r/networking • • 4d ago

Blogpost Friday Blog/Project Post Friday!

4 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking • • 1d ago

Moronic Monday Moronic Monday!

14 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking • • 10h ago

Security How are you guys handling IP cameras on the network?

65 Upvotes

I want to know how other people are setting this up as camera counts start getting higher. Do you put cameras on their own VLAN and keep the NVR/VMS isolated or just treat them like any other IoT network? The part I’m most interested in is remote access. I’d rather not expose cameras directly to the internet but people still need to view footage remotely sometimes. What does your setup look like?


r/networking • • 10h ago

Security Cisco ISE compatibility issues with MS Credential Guard?

6 Upvotes

I learned a few days ago that there were compatibility issues with Cisco’s ISE and Microsoft Credential Guard. Have you guys experienced this? We installed a patch 7 to our Cisco ISE deployment just two weeks ago due to the recently announced CVE, but I was wondering if anyone is experiencing the issue related to the title in your deployment.


r/networking • • 8h ago

Troubleshooting Pre-Punched Patch Panel

3 Upvotes

I've been searching for a pre-punched patch panel with 10 to 18 ft leads. I need to install it in our floor rack, where it will connect to a patch panel mounted on the ceiling. We can't move the ceiling panel into the rack, so I need to patch from the ceiling down to the rack.

Hopefully this is the right place to ask, but has anyone ever come across one of there to purchase? Would love a link or even alternatives that I may not be thinking of.


r/networking • • 17h ago

Other AP throughput is being choked by something

8 Upvotes

I am a junior net admin in a K-12 that uses Extreme Networks in the environment. I have a class with between 15 and 25 students who connect to the nearest AP (model 4020 with WiFi7). Even with the lowest number of students in the classroom, speedtests are as horrendous as 3Mbps (it's supposed to be 1G).

The network drop comes from a Netgear switch a little over 50 feet away, and here's a potential choke, the port is PoE and the cable is Cat5e (predates me).

Running cables is not in my JD and we will need to hire a vendor, but I need to be sure that is my chokehold before calling the company.

What other ways can I troubleshoot to find the issue and address it?


r/networking • • 10h ago

Career Advice Anyone worked in Network Commission/Decommission role

1 Upvotes

I’ve recently come across a job involving network equipment commissioning/decommissioning and wanted to understand what the actual day-to-day work is like.

What kind of tasks are usually involved? Is it mostly coordination/documentation, or does it involve hands-on networking and troubleshooting as well?

Also, how is the career growth from this role if someone wants to move toward networking/NOC roles?

Would appreciate insights from anyone who has worked in a similar role.


r/networking • • 17h ago

Routing OSPFv2 / Segment Routing TI-LFA with FRR: Behavior of the linux dataplane with respect to backup nexthop upon link-failure

3 Upvotes

I'm testing Segment routing (SR-MPLS) and TI-LFA using a virtual testbed implemented with Containerlab and FRRouting (FRR). My main goals are to evaluate how fast the data plane can be restored upon a topological change and therefore what is the best way to manage topology changes in production networks.

In my experimental-lab, OSPFv2 has correctly computed the TI-LFA backup path in the control plane:

  • In FRR (vtysh), show ip route properly shows the primary path alongside the corresponding backup nexthop and backup label (denoted by b ...).
  • To clearly decouple and demonstrate the local Fast Reroute behavior from the global OSPF SPF recomputation, I intentionally configured high SPF throttle timers: timers throttle spf 5000 10000 10000

After triggering an administrative link-down or an actual link loss detected by BFD, traffic is not routed to the precomputed backup path within sub-50ms. Traffic drops about 5.1 to 5.2 seconds before finally resuming again once the 5-second SPF throttle timer has expired and OSPF updates its knowledge of the network through the receipt of LSAs and subsequently Zebra updates the routes in the Linux FIB.

