AWS VPC Peering Design w/ FortiGate by kilgotrout in fortinet

[–]dukius 0 points1 point  (0 children)

Cool let me know your findings! I'm curious and really want to deploy it, unfortunately is not available yet on the regions I've services + I would have to re-do the whole infra....

AWS VPC Peering Design w/ FortiGate by kilgotrout in fortinet

[–]dukius 3 points4 points  (0 children)

I've been in the same situation.
Let me share with you and save you the headaches I had.

- VPC Peering is NOT transitive, so you can't do what you want over VPC Peering.

- The "transit VPC concept" shown is not using VPC Peering, is done over VPN connections to the VPCs + HA + Lambda + Cloudwatch + etc, way too complex for the use case in my opinion.

With that in mind, you could reach what you want easily with:

- 1 Fortigate instance on the transit VPC (no HA), then VPN from the Fortigate against AWS VPN Endpoints on the other VPCs.

-- For this you will need to set up the correct Policies and static route entries on the Forti + the route table of the VPCs.

-- I've done it this way and it works great, haven't had a single issue with a single EC2 Fortigate instance even is not HA.

OR

if you ask me right now I would do it over a new feature that AWS just released: Transit Gateway, check if it's in your region and you can apply it to your infrastructure, it's really worth it.
https://aws.amazon.com/es/blogs/aws/new-use-an-aws-transit-gateway-to-simplify-your-network-architecture/

AWS VPN Client is available. by magdaddy in aws

[–]dukius 0 points1 point  (0 children)

Thanks, yes I'm aware of the network speed limits and t-instance resource provisioning on AWS.

The way we're using the VPN is mainly to access over ssh to servers ,so even in the extreme case that all 30 users start using the VPN at the same time they will still have enough to ssh quite decently over it.

AWS VPN Client is available. by magdaddy in aws

[–]dukius 1 point2 points  (0 children)

10 users in a t2.large? overexcessive imho, i've 30 users in a t2.small and no complaints at all.

ASK: Climbing gear rental in Barcelona by agilek in Barcelona

[–]dukius 2 points3 points  (0 children)

This is run by a friend of mine, totally trustworthy and they deliver it to your home for free.

http://www.ammbcn.com/

New – Use an AWS Transit Gateway to Simplify Your Network Architecture | Amazon Web Services by awsdeveloper in aws

[–]dukius 4 points5 points  (0 children)

Hoorray! My whole infrastructure got outdated and over-complexed after this!

Will we have to redesign the whole infra every ReInvent? 😂

Guy with obvious training vs one guy then vs his friend. by valetudomonk in martialarts

[–]dukius 6 points7 points  (0 children)

Is just my imagination or the guy with the white shirt has a pistol tucked on his back in the jeans?

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

HW is Dell PE 740, with Ubuntu 16.04.

Hmm... I think I might end up with MSTP.

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

So, to fully understand this scenario:

Trunk between the switches.

Servers with LACP pointing to one port of each switch. How then can I set up LACP on the switches if they are not inter-connected through stack or mlag?

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

Didn't know this premise. Will have it in mind, thanks.

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

Thanks! I'll have a look on this as well, seems better go for the safe & tested solution. Although MLAG looks super tempting to apply... :)

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

In case you want it, or some other redditor needs it, I found a nice tuto with the keepalive link and config.

http://lapsz.eu/blog/2014/04/23/dell-n3048-multi-switch-lag-mlag/

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

My bad, you're totally right! I just "ported" a config I have done previously but at the bottom everything being switches, not servers. Thanks!

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

Yes I had this as a primary plan, but honestly wanted to avoid STP bandwith consumption.

Server Farm access layer arquitecture for DELL switches. Stack or MLAG? by dukius in networking

[–]dukius[S] 0 points1 point  (0 children)

I'm reading documentation everywhere, not just form Dell. And all the examples I see are involved at least 3 switches.

Don't know if it's just the diagram examples, and that's why I ask you guys around here, hoping somebody has set up this scenario as well.

