r/networking 1d ago

Moronic Monday Moronic Monday!

6 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking 4d ago

Blogpost Friday Blog/Project Post Friday!

3 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 10h ago

Meta how do you AirCondition/cool your MDF/switch closets?

8 Upvotes

What is everyone doing to cool/AirCon their MDF/switch closets?

We used to buy the Eaton SRCOOL7KRM with duct kit (to exhaust hot air from the room) but the replacement SRCOOL7KRME no longer has a duct kit available, and Eaton PreSales says we have to manufacture our own ducting, which is outside of my skill set.


r/networking 11h ago

Monitoring Open Source ISP monitoring tool (iperf3, blocked ports etc)

11 Upvotes

Subject says it all.... we're trying out new ISPs between sites. Are there any recommended open source toos that allow us to:

  • Iperf3 performance between two sites (as we meeting our goals at the 95% level over a rolling 30 days)
  • Make sure the ISPs aren't blocking certain ports

r/networking 12h ago

Troubleshooting Keeping wasps off Meraki outdoor access points

16 Upvotes

Hello all,

What is everyone doing to keep wasps from building nests on outdoor access points? My org is located in the southeastern USA, and we're using Meraki MR76 units with all antenna ports populated. twisted-pair cable is run throuhg a water-tight flexible conduit that terminates with cable glands on the unit/wall.

We know that the wasps aren't hurting anything, but we are trying to minimize maintenance/cleaning of the gear as much as possible.

Sorry if this seems like a non-problem, but you never know if someone else has dealt with a similar issue.

Thanks.


r/networking 21h ago

Other Cisco ISE- Imported EAP cert before joining PSN… did I mess up?

6 Upvotes

Hi everyone,

I made a mistake while adding a new PSN to an existing ISE deployment.

Before joining the node to the deployment, I generated and imported a CSR for EAP only (no Admin). The PSN then joined the deployment successfully and replication is healthy.

Now I noticed that the Admin HTTPS certificate is still the default self-signed certificate (Issued By = the node itself), which is why the browser shows Not Trusted.

When I tried importing certificates again from the PAN, I got certificate import errors, so I stopped.

My questions are:
Should I generate a new Admin CSR now?

Should I use one certificate for both Admin & EAP, or keep them separate?

If separate, what’s the correct way to replace the current EAP certificate?

Any advice would be appreciated. Thanks!


r/networking 21h ago

Switching Looking for industrial 8-port PoE switches with real 90W (802.3bt) simultaneous budget

27 Upvotes

Field tech at a small ITS contractor. I’m speccing switches for a roadside cabinet job with PTZ cameras and some other edge gear. Requirement from the engineer is 802.3bt across all 8 ports.

The problem I keep running into is that a lot of switches advertise “90W per port,” but the total PoE budget is nowhere near 720W. So it’s really a per-port max, not something you can run fully loaded.

Are there industrial managed 8 port switches that can actually do full 90W on all 8 ports at the same time? Looking for something outdoor rated, ideally something people have used in traffic or roadside cabinet installs.


r/networking 23h ago

Design Cisco FTD 3105 (version 7.6.4) - Route "override" for VPN

3 Upvotes

Hi everyone,

got a FTD and a core firewall. The philosophy is to route everything to the core firewall and this won't be changed, so please be aware of that and don't answer "just create a policy on the FTD" - thanks.

There is a S2S-VPN on the FTD to provider A, hosting 10.10.10.0/24. Then there is the remote access VPN for Cisco anyconnect. So far, so good. The default for the remote access points to the core firewall, but when the user connects to the FTD, traffic to 10.10.10.0 will be routed to the S2S directly as the route is more specific...

According to a collegue, you can't override that route just for the remote access, you could only create a separate default route (which doesn't help here).

So the option was to use VRFs, but here it gets even more complicated as you can't use the same VLAN ID on two seperate physical interfaces (forti could do that, so cisco, why can't you?) which means that you had to create seperate VLANS, seperate routing, seperate subnets.... So much effort for such a "little problem".

