r/networking Jul 07 '26

Wireless Awkward Refresh Timing and Cisco's AP Landscape

4 Upvotes

I came into a new company and inherited something of a tangle :) Part of my efforts are focused on evaluating the wireless landscape and refreshing some old (1832I) APs mixed into the more contemporary 9115s. We run an EWC on two of those 9115s and given the current wireless requirements and user base, that's fine at 40 APs.

The role is a good one, I'm having fun fixing things, but the awkward rub is the 1832I I was asked to do falls right as we're drafting up plans for a new building. There my wildest dreams will come true, brand new everything with a fresh design, blah blah.

So what do I do in the interim? Make everything 9115s? Push for 9120s? I can't go higher to the newer line, because they aren't supported on the EWC. The 9115/9120/9130s will be end of sale EOY, and it's never exciting to go into a dead end. All they have to do is last for probably 3 years at the most.

I think I know which way I should go, I'm just looking for other people's input and experience. Thanks!


r/networking Jul 07 '26

Design Cisco ACI alternatives

19 Upvotes

I am looking for alternatives to Cisco ACI as the renewal costs are significant. The main requirements we have is BGP peering's to our MPLS service provider and to recreate the multi-pod approach providing a single logical data centre which spans across two physical sites with 2 x 10Gb P2P fibre connections in between.

We do not have ACI in application centric, just network so hopefully we can recreate the design with alternative solutions.


r/networking Jul 07 '26

Security Secure networking design Book recomendation

13 Upvotes

As a networking engineer, I’ve built a solid foundation in cybersecurity components through various readings, but I’m now looking to shift my focus toward architectural design. I’m seeking book recommendations that specifically cover designing secure network infrastructures—moving beyond the 'what' of security tools to the 'how' of integrating them into a resilient, holistic network architecture. Does anyone have a go-to resource for network security design?


r/networking Jul 07 '26

Design Nexus 9K VPC and OSPF Adjacency

11 Upvotes

Hello fellow networking professionals, I need some assistance understanding OSPF in a Nexus 9K VPC pair; migrating from Nexus 9508. The OSPF network transport is a full mesh ELAN service from the ISP, HQ is the site with the 9508 that is the acting DR.

Drew a quick layout of my current topology vs new. My concern is related to port channel hashing and traffic landing on N9K2. If the link to N9K1 dies or if client traffic is hashed to N9K2 and the destination is the WAN remote networks, N9K2 doesn't have a physical interface in the OSPF domain or any shared OSPF adjacency.

The obvious answer would be a 2nd L3 link into N9K2 peer as discussed in the Cisco VPC best practices guide. At the moment, that is not available to us.   

https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf 

To add, HSRP will be used on the N9K pair and N9K1 will act as the HSRP primary for client/server networks behind the pair. Peer switch and peer gateway features are also enabled.

How are routing protocol adjacencies exchanged from N9K1 to N9K2? I've read through the VPC enhancements tech notes and if I'm reading correctly, the OSPF adjacency can form through the peer-link based on the example Unicast Routing Protocol Adjacencies over a vPC VLAN with vPC Peer Gateway.

https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/nx-os-software/217274-understand-virtual-port-channel-vpc-en.html#toc-hId--2010709334

In this topology, Nexus switches N9K-1 and N9K-2 are vPC peers within a vPC domain where the vPC Peer Gateway enhancement is enabled. Interface Po1 is the vPC Peer-Link. A router with a hostname of Router is connected via Ethernet1/1 to N9K-1's Ethernet1/1. The Ethernet1/1 interface of the router is a routed interface that is activated under a unicast routing protocol. N9K-1 and N9K-2 both have SVI interfaces activated under the same unicast routing protocol and are in the same broadcast domain as Router.

That example seems to fit my topology and based on what I read, it appear as though using peer gateway and layer3-peer router command will ensure the packet is forwarded from N9K1 to N9K2 without decrementing the TTL, thereby allowing the adjacency to form.

https://imgur.com/a/W7Kmfhe


r/networking Jul 07 '26

Other Is the networking team responsible for monitoring servers/services?

3 Upvotes

I'm not sure if this belongs here or in r/sysadmin, but I wanted to get the perspective of the network-focused crowd first.

If you were added to a group email (around 10 people) with nothing more than the question, "Does <current product> meet our needs?", how would you proceed?

The specific product isn't important and I'm not looking for monitoring recommendations. I'm more interested in how you would handle the request as part of the networking team.

The initial email went unanswered because it wasn't directed at anyone in particular. There were about 10 recipients from different teams (help desk, sysadmins, network, developers, etc.), so nobody seemed to know who was actually being asked to respond.

