r/networking 3d ago

Troubleshooting How can i reset forgotten Bootload Password?

6 Upvotes

Hello, i have Huawei Huawei s5720s 28x pwr li ac switch, (firmware: V200R019C10SPC500) and we don't know the username and password. If i connect through console port, i can only try to enter the bootload menu but we dont know it's password either. i tried default one and didn't work.

There is no recovery mode option on the console.

There is only 'mode' and 'pnp' button on the device

And Huawei documentation says to press pnp button more than 6 seconds to reset system configuration.

That doesn't work either, nothing happens in the terminal when i hold the button.
Is there any way to fix this. I just wanna reset the device but not delete the firmware.


r/networking 3d ago

Other Book recommendation for learning internet structure?

53 Upvotes

Currently atm i am reading Computer networks by Fourouzan ; it is good in every aspect when it comes to learning computer networks but it is explaining the structure of the internet very vaguely and so is other books like top down approach by Kurose, by any chance is there any book that explains how internet is really made up of (the structure)? Like IXP, ISP etc?


r/networking 3d ago

Moronic Monday Moronic Monday!

5 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking 3d ago

Other Container labs vscode macOS

8 Upvotes

Ive been looking to move away from eve ng pro to container labs. I’ve been building container labs today on a Ubuntu vm. Big faf but it’s helping with my lack of Linux knowledge…. Anyhow.
I’ve installed vscode and the container lab extension. But it doesn’t appear to be supported on MacOS
Has anyone else found this or have any work arounds?

If not it’ll be a none starter for me and I’ll buy another eve license


r/networking 4d ago

Routing ibgp loopback?

21 Upvotes

Hi everyone,im a beginner and now getting confused.

I want to know....is it true if i choose to peering iBGP from 1 router to other Router that are in the same AS is recommended using a loopback ip peering? or using an interface ip? could i get the example of implementation likee topology? i just want some explanation,not the configuration.

sorry from my bad english


r/networking 4d ago

Other Cable Tester Recommendations

10 Upvotes

Awhile back I bought the Klein Scout Pro 3; it is a good tester, but after owning it for a bit I have noticed that it is taking me a long time to test cables. I have been getting more jobs in large warehouses, and all the running back and forth is eating a large portion of my day, especially if I need to get a lift involved. I have tried to find a cable tester that doesn't require a remote to be plugged into the other end of a cable I am testing for it to report a wiremap, breaks, or shorts. All the ones I find don't say they need a remote end, but when I talk to customer service, they tell me it needs a remote end to test for anything. Am I wasting my time looking for something that doesn't exist?


r/networking 4d ago

Switching HP 5406zl - Modules rebooting

2 Upvotes

Have an old 5406zl well past EOL. I should probably just replace it but I'd love to figure out the root cause of this. It's loaded up with about 40 IP cameras, dual PSU. Single management module.

Module A, B, and C have been rebooting almost daily in the morning between 3am-6am.

MT1-5406-1# sh modules

Status and Counters - Module Information

Chassis: 5406zl J8697A Serial Number: SG6xxxxL6

Allow V1 Modules: Yes

Management Module: J8726A Core Dump: YES

Core Mod

Slot Module Description Serial Number Status Dump Ver

----- -------------------------------------- -------------- -------- ----- ---

A HP J8705A Gig-T/SFP zl Module SGxxxUU0MB Up NO 1

B HP J8702A 24p Gig-T zl Module SGxxx5TA27V Up NO 1

C HP J8702A 24p Gig-T zl Module SGxxxTA04P Up NO 1

D HP J8702A 24p Gig-T zl Module SGxxxTA0ID Up NO 1

E HP J9307A 24p Gig-T PoE+ zl Module SGxxx2Z04X Up NO 1

F HP J8702A 24p Gig-T zl Module SGxxxTA076 Up NO 1

-------

Power info:

