Titaniumdo you know how to switch a N5k between the different modes?
Titaniumfor FC
Titanium(enable the features)
veersslot X then define the ports
veersand yeah, a lot of our network engineers get bit by the whole 'feature' thing
veers"why can't I create this VLAN interface"
veersoh that yeah
veersfeature npv; no feature npv; after backing up the config
veersbecause cisco seems to think dumping it is the right thing to do
Titaniumdo config in notepad
Titaniumotherwise u lose it
Titaniumdont paste more than like 20 lines at once
Titaniumit will screw it up
veersI tend to do each individual stanza when I paste in
Titaniumone of these days il find out if putty or the device is responsible :)
Titaniumbut i think its NXOS
Titaniumdo you know where to configure FCOE with VPC to a rackmount?
veerswell some things you need to "exit" out of before you paste in the next batch or it'll fall over
Titaniumyeah in vlans, you need to exit before config is applied
veersyou mean building the vfc interface and binding it to a port-channel? or something else?
Titaniumdoes this version have vlan configuration mode?
Titaniumto the port-channel
Titaniumi wonder if they make you configure spanning-tree port edge trunk
Titaniumon ports going to ucs
Titaniumi would take off points
veersfor configuring edge trunk? or not configuring it?
Titaniumit MUST be configured pointing to a UCS
Titaniumif its not configured its wrong
veersyeah; unless they tell me to make it run in switch mode :(
dhankswhere does DFA terminate tunnels? in 1kv and tors?
Titaniumin switch mode, how is the cableing different?
veersI used to yell at one of our engineers because he'd always leave it off
Titaniumand why?
Titaniumin switch mode, there is no uplink tracking
Titaniumso you need a connection between the FI
veerswell now it's a switch so yea you have to treat it like a switch
Titaniumotherwise it blackholes traffic
Titaniumon 1000v, what is the only correct configuration for ethernet port-profiles?
veershrmm not sure I follow the context but that's basically going to be an uplink port-profile
Titaniumone of the lines of config has about 6 choices
veersshould be using MAC pinning if you're using UCS though
Titaniumeverythign else is wrong
Titaniumif you did that and i was allowed to grade it... i would fail you for that point alone :)
veersif I configured mac pinning you'd fail me even though that's the preferred way? haha
Titaniumsomethign else :)
Titaniumalso, make sure to create a vlan on a 1000v
Titaniummake sure you know how to get to vlan manager page on UCSM in the old code
veersand don't forget my system vlans!
Titaniumso you can do disjoint
Titaniumdont forget system vlans, especially on vmkernel ports
Titaniumuplinks are not enough
veersoh yeah hahah believe you me I've run into some customers that forget
Titaniumdo you know how to fix a 1000v if you forgot a system vlan?
Titaniumi ran into customers that never created the system vlans to begin with
veersit's been a while but it'll come back to me
Titaniumtheres several ways
Titaniumyou can move back to vSwitch
Titaniumbut it kills all your vmk ports
Titaniumor you can do esxcfg-vswitch -U dvsname
Titaniumand esxcfg-vswitch -L vmnic1 vSwitch 0
Titaniumto unlink and link
veersyeah that bit I'm pretty familiar with haha
Titaniumthe vmk ports are harder
Titaniumgotta delete and re-create
veersI've got a decade of VMware experience under the belt going into this thing
Titaniumthe easy way
Titaniumis to use vemcmd show prot
Titaniumto get the LTL of the interface with broken system vlan
Titaniumand then use vemset to make it a system vlan
veersI usually create new on the standard to make any repairs
Titaniumits temporary
Titaniumas soon as the vem re-connects to the 1000v it goes back to normal config
veersyeah I blow 'em away when I'm done
Titaniumsystem switchover != reload
Titaniumhow do you check if any VEMs are detached from your 1000v?
Titaniumshow mod vem missing
kuaharaAm I going to need experience working with SNMP in order to answer SNMP questions on the icnd1?
Titaniumwhat port does SNMP use?
Titaniumis it TCP or UDP?
kuahara161 or 162?
Titaniumdo you need experience to know the answers to these?
kuaharahad to look on wiki
Titaniumthen yes you need experience
Titaniumi doubt they will have you create SNMP ACLs or unload mibs
kuaharasnmp was not covered in the cbt nuggets series for icnd1
veerson this exam? not likely
kuaharasomeone asked about like 5 things last night that I had never heard of before
Titaniumits fair game for you!
kuaharaafter having finished the series
kuaharalooks like SNMP is run over udp
kuaharabecause (and I am quoting someone else here) in a congested network, there is a better chance of the data being transferred
kuaharaif I had to guess at an answer myself though, I'd have said something completely different
kuaharaI'm guessing the data it needs is being sent periodically anyway and if the data is lost on one send, there will be several others regardless
Titaniumwho knows how to configure a 1000v for carp?
kuaharait wouldn't seem there is a need to congest the network further by using tcp
TitaniumSNMP uses reports or somethign in SNMPv3 so you can get acks for every trap
Titaniumfor queries it can re-try
Titaniumit does not need to be lossless
Titaniumwhats a trap?
kuaharaan alert that gets sent when certain conditions or events happen
Titaniumwhats a SNMP GET, SNMP GET NEXT, SNMP GET BULK, what are the 2 parameters of getbulk and what do they do
kuaharano idea
onefst250rTitanium: ITS A TRAP!
kuaharawhile I do want to know, is this icnd1 ?
Titaniumtrap is syslog for SNMP :)
Titaniumprobably not
Titaniumi like SNMP, i wrote my own snmp library
kuaharaI hate asking that question only because it makes me sound like I am unconcerned with the information; which is not true.
Titaniumit can generate invalid packets and one day i hope to crash something
kuaharabut in a crunch, I have to prepare for an exam and then go back and likely relearn some things anyway
kuaharajust because in a job, it'll probably be needed information
civillianonefst250r: I lol'd
onefst250rcouldnt resist
kuaharathe material to be familiar with is starting to feel a little endless
Titaniumi prefer to only take an exam when i think i can pass without preparing much
mgeorgethe nikkei is down over 550 points
mgeorgethe Dow Jones is going to tank tomorrow morning
Titaniumwhat will bitcoin do?
mgeorgemake that down 600 points now
mgeorgemarkets around the globe are entering a correction
mgeorge10% or more because stocks do not match economic data
Titaniumi dont care what it does, i care why it does it
mgeorgeim waiting for the twitter bubble to burst
Titaniumis there any kind of long term shorting?
mgeorgetwitter is valued at 65.25 per share yet the company does NOT have a positive cash flow
mgeorgeanywho its my bedtime, looking forward to seeing the dji drop tomorrow morning
mgeorgemy prediction is that it will open up nearly 250 points down because the global markets tanked
mgeorgeanywho g'nite :)
ubuntuskillskidi hear octopus predict stocks well
blackOffwhat is the normal capacity of a bridging table?
hjohnsonwhee that was fun
ubuntuskillsskid[Chemical Brothers - Do it Again]
DareDevil_Hi guys, on a dmvpn network the Hubs public ip address has to be pingable?
DareDevil_Has to be reachable?
Someonefromhellall public ips have to be reachable really...
Someonefromhellthey don't have to actually reploy to icmp echos, if that's what you're asking
Someonefromhellbut filtering those will probably make your life harder
n1njamaking acl's to block icmp from certain countries doesn't hurt either
Symmetriaabout to start upgrades on 11 P/PE routers 9k routers
Symmetriathis is gonna be a whore I can see it
n1njawish I had an asr 9k at my house
n1njaoh the things I could do.. the so many things
n1njawondering if anyone has setup voice in their home to accept local calls and re-route through voip, so you can bounce calls with your cell phone to call international for free.
n1njamake me a guide. my voice skills aren't there yet.
Azeei got my ccna. going for my ccnp switching exam this week.. what kinda jobs i should be looking for as an entry level ?
Someonefromhellsupport in a noc would probably be ideal
DareDevil_I know my question is retarded, but an issue that I am having just made me doubt about it.
DareDevil_About the fact that all the ips have to be pingable
DareDevil_Although the two Peer NBMA Addr from the HUBS are not pingable or responding UUUUU. The tunnel is still Up
DareDevil_Why would that be?
DareDevil_The two dmvpn Peers NMBA Addr are responding UUUU when I ping it from the spokes but still the State is Up
Azeeaccess list ?
Azee(just throwing it out there)
Someonefromhellhaven't played with dmvpn, but I'd assume the tunnel itself would be kinda stateless
Someonefromhellie, as long as your source interface is up, the tunnel will be up no matter what
Someonefromhellwhich is why you shouldn't rely on the tunnel state for routing, use an igp
Someonefromhellsame is true for vanilla gre ( assuming you're not running keepalives )
^NaLiN^vanilla gre ?
Someonefromhellas opposed to dmvpn
^NaLiN^maybe typical gre tunnel static ?
zgjonbalaji had a router/internet speed question, this the right place to ask?
zgjonbalajHave a cisco/linksys E3000 router
noirsHey guys
noirsI cisco talent connection good to go to?
noirsIt's today in stockholm but Idk if I should go
newtmewtACTION is waiting for the day one of our routers dies at one of these locatiosn and we can't reach the property since thier phones run though it....
newtmewtthis is a new set up for us
FungiFoxnewtmewt: you have alternate point of contact info?
FungiFoxcell phone, whatever
newtmewtonly pots line is a fax...
newtmewtand they ignore it half the time
FungiFoxtheir own damn fault then.
newtmewtjust sucks cause all we can do is guess then or send a tech
newtmewtsince we can't talk to them to power cycle the box or anything
newtmewtor check the lights on it
FungiFoxthey using voip phones?
newtmewtsomesort of voip
newtmewtwe don't actually do it
newtmewtwe just provide transport for their data and vpn
ndnihilanyone know how to route ipsec traffic over an outside interface that has an address assigned by pppoe?
ndnihildefault route is ip address pppoe setroute
ndnihilbut need to add a specific route for vpn subnet to that
dadrciptables … -m policy --pol ipsec?
ndnihillol, tables on an asa? that would be nice and easy
dadrcUgh. This isn't #strongswan.
dadrcYeah. Sorry.
ndnihiltypically I just use a route statement like route outside a.b.c.d with the nexthop matching the default route
ndnihilbut this one is in a jungle somewhere connected by some monkeys whistling through some tin cans connected by string
ndnihiland outside interface is assigned by pppoe
ndnihilmaking my usual route statement for ipsec subnet not work
dadrcSounds painful.
ndnihilit is
newtmewtIRRC you just replace where you put the next hop with the interface
newtmewtso "dialer 1" or what ever
dadrcI hate working with other people's crap setups.
newtmewtdon't quote me on that though...
newtmewtACTION uses adtrans at work and often muddies the 2 together since they are similar
ndnihilnewtmewt: not on the asa, it wants a hostname or ip as next hop
newtmewtACTION also has never used an asa
dadrcGuess it's ASA bashing time again.
newtmewtACTION gets the popcorn for ASA hate hour
ndnihilI used to love pix/asa
ndnihilbut starting like mid-7 things went downhill
ndnihileven early 7
ndnihilbut I've got a couple dozen of these out in the wild, and I'm stuck with them
newtmewtACTION is only really familar with ISR G1's and Cat's
ndnihilthis is the only one using pppoe, and suddenly some ass in a tie decided that it was ueber urgent that it have ipsec vpn
dadrcNothing wrong with having a decent VPN
ndnihilthere is if the idiot device you're trying to set it up on wont route it
ndnihilACTION just dropped it off the network, and no way to get anyone in there...
dadrc"Yo, bossman, the ASA just kicked it. Buy me a new one?" ;)
ndnihilsince it was statically allocated addressing, I was just going to assign it straight and see if that worked, but being 3am I kinda forgot that the vpn tunnel to another device inside that network was my only way to access it
ndnihilACTION crawls back under his rock
ndnihilthanks for the chat
mikey__I'm setting up an anyconnect VPN with an asa 5505, and I'm experiencing a problem where my vpn client's routing table is updated with a route to using as a gateway for device cscotun0.
Azeeis there a simulator/emulator for cisco layer 3 switches for ccnp switch exam ?
mikey__I want for the VPN to only connect me to the network, and nothing else.
mikey__ANy ideas?
gypsymaurohow can I see if in a stackable cisco, there is a user defined member priority?
Plazmashow switch
lorenzohi! where can I download packet tracer for linux from?
ImrpovedWho here posted a funny networking meme-site a couple of weeks ago?
yautja_cetanuHi, Does anyone know if its possible to buy wireless 3G dongles/modems that are better then the normal consumer stuff?
dagbyautja_cetanu: define "better"
yautja_cetanuI don't know yet, I've been trying to read about it and I'm kind of trying to look at what is out there. I think "better" means more likely to pick up a stronger wireless signal if placed in the same location.
dagbyautja_cetanu: so you want a device that allows for connecting an external antenna.
yautja_cetanuWe used a normal wireless dongle plugged into a draytek and found the signal was bad. We used a "Mifi" kind of thing and found the signal was better. Which makes me think we might be able to find something better then just the stuff you get from phones4u
yautja_cetanuSure that could work
dagbmy experience with 3g dongles and modems are that they are made as cheap as possible, and then the software (for windows) is generally branded and/or locked to specific operators and generally not available nor updated.
dagbso I would very much recommend forgetting the entire 3g modem idea, and get a 3g router&ap instead
dagbwith an external antenna port
yautja_cetanuI've looked at those, they can get pretty expensive, which is fine but I was wondering if they were mroe expensive because of all the router related features
dagbconsidered how much time I have pissed away at getting 3g modems to work, they are not expensive... :-)
dagbthey -> 3g routers
Symmetriaanyone know the FIB size on an Me3600?
yautja_cetanuCool, I'm googling 3G router with external antenna, this is looking more promising. Is there any particular models you'd recommend?
hkklSymmetria: 20k for ipv4 / 6k for ipv6
yautja_cetanuI'm looking at http://www.3grouterstore.co.uk/index.html now, this looks promising
Symmetriahkkl I presume those are shared?
hkklSymmetria: but depends on sdm carving. so not shared.
