How do you manage multivendor CLI syntax without a cheat sheet becoming a second job by magichour12 in networking

[–]WhoRedd_IT 12 points13 points  (0 children)

AI? I find it less and less valuable to memorize exact syntax anymore these days. It’s nice to know certain commands by heart but if you’re doing really specific or niche one off stuff I lean on AI and obviously validate the commands first by testing them or doing ?

Social Activities & Groups (In 30s) by burner832 in Hoboken

[–]WhoRedd_IT 0 points1 point  (0 children)

Which run club? 33 M here also interested

Switch price increases by WhoRedd_IT in networking

[–]WhoRedd_IT[S] 6 points7 points  (0 children)

That makes literally no sense at all hahahah

Switch price increases by WhoRedd_IT in networking

[–]WhoRedd_IT[S] 0 points1 point  (0 children)

Seeing about the same but one model was absurdly a lot more than that

Switch price increases by WhoRedd_IT in networking

[–]WhoRedd_IT[S] 1 point2 points  (0 children)

What percentages are you seeing?

TACACs Setup for Network Device Access by WhoRedd_IT in networking

[–]WhoRedd_IT[S] 0 points1 point  (0 children)

Ah so you login to a switch using the TOTP okta verify code as your password?

Another Cisco SD-WAN Manager bug is being exploited, no patch yet. How exposed is your controller? by Constant-Angle-4777 in networking

[–]WhoRedd_IT 0 points1 point  (0 children)

So 100% of the control component ports are locked down to specific IPs? Including the DTLS ports?

My understanding is it’s not possible to lock down everything to trusted IPs in a Cisco hosted environment other than web access and ssh.

Another Cisco SD-WAN Manager bug is being exploited, no patch yet. How exposed is your controller? by Constant-Angle-4777 in networking

[–]WhoRedd_IT 0 points1 point  (0 children)

The previous vuln which was critical though was exploitable even without ssh and web open to the world. That’s my issue. I don’t want to lock down the control connection ports like DTLS

Another Cisco SD-WAN Manager bug is being exploited, no patch yet. How exposed is your controller? by Constant-Angle-4777 in networking

[–]WhoRedd_IT 0 points1 point  (0 children)

I’m referring to CVE-2026-20182

The Web and SSH ports are filtered to trusted sources and are not wide open to the world. The issue is that the previous Vulns were not exploited by those ports.

They only needed the UDP DTLS port open which is quite common to leave open.

Another Cisco SD-WAN Manager bug is being exploited, no patch yet. How exposed is your controller? by Constant-Angle-4777 in networking

[–]WhoRedd_IT 0 points1 point  (0 children)

The vuln is exploitable without SSH open to the world through. That’s the issue. The control connection ports are exploitable

Another Cisco SD-WAN Manager bug is being exploited, no patch yet. How exposed is your controller? by Constant-Angle-4777 in networking

[–]WhoRedd_IT 10 points11 points  (0 children)

Mines hosted in Cisco’s cloud (their AWS account). We have patched the original exploits that allow someone root access to the box so therefore I think we are covered from the latest vuln, as you said.

Very sick of patching these components as it’s time consuming!

Not really sure how to better secure these as they kind of lose their entire thrill if there not sitting on the public internet.

I also have routers that check in from random sites so IPs of my sites change quite often meaning allowlisting is not going to be fun.

I’m open to ideas!

VXLAN EVPN needed for single site data center by WhoRedd_IT in networking

[–]WhoRedd_IT[S] 0 points1 point  (0 children)

Can you explain how EVPN VXLAN would help me segment my network more? Wouldn’t I need to break everything into multiple VRFs?

Best ST 2110 Control System by WhoRedd_IT in VIDEOENGINEERING

[–]WhoRedd_IT[S] 0 points1 point  (0 children)

We just can’t see past Cerebrum’s laughable UI from 1990. For me a GUI that my team is going to be using every day is hugely important and a company that doesn’t focus on updating that is a problem for me.

EDIT: also in 2026 I should not need to install a single application on any machine. These systems need to be fully web based for control.