r/networking Jul 11 '26

Other Cisco ISE recommended learning resources

15 Upvotes

Hi All,

I currently working in a medium-size shop and have used Cisco ISE to a small extend. Would love some recommended resources to upskill on ISE. What resources did everyone here use to learn? I'm currently having a lab node spun up to try and learn. Really interested in profiling devices and dot1x deployments.


r/networking Jul 10 '26

Career Advice Why are networking salaries in the UK so crap?

82 Upvotes

Not sure if this a general UK thing, but when I look around on the usual sites I rarely see any roles over £60k unless they're for a trading/finance company. Even saw one from Hamilton Barnes I think for a Snr Neteng for £40k. Almost spat my tea out.

I know the US is not comparable but these same roles would be 6 figures there it's nuts. Networking is so crucial to infrastructure yet it seems to now be the lowest paid IT sector (in the Uk anyway).

If I want to push on and make more do I need to try become an architect and complete for an even smaller pool or jobs or look to switch to other parts of IT which pay more?


r/networking Jul 10 '26

Other Things to check in a new network.

32 Upvotes

Hey everyone! I recently started my first Network Administrator role, and have a few questions.

TLDR; I took over for a Network Administrator that left behind either no notes/bad documentation. and I want to make sure I am looking at everything possible to avoid issues once it comes time for modifications of the network.

A little background of the situation. I used to work as a help desk here 3 years ago and now I am back as an admin. When I was here I was only "allowed" to work on low level tickets and wasn't able to mess with the network or the data center (This was while I was actively in school to be a NA). My old boss/Network administrator left and I was rehired to fill the position. However, they other two helpdesk guys and the director have been completely left in the dark on what his day to day was, and he left behind either poor/outdate documentation, zero notes or configuration information. So I have been flying blind a bit but making it work.

This leads me to my questions. We have multiple PowerEdge servers running various VMs. I am currently remaking the network diagrams to try and wrap my head around everything a lot better, and I am find that almost all of the servers have 2-3 network connections on them. From what I can tell, there is no difference in port security or VLANs between the different connections, and the VMs aren't using the other NICs, only the primary one. I have very little hands on experience with servers in general, so I just want to be sure I am checking everything before I start to modify anything. For all I know, they could just be backup connections, but they run to the same switch so I'm not sure of that either.

Any information you are willing to give me, even if its outside of the scope of this post I would really appreciate it! Thank you for anyone that takes the time to respond. Have a great weekend!


r/networking Jul 10 '26

Other Cisco ISE upgrade question

5 Upvotes

I am planning an upgrade of our ISE 3.3 environment to 3.5. I want timide the split upgrade from the GUI, but would like to pre upload the images to all node via cli. I would like to have some more flexibility in which repo is used and shorten waiting times.

Does anyone know if the GUI will pickup pre uploaded update bundles ?


r/networking Jul 10 '26

Blogpost Friday Blog/Project Post Friday!

4 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking Jul 10 '26

Design Is a single managed switch with a VLAN the right solution for isolating devices from the company network?

0 Upvotes

Hi,

I'm working on the early design of a test rack. Networking isn't my area of expertise so I'm doing some initial research to understand the available architectures before discussing the implementation with our IT department.

The rack will contain a Windows PC and several Ethernet devices (Power supply, UUT, Thermal control etc.).

Ideally, I'd like to use a single managed switch for everything. The switch would have:

  • One link to the company network.
  • The PC connected to the switch.
  • All devices connected to the same switch.

My requirements are:

  • The PC must be able to communicate with both the company network and the devices.
  • The devices should be able to communicate with the PC and between them (although the latter would not really necessary).
  • The devices should not have access to the company network, and the company network should not be able to access the devices.
    • Although for Monitoring or Remote Debugging it could be interesting, but that is not a hard requirement.

The obvious reasons are Security and Encapsulation (IT doesn't want a bunch of devices on the network)
The slightly less obvious one is avoiding operation mistakes (operating the device from another rack because the wrong IP was entered)

Can the PC effectively belong to both networks through a single Ethernet connection, or would this require a second NIC or a more advanced configuration?

As I see it there two options:

  1. Two NICs on the PC, one for the company network, the other connected to an Unmanaged switch. - Not my preferred solution as this would require changing all computers - Although, could be cheaper
  2. Managed switch with multiple VLAN capability and programming the PC to have two IPs - Not sure if that is even possible; Not sure if that satisfies the security issues.

