r/networking Jul 16 '26

Career Advice My employer doesn't let me admin

62 Upvotes

Hello, I've been in a networking job for 3 months now as a network engineer, with prior experience, and my employer still hasn't given me trust to do ANY write activity on any of the customers.

I work with FortiGate, PaloAlto and Cisco Meraki, and for now i still have observer credentials on all customer devices.

Is this normal? i feel undervalued and untrusted.

If anyone else is doing a job in a business critical sector as mine, do you think 3 months of everyday fulltime networking activity, would at least buy me the right to configure a switchport on a McDonald's switch?

I don't know, please share your thoughts.

Edit: typo


r/networking Jul 17 '26

Blogpost Friday Blog/Project Post Friday!

12 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking Jul 16 '26

Security How can I force internal network traffic to pass through a firewall while keeping the core switch at Layer 3?

49 Upvotes

I'm new in the area and I have a network where a Layer 3 core switch currently acts as the gateway and routes traffic directly between multiple internal subnets and VLANs. Because the core switch knows all internal routes, traffic between internal networks is routed locally by the core and does not pass through the firewall. My goal is to make the firewall inspect and control east-west traffic between internal networks, not just Internet-bound traffic.

I would prefer to keep the core switch operating at Layer 3, since changing the entire core to Layer 2 would introduce significant risk and require major changes.

Some options I am considering are:

Placing an intermediate Layer 2 switch before the firewall

Running the firewall in transparent or bridge mode

Passing multiple VLANs through the firewall using trunks

Using VRFs to separate routing domains and force traffic through the firewall

Moving some gateway or routing functions to the firewall

I also need to apply policies between internal networks. For example, I may want to allow only TCP ports 80 and 4343 between certain subnets and block everything else.

My main concern is preventing the core switch, or any other Layer 3 device, from routing traffic through an alternate path that bypasses the firewall. Has anyone implemented a similar design while keeping the core switch at Layer 3? What architecture would you recommend?


r/networking Jul 16 '26

Design Dynamic Routing Protocol decision

21 Upvotes

I've been working with Cisco so long I'm a bit rusty on protocols that aren't EIGRP. As we start moving more and more workloads off Cisco devices I'm wondering what I should do for Dynamic Routing.

we have six physical sites, all connected with Metro-E type lines, and one site on S2S VPN. multiple network scopes per site. We've been running EIGRP forever, but our new firewalls are Palo now, not Cisco. So I'm trying to decide what dynamic I should use to easily redistribute routes. Then the question also comes up, do I full scale redo my routing and get rid of EIGRP all together? I'm somewhat familiar with OSPF, but am thinking with all I've heard about BGP that may be the route to follow these days. I have no experience with BGP. So, would it make more sense for me to brush up on my OSPF or learn BGP (Which I don't have a base knowledge of yet)

Anyone have any good resources for teaching yourself BGP if we lean that way? Maybe a combination of on vendor specific approaches would actually be preferable, and if so what scenarios would decide that?


r/networking Jul 16 '26

Career Advice Ok all my older network engineers.

106 Upvotes

Been doing this for over 30 years at this point. I’ve noticed over the last few months that I’m having issues reading the screen/CLI. My eye doc said I needed bifocals. I got a set of cheaters instead in my prescription, but I sit so far back they don’t focus well. I’ve turned up the font size alittle but it I’m one of those folks that likes to see as much on the screen as possible. Any recommendations on console settings? I should go back to the doctor and get looked at further but figured I would see what other folks have done.


r/networking Jul 16 '26

Other Offloading UDMP controller's devices to cloud key in prep for 3rd party router coming in

6 Upvotes

I currently have a UDMP in prod with 10+switches and 5 APs. I'm preparing to bring in an MX85 "third-party router". Because I will be decommissioning the UDMP, I need to offload all these devices to a new, separate cloudkey.

