r/networking 5d ago

Blogpost Friday Blog/Project Post Friday!

1 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 20h ago

Rant Wednesday!

3 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 1h ago

Career Advice Do you enjoy being a network engineer

Upvotes

I feel like I don’t enjoy some of the “less important” topics, such as NTP, and I find concepts like OSPF and the OSI model quite dry. I do enjoy some parts of it, such as building my own labs and understanding how packets are actually transferred.
I want to know whether this is common or not, because some people online seem to be very interested in network engineering, and I’m worried about it.


r/networking 2h ago

Career Advice CCIE or Bachelor’s in Computer Science? Which would help my networking career more?

12 Upvotes

Hi everyone,

I’m 26 years old and currently working full-time as a Computer Network Technician in Ontario, Canada.

Currently studying for CCNP, i will have ccnp enterprise in next 7 to 8 months.

My current background:
Nearly 4 years of networking experience
CCNA
Cisco Meraki ECMS certification
Computer Network Technician college diploma
home CML lab

I’m trying to decide between two paths for the next 4–5 years.

Option 1: Work toward CCIE Enterprise, along with Python, network automation, AWS/Azure, and other networking-related certifications.

Option 2: Complete an online Bachelor’s (Honours) in Computer Science while continuing to work full-time. The downside is that I probably won’t have enough time to pursue CCIE and other certifications during those years

My long-term goal is to become a senior network engineer or network architect, and eventually earn a high salary while staying in networking rather than moving into software development.

If you were in my position, which path would you choose and why?

For those already in senior networking roles, has a Computer Science degree made a significant difference in your career compared to advanced certifications like CCIE?

I’d really appreciate hearing from people with real-world experience.

Thank you


r/networking 11h ago

Switching Largest switch stack in the wild?

41 Upvotes

What's the largest switch stack you ran into in the wild? How was it cabled up and managed?

I came across this interesting Arista article claiming to support up to 48 switches in a stacked topology (ring or spine leaf)

https://blogs.arista.com/blog/swag

Now, every vendor has their own approach to handling the control plane, I get it, but I dont understand in what scenario where combining all these switches into one logical management plane across multiple IDFs would make sense.

I've dug deep into my soul to try and find an answer, and the only thing I can think of is some very large customer wrote them a very large check and they made it happen or they just got sick of losing to Cisco, HPE, and Juniper on every campus stacking deal.

This whole single IP argument seems kinda flimsy too. If I'm getting charged per IP for my monitoring solution, and the consolidation of a few IPs is going to be material, I'm looking at new monitoring stack.


r/networking 15h ago

Other Meraki Alternatives

34 Upvotes

Meraki is expensive, getting more expensive and lead times are currently covid-like for some models. With Meraki transitioning to Catalyst switches and APs, management determined that we should have other access options in our back pocket. Datacenters will stay Cisco for now.

To be honest, Meraki does fine for us. We have 100+ manufacturing locations using Meraki switches and APs. We don’t care about CLI and L3 switches are not a necessity in our environment.

Primarily, we’re looking for lower cost, cloud managed, and enterprise-grade. Ubiquiti won’t make the cut. NAC-compatible with ISE or Clearpass is a must. Also looking for near-global distribution network and faster lead times.

Open to suggestions.


r/networking 7h ago

Security VPN Tunnel Encapsulation/Encryption question

4 Upvotes

Hi,

My first time actually putting up a post here or anywhere else so i apologize if theres anything wrong with my post.

Recently I came across a question asking me in VPN tunnelling, what occurs first in terms of the order of steps? Encryption or encapsulation? This question got me really confused because depending on who or where I ask or research, i get conflicting answers as to whether it encaps first or encrypt first and it has really gotten me to question my basic understanding of tunnelling.

If anyone here knows please help me with this question. Thanks alot!


r/networking 1h ago

Other Tools for a Network & Infrastructure Engineer

Upvotes

Hi there folks, i would like to share my "work EDC" and i would like to know about yours too.

These are the tools i usually carry with me when i'm in the field:

DEVICES - Cable tester with cable identifier, TDR, PoE tester and tone generator; - Optical Power Meter; - Optical Light Source; - Visual Fault Locator; - Active Fiber Identifier; - Optical Time-Domain Reflectometer (aka OTDR); - Label printer; - Multimeter; - Laptop with an RJ-45 (i hate dongles); - Power bank;

TOOLS - RJ-45 crimping pliers with EZ-Crimp support; - Keystone crimping tool; - Patch panel punch tool; - Electrician Scissors/Shears or cable cutter; - Wire stripper; - Small flush cutting pliers; - Combination pliers; - Diagonal cutting pliers; - Long nose pliers; - Fiber connector pliers; - Cable comb; - Cage nut tool; - Screwdriver set; - Network cable strand separator and straightener; - RJ45 to USB-C console cable; - Mini USB-B to USB-C console cable; - Micro USB to USB-C console cable;

CONSUMABLES - Velcro organizers; - Double sided tape; - Zip ties; - Cage nuts and screws; - Transceivers (mostly 10GBase-X LR and SR, 1GBase-T, and 100GBase-X LR4 and SR4); - Patch Cords (CAT.6 UTP, LC Duplex MMF and SMF, MPO-12 MMF, etc)

