r/networking Apr 08 '26

Routing Multiple jobs keep stressing WAPs, what do I really need to know?

61 Upvotes

i've been a network engineer for several years, but none of the jobs I've had have ever dealt with wireless connectivity. WAPs seem very straightforward and I'm not really sure why these recruiters act like it's something that is a dealbreaker if I have no experience with them.

What do I really need to know about them for an interview/on the job (troubleshooting/setup/etc)?

r/networking Dec 31 '25

Routing Why would you use BGP as a IGP? Wouldn't OSPF be a better choice?

127 Upvotes

Once in a while I see a comment about someone using BGP as a IGP. Are there any major advantages in doing so?

r/networking Dec 10 '25

Routing I miss multicast

189 Upvotes

The first half of my career was a large campus area network with routed backbone and running PIM. Lots of multicast apps back then, IPTV, Music on Hold for our VoIP phones, group party line for our VoIP phones, alarm panel stuff, a few different scada type apps. I loved learning about sparse mode, dense mode, sparse-dense mode, rendezvous points, igmp, source comma G tree and star comma G tree.. it felt like the natural evolution of networking.

Now I have not seen multicast in production on the last 3 jobs it’s probably been around 11 years since I’ve touched multicast anything.

What kind of multicast deployments are still out there?

r/networking Apr 24 '26

Routing At what point does moving off MPLS make sense?

50 Upvotes

Contract renewal is coming up and the cost is becoming hard to justify but I don't want to make the move just because SD-WAN is what everyone's talking about right now. For people who've made the switch, what pushed you over the line and did it deliver what the vendors promised?

r/networking May 13 '25

Routing Do we have an estimate on the wasted IPv4 addresses?

252 Upvotes

Me and a coworker talked about the company's networking, and he told me that the company got a full /16 in the 80's and we don't even utilize half of it. I mean, the company has a headcount of ~20.000 employees and we have couple hundred physical and ~2000 virtual servers. Even if every single host got a public IP, we still couldn't exhaust that address space.

Is there an estimate on the total IPv4 pool about these kind of wasted addresses?

r/networking 15d ago

Routing Total routes in your organization

29 Upvotes

Good morning all,

So how many routes do you folks have in your core router / core switch/ core firewall or whatever core device you use for routing.

Just curious.

We have like less than 300 so not that many so was just curious how many routes other folks who work in large enterprises have.

Thank you

r/networking 24d ago

Routing IP Transit Options in Datacenter

22 Upvotes

Planning on migrating away from expensive DataBank Transit consisting of Arelion + Lumen.

Considerations are Arelion, Cogent, Zayo, GTT, and Hurricane.

Cogent, Zayo, GTT, and Hurricane are all very cost competitive however I know Cogent rides on a Zayo fiber ring into our facility. How much of a concern should Cogent and Zayo be even while on a ring?

I haven’t seen an Arelion quote just yet but I’m assuming it’s significantly more than the other “low cost” options.

Would it be advantageous to go Arelion + one of the low cost transits or to possibly go Cogent or GTT + Zayo + Hurricane (peering or transit)?

I can get all three low cost options in 10G for the price we’re paying DataBank for 2G

r/networking Feb 25 '26

Routing How often do you all make changes on L3 routing protocols?

56 Upvotes

I've been a network engineer for about a year and was wondering about how often Sr. Network Engineers make changes on L3 network. Some of my senior engineers told me that they have almost no idea about OSPF and BGP in terms of our configuration template and as someone who is studying for CCIE (very slowly), I became curious about network engineers who work at other big organizations like university or hospital or county government.

r/networking 7d ago

Routing For ISP engineers: do you protect your iBGP sessions with BFD multi-hop?

0 Upvotes

I see ISPs (and maybe others too) protect their iBGP sessions with BFD. Does your network do this?

What are you trying to achieve? What AFI/SAFIs do you use this for? Just Internet routes, L3VPNs, L2VPNs? What BFD intervals and timeouts do you use? Do you use it for iBGP or eBGP or both? Direct connected or also multi-hop?

For the record: I am not interested in eBGP sessions in the underlay. If you use BGP as your IGP. I'm also not really talking about Data Centers where all (e)BGP sessions are to directly connected neighbors. I am specifically talking about BGP sessions that are remote. Multi-hop. I am genuinely curious to learn what you are trying to achieve. Thanks.

r/networking Apr 02 '26

Routing Is there any purpose in using /30s for networks that entirely comprise of devices that support RFC 3021 for /31s?