Symmetriaso usage of all 6k v6 drastically reduces v4 available?
dagbyautja_cetanu: I would like to try out the huawei 5776, but haven't gotten to it yet
hkklwith ip profile you get 24k/4k
nightcrowhow can I tell what routes are being distributed in my OSPF?
nightcrowI want to see the routes that my router is advertising, not the ones that it is receiving.
yautja_cetanudagb: Ah, thats more mobile wifi right? Its not something you'd plug into an existing network?
dagbyautja_cetanu: true
newtmewtwe normally use the cradlepoint stuff
dagbfor that, cisco 819 and 892, if my memory serves me right
yautja_cetanudagb: We're looking for something to supplement our satelitte modem that is powering a network of about 30 people. Its not ideal but its what happens when you try and make an office in the middle of nowhere! :P
yautja_cetanudagb: Thanks for your help though
dagbyou're welcome
nightcrowhey guys, any ideas regarding my question
dagbyautja_cetanu: hm not cisco 892, no
newtmewtyautja_cetanu: we use the cradlepoint crb450, granted it seems they have disconntinued that model
yautja_cetanudagb: Was that aimed at me? This doesn't like a 3g router? (I think we actually use Drayteks... dunno if people will mind me saying that here :P)
dagbyautja_cetanu: yeah. if you want a 3g router to plug into your network, look at the cisco 819
newtmewtthe 819 is a M2M with 3g/4g
newtmewtlooks like the new cradlepoint model is a COR IBR650, closeset thing
newtmewttakes a USB stick connection in
newtmewtand most of the USB sticks we get have spots for external antenna
newtmewtoh i guess the IBR series has the modem built in...
newtmewtbut has external antennas
yautja_cetanunewtmewt: really? I haven't found any USB sticks with antennes? The USB sticks we've used have been pretty terrible :(
newtmewtyautja_cetanu: look at this http://www.cradlepoint.com/products/machine-to-machine-routers/cor-ibr650-3g-4g-router-no-wifi
newtmewtlooks about what you want
yautja_cetanuyup it does
yautja_cetanuSo you'd put the SIM card into that thing itself right?
newtmewtyou have to buy the right version for the provider/tech
newtmewtbut this one of the common usb sticks we get http://www.amazon.com/Sprint-Sierra-Wireless-Broadband-Adapter/dp/B009ZY10GK
yautja_cetanucool, will have to research it a little more cause I'm in the UK but this look good
newtmewtyautja_cetanu: what type of network you looking for? HSPA+? or LTE?
yautja_cetanudon't think they do karma here but oh well!
yautja_cetanuDon't know yet so I think HSPA+ , really just thinking what is possible at the moment
dagbnewtmewt: looks nice. do you have first hand experience with cradlepoint products?
newtmewtyah cradlepoint has a version with HSPA+
newtmewtdagb: not that exact model but some of the other ones
newtmewtmainly the CBR450 and CBR1200 and 1200
newtmewtthey seem to be turning into ubiquiti in terms of expanding markets...
dagbI assume the ipsec sessions are site-to-site, right?
newtmewtthey have multi wan and edge routing and shit lol
newtmewtdagb: we don't use them for that, so no clue
newtmewtwe just use them as USB 3g/4g dongle to ethernet more or less :D
yautja_cetanucool this is ridiculously helpful :)
yautja_cetanuWhat does it mean when it says Machine to Machine?
newtmewtthey are refering to liek having an ATM talk back to the server
newtmewtso its machine(atm) to machine(server)
yautja_cetanuRight so I don't really need to worry about that. I can plug it directly into a laptop or into a router to power a network?
newtmewtwe do it all the time
yautja_cetanuDo you open them up to put the SIM card in? I can't see any slots
newtmewtwe don't have that model
yautja_cetanuah yeah I see it now
newtmewtbut i see a little cover slot thingy
newtmewtlike i said the ones we use don't have internal modems but the USB dongles
yautja_cetanucool this looks good, I think it will be worth testing
yautja_cetanuDo you know of any tools where I could take it into this Field we work in and test which network would have better signal... other then just looking at the bars on a phone?
newtmewtnot any tools really
yautja_cetanucool ok thanks
newtmewtif we have no clue we normally just send out multiple usb dongles from allt he carriers we use and find the best on site
dagbnewtmewt: :-D
dagb3g dongles suck
dagbquestionable quality and all sorts of weirdness with software, firmware and operator locks
metheo_irchi ppl
metheo_irchkkl, here ?
metheo_irchi )
metheo_irca few odd questions )
metheo_ircfirst, does the configuration of mtu under the "vlan" context (on IOS, cat swtiches, like 3560) is it meaningful ?
hkklmostly no, if there is system mtu
hkklfor example in sup2t system mtu overrides your interface mtu config
metheo_ircon current switch (4900) I see "sh system mtu" as : Global Ethernet MTU is 1552 bytes
metheo_ircthe paticular vlan traverses through two trunks (physical interfaces) that have mtu setting 9000
hkklhmmh, i think 4900M / 4500 is different in that sense
metheo_ircissuing "sh vlan xxx" command I see MTU 1500
hkklas we also have system mtu at 1500 and run interfaces with 9198 mtu
metheo_ircso question is do I have to change vlan mtu setting from default 1500 to let jumboes pass
hkklonly if you are routing i'd guess
metheo_ircMy understanding is the same
metheo_ircIt's meaningful only if I do routing through svi
hkkl'that is atleast how it works for us'
hkkl(very annoying that different platforms work that differently.)
hkklin regards of configs
metheo_ircanother question about ring topology )
metheo_ircYou use it , right ?
metheo_ircIf we have an L2 ring on cisco switches
hkklthough nowadays it's quite limited to spanning-tree and datacenters, as metro is mpls
metheo_ircwell, we avoided using rings and STP but now..it seems we have to )
metheo_ircwhat you can suggest to use - pvst+ or mst ?
Someonefromhelll3 and mpls :p
eirirs_metheo_irc: mst are IEEE and newer, pvst are cisco proprietary
xouswhy the hell do you want a ring toplogy?
metheo_ircxous, unfortunately, REP (and ERPS) not supported on that ioses and that hardware
xoususing 2950s :P
hkklmetheo_irc: mst
dagbmetheo_irc: use REP
metheo_ircxous, redundancy and availability, man )
LeoloveWhat is the difference between CCNP service provider and ccnp service provider operations in layman terms? I am unable to explain the difference.
xouswhat hardware do you have?
xousLeolove: one is for managers
Leolovewhich one? :p
metheo_ircxous, 3560E, 4900M
xoushow many?
xous3560E a TOR switch?
xous10G or 1G uplinks
metheo_irc3 x 3560E + 1 x 4900M in ring with vlan termination through 4900M
metheo_ircxous, does it matter the link capacity for the question ?
xousthe number of interfaces do
metheo_ircthe ring is 10G
xousso the number of interfaces and 10G (and cheapness) is dictating the topology.
metheo_irclets assume, that we have four l2 switches in a 10G ring and whant to use some flavour of STP to use it
hkklmst for sure
hkkleven if r-pvst is easier it doesn't really scale to any decent number of vlans that l2 metro would have
metheo_irchkkl, ok, tnx . think, it will be mst (like more carrier-grade ))
xousthere usually ain't a whole lot of switching in carrier networks :P
hkklxous: l2 metros are quite often
metheo_irchkkl, any suggestions on mst settings (timers, etc) ?
hkkll2 ring with dual pe:s terminating all
xousI suppose so
xousheh. dual pe's if you aren't cheap
hkklxous: ok, add that :)
xouswe have a 1G rep ring in yvr
xoussingle pe
xousfucking hilarious
hkklwe ran pretty much default timers. most important thing is to make sure all non-core links are correctly stp edge ports
xouswe used to have them without UPS
hkklalso planning mst config vlan wise is quite important to think about a moment
hkklas changing it afterwards is ... challenging :)
xousyvr had a nasty problem with power about 2 years ago
xousthat was fucking funny.
hkkls/mst config/instance config
hkkland over engineering instances can make your life hard
Someonefromhelland by challenging you mean disruptive ;)
xousfuck planning
hkklwe had like 10+ instances
hkklthat was awful
xouswe just ripped out two core switches on a days notice
hkkland always instance you wanted was blocking in wrong place
xoushkkl: I thought the idea was the instance should be designed with the physical toplogy in mind
xousif it was a straight up ring why would you want more than two?
metheo_irchkkl, as I understand an single instance should be configured for several vlans with same tail/head ends ?
hkklalas, it wasn't
hkklmetheo_irc: yes, pretty much. of course if you don't need anything differing you can just run everything in single instance
hkklor divide vlans to half or so
metheo_ircwhen first enabling mst ... does it stops the current traffic flow on ports (for a time for port iterations, blocking, learning forwarding etc.) ?
hkklok, how do i bind eem script to tracker down up if i don't have event 'track' available?
xouscisco has a very long document somewhere about upgrading to mst
hkklmetheo_irc: if everything isn't correct, it will do that for sure
metheo_ircpain-in-the-ass ))
xousdesign shit right the first time :P
metheo_ircand do lab testing
xousand don't pick your design after you bought the hardware :P
Someonefromhellsyslog or snmp , depending on what you want the trigger to be
hkkl*Nov 1 14:47:24.243: %TRACKING-5-STATE: 206 ip sla 206 reachability Down->Up
hkkli get that
hkkland i want to also add ipv6 route after ipv4 route with tracker has gone up
hkklas ipv6 route tracking seems to be only on some very newish ios-xe
hkkland i have these sucky 4500/sup6es as datacenter aggregation routers :/
hkklso i guess i will try ipv6
Someonefromhellsyslog is probably the easiest choice
lroeI'm looking for an inexpensive (< $300) to test light levels on fiber (SM and MM) any suggestions?
void64Iroe: Fluke and JDSU I think make some inexpensive simple light meters
lroeis that what I'm looking for a 'light meter'
void64Though I've only seen them work on > 1200 nm
void64Yes, a light meter
void64or OLP
void64Optial Power Meter
void64Fluke, JDSU or EXFO all make them… EXFO might be a bit more higher end and lot more $$
void64JDSU makes a nice set with a power meter and a generator/identifier
kuaharayou won't get a decent jdsu for under $300 though lol
kuaharaor even $3000
void64Pretty sure thats about $300 or under
lroethat's kind of neat. I'm assuming it's windows only
kuaharanot even sure what that is =o
void64It's a power meter with optical scope I think
void64all done in software
void64not sure about compatibility
dadrcit's a … thingy.
kuaharaonly JDSUs I've had to work with are the v1 - v3 meters used by AT&T field techs
kuaharathe cheapest ones run $3k. the version 3 meters are $7k
void64Windows only probably…. but nothing VMware fusion or virtualbox can't fix
void64oh… best test set I've used are the EXFO's, but those are like $15k
void64But those are full test sets, not just power meters… line rate 10GE, reflector/generators and all the standard cert tests
lroeright, I am sure there are excellent expensive tools in this category, I'm looking for a cheap investment to 'double check' our fiber tech
void64actually generators field test reports PDF with your company logo on it you can hand right to the customer
void64Check out that JDSU one….
lroewhat do I use as a light source?
void64If you're looking for something simple just to give you a Db loss, ie: meter only, el-cheapo,then fluke is probably your best option
void64Iroe: you use whatever is on the TX side
void64or you loop it from the far end
mynd|centmorn' gents
void64but that would give you total loss on both spans, not end to end
lroeoh, I don't need a calibrated light source to accurately determine loss?
void64No, the meter usually has a wide enough optical rx window
void64I've never used it for MMF/850nm, so…. I can't speak for that
void64but for 1310+ works fine
void641200+ rather, just check the specs on the optical rx
void64that JDSU mini one looks like it does 850+
void64might not see some higher range CWDM/DWDM channels
void64that MP-60 says it's good for 850, 1300, 1310, 1490 and 1550
MrJayPCI think I found where all the remaining nazis went... my insurance company ¬_¬
void64Most insurance agents go to work wearing ski masks
kuaharamine's really pissed off that my card expired last month and I won't give them the new info
MrJayPCI changed the the purchase date on the car by a week on the insurance quote and it jumped up to £164 / month lol o.0
hkklfriend used that method to get his xbox gold subscription
hkklcanceled credit card
kuaharanext time they call to harass me for it, I'm going to let them know that despite what they think, they are not the most important bill I have to pay each month.
worstadminI have a network dropping packets late at night during san backups - Im attempting to locate this problem - what Im thining is simply clear interface counters and pummel it. Anything else I should do?
oisterhow do you know its dropping packets?
nieroshe can feel his packet senses tingling?
worstadminI use pingdom
worstadminfrom the outside world - getting it every night at the backup time
rstyI'd say that might be your problem
rstyeither way, i'd start with your netflow box... if you don't have one... there are free ones out there and turn netflow on the neccessary devices
oisteryou're pinging from the internet and seeing packet loss while your san backups are running?
nierosyour switch probably just isn't up to the task.
rstydo you have netflow or snmp set up for utilization, etc ?
worstadminrsty: yes using Zabbix - builds mrtg graphs - but I dont see anything standing out in the graphs
worstadminIm looking into netflow now however
rstysnmp is good for where but netflow is good for what
rstyzabbix might have a netflow plugin, i've never used zabbix
SuperNulli need to get me some netflow.
SuperNullwe got DOSed last night and it would of only been easily stoppable with the help of netflow
krthnzBE PART OF IT!
rstyand bosses like graphs, so its good for us in that aspect too
rstythey have to be colorful though
rstyits helped us plenty of times
SomeonefromhellSuperNull : netflow is nice, span is even nicer
Someonefromhellassuming you're not at a scale where it's really impractical/expensive
Titaniumerspan v3 is yet even nicer
mepholichow much additional resources does PFS on IPsec actually use?
nierosasa's do netflow
nierosor are we ASA hate houring for a different reason
oisterworstadmin: look at the devices that share the SAN backup traffic and external monitoring
SuperNullmy co-worker constantly listens to archer. its dumber than i thought it would be.
kmcelroy1archer is hilarious
kmcelroy1you now honorarily suck
nierosarcher IS hilarious.
kmcelroy1see, he knows
SuperNulli dont trust a guy with a beard that beastly.
kmcelroy1from the fine folks that brought you sealab 2021 and frisky dingo
nierosYou're a fool then
SuperNullfrisky dingo was okay
kmcelroy1frisky dingo was fucking amazing
nierosMy beard makes most people feel safe
nierosand most women feel wet.
SuperNullits the absorbant properties they like.
nierosit's the handlebars.
nierosneed something to hold onto see
kmcelroy1have you bitches seen broad city yet?
kmcelroy1that shit is hilarious
SuperNulli have been watching that new cartoon Rick and Morty.. *cough*
SuperNulldoesn't have nearly the amount of cocaine in it tho
kmcelroy1that is pretty weird, but seems entertaining
Someonefromhellso, 3600s don't do l2tpv3
Someonefromhellthey allow you to configure it with no errors logged at all
Someonefromhellthey even show that the tunnel is established
SuperNullgotta love this, this guy wrote software that ALWAYS expects a voicemail box to exist..
