r/networking

BGP Transit Performance Monitoring

For those who run BGP and advertise prefixes into the DFZ, how are y’all monitoring each upstream provider for performance issues?

Right now, we have 2 providers with only default routes, utilizing a /23, and preferring one over the other for outbound.

In what way, if any, could going to full tables be beneficial to us other than better load balancing and traffic engineering for say a shorter path, etc?

reddit.com
u/nicholaspham — 4 hours ago

Need advice for way forward for experienced network engineer

Hi All,

I have been working in networking field for more that 11 years

started my career as network engineer - > senior network engineer -> lead network specialist , I did CCNA once at the start of my carreer , have experience in ACI/nexus , AWS cloud networking , firewalls and loadbalancers

lately feeling really stagnant , as my current organisation is not big , and we are using meraki , so once build that its running on autopilot now , not getting to solve complex issues , no tcpdumps nothing ,most of my day i spend reading techincal documents and few meetings

can anyone suggest how i should proceed further

reddit.com
u/anonymous24101992 — 7 hours ago

Best free resources to learn?

Hi all, I have been wanting to learn how to build and understand a network topology in my free time. Are there any good free resources that anyone would recommend i check out? ​

reddit.com
u/Oxgee — 7 hours ago

Moved into management....

I was a Senior Network Engineer for a couple different companies (For context (10 YOE + CCNP) before moving into an IT Director level role about a year ago.

I’m starting to realize that the stress, politics, and general management nonsense is catching up with me. The money is good, but it’s starting to feel less and less worth it.

Curious if anyone here has made the move into IT management and eventually went back to being an individual engineer. Did you regret stepping back?

For those who stayed in management, how did you get better at dealing with the stress without letting it consume you?

reddit.com
u/tuna_st — 14 hours ago

Network engineers using Ansible/Python for automation in production — what does your workflow actually look like?

Currently managing FortiGate across 100+ sites and starting to build out automation capabilities. Not looking for career advice — genuinely curious how other engineers are implementing this in production environments.

  1. What are you actually automating day to day — config pushes, compliance checks, reporting, something else?
  2. Ansible, Python scripts, Terraform, or something else? What drove that choice?
  3. With AI generating scripts now — do you still write Python from scratch or do you use AI-generated code and focus on understanding the logic?
  4. For Ansible specifically — did you need solid Python first or is YAML-based playbook writing approachable without it?
  5. Is automation genuinely changing how hiring managers evaluate candidates or is it still mostly a bonus?
reddit.com
u/wh00is007 — 15 hours ago

Grab bag network switch

Having had a number of instances where it would have been a big time-saver in the last for monthsm I'm looking for a small (4 port ideally, 8 at most) gig-e switch that can be powered from USB-C (uup to 100w supply available), supports POE and can do span for traffic sniffing. It's to be kept in a tool bag, so reasonable build quality a big plus.

Specific model suggestions much appreciated

reddit.com
u/someanonbrit — 14 hours ago

Best firewall option for small nonprofit (<10)?

Hey everyone, I’m fairly new to the IT job field (about 1 year of experience) and have also been volunteering at this local nonprofit as IT Support on the side outside of my main help desk job. The President of the nonprofit has tasked me with finding a good firewall for them to use and I have no idea where to start.

For additional context, the nonprofit is very small (less than 10 people), they have hybrid work, and right now I’m the only IT person they have (they’ve been using a rotating cycle of volunteers). I do not know how to configure a firewall whatsoever so recommendations, as well as advice on how to configure and implement it would be much appreciated!

reddit.com
u/Dull-Potato7155 — 1 day ago
▲ 18 r/networking+1 crossposts

Torn between 3 offers - seeking advice

Hey all, I currently work as an Enterprise Architect for a consulting company. Most of my workload is professional services and post-sales deployments, but I handle some pre-sales here and there. Business has been slow and I'm looking to move on to something bigger.

I recently landed three solid opportunities (written and verbal offers for all) around the same time and honestly could see myself happy in any of them, which is making this a difficult choice, and would love some outside perspective.

