Tech Field Day – Symantec

Our first session at Tech Field Day 5 was a trip the Symantec campus to hear about some interesting backup solutions from both NetBackup and BackupExec.  I’ve been an on-and-off user of BackupExec for many years now, dating back to version 8 running on Netware boxes and it was still a Veritas product.  However, things have changed significantly today when it comes to backing up devices.  Thanks to Symantec, I have a much clearer picture now of what that entails.

We started out the day by hearing from one of Symantec’s NetBackup product specialists, George Winter.  He described how their product allowed them to do some amazing things, especially in the VMware arena.  You can imagine that my ears perked up at this point, as VMware is something that I’m becoming increasingly attached to from both the network and the server end.  I’ve never had the pleasure of using VMware Consolidated Backup, but from the cheers in the room when we were told that NetBackup instead uses the new VMware storage API calls, allowing a NetBackup appliance to get the information it needs to backup VMware guests without the need for the “agent” software program that has typically been needed in the past.  This is nice for me, since I don’t have to go through the trouble of installing agents on each guest as I bring them online.  I can just tell NetBackup to go out and backup the whole server, or a selected subset of guests chosen by groups.  NetBackup is even smart enough to know that if I add a guest to a folder that is currently being backed up that I probably want the new host backed up as well, so it adds the host automatically.   There was a great live demo of the ease of use in setting up the system and selecting backup options.  Demos are always great for engin…I mean Network Rock Stars because we can see things in action and generate questions based on options we can see in the live client and now some canned flash demo that glosses over the knobs and switches.

After the first session, we were graced by the presence of Enrique Salem, the CEO of Symantec.  He took some time out of his busy schedule to talk to us about the vision of Symantec and some of the emerging opportunities he sees for his company in the next year.  He appears to be a driven guy and dedicated to his principles.  So dedicated in fact that he not only gave us his e-mail address, but his cell number as well.  In front of a live video audience, no less!  Men with this kind of dedication earn big points with me because they aren’t afraid to talk to their customers and partners about their products.

A quick break paved the way for the BackupExec team to step up and start talking about the word that would quickly become the underlying theme to Tech Field Day 5 – dedupe.  For those of you network folks that may not completely understand dedupe, it is the process of removing similar data from a backup stream by use of hashing values in order to reduce the amount of data being transmitted, especially over slow WAN links.  Every time I think about it, it reminds of the basic method in which programs like WinRAR and WinZIP use to compress files.  If you really want to know more about data deduplication, you should head over to Curtis Preston’s Backup Central website.  Curtis is now my go-to person when I have a backup question, and he should be yours as well.

We learned more about how Symantec can use dedupe to reduce bandwidth consumption and tame processor utilization, which are ideas that appeal to me greatly.  BackupExec appears to be positioned more toward the SMB/small enterprise end of the market when it comes to backup software.  This is the realm that I play in more than anything else, so this product speaks to me.  There are a lot of options for backing up the VMware hosts that are found in the NetBackup product line, yet scaled down to allow SMB admins to easily use them to quickly backup and restore data.  They even have the capability of performing single file restoration to guest VMs even though the only thing backed up was the VMDK disk files.  Quite interesting if you ask me, as most of the restore requests I receive are for a single Word document, not a whole server.

Overall, I was very happy with what I heard from Symantec.  Their products appear to fully embrace the new landscape of server virtualization and the challenges that it presents to legacy backup solutions.  My own experience with Symantec in the past has varied from use to use, but this presentation went a long way to repairing some of my hard feelings about their solutions, especially in the BackupExec arena.  I’ll definitely be taking another look at them soon.

You can get more information from http://www.symantec.com or follow them on Twitter as @backupexec and @netbackup.

Tech Field Day Disclaimer

Symantec was a sponsor of Tech Field Day 5, and as such was partly responsible for my airfare and hotel accommodations.  In addition, they provided me with a very delicious hot breakfast and some “swag” that included a steel water bottle, t-shirt, notepad and pen set, and a 2GB Symantec-branded USB drive that contained copies of the presentation we were given.  At no time did they ask for or receive any kind of consideration in the writing of this review.

Tips for Presenting at Tech Field Day

Tech Field Day delegates are a rough bunch when it comes to presenters.  There is a reputation that precedes us when we walk into a briefing center.  I’m surprised they haven’t started confiscating our empty water bottles when we walk in so as to not provide us ammunition to express displeasure.  In fact, our displeasure with the same old presentation comes from the fact that it’s been seen a thousand times.  We want something that appeals to us as delegates for a technical event.  I wanted to put together some ideas for those who might be considering standing up in front of a Tech Field Day.

1. “Analyst” is a four letter word.  The almost-universal Tech Field Day revulsion to the name “Gartner” is probably the most legendary part of presenting.  If the “G” word gets mentioned, groans and hisses are lobbed toward the front of the room, and in some cases they may be followed by bottles, shoes, and chairs.  Other analyst quotes are also likely to generate some noise amongst the masses.  We get tired of hearing about this kind of fluff every day.  My ire with anaylysts is the fact they charge exorbitant amounts of money to tell you common sense things.  I can see the utility of providing head-to-head information on some products, but to be honest I don’t think Gartner has any better idea about private cloud strategy than I do.  Keep the analyst quotes out of your presentation.  Instead, focus on what your product does and why you love it so much.  Think about this scenario.  Your neighbor walks up and complements you on the new picket fence you’ve installed in your yard.  Are you going to thank them and talk about how it was back-breaking work and discuss the reason you used pressure treated pine over oak?  Or are you going to provide your neighbor with a report from the homeowners association detailing how your fence is high in “appeal” and moderate in “privacy” in the HOA “Super Triangle”?  Make your excitement about your product sound organic and we’ll believe it.  Watch the TFD 5 video from Jaspreet Singh of Druva and you’ll realize he loves his product and believes in it.  He doesn’t need to give you analyst quotes about it.

