In this post I explain the different types of NAT and why you need to use them. With the shortages of IPv4 addresses and the yet-to-arrive nirvana of IPv6 we re still using NAT to maintain network connectivity, and network engineers everywhere need to know how and when to use NAT. Introduction: Let’s Talk NAT Like Continue reading
Over the last couple of years I have gathered the number of new job postings for particular jobs advertised on Seek. Here s the results. Seek is the most dominant job-posting site in New Zealand. There s a few others, but Seek has the monopoly here. With Seek, you can set up an alerting mechanism where the Continue reading
I ve been fighting a bug with Junos Olive VMs running under KVM on a CentOS server for the last few days. I use Olive images now and then for network labs and to test configurations, and lately they re not running very well at all on my Linux KVM server. Here s a quick post on the Continue reading
The problem with making changes to any decent-sized network, which is running a routing protocol such as OSPF, is that in order to fully verify the change you will need to log into every device in the network and verify that your change has worked. This post shows how Ansible can be used to perform Continue reading
I ve been using fail2ban to protect a number of services from external attacks. The software works well, but what I wanted to do is to have fail2ban update an ACL on a Cisco IOS router rather then the IPtables on the host itself. Here s the code and some tips on setting it up. The Code Continue reading
The Cisco Zone-based firewall was derived from the old firewall feature set and allows the administrator to define firewall rules based on zones, where each zone may contain one or more logical interfaces. Using Cisco s zone-based firewall isn t as easy as many other solutions (e.g. Juniper SRX, Cisco ASA), and recently I needed to configure Continue reading
Sometimes it s just unavoidable that you need to do in-band management of firewalls. This is particularly the case if the firewall is hosted externally such as within AWS. Here s a quick recipe on restricting management access to the Fortigate firewall. I ve written a similar topic for the Juniper SRX on controlling management access to Continue reading
I had an interesting situation in a lab environment the other day. It seems Juniper has been tweaking how OSPF works with their routers with some interesting consequences. Here s the layout of the test network: All pretty simple and straightforward. R1 is the Area 0, or backbone, router. R2 is the ABR, and R3 Continue reading
The client s requirements were simple: they had an existing Cisco ASA 5505 with a base and unlimited users licence connected to the Internet with a PPPoE interface over ADSL. They wanted to add more bandwidth and redundancy so decided to add an additional 100mbps fibre link. Is it possible? Read on The Requirements After Continue reading
A recently-finished woodwork project. A small coffee table I ve recently finished. The top is made from recycled rimu heartwood, the legs and rails from new macrocarpa. Finished in Pure Tung Oil, and polished with paste wax. The legs and rails are hand-cut mortice and tenon joints. The top was hand-jointed and hand-planed flat, followed by Continue reading