Friday, September 4, 2015

SCE8000 upgrades

To check for ipv6 support from a management access I've upgrade the SCE8000 to build v5

scos-v510-b761-sce8000-k9.pkg


I still see no  support ipv6 or radius-servers  in the SCE 8k engines. Darn, when will cisco start adding these features?


Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  #  # )=
       o 
      /  \

Thursday, September 3, 2015

AMS-IX internet exchange

A contact of mind that  works for one of  biggest tel-mobile operator in Amsterdam,  invited me out to AMS-IX to speak about some technical issues they where seeing.


This is one of the biggest  internet exchange in  the WEST-EU region if not all of the EU. I've done a lot of remote stuff here, but never  been to it much less to Amsterdam.

https://ams-ix.net/

1st off the road trip was very easily to under take. A simple   "tram" to the  Rembrandt Square aka  Rembrandtplein in dutch, was taken.

The folk at AMS-IX where pretty sharp and impressive.  I 've also visited a few other interesting sites out in this area that I would like to high light;

   katten kabinet    http://www.kattenkabinet.nl
   foam fotography museum  http://www.foam.org
   cafe barney

The latter is a cool hip coffee shop that plays some funky music. I've been to this joint like 4 times now  & for the 5 nights  that I was in Amsterdam. They have a more busier cafeshop that I was told of by the wait staff. 

A doble-espresso with redbull wil run you about 8 euros, ask for  the wifi-secret for thompson and they will provide it.

The Cat/Chat cabinet is a great place if your into cat stuff ( cards, pictures, posters, etc,...) It was raining when I ran out to that location, but I had a great time looking at the exhibits regardless.

Foam, had a lot of older series of photography if your into B&W and medium/large format. I was very impress after researching  the works of UK/Ghanian photographer James Barnor who did a lot of work for The "Drum Magazine" and many more.

The AMS_IX is fully ipv6 enabled,  but ipv6 traffic is quite low between the major providers and the general mobile carriers in general. In short " the  Netherlands has been ipv6 enabled for a while " but the general interest within the ISP/SP/Movil-Operators  arena  has been very low.

( a few cool information on the ams-ix

https://ams-ix.net/technical/statistics/sflow-stats/ipv6-traffic
https://ams-ix.net/technical/specifications-descriptions/ipv6-numbering-scheme

Here's a few fotos taken along  the way;








Just bring some euros, a good set of  walking shoes, umbrella and go explore the city of Amsterdam. You probably will find out you need like 2-3 weeks to see the city. Heck the city center and just the redlight district could be 1 week alone.


get the 24hours tram card if you planing on going around to more than 2 sites, it's only 7.50 euros, & don't waste your time on the 1hour card imho


Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
       o 
      /  \

NEXUS OS upgrade

In the process of looking at NEXUS OS new software version. New code has came out so it time to kick the tires








Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
       o 
      /  \

Wednesday, September 2, 2015

Fortigate HA port and finding your mac_address

One of the biggest  mystery with the fortigate and FGCP protocol is to find your ipv4 address & the mac_address that uses on the HA port.

Basically the fortigate use a APIPA ipv4 link-only address aka 169.254.0.0/16 range.

The master is typically always defined with 169.254.0.1 the first .2 next slave .3 and so on. You can have up to 4 slave units.

Using the diag sniffer packet command and by defining the port_ha is a good mean for witnessing the interface traffic and finding both the layer2 and layer3 addresses.

e.g ( diag sniffer packet port_ha "any" )




Finding the  interfaces mac_address on a FGT110 master/slaves



Finding the master-unit ipv4 address
( diag sys ha status | grep master )


Using the diag sniffer command and option for displaying the unit  traffic in HEX

see the red and green lines for src /dst mac_address respectively


Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
       o 
      /  \

How to build secondaries address on a Huawei firewall

In this example we will explore how to build secondaries on the huawei  firewall.

The option of sub after the  define ipv4  address provides us the secondaries options.

e.g1




eg2



I haven't found any literature of the maximum numbers of  secondaries that you can craft.   I'm sure a limitation exists on the max numbers.

Juniper SRX    (  support for secondaries exists per-interface,  limits are set JunOS version and possible hardware platform model-type )

Cisco ASA      ( no support for secondaries per-interface )

Fortinet Fortigate          ( max 32 secondaries address per-interfaces )


If you should use secondaries be very carefully and be aware of the limits such as dhcp issues or lack of dhcp-scopes for secondaries.

" In a newly designed network,  there's no need for secondaries interfaces or if you need it, your design is probably bad or should be reviewed for possible other designs constraints "

imho


Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
       o 
      /  \

Tuesday, September 1, 2015

Forticlient 5.2.4 macosx

I did a complete uninstall and re-install restore for the new MACOSX 5.2.4 forticlient.

Here's the steps that where taken;

1st make a backup  ( encrypted was done here with a passcode )





2nd  remove  old installation



3rd download the new dmg pkg



make sure to check the md5 sum


4th execute the installation process



Finally,  upgrade the AV-database and restore the cfg using the previously made backup






the 1st thing I notice over a period of 3-6 day use, and by comparison , ALL of my sslvpn connections profiles are slow to startup.


    We found if you try to add more than 4 new profile they where not be accepted even after a stop and restart  ( shutdown ) of the new forti_client. We had to end rebooting  the system. This happen on more than 2 machines
    


Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
       o 
      /  \

fritizbox 7400s support ipv6

A quick email support question gave me the following details and links on fritizbox.

http://en.avm.de/nc/service/fritzbox/fritzbox-7490/knowledge-base/publication/show/573_Configuring-IPv6-support-for-FRITZ-Box-home-network/



Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

    ^     ^
=(  *  * )=
        o 
       /  \