Tuesday, 18 April 2017
Designing simple campus network based on best practices
If you are looking for something about designing stable and good network topology, see my figure.
This schema has been created by me based on CCNP - switch book. Genereal speaking If we need good network topology we have to thinking about redundancy and failover strategy.
I know that my topology is simple but is scalable also.
See my picture and I will try to describibe it:
Regarding Access layer - this layer is responsible for switching based on L2. Here we have one switch ber VLAN. This is good because if we have large segment we can use high density port switch. Or we can agregate switches together. Another switch another VLAN. Next level is distribution - it means that our L2 here is finished. And we are starting using L3 functionality. Here we have SVI per vlans for communication with L3 and HSRP for hight availability. HRSP allows us to have stable default gateway if one of distribution switch goes down or crash or other problem.
Redundancy looks good. If we cut one leg from yellow colour connection between access and distribution we still have connection to other L2 and core network (next internet, WAN, data center). If one from distribution switches goes down HSRP takes over default (next hop) gateway role for every VLANs.
Core is full mesh topology - means that we have connetion between all devices in core and distribution switches. There is L3 routing implemented. In my instance OSPF. Because we need fast convergence time if any path failure. Between distribution and access layer switches we have trunk port connecitons.
For summarize:
Processing block can be adaptive. You can add next simillar block based on this topology. I hope that this figure help your understanding network designing. Regarding Spanning Tree there is limited only between access and distribution layer. Based on this VLAN ber switch approach we also have stable STP convergence because there is loop free topology.
Sorry If you find any english bugs here in this post but I'm writing all posts AD HOC without google translator support.
Good Day - networkers!
Tuesday, 24 January 2017
How does works? Smartphone and webbrowser - Packet Tracer 7.0
MPLS (MP-BGP and VRF) & OSPF Provider and Customer point of view
First of all I gonna show you a figure where we see all network project:
P - it is provider backbone (this means that this devices must only transport packets)
PE - this is edge of provider where split MPLS service for many clients
CE - customer edge - place where customer can connect own devicec or use C
C- customer router (sometimes form ISP sometimes not)
Short description for this figure above:
Provider using OSPF for routing convergence and for simpler administration. MP-BGM must be because PE storing many routing tables (each client have one table) and must be exchanged with other PE.
Ready configuretion you will find here:
Configuration files will be soon ...
Friday, 9 December 2016
Short status information
After long period of time. I get new informations:
During next days I gonna write some new posts:
First will be about MPLS and VRF and MPBGP.
For your information I'm available at Linkedin. Here it is:
LINKEDIN - PAWEL ZAREBA
See you later...
Wednesday, 27 April 2016
Saleae Logic Analyzer - analyze Manchester code (decode Manchester)
Hi,
This post I gonna show you how to decode and visualize 10 Mb/s ethernet by Saleae Logic Analyzer. I have simple and very chip module analyzer. But for test and for fun its enought. I was seeking materials about how to decode manchester by this tool but nothing I recieve. Therefore I had to do something. OK Les't go with it.
Because many people need to see and do something to understand therfore I tried to add and share necessary materials for you.
First of all this is what I need to have:
UTP Cat5e 100Mbps cable and Saleae Login Analyzer 24MHz 16 channels.
UTP is important because if you have STP cable It will be quite difficoult to slit cable.
If we have phisical environment ready we can go further. We have to modify our settings.
First you must change your NIC speed for 10Mbps. Menchester is using this speed normally:


Now you can start sample. One important thing. Do not add any prococols before you sample.
OK. We have some data. Show in this figure below (Use your mouse scoll to zoom in your data):

Network programming - Client and Server communication C#
This year I started playing with C#. I'm interested in networking therefore I was wondering how to connect my currently knowledge with programming. So I decided that I need to find programming language - must be flexible, quite simple and must be type RAD. I choose Visual Studio Express 2010 (free edition) with C#.
I have some experience with programming because previously sometimes I had to write some scripts and small program during my study and during my daily routine.
OK. Something about my project.
It is very simple idea. I need client applcation where I can choose host for connection (eg. localhost, remote host), must have progress bar during sending data. I must send different values from 1 to 100.
All messages must be visable. Can close connection. All data should be visable on the server side especially should be visable on the screen of Arduino.
In this figure I show you scenario:
In this fugure I show you how to looks both interfaces:
Friday, 22 April 2016
Two project will be released next week
Next week I want to release and describe my 2 projects.
