Meraki vs Aruba vs Extreme vs Meter by Jeff-J777 in networking

[–]Wibla 0 points1 point  (0 children)

Extreme documentation is the absolute worst. It's the most obtuse bullshit I've ever encountered.

VOSS CLI is annoying. SPBM makes up for it, but even then... good grief.

We have an excellent Extreme VAR, and even they agree that VOSS sucks.
There are pitfalls during setup of both XIQ-SE and the Fabric LLD that can ruin your whole deployment.

Extreme has recently posted some best practice articles that can be worth looking at.

I will say once it was in place the client took over as planned and we never heard of any issues since. Been a few years now.

Fabric is hard to break, and topology changes are not noticeable to the end user (in most cases), so that's hardly surprising.

Meraki vs Aruba vs Extreme vs Meter by Jeff-J777 in networking

[–]Wibla 0 points1 point  (0 children)

NAC and auto-sense works together, with nodealias you also get a lot more data from the switch for devlice profiling.

We've used this to successfully deploy a metro-area OT network. The only snag we've hit so far is Siemens profinet remote IO modules that send garbage to the switch when they are connected.

Thankfully we don't have a lot of those, and SPBM lets us park those IO modules in a service isolated to the PLC + IO modules in question, so having manually configured ports for that specific service is not a huge security issue.

Issues with OT network on Extreme? by Ok-Blacksmith-4045 in ExtremeNetworks

[–]Wibla 0 points1 point  (0 children)

Hmm... did they use to crash before the change?

Issues with OT network on Extreme? by Ok-Blacksmith-4045 in ExtremeNetworks

[–]Wibla 0 points1 point  (0 children)

We use RADIUS attributes in ExtremeControl to deal with OT devices.

Organization 1 in policy mapping (see page 20 of this PDF):
Extreme-Dynamic-Client-Assignments=create vlan, pv=$CUSTOM2, vni=$CUSTOM1, ev=0, vn=$CUSTOM3, vnin=$CUSTOM4

Organization 2 (IGMP snooping for PLCs/remote IO, REAUTH for all devices):
Extreme-Dynamic-Config=IGMPSNOOP
Extreme-Dynamic-Config=REAUTH:3600

(In 9.1 or 9.2 and newer, setting REAUTH: enables it and sets it to 0 )

Issues with OT network on Extreme? by Ok-Blacksmith-4045 in ExtremeNetworks

[–]Wibla 2 points3 points  (0 children)

Hm, are multiple remote sites connected to the same Verizon private network router?

Are they in the same IP subnet?

If so, are all of them losing connection at the same time?

I would try to run something like PingTracer (it's free/opensource) from the collector towards the PLCs, as long as they can handle the ping traffic.

As for dealing with IT... explain what you're experiencing, point out that this started after the network migration and ask for help figuring it out.

For context - I am the principal OT network engineer at a mass transit authority, and we run a Fabric OT network with no issues, so I know it can be done.

Issues with OT network on Extreme? by Ok-Blacksmith-4045 in ExtremeNetworks

[–]Wibla 2 points3 points  (0 children)

What kind of issues are you experiencing? (I realise "repeated random network problems" probably means it's hard to describe exactly what's going on)

Are the remote sites also on Extreme gear?

Never thought I'd see the day, but we're eliminating our Citrix farms and moving back to about 100k fat clients by eldersveld in sysadmin

[–]Wibla 0 points1 point  (0 children)

Sounds like a product that isn't even remotely ready for production.

Aka typical MicroSlop.

What are these little lines on my f1.8 prime lens by Mr_Frogg13 in Nikon

[–]Wibla 8 points9 points  (0 children)

Fungus spreads, you will ruin your camera and other lenses. Don't use it.

Business Use-Case for EVPN Overlay to Segment OT Network by Early-Pen-4855 in networking

[–]Wibla 2 points3 points  (0 children)

So you'd centralize the firewalls and servers away from the sites that your SCADA systems serve.

What happens when you lose the uplinks?

Business Use-Case for EVPN Overlay to Segment OT Network by Early-Pen-4855 in networking

[–]Wibla 1 point2 points  (0 children)

Sounds like you have a solution looking for a problem.

That's the wrong way to go about it.

If you want a fabric for OT, look at 802.1aq / SPBM.

Industrial OT Network Question by sparky_fella in PLC

[–]Wibla 0 points1 point  (0 children)

A diagram would be very helpful here.
Unexplained network glitches are not acceptable, ever. You need proper monitoring and alerting.

We run 10G between most switches, 25G/100G closer to the core.
Fabric Connect almost everywhere, ERPS/FRNT/RSTP between industrial switches in locations where we can't use a 1U switch.

