Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Partycat
Oct 25, 2004

Looks like you saved money too not having any workers

Adbot
ADBOT LOVES YOU

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
There is someone at every chair you can see?

Partycat
Oct 25, 2004

Oh the black squares are people

I thought those were lcd monitors that were off

That'll teach me not to zoom in

abigserve
Sep 13, 2009

this is a better avatar than what I had before
Watched a talk from Barefoot networks (https://barefootnetworks.com/) yesterday out of the NFV World Congress that just wrapped up. The short version: write your own forwarding plane in a high-level language, install it on a switch, it runs at line rate no matter how complicated the program is because it's based on the chip architecture. Then, all those tables (for example, mac tables, IP prefix tables, LFIB...anything you can imagine) and actions (change dstmac, pop vlan, push mpls labels - can be anything because it's defined by you) turn into protobuf declarations which can then be compiled into whatever language you want (Python, C++ at least, I think) and exposed to control-plane software.

Holy guacamole. That right there is the next thing as long as they don't make P4 too esoteric.

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
Does anyone have ASR9006s in production? Do they line up to the proper boundaries when you rack them?

Eletriarnation
Apr 6, 2005

People don't appreciate the substance of things...
objects in space.


Oven Wrangler
Yeah, just checked and the ones I have are precisely 10U.

Pile Of Garbage
May 28, 2007



This is probably more a security question but it's still tangentially Cisco related: anyone here using Cisco Umbrella for DNS resolution? Is it actually any good beyond what it claims to do and can its efficacy be backed up in reporting?

Edit: that's good to know cheers vvv

Pile Of Garbage fucked around with this message at 15:36 on Oct 20, 2017

Thanks Ants
May 21, 2004

#essereFerrari


They're pretty clear about not supporting IPv6 so I laughed at it and ignored the product.

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE

Eletriarnation posted:

Yeah, just checked and the ones I have are precisely 10U.

Mine are 10U, but they need to be one screw (1/2") off from the proper boundaries in order for the holes in the rails to line up.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

cheese-cube posted:

This is probably more a security question but it's still tangentially Cisco related: anyone here using Cisco Umbrella for DNS resolution? Is it actually any good beyond what it claims to do and can its efficacy be backed up in reporting?

Edit: that's good to know cheers vvv

I'm on an ipv4 environment so the ipv6 limitation doesn't bother me. Just signed up a few months ago, and yeah it's pretty effective. The filtering is very up to date on malware identification and hardly anything gets through.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We're a Cisco Web Security customer and they're EOL'ing it and moving everyone to Umbrella.

Pile Of Garbage
May 28, 2007



Judge Schnoopy posted:

I'm on an ipv4 environment so the ipv6 limitation doesn't bother me. Just signed up a few months ago, and yeah it's pretty effective. The filtering is very up to date on malware identification and hardly anything gets through.

Thanks for the feedback. Our customer's infosec lead acquired a trial subscription for Umbrella so I'll probably be reconfiguring our forwarders next week to try it out.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
So umbrella is just a renamed opendns?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

falz posted:

So umbrella is just a renamed opendns?

Yes.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

falz posted:

So umbrella is just a renamed opendns?

New dashboard, but functionally the same yes. We had an on-prem dns filter that was total garbage so umbrella was a huge upgrade. They're also fast and loose with license counts and our reseller said public devices were free, so I was able to roll in our public WiFi for nothing.

It's seriously easy to configure compared to any other filter. Took 5 minutes.

wolrah
May 8, 2006
what?
How can a DNS service not support IPv6? How would there be anything more to it than just "enable IPv6 on your servers, support AAAA records in your backend"?

Thanks Ants
May 21, 2004

#essereFerrari


https://support.umbrella.com/hc/en-us/articles/230901268-Umbrella-Roaming-Client-IPv6-Support

TL;DR is that if you use the roaming client and your devices join a dual-stack network, then it breaks it.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010

Judge Schnoopy posted:

New dashboard, but functionally the same yes. We had an on-prem dns filter that was total garbage so umbrella was a huge upgrade. They're also fast and loose with license counts and our reseller said public devices were free, so I was able to roll in our public WiFi for nothing.

It's seriously easy to configure compared to any other filter. Took 5 minutes.

BRB changing my local client DNS servers to circumvent.

Yeah ok so you could firewall off other DNS servers I guess but that sounds like it would break a bunch of poo poo.

ate shit on live tv
Feb 15, 2004

by Azathoth

falz posted:

BRB changing my local client DNS servers to circumvent.

Yeah ok so you could firewall off other DNS servers I guess but that sounds like it would break a bunch of poo poo.

