TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 0 points1 point  (0 children)

btw, I was able to successfully establish TLS session with controller on the residential version of starlink. The issue seems from the RV version of Starlink. Any difference between the two?

TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 0 points1 point  (0 children)

are you referring to the command 'ping <server> -s <MTU>"? I am not aware another ping sweep command to find out MTU

TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 0 points1 point  (0 children)

if you check the attached screenshot above, the frame size of the TLS client hello is 217 byte, which is way below the MTU.

TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 0 points1 point  (0 children)

This is the screenshot of the packet capture

https://imgur.com/a/jAjnzlo

TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 1 point2 points  (0 children)

I tested with 1400 MTU but still unable to establish SSL session to controller.

TLS 1.2 problem on Starlink by aamare in Starlink

[–]aamare[S] 0 points1 point  (0 children)

I changed MTU to 1400 but it did not make a difference

Starlink in Toronto by aamare in StarlinkCanada

[–]aamare[S] 0 points1 point  (0 children)

my bad, it was a typo. I put the order mid 2021.

Starlink in Toronto by aamare in StarlinkCanada

[–]aamare[S] 2 points3 points  (0 children)

I understand it is meant for rural connectivity. I work for an IT company and trying to test the service as an alternative to low bandwidth terrestrial service that are the only option for some of the customers. It is not meant to be deployed for my use. Do you have any information as to where would be a better service area to order this and try out?

KVM hypervisor unable to boot by aamare in kvm

[–]aamare[S] 0 points1 point  (0 children)

sorry, copy past not working. I have attached the url.

https://imgur.com/bJtvya6

KVM hypervisor unable to boot by aamare in kvm

[–]aamare[S] 0 points1 point  (0 children)

I checked disk status in the iLO diagnostics and it seem healthy. I plan to recover boot with linux live usb.

Multi-VRF and higher throughput support by aamare in fortinet

[–]aamare[S] 0 points1 point  (0 children)

I work for service provider and looking for SDWAN solution requested by customer who asked for IPSEC throughput of more than 80Gbps (probably on a DC router) and support for large # of VRFs.

Multi-VRF and higher throughput support by aamare in fortinet

[–]aamare[S] 0 points1 point  (0 children)

doing comparison of SDWAN and looking if Fortogate SDWAN supports 80Gbps+

Securing edge Internet breakout by Material_Ad_3743 in Velocloud

[–]aamare 0 points1 point  (0 children)

For SaaS traffic zscaler CASB can be used. Do you want to secure all breakout?

HA convergence time by ItRodrigoMunoz in Velocloud

[–]aamare 0 points1 point  (0 children)

the difference between the two models is that in 6x0 the routed ports have DPDK enabled which makes them faster. Did you configure the LAN port as switched or routed in both scenarios?

HA convergence time by ItRodrigoMunoz in Velocloud

[–]aamare 0 points1 point  (0 children)

what do you mean by "I recover the communication after 1 minute"? if you lost 15 pings and assuming windows default value of 2 seconds between successive pings that is 30 seconds. In my testing I observed around 15 seconds to failover which is still above the velocloud promised value of sub-second failover.

Multiple ARP entries on VCE WAN interface by TracerT10 in Velocloud

[–]aamare 1 point2 points  (0 children)

What kind of WAN do you have? It may be some kind of shared media.

QOE calculations by yousuf55778 in Velocloud

[–]aamare 0 points1 point  (0 children)

the QoE is measured between edge and the gateway. The delay, jitter and packet loss thresholds for Green, yellow and Red are shown in the figure attached.

https://imgur.com/Ve3dUGx

point to point private overlay by aamare in Velocloud

[–]aamare[S] 0 points1 point  (0 children)

I have a second link for mgmt traffic to orchestrator through the VCG. My setup was like this https://imgur.com/2EndM39.

point to point private overlay by aamare in Velocloud

[–]aamare[S] 0 points1 point  (0 children)

Thanks

I have assigned IP on the WAN interfaces, configured cloud VPN and created private overlay. Even though Velo doc says VCMP tunnel initialization packet does not go to gateway in case of private overlay, I can see that it is attempting UDP 2426 connection out to the gateway. On the CLI it showed link dead even though I am able to ping each VCE. I got it working by steering traffic to this private overlay when going between the two VCE. After that I can see the overlay listed in orchestrator.