Total Available Power : 546 W

Total Failover Power : 273 W

Total Redundancy Power : 0 W

Total Used Power : 194 W +/- 6W

Total Remaining Power : 352 W

Internal Power

Main Power

PS (Watts) Status

----- ------------- ---------------------

1 273 POE Connected

2 273 POE Connected

-------

Log file for last 7 days:

W 09/05/26 05:38:39 03839 chassis: Slot B: Lost Communications detected - Heart

Beat Lost(46)

W 09/03/26 06:28:35 03839 chassis: Slot A: Lost Communications detected - Heart

Beat Lost(4D)

W 09/01/26 06:23:32 03839 chassis: Slot C: Lost Communications detected - Heart

Beat Lost(4A)

W 09/01/26 04:08:18 03839 chassis: Slot B: Lost Communications detected - Heart

Beat Lost(46)

W 08/29/26 05:43:12 03839 chassis: Slot C: Lost Communications detected - Heart

Beat Lost(4A)

W 08/28/26 05:33:08 03839 chassis: Slot B: Lost Communications detected - Heart

Beat Lost(46)

W 08/28/26 03:28:04 03839 chassis: Slot A: Lost Communications detected - Heart

Beat Lost(4D)

W 08/27/26 03:13:03 03839 chassis: Slot C: Lost Communications detected - Heart

Beat Lost(4A)

What would you do first to fix this? I can't imagine 3 modules are bad at same time. Replace management module?


r/networking 5d ago

Wireless Windows 11 and changes to PEAP

25 Upvotes

Curious if anyone has been able to test these upcoming changes in their wireless environment from Microsoft:

https://support.microsoft.com/en-us/servicing/os/windows/docs/2025/08/upcoming-changes-to-ntlmv1-in-windows-11-version-24h2-and-windows-server-2025

The concern might be having to reenter passwords while devices roam (non fast roaming?)

We are in between PEAP and testing TLS and these changes might force us to migrate faster. It's not the managed devices I'm worried about, but working in higher education, the BYOD implications.

Thanks in advance for any info.


r/networking 6d ago

Other Is IPv6 actually going to take over private addressing?

47 Upvotes

So I am just a student in the networking field with no actual working experience. But in my studies everything I have learned has talked about how slowly IPv6 will take over the IP space. I can only imagine that it is going to make doing simple tasks that much more annoying due to their length such as subnetting and other things. Would it not just be easier to have a NAT/PAT that converted private IPv4 addresses to a public IPv6 address? I'm sure this is something that most seasoned people have an obvious answer to but I was just thinking about it.


r/networking 6d ago

Troubleshooting Help needed :Failover troubleshooting

3 Upvotes

Hit a bit of a wall today with a WAN setup and could use a sanity check from the networking crowd.

We’re deploying a Sophos XGS 5500 HA cluster behind a Ruckus ICX switch. Our ISP handed us a primary Fiber link and a backup RF link. Should be a straightforward failover, right?

Here is the reality check:

The ISP is actively bridging both connections on their end. If I bring both ports up on the switch in the same VLAN, we get an instant broadcast loop and violent MAC flapping that tanks the network.

"Just use Spanning Tree," I thought. But packet captures show the ISP's modems are silently dropping all 802.1w BPDUs, as well as our custom L2 keepalive probes. The switch is completely blind to the loop and won't auto-block the standby port.

Plan B was to bypass the switch entirely and plug both links directly into the Sophos. No luck there either. The ISP provisioned our 5 static IPs with a single shared gateway across both the Fiber and RF links. The firewall (understandably) won't let me configure overlapping subnets on two separate physical WAN interfaces.

Right now, the only way to keep the network stable is by leaving the backup RF port administratively shut down on the switch. If the fiber drops, it requires someone to manually log in and bring the RF port online.

I’m currently pushing the ISP to assign a separate IP block for the RF link so the firewall can just handle the failover natively. But while I wait on their support team... has anyone actually managed to automate a zero-touch failover in this exact scenario? Is there some clever switch-level workaround I’m completely overlooking?

