Serverless Containers vs Kubernetes
Kubernetes has become synonymous with container orchestration, but its complexity can be a burden. Is it still the go-to solution, or are there better options for managing your containers?
Chronological briefs tagged under the Cloud Sovereignty & Platforms strategic pillar.
Kubernetes has become synonymous with container orchestration, but its complexity can be a burden. Is it still the go-to solution, or are there better options for managing your containers?
I did 100 Days of Code Challenge in 2020/2021. Here is what I learned.
Cloud and Software: Web Application Architecture
AWS Cloud Development Kit (AWS CDK)
How to establish AWS Session
Everything you need to know about AWS's IAC, CloudFormation.
CloudFront, an AWS Content Delivery Network
Want to contribute on Unicorn Project? Awesome! Here is everything you need to know.
How to containerize the Go application, and deploy it in ECS managed container orchestrator - Fargate.
Elastic Container Service: Deploy Fargate and Load Balancer using AWS CDK and Python
Intro to Storage for GCP
How to authenticate users in Golang Web with AWS Cognito
Containerize Go application, build an optimal Docker Image using Dockerfile
How to prohramatically, from Golang, consume DynamoDB
Identity Access Management (IAM).
Text can be bold, italic, or ~~strikethrough~~. Links should be blue with no underlines (unless hovered over).
How to use Python boto3 library for Lambdas.
Intro to Pulumi for GCP
Intro to Pulumi for GCP
Business and Technical Requirements
AWS Cloud Development Kit (AWS CDK)
How to safely store your passwords and other confidential info using AWS Systems Manager Parameter Store
Bookmark this page. You will use it as a home page or Agenda for the Unicorn Workshop.
Want to learn AWS? It's well over 200 Services, no one knows them all...
AWS CDK doesn't integrate with AWS CLI Profiles and AWS SSO login. Here is a workaround.
NAT GW is great, but expensive for non-prod environments. Here is how to get down from 100$ a month to 1.10 $.
How to not allow users to register with the existing e-mail
Are you feeling you're working on too many things, without bringing true value?
Everyone is talking about Multi-Cloud being the future, but... is it?
AWS CDK is the new black. Be sure you upgrade it correctly.
Everyone is talking about Kubernetes, but is it really that big of a deal? What's going to happen to it in 5, or 10 years?
If you've been in the world of AWS long enough, you've probably heard of CloudFormation (duh!) and AWS CDK (Cloud Development Kit).
I started my professional career in 2003, in a NOC (Network Operations Center), making sure that Network and Security services of the VIP customers of the ISP (Internet Service Provider) ran smoothly.
Having spent quite some time with Linux and Kubernetes admins, I've come to realize that networking isn't one of their strong sides.
Last week I managed to pass the AWS Solution Architect professional certification exam. Here's my certification, in all its glory:
A question I've been getting a lot from the Network Engineers, should they go for CCIE. There are two points to this question:
As per yesterdays announcement, IBM is acquiring Red Hat in deal valued at $34 billion (more about this here).
Get ready to have your mind blown. One of the easiest procedures I've encountered.
This is something I've been wanting to publish for a while, and finally my Mac got formatted (no questions will be taken at this point...) and I had to re-install it all, and I just couldn't find the instructions on...
After a few months of heavy preps, I managed to pass the exam. I got the electronic certificate, and supposedly I'll get a Cloud Architect Hoodie!
I'm so happy to finally be here, at the Networking part of the Public Cloud!!! I know, there are more important parts of Cloud then Networks, but SDN is my true love, and we should give it all the attention it deserves.
Google has made their Cloud Platform (GCP) so that you can host your application any way your business requires.
We can divide IT systems into transactional (OLTP) and analytical (OLAP). In general we can assume that OLTP systems provide source data to data warehouses, whereas OLAP systems help to analyze it.
We can divide IT systems into transactional (OLTP) and analytical (OLAP). In general we can assume that OLTP systems provide source data to data warehouses, whereas OLAP systems help to analyze it.
In the last many years I've been strongly focusing on the Cloud. I have to admit though that due to various conversations with my customers, Public and Hybrid models have been getting more and more attention, and I...
