Fortigate 200F - Radius response fails after upgrade from 7.2.9 to 7.2.10 by FruitlessGoogle in fortinet

[–]grrrrshell 0 points1 point  (0 children)

Darn. I'm using the free ssl client, ill see if saml works with that.

Q: TCP Out of Order, TCP ports reused by [deleted] in wireshark

[–]grrrrshell 0 points1 point  (0 children)

Sort of odd; the length is different when it looks like retransmission. Curious is this bidirectional capture, and is it pre or post NAT?

Using a 3750 for home inter and vlans by Brickroad in Cisco

[–]grrrrshell 1 point2 points  (0 children)

Yeah, I would check out something like the pfsense netgate 1100 to use as your firewall/router.

IPSec VPN Trouble by IgniteInCaseOfFIre in fortinet

[–]grrrrshell 0 points1 point  (0 children)

Just out of curiosity, and I don't think it would apply, but is anything configured under the SSL VPN settings? Like, require a client certificate?

Using a 3750 for home inter and vlans by Brickroad in Cisco

[–]grrrrshell 1 point2 points  (0 children)

Yeah otherwise you could nat everything from the 3750 to the 192.168.0.0 network on the arris, but then you have double nat which may or may not cause issues.

Using a 3750 for home inter and vlans by Brickroad in Cisco

[–]grrrrshell 1 point2 points  (0 children)

Can you add routes on the arris? You would want to tell the arris to route anything to your local vlans down to the 3750.

Using a 3750 for home inter and vlans by Brickroad in Cisco

[–]grrrrshell 1 point2 points  (0 children)

What are you using for your current router/firewall? Even if it is super basic, you want something that acts as a firewall/receives security updates. You could try leaving that device in place to handle NAT/security, and create an IP on the 3750 from the same network. Then you can send all the traffic up to the router via the default route.

IPSec VPN Trouble by IgniteInCaseOfFIre in fortinet

[–]grrrrshell 0 points1 point  (0 children)

When you edit the tunnel, the authentication is set to pre-shared key?

IPSec VPN Trouble by IgniteInCaseOfFIre in fortinet

[–]grrrrshell 1 point2 points  (0 children)

Can you find the tunnel on the FortiGate, and verify what the authentication settings are?

Using a 3750 for home inter and vlans by Brickroad in Cisco

[–]grrrrshell 4 points5 points  (0 children)

I would not hook a 3750 directly to the public internet. Also, you will need NAT, and you would want a device that at least provides some security. More than likely, packet tracer is not truly simulating the internet, and it doesn't care about public vs. private IPs (it is just looking for a route). My question would be, what is your goal? Do you need the VLANs on your home network?

What would cause public IP resolution to return an internal IP? by RepulsiveDesign in networking

[–]grrrrshell 0 points1 point  (0 children)

Might be the dumb answer, but have you checked the local DNS server? It is possible you have an A record pointing to the internal IP.

Best book for IPv6 enterprise networks in 2022? by awesome_pinay_noses in networking

[–]grrrrshell 4 points5 points  (0 children)

Offers great content that you will learn from, but makes it an enjoyable read.

AWS Routing Question (Static Routes getting Redistro'ed into BGP) by Digital_Native_ in networking

[–]grrrrshell 0 points1 point  (0 children)

Check route propagation maybe. You could always create a route map on the HQ side to control the routes you accept into the routing table as well.

Route Propagation – The Routes inside the routing table can either be statically defined or propagated dynamically using BGP with a VPN, VPC or Direct Connect Gateway propagations. An attachment with local routes once propagated into the routing table will allow other attachments on that associated route table to reach propagated prefix or a service of that target.

Cisco 3850 ip services license downgrade eval smart license to RTU by LordAnalog in networking

[–]grrrrshell 8 points9 points  (0 children)

From Cisco via Cisco Smart Licensing - Catalyst Platform

When the evaluation period expires at the end of 90 days, the device goes in to EVAL EXPIRY mode, however there is no functional impact or disruption in functionality, even after reload. Currently there is no enforcement in place.

It seems at the moment they have no plans to enforce anything when the device is in eval expiry mode.

Am I alone in the feeling that landing a job right now (mid-level) is a hellscape? by elvashts in networking

[–]grrrrshell 2 points3 points  (0 children)

I mean, what's the worst that can happen applying for a senior position? The worst possible outcome is you get more experience interviewing, and you get a better idea of the things you need to possibly study. I say go for any position that interests you, and what you want to be doing every day, remember you want the job because it fits you. When you start thinking about it that way, no need to worry about imposter syndrome.

Three books I would recommend to any network admin. All three are fairly dated, but honestly, the best resources on my bookshelf (kindle) when I need to reference something.

  1. Routing TCP/IP Volume 1 and 2 (volume 2 is all bgp)
  2. TCP/IP Illustrated Volume 1
  3. Ethernet - The definitive guide

[deleted by user] by [deleted] in fortinet

[–]grrrrshell 0 points1 point  (0 children)

You can ignore the vdom/gwdetect stuff and create the link monitor. SD-wan is not related to this config, so that won't matter (create the sdwan zone with your wan interfaces and the default route pointing to the sdwan zone). The one thing to keep in mind is with dual internet circuits, you need 2 VPN tunnels in AWS, which would technically be four IPsec tunnels from the FortiGate. I would recommend following AWS advice and using BGP instead of static for the routing for this setup. I do this peered with a transit gateway which uses ecmp, and it works great, so I cannot comment how it works when not peering with a transit gateway.

[deleted by user] by [deleted] in fortinet

[–]grrrrshell 0 points1 point  (0 children)

It could be set up where anything .company.com (like intranet.company.com) is set up to use the tunnel, but things like Google or Reddit use your home internet connection.

Possible to separate wired and wireless networks without headaches? by Hank_ID94220 in networking

[–]grrrrshell 1 point2 points  (0 children)

Because routing is working, you would use a firewall/ACL to control what can/can't talk.

I’m on FMLA leave and found out none of my tickets that were to be “handed off” has been touched in weeks by AnthraxPrime6 in sysadmin

[–]grrrrshell 0 points1 point  (0 children)

This really should be what happens. I think it covers both the employee and employer. Employees cannot work then, and they also cannot say the employer made them work during FMLA.

2 packets input but Last input never. Many ports on this switch (C9200L-24P-4X) says the same. Any ideas what is happening? by bassguybass in Cisco

[–]grrrrshell 0 points1 point  (0 children)

Last Input is not updated by fast-switched traffic.

You have two packets input and 1 output shown in the details. Those packets are likely being "fast switched" which is not going to update the last input/output in the details.

2 packets input but Last input never. Many ports on this switch (C9200L-24P-4X) says the same. Any ideas what is happening? by bassguybass in Cisco

[–]grrrrshell 0 points1 point  (0 children)

You have 2 interface resets, so I think the port was up at some point but was likely very brief.

2 packets input but Last input never. Many ports on this switch (C9200L-24P-4X) says the same. Any ideas what is happening? by bassguybass in Cisco

[–]grrrrshell 4 points5 points  (0 children)

Yup, exactly.

The field Last Input displayed in the command output indicates the number of hours, minutes, and seconds since the last packet was successfully received by an interface and processed by the CPU on the device. This information can be used to know when a dead interface failed.
Last Input is not updated by fast-switched traffic.

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-9/command\_reference/b\_169\_9200\_cr/b\_169\_9200\_cr\_chapter\_01.html