2.  Pencils have a point.  You should too.  Ever notice that most television shows have a pre-credit sequence today? A little vignette designed to grab your attention and pull you in to make you watch the ensuing 42 minutes of program and 18 minutes of commercials.  Know what they call this little segment in the industry?  The Hook.  It’s designed to draw you in and keep you focused on the show.  Likewise, if you want to keep the attention of a group of tech nerds in a room surrounded with distractions, you need a hook.  In most cases, the hook can be as simple as telling us up front what you’re striving for.  You need to get our attention.  Then you need to keep it.  When I give presentations, I try to do something in the first few minutes during my intro that makes my audience want to listen to me.  To me, the worst thing in the world is a pair of eyes wandering all over the place or focused intently on a computer screen.  At that point, I’ve lost you as a presenter.  TFD delegates like small slide decks for a the same reason they like to have the fat trimmed away on a good steak.  When all the fat is gone, the only thing left is the meat.  On your slide deck, when the fat of pointless exposition is gone, on the meat of the point or purpose is left.  Pick a point or a theme to your whole presentation and try to link back to it for each slide.  I put together a presentation one time for proper networking standards that referenced building a house.  Each slide had house imagery on it and I tried to come back to the that message before moving to the next slide. I reinforced my point in a way that hopefully resonated with my audience.  I’ve already said that should I be invited back for another Field Day, I’m going to make a sign labeled The Point and put it on the desk in front of me.  When I think a presenter is getting lost and is missing the point of the message, I’m going to make them stop and walk over to touch the sign.  That way, they are physically and mentally “Getting to the Point”.

3.  Keep the audience engaged. This kind of dovetails with number 2 above, but you need to find something to keep the attention of your audience.  Most people do this with a demo at Tech Field Day.  But two presenters went above and beyond for me.  Drobo asked a delegate to come up and pull a drive out of one of their demo units while we watched the screens to prove the unit would do what it said it would.  Could the presenter have done this?  Sure.  However, by picking on one of us, he got our attention.  Sure, we heckled Sean and had a good time with it.  We were also focused on what was happening in front of us.  The next day, the Netex “TCP as Beer” example was another way to get everyone in the room engaged.  By passing beer down the table to simulate TCP packets, we not only each had to handle the beer, but keep our buddies engaged as well.  I’m not suggesting that you stoop to the level of making us all do jumping jacks but don’t rely on only your slide deck.  Do keep in mind that many people watch the presentations being streamed over live video, so if you can find something to keep the home audience engaged as well, you’ll have gone a long way to winning the battle for the attention of Tech Field Day.

4.  We have a pulse.  Be sure to check it.  The funny thing about putting a group of technical people into a room during a presentation with communication devices is that we communicate.  We use Twitter to express our opinions about things.  By using appropriate hashtagging, we can let our audience know about things we like or dislike in real time.  During TFD 5, I experimented with an IRC channel for a different picture of things.  I got almost exactly what I expected – a Mystery Science Theater 3000 style of commentary.  For those in the chat room, we were able to express opinions without being restricted to 120-ish characters.  For the delegates in the room, we could express feelings without the need to interrupt the presenters.  Even some our more joking Twitter posts paid off eventually.  Sean Clark remarked that bacon was good.  Jeff Fry was a huge fan of chocolate-covered espresso beans.  When we got to the Thursday presentation by Xangati, we found bacon and chocolate waiting for us.  Even during the presentation, Xangati had a couple of people in the room keeping an eye on Twitter and answering our feedback in real time.  It was kind of surreal to have a second conversation going on in cyberspace even as we were talking in the room, much like the director’s commentary on a DVD.  If you as a presenter really want to get what we’re thinking, you should set up two projectors in the room.  One is for the use of your slide deck and for the delegates to see.  The other is projecting a Twitter feed or TweetDeck search for #TechFieldDay so you can see our feedback as we give it.  That way, you can see what’s working for you as a presenter, or in the worst case scenario, you can see when you’re losing us and need to get back on track.  I’m not saying that kind of presentation would be easy.  But for those with lots of slides, or those going for a more conversational approach, it can give you an idea of what we’re talking about without asking us.

5. If you’re going to skydive without a parachute, you better know how to fly.  At Net Field Day, Force 10 mezmerized the delegates by giving a presentation with just a dry erase marker.  No slides, no projector, no Powerpoint.  Just a whiteboard and a well of technical knowledge a mile deep.  If you’re going to give a presentation with just a whiteboard, you better be ready to keep your audience focused.  You also don’t have much room for error or pacing issues when you have nothing to keep you on track.  I’ve seen slide-less presentations and classes done before.  Narbik Kocharians is almost mythical with his ability to teach a 5-day CCIE prep class with zero Powerpoint.  Wanna know his secret?  He knows his stuff.  He studies everything over and over again.  He can answer questions off the top of his head.  He does his homework.  Think of a presentation just like carving a statue out of marble.  The basic outline is easy to come up with.  But the fine work of making a hand or a face can take days to complete.  The same is true of a presentation.  Throwing together 50 slides about a topic is easy (more or less).  But shaving those down to 25 takes twice as long.  And shaving that down further to 12 slides takes four times as long.  Why?  Because you have to know what you’re talking about the less you rely on visual aids.  You have to have the discipline to focus on the topic at hand and not get dragged off into tangents.  You have to be able to be a lightning rod for the attention of the audience so they don’t drift into solitaire.  I’ll admit, it would be very difficult for me to go totally slide free about something, even my recent IPv6 presentation that I knew backwards and forwards.  Because you don’t have the slides to guide the conversation and direct the focus of your audience, you run the risk of going off script quickly.  And you want your whiteboard presentation to sound more like a live episode of ER and less like Whose Line Is It Anyway.  Don’t just give a slideless presentation just to try and impress the delegates.  Impress us with your knowledge and product first, and your presentation method second.

