#

O_o

thick minnow
#

WPA2.

#

If any of you are using WPS, turn that shit off now!

#

lmao

#

๐Ÿ˜‚๐Ÿ”ซ

#

assuming i can connect to a wired network, where does it become more secure?

stoic moon
#

mine needs to be enabled on the settings

#

like, u go to setings, it enables, searches and disables right away

radiant crane
#

Yeah I'm thinking secure in the sense that you can get access to my secure resources

stoic moon
#

but i had a router with it turned on the whole time, just in standby

#

guys, i have a question

thick minnow
#

@radiant crane im with you on this one

wraith plank
#

@thick minnow the thing is that for wired network u need phisical access and wireless u dont

stoic moon
#

my ISP gave me a router but it doesnt have an settings page

#

i have to go to their website

radiant crane
#

You have to be physically in a build to use WiFi

#

building*

stoic moon
#

that they made to access router settings

#

is there a workaround?

radiant crane
#

@stoic moon Google your ISP default login

#

It's normally a default

stoic moon
#

not the login

wraith plank
#

@radiant crane yah but you dont need tl go to the lan ports to do it so it wont be so obvious

stoic moon
#

the page doesnt exist

#

it gives a 404

#

they removed the page and created a website to access settings

thick minnow
#

@wraith plank, if i manage an enterprise where the public has access to ethernet ports and access to wireless access points, which is more secure

stoic moon
thick minnow
#

or is one more secure

radiant crane
#

@stoic moon What's your default gateway?

stoic moon
#

they blocked it for everyone

#

im not the only one

#

its right thereโฌ†

#

i mean, i can check literally everything on the website they made but...still

radiant crane
#

WiFi is less secure for the end user I get that. You can spoof my network and service users. But in terms of getting to my servers, it's the same as wired. Once you're on, you're only on the network I setup for that SSID or wired port.

#

@stoic moon they probably turned off HTTP/HTTPS access to the router

#

You can try SSH or telnet, but that's a long shot lol

stoic moon
#

i'm just trying to figure out why, do they have better control over the routers?

#

because i can change everything, and with a much better UI

#

:p

radiant crane
#

Yeah that's why I just use my own router for my home

wraith plank
#

@thick minnow if u manage an enterprise lets say u have a main 48 port switch for the wall ethernet plugs (thats the only way im seeing u having public access to the ethernet ports). Just block the access to the main devices on the network(servers with important data) on the port that leads to switch on the router

#

i think this would work. would it??

radiant crane
#

You can block access to servers and stuff with Wireless too

wraith plank
#

yah i know but he was asking about the security of having public access to the ethernet ports

clear igloo
#

Just do 802.1x authentication and have a guest VLAN for non-authenticated users

wraith plank
#

thats simpler

thick minnow
#

^ Lurick said it

radiant crane
#

๐Ÿ’ฏ

stoic moon
#

we have a winner here bois

thick minnow
#

it sounds simple, but its not the easiest solution, and definitely not something you can just turn on like security features on a wireless access point

wraith plank
#

is there any way to use a key fob to authenticate the access to the router

#

?

thick minnow
#

the simplest answer is probably "it depends on the router"

radiant crane
#

Clearpass does two factor, I don't know if you can use an actual key

#

But I also dunno if that works for switch/router logins

clear igloo
#

You can do 2FA for VPN access but SSH access to devices, no

wraith plank
#

if it doesnt it should because it is the way to get into an network and lock it down

thick minnow
#

i mean, you could use a keyfob to authenticate against something else and then configure SSO to get to the router if youve got the backend

clear igloo
#

not really, it's a much larger point of failure, more traffic to manage, and most enterprise gear is SSO with TACACS or Radius login

radiant crane
#

@clear igloo Yeah I have everyone VPN if they want SSH access

clear igloo
#

Yup, VPN with SSO and 2FA to a DMZ network for out of band access to the box if possible is best

radiant crane
#

I would love out of band

thick minnow
#

I agree with Lurick, 802.1X is a good idea. That and separate VLANs on your WAP.

#

Network Security doesnโ€™t just happen on its own, itโ€™s a constant thing that must be done everyday.

radiant crane
#

Whenever our network messes up, I have to run to my routers with a console cable lol

clear igloo
#

That's always fun ๐Ÿ˜›

thick minnow
#

i rarely had to use a console cable, usually only to verify something was stuck

clear igloo
#

It's the one thing I love about labs, you can do term servers and oob to everything ๐Ÿ˜ƒ

thick minnow
#

then sweat as i wait for the thing to reboot behing a rats nest someone else made decades ago

radiant crane
#

We have pretty good network techs here thank god

#

No rats nests

thick minnow
#

People that claim that something is secure, and is foolproof are the ones that understand security the least.

Like one of my professors said: โ€œIf you think youโ€™re too smart to get attacked or hacked, than youโ€™re not so smart.โ€

#

Change my mind. โ„ข

#

i run stuff across a geographic range about the size of a US state and a lot of it was done by techs from places we acquired ove rtime

#

so there are all sorts of weird rats nest designs

radiant crane
#

I could image

#

I work next to my tech, so I could throw something at them if they did something weird

pseudo blade
#

How to secure your laptop: Put it through a chipper repeatedly, burn the result, mix that into a large block of cement and dump the result into the ocean.

waxen scroll
#

@clear igloo I'm proud of our boy

radiant crane
little schooner
#

If you could choose between Dell, Aruba, unifi and HP for networking switch, which one would you pick for a small business who cares about reliability?

pseudo blade
#

Two of any of the above.