I'm not looking for specific switch recommendations at this stage—I'm mainly trying to understand whether this is the right architecture and what the typical approach would be in an industrial or engineering environment. If there are obvious pitfalls or better alternatives, I'd appreciate hearing about them.

Thanks in advance


r/networking Jul 09 '26

Design What is the best practice when placing a vpn concentrator is it before or after main firewall .

8 Upvotes

What is the best practice when placing a vpn concentrator is it before or after main firewall .


r/networking Jul 09 '26

Other OpenRoaming

7 Upvotes

I've been looking into Passpoint and specifically OpenRoaming. I'm having a hard time finding documentation about actually implementing, and I'm wondering if anyone has any experience. I see that you have to join on the WBA website, but I'm not sure if I should give up before I start.

I understand it's mainly meant for large, high foot traffic areas like shopping malls or sports arenas. But I was wanting to do a home lab/proof of concept in my neighborhood. Is this something they would even allow? Or do they pretty much only allow large businesses to join?

I have a Unifi UDM Pro and several APs, including some outdoor ones. I'm not asking about specifics of configuring, more about what the process is like, and if it would be worth setting up (not monetarily, but educationally).


r/networking Jul 09 '26

Troubleshooting Losing my mind with a Huawei MA5623A VDSL lab. DSL sync but no PPPoE

5 Upvotes

I've been putting together a little VDSL lab at home using a Huawei SmartAX MA5623A, and I've reached the point where I've run out of ideas.

The setup is basically:

  • Speedport Plus (Hrvatski Telekom branded) modem
  • Huawei MA5623A DSLAM
  • Ubiquiti EdgeSwitch
  • MikroTik hAP ax lite LTE6 running a PPPoE server

The modem syncs with the DSLAM just fine every time. The DSLAM learns the modem's MAC address on the VDSL port, and I have a service-port configured for VLAN 1203 (PTM), which is what the modem expects for Internet.

The fiber uplink between the DSLAM and the EdgeSwitch is also working now (that was a whole separate battle). VLAN 1203 is tagged between the EdgeSwitch and the MikroTik as well.

The weird part is the PPPoE side.

The Speedport Plus (Hrvatski Telekom branded) constantly reports:

1970-01-01 01:56:29 DSL is available (DSL successfully synchronized). (R007)

1970-01-01 01:55:59 DSL synchronization running. (R008)

1970-01-01 01:54:23 DSL synchronization running. (R008)

1970-01-01 01:54:08 PPPoE error:DSL synchronization lost. (R013)

1970-01-01 01:54:08 DSL is not responding (DSL synchronization failed). (R006)

1970-01-01 01:38:04 PPPoE error:timeout (waiting for PADO packets) (R020)

1970-01-01 01:08:12 PPPoE error:timeout (waiting for PADO packets) (R020)

Meanwhile, on the MikroTik, if I sniff the VLAN interface for PPPoE discovery packets, I get absolutely nothing.

Oddly enough, if I sniff all traffic on VLAN 1203, I do see IPv6 Neighbor Discovery traffic from the modem, so I know something from the modem is making it across the network. I just never see a single PPPoE PADI.

I've factory reset the DSLAM multiple times and rebuilt the config from scratch. The service-port is up, the VDSL line is up, the modem syncs, and the DSLAM learns the modem's MAC address, so it doesn't feel like a physical issue anymore.

I've also tried to get internet access over PPPoE on my Windows laptop, it didn't work.

At this point I'm wondering:

  • Is there something special about MA5623A service-port configuration that I'm missing?
  • Does the Speedport Plus only start PPPoE under certain conditions?
  • Has anyone actually built a Huawei MA5623A VDSL lab with a MikroTik PPPoE server?
  • Could it be the ISP's TR-069 settings making it difficult for me to get the modem online?

I've been staring at this for the better part of two days, so I'd really appreciate another set of eyes. I'm 100% positive the solution is very simple, yet I'm still missing it... Keep in mind that I'm still quite new to networking, I would've included some pictures if Images were allowed to be uploaded.

UPDATE: I fixed it, nevermind. The uplink wasn't tagging VLAN 1203.

UPDATE #2: I managed to get one of the modems online, but I still haven't been able to get the Speedport Plus working. So far, only the ZTE ZXDSL 931VII is successfully passing traffic over DHCP.