I hope these tips will be useful not only to presenters for Tech Field Day, but for technical presenters in general.  We aren’t the usual group of marketing drones or unwashed masses.  We do our homework and we bring lots of questions to the table.  We aren’t impressed by slide transitions or rankings.  We want to see the gears and knobs and switches.  We want to see it work or see it break in real time.  Keeping all that in mind will put you ahead of the game when you step on the floor for your turn with the Tech Field Day delegates.  It should also help you avoid any flying water bottles.

Things I Learned From Tech Field Day, Part 2

Day 2

The inclusion of a self-serve machine for making an on-demand Dirty Chai is instantly successful.

Using beer as an analogy for TCP transmission is nice.  If you don’t mind near 100% packet loss.

The History of Network Protocols isn’t nearly as exciting as you might believe.

Setting up an IRC channel was easier than I thought.  Controlling it is an entirely different matter.

Some people don’t like IPv6.  Some people really like NAT.  These people should be rounded up and forced to eat lunch with me so I can prove them wrong.

Deduping the word “dedupe” from Tech Field Day 5 might have trimmed 4 hours from the total presentation time.

Standards are good.  Unless they are bad.  Then they can still be good, but only if you aren’t bad.

Jay Mellman is really tall.  And coming from me, that’s high praise.

Don’t let your kids succumb to George Lucas Syndrome.

Even 10-year-olds need to go on a date every once in a while.

Even a van full of the Tech Field Day Gold Support Team can’t make some people see reason.

Hotels don’t frown on you bringing your own beer to the pool at 9:00 p.m.

I can be entertaining and funny so long as everyone else is highly intoxicated.

Tech Field Day 5 has come to a close.  I have gained a lot from my experience here, while at the same time realizing I have much more to learn.  Seeing my online friends in reality was as fun as I imagined, and meeting new friends was great as well (yes, even Curtis Preston).  I have a healthy respect for Stephen Foskett and his crew and the wonderful job that they do putting together each Tech Field Day.  The coordination that allows us to seamlessly move from one briefing to another so easily takes a crack team to pull off.

In the coming days, I will have many more words to write about the sponsors of TFD 5.  While they did pay to fly me to California and gave me a place to catch a combat nap between sessions, I am in no way beholden to them.  I plan on giving my fair and honest opinion about the things I’ve seen.  I hope that my readers will find my condensation and appraisals to be useful and maybe even a little insightful.

In the end, I have found this experience to be quite unique.  I look forward to the day when I might be able to attend another TFD and gain even more knowledge that I can share with my friends and colleagues.  Who knows what I might learn next time?  I might even bring a belt.

Things I Learned From Tech Field Day, Part 1

Don’t be late in the morning.  Claire will find you and drag you to the van.

Symantec knows how to cook breakfast.  And they even remember the Diet Dr. Pepper.

Streaming video is frowned upon by almost every cell phone provider.

I’m not the only person that sweats during presentations.

CEOs are very forthcoming with their cell phone numbers.

Drobo means business.  And lots of frosting.

Skype should be disabled during presentations.

Storage companies that dedupe their own names are very meta.

Even a deduped backup is enough to make a Mi-Fi crawl.

Bacon and chocolate-covered coffee beans are the best. bribes. evar.

Charles Babbage built the first computer in slightly more time than it took to talk about it (and I have it on video).

The lack of a console port on the Babbage Difference Engine made me cry a little.

Lady Gaga hates bad restores.

And, the Tech Field Day crew knows how to keep my brain working overtime.

There were a lot a great presentations today with tons of good information that I’m still trying to digest.  Great companies, great stories, and a realization that I’m still very green when it comes to some of the rabbit holes of backup and virtualization.  I promise to give each presenter their due in time, with appropriate information and opinions on each.

Tomorrow should be an interesting day with some more networking-focused companies.  If you’d like to see the live stream of our event, head over to the Gestalt IT website for Tech Field Day 5 (http://gestaltit.com/field-day/tfd5/) and watch along with us.  If you have any questions you’d like answered during the presentation, don’t hesitate to shout them out on Twitter with the #TechFieldDay hashtag.  I promise I’ll do my best to keep up and ask away.

Let Me Google (Chrome) That For You

Back in December, I applied for a Google Chrome OS notebook.  I figured that if I got one I could use it for testing and checking out Google’s ideas about a web-enabled OS.  I then promptly forgot about it.  Guess what showed up on Monday?

I am now the proud possessor of a Google CR-48 Chrome OS laptop.  It’s a pretty utilitarian thing, which suits me just fine.  The finish is matte all over.  No fancy aluminium or gloss plastic.  Likewise, the connection ports are equally spartan.  An SD card slot, headphone jack, single USB port, and a power connector adorn the right side.  The VGA out occupies the left side.  No Firewire, no Ethernet, no optical drive.  This thing is designed to use wireless to connect to the network and pretty much run on it’s own without many (if any) peripherals.