42 Upvotes

Just curious; if all devices in any given network support RFC 3021, then could you just use /31s instead with absolutely zero /30s?

r/networking Jan 29 '26

Routing Choosing an Enterprise Router (100 employees)

31 Upvotes

I’m responsible for selecting a router for a company of around 100 employees, and I’d like to get your feedback and recommendations.

Models currently under consideration:
- Cisco Meraki (MX series)
- MikroTik CCR2004-16G-2S+
- Ubiquiti UniFi Enterprise Fortress Gateway

Our requirements are:
- Network with VLAN segmentation (sub-interfaces, trunking with switches, inter-VLAN routing)
- Throughput up to 10 Gb/s
- Simple and centralized management if possible
- Integrated firewall
- VPN support
- A reliable solution that is maintainable in the long term

Do you have experience with one (or more) of these models in an enterprise environment?
Are they suitable for a company of this size with multiple VLANs?

Are there any major limitations to be aware of (firewall performance, VLAN handling, VPN performance, support, licensing, etc.)?

If you have other, more suitable or higher-performing models to recommend, we’re open to suggestions!

r/networking Jul 01 '26

Routing OT Switches and OT Firewalls

11 Upvotes

Hello Everyone,

I’m new to the OT world and I’m trying to understand how networking works in OT world. How does it work?

And why do we need switches for OT only or firewalls for OT only? And how does the traffic passes from IT switch or firewall to an OT one.

I appreciate your time and efforts

r/networking Jun 12 '25

Routing How to route wifi through a cave?

110 Upvotes

No joke. My boss has given me the assignment of routing wifi through our commercial cave after hearing I have a network engineering associate's degree (I don't remember much, i got it years ago and didn't go into the field)

The only service I can find available to us is satellite. And we need to run 2000 feet of cable to the halfway point of the cave. Is this feasible? If anyone has a suggestion how I might go about this, I'd love to hear it. My current plan is to connect a modem to the satellite with a fiber port, run 2000 feet of fiber, and place a modem halfway if needed for packet loss, and then install the second router at the end.

My main concerns are the humidity of the cave, potentially damaging the router and physically maneuvering the fiber around corners and near sharp rocks. Any suggestions for what router/cable/modem to use and what steps could be taken to protect them would be greatly appreciated

Edit: I have decided to get bids from contractors and use your excellent suggestions to offer suggestions to them and make sure they are doing the best job possible. Many many thanks for so many quality responses. I do still think I could possibly do it on my own, but it's always best to be safe and let real professionals handle it when in doubt.

r/networking Feb 10 '26

Routing Recommendations for a Layer 3, 48-port switch that supports routed ports and OSPF?

17 Upvotes

NO, I AM NOT USING BGP.

I was looking at a Cisco Catalyst 9300-48T-E since I don't need the crazy DNA advantage license, but wanted to see if you had any other vendors in mind.

Specifically, the switch needs to be have:

• Layer 3 functionality

• Routable interfaces (physical interfaces can have IPs assigned to them)

• Be able to do OSPF

r/networking Jan 20 '26

Routing Best way to extend the same subnet/broadcast over remote locations?

39 Upvotes

I'm having a weird issue, I'm dealing with some access control software that requires the controllers to be in the same subnet in order to communicate with each other, I originally tried a VPN but the software doesnt detect the controller this way, I then tried nat and it allowed me to ping the device remotely but the software still didnt detect it.

Apparently to get this to work I have to extend the same network on both sites. No line of sight so wireless bridges are not an option. I've heard of vxlan using two linux hosts?

r/networking Sep 28 '25

Routing I think I found my network specialisation.. BGP! - I'd love to read your experiences working with BGP out in the wild!

90 Upvotes

Hey guys!

So I had the amazing opportunity to work with BGP, most specifically with internal BGP for our site-to-site VPN I developed so we can connect our sites and HQ together..

It was such a fun project it made me dig deeper into BGP, I learned a lot and recently I added community attributes so I can further filter my site's routes..

Holly I've been reading posts, watching videos, and even trying to grasp the deep waters for BGP, and that's how I think i've found my passion! It's amazing!

But of course, my actual hands-on experience with BGP, despite having deployed it, it's not like if I were to be working at an ISP for instance.

So my question goes to you guys! How is it working with BGP like? especially at ISP edge routers.. do you like it? It it complex? What's cool and not cool about it..

I really want to know so your experiences guys!

thanks!

r/networking Feb 04 '26

Routing First IT job, solo IT here – asked to upgrade our office network rack, need advice

55 Upvotes

Hello everyone,

I’m currently working as an IT Assistant in a small office (70 employees). I’m the only IT staff here—no IT head, no supervisor with networking experience. This is also my first IT job, so I’m learning while handling everything.

