r/networking • • 4d ago

Switching What is the purpose of assigning an Access port to be a Trunk port?

47 Upvotes

Networking noob here going through the Network+ CertMaster Learn courseware for the class I'm taking at my community college.

I've got the basic understanding of Access ports, Trunk/uplink ports, and their respective frames down. Access ports are for hosts belonging to one VLAN with frames that have their VLAN tags removed before forwarding, and Trunk ports are for carrying frames that keep the VLAN tags across multiple VLANs. Still a bit fuzzy on the details but that understanding will come with time, I'm sure.

My one big question is why would you want to assign an Access port as a Trunk port? The Network+ CertMaster page on tagged and untagged ports says an untagged Access port for a host might occasionally be set to a tagged Trunking port if that host is used for virtualization with multiple operating systems on different VLANs, allowing that host to send frames to multiple VLANs. But if a regular Trunking uplink port can already be used to send frames from Access ports to other VLANs, then why assign that virtualization host to be a tagged Trunking port as well? Would it not be simpler to send that virtualization host's frames over the same Trunking port that all the other Access ports on the switch are sending theirs over?

I'm assuming the answer is much more complex than this. It could also be that my understanding of VLANs and Trunking is really missing something, or it's something about virtualization hosts that I don't have a grasp on.


r/networking • • 4d ago

Design Tools/software to emulate slow/broken connections?

6 Upvotes

I am a network engineer responsible for supporting point-of-sale deployments. I'd love to be able to set up an environment where I can dial bandwidth (not 1Gb/100Mb/10Mb, but much more granular), play with jitter, latency, and see where the limits are with systems that we deploy and to better understand what causes issues with them after deployment. Once I would pilot this tool or solution, we can built it into our QA lab environment. Only needs to really support speeds up to about 250Mb or so (think small store, not shopping mall or office park).

Basically, I'd like to emulate everything from a solid fiber internet connection all the way down to a cellular modem on a crappy signal to test real-life thresholds and limits. What do you guy use for this?


r/networking • • 4d ago

Design Need Help fixing Double Gateway Choas

7 Upvotes

I'm trying to help my uncle's firm fix a network issue. Their MSP has up an disappeared. I'm probably just an idiot but I can't figure out how to make this network work like they describe.

Originally the setup was a pfsense negate appliance acting both the gateway and a tunnel back to a vendor backend-servers that support some core services for the office. There was a dumb switch cause only had 2 or so workstations.

About a year ago, the firm quadrupled in size. They hired an MSP who installed UniFi network equipment. The intended design was for the UniFi gateway to handle general traffic—providing security controls and monitoring—while routing only the vendor server traffic to the pfSense box.

​However, the MSP never configured the routing rules, so the pfSense appliance is still acting as the sole gateway. This is problematic because there have been multiple recent security incidents, but we lack the logs or insights to evaluate them.

What I tried was to create a new subnet and vlan (100) and created a static route for traffic to the backend-servers. But that just bounces off the pfsense box, because I assume it only wants traffic from within its own subnet.

So workstations are in x.x.200.0/24 with the Unifi as the gateway, but I can't reach the backend-server

Pfsense gateway is at x.x.1.254 and it's pointing to backend-server resources at x.x.111.111/32.

I still learning network so pardon me if this is supposed to be obvious.

tl;dr: Currently, the workstations are on x.x.200.0/24 using the UniFi as their gateway, but they cannot reach the backend server. The pfSense gateway is at x.x.1.254, pointing to the backend server at x.x.111.111/32. How was this split-routing setup actually supposed to work?


r/networking • • 4d ago

Design Please verify my understanding regarding SASE framework.

12 Upvotes

Please correct me or enlighten me on my understanding of SASE framework:

SA - Secure Access --> basically allowing users to access the resources, cloud or on prem, in the most secured way
SE - Secure Edge - Making sure all traffic between any sites edge router/firewall is reaching its destination, whether another site or internet, in a secured manner.

sub components: ZTNA, CASB, SWG, FWaaS, SD - Wan

ZTNA - Continuously verifying user & device identity. Unlike old methods like enforcing NAC via AAA server like ISE, here client/device was authenticated only once initially.