Let me start by saying that I've been a big NSX fan ever since it came to the market. I was one of the first CCIEs to get to the VCIX-NV (VMware Certified Network Virtualization Expert).
It's 2018, and looking back at 2017 I must say that I'm quite happy, because having all in mind - it seems that Cisco is taking Cloud seriously.
The VM-Series firewall for VMware NSX is jointly developed by Palo Alto Networks and VMware.
Ever since Cisco bought Insieme and created Cisco ACI, and VMware bought Nicira and created NSX, I've been intensively deep-diving and blogging about both these solutions, how they compare to each other and to some...
Before we get into the details about each technology, and how you should choose which one best fits in your environment, I would strongly advise you to sit down and think about what exactly you need, what would be...
System Integrators, buckle up, DevOps is coming, and if you play your cards right - your role is about to get crazy important.
Before we start, lets once again make sure we fully understand what Bridge Domain is. The bridge domain can be compared to a giant distributed switch.
VNF (Virtualized Network Function) refers to the implementation of a network function using software that is decoupled from the underlying hardware.
This is a question I've been getting A LOT in the last few years, and even though it sounds rather simple, somehow it gets really complex to convince all the parties (Developers, Systems/Virtualization and Network...
Note: This post requires basic knowledge of Cisco ACI architecture and ACI logical elements, as well as understanding of what OpenStack is, what the OpenStack elements (Projects) do, and the principles of what OVS...
Note: This post requires basic knowledge of Cisco ACI architecture and ACI logical elements, as well as understanding of what OpenStack is, what the OpenStack elements (Projects) do, and the principles of what OVS...
Software BIOS: version 07.17 NXOS: version 6.1(2)I3(3a) BIOS compile time: 09/10/2014 NXOS image file is: bootflash:///n9000-dk9.6.1.2.I3.3a.bin NXOS compile time: 1/26/2015 11:00:00 \[01/26/2015 19:45:44\]
First of all, I need to explain why I decided to write such a post. It's quite simple to everyone who ever tried to Deploy/Configure/Understand how Cisco ACI works using the official Cisco Documentation.
In the last few years, with an exponential growth of interest in the SDDC (Software Defined Data Center), many vendors have shown an interest, and some have even managed to engineer a more-or-less decent SDN...
Cisco Nexus 9k Switches make the ACI Fabric, which is the Control and the Data plane of ACI Architecture.
At this point I will assume that you already read my previous posts about: Cisco ACI Fundamentals.
Before we get deeper into the ACI (Application Centric Infrastructure) as the Cisco's official SDN solution, we need to clarify a few terms that will be used:
This is a question I´ve been hearing a lot when we present the OpenStack to a new client, mostly from the guys who control the Networking infrastructure.
The basics of the OVS (Open Virtual Switch) and OpenStack Neutron module were described in my previous post.
Practical notes on openstack neutron and ovs (open virtual switch) translated to the network engineers language — OpenStack, VMware configuration, design, and troubleshooting guidance.
In my next post I'll be focusing on the NSX and Palo Alto integration, and all the improvements this brings to the Micro Segmentation.
To prepare for the VCIX-NV Exam, the ideal environment to practice is similar to the one we may find on the Hands-on-Labs:
TIP: Be sure to use the HUU (Host Upgrade Utility) when adding the Blade to the UCS architecture, to make sure you have the latest drivers and the Firmware.
TIP: In FCoE world there are no HBAs, but there are CNAs instead. All the Storage concepts stay the same.
OpenStack is basically an open source CLOUD stack, and it delivers the possibility to consume the platform resources using the REST API calls.
Unified Fabricis a term for all of the equipment that makes LAN and SAN possible. There are two different networks (LAN as Front-end and SAN as Back-end) that we are trying to “converge”, and 10G is an enabler of...
TIP: If you are a Networking professional, the odds are you don’t know much about Web services, and RESTful API everyone is mentioning all the time is your confusion point.
Practical notes on how vxlans work — Networking, VMware configuration, design, and troubleshooting guidance.
In July 2012 VMware acquired Nicira (Nicira was founded by Martin Casado of Stanford University and it had a product called NVP - Network Virtualization Platform), and that’s basically how VMware started the NSX...
