Recent posts

#91
Routing and Switching / Re: Redundant interfaces keeps...
Last post by deanwebb - November 21, 2023, 04:56:39 PM
If you have different NICs involved, there should be different MAC addresses for each - so I don't understand why the same MAC address would appear on two interfaces. Can you explain that part in more detail?
#92
Routing and Switching / Redundant interfaces keeps tri...
Last post by kurdam - November 21, 2023, 01:34:21 AM
Hi,

I'm opening this thread because i think i'm missing some knowledge regarding the spanning tree protocol on redundant/dual-controller hardware.

To explain my problem here are some details:
I'm working in an infrastructure where we are located in two datacenters, we have on each site a symmetrical configuration.
Our entry point in the infrastructure is a fortigate that is used as a gateway for all our VLANS (public and private) as well as our firewall, from there we are connected to two Cisco Nexus 9000 in a vPC configuration and from that we also have some catalysts connected also in vPC.

I have set all the STP weights at the switch level instead of on the interface level because it was recommended to me and it is easier to manage.
I have tried STP, rSTP, and MST with exactly the same results
Before and after the implementation of vPC i had exactly the same problems.

On this infrastructure are connected some end devices (hypervisors, NAS and some network storages (dell equallogic)).

All the connections in this infrastructure are setup to have a redundant path on another network hardware to avoid downtime if something goes down so we either have dual-controller or dual network interfaces (via VDS or linux bound set up in active/standby configuration) on all our hardware

I think i'm missing some knowledge with this kind of configuration because no matter what i tried i can't seem to be able to avoid network loops when we have for example a router update.

I studied the logs and err_dis_loop are occuring on our switches interfaces seemingly at random on our servers and storages (because each time it's happening on a different hardware). I understand that due to this configuration, with network loops everywhere that this is to be expected even if i tried to upgrade to a vPC infrastructure in order to reduce the problem.

I suspect that during the STP convergence, the dual controller is also switching its active interface in order to find a path that is working and the switch in not understanding what is happening because it sees the same MAC address on two interfaces so it blocks the ports (or at least one).

tldr: Is there some specific configuration that i have to set up in order to avoid blocked ports during a convergence in a infrastructure with dual controller / VDS / linux bound interfaces/hardware ?

Thank you in advance for your help and i will be happy to give you more information if you need them. ;)
#93
Routing and Switching / Re: using smartphone as a gate...
Last post by deanwebb - November 17, 2023, 01:21:21 PM
Cell phone providers may prefer that your phone operate only as a metered hotspot rather than an open-use router or bridge, for starters. They want their money if you have a metered plan that starts to pay them after a certain amount of usage.
#94
Routing and Switching / Re: using smartphone as a gate...
Last post by ggnfs000 - November 16, 2023, 09:21:40 PM
Quote from: deanwebb on November 12, 2023, 10:35:42 AMIt may be that the operation has to be done on a smart phone that has the OS broken into, in order to expose features that cell providers would rather have shut off.
what do you think it could be that cell phone providers shut off?
On a plusnote, i setup routing and remote access on my windows 2012 server and it worked some of my devices at my home!!
router is between home local LAN and USB connected smartphone which provides access.
With this configuration, Out of 6-7 devices at home, 2 of my devices (pc and laptop) had internet access through windows 2012 server acting as router. But rest did not have. Although it is welcome news that it worked, it still seems flaky.

I also not sure why other devices were not able to get online.
I installed wireshark perhaps to investigate and find something.
#95
Routing and Switching / Re: Network routing, maybe I a...
Last post by deanwebb - November 14, 2023, 01:54:05 PM
Granting that VLAN access would be a matter of making sure the routing tables on the switch and firewall (or just firewall if the switches have no routing functions on them) are able to reach the VLAN. If they can, then it can be permitted Internet access with proper firewall configuration - likely defining that VLAN as part of the inside or trusted zone on the firewall.
#96
Routing and Switching / Re: Network routing, maybe I a...
Last post by szuguan - November 13, 2023, 07:17:51 PM
Quote from: deanwebb on November 09, 2023, 08:40:15 AMIf the Windows DC is doing DHCP, then each switch with devices that need a DHCP address should have a setting that points to the DC as the DHCP server. The setting would be for an "IP Helper" or "DHCP Relay". If another device is handing out DHCP addresses, that can lead to a conflict with the Windows server.

"Next step" is either what the business needs are. If you're not in a business and this is a lab, then it's to set up a scenario you want to work with. If it is your lab, I'd make sure that the firewall is set to block incoming traffic from the nasty old Internet. :)

So glad to have your reply, thank you.
With my current network setup, I want to let those devices connected to vlan 1 have internet access, refer "picture 2".
Possible? Or you have better/easier suggestion?
#97
Routing and Switching / Re: Network routing, maybe I a...
Last post by szuguan - November 13, 2023, 07:13:46 PM
Hi, please refer to this new "picture 2". It is more clear on what I want to achieve and my current network setup.

Please guide/advise me, thank you.
#98
Routing and Switching / Re: using smartphone as a gate...
Last post by deanwebb - November 12, 2023, 10:35:42 AM
It may be that the operation has to be done on a smart phone that has the OS broken into, in order to expose features that cell providers would rather have shut off.
#99
Routing and Switching / Re: using smartphone as a gate...
Last post by ggnfs000 - November 11, 2023, 11:14:18 PM
I am thinking following possible configurations.
Some sort windows server or linux server PC (or miniPC) with two network cards (one is ethernet and other is USB-C).
Setup dhcp to server the ethernet port.
Connect wireless switch to ethernet.
Confirure windows or linux server as a router so that all traffic from ethernet side will go to USB.
Feasible???

I read online about it somewhere, articles are scarce but at least one article said it may not work (not certain though) as wireless internet through smartphone uses different protocols or something.
#100
Security / Re: Manage security on unmanag...
Last post by DarkCorner - November 11, 2023, 02:30:43 AM
OK. Thanks for your suggestions.