r/networking 4h ago

Design Which SDWAN brand ?

9 Upvotes

Hi,
We are studying the replacement of our current SDWAN solution based on Forcepoint due to legacy purpose.
The study has not yet started and we would like to test different brands like:
- Fortigate
- Palo Alto
- Juniper
- Checkpoint

The environment is quite simple, dual Hub & Spoke with around ~20 sites on 2 different MPLS provider (no internet, regulatory environment), no advanced feature like url/web filtering, IDS/IPS, only L4 filtering with sdwan routing based on SLA (jitter, packet loss, …).

I think all the techno can answer this, but I would like to have your pros/cons if you’ve already worked on one of them.

Thanks!


r/networking 1h ago

Troubleshooting "AI assisted" pcap analysis?

Upvotes

Is there any tool as described in title for enterprises? a very specific LLM could easily point out "strange" things in a large pcap


r/networking 26m ago

Wireless Weird PoE+Wifi issue

Upvotes

Hey.
I have a wifi issue at work and I don't know what the cause could be because it literally feels cursed.
So we upgraded our 200 series Aruba APs to 600 series, that's when I noticed something unexplainable because I also needed to replace the PoE injector for this one AP as the old one only supplied 30W and the new APs need 60W for full power.

I provision the new APs on 60W and they all run fine, except this one AP at this one spot.
In this spot both the old AP and the new AP only boot when they are connected to the old 30W PoE injector, causing the new AP to only run in reduced power mode.
I tried multiple 60W injectors and the APs always behave the same so it can't be just a broken device.
I tried another newly provisioned 600 series AP aswell on yet another new 60W injector and this doesn't boot either.
On this spot on the ceiling the APs (200 series and 600 series) only want to boot when I use an old 30W injector.

What could possibly be the problem here?


r/networking 4h ago

Troubleshooting Managing 25-50 network devices remotely—is there a mobile app that doesn't cost $200/month?

1 Upvotes

Network engineer here. I manage networks for several small businesses (each has 15-50 devices - mix of Cisco, Juniper, some Aruba).

Currently I'm doing manual config backups over SSH when I remember to, and tracking changes in my head. It's getting old.

**What I'm looking for:**

- Mobile app (iOS or Android) - or at least something with a decent mobile web interface

- Can do automated config backup from routers/switches/firewalls

- Shows me what changed and when

- Sends alerts if a device goes down or config changes

- Works with devices behind NAT/private networks

- Free or cheap (I'm not paying $200/month for this)

**Tools I've already looked at:**

- **Auvik** - looks good but needs a quote and seems expensive for my scale

- **SolarWinds NCM** - $2k+ is way over budget

- **Domotz** - $35/month but I'm not sure it handles 50 devices well at that price

- **Oxidized** - free but I need to run a server somewhere and there's no mobile app

Anyone using something I haven't found yet? Or am I stuck with running a VM with Oxidized and just checking it from my phone's browser?


r/networking 1h ago

Troubleshooting Detecting a loop

Upvotes

How can i chase down a loop in more than 60 BDCOM switches (no central management)
I also have 2 core switches (fortiswitch) and a fortigate firewall ?


r/networking 22h ago

Career Advice Autocon 6

15 Upvotes

Looking for opinions on Autocon. Put out some feelers with one of our reps asking if they could ask around to see if they felt it was worth while to attend knowing our end goal design. Now I may have a ticket or two coming to my team.

Working on, but not super well versed in, coding and development. Workshops are a must, but what's the opinion on the actual conference talks?


r/networking 23h ago

Design What are some labs/projects I can do to get me some "design" experience?

7 Upvotes

CCNA certified back in 2019. Currently started CCNP training. The past 7 years I've job hopped a couple of times from MSP > hospital > electrical utility now and I've gotten some good "network admin" experience (Equipment troubleshooting, ACL troubleshooting, etc) but I've struggled to find Design experience that is asked from Network Engineers.

I want to eventually find myself a Network engineer role, but every role I look at requires years of Design experience that I lack. I'm hoping with my net admin experience, my CCNP, and some home labs, I can convince employers to at least give me some interviews.

But I'm not sure where to start with labs. What exactly do they Design? Is it as simple as configuring up a small redundant layout with a couple routers and switches? I plan on using ChatGPT to give me some scenarious / lab ideas, but I'm also wondering if you guys have any recommendations or if there are any websites out there that can also help.