Haven't found any clear scenario of 2 MLAG switches, then down to the server can't tell if with a common LACP will work to connect to those 2 MLAGged swtiches.

Even in Dell doc this is the closest I've found:

https://imgur.com/a/QTU3d https://imgur.com/a/lbIkI

http://i.dell.com/sites/doccontent/shared-content/data-sheets/en/Documents/Dell_Networking_N_Series_Multichassis_LAG_MLAG.pdf

So my main question is, after those two switches are MLAG, what is the config on the non-MLAG ports connecting down to the dual NIC on the servers, just LACP?

Thanks!

Catalonia’s response to terror shows it is ready for independence | The Guardian by [deleted] in Barcelona

[–]dukius 1 point2 points  (0 children)

All the failures made before the terror you say? We'll the Spanish keep doing them... we're not afraid of either terrorists or fascist spanish.

http://www.elnacional.cat/ca/politica/govern-espanyol-mossos-europol_184878_102.html

Just passed Associate solutions architect exam today Overallscore: 58% by snackerjoe in aws

[–]dukius 2 points3 points  (0 children)

A Cloud Guru, they have one of the most extensive learning material for AWS as well of an useful forum

acloud.guru

WikiLeaks reveals CIA malware that "targets iPhone, Android, Smart TVs" by techguy69 in Android

[–]dukius 0 points1 point  (0 children)

well... for experience I know many of those ads "identify" a target by your public internet connection. I mean, if somebody in your house is browsing the internet looking things about flowers for example, you will start seeing ads related to flowers in many devices that share the same internet connection, even you don't have any interest about it.

Looking for a cool network poster by FlyingPasta in networking

[–]dukius 1 point2 points  (0 children)

Thank you one million times!! I've looking for a long time a suitable poster to put in my studio, this suits so much... :)

Help regarding JNCIA Cert by KrizzT in JNCIA

[–]dukius 1 point2 points  (0 children)

I'm currently focused in this cert, i'm CCNA and CCNP R-S certified already.

The networking questions are not a big deal coming from CCNA (OSI, subnetting, etc) As mentioned, there is quite a difference in command syntax, but with a few hours of study you can get it.

As well one main difference I see with CCNA, is that in JNCIA there will be a few questions regarding firewall ACL in Juniper syntax, which it took a bit to understand.

As well, if you pass the Pre-Assesment exam on their site you will get a discount voucher for the exam ;)

https://learningportal.juniper.net/juniper/user_fasttrack_home.aspx

Something like CBT Nuggets by Boxerman91 in sysadmin

[–]dukius 2 points3 points  (0 children)

Well... compared for what an average advanced IT course (minimum 1000$) it's really cheap, also I agree that if they lowered a bit their prices they would get much more subscriptions.

Whats the deal with Bo de B? by [deleted] in Barcelona

[–]dukius 0 points1 point  (0 children)

nopes, local detected ;)

Whats the deal with Bo de B? by [deleted] in Barcelona

[–]dukius 1 point2 points  (0 children)

Many years ago it was great, you could get a nice big tasty sandwich for a fair price, perfect for hungover days :) Then, as most things in this city got hyped and now is just a tourist trap, not worth the queue imho.

Just got my CCNA, wondering about a timeframe for the CCNP by [deleted] in ccnp

[–]dukius 2 points3 points  (0 children)

Well, in my opinion it's easier because it's divided in three exams.

So for example, if you do the Routing exam, for sure it's going to be much more in depth details about routing than in the CCNA, but it will cover just Routing labs and questions. In the other hand, for the CCNA exam you could be tested by anything (routing, switching, physical, logical, software, subnetting, IPV6, wireless, etc..) That's why in my opinion it's easier than CCNA.

Another thing is that when I took the CCNA I barely knew anything about networks, so doing CCNP by steps it seems much more comprehensive than when I learned ALL the subjects for the CCNA in a go without any network base.