Palo-alto global protect, Zscalar client, forti-client, cisco anyconnect/secure access can be used to implement it. Basically, all laptop traffic will be tunneled to DC OR all laptop traffic will be analyze be a firewall. FW can be cloud or on prem.

CASB - Cloud access secure broker - as name suggests, allowing users to access cloud applications, like share-point in a typical office environment, in a secured manner.

No idea how to implement it but i guess same products as above would help. OR may be some firewall in between.

SWG - Again, as name suggests, allowing users to access internet in a secured manner.

same products as above can be used to implement it. Or in work from office environment, tunnelling all traffic from branch to HQ/DC and breaking to internet from DC/HQ where we have high end firewalls with strict policies and maybe ssl inspection enabled.

FWaaS - a subscription based firewall services offered by some other company. This firewall services maybe on prem BUT its mostly cloud based.

SD - WAN - dynamic traffic steering, in a secured way, based on policies/rules set by the admin.

Numerous sd-wan vendors, like catalyst sd wan, versa sd wan, silver peak, fortigate etc. Some companies have firewall integrated with SD-WAN so we have more security features in a same box OR managed by central manager.

Question:
1. is this correct?
SA components are - ZTNA, CASB and SE components are - SWG, FWaas, SD-WAN

  1. If i need to implement SASE framework in a enterprise, lets say a retail store network like Walmart or fast food chain like McDonalds, where sites can be categorized as: Stores, warehouses, Corporate office, DC, HQ etc.

    So what would be my approach to implement SASE framework?

And what solutions are offered by different vendors? and how to integrate different vendors to achieve the goal? Because many companies would use cisco entirely in their lan, other vendor in wlan, then another for firewall, vpn, and sd-wan..so on.

TLDR: Please guide me on SASE framework, its implementation, solutions offered by different vendors and how to integrate them.


r/networking • • 5d ago

Design OM4 vs OS2

24 Upvotes

Hi all,

This is my first post here and please know I’m not SME:)

We are in the middle of a large greenfield project for a new office and a factory. We have outsourced most of networking globally to big IT house. They have sent me a lld now with all the deats of patching, switches etc.

They have all short pulls made with om4 and sr sfps. I personally think this is not so future proof and also unnecessary (cost of lr is no issue) we have absolute majority done with os2+lr. Do you think this design solution is worth arguing over? I’d really like all done with the same cable and sfps everywhere. Is there any benefit in using om4 + sr here?


r/networking • • 5d ago

Routing Is there anything a Router can do that Linux can't? (other than merely doing it faster)

71 Upvotes

Setting aside performance and hardware efficiencies that physical router platforms might provide.... is there anything a real, enterprise grade, Router can do that can't also be done on a linux machine?


r/networking • • 5d ago

Design IPv6 Point to Point Link Addressing

26 Upvotes

Hi all,

Wanted to asking my fellow network engineers what IPv6 subnet size you would use on a point to point connection between 2 routers and why.

/127 or /64

Technically both of these would work but I’m just curious. Any useful technical or security reason would be greatly appreciated!


r/networking • • 5d ago

Design I need to standardize our network devices hostnames. Should I do it all now, or when we upgrade them in time?

2 Upvotes

Pretty much the title. The hostnames aren't bad, just some have words like 'core' or '9200'. We don't have monitoring or backups so it probably wouldn't affect anything if I changed them, right?


r/networking • • 5d ago

Troubleshooting Network Switch Issue

9 Upvotes

Here is my setup. I have a Palo Alto that connects to my switch stack that is Aruba 6300M. From there I have a fiber line to an IDF that has a Aruba 2530. We purchased another building across the street. The old tenants left all their Meraki equipment. I have all the Meraki equipment claimed and licensed in our Meraki portal. (I had a temp firewall and cradle point so the Meraki equipment could get internet access)

Instead of getting an internet line for the building we did a wireless P2P. I got two Ubiquity Wave Nanos and installed them. I then created a separate VLAN for this building and the default gateway lives on the Palo.

