Showing posts with label Networking. Show all posts
Showing posts with label Networking. Show all posts

Saturday, May 16, 2009

Platforms for OS based Appliances

Sometimes I need a box for snort sensors or linux appliances, or BSD or even firewall distributions:

http://www.arinfotek.com/  Has some cool security oriented appliances- the Teak series.  

With iBase and Win Enterprise as competition in this sector.  Some have SSL acceleration or other cool security chips.

Here are some really cool boxes either way though:

The first is a full fledged tiny PC- also with bargain price:

Fit-PC2  It is a full PC even though it is small enough to stick to the back of your monitor.  Power consumption is a ridiculously low 5-8W.

The second is Hero Logic-   in competition with Soekris, but seems like a great polished product.  I'd love to try one out.

Thursday, July 24, 2008

NAT in my IPv6? It is more likely than you think...

NAT in my IPv6?

For the good: potentially make it easier to speed up IPv6 adoption.

For the bad: probably break end to end connectivity for some situations.

I hope not. I thought 6 to 4 tunnel was good enough. Guess not.

Monday, July 21, 2008

WRT54G Benchmarks

Alright benchmarked the WRT54G v.3 that I have with dd-wrt v.24. 216Mhz default, no overclock. Basically the thing does everything in software except layer 2 switching and runs out of CPU. I needed to know where the cut off is, because broadband keeps getting faster. You can depend on the box for about 20Mb/s throughput. If you approach that limit, you may run into CPU problems. I also found out the default window size on iperf on Windows client is 8K (too small for 100Mb networks). So all my tests use 256k window sizes (default on linux and os x). All tests were performed with iperf.

Full test notes for posterity:
test 1-LAN bandwidth- both ports plugged into lan ports, same vlan: iperf -s on vista server, iperf -c on OS X client 93.7 Mb/s no CPU on WRT54g.
test 2- LAN bandwidth- both ports plugged into lan ports, same vlan: iperf -s on OS X iperf -c on vista, 61Mb/s (too small a windows size 8K on windows), no CPU.
test 3- LAN bandwidth same as 2, but with real window sizes: iperf -s -w 256k on OS X, iperf -c 192.168.100.8 -w 256k- 93.7Mb/s second switched no CPU.
test 4- routing (no SPI/Firewall) from LAN to WAN same iperf settings as above except client is on the other network - 22.7Mb/s CPU pegged.
test 5- reverse client and server traffic now WAN to LAN- 22.7Mb/s CPU pegged.
test6 - enable SPI/firewall, repeat test 5- 18.3Mb/s. CPU pegged.
test7- reverse client and server now LAN to WAN- 18.3Mb/s CPU pegged.
test8- LAN to wireless- 17.3Mb/s no encryption G only, some 2.4Ghz interference. CPU not pegged, but high (fluctuating between 50-65%).
test9- wireless to LAN- same as above- 17.3Mb/s CPU, not pegged but high (fluctuating between 50-65%).

I should try with WPA, but there is so much interference here. I can't be sure what I'm testing, the wireless, the encryption, the interference.

Summary of results: the switch in the Linksys I have is in hardware- it gives 93.7Mb/s throughput. So L2 performance is good.

Just routing from Lan to WAN with no firewall you can get 22.7Mb/s and it is CPU limited. With a firewall enabled from LAN to WAN, you are limited to 18.3Mb/s and it is CPU limited. Linux iptables style firewall (what dd-wrt uses) is a pretty efficient packet filter (about 10% overhead it looks like).

On the wireless from wireless I got 17.3Mb/s throughput (no encryption), and there was still CPU left. That implies the wireless G protocol or interference will probably be the limit not WRT54G. Basically if you are doing more than 17Mb/s, the WRT54G could be a choke point as could wireless 802.11g. If you want more performance overclock or get a higher CPU dd-wrt capable box and don't use 802.11g wireless. We'll call it 17Mb/s is the upper end for an internet connection for these boxes (due to CPU and 802.11g being limiting factors), more features may make the ceiling a little lower.

Tuesday, July 08, 2008

GNS3 http://www.gns3.net

So there is a Cisco router simulator called dynamips. I was using it for a while on linux. It is kind of hard to setup and a pain in some ways. Now there is a graphical front end to it:

http://www.gns3.net Graphical Cisco Router Topology emulator

It makes it super easy to lab up simple topologies virtually (no clunky router hardware to dig around with you), and to test configurations and syntax. All you need in gns3 and at least one IOS binary. I used it on OS X, and it worked like a dream. Just get the DMG, click the image, copy GNS to the applications directory, then in the config stage I pointed gns at some images I had on my laptop (my tftp library I keep to upload to the lab). It fired up.

Then you can drag and drop some topologies. Console into the routers, etc.

This site had some nice tutorials for gns3 that the gns3 site doesn't cover.

Thursday, April 17, 2008

F5 advanced troubleshooting

Say you have a version 9.x F5 Bigip. Nice loadbalancer, does some cool stuff. You add some new config and suddenly you have what looks like a layer 2 problem. So you console the box, and run top and the CPU (and maybe RAM) is pegged. Something called tmm is pegging the box.


TMM is a daemon that does most of the traffic management on F5. It is written by F5 and is opaque... except for:

tmstat

/usr/bin/tmstat from F5 gives you some output about what tmm is doing. So you can kind of figure out where things are going wrong, while you are dialing support.

Output looks vaguely top like:
NAME
CPU: 0% busy 1% idle 99% sleep Thu Apr 17 13:59:00 2008

Memory Allocated New Flow Old Flow Poll
21,081,060 / 1,807,745,024 99,851 25,284 1,228,703 Cycles
[ . : . | . : . ] 1 20 2,035 Total
vnic
Tc4,240b rx Cryplinkps 21,664b txass 27 Timers
[ . : . | . : . ] i8254x:00 (t[ . : . | . : . ]otal) 0 Stats
23,832b rx 1,000 linksa 4,112b txeudo
[ . : . | . : . ]ects 0 fu[ . : . | . : . ]tropy Virtual Class
Wa0b rx 0 linkecord 0b txcure 10,867,070 (total)
[ . : . | . : . ] 0 ci[ . : . | . : . ] 10,485,780 mco db
0 De0b rx 0 linkunseen) 0b tx 168,855 ssl
[ . : . | . : . ] [ . : . | . : . ] 143,727 tcl
0b rx 0 link 0b tx 68,708 (unseen)
[ . : . | . : . ] [ . : . | . : . ]
0b rx 0 link 0b tx Umem Class
[ . : . | . : . ] [ . : . | . : . ] 854 (total)
0b rx 0 link 0b tx 513 xfrag
[ . : . | . : . ] [ . : . | . : . ] 127 connflow
0b rx 0 link 0b tx 117 listener
[ . : . | . : . ] [ . : . | . : . ] 19 poolmbr
0b rx 0 link 0b tx 78 (unseen)

Saturday, February 16, 2008

Some good wireless networking training- free

Aruba makes a nice lightweight access point (LWAP). Centrally managed from a central point. Part of their magic is a GRE tunnel from AP to controller, so the controller can do all kinds of nifty tricks with/to the wireless client packets.

Here is some network training that is has some free options:

Free Wireless Training

Some is Aruba specific (hello mounting Aruba hardware). But the networking fundamentals course is vendor agnostic and has some good information.

Ever wondered why 802.11b clients slow down 802.11g networks, then do the networking fundamentals:

http://www.arubanetworks.com/education/networking_fundamentals.php

It does a review of basic networking, covers wireless and security basics. Self paced in wmv and mov formats.

The other training courses are more Aruba-centric.

Friday, June 16, 2006

LVM and a rant on bonding and 802.1q

use LVM if you are using a modern linux.

Really. It will make your life easier.

Bonding and 802.1q configuration under linux suck right now. If I get time to experiment, I will figure out the model config. But really Redhat or Suse needs to come out with a configuration tool so you can bond interfaces (and use static or dhcp addresses) and use 802.1q vlan tagging on those interfaces (or non-bonded interfaces).

Monday, May 29, 2006

Cisco 2500 router IOS upgrade

Bucket of pain. The 2500 series routers can have 16Mb of RAM and 16Mb of flash. It stores the OS, called IOS in the flash. The config goes in NVRAM and the boot stuff goes in the boot rom.

I have two routers with two banks of 8Mb flash and it was a mother to upgrade one of them.

The first router upgraded fine with the classic copy tftp: flash: syntax. It erased the old IOS and put the new one on over and away it went (only had to good with the conf reg once 0x2142 to get rid of a config with a password I forgot).

The second one was pain. The two Flash banks showed up seperate, the copy tftp: flash: spat back READ ONLY FILE SYSTEM... so on and so forth.

Here was the fix:

conf 0x2101 (this boots a rom or cut down IOS).
partition 1 16 (make one big 16Mb partition instead of two 8s)
copy tftp flash
conf 0x2102

The 2500 is great for a lab, but don't use one in production. The new ISR routers are quite nice.

Tuesday, May 16, 2006

Use DNS- it's good enough for the internet

I just fixed a couple boxes that didn't know what localhost was... actually they did, but it was wrong (pointing to their actual IP address, not 127.0.0.1).

Look don't mess with host files. You don't need to. Use DNS.

If you have more than one host, use DNS with Dynamic DHCP. You can reserve IP addresses so that hosts always get the same IP, you can extend lease times, you can put all kinds of things in DNS. But if you update dynamically you will always have the forward and reverse DNS correct (A record and PTR) and you won't have stupid host file troubles like I just had.

Friday, May 12, 2006

Cisco 3005 VPN concentrator resurrection

I found an unused 3005 going through one site's material. Since the current VPN terminates on PCs, I thought I'd get the 3005 going.

While I had the 3005 on the shelf in the lab, I found a problem. The 3005 has a public and private interface. The private interface would intermittently drop physical connection. I inspected the network jack, it looked good, no bent pins. But everytime I'd wiggle the network cable (or even move the middle of the cable), the connection would drop.

So I tore the out of warranty and service 3005 apart (don't do this, it will void your warranty). I checked the posts and solder on the network jack. It looked good, so I put the 3005 back together. While I had it apart I noticed two little silver tabs on the sides inside of the jack where the pins are. I used a very fine screwdriver and bent these two tabs out on both jacks hoping it would tighten the grip on the network cable.

Sure enough it works. I'll try to get a macro picture up soon.

Tuesday, May 09, 2006

Silly Juniper...

Just got the Juniper ScreenOS Product Documentation CD Version 5.0 June 2004 Rev. B in some brand new NetScreen 50 boxes.

Either the doc CDs aren't revisioned very often or these NS50's move kinda slow... any way,

The disc is CDFS or whatever, but all the directories are 444 permissions on linux and MacOS. You can't change directories to read the PDFs when anything but root. On a linux box, at least you can be root, on a Mac it is really inconveniant. In either case, why would I want to be root when I'm reading PDFs?

Looks like nobody at Juniper uses the doc CD on different architectures. Maybe they only use windows internally or have all the docs on the webserver internally.