#

Redundant everything.

radiant crane
#

Unifi is ubiquity right?

little schooner
#

Yes

pseudo blade
#

Yes.

little schooner
#

@pseudo blade which ones?

radiant crane
#

Small business, Unifi is cheaper I think

pseudo blade
#

What's my budget?

thick minnow
#

im in security now, i have accepted that i am screwed seven ways sideways and every mole i wack just means someone found 7 more

little schooner
#

I feel like unifi is lacking in the quality department for switches

#

Maybe $1.2

#

Thousand

radiant crane
#

Lol

pseudo blade
#

A Dollar twenty? 10mbit hub.

#

:P

little schooner
#

Lool

#

No 1200

radiant crane
#

you get one ethernet cable to share

pseudo blade
#

Access or core?

radiant crane
#

And how many users?

little schooner
#

Access

#

Uh 50 users

pseudo blade
#

50?

#

Hm.

little schooner
#

Yes for now

pseudo blade
#

More than 50 later?

little schooner
#

Until the room destruction

#

Yeah

pseudo blade
#

Do I need 10 gig uplinks?

little schooner
#

Yes at least 2

pseudo blade
#

Is this your previous scenario?

little schooner
#

Sort of

#

But we had a budget increase

#

The business department is listening to all our demands

radiant crane
#

Aruba 48 port starts at $1K

#

So that's out

pseudo blade
#

How many vlans can it see?

little schooner
#

We don't use any vlans here

pseudo blade
#

Mhm.

little schooner
#

But we'd prefer a very reliable switch that isn't frustrating to configure

#

Or suddenly stop working from misconfiguration

#

Or have broken igmp

radiant crane
#

Which switch did you have trouble with?

little schooner
#

We were testing edgeswitch before

thick minnow
#

i think juniper switches have the ability to test config changes before commit?

radiant crane
#

Yeah and rollback

#

I miss my Junipers

little schooner
#

That sounds pretty cool

#

All switches should have that

thick minnow
#

i only got to touch one once when we were testing it out

pseudo blade
#

Cisco's right out at that price range and feature set.

little schooner
#

Yeah and money for updates is tight too

clear igloo
#

Have you considered used/refurb at that price range?

pseudo blade
#

I'd legit consider Mikrotik, but more redundancy.

little schooner
#

@clear igloo we have actually

#

Like ebay

radiant crane
#

What's the eBay prices?

#

Maybe we can start there

little schooner
#

In class right now

#

I'll bbl

pseudo blade
#

Going refurb seems undesirable considering the typical level of vendor spite.

radiant crane
#

My only problem with refurb is I like everything to match

pseudo blade
#

I'm kinda spoiled by MT. They have some legitimately nice stuff if you know what you're looking for. Downside: If you get stuck you have less options, can't just pull a CCNA out of a hat and get it fixed in an hour.

radiant crane
#

Is the CLI for MT different than IOS?

pseudo blade
#

Different, absolutely. Harder... Maybe not.

#

I use both.

radiant crane
#

We have all cisco stuff and one Aruba distribution switch. Aruba OS and IOS and pretty similar

#

We're demoing to move to Aruba distro and access

pseudo blade
#

Most vendors just clone IOS.

thick minnow
#

ive noticed a lot of new techs out of school are taught solely how to use the Aruba "GUI" if faced with CLI

pseudo blade
#

Some things make more sense in RouterOS as a result.

radiant crane
#

The GUI isn't bad

pseudo blade
#

Some things don't.

#

Aruba's GUI?

radiant crane
#

It's also nice to have that option

pseudo blade
#

Never got to play with Aruba kit.

radiant crane
#

But if you know IOS, your know ArubaOS

#

you*

pseudo blade
#

Yeah. Same with Force10 switches.

#

Straight clone.

#

Huawei's half-and-half.

radiant crane
#

The only diff I saw was "sh int status" is "sh int brief" for Aruba

thick minnow
#

i havent touched anythign but hp->aruba since school

pseudo blade
#

I'd like Cisco as an option for anything more than I do if it were priced logically.

radiant crane
#

Yuppers

#

That's kinda where Aruba comes in

pseudo blade
#

There's nothing special inside them.

radiant crane
#

We're gonna mess with the Clearpass and hopefully assign wired VLANs by 802.1x

#

fingers crossed though

#

That might just be vendor talk

thick minnow
#

man, its been a while since ive had to deal with a lot of this, the last year, i've mostly been developer wrangling and knee deep in bash and powershell script

radiant crane
#

I found out about Netmiko and Python about a couple months ago

#

Boy howdy

thick minnow
#

i really need to get more into python, its easy enough to read that if i disappeared, someone would at least be able ot figure out what was going on.

fresh copper
#

Itโ€™s easy to write Python that no one will ever be able to read

clear igloo
#

Yah, you can definitely make it hard to read ๐Ÿ˜›

thick minnow
#

i do try my best to make things easy to read and document harder concepts

#

also try to make tools rather than one off scripts

#

unless someone is an ass to me

#

๐Ÿ˜›

pseudo blade
#

Itโ€™s easy to write Python that no one will ever be able to read Easy. Delete it.