My technical understanding:

  • Control Plane: FRR/OSPF calculates the TI-LFA path successfully and passes it internally as backup nexthop information to Zebra.
  • Data Plane: By default, the native Linux kernel (FIB) does not provide a hardware-equivalent, autonomous local Fast Reroute / nexthop failover mechanism for MPLS/IPv4 routes upon interface-down events (similar to the points raised in GitHub issue: “FRR TI-LFA: When the primary path fails, the backup path does not work #15589”).
  • Implication: Zebra does not immediately promote the backup path to active in the kernel as an instantaneous, local reaction to the link-down event. Instead, the FIB update only happens as part of the regular post-SPF cycle.

Does somebody know if there are:

  1. existing workarounds or options for dataplane failover under Linux / FRR?
  2. Are there configurations or extensions that allow Zebra to program backup nexthops into the dataplane so that failover occurs locally without waiting for an SPF run?
  3. Anybody knows the current status or outlook regarding this: Is an autonomous, SPF-independent activation of backup nexthops (either directly in Zebra/Linux FIB or via external dataplane integrations like VPP) planned or actively being developed in FRR?
  4. Is it correct to assume that commercial virtualized router images (such as Cisco XRv9k, Nokia SR OS / vSIM, etc.) differ fundamentally here because their software forwarding engines (or emulated hardware pipelines) handle pre-programmed backup paths directly at the dataplane level upon carrier-loss or BFD triggers?

Thanks a lot for your help.


r/networking • • 1d ago

Other Still referencing white papers?

35 Upvotes

So here I am, about 7 years in, Senior Engineer that still (very often) references white papers for a lot of configuration context. It’s not that I don’t know the tech and the logic, it’s more of a devils advocate tactic I do to myself for reassurance, even this far into my career. Do any of you mid-sr level do this as well, like a lot haha ?

For context, I’m not saying it’s looked down upon for referencing, it’s practically how I/You learn and very much the go-to way I tell junior engineers to take before escalation. There’s just times I feel heavy with Imposter Syndrome (aware this doesn’t go away haha). Surely I’m not alone 😆


r/networking • • 14h ago

Switching Network Inventory Project

1 Upvotes

Good day. I'm a new infrastructure specialist for a school district. I support three schools and we're looking to upgrade our switches. I have been tasked with creating a spreadsheet for all closets in all buildings. I want to include VLANs as well. Essentially I want to have every port documented, but I'm really starting from scratch.

I'm primarily using Aruba 2930M-48G-PoE+ switches.

Any advice, tools, spreadsheet, examples would be great. This is the first time I'm doing something like this, and I want to do it right! Thank you for reading!


r/networking • • 23h ago

Design Will BGP replace PCEP?

4 Upvotes

Will BGP with some special AFI replace PCEP since vendors trying to reduce number of control plane protocol. If not, why is it not feasible?


r/networking • • 1d ago

Other Actual training..

17 Upvotes

I've been in this field about 8 years now and am at the point where I need to get my certs up. I have a Juniper account through my work and a cisco learning account. This is a two part question.

  1. I see no options to access amy form of a lab on juniper HPE, everything that includes a lab is $2k-$4k for a 3 day online course, which Im sure will be led by someone with a heavy accent.. Always helpful when trying to learn. So are there any options of virtual juniper labs out there? Something similar to packet tracer where I can actually practice and not just listen to some guy.

  2. For those who are self-taught, whats your method? I'm primarily a hands-on learner and pick things up quick so long as I can practice. Packet tracer is fine for cisco, but I really need juniper routing practice. Any advice?


r/networking • • 2d ago

Career Advice Fortinet MSSP engineer looking at AI data center networking. Realistic move or ?

14 Upvotes

Background: I have a degree in CS / network security, so I'm comfortable with both programming and networking. I started in presales, then moved into a technical role at an MSSP that works mostly with Fortinet. Day to day I deploy SD-WAN and troubleshoot client infrastructure across the product line (FortiGate, FortiWeb, FortiMail, etc.).

I'd like to move toward something AI-related and eventually work for a vendor or a bigger company. The path I'm considering is AI data center networking: RDMA, RoCEv2, InfiniBand, NVIDIA's networking stack, and so on.