Someonefromhell...they just forward nothing :P
SuperNullwhich never gets created for virtual/forwards.
SuperNullso in portions it just fails cause.. fails.
kmcelroy13600s? the AP or the router? :P
kmcelroy1or that, :P
kmcelroy1weird, you would think that could do l2tpv3
routerprodoes anyone know if you can change a PPPoE dialer interface username/password , will it drop the connection? I can't remember if pppoe does auto only on initialization or all the time
kmcelroy1i would think if you pulled the u/p it would drop it
kmcelroy1but if you have to change that, it would probably not be up anyway
routerproit is up currently
kmcelroy1then don't change it?
routerproits weird
routerproits wholesale dsl
SomeonefromhellI would think it won't drop
routerproits using the last mile providers user/pass yet the isp wholesaling is saying it needs to use theirs so they can view it
Someonefromhellhowever, if you're not sure, schedule a window
Someonefromhellif you're sure, schedule a window anyway
Someonefromhell^ golden rule of networking :p
eirirs_windows task scheduler
kmcelroy1really? i would think it would since it no longer has credentials, but i am not sure
routerprono other way in to the router unfortunately
routerproso i need to figure out how to make the change and not lose connection
kmcelroy1routerpro: smart hands
Someonefromhellhow about making another username/password and doing something stupid like, allowing both pap and chap with different creds on each ?
kmcelroy1or you could just EEM script the u/p change
kmcelroy1i have done that on things i will lose connection to, works well
routerproanother dialer interface you mean
kmcelroy1the script will keep going and finish the job for you while you are disconnected
routerproyea i was thinking that eem maybe
Titaniumthis assumes you wrote it correct
Someonefromhellno, on the same dialer, different pap and chap creds, it should try both of them
Someonefromhellbut eem works as well
kmcelroy1Titanium: well, you test it on something else first obviously :P
kmcelroy1but i have done things like that with eem before
Titaniumnot as obvious as you would think
routerprotwo dialers one interface ;)
eject_ckHi all
mepholicgod damnit
mepholici fucking hate sonicwalls
kmcelroy1don't we all
kmcelroy1could be worse, could be a checkpoint
eject_ckI have switch: Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 12.2(55)SE7, RELEASE SOFTWARE (fc1). I can't get ipv6 working between my local machine and ISP when I'm using switch (I have no way to test it without switch because of Fibre Optic port). Q: do I need to configure anything specific to get ipv6 traffic working on this switch ?
kmcelroy1that is a layer 2 switch, so it shouldn't matter
pffsdunno, I remember my 3550 breaking ND
pffswhich makes ipv6 not work so well
kmcelroy1well, the 3550 is layer 3 and old as shit :P
pffsdon't hate on my 3550 :(
pffsit was cheap!
archuser2just make a dump and see what's going ot
kmcelroy1by dump i assume you mean span the port and sniff :P
archuser2what for?
archuser2dump it on your pc.
archuser2check all those NS/NA/RS/RA.
russixeject_ck: make sure you're learning the respect MAC addresses per port & they're in the same VLAN. 'sh ipv6 int' can also give some ND hints
pffsdoes 12.2 have any ipv6 support?
eject_ckyes I think
eject_cksh ipv4 int return empty line
eject_ckI don't need ipv6 on this switch
pffsit would be show ip int or show ipv6 int
pffsshow ipv4 int shouldn't even work
eject_ckI'm connected via usb cable :)
eject_ckusing console via tip
eject_ckthis is my config
eject_ckI don't need access this switch via ip
eject_ckAgain I have ISP on GigabitEthernet1/0/1 and my router on GigabitEthernet1/0/28
pffsI mean, the IP portion of it shouldn't matter because it should only be looking at the ethernet header
eject_ckI have two vlans where 545 is IPv4 interface and 544 is Ipv6
straterraHmm..can you use Twinax/DAC cables to directly connect servers, without going to a switch first?
pffseject_ck: why do you have two vlans?
eject_ckwhen I assign ipv6 address to vlan544 on my OpenBSD router I don't see traffic between my router and ISP]
eject_ckwhere ipv4 works perfect on both interfaces
pffseject_ck: does your router have an interface on that vlan?
archuser2ipv6 mld snooping
archuser2where is trust on uplink port?
eject_ckISP LINUX box -> vlan544, vlan545 ------ FIBRE OPTIC ------ 2960S switch with FO port -> Cooper Port on server (router under OpenBSD)
eject_ckarchuser2: sorry I don't understand :)(
pffseject_ck: again, does your router have an interface on that vlan?
eject_ckpffs: yes
pffsdoes your switch show its mac address?
pffsI also don't really know why you need two vlans
pffsseems kinda dumb to me to segment ipv4 and ipv6 by vlan
eject_ckI've tried to assign IPv4 address on vlan544 (virtual interface) on my and on ISP side and it works
nitramucs, vm-fex, kvm
nitrami do a live migration of a vm
kmcelroy1pffs: that's cause it is :P
nitramafter first migration, traffic continues to flow in vm
pffskmcelroy1: if you don't have the ipv6 SDM turned on, will it break switching ipv6 packets?
nitramafter migration back, there is no more connectivity to vm
nitramany ideas?
Someonefromhellit is dumb
pffsIt doesn't seem like it should matter since it should never look beyond the ethernet frame
Someonefromhelland it will switch ipv6 frames just fine regardless of the sdm
Someonefromhellit might have trouble routing them though
kmcelroy1pffs: it shouldn't matter
pffsI don't think the 2960-S will router ipv6 frames no matter what
kmcelroy1since it is purely switching them, it shouldn't give a damn
nitramif i migrate a third time, the traffic to the vm works again
nitramafter the forth it stops
nitramit will only continue to work on the target host of the first migration
archuser2l2 multicast addresses are kinda different in ipv6
archuser2so it probably give a damn
eject_ck544 90e2.ba0e.f795 DYNAMIC Gi1/0/28
eject_ck 544 90e2.ba29.95a0 DYNAMIC Gi1/0/1
eject_ck 545 90e2.ba0e.f795 DYNAMIC Gi1/0/28
eject_ck 545 90e2.ba29.95a0 DYNAMIC Gi1/0/1
Someonefromhellno it won't
Someonefromhellit might not do mld snooping
Someonefromhellbut that's pretty much it
archuser2well I run ipv6 over old l2 3com or something like that
eject_ckSomeonefromhell: I've added it during troubleshooting
archuser2but I never thought why 3333.* works...
SuperNullanyone know isc dhcp decent ?
gewtmulticast is evil
kmcelroy1gewty gewt, multicast is the future
gewtbut it's also evil
kmcelroy1taste the future
pffstaste mah balls
pffseject_ck: I'm assuming that those correspond with the correct MACs for each vlan?
pffsalso, why do you have two vlans?
eject_ckit was ISP's idea
eject_ckone vlan for ipv4 and one for ipv6
kmcelroy1sounds like an amazing idea
eject_ckwjy not ?
kmcelroy1i would ignore the ISP :P
pffsIt's a terrible idea
kmcelroy1also, why turn off spanning tree?
pffsDo you have any reason to segment devices into ipv4 and ipv6 only?
eject_ckboth vlans are using same physical interface on server (inet6 alias 2a01:d0:0:31::2 64 vlan 544 vlandev em0 )
kmcelroy1and there is the problem
eject_ckspanning tree ?
mepholicspamming tree
eject_ckI've disabled it during reoubleshoting
kmcelroy1same physical interface for 2 different vlans :P
eject_ckwhy ?
mepholic>Disable STP. network status = now in ruins
archuser2anyway, did you dump it?
KenMatlockmepholic: only if you actually have a loop in L2, otherwise it really doesn't affect anything
archuser2and prolly debug ipv6 something on 2960
mepholicKenMatlock: yeah
mepholicmost simple networks are fine, but if you have an actual infrastructure
mepholicusually bad idea
eject_ckwell, I have ipv4 traffic working in this setup
eject_ckin both vlans
eject_ck544 and 545
eject_ckissue is only with ipv6
pffsyou probably won't be able to debug anything ipv6 on the switch because I don't think it'll actually see anything
pffsI don't think you can even turn on ipv6 on the 2960-S
kmcelroy1you can
kmcelroy1for management and shit
kmcelroy1it just isn't going to do any routing
pffsThat should require changing the SDM though, right?
kmcelroy1looks like it
kmcelroy1change that and a reload
pffsand I don't think the 2960-S has the ipv6 SDM
kmcelroy1but i doubt he needs that right now
kmcelroy1it says it does
pffsmaybe I misread the 2960 page
kmcelroy1the 2960 lite image won't do it
kmcelroy1but the rest will
archuser2ya keep talking about routing on l2 switch...
kmcelroy1no one is talking about routing
archuser2it should do mld snoopings and first hop security.
kmcelroy1we are talking about management
kmcelroy1remember that part where i mentioned managment and not routing?
kmcelroy1that was good times
archuser2yeah...but who needs to manage switches over v6 through...
kmcelroy1people with IPv6 networks probably
kmcelroy1but besides those people, fucking no one bro
archuser2ipv6 only networks, I believe.
kmcelroy1you believe correct bro
worstadminmrw when I realize nothing in this cabinet supports netflow
kmcelroy1but those will never exist
kmcelroy1worstadmin: that is the worst, ha
worstadmin3560's, asa 5520's and 4948s
eject_ckpffs: Switch(config)#sdm prefer ?
eject_ck default Default bias
eject_ck lanbase-routing Lanbase routing
mikejones2553afternoon all. i'm having a hard time trying to put into words for management why a large layer2 isn't so smart. i wonder if you all could help me find the right phrasing
kmcelroy1mikejones2553: broadcast storm :P
void64fuck man, I got a friend who live in FL, no state income tax and his property taxes are half of mine on an assessment thats 3X more than mine
kmcelroy1but in general it sucks
mikejones2553kmcelroy1: "but we can turn on storm control"
kmcelroy1i have a legacy layer 2 network that spans the country and it sucks nutsack
kmcelroy1have to have trunks all over, makes my life a pain in the ass
kmcelroy1have to deal with spanning tree
void64mandates in NY kill property owners
kmcelroy1it is dumb as shit
kmcelroy1and i hate that it was designed like that, so we are migrating from it shortly
mikejones2553kmcelroy1: "but mc-lag says we don't need spanning tree"
mikejones2553(i don't agree with either of those statements btw)
mikejones2553for me the biggest issue is, when there's a problem, i can't find it quick
mikejones2553multi-chassis lag.
void64hahaha right
mikejones2553vpc/mct/vlag. lots of names
kmcelroy1yea, hashing is awesome to load balance :P
kmcelroy1fucking routing is where it is at
mikejones2553"but how is ecmp any different"
drkatvoid64 hows the job market in albany
kmcelroy1the control you gain is so worth it
void64drkat: great if you're a short order cook or a lawyer
kmcelroy1i can't wait to get rid of this damn layer 2 network i have to deal with
drkatRochester isnt much better
kmcelroy1the only other stopping point is the damn SPAN network they use for SIP monitoring
void64drkat: albany is the political cesspool of the state
oisterwe have a large L2 network and its really starting to become a problem for growth
void64though few tech companies now in saratoga county
kmcelroy1oister: it always is :P
mikejones2553oister: how so?
drkatvoid64 hmm
drkatSaratoga is nice
drkatmy sister in law went up at skidmore
oistermikejones2553: adding a new network requires adding a vlan to a bazillion trunks
void64drkat: Saratoga is great if you can live *and* work close by
void64if you live in saratoga but commute to Albany, it's a nightmare
drkatlotta old money in saratoga
oisterand now that everything is virtualized they are spinning up networks like crazy
mikejones2553oister: i can see that. we don't add new networks often
void64I gotta get the hell out of NY lol
oisterwell if you do it will become a big pain
void64F this place
drkattell me about it
mikejones2553void64: head west :D
drkatfucking NY is killing me
kmcelroy1you don't want to head west
void64I'm heading south
drkati hear NC is the place to be
void64NC, SC, FL or TX
kmcelroy1you don't want to go south either :P
kmcelroy1texas and florida suck
drkatNorth Carolina nicca
mikejones2553circuit: why would i want to go to michigan?
kmcelroy1texas is an arid desert wasteland that i can only describe as a living hell with shopping everywhere
drkatima go to ATL
void64Almost landed a job with Apple at their maiden dc in NC, but they didn't want to shell out for reloc..
void64cheap fucking apple and their billions
drkatyeah finding someone to relo is gonna be a bitch
void64and who the fuck are they going to find in maiden
tannervoid64 were you going to make >100k at Apple?
void64it's in the middle of nowhere
pffsvoid64: I almost took a job there
pffsbut it's so far from my house
void64tanner: yes.
pffsand wasn't paying that much
tannersounds like you made a bad business decision
pffslike 35k for a job 50 miles away
void64tanner: not really, I make over that now
pffsMight be worth looking into again when I'd be considered for something other than basic NOC monkey
tannerthen it sounds like you didn't want the job
mikejones2553anyone else care to interject on the benefits and drawbacks of a large l2 ?
drkatwish i made >100k
kmcelroy1there are no benefits to a large layer 2 :P
kmcelroy1just headaches
void64tanner: it costs like $35k to reloc by all said and done, apple has 100's of billions in cash, they could of at least givena sign on bonus to help cover some of it
oisterdrkat: tallest blade of grass is first to get hit by the lawn mower
mikejones2553kmcelroy1: ip mobility comes to mind as a benefit
void64A lot of companies do
pffsmikejones2553: if you make l2 big enough you never need a l3!
drkatoister that was deep
tannervoid64 what benefit is it to them to do so? and 35k to relocate? What are you moving, pallets of gold?
void64Had a job offer fro Cymru in Orland, almost took it, they would of paid like $20k to reloc, but the salary wasn't there
oisterdrkat: we had a guy here making over 100k and he was the first to get let go when times got tough
oisterof course he didnt deserve the $ either though
kmcelroy1oister: yea, but then they can go to the next job and demand similar salary
diozyou don't deserve $
void64tanner: $35k by the time you go through paying realtors, and it's easily $15-$20k to move all of your shit 1000 miles away
kmcelroy1you always want as much as you can get
diozsup kmcelroy1?
circuitvoid64: what kind of work are you doing now
oisterkmcelroy1: his skillset didnt demand that kind of $ though
oistersomehow weased his way into it
kmcelroy1meh, lots of people get overpaid :P
tannervoid64 weird. cost me less than $10k to move 3000sq ft of crap from NY to AZ
kmcelroy1we have had complete idiots getting paid 6 figures over and over
void64circuit: network architect for service provider here in albany
void64tanner; did you hire a moving company?
tannervoid64 yup
LeoloveHi, I am CCNP Voice and preparing for my CCIE Voice. Voice was always my first choice due to interest. I would like to follow other track as well now. So, which track do you think suites and create combo with voice?
void64tanner: damn man when was that, 1980 ?
tannerpacked, loaded, unloaded and unpcked
tannervoid64 2012
void64tanner; thats strange because I just talk to a guy who moved from Albany to AZ and it cost him nearly $20k
tannervoid64 don't use mayflower? :)
void64tanner: who knows
diozshould i have a beer at 11 in the morning?
imemyself_can you enable HSRP during the cutover?
envirocbrwe have a 4510R which is so old it only runs Telnet
ralfiboyso is there a way to express a BGP as-path ACL that allows you to pad the AS path w/o updating the BGP peer?
envirocbrand the MSTP instance doesn't work with my other, newer, 2960s switches
envirocbrimemyself_: Nope
ralfiboy... only thing I can think of is two lines -- ^ASN and ASN$
envirocbrimemyself_: THe IP shema is screwed up
envirocbrBut I guess I can take a look at that too
envirocbrI mean, they have to be L2 adjacent
envirocbrBUt I see your point
envirocbrI can switch the active members as need be, correct?
ralfiboywhere ASN is the same value ...
imemyself_hmm. Even if you were able to isolate the traffic, I think you'd potentially have issues with the ARP cache on hosts
imemyself_if the default gateway's MAC is changing
void64SuperNull: Also I'm not sure how it works between vendors, luckily in our case it's all Cisco ASR's (9K or 901/903's, so they seem to sync up well over the network) Not sure about these one offs or what SP's have at the tower
SuperNullvoid64 do you guys use any NIDs ? like accedian or what ever?
