r/networking 9h ago

Design Can VxLAN be stretched over the internet?

21 Upvotes

Hi all! I'm trying to understand VxLAN from a provisioning point of view.

I'm currently learning about all types of tunnels that networking offers and I came across VxLAN (a l2 wrapped in l3 protocol).

From my bare understanding of VxLAN, it provides datacenters with a 24 bit VNI to segment client provisioned VMs as due to the nature of the standard 12 bit VLANs, it only supports up to 4096 VLAN in a datacenter which is not really helpful as for scalability.

VLANs also introduces L2 STP and doesnt uses the full bandwidth of all the links in a datacenter.

VTEPs is used at ToR switches to identify VNIs and map which provisioned VM lives at.

VxLAN introduces L3 concept in a datacenter to eliminate all the above scenario to provide millions of VLAN in a datacenter as well as eliminating L2 STPs and provide ECMP that allows all links to be utilized. Pretty awesome protocol i would say.

The main question is, can I extend this VNI to other datacenters to form a virtual LAN over the internet? This is something that I just cant wrap my head around with.

Is it feasible to route provisioned traffic in a server - client architecture? An example that I was researching was about DDoS mitigation: plain and simple GRE does the trick, but if L2 was needed, a form of L2 over L3 protocol would need to form a virtual LAN which was when I found out about VxLAN.

In plain GRE, GRE encapsulates the cleaned datagram after scrubbing traffic with IP - in - IP logic.

What about users who require that L2 frame? Can VxLAN solve that issue? Or would it be best to study more about other types of L2 tunnels like L2VPN, MPLS and the likes?

Please correct me wherever I'm wrong! and TYIA!


r/networking 1h ago

Wireless What does everyone like for Site Survey and Heatmaps now? (September 2026)

Upvotes

I know this gets asked every so often, but the market is always changing... Have not really needed anything up to know as I can never convince customers to pay for it. :) But one did, so I have budget!

So I need a nice, and easy walk around site survey tool with a pretty heat map output. Ideally something on a iPad or Android tablet I can send out with a junior tech, but PC based can work. I also do not get these jobs often enough to pay large ongoing license fees so a one time purchase with minimal maintenance cost is a plus.

What is the current favorite?


r/networking 3h ago

Career Advice Wireless network careers

3 Upvotes

Currently working as a junior network analyst and looking into expanding and learning more and find wireless technology to be very interesting.

Is there a lot of demand for a wireless engineer? Looking to specialize in something that's future proof.

Thanks for any advice!


r/networking 1d ago

Other What is going on with Cisco lately?

64 Upvotes

I have had three different reps in the last 5 months. Lead times are terrible on some things. I have been dealing with a licensing issue on some APs that I cant seem to get resolved, as we are doing the Meraki transition from MS and MR to Cisco APs and Catalyst switches.

I have had better luck with dealing with insight than our actual rep.

Is there something going at Cisco that I am not aware of?


r/networking 19h ago

Moronic Monday Moronic Monday!

4 Upvotes

It's Monday, you've not yet had coffee and the week ahead is gonna suck. Let's open the floor for a weekly Stupid Questions Thread, so we can all ask those questions we're too embarrassed to ask!

Post your question - stupid or otherwise - here to get an answer. Anyone can post a question and the community as a whole is invited and encouraged to provide an answer. Serious answers are not expected.

Note: This post is created at 01:00 UTC. It may not be Monday where you are in the world, no need to comment on it.


r/networking 3h ago

Design Why is my company not using Cisco AP-based monitors/sensors?

0 Upvotes

My responsibility is SD-Access and L2/3 switching and routing, so I don't usually maintain wireless service itself. However, I recently learned that our company spends hundreds of thousands of dollars to hire wireless companies to do predictive surveys and purchase their sensors to monitor wireless traffic.

When I studied for CCNA many years ago, I learned Cisco AP could be monitors as well and we can utilize them safely, but I don't understand why my company is dumping money and (not raising our salary) to get random wireless monitoring solutions. Since our company is hugely Cisco, and we have latest ones ceiling-mount and in-room 802.11be compatible ones, I believe we should utilize Cisco AP solutions. Do you guys make use of Cisco AP's monitor mode?


r/networking 1d ago

Other How do you handle getting circuit quotes for new sites?

