Tuesday, March 10, 2015

Learn for Free

Not just technical skills...


Coursera is one of my favorite places to learn a new topic or even expand my horizons on topics with which I am already familiar.  The pacing of a real class structure, with weekly lectures and homework, applies just enough pressure to keep me motivated throughout the class and permits just enough flexibility to fit it into my real-life schedule.
Coursera is an education platform that partners with top universities and organizations worldwide, to offer courses online for anyone to take, for free.

https://www.coursera.org/




I believe this is a trend we will continue to advance as more and more colleges and universities open up classes for free.
Open.Michigan is a University of Michigan initiative that enables faculty, students, and others to share their educational resources and research with the global learning community.

http://open.umich.edu/


Thursday, March 5, 2015

Software Defined Networking (SDN) class at Coursera

Looking forward to this class starting May 25th, 2015:

https://www.coursera.org/course/sdn

Software Defined Networking

About the Course


This course introduces software defined networking, an emerging paradigm in computer networking that allows a logically centralized software program to control the behavior of an entire network. 

Separating a network's control logic from the underlying physical routers and switches that forward traffic allows network operators to write high-level control programs that specify the behavior of an entire network, in contrast to conventional networks, whereby network operators must codify functionality in terms of low-level device configuration. 

Logically centralized network control makes it possible for operators to specify more complex tasks that involve integrating many disjoint network functions (e.g., security, resource control, prioritization) into a single control framework, allowing network operators to create more sophisticated policies, and making network configurations easier to configure, manage, troubleshoot, and debug.

Tuesday, February 21, 2012

Enabling IPv6 on CentOS 5.6


Some additional information about IPv6 support and configuration is available from the CentOS wiki at:
http://wiki.centos.org/FAQ/CentOS5
These are the steps I followed to get IPv6 to work.
Edit the network file:
vi /etc/sysconfig/network
Set IPv6 networking to ‘yes’:
NETWORKING_IPV6=yes
Exit and save these changes.

Option 1, EUI-64 auto-assigned IPv6 address:

Edit the interface file:
vi /etc/sysconfig/network-scripts/ifcfg-eth0
If you want to have an auto-assigned IPv6 address based on EUI-64 auto-configuration:
DEVICE=eth0 ONBOOT=yes BOOTPROTO=none HWADDR=00:13:21:0D:0D:B9 # Required for EUI-64 auto addressing. DHCP_HOSTNAME=v6LAB-WWW1.opr.test.statefarm.org IPV6INIT=yes # Enables IPv6 addressing on interface. IPV6_AUTOCONF=yes # Enables EUI 64 auto-addressing. #IPV6ADDR= #IPV6_DEFAULTGW=
HWADDR and DHCP_HOSTNAME should be updated to match the specifics of each server but is likely automatically configured from install.
Exit and save these changes.

Option 2, static IPv6 address:

Edit the interface file:
vi /etc/sysconfig/network-scripts/ifcfg-eth0
So it the file should look something like this:
DEVICE=eth0 ONBOOT=yes BOOTPROTO=none HWADDR=00:13:21:0D:0D:B9 # Required for EUI-64 auto addressing. # Optional for static. DHCP_HOSTNAME=v6LAB-WWW1.opr.test.statefarm.org IPV6INIT=yes # Enables IPv6 addressing on interface. IPV6_AUTOCONF=no IPV6ADDR=AAAA::260:3EFF:FE11:5001 IPV6_DEFAULTGW=AAAA::260:3EFF:FE11:6780
HWADDR, DHCP_HOSTNAME , IP6ADDR, and IPV6_DEFAULTGW should be updated to match the specifics of each server.
Exit and save these changes.
Restart the interfaces with the new options:
service network restart
If there is no error message, IPv6 setup is complete. Jump to IPv6 Test and Validation.
If you get this kernel error:
CRITICAL : [ipv6_test] Kernel is not compiled with IPv6 support
See the section for Enabling IPv6 on CentOS 5.6 Kernal (if needed).

