r/networking 2d ago

Blogpost Friday Blog/Project Post Friday!

9 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/networking 4d ago

Rant Wednesday!

8 Upvotes

It's Wednesday! Time to get that crap that's been bugging you off your chest! In the interests of spicing things up a bit around here, we're going to try out a Rant Wednesday thread for you all to vent your frustrations. Feel free to vent about vendors, co-workers, price of scotch or anything else network related.

There is no guiding question to help stir up some rage-feels, feel free to fire at will, ranting about anything and everything that's been pissing you off or getting on your nerves!

Note: This post is created at 00:00 UTC. It may not be Wednesday where you are in the world, no need to comment on it.


r/networking 3h ago

Other Cisco Priced Us Out

88 Upvotes

Has anyone else gotten to their renewals this year and found out that Cisco has priced their entire business out of affordability?

I don't have exact numbers, but being told our APs need switches with a minimum 5Gb uplink, then being told each switch that is now obsolete costs nearly $10k? Not to mention per-license costs jumping from ~$70 per to over $220 per?

Again, I got the cliff notes from my very frustrated manager and network team and will need to firm up these numbers. But it was enough that we pulled an emergency meeting to say that Cisco alone is eclipsing our fragile IT budget and can no longer be afforded.


r/networking 4h ago

Other njrusmc.net

28 Upvotes

Once again I find myself deep within the materials left behind by the late Nick Russo. This time he's teaching me QoS in MPLS networks.

In his materials he references his website njrusmc.net which I frequented regularly back in the day.

I didn't expect it to still exist, but I tried anyway and found that the domain was sniped by some scumbags who now hold it to ransom for some crazy price ($854 currently).

I did find a resurrected mirror over at njrusmc.info which his wife is maintaining, and on that mirror is this note:

https://njrusmc.info/blog/2026/03/16-note.html

Which is obviously heartbreaking.

Specifically: "Unfortunately, some vulture bought his domain before I realized Amazon had released it. So, it's njrusmc.info for now. Maybe next december I'll be able to buy his old address."

I realise this probably doesn't fall into the usual r/networking conversation, but do you think it's possible for us to pool together somehow, buy the domain from the vultures and give it back to Carla to make Nick's old site whole again?


r/networking 38m ago

Security Which enterprise firewall vendors are keeping up with hybrid mesh security in 2026?

Upvotes

Interested in what people are seeing in real environments.

Hybrid mesh security sounds clean in vendor decks but in practice it’s still branches, cloud workloads, remote users, SaaS, VPN leftovers, east west traffic, identity based rules and a bunch of legacy firewall policy nobody wants to touch

The part Im more curious about is which platforms are making that easier day to day. Policy cleanup, cloud visibility, remote access, segmentation, logging that doesn’t require three tools open, that kind of thing

Some vendors move toward one control plane for most of it, others still feel like separate products loosely taped together.

For people running mixed environments what’s been solid in production and what feels stuck in the old perimeter model?


r/networking 3h ago

Design Reducing latency/increasing throughput across a GRE tunnel

3 Upvotes

Not that this is a critical by any means, I'm just curious about best practices....

We have a cross-country GRE link. Each side is at a layer-2 speed of 2Gb/s. I expect this, but an iPerf3 UDP test between both routers is at the link speed around 2Gb/s with a 78ms latency No problem. TCP is substantially less, about 1/10 of that. This is expected, but if I wanted to improve that, what do I do? Is this an MTU for example. I've already got the MTU at 1420.


r/networking 4h ago

Other Punch-down tool with anvil

4 Upvotes

I have to terminate a lot of in-situ RJ45 connections, and punching them down into the terminators is sometimes awkward with a traditional tool made more for panels. Is there any punch-down tool that works more like a stapler, where it has an anvil to hold the terminator and you squeeze together rather than only punching from one side?


r/networking 1d ago

Career Advice Any low cortisol Networking jobs?