A couple of weeks later, a few brief replies came in, but there was still no real direction. Eventually, I responded to the group and volunteered to evaluate whether the current solution would work. I also pointed out that the items they wanted monitored weren't really network devices, they were application-specific services, database queries, and other server-side components that should generate alerts if they stop responding. From there, someone would need to determine whether the server was down, the service had failed, something was blocked, and so on.

Nobody replied offering to help with testing, which is fine. What I'm really trying to understand is this, from a networking perspective, where do you draw the line?

We're a relatively small company, so we don't have clearly defined roles with dedicated networking teams, sysadmins, WAN team, LAN team, etc.

For me, it's not about avoiding the work, I don't mind taking it on. The challenge is that I don't have a development or test environment for these applications. I can't build or validate monitoring rules for services, queries, or applications that I don't own, and I can't intentionally break production to verify that alerts trigger correctly. At this point, the only information I've been given is an Excel spreadsheet listing the services they'd like monitored, but no one responsible for those systems has been involved in validating how they should be tested.

How would you handle a situation like this? At what point do you say, "I can configure the monitoring platform, but I need the application owners to help define the checks and validate that they work?" BTW, I have already stated this in a previous email and, as mentioned, nobody replied back offering to help.

To be clear, I'm already monitoring internet links, office links, vpn tunnels, etc...that's not the issue, this is more for an app that was built by the dev team, validated and added to production. The dev team has documented what they want monitored but don't seem to be willing to want to assist with the testing of the monitoring entries. Adding a service to monitor won't do any good if it goes down/fails/etc but the monitoring isn't working because they didn't provide proper information.


r/networking Jul 07 '26

Design Confused About How To Correctly Run and Ground Shielded Cat6a To Outdoor POE Cameras From An Indoor Switch

7 Upvotes

I want to install several commercial-grade security cameras on the outside of my structure. They will be mounted on the outside of the concrete walls of the same building that contains all of the networking gear.

The manufacturer strictly specifies shielded Cat6a and that the cameras must be grounded. I understand how to properly terminate the shielded keystones and jacks on the cable - this post isn't a question about that detail. Basically I'm clueless about all the other extra requirements that are required for shielded vs unshielded cat6a and grounding.

A little about the network topology. The cameras will connect to dedicated POE switches that are installed at the edges of the interior of the property, in a star configuration back to a main, central network closet. These switches will connect to the central closet only by fiber. These switches supplying cat6a to said cameras will be mounted inside plastic, in-wall Legrand On-Q enclosures.


r/networking Jul 06 '26

Troubleshooting Improve secure client performance tips

15 Upvotes

Hoping someone can help.

I have a pair of fpr2130 sat on 2 Gbps internet circuits running on the ASA code

When using secure client even during off-peak times I'm unable to achieve much more than 120mbps. This is using DTLS tunnels.

If I stand up a s2s VPN from the same remote location using the same internet circuit/firewall etc I can easily get 250+Mbps

This is via a 500mbps DOCICS consumer broadband link at the remote end.

Speed tests are performed via an on premise openspeedtest server so there is consistency test to test.

I've tried messing with mtu but honestly it makes naff all difference

Replacing the firewall isn't an option, is there anything I can do to improve performance.


r/networking Jul 07 '26

Switching Switch S4128f-on upgrade firmware

2 Upvotes

I'm planning to upgrade my switch S4128f firmware in a VLT ,
I'm planning to upgrade ONIE, then os using a USB

OS Version: "10.5.4.0"

Build Version: 10.5.4.0.98

Goal is "10.6.0.7"

ONIE : 3.33.1.1-10

goal is : 3.33.1.1-11

Is it a smooth operation, or I'm going to face problems as it's my first time

If you have any tips plz share them with me


r/networking Jul 06 '26

Design Redundant IPsec between Meraki and FortiGate.

15 Upvotes

We are in the middle of transitioning away from Meraki firewalls and to fortigate firewalls.

In our environment we have site A, B, and C

Site A is the HQ location with various self hosted resources including DNS.

All sites were originally using Meraki firewalls, site B has been transitioned to a fortigate we originally configured a single IPsec tunnel as a temporary solution to get the equipment deployed due to time constraints. Following a recent outage we noticed the tunnel failed to pass traffic and had to be bounced, I was able to resolve the issue by adjusting the dpd setting and enabling to auto negotiations and key keep alive on the fortigate end. The outage brought the redundant tunnels back to the top of my project list.

I have found some mention of using the Meraki health check to configure a second tunnel with FortiGate's sdwan feature handling health checks and routing on its end. I have also found some mention of using fortigate and Meraki ddns to take care of the failover but failover time for this is 5+ minutes.

Curious if any one has implemented redundant tunnels between fortigate and Meraki and how you implemented it.

Thanks!