\-Virtual Switch (vSwitch): Manages virtual machine and networking at the host level. There is NEVER a direct connection between two vSwitches, and the Spanning Tree is OFF.
Before you even consider getting into the NSX, be sure you understand deeply the vSphere, vCenter and ESXi concepts, including the vSphere Networking (vSwitch and vDS).
Disclaimer: I wanted to name the post "OpenStack for dummies", but I took a wild guess that CCIEs don't really like to be called dummies, so I "tuned" the title a little bit.
Long version: No, they are not. Nexus 1000v is used for L2 interconnection of the VMs.
SDN (Software Defined Networking) and Network Virtualization, although often in the "same basket", are two different concepts.
CCIEv5 started in June, and since my plan is to have the exam prepared for December, I'll first be getting into the New Topics of the Blueprint v5 Lab Curriculum.
Most of you who've been following my blog in the past, or even most of you who've stumbled upon it by randomly looking for "some Cisco stuff "on Google, are aware that this blog was originally designed as my personal...
DMVPN is documented under "Security and VPN", for IOS 12.4T it can be found here.
Don't forget that in Frame-Relay "broadcast" is defined ONLY DIRECTLY HUB AND A SPOKE, ON BOTH SIDES of the pvc!!!
It's enough to configure the extended ACL, and hit a question mark when you want to define a PORT, just to realize that there is an entire world of ACL configuration options that we never knew about.
Practical notes on ccie blueprint v5 announced — Cisco, Networking configuration, design, and troubleshooting guidance.
Probably most typical usage of IP SLA is to measure the and UDP Jitter and Echo, to make sure that the path is good enough to send the sensitive VoIP traffic.
Practical notes on pbr - policy based routing — Networking, Cisco configuration, design, and troubleshooting guidance.
Practical notes on ipv6 tunnels — Networking, Cisco configuration, design, and troubleshooting guidance.
From Cisco Docs: "Route dampening is a BGP feature designed to minimize the propagation of flapping routes across an internetwork.
Another way to make the BGP configuration easier by avoiding configuring the same command set on every router.
Step 1: Start with the Link-Local "Signature", which is FE80:: - For Link Local IPv6 Addresses
Loopback: ::1/128 Multicast: FF00::/8 Link Local: FE80::/10 - used for stateless auto-configuration, Neighbor discovery, Router discovery FC00::/7 Unique Local, Unicast (equivalent to the IPv4 private addresses), not...
Before the command has been applied the external (LSA5) subnet within the area 0 is seen as: sh ip ospf database external 6.0.0.0 OSPF Router with ID (1.1.1.1) (Process ID 1) Type-5 AS External Link States LS age:...
First there is an "old school" method of setting time on your IOS Device, which is fine if you're one of those :) clock set 16:50:00 15 NOVEMBER 2013 \Nov 15 16:50:00.000: %SYS-6-CLOCKUPDATE: System clock has been...
IRDP enables Routers to automatically discover the IP of their potential Default Gateway. It uses ICMP and Solicitation Messages.
GLBP is different from HSRP and GLBP, as in - it's more complex and gives more possibilities, such as LoadBalancing It's got 1 VIRTUAL IP, and VARIOUS MACs
Redundancy Protocol, Cisco Proprietary. Configuration is quite straight-forward, but there are many ways to tune it, in accordance with your needs: interface FastEthernet0/0 ip address 172.25.25.2 255.255.255.0...
VRRP Authentication is configured PER GROUP using the command "vrrp X authentication text PASSWORD", and the debug on the VRRP Pair router is as follows (before the authentication is configured on BOTH):...
Using the DHCP Pool configured on a IOS device is somewhat obsolete, but in cases of smaller companies where this solution is inevitable (or in a case such as mine, preparations for a CCIE exam) - you should know how...
Scalability for Stateful NAT feature allows Stateful Network Address Translation (SNAT) to control the Hot Standby Router Protocol (HSRP) state change until the NAT information is completely exchanged.
This approach is used when you want to configure NAT and integrate it with HSRP (enable the same NAT on all the routers that form the HSRP group).
Make sure you understand how this command works, because it´s quite a complicated principle because it works a bit "upside down".