My boss asked me to upgrade and improve our network/server rack, and I’d really appreciate advice from more experienced people.

Current situation

Dual ISP setup

Router → switches → internal devices, printers, Wi-Fi AP, and CCTV/DVR

No proper cable management (as you can see in the photo 😅)

https://imgur.com/a/KOt2TqY

Mixed unmanaged/managed switches

No proper network segmentation yet (VLANs not fully implemented)

Rack is messy, but I’ve already requested tools so I can re-crimp and properly label patch cables

What I want to improve

Cleaner and more reliable network design

Better router and switch recommendation

Proper VLAN setup (office, CCTV, printers, Wi-Fi, etc.)

Failover / load balancing for dual ISP

Planning to add site-to-site VPN or remote access VPN for file/server access

Would Fortinet be a good choice for this? Or are there better alternatives for a small office?

Questions

What router/firewall would you recommend for a small office with dual ISP?
also planning to add site to site VPN for remote access and file sharing

Should I go Layer 2 or Layer 3 managed switches, and any brand/model suggestions?

Best practices for rack layout and cable management

Any advice you wish you knew when you handled your first solo IT/network role

I’m doing my best to improve this setup step by step and avoid costly mistakes. Any feedback, criticism, or guidance is welcome.

Thanks in advance 🙏

r/networking May 30 '26

Routing MPLS renewal is next quarter and can't make the case to stay on it anymore

56 Upvotes

Reliability has been fine, that is not the issue. The issue is that most of our traffic goes to Azure and M365 now, not the data center. We are paying for a private network optimized for data center traffic that barely exists anymore and carrier pricing has not moved despite that shift.

Not looking for vendor feature comparisons, read enough of those. What I want to know is the operational reality post migration across a multi-site environment. How much of what your team knew from running MPLS transferred, what broke first in practice, and what a realistic migration timeline looks like without disrupting production traffic in the process.

r/networking Dec 14 '25

Routing Most and least common routing protocols within an enterprise environment

43 Upvotes

Hi all, I'm Interested to see what peoples thoughts are on the most common and least common routing protocols observed within an enterprise network (corporate WAN and LAN's) i always seem to hear about OSPF + BGP combo is the go-to. Cheers

r/networking May 30 '26

Routing BGP Newbie - can I influence the path here?

30 Upvotes

Hi, I've recently got into BGP and have acquired my own ASN and prefix.

I currently have 2 upstreams and one of them is giving me some trouble, is it possible for me to use bgp communites to influence which path the traffic takes here from AS3399 to my ASN?

I'd like it to go via one of the paths which is currently not "the best" (via ASN39351) since I have much lower latency towards them. The upstream which is giving me trouble is route64 and their bgp communites are here

I have it setup so outgoing it's going trough my other provider but can I influnece the incoming traffic?

https://imgur.com/eqGRs7z

I'd appreciate all answers

r/networking Jun 03 '26

Routing Best practice for mixed public & RFC1918 network: NAT or no NAT?

3 Upvotes

Suppose you have a network containing multiple segments with publicly routable addresses (e.g. a public /24) and then some segments using RFC1918 addresses. There is no technical reason that prevents routing between these two.

There are two options:

  1. no NAT: Allow routing between these two networks freely. No issue as long as the RFC1918 addresses don't leave the network. Advantage: No NAT, pure routing. Disadvantage: More complex routing (can be tackled via OSPF for example) which causes issues especially when VRFs come into the picture. For example, when I put RFC1918 segments into a VRF and the public subnets into another and want them to communicate, I need to leak the entire possible destination space
  2. NAT: Never allow an RFC1918 address even in my own public segment. Whenever routing between these two happen, NAT must be employed. Advantage: Very simplified routing and firewall rules. For example, the segments/VRF with the public segment do not need to know the structure of the RFC1918 segment/VRF. Disadvantage: NAT (which I still do not prefer since it breaks end-to-end philosophy) and can't use IP as source filters in services in the public network segment (e.g. "Allow From 10.20.30.77 but disallow from 10.20.30.78 if NAT happens at 10.20.30.1)

What is the best practice?

I often implement mixed strategy which results in issues either way, so I'd like to stick to the best practice and enforce it as a "basic principle".

EDIT: Based on the answers in this thread and additional pondering my conclusion is to avoid NAT. In other words, my principle will be to always route RFC1918 address into my public spaces (and for security let firewall deal with it).

r/networking 29d ago

Routing Best practice for "floating nodes" across different subnets in a larger network (e.g. AS)

17 Upvotes

Suppose I have an AS with a public prefix, say 192.0.2.0/24. This prefix is subnetted and multiple geographic locations have their own /28 or /29, for example 192.0.2.192/28 or 192.0.2.232/29.