All 3 opportunities are fully remote

Option 1: Solutions Architect (network security)
compensation: 195k OTE, 70/30 base/commission split

  • Lots of customer calls, discovery, architecture design, scoping, HLAs, and hands off designs to post sales team
  • Access to lots of training from major networking/security vendors
  • I like the idea of having a commission component and being rewarded for building strong relationships with AEs/customers
  • My biggest worry is drifting away from hands-on/technical-work long-term

Option 2: Senior Network Engineer, mid-size enterprise
compensation: 170k base salary+ benefits

  • Small team
  • Work with SD-WAN, spine/leaf, ZTNA solutions, multiple public cloud workloads, and data centers. I think this would expand my skillset quite a bit
  • More traditional engineering role, lots of hands-on

Option 3: Senior Network Engineer, contract (extension or conversion likely)
compensation: 110/hr

  • Heavy design work and security hardening, SD-WAN, multiple data centers, campuses, and some OT. I have the most familiarity with the primary firewall vendor this company uses, lots of hands-on
  • 1099, so self-employment tax, no benefits, no paid holidays/PTO included
  • Higher hourly compensation but more responsibility for benefits, taxes, time off

My biggest dilemma is really option 1 vs option2/3.

If you made the jump from hands-on engineering into presales/SE work, how did that work out for you? Did you love it, regret it, wish you went a different direction?

I personally thrive in high-pressure environments and think I'd enjoy the customer facing/sales side, but I also genuinely enjoy being hands-on with engineering work.

For those who have done both, which path gave you better career growth and earning potential without making you feel like you were leaving the technical side behind?

reddit.com
u/viper_4034 — 1 day ago

Enterprise vs ISP?

Hello, I currently work as a network engineer for an enterprise and we are dealing mostly with Cisco stuff - switches, DC with ACI, ISE and so on. We use automation like Terraform and Python/Ansible and we have 9800 controllers, so the job is good and does not get boring.

I can also join an ISP an work on the backbone network, MPLS, L2/L3 VPN and BGP. I like routing, so I wonder if you think this is a good opportunity or it's a step back compared to the broad aspect of technologies I'm currently dealing with?

Do you think that ISP experience is worth it or I should stick with the enterprise?

reddit.com
u/NetMask100 — 1 day ago

Tips/best practices for security

Hello all, I was hoping to gather some information on possible security implementations at my new job. I landed my first real networking job and im a little overwhelmed. My first task has been to brainstorm and implement, if possible, any security features for the company. We are an organization of about 100-150 people over two different locations. Mostly all office people (sales/marketing ect). So far I have added vlans and acl's to segregate untrusted networks from our main lan. We are using meraki equiptment. Any suggestions are appreciated and if there's more information I can provide that would help make suggestions easier please let me know. Thanks

reddit.com
u/Striking_Taste_7213 — 1 day ago

Auto Detecting BiDi

I'm in a position where using simplex SFPs made the most economical sense. I'm about 5 years in on a few sets of generics. It got me thinking, what is the technical hurdle to building both wavelengths into a BiDi adapter and having them auto negotiate? For years nics and switchports couldn't do Auto MDIX now almost every device has it baked in. This would eliminate the need for a matched pair.

reddit.com
u/jstar77 — 1 day ago

Is it possible to get a remote job in networking and work from any country?

I've been working as a network engineer in the enterprise sector for the last 15 years. I want to find a remote job that would allow me to live in another country, maybe somewhere like Thailand or Vietnam.

I've started monitoring remote job boards, and all I'm seeing are offers for software engineers and DevOps roles.

So what do you think? Is it even possible to land a role like this as a network engineer these days? Or is it better to pivot and transition into something like DevOps or cloud engineering first?

reddit.com
u/Goleeaph — 2 days ago
▲ 2 r/networking+1 crossposts

Can't trunk from D-Link to Arista

Edit: Thank you to everyone that caught my missing native vlan.

My work has replaced our Cisco switches with Arista switches. Connecting the D-link to the Cisco worked but I can't get me D-link 1210-28MP to connect to my Arista 720XP when trying to trunk.

If I leave VLAN settings as default on the D-Link I can get traffic between the two but when I try the trunking settings on the D-Link it looks like only ARP, LLDP, and OSPF traffic is seen. The connection is from port 18 on the D-link to port 15 on the Arista, copper connection.