#

If you want to distribute it, making it so nobody will want to read it after seeing it is probably easier :P

thick minnow
#

^this

#

nah, i try to go with standards and such so people can hopefully learn from me, or at least my mistakes at a miminum

fresh copper
#

I always follow PEP 8 but I can still have some crazy things

little schooner
#

@radiant crane I've seen some Aruba 2540 48 port switches go for $890 on ebay

#

And they have 4 sfp+ and meet the requirements

#

But i don't know if it's reliable

#

Updates are free I think...

clear igloo
#

@little schooner I think it's HP that provide free updates but I could be wrong. I don't know of really any other vendors that do by default unless it's a critical issue or security problem

#

You could also look at something like the WS-C4948E-S which are about $150 on ebay right now but used in most cases

radiant crane
#

Aruba and Cisco are enterprise level, so they're reliable or at least should be

chrome raptor
#

Which managable switch company should i look for when buying this stuff? Ofc not Cisco since its too damn expensive

clear igloo
#

What sort of features do you need? If it's not enterprise level stuff then Ubiquiti is usually pretty good for prosumer level stuff

#

Like if you just need ports and vlans then even a TP-Link or similar managed switch is plenty

thick minnow
#

was about to watch this cisco presentation

#

is it on in 5 mins?

chrome raptor
#

More like home\small business @clear igloo

clear igloo
#

@chrome raptor Yah then TP-Link, Ubqiuiti, etc. are going to be more than capable

#

@thick minnow I believe so, 1pm EST

chrome raptor
#

But security wise? Is tp-link up to the challenge?

clear igloo
#

@thick minnow They're probably going to do a lot of talking about the Catalyst 9600 switch, Catalyst 9100 APs (WiFi 6), and some 5G stuff

#

What sort of security, I believe they do have several that offer dot1x and whatnot

chrome raptor
#

I am beginner in that stuff tho i have encountered tplink in some articles about vurnelabilities

little schooner
#

Do you think it's possible to replace the Cisco fans with quieter ones? In a personal use setting

hallow lintel
#

yes

#

go find the noctua equivalent fans

clear igloo
#

@little schooner in most cases no

#

Unless you don't mind some janky fans and turning off the fan notifications ๐Ÿ˜ƒ

little schooner
#

@clear igloo oh gosh I remember this actually. My supermicro server keeps bothering me that the fan speeds are too low and in the red zone for some reason

radiant crane
#

Any of you guys mess around with the Aruba/HP switch? What's with this "dual personality" ports?

thick minnow
#

Howโ€™s it going Networking Nerdsโ„ข?

little schooner
#

What are the chances of the Cisco switches being fake on ebay

clear igloo
#

@little schooner Depends on the seller, price, etc.
Like if they are selling a Catalyst 9300 or something for $100 then it's a fake but if it's old hardware for that price then it's likely good

little schooner
clear igloo
#

@little schooner Yah, that looks legit

merry inlet
#

Hi guys! I'm looking for somebody who have some knowledge about setting up the "Pihole". Send Priv message pls!

timber pulsar
#

when does contention-based media access control protocol outperform control access protocols and vice versa? Please send in DM's

hollow marlin
#

@timber pulsar are you referring to wireless?

thick minnow
#

Looking into ip cameras and saw that ubiquity has some that works with their enterprise system. Anyone have experience using their systems? Currently use gigabit Asus triband wireless router. RT ac3100

hollow marlin
#

Cameras are...ok.. decent quality in day light and Unify makes setup a breeze. Not enterprise.

#

But they are wicked expensive and can build a better system for half the cost

naive meadow
hallow nimbus
#

๐Ÿ‘€

thick minnow
#

Not bad at all

#

@hollow marlin do you have any suggestions on where to start? We are building a new house and in the house we have now someone lived through a home invasion and to make things feel safer I want to have cameras up.

thick minnow
#

okay so mesh looks like a good way to go with things now but Im not sure if unifi is the way to go. We will have gig speeds so any suggestions?

pine panther
#

i wonder if swapping a long cable for a smaller one would help the speeds go up

#

i mean

#

i think it wouldnt matter

#

since all the cables have some distance before the speed degrades

#

and im like 2 meters away from router

#

and i use like 10meter one

#

just wondering

naive meadow
#

I think mine is a couple of meter it runs on a diagonal angle across the floor

#

not sure what type it is

pine panther
#

i mean if the speed downgrades from like 1 meter cable to 10 meter cable

#

becouse it needs to travel further distance

#

u know

#

shorter cable = better speed (stable-er speed)

naive meadow
#

yeah I have no ports in my room

clear igloo
#

@pine panther Ethernet will run the same speed up to 100m before you see degradation

pine panther
#

yeah thought so

#

ethernet cable

#

the smaller ones just help the looks

#

and declutter things

clear igloo
#

Yah, they look cleaner when you don't have excess

pine panther
#

but idk if this is some black magic

#

as i used a smaller cable from the switch to my pc i dont get 15mbps i get 17mbps