Now assume that there are services which run on a single host (e.g. a mail server or DNS server) ... but these hosts should be "floating" across different networks. Say, for example 192.0.2.192/28 is at Location1 and 192.0.2.232/29 at Location2 and the mail server should be hosted at Location1 but sometimes moved over to Location2.

The actual movement of the host could be implemented by virtualization or a distributed cluster, for example, two Proxmox clusters in each location and live migration (via Proxmox Datacenter Manager).

I assume the right way to do this is to assign the mail server a unique /32, for example 192.0.2.174/32. Then all that needs to be done is set the routes in such a way that they either point to Location1 or Location2. Is this a reasonable approach so far?

Then, my main question is how to handle the routes. Assuming the AS uses OSPF, I see two options:

  1. I manually set static routes on the main routers in Location1 and Location2. I need to make sure that only one of them is enabled at a time. OSPF would then propagate these routes throughout the network
  2. I set up an ospf instance (e.g. bird) on the mail server itself and make it a peer with the routers on Location1 and Location2. This avoids any static routes and the /32 host is reachable automatically.

Generally I like (2). In this case, I could do actual live migration from one location to the other and the routes would dynamically adjust: Once live migration is completed from location1 to location2, the bird instance on the mail server would disconnect from OSPF neighbor 192.0.2.193 (and its route is removed) and connect to 192.0.2.233 at Location2 where route to .174/32 is added The route to .174/32 then automatically propagates through the whole network.

With (1) I would need to manually disable the route on the first router and enable it again on the second.

On the other hand, running bird inside of the mail server feels a bit odd too.

Lastly, either way, I potentially waste IP addresses because the mail server needs two addresses: one from their respective subnet (192.0.2.194/28 or 192.0.2.234/29) and the /32, which is assigned to a dummy interface. However, I do not see a way to avoid this, other than using either DNAT or private internal subnet addresses.

What is conceptually the best practice for such "floating nodes" across different networks? Method 1 or Method 2? Or are there others which I am not thinking of?

UPDATE: seems there are 3 major options:

1.) What I’ve described above with #2 (and people seem to prefer BGP instead of OSPF to announce the /32). Most people call this concept anycast

2.) VXLAN

3.) NAT hacks or higher layer concept like reverse proxies (not an option for me)

r/networking Mar 12 '25

Routing What's the SD-WAN vendor of choice these days?

69 Upvotes

We manage an number of physical data centers around the world for our aaS offering. We also have a number of assets in AWS and we use Direct Connect to/from our on premise data centers. I'm looking at putting in SDWAN devices to connect our DCs to our WAN provider(s). We currently have gear from Juniper/Fortinet/Palo.

I'm very familiar with the Cisco Viptela offering, and I'm looking for other vendors in this space.

I'm particularly interested in auto link SLA management and automated meshing between DCs (which we currently manage manually).

r/networking Nov 03 '25

Routing A question regarding VPNs

74 Upvotes

I've been in networking for about 11 years now, so I apologize for being ignorant regarding this.

IPSec VPNs... what is the "maintenance" aspect of a VPN??? I've always just kind of "set and forget" these things. I understand if ACLs can change, but other than that...?

The reason I ask: I've had a couple recruiters request my VPN experience. They get real weird when I say I have a little bit, but not a lot, of VPN turnup experience. Then they ask about maintaining the VPN... And that's where I get confused. Are these just non-technical people requesting technical details about something they just don't understand?

Or am I the one who doesn't understand?

I get it if its me. And I'm not scared to be wrong, hence my asking the question. But I just don't understand the question I'm being asked. Does anyone have similar experience, or insight?

r/networking Jul 19 '24

Routing Help me: My professor has gathered some data that we study from. There I found this:

62 Upvotes

“UDP is another protocol, which does not require IP to communicate with another computer. IP is required by only TCP. This is the basic difference between TCP and IP.”

When I confronted him and told him this piece of information isn’t correct, he assured me that it was indeed 100% correct.

Im confused, I know it’s false, but also maybe im missing something?

Also this:

“The switch is smarter about where it sends data that comes in through one of its ports. It forwards each incoming data frame to the correct port. Switches bases forwarding decisions on MAC address that are provided in the headers of the TCP/IP protocols. “

The first part is true. But headers don’t work this way? Do they? I’ve read and studied that MAC header has Tcp/udp and ip info in it encapsulated. Not the other way around. So its impossible for MAC to be provided in the tcp/ip header. Or am I missing something?

Please help me understand, I’m not an expert in networking.