This is a configuration that I´ve never implemented in any production environment, but I see quite a few cases where it can be usefull.
Port Address Translation (PAT) means using PORTS in order to NAT various Inside Local IPs to 1 Inside Global IP.
Do not forget to configure the "ip nat inside | outside" on the appropriate interfaces!
Inside Local - Private IP of the host in your Network Inside Global - Public IP that outside network sees your hosts as Outside Local - How the local network sees IP of the remote host Outside Global - Public IP of...
Cisco Documents: SecurityAAASecure Shell Configuration Guide http://www.cisco.com/en/US/docs/ios-xml/ios/sec\usr\ssh/configuration/12-4t/sec-cfg-secure-shell.html
Cisco Docs: Securing User Services ConfigurationAuthentication Authorization and Accounting http://www.cisco.com/en/US/docs/ios-xml/ios/sec\usr\aaa/configuration/12-4t/sec-cfg-authentifcn.html
root primary - sets the priority to: if ROOT 24576 - sets to 24576 (priority 24576 sys-id-ext 12) if ROOT =< 24576 - sets to 4096 root secondary - sets the priority to 28762
Practical notes on multiple spanning tree protocol (mst) — Networking, Cisco configuration, design, and troubleshooting guidance.
Practical notes on private vlans — Networking, Cisco configuration, design, and troubleshooting guidance.
VLAN Membership Policy Server - provides a centralized server for selecting the VLAN for a port dynamically based on the MAC address of the device connected to the port.
Cisco Docs: Cisco Docs: Secure DATA PLANESecurity Configuration Guide: Unicast Reverse Path Forwarding http://www.cisco.com/en/US/docs/ios-xml/ios/sec\data\urpf/configuration/12-4t/sec-data-urpf-12-4t-book.html
Cisco Docs: Secure DATA PLANESecurity Configuration Guide:Zone-Based Policy Firewall http://www.cisco.com/en/US/docs/ios-xml/ios/sec\data\zbf/configuration/12-4t/sec-data-zbf-12-4t-book.html
BGP is all about tuning. The non-tuned BGP is basically a RIP, but once you adjust it to your needs - no other routing protocol can come even close.
\- PREFIX LIST: You define the PREFIX list, and apply the same prefix list to the BGP neighbor
^ \- START of Line $ \- END of Line | \- Logical OR \ \- ANY DELIMETER ? \- ZERO instances of the PRECEDING character \ \- ZERO OR MODE instances of the PRECEDING character + \- ONE OR MORE instances of the PRECEDING...
Community attribute is one of those non-standard BGP attributes that you really need to know well if you wish to use it.
This is a pretty complex BGP issue because you really need to know the BGP philosophy and maybe even have some basic experience in programming.
It's configured on PER-NEIGHBOR, or as described in the Previous Post - on the PER-PEER-GROUP basis.
When you need to prefer LESS the eBGP route - you need a way to tune it, because not many routing protocols "beat" the eBGPs Administrative Distance (20).
Two first things that are considered the "BGP configuration best practice" are to disable the SYNCHRONIZATION and disable the Auto Summarization.
It's a simple concept, just a group of neighbors we want to configure with the same group of parameters.
First of all, why was the concept of Route Reflectors introduced? It´s quite simple actually.
On the Multipoint Frame-Relay network the default OSPF type is NON-BROADCAST. This means that the OSPF Neighbors will not be formed like on the standard Broadcast Network Segment.
The big CON is that even though the Route is not added to the Routing Table - it will stay in the database, and it will be further propagated to the other OSPF Neighbors.
First lets make sure we're comfortable with the LSA types, because you will not understand Stubs before you understand LSAs 100%
GRE - Generic Routing Encapsulation, is a method of tunneling data from one router to another.
Practical notes on ofpf cost tuning — Networking, Cisco configuration, design, and troubleshooting guidance.
At this level I suppose you know how to configure the Virtual Link, and what is it's purpose.
Practical notes on ospf authentication — Networking, Cisco configuration, design, and troubleshooting guidance.
First a heads up - it's a bit complicated because there are just too many details... Subjective impression!