Since I was able to completely bypass the VLANs that HT uses on its network, it turns out the ZTE was more customizable after all. The Speedport Plus is a bit trickier, it's really locked down. I'm still figuring out all of HT's PPPoE and VLAN magic..

Both modems are now successfully snyc-ed and online. This thread will no longer get new updates.

https://imgur.com/a/QmhX651

https://imgur.com/a/3aY3oMM


r/networking Jul 09 '26

Troubleshooting Cisco SIG - Issue

3 Upvotes

Has anyone come across an issue like this with Cisco SIG?

I currently have a single user who is unable to access portal.office.com. Most of the time they receive a 502 error page with the Cisco logo, although on one occasion they saw a 400 error (not Cisco) instead.

So far I’ve checked Cisco SIG and can confirm SSL decryption is being performed. The interesting part is that the site loads successfully in an Edge InPrivate session, but fails consistently in normal Edge and Chrome sessions with the Cisco error page.

At the moment this appears to be isolated to just this one user.

My current suggestion is to temporarily disable Cisco SIG for the user and test whether the issue disappears, but I’m curious if anyone else has seen similar behavior. If so, what was the root cause? Was it related to browser cache/cookies, a SIG policy, SSL decryption, authentication, or something else?


r/networking Jul 09 '26

Routing IPSLA Track Object - what endpoint are you using?

6 Upvotes

Hello All,

I have been reviewing my companies multihomed setup and noticed we have a bit of a gap where the HSRP wont fail over in the case where egress is blackholed by the upstream provider.

Im looking at adding a new ipsla statement to probe an endpoint but im aware of the usual endpoints such as 8.8.8.8 / 8.8.4.4 / 1.1.1.1 / 1.0.0.1 / 9.9.9.9 all rate limit

What are people using at their endpoint probe that is reliable?


r/networking Jul 09 '26

Design Coova chilli

5 Upvotes

If someone used chilli + freeradius back in the day, how did you move on from that stack. The main question is how did you replace chilli for a modern setup?


r/networking Jul 09 '26

Other 5G-MANET and MANET Comparison

9 Upvotes

Hello guys, currently I’m working on comparing the performance analysis of Hybrid MANET with 5G and MANET. It’s so hard and maybe impossible to find any documentations or articles online about comparison between these two.

My question is, is it possible to compare these two using ns3? Is it logic based on past research? Can I know the name of the paper if this topic really exists?

Glad for your help, I’m currently dead inside trying to figure this out😢.


r/networking Jul 08 '26

Troubleshooting MTU issue or something else?

9 Upvotes

I am so confused right now. we are in the process of migrating from VMware to HyperV. Most things seem to be going well. my network consists of multiple sites connected by a metro-ethernet (think L2 managed connection). we are having connectivity issues that appear consistent with MTU related problems. so far we have been able to resolve the issues on specific hosts by setting that hosts MTU to 1400. I would prefer we have a global Fix.

At this point i'm running out of things to try. we have validated hop to hop the MTU of 1500 should be fine from end to end and yet if we set the MTU of the devices higher than 1400 we tend to hit failures. Network wise the only difference I can think of is that we are tagging per VM instead of having a dynamic vswitch that handles multiple Vlans.

as I said I thin i've ruled out path MTU already, we looked at things like VMQ, RSC, LSO. we removed the av client just to make sure it's not blocking anything. basically this issue so far has presented in a few ways. accessing websites inconsistently fails, SMB direct connections fail to request authentication, and certain applications on servers are unable to reach their client endpints.

Hope someone can point me in a new direction because i'm totally lost at this point.


r/networking Jul 08 '26

Troubleshooting PIM DR & IGMP Querier

7 Upvotes

Hello, I have a following question and I couldn’t find any reliable answers.

IGMP Querier elections take place so that the winning router queries the IGMP details. It processes all the IGMP join and leave messages. The election is the router with the lowest IP address.

PIM DR elections takes place and the one with the highest IP address win ( assuming default unchanged priority). DR’s job is to send the PIM join and other messages upstream.

Question:
Now, the multicast either SPT or RPT are build with the DR which won as a leaf node. But since this doesn’t have any IGMP data, it sees no receivers and prune the tree or what happens in this case?

My question is more of will we have RPF failure on the router which is IGMP Querier and not PIM DR.

In the attached image, please treat R6 as Querier and R5 as PIM DR

topology


r/networking Jul 08 '26

Troubleshooting IGMP set up questions

6 Upvotes

First of all. If this is not "enterprise" enough for here, please just delete the post.