But the issue is when I plug the Meraki into the Wave Nano the Aruba switches in my IDF go offline, and everything connected to the IDF goes offline. Once I unplug the Meraki everything comes back online in the IDF. If I plug my laptop into the Nano everything works just fine. I can reach our HQ LAN, and I get internet.

I checked the switch logs on both sides and there is nothing in the log that would indicate any issues.

I also tried disconnecting everything from the Meraki switch and just tried one Meraki switch on the Nano and that still took my IDF offline.

But I created a temp VLAN and assigned it only to the port the Nano is plugged in. I then plugged in the Meraki into the other Nano and everything was fine.

I can't figure out what is going on. Any Thoughts????


r/networking • • 5d ago

Monitoring How do you monitor policy based vpn tunnels?

9 Upvotes

I have Cisco ASA with multiple policy based tunnels which go down naturally if there is no interesting traffic for them. This makes monitoring a bit harder.

So I was thinking either to generate ping for the tunnels to keep them up or use "vpn-idle-timeout none".

Anyhow lets say they are constantly up.

How do you monitor them afterwards? And how do you differentiate the tunnels by alarm, to know which one is down (assume remote IP in snmp trap somewhere?) ?


r/networking • • 5d ago

Design Cisco SDWan private underlay question

8 Upvotes

I'm building out a new SDwan deployment at the company I am now working for, and have a question about private underlay routing.

Last time I built out SDwan was a few years ago, and I double terminated the Spectrum Elan to both the SDwan Cedge and also to the backbone Cores by using an Aggregate switch. OSPF and VRRP on both Data Center Cores for .1, and .2 and .3 for both DC Cores. That way the Edges can get to the internet by using .1 as a default route, since the private underlay is a routed network that has internet access.

I am now working on setting it all up again, and instead of double landing my Spectrum Elan on both the Cedge and the Core using a Agg switch, I was wondering if it would be better to do a prefix-list and allow the WAN subnet to be redistributed my VPN0 VRF into my VPN VRF and then into OSPF on the Cedge? I can still setup my Data Center Cedges with .2 and .3 in each DC for WAN, and use .1 VRRP between them. But then I need to allow the routing to go through the Cedge and not have to use a separate interface on the Core to allow the WAN access to the internet.

If you think #2 is a workable solution, is there a document out there that lays out what needs to be done using the UX2.0 interface? I can't seem to find anything worth while.


r/networking • • 6d ago

Security Spamhaus DROP FP %

4 Upvotes

Hi, we are thinking about including spamhaus drop list on our FW, but I would like to know what is the false positive occurence from your experience? I cant find much info about it online. Thank you


r/networking • • 6d ago

Rant Wednesday!

14 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking • • 6d ago

Design Looking for a network resource management program

13 Upvotes

 I am the primary network infrastructure consultant for a company that has outsourced almost everything to an MSP. the MSP has asked me to provide them a detailed network map that includes everything from Patch panels to switches to routers in one package so that they can "do there jobs" in diagnosing network issues. They eventually want to install solar winds or PRTG, but i know that this is a long and involved process and wont happen quicky. Good news for me is that the MSP (located out of Orlando, but really out of Mumbai) has retained my services for all the remote hands services, so i am safe for now. With that said they want me to map all the switches, routers, and devices per patch panel and destination port into device port. we have about 5000 ethernet patch panel ports, and about 1400 Patched devices. We have over the three campuses approx. 3000 switch ports of 50ish devices available of which maybe 1500 are in use.

