This is the retired Shane Killen personal blog, an IT technical blog about configs and topics related to the Network and Security Engineer working with Cisco, Brocade, Check Point, and Palo Alto and Sonicwall. I hope this blog serves you well. -- May The Lord bless you and keep you. May He shine His face upon you, and bring you peace.
Tuesday, June 28, 2016
Monday, June 27, 2016
Another Start...
Although I really enjoyed working at the security firm I have recently moved to, I have an opportunity to focus on a vendor product line that I really believe in. I'm excited to join this manufacturer and I'll be starting today at my new position with them. More posts to come on the technologies...
Sunday, June 26, 2016
Sunday Thought: Even The Gentiles...
Acts 11:18 is an amazing verse to me. Me, being a Gentile, can appreciate this verse.
18 When they heard this, they had no further objections and praised God, saying, “So then, even to Gentiles God has granted repentance that leads to life.”
18 When they heard this, they had no further objections and praised God, saying, “So then, even to Gentiles God has granted repentance that leads to life.”
Saturday, June 25, 2016
Wednesday, June 22, 2016
Zip And Password Protect In MAC Terminal
Ive never been a fan of MACs, but the company Im with now requires me to use one. So, I manage. Recently, I needed to password protect some files I was sending, so I went into a bash session and typed the following: zip -er [Filename I want to zip to] [Folder I wanted to zip]
So, it looked like this when I was done: zip -er Shane.zip Shane.Folder
Just FYI if you need to zip up files and password protect them. The protection works across any platform when someone wants to open the file.
So, it looked like this when I was done: zip -er Shane.zip Shane.Folder
Just FYI if you need to zip up files and password protect them. The protection works across any platform when someone wants to open the file.
Monday, June 20, 2016
Get Certified...
I renewed my Cisco CCNP/CCDP certs today by taking one of the professional level tests. It's important to stay up on your certs if you want to work at a VAR or a solutions provider.
Pick what you like to do in IT, get some experience and go get certified. Then pursue it even more.
Pick what you like to do in IT, get some experience and go get certified. Then pursue it even more.
Sunday, June 19, 2016
Saturday, June 18, 2016
Thursday, June 16, 2016
Home Projects: Fixing A Truss
I hate to say that I didn't get any pictures of this. In the old '35 house we are redoing, there was one truss in particular that was split, viewable from inside the attic. Now there was no sagging in the roof or anything, but we needed to repair it. So my son-in-law and I got in the attic to sister two 2X4s together on the outside of the broken beam. This wasn't easy, as he had to lay on his back pushing upwards on the broken and new wood while I put twelve 4 and 3/4 screws in place. Either way, it's fixed and ready for longer and stronger life.
Wednesday, June 15, 2016
Cisco R&S: PortFast Tidbit
Just a real quick post, but did you know that, on a Cisco switch, when you configure a voice vlan on a switchport (switchport voice vlan x), that portfast is enabled automatically? Well, that makes sense if you have ever seen an IP phone boot up. But the thing is that if you take that config off, portfast is still enabled. This can cause you an issue if you happen to plug in a switch or something on that port later. The point is that if you unconfigure a voice vlan on your switch, you need to also disable portfast as well. Just FYI.
Tuesday, June 14, 2016
Enterprise NGFW 2016 Gartner Chart
NGFW 2016 Gartner Chart
This is interesting. I have always believed Palo and CP were the leaders. It still appears that way according to Gartner.
This is interesting. I have always believed Palo and CP were the leaders. It still appears that way according to Gartner.
Monday, June 13, 2016
Quote For The Day: 18
After the Orlando terrorist attack: “If we do not get tough and smart real fast, we are not going to have a country anymore. Because our leaders are weak, I said this was going to happen -- and it is only going to get worse. I am trying to save lives and prevent the next terrorist attack. We can't afford to be politically correct anymore.” ~~ Donald Trump
Sunday, June 12, 2016
Sunday Thought: Life Is Short
There is a song I've heard recently by Switchfoot called "Live it well" that is very interesting to me. See what you think.
Friday, June 10, 2016
Quote For The Day: 17
"Dear children, let us not love with words or speech but with actions and in truth." ~~ Apostle John
Thursday, June 9, 2016
Brocade vs Cisco: VDX/Nexus Etherchannel (Port-Channel) Utilization
You know, I've been meaning to write about this for a while now. There is this misconception about etherchannel link utilization that is going around. Meaning, if you have a port-channel configured with a few connections in a Cisco Nexus datacenter gear, don't think that all links will be utilized equally. Cisco uses "flow based" load balancing (hash based) to get data across the port-channel. So, flow #1 might be utilizing 90% of the first link in the port-channel, where the flow #2 might be using 5% of the second link in the port-channel, and flow #3 might be using 30% of the third link. Sure, you get the redundancy, and the bandwidth is technically there. But that doesn't mean that the load is evenly distributed across all links in the port-channel like you might think. This is handled in the IOS software. Flow based load balancing inherently results in point congestion and packet drops on single physical links without the capability of using unutilized capacity on additional links between the same switches.
In comes the Brocade VDX. The VDX actually DOES do "frame-level based" load balancing across its ISL links (trunk link). And, this actually does allow for full utilization of the bandwidth of a port-channel (called a trunk in Brocade). This is handled in the ASICs (hardware) instead of the software, and its Brocade proprietary.