The hardware is very netbook-ish.  An Atom processor with 2GB of RAM, along with a 16 GB SSD.  The latter allows the machine to wake from sleep almost instantly, much like a certain Air-y demo from the Fruit Company Not-A-Netbook press conference last year.  There’s even an integrated Verizon 3G modem for connectivity outside of Wi-Fi areas.  All in all, the looks combined with the hardware specs would most likely not even get a second glance from a buyer.  It’s what’s under the hood that is so very different.

For those of you out there that are fans of the Google Chrome web browser like I am, you’ll find the interface to be identical on the CR-48.  Here’s the catch, though.  That web browser is the ENTIRE OS.  No start menu.  No dock.  The whole OS concept revolves around the browser, and by extension, the web itself.  The user account for the system is a Google account.  It pulls your information from GMail, Google Docs, and even your Chrome favorites if you’ve set them to sync.  All of my Google information was pulled down the first time I logged into the laptop.  The 16GB drive is enough to handle a few downloads, but most of your file manipulation will occur in the “cloud”.  Google Docs for an office suite, for instance.  Any other apps you might need can be downloaded from the Google Apps Web Store.  Twitter clients, note taking apps, remote access apps, and so on.  They can all be “installed” into the browser OS for access to the things you use the most.  The more I used the system, though, the more I found myself thinking in terms of web-based content and less in terms of document storage and programs like I think of on my work laptop.   For a child or a spouse the spend 85-95% of their time doing online-related content creation and consumption (like Facebook or webmail), this would be the perfect laptop.

That’s not to say that the CR-48 is a perfect laptop.  There are some issues, even taking into account this early beta type OS/Platform.  Bluetooth doesn’t work.  Neither does connecting to a Wi-Fi network that uses certificate authentication.  The trackpad is a little tough to get used to.  I’ve heard some people compare it to the type found on the latest Macbook.  It takes some getting used to, and the gesture support isn’t quite intuitive for me just yet.  The other bug I ran into was with the Verizon 3G modem.  There’s a quick link for activating the Verizon account that Google has graciously provided.  However, I hit a geographical snag.  It appears that the Verizon towers in my area code (405) used to belong to Alltel Communications before they were purchased by Verizon last year.  So, when the activation signal was sent, it wouldn’t register correctly.  I was only able to activate it correctly when I went out of state.  To Google’s credit, they Chrome Netbook Ninja (support person) I talked to diagnosed the problem inside of 5 minutes after the Verizon pre-paid tech fought with it for 30 minutes.  Kudos to Google for having competent support people.  And even more kudos for allowing them to call themselves ninjas.

I plan on using the Chrome netbook to take notes during Tech Field Day this week to give it a good run and see how well it performs.  I may even let my kids start using it to see how well it holds up to the gentle caresses of a 5 year old and a 2 year old.  Stay tuned for further reports.

When Is A Trunk Not A Trunk?

When I was an impressionable youth back in my college years, I decided it might be a good idea to take Japanese as a foreign language.  I spent three semesters learning vocabulary and kanji and eventually managed to forget pretty much everything I learned.  One lesson that did stick with me, however, occurred in my first semester.  Our professor was explaining to us gaijins (Westerners) that we needed to be very careful about how we pronounced certain words.  Since words in Japanese are limited by a very small number of vowel sounds, there are many cases were words use the same sounds but have totally different meanings.  Such is the case with shujin. When pronounced as I have written it, it is the word for “husband”.  However, if you hold the “u” sound a little too long, as in shuujin, you instead have referred to that person as a “prisoner”.  As my professor explained, “Well, perhaps those two words really aren’t so different.”  In this case, a small difference in pronunciation can have a profound difference in meaning.

Another place where I see an issue similar to this is when someone starts asking questions about terminology differences between HP Networking (nee Procurve) and Cisco terminology on switches.  Often, these questions boil down to two major terminology differences based around one word: trunk.  It’s pronounced the same in both vendors world, but just like in Japanese, it can have a very different meaning depending on how it’s used.  Allow me to illustrate:

In Ciscoland, when I use the term trunk, I am referring to a port that carries multiple VLANs.  Trunk ports carry information about each of the VLANs on the switch in either Cisco’s ISL proprietary format or in the 802.1q vendor-neutral format.  Newer switches, like the 2960, have no support for ISL and will only form trunks using 802.1q, so I’ll use 802.1q for my examples.  Just keep in mind that if the switch doesn’t support ISL, you don’t need to configure the trunk encapsulation.  When these ports are designated as “trunks”, the frames are tagged with a special 802.1q header that indicates which VLAN they are a part of.  The only VLAN that is not tagged with an 802.1q header (by default) is the native VLAN.  On Cisco equipment, the default native VLAN for an 802.1q trunk is VLAN 1.  The behavior of Cisco IOS is to transmit information about all VLANs present on the switch over the trunk.  You can narrow this behavior through use of the switchport trunk allowed vlan command.  A sample Cisco trunk config might look like this:

Switch(config)#interface gig 0/1
Switch(config-int)#switchport trunk encapsulation dot1q
Switch(config-int)#switchport trunk allowed vlan 1,10,99
Switch(config-int)#switchport mode trunk

This configuration is sufficient to setup an 802.1q trunk and only allow VLANs 1, 10, and 99 to pass traffic on it.