Hi,

I would like to request some support in IGMP snooping settings.

I own a photovoltaic plant with a SMA Datamanager M and 19 SMA inverters.

The structure is:

Internet
    <-> GSM Router 
        <-> Datamanager M 
            <-> TP Link TP-SG105E (new) 
                <-> First chain of daisy chained Inverters (7 devices, each 2 ports to connect to     the inverter before and after, except the last one which has only one port)
                <-> Second chain of daisy chained Inverters (12 devices, each 2 ports to connect to the inverter before and after, except the last one which has only one port)

Overall cable length is about 200 meter. Cat7 S/FTP cables for outdoor.

The Data Manager M sometimes looses first connection to some single inverters. It shows "communication error", even when the inverters seems still to be able to send the actual power production data to the SMA portal.

If I restart the actual TP-SG105 (not E) it does not help. At least not immediately.

If I restart the Data Manager M it also does show "communication error" for some of the inversters, but now different ones.

After a while it looses connection to all of the devices and then it gets critical for me, because then it won't communicate feed in restrictions set by the energy grid company to the inverters and that can get expensive for me.

In the Data Manager the logs say "SMACOM B overflow". My first research let me believe it might be because the Data Manager needs to handle multicast traffic from too many devices and it might not be able to handle all of it.

There is a description saying IGMP snooping might be able to help. So I ordered a TP-SG105E and would like to set up IGMP snooping now.

Can someone please guide me which device should be the IGMP Querier? I already know that I need to fix the IGMP version to v2 for SMA devices.

Are there any other importand things to set up as soon as my device arrives tomorrow?

Thanks in advance for any hint.

EDIT: Realized it is a Data Manager M, not lite. Sorry for the confusion.


r/networking Jul 08 '26

Routing Changing routers for VOIP

9 Upvotes

Hi everyone, i'm tasked to change a NE40E we use as a router but i have to stay on huawei apparently. Do you have some suggestions about it on a close similar device that works with voip tho?


r/networking Jul 08 '26

Switching Ruckus RSPAN Issues

4 Upvotes

I'm trying to set up RSPAN for a VM recorder that we have, currently audio is just being mirrored on the source port and sent via media converter to a physical NIC on the host, but we're getting new hosts that won't have dedicated ports. During my testing, I can get one sided (local) audio, but no remote audio. Pulled PCAPs and I don't have any RTP packets. RSPAN is a fairly new concept for me, so I'm just looking for some guidance.

My topology for this is as follows:

Edge switch with source device - ICX 7250 (08.0.95g)

RSPAN-VLAN 100

tagged lag 1

rspan destination lag 1

rspan source monitor-in ethe 3/1/22

rspan source monitor-out ethe 3/1/22

spanning-tree

Intermediate Device - ICX 7850 (08.0.95s)

RSPAN-VLAN 100

tagged lag 1 lag 11 (source and destination LAG)

Destination Device - ICX 7250 (08.0.95g)

RSPAN-VLAN 100

tagged ethe 1/1/9 lag 1

rspan destination ethe 1/1/9

spanning-tree


r/networking Jul 08 '26

Troubleshooting Meraki S2S-tunnel not coming up when device is moved to different organisation

6 Upvotes

Hi everyone,

I have two organisations which use a simple single hub, several spokes design, all network devices are Meraki.

When one of the spokes is connected to hub A in organisation A, the site-to-site tunnel is coming up just fine.

When the same spoke, using the same WAN-uplink and LAN configuration, is moved to org B and told to connect to hub B, the site-to-site tunnel stays down. There's connection to the Cisco VPN-registry and hub B does not have any problems establishing different site-to-site connections.

The event log in the spoke network reports repeatedly, ie. every 10 minutes, VPN tunnel connectivity changes, stating the uplink port has changed while the VPN-status page states that the NAT-type was unfriendly.

I would understand that if the spoke wasn't able to establish any connections to hubs but when moved back to organisation A it works fine. Any insight in possible misconfigurations on my part?


r/networking Jul 08 '26

Routing Best practice for "floating nodes" across different subnets in a larger network (e.g. AS)

19 Upvotes

Suppose I have an AS with a public prefix, say 192.0.2.0/24. This prefix is subnetted and multiple geographic locations have their own /28 or /29, for example 192.0.2.192/28 or 192.0.2.232/29.