#

xd

#

not a big difference but there is some

#

now i use a meter one and the worse one was like 15meter

keen citrus
#

That is a bad quality cable then

clear igloo
#

It could be the longer cable is damaged or just crap quality

keen citrus
#

^

clear igloo
#

But you also have to see if you ran the same number of tests over the same period of the day did the average make any difference or was it just a couple of tests?

pine panther
#

avg with the old was like 14.3 and with new 17.8

#

20mbps ISP

covert ibex
#

@clear igloo
I thought it started a little over 30m.

hollow marlin
#

30m for 10gig on Cat5/6

#

*cat5e

thick minnow
#

cat6a is 10gig over 100m right?

outer nexus
#

is 47% humidty and 19.1 ยฐC is okay enviorment for a server?

thick minnow
#

thats within in the safe range so yes?

outer nexus
#

okay great. Thank you. ๐Ÿ˜ƒ

thick minnow
#

I think humidity is 40-60% and temp is 10-27 but i could be wrong. I know the ideal temps are between 20-22

#

anything around that is fine though imo

#

Is this for a small home server or a larger server room?

outer nexus
#

Currently 1 9u rack with 3 servers in for work related stuff. Expanding later this year (hopefully) to many more servers.

hollow marlin
#

@thick minnow yeah 6a is 10gig over 100m

thick minnow
#

real expensive though. Any reputable companies with decent prices?

hollow marlin
#

Like cable is expensive?

thick minnow
#

Last time I checked prices it was waaaay more than cat6

#

Also is cat7 a thing now??

outer nexus
#

cat7 is very close to same price as cat6 where i live. Sometimes its the same.

pine panther
#

i wish i could get c7 tho

#

but idk if i can plug it in normal etherpnet port on motherboard

#

or i need a external ethernet card

outer nexus
#

@pine panther You can. cat7 works justlike a cat6. ๐Ÿ˜ƒ

pine panther
#

i got cat5e

clear igloo
#

@outer nexus Just keep in mind there isn't any official electrical TIA/EIA spec for Cat7, it's only an ISO standard so quality can vary a large amount

outer nexus
#

True

thick minnow
#

What do you all think is the time scale for when 10 GB ethernet will be needed?

#

In a home I mean

hollow marlin
#

@thick minnow never. People don't realize that people can even reliably saturate 150mpbs let alone a gig. (I'm not talking large downloads)

#

*cant

thick minnow
#

So trying to run 6a isnt worth the extra cost

hollow marlin
#

6a really isn't much more. Cat5e will last a long time. Other than streaming we are not pushing more bandwidth on day to day activities

pine panther
#

like the standard internet is like 50-100mbps

#

speed*

hollow marlin
#

100 is the sweet spot for a typical family. Heavy streaming I see max spikes around 120mbps. That was the flow of ~1200 homes

thick minnow
#

We have the gig package and get around 500 to 600 down on a 14 year old connection from the street. I'm assuming the new house will have a higher percentage of the supposed gig speeds I hope

little schooner
#

@thick minnow of course it's worth the cost, it's so minor and has all the extra benefits of future proofing

#

Do you really want to rerun everything again

#

And one way to saturate the connection is to simply host a file share on an SSD and download big files like videos or isos

#

Then you will see how clear the benefit becomes

hollow marlin
#

@little schooner that's not the average. Like I said, large files are the only reliable way to saturate over a 100mbps.

#

Day to day browsing/streaming. You wouldbt notice anything

thick minnow
#

Hmm. Well so far in my life I havent needed to transfer anything like that but if I create a lab for myself I might.

covert ibex
#

@hollow marlin
Are you saying average doesn't include the people with a NAS?

clear igloo
#

Average doesn't include people downloading ISOs nonstop from the internet or redownloading a 500 game steam library every week ๐Ÿ˜›

hollow marlin
#

@covert ibex the average person doesn't have a NAS. Again NAS, large files, steam....those are outliers.

thick minnow
#

Steam... had an issue with them trying to get back into my account after I did a fresh windows install. Got in now and have the info stashed somewhere now.

thick minnow
#

Steam is hella slow when it comes to downloading games and update patches sometimes.

#

Even with pretty good download speeds, I still find Steam to be a sub-par sometimes when it comes to downloading updates, let alone full games.

#

Then again it could just be me, perhaps I should optimize my home network.

lol

hollow marlin
#

It's not your network, steam uses a ton of CPU and time unpacking the downloads. This tends to feel like steam is slow

little schooner
#

@hollow marlin I kinda wish Comcast would bump their upload speed to at least 20 mbps

#

The upload speed can kill a home connection if you have cloud backup running in background

#

It's happened to me too many times

hollow marlin
#

Optic limitations are finally becoming a thing of the past and sysmetic connections just make more sense

#

Upload is a silent killer for networks

little schooner
#

I finally have a new competitor in the area that can provide 150 mbps symmetric for $50

#

But I have to wait until next year for the full rollout in the state

#

That's very bothering that Comcast can still basically rip me off for another year

pseudo blade
#

Govt. here made it so that the only way to sell symmetric connections via the NBN is to pay them for a faster connection and artificially limit the download speed...