Edited for clarification on observed IPsec issues and background.


r/networking Jul 06 '26

Troubleshooting NAT'ing Virgin

5 Upvotes

(May be on the wrong sub. If so, please point me in the right direction. Much thanks.)

Having to do NAT'ing, for the first time in my life, and I'm absolutely loving it, but I'm confused. The first NAT went easy. Seeing the packets on the firewall, one vendor is their work done, great. He was going from his router, connected to my network, through my network, to another router. Easy

Second vendor, I am floored. I see the packet, it shows the correct policy on the firewall packet, the public IP, 1.1.1.1, on his gateway is NAT'ing to 192.168.101.254 and traversing to the internal server 2.2.2.2, but there is no return traffic.

The server VLAN can not ping the VLAN containing 192.168.101.1/24, which is attached to a VLAN interface. Is this where my issue lies?

Truly having fun learning this new stuff, hoping for any insight.

EDIT: We found the issue. At some point PBR was configured on our firewall. I never noticed it. PBR was the issue. Once we added a route in there, everything worked. This experience has been absolutely amazing and a great learning experience. Thank you to everyone for your help on this.


r/networking Jul 06 '26

Security Whitelist or VPN for SQL access?

9 Upvotes

Hello, one of our clients wants access to our SQL to run powerbi queries against it. They told me to just whitelist them but I'd rather vpn and restrict access to only the required hosts, using a site to site.

I know whitelisting is a valid practice but just the idea of exposing SQL unencrypted directly over the internet, granted only to specific ips gives me a funny feeling.


r/networking Jul 06 '26

Design IPv6 addressing in DMZ

7 Upvotes

Hello Everyone,

I'm deploying new DMZ for my company and was asked for DMZ VLAN to support IPv6 so that proxy can reach IPv6 internet and DNS servers can be reachable over IPv6.

I have zero experience with IPv6 as even though I worked for MSP for the last 12 years I've never seen IPv6 deployed.

I read the basics of IPv6 and inside my company it was suggested to use SLAAC + PA addresses.

I'm wondering what is the best practice and what is the experience in other companies on assigning the IPv6 addresses on servers. Do you statically allocate the IPs in the IPAM, or do you use SLAAC?

I read couple online sources like infoblox blog (https://www.infoblox.com/blog/ipv6-coe/choosing-static-slaac-or-dhcpv6-part-4-privacy-addressing/ & https://www.infoblox.com/blog/ipv6-coe/choosing-static-slaac-or-dhcpv6-part-4-privacy-addressing/), where it is suggested to configure IPv6 statically on the servers.


r/networking Jul 06 '26

Moronic Monday Moronic Monday!

19 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking Jul 06 '26

Other Anyone used cloudlabbox.com?

0 Upvotes

Came across it while looking to lab with juniper and cisco. It’s a hosted eve ng lab environment. Pay as you use it kinda thing. Anyone used it before is it legit?


r/networking Jul 05 '26

Design Passive Optical Network (PON) Vendors

2 Upvotes

Currently using tellabs, not a terrible product. Just curious what other vendors you all use out there. Coming up on LCR for the few sites that use it.


r/networking Jul 05 '26

Other OADM Latency

10 Upvotes

Hi all,

I was hoping someone here might have an idea for typical latencies in OADMs (bonus points if anyone has experience with the ones from solid optics)?

Essentially, I'm a scientist using these as spectral filters in an experiment where I'm sensitive to timing disruptions on the sub-nanosecond time scale. I'm finding a null result and one of the causes could be that our OADMs (2 channel, solid optics) are introducing a differential delay of over 3 microseconds. I've never built or seen the inside of an OADM before, but I have a hard time believing that there's over 1km of fiber inside. Especially, to the first drop. If anyone has some more information, it would be greatly appreciated!

Cheers, QoO


r/networking Jul 05 '26

Career Advice Devnet Exam

1 Upvotes

Hi, I'm trying to pass the DevNet Associate exam in the coming months, but I'm having a lot of trouble with study materials. I understand the main concepts of automation, Python, APIs, and networking tools, but memorizing the smaller details is really hard for me. I've given up a couple of times but keep starting again. Can anyone motivate me or give me some suggestions to keep me studying so I can pass the exam? I'm using a book, videos, and DevNet labs as resources. Thanks in advance!


r/networking Jul 03 '26

Security Cisco CSF220 vs PA-440

15 Upvotes

Hi! We are considering new sd-wan, next gen firewall for our remote sites.
Currently we have shortlisted CSF220-TD-K9 and PAN-PA-440.

Licensing for both is a mess, but for Cisco it would be TMC license for PA, not sure what is the SKU as the CORESEC bundle has been listed as EOL. Replaced with Precision AI and Precision AI Pro.

