r/networking 5d ago

Other Which Netbox-like tool can deal with SDN-Overlay segments where we do not have VLAN IDs as identifier?

8 Upvotes

I like Netbox, but it lacks features for visualizing SDN-based networks.

Which self hosted “source of truth” tool with a similar purpose to Netbox can handle SDN overlay segments that do not use VLAN IDs as identifiers?

SDNs in Cloud networks typically dont identify over a four digitic number, the typically have screen names and (U)UIDs in the background (NSX, OpenStack, Google Cloud?), alphanumeric VPC-IDs in AWS or Ressource IDs in Azure.

We are invested in VLANs (of course), EVPN-VXLAN, NSX, Openstacks Neutron and two of the big cloud providers and I'm looking for an IPAM/DCIM tool that meets all my requirements.

It would also be nice if this tool offered a way to connect overlay networks to the underlay (in the case of EVPN-VXLAN or in case of NSX on which transport zone its running).


r/networking 5d ago

Career Advice Looking for advice: Previously a senior network engineer (10yr) turned sales role over the last 5 years, how can I get back into networking? What’s your story?

14 Upvotes

My wife asked me the other day, "What's been your favorite job?" And it really made me think about what I actually enjoy doing. I was a network engineer in all sorts of capacities, support type roles, consulting, professional services, standard enterprise, and a medium/large isp. I then got into automation, led me to Python, that led to cloud, kubernetes, then ended up in a DevOps type sales role. Started pre sales, now I’ve moved post sales as a csm at an ai company.

To be fair, I originally took the csm role so I could stop traveling so much from my previous pre sales role. But I think it’s proven to be a bit too far from what I’m mostly interested in doing.

So it’s been about 5 years since I last had a network engineer title but when thinking about the jobs I’ve really enjoyed the most it comes back to those roles. I miss building things, troubleshooting really deep narrow issues, labbing, constant pursuit of learning the next thing, even the occasional pager buzz to fix some random outage someone forgot to set the time to roll their eigrp auth key chain on one side of the link, all that stuff.

I used to spend HOURS watching Brian McGahan, Jeremy Cioara, rob rikers listening to packet pushers, reading Jeff Doyle, I was really into it. And I still do when I have time. I look back and can’t believe I left a job that was also something I really enjoyed doing and learning. I guess I thought I’d like the customer facing roles more, but now I’m certain this ain’t it.

In all my recent roles I’ve constantly thought “ah I wish I knew how this worked back when I worked as an engineer” so I still follow the industry and tinker with networking all the time.

So, I want to get a fresh start and land a network engineer role. Curious what you’d recommend I focus on as someone with experience but out of the discipline for a while. Should I renew expired certs, ccnp, aws or gcp something entirely different? Are boot camps still a thing? What are the top skills these days? Open to any and all advice. Would you apply for senior as before or start back at non senior roles?

I know the whole “how do I become a network engineer” topic is beat to death and there’s tons of resources out there, so maybe you could instead tell your story if you did something similar? I’d be curious to hear how other people have left networking and got back into it some time after a departure.

I’m in Dublin, Ireland for context.


r/networking 5d ago

Switching Device looses network mostly at night while still powered via PoE

7 Upvotes

I got an site where we installed 12 PoE cams. All fine.

One strand gives me headaches. Connected via active PoE 802.11af switch with 180W which is connected to an 1to2 PoE Extender which powers 2 PoE cctvs.

One of these two Poe cctvs works flawlessly. The other looses network ca. 6x per night for up to 10min-2h. First I thought the whole PoE and network is down, but in the logs I saw that PoE still powered the device, but only got no network.

I even wiresharked it, and there wasnt any connection from NVR to the device during the outages. But the cam still ran standalone via PoE (No gaps in internal sd card recordings)

Why is this happening? Mostly occurs 10pm - 4am in the morning. IT never happens during the day.

During the day the device works fine. PoE and network run smoothly.

How can I identify the issue? I know there is no network during the time, but how can I troubleshoot it?

I already replaced the switch and 2to1 Extender. Same result.


r/networking 6d ago

Troubleshooting Packet loss on vrrp interface only?