hollow marlin
#

I mean, almost all downlads are artificially limited from 1/2.4/10gig

subtle nacelle
#

Hey can someone tell me The difference between a MoCa and a modem. Modems with coaxial cable input seem to do the same thing that MoCaโ€™s do whatโ€™s the difference?

hollow marlin
#

Moca are typically used to convert Ethernet to cable. Say your house has cable run to every room but not Ethernet. You could get two moca adapters and just attach your devices. Modems actually convert the signal from the ISP. Each use different frequencies

subtle nacelle
#

Could a modem do the same thing as a MoCa. MoCaโ€™s seem so expensive for what they do and Iโ€™m trying to save money

hollow marlin
#

Theoretically yes, but they are not designed to do so. Moca is quite expensive for what it is and it can get complex in some situations

subtle nacelle
#

Sigh Might as well try both and then return the one that doesnโ€™t work or is most expensive

hollow marlin
#

What is your goal?

unreal wedge
#

Don't usea MoCa unless your ISP gives you one. And don't use a modem if your ISP gives you a MoCa, use a router.

subtle nacelle
#

Well strap yourself in for a long story.

I already have Internet in my house but I want Internet in my room because gaming has been extremely annoying for me on a wireless connection. So I went out to my cable box and the main cable only plugs in to the room where are my router is. My plan is to use a splitter and have one going to my router and one going to my room. And since MoCas are so expensive I was thinking about getting a router or a modem to switch it to ethernet

hollow marlin
#

@unreal wedge why would the ISP give a moca? Only DOCSIS will provide a connection

#

They use two different frequecies. There is no harm using your own with DOCISIS

unreal wedge
#

I'm skimming and trying to give a simple answer. My ISP gave me a MoCa for my fiber setup.

subtle nacelle
#

K

hollow marlin
#

@subtle nacelle While many people here dislike power line adapters they are not bad for what they are. Sure you wont pull close to a gig like Moca but you will get 100-150mbps and much lower latency than wireless.

#

Plus they are a bit cheaper

#

But people like to focus on the pure throughput

subtle nacelle
#

Hmm something to think about...

#

Iโ€™m still leaning towards getting a modem though

thick minnow
#

What's a moCa?

hollow marlin
#

Its a coax to ethernet converter

thick minnow
#

Hmm. Dont modems just do that in general? Or am I wrong

hollow marlin
#

Technically yes, but there are differences with DOCSIS and MoCa.

thick minnow
#

Ah. I'll have to do more research.

#

Apparently my Cox one is a docsis

unreal wedge
#

MoCa master race.

hollow marlin
#

Nah, fiber master race fam

unreal wedge
#

My MoCa is part of a in-home fiber network, fite me.

hollow marlin
#

No need, already hurting yourself.....waaa pow

pine panther
#

whats moca @unreal wedge

radiant crane
#

@winged lynx It's internet over Coax cable, the same cable you use for TV stuff

fresh copper
#

Not too long after I decided to run cat5e, my ISP decided to upgrade my modem to one that has MoCa built in so I could have just got a MoCa adapter (my house has Coax everywhere). Itโ€™s meant for their multiroom tv (which I donโ€™t have since I get tv from someone else) but you can use it for whatever

little schooner
#

Is there a real difference between sfp and dac connected cables for 10G communication? I've read online that DAC is more cost efficient but shorter distance than it's sfp+ counterpart. Is that the main reason or are there more?

pine panther
#

i dont think so

fresh copper
#

Yea. DAC cables mainly have the length limitation and are also huge and donโ€™t bend well. The can be a lot less expensive in many cases though. They are also not suitable for places with huge amounts of EMF but at that point any computer may also have issues.

Usually they are used for interrack comms with fiber for external connections

#

Interrack meaning inside rack rather than between racks

pastel dew
#

Is it normal that infiniband has higher latecy than ethernet?
I'm not sure if I set it up correctly

hollow marlin
#

@pastel dew possible just a chipset difference? I mean those results are almost negligible in real world use.

clear igloo
#

I would almost call those results margin of error even

hollow marlin
#

exactly

hollow marlin
#

why is AAA documentation so fragmented between whitepapers ๐Ÿ‘บ

little schooner
#

@hollow marlin well I guess more reason for companies to pay that support cost so they don't have to deal with the problem

topaz cove
#

So looking for recommendations for home network planning, I want 2 individual 10gb connections from my unraid server to computers so each computer has dedi 10gb probably through nic teaming I imagine so there's 20gb of bandwidth, I was looking at using one of the new microtek 10gb sfp+ switches that's only like 100$ and has 4 10gb ports and can use last gb eth port on the switch to run to a pfsense router for my gb internet. I have not used sfp based connections before and was curious if there was like keystone's or anything for them I could use for like a wall plate termination for a cleaner aesthetic in my computer area on other side of wall from the server? Or just run a wall plate that has like the whisker biscuit type thing for feeding random cables through be my best bet?