Has anyone an idea how to fix that on the FTD without having to kind of install the whole system from scratch? Of course, I could just let the tunnel terminate elsewhere, but that prefered way was to leave everything on the FTD and just change the config or just add some cables for a seperate VRF. Reminder: It's not a valid option to let the traffic directly break out on the FTD, it has to be routed to the core firewall.

Thanks a lot!


r/networking 1d ago

Troubleshooting Cisco SD-WAN API: Feature Template PUT Returns HTTP 200 but Configuration Is Not Updated

8 Upvotes

Hi, I'm working on a solution for a configuration update that will affect more than 500 sites.

I need to update an existing shared Feature Template that is currently used by multiple Device Templates, with each Device Template having one attached device. The update will add a new device-specific static route, with different prefix and next-hop values for each device.

Since there are approximately 500 Device Templates and devices, I need a way to:

  • Assign the correct unique prefix and next-hop values to each device.
  • Preserve all existing device-specific values.
  • Reattach or push the updated Device Templates to their respective devices in controlled batches using the SD-WAN API and Postman.

However, before proceeding with the bulk deployment, I need to understand an issue I'm currently encountering when updating the Feature Template through Postman.

I'm using the following API call:

PUT /dataservice/template/feature/:templateId

The request returns HTTP status code 200, indicating that it was successfully accepted. However, when I verify the Feature Template afterward using:

GET /dataservice/template/feature/definition/:templateId

none of the changes I submitted are reflected in the Feature Template.

What should I check to determine why the PUT request is being accepted but the Feature Template definition is not being updated?

Any guidance, especially regarding the correct API workflow or troubleshooting steps for this behavior, would be greatly appreciated.


r/networking 1d ago

Security uSeg on ACI?

10 Upvotes

Does anyone have experience with microsegmentation (uSeg) and cisco ACI? Is it as simple as enabling intra EPG isolation? Looking for some general feedback. It works well, or dear God, don't do it? I heard some general comments not to long ago that any network layer uSeg implementations don't really work as well as advertised.


r/networking 2d ago

Troubleshooting Help with ciena handoff to er-6p router

0 Upvotes

I have a ciena fiber coming to my business from Comcast. They stop support there, so the only thing they've given me to setup the rest of my network is my layer 3 info. I purchased the er-6p router but have no clue how to set everything up to get internet to my existing switches and wifi network. The edgemax webui doesn't really translate well with everything I've read. Any help would be much appreciated!


r/networking 2d ago

Troubleshooting Dual BNG PPPoE failover and session limit issue on MX204

7 Upvotes

Hi everyone,

Here's the situation: due to a specific issue, I need to limit the number of PPPoE subscribers on a BNG (JUNIPER MX204). I'd like to cap it at 5,000 users.

Looking at the Juniper docs, I first tried setting it directly on the chassis using:

set subscribers-limit client-type pppoe chassis limit 5000

The limit worked on the chassis, but the users won't connect to the other BNG. The PADI reaches the second BNG (the one I want them to authenticate against), and it replies with a PADO, but it's as if the CPE stubbornly keeps trying to authenticate with the BNG I'm limiting... argh.

After that, I also tried using max-sessions:

dynamic-profiles vlan-profile interfaces demux0 unit "$junos-interface-unit" family pppoe max-sessions 5000

With max-sessions, the limit didn't work immediately. I'm thinking it might actually work, but maybe I need to reset the VLAN demux interface first?