So, given the basic criteria what i am looking for is software capable of taking this picture

Jigamabob 43 >>>>> patch B2B-A16/4 >>patch B1B-R1/4 >> Cisco 4300-gi2/22

Yes i am aware i can do this on a device by device basis in excel or i can do it all in PRTG or Solar Winds (i think) but if anyone knows a database program that can handle this kind of a task please let me know. In the end if it spits our a network connections map that's even better still. Free is always good, but a reasonable cost i am sure they will agree to. And yes this is going to take 2 of my techs weeks to go through. just trying to make it easier without writing my own database

Any ideas are welcomed


r/networking • • 5d ago

Switching Are current UniFi PoE switches truly "connect and forget" for critical departments?

0 Upvotes

I'm the sole IT person for a manufacturing company moving into a new 100K SWFT building. Critical departments include the factory floor and a call center, so a switch needing a mid-day reboot is a real cost.

My experience so far:

- Netgear GS752TPP: main PoE switch (phones, APs, cameras) for 8 years without a single reboot

- Netgear GS316 PoE family: across warehouses and factory, never failed

- EdgeSwitch 48-500W (2018): locked up about once a month and stopped accepting new connections, forcing mid-day reboots with the call center on it. RMA once, no change.

I'm considering going all UniFi for central management and config backup (we already use UniFi APs), but that EdgeSwitch experience makes me hesitant.

For those running current-gen UniFi PoE switches in production:

  1. Do they run for years without freezes or reboots?

  2. Any issues with heavy PoE loads (about 50 cameras, VoIP phones, APs)?

  3. Have firmware updates pushed from the controller ever caused problems?

  4. Would you trust them for a call center and factory, or stick with what's proven?

Thanks for any real-world input.


r/networking • • 6d ago

Monitoring Bandwidth billing software

21 Upvotes

I work for a niche business only SP that allows customers to burst above their commit rate unless they request their services are capped. We currently use Observium's billing module with some custom enhancements to add multiple bursting rates as well as change the base rate depending on the customers contract.

This works but it's meant that upgrading Observium breaks this, and the person that wrote the enhancements is long gone, as is any capability to support this from a dev point of view.

My view for a while has been Observium shouldn't be doing this given it has to be hacked to work and my boss and I are in agreement that new software is required. Googling and a search of similar topics here have suggested Splynx, Kentik and FluxBilling, but I'm looking to see if anyone here has any other suggestions or feedback on those 3 solutions.

In terms of capabilities I'm only really looking at billing. Observability/monitoring will continue to be handled by Observium (but I'll also look at LibreNMS given the billing stuff would be stand-alone), Netbox handles the stuff it's good at and detailed traffic analytics (flow based stuff) is handled by its own platform.


r/networking • • 6d ago

Wireless Deploying dpsk through intune

4 Upvotes

Hello everyone, I was wondering if anyone here has had success deploying dpsk at scale for devices in InTune. I am researching it and all I can find and wifi profiles through InTune something I already have set up. I'm debating if I should just do all this manually. If anyone has done this in the past let me know! I would appreciate any feedback.


r/networking • • 6d ago

Other How to limit DNSSEC query sizes?

6 Upvotes

I’ll be implementing DNSSEC soon and am doing some preliminary planning. We are using EDNS0 and will allow TCP as well, but I have a few questions.

https://sec.cloudapps.cisco.com/security/center/resources/dnssec_best_practices.html#7

  1. Cisco recommends setting a maximum packet size to 4096 and claims “No legitimate DNSSEC packets should be larger than 4096 bytes.”

Is that true? And why?

2) Currently our ASAs have the following policy map parameters for dns inspection:

message-length maximum client auto

message-length maximum server auto

It seems like this may frequently exceed 4096 by a huge amount, but does it matter? Also does this config make sense in general? Is there any reason to run both parameters?


r/networking • • 8d ago

Moronic Monday Moronic Monday!

25 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking • • 9d ago

Security Would you consider replacing Palo Alto and/or Fortinet with Juniper SRX?

83 Upvotes

Whenever the conversation on enterprise firewalls comes up on this group, I've noticed the discourse is always incredibly predictable:

"Palo Alto if you can afford it, Fortinet if you cannot. Honorable mention: Cisco FTD but we all hate those"

Juniper SRX? Never even mentioned in these topics.