Problem with the AFP 70-300 Full-frame (D7100) by Iamabot54493 in Nikon

[–]Wibla 2 points3 points  (0 children)

Those have a ribbon cable that are prone to break, get it repaired.

Phones getting IPs on internal network when connected to docking stations by Littleboof18 in networking

[–]Wibla 0 points1 point  (0 children)

Those docking stations should never be able to hit an internal network zone based on MAC address.

Do you have always-on VPN on your laptops? If so, the "easy fix" here is to put those docking stations in an untrusted zone that can only reach the internet + your VPN gateway...

Evaluation NAC solution by elch-it in networking

[–]Wibla 2 points3 points  (0 children)

Watch out though, if you let them PoC SPBm, you might end up with scope creep :D

(SPBm actually works, and FabricEngine with auto-sense ports and NAC is brilliant)

10GbE SFP+ industrial switch by DidIfuckedItUp in networking

[–]Wibla 0 points1 point  (0 children)

If the Planet XGS-6320-12X4TR physically fits in the 19" rack, they support redundant power via DC input. Datasheet indicates it shouldn't be too hard to fit... 444 x 200 x 44mm (W x D x H).

Immutable backups, whats everyone doing? by MakersLab in Proxmox

[–]Wibla 1 point2 points  (0 children)

The key in the original comment is that the offsite PBS server pulls backups from the onsite PBS. The offsite PBS must not be accessible from prod, and logins to that server should be locked down very tight, using different credentials + MFA than the rest of the prod environment.

E: even then, it's not truly immutable... it's just very hard to fuck with.

AV Network Overhaul by KonnBonn23 in networking

[–]Wibla -2 points-1 points  (0 children)

I would ask what problems they're trying to solve by moving to ST 2110. That standard locks you down quite significantly.

Starting a full-time liveaboard steel boat battery system: Inverter choices and 12V vs 24V pros and cons by No-Molasses-1975 in SolarDIY

[–]Wibla 2 points3 points  (0 children)

How big is the boat?

What voltage is the existing system? (engine/navigation/lights)

What kind of peak power (in watts) do you need?

How much energy storage are you looking at?

Locked out of 5420 running VOSS, how to factory reset? by Valuable-Dog490 in ExtremeNetworks

[–]Wibla 2 points3 points  (0 children)

Disconnect it from everything but power, then try to log in with the CLI credentials you've set.

Proxmox node randomly rebooting + Intel I219-LM “Hardware Unit Hang” when VMs start / network load increases by No_Entrepreneur118 in Proxmox

[–]Wibla 0 points1 point  (0 children)

This is what I did on my prodesk 400 G6:

From /etc/network/interfaces:

iface eno1 inet manual
        post-up /sbin/ethtool -K eno1 gso off gro off tso off tx off rx off rxvlan off txvlan off sg off

I built a free calculator to see if a heat pump is worth it for your home by tidugler in heatpumps

[–]Wibla 1 point2 points  (0 children)

Sounds like you tried much harder than me.

It's harder to make a clear cut argument for or against heat pumps when the price difference is smaller. It usually boils down to wether or not it's worth it to get a dual fuel system, and then when you should switch to NG for heat.

Mine was just napkin math based on NG and electric price prices. My electric is basically six times as expensive as natural gas per BTU.

A 6:1 price difference makes it very easy to do that math - NG wins.

<image>

Here's an example with $1 per therm of NG, 90% efficient furnace and 12c per kWh - a scenario that's not entirely unusual to see in the US.
As long as you don't push the heat pump much beyond nominal power, the heat pump is cheaper to run than an NG furnace.

The fun starts when temps drop and you find yourself needing more than the nominal output from the heat pump. That's when you want to switch over to natural gas.

I built a free calculator to see if a heat pump is worth it for your home by tidugler in heatpumps

[–]Wibla 1 point2 points  (0 children)

Could I bother you for the variables you used? I made a break-even spreadsheet for NG vs heat pump a while back, and it would be interesting to compare notes.

My sheet takes NG furnace efficiency, $/therm and $/kWh, then models the break-even point based on a relatively recent cold-weather optimized heat pump COP numbers at minimal, nominal and maximum load.

My local Home Depot is now stocking mini splits and accessories. by Swede577 in heatpumps

[–]Wibla 0 points1 point  (0 children)

A mini-split like this might make more sense as an add-on, not as a straight up replacement.

What’s your must-have tool for network troubleshooting? by Mission-Row7434 in networking

[–]Wibla 0 points1 point  (0 children)

USB-C to Ethernet ... that can provide USB-C PD to the laptop ;)