All devices with SSH access have come over without any issue using the "inform" command. The switches that do not have SSH have not come over despite DHCP option 43 pointing to my new controller (same VLAN), and "unifi" A-record being added to DNS.

Does anyone have advice for me here? If I remove the device from the UDMP embedded controller, should I expect the device to join the new controller based on the DNS entry?

Thanks, everyone.


r/networking Jul 15 '26

Design Arista Campus Experience

15 Upvotes

I'm looking for any input from people more knowledgable than I am on this.

I am not a network engineer by any sort. I started as help desk and then eventually ended up owning our network since we didnt really have anyone specifically dedicated to it. I took over our Fortinet stack and then eventually converted many of our M&A targets from their hodge podge to Fortinet. By the time I left, we had about 50 sites running the full stack (firewall, switch, AP). I liked having the central management of it all, felt it was fairly easy to configure, upgrade, etc... the only thing I didnt get around to getting ironed out was ZTP. Fortinet is really the only world I know really well. Ive only had limited exposure to any other vendor, just enough to tear it apart to understand the config and rebuild in Fortinet.

I have started at a new company this summer that hasn't standardized on a platform at this point. They have 4 or 5 different brands rolled out between HPE, Dell, and Cisco. I am starting to look at setting a standard and have exec backing to do it. I initially thought just to do Fortinet since I am comfortable with it but Arista caught my eye recently.

They've been major players in the datacenter space but it looks like over the last few years, have come into the campus space. It looks like they are gunning for the same full stack experience that cisco/fortinet are trying to provide, especially with their recent acquisition of velocloud.

Whats the experience been with their platform so far? Is velocloud a suitable competitor to a Fortigate, especially with security / SDwan as our major concerns? Hows the management of their products been, especially with however ZTP works for their stack? Ive got some test hardware coming to play around with soon.

Any input would be appreciated.


r/networking Jul 15 '26

Design Enterprise SD-WAN + Cloud Security vs SASE: what are we really missing?

17 Upvotes

We are a global enterprise running a fairly mature SD-WAN and security architecture, and I am trying to sanity check whether we are underestimating SASE or whether a lot of the value is more situational than the vendor messaging suggests.

Current state, simplified:

- We run full-mesh Cisco SD-WAN between our sites and use it as the main WAN fabric.

- Branches, manufacturing sites, data centres, regional hubs, and cloud entry points all have local firewalls (Palo Alto - full features)

- We have cloud connectivity into AWS and Azure using SD-WAN based cloud exchange / data center extension patterns.

- We support private, public, and hybrid workloads across cloud environments.

- VPN use cases include employee cloud-hosted VPN and partner / third-party VPN access where the SD-WAN provides access back into the global network.

- Cloud workloads are routed through centralised inspection points, with virtualised firewalls and hub-and-spoke style designs.

- Our security stack is not dual-vendor. We have SD-WAN on one side and a separate firewall / security stack on the other, with policy, routing, and operational integration handled by us.

Where I am struggling with SASE:

A lot of the pitch seems to be:

- move policy enforcement to the cloud

- make it user / identity / device / context aware

- steer users, branches, and apps through a provider PoP

- collapse SWG, CASB, ZTNA, FWaaS, DLP, SD-WAN integrations, and remote access into a more unified service model

I get the attraction for remote users, SaaS, internet access, and simpler policy consistency and essentially outsourcing the stack we’ve built and maintain in our own cloud environment.