hollow marlin
#

@topaz cove what will you use the 10gig for? It would work but you really need experience for mikrotik. It's not the most user friendly but they are Rock solid for the cost. Heads up is you might have 20gbps total you can only have 1 max stream of 10gig. Finally they do make wall plates which are essentially bulk heads in a outlet cover

topaz cove
#

I've got some experience with networking in Cisco and work with network environments, biggest concern for me is the cable networking

little schooner
#

@topaz cove the commands are very different but at least the documentation is decent

topaz cove
#

Also the reason for 10gb dedicated for each computer is in hopes that I could use the unraid server as a Nas for game and document storage for 2 sff computers. And with the 1 max stream do you mean each computer can only have 10gb or total both computers can only use 10gb between them even with nic teaming?

hollow marlin
#

I mean device to device 10gig max. The other 10gig nic can be used for other things. Thats how LACP on the Tik will handle it.

topaz cove
#

Ah okay, good to know thanks

pseudo blade
#

I really hope Mikrotik ups the base amount of flash space they ship, and soon. Watching flash usage crawl up quite rapidly, this is pretty much only essential packages and doesn't include the base package...

#

This would have left me with about 5MB free at the beginning of the year.

#

LTAP mini with advanced-tools,dhcp,gps,ipv6,lte,ppp,security,system and wireless on 6.44.3.

short spire
#

Not sure if this belongs in Networking or Deals channel, are Ali Express Wifi cards worth the hassle?

pseudo blade
#

How long's a piece of string?

outer nexus
#

|------------------------|

#

@short spire I would not buy from Ali Express. I do not trust the quality ๐Ÿ˜ƒ

covert ibex
#

@short spire
You get exactly what you pay for.
No more, sometimes less.

slow belfry
#

--oftopic

|------------------------|
I actually hate MySQL always doing that, they have a way to ignore that. Just had to say that ๐Ÿค”

hollow marlin
#

@pseudo blade I still despise that they do that. No reason to have 16mb. But if you manually push packages through netinstall you can get some space. I just have a small flash drive in my AC2 for logging

pseudo blade
#

Netinstall isn't generally necessary for that as unless the device uses SMIPS, packages just load and install from RAM, and 64MB RAM is enough to make that happen.

#

It's just that Mikrotik are reaching the point where even that's not enough, growing by a few hundred kilobytes per month of patches on MIPSBE.

#

The base package under 6.44 for MIPSBE uses about 1MB more disk than the last 6.43 build.

#

Because the SMIPS packages are effectively limited to half of flash if you wish for OTA upgrade support, those devices are an absolute pain in the ass to manage.

hollow marlin
#

When it comes to per package installation, netinstall is the only way to go. The bigger problem with package s are still a ton of decent routers with 16mb of RAM also that cannot upgrade without farting around with it.

pseudo blade
#

@hollow marlin No arch for us yet outside of SMIPS requiring Netinstall, plus Netinstall's given us enough issues that I was tasked at work to write an alternative.

hollow marlin
#

Never had a problem with it

pseudo blade
#

Plus our devices are up poles all over the country, so netinstall isn't practical regardless.

#

PSA: Unless you're on a really, really tight budget... Don't buy SMIPS stuff, it's cheap for a reason.

hollow marlin
#

All we deploy I'd ac2. Not deploying $19.95 routers to customers

pseudo blade
#

Good plan :P

#

We've got well over 100 of varying models outdoors, going very heavy on automating configuration and management.

outer nexus
#

Anyone know if dLink managed switches have issued with powerfailure and afterwards not working (no internet connection, all LEDs show up correctly, just no connection)...

little schooner
#

@outer nexus I've seen that happen on my net gear switch. All LEDs were lit and it was doing nothing. A reboot with the power cable disconnected for 1 minute solved the problem

outer nexus
#

@little schooner okay. Will try disconnecting it for one-two minutes ๐Ÿ˜ƒ

#

@little schooner thank you it worked. Now getting pings from the servers again ๐Ÿ˜ƒ

little schooner
#

No problem

#

it RARELY happens but when it does

#

its very noticable when the internet is down lol

celest geyser
#

Anyone here familiar with setting up NAT Reflection in pfSense?

celest geyser
#

I am inside my network trying to access my port forwards, but it's just giving me my pfSense Web Interface
Because it's figuring out like -> no need to go outside the network since wan ip == router ip -> i'll just give you the web interface
but i want to forward port 80 for example, and be able to access it from inside the network with the external wan ip

thick minnow
#

Ok guys, so I have an install of KDE Neon (based on Ubuntu 18.04) and it's running many processes with weird names, run as root. 192.168.1.65 is my phone's IP on the local network, but my phone isn't even on. This isn't normal behaviour, right?