D-link settings are:
port 18
VLAN 1 Not a Member
VLAN 44 untagged
VLAN 244 tagged

Arista
interface Ethernet15

description Uplink to Access Switch

load-interval 30

switchport trunk allowed vlan 44,244

switchport mode trunk

spanning-tree portfast edge

Any help?

reddit.com

URLs Can't be Accessed by the Public

Ok, apparently my post yesterday was low quality and heaven forbid I ask questions and request for simple explanations. You networking guys are a tough crowd. I've never received more downvotes for trying to learn. I am new, forgive me.

Here's the issue:

A third party needs to access "rest services" on an internal server. From what I understand, everything accessible to the public needs to go through our DMZ'd Web Server. We can get to the Web Server and log-in portal just fine.

Here's the path: Public User > Hits our A.x.x.x > NAT on Firewall translates it to Web Server B.x.x.x > Web Server B.x.x.x communicates through specific ports to Portal Server Y.x.x.x and Main Server Z.x.x.x.

Our GIS manager says a company needs to access URLs (example is https://SERVER(Z.X.X.X).DOMAIN.COM:OPENPORT that point to server Z.x.x.x.

Now everyone yesterday is just keep on saying that it's a DNS issue. I'm not saying it's not. Server Z doesn't have a direct path to it from the public and I'm under the impression that's how it should be? There is no NAT rule for people to access server Z, so it makes sense that they aren't accessible to the public.

Here are my questions:

  1. Am I supposed to get another externally accessible IP address and NAT it to Main Server Z.x.x.x?
  2. Shouldn't these URLs just be accessible through A.x.x.x?

I'm not trying to be lazy and just have you guys answer all my issues, but I've been working on this forever and even my IT DIRECTOR is just like, "I don't know how this stuff works, figure it out." I've reached out to the company that makes the software and I'm trying to communicate with a third party for assistance.

I hate being a new networking guy when there is almost nowhere to go for help.

reddit.com
u/CrazyBinnegin — 1 day ago

Help with Nokia 1830 PSS PWRADJFAIL alarm

Can anyone with experience with Nokia 1830 PSS explain to me why this alarm triggers. As far as I know if the current span loss is within +-2db of the design loss, control plane should adjust it, but I am seeing otherwise for some cases.

reddit.com
u/EyeFirm7822 — 1 day ago
▲ 1 r/networking+1 crossposts

[Survey] Wireless Communication Problems in Businesses — IDT Student Project

Hi everyone!

We are engineering students conducting a short IDT (Innovation Design Thinking) project survey on wireless communication problems in businesses and organizations.

We are looking for responses from people involved in:

• Manufacturing

• Industrial automation

• IoT / technology

• Logistics / warehousing

• Operations & maintenance

• Engineering

• Business management

• Any work environment that uses wireless devices, sensors, or connected equipment

The survey focuses on understanding:

• How frequently wireless communication problems occur

• Common issues such as disconnections, packet loss, interference, and unstable connections

• Their impact on operations

• How businesses currently detect and troubleshoot these problems

• Limitations of existing approaches

• Useful features for a potential wireless monitoring solution

• Expected cost of such a solution

⏱️ Time required: 3–5 minutes

🔗 Google Form:

In comments

This survey is only for our IDT student project. We are not selling anything, and no confidential business information is required.

If you have experience with wireless systems in a business or professional environment, we'd really appreciate your response.

Thank you!

reddit.com
u/Wild_Bookkeeper4330 — 1 day ago

NAT Commands

https://imgur.com/a/4tC8J8j

In a situation where an NVR + Cameras live at Site A and Cameras also live at Sites B and C. The NVR can only reach cameras (not regarding it's internal switch network) that appear to be on it's local network.

I'm attempting to create NAT rules that make remote cameras appear to be on the same network as the NVR but having issues on what exact commands are needed for this type of NAT setup.

Edit: it is not a routing issue. It’s a design limitation that Reolink does for the NVR hence why I’m trying to do NAT rules on the Catalysts. Normally do DNATs on Fortigates and it has historically worked great for this camera situation but this environment doesn’t have Fortigates

https://community.reolink.com/topic/6726/unable-to-access-reolink-ip-cams-from-different-vlan

u/nicholaspham — 2 days ago

Radius, NAT, CGANT.