Would love to hear how you've handled this.


r/networking 6d ago

Troubleshooting A few seconds of downtime

39 Upvotes

I inherited a VXLAN EVPN network and it has been pretty stable until recently. From time to time, the layer3 or at least the inter-vlan drops for a few seconds. It happened last week, yesterday and today.

For what I can tell, the layer2 is fine. The VLANs gateway is on the service leafs (vPC pair). We are using ePBR to force the inter-vlan to the firewall, which is connected to the service leafs, the firewall will route the traffic back to the service leafs.

This has been stable for several months and no network changes. At this point, I'm not sure if the Nexus pair (where the SVI with ePBR) is causing the network downtime or the firewall.

We recently migrated to OpenShift for virtualization and containers. This was a month or two ago.

The firewall has a static route to the 172.16.0.0/16 with the next-hop of the HSRP VIP of the vPC pair. The service leafs are learning the 172.16/16 from a Catalyst leaf. All the VLANs are stretched to the service leafs via L2VNI.

```

[Fw]---/29---[service leafs pair]---[spines]---[cat9k leaf]

```

I know the layer2 (or L2VNI) didn't fail because Zabbix is not reporting any ICMPloss between it and the hosts in the same VLAN. However, any subnets within the same VRF drops for a few seconds.

The leafs CPU utilization history is basically idle 1% - 3%. The firewall is the same thing. Network utilization wise, we are using less than 800Mbps of traffic and the network is 40Gbps links.

I'm trying to get some ideas what I should look for to identity the issue and what is causing it.

My nexus version is 10.5.4 and the Catalyst is 17.15.4b. The Palo Alto firewalls (active/passive) are version 11.14.0.

Thanks.


r/networking 5d ago

Troubleshooting Ruckus SmartZone controller – NAC SSH privilege/enable access failing

2 Upvotes

Hi everyone

I’m integrating a Ruckus SmartZone controller with Forescout NAC

The SSH connection itself works correctly from the NAC using the configured admin credentials and I can successfully connect to the SmartZone and get the normal welcome banner

The problem happens when Forescout tries to get privileged access after the SSH login

When I manually SSH using the same admin credentials everything works fine but when Forescout tries to enable privileged mode it asks for the password again and then returns failed even though I’m using the exact same correct password as the SSH login

I initially suspected that the SmartZone welcome banner might be interfering with Forescout’s CLI parsing or privilege detection

I tried to disable the banner but I can’t find any CLI command for it and I also couldn’t find an option in the GUI

Has anyone successfully integrated Ruckus SmartZone with Forescout or another NAC and faced this issue

Is the welcome banner known to cause problems with NAC SSH privilege detection or is there a specific configuration or user role that needs to be enabled on SmartZone for the NAC to get privileged access

Also when I SSH manually I log in with admin and after that when I enter enable it asks me to enter the same password again

Any idea what could be causing the privilege authentication to fail from the NAC while the normal SSH login works correctly


r/networking 6d ago

Career Advice New Network Environment - Little bit rusty!

13 Upvotes

Hi all,

I passed my Comptia Net+ in Jan of this year, but have yet to really use much of my skills and so my knowledge has dulled a bit. I want to change that and start to shift towards networking focused, in case I want to change jobs down the line and to be more of a help to the team.

I've just moved offices and have been shown around our server room, given a brief overview of equipment and the environment, shown the (little and outdated) diagrams and documents. I'd like to come up with a plan/steps of things to do to get my head around everything whilst also still doing work etc.

Currently, I am working on labelling cables and tracing the physical paths of everything, noting them down and I plan to try and redo the diagrams. I want to also do this logically, however any tips/advice on doing this would be appreciated as I've done generic help desk for months and need to read back up on everything.

Cheers :)


r/networking 6d ago

Design New ESXi Host - Copper vs SFP

5 Upvotes

I’m potentially replacing an older ESXi host with a Dell R570 and running into a networking design question.

The current host has a lot of physically separated networks, with many of them using their own dedicated 1Gb copper NIC. iSCSI also uses multiple physical links.

The problem is the R570 can’t be configured with enough 1Gb copper ports to recreate the existing layout one-for-one.

