<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://camarreal.dedyn.io/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://camarreal.dedyn.io/feed.php">
        <title>dokucama - network_stuff</title>
        <description></description>
        <link>https://camarreal.dedyn.io/</link>
        <image rdf:resource="https://camarreal.dedyn.io/lib/exe/fetch.php?media=wiki:logo.png" />
       <dc:date>2026-05-01T15:02:04+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:checkpoint&amp;rev=1718874307&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptocurrencies&amp;rev=1742645580&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptography&amp;rev=1734643552&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:cscaler&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:cumulus&amp;rev=1727023672&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:cybersecurity&amp;rev=1726669699&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:dell-force10&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:ecmp&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:esxi&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:eveng&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:f5&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:flow_information&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:flowspec&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:fortinet&amp;rev=1732029834&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:frr&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:haproxy&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:huawei&amp;rev=1712759379&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:iot&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:irr&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:jpuppet&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:juniper&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:kubernetes&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:linux_network_internals&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:linux&amp;rev=1728235035&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:lld_notes&amp;rev=1708152194&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:machine_learning&amp;rev=1747075969&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:microwave&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:mtunotes&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:netapp&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:netbox&amp;rev=1751647274&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:netscaler&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:openwrt&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto_lab&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:product_sunsetting&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:ptp&amp;rev=1750172516&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:pxeboot&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:sase&amp;rev=1715098063&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:scapy&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-access&amp;rev=1736286964&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-wan&amp;rev=1737567486&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:service_mesh&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:sonic&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:sso&amp;rev=1734646083&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpdump&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpnotes&amp;rev=1728909876&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:transit-marseille&amp;rev=1755355331&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:transit&amp;rev=1755355478&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:vpn_troubleshooting&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:vyos&amp;rev=1698935895&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:wifi&amp;rev=1742036484&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark-troubleshoot&amp;rev=1719917268&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark&amp;rev=1752182516&amp;do=diff"/>
                <rdf:li rdf:resource="https://camarreal.dedyn.io/doku.php?id=network_stuff:zscaler&amp;rev=1725267633&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://camarreal.dedyn.io/lib/exe/fetch.php?media=wiki:logo.png">
        <title>dokucama</title>
        <link>https://camarreal.dedyn.io/</link>
        <url>https://camarreal.dedyn.io/lib/exe/fetch.php?media=wiki:logo.png</url>
    </image>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:checkpoint&amp;rev=1718874307&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-06-20T09:05:07+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>checkpoint</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:checkpoint&amp;rev=1718874307&amp;do=diff</link>
        <description>Policy lookup (cli)
(not possible?)

Search policies

text search box above</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptocurrencies&amp;rev=1742645580&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-03-22T12:13:00+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cryptocurrencies</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptocurrencies&amp;rev=1742645580&amp;do=diff</link>
        <description>Blockchain 
A blockchain is an immutable digital ledger that records every single transaction ever made.

	*  Blockchain transactions are irreversible in that, once they are recorded, the data in any given block cannot be altered retroactively without altering all subsequent blocks.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptography&amp;rev=1734643552&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-12-19T21:25:52+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cryptography</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:cryptography&amp;rev=1734643552&amp;do=diff</link>
        <description>Asymmetric Key encryption:



	*  Kpriv
	*  Kpub

----------

OPENSSL/CERTIFICATES
See crypto summary here:HERE


To check the TYPE of certificate we have:
openssl x509 -in jaime-cert.cer -inform [der/pem] -noout -text
To READ the contents of a certificate:</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:cscaler&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cscaler</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:cscaler&amp;rev=1698935895&amp;do=diff</link>
        <description>Allows the same kind of segmentation we can get in an EC2 instance (security groups, acl and so on) but in end user stations

	*  Requires cscaler agent running on the computs
	*  cscaler has their own cloud
		*  they offer there: authentication, firewall (inspection) and metrics</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:cumulus&amp;rev=1727023672&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-09-22T16:47:52+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cumulus</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:cumulus&amp;rev=1727023672&amp;do=diff</link>
        <description>cheatsheet

----------

Install packages:
sudo -E apt-get update
sudo apt-get install iperf

----------

CUMULUS MULTICAST:
net add interface swp1 igmp join  224.10.2.1  # for an interface to join a group
net add pim rp 10.1.0.5 224.10.2.0/24
! The above works and &#039;net show mroute&#039; shows state</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:cybersecurity&amp;rev=1726669699&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-09-18T14:28:19+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>cybersecurity</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:cybersecurity&amp;rev=1726669699&amp;do=diff</link>
        <description>Data Types

	*  Regulated: Data governed by laws (e.g., GDPR, HIPAA) that mandates its protection.
		*  Example: Personal health records or financial transactions.