#

Plus the random IPs, other than my phones one

pastel dew
#

@celest geyser
iptables -t nat -A POSTROUTING -o <interface
which can access wan> -s <private ip subnet> -j MASQUERADE

celest geyser
#

@pastel dew what exactly will that do? I am not too familiar with low-level iptables.

pastel dew
#

wait...
I misunderstood what you mean

celest geyser
#

I think so

#

I can show you in a screenshare if you want

pastel dew
#

@celest geyser
iptables -t nat -A PREROUTING -p tcp -i <interface> --dport <port listen on public ip> -j DNAT --to-destination <private ip>:<port listen on private ip>

#

if you connect to public ip:port it will forward to private ip:port

celest geyser
#

I just want to disable the wan -> internal ip routing, want it to go outside the network and actually reach the port forward rules

pastel dew
#

where is the service you want to access
I thought it's inside NAT. is it?
and want to access service which inside NAT using public ip?

celest geyser
#

Well, I want to check if something is port forwarded

pastel dew
#

I start thinking, is my English really that bad? (ยด๏ผ›ะด๏ผ›`)

celest geyser
#

I'm probably just stupid for the way I am explaining it

fresh copper
#

I think what @celest geyser is saying is that he sees these process making connections to the IP of his phone even when his phone is not on and does not know what they do and why they are making these connections.
In my quick research, I have no idea either. All the ones going to port 443 are probably https connections but I donโ€™t know about the ones to your phone. Maybe there is some sort of service that I donโ€™t know about for remote syncing or something.

celest geyser
#

Sorry Bryce I have no clue what you mean. My problem doesn't involve a phone or processes connecting to some daemon.

fresh copper
#

Oh

#

Wait

#

I look on the wrong person

#

Iโ€™m so sorry

celest geyser
#

Haha

#

No worries

fresh copper
#

It was some other person that just posted right in the middle of the conversation and I got confused

celest geyser
#

I think you meant @thick minnow

fresh copper
#

Yea

pine panther
#

are shielded ethernet calbles worth it?

#

and if they are what are the benefit from them

covert ibex
#

@pine panther
Good for high interference locations.
Like.. radio towers, MRI machines, bigger than personal servers.

pine panther
#

how about i buy these for my pc and personal use around the house?

covert ibex
#

@pine panther
Without links, that's showing my cart, not yours.

pine panther
obsidian matrix
#

so does anyone here have experiance with SuperMicro's IPMI system and ovh's implementation for ikvm as i am trying to install windows server 2019 mounted as a virtual disk over ikvm (Java iKVM viewer) and getting a max send of 1.2-1.5Mbps would restarting the ipmi possibly a fix throughput issues

thick minnow
#

Can anyone as simply as possible tell me the easiest way to have each of the seven different branch locations to be on different VLANs but use the 10.x.x.x A class network with a /16 CIDR block notation?

#

It's for my networking class final project. Figured I'd ask for some advice.

clear igloo
#

10.1.0.0/16
10.2.0.0/16
10.3.0.0/16
etc

#

Or are you saying you have a 10.0.0.0/16 network to subnet up?

thick minnow
#

2. The main location has a server which is required to be accessed by all users in the other locations. The server is on its own VLAN.

3. The network should use either Class A, B or C private IP Addresses and is to be subnetted for the required number of networks and hosts.

4. There should be a wireless network in all 7 locations and that wireless network should be a separate subnet at each location.

5. The company has an enterprise VOIP phone system, which should be on a separate VLAN at each location with a phone gateway at the main location.

6. All buildings have network video surveillance and that should be a separate network as well.

7. There is a physical door access security system that uses badges for entry. This should be on a separate network at each location.

8. Internet access all comes through the WAN to the main branch and there is a firewall at this location.

9. There are no fiber facilities between these branches due to geographical distances. We will assume a T1 WAN has been setup.
#

That's my assignment.

#

๐Ÿ˜‚ ๐Ÿ”ซ

#

๐Ÿ’ฅ

#

โ˜ 

#

lmao

#

I'm using Lucid Chart, so that's good at least.

#

You can collaborate if you want.

clear igloo
#

You need at least a /23 for the users and a /24 for wireless, and maybe a /25 for surveillance and another /26 for other security and one /26 for VoIP. So subnet out the original /16 so that each site has a /21

#

Vlan 10 - Server
Vlan 5x - Wireless Site x
Vlan 6x - VoIP Site x
Vlan 7x - Surveillance Site x
etc

pine panther
#

@thick minnow yo how do u make like a separet kind of winow like u did there

thick minnow
#

I kind of get what you're saying but what do you mean by VLAN 6x etc?

#

@pine panther Seperate Window?

clear igloo
#

6x = 6 + Site number
Site 1 would be 51, 61, 71, etc
Site 2 would be 52, 62, 72, etc.
And so on

#

If you really want to blow their minds set it up with hundreds instead of tens so 5xx, 6xx, 7xx, etc. so Site 1 would be 501, 601, 701, etc. to allow for more than 10 sites

#

I mean you could just have the same Vlan ID for each site and just use the IP address space to denote site as well since it's routed the VLAN ID won't be carried out of the local site

thick minnow
#

So like Branch 1: would be Hosts VLAN 1, WAP VLAN 2, IP -CAM VLAN 3...

pine panther
#

"youre assignment"

thick minnow
#

Oh that, code block thing? Just do the gravies key. to get

#

three on top and three on bottom.

#

@clear igloo I don't want more complexity, I just want a simple solution that works. I don't need real world examples or principles to follow here for this assignment.

#

If we collaborate you can edit my document and show me what you mean.

clear igloo
#

5x, 6x, 7x, is simple to me

thick minnow
#

What are you using double numbers for vlans?

#

why cant just VLAN ID for branch one be just 1?

#

Site two would be 2 etc...