Enabling IPv6 on CentOS 5.6 Kernal (if needed)

The kernel options to support IPv6 on the Ethernet modules need to be enabled. Edit the module probe configuration file:
vi /etc/modprobe.conf
Search for these two lines and comment them out if they exist:
#alias net-pf-10 off #alias ipv6 off
And change this one from ‘1’ to ‘0’:
options ipv6 disable=0
So these lines look like this:
#Uncomment the next two lines to disable IPv6 support at boot. #alias net-pf-10 off #alias ipv6 off #Swap commented/uncommented lines below to disable IPv6 support at boot. #options ipv6 disable=1 options ipv6 disable=0
The only way for the new module options to take place is by a reboot:
shutdown –r now

IPv6 Test and Validation

With IPv6 enabled, we can confirm the interface has at least two IPv6 addresses. A global and a link(local) address:
[root@v6LAB-W1 ~]# ifconfig eth0 Link encap:Ethernet HWaddr 00:13:21:0D:0D:B9 inet6 addr: aaaa::213:21ff:fe0d:db9/64 Scope:Global inet6 addr: fe80::213:21ff:fe0d:db9/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:63 errors:0 dropped:0 overruns:0 frame:0 TX packets:96 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:6813 (6.6 KiB) TX bytes:15909 (15.5 KiB) Interrupt:209 Memory:fdef0000-fdf00000
We can ping the router (like Windows, the command is ping6):
[root@v6LAB-W1 ~]# ping6 aaaa::260:3eff:fe11:6780 PING aaaa::260:3eff:fe11:6780(aaaa::260:3eff:fe11:6780) 56 data bytes 64 bytes from aaaa::260:3eff:fe11:6780: icmp_seq=0 ttl=64 time=0.594 ms 64 bytes from aaaa::260:3eff:fe11:6780: icmp_seq=1 ttl=64 time=0.541 ms 64 bytes from aaaa::260:3eff:fe11:6780: icmp_seq=2 ttl=64 time=0.529 ms 64 bytes from aaaa::260:3eff:fe11:6780: icmp_seq=3 ttl=64 time=0.546 ms --- aaaa::260:3eff:fe11:6780 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time 3001ms rtt min/avg/max/mdev = 0.529/0.552/0.594/0.034 ms, pipe 2 [root@v6LAB-W1 ~]#
If we console into the router, we can ping our new server:
v6LAB-R1# v6LAB-R1#ping aaaa::213:21ff:fe0d:db9 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to AAAA::213:21FF:FE0D:DB9, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/4 ms v6LAB-R1#
And ssh to it:
v6LAB-R1# v6LAB-R1#ssh -l root aaaa::213:21ff:fe0d:db9 Password: Last login: Wed May 25 05:48:50 2011 from localhost6.localdomain6 [root@v6LAB-W1 ~]# [root@v6LAB-W1 ~]#

Apache/HTTPD configuration

No special configuration is necessary to enable IPv6 requests on Apache.
After installing Apache, it needs to be set to start at boot using this command:
[root@v6LAB-W1 ~]#chkconfig --level 2345 httpd on

Monday, October 10, 2011

Tweet forwarded by @russruns

cmross: Will seek this out later today.  Steve Jobs banner in the Windy City a nice tribute http://t.co/UjlQ2eG0 via @zite
Original Tweet: http://twitter.com/cmross/status/123434197460324352
Sent via TweetDeck (www.tweetdeck.com)

Tuesday, October 4, 2011

F5 LTM GTM IPv6 quick hit

Just quick note, F5 products LTM and GTM work just great with IPv6.  But IPv6 address shortening (double-colons '::') is not permitted in the GUI or tmsh.
LTM and GTM are Linux based systems, so if you are using BASH, the standard rules apply.
But if you are using the GUI or tmsh, IPv6 addresses must be fully completed.
This:
fe80:0:0:0:201:d7ff:fed4:d041
Not this:
fe80::201:d7ff:fed4:d041     ^^  Cannot have a double colon.

Wednesday, September 28, 2011

IPv6 SLAAC(er)

Promoted as a feature of IPv6, allows a device to connect to a network and receive an addresses without the administrative overhead of managing a DHCP.

But there are a few limitations that limit its usefulness in an enterprise environment:

  • SLAAC only works with /64 subnets. No more, no less.
  • SLAAC does not hand out DNS information (or any Windows domain specific info).

You get an address, a fixed subnet, and a default gateway. Period. This doesn't make it entirely useless, but definitely SLAAC is not a DHCP killer.