	*  Trade Secret: Proprietary information that provides a competitive edge; it’s not publicly known and is protected by law.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:dell-force10&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>dell-force10</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:dell-force10&amp;rev=1698935895&amp;do=diff</link>
        <description>FN-IOM - (Force 10 Networks)

PE-FN-410S-IOM

	*  VLT (Cisco vpc or juniper MCLAG):  &lt;https://bladesmadesimple.com/wp-content/uploads/2014/11/PowerEdge-FX2-%E2%80%93-FN-IO-Module-%E2%80%93-VLT-Deployment-Guide.pdf&gt;
	*  VTL mode : all configurationsexcept VLAN membership are automated. Port 9 is dedicated to the VLT interconnect in this mode. &lt;&lt; This is a problem because we are already using it for uplink</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:ecmp&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ecmp</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:ecmp&amp;rev=1698935895&amp;do=diff</link>
        <description>*  BGP multipath: for links in different PEs. Uses maximum-paths eibgp 3 (cisco); maximum-paths 2 ecmp 2 (arista)
	*  BGP additional paths: this is normally through a single links. Command: additional-paths send/receive (cisco); bgp additional-paths send any</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:esxi&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>esxi</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:esxi&amp;rev=1698935895&amp;do=diff</link>
        <description>ENABLE SSH. ESXI GUI: &lt;https://www.experts-exchange.com/articles/28874/HOW-TO-Enable-SSH-Remote-Access-on-a-VMware-vSphere-Hypervisor-6-5-ESXi-6-5.html&gt;

CHECK VERSION AND LOOK FOR A CHEATSHEET:
] vmware -v
VMware ESXi 6.5.0 build-5969303
VM LIST
esxcli vm process list # List VMs, name , drives, etc etc
NETWORK SHOW

https://www.tunnelsup.com/networking-commands-for-the-vmware-esxi-host-command-line/
esxcfg-nics -l
Name    PCI          Driver      Link Speed      Duplex MAC Address       MTU    …</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:eveng&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>eveng</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:eveng&amp;rev=1698935895&amp;do=diff</link>
        <description>----------

----------

Installed eve-ng installed as vm under KVM and “Virtual Network (NAT)“


To access KVM via my laptop&#039;s virtual-manager (while in ocna), we just use ssh and the ssh proxy settings in  .ssh/config:


## us-ashburn-1 V2
Host 10.195.* 10.197.* *iad1.mycompany2datacloud.com *iadshared1.mycompany2datacloud.com !bastion-62-* *ash.oci.mycompany1.co.uk *iad.oci.mycompany1.co.uk
ProxyCommand ssh bastion-iad.mycompany2datacloud.com -W %h:%p</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:f5&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>f5</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:f5&amp;rev=1698935895&amp;do=diff</link>
        <description>*  Local Traffic Manager, directs different types of protocol  and  application traffic  to an appropriate destination server
	*  WebAccelerator™
	*  BIGIP+LTM+APM (Local Traffic Manager + Application Security Manager)



TMOS is the f5 operating system: CLI utilities (to configure it)</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:flow_information&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>flow_information</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:flow_information&amp;rev=1698935895&amp;do=diff</link>
        <description>FLOW INFORMATION

