Тёмный
Doctor Networks
Doctor Networks
Doctor Networks
Подписаться
Configuring the Cisco ACI Policy Model
53:26
5 месяцев назад
Nat Overload with Multiple ISP's
19:16
Год назад
ASA Active/Standby Failover - Detailed Lab
1:11:59
2 года назад
Nat Exemption - Demystified !
27:00
2 года назад
FortiGate LED & Ports
14:18
2 года назад
AAA and RADIUS vs TACACS+
7:19
3 года назад
Комментарии
@asifalikhan3796
@asifalikhan3796 19 часов назад
Can you create some content on DDNS ssl vpn and ipsec
@srh_btk
@srh_btk 19 дней назад
Amazing explanation. Thank you so much!
@doctor.networks
@doctor.networks 19 дней назад
Welcome 😊
@kareemRamadan-xe9xf
@kareemRamadan-xe9xf 24 дня назад
Great and to the point
@doctor.networks
@doctor.networks 23 дня назад
Thanks bro, Good to know you liked it
@teanam6496
@teanam6496 28 дней назад
If I want (full) 2-way communication between 2 (or more) EPGs, does that mean I need two contracts between each EPG where one is the provider *and* consumer (one in each direction)? Like, if one isn't *only* providing a service to another, but both are providing (and consuming) to each other.
@doctor.networks
@doctor.networks 27 дней назад
Yes exactly, you would need two set of contracts. The same way I configured for one, you configure for the other side as well. Thanks for the comment 👍
@teanam6496
@teanam6496 28 дней назад
So, at the end with the "re-using" All the config guides I've seen so far, made a Switch Profile for 1 switch and an Interface Profile for 1 Port. Now, if I have a Fabric with 100+ Leafs and thousands of Servers, I'd be doing profiles for months and whenever there's a new server and/or a new leaf, I'd clicking through tabs and profiles for days. Does that mean it's possible to create 1 "master" profile to use for all Leafs and another "master" profile for all ports on a leaf? Or maybe a 'few' general ones depending on what you want to connect and you're good to go? If every (bare metal) server and/or port needs its own profile, it would be pure madness in a bigger fabric. I mean, normally, ports are all configured the same/similarly (for standard servers) and only the VLANs change (or now the EPG deployment on a port).
@doctor.networks
@doctor.networks 27 дней назад
Normally you will not have to go thru all this again & again, you have a quick way to create profiles in ACI as well. Moreover the problem mainly comes between the VPC & NON VPC ports(Normal Access/Trunk). If you dedicate everything as NON VPC & your server team is OK with it then a master profile can work. But I know that somewhere you're going to need VPC's then it will be a little hasle removing those interfaces from profiles & creating a VPC profile for them.
@teanam6496
@teanam6496 26 дней назад
@@doctor.networks Thank you for the reply! The networking team in our company and I are still pretty "old-school". We're using legacy NX-OS without anything fancy like VXLAN, so all of this looks extremely unintuitive to me. Right now, when the server team tells us they need 4 channeled ports, we SSH on the the VPC pairs in the rack, copy our VPC template over the ports, allow the VLANs they need and that's pretty much it. And when the server gets removed later on, we simply default the port. Having to do a switch profile for every leaf and then a new interface profile for every used port seems like a *lot* of extra work rather than simplifying it. After having done all the profiles and policies and whatnot, you then also still need to go in the EPGs menu and link all the needed EPGs to the ports. (Which can be a whole lot, like we have server that access 20-30 VLANs, so instead of "sw trunk allowed vlan 100-130", it's going through 30 individual EPGs menus now...?) And when the server gets decommissioned, you have to find and delete profiles (among the hundreds or thousands others) and remove the static bindings in the EPGs. You have every switch and port accessible from the same system, which is super cool, but if having to go through a dozens of menus takes more time than SSH-ing to the switches and configuring the ports manually, something about the whole ACI things seems odd to me. -- We've ordered a lab for next month and I'll be trying your videos to build it myself and experiment a little before having a session with our cisco rep over what the best approach for our usecase and current hiearachy is.
@senditall152
@senditall152 29 дней назад
thank you!