Hi Networking warriers, noob here. so I just recently discovered radius. So what i want to know is that, is radius possible if the server is not on my local network, I am renting a server in the cloud because i do not have a linux machine to run Freeradius. In the clients.conf file, the ipaddr =x.x.x.x, what do I put there if I am NAT'ed and i'm have multiple NASes? to make matters worse, at the moment I am CGNAT'ed, is it possible?

reddit.com
u/MegaRuffmaestro — 2 days ago

WiFi network qverload at conference. How to load test and prevent capacity issues

We had a conference recently where the Wi-Fi looked fine during testing the day before. We tested with a few tablets, badge printers and laptops and had no issues. Once around 800 attendees arrived, things started falling apart. Tablets kept disconnecting, badge printers became slow, and staff had to keep refreshing the check-in system. The venue Wi-Fi showed a strong signal, so I am assuming the issue was capacity rather than coverage.

For the next event, what should we be testing beforehand?

reddit.com
u/Fit-Firefighter-8943 — 3 days ago

Odd Traceroute

While troubleshooting a network issue for packets appearing to be duplicated (only once, not a continual flood), I did a trace from a nearby system and have output unlike anything I've seen before.

Localhost#traceroute 192.168.10.20

 Traceroute to 192.168.10.20 ,30 hops max 0 byte packets:

1  192.168.255.252     <1  ms    <1  ms    <1  ms
2  192.168.10.20       3   ms    <1  ms    2   ms
3  192.168.10.20       <1  ms    4   ms    <1  ms
4  0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
5  192.168.10.20       2   ms    *         <1  ms
6  192.168.10.20       <1  ms    2   ms    *
7  192.168.10.20       <1  ms    <1  ms    2   ms
8  0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
9  192.168.10.20       2   ms    *         <1  ms
10 192.168.10.20       <1  ms    2   ms    *
11 192.168.10.20       <1  ms    <1  ms    2   ms
12 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
13 192.168.10.20       2   ms    *         <1  ms
14 192.168.10.20       <1  ms    2   ms    *
15 192.168.10.20       <1  ms    <1  ms    2   ms
16 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  1   ms
17 192.168.10.20       2   ms    *         1   ms
18 192.168.10.20       <1  ms    <1  ms    *
19 192.168.10.20       <1  ms    <1  ms    2   ms
20 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
21 192.168.10.20       2   ms    *         <1  ms
22 192.168.10.20       <1  ms    2   ms    *
23 192.168.10.20       <1  ms    <1  ms    2   ms
24 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
25 192.168.10.20       2   ms    *         <1  ms
26 192.168.10.20       <1  ms    2   ms    *
27 192.168.10.20       <1  ms    <1  ms    2   ms
28 0.0.0.0            *        [192.168.10.20    ] reports:  <1  ms   [192.168.10.20    ] reports:  <1  ms
29 192.168.10.20       2   ms    *         <1  ms
30 192.168.10.20       <1  ms    2   ms    *


Hop Count = 30 Last TTL = 30 Test attempt = 90 Test Success = 69

I checked several other systems directly attached to this same switch and got similar results. However, doing a trace to a system connected to a downstream switch connected to the problem switch seemed just fine:

Localhost#traceroute 192.168.10.120

 Traceroute to 192.168.10.120 ,30 hops max 0 byte packets:

1  192.168.255.252     <1  ms    <1  ms    <1  ms
2  192.168.10.120      2   ms    1   ms    4   ms


Hop Count = 2 Last TTL = 2 Test attempt = 6 Test Success = 6

Vlan involved is trunked between the two switches, an IP Route on the upstream switch routes the traffic to the problem switch.

The connected systems are all various servers, and connections to these all seem to be operating just fine otherwise. I only noticed this because the 10.20 system is my DHCP server (for multiple subnets) and it suddenly started seeing duplicate DHCP requests coming in, and was sending duplicate replies as a result. This wasn't causing any problems so I didn't investigate until I saw my logs were growing faster than normal.

Has anyone come across a trace similar to the above, and if so, what was the cause? I'm not a network dummy, but this is a new one for me.

reddit.com
u/jimbo_rr — 3 days ago