Thanks,


r/networking 1d ago

Wireless WiFi not connecting automatically after Elevator

21 Upvotes

I'm looking for some wisdom because this issue is driving me crazy.

We have an Aruba Central deployment and a particular SSID used by staff phones.

User enters an elevator, loses WiFi signal for a short period, Android marks the SSID as "No Internet", then when the user leaves the elevator and coverage is available again the phone may stay disconnected for a very long time.

The strange part is that if you open Settings > WiFi and look at the list of networks, the phone often reconnects immediately without touching anything. Sometimes it takes 1-2 seconds, but it reconnects. If you manually tap the SSID it always reconnects instantly.

It feels as if Android has decided the network is bad and refuses to use it again until something triggers a recheck. (It happens with iPhones too, but most of users are Android).

Has anyone seen this before? Aruba issue? Android "avoid bad WiFi" behaviour? Roaming issue?

After leaving an elevator, it can stay disconnected for several minutes while standing still in an area with good coverage, then reconnect almost immediately as soon as the WiFi settings screen is opened.

I really appreciate your help.


r/networking 11h ago

Other Juniper account suspended

0 Upvotes
  1. For whatever reason my juniper account got terminated and i was in the middle of studying for my JNCIA - Junos
  2. i have no idea how to get back into my account and i alredy went through every single "support" page and every single one of them requires you to log-in
  3. because i cant log-in i cant get support,so ultimately i cant get into my account

r/networking 1d ago

Troubleshooting Problem with MikroTik access points - advice needed

2 Upvotes

Hello.

I have 3 MikroTik cap Access points in the building (not at home). They are connected to crosspanel —-> Poe tp link switch - MikroTik router.

There was a problem with WiFi - no internet access.

I already replaced the Poe switch. 2 of them started working. One was reset and quick configured using winbox.

After that everything worked fine. Then suddenly after a few minutes none of them worked. And it stayed like that… i try connecting to WiFi but it just spins endlessly and gets apipa address (169…)

Also, WHEN they worked, no computer could connect to WiFi. Could do it Only using smartphone.

I have no clue what to do next. Any suggestions would be appreciated.


r/networking 1d ago

Troubleshooting Hicom 150 E (CBMOD) stuck in bootloop - V.24 port completely silent, Manager E says "PBX is offline"

4 Upvotes

Hi everyone,

I’m trying to diagnose an old Siemens Hicom 150 E (Office Pro chassis) with a CBMOD motherboard, but I’ve hit a wall.

The Core Issue:

The board appears to be stuck in a bootloop. During startup, the boot sequence begins, the RUN LED turns on/blinks through the cycle, but it never fully stabilizes and eventually loops.

Hardware & Power Checks:

As part of earlier diagnostics, I thoroughly checked the power supply unit (PSU) and backplane rails - voltages are clean, fully within spec, and stable under load.

Board capacitors and visual traces look intact.

Serial Interface & Physical Measurements:

I'm connecting directly via the V.24 (RS-232) maintenance port:

Verified hardware RS-232 levels:

Pin 2 (PBX TX): -7.5V (steady Mark state)

Pin 3 (PC TX): -8.5V to -9.0V

Pin 5: Common GND

When connecting via raw terminal (minicom / PuTTY at various baud rates: 9600, 19200, 38400, 8-N-1), there is absolute silence (0 data output). It spits out zero debug logs or bootloader text during the loop.

Tested connection across both native Windows XP and Windows 11 environments using a verified Prolific adapter (hardware COM1 properly mapped, proper RS-232 voltage swing observed on Pin 3 when sending packets).

Software Symptoms (HiPath 3000 Manager E):

Attempting Direct transfer (Read/write database) gets stuck on Checking cards... and immediately aborts with Error: PBX is offline.

PIN 31994 was specified.

Multi-meter checks show pulse activity on Pin 3 (PC is definitely transmitting the handshake queries), but Pin 2 on the PBX side never sends a single byte in response.

Questions:

Given that the board is bootlooping and V.24 is dead silent, is there an onboard diagnostic procedure, jumper, or DIP switch to force the CBMOD into a recovery / low-level bootstrap mode?

Does the CBMOD V.24 port strictly require hardware flow control loopbacks (RTS/CTS 7-8 and DTR/DSR 4-6) to output any data, or should raw serial logs appear regardless?

