Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
H.R. Paperstacks
May 1, 2006

This is America
My president is black
and my Lambo is blue

QPZIL posted:

Bundle-POS sure sums it up alright.

We should just call it by the IEEE standard (802.3ad) - Aggregated Ethernet (like Juniper does).

Adbot
ADBOT LOVES YOU

z0rlandi viSSer
Nov 5, 2013

Agreed.

1000101
May 14, 2003

BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY FRUITCAKE!

dont change my name posted:

Can someone give me a detailed honest assessment of the Nexus line? We have 5010's, 7010's, 5596's and 2148's and what have you and I am simply not impressed with the Nexus.

What am I missing about the Nexus that I should reconsider?

Edit: also we've been considering moving off of 12.2 SP train to 15.1 on 6500's

Anyone else move to 15.1? How is it?

Vpc is a pretty rad feature as is fex. One of my customers manages 480 access ports from one pair of 5ks. I will say the 5010 is kind of lovely (it's an into product) but the 5500 series is decent for layer 2.

What sorts of issues are you having? Could you describe your design a bit?


Also for the person looking for an ios to nxos primer: http://docwiki.cisco.com/wiki/Cisco_Nexus_7000_NX-OS/IOS_Comparison_Tech_Notes

1000101 fucked around with this message at 08:45 on Feb 5, 2014

ruro
Apr 30, 2003

So I have to buy an HSEC license to get >85mbps bidirectional IPSEC on an ISR G2 now? That's a bit irritating.

z0rlandi viSSer
Nov 5, 2013

Welcome to Cisco.

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

ruro posted:

So I have to buy an HSEC license to get >85mbps bidirectional IPSEC on an ISR G2 now? That's a bit irritating.
We are moving all of our VPNs to these: http://www.ubnt.com/edgemax

$100 for the base model, which should get at minimum 100mbps of IPsec throughput. The higher end model which I believe is priced around $350 has more than double the cpu, but don't know how that will impact offloaded IPsec. Either way, it's going to be cheaper than cisco.

ate shit on live tv
Feb 15, 2004

by Azathoth
I hate /24's for user segments, or as it is now, citrix segments. Why do people insist on /24s?

If you have lots of employeers, say in the thousands, especially with virtualized desktops, why not just make a /22, or even a /20 for all of the virtual desktops?

bort
Mar 13, 2003

I use /22s but I always wonder: how many nodes/subnet is too many?

madsushi
Apr 19, 2009

Baller.
#essereFerrari

Powercrazy posted:

I hate /24's for user segments, or as it is now, citrix segments. Why do people insist on /24s?

If you have lots of employeers, say in the thousands, especially with virtualized desktops, why not just make a /22, or even a /20 for all of the virtual desktops?

/24s are the golden standard because it lets people ignore the first 3 octets and only have to understand the last octet. Once you start moving into /23 and above (or below, depending on how you look at it), you have to start thinking about multiple octets at once, and I would wager the majority of network admins have no idea how to do the binary/math work in their head.

some kinda jackal
Feb 25, 2003

 
 
Wouldn't a /22 make for a really chatty wire? I guess you'd have to strictly control the broadcast domain.

madsushi
Apr 19, 2009

Baller.
#essereFerrari

Martytoof posted:

Wouldn't a /22 make for a really chatty wire? I guess you'd have to strictly control the broadcast domain.

I don't know, I think a lot of the fear around bigger subnets is not as relevant today (with 1Gbps as the standard edge port and multi-gig between switches). I wouldn't want to do a /22 spanning a WAN, but for one LAN, I don't think the traffic would be that significant.

Basically I think it comes down to network admins being able to go "10.10.10.x is workstation, 10.10.20.x is printers, etc" and having that be really easy. Which is a good point, since being able to remember the exact subnet of any site/service is pretty handy for most admins.

ate shit on live tv
Feb 15, 2004

by Azathoth
Well for remote sites, /24s make sense. For a huge homogenous group of hosts having multiple /24s is pointless, wasteful, and confusing.