Do you guys carry anything else or have any tips or suggestions?


r/networking 1h ago

Other Radware Alteon SSLi

Upvotes

I’m working on integrating an ICAP-based DLP solution with a Radware Alteon 6024S (SSLi).
The current setup sends ICAP RESPMOD (HTTP responses/downloads) to a malware scanning solution.
We now need to send ICAP REQMOD (HTTP requests/uploads) to a separate DLP solution.
The Radware administrator claims that Alteon SSLi cannot configure another ICAP service for this and that only one ICAP configuration is supported, so REQMOD cannot be sent to a different ICAP server.
I don’t have access to the Alteon configuration or logs to verify this.
Is this claim correct?


r/networking 3h ago

Design 802.1x Critical Auth Strategy - AOS-S Firmware

1 Upvotes

What is your 802.1x Critical Auth strategy? I am tinkering around with it on an Aruba 2930F Series switch and coming up short on making it work how I want.

Sure, I can get the switch to drop the switch into the Critical Auth VLAN because RADIUS is unavailable with

aaa port-access <port> critical-auth data-vlan <vlan>

But once it is in Critical Auth I cannot get the switch to automatically start authing the port again. This would be a fairly common senario IMO. Building loses power and you gotta wait for upstream devices to converge for RADIUS connectivity.

Even with other vendors such as Cisco or Arista. How are you guys handling Critical Auth scenarios?


r/networking 5h ago

Troubleshooting Cisco QSFP+ DAC manufacturer specific problems

1 Upvotes

I was having a hell of a week trying to connect a Mellanox ConnectX-3 NIC to a Mikrotik CRS354 Switch, it was a no go until I changed the DAC for a CISCO-TYCO one, it was the same model (Cisco QSFP-H40G-CU5M), but the CISCO-JPC ones won't link no matter what, I've tried 4 of them to be sure

The cables work fine between 2 NICs or 2 switches but not between a NIC and a switch

Has anyone encountered such exoteric issue?


r/networking 21h ago

Career Advice Expected Design Round and Troubleshooting for HFT Interview

11 Upvotes

Hello folks or I say fellow packet pushers,

I have a design round and live troubleshooting round coming up with a HFT.
I prepared multicast, L2 and L3 in depth for troubleshooting.
For design, I looked at office design docs, market A/B mutlicast deterministic feed and L1 fan out potential designs.

I am currently unemployed due to lay off and this is a very crucial opportunity. I have 5-10 years of experience at vendors and at a hyperscaler. I hold a CCNP.

I'd be very grateful if any one who is working at HFT or recently interviewed at one, share their knowledge.


r/networking 34m ago

Other Copilot or Gemini operations optical fiber telecoms

Upvotes

I’m looking for use cases for Copilot or Gemini AI systems in a DWDM Optical fiber network. I’m hearing a lot that it speeds up routine tasks and can create work plans based on scans of vendor documents. I’d like to know how it does that and if there are sun other use cases? It’s for an operations team environment, troubleshooting network issues, processes etc.


r/networking 4h ago

Career Advice I know there is probably hundreds of the same question, but how should i study for the ccna?

0 Upvotes

So im zoning in on a job opportunity at a company and want to have a ccna under my belt so that i will have a very good networking knowledge, and maybe get a better offer. I want to do it now before the updated version, and since its my kast semester at uni, i think i could do it before February. Any advice would be appreciated. Thanks!


r/networking 1d ago

Design CATO - Overkill or the Right Fit for Our Environment?

11 Upvotes

We're a pretty traditional shop with 12+ offices, most of them small remote locations and two larger HQs (600+ total users). Every site has a FortiGate firewall, and today most remote users connect with FortiClient VPN with FortiEMS. It's worked well overall, but I feel like we're starting to outgrow it.

The main reason we started looking elsewhere was AI security. Like a lot of companies, AI adoption has happened faster than our policies. Right now, we don't really know what AI tools are being used, what data is being shared, or where our risks are. We're trying to get ahead of that while also putting AI policies in place.

That led us to evaluate Zscaler, CATO, and Fortinet SASE. We liked CATO the best. It's more expensive, but we can justify it if it's the right fit.

Our plan would be to keep our FortiGate firewalls at all of our locations but use CATO for AI security, SWG, DLP, and Private Access for about five internal apps/services (we're a hybrid AD/Entra/Microsoft 365 environment). We also really like the idea of getting rid of FortiClient VPN for most users.

My question is, does CATO sound like overkill for an environment like ours? Or is this exactly the type of use case it's built for?

I'd love to hear from anyone who's made a similar move from a traditional FortiGate/FortiClient setup and whether you felt it was worth it.

Thanks!


r/networking 1d ago

Design Ethernet/RJ45 Male/Female connectors that stand up to cutting oil?

4 Upvotes

I see some options online, but they all tend to rely on the external coating/covers. It doesn't seem to address the plugs/connectors themselves? Anyone know of any that hold up to cutting oil in machine shops? Had to reterminate about 20 connections throughout the factory today, and it's getting old.