This two project are connected with network communication.
Firs project is made of Arduino Due, LCD Display, Serial connection USB, C# network applications.
Generally I've wrote 2 programs in C#. It's client & server.
Server listening on PC which is connected with Arduino with display LCD sheeld. Between PC and arduino I using USB connectio (by COM).
Client has been done for sending data which should be display (visable) on Adruino LCD. There therefore Client should be connect by the network to server and send data. This is shor about first project.
Second project is about decode Manchester code which is used in 10BaseT Ethernet standard.
In this project I've used Saleae Logic Analyzer 24MHz with 8 channels. I've establish connection between switch and PC via ethernet cable CAT5e. Network device will be configured at 10Mb/s band. All communication will catched by Saleae Logic Analyzer and decoded by it. Manchester protocol is embeded in Saleae Sofware. Sound's good.
So, see you soon!
Friday, 25 March 2016
ADC converter (modulator)
This is my first post regarding modulations. I'm intrested in electronic.
Recently I was wandering how to create simple converter to convert analog signal to digital.
I've found program named LTSpice it's free and very good in my opinon (it's not only my opinion).
My aim was, do the modulator as soon as possible. Must be simple and workable. I do this.
Here is electronic circuit:
Tuesday, 22 December 2015
Purple belt - BJJ
CCNA Exam Passed!
Today is my big day. I achieved CCNA title and pass this exam with good score.
I can rest for now, its also the end of 2015 year there fore I'm starting prepairing for christmas and new year party.
I hope that new year 2016 will be good time to try go further for achieve CCNP title.
Wooooooohhhoooooo!
Tuesday, 7 July 2015
Cisco Security - IPSec Tunnels diagnose
That means then interfaces first shut down and by short time move up.
I will show you what should we do for diagnose this issue.
First check logs by command:
sh logg
result:
2755318: Jul 7 14:46:16: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel30, changed state to down
2755319: Jul 7 14:46:16: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel20, changed state to down
2755929: Jul 7 14:48:06: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel20, changed state to up
2756083: Jul 7 14:48:16: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel30, changed state to up
If you saw something like above then tunnel is flapping.
Next use this command for checking status of tunnels:
sh crypto isakmp sa
result:
IPv4 Crypto ISAKMP SA
dst src state conn-id status
x.x.x.x x.y.z.z QM_IDLE 1194 ACTIVE
y.y.y.y x.y.z.z QM_IDLE 1193 ACTIVE
If status is ACTIVE then crypto key has been exchanged correct.
Next important command is:
sh crypto session brief
this command allow us to check status of all tunnels.
Last command is:
sh crypto session detail
In this command important is uptime parameter. It maight be useful when we want know how long tunnel is running.
This commands are useful for basic troubleshooting. In future I will write more detail information.
My IT team from Asia
I'm glad that I was working with this guys.
It was big plesure to work with you guys. Many thanks for all! Sie! Sie!
Monday, 18 May 2015
Wednesday, 22 April 2015
EEM - Embedded Event Manager
Look below. Here is my script which I use daily. In working hours I must use limitation for DFS traffic from our local machines. I did not have time for create complicated script so my idea is simple: "Remove QoS policy from interface where limit is active by selected period" after specified time I add QoS policy to interface again.
Look:
event manager applet DISABLE_DFS_LIMIT_WEEK
event timer cron cron-entry "10 18 * * 1-5"
action 1.0 cli command "enable"
action 2.0 cli command "configure terminal"
action 3.0 cli command "interface GigabitEthernet0/1"
action 4.0 cli command "no service-policy input QOS_MARKING"
action 5.0 mail server "$_email_server" to "$_email_to" from "$_email_from" subject "routername1: Bandwidth limit between X and Y is uncontrolled"
This same script you can use for enable but must change only cron settings and one command. Look at bold and underline fonts.
Usefull mdf file - Embedded Menu Manager
Here is created file named *.mdf.
You can run this file using "emm" tool include cisco IOS.
MDF file allows you to create menu with many functions. It is very useful for administrators who using many of this same function to analyse, diagnose, or checking network parameters. MDF - using XML language. You can use ISO commands include XML, you can use TCL scripts also.
Here is simple mdf file which I created and moved to router. If you want to run this file use:
Wednesday, 18 March 2015
Polycom RealPresence Desktop & Active Dircetory communication
I decided that I will be using shortcut for easy notification. In this scenario:
RPD is a Polycom server AD is a Windows Server with 2008R2 operating system.