Variance is a EIGRP feature that enables UNEQUAL load balancing. The only condition that needs to be met is: Paths need to be in the routing table and MEAT THE FEASIBILITY CONDITION!
The EIGRP route summarization is done exactly the same like RIP summarization, which makes sense because both protocols have the Distance Vector nature.
The EIGRP timers are configured (a bit non-intuitive commands from my point of view) on the interface towards the EIGRP neighbor:
RIP offset list \- used to INCREASE the Hop Count. To implement: \- define the ACL defining the relevant routes \- set the Hop Count to be increased (by 13 in this case):
RIP (IPv4 versions) is a bit obsolete, I know, and very few production environments will use it as a "routing protocol of choice", but it´s also quite simple and there is simply no excuse for a Network Engineer to...
This was originally posted by another blog, router-switch.com and I must say that agree only partially.
Practical notes on top interview questions for network engineers, part 2 — Networking, Cisco configuration, design, and troubleshooting guidance.
From what I've read the 50% of passing the CCIE is knowledge and speed, and the other 50% is knowing how to organize yourself.
I remember when I was first getting into Frame Relay I had much trouble getting the concept of DLCIs, LMIs and how it all works, because it´s so much different then other L2-L3 protocols.
It's true, I've read millions of how-to stories. Ok, maybe not millions, cause there are currently like 17k R&S CCIEs in the world, but...
Practical notes on narbik in web-iou — Cisco, Networking configuration, design, and troubleshooting guidance.
Cisco Docs: Secure DATA PLANESecurity Configuration Guide:Cisco IOS Intrusion Prevention System http://www.cisco.com/en/US/docs/ios-xml/ios/sec\data\ios\ips/configuration/12-4t/sec-data-ios-ips-12-4t-book.html
Practical notes on ospf: area range v.s. summary address — Networking, Cisco configuration, design, and troubleshooting guidance.
When we are talking about the QoS Congestion Management and Avoidance, the three most important terms are: queuing, dropping and scheduling.
Practical notes on cisco waas part ii: configuration — Cisco, Networking configuration, design, and troubleshooting guidance.
Practical notes on cisco waas part i: wan link optimization: how does waas work? — Cisco, Networking configuration, design, and troubleshooting guidance.
Quality of Service (QoS) is the ability to provide different levels of performance for individual applications and services that run over the networks.
The routes can be advertised using the "network" command, but there is also another way. You can do an entire configuration on the Interface Level!
There are quite a few ways to structure the configuration of the Load Balancing Service on a Cisco ACE device, or a Load Balancer (LB).
In this document I´ll explain how to filter the http protocol on a Cisco ACE Load Balancer, and how to redirect the filtered http traffic to another URL.
Interface Trust State Rate (pps) Burst Interval --------------- ----------- ---------- -------------- Gi3/0/1 Untrusted 5 1 <--- THE CHANGED ONE Gi3/0/2 Untrusted 15 1 <--- 15 pps IS THE DEFAULT VALUE
ACE Load Balancer SSL Certificate Part I, Generate the CSR (Certificate Signing Request)
Practical notes on ace load balancer ssl certificate part ii: install the ssl certificate — Networking, Cisco configuration, design, and troubleshooting guidance.
VLAN Trunking Protocol: most commands can be configured in PRIVILEGED, CONFIGURE or DATABASE mode
The concept is rather simple - The Switches send these probes called the BPDUs (Bridge Protocol Data Units) to discover loops in the network.
\Take SPECIAL CARE about the MTU SIZE on Swithches (might need to increase to 1504 due to the ADDED 4 BYTES IN THE TUNNEL)
CBAC and Zone Based FW are all DATA Plane policies. Another type of Security Policies is a Control Plane Policy.
If you need to define a BANNNER to display the user restrictions, have in mind that you can use the variables: $(hostname) $(line) $(domain)
PAgP (Port Aggregation Protocol) - Cisco Prop. DESIRABLE or AUTO or NONEGOTIATE \in case the link is configured as ACCESS, or the "switchport nonegotiate" command \- Protocol Value: 0x0104 \- Same multicast group MAC...
No Service Password-Recovery feature is a security enhancement to prevent anyone with console access from accessing the router configuration and clearing the password.