#

And then within those vlans just have different subnets?

clear igloo
#

Because you need at least 4 VLANs per site

thick minnow
#

So B1 would be VLAN ID's 1,2,3,4?

clear igloo
#

The first digit signifies if it's user, wireless, voice, video, or security. The second digit signifies the site number

thick minnow
#

Interesting... so if I wanted I could say that 11 is users, 22 is WAP, 33 is voice, 44 is security, and 55 is Physical Sec?

#

And all that is just on one branch?

#

And each of those VLANS will have multiple subnets?

clear igloo
#

11, 21, 31, 41, 51 for site 1. Each VLAN has it's own subnet per what I mentioned earlier. You can, depending on your teacher, just keep it simple and reuse the same VLANs at each site but change the subnet IPs around

#

The VLANs are just local to the site but not sure how much of a stickler they might be about that if you don't mention it somewhere that the VLAN tag is stripped when it's routed to corporate

thick minnow
#

Nah, my professor isn't a stickler.

#

If I just make the diagram with an ok explanation it will be good enough.

clear igloo
#

Then just use 10 through 15 for each site. I avoid using VLAN 1 at all costs just out of habit and give each site a /21 and then subnet as mentioned before.

thick minnow
#

/21 CIDR for each site? What about like /22 for WAP or /23 etc..?

#

Hey, if /21 works, I'll take it.

#

I'll just have 4 separate VLANs and 4 subnets per building that's easy.

clear igloo
#

Simple would be this:
Site 1:
Users - Vlan 10 - 10.0.0.1/23
Wireless - Vlan 11 - 10.0.2.1/24
Voice - Vlan 12 - 10.0.3.1/24
Video - Vlan 13 - 10.0.4.1/24
Security - Vlan 14 - 10.0.5.1/24

Site 2:
Users - Vlan 10 - 10.0.8.1/23
Wireless - Vlan 11 - 10.0.9.1/24
Voice - Vlan 12 - 10.0.10.1/24
Video - Vlan 13 - 10.0.11.1/24
Security - Vlan 14 - 10.0.12.1/24

Site 3:
10.0.16.0/21 and so on

thick minnow
#

Makes sense, thanks for the help my friend.

#

Sorry if I'm dumb about this all.

#

lol

clear igloo
#

I miscounted, you need 5 and a /21 works

thick minnow
#

I still have 9 days left.

#

So I'm not too worried timing wise.

#

5 VLANS per building?

clear igloo
#

Yes, 5 per building

#

I was thinking wrong, forgot that a /21 gives you 10.0.0.0 through 10.0.7.255 so just /24s and a /23 for the users and you're set

thick minnow
#

This lists all the possible 10.0.X.X networks possible with /21 CIDR.

clear igloo
#

Yup, I wasn't subnetting right in my head ๐Ÿ˜›

#

Updated the example ๐Ÿ˜ƒ

thick minnow
#

254 hosts per each network is fine. it gives me enough wiggle worm.

#

Remember it's 200 people per branch.

clear igloo
#

But with expansion

thick minnow
#

200x8(I included the main branch.) comes out to 1,600 users.

#

254x32 =

#

~8,000 hosts.

pine panther
#

are shielded cables worth for home use?

thick minnow
#

And those all are just on one VLAN right?

clear igloo
#

@pine panther Unless you're running next to high voltage power, not really

#

@thick minnow The are on the same VLAN id but different subnets

thick minnow
#

1: Right so, that means I will need 5 VLANs per branch buildings. HQ will need 6 VLANS because there is a server at HQ that needs to be accessible to everyone and needs to be on it's own VLAN.
2: Since each location needs room for a minimum of 200 users, that means that I will need a subnet capable of holding at minimum 254 hosts PER network on the subnet.(We have concluded that subnet with CIDR prefix of /21 should be more than enough.)

clear igloo
#

Correct

thick minnow
#

I was just curious though, in the IP-Subnet-Calculator it says the the usable host range starts from 10.0.0.1 to 10.0.7.254.

Does that mean that 1.0.2.254 would be valid? Since it goes up to 10.0.7.254, does that also mean that there really is a total of 7x254 = 5,278 hosts just in that network range alone?

#

Or am I just make this more complicated than it needs to be?

clear igloo
#

Making it more complex. Remember, within that /21 you break it out further per VLAN

pine panther
#

This is literally the only channel i have unmuted here lol

half valley
#

Currently learning about subnetting in my networking class, gonna take awhile for my brain to wrap around. Weโ€™ve practiced with PacketTracer and soon to be our lab machines

hollow marlin
#

@half valley super easy once you get the hang of it. Just dont over think it, its how people get lost

half valley
#

thanks!

waxen scroll
#

Also lurick is right. That's a sane design. Don't listen to books where they make vlans for every group. Like marketing, sales, hr, etc. It's just not needed unless you're doing firewall segmenting, which almost nobody does

little schooner
#

@waxen scroll is 1000 clients a good spot to start using another vlan?

#

That broadcast domain would be getting big

hollow marlin
#

1000 clients is nothing

pine panther
#

So i got a hotel should i invest into a separate server or use adsl with switches

waxen scroll
#

/22 is biggest I'd use I think

little schooner
#

@waxen scroll that's around 1000 is it not?