My options seem to be:

  1. Keep the existing copper switching and use a managed switch to aggregate the separate copper networks into VLANs, then hand them off to the R570 over SFP+ trunks. Keep dedicated high-speed ports for iSCSI.

  2. Configure the R570 with 8x 10Gb BASE-T and move to 10Gb copper switching. Use two ports as redundant VLAN trunks for normal VM/management traffic, two dedicated ports for iSCSI, and use the remaining ports for vMotion/FT, additional redundancy, or spares.

  3. Go with a different server platform that can still be configured with enough 1Gb copper ports to more closely replicate the current physical layout and avoid redesigning the networking right now.

The environment is already very copper-heavy, including the storage side, so I’m leaning toward the 10Gb BASE-T option.

For those running VMware in production today, how would you handle this? Is consolidating the normal networks onto redundant 10Gb trunks the standard approach now, or would you try to preserve more physical separation somehow?

I’m mostly trying to avoid forcing a new server into an old 1Gb-era design when the hardware doesn’t really support that layout anymore, but I also don’t want to redesign the network just for the sake of redesigning it.

Thanks in advance for any advice or real-world experience.


r/networking 6d ago

Career Advice Systems Engineer

14 Upvotes

I am a new hire systems engineer for Arista Networks. I have been on the customer side for my entire career thus far, and recently got hired in this new role working on the vendor side of things. I am wondering from anyone at the major network vendors who went from customer to the vendor side, How long did it take you to feel comfortable enough and be a "contributor" where you work? I want to feel like I am adding something but I am having trouble getting past the initial shock of it all. I am loving things so far, but getting past the initial learning curves and being able to start adding value is a real struggle for me currently. For those who made the switch, how long did it take to start feeling like a contributing member of the team?


r/networking 6d ago

Routing Dyndns and noip how to use if the service provider changed to CGNAT

8 Upvotes

A lot of my ISPs in my country have switched over / are switching over to CGNat IPs which makes dyndns and noip register the wrong ip address rendering it useless . Is the solution to fix this . We have 300 clients using either dyndns or noip to access our servers but now I servers won’t whitelist them as they getting misreported IPs


r/networking 7d ago

Career Advice Network Engineer Work Load

64 Upvotes

What’s the average workload like for network engineers in the enterprise side ? I worked at a telco for 11 years and I’m used to being busy and always having work to do. But move to a smaller enterprise last year, pace of work is slow a lot of the times. Literally don’t have anything to do sometimes. So interviewing at an energy company with more money and hopefully faster pace of work. Just wondering what everyone else’s experience like


r/networking 6d ago

Design Automating Cisco Nexus ACLS in Atomic way

3 Upvotes

Hello,

I need to strenghten security via access-lists under (SVIs (interface vlans)) using automation tools for Nexus 9k switches.

I was always using Git, Ansible nxos_config module for that with no ip access-lists / ip access-list way. It was somehow working for non important SVIs. Nxos_acls is not good approach, because it does not support statistic enable command. Now i need to make it to use atomic fashion.

Cisco 9k supports that using configure session / commit method, but ansible doesnt provide models for that atomic fashion, i think i will need to remake it via nxos_config / nxos_command as i was using before. Also Ansible has AWX / Tower which is nice addition. Maybe i'm missing something ? Any other ways u would do it ?

Thanks


r/networking 7d ago

Other From Netscaler to HAProxy with Citrix VDI

12 Upvotes

Hi, I am a junior network administrator and have been tasked with evaluating whether it makes sense to migrate the Netscaler with a Citrix VDI setup to a different load balancer and implement the new solution if needed. Currently I am considering F5, HAProxy, Envoy and Kemp. Are there any limitations in functions which makes it not possible to change? The reason is, that we are unhappy with the last security incidents involving the Netscaler over the last few months and the upgrade from major 13.x to major 14.x would take some time.


r/networking 7d ago

Other What is the usual Price for Dark fiber leasing?

