Current frustration...

Started by deanwebb, September 08, 2015, 10:09:38 AM

Previous topic - Next topic

icecream-guy

#90
Argh, why don't users understand the concept of stateful firewalls,

user request.  source desktop <-> Server,  bi directional?

I call user,  Asks: do you have a need to ssh to your desktop from the server?
he says he doesn't understand what I am asking.
I ask user if these running a ssh server on his pc?
he says not.
I tell hum I'm cancelling the bidirectional flow since it's not need
(i can see his puzzled look over the phone)

---

another customer asks to open port 8443 to his server  hisserver.mynetwork.com
I respond back request is completed.
he responds back, it's not working and includes the URL to the server http://hisserver.mynetwork.com:9000/web/app

:facepalm2:
:professorcat:

My Moral Fibers have been cut.

deanwebb

Yes, please can you do the needful and open port 8443 so I can communicate on port 9000?

:rofl:
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

SimonV

Working on a warehouse wifi refresh, found this on 4 of the 10 standalone access points:

XXXAP03#sh ver | inc uptime
XXXAP03 uptime is 7 years, 39 weeks, 4 days, 21 hours, 0 minutes


XXXAP03#sh ip int br
Interface                  IP-Address      OK? Method Status                Protocol
BVI1                       xxx.xxx.xxx.xxx  YES NVRAM  up                    up
Dot11Radio0                unassigned      YES NVRAM  administratively down down
Dot11Radio0.1              unassigned      YES unset  administratively down down
Dot11Radio0.10             unassigned      YES unset  administratively down down
Dot11Radio0.33             unassigned      YES unset  administratively down down
Dot11Radio0.34             unassigned      YES unset  administratively down down
Dot11Radio1                unassigned      YES NVRAM  administratively down down
FastEthernet0              unassigned      YES NVRAM  up                    up
FastEthernet0.1            unassigned      YES unset  up                    up
FastEthernet0.10           unassigned      YES unset  up                    up
FastEthernet0.33           unassigned      YES unset  up                    up
FastEthernet0.34           unassigned      YES unset  up                    up


:yuno:

EOS


deanwebb

Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

SofaKing

Networking -  You can talk about us but you can't talk without us!

deanwebb

Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

deanwebb

Gave an instruction to the contingent staff to do some maintenance work on 43 devices that worked great for 40 of them.

On the three it didn't work for, it totally hosed up our guest wireless environment.

:wall: :wall: :wall: :wall: :wall: :wall:

Fixing that now and making a note to never issue broad, all-inclusive instructions again...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

icecream-guy

Quote from: deanwebb on March 01, 2017, 12:16:22 PM
Gave an instruction to the contingent staff to do some maintenance work on 43 devices that worked great for 40 of them.

On the three it didn't work for, it totally hosed up our guest wireless environment.

:wall: :wall: :wall: :wall: :wall: :wall:

Fixing that now and making a note to never issue broad, all-inclusive instructions again...

now you can understand why we only do 1 task on 1 device per maintenance window.  short windows, lots of verification, time to roll back, and reverify everything.   makes sure nothing else impacts the maintenance, and if something does, it can only be 1 thing.
:professorcat:

My Moral Fibers have been cut.

NetworkGroover

Quote from: ristau5741 on March 02, 2017, 10:54:14 AM
Quote from: deanwebb on March 01, 2017, 12:16:22 PM
Gave an instruction to the contingent staff to do some maintenance work on 43 devices that worked great for 40 of them.

On the three it didn't work for, it totally hosed up our guest wireless environment.

:wall: :wall: :wall: :wall: :wall: :wall:

Fixing that now and making a note to never issue broad, all-inclusive instructions again...

now you can understand why we only do 1 task on 1 device per maintenance window.  short windows, lots of verification, time to roll back, and reverify everything.   makes sure nothing else impacts the maintenance, and if something does, it can only be 1 thing.

Think you can probably find a better way to handle things.. that won't a hundred change control windows.   Of course, easy for me to say. 

Why did the same process break three devices while wasn't an issue for the other forty?
Engineer by day, DJ by night, family first always

deanwebb

40 of the devices needed an *internal* web server cert.
3 of the devices needed an *external* cert, but since I didn't leave them out of the instruction to "get an internal web cert on all these boxes!", they got an internal cert that invalidated the external cert when they had to have their private key regenerated for the internal cert...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

icecream-guy

Quote from: AspiringNetworker on March 02, 2017, 04:28:44 PM
Quote from: ristau5741 on March 02, 2017, 10:54:14 AM
Quote from: deanwebb on March 01, 2017, 12:16:22 PM
Gave an instruction to the contingent staff to do some maintenance work on 43 devices that worked great for 40 of them.

On the three it didn't work for, it totally hosed up our guest wireless environment.

:wall: :wall: :wall: :wall: :wall: :wall:

Fixing that now and making a note to never issue broad, all-inclusive instructions again...

now you can understand why we only do 1 task on 1 device per maintenance window.  short windows, lots of verification, time to roll back, and reverify everything.   makes sure nothing else impacts the maintenance, and if something does, it can only be 1 thing.

Think you can probably find a better way to handle things.. that won't a hundred change control windows.   Of course, easy for me to say. 



As large and complicated that our network is, and the lack of knowledge about who connected what where, and as loud as the customers yell when their stuff goes down, even when we notify them. Best to play it safe.
:professorcat:

My Moral Fibers have been cut.

SimonV

nottherealhostname(config)#crypto key gen rsa mod 4096 gen
The name for the keys will be: nottherealhostname.domain.com

% The key modulus size is 4096 bits
% Generating 4096 bit RSA keys, keys will be non-exportable...
[OK] (elapsed time was 168 seconds)


Three minutes of my life wasted, per switch

deanwebb

^ And you can't script that, either.

:steamtroll:
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

wintermute000