	*  SFlow UDP-6343
	*  Netflow (v5, v9) UDP-2055 or UDP-9996
		*  IPFIX


Neflow vanilla configuration CSR1000v
flow exporter Flow-exporter
 destination 10.10.11.143
 source GigabitEthernet1
 transport udp 9995
 template timeout 180    # every 3 minutes the router sends &#039;options template&#039; which includes the sampler rate. This allows &#039;embedded sampling&#039; to be requested by collector
 template data timeout 180    # &#039;data&#039; and &#039;options&#039;. the lack of templates just means it takes X …</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:flowspec&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>flowspec</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:flowspec&amp;rev=1698935895&amp;do=diff</link>
        <description>FLOWSPEC IN CISCO NCS5500
&lt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/BRKSPG-3012.pdf&gt;
show bgp ipv4 flowspec summary    ! To see the current flowspec established sessions
!
show flowspec afi-all detail      ! To see what flowspec rules are currently applied
AFI: IPv4
Flow :Dest:25.1.102.1/32,Proto:=17,Length:&gt;=500&amp;&lt;=1550
Actions :Nexthop: 25.3.9.3 (bgp.1)
Statistics (packets/bytes)
Matched : 0/0
Dropped : 0/0
!
show policy-map transient type pbr pmap-name
__bgpfs_default_IPv…</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:fortinet&amp;rev=1732029834&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-11-19T15:23:54+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>fortinet</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:fortinet&amp;rev=1732029834&amp;do=diff</link>
        <description>*  Fortinet NSE 7
		*  FortiManager (fmg)
		*  Fortigate (fw)
		*  FortiAuthenticator
		*  FortiGuard (TODO)
		*  FortiAnalyzer (logging)


----------

Deploying FortiX:
To identify the hardware:
get system status
	*  [cheat_sheet] (with cli commands)
	*  console</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:frr&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>frr</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:frr&amp;rev=1698935895&amp;do=diff</link>
        <description>INSTALLATION



	*  Install any of the supported base linux. eg: Debian/Ubuntu
	*  Follow this steps: &lt;https://deb.frrouting.org/&gt;
	*  Uncomment net.ipv4.ip_forward=1 in /etc/sysctl.conf and then apply with: sysctl -p
	*  If possible to access via console, remove all the network configuration from the linux level.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:haproxy&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>haproxy</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:haproxy&amp;rev=1698935895&amp;do=diff</link>
        <description>BASIC CONCEPTS

External Link

/etc/haproxy/haproxy.cfg
We define acl and backends.
Then acl define what backend we use.
use_backend blog-backend if acl_url_blog
----------

OPERATION:

Restart:
/etc/rc.d/init.d/haproxy restart
----------

MONITORING

From the cli, this command gives us a csv, dump in Calc. Check max connections and current connections.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:huawei&amp;rev=1712759379&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-04-10T14:29:39+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>huawei</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:huawei&amp;rev=1712759379&amp;do=diff</link>
        <description>Layer  Models  Brief Description  Access  S5720 Series  Versatile switches commonly used for various applications.              S6720 Series  High-performance switches with advanced features.              S6730 Series  Scalable switches suitable for large-scale networks.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:iot&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>iot</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:iot&amp;rev=1698935895&amp;do=diff</link>
        <description>IOT
LPWAN

LoRa + LoRaWAN = LPWAN


HOME REALM

	*  Bluetooth LE External Link
	*  Zigbee</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:irr&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>irr</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:irr&amp;rev=1698935895&amp;do=diff</link>
        <description>IRR SANITATION SEE THIS ABOUTMANRS

\\&lt;https://panda314159.duckdns.org/doku.php?id=network_stuff:irr&amp;do=edit&gt;
This is a hands-on guide and this is the HE algorithm explained step by step Link

	*  IRR fields (from ripe): 
		*  THESE ARE OBJECTS (big blocks) AND HAVE FIELDS:  as-block, as-set, aut-num, domain, filter-set, inet6num, inetnum, inet-rtr, irt, key-cert, mntner, organisation, peering-set, person, poem, poetic-form, role, route, route6, route-set, rtr-set</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:jpuppet&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>jpuppet</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:jpuppet&amp;rev=1698935895&amp;do=diff</link>
        <description>PUPPET FOR JUNOS JPUPPET:


	*  Introduction: &lt;https://forums.juniper.net/t5/Puppet-for-Junos-OS/bd-p/puppet_junos&gt;
	*  VLANS EXAMPLE: &lt;https://www.juniper.net/documentation/en_US/junos-puppet1.0/topics/example/automation-junos-puppet-manifest-file-creating.html&gt;
	*  Forum: &lt;https://forums.juniper.net/t5/Puppet-for-Junos-OS/bd-p/puppet_junos&gt;