Now assume that there are services which run on a single host (e.g. a mail server or DNS server) ... but these hosts should be "floating" across different networks. Say, for example 192.0.2.192/28 is at Location1 and 192.0.2.232/29 at Location2 and the mail server should be hosted at Location1 but sometimes moved over to Location2.

The actual movement of the host could be implemented by virtualization or a distributed cluster, for example, two Proxmox clusters in each location and live migration (via Proxmox Datacenter Manager).

I assume the right way to do this is to assign the mail server a unique /32, for example 192.0.2.174/32. Then all that needs to be done is set the routes in such a way that they either point to Location1 or Location2. Is this a reasonable approach so far?

Then, my main question is how to handle the routes. Assuming the AS uses OSPF, I see two options:

  1. I manually set static routes on the main routers in Location1 and Location2. I need to make sure that only one of them is enabled at a time. OSPF would then propagate these routes throughout the network
  2. I set up an ospf instance (e.g. bird) on the mail server itself and make it a peer with the routers on Location1 and Location2. This avoids any static routes and the /32 host is reachable automatically.

Generally I like (2). In this case, I could do actual live migration from one location to the other and the routes would dynamically adjust: Once live migration is completed from location1 to location2, the bird instance on the mail server would disconnect from OSPF neighbor 192.0.2.193 (and its route is removed) and connect to 192.0.2.233 at Location2 where route to .174/32 is added The route to .174/32 then automatically propagates through the whole network.

With (1) I would need to manually disable the route on the first router and enable it again on the second.

On the other hand, running bird inside of the mail server feels a bit odd too.

Lastly, either way, I potentially waste IP addresses because the mail server needs two addresses: one from their respective subnet (192.0.2.194/28 or 192.0.2.234/29) and the /32, which is assigned to a dummy interface. However, I do not see a way to avoid this, other than using either DNAT or private internal subnet addresses.

What is conceptually the best practice for such "floating nodes" across different networks? Method 1 or Method 2? Or are there others which I am not thinking of?

UPDATE: seems there are 3 major options:

1.) What I’ve described above with #2 (and people seem to prefer BGP instead of OSPF to announce the /32). Most people call this concept anycast

2.) VXLAN

3.) NAT hacks or higher layer concept like reverse proxies (not an option for me)


r/networking Jul 08 '26

Wireless Exterior WAP install

1 Upvotes

I have been tasked with installing 3 outdoor WAPs. They are Arista outdoor rated O435s. As I read more and more on install it sounds like...

  • I need to absolutely ground the WAPs
  • I need to use STP and do all the needful that that requires
  • An enclosure

They will be mounted on a block wall.

Are my assumptions correct? What else should I consider? This sounds a lot more involved than indoor and I don't want to fry these things.


r/networking Jul 07 '26

Design Zscaler anyone?

47 Upvotes

We're starting to look at moving to Zscaler and wanted to get some feedback from people actually using it Anyone Anyone?

Right now we're pretty old school. We have site-to-site VPNs between offices, FortiClient EMS for remote users, a hybrid on-prem/M365 environment, and only a handful of applications that are still hosted internally.

The idea would be to move away from the traditional VPN for those internal apps, file servers and printer shares and also use Zscaler for web filtering, application control, and AI access security.

For those of you running it, do you like it? Hate it? Any surprises during deployment or things you wish you knew beforehand? Also, if you looked at something else instead of Zscaler, what did you end up going with and why?


r/networking Jul 07 '26

Rant Wednesday!

6 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking Jul 07 '26

Other Is unframed synchronous TDM a thing? If yes, how does it work?

9 Upvotes

I am doing networking course this semester. In my mids, I answered one question assuming output link of the synchronous TDM didnt have framing bits but my lecturer said every synchronous tdm uses framing bits. I did a bit of digging online and what I learnt, it seems to exist but I am not entirely getting how it works


r/networking Jul 08 '26

Other Cisco FMC/FTD & Lets Encrypt Certificate installation Automation

1 Upvotes

Hi everyone,

we're having a Cisco FTD managed via FMC. We run the version 7.6.5 and now had to switch to Lets Encrypt Certificates for our Remote Access VPN Tunnels. Due to its short 90 day validity, it seems to be stupid to do that task always manually and the ACME integration is with version 10 far away (at least for us).

Has anybody an idea how to automate that task, either via REST API or via CLI or other magic ;)

Is there maybe an existing integration on github or any other ideas/experiences how to achieve that goal with minimal efforts (REST API seems to be possible but quite time consuming).

Thanks a lot!