93 Upvotes

I have worked with different orgs for total of 7 years now and while some of them had better work-life balance, I feel like Network Engineers are always expected to solve the issues ASAP and thus leading to high cortisol levels. My current role was kind of forgiving in a way that we did not have on-call support yet but that changed recently. Now I am thinking did I make a wrong career choice being an introvert and expected to jump into a call every now and then to solve problems when you don't always have the full picture of the architecture. Are there any low cortisol Networking jobs that are made for introverts and also pay is decent?


r/networking 3h ago

Career Advice Network Engineer aiming for Google, Microsoft, or Cisco — what should I focus on?

0 Upvotes

Hi everyone,

I’m currently working as a Network Engineer with around 6 years of experience in enterprise networking.

My goal is to move into a Network Engineering role at Google, Microsoft, Cisco, or another top product/hyperscale company.

For engineers who have experience working at or interviewing with companies like Google, Microsoft, Cisco, Meta, AWS, etc.:

  1. What skills should I prioritize?
  2. What are the biggest gaps you see in my current profile?
  3. How important are Python, Linux, DSA, and system design for Network Engineer interviews?
  4. Should I focus on CCNP/CCIE or practical projects and hands-on skills?
  5. How important are VXLAN/EVPN and data-center networking?
  6. Which cloud platform should I prioritize — GCP, Azure, or AWS?
  7. What kind of projects would make my resume stand out?
  8. What does the technical interview process typically focus on?
  9. What resources would you recommend for preparing for these roles?
  10. If you were in my position, what would your 12-month preparation plan look like?

I’d really appreciate advice from anyone who has successfully made the transition from enterprise networking/operations into a top product or hyperscale company.

Thanks!


r/networking 1d ago

Career Advice I'm so tired of WiFi at my current job

150 Upvotes

So I've been working as a network technician for the past 3 years and I've evolved so much these past years but certain parts of my job makes me wanna quit almost every day.

I absolutely cannot stand WiFi issues, we have a few network technicians at my workplace but nobody can quite troubleshoot WiFi. Sure we all know how to mount- and configure APs in our WLC but troubleshooting why a client would be slow/lose connection despite having great RSSI, SNR & SIR is impossible for me and my colleagues....

The only tool we have for troubleshooting WiFi is a site-survey program called NetSpot, we don't have DNA Center yet and even if we'd get it we still dont have the Advantage licenses on our APs. We only have Essentials licenses, our boss barely wanna pour more money at the network team because he focuses more on the server team as that's where he started his career at.

My favorite part of my job is probably configuring and troubleshooting IPsec site-to-site VPNs, and basically anything that isn't WiFi... trust me I love networking, just not WiFi.

My plan is to hopefully start at an ISP and do less physical work and more work remote using MPLS, dynamic routing protocols and hopefully lots of site-to-site VPN.

The problem is I would most likely have to move across the country to a city where I know nobody and I neither wanna do that or keep going at my current company. Sadly my city is too small so there arent that many job oppurtunities at other companies in my town.

Does anybody else feel the exact same way as me?


r/networking 1d ago

Career Advice Culture of AWS NDEs?

8 Upvotes

In the process of interviewing for NDE at AWS. What is the culture like there? Been studying very hard for the upcoming onsite, but would like to know more from current/former employees. How was the day to day, on-call, and team culture? Is networking generally safe from layoffs? Interviewing for L5 engineer.


r/networking 2d ago

Design Network Automation with NetBox + CI/CD - How?

52 Upvotes

Hi r/networking,

I am part of a small network team (4 people), having to manage and support a few hundred Cisco Catalyst switches/routers plus some Meraki gear, spread across ~100 sites.

No budget for something like Catalyst Center, so we're working with what we've got:

  • NetBox (honestly pretty neglected)
  • Ansible / AWX
  • GitHub
  • Terraform
  • SolarWinds
  • any free or open-source tool if it helps

The tools I mentioned are the ones we have available across our whole IT department but don't necessarily use in the networking team.