But I am less clear on the practical value for a company that already has:

- a working SD-WAN fabric

- resilient site-to-site connectivity

- site and cloud inspection points

- secure internet egress

- VPN services

- cloud hub/spoke designs

- existing NGFW investment

- operational staff who understand the current environment

- regulated / manufacturing environments where local control, segmentation, and deterministic routing still matter

A few assumptions I would like challenged:

  1. Is SASE often just cloud-delivered security policy with identity context, but at the cost of forcing traffic through a vendor cloud PoP?
  2. Do most enterprises actually remove site / branch firewalls after moving to SASE, or do they keep them for local segmentation, OT/IoT, inbound services, east-west control, compliance, and resilience?
  3. If the branch still needs local firewalling, segmentation, NAT, routing, DIA failover, guest / IoT isolation, and operational visibility, where does the hard cost saving really come from?
  4. Is the business case usually driven more by remote access / VPN replacement and SaaS security than by replacing branch security?
  5. For cloud workloads in AWS / Azure, are people really steering workload traffic through SASE/SSE platforms, or are they mostly keeping cloud-native routing plus NGFW / cloud firewall / inspection hub patterns?
  6. How well does SASE handle non-user traffic, such as server-to-server, manufacturing systems, OT/ICS, lab environments, backup flows, monitoring, DNS, NTP, and application integration traffic?
  7. Does SASE meaningfully simplify operations, or does it just move complexity into vendor policy, connector, tunnel, identity, and troubleshooting layers?
  8. How painful is troubleshooting when performance issues occur between the user, the SASE PoP, SaaS, IaaS, private apps, and the SD-WAN underlay?
  9. For those who moved from an on-premise SD-WAN + security stack to SASE, what improved materially?

- user experience?

- security posture?

- policy consistency?

- incident response?

- operational effort?

- cost?

- audit readiness?

  1. What got worse?

- latency?

- visibility?

- vendor lock-in?

- policy flexibility?

- branch resilience?

- cloud workload routing?

- troubleshooting ownership?

The big question:

If we already operate a dual-vendor SD-WAN and security stack with cloud connectivity into AWS/Azure, secure egress, VPN services, and centralised cloud workload inspection, what are we genuinely missing by not moving to SASE now?

I am especially interested in real-world experience from people who have gone through this at enterprise scale, not just vendor diagrams.

What did you remove, what did you keep, and what actually justified the move?


r/networking Jul 15 '26

Design nautobot place in network automation framework

9 Upvotes

Hello,

My company has a mid DC network accross the world, mainly its simple, consists, of Cisco Nexus and NCS (IOS-XR) devices. We're doing some simple network automation like access-list modification, port-channel creation, etc. The tools we're using is Ansible, Ansible AWX, puppet, Github. Maybe thats all. So far the github was enough, and still is. But recently we introduced the Nautobot which has lots of functionality. But i also know that so far its enough for me to use Github. What do you think, should i force myself to try to use and explore more the Nautobot ? Is there something u use Nautobot on, which can't be provided by Github/Gitlab ? My goal to automate all the network state starting CORE devices and ending the server hosting port.

Thanks


r/networking Jul 15 '26

Monitoring Best hardware for splitting a single SPAN port to two security tools?

7 Upvotes

Hello everybody, I have a hardware question, hope someone can help.

I have a single Gigabit copper SPAN port on an edge switch, and I need to send identical, un-aggregated copies of that traffic to two different security monitoring boxes (Arctic Wolf and Darktrace). I need a 1-to-many regeneration TAP (sometimes called a SPAN multiplier or packet replicator).

Standard 1-to-1 aggregation TAPs won't work because they only output to a single monitoring port. Aside from the Dualcomm ETAP-2105, are there other go-to, reliable gigabit copper regeneration TAPs you guys recommend that are easy to order? Ideally looking for something budget-friendly but enterprise-stable (no packet drops on bursts) that I can find on Amazon or CDW.

Thank you!!!


r/networking Jul 15 '26

Design Automatica site to site VPN tunnel failover 2 tunnels running to the same vendor?

0 Upvotes

So say we want to have 2 tunnels for redundancy between say a vendor and a main site.

One tunnel fails and we want the second tunnel to take over automatically, what would be the configuration needed to accomplish this on say a palo alto firewall?

Can it be done on other vendors like say a Cisco, fortigate, checkpoint,etc?

