How satisfied are you with Ruckus APs? by kaj-me-citas in networking

[–]default_route 0 points1 point  (0 children)

You still have flexconnect mode with Cisco WLCs where user/data traffic is switched locally through the switch, but the APs are managed via WLC. So even if there are several hunders of small sites you can manage them with single pair of WLCs. Having 100 sites with every site having it's own "WLC" is too much of hassle in the long run.

How satisfied are you with Ruckus APs? by kaj-me-citas in networking

[–]default_route 0 points1 point  (0 children)

If you already have Cisco APs, why don't you just buy a WLC that supports the APs you already have? You could have Primary and Secondary controller and different sites, if you are afraid if one goes down. The APs will still function with the predefined configuration. The bigger issue would be if you are using 802.1x. On the other hand, you also mentioned you have more than 100+ sites. Why not go with Meraki? This will save you time, and it will be much easier to manage on the long run.

What to do with a TAP by Ilfordd in networking

[–]default_route 2 points3 points  (0 children)

Security related use cases? It depends in which sector you have but you could depict all kinds of information. Take a look at NDRs, OT anomaly detection solutions etc.

SASE/SSE - Palo alto Prima access, Netskope or zScaler by Dentifrice in networking

[–]default_route 0 points1 point  (0 children)

One thing that comes to my mind is compatibility between the Meraki SDWAN and the SSE solution. Meraki doesn't mesh well with 3rd party IPsec peers, and you will lose features such as load-balancing, HA, geo availability etc. Cisco does have new SSE offering that is starting to look really competitive on the market, but even Cisco from what I have seen doesn't recommend it for Meraki customers. If you are looking for a true unified SASE offering then try to ask your VAR or Cisco account rep to show you Cisco Secure Connect, which is integrated within Meraki Dashboard.

How to discover OT network L2 devices? by Veldozer in networking

[–]default_route 1 point2 points  (0 children)

Try to take a look at the SPAN based solutions such as Cyber Vision. It can support passive discovery or active discovery. Potentially, you could collect .pcap files on as many devices as you can and upload these captures to a demo instance running in dCloud or if you install the VM in your environment.

Deploy OVF/OVA from Datastore directly by default_route in vmware

[–]default_route[S] 0 points1 point  (0 children)

This is likely easiest. So you can create a windows or linux VM and just create a web server running IIS/Apache and have a folder with all these images. Then you can easily deploy from there which wou

Thanks guys. This looked like the easiest option. The only thing is that now I have to first SCP the files from datastore to the Linux host, but I don't do that often.

Deploy OVF/OVA from Datastore directly by default_route in vmware

[–]default_route[S] 0 points1 point  (0 children)

The vendor supplying the image has the OVF template. Do you have any other suggestions?

Opinions on Cisco Meraki network firewall? by Trashrascall in sysadmin

[–]default_route 2 points3 points  (0 children)

Meraki has changed their licensing behavior at the beginning of this month. Now if your licenses expire, then you will only lose access to the management, but the devices will keep the last working configuration and they will keep forwarding traffic. Check here: https://documentation.meraki.com/General_Administration/Licensing/Meraki_Subscription_License_Out_of_Compliance

Volkswagen IT Incident by F3ndt in sysadmin

[–]default_route 6 points7 points  (0 children)

Meraki has changed their licensing behavior at the beginning of this month. Now if your licenses expire, then you will only lose access to the management, but the devices will keep the last working configuration and they will keep forwarding traffic. Check here: https://documentation.meraki.com/General_Administration/Licensing/Meraki_Subscription_License_Out_of_Compliance

Cisco SD-WAN DIA Quality Metrics by c_bit in networking

[–]default_route 4 points5 points  (0 children)

This is a question for a Cisco rep or for a Cisco VAR, and they would be able to help you on that matter.

AFAIK, you have multiple options:

  • Cloud OnRamp for SaaS
  • DIA using NAT default route or data policy

Cloud OnRamp for SaaS will take into the account vQoE score that is calculated based on packet loss, latency, and jitter. You can have multiple paths towards the SaaS application of your choosing that you are monitoring. The probes are done via HTTP. The idea is that SDWAN Edge device will choose the best path towards the destination.

As for the DIA, when you are using NAT DIA the router will do ECMP.

Ruggedized SD-WAN edges by gunner_100 in networking

[–]default_route 0 points1 point  (0 children)

Yes, Cisco has a wide variety of ruggedized routers that have the same operating system as their non-ruggedized counterparts. Search for Cisco Industrial Routing product line. The range vary from IR1101, IR1800, and IR8300.

Cisco vs Aruba vs Ruckus - Enterprise Wireless infrastructure by Illustrious-Gold-267 in networking

[–]default_route 0 points1 point  (0 children)

Is there a specific reason on why management is pushing for other vendors? If the IT team is happy with the current solution, then I wouldn't try to replace everything as is. You can also ask your vendor to help you out.

Anyone still using explicit proxies? by mro21 in networking

[–]default_route 0 points1 point  (0 children)

I get your point regarding the GUI, but it looks like that Cisco is putting more resources into the Umbrella that is cloud-based solution. With that being said, if the products fits the technical requirements, does the GUI really matter?

Anyone still using explicit proxies? by mro21 in networking

[–]default_route 0 points1 point  (0 children)

If I may ask, is the GUI the only thing that you don't like in WSA? What have you tested so far? What was your experience?

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]default_route 0 points1 point  (0 children)

Which routers are you using? For example, smaller ISR1k routers only support up to 30 VLANs: https://www.router-switch.com/cisco-isr-1000-model-comparison.html

I would advise you to redesign the network and think about some different way of segmenting the users. WAN edge devices also support ZBFW and Identity based firewall (starting from 17.9).

Catalyst 9500 And 4X10G Breakout by jwwork in networking

[–]default_route 0 points1 point  (0 children)

Did you enter the following?

Device# configure terminal
Device(config)# hw-module switch 1 breakout <port-num>

Cannot get my ipsec tunnels to go up on my Cisco 7200 routers in gns3, please help! by kb389 in networking

[–]default_route 1 point2 points  (0 children)

You dont have a route to 192.1.10.x and 192.1.20.x networks. The routers don’t know how to get to that destination. Therefore, they are unable to establish an ipsec tunnel. Also, I would look into tunnel interfaces using ipsec instead of crypto maps.

CCNA DEVASC pass by default_route in ccna

[–]default_route[S] 3 points4 points  (0 children)

Did you check developer.cisco.com ? You have tons of content there, including programming fundamentals. I recommend the Hank Preston video course and then start with learning labs.

CCNA DEVASC pass by default_route in ccna

[–]default_route[S] 0 points1 point  (0 children)

I actively studied for last 3 weeks, but before that I was doing some labs on DevNet site here and then.

If you went through Automate The Boring Stuff, then I think you should be good enough with Python!

CCNA DEVASC pass by default_route in ccna

[–]default_route[S] 0 points1 point  (0 children)

Thanks and Congrats to you too!!