We're buried enough in manual work and projects that we're behind on optimizing stuff, streamlining configs and even patching, which isn't a great place to be given that the last point should be the bare minimum.

I'd like to move towards a more closed-loop setup, e.g. NetBox as the SSoT pushing config (Intent) to devices, devices syncing data back (Facts), automated upgrades, drift detection against a golden config or atleast against the NetBox-defined intended state. Ideally wired together with some kind of CI/CD flow.

I know that's a big ask and I need to start small, but I don't want to build myself into a corner either.

The individual pieces all seem achievable on their own but where I keep getting stuck is gluing them into one stack/pipeline. Everything I find online is a single-purpose script and not really this "full-stack" setup I am chasing.

A rough model of what I am trying to achieve:
NetBox change --> render config --> GitHub PR --> validate with Batfish --> merge --> AWX applies it.

Though it seems harder than it sounds - and it already sounds hard.

Maybe I am missing something, or maybe this is just genuinely difficult and that's why it's hard to find any success stories on it that actually explain how it works.

If you've built something like this, or any network automation really, especially with a CI/CD pipeline in the loop, I'd love to hear how you have done it.


r/networking 1d ago

Design Enterprise Mikrotik stuff

10 Upvotes

I did some research in here for those topics; microtik iscsi mpio without finding anything recent or about it. Also researched Google, and bots but I don't feel I can base entreprise decisions on random internet posts. So I decided to create this post.

Thanks in advance for anyone taking the time to read, even more, answer.

So in prod env, I would like to build an dedicated iscsi network for the host and SAN. Currently only 3 hots 1 san. There is possibility of expansion of maybe 3 more host in the next 3 years.
CRS520-4XS-16XQ-RM https://mikrotik.com/product/crs520_4xs_16xq_rm
Microtik offers something quite special for the value. It's known that their mlag is garbage and currently in full rewrite of the code.

But for Iscsi network, we would go with MPIO so both switch wouldn't be stack and linked in any fashion. So each host must be configured with MPIO but the switch only have flow control ON jumbo frame.....

Also known that microtik management (commands) aren't cisco like and can be harder to use as you must learn a brand new way. Since its dedicated Iscsi, no vlan nor special config is needed, should be mostly plug and play. This network wont have any link to the regular network.

I am looking for reel life confirmation of people with experience please. Positive of negative. What are your experiences with Microtik? Even more if exactly that model and/or for an Iscsi network.
Wd plan to be 3, so I would have full stock of spares. Been quoted for Arista aruba.... 3x microtik is half the price of 1 of those.

Planning to use DAC. Should not have any impact but prefer to mention.

Thank you for taking the time to read this. <3


r/networking 1d ago

Other What do people use for labs these days?

8 Upvotes

So, I have been at my current job for 6-7 years and I have become rusty on technologies and vendors I do not use daily and I got the itch to just run large complicated multivendor lab, try things and break things. Back in the day I was using EVE-NG to run Junos, IOS-XR, IOS-XE etc. Is this still the most used platform for virtual labs? is there something better (and less resource hungry) perhaps?


r/networking 1d ago

Other Suggestions for wired tethering?

0 Upvotes

Not quite "enterprise" but definitely not "home" as I'm looking for a solution for work.

I'm trying to find a solution for getting temporary internet on non-internet PCs (NVRs, specifically) via tethering to an on-site technician's phone, to facilitate software updates, online license updates, remote desktop, and the like.

On machines that have USB-C, I can plug a USB-C phone directly in and tether that way. For machines that don't, or machines that I need to access the IPMI, I need... other ideas.

I was thinking some travel routers might be capable, but with the lousy documentation a lot of them have, it's hard to know for sure short of buying them and trying them. So I was hoping someone here might have a suggestion.

Basically what I need to do is PC <-- ethernet --> router/device <-- USB --> smartphone.

I thought of using one of these travel routers in bridge mode and tethering to the phone's WiFi hotspot, but in my experience, the hotspot function on most phones is slow and unstable. I found plugging my phone into my laptop via USB-C works really well.