If you want to learn more about the Brocade VCS solution for data centers, then click on this link to download "Brocade VCS Fabric Technical Architecture" paper. I highly recommend it.
In comes the Brocade VDX. The VDX actually DOES do "frame-level based" load balancing across its ISL links (trunk link). And, this actually does allow for full utilization of the bandwidth of a port-channel (called a trunk in Brocade). This is handled in the ASICs (hardware) instead of the software, and its Brocade proprietary.
If you want to learn more about the Brocade VCS solution for data centers, then click on this link to download "Brocade VCS Fabric Technical Architecture" paper. I highly recommend it.
Wednesday, June 8, 2016
Home Projects: Wiring Nightmares
I've touched on it a bit, but I, unknowingly, hired a bad electrician regarding this old '35 house. Thankfully, he is gone and we now have a reputable company in there correcting everything and making sure all the wiring is good and safe, and up to current code. I think we all should have a good work ethic, but as it turns out, it seems hard to find people these days with one.
Check out the 'replacing of old wire with new' job that the original "electrician" did below. Terrible work ethic. It's important, and if you think it's not, think again.
I heard yesterday of someone who bought a house, and when they had the power turned on, by 2pm the whole house burned to the ground. Electrical is the first thing I think of.
This is the 'new' wiring to a wall jack in the house. Again, it's all getting fixed with the new guys.
Check out the 'replacing of old wire with new' job that the original "electrician" did below. Terrible work ethic. It's important, and if you think it's not, think again.
I heard yesterday of someone who bought a house, and when they had the power turned on, by 2pm the whole house burned to the ground. Electrical is the first thing I think of.
This is the 'new' wiring to a wall jack in the house. Again, it's all getting fixed with the new guys.
Tuesday, June 7, 2016
Cisco R&S: SDM Templates On Switching Gear
On occasion, I have needed to change the SDM template for one reason or another. Primarily to be able to do PBR on 3750s (routing template). I thought it would be an interesting post to walk through the different SDM templates available. You may have certain needs in your network, and changing from the default template may be beneficial for you. Use with caution though.
Below are the different SDM templates:
Below are the different SDM templates:
- Access—The access template maximizes system resources for access control lists (ACLs) to accommodate a large number of ACLs.
- Default—The default template gives balance to all functions.
- Routing—The routing template maximizes system resources for IPv4 unicast routing, typically required for a router or aggregator in the center of a network.
- VLANs—The VLAN template disables routing and supports the maximum number of unicast MAC addresses. It would typically be selected for a Layer 2 switch.
- Desktop dual IPv4 and IPv6 default template—supports Layer 2, multicast, routing, QoS, and ACLs for IPv4; and Layer 2, routing, and ACLs for IPv6 on desktop switches (all Catalyst 3750 switches except Catalyst 3750-12S).
- Desktop dual IPv4 and IPv6 routing template—supports Layer 2, multicast, routing (including policy-based routing), QoS, and ACLs for IPv4; and Layer 2, routing, and ACLs for IPv6 on desktop switches (all Catalyst 3750 switches except Catalyst 3750-12S).
- Desktop dual IPv4 and IPv6 VLAN template—supports basic Layer 2, multicast, QoS, and ACLs for IPv4, and basic Layer 2 and ACLs for IPv6 on desktop switches.
- Aggregator dual IPv4 and IPv6 default template—supports Layer 2, multicast, routing, QoS, and ACLs for IPv4, and Layer 2 and routing for IPv6 on Catalyst 3750-12S aggregator switches.
- Aggregator dual IPv4 and IPv6 routing template—supports Layer 2, multicast, routing (including policy-based routing), QoS, and ACLs for IPv4; and Layer 2, routing, and ACLs for IPv6 on Catalyst 3750-12S aggregator switches.
- Aggregator dual IPv4 and IPv6 VLAN template—supports basic Layer 2, multicast, QoS, and ACLs for IPv4,and basic Layer 2 and ACLs for IPv6 on Catalyst 3750-12S switches.
Monday, June 6, 2016
Check Your Work
My wife pointed out to me that, during a milk commercial, the banner behind the contestants on the SPELLING BEE stage, one of the words was misspelled. The word "ingredient" is certainly misspelled. The point of this post is you should always check your work. I wonder how many people proofed this before letting it go public.
Sunday, June 5, 2016
Sunday Thoughts: If Its Anything Like This
I'm not one for anything scary. So you might understand if hell is a place that I certainly don't want to be, nor do I want that for anyone else.
I'm a visual person. And this scene from Constantine really creeps me. I'm sure Hollywood has desensitised us to some degree, but just think about this. Click here for the scene.
I'm a visual person. And this scene from Constantine really creeps me. I'm sure Hollywood has desensitised us to some degree, but just think about this. Click here for the scene.
Friday, June 3, 2016
Cisco R&S: UplinkFast Theory Of Operation
I've had to do some research on UplinkFast recently. I wont bore you with the details of what I'm doing, but I found a good document that explains the theory of operation of it HERE.
Thursday, June 2, 2016
Wednesday, June 1, 2016
Home Projects: Quarter Sawed Hardwoods Redone
I didn't do this myself, but in the '35 house, we had the quarter sawed hardwoods redone. Looks much better.
Subscribe to:
Posts (Atom)