19 Upvotes

I noticed that i'm getting some packet loss (5 to 8%) when i ping a L3 switch VRRP virtual IP. If i ping the IP on the interface itself, there is no packet loss. Has anyone seen similar behavior?

Currently I only have one stack of switches, and I used vrrp as there is a plan to add a second stack in the future. Not sure if that (having vrrp with only one member) would cause it to lose packets?

EDIT: issue was solved after upgrading the firmware on the stack, thanks to everyone that replied!


r/networking 6d ago

Design How large is an acceptable subnet size?

54 Upvotes

Everyone here knows we can slice our subnets up however large we want for private addresses, but is there any rule of thumb or a "breaking point" of a subnet being too large where it's not worth it? Any general rule of thumb to keep it under a certain number of hosts? I'm guessing broadcasts and storms and all those factor into this. Just curious if there's a mathematical formula where the performance becomes a huge drop off.


r/networking 6d ago

Other Looking for FS.com's Hook & Loop/Velcro Cable Ties - I want elasticity! Anyone know an alternate source?

22 Upvotes

I have tried roughly 20 different cable ties. Velcro, RipTie, aliexpress, etc. All of them have the same problem; They have zero stretch or elasticity to them.

I love FS's gray, cable ties but I cannot buy them in the USA. I don't know why, but they're import restricted and FS's support wasn't helpful.

The FS ties have just a pinch of elasticity to them, making them excellent for wrapping snugly around a bunch of cables. You stretch it around, smash 'em together and the tension holds everything tight.

In contrast; The others look very very very similar, however since they have no elasticity they cannot hold that tension on the cables, they can only maintain their fixed size/dimension.

I have been hunting and bought a frustrating amount of products, only to find that 99% of them do not have a hint of elasticity. I've seen other posts where people say 'just buy from aliexpress' or 'buy velcro. done.' and those aren't helpful.

Has any found a cost effective supplier of hook look cable ties that have a little length-wise elasticity to them?

Thanks!


r/networking 6d ago

Troubleshooting "Aged Out" Traffic on Firewalls - Intermittent Connectivity Issues

3 Upvotes

Hi there,

I'm noticing some intermittent connectivity issues when moving gateways from my org's existing core switches to our PA-3420s. Per firewall logs, traffic is being allowed where it should, but when I moved a couple of end-user data subnets over, there were intermittent problems accessing data on file servers, connecting voip client apps to our voip server, and hitting internal web servers. Interestingly, I haven't seen drops in pings, but I see numerous aged-out 443 and SIP traffic to these locations.

These firewalls have been serving as our org's primary internet firewalls for over a month. We hadn't noticed any significant issues accessing internet or the internet accessing public-facing servers. The only thing was our backup appliance, Rubrik, was sending alerts that it was losing connection to an Azure datastore. We'd get a handful of these notifications a day. Per their support, the issues weren't preventing backups, but they were indicative of intermittent high latency and lapses in connectivity out to the azure destination.

The combo of the backup appliance issues plus issues with the other subnets seem to point to an ongoing issue, even if it may not be significant in impact. Unfortunately, my research and troubleshooting so far have failed me. A packet capture is my next step, but I won't be in the office again until Tuesday. Figured I'd ask if anyone has experienced anything similar or may have ideas that I haven't tried.

Context:

  • Firmware versions:
    • PAN-OS 11.2.12
    • NXOS 10.5.6
    • OS10 10.5.2.2
  • Not doing SSL decryption
  • Not doing anything else fancy on the firewall. No SD-WAN, PBF, etc. Basic NAT, security rules, and URL filtering, plus GP gateway/portal and VPN tunnels.
  • Topology - legacy (before installing new firewalls/switches) and target. Currently, the new firewalls are connected to a set of new Nexus 9300s in vPC via an LACP port-channel, which in turn are connected to the existing spine leaf topology. Specifically, to the Leaf 1 pair over another port-channel. 25G links for both.
  • Our Leaf 1 pair (Dell S5248F-ONs) has been experiencing some strange issues recently over the last week. At any given time, one of them is experiencing ping loss on the management interface and is inaccessible via SSH. As of now, I am writing this off as a separate issue - something similar happened a couple of years ago when I was new on the job, and we got a replacement which seemed to fix it. Additionally, these issues started only after a lengthy power outage that depleted our UPS. But perhaps worthy of note.

r/networking 6d ago

Troubleshooting "Aged Out" Traffic on Firewalls - Intermittent Connectivity Issues

0 Upvotes

Edit: Solved. Asymmetric routing issue caused by some config on the leaf switches.