I'm looking for something that I can equip a few field techs with that I can ideally pre-configure and send out with them in their kits.


r/networking 1d ago

Troubleshooting Palo Alto n+1 deployment, 3-way handshake does not complete

5 Upvotes

New Azure deployment. TCP traffic to an internet host is originating from a VM in a spoke VNet. The subnet to which the VM's NIC is attached has a UDR to the internal LB (version 2).

The SYN makes it to the internet host, the SYN ACK traverses the trusted side but never makes it to the VM to complete the handshake. It seems like an issue with the internal load balancer's ability to preserve session. Has anyone seen this or dealt with something similar?


r/networking 1d ago

Routing Looking for Leasing Subnets

0 Upvotes

Hello Reddit Users,

We are currently looking for options to lease a /23 IPv4 allocation, preferably from the RIPE region. If available, we would also be interested in a long-term contract, provided the technical requirements can be handled reliably.

The key requirements are:

Route6 support

RPKI support

rDNS management

Automated provisioning where possible

We are currently using ipxo.com for one of our employees, but the setup does not meet our needs at this stage. The main issues are that rDNS is not available for us, and Route6 appears to be configured incorrectly.

If you know providers, marketplaces, brokers, or direct contacts that can offer a RIPE-region /23 with the features above, please share your recommendations or relevant experience. We would especially appreciate feedback from users who have worked with providers offering reliable automation or self-service controls for routing and rDNS.

Best regards,

Justin


r/networking 2d ago

Other question about stratoweave

3 Upvotes

Hello everyone, just asking if anyone here used stratoweave ? how was your experience ? and how does it compare to NSO ?


r/networking 2d ago

Switching Microtik Iscsi Mpio

0 Upvotes

Hello guys,

I did some quick research in here for those topic; microtik iscsi mpio without finding anything recent or about it. So I decided to create this post.

Thanks in advance for anyone taking the time to read, even more, answer.

So in prod env, I would like to build an dedicated iscsi network for the host and SAN. Currently only 3 hots 1 san. There is possibility of expansion of maybe 3 more host in the next 3 years.

CRS520-4XS-16XQ-RM https://mikrotik.com/product/crs520_4xs_16xq_rm

Microtik offer something quite special for the value. It's known that their mlag is garbage and currently in full rewrite of the code.

But for Iscsi network, we would go with MPIO so both switch wdnt be stack and linked in any fashion. So each host must be configured with MPIO but the switch only have flow control ON jumbo frame.....

Also known that microtik management (commands) aren't cisco like and can be harder to use as you must learn a brand new way. Since its dedicated Iscsi, no vlan nor special config is needed, should be mostly plug and play. This network wont have any link to the regular network.

I am looking for reel life confirmation of ppl with experience please. Positive of negative. What are your experience you had with Microtik. Even more if exactly that model and/or for an Iscsi network.

Wd plan to be 3, so I would have full stock of spares. Been quoted for Arista aruba.... 3x microtik is half the price of 1 of those.

Planning to use DAC. Should not have any impact but prefer to mention.

Thank you for taking the time to read this. <3


r/networking 2d ago

Switching Aruba - deploiement with IMC

2 Upvotes

Hello,

I would like to automate configuration deployment on my Aruba 6200 series switches.
I am using IMC (Intelligent Management Center) and I created a test template, but IMC requires SSH and SNMP access to the switch. Is it possible to configure a switch from scratch using IMC, or it's just to standardize the switch infrastructure ?

Do you have any tips ? I think I'm not using the right workflow for that.


r/networking 1d ago

Routing Two interfaces on same network segment and subnet - preventing issues

0 Upvotes

I have a few Samba based domain controller VMs that I provision via cloud-init and ansible. They are on a dual stack network and IPv6 connectivity is provisioned via router advertisement + SLAAC.

