▲ 11 r/Cisco

SASE migration off MPLS, weighing Cato against staying on Cisco, tell me what you underestimated

Manufacturing, 14 sites in 3 countries, on MPLS since before my time. Renewal landed about 30% up for the same thing and the account manager's capacity cost story didn't pass the smell test.

The traffic changed and the circuits didn't. Everything's going to M365 and a couple SaaS, we haul cloud traffic across the private network to break out centrally which is the daftest route for it. The MPLS is doing a stellar job carrying traffic to a data center that hosts less every year.

I know roughly where this ends: SD-WAN, broadband and LTE at the little sites, keep something private where two plants talk. But on is security I’m abit fuzzy cause right now it's at the central breakout. Local breakout means either a box at every site or cloud inspection and I've run neither.

Cato keeps coming up for the cloud inspection side and part of me just wants to stay in the Cisco world, I know.

Whoever's done this migration, what issues came up that the plan didn't show? Give me war story, not the pitch.

reddit.com
u/Specialist_Dish_9087 — 7 days ago

How are you getting ai spend visibility broken down by team

Trying to get ahead of ai spend visibility before it becomes a real problem and I'm stuck on where to even start.

Right now the AI bill is a few big numbers with no owner. A Bedrock line. An OpenAI org someone put on a company card. Some GPU instances that come and go. And a pile of coding agent seats that finance treats as SaaS. Nothing is split by team or project.

We solved this years ago for normal cloud with tags and allocation. That does not work here. Tokens and GPU hours and per-seat tools don't line up with the way we allocate EC2, the model we use for everything else just doesn't fit.

The bigger issue is, it's a bill that goes up every month and no team's name is on it.

Those who has sorted this out, where did you put the visibility and who ended up owning it?

reddit.com
u/Specialist_Dish_9087 — 24 days ago
▲ 51 r/Cisco

Still on MPLS across 14 sites and the renewal came in 30 percent higher, talk me through what you did.

In manufacturing with 14 sites across three countries. MPLS since before I was here. Renewal quote landed last week about 30 percent up on the last one with no change in what we get and the account manager said something about capacity costs that I did not find convincing. 

Meanwhile, the actual traffic pattern has completely changed but not the circuits. Everything is going to M365 and a couple of SaaS things now such that we are hauling cloud traffic across the private network to break out centrally, which is the least sensible possible route for it. The MPLS is doing a great job of carrying traffic to a datacentre that hosts progressively less every year. 

I know where this ends up: SD-WAN, broadband and LTE at the smaller sites, keep something private where the two plants that talk to each other need it. What I don't have a feel for is the security side. Right now security happens at the central breakout. If every site breaks out locally then either I put a box at every site or I do the inspection in the cloud, and I've not run either. 

For the people who have done this migration, what did you underestimate? Not looking for a vendor pitch, more interested in what went wrong.

reddit.com
u/Specialist_Dish_9087 — 29 days ago

Every "official" base image ships 400 packages my app has never once called

Was trimming a Python service image today and actually counted. The base drags in a shell, a package manager, curl, git, tzdata, half of coreutils and a pile of libraries the app has not touched in years of running. Every one of those is a line in my scanner report and a thing an attacker gets for free.

We ship one app. Why am I also shipping a whole Linux userland to run one binary.

Anyway. Back to it.

reddit.com
u/Specialist_Dish_9087 — 1 month ago
▲ 1 r/AZURE

How do you baseline branch-to-VNet latency? The built-in metrics keep lying to me

Ok this one had me going for a good week. Two of our branch sites were dragging getting to the Azure stuff and i was dead sure it was the last mile, so i swapped both circuits but nothing changed, which is when it clicked that it wasn't the last mile at all. The traffic was hairpinning out through some region half a country away before it even reached the vnet.

The Azure latency graphs looked fine the whole time which is what threw me, they measure from inside their own edge not from my branch. Once I started probing hop by hop from each site to the actual workload the real picture showed up, embarrassing how far off id been.

How are you all properly baselining this? trusting the expressroute and peering metrics or running your own probes from each site. Mine and Azures disagree enough that I stopped trusting the built-in ones.

reddit.com
u/Specialist_Dish_9087 — 1 month ago
▲ 5 r/fit

What actually helped me stay consistent with exercise

I used to overthink workouts and end up skipping most of them. What finally helped was keeping things simple and repeatable. Short sessions, same time each day, and no pressure to be perfect. Even 15 to 20 minutes counts. I also stopped chasing motivation and focused more on routine. It’s not flashy, but it works better long term. Curious what keeps you all consistent… do you follow a plan or just wing it most days?

reddit.com
u/Specialist_Dish_9087 — 3 months ago