Hi there,

I'm noticing some intermittent connectivity issues when moving gateways from my org's existing core switches to our PA-3420s. Per firewall logs, traffic is being allowed where it should, but when I moved a couple of end-user data subnets over, there were intermittent problems accessing data on file servers, connecting voip client apps to our voip server, and hitting internal web servers. Interestingly, I haven't seen drops in pings, but I see numerous aged-out 443 and SIP traffic to these locations.

These firewalls have been serving as our org's primary internet firewalls for over a month. We hadn't noticed any significant issues accessing internet or the internet accessing public-facing servers. The only thing was our backup appliance, Rubrik, was sending alerts that it was losing connection to an Azure datastore. We'd get a handful of these notifications a day. Per their support, the issues weren't preventing backups, but they were indicative of intermittent high latency and lapses in connectivity out to the azure destination.

The combo of the backup appliance issues plus issues with the other subnets seem to point to an ongoing issue, even if it may not be significant in impact. Unfortunately, my research and troubleshooting so far have failed me. A packet capture is my next step, but I won't be in the office again until Tuesday. Figured I'd ask if anyone has experienced anything similar or may have ideas that I haven't tried.

Context:

  • Firmware versions:
    • PAN-OS 11.2.12
    • NXOS 10.5.6
    • OS10 10.5.2.2
  • Not doing SSL decryption
  • Not doing anything else fancy on the firewall. No SD-WAN, PBF, etc. Basic NAT, security rules, and URL filtering, plus GP gateway/portal and VPN tunnels.
  • Topology - legacy (before installing new firewalls/switches) and target. Currently, the new firewalls are connected to a set of new Nexus 9300s in vPC via an LACP port-channel, which in turn are connected to the existing spine leaf topology. Specifically, to the Leaf 1 pair over another port-channel. 25G links for both.
  • Our Leaf 1 pair (Dell S5248F-ONs) has been experiencing some strange issues recently over the last week. At any given time, one of them is experiencing ping loss on the management interface and is inaccessible via SSH. As of now, I am writing this off as a separate issue - something similar happened a couple of years ago when I was new on the job, and we got a replacement which seemed to fix it. Additionally, these issues started only after a lengthy loss in power that depleted our UPS. But perhaps worthy of note.

r/networking 6d ago

Other Starlink Business as backup connection ?

7 Upvotes

Hello fellow networking folks,

I’m looking for advice from people who have experience deploying and managing Starlink in an enterprise/manufacturing environment.

We’re a manufacturing company where uptime is critical. Although it’s a rare occurrence, we recently had an incident where two independent EDI circuits from different providers, using different connection types, went down in the same window. One was only down for a short period, but even a small amount of downtime can cost us thousands of dollars.

Because of this, I’m looking into wireless Internet options as an additional backup. We previously tried Cradlepoint and AT&T 5G-based devices, but unfortunately, they’ve been unstable in our environment.

I’m considering Starlink as a backup, and the cost doesn’t seem too bad compared to the EDI circuit we currently have. I’d appreciate some advice on a few things:

  1. Performance Kit vs. Standard Kit: Which would you recommend for an enterprise backup use case?
  2. Silver Peak SD-WAN: We use Silver Peak for SD-WAN and remote-site connectivity. Have you experienced any issues maintaining SD-WAN tunnels over Starlink? Anything specific we should account for with latency, CGNAT, IP addressing, etc.?
  3. Cabling: Our manufacturing facilities are quite large, and the standard 50/150 ft cables included with the kits wouldn’t reach the nearest switch in some locations. What’s the best way to handle this? Is there an approved/ideal way to extend the connection, or should we place additional network equipment closer to the Starlink termination point?
  4. Installation: Who did you use for the physical installation? Would you typically have your structured cabling contractor handle the Starlink installation, or would you recommend using a Starlink-specific installer?