SuperNulltrying to find some people who use it other than the cell customers directly..
imemyself_with FHRP isolation, usually there'd be one active member at each site. You'd have to remove some ACL's if you wanted hosts from one site to hit the router from the other site for outbound traffic
void64SuperNull: We do not, but the last mile providers are using Accedian that much I know, but I have no experience with them
envirocbrimemyself_: I drew it out, I'll probably lab that up
pffswelp, tried installing it on server 2k and server 2k3, just sits there
void64Accedians have all that SLA crap VZW wants to see
SuperNullvoid64 im looking into some NIDs for our peoples.. mainly for remote testing abilities and all that.
SuperNullwe have these nice ethernet 'service level meters' basically hand held gigabit traffic generators with BIT testing, RFC2544, lots of stuff.. it would be nice if each customer had an RFC2544 end point
SuperNullYouthInAsia ?
void64SuperNull: We have the EFXO test sets around somewhere. I mentioned them earlier, they are pricey but very cool. You can just fire off a PDF or even print a test report right off the unit with company logo, etc right on it
SuperNullthese ones also have T1/PRI integrated for.. the Lulz.
SuperNuller DS3 also. but not something we use
void64SuperNull: Lots of places looking for Y.1564 results now, and I think the EXFO's do those as wel…
SuperNullyeah i dunno if these do that actually.
Captain_matrixso what cisco product do you guys recommend for ids/ips ?
void64I don't think we have any TDM circuits left for IP term… only TDM I know we still have floating around is DS3s' for SS7 and OC3/12 ATM for some DSL still
MrJayPCNone :p
Captain_matrixor do you suggest using something like snort?
Captain_matrixreally? so snort is the *best* ids out there ?
Captain_matrixI figured proprietary cisco stuff would have an edge on it
void64Captain_matrix: Snort is pretty good if you want to build something
SuperNullvoid64 we have SIP->PRI so the PRI portion of it is okay. T1 is .. a once a year thing maybe.
SuperNullwe dont have any real TDM transport stuff so it usually is a end to end t1 kinda thing
toastrsourcefire (cisco) will still probably sell you commercial boxes if you want
Captain_matrixvoid64: how would you setup snort in an enterprise though ?
Captain_matrixI mean do you just setup a linux box and put it betewen asa and a router/swtich ?
void64Captain_matrix: Well if it's just IPS (for reporting) that depends on where you want to intercept the traffic
Captain_matrixor did you mean as a hips/hids?
void64Snort for IDS is a bit more complicated to deploy and setup
j0byou do not get the performance
void64The only IPS/IDS we're actually using and have deployed are FortiNets'….
j0bwith snort on a pc
toastryou can have snort+barnyard+snorby setup in a couple hours
j0brun in production were we had it distributed
j0bnot even then
MrJayPCNot had a problem with it at home :|
void64Captain_matrix: it all comes down to how much money and time you have to throw at it
toastrthere's always security onion if you want something that has most if rolled up already
Captain_matrixvoid64: time plenty ,money none :P
void64Captain_matrix: then take toastr's advice
toastrj0b: you can get pretty good performance if you have multiple instances running
Captain_matrixso normally you just copy normal traffic to a snort server and it just generates reports?
void64I love all these enterprises that want network security but don't have a dime to spend on it
j0bCaptain_matrix: port mirroring
Captain_matrixfigured it'd sit somehwere in between transparently and kill connections
MrJayPCYou mean don't want to spend a dime...
Captain_matrixj0b: that's ids though ,not ips right?
j0bids yes
void64Captain_matrix: IDS yes… IPS takes more work
j0bwell both
j0bif you want
toastryou're still going to spend money on signatures if you don't want stuff from 30 days ago
Captain_matrixso are the free rules any good ? or do you *need* the subscriptions ?
toastrunless you're using like emergingthreats open ruleset
SuperNullWhat do you guys do for DOS incidents with link overload ? ex: some ass clown pushing 4gigabits to a 1gigabit device.
Captain_matrixahh,just answered my question :)
void64SuperNull: RTBH
j0bSuperNull: not a PC, thats for sure;)
j0bwell, the packet rate is interesting. 4 gig says nothing because it will handle it self
SuperNullRTBH = ?!
SuperNullim gonna have to look into that.
SuperNullACTION 'bookmarks'
void64We use a combination of netflew at the edge and when we see a host trigger a certain threshold we think is suspect we have a IBGP route server that we can send host routes into BGP which will propagate host routes to null at the borders and upstream
circuitrtbh sounds like tar pitting
void64No it's blackholing
void64no tarpit about it
circuitahh i guess youre right
SuperNullso your upstream providers accept /32 routes ?
j0bnetflow is a must if you should deal with these things
void64If you mean by tarpit just gracefully rejecting ot dropping traffic
void64SuperNull: Each ISP is different, most will accept a /32 route with a blackhole community
j0bhave tried to get my former employees to understand that
j0bbut no
void64SuperNull: we use an internal community that gets translated at the edge for each upstream connection to trigger their community
j0bvoid64: what do you use for analyzing tool for netflow?
SuperNullj0b good question
void64Some providers like Cogent use a route server instead
j0bsearching for a good open source one
void64j0b: flowtools
j0bis the best from what i can find
void64ntop: can't handle our traffic volume
j0bvoid64: can not parse the netflow file or what?
void64we use "flowd" (freebsd port) which does the collection
void64then we use perl flowtools to parse what we need
squibbyI like flow-tools
squibbyalthough the version that seems to be in the package managers of teh linuxez is the buggy version
squibbyso I end up downloading it from google direct
void64flowd comes with flowd-reader ….
void64the biggest PITA is figuring out the right sampling-rate for your traffic… not to overload your linecards or your flowd receiver
MrJayPCThese Superchargers are veritable electron fire hoses, delivering DC energy directly into the battery at rates up to 80 kW, bypassing the on-board 10-kW (or optional 20-kW) inverter(s), and gaining 150 to 160 miles in range in 30 minutes. As Tesla says, stops on long drives often take that long anyway, if you use the bathroom, stretch, and grab a snack.
SuperNullwhat kind of hardware horse power is needed for netflow receiver ? nothing really?
void64I think we only sample 1 in 1000 or maybe 1 in 10000 packets
MrJayPCOuch.... that's a fast charge o.0
void64superNull: depends on how many flow samples you're collecting and sending
SuperNullwell fuks.
void64SuperNull: how many edge router devices, and how many PPS you're sampling
void64I can tell you
void64flowd is by far the fastest and most lightweight
void64nTOP is a pig
SuperNullvoid64 we gotta get our netflow up DDOS is becoming more and more a problem..
void64good for smaller connections but not service provider 10GE uplinks
oistergoing through some old junk and stumbled upon a fasthub 400
MrJayPCI stopped using nTOP at home because it was such a resource hog
void64SuperNull: I sleep better at night with RTBH setup
void64knowing I can mitigate a target almost instantly
SuperNullvoid64 we canceled a customer for pissing off someone on xbox..
void64SuperNull: sometimes you have to
SuperNullcall of duty or something.. they admitted it..
SuperNullparent calls in 'my stupid son blah balh'
SuperNullnow hes cool with her being at my house
SuperNullMrJayPC im the kind of dick head that would of smeared it all over to the point she would of just thrown the jacket out
SuperNullnot sure if boss shitting, masturbating or doing lines
SuperNullhe literally was causing noise to come from the bathroom like he was moving around a lot
SuperNullaparently he lost 4k in cash sitting 'in the center of my truck'
SuperNullhe moves out after this ..
void64oh boy
kmcelroy1fun times
SuperNulla month after that..
SuperNullmysteriously another 3k goes missing from his truck
SuperNullhe blames my co-worker again.
squibbygot yourself a bonus incoming?
sartannot sure
sartani hope so!
squibbyor maybe a nice sack of shit wrapped up in a box
sartansalary increase comes as part of this
sartanapparently i pissed some people off
sartanwe'll see.
Harlocki had those recorded ones you have one a trip or free airmiles or something
squibbyI didn't get a salary increase this year because I was "too new" when reviews came around
sartani did get a bonus yesterday thoguh
Harlocki hit 9 to connect to someone them put the call on hold
squibbysartan: do you have to fill out any of those self appraisal forms
Harlocki should make a custom hold audio fine for them
squibbysartan: I just discovered that lovely system this year too
squibbywhat a pain
sartanbeen doin it everywhere for yeras
sartani have lots of reports to fill out.
sartanit takes a lot of time
squibbyfuckin' nonsense
squibbyis that a bank/finance thing?
Harlocki also gets calls at work from telemarketers who claim to hp
MrJayPCI wish I got a pay rise from my review
circuiti wish i had a job
kmcelroy1you do have a job, you are a circuit
sartanwhat, reviews?
sartani hope you're being reviewed.
kmcelroy1i wish i had reviews, ha
kmcelroy1but i got a nice bonus beginning of this year, so maybe that will keep up
adaptrthe year ? or the bonus
kmcelroy1the bonuses
kmcelroy1if all goes well we are supposed to get 4 a year
kmcelroy1but they have been on a spending tirade
MrJayPCI had my review last week and my manager couldn't find anything to fault me on my performance :/
sartanmy boss always finds picky shit
RedShifthey guys, anyone got AIR-CT2500-K9-1-9-0-0-FUS.aes?
kmcelroy1so he blew you then called you a fag?
sartanis that an AP firmware?
RedShiftAP controller firmware
RedShiftField Upgrade
squibbyyeah I got a pretty stellar review as well
sartanshouldn't your controller just push whatever firmware as applicable
squibbybut they said I was fat and kind of a dick and I should work on that
kmcelroy1squibby: sounds spot on
sartani do well enough on my reviews, but the consensus is i can be arrogant
sartanwell, i'm just better than you.
squibbykmcelroy1: I made that last part up
squibbyit's true but they didn't say that
kmcelroy1the part about you working on it?
RedShiftsartan: it's not for an AP, it's for a WLC
squibbykmcelroy1: lol are you mad at me today
squibbyI can feel the tension oozing out of my monitor
kmcelroy1ha, nah, just tugging your nuts, i'm bored
sartanRedShift: guess i'm confused
ehnde"ou need to assign the IP Address to interface FastEthernet0/0 as well ass hard code"
ehndemaybe a little juvenile but i'm amused
pffsbonuses would be nice
circuitan income would be nice
kmcelroy1circuit: i get the feeling you are jobless and want that to stop, am i on the right track here?
circuitkmcelroy1: well im a student so at the moment being jobless is kind of normal lol
circuitalthough im graduating in august
pffsgod dammit CCX
pffswoooo finally got the editor working
squibbyso I went out to my car to get my lunch and this happened today. please also take note of my ms paint skills. http://imgur.com/QKKl0L8
kmcelroy1are those makeshift balls?
squibbyI dunno it's pretty good though I like it
squibbyI should switch professions
squibbyI think I'm going to print this out as is and stick it on his car
kmcelroy1you should find a job where you can draw dicks and balls on things
kmcelroy1i think you missed your calling :P
s1skosquibby, why did you block the blue car? :)
squibbys1sko: I'm sure if you repeated that question to yourself a couple of times you'd figure it out
s1skojust kidding ;)
circuitthe right testicle looks like a halo2 helmet
squibbylol what
kmcelroy1or does the halo2 helmet look like the right testicle?
kmcelroy1that is the real question here
squibbyI think technically it's the left testicle. from a pov standpoint
circuitok now youre just being picky
squibbyI mean fuck that guy
squibbylook at the size of that space
s1skoI think its the bad influence of the car that makes him a shitty driver
s1skowe have a lot of those people here in DE
circuitsquibby: that happened to me at school about a year ago.
circuitwanna know what i did?
kmcelroy1bmws start eating at people's brains and causing them to forget how to park
circuitnot forget to park, forget how to give a fuck about other people
kmcelroy1nah, they probably never gave a fuck about other people
kmcelroy1that is generally how you end up in a BMW
circuitjesus that is so fucking true
squibbyone of my friends is a fancy car dbag
circuitremind of me people who own macs
circuitfuck them
GraNNy-I own a mac, no bwm's
squibbyinstead of a house he decided to get a 100K nissan
GraNNy-what are you, linux fanatic?
SuperNulli feel old looking at these magic cards that came out that are new to me..
squibbyGraNNy-: did you see my link
sartani'm a linux fan!
SuperNullin 2011 :( im old.
GraNNy-squibby: nope, re-url?