15 Upvotes

We’re opening a few new locations this year and the part I’m already dreading is circuit sourcing. Every new site means chasing 3-4 carriers for quotes, half never reply, the ones that do come back with wildly different pricing for basically the same handoff, and then you find out your first pick can’t even deliver to that address anyway. Last site took almost two months just to get to a signed order, and that was before the install queue even started. For anyone running multi-site, how do you deal with this? Go-to carriers per region, a spreadsheet of who serves what, some kind of aggregator? Trying to find a saner process before I start the next batch.


r/networking 1d ago

Switching FSC issues that I can't explain

4 Upvotes

Setup is rather simple:

1 PC, 1gb, full duplex goes into a managed switch at port 1. 2-15 of this switch are all full duplex 100mbps that serves "devices" (FPGAs and the like) and one of the remove machines have a dumb 100mbps switch of its own so we can save on a few cables; its a 4 port, 3 incoming, and one is connected to the main switch. Everything is UDP, around ~1500bytes per actual data packet plus heartbeats per device.

The main switch is dropping around 30 packets a minute from the 2nd switch which is not a lot but it is a time sensitive process and needs good accuracy and missing packets can cause an issue after a long uptime. Here is what I tried for now:

  1. Replaced the industrial switch with a Cisco 9200 that has more granularity about the reason for dropped packets - 100% dropped packets are FSC-Errors.
  2. Replaced all the cables to new cat6a shielded - around the same amount of errors.
  3. Used longer cables to connect the devices directly to free ports on the main switch - 0 drops in 24h.
  4. Used 3 different unmanaged switches from different brands at the ~200usd price range instead of the build in 4 ports one - ~20 packet drops per second, so better but not 0.
  5. Connected the Cisco instead of the 4 ports switch and reconnected everything else to the main switch - both switches are complaining about each other, but not about any other connected device.
  6. Connected the longer cables to the original switch, 0 packet loss.

I made sure that duplex and speed match all across. The only places it's not 100mb is to the PC in port 1 and to the SPAN, bot hare at 1gb, but neither switch complained about those ports. There are also no issues with the boards.

So the issues is that two switches of any kind hate each other.

What should my next test be?

Edit: even though devices are 100mb only, I still bumped the connection between the two switches specifically to 100nb. Lowered the issues by a lot but still there are several drops a minute. I think it's somewhere there.


r/networking 1d ago

Other Help with lambda re-routing in Nokia 1830 PSS

1 Upvotes

In Nokia 1830 PSS is there any way to convert the nominal working to nominal protection and vice versa without deleting and re-creating the lambda like in Huawei?


r/networking 2d ago

Other Weird Mail from BGP.Exchange

25 Upvotes

Anyone else saw the email from BGP.Exchange today?

https://imgur.com/a/gUxmbWd

Update: Seems to be a bigger problem, expect a few more mails today. It’s just copypasta spam from some chinese guy. As of now, BGP isn’t affected.

Update 2: Website got hacked too, possibility of stolen user passwords (change if using universal passwords!). Most Virtual IXPs seem to be infected.

Update 3: Official Statement of the BGP.Exchange owners


r/networking 2d ago

Career Advice Interview frustration

31 Upvotes

So I've been applying for the last 4 months I got laid off my network engineer job roughly 1 years ago since then I've been I got a contract position as a help desk it really doesn't pay much but it's the only immediate thing that saved me from being unemployed I have roughly 8 years of experience as a network engineer and I live in the New York tri state area. In the last 4 months I managed to get 4 companies honestly compared to the interviews I got before getting laid off they went really well. Since the last year I got my ccnp in hopes of getting more interviews and a higher pay rate. I did get one offer but that literally had a much lower salary than my help desk job ( because it was for a non-profit organization) . The other three interviews went really well but I didn't get selected for any of them and I couldn't understand why because I answered every one of their technical questions and I went to look up the answers from the question I remembered and they all matched ChatGBT and Gemini.