My concern is that I almost never do DC work. No EVPN/VXLAN, no spine-leaf deployments. Can I realistically get into AI DC networking from where I am, or do I need a traditional DC role first?

I also thought about cloud networking since I can code, but I've never worked at a cloud shop or done DevOps work, so I dropped the idea.

If anyone here made a similar jump from MSSP/security work, how did you do it?

Thanks !


r/networking • • 2d ago

Career Advice PhD in deterministic/low-latency networking: fitting industry roles, and how to position myself?

36 Upvotes

Hi all,
I'm finishing a PhD in deterministic/low-latency networking next year. My research is on communication networks with provably bounded latency (using e.g., network calculus, TSN/DetNet scheduling). My research combines theoretical aspects and practical, hands-on implementation work. I also have 5y+ previous experience as a software engineer (including at Nokia as well as in non-Telco companies).

I'd like to stay in the low-latency networking industry after my graduation, and I am currently exploring my options. I'm trying to figure out:

  • Which companies/sectors actually hire for this (HFT, telecom, industrial/automotive, cloud…)?
  • What roles and pay ranges are realistic in your region? (Currently, I am Belgium-based, but I am open to relocating.)
  • How to translate academic work (papers, proofs, algorithms) into something hiring managers value?

Any help or insight is certainly appreciated. Thank you!


r/networking • • 3d ago

Design VXLAN campus design

28 Upvotes

Hi all,
Designing a campus fabric and want a sanity check on the topology:

Per-IDF leaf pair: 2x 100G VXLAN EVPN leafs in a vPC pair on each floor

Roles: Both are VTEPs and anycast gateways (L3 boundary at the IDF)

Uplinks: Each IDF leaf pair connects to the main campus spines

Access layer: Plain L2 switches, LACP to both IDF leafs (not VTEPs, pure L2 trunks/access). Said differently, hung off those two IDF leafs above we’d hang a bunch of L2 access switches to provide more access ports for devices across the floor.

Why I like it (my assumptions):
Fewer fiber runs compared to home running every switch to campus spines and less VTEP sprawl

Simpler ops: junior engineers just change a port's VLAN

Questions:
How common is this design in campus deployments?

Any gotchas with vPC + VXLAN EVPN (peer-link sizing, orphan ports, convergence)?

Would you do this, or put VTEPs on every access switch?

Thanks!


r/networking • • 2d ago

Design Recommendations for Core and Edge Routing Design

8 Upvotes

Hello everyone,

I’d like to optimize the network design and separate core and edge routing.

So far, I’ve been using three routers that handle both inter-VLAN routing and edge routing and are part of a VRRP cluster.

Now I’d like to deploy a core router running VyOS that acts as the default gateway for all networks and initially handles inter-VLAN routing. The three edge routers will be connected to this core router, with each one connected to a different Internet line or provider.

The core router should use policy-based routing to determine which networks, clients, or services are routed to the Internet via which edge router or WAN connection. Additionally, failover should still be available in the event of an Internet connection failure (as has been the case with VRRP).

My question is: what is the best way to set up this configuration? On the one hand, I could set up a transport network containing the three edge routers and use VRRP again. In that case, I would likely need a transit switch between the core router and the edge routers so that the VRRP cluster’s traffic does not have to pass through the core router’s CPU.

On the other hand, it would certainly also be possible to connect the edge routers directly to the core router’s interfaces and operate without VRRP. Which protocol could I then use to implement both policy-based routing and failover?

Which network design would you recommend for my situation? I’d appreciate any tips and assistance.

Thank you in advance for your tips, and best regards

Regina (she/her)


r/networking • • 3d ago

Other How many of you study at your work/while working?

72 Upvotes

Hey there, just curious how many of you study for certs or other stuff while working?

When I have downtime, I try to utilize my time to study for a cert I've been prepping for.

Just got curious how many of you study during your work hours? If not, what are you doing when you having nothing to do?