GraNNy-went to lunch
squibbywhat should I do
s1skoask the reception to call him "because he left the lights on"?
s1skojust for the lulz?
ehndei've got a macbook at work and it's a piece of crap
ehnde2010 macbook
ehndeso slow
GraNNy-ok, that wasn't the most horrible parking. I thought I was going to see someone doing an almost 45-degree parking
squibbyI can't get in the car!
myndsquibby: should glue the handle, or put gum (or something sticky) under it :-)
circuitrofl ^
circuitgum under the handle is actually perfect
GraNNy-squibby: aaaah, context
squibbythese aren't compact spaces or anything
GraNNy-squibby: always have chalk in the car
kmcelroy1shove razor blades under the handle
GraNNy-squibby: chalk the pavement with "asshole" take a picture, and viral it
MrJayPCI once keyed a BMW ;o
kmcelroy1go buy some lye at the store and use some petroleum jelly to hold it under the handle
kmcelroy1that would be hilarious
s1skoI mean if you look for retaliation...find is edge port :)
GraNNy-squibby: another thing you could do is put up a fake parking ticket
circuitsquibby: do you have any idea who it might be
void64any good disaster movies coming out worth a damn?
squibbyno I already asked facilities and he says he's not any of our plates
circuitthat means open season
MrJayPCGo get a big truck and drag it somewhere
kmcelroy1cover it in gasoline and light it on fire
GraNNy-borrow some lipstick and put "park better asshole" on his front windshield
RedShiftset the world on fire, aye aye aye
circuitall valid solutions
FungiFoxfor a cisco tech....
GraNNy-squibby: so no way you can in through the other side door?
kmcelroy1you could break into the car, hide in the back seat and kidnap him, then rape him
FungiFoxkmcelroy1: is thinking arch now.
FungiFoxlinux distro.
kmcelroy1yea, but that was random
squibby GraNNy- oh I can
RedShiftwhat if you just leave him an angry not?
RedShiftyou know, be canadian about it
MrJayPCHow smooth is the carpark surface? Go get a couple of big trolly jacks then lift the whole thing and move it ;)
RedShiftwrite a strong worded letter
GraNNy-kmcelroy1: the AIDS dude, the AIDS.
FungiFoxMrJayPC: lol, grand theft auto charges and everything.
MrJayPCAnd just for extra lolz leave it on brick stacks
kmcelroy1i am confused
MrJayPCMotor vehicle theft (sometimes referred to as grand theft auto by the media and police departments in the US) is the criminal act of stealing or attempting to steal a car. <-You're not stealing it, just moving it lol
GraNNy-squibby: if he had his windows cracked, maybe a small baggie of baking soda and a call to the cops saying you see drugs in his seat?
s1skolong term strategy: wait until he parks tomorrow and block his car in return - but leave very late
circuitGraNNy-: fuck that if youre going to do this use real drugs
kmcelroy1other option, duct tape nails to the ground behind his front tires
MrJayPCWe used a forklift at work one day to move a customers car
GraNNy-squibby: got any friends on /b/ ?
kmcelroy1or remove his valve cores, that is hilarious
SuperNullwhat the fuck ? http://imgur.com/JpxwXr1 how does the latency and the jitter graph make any sense in correlation to each other?
squibbyGraNNy-: lol no
Bluedog2ton of mac hate here, lol
squibbyI'm too old for that shit
SuperNullkmcelroy1: you know RFC2544 testing ? http://imgur.com/JpxwXr1
Bluedog2SuperNull: that a provider link ?
Bluedog2good performance there, lols
SuperNullthat is a small radio link
SuperNullonly good for 50megabit aproximately.
Bluedog2that makes more sense.
kmcelroy1what exactly are you worried about?
SuperNullwe have it split 25/25 meg
squibbyyeah what's with all the mac hate anyway
SuperNulllook at the jitter vs latency
SuperNullhow does that logically make sense.
kmcelroy1does it measure them at the same time or separate measurements?
Bluedog2SuperNull: is that averaged out
Bluedog2or just a single snapshot
Bluedog2that seems off to me
SuperNullyou would expect the latency and jitter to correlate linearly together some what?
Bluedog2unless you got some jacked up transport gear in the middle that can't handle variable frame sizes too well
kmcelroy1assuming they did the measurements properly :P
Bluedog2SuperNull: not necessarily
SuperNullthis is a bench top test..
SuperNullend to end with a loopback
SuperNulland a legit rfc2544 meter
Bluedog2SuperNull: that gets into specific performance characteristics of how each vendor handles certain packet sizes, etc
kmcelroy1SuperNull: and i see your note on the bottom homo :P
void64Radio links are generally half duplex, no?
SuperNullvoid64 this is TDD.
SuperNullso .. yes... ultimately.
Bluedog2void64: ive ususally dealt with gear with 2 separate channels.
SuperNullif its microwave its FDD
SuperNullkmcelroy1 what ever are you talking about
void64Yeah my knowledge for wireless ends at WIFI so, got me
SuperNullthis is not wifi .. for sure.
SuperNullits actually 'cell' or atm based.
Bluedog2sidenote: I find it funny everyone doing microwave from CHI to NYC to beat fiber route latency
SuperNullor at least it was..
Bluedog2for their trading bullshit
void64Is that one way latency ?
SuperNullbluedog2 in theory microwave is about the same speed... if electronics dont slow it down much
SuperNullwe got a request for it
SuperNulli laughed.
squibbyyeah. signals propagate faster through the atmosphere than fiber
Bluedog2SuperNull: true, but they are pointing it directly at NYC rather than any physical turns for whatever reasons
Bluedog2squibby: i dunno aout that
SuperNullsquibby faster due to direct shot vs .. fiber route
kmcelroy1i think it is probably more because the microwave is a straight shot and the fiber link has hops
Bluedog2its a matter of physics, fibers go all over the place due to logisitical reasons, microwave can be shot *
Bluedog2kmcelroy1: yeah
SuperNullyou wouldn't make a direct shot without hops kmcelroy1.
kmcelroy1which means the fiber is probably a longer distance
SuperNulllongest range microwave stuff is like 100miles~
kmcelroy1maybe they do some mega tower shit, i don't fucking know :P
Bluedog2SuperNull: people have gone as far to lease repeater space
kmcelroy1but either way, the fiber will be a hodge podge
SuperNullnah they just back to back dem bitches.. and its still less distance
chumpnot if you build an express route
Bluedog2i express route all my packets
Bluedog2the toll fees are a bitch
chumpthose algorithmic traders pay top dollar for microseconds
Bluedog2chump: which i think is a matter of debate in regards to actual value (why are we jerking over .001 second... srsly)
Bluedog2but i digress
SuperNull$crye where are you
chumpBluedog2: because they can get their massive trades in before the competition
SuperNullScrye may know some things about dat HFT
chumpand influence pricing
SuperNullchump better yet its probably an 'order' or 'program' to do so.
SuperNullhigh end traders have on site equipment
kmcelroy1more you catch the trade at a different price and can see it higher or lower on the other spot, thereby knowing the future if you will
Bluedog2chump: oh, i know the technicals fairly well, i just think it is kinda silly how fast it is going
chumpyeah right in the exchanges
SuperNullIts theft.
kmcelroy1only from other trades, so no one cares
SuperNullit affects everyone ?
chumplondon to frankfurt is another big one
SuperNullisnt that smaller than the US is wide.
SuperNulli think the better question is..
kmcelroy1i think he meant big as in popular
kmcelroy1since london is a major financial center
SuperNulloh oh.
SuperNullcity of london mmm
FungiFoxneed quantum bit computer to do my stock trading.
SuperNullno need, start a central bank, print all you need.
Bluedog2i understand the need for liquidity, but i feel that is becoming a way to hide the real gains
FungiFoxi buy em all and nothing at the same time.
Bluedog2(for them)
chumpI'm at about 17ms from CHI/NYC
FungiFoxwhat you ping?
chumpI mean our fiber route
chumpfor ultra low latency
SuperNullso kmcelroy1 if we put a mask on you, are you down with the gang bang?
chumpstandard is about 23ms
chumpNY to London is about 64ms
SuperNullone of our vendors was telling us how they had to make special radio firmware for the HFT people..
kmcelroy1SuperNull: all you man, all you
SuperNullshe only has one version of hepatitis right?
kmcelroy1that will be a surprise for you
SuperNullthe HFT stuff was much slower throughput but removed all the forward error correction and massive buffers so that it wouldnt add any crazy latency.
SuperNulli will bring my portal hep C test with me.. just gotta remove some scab juice
SuperNullthe new microsoft CEO makes me think 'apple'
kmcelroy1he is like a brown steve jobs
SuperNullmaybe he will introduce the microsoft newton.
GraNNy-so is anyone here going to NANOG in ATL?
GraNNy-guess not
eirirs_whats it
SuperNullgranny- they dont let the real engineers go to shows here..
GraNNy-eirirs_: like RIPE for the americans
squibbyso I guess republicans are pissed off at coca-cola for some commercial
squibbynot feature 100% english in
GraNNy-squibby: http://publicshaming.tumblr.com/post/75447787843/speak-english-racist-revolt-as-coca-cola-airs
GraNNy-it's amazing what stupid crap people will say on twitter
void64Need to check the NANOG schedule.
sartanhmm cisco might give me clcs to hit up live this yera.
void64How much in credits is a live pass ?
sartani don't know, id' have to look it up
sartan1:$100 ?
void64I'd have to check the balance of credits we have ….
void64No I think it's more than that
void64I could be wrong
void64actually that might be about right, so probably like 30 credits?
RedShiftanyone got 2960G switches in production?
RedShiftare they still any good?
jamesdRedShift: i'm sure many people do..
GraNNy-define "good"
kmcelroy1GraNNy-: not bad
GraNNy-kmcelroy1: I don't think i've seen a cisco switch be "bad"
GraNNy-well, i take that back
kmcelroy1the 4948 is kinda lame :P
kmcelroy12960 lan lite
GraNNy-2948g's were crap. and the 3524xl/3548xl's were terrible.
kmcelroy1that was pretty lame
RedShiftwell there was this one series that had bad powersupplies
mAniAk-_1GraNNy-: 2960 and 2960g are pretty shitty
myndGraNNy-: i concur
RedShift3560G's I think?
myndhad quite a few 3500XL's at last gig ... always had issues with them
void64I like the 4948E's
void644948E-F anyway
GraNNy-OTOH, cisco > Extreme any day of the week
Titaniumveers hey
Titaniumyou pass?
void64I'll tell you though, performance wise, Brocade CES vs a 4948E I think the CES still has an edge.
void64But software feature wise IOS still kills Brocade
RedShiftIIRC 2960G isn't wirespeed?
void64I actually miss the Foundry days, I think Brocade has dropped the ball on their Ethernet R&D
veersTitanium: next Friday
void64I know they have on their ServerIrons… they're getting crushed by F5 and A10
veersthat's D Day hahah
drkatshit i managed a network for 3548's
drkatand 3550
hkkli think we only have 3548s and other XLs in oob network anymore
j0bgreat switches
hkkli think last was decommissioned from production network year ago or so
hkkl3550s are still used for production and oob network :)
j0bused 200 of them, then we switched too 3560
jamesdACTION uses 3550's for production i my home network... but i'm a crazy geek
j0bproduction and home network... i dunno:p
j0bdoesnt sound right hehe
j0bno offense
kmcelroy1offense taken
Dez_Bryanthello all
Dez_Bryanthow is everyone doing?
j0bkmcelroy1: :(
GraNNy-Dez_Bryant: HTTR!
jamesdj0b: the more your family depends on it the more it feels like production... kids can't get to facebook or email and they would put in a critical ticket if i had a ticketing system ;-p
Dez_Bryantwould anyone here be willing to offer me some career advice
Dez_Bryantbecause i am n00b
j0bjamesd: true true:D
GraNNy-Dez_Bryant: what do you want to know?
mepholicvery noob choice
kmcelroy1sure, don't get into IT, be a banker, make money, get bitches
jamesdDez_Bryant: mcdonalds.com
drkatDez_Bryant goto college
drkatget an MBA
GraNNy-you guys are terrible :P
Dez_BryantGraNNy-: basically, how do i get my manager to give me the engineering position i deserve
kmcelroy1GraNNy-: you mean we are right? :P
drkatDez_Bryant suck him off?
GraNNy-Dez_Bryant: you leave for a better job
jamesdj0b: thanks, i am a whole, aka contractor, i will do anything, just approve my paycheck
Dez_BryantGraNNy-: but how am i supposed to get an engineer job without an engineer's experience?
mepholicDez_Bryant: leave for a better job
Dez_Bryanti've been trying to move up but my manager is making it impossible
Dez_Bryanti don't want to move vertically in my career....
mepholicDez_Bryant: how did I do it?
GraNNy-Dez_Bryant: leave, your manager is not letting you grow
kmcelroy1you mean horizontally?
j0bDez_Bryant: just leave
GraNNy-what do you do now
mepholicnone of my past titles have had the word "engineer" in it
j0bhave been in the same situation
mepholicmy current title does
kmcelroy1vertically seems like the move you want to do
Dez_Bryantkmcelroy1: yes horizontally
drkatim a big fan of lateral
j0btheres always jobs in IT
j0bfo real
mepholicand it doesn't even have the word "junior" next to it
kmcelroy1just leave
GraNNy-Dez_Bryant: what do you do now?
kmcelroy1or take my real advice and be a banker
Bluedog2IT is one of the few fields where upward zigzaging at the beginning of your career isn't frowned on.
Dez_Bryanti've just invested so much of my time and energy and they won't give me the damn engineer role
Dez_BryantGraNNy-: NOC :(
kmcelroy1make money, get bitches
GraNNy-Dez_Bryant: do you have enable?
GraNNy-NOC isn't a bad thing
Dez_Bryantenable? like enable access?
Dez_BryantGraNNy-: yeah but i only have NOC experience... no engineer experience and i want an engineer job!
Dez_BryantGraNNy-: yes
GraNNy-Dez_Bryant: dude, I could give a shit at that point.
GraNNy-interview for engineer jobs
Dez_BryantGraNNy-: but i've never touched the "important protocols" in production
Dez_Bryantthey'll never hire me
GraNNy-well, if you have that attitude, you won't
Dez_Bryantwell if looking for a new job is all i've got then i guess i'm going to have to do that
GraNNy-listen, you are in the NOC and you can troubleshoot things right? Are you good at troubleshooting?
Dez_Bryant /sigh
jamesdDez_Bryant: do you have a server that you work with?
Dez_BryantGraNNy-: yes i am
jamesdor cisco gear...
drkatlets not bring the NOC into this
Dez_Bryantjamesd: i have a lab at home. i have a CCNP just no experience to back it up... i THOUGHT i would get that experience when i get moved up to engineering. but after 5 years my manager is still saying there isn't a position open
Dez_Bryanti only have shitty NOC monkey experience
GraNNy-5 years? who stays at a job for 5 years?
drkatDez_Bryant look my resume is like 80% fabrication cuz of the HR monkey requirements, just wing it
drkatGraNNy- people who dont contract?
kmcelroy1i will have been at my job for 3 years next month
GraNNy-drkat: most people stay at a job at most 2 years and then jump in IT
Dez_BryantGraNNy-: what? no way
GraNNy-Dez_Bryant: where do you live?
