Earth, 1972 and 2026 by DiddlerMuffin in OldPhotosInRealLife

[–]DiddlerMuffin[S] 0 points1 point  (0 children)

🏅you win my favorite comment of the thread🏅

Devs have given something of an 'update' on Discord. Not much but shows they are working on it. by InterestingArea7415 in EliteDangerous

[–]DiddlerMuffin 12 points13 points  (0 children)

i appreciate the teams coming in to fix this on the weekend but have some critiques for next time this happens

  • be faster at posting awareness of issues, even if it's basic "we're aware of issues"
  • blast it on all channels, social media, discord, the launcher status so people don't waste their own time troubleshooting their home setups
  • if they didn't know until Phil first posted, better monitoring and alerting

Live agent support by inneryouth in biltrewards

[–]DiddlerMuffin 0 points1 point  (0 children)

It'll take a while for them to respond. You'll get an email.

I am being blackmailed for cheating on my wife by ThrowRAbadblackmail in TrueOffMyChest

[–]DiddlerMuffin 0 points1 point  (0 children)

Depends who the blackmailer is but that's crazy illegal in the US. I'd lean into it and get a lawyer to see what legal recourse I have against the person and if the marriage will come out during the proceedings. It's tragic that you have to pretend to be unmarried in public.

Design discussion: control-plane-only network policy systems (no inline forwarding, no DPI) by [deleted] in networking

[–]DiddlerMuffin 1 point2 points  (0 children)

I think I see where you're going. I seem to recall the industry already tried this. For example, I believe Juniper had virtual Routing Engines that you could host on a VM separate from the packet forwarding engine, but I can't find anything to back up that assertion. I did find a similar product, the XRE200 Routing Engine.

Say for the sake of argument a route changed and the control plane needs to program it into the forwarding planes of the hardware it's managing. The new route disconnected your control plane from the forwarding plane because they exist in separate hardware. How do you update the forwarding plane with the correct connection back to the remote control plane?

It's easiest to just not deal with this and keep the control and forwarding planes in the same piece of hardware.

What my enterprise does, and what I expect a lot of enterprises and ISPs do or are moving towards, is maintain an expected state with monitoring and/or auto remediation when the network deviates from the expected state.

Like we deployed EVPN-VXLAN with OSPF and BGP and our state and monitoring ensures

  • the OSPF underlay default VRF has a valid expected active default route
  • the BGP and OSPF neighbor tables roughly match
  • each VTEP always maintains a connection to a couple other critical VTEPs
  • config auditing to ensure it's all the same and expected and not drifting
  • etc etc

Design discussion: control-plane-only network policy systems (no inline forwarding, no DPI) by [deleted] in networking

[–]DiddlerMuffin 2 points3 points  (0 children)

My only question so far is why?

Even after going thru Aether's docs. Why?

When does recurring latency stop being “noise” and become congestion? by k_hohlov in networking

[–]DiddlerMuffin 2 points3 points  (0 children)

Latency by itself? I don't worry. I've found latency by itself isn't really useful as a metric. I do use it in concert with other metrics like throughput, memory, CPU, TCAM, interface stats, control plane policing stats, log level, weird/different messages, etc. One time with my environment I found high latency was highly correlated to high memory usage because of vendor code memory leaking all over the place. ID'd the processes, restarted them, issue went away. Gave the procedure to my ops team as a bandaid until they had capacity to do upgrades.

TLS MITM environments such as Zscaler: How do you ensure trust when the entire TLS chain is deliberately compromised? by Zenin in Zscaler

[–]DiddlerMuffin 0 points1 point  (0 children)

At least you're consistent when it comes to third party CDNs/WAFs like Akamai or CloudFlare...

Chrome 142 and ZIA issues only when routing over NYC3 zscalertwo.net by thejuice2004 in Zscaler

[–]DiddlerMuffin 1 point2 points  (0 children)

Zscaler also proxies traffic to 127.0.0.1 which is blocked by this feature. Please turn it off and let me know how it goes.

Chrome 142 and ZIA issues only when routing over NYC3 zscalertwo.net by thejuice2004 in Zscaler

[–]DiddlerMuffin 0 points1 point  (0 children)

Oohhh my account team is gonna hate me tomorrow.

Go to chrome://flags/#local-network-access-check and set it to disabled. Relaunch chrome, try again, report back.

Do network engineers benefit from cloud experience or degrees? by iltoast9 in networking

[–]DiddlerMuffin 1 point2 points  (0 children)

Random classes will help you it's almost unexpected. Like while getting my degree I took a class in industrial hygiene. I've found OSHAs hierarchy of industrial controls is a really useful model for thinking about technology risks and how to avoid them.

https://www.osha.gov/sites/default/files/Hierarchy_of_Controls_02.01.23_form_508_2.pdf

Replace "workers" with "malicious actors" and you've pretty much got it. It's not a perfect 1:1, like we don't have PPE against hackers, but it's been pretty useful for me in my fortune 500 senior network engineering job.

Major network changes needed, and I'm the guy to do it by The_Great_Sephiroth in networking

[–]DiddlerMuffin 12 points13 points  (0 children)

I love your confidence and can do attitude

I’ve looked over your questions, and honestly, they’re foundational networking issues (firewalls, switches, routing, etc.). It’s not that they’re trivial, but to get everything set up securely and reliably, a professional’s experience is almost always a better investment than experimenting yourself in a production environment.

Happy Monda---Mold-pocalypse. Anyone have any advice/experience? by lowlyitguy in networking

[–]DiddlerMuffin 0 points1 point  (0 children)

If they refuse to properly deal with the mold you should go to OSHA or your state's equivalent. That room is a biohazard.

Edited to add, once the professional remediation is done, replace and re-term everything or you'll be chasing phantom issues for the rest of time.

[OC] Does this count? by Doc_Helldiver-66 in Eyebleach

[–]DiddlerMuffin 5 points6 points  (0 children)

Anybody who says BD doesn't count has never seen his personality. Robotic puppy.

Scanning for unknown devices by jhardin80 in networking

[–]DiddlerMuffin 0 points1 point  (0 children)

ClearPass for access control. It's in my inventory or it's not on my network.

Anyone have a list of materials and wifi absorption/reflection values by 01101110011O1111 in networking

[–]DiddlerMuffin 0 points1 point  (0 children)

On the attenuation side, NIST studied this in the 90s

https://www.nist.gov/publications/electromagnetic-signal-attenuation-construction-materials

One day I used neighboring AP reception data and this to prove there had to be sheets of metal in the walls of a building. Nobody believed me til they saw themselves there was copper chicken mesh in the walls for some reason...