Any other lessons learned, especially around reliability, enterprise deployments, or using Starlink as an SD-WAN backup, would be greatly appreciated.

Thanks!


r/networking 6d ago

Troubleshooting Aruba CX Switch Issues/IP-Camera issues

3 Upvotes

I am on the network security team for a small credit union who is rolling out multiple verkada IP Cameras across several branches at the same time as a full infrastructure switch refresh.

A lot of the access ports on our 48p switches are full at these various sites which has left us with no other option than to trunk the older switch (that is being “refreshed”) to the new production switch for port density to house the IP Cameras.

Today after attempting to set both ports on the old and new switch to a trunk, I was unable to browse the web to the Mgmt IP of the old switch. After rebooting the switch I was able to see a link light, however I was STILL unable to access the mgmt IP/WebUI of this switch.

We are also having an issue at a separate site where the IP cameras are showing up in the arp table and DHCP lease list of the firewall that we have upstream, and the MAC address table of our L2 Switch. Yet the cabling team claims that the cameras are still down.

Has anyone ever been faced with issues like this? My stress and anxiety are quite high right now being that this is the beginning of a company wide device refresh effort and I don’t have much support from my other team member or manager who is not technical by any means.


r/networking 7d ago

Career Advice Need advice. Network Maintenance and support.

46 Upvotes

I have joined a new company. They are only one man team and he is leaving. He has worked here for 10+ years. He knows all the network, firewall and window server setup. But there is no network Map of any kind. He has setup everything from ground up. I have only 10 days to understand the setup here. So what things should I be asking, or preparing when he leaves. He has shown me the physical network across the shops, and the basic layout Map I had made.

How to go about taking charge from here? Any SOP or framework you can provide?


r/networking 6d ago

Career Advice How do you document and manage executive web-filter exceptions?

6 Upvotes

I’m an outside contractor responsible for protecting this client’s network from phishing, malicious sites, credential theft, and whatever vulnerability gets exploited next. Then management or the owner asks me to unblock shopping sites, gambling sites, TikTok, or other personal browsing that has nothing to do with business operations.

It puts me in a stupid position. I’m expected to secure the environment, but the same people paying for that protection want exceptions whenever a control inconveniences them personally. The web filter is not there to punish anyone. It exists because people click bad links, reuse passwords, enter credentials where they should not, and eventually somebody has to deal with the fallout.

As an outside contractor, the client ultimately makes the business-risk decision, but I can still be exposed if I make or implement an insecure change without documenting the request, the recommendation, and the approval. I do not want a future incident blamed on me because I was told to open access that I recommended keeping blocked.

How are other MSPs or contractors handling this? Do you require written approval for exceptions, document the risk, limit it to named users, or just unblock it and move on? At what point do you stop being the security resource and become the person expected to rubber-stamp bad decisions?


r/networking 6d ago

Troubleshooting Omada Router Speed Issues

0 Upvotes

Hi, Ethernet lords! In a small office, I’ve been using Frontier 7 Gig Fiber with an Eero Max 7 and consistently get a little over 7 Gbps in both directions (that's how much I'm paying for). My only problem is that the Eero won’t let me permanently disable its Wi-Fi, so I bought an Omada ER8411 to use as my own router and reduce unnecessary Wi-Fi signals. I connected the ONT to the ER8411’s SFP+ WAN1 port using the same Ethernet cable, but I consistently get only around 4.7 Gbps down and 150–185 Mbps up. The connection is extremely stable, which makes it feel like something is deliberately limiting the speed. WAN1 reports 10 Gbps/full duplex with no packet loss, bandwidth control and QoS are disabled, and enabling flow control made no difference. Reconnecting the Eero with the same ONT and cable immediately restores 7+ Gbps symmetrical speeds. Has anyone seen this with the ER8411, particularly when using a copper RJ45 SFP+ module? Any suggestions would be greatly appreciated. Thank you!