P.S. I'm not saying my work is like this every single day... if something happens, obviously I'd have to jump on a call to troubleshoot and analyze stuff...


r/networking • • 3d ago

Other FS no longer vendor programming SFPs?

92 Upvotes

We've recently received several orders of FS.com optics that had the default "FS" vendor coding in them, resulting in Transceiver Unsupported errors on our switches. Assuming this occurred in error, we reached out to our account manager, who to our surprise confirmed that they are no longer coding/configuring transceivers, and customers will need to do this themselves. Has anyone else encountered this? Here's the email from our Rep:

There has indeed been a recent change in our coding process. Starting June 6, FS began gradually transitioning certain compatible optical modules to a new custom coding mechanism, including our Arista-compatible modules. The main difference from the previous coding is the Vendor Name information. The modules are now shipped with the default FS vendor coding, rather than being pre-coded specifically as Arista. To ensure the modules can be properly recognized and used in your Arista environment, there are two possible approaches:

Option 1 – Configure third-party transceiver compatibility on the switch

If you have a larger quantity of optics, we recommend this approach as it avoids having to reconfigure the modules one by one. You can enable third-party transceiver support through the switch CLI.

Option 2 – Reconfigure the optics through FS BOX

If changing the switch configuration is not preferred, you can use the Online Configuration feature on your FS BOX to change the Vendor Name from “FS” to “Arista” on the optics individually.

We understand that the second option can be inconvenient when dealing with a large number of modules, so Option 1 may be more practical for your environment.

Please let me know which approach works better for your setup. If needed, we can also help you with the configuration steps.


r/networking • • 3d ago

Design Endpoint only supporting /24 network configuration. How to deal with it?

59 Upvotes

So I've been a network engineer for around 20 years now, and the past 10 years I've been the allround network engineer for a large municipality. Recently we opened a new building and I built the network. A firewall, a switch, some AP's, and a bunch of VLANs of different sizes depending on their use. Nothing out of the ordinary.

Now I've also had to deal with a ton of parties requiring connectivity for building automation, climate control, sensors, cameras, alarm installation and so on. Today the project manager reaches out to me that one of the parties has trouble getting their building automation system to work properly on the network. They say the system only works with a /24 subnet, and I gave them an IP in a /28, and they demand I enlarge the subnet to /24 (which I can't because overlap etc).

The funny thing is, they have this /28 IP config in the system, and I can ping it even outside it's subnet, so IPv4 connectivity works just fine and traffic gets routed properly.

How do you guys deal with this kind of BS? Should I honor the project managers wishes and redesign the network to give them a /24? Hasn't support for a variable subnetmask other than /24 been like common for the past 30 years? I feel like I'm being played here by some incompetent installation company that doesn't know how to configure their equipment and just blames in on the network, but I can't prove it.


r/networking • • 3d ago

Design Untrusted and Trusted zone design

5 Upvotes

Interested in thoughts on this scenario.

A client has multiple branch sites where trusted, client-managed networks are routed over the private WAN, with access restricted to required private applications and services.

Each branch also has untrusted VLANs for guest devices and third-party managed devices requiring Internet access only. These VLANs terminate on the branch firewall, which provides local Internet breakout and enforces the security boundary. They have no route to the private WAN or corporate resources and use repeatable IP scopes across sites.

Security have requested making these networks reachable over the WAN for central vulnerability scanning. This would also require re-addressing the untrusted networks so each site can be uniquely routed.

How would you approach this?

Should isolated third-party devices be centrally scanned at all, or should assurance sit with the device owner/provider? And is vulnerability scanning appropriate or useful for guest networks containing unmanaged devices?

If scanning is required, how would you achieve it without fundamentally changing the existing isolation model?


r/networking • • 3d ago

Wireless Replacing AP’s and catalyst center

5 Upvotes

I have a large number of APs that we’re replacing, and I realized today that as the installers unplug the old APs and bring the new ones online, the old APs may disappear from the Catalyst Center maps.

Is there a way to preserve the existing AP placement on the floor maps before they are removed?