@SureshGarapati-td8gd
@SureshGarapati-td8gd Месяц назад
It was indeed insightful video. A quick question, is it safe to enable xforwarder, I was just wondering if xforwarder is exposing the Citrix backend infrastructure to somebody who is logging in from Internet? Is my understanding correct? Is it not a security issue? Look forward to seeing your response.
@doctor.networks
@doctor.networks Месяц назад
Thanks mate. Appreciate your comment, X forwarding only pulls out the client source IP (which could be a Internet Public IP) & puts that in the HTTP header, that packet will be sent to the backend servers. There is nothing as such that will be exposed to the client actually so i think it's pretty safe.
@DD-mr2tk
@DD-mr2tk Месяц назад
Thanks alot. I wasn't getting an ip address and i now know why.
@TheTylerMayfield
@TheTylerMayfield Месяц назад
Great guide. Thank you! Thanks for all the other videos you do as well. I'm learning a lot!
@doctor.networks
@doctor.networks Месяц назад
You are welcome brother 👍
@PradeepKumar-oj8qh
@PradeepKumar-oj8qh Месяц назад
I am trying to configure a text sms message with this radius option but its only working with the Duo push approval option. Is there anything specific to be done to get a sms text ?
@doctor.networks
@doctor.networks Месяц назад
Bro it's been a long time since I have looked into Duo 😀 but you would certainly need to have a SMS API setting in the duo cloud. check if it's supported
@legendz78
@legendz78 Месяц назад
Very cool I didnt know you could clone policies in reverse.
@ofsep
@ofsep 2 месяца назад
Hello, you forgot to mention that DNAT is necessary if the 10.1.1.0/24 subnet from BLIZZ wants to communicate with the 10.1.1.0/24 subnet of CENTICS.
@SandeepKumar-bv6wl
@SandeepKumar-bv6wl 2 месяца назад
Single trunk link is enough to get All vlans from switch pls.tell.reason for three links to switch
@doctor.networks
@doctor.networks 2 месяца назад
Hi Sandeep. It is a single physical Interface. There are 3 logical interfaces with vlan tags,same as you would do via a trunk.
@muralin3460
@muralin3460 2 месяца назад
Beautiful bro❤
@doctor.networks
@doctor.networks 2 месяца назад
Thank you so much 😀
@askmethod
@askmethod 3 месяца назад
thanks man. but i have question regarding upgrading from forticloud. is the way possible if there is two firewalls in HA
@doctor.networks
@doctor.networks 3 месяца назад
Welcome bro. Ye 100% will work with HA firewalls as well.
@askmethod
@askmethod 3 месяца назад
@@doctor.networks thanks bro
@askmethod
@askmethod 3 месяца назад
nice work bro. keep it up
@ericsadforcanada8160
@ericsadforcanada8160 3 месяца назад
Great video! Thanks.
@doctor.networks
@doctor.networks 3 месяца назад
I'm glad it helped
@shivamchoudhary5810
@shivamchoudhary5810 3 месяца назад
Very informative session , Can you provide any if they are an overlapping network how destination work there
@PakistanAlg
@PakistanAlg 3 месяца назад
salam,ahmad bhai,have u recorded videos for ISE 3.0
@doctor.networks
@doctor.networks 3 месяца назад
Waslam, No brother didn't had the time but in future InshAllah will do.
@alirezakarimi2174
@alirezakarimi2174 3 месяца назад
It was an amazing video and helped me a lot. please create a video for a simple application like a web server and it's database and the EPGs for each one of them and show the communication end to end
@doctor.networks
@doctor.networks 3 месяца назад
Thanks man glad it helped. I'll have to see how I can do a lab which involves DB & WEB
@mohammedredatarmidi1831
@mohammedredatarmidi1831 4 месяца назад
Bro is saving my life rn ! :)
@doctor.networks
@doctor.networks 4 месяца назад
hhhhh what do you mean by "rn"?
@Regulator596
@Regulator596 4 месяца назад
I don't know if you still read comments here. But I've been having trouble with the differences between TACACS+ and RADIUS. This video completely cleared up every question I had about it plus a few more I didn't even know I had. Thank you so much for the video! Great content!
@doctor.networks
@doctor.networks 4 месяца назад
I still read comments here brother 😀 You are very welcome. When I was making this video I didn't knew it would help so much people. I'm happy that it helped you.