To enable a Cisco router to being making SLAAC announcements, all you need to do is configure an interface with an IPv6 address and a /64 subnet:

interface GigabitEthernet0/2
no ip address
duplex auto
speed auto
ipv6 address 2001:1890:1208:240::1/64

This line:

ipv6 address 2001:1890:1208:240::1/64

causes the router to begin making ND announcements which permit other devices to SLAAC themselves. We can verify announcements with a show ipv6 interface:


V6-R1-2911#sh ipv6 int gi0/1
GigabitEthernet0/1 is up, line protocol is up
IPv6 is enabled, link-local address is FE80::xxxx:xxxx:xxxx:xxxx
No Virtual link-local address(es):
Global unicast address(es):
   2001:xxxx:xxxx:xxxx::1, subnet is 2001:xxxx:xxxx:xxxx::/58
Joined group address(es):
   FF02::1
   FF02::2
   FF02::1:FF00:1
   FF02::1:FFFD:CCC1
MTU is 1500 bytes
ICMP error messages limited to one every 100 milliseconds
ICMP redirects are enabled
ICMP unreachables are sent
ND DAD is enabled, number of DAD attempts: 1
ND reachable time is 30000 milliseconds (using 30000)
ND advertised reachable time is 0 (unspecified)
ND advertised retransmit interval is 0 (unspecified)
ND router advertisements are sent every 200 seconds
ND router advertisements live for 1800 seconds
ND advertised default router preference is Medium
Hosts use stateless autoconfig for addresses.
V6-R1-2911#

Tuesday, September 13, 2011

So you've got IPv6...

...now what?

This site contains a list of websites with verified IPv6 connectivity. Regularly updated and tested. Also provides the resolved IPv6 address so you can perform basic ping testing in case your DNS is flaky (anyone else have this problem?).

Global IPv6 Deployment Progress Report

Haven't ruled out a problem on the local end, but we do get better (but not 100%) responses from:

Public DNS servers:

  IPv6 IPv4
Open DNS 2620:0:ccc::2
2620:0:ccd::2
208.67.222.222
208.67.220.220
Google Public DNS 2001:4860:4860::8888
2001:4860:4860::8844
8.8.8.8
8.8.4.4

Monday, November 29, 2010

Flickr API

This falls into the category of both work and fun.  Many of my clients use an online host to manage their photos. My personal favorite is Flickr. Whether you’re a professional photographer looking to expand your market or show off your latest, or you’re in a sales/marketing/promotion role and sharing pictures from the latest trade show, or simply have a need to share more than a handful of digital photographs, a photo-specific hosting site makes the job much easier and allows you to focus on results rather than the process.

Flickr provides the ability to easily embed photos in other applications and a highly extensible API for extracting and using photos for your own customized needs.

Before you begin creating scripts, you’ll need a Flickr API key.

From your account page, click on the “Sharing & Extending” tab.

Scroll down to “Your API keys” and click on the link to the right, which likely says “You have no API keys assigned to this account.”

Click on the “GET A KEY” button.

For now, we’ll stick with non-commercial applications, so click on “APPLY FOR A NON-COMMERCIAL KEY”.

You’ll need a name and description for you app.  For now, we can name it “Test Key” and give it a similar description. After reading the terms of use, confirm and check the boxes and click “SUBMIT”.

You’ll be given two hex strings, a “key” and a “secret”.  Since we created non-commercial keys, save these and don’t share with anyone.  You’ll want to copy/paste someplace for quick reference, but you can always retrieve them from your account page if necessary.

With your API key, we can now begin writing a script.

Once again, Perl provides a readily available repository called Flickr::API.  Use cpan to install:

cpan> install Flickr::API

I’d also recommend having Data::Dumper available.

cpan> install Data::Dumper

The first script will simply confirm your perl module is working properly and your API key is functionally.  Fortunately Flickr provides a test method.  Make sure to replace your_key_here with your Flickr API key (not your secret).

# C:\Perl\bin\perl.exe

use Flickr::API;
use Data::Dumper;

my $api = new Flickr::API({'key' => 'your_key_here’});

my $response = $api->execute_method('flickr.test.echo');

print "Success:\t$response->{success}\n";
print "Error code:\t$response->{error_code}\n";
print "\n\n\n";
#print Dumper ($response);

For now, leave the last line (Dumper) commented out. Running the perl command should give you these results:

R> perl Flickr-test.pl
Success:        1
Error code:     0

If the results are flipped (success: 0 and error: 1), there’s a high probability your key isn’t correct, or there were problems with the Flickr::API module.

Tuesday, November 9, 2010

Standards

We are regularly called on to report on the latency and packet loss to a remote location.  We allow the perl script to schlep the data into a csv file, which then gets exported into Excel to produce a graph.   Excel has great capability to create charts on-the-fly, edit, and annotate. But consider these two graphs, charting exactly the same data set:

 

image

image

 

The graph on the bottom produces a much dramatic display of latency, and washed out the packet loss.  The top graph emphasis the packet loss, while reducing the impact of the latency.  Both are accurate, but the tell a different story.