GUIDE

	*  Official version : &lt;https://github.com/Juniper/jpuppet-download&gt;
		*  Less official version: &lt;https://forge.puppet.com/juniper/netdev_stdlib…</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:juniper&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>juniper</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:juniper&amp;rev=1698935895&amp;do=diff</link>
        <description>DHCP IN JUNOS:
Apply this whole config, included dhcp server address. Seems not to work on fpx interfaces:
set interfaces ge-0/0/7 unit 0 family inet dhcp-client client-identifier prefix host-name
set interfaces ge-0/0/7 unit 0 family inet dhcp-client lease-time 86400
set interfaces ge-0/0/7 unit 0 family inet dhcp-client retransmission-attempt 6
set interfaces ge-0/0/7 unit 0 family inet dhcp-client retransmission-interval 5
set interfaces ge-0/0/7 unit 0 family inet dhcp-client server-address …</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:kubernetes&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>kubernetes</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:kubernetes&amp;rev=1698935895&amp;do=diff</link>
        <description>KUBERNETES IS AN ORCHESTRATOR FOR CONTAINERS:


Hierarchy: Cluster &gt; Node &gt; Pod 

+ private worker nodes



	*  Container engine (podman(rhel, lxc or docker) runs the containers 
	*  k8s orchestrates them

K8s is a container orchestrator, designed for creating clusters and hosting pods, its networking model meets exactly those needs. The service mesh (or network layer) ensures that communication between different services that live in containers is reliable and secure.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:linux_network_internals&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>linux_network_internals</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:linux_network_internals&amp;rev=1698935895&amp;do=diff</link>
        <description>LINUX KERNEL NETWORKING:



Linux has Two main APIs for networking:

	*  Ethtool is for physical link management (speed, duplex, buffers etc.)
	*  Netlink is for the rest. Every network device is represented as a netdev object in the kernel.
		*  NETLINK (successor of ioctl): api (no restapi), system call. Is the way ip route talks to the kernel. socket family is a Linux kernel interface used for inter-process communication (IPC) between both the kernel and userspace processes, and between diffe…</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:linux&amp;rev=1728235035&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-10-06T17:17:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>linux</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:linux&amp;rev=1728235035&amp;do=diff</link>
        <description>BASIC IP OPERATIONS
Assign static IP and gateway (not permanent)
ip address add 10.0.0.3/24 dev eth0
ip addr add 192.168.12.1/24 dev lo # this is for a loopback address
CREATE NEW INTERFACE (permanent):

Annotate name and hw address
ip link show
Generate UUID:</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:lld_notes&amp;rev=1708152194&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-02-17T06:43:14+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>lld_notes</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:lld_notes&amp;rev=1708152194&amp;do=diff</link>
        <description># RA

	*  Introduction: like in situation, motivations (in case of solving an issue, etc..)
	*  Business context. 
		*  Use cases.
		*  To-be &#039;process&#039;
		*  as-is landscape.

	*  Integrations

----------

# Index 1

	*  Project Delivery
		*  Pre-requisites</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:machine_learning&amp;rev=1747075969&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-05-12T18:52:49+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>machine_learning</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:machine_learning&amp;rev=1747075969&amp;do=diff</link>
        <description>ML  ;  network-for-ML-workload

NOTES ABOUT MACHINE LEARNING AND ARTIFICIAL INTELLIGENCE AI



	*  Training pending to watch/read:
		*  Basic algebra / vectors: &lt;https://youtube.com/playlist?list=PL49CF3715CB9EF31D&gt; min25 v2


Notes:


Vectors and matrices are basic for machine learning. 



	*  Supervised learning: tagging. &lt;http://stanford.io/2nRlxxp&gt;
		*</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:microwave&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>microwave</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:microwave&amp;rev=1698935895&amp;do=diff</link>
        <description>*  MICROWAVE BANDS:
		*  ..
		*  Ku 8-10GHz (urban links (above 10GHz , rain is a problem)
		*  K  18-27 (~1cm)
		*  ..