@damarrizkyramadhan654
@damarrizkyramadhan654 4 месяца назад
Really good video
@doctor.networks
@doctor.networks 4 месяца назад
Glad you liked it Brother
@zosmanovic9763
@zosmanovic9763 4 месяца назад
this should be on the homepage for everyone
@doctor.networks
@doctor.networks 4 месяца назад
I'll put it there 😀
@swgvoyage3878
@swgvoyage3878 4 месяца назад
Why need this much of policies for intervlan, i think just create a zone and add the vlan's to that zone, that's bettee to simplifying 😊
@doctor.networks
@doctor.networks 4 месяца назад
Yeah but but you may need different policies for a set of vlans, you can actually create multiple zones referencing multiple vlans. The video is to give a concept that's why kept it simple. Obviously zones will be a better approach in the long term.
@YAHD2024
@YAHD2024 5 месяцев назад
thank you, keep going on
@doctor.networks
@doctor.networks 5 месяцев назад
Welcome, Yes sure will do 🙂
@sidrish143
@sidrish143 5 месяцев назад
Superb explanation, thanks for sharing
@doctor.networks
@doctor.networks 5 месяцев назад
You are welcome brother
@sanjedgaming8124
@sanjedgaming8124 5 месяцев назад
cli login problem, root and eve is not working
@doctor.networks
@doctor.networks 5 месяцев назад
I think recently they changed it to username eve & password eve aswell
@sanjedgaming8124
@sanjedgaming8124 5 месяцев назад
@@doctor.networks after reinstalling 5-6 times its working now.
@netconfig999
@netconfig999 5 месяцев назад
ACI is new modern network solution, please help do for more.
@doctor.networks
@doctor.networks 5 месяцев назад
Yes bro working on 2 new videos on ACI
@netconfig999
@netconfig999 5 месяцев назад
thanks for sharing this VDO, this is really helpful Thanks❤❤
@doctor.networks
@doctor.networks 5 месяцев назад
You are welcome @netconfig999. Nice channel name by the way 😀
@doctor.networks
@doctor.networks 5 месяцев назад
ACI EPG to DOMAIN ISSUE UPDATE ============================ The EPG was not binded to the Physical domain & yet the communication began to work because of a bug as mentioned in this Cisco Forum. In later releases it may be fixed. community.cisco.com/t5/application-centric-infrastructure/epg-without-a-physical-domain-association/td-p/4462831
@thefireburningchannel
@thefireburningchannel 5 месяцев назад
Super ! 😀
@doctor.networks
@doctor.networks 5 месяцев назад
Thank you! Cheers!
@rblpolicy2435
@rblpolicy2435 5 месяцев назад
Hi bro, Would you recommend having a professional Eve community license. The purchase one as i see the free have bugs
@doctor.networks
@doctor.networks 5 месяцев назад
Recently I haven't been using the Pro addition, but yes if you can buy it i would definitely recommend. It has other owsam features too
@smartinezs
@smartinezs 6 месяцев назад
Great, diameter missing😢
@doctor.networks
@doctor.networks 5 месяцев назад
Bro I don't think there is much use of it nowadays actually. You need to learn it for deployment or just for knowledge?
@smartinezs
@smartinezs 5 месяцев назад
@@doctor.networks yes bro, At least in Latin America we still deploy 4G, Volte. Thanks for your answer 💪🏾
@mohdyaseen5198
@mohdyaseen5198 6 месяцев назад
my question is why do you match interface gi0/1? why just match the ACL
@capricornnnn
@capricornnnn 6 месяцев назад
Thanks. I am still on 29:30 and I saw your securecrt colors. How you have two color settings like blue for Home-RTR and white for commands?
@doctor.networks
@doctor.networks 6 месяцев назад
Hi, It's actually via regular expressions & all devices get that color. Here is how you do it. Navigate to Session Options >> Appearance >> Highlight Keywords & then edit. Put in the following in the word section one by one & set the color as needed: [^#]+# [^>]+>
@capricornnnn
@capricornnnn 6 месяцев назад
@@doctor.networks Thanks. I think I tried this before but doesnt work for me. I have some key highlight already set but will try again. What is your font and size? I
@capricornnnn
@capricornnnn 6 месяцев назад
@@doctor.networks Now it works :)
@garygatten1154
@garygatten1154 6 месяцев назад
Good stuff, thanks. Same situation, only ISPs (Gi1 and Gi2 in your diagram) are each in a different VRF - Internet1 and Internet2. I've tried the config you demonstrated but it doesn't work, presumably because of the VRFs. (Gi0 / Inside is GRT). When I use a basic NAT statement as in a single ISP (no route-map), it works, but of course I must change the nat manually or use EEM triggered by IP SLA tracked object. So, what am I missing? Will this even work with VRF's? I have seen similar NAT use cases where it simply won't work when overloading an interface, must be a different IP - is this one of those cases? TIA!