Typically, charts aren’t viewed in a vacuum, but are rather compared against other charts—charts of other locations, or historical charts.  For this reason, it’s important we compare charts of similar scale.

Not only must the axis be the same, but the proportions of the X and Y axis should be similar.

As part of the post-mortem templates, or performance report template, include graph standards: latency maximums, time-scales, and graph sizes.  It will make it easier for everyone to compare events as needed.

Friday, October 1, 2010

Cybersecurity Awareness Month, 2010

The cyber threat has become one of the most serious economic and national security challenges we face. America’s competitiveness and economic prosperity in the 21st century will depend on effective cybersecurity. Every Internet user has a role to play in securing cyberspace and ensuring the safety of ourselves, our families, and our communities online.

http://www.dhs.gov/files/programs/gc_1158611596104.shtm

Wednesday, May 5, 2010

Browser Acid Tests

Since I've been working at a hotspot ISP I've taken an interest in browser compatibility. We require the completion of a registration page before users can use our service. If users are unable to complete the registration because of a browser compatibility issue, it's a loss of service for the user and a loss of revenue for our company.



This has led to understanding browsers at a deeper level and their rendering of HTML/CSS standards. Strict enforcement of browser standards can be tested via the AcidTest website.



However, strict enforcement of standards does not mean a better browsing experience. With well over 50% market share, most websites are designed to work with Internet Explorer first and foremost.



You can access the testing site directly at: http://acid3.acidtests.org/



Firefox 3.6.3 gets a respectable 94%:


ScreenShot 10-05-05 10-43-18001.png



Chrome 4.1 gets 100%:


ScreenShot 10-05-05 10-43-13001.png



Opera 10 also gets 100%:


ScreenShot 10-05-05 10-43-15001.png



I.E. 7 produces a completely unusable rendering:


ScreenShot 10-05-05 10-43-10001.png

Tuesday, January 26, 2010

When is a graph not a graph...

I continued to be surprised at the number of times a group of people can look at the same graph and come to, not only different but, directly opposing conclusions.



Our department was recently contacted because one office was experiencing "slower than usual" transport speeds. Since my client heavily depends on transferring files betweeen offices and between client, a report of slow transfer speeds gets shoved to the top of stack.



I asked what speeds they usually experience, and what they are experiencing now. The response consisted of simply this graph:




image001.png



So...do you see the problem? Me neither. There's not even a label on the Y axis as to what this graph represents. It's certainly not megabits/sec, or even megabytes/sec. Possibly bytes/sec. So I called backed to ask and found out it's the number of files transferred per hour.



Now that we have that settled. It actually appears that we have recently transferred more files per hour than in the recent past. So another call is placed to clarify the perceived slowness. "It takes longer." "You're transferring twice as many files." "It shouldn't take this long." "How long should it take?". "It should be faster."



At this point I needed to prove (at least to myself) that there was definitively no network issue or--if there was--to uncover it.



At first glance, a chart of bandwidth utilization didn't reveal anything telling. There were no errors, no buffer allocation problems, latency was well within tolerance. However, one noticable artifact is that the bandwidth seem to be stair stepped. Many lines peaked at 0.5 mbps, with several more around 1.5 mbps, a few lines at 3.5 mpbs, and none more than 4 mbps. Since this was a dedicated T3 circuit, I would have expected more random spikes.



201001-OR-Bandwidth.PNG



Since access to the far end was limited, we could only test in one direction. It was now time to dig into the application and how, exactly, were files being transferred. We found out (1) files are being transferred via FTP, (2) a script kicks off every other hour to send all files in a given directory, (3) a third script is kicked off on demand.



This is now beginning to make sense. With limited visibility on the far end, we decided to push a 1 gig file (hope they have space). Bandwidth raised to 2 mbps and platuaed. While that was running, a second transfer was started. Bandwidth raised to 4 mbps. We continued adding multiple threads, up to 10 consecutive 1 gig files were being pushed. The circuit climbed to an almost predicatble rate of 20 mbps.

201001-OR-Bandwidth-multistream.PNG



With this evidence we were able to contact the server own on the far end. Indeed, his server was limiting the per session throughput to 2 mbps.



But this really wasn't a lesson in technical troubleshooting. This was a lesson in investigative work. A nameless graph and seemingly contradicts the end-user reports. Armed with limited capabilities, we were able to diagnose the problem and, better yet, propose a new solution.