	*  MODULATIONS</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:mtunotes&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>mtunotes</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:mtunotes&amp;rev=1698935895&amp;do=diff</link>
        <description>MTU NOTES AND PMTU NOTES

Check out this ipspace-article</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:netapp&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>netapp</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:netapp&amp;rev=1698935895&amp;do=diff</link>
        <description>NETAPP


version
storage show disk  &lt;--to show the disk and the filer that &#039;owns&#039; them
system controller show   # to see the FAS version
----------

CLUSTER/NODE HEALTH:

NFS
vserver export-policy rule show   # under &#039;Client Match&#039; column is the IPs os the servers mounted!!
exportfs
config dump -v config_file
system node service-processor show</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:netbox&amp;rev=1751647274&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-07-04T16:41:14+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>netbox</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:netbox&amp;rev=1751647274&amp;do=diff</link>
        <description>NETBOX


IPAM: (TODO: Document mycompany2 ipam system with API)

	*  DCIM: data center infrastructure management  tool
	*  Source of truth / Source of record: System with authoritative status for the data. Note is single source of truth for a data domain</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:netscaler&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>netscaler</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:netscaler&amp;rev=1698935895&amp;do=diff</link>
        <description>Netscaler NS12.0 (Build 57.153.nc)  in NSMPX-15000-50G

Port configuration (front and back panel): External Link. : 4x40GE QSFP+ and 8x10GE SFP+ ports.

	*  CHEAT SHEET: * &lt;https://theitgeekchronicles.files.wordpress.com/2011/09/netscaler9cheatsheet.pdf&gt; 
	*  Cluster commands:
		*  sh cluster instance 1
		*  sh cluster node 0-1

	*  MY  NOTES on ns10 :</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:openwrt&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>openwrt</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:openwrt&amp;rev=1698935895&amp;do=diff</link>
        <description>UCI commands:

unified configuration interface. configuration is split into several files located in the /etc/config/ directory. 

You can edit the configuration files with a text editor or modify them with the command line utility program uci. &lt;https://openwrt.org/docs/guide-user/network/ucicheatsheet&gt;

----------</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto_lab&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>palo_alto_lab</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto_lab&amp;rev=1698935895&amp;do=diff</link>
        <description>*  eveng requirements:
		*  PANOS: 8 vCPUs + 16G
		*  each gateway  : 2 vCPUs + 4G


	*  &lt;https://www.eve-ng.net/index.php/documentation/howtos/howto-add-palo-alto/&gt;
	*  Oracle OCI instance:
		*  24 G  + 6 oCPUs</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>palo_alto</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:palo_alto&amp;rev=1698935895&amp;do=diff</link>
        <description>USER --https-- PANORAMA(vm-ver10)  -- sgzdmzfw01(PA-5050)
                                   -- ldzdmzfw01(PA-5050)
----------

UI:



	*  Contexts 
	*  Commit from panorama. We can stage multiple changes and stage OOH,
	*  Policies (pre and post rules)</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:product_sunsetting&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>product_sunsetting</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:product_sunsetting&amp;rev=1698935895&amp;do=diff</link>
        <description>TIMELINE:



	*  EOL: is when the manufacturer announces the end of production for a certain device. Usually, within three to six years from the launch of a product
	*  Deprecated
	*  Sunset
	*  End of Grace
	*  EoSa : End of sale for the product.
	*</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:ptp&amp;rev=1750172516&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-06-17T15:01:56+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>ptp</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:ptp&amp;rev=1750172516&amp;do=diff</link>
        <description>Precision Time Protocol (PTP) – A Deep Dive for Network Engineers

Precision Time Protocol (PTP), defined in IEEE 1588, delivers sub-microsecond and even nanosecond-level time synchronization across a network. Compared to NTP, which typically provides millisecond-level accuracy, PTP is hardware-assisted and deterministic.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:pxeboot&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>pxeboot</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:pxeboot&amp;rev=1698935895&amp;do=diff</link>
        <description>Key points in this article (Junos)link


	*  Interesting folders:
		*  /var/lib/tftpboot/
		*  /var/lib/tftpboot/pxelinux.cfg/
		*  /var/www/repo/html/ks-70-em1.ks   # whatever is referenced in the centos7.menu above
		*  /etc/dhcp/dhcpd.conf</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:sase&amp;rev=1715098063&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-05-07T16:07:43+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sase</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:sase&amp;rev=1715098063&amp;do=diff</link>
        <description>SASE (Secure Access Service Edge) ~ SD-WAN with security


