Current Events > F*** yeah, just fixed the guest wifi at work

Topic List
Page List: 1
CableZL
10/19/18 2:33:33 PM
#1:


This problem has been plaguing me for a little over a month!

F*** yeah

I feel good

dunna nunna nunna na

I knew that I would

dunna nunna nunna na
---
... Copied to Clipboard!
#2
Post #2 was unavailable or deleted.
Muffinz0rz
10/19/18 2:36:16 PM
#3:


Why did you manually censor fuck
---
Not removing this until Pat Benatar is in Super Smash Bros. (Started 8/31/2010)
2018 NFLB Autumnsim (3-3): https://imgur.com/vNWlGwD
... Copied to Clipboard!
CableZL
10/19/18 2:39:14 PM
#4:


Muffinz0rz posted...
Why did you manually censor fuck

habit
---
... Copied to Clipboard!
Kaiganeer
10/19/18 2:39:34 PM
#5:


what was the problem
... Copied to Clipboard!
CableZL
10/19/18 2:53:00 PM
#6:


Kaiganeer posted...
what was the problem


We have 5 different floors across 2 different buildings at our corporate office that have wireless access points installed. About a month ago, we noticed that the automatic redirect function didn't work on the 1st floor of building 2.

We have Aruba APs that all work in a cluster, so the configuration is the same across all of the APs, and they elect a master AP to handle global configuration changes.

About a month and a half ago, our security architect wanted to monitor internet traffic and capture the data on a server. So, I set up an RSPAN (remote SPAN) session to send all internet-destined traffic that hits the core switch's uplink ports to a server connected to a downstream switch.

In order to setup an RSPAN session, you have to create an RSPAN VLAN just so the core switch can send the traffic to the downstream switch separated from the rest of the normal traffic. When you create a new VLAN on a Cisco, it is automatically allowed on all new and existing trunk ports.

Microsoft Visio Extremely Basic Network Design Diagram:
Firewall <-> Core Switch <-> Access switch stack <--(switch 8 port 30)--> Traffic Capture Server
- The RSPAN session is set up so that internet-destined traffic that goes from the core switch to the firewall is then sent on the RSPAN VLAN (VLAN #4094 in this case) to the access switch stack. Then I set up RSPAN configs on the access switch stack so that it sends the RSPAN traffic out of switch 8 port 30, which is connected to the traffic capture server.

I had to run the switchport trunk allowed vlan remove 4094 interface config command on all of the ports connected to APs on the 1st floor of building 2 in order to fix it. This was kind of a shot in the dark, but it's the only real difference between the configuration on the 1st floor compared to the other floors.

I don't understand why having the RSPAN VLAN allowed on the trunk ports connected to the Aruba APs would break the guest wifi redirect, but I'll ask Cisco about that.

(trunk ports allow all VLANs by default, vs access ports that allow only 1 data VLAN and 1 voice VLAN if the voice VLAN is configured).
---
... Copied to Clipboard!
GiftedACIII
10/19/18 3:18:01 PM
#7:


Congrats
---
</topic>
... Copied to Clipboard!
EliteLevel
10/19/18 3:25:54 PM
#8:


Good. Now people can get back to watching porn again.
---
Judge not, lest ye be judged and get butthurt.
... Copied to Clipboard!
CableZL
10/19/18 3:32:09 PM
#9:


EliteLevel posted...
Good. Now people can get back to watching porn again.

lol, we still block that stuff on our network.
---
... Copied to Clipboard!
EliteLevel
10/19/18 3:48:30 PM
#10:


CableZL posted...
EliteLevel posted...
Good. Now people can get back to watching porn again.

lol, we still block that stuff on our network.


Must be a terrible place to work then.
---
Judge not, lest ye be judged and get butthurt.
... Copied to Clipboard!
CableZL
10/19/18 3:53:59 PM
#11:


EliteLevel posted...
CableZL posted...
EliteLevel posted...
Good. Now people can get back to watching porn again.

lol, we still block that stuff on our network.


Must be a terrible place to work then.

It's a great place to work, actually. Best company I've ever worked for by far.
---
... Copied to Clipboard!
EliteLevel
10/19/18 3:55:02 PM
#12:


CableZL posted...
EliteLevel posted...
CableZL posted...
EliteLevel posted...
Good. Now people can get back to watching porn again.

lol, we still block that stuff on our network.


Must be a terrible place to work then.

It's a great place to work, actually. Best company I've ever worked for by far.


I used to work in a truck until I came into an inheritance.
---
Judge not, lest ye be judged and get butthurt.
... Copied to Clipboard!
Topic List
Page List: 1