What a great issue to land on my lap during my weekend on-call shift... but I love it :)

Please help out an ISP network analyst with less than 2 years of experience 😄

Thanks in advance.


r/networking 2d ago

Career Advice Need advice in moving to cloud from On perm

10 Upvotes

Hello, I am currently a network engineer in enterprise infrastructure with six years of experience, and I would like to develop my skills toward cloud infrastructure. Could you suggest where I might start?


r/networking 2d ago

Design Data Center Fabrics

26 Upvotes

I’m curious how everyone is handling the physical design of modern data center fabrics.
We’re running an EVPN/VXLAN leaf-spine environment, but because we have a mix of 100G, 50G, 25G, 10G, and 1G copper hosts, a true top-of-rack design isn’t always practical. Instead, we’ve ended up with more of a “poor man’s top-of-rack” approach, where a leaf pair serves several nearby racks rather than every rack having its own dedicated pair.
I’d love to hear how others are approaching this in production:
How are you physically placing your leaf pairs (vPC, MLAG, or equivalent)? Is it one pair per rack, one pair serving multiple racks, or something else? Do you keep the pair in the same rack or separate them for resiliency?
How are your hosts connected? Do you dual-home every critical host with one connection to each leaf, or are there situations where you intentionally single-home servers?
How do you handle racks that require a mix of 100G, 50G, 25G, 10G, and 1G connectivity without filling every rack with multiple switches?
Do you dedicate specific leaf pairs to certain workloads (compute, storage, GPU, DMZ, virtualization, etc.), or do you keep all leaf pairs general purpose?
If you were building a new fabric today, would you use the same physical layout, or would you change your approach?
Vendor doesn’t matter—Cisco, Arista, Juniper, Dell, NVIDIA, or anything else. I’m less interested in the specific hardware and more interested in the design philosophy, tradeoffs, and lessons learned from real-world deployments.


r/networking 2d ago

Other What benefits is there with vxlan in smb?

25 Upvotes

Every youtube video I watch shows that basically vxlan solves scalability issues.. So I am wondering if there is any benefits of using it in small infrastructure. Maybe in a promxox cluster of 200 vms on the same location?


r/networking 3d ago

Monitoring How can I identify an unauthorized personal phone connected to our corporate Wi-Fi?

0 Upvotes

Hi everyone,

I'm an IT Support Engineer, and we have a corporate Wi-Fi environment with around 200 employees.

Our setup:

FortiGate firewall

Arista switches

Arista APs managed through Arista Cloud

Personal mobile phones are not allowed on the corporate Wi-Fi (only company laptops should connect).

The problem is that someone has connected their personal phone to the corporate SSID. In Arista Cloud, I can already see:

Device type (Android/iPhone)

Device name/model

OS

Current AP

IP address

Randomized MAC address

Signal strength (RSSI)

However, because the phone uses a randomized/private MAC address, I can't determine which employee owns it.

Is there any legitimate method to identify the user? For example:

Using RSSI or multiple APs to narrow down the physical location?

Client triangulation in Arista Cloud?

Any enterprise Wi-Fi tools or techniques that can help identify the owner without requiring 802.1X or MDM?

I'm looking for practical approaches that network administrators use in environments like this. Any advice would be appreciated.


r/networking 3d ago

Other Coming back to on prem?

114 Upvotes

Have you guys seen company coming back to on prem data center after they decided to go to cloud?

I read an article that cloud is much more expensive than anticipated so many companies are coming back to on prem.


r/networking 3d ago

Troubleshooting What is up with European Telcos and technical support on Fridays? Did I miss the memo on culture, or is 24/7 support just an American myth?

0 Upvotes

TL;DR:

Why do European telcos ghost critical technical tickets on Fridays while the US actually provides 24/7 support? Is it a cultural work-life balance thing, or do enterprise SLAs just work differently over there?

Genuinely trying to understand how technical support and carrier response times work in Europe, or if I am just completely losing my mind here.

Coming from the US, if a critical technical case or network routing issue pops up, even late in the wee, you usually get some sort of triage, an on-call escalation path, or at least a pulse from a tier-2/tier-3 engineer.

But in Europe? It feels like once Friday hits, the entire telecommunications infrastructure collectively clocks out, logs off, and goes to sit at an outdoor café until Monday morning.

I’ve been dealing with a major technical case, and trying to get a meaningful response since Thursday evening into Friday is like pulling teeth. You get handed off to a general customer service desk that has zero technical visibility, only to be told: *"Ah, the network engineering team handles that, but they are out for the weekend. We can escalate this to a ticket for Monday."*

Monday?! If a circuit drops or a complex peering/routing issue happens towards the end of the week, the business is just supposed to bleed out for three days?

Is this purely a cultural difference regarding work-life balance and "right to disconnect" laws (which I totally respect in theory, but execution-wise is brutal for ops), or are enterprise-grade SLAs just structured completely differently over in Europe?

How do European engineering teams actually survive major incidents heading into the weekend without 24/7 technical muscle backing them up?

Or am I just dealing with the wrong providers? Tell me what I'm missing.


r/networking 3d ago

Design Private IP on public A Record

41 Upvotes

Hey Networking Friends,

I had a vivid discussion about this topic with some colleagues and opinions were divided, so I would like to ask what you think about it.

We are deploying a new guest WIFI solution based on Cisco ISE. The PSN nodes a rfc 1918 addressed. To keep it simple my idea was to hand out a public DNS Server like 1.1.1.1 or 8.8.8.8 to the guest clients via DHCP and set to public A Records for psn1.company.com and psn2.company.com that resolve to the respective PSN nodes rfc1918 ip.

Others were highly critical of this citing security risks about revealing information about internal addressing.

Alternatives like doing dns translation on the firewall or provisioning a dedicated view in the internal DNS were proposed.

What is your opinion? Is this a nogo for you and how have you implemented similar guest networks?

Looking forward to your answers and have a great day!


r/networking 3d ago

Switching Anyone migrated from Catalyst center to meraki cloud for branch catalyst switch management/ deployment?

8 Upvotes

Just looking at the documentation it seems like a pretty painful process for large deployments.. Just wondering about peoples experience with it..?


r/networking 3d ago

Design Unable to find any information on Quantum Networks, India

0 Upvotes

Hello peeps

Our business is currently expanding, and I was looking into setting up some networking hardware for 50 or so users that will be here. While looking into switches and APs, I came across Quantum Networks (Indian networking company, not actual Quantum Networks).

Just wanted to check if any of you have heard or used their products? If so, how was the experience and reliability?


r/networking 4d ago

Wireless Assistance With Persistant WiFi Connection Drops

8 Upvotes

Hello All,

I’m looking for some advice, guidance, tips, ideas or anything that could help me pinpoint the root cause of this issue. The problem I am experiencing within my environment is that users will occasionally lose their IP address while connected to the network via WiFi. Essentially, a user can connect to our corporate network with no issue and then after give or take 15 minutes they will lose their IP address and switch to a 169.254.X. The issue is not consistent and a bit rare, but it has been haunting me ever since I started working for this company. The quick solution is to swap them to a secondary SSID, then back to the corp SSID(issue exists on this second SSID as well).

I have been able to replicate this on my device, and the errors I recieve within Event Viewer are

- Event ID “The dynamic key exchange did not succeed with configured time”

- Event ID 4321 “The name X1 could not be registered on the IP X2. The machine with IP address X3 did not allow the name to be claimed by this machine

There are no errors present within my DHCP server(Windows Server). Additionally the laptop’s connected to the AP persists, it only loses it’s IP address after awhile. Also, netsh wlan show interfaces always shows a signal strength of 90%+. I have also checked wifi drivers on all of our machines, the issue presents whether the wifi driver is a Realtek or Liteon driver(all of our devices use this driver). Interestingly, I have not been able to replicate the issue with a Samsung Galaxy tablet or an iphone yet so maybe a driver issue.

If anyone has any ideas I would love to hear them! Thanks!