DNS is one of the easiest things to block. But more likely it just intercepts DNS requests so unless you are resolving through an IPSEC tunnel or something, the response you get back from any request will be from the Umbrella DNS resolver.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
The website says it's cloud security so I presume there's no on prem anything, so you have to force client DNS to get there somehow.

I would guess that a large number of their Enterprise customers forget that step, dunno.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

You can have an on prem appliance to do AD integration, but it's basically using Umbrella's DNS servers instead of your ISPs, or Googles, or whatever DNS servers you're forwarding to.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

ate poo poo on live tv posted:

DNS is one of the easiest things to block. But more likely it just intercepts DNS requests so unless you are resolving through an IPSEC tunnel or something, the response you get back from any request will be from the Umbrella DNS resolver.

Yeah our ASA redirects dns to the DNS servers, which hits umbrella. I tested manual dns resolution and umbrella caught it all.

Point is, my users aren't trying to circumvent it anyway. They just don't want to go to a site and get that full page Microsoft support spam that yells at you through the speakers. Our old filter let that poo poo thought all the time, not even once on umbrella.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Judge Schnoopy posted:

Yeah our ASA redirects dns to the DNS servers, which hits umbrella. I tested manual dns resolution and umbrella caught it all.

Point is, my users aren't trying to circumvent it anyway. They just don't want to go to a site and get that full page Microsoft support spam that yells at you through the speakers. Our old filter let that poo poo thought all the time, not even once on umbrella.

Do you put the Umbrella client on laptops? We have like 60 remote users who are morons. Today we use the CWS agent.

n0tqu1tesane
May 7, 2003

She was rubbing her ass all over my hands. They don't just do that for everyone.
Grimey Drawer
Just because I've run into this with two customers now, Cisco SpeakerTrack will detect the faces in the portraits and pictures you have hanging on the wall in your conference/meeting/board room, and politely include them in all of the automatic framing/zooming it does with the cameras.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010

n0tqu1tesane posted:

Just because I've run into this with two customers now, Cisco SpeakerTrack will detect the faces in the portraits and pictures you have hanging on the wall in your conference/meeting/board room, and politely include them in all of the automatic framing/zooming it does with the cameras.

Reminds me of https://www.youtube.com/watch?v=t4DT3tQqgRM

Partycat
Oct 25, 2004

n0tqu1tesane posted:

Just because I've run into this with two customers now, Cisco SpeakerTrack will detect the faces in the portraits and pictures you have hanging on the wall in your conference/meeting/board room, and politely include them in all of the automatic framing/zooming it does with the cameras.

Yes this is the built in trolling feature
Add pictures of dear leader to the conference room

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
Looks like we're not idiots. Cisco is sending us new rails.

ate shit on live tv
Feb 15, 2004

by Azathoth
Oh joy, another DDoS. 21Gig UDP, 173M bps, only 15K unique IPs though.

e: I think those last numbers are off by an order of magnitude.

ate shit on live tv fucked around with this message at 22:08 on Oct 30, 2017

tortilla_chip
Jun 13, 2007

k-partite
Does anyone have reading recommendations for getting up to speed on LTE/EPC environments?

mythicknight
Jan 28, 2009

my thick night

Trying to wrap my head around cucm licensing is a clusterfark.

We use extension mobility almost exclusively. Owner IDs are set to anonymous on phones, since anyone can log into any phone (and whoever the ownerid gets set to would be able to control the phone from the user portal).

We also have a shitload of CUWL Standards for who knows what reason, but everything seems to be borrowing from that pool to use Enhanced and Essential licenses.

Should I just get Enhanced & Essential licenses for the future? Or stick with CUWL?

Wonder if anyone else has run into this.

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...
I'm not sure I'm reading your post right, but check this licensing guide that should be right unless they changed their mind today.

https://www.cisco.com/c/dam/en/us/p...g_aag_v5a_1.pdf

https://www.cisco.com/c/en/us/products/unified-communications/unified-communications-licensing/index.html

Of course this can be different based on your CUCM version, etc.

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Have any of you ever deployed multi-datacenter ASA clustering, does it..work? One of my friends works in a fairly complex healthcare environment and he was looking for a solution that clustering + zoning solves, however I have not hosed with a multi-datacenter deployment. I would probably just try to solve the underlying problem that requires such an elaborate solution, but we're not their integrator so ¯\_(ツ)_/¯

KennyG
Oct 22, 2002
Here to blow my own horn.
I have something that's perplexing me. I am trying to use tunnels that exist on the "internal" default vrf as my site-to-site link for multi-site BGP that live on my two public VRFs - ISP100, and ISP200.
I'm trying to preserve IP space as i have about 18 sites that if I needed two public sets of IPs for my internal tunnel network, it would consume 64 of my c block of addresses.

