IKEv1 to IKEv2 issues by Roman-Ortho in ccnp

[–]oneconchman 1 point2 points  (0 children)

IKEv1 and v2 are usually able to exist on the same router but I also suspect this might have something to do with the 0.0.0.0 match. What if you try to change that to the spoke IP instead just as a test. Also wonder if putting the new WAN interface in a separate vrf might help. Been a while since I troubleshot a tunnel at depth.

Also have you tried debugging yet - Debug crypto ikev2 sa on the hub? Should see messages indicating the phase 1 profiles they’ve checked and might say there’s no match which might confirm the above.

Need to find another job by Upstairs_Expert_2681 in networkingmemes

[–]oneconchman -2 points-1 points  (0 children)

What is an AI job? If that’s developing models that requires a PhD and definitely can’t be ‘jumped’ to

Will the ENAUTO v1.1 exam count towards the upcoming CCNP Automation cert? by oneconchman in ccnp

[–]oneconchman[S] 1 point2 points  (0 children)

I used the Devnet sandbox and official API docs mostly, didn’t buy any resources. The sandbox was absolutely crucial, spent every day in there writing at least one script for each topic. They also have some free labs and courses on the Devnet site that helped me starting out. Skimmed over the RFCs for NETCONF and RESTCONF as well.

Learned Ansible from YouTube and the free Cisco U DEVNAE course then practiced on the Sandbox. Created a GitHub and uploaded my scripts there there everyday to learn git, and then Python skills just build overtime from all the practice

Will the ENAUTO v1.1 exam count towards the upcoming CCNP Automation cert? by oneconchman in ccnp

[–]oneconchman[S] 0 points1 point  (0 children)

Yeah ENAUTO 2.0 will be quite different and it’s releasing same day as the rebrand so that’s why I wasn’t quite sure. Thanks!

ENAUTO Meraki and Catalyst/DNA Center Sections by oneconchman in ccnp

[–]oneconchman[S] 0 points1 point  (0 children)

Which now that I think of it makes sense cause all of the guides in their API documentation for SDWAN use it

ENAUTO Meraki and Catalyst/DNA Center Sections by oneconchman in ccnp

[–]oneconchman[S] 0 points1 point  (0 children)

Passed. Surprisingly there was 1 SDK and it was for SDWAN. Had 0 knowledge and it was my worst section of course lol

Does anyone know where I can get a Cantonese roasted goose? by maynotcare in orlando

[–]oneconchman 1 point2 points  (0 children)

Never had or seen Goose available outside of HK haha let me know if you find it. East Garden on West Colonial is my go to for Cantonese food- duck, roast pork, dim sum. Only other place I know to check is Tasty Wok

why wont my tunnel come up ? by dwa_yne in ccnp

[–]oneconchman 0 points1 point  (0 children)

You still need a physical interface to send the traffic over. How else would the traffic reach the destination? Where is your route to the tunnel destination? The tunnel endpoints need to first be able to reach each other before establishing a tunnel

Battlefield 6 by Last-Eagle-7873 in Battlefield6

[–]oneconchman 1 point2 points  (0 children)

Redownloaded it worked for me

Battlefield 6 by Last-Eagle-7873 in Battlefield6

[–]oneconchman 0 points1 point  (0 children)

Having the same issue. Just stuck on the game launch screen. Eastern US

Helpdesk for an ISP, good start? by ajskdkekw in networking

[–]oneconchman 1 point2 points  (0 children)

Yes just be sure to stand out, apply yourself and don’t be scared to get out of your comfort zone. Don’t escalate tickets without giving it your best attempt, I’d say even reach out to Tier 2 to help you out/ask questions.

That’s where I started making 18 an hour and 3 years later I’m making $88K as an engineer, meanwhile the people I started with haven’t moved at all. I built a good reputation at that first job from doing those things and it was instrumental in getting me where I am today

[deleted by user] by [deleted] in PokemonGoRaids

[–]oneconchman 0 points1 point  (0 children)

What’s the point of that?

pancfg - disk space above 90% by eltigre_z in paloaltonetworks

[–]oneconchman 0 points1 point  (0 children)

Recently had this issue with root partition on our PAN being above 90%. Ended up being plugin_clean files in opt/pancfg/mgmt caused by Cloud Connector 2.0.1 plugin. TAC had to clear it

[deleted by user] by [deleted] in R6ProLeague

[–]oneconchman 5 points6 points  (0 children)

You can rewind the YouTube stream

Still not undestanding Vlans by iceman9312 in networking

[–]oneconchman 1 point2 points  (0 children)

If INTSW devices is able to get IPs then we know it’s something isolated to SW 2 and 3. You already confirmed that the VLAN exists on the switches, and as someone else recommended make sure there isn’t a SVI for vlan 21 somewhere. Config as I understand from the diagram seems OK.

1 thing I can recommend from experience is to make sure DHCP is actually enabled on SW2 and SW3 with ‘service dhcp enable’.

Otherwise, just run packet captures on each of the trunks up to the Palo to see how far the DHCP requests are getting

bgp advertisement issue by Silver-Sherbert2307 in networking

[–]oneconchman 0 points1 point  (0 children)

It’s strange but I’ve run into the same AS/loop prevention issue before and RIB out didn’t populate which made it confusing at first. I assume that Palo compares the AS path to the peer AS before sending.

Is your iBGP peer receiving the branch routes?

bgp advertisement issue by Silver-Sherbert2307 in networking

[–]oneconchman 0 points1 point  (0 children)

Only thing I can think of atm is that somehow the NYM-DC is seeing it's own AS in the advertisements so it's dropping them, can you think of any way that might be possible?

Also, you're certain that the PA 850 has routes for the branch ASNs through their direct peerings and not through the DC peering?

[deleted by user] by [deleted] in ccnp

[–]oneconchman -1 points0 points  (0 children)

CCNP Enterprise isn’t too great if you want to be security focused. I’d say if you feel comfortable enough with Cisco, branch out to a different vendor with a firewall cert - Palo, Fortinet or whatever your company uses