I'm wondering why, though? What am I missing, or rather what are SRX missing to not be a major contender for enterprise NGFW consideration? It looks like SRX is more heavily used in Carrier & Telco networks versus enterprise networks.

Do you consider SRX a true "NGFW" firewall? Is it really as simple as "Palo and Fortinet have a nice GUI to manage and audit the security policy, and Juniper doesn't?"


r/networking • • 9d ago

Monitoring SNMP headaches

50 Upvotes

I'm building some network automation software and I keep running into difficulties with SNMP. Does it feel to anyone else like the standardization was a promise that never actually materialized? I feel like I'm constantly using vendor-specific MIBs. There are devices that stop responding over SNMP. There are devices that take nearly 5 minutes to walk a subtree (sometimes... until you restart the SNMP service). There are devices that don't return interfaces properly. There are devices that spike CPU just reading some standard subtrees. This is partly an airing of my frustrations and partly a sanity check.

Do other people see these same issues? Am I being stupid with my code? Am I a fool for using SNMP? If so, what is the best thing to use these days? And how about with older hardware?


r/networking • • 10d ago

Wireless Any suggestions on roaming omni directional wifi bridges?

8 Upvotes

Hello, I'm developing a network where the clients are cameras attached to some vehicles. The vehicles are in constant motion and need to be able to switch from AP to AP reliably without sticking to far away APs.

Originally I tested this out with just the cameras but I could not find a single wireless camera that supported roaming. They all tend to stick to an AP even though its closer to another one.

So I'm going to test some wireless bridges. Has anybody worked with anything like this before? A 360 omnidirectional bridge that isn't fixed on a ptp wireless connection and is capable of roaming throughout the network connecting to the AP with the best signal available. Thanks


r/networking • • 11d ago

Career Advice What network engineering speciality gets to travel often or ocassionally

64 Upvotes

At the mid to senior level do specialezed enginneers at (ISPs, Core Guys, Security Guys etc) Travel alot, either between sites or to other countries?

If so ,why?


r/networking • • 10d ago

Other Network Adjacent Question

9 Upvotes

Looking to spend some lab budget for my team and one of the items I want to get for our labs to demo for possible remote locations is some sort of compute we can deploy along with firewalls, switches, etc. that we can manage.

For right now, it is just for the lab, but I see potential uses is when we deploy network gear to remote locations without any supporting compute we can piggyback on, a server that would allow us to run local tools (tbd what those would be).

Looking for something like a larger Pi, something like a Mac Mini format, etc. Basically some sort of smaller server that can deployed and managed by us so we can use it to run tools, etc. without relying on our server teams, etc. Ideally I would love something that can rack in a standard network rack and is not a full depth server.

(And before comments about separation of responsibilities, bypassing safeguards, etc. I am high enough up in the company senior management chain that decisions like these rest solely with me. I do not need permission).


r/networking • • 11d ago

Security Emergency patch advisory: Cisco ISE CVE-2026-76460 (CVSS 10.0) — no workarounds, active exploitation

164 Upvotes

Heads up for anyone running ISE. CVE-2026-76460 is an unauthenticated API bypass that gives root on every ISE persona (admin, PSN, MnT, PxGrid). All supported versions affected. Already being exploited in the wild.

Cisco says there are no workarounds. Your options are patch or take ISE offline (which means shutting down network auth).

Practical steps: 1) inventory ALL ISE nodes, 2) schedule emergency maintenance this week, 3) check for compromise before patching (look for unexpected cron jobs, modified system files, unauthorized admin accounts), 4) restrict management interface access to a dedicated management segment, 5) if compromised, rotate ALL RADIUS shared secrets across every switch, AP, and WLC.

The management interface runs on 443 by default, same port as sponsor/mydevices portals. If any of those are internet-reachable, your ISE API is reachable.