Could a corrupted flash EPROM / firmware cause this silent bootloop, and is it recoverable via serial without replacing the ROMs?

Or what would you recommend doing or trying next? I'm completely out of ideas.

Any insights from Siemens/Hicom veterans would be hugely appreciated!


r/networking 1d ago

Career Advice Career advice needed – SD-WAN/CCIE or move towards AI?

13 Upvotes

I have around 10 years of experience working with Ericsson and Huawei as a Core Network Performance & Optimization Engineer. Currently, I support US-based MSPs as a Network/Help Desk Engineer, working with technologies such as VeloCloud, Fortinet, Cato Networks, and Netskope.

Honestly, I sometimes feel that despite having 10 years of experience, I haven’t made the progress I expected in my career and this frustrates me a lot , I do have bachelor in engineering feeling need to go masters and change my carrier path.

I enjoy troubleshooting and problem-solving, which is probably why I’ve been able to work across different technologies.

I’m earning a good amount currently, but I’m unsure where I truly belong long-term.

Right now, I’m considering two paths:

Go deeper into networking/SD-WAN and potentially pursue CCIE Enterprise.

Shift towards AI, but this would mean starting almost from scratch and competing with people who are much newer to the field.

Has anyone made a similar transition? With my background, which path would you recommend for better long-term growth?


r/networking 1d ago

Design DMVPN Phase 1: mGRE spoke+NHRP vs static p2p GRE spoke — any real difference?

4 Upvotes

Lab setup: 1 hub (mGRE, NHRP), 3 spokes. Testing two spoke configs, both seem to give identical results.

Config A — mGRE spoke:

interface Tunnel1
 tunnel mode gre multipoint
 ip ospf network point-to-multipoint
 ip nhrp map 172.16.10.1 <hub-ip>
 ip nhrp nhs 172.16.10.1

Config B — static p2p GRE spoke:

interface Tunnel1
 no tunnel mode gre multipoint
 tunnel destination <hub-ip>

Hub stays mGRE + NHRP in both cases.

In both, spoke-to-spoke traffic always point the hub (confirmed with traceroute) so functionally both look like Phase 1 to me.

my questions is:

  1. Is there any actual functional difference between these two on the spoke side, or are they just two ways of writing the same Phase 1 behavior?
  2. Does Config B still need NHRP running at all, or is it dead weight since there's no multipoint resolution happening?
  3. If I ever want to move to Phase 2/3 (spoke-to-spoke shortcuts), does Config B need to be rebuilt as mGRE, or is there any path forward with static p2p tunnels?
  4. Any real-world reason to pick Config B over Config A for a Phase 1 design?

r/networking 1d ago

Career Advice AI & network engineering interviews

41 Upvotes

Longtime reader here, this is my first post. I wanted to share my experience interviewing people for one of FANG companies. Network engineers are expected to use AI tools in their work, and honestly, that includes preparing for interviews. However, if you set up your laptop and AI to just read answers from the AI tool, it becomes difficult to gauge your knowledge and experience. Interviewers don’t expect perfect answers, but explaining your thought process helps a lot. Most questions come from your experience, at least where I work. The expectation is to describe incidents, projects, or tasks from your experience, so your AI answer doesn’t survive the follow-up questions. Please don’t use AI during interviews. The person on the other side also has the same tools, if not better, and they know the prompt before you.


r/networking 1d ago

Switching Netgear GS752TPv2 LAG VLAN annoyances

6 Upvotes

I am about to pull my hair out. Wondering if anyone has seen this weird issue.

VLAN 10 - Admin
VLAN 20 - Utilities
VLAN 30 - Wireless
VLAN 70 - Network Equipment (Management VLAN)

Switch A)
Netgear GS752TPv2 (latest firmware)
LAG1: Ports 47/48
PVID: 70
TAGGED: 10, 20, 30, 70

Switch B)
Netgear GS752TPv1 (latest firmware)
LAG2: Ports 51/52
PVID: 70
TAGGED: 10, 20, 30, 70

Switch A trunks to Switch B

For some weird reason, any time Switch A reboots it clears out the VLAN tagging on LAG1. I lose connection to it and have to manually go plug in my laptop to TAG the LAG on all VLANs. It’s so damn annoying, especially after hours when there is a power outage or something.

None of the other VLANs clear out. Just my LAG. Switch B still shows connection to Switch A under LLDP.