Dez_Bryantthe newest guy in my team has been here 2.5 years
kmcelroy1people move around a lot in IT
Dez_BryantGraNNy-: i live next to Fort Hood, TX
kmcelroy1it is like sales, people move back and forth
Dez_Bryanti wanted to stick it out until i got that engineer opportunity because people told me to get out of the NOC monkey rut i needed to move up within my own company
GraNNy-you are like 60 miles away from austin. get a job there and have them help pay for moving expenses.
jamesdDez_Bryant: look on job boards... apply, bullshit HR, (you helped a number of small clients setup there small bussiness networks, did a few Proof of concept, nothing more that a week or two), impress the other engineers with your knowlege, poof your an engineer.
Dez_Bryantnow i'm 5 years older and still no engineer job and no engineer experience to get the job
Dez_Bryanti feel so cheated
Dez_Bryantand frustrated
drkatoh god
squibbywhy are finance department people so socially awkward and awful
GraNNy-Dez_Bryant: are you a troll? the woe is me is getting old
drkatDez_Bryant - well you're gonna have to umm.. fake it til you make it
kmcelroy1should have been a banker
void64Rackspace is going gangbusters hiring people in Austin and San Antoinio
squibbyevery god damned time I'm near the CFO's office he wants me to provide a cost and benefit analysis on a service we're using
jamesdsquibby: they ask the same about IT guys.
squibbyand I'm not even the damne cto - dude needs to fuck off
Dez_Bryantjamesd: i can't just lie...
kmcelroy1lie bitch
kmcelroy1lie through your fucking teeth
kmcelroy1get paid
jamesdDez_Bryant: you are stretching the truth... its just to get past HR, the engineers will test your knowledge.
myndjust over emphasize
kmcelroy1capitalism rewards the biggest douche, so get on board
drkateither lie and get the job, or be honest and be unemployed
drkatyour choice
squibbyjamesd: he wanted to know why we have to put up with archiving with the o365 system and then launched into a series of questions about how it saves the company money or benefits us somehow
jamesddoing a lab is like setting up a bussiness lan, just you didn't get paid for it.
GraNNy-oh please, I don't think i've ever lied on my resume. when they asked, i told the truth, but spun it positively.
Dez_Bryantwow that sounds terrible but i guess it's my only choice
Dez_Bryanti guess that's what i needed to hear
Dez_Bryantthanks guys
GraNNy-Dez_Bryant: you need a career counselor
jamesdGraNNy-: i am doing the same... i did everthing i have said just did it for my self for fun, and didn't get paid...
drkatGraNNy- so when asked about a tech you've never used before?
kmcelroy1you need to just learn to do whatever benefits you the most :P
GraNNy-drkat: i don't put it on my resume?
void64Lying on your resume just to get in the door can be disastrous… lol
void64Especially for a experienced engineering job
kmcelroy1shit, there are people who make 25 year careers off lying :P
Dez_Bryantvoid64: and that's what worries me
kmcelroy1and still keep getting jobs
Dez_Bryantvoid64: but i guess i can "over emphasize"
GraNNy-kmcelroy1: yeah, sociopaths called CEOs :)
drkatGraNNy- well here's a perfect example of some of the jobs that are posted. Half the technologies he's never done?
drkatso how is he suppose to get the interview
drkathe doesnt have those skills
GraNNy-drkat: because he's still got half. dude, most jobs reqs are bullshit
jamesdvoid64: proof of concept contractor... (fills the 18 month gap when no one was hiring ) and just documents anything fun i played with while unemployed...
void64The larger the company the more resources they have to confirm your history/references
Dez_Bryantdrkat: i have them but only book knowledge
tgunris there any way from a 7206 to see if a dhcp mac-address bound address has been issued to the client?has been
Dez_Bryantfrom my CCNP studies
Dez_Bryantwhich my manager told me to get so i can move up to engi
GraNNy-drkat: you find the hiring manager on linkedin and talk to him/her instead.
GraNNy-i can't remember the last time i submitted to the HR blackhole
drkatGraNNy- I tend to be told to apply online and HR will be in touch with that method :)
Dez_BryantGraNNy-: so you just contact people directly? instead of spam clicking jobs on indeed/monster?
drkatthey're probably being nice
kmcelroy1drkat: gotta show
void64Interviews are usually three part when I get them, phone with the recruiter person, then they setup a general Q&A with other leads to make sure you're not an idiot before they invite you in for an actual… Some interviews are straight forward others will be like a SIX HOUR process.
drkatkmcelroy1 ?
GraNNy-Dez_Bryant: do you know how many people spam click that shit?
kmcelroy1gotta show some balls man, then you get in the door
drkatshow my penis?
kmcelroy1or sack
jamesdvoid64: i don't list it on the job app just my resume... everything is verified, by that point i have a job offer, note i didn't say i made money doing it, just a few small contact deals.
kmcelroy1nut cleavage
Dez_BryantGraNNy-: a million i suppose. what's the best method if yo don't mind sharing
void64I heard the Rackspace ones are fucking six hours! WTF… If I'm there six hours, i"m getting paid lol
GraNNy-Dez_Bryant: search for the company and see if you can find CTO / CEO / VP of IT/Engineer. Then either email firstname.lastname@company.com or contact them via linkedin.
kmcelroy16 hours for a fucking interview?
kmcelroy1jesus christ
Dez_Bryantwow! aiming for the CTO/CEO? jeez
kmcelroy1i'd tell them to suck a fucking cock
void64I've been contacted from AWS recruiters, to bad the only positions they have are in Seattle
void64Yeah no shit, seriously
jamesdgoogle used to fly people out to the interview it took all day, and people used flew in the night before all paid
drkatwell in larger organizations CIO dont care bout you
drkatgood luck with that
generalshenanigaAnybody experienced with PCI security? Do I *have* to get a dedicated firewall, or will a 2901/K9 suffice?
squibbygeneralshenaniga: that's a fairly vague question
generalshenanigapretty simple setup... DIA with a /29 of public IPs
generalshenanigaPCI scope will be limited to a single IP based credit card terminal
generalshenanigaalready planning to create a separate VLAN for the cc terminal, NAT to one of the public IPs, and using SPI... is that sufficient?
generalshenanigaso in theory there's full logical isolation between the PCI scope and the rest of our equipment (one internal server, a few workstations, and wireless)
squibbygeneralshenaniga: PCI assessments usually include a questionnaire that goes over their network security expectations
generalshenanigaI was told by our payment processor that they have to do a "scan" of our network (public IP) before we can start using it
generalshenanigadefinitely not the self-assessment obne
drkatgeneralshenaniga that would satisfy most PCI audits
squibbystep 1) complete questionaire. answer yes to everything. step 2) hire a bullshit automated penetration testing firm like scansafe to scan your public IP and give you a thumbs up
generalshenanigaThe weird thing here is that our payment processor seems to want to do the scan on their own, and require that before they'll release any funds to us from it
squibbytotal fucking scam industry
drkatgeneralshenaniga they will run a vulnerability assessment
drkatmost payment processors do it to give you the thumbs up
squibbyprovide snakeoil security audit results - rinse and repeat - profit
drkatyeah i had a customer dinged on a open web port
drkatthat was for like a HVAC machine
generalshenanigaMy net eng mentioned that one of the most common dings is ISAKMP on the default port of 500
squibbyit sounds like generalshenaniga is small business, this is a no sweat ordeal
squibbyoh for fuck sake
generalshenanigaIn this case it's small business, though our main account number with the payment processor is medium sized
squibbysuch bullshit
drkatisakmp is not a violation of pci
drkateven on port 500
generalshenanigaI don't even know what ISAKMP is, but Google tells me it's related to IPsec, which we're not using
squibbywhat you don't want is an onsite auditing team
squibbyif you're large enough to require that, I would hope you'd be a little more familiar with security anyway
generalshenanigayeah, especially with the employees that work there. "What's your password?" "Here you go"
drkatall they need to determine is the CC processor is OFF your regular lan and not accessible
kmcelroy1why would port 500 isakmp be a violation?
generalshenanigaNot necessarily a violation, but something that commonly gets flagged on scans
squibbybecause the snakeoil scan sites need to pretend like they're doing something
kmcelroy1seems retarded :P
squibbyhave you ever done PCI?
squibbyit's a joke
kmcelroy1i haven't
generalshenanigaNext question- I have a 2901 and a 3560G (layer 3)... 2901 will be used as a voice gateway. Where should I put the NAT configs? on the 3560? (No NAT needed for Voice, just data)
generalshenanigacan a l3 switch do NAT?
kmcelroy1i don't believe the 3560 can do NAT :P
kmcelroy1but i honestly don't remember
bmoracacan it?
bmoracai didn't think it could
bmoracalast i checked, the 4500 couldn't even do NAT
kmcelroy1i think you are correct
generalshenanigaI've got it set up as ROAS. Thinking of treating the 3560 as a l2 switch
kmcelroy13560 should stay layer 3
kmcelroy1be your internal routing
kmcelroy1then use the 2901 as the edge
bmoraca-workrouter on a stick is dumb if you have a 3560 :)
kmcelroy1do your NAT there
generalshenanigawhere would you put your DHCP pools? 3560?
kmcelroy1a server
bmoraca-workgeneralshenaniga: a windows server
kmcelroy1cisco DHCP is a pain in the ass
kmcelroy1but if you must use it, do it on the switch
generalshenanigawe don't do DHCP on the Windows side. DNS is definitely Windows, but our DHCP needs are minimal
kmcelroy1would still do it on the server
generalshenanigawe don't have a DC at that location, don't want to lose DHCP in a WAN outage
kmcelroy1just run DHCP at the central site then
kmcelroy1dhcp relay
SuperNullcisco routers can use a remote dhcp 'database' file.. not sure what happens if you lose connectivity to that database
generalshenanigaYeah, that's my worry. especially when our phones use SRST, local DHCP is a must
kmcelroy1put a 24 hour lease on
kmcelroy1or longer
kmcelroy1not like they are getting new addresses 24/7
generalshenanigathis is true
SuperNullyeahhh could always do week long leases and cross your fingers you never lose the database.
kmcelroy1what database?
kmcelroy1no one wants to run your weird remote dhcp bullshit :P
kmcelroy1he is talking about host DHCP
SuperNullthe lease database..
SuperNullbe it file, or memory.
SuperNullits a nightmare if you lose it with a shit ton of time left on most devices.
kmcelroy1the lease database would be in the god damn server, not the router you gomer
kmcelroy1pay attention
SuperNull<-- run dhcp network for 20k-30k devices devices
SuperNullkmcelroy1 thats the point .. hes saying he doesnt want centralized dhcp
kmcelroy1he probably has like 20 devices there
SuperNullcause loss of connectivity
SuperNulldevices devices!
kmcelroy1which doesn't matter, just run long leases
kmcelroy1if your IP link is down more than 24 hours, you have bigger problems
SuperNullwhat happens if all phones get the lease the same time and boom miraculously the fail happens as they need to renew
kmcelroy1that won't happen
kmcelroy1and if it does, setup a local lease in 30 seconds and move on with your life :P
kmcelroy1also, SRST is a waste of time :P
squibbySuperNull: I want you to know I get it but I didn't laugh
sartansrst is not a waste of time
sartanare you kidding
kmcelroy1it is
sartanACTION cracks knuckles
kmcelroy1no one uses it
SuperNullsquibby did you happen to watch 'in living color' years ago ?
kmcelroy1they just like buying it, cause on paper it sounds neat
sartanwell, i'm using it
sartansaves my ass
squibbySuperNull: yes - that's why I'm letting you know I got it
kmcelroy1to do what?
sartani don't want to pay for a subscriber server fuckign everyhwere.
toastrwe use it to and it has saved the bacon
sartanyou go ahead and take calling ability away from people who bill at 1500 dollars an hour.
sartanI just dare you!
sartanany environment that doesn't deploy srst is immature and run by wannabes
SuperNullsquibby one of the common customer tech support phrases used to be 'ride the snake'
squibbyyeah I'm afraid I don't know that skit
SuperNullsomeone should overlay IT support audio http://www.youtube.com/watch?v=PlLPogmB8M8
squibbyI know homie the clown and fire marshall bill
SuperNullsquibby it was a skit for methamphetamine as a weight loss supplement..
SuperNullthe skit with the old man dragging a dead dog around used to crack me up as a kid. unfortunately im not a kid anymore.
pffsYou know what's awesome?
dwxreaperthe juicer one is the best, jim carrey as the juice man?
pffsCelebrity Jeopardy.
pffsHow great was that shit.
egadsonI'm trying to set up OSPF at two different sites. Should each site have its own area 0, or should I put area 0 at the L2L VPN connections on each ASA that are connecting the private networks between sites?
pffsegadson: are they on the same ospf?