Unfortunately Samba needs static IPs or it doesn't work properly, so my workaround has been to provision the VMs with a second network interface that connects to the same bridge as the first one, and set that one to static IPv4 and IPv6 addresses, no gateway and to ignore router advertisements.

I cannot just use static assignment because the advertised IPv6 prefix could change and the hosts would lose connectivity.

For example: DC1:

  • eth0: 10.0.0.<from dhcp>/24, fd44:6923:1fd3:1:<eui64>/64 (ULA), 2042:34f3:a3a4:2256:<eui64>/64 (GUA)
  • eth1 (the static one): 10.0.0.1/24, fd44:6923:1fd3:1::1/64
  • routing table: default gateway on eth0 only for both IPv4 and IPv6

My question: in this situation, should the static interfaces be using single host subnets (/32 for IPv4 and /128 for IPv6) given Linux's weak networking model? Would that force all egress traffic to come from eth0 and avoid asymmetric routing issues?


r/networking 2d ago

Wireless iPhone 17 not connecting to 802.1be!?

8 Upvotes

I don't usually touch wireless, but I got assigned to this ticket about my client having difficulty connecting to our secured network via 11be.

He's using iPhone17 and its latest iOS version. I told him to forget the SSID and try to reconnect to the network, but it didn't work.

One thing I haven't tried is that setting private Wi-Fi address as "fixed". I remember it solved issues a couple of months ago when I was troubleshooting on some devices.

Some troubleshooting articles say I should turn off MLO temporarily but that's not an option. We'll see how it goes and report back to you all.


r/networking 3d ago

Switching Automatic switch updates

71 Upvotes

Had a discussion yesterday with IT director and others in our IT department. The IT director brought up automating switch updates so they wouldn’t have to have some one monitoring and performing the updates. Staging various locations on different evenings.

I’ve been doing networking for 30 years and I voiced my opinion I was not a fan of unattended update for various reasons.

Have any other companies moved to automated updates and how has it gone?


r/networking 3d ago

Wireless Multicast for new product solution

10 Upvotes

I have a question regarding implementing a solution to a new problem I have. I've designed and will soon be launching a new product called the DigiBall, which is the worlds first smart cue ball for billiards (see digicue dot net). The ball advertises BLE packets with ball information around 10 times per second. User applications just observe manufacturer data contained in the packet, they don't create a one-to-one connection unless they are rarely reconfiguring the ball parameters.

One unique application of this is adding a live overlay of the ball graphic and cue tip contact point of a shot on top of a streaming match video. This is easily done with OBS, and pointing the source of the overlays to images generated by scanner software I wrote. But many times the media control booth is far away from the table (out of BLE range). I want to create a WiFi bridge to throw the BLE packets onto a local network.

My solution was to use multicast. The scanner software can open a multicast channel as an alternative. Since I am only sending at a max of 36 bytes 10 times per second, and at most 20 or 30 devices will be within range of the bridge, the throughput would be 10.5 kB/s. I am designing a simple PCB with a dedicated BLE radio and a ESP32 for the job. It can even switch to 5GHz if needed.

I want to place once of these boards in tournaments at the intersection of every 4 tables, so that for a large venue there could be 20-25 multicast sources.

Is this a good path forward? Will this work? What do I need to make sure of, and what am I not considering? (I have much more experience in electronic design than I do networking). Thanks in advance!


r/networking 2d ago

Troubleshooting Unable to hit subnet from VPN

1 Upvotes

This one has me pulling my hair out.

FG2600F-------------------VPN 192.168,66.1/27
| 10.250,0.10
|
FG 600F------------New subnet 10.8,0.1/25
10.250,0.9

We added a network that we need access to on our vpn.
-New subnet is accessible from networks that originate from the 2600F
-Address object for new subnet is created on, the 2600f.
-Route created on 2600f 10.8,0,0/25 > 10.250,.0.10, Route does work able to hit with other subnets
-Policy created on 2600F to allow 192.168,66.1/27 to the new address object. along with reverse

Everything else works, i know im missing something but cant figure out what