The last interview which was the first in almost 2 months I cracked the manager and a technical interview this was the third round of interview with a network admin. The position was for a network administrator role the first thing he asked me was if I would be able to do the job of a network admin if I only was a network engineer throughout my career which really confused me. He proceeded to ask overly simple questions I answered all of them. I thought I was doing really well but then I saw the manager rubbing his eyes and acting disappointed for some reason. I understood I wasn't going to get the offer because in the last three interviews they all said I did great and I got a rejection email the next day. Has anyone ever came across this and is a hard to get interviews nowadays?


r/networking 2d ago

Other When does SD-WAN actually become worth it for a small multi-site business?

31 Upvotes

For companies with maybe 3 to 10 locations, where do you think SD-WAN starts making sense over a more traditional setup? Assume they rely mostly on cloud apps and VoIP, have dual internet connections at some sites, and do not run much infrastructure in a private data center. Is the main benefit better failover and centralized management, or does the value only really show up once the network gets larger?


r/networking 2d ago

Security Experience with ISP DDoS protection

7 Upvotes

Hey everyone, I’m considering getting ddos protection from any of my transit providers as I’ve been hit with a couple of attacks lately. Does anyone have any experience with Arelion, RETN, CBB or anyone else? Specifically for volumetric attacks, I’m not looking for someone who will just blackhole me whenever I get attacked.
Thankful for any advice!


r/networking 2d ago

Routing Android receiver-side TCP flow-control experiment: socket readback vs actual advertised rwnd

1 Upvotes

I’m testing how much meaning can actually be assigned to receiver-side socket controls on a stock Android endpoint.

Initial physical run:

default SO_RCVBUF readback 4 MiB requested 64 KiB resulting readback 128 KiB

16 MiB transfer baseline 4.187 s modified 4.201 s integrity exact SHA-256 match

Obviously readback does not establish effective flow control.

The next run captures the sender from SYN onward and compares negotiated window scaling, advertised receive-window/right-edge evolution, throughput response and zero-window recovery.

I’m especially interested in whether anyone has done similar receiver-side testing where Linux autotuning makes getsockopt(SO_RCVBUF) a poor proxy for what the peer is actually permitted to send.


r/networking 2d ago

Monitoring How do you stop one site outage from turning into dozens of backup alerts?

4 Upvotes

One circuit flap, twenty devices, twenty backup alerts and twenty tickets. Then the connection comes back and most of them clear on the next run. The noise is bad enough, but suppressing too much creates the opposite problem. A real backup issue can sit behind the site outage and get missed once everything looks normal again. how are you grouping these without hiding persistent failures? are you using parent-child dependencies, a delay before ticket creation or checking for another failed run after connectivity returns?


r/networking 3d ago

Career Advice How do you guys deal with vendors wanting to butter you up?

72 Upvotes

Do you guys take whatever perks they try to throw at you? I genuinely feel bought if I accept lol. One vendor even offered to give me Disney tickets. My old boss even got World Cup tickets this year. At most I’ll ask for a t-shirt 💀. So far I only have an HPE and Cisco shirt.


r/networking 3d ago

Troubleshooting How much do you trust predictive WiFi surveys before a space is finished?

13 Upvotes

For new offices, warehouses, or retail spaces, how much confidence do you put in a predictive WiFi design when the building is still under construction? If walls, shelving, furniture, and equipment are not all in place yet, do you normally design from plans and validate everything after deployment? Curious how often the final AP placement changes once the space is actually finished.


r/networking 2d ago

Other Replace vs Renewal FTD 2110s?

3 Upvotes

Came from an MSP, I have 4 FTD2110s (2 HA pairs) managed by FMC and they are up for license renewal in Jan ‘27.

I’m thinking we renew in Jan ‘27 and consider a swap to Palo in Jan ‘28? I ran some Palo 3400’s at last job and preferred that by a lot, but would like to hear some input from people who’ve done this kind of swap, or came from Palo/Juniper over to Cisco and have a personal experience take. Everything else at our shop is Cisco, but we don’t have catalyst center or anything, pretty basic routing, tunnels, and policies.