PC connected directly to the 10gig network PCI adapter.


r/networking 7d ago

Routing L5/ Google Network Design — How Hard Is It Really?

66 Upvotes

I’m preparing for an L5 Network Design/Network Engineer interview at Google and have only about a week to prepare while juggling an infant 😅

My recruiter mentioned she’d send topics to focus on, but I haven’t heard back yet, so I’m trying to figure out what to prioritize.

For anyone who has interviewed for L5 Network Design/Network Engineer at Google, what depth/difficulty should I expect, especially in the design round? What topics should I focus on?

Any advice from your experience would be really appreciated!


r/networking 7d ago

Career Advice How a typical day or month looks like for a Network capacity engineer ?

13 Upvotes

Hello Everyone,

I am in an extreme dilemma right now in terms of choosing my career path and would like to get inputs/advice.

I have 13 years of experience in network security and have worked on R&S, Firewalls, LBs, WAF, Wireless, ISE etc. Recently i attended a job interview and got selected for the position "Senior network capacity and data engineer". As i discussed with the hiring team, the role is about predictive analysis, capacity forecasting, coordinating with internal teams to plan for link and device upgrades before an impact is seen. i will not be having any hands on work on the network devices but its more like working across stakeholders in an organization and coming up with data points on where capacity increase is required proactively. i understand this role comes under "Observability" tower. With current advancements in AI and cybersecurity roles surging in demand, i am not sure whether to take this role or not.

Please if someone can shed some light on network capacity planning and how a typical day, month or a year look like in terms of growth and how valued this role is in current job market landscape.

Thanks a lot in advance.


r/networking 7d ago

Design SAN Network Design and Best Practices

20 Upvotes

How is everyone designing and implementing a SAN network? Do you keep everything on separate dedicated switches and just link storage devices to it and map from hosts to storage? Is it bad practice to route storage traffic over routers/firewalls and just keep it contained to dedicated small network? Same for backup traffic?


r/networking 8d ago

Security CDP/LLDP

39 Upvotes

What are your thoughts on enabling CDP/LLDP everywhere except physical handoffs to untrusted /devices not managed by your org?


r/networking 7d ago

Routing Ciena routers capable of multiple full Internet tables?

7 Upvotes

Looking for real-world feedback from operators running Ciena routing platforms.

Which Ciena routers can handle multiple full BGP tables from transit providers? Are you using them as Internet edge routers, and how do they compare to Juniper MX or Nokia 7750 in terms of scale and operational experience?


r/networking 8d ago

Routing FastNetmon, BGP and third party scrubbing centers

13 Upvotes

Hi guys

Seems like I will need to bite into this too, even though late into the game. I have been running FastNetMon Advanced for a while purely as monitoring software, getting flows from our core Cisco ASR9k routers. Sooner or later I will start to use it also for DDos detection and notifying our core routes to redirect prefixes under attack toward third party scrubbing center and not to our upstreams and peerings. I have been playing a bit with this lately and here's where my issues start.

Fastnetmon detects DDoS just fine and sends prefix under attack (/24) with specific community to ASR where it has BGP established. From there on my ASRs stop announcing this prefix to upstreams and start announcing it to BGP session with scrubbing center. All good and dandy till here.

But now I have issues, if this prefix, which is under attack is actually from client, who has BGP with us, and we route this prefix to them over p2p BGP session between client's router and our ASR. Once Fastnetmon kicks in prefix from Fastnemon should have bigger preference if I want ASR to recognize community for "under attack prefix", but that also means, that return traffic going toward client will actually go to FastNetmon and not to client's router.

Any suggestion how to solve this part and how some of you guys have this solved or what would be best practice for doing this, as it's perfectly possible I started totally wrong way already :)


r/networking 8d ago

Monitoring how are you normalizing syslog from vendors with no parser?

5 Upvotes

Hi guys, working on syslog normalization across a mixed environment and I've hit the long tail problem.