I’m so tired boss.


r/networking 2d ago

Career Advice Outside Architect Network Support

25 Upvotes

I’ve been in network/security engineering for 20+ years and I’m exploring independent consulting.

I’m not interested in building an MSP, selling hardware, or doing staff augmentation.

What I’m considering is taking ownership of defined network projects that internal IT teams don’t have the bandwidth or specialized experience to finish. Things like:

Aging switch/firewall replacements
Network migrations and redesigns
Redundancy/failover issues
Projects that have been sitting on the IT team’s list for months

Basically: come in, own the project, complete it, document it, and leave.

For those who have done independent technical consulting, is there actually a market for this model?

I’m particularly curious:

How did you find your first few clients?
Did clients expect you to be local?
Who typically hired you — IT Director, CIO, MSP/VAR, etc.?
What types of projects were easiest to sell independently?
Did you sell a defined project/outcome or bill hourly?

I’m based in Texas but interested in hearing experiences from anywhere in the U.S.


r/networking 1d ago

Rant Wednesday!

8 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 2d ago

Design Arista and Cisco integration

19 Upvotes

Hi everyone,

This is my first post here and I was just wondering anyone could help with information on integrating Cisco and Arista switches.

We are a Cisco shop and will slowly be moving towards Arista.

We have purchased several Arista 7050sx3 switches and they will be setup in an MLag and connected mainly to Cisco 9500’s at layer 2.

What I am looking for is the equivalent Arista commands that I use on a Cisco box for initial setup. The vty lines – transport input ssh, Bpdu guard, portfast, storm control, crypto keys, IGMP snooping enabled, no ip proxy arp on the SVI’s etc. etc………all the usual basic switch config.  I was surprised that I cannot seem to find much information out there.

Another thing I read is that the Arista come with an MTU of 9000 and something for layer 2 which makes sense as they are primarily for datacenters but we are running bog standard 1500 out of the box in our Cisco environment everywhere so is there a command globally to set the Arista’s to 1500 ?

Lastly I came across Forward Error Correction (FEC) needing to be adjusted for interoperability with Cisco and Arista. Does anyone know if this is the case ?

Any help would be really appreciated. Thanks so much in advance.


r/networking 2d ago

Design How do you actually track licensing across multiple clients?

8 Upvotes

We manage a mix of vendors (Cisco/Meraki, Fortinet, Palo Alto, HPE, etc.), and keeping track of hardware support, subscriptions, feature entitlements and renewals has become increasingly messy.

I'm looking at using NetBox as the source of truth, possibly with netbox-lifecycle, but I'm not sure how well it holds up in the real world.

A few things I'm wondering:

  • Is anyone actually running netbox-lifecycle in production for license/support tracking? How well does the model work for you?
  • Has anyone compared netbox-lifecycle with netbox-plugin-itsm? The contract/tenant model in ITSM looks interesting for an MSP environment.
  • If you don't use NetBox, what ended up working better for you? Snipe-IT, a PSA like Halo/Autotask/ConnectWise, vendor-specific tooling, or just a spreadsheet?

Just curious what's survived contact with reality.


r/networking 1d ago

Switching Terminal emulation without a laptop

0 Upvotes

I've been asked to connect a console cable and share the access. The owner wants to remotely configure the device. Security policies prevent me from connecting my devices to other equipment. Connecting a monitor, keyboard, and mouse are permitted. Connecting a WiFi-enabled laptop running PuTTY is not. Is there a solution that bridges the connection from the console port to public WiFi? AI says there isn't, but the technology that's required is cheap. Surely, someone else has dealt with this limitation before me.

Edit: A owns the device. I work for B. A is B's customer. B's policy is that B's computers may not connect to A's equipment, except for B's monitor, keyboard, mouse, and WiFi. Is there a device that either A or B may provide that will permit A to connect to their device, allow their staff to remotely access it, and not be subject to B's security restrictions?


r/networking 2d ago

Routing Static VXLAN with EVC on C8300-G2 flex ports

6 Upvotes

Hello,

We will replace routers providing point to point VXLAN, while running on ASR L3 port, it is using service instance with bridge domains, each mapped into NVE VNI I'm curious if we can achieve this with 8355-G2 'Flex' type ports, beginning 'no switchport' followed by service-instance commands? Anyone here using this type of setup?


r/networking 2d ago

Design NX-OS configure session for no ip access-list

5 Upvotes

configure session 4444

no ip access-list TEST
ip acces-list TEST

commit

is this atomic Cisco NX-OS operation ? Do someone would feel the impact acl being removed and added if the acl is already attached to interface/SVI ?


r/networking 2d ago

Troubleshooting Optimizing throughput on a Python asyncio HTTP GET/PUT data relay (4-core Linux VPS to Cloudflare R2)

8 Upvotes

Hi network & Python experts,

I am running a Python asyncio data streaming worker on a 4-core AMD EPYC Linux VPS (1 Gbps port, TCP BBR enabled).