Is a cloud-based model combining network security functions with WAN capabilities (like SD-WAN) to support dynamic secure access to organizational resources. It is ideal for businesses with dispersed workforces needing secure and efficient connections to applications, irrespective of user or resource location.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:scapy&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>scapy</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:scapy&amp;rev=1698935895&amp;do=diff</link>
        <description>yum install pip
yum -y install python-pip
yum install epel-release
yum install python-pip
pip install --upgrade pip
pip install --pre scapy[basic]
Lots of examples Here 

Other ways of generating traffic:
# A-end
yum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
yum install pv -y
dd if=/dev/urandom bs=1000 count=1000 | pv -L 10M | nc 10.80.8.1 4444
# B-end
yum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
yum install nmap
nc -kl 4…</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-access&amp;rev=1736286964&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-01-07T21:56:04+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sd-access</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-access&amp;rev=1736286964&amp;do=diff</link>
        <description>CISCO SD-ACCESS - LAB NOTES

	*  Catalyst Center (DNA, controls ios-xe) needs a lot of resources. Like x40 cpus 150G
	*  They&#039;ve released an OVA for DNA center but very weighty (x200 micro services / containers ) 
		*  So don&#039;t use the OVA file. Take the installer that Cisco gives you to reinstall their physical appliances, which is just an ISO. Mount a VM with the requirements that I just stated. See this</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-wan&amp;rev=1737567486&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-01-22T17:38:06+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sd-wan</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:sd-wan&amp;rev=1737567486&amp;do=diff</link>
        <description>SD-WAN



TL;DR: SD-WAN maps applications to links based on performance and security requirements.

IPSec tunnels secure traffic over public internet links but are a supporting feature, not the primary focus of SD-WAN.

viptela

	*  Fortigate
	*  Palo Alto-prisma</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:service_mesh&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>service_mesh</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:service_mesh&amp;rev=1698935895&amp;do=diff</link>
        <description>Intimately related to k8s and microservices


	*  Is an infra layer to connect services (via application layer (restapi,URLs..). All in the application layer, we don&#039;t worry about l1,l2,l3. Network connectivity is abstracted and gave it for granted.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:sonic&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sonic</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:sonic&amp;rev=1698935895&amp;do=diff</link>
        <description>Sonic NOS uses Redis, which is no more than a no SQL dB that runs purely in memory


&lt;https://github.com/Azure/SONiC/wiki/Architecture&gt;</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:sso&amp;rev=1734646083&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-12-19T22:08:03+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sso</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:sso&amp;rev=1734646083&amp;do=diff</link>
        <description>SAML-SSO vs OAUTH-SSO:


What is and Identity Provider IdP?


OpenID and SAML are  associated with federated services,


OAuth:



Setup: A project is created with a Unique ID and with the URL to which users are redirected after sign-in to the OAuth provider. That ID is then stored in the SP.
In the case of Google, this uses an OAuth a user connects to the Service Provider (SP) and the SP (e.g. apache) checks if there is a session for the user.
If not then it generates a unique</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpdump&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>tcpdump</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpdump&amp;rev=1698935895&amp;do=diff</link>
        <description>TCPDUMP NOTES 

tcp_notes

To write the tcpdump output in pcap format. If we Add capital W, that means rotate:
tcpdump -ni eth0 -s0 -w /var/tmp/capture.pcap
tcpdump -ni eth0 -w /var/tmp/trace -W 48 -G 1800 -C 100 -K    # 48 files, either every 1800 seconds (=30 minutes) or every 100 MB, -K don&#039;t verify checksum
tcpdump -nni bond1 -w /var/tmp/trace -W 1 -G 20 -C 100 -K
tcpdump -e -r sflow_2022_new.pcap   # to read an existing pcap (remove -e if not interested in ethernet headers)</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpnotes&amp;rev=1728909876&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-10-14T12:44:36+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>tcpnotes</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:tcpnotes&amp;rev=1728909876&amp;do=diff</link>
        <description>TCP NOTES


This is announced during the tcp handshake:


	*  MSS is announced (not really negotiated but just announced).
	*  Window scaling is also announced. The default window size is 64kB which is far too small. That&#039;s way window scaling is ON 99% of the times.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:transit-marseille&amp;rev=1755355331&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-08-16T14:42:11+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>transit-marseille</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:transit-marseille&amp;rev=1755355331&amp;do=diff</link>
        <description>Interxion Marseille (MRS1-MRS5) Campus</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:transit&amp;rev=1755355478&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-08-16T14:44:38+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>transit</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:transit&amp;rev=1755355478&amp;do=diff</link>
        <description>NEW SWITCH DEPLOYMENT, BASIC ACCESSORIES, NEVER FORGET!!