On to the next...

Thursday, December 17, 2009

Whats Up Gold 12.4 - Changing Interface Stats Graph

Seems to be a regular request to change the reporting screens from "percent utilization" to an absolute rate; mbps or even just bits per second. The official way to do this (per Ipswitch) is to create new active monitors. But here's an easier way (note, this is a hack, not supported by Ipswitch).

The one down side is you have to pick a single rate in which to report all circuits, that is, the graph can be changed to report "bits per second", or "megabits per second", but there's no easy way to have it change intelligently based on the circuit.  What that means is, your sub-rate T1 lines and 10-gigabit switchports must all be reported in the same rate. 

The instructions below will change the graphs to "mbps" which should be good enough for most situtations.

Browse deep into the WUG installation directory to:
[sourcecode language="php" gutter="false"]c:\Program Files\Ipswitch\WhatsUp\HTML\NmConsole\Reports\Full\Device\Performance\RptInterfaceUtilization[/sourcecode]
Make of copy of the file "_RptInterfaceUtilization.inc" and save this original file--just in case.

Open up _RptInterfaceUtilization in your favorite text editor.

Look in the top section, around line 10 for the line:
[sourcecode language="php" gutter="false"]oAspForm.DeclareTranslation("sPercentUtilization", "Percent Utilization");[/sourcecode]
This is what gets printed on the vertical axis. Change the second parameter to read:
[sourcecode language="php" gutter="false"]oAspForm.DeclareTranslation("sPercentUtilization", "Mbits per second");[/sourcecode]
This is just a text field so it be whatever you want. Just keep it realitively short.

Now, scroll down to somewhere around line 35 for this section:
[sourcecode language="php" gutter="false"]" ((nIfInOctets_Avg  * 8.0) / (1.0 * NULLIF(nIfSpeedIn,  0))) * 100.0  AS nIfInOctetsUtilization, " +
" ((nIfOutOctets_Avg * 8.0) / (1.0 * NULLIF(nIfSpeedOut, 0))) * 100.0  AS nIfOutOctetsUtilization, " +
" ((nIfInOctets_Max  * 8.0) / (1.0 * NULLIF(nIfSpeedIn,  0))) * 100.0  AS nIfInOctetsUtilizationMax, " +
" ((nIfOutOctets_Max * 8.0) / (1.0 * NULLIF(nIfSpeedOut, 0))) * 100.0  AS nIfOutOctetsUtilizationMax  " +[/sourcecode]
These lines take the sampled interface rate and divide it by the maximum interface speed to get the percentage. We need to alter this formula to just give us the absolute rate in Mbps.  Since SNMP reports octets we still need to multiple by 8 to get bits and then divide by 1 million to get megabits. Change these lines to:
[sourcecode language="php" gutter="false"]" ((nIfInOctets_Avg  * 8.0)/1000000)  AS nIfInOctetsUtilization, " +
" ((nIfOutOctets_Avg * 8.0)/1000000)  AS nIfOutOctetsUtilization, " +
" ((nIfInOctets_Max  * 8.0)/1000000)  AS nIfInOctetsUtilizationMax, " +
" ((nIfOutOctets_Max * 8.0)/1000000)  AS nIfOutOctetsUtilizationMax  " +[/sourcecode]
Be careful that the parens match, as to do the quotes. Double check your work and save this file. Make sure it gets saved with the exact same file name and it only has an extension of ".inc"

Fire up your interface utilization reports and send them to the management team.

I should add that an WUG upgrade might possibly overwrite these changes.



Thursday, December 3, 2009

Cisco QoS Primer

A great list of documents from Cisco about Quality of Service; how to use it, configure it, and manage it.

http://www.cisco.com/en/US/tech/tk543/tk759/tech_white_papers_list.html

Thursday, October 1, 2009

National Cybersecurity Awareness Month

Full Story: http://www.dhs.gov/files/programs/gc_1158611596104.shtm

October marks the sixth annual National Cybersecurity Awareness Month sponsored by the Department of Homeland Security. The theme for National Cybersecurity Awareness Month 2009 is “Our Shared Responsibility” to reinforce the message that all computer users, not just industry and government, have a responsibility to practice good “cyber hygiene” and to protect themselves and their families at home, at work and at school.

Americans can follow a few simple steps to keep themselves safe online. By doing so, you will not only keep your personal assets and information secure but you will also help to improve the overall security of cyberspace.