In HPvania, the terminology used for a port that carries multiple VLANs is a tagged port.  On an HP switch, the individual ports are rarely configured directly.  Instead, the VLAN itself is configured and the ports are added to the VLAN configuration.  In order to setup an access port, it is configured as an untagged member of the VLAN it needs to belong to.  Since HP does not support ISL trunking, the terminology is straight from 802.1q.  The untagged ports do not carry 802.1q headers that specify they VLAN information.  This would be known as an “access port” on a Cisco switch.  In order to create a port that carries information for multiple VLANs, we must “tag” those VLANs on that port.   This modifies the packets sent on that port to carry VLAN tags for the VLANs indicated.  A sample configuration for an HP switch connected to the above Cisco switch might look like this:

Switch(config)#vlan 1
Switch(config-vlan)#untagged 1
Switch(config-vlan)#untagged 48
Switch(config-vlan)#vlan 10
Switch(config-vlan)#tagged 48
Switch(config-vlan)#vlan 99
Switch(config-vlan)#tagged 48

Notice that the configuration is done under the VLAN and references the port number on the switch.  Access ports are untagged members of a particular VLAN, and the native VLAN of an 802.1q trunk is also an untagged member.  Even though 802.1q has a native VLAN that doesn’t carry a tag, on an HP switch this VLAN needs to be explicitly set.  The other VLANs must be tagged to the uplink port in order for their information to be carried between switches.  This lends itself to being an additive solution, where VLANs are only present on a trunk if they have been specifically configured.  There is no need to prune VLANs or exclude them from the trunk if they aren’t needed.  They just aren’t configured in the first place.

Which method is better?  This tends to devolve into an OSPF vs. IS-IS type of argument.  If you are more comfortable with one you tend to prefer it.  I tend to use the Cisco terminology in my day-to-day operations, and I have a slight preference for not needing to remember to add each individual VLAN to an uplink port.  However, from a security perspective, I do like the HP idea of only adding VLANs that are needed.  In fact, this same concept of VLAN creation is present in the Force10 OS.  If you’d like to see more of it in action, you should check out Stretch’s excellent intro to Force10 over on Packetlife.net.

So, if HP refers to an uplink carrying multiple VLANs are a tagged port, then does HP have a “trunk”?  In fact they do.  In HPvania, a trunk is a logical construct that aggregates multiple ports into one logical link.  For those of you that might be out there scratching your heads about this one, this means that when you “trunk” a group of ports on an HP switch, you are creating one LACP link from up to four individual ports.  This kind of configuration should look like this:

Switch(config)#trunk 19-24
Switch(config)#trk1
Switch(config-trk)#lacp
Switch(config-trk)#vlan 1
Swtich(config-vlan)#untagged trk1
Swtich(config-vlan)#vlan 10
Swtich(config-vlan)#tagged trk1
Swtich(config-vlan)#vlan 99
Swtich(config-vlan)#tagged trk1

Those of you that are fans of irony will appreciate that the above config sets up this LACP port aggregation to pass multiple VLANs to another switch.  In other words, we are configuring a Cisco “trunk” on top of an HP “trunk”.

In Ciscoland, the idea of aggregating multiple ports into a grouping is referred to by many names, usually “port channeling” or “Etherchanneling”.  The latter is the term that usually describes the Cisco-proprietary Port Aggregation Protocol (PAgP) links that are created by default.  However, this term has more or less become genericized and is used to refer to any group of aggregated ports on a Cisco switch.  Cisco does support LACP on aggregated ports, so let’s see how we’d configure this switch to use LACP and send tagged VLAN traffic back to the HP switch:

Switch(config)#interface range gi 0/19-24
Switch(config-int-range)#switchport trunk encapsulation dot1q
Switch(config-int-range)#switchport trunk allowed vlan 1,10,99
Switch(config-int-range)#switchport mode trunk
Switch(config-int-range)#channel-group 1 mode active
Switch(config-int-range)#channel-protocol lacp

This will set the aggregated ports to use LACP and pass VLANs across the link with 802.1q tags.  Note that you must set the channel-group command to “active” in order to use LACP on the link.  If you set it to “auto” or “desirable”, it will use PagP by default.  If you set the mode to “on”, it will not use LACP or PAgP at all.

There you have it.  The terminology is different, but as long as you know what you are trying to accomplish, you can usually figure out what you need to configure in order to make it all work correctly.  Hopefully you’ll never find yourself married to any particular configuration, much less become a prisoner of it.  In the end, just remember that a trunk is still just a trunk.  The meaning is entirely up to you.

Tune In and Switch Off

As I sit here right now, the country of Egypt is a black hole on the Internet.  All 3,500 prefixes originated by Egypt’s four major ISPs have been withdrawn from the global BGP table.  There is no route into or out of the country, save the one ISP utilized by the Egyptian Stock Market, most likely in an effort to keep the country’s economy from collapsing.  This follows on the heels of other government interference in cybercommunications in Tunisia this past month and Iran last year.  Egypt, however, is the first country to completely darken the Internet in an effort to keep services such as Twitter and Facebook from coordinating resistance and allowing information to be disseminated to the world at large.  I learned a very long time ago that arguing about politics never leads anywhere.  What I would like to comment on, however, is the trend toward censoring information by disrupting network communication.

Egypt yanked all Internet access for its citizens in an effort to control information.  Tunisia has been accused of affecting Internet traffic for its citizens as well, blocking certain routes and causing outages on the Web.  Iran limited access to social media and even attempted to severely rate limit Internet traffic during the election protests last year.  This trend shows that governments are starting to realize the power that the Internet provides to disaffected groups of people.  No longer to “subversives” need to meet in underground basements or abandoned warehouses.  Those places have been replaced by chat rooms and e-mail.  Relying on one or two trustworthy individuals to get the word out by smuggling rolls of film to the mass media has been replaced with instant pictures being uploaded from a cell phone to Twitter or Flickr.  The speed with which protests can become revolutions has become frighteningly accelerated.  So too is the speed with which the affected government can slam the door shut on the ability for these revolutionaries to use the very media which they rely on to spread the word.  Egypt was able to successfully cut off access within a few hours of the first rumors of such a thing being contemplated.