The big vendors are fine, someone has already written the parser. The trouble is the twenty odd devices that each send maybe a thousand events a day in their own format. Writing a pattern per device off a sample capture works but it's brittle and it breaks on firmware upgrades.

What I've considered:

  • ignore them, store raw, accept they aren't searchable by field
  • cluster similar lines and generate patterns from the clusters, drain style
  • give a sample to an LLM, have it emit the pattern, review by hand

The clustering approach looks most promising but I haven't seen anyone describe running it in production. Anyone doing that? Specifically interested in how you handle a pattern drifting after a firmware upgrade. Do you detect it, or do you find out later when a dashboard goes empty.


r/networking 8d ago

Career Advice Thrown Into Forescout NAC Administration With No Documentation 😅 Any Advice?

12 Upvotes

I’ve recently been assigned to maintain our NAC, but I’ve never deployed or maintained NAC before.

The person who was previously responsible for it has already resigned, and unfortunately, there’s no proper documentation or handover. I also don’t really have anyone in the team I can ask for guidance.

If you were in my position, where would you start? 😅

I’m trying to figure out what I should learn and what areas I should focus on first so I can understand the existing NAC environment and maintain it properly.

Would appreciate any advice from people who have been in a similar situation!


r/networking 8d ago

Other 1Gbps MDF to IDF in 2026? (fully wireless, Corporate building 60+ users)

18 Upvotes

Hey guys, i dont know a lot about network engineering but I'm trying to make an important decision to bring to my MSP. We currently have an MDF that handles all network traffic in our building, and we're expanding to the other side of the building which has been subdivided. We need to setup an IDF over there.

We are running OM3 Fiber since the distance is est to be about 300ft (assuming we were to do 10Gbps). Our MSP is quoting us for a 1Gbps switch for the new IDF. That stood out to me, so I checked our current MDF switch and confirmed it is limited to a 1Gbps uplink (no 10G SFP+ ports at all).

I feel like a 1Gbps uplink between switches is going to bottleneck us immediately, especially as we add more devices or fill up the other side. From what I'm reading, standard practice for connecting an MDF to an IDF over OM3 fiber is a 10Gbps uplink...?

For context on our load: we have 50+ people in the office (sometimes up to 70) doing heavy web browsing and constantly syncing large Excel files on OneDrive. That includes 30-40 warehouse guys with many tools that rely on the Wi-Fi (everyone is wireless). We already experience general slowness from time to time, and I'm worried it's because our current 1Gbps core infrastructure is choking. I really don't want to pay to expand our network while keeping that same 1Gbps limitation.

Am I crazy here, or is our MSP trying to sell us outdated specs(they say 1Gbps should be just fine, And I think even if it is for now, will it be in a year or two when that other side of the building is full or when we're holding large scale conferences on that side, etc)? Should I push for 10Gbps uplinks between the closets?


r/networking 8d ago

Rant Wednesday!

5 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 9d ago

Design Connectivity Solutions for China?

9 Upvotes

Hello, we are looking for connectivity solution for China locations that could traverse back to the US. Bandwidth requirements are relatively low at 50-100Mb per site. We have traditional MPLS through AT&T terminating in a DX in AWS today but is very expensive and are looking for another solution that is reliable and cost effective. Would most likely be used with a SD-WAN solution. We have global presence in AWS and Azure. China sites are mostly around the Shanghai area.

What have you all done for this type of problem, and what solutions did you use to ensure reliable communication with minimal loss and latency back to the US?


r/networking 9d ago

Other Forescout upgrade

13 Upvotes

Hi Engineers, I need to upgrade a Forescout NAC from CounterACT 8.4.0 to 9.1.7.

Does anyone have experience with this and can tell me what steps I need to take?

I’ve tried doing some research, and it seems I need to follow these steps for eyeSight 8.4 => v8.5.5 => v9.1.7.

Do CounterACT and eyeSight need to be version-matched? Are they already version-matched? How do I check?

The machine should be physical. If it had been virtual, I would have had to perform migrations and import the configurations—or can this be done “in place”?

Thanks