And yea broadcast storms aren't really a concern anymore unless you are talking multiple GBs of broadcasts causeing link saturation issues, cpu use wise, it wouldn't even register.

ate shit on live tv fucked around with this message at 21:39 on Feb 6, 2014

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

We use /23's :cool:

bort
Mar 13, 2003

I agree the old "200 nodes per segment" isn't relevant anymore, but nobody I know would fill a /16 with workstations. /22 seems to be the defacto "big network" but I was just wondering if that was based in anything other than "we outgrow /24s too quickly."

Count Thrashula
Jun 1, 2003

Death is nothing compared to vindication.
Buglord
We use anywhere from /19 to /24 within the same subnet depending on what device you're looking at.

I started this job in a mess. :shepicide:

1000101
May 14, 2003

BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY FRUITCAKE!
I'd probably use /24s or smaller for desktops/phones. I'm an advocate of using l3 links to my access switches though.

Moey
Oct 22, 2010

I LIKE TO MOVE IT
I am in the process of re-organizing our network. Biggest segment will be a /23 for that sites phones, but there will most likely be only 210ish devices on there. Looking back, I could probably make that a /24...


After I left my old job they needed to expand a scope and didn't really know what they were doing, so the two /23 scopes went into a giant /16....

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer
At each branch office, which usually has about 10 PCs, 5 Printers, and 10 phones (as a ballpark) we assign multiple /24 subnets, one for PCs and printers and one for phones. In addition, we assign /29 or /30 subnets for firewalling other devices off. For example, an ATM or outdoor digital sign will have it's own /30 with a firewall. This prevents someone who breaks into an outdoor cabinet from gaining access to the rest of our network. For servers we have traditionally assigned /24 subnets. We use /21 for our VDI and Citrix server subnets. Finally, we use /32 and /30 subnets for our VPN tunnels, which connect using GRE tunnels that use loopback IPs as their endpoints.

BurgerQuest
Mar 17, 2009

by Jeffrey of YOSPOS
A previous admin with not much networking experience settled on /19 for no apparent reason. For a 30 person office (ok, maybe 100 IP related devices total, MAYBE). When it came to setup a branch office, he used the next available /19. Fortunately he left so when the new admin came to setup the next branch, for 3 people, I asked him to use something more reasonable. So we have 172.16.32.0/19, .64/19 and .96/24 for our 3 offices. When 172.16.32.0/23, .2/24 and .3/24 would have been ample. It's not hurting anyone, it just hurts my head a little wondering why he'd think we'd ever need 8000+ hosts on a single network (for our size organisation), or even why that'd be a good idea in any event.

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer
He was planning for the internet of things.

Contingency
Jun 2, 2007

MURDERER
/23. First half is for static IPs and DHCP reservations, and additional pool capacity if push comes to shove. Doesn't stop our server guys from making their dynamic IP static and disrupting the next person to get issued that IP though.

psydude
Apr 1, 2008

Look at you all with your fancy well-designed networks. I was still having to move from flat class A address space to CIDR prefixes on one network at my last job.

I tried using VLSM on a smaller network I designed, but it kept confusing the helpdesk so I just went back to /24 for everything because gently caress it.

bort
Mar 13, 2003

All it takes is one good-sized acquisition and your well-designed network is a giant bus wreck.

sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh


So I'm pretty loving excited. I got to do this for the first time on a nexus device today.

code:
switch# sh ver
Cisco Nexus Operating System (NX-OS) Software
TAC support: [url]http://www.cisco.com/tac[/url]
Documents: [url]http://www.cisco.com/en/US/products/ps9372/tsd_products_support_serie[/url]
s_home.html
Copyright (c) 2002-2013, Cisco Systems, Inc. All rights reserved.
The copyrights to certain works contained herein are owned by
other third parties and are used and distributed under license.
Some parts of this software are covered under the GNU Public
License. A copy of the license is available at
[url]http://www.gnu.org/licenses/gpl.html.[/url]

Software
  BIOS:      version 3.6.0
  loader:    version N/A
  kickstart: version 5.2(1)N1(4)
  system:    version 5.2(1)N1(4)
  power-seq: Module 1: version v2.0
             Module 2: version v1.0
             Module 3: version v5.0
  uC:        version v1.2.0.1
  SFP uC:    Module 1: v1.1.0.0
  BIOS compile time:       05/09/2012
  kickstart image file is: bootflash:///n5000-uk9-kickstart.5.2.1.N1.4.bin
  kickstart compile time:  3/19/2013 3:00:00 [03/19/2013 10:12:59]
  system image file is:    bootflash:///n5000-uk9.5.2.1.N1.4.bin
  system compile time:     3/19/2013 3:00:00 [03/19/2013 12:10:47]


Hardware
  cisco Nexus5548 Chassis ("O2 32X10GE/Modular Universal Platform Supervisor")
  Intel(R) Xeon(R) CPU         with 8263848 kB of memory.
  Processor Board ID FOC17515LG7

  Device name: switch
  bootflash:    2007040 kB
A brand new 5548UP and it's all mine.

some kinda jackal
Feb 25, 2003

 
 
I can't wait to do the same thing


on a VIRL vm

Count Thrashula
Jun 1, 2003

Death is nothing compared to vindication.
Buglord

Martytoof posted:

I can't wait to do the same thing


on a VIRL vm

I hope there's a way for me to use VIRL stuff without taking out a mortgage or something :ohdear:

some kinda jackal
Feb 25, 2003

 
 


If the Personal edition isn't crippled all to hell then it should be pretty affordable. Assuming this dude isn't full of poo poo.

Fatal
Jul 29, 2004

I'm gunna kill you BITCH!!!
Back to / chat, I've worked with customers with more than 10 /24s per site for data access (they didn't understand the concept of VLSM) and on the other end of the spectrum customers breaking down their network using a single /16 per site (ranging from 200-2000 users per site). With /16 they carved out different services using the 3rd octet & DHCP reservations, all on the same logical segment. Never underestimate the creativity of somebody with no concept of modern subnetting :downs:

Fatal fucked around with this message at 02:24 on Feb 8, 2014

ToG
Feb 17, 2007
Rory Gallagher Wannabe
I've been places were each area had their own data and printer vlans. Mostly /24s. It seems useless at first but its handy knowing where something is via its ip address

H.R. Paperstacks
May 1, 2006

This is America
My president is black
and my Lambo is blue
With Private addressing a lot of what we did was to keep it simple for the admins when working between the two large active/active datacenters.

Site1 - 192.168.0.0/19
Site1 - OOB - 172.16/16

Site2 - 192.168.96.0/19
Site2 - OOB- 172.17/16

EDIT: I should note that the /19s are segmented into /24s mostly, the datacenters aren't one big /19.

This allows systems to just increment their hostname scheme and IP address by 100 and easily tell what site it is. For OOB, the 3rd and 4th octet match their production.

Site1
System1 - 192.168.7.10
System1 OOB - 172.16.7.10

Site2
System101 - 192.168.107.10
System101 OOB - 172.17.107.10

Admins can quickly identify where the system is located by either the hostname or IP.

We don't run DHCP for various DoD reasons and we don't have wifi or BYOD on the network so everything is statically addressed and maintained in DNS / phpIPAM.

Wasteful? Sure.
Am I worried about it or a merger/acquisition? No one is buying the DoD anytime soon :)
Does this simple layout allow my team to focus efforts on other things, rather than having to explain to admins subnetting and other networking subjects they are bound to screw up? Absolutely!

H.R. Paperstacks fucked around with this message at 20:50 on Feb 8, 2014

z0rlandi viSSer
Nov 5, 2013

Congrats. You "get" it.

ruro
Apr 30, 2003

Martytoof posted:

If the Personal edition isn't crippled all to hell then it should be pretty affordable. Assuming this dude isn't full of poo poo.
VIRL is the most exciting thing to me to come out of Cisco in the past three years at least.

Marvel
Jun 9, 2010
This isn't really Cisco-specific but I do have a networking question.

My company is moving offices and I'm wiring it up for the first time but I don't really know what I'm doing.

I need at least 4 ports of 802.3t PoE for the 4 ubiquiti 802.11ac access points plus a shitload more normal PoE ports for phones. I think I'm getting a Netgear GS728TP-100NAS switch, plus a bigass
CyberPower OL1500RTXL2U UPS (power is poo poo here and this will power a couple mac mini servers, router, modem, etc)

Plus a Tripp-Lite floor-standing rack and a patch panel. Does that sound OK?