For those of you that think that something like that could never happen here (here being the US), let me direct your attention to the Protecting Cyberspace as a National Asset Act.  This hotly debated bill would give the government more ability to combat large-scale cyber warfare and allow them to protect assets deemed vital to the national interest.  The biggest concern comes from a provision inserted that would give the president the ability to enact “emergency measures” to prevent a wide-reaching cyber attack.  This includes the power to shut down major networks for a period of up to 120 days.  After that time, Congress must either approve an extension, or the networks must be reactivated.  I won’t delve into some of the wilder conspiracy theories I’ve seen surrounding this bill, but the idea that our networks could be shut down without our consent to protect us is troubling.  According to my research, there is no provision that defines the situation that could cause a national shutdown.  The president, acting through the National Center for Cybersecurity and Communications (NCCC) Director, is supposed to inform the affected networks to enact their emergency measures and ensure the emergency actions represent the least disruptive means feasible to operations.  In other words, the NCCC director just has to tell you he shut you down and you should try to make things work as well as you can.

Using this as a possible scenario, assume some kind of external driver causes the president and the NCCC director to shut down a large portion of the Internet traffic.  It doesn’t have to be a revolution or something so sinister.  It could be a Stuxnet-type attack on critical power infrastructure.  Or maybe even a coordinated cyber attack like something out of a Tom Clancy novel.  In an attempt to deter the attack or mitigate the damage, let’s say the unprecedented step of withdrawing a large number of BGP prefixes is taken, similarly to what Egypt has done.  What kind of global chaos might this cause?  How many transit ASes exist in the US that would pass traffic around the world.  I’ve seen stories of how the World Trade Center attacks in 2001 caused a global Internet slowdown due to the amount of traffic that was passed through the networks located there.  That was two buildings.  Imagine withdrawing even half the traffic that flows through the US and networks located here.  What impact would that have?  The possibilities would be mind-boggling.  Even a carefully coordinated network shutdown would have far reaching impact that no one could foresee.  Chaos is funny like that.

The Internet, or cyberspace or whatever your term for it, is now something of a curiosity.  It exists on its own, independent of the laws of nations or man.  Those who seek to control information flow or restrict access find themselves quickly thwarted by the fact that packets and frames do not respect political boundaries.  For every attempt to shutdown The Pirate Bay, a simple move to different location allowed them to stay active.  Even when pressure was applied to the people behind the site, it was quickly seen that their creation had taken on a life of its own and would persist no matter what.  What of the Wikileaks saga, where the attempt to behead the organization by targeting its leader has only fanned its flames and most likely ensured its survival no matter what may happen to Julian Assange.  Those of us who live our lives in this electronic realm see differences in the way culture is developing.  There are lawless places in the Internet where mob rule is the law of the cyberland.  Information is never truly forgotten, merely pigeonholed away until it is needed again.  Attempts to impose political will upon the citizens of the Internet are usually met with force, protest, and in some cases, retribution.  I keep wondering when organizations are going to figure out that attempting to erase information is tantamount to daring the Internet to publicize it.  In the same way, attempting to shut down access the Internet and social media at large is a sure way to force people to circumvent these restrictions.  As we watched Egypt vanish from the cyber landscape last night, many of my friends remarked that it would only be a matter of time before someone challenged the blockade and won.  Someone could hack the edge routers and reestablish the BGP peering with the rest of the world and the floodgates would be opened again.  Whether or not that happens in the next few days remains to be seen.

As the world becomes more reliant on the Internet to provide information to everyone, we as cyber citizens must also remain vigilant to keep the information flowing freely.  The Internet by design lends itself to surviving major disruptions without totally crashing.  It is our responsibility to show the world that information wants to be learned and shared and no amount of meddling will change that.

I Am A Network Ninja

I am a network ninja.

I appear meek and uninteresting.  My stealth and guile are my weapons.  I have succeeded in my task if you never knew I fixed the network.  My khakis and polo shirt allow me to blend into the crowd of salespeople and marketing drones, yet hide my knowledge of BGP and MPLS.  I care not for the ritual troubleshooting combat of TAC engineers.  I use whatever methods I can to achieve victory over that which might harm my network.

My tools appear deceptive at first.  A laptop. A console cable. Simple business cards.  Yet, when in my hands, they become the weapons of legend.  Repeating Youtube videos to distract the masses while I work my network ninja magic.  A console cable to garrote those who question my skill with OSPF.  Business cards to use as shurikens to force back the account managers who dare to be technical and disrupt my troubleshooting chi.

My SNMP spies report every movement of the enemy to me.  I know what the battlefield will look like before the battle is even commenced.  With a flash of light from my LED iPhone camera flash, I mysteriously appear at your side, asking you why you are downloading a torrent on my network.  Before you can speak your lies, my honed reflexes have rate-limited your switchport.  I give you the choice of no choice.  Continue downloading at your peril, for your fate is in your own hands.  Before you can put up a fight explaining why you need a copy of Harry Potter before it’s released in theaters, I disappear with a puff of smoke, off to sow havoc in the server room.