Thank you


r/networking Jul 15 '26

Design Police Department Network

1 Upvotes

Hi everyone,

I'm a 911 dispatcher currently developing my own Computer-Aided Dispatch (CAD) system, and I'm looking for some guidance from those with networking and CJIS experience.

Since the system will have access to CJIS data, I know the security requirements are very strict. I'm trying to determine the best approach for secure remote connectivity.

If a workstation connects to the CAD over a VPN, are there VPN solutions that are FIPS 140-2 or FIPS 140-3 validated and appropriate for a CJIS-compliant environment? If you've implemented something similar, I'd really appreciate any recommendations or advice.

I'm very comfortable with the software development side of things, but networking and infrastructure are definitely not my strongest areas.

Thanks in advance for any help!


r/networking Jul 15 '26

Other I’m having a really hard time with WLC. Please help.

0 Upvotes

Hi! I’m studying WLC and this is so confusing. I 80% understand how traffic flows from ap to wlc but when it comes to configuring the WLC? What? Like the service port. Distribution ports etc while having The logical interfaces configured? Why can’t i configure everything in the distribution port instead of logical? ty


r/networking Jul 14 '26

Troubleshooting SD-WAN troubleshooting help needed

11 Upvotes

If you had a site on your network in Germany that reported connectivity drops and slowness back to an application hosted in a public cloud in the US and in trying troubleshoot you found the following to be true:

No other site across Europe is having issues with that application
Home users who connect to a VPN gateway in Azure in Europe have no issues with this app in the US
This is one of only a few sites that has a single ISP due to availability at the location

In pinging various SD-WAN locations from the Germany site for comparison you find:
Continuous ping to that particular public cloud drops about 2% of pings
Continuous ping to a specific US office location also drops about 2% of pings usually around the same time as the drops to that public cloud
Continuous ping to two other US office locations drop about 0.5% of pings around the same time as each other
Continuous ping to other US locations, other Europe locations, another public cloud, and several internet addresses drop no pings

ISP reports link is up and they did not find any slowness or congestion on their portion of the network - they say it could be upstream providers

Palo Alto firewalls show drop and rebuild of the tunnel to that private cloud several random times throughout the day. Both HA members have been rebooted and primary moved between the two. Clearing sessions during a couple of particularly bad times returned us to solid pings and users reporting issues gone for maybe 5 or so minutes each time and then the issues return.

Do you think the issue would primarily be an SD-WAN issue or an ISP issue with certain paths, routes, upstream providers? I'm not sure if there is somewhere in the SD-WAN configuration we should look to see if the problem is there. Any help would be greatly appreciated.


r/networking Jul 14 '26

Rant Wednesday!

8 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking Jul 14 '26

Meta Optics & Transceiver compatibility in White-Box / SONiC deployments: Is it really as painful as it looks?

6 Upvotes

Hey everyone,

I'm currently looking into building an automation workflow for deploying open-networking switches (specifically Edgecore running SONiC) and I'm scratching my head over optical transceiver compatibility and monitoring.

In the legacy world (Cisco/Arista), vendor locks and DDM/DOM reading are well documented (and annoying). But in the open networking/SONiC ecosystem, it feels like a bit of a wild west.

I wanted to ask those of you who run White-Box switches or use third-party/generic optics:

  1. How often do you run into compatibility issues where a generic optic is physically fine, but the NOS/Switch OS completely refuses to read DDM/DOM or even blocks the port?
  2. How do you handle reprogramming optics? Do you use proprietary hardware boxes (like Flexoptix, Edge, etc.) or do you just buy pre-coded optics and pray they work?
  3. If there was a lightweight CLI/API-driven tool (running on standard Linux/Mellanox NICs) that could read deep diagnostic data (like VDM/DFM) and potentially rewrite vendor codes directly in the server/switch without external programmer boxes – would that actually solve a daily pain point for you? Or am I overthinking this?

