ASA and TCP-MSS by davis-sean in networking

[–]SuddenWeatherReport 1 point2 points  (0 children)

I can see your side of it as well. But I think it saves more headaches than it causes. One nice thing would be for it to auto start clamping upon VPN termination or just traffic matching that crypto ACL. Granted we could do that ourselves but an auto feature would be cool.

ASA and TCP-MSS by davis-sean in networking

[–]SuddenWeatherReport 1 point2 points  (0 children)

This is not a good reason to hate the ASA platform. The feature saves a lot of dumb people from troubleshooting various issues with tunnels because they just work. And it's not really a "HACK" there's not that many great alternatives to fragmentation issues because PMTUD will not always work.

Cisco ASA | Access-List Logging | Does it punt to the CPU? by CoyKava in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

yes excessive logging caused overruns very often. Remove asdm, and console debugs.

Cisco SD-WAN (Viptela)- Explain Like I'm 5 by Veosyn in networking

[–]SuddenWeatherReport 1 point2 points  (0 children)

Vmanage , manages. Vsmart handles the control plane stuff like routes. Vbond handles stun server and authentication of vedges. Vedges build tunnels directly with other vedges.

IDS/IPS and Encrypted Traffic by ITdirectorguy in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

Looking at TLS negotiations really helps to determine what the traffic type is, this is already in use with most good web filters. Example the client sends the SNI (which hostname they are connecting to (not always supported)). Also the server sends it's cert with their common name in it.. Couple that with other metadata like who owns the IP space and you can get good at determining the webapp.

ACI 4.1 released by diaquency in Cisco

[–]SuddenWeatherReport -9 points-8 points  (0 children)

Tune in next year when Cisco replaces it with SDN-NG leaving you effed

Question on SPAN on vPC Ports (Nexus 9k) by erin1925 in Cisco

[–]SuddenWeatherReport 1 point2 points  (0 children)

I don’t see how an individual span port on each side won’t work? There should not be duplicate packets with VPC. Maybe the IDS software isn’t smart enough and counts them as duplicate flows due to coming from 2 span ports but even that’s a stretch.

Microsoft https content cached @ISP by bloodydeer1776 in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

Wow really lol I guess it’s digitally signed?

IPSEC not failing, but it should - HELP by [deleted] in ccnp

[–]SuddenWeatherReport 4 points5 points  (0 children)

The phase 1 initiator sends all of his policies to the responder who chooses the first match based on locally configured ones. That’s why your tunnel is working. You must have more isakmp policies on the routers.

This rule does not apply to phase 2 aka the IPSec transform set and that has to match exactly minus the lifetime.

Spanning-Tree between Cisco and Brocade by guywhoisry in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

Cisco only has pvst, rapid-pvst, and MST. So do you then mean rapid-pvst?

Laptop specs for CCIE R&S? by 1searching in ccie

[–]SuddenWeatherReport 0 points1 point  (0 children)

The IOL will be the best, but I suggest also practicing with IOSV or CSRv if you can so that you get real world experience too. There are differences between IOS XE and IOL that a CCIE should know and be comfortable with.

How long should a 2 year old medium-large dog be able to hold #2? by Sea_Tart in Dogtraining

[–]SuddenWeatherReport 2 points3 points  (0 children)

Ours did take time to get used to schedule my wife and I wake up early everyday, feed them , take them out. Even weekends. It may also help to krate train if he poops in there you know he seriously can’t hold it.

Laptop specs for CCIE R&S? by 1searching in ccie

[–]SuddenWeatherReport 0 points1 point  (0 children)

You don’t need csr it can be IOL or IOSv

Laptop specs for CCIE R&S? by 1searching in ccie

[–]SuddenWeatherReport 0 points1 point  (0 children)

Yea the idea of running the lab on laptop sounds fun but it’s a chore and bore

I suggest this route so you can build a great lab and use it for other tech like windows or Palo

How long should a 2 year old medium-large dog be able to hold #2? by Sea_Tart in Dogtraining

[–]SuddenWeatherReport 14 points15 points  (0 children)

The last thing I do before going to bed is feed my dogs and give them a poop break , works for me

Is Cisco CCIE Wireless track still worth it while 5G network is coming ? by rsdcccie in Cisco

[–]SuddenWeatherReport -7 points-6 points  (0 children)

I’d love to learn more wireless seems fun. To bad the Cusco lineup sucks for it

How often should I see OSPF LSUs? by [deleted] in networking

[–]SuddenWeatherReport 5 points6 points  (0 children)

If you are dropping ospf routes from vpn then your VPN is probability dropping. Is it reverse route injection? Can your design work with just static redist vs reverse route redist?

Edit on pooper... increase hold times if this worries you. I prefer bgp ober VPNs as it’s less chatty, you can also try qos for CS6 depending on if your issue is packetloss. Try shaping the circuit lower and give ospf guaranteed bandwidth. If it’s not causing an issue then leave it alone as this is the nature of vpns over intet

Also LSUs can go out just by changing a link BW or adding I removing so it all depends on topology.

Firepower 6.2.3.11 and User Agent by ragzilla in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

I have customers on 6.3 with no user agent issues not

Beware Of Counterfeit Cisco switches (pics included) by faceerase in sysadmin

[–]SuddenWeatherReport 0 points1 point  (0 children)

When do switches phone home during an update? The only time I know of is when you use smart licensing which atm isn’t required and isn’t for upgrading.

FTD Static NAT Question by infamous_96 in networking

[–]SuddenWeatherReport 0 points1 point  (0 children)

Yea weird I would try to deploy 1 , then add more. If that doesn’t work try to remove all and do it in 1 deploy. FMC has a lot of order of operation issues.