I train my students without training.  I give them difficult configuration tasks and force them to gather information about switches by hand.  I make them learn from experience and recognize danger before they can perceive it.  I create spanning tree loops and redistribution quagmires so my students will never fear the hell of a network gone wrong.  When they realize that my difficult tasks and exacting manner have in fact taught them the way of network ninjitsu,  I send them into the world, knowing they will carry on my legacy and teach other network ninjas as they have been taught.

My deception is my strength.  When the C-level shoguns ask why the network is slow, I appear to give them many answers, yet I reveal none.  The questions for me become questions.  I ask him for his opinion of what might be wrong.  I feign ignorance in his presence, knowing how to use his ego and strength as a weapon of my own.  As he explains how the network needs his experience, I wait for the opening. When confusion reigns and all appears cloudy, I strike.  I turn off the shogun’s Internet radio and appear demure, claiming all should be well thanks to his enlightenment.  As I retreat to my network dojo, the shogun feels content, knowing he fixed the problems and showed his network serf a thing or two about the way things work.  My greatest work is fixing the network without fixing the network.

When others speak of the mysterious forces that weave magic and make the network bend in ways they never dreamed of, I shall laugh and tell them they must be dreaming.  There is no such thing as a network ninja.

Yet, I AM a network ninja…

These /8s Are Now Diamonds

The end times are upon us.  According to many reliable sources, the allocation of IPv4 addresses is quickly reaching it’s conclusion.  Of the final seven /8s available to be allocated by IANA, APNIC is about to exercise its option on two of them.  When that happens, the final 5 will be allocated as planned to each of the 5 Regional Internet Registrars (RIRs) and completely deplete the source pool of allocatable IPv4 addresses.  Now, before Chicken Little starts screaming about what this means, let’s take a step back and examine things.

I liken the total allocation addresses from IANA to the RIRs to a resource exhaustion.  For the sake of discussion, lets pretend the IPv4 addresses are diamonds.  The announcement of of total allocation would be like De Beers announcing that all of the diamonds in the earth’s crust have been mined and there are no more available.  That doesn’t necessarily mean that all the engagement rings and tennis bracelets for sale will disappear tomorrow.  What it means is the primary source for this resource is now depleted.  Just like we can’t manufacture any more IPv4 addresses, in this example we can’t mine any more diamonds.  So what happens next?

Usually, when a resource starts becoming scarce, the cost to acquire that resource will be driven up.  In this particular case, people like Greg Ferro have already suggested that there will be a “run” on addresses.  Again, this is a behavior that is typically seen when the announcement is made that a resource is becoming hard to come by.  I think that the RIRs will start putting policies in place to prevent ISPs and other parties from requesting more IPv4 addresses than they currently need.  That will prevent the pool that the RIRs currently possess from becoming depleted faster than necessary.  It will also hopefully stave off the resale of these addresses on the black market, which is a distant possibility but possible nonetheless.  Just like in our fictional diamond example, the price of the diamonds at the jewelry store will go up, and most stores will implement policies restricting the sale of large numbers of stones to single parties, so as to prevent hoarding and help keep prices high.  This will also stave off the onset of a diamond secondary market, where speculators will sell stockpiles of stones for exorbitant prices.

So, now that IANA has run out of addresses, what’s next?  Well, the next countdown becomes the date the first RIR runs out of it’s allocation.  Right now, that’s projected to be APNIC sometime in October 2011.  APNIC has been burning through its addressing at blinding speed, and so they find themselves at the head of the IPv4 exhaustion line.  Once APNIC runs out of addresses, the only thing they can offer their customers going forward is IPv6 address space.  For some customers, this will be rather unsavory.  These types of customers will feel that IPv6 hasn’t penetrated deep enough into the market.  They’ll pay any price for those precious v4 prefixes.  So, I imagine that APNIC and the other RIRs will hold a small portion of IPv4 address blocks in reserve for those customers that are willing to pay big bucks for them.  For the customers without the pocketbook or that don’t care about the address space they receive, they’ll get IPv6 and likely won’t think twice about it.  Just like in our diamond example, when the first jewelry supply runs out of stones purchased from De Beers the price will start going up.  Perhaps they’ll offer lab-created diamonds of similar quality.  But there will be customers that feel the lab-created stones are inferior and those same customers will pay a significant amount of money to get the “real” stones.  In these cases, the smart jewelry supplier will hold back some of the best gems in order to get a much better price for them.

Once the first RIR runs out of address, things will accelerate from there.  Depending on the level of IPv6 preparedness in the market, you may start seeing customers hosting equipment in locations where RIRs still have address space to assign.  I would sincerely hope that by the end of 2011 that most everyone has either begun their IPv6 prep in earnest or completed it with flying colors.  Otherwise, I predict there will be a migration of data centers to locations served by AfriNIC, which is the RIR with the largest block of unallocated /8s.  The final exhaustion of IPv4 addresses isn’t predicted to occur until July 2012.  That gives customers and plenty of time to decide how to implement IPv6 rather than moving data centers around to mop up what little IPv4 address space remains.  In our fictional example, as the jewelery suppliers start running out of diamonds to give to their customers, their customers will begin shopping around to find suppliers that still have stock, even if they have to start importing stock from supplies located overseas.