Let's start:
RPD -> AD = DNS QUERY
AD -> RPD = DNS RESPONSE
RPD <-> AD = SYN,SYN ACK
RPD -> AD = NBSS SESSION REQUEST
AD -> RPD = NBSS POSITIVE SESSION RESPONSE
RPD -> AD = SMB NEGOTIATE PROTOCOL REQUEST
AD -> RPD = SMB NEGOTIATE PROTOCOL RESPONSE
RPD -> AD = SMB SESSION SETUP ANDX REQUEST, NTLMSSP_NEGOTIATE
AD -> RPD = SMB SESSION SETUP ANDX RESPONSE, NTLMSSP_CHALLENGE, ERROR: STATUS_MORE_PROCESSING_REQUIRED
RPD -> AD = SMB SESSION SETUP ANDX REQUEST, NTLMSSP_AUTH, USER: domena\nazwa_komputera
AD -> RPD = SMB SESSION SETUP ANDX RESPONSE
AD -> RPD = SMB TREE CONNECT ANDX RESPONSE
AD -> RPD = SMB NT CREATE ANDX RESPONSE
RPD -> AD = DCERPC BIND: CALL_ID: XXX
RPD -> AD = LSARPC LSA_OPENPOLICY2 REQUEST
AD -> RPD = LSARPC LSA_OPENPOLICY2 RESPONSE
AD -> RPD = LSARPC LSA_QUERYINFOPOLICY RESONSE
RPD -> AD = LSARPC LSA_CLOSE REQUEST
RPD -> AD = SMB CLOSE REQUEST
AD -> RPD = SMB CLOSE RESPONSE
RPD -> AD = NT CREATE ANDX REQUEST, PATH: \NETLOGON
AD -> RPD = NT CREATE ANDX RESPONSE FID: XxXXXX
AD -> RPD = DCERPC CALL_ID: XXX .. RESULT: ACCEPTANCE
RPD -> AD = RPC_NET NETSERVERREQCHALLENGE REQUEST
AD -> RPD = RPC_NET NETSERVERREQCHALLENGE RESPONSE
RPD -> AD = RPC_NET NETSERVERAUTHENTICATE2 REQUEST
AD -> RPD = RPC_NET NETSERVERAUTHENTICATE 2 RESPONSE
AD -> RPD - RPC_NET NETLOGONSAMLOGON RESONSE
MANY ACK, RST, ACK AND RETRANSIMISSION ALSO
RPD -> AD = RPC_NET NETLOGONSAMLOGON REQUEST
AD -> RPD = RPC_NET NETLOGONSAMLOGON RESPONSE
I dropped many duplicate TCP [ack] AND other retransmissions. If you have any problem with communication between, you can compare this communication and find differences to resolve your problem. If you are a programmer this type communication maybe it can be interesting for you.
Monday, 9 March 2015
Usefull commands for admins (cisco router)
sh crypto session brief
How to check VPN tunnel/tunnels status:
sh crypto isakmp sa
Show IP NAT translations include IP
sh ip nat translations | inc x.x.x.x
How to verify QoS policy:
sh policy-map interface type x/x
Show me neighbor devices (CDP must be enable):
sh cdp neighbors
Wednesday, 4 March 2015
How to export certificate from ASA to JAVA (self-signed)
asa1(config)# sh crypto ca trustpoints
Next we are using export to pem file (must write name of trustpoint):
asa1(config)# crypto ca export TRUST_NAME identity-certificate
you will see:
-----BEGIN CERTIFICATE-----
MIIB+zCCAWSgAwIBAgIEJqphUTANBgkqhkiG9w0BAQUFADBCMRMwEQYDVQQDEwpD
TkJFSUZXRDAxMSswKQYJKoZIhvcNAQkCFhxDTkJFSUZXRDAxLmRwY2xlYW50ZWNo
LmxvY2FsMB4XDTEzMTEwNjE1MzQwOFoXDTIzMTEwNDE1MzQwOFowQjETMBEGA1UE
..
-----END CERTIFICATE-----
Next you must copy this all text from console and paste in text file (notepad) and save as *.CSR
Next open Java Control Panel, go to Security tab and run Manage Certificates button. You shoud see Certificates window. Select Certificate Type like "secure site" and import your file. Now you can open your ASDM via web browser using Java.



















