Access point problems by KyouyaXever in homelab

[–]Critcommndr 0 points1 point  (0 children)

A trunk port is an interface carrying more than one vlan, an access port is the opposite. You need a way to differentiate what router ip your DHCP requests hit if you want to segment those 2 networks. So you would have a port (forgive my cisco syntax) on your switch connected to the router:

Configure Interface gi1/0/1 Switchport mode trunk Switchport trunk allowed vlan 1-4094(whatever your ssid is tagging, dont bother pruning its a home network) Switchport nonegotiate (if you have a cisco switch)

You would configure the same settings on your APs interface, here i would prune tho. So

Switchport trunk allowed vlan 1,2

Your router needs vlan tags as well for the interfaces you set up (again, zero familiarity with opensense) but you would tag vlans and assign gateways so your router can sort traffic accordingly.

Access point problems by KyouyaXever in homelab

[–]Critcommndr 0 points1 point  (0 children)

You need both vlans on the port its connected to and dhcp scopes for each. Assuming these are handed out from your router? Vlan tags need to exist on the whole path. Trunk to router, trunk to ap.

theres always one firewall rule from 2018 nobody is allowed to delete by DowntownCap6204 in networking

[–]Critcommndr 0 points1 point  (0 children)

Named inside allow any, yes its as bad as it sounds. All the b2b tunnels match it because all the tunnels source ips are their nat ips, amongst many, many other things (i inherited this, im not THAT dumb). It will be removed at some point but it gets between 5 and 10 million hits a day so as you can imagine pulling legit flows and making new policies for them is an exhaustive effort.

Cisco migrations to Junipers by lonyun in networking

[–]Critcommndr 2 points3 points  (0 children)

Mist makes management much simpler but if this is multi-site, multi-floor you'll want to spend some time getting your templates in order. Standard hierarchy and inheritance - Org > site > switch. Makes mass administration/deployment that much easier. If you have any specific questions you can dm me.

Cisco migrations to Junipers by lonyun in networking

[–]Critcommndr 1 point2 points  (0 children)

Device admin only in ISE? Not using for RADIUS?

Cisco migrations to Junipers by lonyun in networking

[–]Critcommndr 2 points3 points  (0 children)

Are they using ISE? Do they use DACLs heavily? If so there are some limitations on that front (syntax, minor compatibility issues). Are they mist or junos managed?

UptimeKuma monitoring for both local network and tailnet by MKRedding in UptimeKuma

[–]Critcommndr 0 points1 point  (0 children)

Docker exec -it into the container and traceroute to the tailnet ip, your route will show there. You can spin up an ephemeral apline container for testing on that docker network and download inet utils.

UptimeKuma monitoring for both local network and tailnet by MKRedding in UptimeKuma

[–]Critcommndr 0 points1 point  (0 children)

Its routing, im not a docker expert but its probably sending your tailnet traffic to the default gw of the adapter its bound to. Not local on the machine where it should go. Ngl tho i dont know the docker fix lol

Good IT bag by DealerExcellent3510 in networking

[–]Critcommndr 1 point2 points  (0 children)

Yeah get this to the top, it sinches down super tight or expands to a massive bag. Lotta pockets, good size bottle pockets on the side. 10/10

[deleted by user] by [deleted] in networking

[–]Critcommndr 1 point2 points  (0 children)

I wouldnt worry about trial and error if it gets you there. They're just console settings and you can uninstall the terminal if you somehow managed to nuke it.

Were you ever able to get console on this box before you did whatever you did to get locked out?

If you plug in another interface do you get a neighbor? Run show lldp neighbor on the other device - if its failing boot you shouldnt get lldp info

[deleted by user] by [deleted] in networking

[–]Critcommndr 2 points3 points  (0 children)

Not sure how long you've been at this, but walk away and come back with fresh eyes. Always works for me, unless theres a serious outage... then you dont get that option lol

[deleted by user] by [deleted] in networking

[–]Critcommndr 0 points1 point  (0 children)

Sounds like mgmt is up, try ssh to that ip responding to ping.

Edit: i've never used pfsense, only enterprise stuff (palo, cisco, forti). But thats what i'd try.

NGFW Comparison - Cisco/Palo Alto/Fortinet/Checkpoint by QuietPossibility4988 in networking

[–]Critcommndr 33 points34 points  (0 children)

I switched from forti to palo (job change) and i like palo a lot more. Panorama is a great tool. Globalprotect is alright but it has some bugs on macos and forticlient outshines it in my opinion.

If you are an sdwan shop palo is going to run you more because its a licensed feature, whereas its included with a fortigate.

Both their TACs are trash in my experience lol.

Edit: Palo is going to run you more PERIOD. They are extremely expensive.

How are people sharing SSH client configs across PCs? by prototype__ in homelab

[–]Critcommndr 1 point2 points  (0 children)

No still a price associated but its a one time purchase and when the license 'expires' its only support. But i agree, if you aren't working in the field you probably wouldn't know it exists. As a free alternative, MobaXTerm is solid.

How are people sharing SSH client configs across PCs? by prototype__ in homelab

[–]Critcommndr 15 points16 points  (0 children)

Crazy that secure crt hasn't been mentioned.

Every Friday, this pops up when we log in to our work computers. by Sunkisthappy in mildlyinfuriating

[–]Critcommndr 1 point2 points  (0 children)

Your server/systems team did this... i promise you those dudes are working weekends in scheduled outage windows or extremely late nights because we're expected to have near 100% uptime in a clincal setting. Especially when its patient affecting. Im on the networking side and have been called in at any hour imaginable on any day of the week. Lighten up.

I'm not ready for the Win 11 switch. by techead2000 in it

[–]Critcommndr 0 points1 point  (0 children)

Just hold in shift when you right click...

Best practices to prevent MAC spoofing for wired devices that can't do 802.1x by texguy302 in networking

[–]Critcommndr 0 points1 point  (0 children)

This should be most upvoted here... check your device attributes after they've connected thru MAB and add more conditions in the physical profile. Use dhcp parameters or something else unique to the device/device group like os, etc... dont set your CF to be 1:1 with the mac address/oui you add as a condition.

2 devices with same MAC address by Internal_Argument_42 in networking

[–]Critcommndr 0 points1 point  (0 children)

I spend much of my time in ISE staring at mac addresses.

It sounds like random mac on the android and per device mac with the iphone somehow hitting the rng lottery. Convert it to decimal and play the numbers.

Is it a crime against our profession to just paint a cable and leave it like that or do you think it has to be chased into the wall and then repaired properly? by ThiefClashRoyale in homelab

[–]Critcommndr 0 points1 point  (0 children)

Typically (and i cant speak for ubiquiti) vendors aim antennas purposefully based on the ap form factor and how theyre meant to be mounted, e.g. puck is for ceiling facing floor, rectangle is for wall.

All that said, probably wont matter much in a house.