	*  DATACENTER 
		*  (1) RACK PDUs

	*  CISCO ORDER 
		*  (2) REDUNDANT PSU 


----

	*  (3) CORRECT POWER CORDS 
		*  (4) MOUNTING RAILS! 
		*  (5) STACKING CABLES (VSS) 5.1 9300LM HAVE SPECIAL EXPENSIVE T3 TYPES AND NO STACKPOWER</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:vpn_troubleshooting&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>vpn_troubleshooting</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:vpn_troubleshooting&amp;rev=1698935895&amp;do=diff</link>
        <description>Cisco



	*  &lt;http://www.fir3net.com/Cisco-ASA/how-to-configure-a-cisco-asa-site-to-site-vpn-between-a-static-and-dynamic-ip-based-peers.html&gt;
	*  
	*  &lt;http://www.fir3net.com/Cisco-Router/configuring-a-preshared-site-to-site-vpn-between-2-cisco-routers.html&gt;
	*  
	*  &lt;http://www.fir3net.com/Cisco-ASA/cisco-asa-certificate-based-ipsec-vpn-error-certificate-validation-failed-peer-certificate-key-usage-is-invalid.html&gt;




Juniper SRX

	*  &lt;http://www.fir3net.com/Juniper-SRX-Series-Gateway/trouble…</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:vyos&amp;rev=1698935895&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-11-02T14:38:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>vyos</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:vyos&amp;rev=1698935895&amp;do=diff</link>
        <description>*  based on vyatta fork of the os community edition (2013). now fully independent
	*  &lt;https://github.com/bertvv/cheat-sheets/blob/master/docs/VyOS.md&gt;</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:wifi&amp;rev=1742036484&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-03-15T11:01:24+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wifi</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:wifi&amp;rev=1742036484&amp;do=diff</link>
        <description>* BSSID ( Basic Service Set Identifier ): MAC physical address of the AP or wireless router that is used to connect to the WiFi

	*  STA (Station): Is the end station. The wifi client.

 WIFI TROUBLESHOOTING 

	*  Optimizations &lt;https://meraki.cisco.com/blog/2011/07/12-ways-to-optimize-your-event-wi-fi-deployment/&gt;
	*  Radio settings:</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark-troubleshoot&amp;rev=1719917268&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-07-02T10:47:48+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wireshark-troubleshoot</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark-troubleshoot&amp;rev=1719917268&amp;do=diff</link>
        <description>Guidelines for Investigating Latency Issues with Wireshark

Initial Setup

	*  Load the PCAP Files: Open Wireshark and load the provided PCAP files for both application and database endpoints.
	*  Time Synchronisation: Ensure the clocks on both endpoints are synchronised. If not, account for any time differences when analysing traffic.</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark&amp;rev=1752182516&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-07-10T21:21:56+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wireshark</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:wireshark&amp;rev=1752182516&amp;do=diff</link>
        <description>WIRESHARK NOTES

tcp_notes + Cheatsheet

This is to caprutue and show in wireshark live traffic. Running on a linux based router like openwrt:
tcpdump -i eth0 -U -s0 -w - &#039;not port 22&#039; | /Applications/Eve\ Wireshark.app/Contents/MacOS/Wireshark -k -i - # To pull live traces from home openwrt router
tcpdump -nni any -U -s0 &#039;port 22 and not host 10.33.3.6&#039; -w /var/tmp/trace -W 48 -G 1800 -C 100 -K</description>
    </item>
    <item rdf:about="https://camarreal.dedyn.io/doku.php?id=network_stuff:zscaler&amp;rev=1725267633&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2024-09-02T09:00:33+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>zscaler</title>
        <link>https://camarreal.dedyn.io/doku.php?id=network_stuff:zscaler&amp;rev=1725267633&amp;do=diff</link>
        <description>Allows the same kind of segmentation we can get in an EC2 instance (security groups, ACL and so on) but in end user stations.

Zscaler has their own cloud. they offer there: authentication, firewall (inspection) and metrics

Agents

	*  Requires Zscaler agent running on the computers</description>
    </item>
</rdf:RDF>