Once the last RIR runs out of addresses to give to its customers, then it will be a matter of time before the last of the IPv4 addresses are allocated to the final end users by the ISPs and other middle men.  Customers that deal directly with ARIN and RIPE and the other RIRs will be out of luck, instead needing to move to IPv6 to continue growing their Internet presence.  Hopefully by the time this occurs in late 2012, IPv6 will be firmly entrenched and the drive to allocate the final IPv4 address space will be greatly lessened.  With end users concentrating on their shiny new IPv6 address blocks, the last of the IPv4 addresses can be handed out to those truly in need.  After that, the Internet can go forward operating on a dual-stack of IPv4 and IPv6 until the last of the IPv4-only hosts go dark, leaving us totally on IPv6.  I doubt that day will ever truly come, but it’s a possibility that’s out there.  And in our fictional diamond example, people will still show off their fancy jewelry, but the world at large will start to turn to the next precious stone like rubies or sapphires.  While diamonds will never truly be gone, the demand for that which can no longer be obtained will be lessened greatly, only pursued by those with the resources to expend to obtain something so expensive.

The final and total allocation of IPv4 isn’t something that’s going to happen overnight.  It will be a death by degrees.  Just like boiling a frog one degree at a time, there was a time we might not have known what was going on until it was too late.  Thankfully, enough people have been getting the word out to cause everyone to start making their plans early and get ready for what is coming.  This was no more apparent to me as when I contacted a local technology group putting on a conference to request a presentation slot to speak about IPv4 exhaustion and IPv6 planning.  The person on the other end of the phone was a rather technical person, yet I had to spend some time explaining just what IPv6 was and why getting the word out was so important.  So, to those of you that have influence on communication and/or blogging and tweeting avenues, keep talking about what’s going on with IPv4 depletion as we approach the true end of the address space.  That way, we don’t find ourselves scrambling for diamonds at the last minute or wondering if we need to upgrade to Diamondv6.

For Want of a Nail

I have been weighed.  And measured.  And my configuring skills have been found…lacking.  Welcome, everyone, to the post-lab wrap up post.  Jan 20th looked like a good day for me.  I found all the faults in the troubleshooting section.  The config section looked very beatable to me.  I double checked all the configs with the hour and a half of extra time I had available.  I found some dumb mistakes that were immediately corrected.  And when I left the lab, I had a very good feeling about this one.  Alas, 58 minutes later, the score report I received indicated that I wasn’t as good as I had expected.

Without gory, rule-breaking details, I really thought I did better.  I had reachability in my lab without violating any of the constraints.  My paper was filled with two check marks next to all by one task that I was working on when time was called.  I re-read each question and physically put the point of my pencil on each word on the screen to make sure I didn’t read over anything and miss a subtle nuance that could sink me.  In the end, I think those nuances are what might have sunk me.  It’s not enough to have full reachability if you miss a little phrase that tells you to avoid a certain method or use a specific technique.  While I feel that I had accounted for all of those possibilities, the score report doesn’t think so.  And since the cold reality of the score report is more official than my high hopes, it looks like this trip to sunny San Jose was a bust as well.

After posting my results on Twitter, along with the condolences there were a lot of questions about whether or not I should as for a lab re-grade.  For those not familiar, the lab is partially graded by a script.  In cases where the script returns some strange results a proctor will look over your lab and double check certain tricky tasks.  Historically, I’ve gotten my scores after 3-5 hours.  The fact that I got this report while sitting at In-and-Out burger confused me.  Perhaps the first pass of the grading script didn’t have any issues with my configs.  One or two people even suggested that as a good sign that I might have even passed from the script alone.  So, as I stared at the percentages in front of me, I contemplated something I had never tried before.  I wanted them to take another look at my exam.  I wanted another proctor to take the configurations saved from my equipment and load them up onto new routers and regrade my exam by hand.  This process is not without it’s downsides, though.  First, it costs $250 for them to even do it.  If you get re-graded to a passing score, there is no refund.  Secondly, there is as much possibility of you losing points as there is passing.  This is because the human eyes of the proctor may catch something incorrect that the script missed.  So, you may have only been 3 points from passing, only to now find that you are 8 points away due to some other mistakes.  However, if you are very close to the mark, as in ~2-3%, there is no reason not to take the chance on the regrade.  After all, it’s still cheaper than a new $1400 lab attempt, right?  Third, the regrade attempt takes up to three weeks.  So if you’re hoping for a fast turnaround before deciding to take another lab attempt, you’re going to have a cool your jets for the better part of a month.  On the bright side, Cisco is usually very understanding and will refund the $1400 if you’ve booked another lab attempt and your re-read is honored and changed to a passing score.

Turns out, Cisco won’t even look at tests that are not “statistically close to the historical passing rate.” English?  If you aren’t within about 5% of the passing score, you don’t even have the option to have it regraded.  And, at least in Cisco’s eyes, I was wide of the mark this time.  I’ve filed a case with support to at least be granted the option for the regrade.  We’ll see what happens.  In the meantime, I’m getting back on the horse.  I’ve already had conversations with my employer about when and if there will be another attempt on their dime.  I’m not packing away any lab equipment for the time being.  I’m getting right back into the thick of things to keep it all fresh.  In fact, my wife and I went to the final closing party for a local pub that we’ve been going to since college.  As I sat there surrounded by all the merrymakers and noise of a bar full of people, all I could think of was how much I wanted to get back home and start labbing up some multicast questions.  It seems that the lab has transformed me and sharpened my focus into laser-like precision.  I think about how I’m going to configure tasks and how I’m going to move efficiently from one task to the next.  I pace myself based on the amount of work I can get done in 6 hours with a 40-minute lunch break.  I review flash cards and GNS3 configs during my free time.

No matter what, I’m going to go back and try this again.  I feel like the top of Everest is in sight and I just need one last push to reach the summit.  I’ve come too far to fail now.  More studying, more refining of my task config skills, more “stick time” for this airplane of router and switch configuration.  For want of a nail, this lab was lost.  But the next time around, the only nail will be the lab being nailed by me.