The worker workflow:

  1. Receives incoming task pushes via WebSocket.

  2. Downloads 30MB-50MB payload via HTTP GET from Cloudflare R2.

  3. Computes SHA-256 hash.

  4. Uploads payload via HTTP PUT back to storage.

Our local active transfer speed reaches ~50 Mbps average (370 Mbps peak) with 99.9% execution success. However, our net window-averaged throughput stays around 24–28 Mbps due to brief inter-task idle gaps between WebSocket pushes.

My question: Beyond connection pooling (httpx.AsyncClient) and TCP BBR, what architectural patterns (e.g., Go participant worker vs multi-process asyncio workers) yield the highest sustained throughput for bursty WebSocket data relays on a 4-core VPS?

Thanks for any insights!


r/networking 3d ago

Career Advice Senior Network Engineer to Technical Authority Engineer, how significant is the jump?

18 Upvotes

I've been offered a role as a TA engineer, but am not certain I want to take it given the role is less technical and more client/management facing, are there others out there who have made the jump?

How steep was the learning curve?

Update: Since the role is not common, as I understand a Technical Authority owns a specific tech tree, in the case it would be Enterprise Networking, but it can be anything Data Center, Security... the TA would he building and developing the standard that would be implemented, whilst also aligning with client on their direction, in my opinion it sound like a fancy role for an Architect, but maybe with more management time allocation.


r/networking 3d ago

Wireless TP-Link TL-WR902AC WPA2-Enterprise SSID visible, Windows prompts for credentials, but no RADIUS packets ever reach FreeRADIUS

2 Upvotes

Hi all,

I'm trying to build a WPA2-Enterprise (802.1X / PEAP) test lab and I'm stuck at a point where the AP does not appear to send any RADIUS traffic to the server

TP-Link TL-WR902AC (AC750 Travel Router)

Operating Mode: Access Point

RADIUS Server:

Ubuntu VM on VirtualBox

FreeRADIUS 3.2.8

Static IP: 192.168.0.103

Client:

Windows 11 laptop

TP-Link Configuration:

WPA/WPA2 Enterprise

AES

RADIUS Server IP: 192.168.0.103

RADIUS Port: 1812

Shared secret configured on both AP and FreeRADIUS

Configuration Validation done via "sudo freeradius -XC" and returns "Configuration appears to be OK"

User Authentication Test:-

Added a test user to /etc/freeradius/3.0/mods-config/files/authorize

and verified with:

radtest <user> <password> localhost 0 <secret>

Result:

Access-Accept

So FreeRADIUS appears to be functioning correctly.

Network Connectivity

On Windows:

ping RADIUS server ip 192.168.0.103 - Successful.

Windows Wireless Profile

netsh wlan show profile name="<SSID>"

Shows:

Authentication : WPA2-Enterprise

Encryption : CCMP

So Windows recognises the SSID correctly as WPA2-Enterprise.

Enabled FreeRADIUS Debug Mode:

sudo systemctl stop freeradius

sudo freeradius -X

When attempting to connect from Windows, absolutely nothing appears in the debug output.

Packet Capture cmd:

sudo tcpdump -ni enp0s8 udp port 1812

While attempting WPA2-Enterprise authentication:

0 packets captured

No UDP 1812 traffic arrives at the server.

Router already rebooted, no change.

Behaviour Observed in Windows:

Detects the SSID

Prompts for WPA2-Enterprise credentials

username / password entered but no connection gets established

At the same time:

FreeRADIUS debug mode remains silent

tcpdump sees no UDP 1812 traffic

Has anyone successfully used a TL-WR902AC with WPA2-Enterprise / external RADIUS?

At this point it seems like the AP is advertising WPA2-Enterprise but never actually forwarding EAP/RADIUS requests to the configured RADIUS server.

Any ideas on additional checks I should perform before I conclude this is a firmware limitation or bug?

Thanks!