@doctor.networks
@doctor.networks 6 месяцев назад
Hi Gary, interesting scenario. Now rather then asking you a bunch of questions, I would request if you could send the running config of your router to info@doctornetworks.net. I will be happy to assist (No charges).
@garygatten1154
@garygatten1154 6 месяцев назад
@@doctor.networks Stay tuned - coming your way.
@sajjadakram786
@sajjadakram786 6 месяцев назад
Video is ok, but accent guru key tarah karney key chakar sir dard kar diya
@doctor.networks
@doctor.networks 6 месяцев назад
hhhhh I'm sorry for that brother. I'm not so perfect so accept my sincere apology.
@sajjadakram786
@sajjadakram786 6 месяцев назад
@@doctor.networks no dear I was on humour side, awesome video keep it up
@doctor.networks
@doctor.networks 6 месяцев назад
😀 thank you brother
@撥號衝浪
@撥號衝浪 6 месяцев назад
Thx❤❤
@撥號衝浪
@撥號衝浪 6 месяцев назад
Thank you so much.i like watching your videos
@doctor.networks
@doctor.networks 6 месяцев назад
You are most welcome, glad that you liked them
@galacticaldread7234
@galacticaldread7234 6 месяцев назад
i am preparing for my Security+ exam, thank you so much for the clear video on the difference between RADIUS and TACACS+ :')
@doctor.networks
@doctor.networks 6 месяцев назад
Welcome, Glad that it helped you 😊
@nightlover6665
@nightlover6665 3 месяца назад
sup dude ........what about ur exam .......did u cleared it yet or still preparing ........need help regarding it & suggestions i am also preparing for it
@balaramaraju5772
@balaramaraju5772 6 месяцев назад
Thanks for the detailed video.
@doctor.networks
@doctor.networks 6 месяцев назад
You are welcome
@mcorleone77
@mcorleone77 6 месяцев назад
thanks for posting it. Is eve-ng running on your PC or on an EXSi ?
@doctor.networks
@doctor.networks 6 месяцев назад
Specifically for this video it's a physical ForiGate box. Normally for my videos I use Eve-ng on a Esxi server to offload resources
@sivprog
@sivprog 6 месяцев назад
Thank you so much for such a great video I really appreciate your effort
@doctor.networks
@doctor.networks 6 месяцев назад
Welcome brother. Hope so one day I'll start remaking such material
@MohamedAzhari-ic6cm
@MohamedAzhari-ic6cm 7 месяцев назад
Thanks well
@09alexandr
@09alexandr 7 месяцев назад
Hello, is there a way to have NATed traffic being balanced?
@doctor.networks
@doctor.networks 7 месяцев назад
On cisco NO. You can do that on Fortigate by utilising the SDWan feature
@garygatten1154
@garygatten1154 6 месяцев назад
PBR/PFR. Not truly balanced, that's impossible with two different ISPs, but you can direct traffic x on int1 and traffic y to int2. In route- map you set next hop based on your traffic matching.
@roberthuang1308
@roberthuang1308 7 месяцев назад
This is the best video I've ever seen. To be honest, your presentation is much better than the Cisco Authorized instructor's. Keep it up!
@doctor.networks
@doctor.networks 7 месяцев назад
Glad to hear that & thank you for the appreciation 😊. I sure hope someday I can get back on this teaching track 🙂
@roberthuang1308
@roberthuang1308 7 месяцев назад
Great video. Thank you!
@qennaq
@qennaq 7 месяцев назад
Hi. How can it be configured when it is an HTTPS service?
@doctor.networks
@doctor.networks 7 месяцев назад
I believe you would need ssl offloading on citrix as you can't actually open a HTTPS packet without deception