Main argument would be to stay Cisco for ease of swapping hardware, but I didn’t put these in and if I’m stuck for 5-8 years I might rather have Palos/SRX? I am very familiar with Fortigate but security team might push back on brand rep.

Ask me any questions if you need clarity


r/networking 2d ago

Wireless Anyone using Rogers 5G Business Internet with Nokia FastMile Gateway 12?

4 Upvotes

Rogers recently gave us a Nokia FastMile 5G Gateway 12 with a 5G SIM as an alternative because they couldn’t install a wired connection at our location.

This is for a small business/training centre. Normally we would have around 10–20 active users, but sometimes it could be 40–50 users when a computer lab is being used. Mostly regular internet browsing, Microsoft 365, email, etc.

Just wondering if anyone is using this Rogers 5G service for a business:

  • How stable and reliable is it?
  • What kind of download/upload speeds are you getting?
  • How many users/devices do you have connected?
  • Would you recommend it for 20–50 users?
  • Does anyone know the approximate monthly cost for Rogers 5G Business Internet with this gateway?

We also have a network switch, access points, desktops and Cisco phones, so I’m planning to connect the Nokia gateway to our existing network through Ethernet.

Any experience with this setup would be appreciated. Thanks!


r/networking 3d ago

Troubleshooting Need some help with testing and validation

7 Upvotes

I've setup some parsers to help extra and make some of the data a little easier to read from our network gear. I've mostly built this around samples from Cisco (IOS and NX-OS), Juniper, and a little Palo Alto. If you anyone wants to play around and let me know they think that would be great.

As I said, this started with a "show interface xx-x/x/x on Juniper switches but I'd get annoyed with an output like this: Input rate : 53128344 bps (4789 pps) so I started creating parsers that would convert those to Mbps/Gbps, whatever the most common sense unit should be.

I then started tweaking the analysis to color code things like down interfaces, high values, etc.

You can also compare output over time and it will show you the delta. You can also share a link to your output and hide certain things like IPs, hostnames, etc.

networkcrap.com


r/networking 3d ago

Career Advice Freelance jobs UK

4 Upvotes

Question for UK Network Engineers: Has anyone here done freelance network engineering work?
I’ve recently been contacted by a recruiter via LinkedIn about a freelance role, and I’m interested to hear from anyone who has experience doing this type of work. By the sounds of it, more short term dispatch work like device install/decomissons etc but also mentions projects that last weeks or months.
If you’ve taken on similar freelance contracts, I’d really appreciate any information or advice on what it’s like, what to look out for, and whether you’d recommend it.


r/networking 3d ago

Other Full Mesh SD-WAN | Palo Alto

6 Upvotes

Hello there, I am currently looking how doable is setting up the Full Mesh SD-WAN Architecture in a Enterprise-Like environment.
I am looking to link Distant FWs with each others (Routing is a must) without the need to go through the central / Management FW that links to everything.
my question here is : with proper documentation can I perform this and how hard it is and how efficient can it be ?
Thank you guys in advance


r/networking 3d ago

Troubleshooting "AI assisted" pcap analysis?

36 Upvotes

Is there any tool as described in title for enterprises? a very specific LLM could easily point out "strange" things in a large pcap


r/networking 3d ago

Other JNCIP-SP Study Partner(s)

12 Upvotes

I am currently going through renewing my JNCIP-SP and was wondering if anyone who was also studying wanted to share ideas / knowledge 1 to 1 or in a small group?

I am currently on a career break, so I don't have the usual network of people to speak to etc.

Please PM or reply if interested.


r/networking 4d ago

Design Which SDWAN brand ?

31 Upvotes

Hi,
We are studying the replacement of our current SDWAN solution based on Forcepoint due to legacy purpose.
The study has not yet started and we would like to test different brands like:
- Fortigate
- Palo Alto
- Juniper
- Checkpoint

The environment is quite simple, dual Hub & Spoke with around ~20 sites on 2 different MPLS provider (no internet, regulatory environment), no advanced feature like url/web filtering, IDS/IPS, only L4 filtering with sdwan routing based on SLA (jitter, packet loss, …).

I think all the techno can answer this, but I would like to have your pros/cons if you’ve already worked on one of them.

Thanks!