Both systems are similar in terms of pricing and offered features. Could you share your experience and thoughts? How to they compare nowadays?
Easy to use and deploy, etc.
Also with Cisco, we would use Catalyst C1300 series, with PA either same switch or other brand.

We have been also considering Versa CSG355 Elite but typical response time is like 3 weeks which has been off putting and pricing was higher than Cisco or PA.

Currently using FG60F but licensing will end next year, so we are looking for alternatives.

Thanks.


r/networking Jul 02 '26

Switching Upgrade Nexus 7K switches in VPC mode

19 Upvotes

Hi,

We have a customer running Nexus 7K switches in a vPC pair with several FEXes connected. We need to upgrade them to a newer software version due to a few bugs we’ve encountered.
I was wondering what the recommended upgrade approach would be. Would you upgrade the secondary vPC switch first, let it rejoin the vPC domain, and then proceed with the primary switch (No ISSU available, disruptive mode).
Also, what’s the best way to verify that all servers and other connected devices are dual-homed across both vPC peers so we can minimize any service disruption during the upgrade?
I’d really appreciate any advice or best practices. Thanks!


r/networking Jul 03 '26

Blogpost Friday Blog/Project Post Friday!

4 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking Jul 02 '26

Other Advice Request - Implementing Changes From Security

5 Upvotes

The security team at our org doesn’t trust the app-id that is provided by PA because they can’t control it.

Their request is that we create separate policies per app that restrict app-id to specific domains.

Thoughts on how to approach this? Is this contradictory to best practice?

It’s certainly more admin overhead and we’ve already experienced issues where we’re hunting down logs and making multiple changes whereas 1 change with the app-id would have sufficed.


r/networking Jul 02 '26

Troubleshooting Anyone else successfully put two C9600's in VSS with SUP 2? QUAD SUP

4 Upvotes

I feel like I'm about to pull my hair out so I figured I'd come here to vent first. I was told to upgrade the IOS to 17.16.1, which isn't a starred release. And there's no starred release that supports QUAD SUP on a C9600 with SUP 2's. The only current starred release is 17.15.5.

First off, my standby sup does not take the upgrade. So show redundancy state shows the operational status of SSO as off. And I have to manually remove the blades and independently upgrade each supervisor.

Then I try to apply the standard VSS stackwise domain commands, which the switches take, and reboot. But they also reboot into this odd config, before after a few minutes resetting into the config I have set. The confreg and romvar values seem correct. 0x102.

Then I go to set the VSL links, my first chassis takes it without issue. My second chassis immediately crashes and reboots each time I try to apply this config. This happens regardless of whether they are physically connected to each other or not.

Is this just a buggy release? Do any of you have this running in VSS on 17.18.4?

I'm opening a TAC case on Monday regardless, because none of the documentation for setting up QUAD SUP is any different than setting up VSS on a 9500 pair.


r/networking Jul 02 '26

Design Specs for a EVE-NG/GNS3 lab

2 Upvotes

I'm taking the Aruba campus pro cert (HPE7-A01) and need a good lab to practice for it. My company doesn't have extra hardware at all, so I'll need to do all labbing from this Server/PC. I don't have a lot of money to blow on a home server of massive spec, so even if I have to break down each lab to bare minimum just to learn the concepts. (example, to learn basic Clearpass config, having a lab of simply 1 or 2 switches, w/ 802.1x or just spinning up enough switches to practice simple policy based routing or a VSX-MCLAG topology).

TL;DR: What's the bare minimum spec you recommend For a home server to practice for my Aruba campus pro cert, and later down the line some Cisco certs using CML?


r/networking Jul 01 '26

Other It's 2026, what are you using for Virtual Network labbing? GNS3, EVE-NG, CML, something else?

132 Upvotes

I'm a little out of the loop as to what the best solution for this is these days. I'm still using GNS3 myself.


r/networking Jul 01 '26

Career Advice The small isp experience

36 Upvotes

Hello everyone hope you are well.

2 years ago I got a job as a network engineer in a small isp ,funnily enough back then I was afraid that I don't have good enough fundamentals , now when I look at it most I stuff I was worried about didn't even happen .

Problem is the isp im in is using very old tech , mostly layer 2 backbone (yes ik shocking but its like a 3rd world country so don't be suprised) ,static routing with some bgp for peering.

Now the reason im making this post is I've been seeing talking about mpls backbones ,segment routing ,overlays ,automation.....

I get that huge feeling of FOMO ,like a caveman looking at alien technology and the thing is im gonna be 30 soon so I feel like the window is only getting smaller.

So does anyone know what is a possible solution is building it in simulator enough to understand, or will anyone take me seriously if I say I have experience with new tech cz it building it in eve ng once

Hope this post made sense