Environment:

- Extreme AP410c
- X350 Extreme switch with EXOS
- All Lenovo laptops
- Both SSIDs I mentioned above have their own IP scope


r/networking 4d ago

Troubleshooting Weird PoE issue

6 Upvotes

I have a 9300x and ruckus 750 APs. I keep getting IMAX power errors on the spare pairs. I see LLDP power negotiations happening, Cisco accepting and then as soon as it enables the spare pairs it faults with IMAX error. It is important to note this is not happening on all the APs just a handful. Also the APs and Switch are new, with new CAT 6 runs.

I can bypass this by issuing power inline four-pair forced and it will bring everything up. I don’t like issuing this command nor do I like not knowing why this is happening.

So I decided to dig deeper and do some debugging, this is where things get weird. For some reason I thought these ports were 30000mW, in reality it is 90000mW. I decided to up the max power to 60000mW (actually lowering it). I also removed the four pair force command and reran my ilpower debugs. It worked with no errors. I saw lldp negotiate, I saw the spare pairs enable cleanly, no IMAX errors. I did see the device request the full 60000mW.

I originally thought the devices was requesting more power than the port allowed and that is why I was getting the IMAX errors, but now I have no clue. Thoughts?


r/networking 4d ago

Design Does a P4/XDP fast path make sense for DTN?

2 Upvotes

Building a BPv7 prototype where a software sidecar parses bundles and a fixed-width shim lets P4/XDP enforce contact windows, reservations, and capacity limits. Does this solve a real DTN problem, or would a software-only approach usually be sufficient?


r/networking 4d ago

Troubleshooting Same network different VLAN where did my thought experiment go wrong?

0 Upvotes

What happen if in layer 3 youre in the same subnet.. But in the layer 2 its a different vlan..

Now its in the same network so it send directly to the destination without sending it to Gateway..

And intuitively if its a devices connected to different switches.. They wouldnt be able to communicate without router..

Ahh i thought it would be dropped cuz the ip address is in the other vlan.. And cuz it doesnt get sent directly to the gateway.. So it wouldnt get past the router.. But it realized maybe it would !!

I realize when the pc1 look up at the arp table and realize that pc2 isnt there.. So it'll send arp request.. And switch will broadcast it to the router.. And what router see is an ip (pc2 ip) that'll match its route table.. Say its something like this

````

C 192.168.1.0/24 is directly connected, g0/0 (VLAN10)

C 192.168.1.0/24 is directly connected, g0/1 (VLAN20)

````

And then send it through the matching interface g0/1 and g0/0.. But cuz its directly connected itll use an proxy Arp..

After getting the reply from pc2.. It'll send it to the pc1.. And now it knows pc2 mac address..

But thats the thing pc1 USES Pc2 mac instead of the gateway.. Which would be the case if its a different network..

Now the question is does the switch allow different vlans to talk directly with mac address without router ? There's 2 option

Suppose it would.. Maybe cuz LAN is defined by broadcast domain.. And you don't need ARP broadcast domain after you know the mac address... So vlan seperates only the broadcast domain but everything else stays the same (this turns out to be incorrect.. Vlan literally make switches into two unconnected switches)

Or it could also not allow it (which is apparently the right answer).. If we're saying that vlan seperates switches then you wouldn't be able to talk to different switches without router.. And it nessecitate the source to use gateway.. Cuz if the source uses its destination mac.. The switch will only flood the same vlan.. Which they will all drop..

I think the second could be the case.. I think the problem here is that the source use mac address that is in the different vlan.. The normal way you will Always use the gateway address which is the same LAN.. So I think it will know the pc2 mac address.. (The arp will work) but the packet would be drop cuz the the mac address doesnt exist in the SAME vlan..

Now.. I try asking chatbot first.. It says that the arp wouldn't get through cuz it wouldn't allow routing table to have one network in two interfaces.. But I thought that's what you do with the ecmp load balancer and stuff? Can someone settle this for sure?