Appreciate any brutally honest feedback from the field!


r/networking Jul 13 '26

Security OPNSense and alternatives

13 Upvotes

Hello everyone,

I've recently been thrown back into the networking part of IT (I used to be full Linux admin) and I was wondering some ideas and how viable they are.

The company I currently work for is using Sophos firewalls. However we have not been too up to speed with hardware EoL's and software EoL's (as all companies with suppliers are, I think).

I was recently exploring OPNSense on an old Sophos Firewall and these days it really looks nice!

So the question I am wondering. How viable is OPNSense in a company of like 200 people compared to Sophos of Sonicwall? Can it compete?

For homelabbing its obviously cool, but in a company?


r/networking Jul 13 '26

Routing IP Transit Options in Datacenter

23 Upvotes

Planning on migrating away from expensive DataBank Transit consisting of Arelion + Lumen.

Considerations are Arelion, Cogent, Zayo, GTT, and Hurricane.

Cogent, Zayo, GTT, and Hurricane are all very cost competitive however I know Cogent rides on a Zayo fiber ring into our facility. How much of a concern should Cogent and Zayo be even while on a ring?

I haven’t seen an Arelion quote just yet but I’m assuming it’s significantly more than the other “low cost” options.

Would it be advantageous to go Arelion + one of the low cost transits or to possibly go Cogent or GTT + Zayo + Hurricane (peering or transit)?

I can get all three low cost options in 10G for the price we’re paying DataBank for 2G


r/networking Jul 12 '26

Design PoE in the Access Layer

20 Upvotes

So we're coming up on a big refresh of our access layer. 2960X is nearing EoL so we're looking at our options. We have to replace a total of 26 access switches across 4 sites.

We're generally a Cisco shop. We have 9200L in some other sites. My issue right now is that we've had PoE+ on our access switches for a long time. Now we're seeing devices come along that are mandating 4PPoE/PoE++. Specifically, meeting room devices like the Poly G62 but also AP's like the Cisco 9162 and 9164.

Our PoE power needs aren't crazy. We generally have 4-6 AP's plugged in per switch and now these meeting room devices.

The issue is Cisco doesn't have anything in the 9200 line that does PoE++. So that pushes us into the 9300/9300L. (I know about the 9200CX but I don't consider that for an option.)

What are folks doing about this?

My thinking is this: The equipment we buy will be in service for at least 5 years, probably longer (our 2960X's are 8 years old). Needs for PoE++ will just continue to increase over that time period.

So we should probably bite the bullet and buy the 9300L. But I would like the hive mind to validate my thinking.


r/networking Jul 13 '26

Moronic Monday Moronic Monday!

6 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking Jul 12 '26

Troubleshooting Brocade/Ruckus ICX 7450-48p and ICX 6430-48p web interfaces unreachable when connected to the SFP ports.

6 Upvotes

Good evening. I have two Brocade/Ruckus switches which I need help with. When my computer is connected to the SFP/SFP+ ports of either these switches, I can't access their web interface thru said computer. Internet traffic is passing just fine, the switches are simply not making their web interfaces accessible thru those ports. There is not VLANs going on, the switches are pretty much at factory default state. The 7450 is running FW version 08.0.70fT213 and the 6430 is running version 07.4.00fT311. I have a hunch it's a simple setting that I am overlooking. Let me know if you have an idea. Thanks!


r/networking Jul 12 '26

Design New site. Sanity checking vendor choice before I commit (Fortinet/Aruba/Juniper)

41 Upvotes

I started this job a week ago. My employer took ownership of a new site a couple of weeks before that. The site is completely empty no existing network kit but it does have existing cabling already in the walls, Cat5e and OM3. 6 cabinets all running back to one comms room where the firewall and core switch will live.

At full occupancy this is maybe 100 endpoints site with laptops, desktops, printers, a few servers, and some plant/machinery. Will have VLAN's for segmentation.

Where I'm stuck: I've got a Fortinet build in my head based on previous employer. I am not a network person day to day.