My concern is that if the installers replace 50 APs at once, I could suddenly have 50 AP locations missing from the maps with no easy way to determine exactly where the replacement APs should be placed.


r/networking • • 4d ago

Design Network Design Practice Ideas/Resources

22 Upvotes

Hi everyone,
I am a network engineer working in vendor TAC. As you probably know, TAC does not support with design/config and the cases are mostly related to platform/product issues. Being here for few years, I realized I started getting a bit rusty on the design side.
The problem is I understand the theory very well but have no idea how to apply this in real life due to lack of design practice. The only solution I see is doing more labs apart from my work and I have everything needed for that - both physical and virtual devices.
But I don’t know where to start or what to design. Did anyone have similar issue?
Please share some resources with design ideas, advices how I can practice network design.
Thank you in advance!


r/networking • • 4d ago

Career Advice Interviewing for security and senior network roles, a few things that keep happening

82 Upvotes

I do technical rounds for security and senior network roles, so this is mostly from that side. nothing groundbreaking, just patterns.

the number of people with 8+ years and a "senior" title who can't walk me through what happens to a packet crossing a firewall and a NAT is higher than I expected. not trying to trap anyone. I'll ask something like "rule looks right but traffic isn't matching, what do you check?" and the good ones go straight to the hit counters, the policy order, the NAT rules applying before the policy. the weaker ones say "I'd restart the firewall." that's usually where the interview ends for me.

on the security side I care way more about order of operations than tool names. give them a compromised host and I want to hear scope, contain, preserve evidence, then fix. the "just wipe it" answer is a quick no from me. you just destroyed your evidence and you still don't know how they got in.

"we used a SIEM" tells me nothing. "I tuned noisy 4625 alerts and got the volume down a lot" tells me you actually sat in the console. same for network folks, I'd rather hear about the one thing you designed and what broke than a list of vendors.

if you haven't done SD-WAN or zero trust in prod, just say so and tell me how you'd approach it. I will always take that over a bluff. in this field people act on what you tell them.

and ask questions at the end. on-call load, change process, how they do post-incident reviews. most people ask about perks, so the ones who ask that stand out.

curious how other interviewers weigh depth vs breadth for senior hires. I lean depth but I know that's debatable.


r/networking • • 4d ago

Career Advice Career and certification advice

14 Upvotes

Hello all,

I hope this is okay to post, please delete/ ignore if not!

I recently started working as a systems & network engineer. My previous experience was just support desk. I've been learning a lot in this role, I find network engineering super interesting! But I am very new to it.

They want me to get certified so that I can stop relying so much on my seniors. The kind of things we are doing is BGP, OSPF, Multicast, Firewall (Palo Alto and Cisco), IP sec. I'm expected to know how to do stuff - for example how to set up functional zfs servers and communicate with the network suppliers and come up with my own solutions to issues we have within our own network ... I am really clueless currently and you can probably tell from how I'm writing about it. I hate how much time I spend with AI and not knowing it from my own head

It's a trading firm so the networking is specific to that. I have seen advice for the Cisco CCST/NA/NP/IE exams, is following those courses in order a good idea? Or is there some very functional course that would be better for my situation ? I just really need to know what is going on around me and how to fix stuff on my own ASAP lol. Costs don't matter since the company offered to pay for it (I'm in a very lucky position!). Based in the EU if that matters at all

Really appreciate any advice and thank you 🩷


r/networking • • 4d ago

Wireless 5G private network hardware. What can be done with this stuff that's useful and fun?

12 Upvotes

Lucked into some surplus 5g stuff in a recycling lot. Looks like new. Some still sealed on boxes. It appears to be a complete 5G private network, minus cabling and a rack to put it in. Five n78 band radios, iru, ran, server, stack of blank sim cards. Did not know what it was at first. Picked it up because I recognized the radios as radios and thought I might be able to repurpose to 3GHz amateur radio use. That's a dead end as they are too highly integrated.

Oh! I'm an old guy who works as a nurse now. I used to trade surplus computer and networking hardware. But that was almost 30 years ago :-).

-Bob