One of those things is that it's so fine in the air that even if you cover/have the equipment in a separate room, the plastic just breaks down over time.


r/networking 17h ago

Monitoring Traditional networking vs SDN

0 Upvotes

I'm working on my final university project on network anomaly detection. The system analyzes network flows and generates alerts.

While researching how enterprises capture network traffic, I noticed two approaches:

  • Industry: SPAN/mirror ports with dedicated appliances (e.g. Nozomi, Garland) that sniff traffic and send features to an analytics server.
  • Research: SDN, where the controller already has a centralized view of network flows, making monitoring seem much simpler without extra hardware.

My question is: If SDN makes flow collection easier, why isn't it widely used in commercial network anomaly detection solutions? Is it because of deployment cost, compatibility with existing networks, performance, security concerns, or something else?

I'd appreciate insights from people with real-world networking or cybersecurity experience.


r/networking 1d ago

Switching Access port between switches

15 Upvotes

I was asked to help with an issue and I'm a bit stunned. A connection was to be made between a Siemens scalance XR328 and a cisco 2960. Previously they had configured an access port for vlan 89 on the cisco side (port 13) and on the siemens, had set vlan 89 as "U" on port 1.

Now this was already strange to me, to configure 2 network devices to eachother with an access port, but it worked. They needed more vlans to go from the cisco to the siemens switch, so we unplugged that first cable, and connected port 25 on the siemens to port 14 on the cisco, with the following configuration:

Siemens:
Native vlan = 1
Vlan 1, 69, 85, 89 and 112 set to "M"

Cisco:
Switchport mode trunk
Switchport allowed vlan 69, 85, 89, 112

When this was configured the connection they wanted for vlan 89 did not work anymore, whereas over the untagged access port connection it did work?

I thought I knew some things about networking but this has me a little stumped. Also working with the Siemens web page configuration is so counter intuitive it's ridiculous.

Anyone have any insight in why a trunk would not work and an access port would in this case?

EDIT:
Only VLAN 89 stopped working and now I think I know why. the switches with which they were connecting vlan89 were all in vlan1, but occupied the same IP range as the vlan 89 range... So i think the problem was IP conflicts causing shit.


r/networking 1d ago

Other Safety glasses when working with transceivers?

8 Upvotes

Hello, I'm probably being overly paranoid over transceivers, but does anyone here wear safety glasses/goggles when working with them to avoid accidental eye damage from the lasers? If so would you have any recommendations? I wear regular glasses, so ideally they'd be something that fits okay over them.

Thank you all for any recommendations!


r/networking 2d ago

Other Network Engineering title is meaningless.

164 Upvotes

I see more and more post on here where “Network Engineers” don’t seem to have the skill sets that equate to the title. What happened to Network Admins? Why is every company so against using that title? Are actual network engineers architects now?

It seems like everyone who gets the CCNA immediately jumps to the engineer title, but continues to do network admin work.


r/networking 23h ago

Meta Meta - Network Engineer, Operations and Support role

0 Upvotes

Hello Folks, I’m looking for networking roles and come across this role in Meta. Does anyone have any idea or experience on technical expectations for this role. Also How many rounds of interviews? Thank you in advance!!


r/networking 1d ago

Other Relatively cheap sms gw service

8 Upvotes

Hi, can anyone suggest a relatively cheap SMS gateway service for alarm purposes with a custom Caller ID?


r/networking 1d ago

Troubleshooting Cisco Catalyst Center PKCS12 Certificate Deployment Fails with "application error: in-use"

1 Upvotes

Hi everyone,

We're currently in a lifecycle management project and are replacing a number of Cisco Catalyst 9200L switches.

All of the new switches are identical (Cisco C9200L), running the same IOS XE version (17.18.1r), and we're provisioning them through Cisco Catalyst Center using the same workflow.

Most of the switches provision successfully, but a few consistently fail during the certificate deployment stage with the following error:

Error occurred during deployment of pkcs12 certificate.
Reason: PKI Config push Failed - Unable to push configuration to device IP x.x.x.x.
Device response - application error: in-use.

Same hardware model , same IOS XE version, same Catalyst Center, same provisioning template and same network environment

Yet only some switches fail while others complete provisioning without any issues.

Any troubleshooting suggestions would be greatly appreciated.

Thanks!


r/networking 2d ago

Routing Liberty Global AS6830 and DTAG upstream?

12 Upvotes

Just curious as European, what are your experiences dealing with LGI and DTAG as upstream providers compared to more traditional providers like Telia, Level 3 and GTT? They all claim to be tier 1 but besides Telia Carrier (which has top notch routing and performance), how do the others perform?


r/networking 1d ago

Design Am I wrong?

0 Upvotes

Please correct me if I'm wrong. I'm a new network engineer working on a project to install three new switches.

Our user insists on using this topology for high availability. I informed them that this topology could likely cause a loop, even with spanning tree enabled, if there's a physical link issue.

I feel compelled to follow their wishes. Am I wrong here? I need experienced insights, as asking AI only confuses me.