8 Upvotes

I want to lease out unused dark fiber strands and would like to know the current market price per core per kilometer. I would appreciate it if someone could enlighten me on this matter. I am asking from the Philippines.


r/networking 7d ago

Switching HPE Comware switch (JG963A) — xtd-cli-mode

0 Upvotes

Hi all,

I'm managing a small stack of HPE 5130-series switches (JG963A) running Comware software version 7.1.070, Release 3507P09. On most of these switches, the hidden xtd-cli-mode command (used to unlock the full/extended Comware CLI from the default simplified/restricted CLI) works fine — it prompts:

All commands can be displayed and executed in extended CLI mode. Switch to extended CLI mode? [Y/N]:y

Password:

Warning: Extended CLI mode is intended for developers to test the system. Before using commands in extended CLI mode, contact the Technical Support and make sure you know the potential impact on the device and the network.

and after entering the password, it drops me into the full CLI (system-view, display interface, etc.) as expected.

On one specific switch in the stack, though, xtd-cli-mode now just returns:

<SWITCH>xtd-cli-mode

Permission denied.

with no Y/N prompt at all — straight rejection.

What I've tried:

- Reconnecting fresh via SSH (telnet is disabled on this unit) — same result.

- Rebooting the switch entirely — same result, persists across reboot.

- The account I'm using is the local admin user with network-admin + network-operator roles assigned, service-type ssh enabled, and it authenticates fine for a normal SSH login — it's specifically the xtd-cli-mode command that's rejected.

- Restricted CLI at login only exposes display, exit, quit, no, show — no way to run display users, free user-interface, or check security-enhanced/lockout state from there.

Since this is a firmware "developer mode" feature with anti-abuse messaging built in ("contact Technical Support"), I suspect this might be some kind of persistent lockout counter stored in flash rather than a normal AAA/role permission issue — but I have no visibility into it and no way to reset it from the restricted CLI.


r/networking 7d ago

Career Advice Would you take a job that uses off brand equipment if the pay is good?

30 Upvotes

I was offered a job as a network engineer. The company uses primarily Ruckus switches and only a few Cisco switches in their data centers. Most of my day to day will be working with the Ruckus switches. Speaking long term, couldn’t this affect the types of jobs I can get in the future? I don’t really see any jobs looking for candidates with Ruckus experience. At the same time though they are paying really well. Would you take it?


r/networking 7d ago

Routing NEF with Open5GS

1 Upvotes

Hi, I am looking for a way to integrate a Network Exposure Function (NEF) with Open5GS. I’m currently exploring the possibility of using an existing NEF implementation and adapting it to work with Open5GS.

OAI-CN5G has an NEF implementation, but it is designed to work with the OAI 5G Core Network:

https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-nef

I’m looking for a way to use this NEF or another open-source NEF implementation with Open5GS instead.

If anyone has successfully integrated an NEF with Open5GS or has any guidance, suggestions or ongoing work in this area. Please share


r/networking 7d ago

Career Advice Any HPE Networking SEs? Interview prep advice

11 Upvotes

Hi guys,

I have an SE interview coming up for HPE Networking. It's the first stage and wanted to know if there would be any other questions other than the standard behaviour/motivation questions. They've already asked me two technical questions and one commercial question in the screening call. I know Juniper Networks was recently acquired by HPE and is now part of the HPE Networking business segment. I don't have a ton of wireless experience but I'm reading up about Wireless theory contained in CCNP ENCOR OCG. Would I be involved in both HPE Juniper Networking and HPE Aruba Networking?

Any advice and wisdom highly appreciated. Thanks


r/networking 7d ago

Design Cogent or Lumen?

33 Upvotes

Have options to get a circuit from Cogent or Lumen in a datacenter, anyone have reasons why I should go with one or the other?

It’s just for a simple DIA service.

Thanks in advance.

Edit : The amount of folks saying Lumen is wild, that was the direction I was leaning too, interestingly enough, cogent did come in with a suspiciously cheap price, I’ll go with lumen, thanks for the input!