KickStarRabbithey yo
egadsonpffs: not currently...wondering if I should set them up as separate ospf networks
egadsonor ospf instances rather
egadsonASA L2L VPNs connect the sites -so I'm not even sure I could set those L2L VPNs up as part of the OSPF network since the ASAs won't have an IP interface on the L2L nets
kmcelroy1you will do separate as the ASA won't pass the routing info across
kmcelroy1you can use reverse route injection and redistribute the static into OSPF
baristatamis there documentation somewhere where I can show the tech that "activation key not valid" on the ASA is only for the sec+ license
drkatsh ver?
baristatamdrkat, sh ver doesn't really prove anything, especially since NOW it has a beefed up license
drkatwhat are you specifically looking for?
kmcelroy1have you tried farting on it
baristatamtech claimed he couldn't do his job because it said ""The Running Activation Key is not valid, using default setting"
baristatamand I want to contest the bill
baristatambecause he's retarded
squibbywhat security level did he order
drkatshow activation-key detail?
baristatamall he was doing was setting up a s2s VPN he didn't need any advanced features
squibbyASAs have varying feature keys. what did he specify in his ordewr?
kmcelroy1that error should be related to the 3des/AES license from what i can see
kmcelroy1which means he wouldn't be able to do the VPN
kmcelroy1get your license, fix your shizzle
kmcelroy1he was probably right
squibbyASAs should do like 10 ipsec tunnels with base license
squibbywhat model?
kmcelroy1if you lose the 3des license, you won't be able to do shit from what i remember
kmcelroy1i have had to recover one before
squibbyand you typically need to license 3des and aes separately, yeah
sartanhow could you lose a license?
baristatam"It indicated "The Running Activation Key is not valid, using default setting" this will not allow me to save any config on the ASA after a reboot and would cause multiple re-configs in the future with this not fixed"
baristatamI think you misunderstand squibby
squibbyunless he's happen with DES
kmcelroy1sartan: you wipe the whole thing and it kills the key
kmcelroy1it is weird, but it seems to be somewhat common
sartanodd, haven't heard of that
drkatwell even in the default setting it shouldnt have affected l2l
kmcelroy1mine happened with an upgrade from what i remember
baristatamI ordered the ASA. Base license. It's only going to be used for a s2s VPN. Called a tech to go set up the VPN and that's what he claimed on the bill
baristatamwhen it was just set to ignore system config
baristatamand I changed that
baristatamkmcelroy1, no it was because confreg was set to ignore system config
baristatamIt fixed it, that's all I had to do
baristatamit's 5505 it was a brand new ASA
baristatamonly one VPN needed to be set up
baristatamNo one lost a license -_-
baristatamyou guys are being retarded too
squibbyI wasn't advocating his position
squibbyI was just asking a question
kmcelroy1maybe you should setup your equipment properly :P
baristatamkmcelroy1, why should I set up my equipment when that's what I'm PAYING THE TECH FOR
baristatamthen I would just do it myself
kmcelroy1maybe you should have, ha
baristatamWell I ended up doing it
squibbyso they're just running des on their l2l ?
baristatamI don't know what these words mean
baristatamI bought an ASA so that I could create a VPN from another building to our office. That's all I wanted to happen
squibbybaristatam: des is a really old legacy cipher which is the only thing enabled with the base license
baristatamso are you guys saying I did need the activation key?
baristatamCause Scrye says I didn't
squibbyfor 3des/aes, yeah
squibbyscrye doesn't care about security - has he mentioned this yet?
squibbyhe doesn't give two shits
baristatamwell see
baristatamthe tech claimed he couldn't save ANY config on the thing
baristatamand it was the activation key's fault
squibbyyeah we got that , he's a herp derp and doesn't understand what confreg is
kmcelroy1i was more concerned with the license issue, which was the original complaint :P
squibbywe're just trying to tell you that base license for l2l isn't a great idea
baristatamget your order squibby ? ;)
squibbybaristatam: I haven't paid yet.
squibbyI'm being a bum
squibbyI'll paypal it today or tomorrow
baristatamwell did you get the picture?
squibbyhah. no.
baristatamaw damn I ruined the surprise
squibbymaybe I'll pay now then
baristatamwooorth it
squibbyhe's not planning on e-mailing it right
squibbyI like being married atm
kmcelroy1ass to mouth?
generalshenanigaasynchronous transfer mode?
baristatamsquibby, probably should let him know then
baristatamor just not request things that would break your wife's trust =p
drkatoh you guys
kmcelroy1drkat: i hear some people like their wives :P
squibbybaristatam: you know I did kinda ask in jest - didn't think he'd take it serious
squibbyit's paid btw
sartanlatte, please
baristatamyou very well knew I'd deliver
squibbyI guess there is no not serious with scrye
squibbyoh I see is bmcgahan's pics the surprise?
drkatthat guy
baristatameveryone knows what bmcgahan looks like
mgeorgehmmm got a dmca takedown notice from disney for downloading the movie brave
mgeorgeexcept i never downloaded the movie brave
kmcelroy1that will teach you
drkatyou disney fan
mgeorgeoh yeah you know me
mgeorgefat guy with pop corn watching disney movies haha
drkatbetter than masturbating to said disney movies
mgeorgewife did not download it nor did I
drkatwhile eating pop corn
mgeorgeso either someone knows my wifi key or i got malware on one of my machines
squibbylol it triggered a fraud notification
drkatkid at one of my jobs downloaded book of eli
drkatthe company got a letter
drkatkid was not fired
bmcgahanACTION looks around
mgeorgeoh man who let brian in here?
drkatbut if it were me? i'd have been out the door
mgeorgegot to play with a PaloAlto firewall today
mgeorgequite nice actually
squibbymgeorge: yeah I like mine
squibbygood app firewall
drkatim doing iboss
drkatits neat
squibbysupports GRE and VTIs too
generalshenanigadumb question: router on a stick, trying to add a management subnet, can't get ping responses. created Vlan on switch, trunk interface to router, subinterface on router, but no connectivity
generalshenanigashould I be using a 'switchport trunk native vlan' on the trunk interface of the switch and assign the IP on the main interface (as compared to a subinterface)?
squibbygeneralshenaniga: switches in L2 mode only support one active management SVI
squibbyhave you verified that he SVI is up and up
generalshenaniganot sure on SVI (don't know SVI...), the mgmt vlan is up/down
generalshenanigawould I have to use Vlan1?
squibbygeneralshenaniga: pastebin your switch and router configs
generalshenanigadurr, vlan wasn't allowed on the trunk, just kidding
jatoI had that issue once
jatobut in my case it was GNS3 being odd, I quit and restarted everything and it worked, but for a good 15 minutes I thought I was retarded
squibbygeneralshenaniga: you have int vlan 1 shutdown right
generalshenanigaI do now :)
squibbygeneralshenaniga: bounce the problem svi too
generalshenaniganot sure what that means :X
squibbyoh come on
squibbyshut and no shut
generalshenanigaanother 'durr' moment: SVI = subinterface?
generalshenanigaYeah, not quite CCNA ready yet :P
squibbythe manaagement vlan int
squibbywhat vlan did you put the management IP on on the switch
squibbyright so shut down int vlan 240 and then no shut it
generalshenanigaIt's good to go now, I didn't have 240 as an allowed vlan on the trunk to the router
squibbyI thought you said you were just kidding
generalshenanigaSadly, I wasn't...
generalshenaniganext question: I know how to selectively route traffic based on destination, how about based on source (vlan)?
FungiFox* Received a CTCP SOURCE from Kazfd (to #cisco)
cbt998hi, i'm trying to setup ibgp and exchange full bgp tables bidirectional, is that possible?
sartanthat was.. unusual
sartancbt998: yeah it is possible
sartanbut you might want to be more specific in your design topo
sartangeneralshenaniga: you can do source based routing yes, it's called policy routing
sartanip access-list ext VLAN15; permit ip; route-map PBR_VL15 10; match access-group name VL15; set ip next-hop; int vlan1; ip policy route-map PBR_VL15
j0bkeeping it real
cbt998sartan: well, i have rouer A with 3 ebgp, all sending full tables to that router, router B has 1(different) ebgp sending also a full table, now i setup ibgp between A and B and A is sending B a full table but B is only sending about 1400 routes..
oisterare you using next-hop-self or peering with loopbacks?
sartanall ther otues should be sent but they might not be inserted into the RIB because they're not the best path to that destination
sartanoister: nailed it. was baout to mention that too
sartanadditinoally the ibgp peer needs to know the next-hop of those received routes. in this scenario you'd probably use next-hop-self
j0bterabit: djeeez
j0byou just made a fool of your self
squibbyI've got your CTCP response right here -
squibbyACTION unzips his pants
terabitACTION hides
j0b /exec uname -mrs
j0b23:38 FreeBSD 9.2-RELEASE amd64
j0bthere you go man
terabitdidn't think I'd get any reply
squibbyfuckin' baller status
squibbyfreebsd? j0b doesn't give fucks
j0bkeep it real
cbt998sartan: if i setup a deny all prefix list on router A then a full tables from B is received
sartancbt998: both routers will only install the best route to that destination...
sartanaspath is probably way shorter on A than it is on B?
cbt998sartan: yes
sartanok, so what would you like to change?
sartanyou'll have to influence some of the routes somehow
sartanwhat would you like outbound traffic to look like?
cbt998sartan: to be honest i like to be sure that if maby 2 ebgp connections on A fail, i'm safe and routes will be sent from router B
sartanyea as long as the paths are valid.
sartanon router C (assuming) do a sh ip bgp <prefix> and make sure you have more than one htere both with >
sartan> is for valid, and * will be the best path, and only one of those should be in the routing table (routing information base, RIB) since the router can really only use one right now
yeledanyone seen `no ip redirects' actually adding CPU on a 3750
cbt998sartan: to be clear, B is only sending 1400 routes so there are a couple of > on A
yeledfrom a flat 15% to a peaky 40-60%
yeledcould it really just be all that bad traffic entering and leaving the one interface..
yeledyes, just found some graphs to prove it :(
sartancbt998: ufnortunately this sort of questino is really dependant on the routes you're receiving, but in other words bgp is functioning normally
cbt998sartan: so basically if i want to use the table of B the i need to manipulate routes on A to make them prefer B so B can send them to A - or i nee to get an upstream on B that has a shorter aspath ?
jato_Probably not enough coffee. Logged into one of our internal routers (not a cisco) to find all the firewall rules missing
jato_Turns out I was just filtering incorrectly, they are all actually there
jato_Brown pants moment for a brief second
sartancbt998: right. you can modify the routes by maybe setting a local preference on the received routes from B so your entire ASN prefers one path over the other
sartanyou can do this with a simple incoming route map
xerathjato_: I've found myself nearly calling the NOC in panic because i thought all our BGP sessions were down. Turns out I was logged in to a lab router... Monday morning.
cbt998sartan: to be clear, both routers have the same AS number...
sartancbt998: yup. clear.
sartanno offense but it seems you don't have too much experience with bgp?
cbt998sartan: lab setting :-)
sartanbasically speaking, your entire ibgp routing domain will share the same view of the bgp table
sartanthere are a number of rules in place that tell routers which paths to prefer to tohers, which ones to install to their routing table (they don't have to be installed) and which will be preferred
sartanone of the rules in bestpath is the local preference attribute. a local pref setting will allow your entire asn to prefer a particular prefix over the other, regardless of where it came from
sartanwhat you want to do is assign a local preference of 100 (or whatever) to incoming routes. apply a route map to the ebgp peer on router A to set the local preference to 100, so that those routes will always be preferred to the ones learned from B's ebgp peer
jato_Haha, mornings especially without coffee are the best
cbt998sartan: i think it's clear, B get's routes from A and they are better than the other ebgp that is connected to B so B does not send those routes to A
sartansome of the specific language there doesn't make sense but i think you get the idea?
sartananyway, the great thing about bgp is that everything can be influenced to do what you want it to do
sartanhttp://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080094431.shtml start at 'how the best path algorithm works'
sartanoh, it's a dragon
squibbya dragon. http://www.homestarrunner.com/sbemail58.html
diozsup drkat
drkata whole lot of nothing
drkatclappers to the front
drkatif i counted how many hours I've wasted on irc
sartanif i had time in a bottle
ill_rek_uwhy not both?
MrJayPCAnderson plugs make those vibe things look like toys
GraNNy-KickStarRabbit: ewww, why?
KickStarRabbiti might fall asleep
KickStarRabbitoh hey granny did you get your sec+
GraNNy-O_o sec+ ?
GraNNy-I don't recall talking about wanting to get it?
blackOffonly reason to get that is for microsoft certs
blackOffif you couple it with server+,a+, or network+
KickStarRabbiti am up for a net sec eng position
KickStarRabbitand they want me to know that
GraNNy-KickStarRabbit: usually that means firewall, unless you're going to be doing pentesting or something
blackOffyou should get some LPIC certs
KickStarRabbiti just want the job
blackOffand or just keep going in general
KickStarRabbiti am studying the exam cram
GraNNy-KickStarRabbit: exactly what do they want you to do for a net sec position?
GraNNy-do IN, not for
Titaniumsecurity is fun
Titaniumi found a security flaw and got it a CVE number :)
Titaniumnow i need to beat my personal high score
KickStarRabbitgranny https://megapath.tms.hrdepartment.com/jobs/1327/Network-Security-Compliance-EngineerAustin-TX
blackOffwhat's it pay?
KickStarRabbiti am not qualified for this one but there is a position open 1 level below
MrJayPCCISSP and CCIE certifications or equivalent experience required ...lol
KickStarRabbityeah thats funny
Titaniumcissp is hard
GraNNy-MrJayPC: i was just about to say the same thing
blackOffcissp is good
blackOffthat is the standard
KickStarRabbiti know the sr engineer and he will help me get the cissp
Titaniumbut 5 years
GraNNy-In depth knowledge of information security practices related to PCI, HIPAA, SOX, CPNI, and OWASP application security
KickStarRabbitonce he gets me hired
GraNNy-do you even know unix?
KickStarRabbiti gotta submit my resume asap so am adding a bunch of filler
KickStarRabbiti know unix pretty well
sartani could do that job
Titaniumjust pick 4 letters at random and say you are an expter
GraNNy-this job sounds like they want everything but the kitchen sink
sartanrun the department that does that job
blackOffthat's like a $100k/year position
KickStarRabbiti might have to move to austin
MrJayPCGraNNy-, I was half expecting daily hand jobs to be in there too
sartanso, a huge pay cut?
GraNNy-MrJayPC: lol
blackOffi probably wouldn't take less than 100k for that position
blackOffor more
GraNNy-i have to agree with blackoff
Titaniumyou can find people willing to deal with PCI, HIPAA, and SOX all day for that little?
MrJayPCI just wouldn't take it.... there are easier ways to earn money lol
sartanopen at 145k
sartanlet them negotiate down
KickStarRabbitwell the job below that is maybe 75- 85
blackOffengineers can make less than that
KickStarRabbiti hope I have a in with then already
blackOffbut not for long
sartanthat job posting is like 4 different jobs each one senior
sartanthe hiring manager is pretty insane
GraNNy-KickStarRabbit: i hope you get the job, you'll learn a lot
GraNNy-or blow your brains out
KickStarRabbiti know
KickStarRabbitbrains blown
KickStarRabbiti have read two sec+ books already
KickStarRabbitin 2 weeks
MrJayPCHow did you hear about this job? <-There doesn't appear to be an option for while the job was being mocked in IRC :/
KickStarRabbitthe senior sec engineer reached out to me personally
KickStarRabbitas I lost out on the network service technician already then kinda know me
MrJayPCMust resist jokes....
GraNNy-KickStarRabbit: well, if you have a good reccomendation that will go far
KickStarRabbiti plan to bullshit my way in!
KickStarRabbitwhats an acceptable bullshit ratio on resumes now
GraNNy-i don't think that's wise
blackOfflol, in security?
MrJayPCDepends how stupid you want to look later on when you don't know something you should
blackOffdon't get killed.
KickStarRabbiti assume most of that has got to be hands on
GraNNy-KickStarRabbit: i'd look at what they want in that job posting and figure out what exactly you can do, and focus on those things and tell them that
GraNNy-This role breaks down to 80% project, 20% hands on and will involve a lot of coordination, understanding and communication of security concerns throughout the organization.
KickStarRabbitthat sounds solid
GraNNy-Ability to define security strategies that ensure every client deployed MegaPath application, system design and architectural enterprise security solution design is in fact, secure to industry standards. <--- LOL
sartani tried to hire someone like that with a posting i put up
sartanthose people are really hard to find
sartanif at all
KickStarRabbityeah ... I( maght be in for a "blowing my brains out"
GraNNy-KickStarRabbit: http://securityreactions.tumblr.com/
GraNNy-that might also be a good way to learn. even I don't understand some of the acronyms they use for the security jokes
sartanACTION lhttp://mistrust.ca/static/drop/netsec.txt
dwxreapersecurity is a weird thing you could spend millions and a 14 year old could figure something out. I found a few vulnerabilities over the last few years and updated the vendors. PCI compliance wouldn't of mattered
KickStarRabbitwhose that sartan
MrJayPCWhen manager telling you : “We don’t need SSL on internal network”.
sartanone of my employees, KickStarRabbit
sartanbasically, here's a $desc
GraNNy-KickStarRabbit: do the best you can, if you don't get the job, meh, you'll find something else
sartani hope to get maybe 2 out of 10 requirements
MrJayPC7+ years experience in routing and switching in Cisco IOS & JunOS environments.
KickStarRabbitso should I list certs i am pursuing on resume or is that a big nono
sartanKickStarRabbit: it's irrelevant
sartani'm working on 15 phds
blackOffsartan, you're trying to get 15 phds?
sartanyes, see, it says right here on my resume
freaxdood tbt
KickStarRabbitso a big nono on embelishing on the future
shaunoI'd tailor it to what they're looking for. I've seen a position that required a ccna, but preferred that you were looking toward the ccnp. so I'd parrot exactly that because it's what the HR droid is looking to tick off
GraNNy-sartan: hey, where are you located again? toronto?
sartanyour 5x CCIEs don't count, you're missing your A+ and CCNA, sir
MrJayPCI saw a job up a while ago that wanted a CCIE or preferred CCNA.... found that pretty funny
sartani wonder if i have a copy of my own description anywhere
KickStarRabbitlet me see your resume sartan so I can copy
sartani'll pass on that
sartani should probably update it
KickStarRabbiti am curious how to list 5 phds
sartanin bold, each on their own page
sartanhiring mangaers only look at the first 2 pages of your resume
sartanhaving one phd in awesome and another phd in good worker
KickStarRabbitso i need alot of tech info in a small pt
sartanhow small can you fit it?
mgeorgeman im way to impatient to trade forex
blackOffwhat is the best monitor/tablet/laptop for reading ebooks/pdf's on?
blackOffmy kindle doesn't like my books
sartanblackOff: technical books?
sartanhmm, ipad?
blackOffyou might be right
sartani buy my tech books dead tree
blackOffyeah i like real books
MrJayPCTech books are a pain in the arse to read because of how thick they are :|
tmx1good ole papyrus
blackOffnah, just read
hjohnsonanyone here played with WAAS?
KickStarRabbitwifi as a service
sartanjust steelhead
KickStarRabbitds3 is 28 T1s right
onefst250rits as wide as your mom
onefst250rso, huge
KickStarRabbitshes a champ
rlin_ACTION hates juniper with nexus vpc
onefst250rfix your network in seattle
onefst250rpeople on my network with giges are getting garbage speeds from your speedtest servers
onefst250rand bitching to my noc
KickStarRabbitlet me chk
dwxreaperI like how some speedtest site somehow equates to anything at all
rlin_iperf is for the real men; speedtest.com is for dummies
KickStarRabbitwhat CO
KickStarRabbitor whats the common network element
onefst250ryeah, but, 1) most people dont know what iperf is and 2) doing iperf on an internet circuit is difficult for most customers as they only own one end of the internet
dwxreaperit's not a good test though, you can browse the web on an xp box, and then on ubuntu, and see a 10x increase in speed
rlin_true. that's why most providers should provide a free iperf server fro the customer to test their "bandwidth"
rlin_that would be nice
rlin_i know some providers have files that you can download to test your bw. that's it
rlin_btw..is jperf just a graphical front end of iperf?
dwxreaperthat extended windowing that older OSes don't have makes a huge difference when browsing the web etc
Titaniumbut it crashes a lot
Titaniumthe graphs are worth it
rlin_oh i see
rlin_i actually want to modify iperf to be part of our active monitoring toolset...
Titaniumiperf can kill a network
nemiththats kinda the point
Titaniumno, it can send UDP traffic to a multicast address
Titaniumat 10gbps
Titanium1gbps i think or something
dissolvedammit i was clearing a password to a 2003 server and i blanked it like an idiot instead of editing the pw. now it wont let me edit it saying pw is set to *BLANK* cannot edit
dissolvenm the password becomes *
Titaniumdid you know i can copy and paste the star?
drkatcant wait til my 24" monitor gets here
drkatthis work on my laptop shit sucks balls
steve_mfinally got a chance to sit down and set up a stratum 1 ntp server with a GPS receiver + PPS... pretty neat stuff
hjohnsonACTION returns
onefst250rdissolve: also, you're fucked if that is the only admin account
onefst250ryou'll have to EDR commander it or something
hjohnsonsteve_m: do you really needtiming that accurate?
steve_mhjohnson: no, of course not
steve_mhjohnson: i actually just don't even know if I can believe what I'm seeing
hjohnsonmy last job we had a GPS frequency base, but we actually needed the traceability for a frequency standard
steve_mmy average offset with the kernel PPS driver and this GPS receiver is in the 500 nanosecond range now
gewthjohnson: he probably does it the same reason i want to accept a 24-processor server that requires 6.44kW to run
gewt"because I can"
hjohnsoni'm actually surprised with how well ntp works over satellite
hjohnsonI've watched the clock and verified against WWVB and it was pretty damned on
steve_mmakes sense
hjohnsonat least on low jitter links like ours
steve_mat 500 nanoseconds I think this is pretty much precise down to around the time it takes light to go 150 meters
steve_mfor an $85 receiver that's pretty amazing
steve_mfor my next trick I'll probably try attaching a wwvb radio receiver to the line in and fudging it
hjohnsonI'm building a project around a trimble GPS block
hjohnsonway way more accurate timing than I'll ever need
hjohnsonbut, eyah, because I can
drew__haha these guys i work with want to buy a fucking ntp box
drew__im like.. get a fucking $35 usb gps idiot
hjohnsondrew__: there are a few things where it's needed
hjohnsonbut we needed a traceable frequency standard
hjohnson(since we were selling RF translators and stuff where frequency accuracy is paramount)
steve_mthere is USB GPS that can be had for around that price that actually has pretty accessible pins on the GPS and a pad to solder the PPS pin to the DCD line on the serial chip
steve_mthat will get you microsecond precision
steve_mfor $30
hjohnsonsteve_m: real men connect it to the interrupt line on the ISA bus!
hjohnsoner... wait...
hjohnsonman, though... I wish that 3560-8PCs were more reasonably priced
steve_mI wish I knew more about this time stuff
hjohnsonI have a bunch of places where I could use them, and would be much nicer than throwing a 24 port switch
steve_mit is pretty high nerdery
hjohnsonsteve_m: I've met the ultimate time geek. :)
steve_mis that david mills himself?
hjohnsonpretty cool guy... was working in his office, and see this hunk of metal on the shelf
hjohnsonask what it is.. "Oh, that's the prototype of the atomic clock I built as part of the GPS program"
hjohnsonisotopically pure titanium, fused windows for the laser ion trap, etc...
steve_msee, you just said at least 8 things I don't understand
steve_mI clearly need to learn more
gewtisotopically pure titanium?
Zexeslol, hjohnson... no big deal, right?
gewtthe alloyed elements are without impurities?
hjohnsonok, so atomic clocks work based on a physical property of certain ions
gewtcaesium clocks are best clocks!
hjohnson(usually sodium)... that produces an ultra precise frequency
hjohnsoner ceasium
steve_myea I know that much
hjohnsongewt: it's a single isotope of titanium
steve_mI've ready a book I recommend called Splitting the Second
steve_mpretty interesting
gewthjohnson: ahh
steve_mand have a text book I'd like to chew through on the history of timekeeping
hjohnsongewt: I don't know what that would cost to purify like that, or how you'd do it
gewthjohnson: probably a lot. :P
steve_msome cesium isotope changes state at something like 9.192ghz and ah-ha that is the atomic standard
steve_mbut then everything just flat out snowballs into craziness
gewtACTION hands steve_m a smoke alarm bomb
hjohnsongewt: yeah
hjohnsonwell, you need it to be in an ionized state for it to work
hjohnsonyou also need it to be super cold in order to reduce the noise in the signal
hjohnsonso the way you make it super cold is by cooling it in a laser trap
hjohnson(think slowing down a bowling ball by shooting a stream of pingpong balls at it)
steve_mmy brain just fell out of my ear
steve_mand is sliding across the floor
steve_mI guess I just have to leave the science to the scientists
gewtthat's what I do
steve_mI wish scientists would make me a money machine
gewthjohnson: i took a test thing today that assessed my skills
steve_mthat I can feed water, and out comes dollar bills
gewthjohnson: it said I was good at "engineering" and "problem-solving"
gewtwhich is pretty much a case of "NO SHIT."
steve_mmy test told me that I like insane Brazilian women, samba, and aviation
steve_msame case for me, gewt
gewtit also recommended i pursue a career managing oil refineries, iirc
FungiFoxmine said "somebodys gotta do it" at the end, whats that mean?
steve_mplumbers make bank, FungiFox
FungiFoxhot on the left, cold on the right, shit don't flow uphill and paydays on friday... all you gotta know.
steve_mACTION thumbs up
fuhgeddabouditrv082 freq lost vpn connection however shows connected in the status view any suggests ?
hjohnsonfuhgeddaboudit: try buyign a router rather than som elinksys piece of shit/
dissolveanyone else ever have fun playing with atto ssd bench
fuhgeddaboudithjohnson, e.g. ?
dissolvei got my read up to 4gigs
dissolvejust curious... is sata limited to 6gbs per channel or total?
hjohnsonfuhgeddaboudit: pretty much anything that's not a linksys piece of shit?
hjohnsondissolve: it often depends on the channel between the controller and the CPU
gewtdissolve: probably depends on the controller
dissolvek i got that
hjohnsondissolve: so if it's on 1-lane PCI-E, its realistically only going to be doing 2gbps or so
gewtdissolve: some shitty ones won't do 6gbps total. :P
dissolvei got 3 ssds in raid0 on a evga z87 mobo i7 x4771
hjohnsonACTION checks to see how much his NAS has
sartan3x 3tb here, 2 mor ebays...
Symmetriadon't suppose anyone has a full tarball of xr 4.3.4 lying around somewhere on a really fast link do they? cause snoreeeee downloading this from cisco is taking forever, god their downloads are slow as shit from cco
sartannext version fo synology supports ssd caching
dissolvegot it to write at around 1800 MBs
fuhgeddaboudithjohnson, could u pls name the models ?
dissolvei think thats good for a home computer that i just do homework on lol
fuhgeddaboudithow do i know if it linksys or not
SymmetriaI'll be curious to run that test on my new high speed NAS when it arrives, heh, I got 4 new disk array units on the way that I ordered recently
Symmetria1 equilogix unit full of 750gig SSD's
dissolveim curious right now
Symmetriaand 3 powervault units running 12 x 4TB disks in each of them
dissolvewell aren't you just made of money
dissolveyes that is incredible
Symmetriagonna be curious to see though if the iscsi slows down that equilogix unit
dissolvenow see how fast a u can load counter strike
dissolvedidnt know 750gb ssds were out
FungiFoxSymmetria: how much you charge to physically touch?
Symmetriadissolve they have 1TB SSD's actually
Symmetriabut the 1TB's are stupid pricey
Symmetria750G SSD isn't THAT much more expensive than a 15k RPM 900gig SAS drive
dissolvei had a 32gig scsi 15k 10 years ago for gaming i thought i was the shiet
Symmetriaheh the equilogix unit is a pretty nifty thing though, because all its raid calculations etc are done on the unit and not on the server itself
Symmetriathe PV on the other hand is basically just a very large jbod on a high speed internal raid controller
SymmetriaACTION thinks today is going to be a long day fighting with vendors
drew__if you bought scsi for gaming your parents were too rich
Symmetriaheh other than the original computer my parents bought when I was 12, I've bought every piece of computer hardware my family has ever owned
dissolvei got it for my 17th birthday thats all i wanted lol
Symmetriamy parents were and still are perm. broke ;p
dissolvei loaded half life and team fortress classic very quickly
dissolvelol i tried to use that comp as a server with my 250/50KB/s RR connection lol
dissolvegot a total of 9 people
dissolvei mean for HL hosting
Symmetriaheh recently on the work network we put down a massive gaming platform
Symmetriaas a proof of concept platform
dissolvei bet
Symmetriawe wanted to demonstrate that gaming in east africa was viable and if you put the content locally and had low enough latencies people would come
Symmetriaits working pretty well
dissolvei calc'd just what i could do with the verizon fios at my moms 300/65mbps .... at the speed of the same game... which is still around!! 8193 peoples! lol
dissolveif u could run 256 thirty two person game servers
dissolvethat would have been great for a 17 year old :D
Symmetrialol, I should host a server at my house ;p but that would be cheating
SymmetriaI decided working from home, if I was gonna work, I needed to be able to work in exactly the same way I do at the office
Symmetriaso I had redundant 10gig fibers pulled in ;p
dissolvewtf how
dissolveACTION is on 65/5 =[
Symmetriadissolve helps that the company I work for owns 800 kilometers of fiber in the city I work in and the fiber ran right past my door
dissolvegive me some money
Symmetria(when I rented this place, the first thing I did was say to the rental agency who was helping me find a place to live, the only roads I wanna live on are these....)
Symmetriathe guy says "why"
SymmetriaI said "thats where the fiber is, those roads, or gtfo"
Symmetrialol so moved in, and then it only took 2 days to get completely sorted
dissolvewell in a few years i wish to join ..... underneath you or something at least
Symmetriathing is, all they had to do was drill under the road and pull the fiber there, and then drop it into the housing compounds internal ducting
Symmetriaand some splicing
SymmetriaALL the housing compounds in Kenya are pre-ducted for cabling
Symmetriaso it becomes REAL easy once you get the cable to the gate house
dissolvehire me! i'll work almost free!
jato_I have now been tasked with implementing some security related ISO standard...
dissolveACTION goes back to studying multi area ospf =[
jato_Satisfaction level...dropping