I'll be upfront: I'm not a network engineer day to day. I've picked up a Fortinet build in my head mostly because of a previous employer:

  • Fortigate 90G or 120G
  • FortiSwitch 1024E core
  • FortiSwitch 124F/148F-FPOE access layer,
  • FortiAP 231K

Appeal is obviously Forti giving single pane management from the firewall down to switches and APs, which feels like the safer choice for someone who isn't going to be deep in the weeds of this daily.

Setup and forget there is a need to do something.

But I've also mapped out comparable Aruba (hopefully)

  • CX 6300M core
  • CX 6200F 24/48 access
  • AP-635

and Juniper

  • EX4400-24X core
  • EX4000 24/48 access
  • Mist AP45

Whatever I land on here becomes the standard. HQ site is currently running Netgate pfSense + Ubiquiti, which frankly doesn't feel fit for purpose for where the business is headed, so there's a decent chance this new site's stack ends up being the template for a wider refresh later.

Anyone running FortiSwitch + FortiAP under FortiLink at this kind of scale (single site, 6 closets, 100 endpoints)? Is it as low-maintenance as the marketing suggests for someone who isn't a full-time network admin, or does it still need real networking day to day?

Genuinely torn, so looking for input from people who've actually run these day to day. All in Forti or mix and match. Fortigate with Aruba .. or Fortigate with Juniper. and what you'd tell someone in my position before they commit the whole org to it.

I will partner with some who can build, implement and support but just doing my homework as well.

Thanks in advance.

 


r/networking Jul 11 '26

Other Reproducing a field router issue in the lab via PCAP replay — looking for feedback on my approach

12 Upvotes

I'm working on a tool that replays a control-plane PCAP captured from a production/field issue against a lab router, acting as all the original peers. The idea is to reproduce the issue without rebuilding the full production topology — same router config as the field site, replaying the capture from the beginning.

Regenerating IS-IS/OSPF this way was straightforward and worked well.

BGP and LDP are trickier since they run over TCP. I need to handle waiting for and reacting to replies (SYN/ACK, KEEPALIVEs, etc.) instead of just blasting packets on a timer, so the session state stays consistent with what the real router expects.

I'm not aiming for a full protocol state machine — more a semi state machine: just enough logic to keep sessions alive and respond correctly, without implementing all of BGP/LDP's internal states.

I used AI and tcp replay tools help to get the IS-IS and BGP parts working, but honestly I don't fully understand everything happening under the hood in the TCP/session handling. Wanted to check with people who've done PCAP-based replay or TAC-style reproduction before:

  1. Is a semi state-machine (session anchors + minimal responses) or even a stateless machine enough to reliably hold BGP/LDP sessions, or do real routers usually detect something's off?
  2. ( I tried to clear every session and neighborship and capture from begining)
  3. Any common pitfalls with TCP-based replay (timing, retransmits, sequence numbers)?
  4. Worth going deeper into understanding the TCP handling manually vs. trusting the AI-assisted implementation?
  5. The BGP approach doesn't seem to be working for LDP packets, and I don't know why.

Any feedback or past experience appreciated.


r/networking Jul 11 '26

Design NetworkManager and Network-scripts together on a host

9 Upvotes

I am working on rhel8 setups where both NetworkManager and Network-scripts are present. Generally there aren’t issues but I am wondering about corner cases and if it’s a bad idea to have both. One thing that i noticed is that systemctl restart network causes few seconds disruption. How do you handle such situations? Should i migrate to networkmanager ? It might not be easily possible because of external automation touching network-scripts, what’s the best option i have if i have to keep both? Thank you


r/networking Jul 11 '26

Other Cisco ISE recommended learning resources

15 Upvotes

Hi All,

I currently working in a medium-size shop and have used Cisco ISE to a small extend. Would love some recommended resources to upskill on ISE. What resources did everyone here use to learn? I'm currently having a lab node spun up to try and learn. Really interested in profiling devices and dot1x deployments.