Pictures are worth 1000 words so:


The left side is up and running well. The traffic is spread across both and I'm moving data efficiently, but I'm trying to add in the right side so that it links up and if someone reaches the left side bound for 9.9.9.9, they ride the tunnels. The tunnels are DMVPN and multi-site connections are working but linking the VRFs are just throwing my brain for a loop. Obviously numbers have been changed to protect the ignorant.

I don't think I want to 'leak' the private routes into the public side... do I?

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

KennyG posted:

I have something that's perplexing me. I am trying to use tunnels that exist on the "internal" default vrf as my site-to-site link for multi-site BGP that live on my two public VRFs - ISP100, and ISP200.
I'm trying to preserve IP space as i have about 18 sites that if I needed two public sets of IPs for my internal tunnel network, it would consume 64 of my c block of addresses.

Pictures are worth 1000 words so:


The left side is up and running well. The traffic is spread across both and I'm moving data efficiently, but I'm trying to add in the right side so that it links up and if someone reaches the left side bound for 9.9.9.9, they ride the tunnels. The tunnels are DMVPN and multi-site connections are working but linking the VRFs are just throwing my brain for a loop. Obviously numbers have been changed to protect the ignorant.

I don't think I want to 'leak' the private routes into the public side... do I?

I'm assuming 9.9.9.9 is in the default vrf, you didn't explicitly state.

Is the source of the traffic in the defualt vrf or one of the ISP vrfs? If the former, the route should be in your dynamic routing table. If the latter, you need to leak it.

KennyG
Oct 22, 2002
Here to blow my own horn.
Thinking about this, I think this is my issue. I need to leak that 9.9.9.9 route across the vrfs.
Thanks.

The 9.9.9.9 should exist across all of them.

Partycat
Oct 25, 2004

mythicknight posted:

Trying to wrap my head around cucm licensing is a clusterfark.

We use extension mobility almost exclusively. Owner IDs are set to anonymous on phones, since anyone can log into any phone (and whoever the ownerid gets set to would be able to control the phone from the user portal).

We also have a shitload of CUWL Standards for who knows what reason, but everything seems to be borrowing from that pool to use Enhanced and Essential licenses.

Should I just get Enhanced & Essential licenses for the future? Or stick with CUWL?

Wonder if anyone else has run into this.

What release are you running?

IIRC there was a place you could be at where you could be you'd be eating up a license for the device anonymous (which is correct) and the device profile

But that shouldn't be the case any longer

Dalrain
Nov 13, 2008

Experience joy,
Experience waffle,
Today.
I recently got on-site to one of my employer’s data closets to find a spaghetti mess of copper and fiber, and I think I’ll be spending the weekend trying to tame this crap. Can anyone recommend a resource (videos? books?) that teach how to properly loom 2-post racks to make the results not-terrible?

I freely admit I’m not a data center guy, I haven’t done pulls and don’t have the experience to do much more than velcro wraps and basic cosmetics. I was curious if there are any special tricks to hiding the slack and so forth, such that future coworkers won’t curse my name as I’m doing for whomever did this total pasta-job.

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...

Dalrain posted:

I recently got on-site to one of my employer’s data closets to find a spaghetti mess of copper and fiber, and I think I’ll be spending the weekend trying to tame this crap. Can anyone recommend a resource (videos? books?) that teach how to properly loom 2-post racks to make the results not-terrible?

I freely admit I’m not a data center guy, I haven’t done pulls and don’t have the experience to do much more than velcro wraps and basic cosmetics. I was curious if there are any special tricks to hiding the slack and so forth, such that future coworkers won’t curse my name as I’m doing for whomever did this total pasta-job.

If you haven’t done it before I would highly recommend not doing it by yourself. Get someone who knows how to do cable and fiber runs or you may Be in for some pain.

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

Bigass Moth posted:

If you haven’t done it before I would highly recommend not doing it by yourself. Get someone who knows how to do cable and fiber runs or you may Be in for some pain.

I'll second this; the money you spend on a knowledgeable person is not that high and you'll easily make it back in reduced total man hours.

Adbot
ADBOT LOVES YOU

Dalrain
Nov 13, 2008

Experience joy,
Experience waffle,
Today.
Darn, that’s not what I was hoping to hear. :(

I guess since I’m an “individual contributor” with no influence or budget, I may just be up a creek on it. Oh well, at least I have my roll of velcro. :)

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply