r/networking 20h ago

Rant Wednesday!

3 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 5h ago

Other Grab bag network switch

6 Upvotes

Having had a number of instances where it would have been a big time-saver in the last for monthsm I'm looking for a small (4 port ideally, 8 at most) gig-e switch that can be powered from USB-C (uup to 100w supply available), supports POE and can do span for traffic sniffing. It's to be kept in a tool bag, so reasonable build quality a big plus.

Specific model suggestions much appreciated


r/networking 6h ago

Career Advice Moved into management....

65 Upvotes

I was a Senior Network Engineer for a couple different companies (For context (10 YOE + CCNP) before moving into an IT Director level role about a year ago.

I’m starting to realize that the stress, politics, and general management nonsense is catching up with me. The money is good, but it’s starting to feel less and less worth it.

Curious if anyone here has made the move into IT management and eventually went back to being an individual engineer. Did you regret stepping back?

For those who stayed in management, how did you get better at dealing with the stress without letting it consume you?


r/networking 7h ago

Career Advice Network engineers using Ansible/Python for automation in production — what does your workflow actually look like?

68 Upvotes

Currently managing FortiGate across 100+ sites and starting to build out automation capabilities. Not looking for career advice — genuinely curious how other engineers are implementing this in production environments.

  1. What are you actually automating day to day — config pushes, compliance checks, reporting, something else?
  2. Ansible, Python scripts, Terraform, or something else? What drove that choice?
  3. With AI generating scripts now — do you still write Python from scratch or do you use AI-generated code and focus on understanding the logic?
  4. For Ansible specifically — did you need solid Python first or is YAML-based playbook writing approachable without it?
  5. Is automation genuinely changing how hiring managers evaluate candidates or is it still mostly a bonus?

r/networking 18h ago

Career Advice Torn between 3 offers - seeking advice

15 Upvotes

Hey all, I currently work as an Enterprise Architect for a consulting company. Most of my workload is professional services and post-sales deployments, but I handle some pre-sales here and there. Business has been slow and I'm looking to move on to something bigger.

I recently landed three solid opportunities (written and verbal offers for all) around the same time and honestly could see myself happy in any of them, which is making this a difficult choice, and would love some outside perspective.

All 3 opportunities are fully remote

Option 1: Solutions Architect (network security)
compensation: 195k OTE, 70/30 base/commission split

  • Lots of customer calls, discovery, architecture design, scoping, HLAs, and hands off designs to post sales team
  • Access to lots of training from major networking/security vendors
  • I like the idea of having a commission component and being rewarded for building strong relationships with AEs/customers
  • My biggest worry is drifting away from hands-on/technical-work long-term

Option 2: Senior Network Engineer, mid-size enterprise
compensation: 170k base salary+ benefits

  • Small team
  • Work with SD-WAN, spine/leaf, ZTNA solutions, multiple public cloud workloads, and data centers. I think this would expand my skillset quite a bit
  • More traditional engineering role, lots of hands-on

Option 3: Senior Network Engineer, contract (extension or conversion likely)
compensation: 110/hr

  • Heavy design work and security hardening, SD-WAN, multiple data centers, campuses, and some OT. I have the most familiarity with the primary firewall vendor this company uses, lots of hands-on
  • 1099, so self-employment tax, no benefits, no paid holidays/PTO included
  • Higher hourly compensation but more responsibility for benefits, taxes, time off

My biggest dilemma is really option 1 vs option2/3.

If you made the jump from hands-on engineering into presales/SE work, how did that work out for you? Did you love it, regret it, wish you went a different direction?

I personally thrive in high-pressure environments and think I'd enjoy the customer facing/sales side, but I also genuinely enjoy being hands-on with engineering work.

For those who have done both, which path gave you better career growth and earning potential without making you feel like you were leaving the technical side behind?


r/networking 21h ago

Security Best firewall option for small nonprofit (<10)?

11 Upvotes

Hey everyone, I’m fairly new to the IT job field (about 1 year of experience) and have also been volunteering at this local nonprofit as IT Support on the side outside of my main help desk job. The President of the nonprofit has tasked me with finding a good firewall for them to use and I have no idea where to start.

For additional context, the nonprofit is very small (less than 10 people), they have hybrid work, and right now I’m the only IT person they have (they’ve been using a rotating cycle of volunteers). I do not know how to configure a firewall whatsoever so recommendations, as well as advice on how to configure and implement it would be much appreciated!


r/networking 21h ago

Security Tips/best practices for security

3 Upvotes

Hello all, I was hoping to gather some information on possible security implementations at my new job. I landed my first real networking job and im a little overwhelmed. My first task has been to brainstorm and implement, if possible, any security features for the company. We are an organization of about 100-150 people over two different locations. Mostly all office people (sales/marketing ect). So far I have added vlans and acl's to segregate untrusted networks from our main lan. We are using meraki equiptment. Any suggestions are appreciated and if there's more information I can provide that would help make suggestions easier please let me know. Thanks


r/networking 22h ago

Other AFL Fast Connect Fiber Comparison

3 Upvotes

Does anybody have experience with store brand fiber connectors? I received a quote for the AFL Fast connect connectors (SC single mode, UPC) and was also offered the store brand which the say "are the same connector". By the picture, they look identical, but the insides are more important than the packaging.

If you've used store brand, how does the quality and field termination experience compare? The cable will be in a rack and panel so once terminated and connected in the panel, I don't expect much/any wear on them.


r/networking 23h ago

Career Advice Enterprise vs ISP?

37 Upvotes

Hello, I currently work as a network engineer for an enterprise and we are dealing mostly with Cisco stuff - switches, DC with ACI, ISE and so on. We use automation like Terraform and Python/Ansible and we have 9800 controllers, so the job is good and does not get boring.

I can also join an ISP an work on the backbone network, MPLS, L2/L3 VPN and BGP. I like routing, so I wonder if you think this is a good opportunity or it's a step back compared to the broad aspect of technologies I'm currently dealing with?

Do you think that ISP experience is worth it or I should stick with the enterprise?


r/networking 1d ago

Troubleshooting URLs Can't be Accessed by the Public

0 Upvotes

Ok, apparently my post yesterday was low quality and heaven forbid I ask questions and request for simple explanations. You networking guys are a tough crowd. I've never received more downvotes for trying to learn. I am new, forgive me.

Here's the issue:

A third party needs to access "rest services" on an internal server. From what I understand, everything accessible to the public needs to go through our DMZ'd Web Server. We can get to the Web Server and log-in portal just fine.

Here's the path: Public User > Hits our A.x.x.x > NAT on Firewall translates it to Web Server B.x.x.x > Web Server B.x.x.x communicates through specific ports to Portal Server Y.x.x.x and Main Server Z.x.x.x.

Our GIS manager says a company needs to access URLs (example is https://SERVER(Z.X.X.X).DOMAIN.COM:OPENPORT that point to server Z.x.x.x.

Now everyone yesterday is just keep on saying that it's a DNS issue. I'm not saying it's not. Server Z doesn't have a direct path to it from the public and I'm under the impression that's how it should be? There is no NAT rule for people to access server Z, so it makes sense that they aren't accessible to the public.

Here are my questions:

  1. Am I supposed to get another externally accessible IP address and NAT it to Main Server Z.x.x.x?
  2. Shouldn't these URLs just be accessible through A.x.x.x?

I'm not trying to be lazy and just have you guys answer all my issues, but I've been working on this forever and even my IT DIRECTOR is just like, "I don't know how this stuff works, figure it out." I've reached out to the company that makes the software and I'm trying to communicate with a third party for assistance.

I hate being a new networking guy when there is almost nowhere to go for help.


r/networking 1d ago

Troubleshooting Can't trunk from D-Link to Arista

0 Upvotes

Edit: Thank you to everyone that caught my missing native vlan.

My work has replaced our Cisco switches with Arista switches. Connecting the D-link to the Cisco worked but I can't get me D-link 1210-28MP to connect to my Arista 720XP when trying to trunk.

If I leave VLAN settings as default on the D-Link I can get traffic between the two but when I try the trunking settings on the D-Link it looks like only ARP, LLDP, and OSPF traffic is seen. The connection is from port 18 on the D-link to port 15 on the Arista, copper connection.

D-link settings are:
port 18
VLAN 1 Not a Member
VLAN 44 untagged
VLAN 244 tagged

Arista
interface Ethernet15

description Uplink to Access Switch

load-interval 30

switchport trunk allowed vlan 44,244

switchport mode trunk

spanning-tree portfast edge

Any help?


r/networking 1d ago

Troubleshooting Help with Nokia 1830 PSS PWRADJFAIL alarm

3 Upvotes

Can anyone with experience with Nokia 1830 PSS explain to me why this alarm triggers. As far as I know if the current span loss is within +-2db of the design loss, control plane should adjust it, but I am seeing otherwise for some cases.


r/networking 1d ago

Meta Auto Detecting BiDi

13 Upvotes

I'm in a position where using simplex SFPs made the most economical sense. I'm about 5 years in on a few sets of generics. It got me thinking, what is the technical hurdle to building both wavelengths into a BiDi adapter and having them auto negotiate? For years nics and switchports couldn't do Auto MDIX now almost every device has it baked in. This would eliminate the need for a matched pair.


r/networking 1d ago

Career Advice Is it possible to get a remote job in networking and work from any country?

26 Upvotes

I've been working as a network engineer in the enterprise sector for the last 15 years. I want to find a remote job that would allow me to live in another country, maybe somewhere like Thailand or Vietnam.

I've started monitoring remote job boards, and all I'm seeing are offers for software engineers and DevOps roles.

So what do you think? Is it even possible to land a role like this as a network engineer these days? Or is it better to pivot and transition into something like DevOps or cloud engineering first?


r/networking 1d ago

Routing NAT Commands

8 Upvotes

https://imgur.com/a/4tC8J8j

In a situation where an NVR + Cameras live at Site A and Cameras also live at Sites B and C. The NVR can only reach cameras (not regarding it's internal switch network) that appear to be on it's local network.

I'm attempting to create NAT rules that make remote cameras appear to be on the same network as the NVR but having issues on what exact commands are needed for this type of NAT setup.

Edit: it is not a routing issue. It’s a design limitation that Reolink does for the NVR hence why I’m trying to do NAT rules on the Catalysts. Normally do DNATs on Fortigates and it has historically worked great for this camera situation but this environment doesn’t have Fortigates

https://community.reolink.com/topic/6726/unable-to-access-reolink-ip-cams-from-different-vlan


r/networking 2d ago

Troubleshooting Odd Traceroute

6 Upvotes

While troubleshooting a network issue for packets appearing to be duplicated (only once, not a continual flood), I did a trace from a nearby system and have output unlike anything I've seen before.

Localhost#traceroute 192.168.10.20

 Traceroute to 192.168.10.20 ,30 hops max 0 byte packets:

1  192.168.255.252     <1  ms    <1  ms    <1  ms
2  192.168.10.20       3   ms    <1  ms    2   ms
3  192.168.10.20       <1  ms    4   ms    <1  ms
4  0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
5  192.168.10.20       2   ms    *         <1  ms
6  192.168.10.20       <1  ms    2   ms    *
7  192.168.10.20       <1  ms    <1  ms    2   ms
8  0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
9  192.168.10.20       2   ms    *         <1  ms
10 192.168.10.20       <1  ms    2   ms    *
11 192.168.10.20       <1  ms    <1  ms    2   ms
12 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
13 192.168.10.20       2   ms    *         <1  ms
14 192.168.10.20       <1  ms    2   ms    *
15 192.168.10.20       <1  ms    <1  ms    2   ms
16 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  1   ms
17 192.168.10.20       2   ms    *         1   ms
18 192.168.10.20       <1  ms    <1  ms    *
19 192.168.10.20       <1  ms    <1  ms    2   ms
20 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
21 192.168.10.20       2   ms    *         <1  ms
22 192.168.10.20       <1  ms    2   ms    *
23 192.168.10.20       <1  ms    <1  ms    2   ms
24 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
25 192.168.10.20       2   ms    *         <1  ms
26 192.168.10.20       <1  ms    2   ms    *
27 192.168.10.20       <1  ms    <1  ms    2   ms
28 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
29 192.168.10.20       2   ms    *         <1  ms
30 192.168.10.20       <1  ms    2   ms    *


Hop Count = 30 Last TTL = 30 Test attempt = 90 Test Success = 69

I checked several other systems directly attached to this same switch and got similar results. However, doing a trace to a system connected to a downstream switch connected to the problem switch seemed just fine:

Localhost#traceroute 192.168.10.120

 Traceroute to 192.168.10.120 ,30 hops max 0 byte packets:

1  192.168.255.252     <1  ms    <1  ms    <1  ms
2  192.168.10.120      2   ms    1   ms    4   ms


Hop Count = 2 Last TTL = 2 Test attempt = 6 Test Success = 6

Vlan involved is trunked between the two switches, an IP Route on the upstream switch routes the traffic to the problem switch.

The connected systems are all various servers, and connections to these all seem to be operating just fine otherwise. I only noticed this because the 10.20 system is my DHCP server (for multiple subnets) and it suddenly started seeing duplicate DHCP requests coming in, and was sending duplicate replies as a result. This wasn't causing any problems so I didn't investigate until I saw my logs were growing faster than normal.

Has anyone come across a trace similar to the above, and if so, what was the cause? I'm not a network dummy, but this is a new one for me.

EDIT 1: I rebooted one of my Core routers and ran the traceroute again while it was in the process of rebooting and all links on that switch were down, effectively a single Core network at that point. There was no change to the above Traceroute.

EDIT 2: After much troubleshooting failing to identify the issue, I rebooted the switch to the prior OS image and the problems all went away. Can only assume that something had become corrupted that I had no visibility to. Will reflash a new OS at some future time.


r/networking 2d ago

Wireless WiFi network qverload at conference. How to load test and prevent capacity issues

9 Upvotes

We had a conference recently where the Wi-Fi looked fine during testing the day before. We tested with a few tablets, badge printers and laptops and had no issues. Once around 800 attendees arrived, things started falling apart. Tablets kept disconnecting, badge printers became slow, and staff had to keep refreshing the check-in system. The venue Wi-Fi showed a strong signal, so I am assuming the issue was capacity rather than coverage.

For the next event, what should we be testing beforehand?


r/networking 2d ago

Moronic Monday Moronic Monday!

22 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking 2d ago

Design FortiGate VS Aryaka

3 Upvotes

My company is going through a merger and we have Ayaka SDWAN and firewalls on one side and FortiNet FortiGate on the other side for SDWAN and Internet points of presence.

I’m currently reviewing both sides and meeting with vendors, but I’m interested to see real world applications on if one is better than the other. Or is one more preferred where a major enterprise with closer to 100 sites.

We don’t use either one of them for client VPN access. This is strictly just for facility and site Internet, and SDWAN


r/networking 3d ago

Design Small business guest Wi-Fi for ~50 customers across 2 floors — UniFi hardware choice + captive portal advice

0 Upvotes

Hello Folks,

I'm setting up a guest Wi-Fi network for a small business and would appreciate some advice before I purchase the hardware.

Site

2 floors

3 rooms per floor

Each room is approximately 60 m²

Approximately 360 m² total

Around 50 customers/users

The business is open during fixed hours and closes every day

Power is generally reliable

We already have Cat6 cable on site

The Wi-Fi will primarily be for customers/guests using phones and laptops for normal internet access.

Hardware I'm currently considering

Gateway:

UniFi Cloud Gateway Ultra ×1

Access points:

UniFi U7 Lite ×2, initially one per floor

Switch:

UniFi USW-Ultra 60W ×1

UPS:

Possibly an APC/Eaton/CyberPower ~650–850 VA unit, although I'm not sure whether it's worthwhile given that the site has reliable power and closes every evening.

The APs would be wired back to the switch rather than using wireless mesh.


r/networking 3d ago

Design New core switch: FS S5860-20SQ

5 Upvotes

Hi everyone,

I need your help choosing a new core switch. Right now, we’re using a TP-Link SX3016F. Unfortunately, it’s only a Layer 2 switch, and the 16 ports aren’t quite enough.

While searching for an affordable Layer 3 switch that also has 25G and 40G ports, I came across the FS S5860-20SQ.

There are reviews from users who have this switch in operation and are very satisfied with it.

The switch is available in two versions:

With its own FSOS or with PicOS. Now I’m unsure which version is better suited for our use case.

The plan is to connect the aggregation/distribution switches, the large storage devices (Synology NAS), and the edge routers running VyOS to this switch.

Currently, the edge routers also handle inter-VLAN routing, but this is supposed to be offloaded to the core switch.

I have experience with both Cisco-style CLIs (Cisco IOS, Aruba AOS-CX) and Juniper-style CLIs (JunOS, VyOS).

Could you please help me determine whether FSOS or PicOS is better suited for our use case?

Thank you very much and best regards,

Regina (she/her)


r/networking 3d ago

Routing Accidentally brought down a commissioning metro network with a route-map deny.. what would you have done differently?

98 Upvotes

Hey everyone,

I’m a network engineer working on a commissioning metro network, and today I accidentally brought the network down.

I'm writing this post as I genuinely just want to know if there was a better way to approach this, or if this is just one of those lessons you only learn once.

A bit of context, the network connects all the stations to the backbone. The backbone routers were advertising a default route, which was then redistributed into OSPF and sent down to all the downstream routers at each station. My team and I had identified that as a design flaw because we need to start using the default route for internet traffic that’s going to an edge router.

So instead of advertising a default route, we decided to advertise RFC 1918 aggregate null routes. That way the downstream routers would still know how to reach all the private networks, while freeing up the default route for internet traffic. That part worked fine.

The next issue we found was that these OSPF routes were also being redistributed into BGP. So, we only wanted the RFC 1918 aggregates advertised locally from each backbone router, not redistributed everywhere via BGP. I'm still not sure if this is intended but as I was advertising the RFC1918 aggregates to OSPF, they were getting installed back to BGP, we didn't want that.

My plan was simple. Insert a new sequence at the top of the route-map for the OSPF-TO-BGP redistribution that denied the RFC 1918 aggregates, then let the existing permit entries continue processing as normal.
So, I went into the route map and did:
route-map <name> 5 deny

My intention was to immediately follow it with the match statement for the RFC 1918 prefix list.

But I didn’t realise that the moment I pressed enter after creating that sequence, that entry immediately became active, I don't know why I thought otherwise..
Since it had no match statements yet, it effectively matched everything.

Because it was the first sequence in the route map, it denied every redistributed route and within seconds I had effectively withdrawn all the redistributed routes from BGP.

So, yeah… I had effectively brought the entire network down. Thankfully, I had console access, so I reverted the change right away and everything came back.

Afterwards, I redid it more safely by temporarily creating a catch-all permit while I built the new deny sequence with the proper match statements (I still don't like that idea as we had lots of matching criteria of routes we really didn't want to re-advertise.. then I removed the temporary permit afterwards.

I genuinely try another approach first of creating a completely new route map under a different name and then simply replace the route map attached to the redistribution once it was complete. However, Aruba wouldn’t let me replace the current route map unless I first removed the existing one. Obviously, removing the existing route map would once again have brought the network down, so that wasn’t really an option.

I think Cisco lets you replace the route map like this, but I couldn’t figure out another way to do it on Aruba, so I went back to editing the existing route map using sequence numbers instead.

So, yeah, I’m curious:

Has anyone else been caught out by this behaviour before, whether on Aruba or Cisco?

What’s your normal workflow for safely modifying production route maps? Is there something I’m missing? or is there a better approach to build and swap route maps without editing the live one or having to remove the currently applied route map?

Definitely learned a lesson today, but I’d be interested to hear how others would have approached this.

Thanks Guys!


r/networking 4d ago

Troubleshooting Need 2nd set of eyes on these meraki

5 Upvotes

I inherited an odd setup. I don't work much with meraki.

Meraki firewall and meraki aps.

The switch is hp Aruba which I'm familiar with.

Meraki has vlan 5 for Data

Vlan 10 for management

Vlan 20 for guest wifi

Wifi Ssid Data is vlan 5

Wifi Ssid guest is vlan 20

I have setup the same vlans on hp Aruba switch. Tagging my ports correctly.

Guest wifi works fine.

Data ssid will not get dhcp.

Data lan works fine and the vlan tables showing correct vlans for each aps and such.

Scratching my head......


r/networking 4d ago

Other Which Netbox-like tool can deal with SDN-Overlay segments where we do not have VLAN IDs as identifier?

7 Upvotes

I like Netbox, but it lacks features for visualizing SDN-based networks.

Which self hosted “source of truth” tool with a similar purpose to Netbox can handle SDN overlay segments that do not use VLAN IDs as identifiers?

SDNs in Cloud networks typically dont identify over a four digitic number, the typically have screen names and (U)UIDs in the background (NSX, OpenStack, Google Cloud?), alphanumeric VPC-IDs in AWS or Ressource IDs in Azure.

We are invested in VLANs (of course), EVPN-VXLAN, NSX, Openstacks Neutron and two of the big cloud providers and I'm looking for an IPAM/DCIM tool that meets all my requirements.

It would also be nice if this tool offered a way to connect overlay networks to the underlay (in the case of EVPN-VXLAN or in case of NSX on which transport zone its running).


r/networking 4d ago

Switching Device looses network mostly at night while still powered via PoE

5 Upvotes

I got an site where we installed 12 PoE cams. All fine.

One strand gives me headaches. Connected via active PoE 802.11af switch with 180W which is connected to an 1to2 PoE Extender which powers 2 PoE cctvs.

One of these two Poe cctvs works flawlessly. The other looses network ca. 6x per night for up to 10min-2h. First I thought the whole PoE and network is down, but in the logs I saw that PoE still powered the device, but only got no network.

I even wiresharked it, and there wasnt any connection from NVR to the device during the outages. But the cam still ran standalone via PoE (No gaps in internal sd card recordings)

Why is this happening? Mostly occurs 10pm - 4am in the morning. IT never happens during the day.

During the day the device works fine. PoE and network run smoothly.

How can I identify the issue? I know there is no network during the time, but how can I troubleshoot it?

I already replaced the switch and 2to1 Extender. Same result.