What do you do for all the super short cables you need to hook everything up? Seems overkill to make all those cables by hand?

Edit: Derp, looks like you can buy a pack of 1ft patch cables.

Marvel fucked around with this message at 09:14 on Feb 10, 2014

SamDabbers
May 26, 2003



Marvel posted:

This isn't really Cisco-specific but I do have a networking question.

My company is moving offices and I'm wiring it up for the first time but I don't really know what I'm doing.

I need at least 4 ports of 802.3t PoE for the 4 ubiquiti 802.11ac access points plus a shitload more normal PoE ports for phones. I think I'm getting a Netgear GS728TP-100NAS switch, plus a bigass
CyberPower OL1500RTXL2U UPS (power is poo poo here and this will power a couple mac mini servers, router, modem, etc)

Plus a Tripp-Lite floor-standing rack and a patch panel. Does that sound OK?

Seems like a decent setup. Are you doing the cabling for the drops too, or is a cabling contractor taking care of that?

Marvel posted:

What do you do for all the super short cables you need to hook everything up? Seems overkill to make all those cables by hand?

Edit: Derp, looks like you can buy a pack of 1ft patch cables.

Buy all your cables from Monoprice.

Marvel
Jun 9, 2010

SamDabbers posted:

Seems like a decent setup. Are you doing the cabling for the drops too, or is a cabling contractor taking care of that?

My friend and I already muddled through the cabling this weekend. It only cost me 4 hours and a pizza so if I screwed something up I can redo it. I'm thinking of using a little PC Engines WRAP board running pfSense for the router (already on-hand). My upstream connection is pretty terrible so it won't be pushing too many packets. It apparently can do the QoS for the phones.

SamDabbers
May 26, 2003



Marvel posted:

My friend and I already muddled through the cabling this weekend. It only cost me 4 hours and a pizza so if I screwed something up I can redo it. I'm thinking of using a little PC Engines WRAP board running pfSense for the router (already on-hand). My upstream connection is pretty terrible so it won't be pushing too many packets. It apparently can do the QoS for the phones.

Unless your office is stuck on <10Mbit DSL, that WRAP board is likely not powerful enough. You're already using UniFi APs, and an EdgeRouter Lite will blow the WRAP board out of the water for about $100.

Marvel
Jun 9, 2010

SamDabbers posted:

Unless your office is stuck on <10Mbit DSL, that WRAP board is likely not powerful enough. You're already using UniFi APs, and an EdgeRouter Lite will blow the WRAP board out of the water for about $100.

Awesome, that looks like a good deal. I'll get one of those.

Inspector_666
Oct 7, 2003

benny with the good hair

Fatal posted:

Back to / chat, I've worked with customers with more than 10 /24s per site for data access (they didn't understand the concept of VLSM) and on the other end of the spectrum customers breaking down their network using a single /16 per site (ranging from 200-2000 users per site). With /16 they carved out different services using the 3rd octet & DHCP reservations, all on the same logical segment. Never underestimate the creativity of somebody with no concept of modern subnetting :downs:

Literally related to CIDR notation, we had a client once tell us that printers had to be assigned IPs between 192.168.1.2 and 1.24. When pressed on this, we found out the people on the phone with us were looking at a note that said 192.168.0/24 :ughh:

Badgerpoo
Oct 12, 2010
Started to run out of DHCP leases on our wireless again, this is with 20 /22 networks being given out. Anyone have any pro/cons of either just adding more /22s or consolidating into /21 or /20s? The only benefit I can really think of is neatness of config. This is 6x WiSM2s and ~2k APs fwiw.

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth
Ran into a wierd thing on a Cisco 6500.

I have some Etherchannels and one of them looks something like this on the sh etherchannel summary screen

115 Po115(SD) LACP
115 Po115A(SU) LACP Te5/4(P) Te5/5(P) Te6/4(P) Te6/5(P)


Po115 is down
Po115A is up

Where did that interface come from?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply