Michael McNamara https://blog.michaelfmcnamara.com technology, networking, virtualization and IP telephony Sat, 13 Aug 2022 13:35:48 +0000 en-US hourly 1 https://wordpress.org/?v=6.0.3 HPE/Aruba ClearPass 802.1X auth fails with Android 11 https://blog.michaelfmcnamara.com/2022/08/hpe-aruba-clearpass-802-1x-auth-fails-with-android-11/ https://blog.michaelfmcnamara.com/2022/08/hpe-aruba-clearpass-802-1x-auth-fails-with-android-11/#respond Sat, 13 Aug 2022 13:34:04 +0000 https://blog.michaelfmcnamara.com/?p=7429 This is another one of those “it must be the network” posts. It was an interesting problem to chase so I thought it worth the effort to post it here for anyone that hasn’t seen this problem before.

The trouble ticket came in as a brand new “out of the box” Motorola G Pure was failing to authenticate via RADIUS 802.1X to our wireless network using valid credentials. However, if you managed to get it the device connected via guest wireless and enrolled in Soti then it was able to authenticate via RADIUS 802.1X without an issue.

A quick review of the HPE/Aruba ClearPass instance showed an error code 215, a TLS session error. Which interestingly enough was reporting as an expired certificate, although this certificate error was on the client side which was odd giving that historically Android devices don’t validate or care about the RADIUS certificate.

The text of the error read as follows;

EAP-PEAP: fatal alert by client - certificate_expired
TLS Handshake failed in SSL_read with error:14094415:SSL routines:ssl3_read_bytes:sslv3 alert certificate expired
eap-tls: Error in establishing TLS session

It turns out I’ve seen this issue before with Android 10 but in that case the device was failing to open a captive portal page when connecting to a guest WiFi network because the SSL certificate securing the captive portal was “invalid” to the mobile. Why you ask? The device had the wrong date/time. And that’s exactly what’s happening here… although Android 11 is taking the issue a little further because it views the RADIUS certificate as invalid it’s not allowing the RADIUS 802.1X authentication to proceed.

The issue is the Motorola G Pure will boot up with a default date and time that appears to be related to date of that specific software build. In this case the default date was June 30, 2022 – fairly new I’d agree. If there is a SIM in the device it will pull the correct date/time from the cellular network, but if these are just being used on WiFi then they won’t automatically update their date/time until they are connected to a wireless network. Unfortunately we had just recently renewed our RADIUS certificate (publicly signed) on July 14, 2022. While the certificate hadn’t expired it wasn’t yet valid because the mobile had a date & time that was before the issue date of the certificate.

This wasn’t an issue in Android 10 because Android 10 didn’t validate the date of the RADIUS certificate, but Android 11 will attempt to validate the RADIUS certificate being used in the RADIUS 802.1X exchange. It should also be mentioned that you’ll need to make sure you have the “Domain” box filled in with the domain of the certificate used by the RADIUS server – that’s new with Android 11 as well.

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/08/hpe-aruba-clearpass-802-1x-auth-fails-with-android-11/feed/ 0
Palo Alto PAN-OS 8.0 Upgrade Failure https://blog.michaelfmcnamara.com/2022/08/palo-alto-pan-os-8-0-upgrade-failure/ Mon, 01 Aug 2022 16:00:00 +0000 https://blog.michaelfmcnamara.com/?p=7412

It turns out that in the year 2022 upgrading from PAN-OS 8.0.x requires a TAC case and an older content update file that’s not readily available on Palo Alto’s Support website.. Hopefully this will save someone else the down the road.

I recently needed to press an older PA-220 that had been in laying around in a lab into a production environment due to the supply chain debacle that we’re all currently living in. I reached out to my reseller and had the firewall fully licensed and was able to apply those licenses to the hardware. In preparation of the deployment I tried to bring the PA-220 up to PAN-OS 9.1.14. And was unable to upgrade past 8.0.20 even with the device being fully licensed.

When I tried to upgrade from 8.0.20 to 8.1.23 I would get an error during the software install, “Failed to install 8.1.23 with the following errors. SW version is 8.1.23 Error: Upgrading from 8.0.20 to 8.1.23 requires a content version of 769 of greater and found 655-3816. Failed to install version 8.1.23 type panos

Even though the device was fully licensed there were no Dynamic Updates available to download or install. I even tried to manually download them from the Palo Alto support website and install them and that was met with a different error when trying to commit the change.

I opened a case with Palo Alto Support and eventually they provided me content update 8424-6791 which I was able to manually install and apply, after which I was successfully able to upgrade to 8.1.23. I was then able to download and apply the latest and greatest greatest content updates from the webUI and eventually upgrade the firewall to 9.1.14.

Cheers!

]]>
Retirement Planning – Personal Capital https://blog.michaelfmcnamara.com/2022/07/retirement-planning-personal-capital/ https://blog.michaelfmcnamara.com/2022/07/retirement-planning-personal-capital/#comments Sun, 03 Jul 2022 14:28:15 +0000 https://blog.michaelfmcnamara.com/?p=7371

I’m at that point in my life where I feel I need to start keeping a closer eye on my retirement investments and make sure that my wife and I will be ready when we decide to retire. I’m not intent on making a lot of changes or moving any investments around but I feel I need to be an educated investor and make sure that my retirement goals are on track. I recognize that writing this post in June of 2022 it is not the best time to want to start tracking your retirement investments, with the US stock market being down ~ 15.0% already this year and the possibility of a recession looming here in the United States.

Here are my personal numbers if anyone is interested, I probably need to re-balance as I’m over committed to US stocks. I’m in it for the long haul, so while the numbers above might be disappointing there isn’t a whole lot I’ll be doing about it right now, it’s better to just stay the course and continue to invest while the market in general is down IMHO.

I’ve been saving toward my retirement since my first job at Manhattan College, and yes, I still have my TIAA-CREF (403b) retirement account that I enrolled in back in 1995. The challenge is trying to manage all the various accounts that either myself or my wife have. That’s where I’ve found Personal Capital to be an incredibly useful (and free) tool. There are a ton of great reviews on Personal Capital out on the net so I’m not going to go into any depth here other than to just to say it’s an incredibly useful tool IMHO. If you don’t feel comfortable managing your own retirement accounts or need help I would strongly suggest you seek professional assistance from a CPA.

Cheers!

Personal Capital Referral Link: https://pcap.rocks/m32436

]]>
https://blog.michaelfmcnamara.com/2022/07/retirement-planning-personal-capital/feed/ 2
Elo Touch – 5Ghz Wireless (Channel Support?) https://blog.michaelfmcnamara.com/2022/05/elo-touch-5ghz-wireless-channel-support/ Thu, 12 May 2022 02:51:35 +0000 https://blog.michaelfmcnamara.com/?p=7321

We had an issue a few months back with a number of Elo Touch all-in-one systems. These devices had been installed and working for almost three years and then literally overnight they started having issues connecting to our wireless infrastructure – all at the same time. Oddly enough the issue was only impacting the Elo devices, we had numerous other devices including Lenovo laptops, macOS laptops, Apple iPhones, Zebra TC20/TC21 Handhelds (Android), Zoom Conference TVs (Apple Mac Mini) all working without issues or problems. The initial troubleshooting didn’t turn up anything simple, there were no locked out accounts or other RADIUS 802.1X authentication issues. We just didn’t see the devices in question even trying to associate to any of the APs so we were initially stumped. While we worked to get an engineer onsite we performed the obligatory rolling reboot of the Cisco WLC 5520s (primary and standby) along with the Cisco AP 4800s (they had an uptime of just over 645 days) just to check that box for lack of any other direction at that time.

What was the issue?

In this specific facility we only use the 5Ghz band for our production networks, 2.4Ghz is setup for the guest network. In the end we determined (still waiting on confirmation) that the devices in question don’t appear to support all the 802.11a 5Ghz wireless channels. We found the following reference on several Internet websites.

Elo devices cannot operate on 5G wireless networks utilizing 5.250 to 5.350 GHz OR 5.470 to 5.725 GHz.

I didn’t know the frequencies off the top of my head so I had to look them up… thanks to the folks at Wireless LAN Professionals for the chart below. That potentially removes channels 52-64 and channels 100-144 from being used, only leaving channels 36-48 and I would have to guess the device likely doesn’t support the UNII-3 band and channels 149-165 so that’s super restrictive.

Credit: Wireless LAN Professionals

In a large fulfillment center it’s usually feast or famine, too much RF signal or not enough RF signal and it takes a lot of work to find that happy medium.

What happened?

It would appear that Dynamic Channel Assignment (DCA) on the Cisco WLC 5520 changed an AP from channel 48 to channel 136 the morning the issue started, found the log entry, and that was the only AP in the physical area around the clients that was using any of the channels between 36 and 48. In short the Elo devices were blind to the wireless access points around them because they were on channels that the devices didn’t support. This was later confirmed by performing some remote wireless packet traces from some one of the Cisco 4800 APs in sniffer mode. We captured numerous packet traces across numerous 5Ghz channels but we were unable to see any of the Elo devices communicating in any channel other than 36-48. We were looking for active probe requests in the wireless packet traces which is not fool proof as the client can still listen passively. We manually set the AP back to channel 48 and the devices immediately started working. We’ve temporarily disabled TPC and DCA while we try to validate what channels the device supports.

The Elo vendor reps we contacted claimed that the devices support all the “standard” 5Ghz channels but from the evidence we collected that doesn’t appear to be the case. I hope to be able to get my hands on one of these devices in the coming weeks to try and validate my suspicions.

I still need to confirm but this is really the only explanation that fits the available evidence.

Anyone else ever have such an odd problem?

Cheers!

Update: July 2022

I was able to get my hands on ELO and was able to verify that it could in fact communicate in the UNII-2a bands, so I’m not sure what to make of this issue with that new technical tidbit.

]]>
Let’s Encrypt SSL Wildcard Certificate https://blog.michaelfmcnamara.com/2022/04/lets-encrypt-ssl-wildcard-certificate/ https://blog.michaelfmcnamara.com/2022/04/lets-encrypt-ssl-wildcard-certificate/#comments Fri, 22 Apr 2022 17:42:47 +0000 https://blog.michaelfmcnamara.com/?p=7363

In July of 2020 I wrote about the relative cheap cost of a standard SSL certificate from RapidSSLonline in an article titled, “Your certificate expires in 1 day!!!“. While standard SSL certificates were available for ~ $14.99/year at the time the cost of a wildcard SSL certificate is considerably more expensive than a standard SSL certificate. In December 2021 the wildcard SSL certificate that I use on this site was set to expire so I made the decision to try Let’s Encrypt.

I’m happy to report that it’s been an extremely painless adventure with the only caveat being that I had to manually renew the SSL certificate every 90 days. After some research I found that really isn’t an issue thanks to Martijn Veldpaus. Martin has written some scripts that help bring together certbot and the API calls to GoDaddy, I’m using GoDaddy as my domain registrar and as my DNS provider, to perform the DNS verification that’s required by Let’s Encrypt to prove that you own the domain.

I’m saving myself about $149/year by using Let’s Encrypt instead of a traditional Certificate Authority.

If you are a GoDaddy customer looking for an extremely easy way to setup the automated renewal of your wildcard SSL certificates with Let’s Encrypt I would strongly suggest you check out Martin’s github repository Certbot-Godaddy.

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/04/lets-encrypt-ssl-wildcard-certificate/feed/ 2
Ansible Default Forks = 5 https://blog.michaelfmcnamara.com/2022/04/ansible-default-forks-5/ Fri, 15 Apr 2022 14:10:15 +0000 https://blog.michaelfmcnamara.com/?p=7368

We recently starting using Ansible to help perform software upgrades on the large number of Juniper EX-4300 and EX-2300 switches in our environment. Like the vast majority of organizations our downtime windows are extremely short and unfortunately the element of human error is usually greater than the standard mean between 12AM and 6AM. Thankfully Ansible solves most of these issues and is very reliable. Out of the box, Ansible has a configuration default of 5 forks and as such it will only upgrade 5 switches at a time. If you are going to be working with any sizable number of devices you’ll need to update the configuration value in the ansible.cfg file.

[defaults]
inventory = inventory
host_key_checking = False
log_path = ~/ansible/ansible.log
forks = 30
timeout = 60

You’ll need to make sure that whatever server or virtual machine is running your Ansible instance can support the number of forks you configure.

Cheers!

]]>
Raspberry Pi 4 Bullseye WiFi – Country Code https://blog.michaelfmcnamara.com/2022/03/raspberry-pi-4-bullseye-wifi-country-code/ https://blog.michaelfmcnamara.com/2022/03/raspberry-pi-4-bullseye-wifi-country-code/#comments Tue, 15 Mar 2022 01:52:27 +0000 https://blog.michaelfmcnamara.com/?p=7354
Raspberry Pi 4

I recently had the opportunity to setup a Raspberry Pi 4 in a headless configuration and ran into an interesting issue around the WiFi configuration with Bullseye.

When logging in via SSH the following text was visible at the bottom of the motd;

Wi-Fi is currently blocked by rfkill.
Use raspi-config to set the country before use.

It turns out that Bullseye will disable the WiFi driver in the kernel unless the country code is set.

This is really only an issue if you are using the Raspberry Pi in a headless configuration without the desktop GUI.

What’s the workaround?

I edited the wpa_supplicant.conf file in /etc/wpa_supplicant as follows, adding the US country code;

ctrl_interface=DIR=/var/run/wpa_supplicant GROUP=netdev
update_config=1
country=US

Then you need to copy the file /etc/wpa_supplicant/wpa_supplicant.conf to /boot and reboot.

sudo cp /etc/wpa_supplicant/wpa_supplicant.conf /boot
sudo init 6

When the Raspberry Pi booted back up… the wireless drive was loaded and I was able to connect to the intended wireless network.

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/03/raspberry-pi-4-bullseye-wifi-country-code/feed/ 1
APC UPS NMC stops responding via HTTPS https://blog.michaelfmcnamara.com/2022/02/apc-ups-nmc-stops-responding-via-https/ https://blog.michaelfmcnamara.com/2022/02/apc-ups-nmc-stops-responding-via-https/#comments Sun, 20 Feb 2022 15:22:36 +0000 https://blog.michaelfmcnamara.com/?p=7345

Who doesn’t love a good mystery, I’m no exception. A few weeks back we had an interesting issue pop-up. It was midnight on a Sunday night and PagerDuty started firing off an alert that a UPS in one of our distribution centers had just stopped responding via HTTPS. The UPS was still online responding to both ICMP and SNMP traffic, so the alert was acknowledged and the alarm was paused until it could be reviewed the next day.

The UPS itself was fairly new having been installed just under a year ago. It was an Schneider Electric/APC 3000RT Smart-UPS with an AP9631 network management card. Interestingly enough we just had an issue with a brand new APC 8000SRT Smart-UPS with an integrated AP9537SUM network management card that had essentially started doing the same exact thing a few days earlier. Only that installation was only a few days old when it stopped working. Again ICMP and SNMP worked fine… as did HTTP (if you enabled it).

What was that all about?

After a few hours of troubleshooting and digging I discovered that the self-signed SSL certificate installed on the NMC had expired. Any attempt to connect to the NMC via HTTPS after that point would result in the socket getting immediately closed upon connecting by the NMC. Removing the self-signed SSL certificate and rebooting the NMC caused the self-signed SSL certificate to be regenerated and the problem was resolved. You can remove the SSL certificate by enabling the HTTP server via either SSH or TELNET (will depend on the age of your card as to which one is enabled by default), login in via HTTP go to Configuration -> Network -> Web -> SSL Certificate and select Remove and Apply. You just need to reboot the NMC and you should be able to connect via HTTPS.

1 Year?

The self-signed SSL certificate is only good for one year, after which you’ll need to regenerate it again. The latest version of the firmware/software (NMC2 – v7.0.4) from APC sets the expiration date for all self-signed SSL certificates out to 2035 – not sure if the web browsers will start to complain about that.

Ripple20?

If you haven’t already patched your APC network management cards it might be a good time to take care of that task as well. We had to patch all of our APC and Eaton network management cards that are used throughout our network.

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/02/apc-ups-nmc-stops-responding-via-https/feed/ 4
PanOS 9.1.12 breaks GlobalProtect VPN https://blog.michaelfmcnamara.com/2022/02/panos-9-1-12-breaks-globalprotect-vpn/ Thu, 03 Feb 2022 22:00:00 +0000 https://blog.michaelfmcnamara.com/?p=7337

When possible it’s always a good idea to test any software upgrades, because you just never know what your going to get. That was the case recently when I upgraded our test PA-220 from 9.1.7 to 9.1.12-h3 and seemingly breaks all GlobalProtect VPN functionality. The portal doesn’t respond on TCP/443 at all, so it looks like the firewall itself is dropping the traffic.

The issue turned out to be Strict IP Address Check which was just “resolved” or enabled in 9.1.12.

AN-175934 Fixed an issue where packed-based zone protectio settings (such as
Strict IP Address Check) were not applied to return traffic.

When I disabled Strict IP Address Check on the zp_untrusted zone protection profile GlobalProtect started working again.

What is Strict IP Address Check?
Check that both of the following conditions are true:

  • The source IP address is not the subnet broadcast IP address of the ingress interface.
  • The source IP address is routable over the exact ingress interface.

If either condition is not true, discard the packet.

Looks like a bug to me.

Cheers!

]]>
AOL (Verizon) breaks Microsoft Outlook https://blog.michaelfmcnamara.com/2022/01/aol-verizon-breaks-microsoft-outlook/ https://blog.michaelfmcnamara.com/2022/01/aol-verizon-breaks-microsoft-outlook/#comments Sun, 30 Jan 2022 13:20:10 +0000 https://blog.michaelfmcnamara.com/?p=7327 What is going on with AOL and Microsoft Outlook?

I’m a Verizon FiOS customer and was migrated to AOL back in 2017. Within the past 30 days I’ve heard and seen a number of issues with people connecting to their AOL inbox from traditional email clients such as Microsoft Outlook, Thunderbird or even the native email clients on iPhone and Android.

The loving wife had this same issue and I wrongly assumed end user error. You would think I’ve learned by now to not jump to conclusions. It seems she’s not the only person with issues as there are numerous posts on numerous message boards all within the past 30 days with dozens if not hundreds of people reporting the same issue.

The general consensus is that:

Verizon/AOL accounts require an AOL “App Password” to be used as the password for the account configured in Outlook or in any email client (iPhone, Android, Thunderbird, Outlook, etc)

What’s more interesting is that AOL apparently is not blasting out this new feature to all users at the same time because my Microsoft Outlook 365 client continues to work fine while my wife and many others are having to generate an “app password” to get their email flowing again. Some of the posts suggest that if you’ve activated “2-step verification” on your AOL account that you’ll need to generate and use an “app password” to access your email from a legacy email client.

I did find the following article from AOL:
https://help.aol.com/articles/allow-apps-that-use-less-secure-sign-in

The article linked above suggests that AOL is actively blocking clients that it believes are less than secure. Is that because the client is passing the username/password in the clear (unencrypted) in a legacy POP3 connection and not using IMAPS or POP3S?

If your traditional email client stops working it might be more than just a password issue. You might want to try either upgrading your email client or setting up an AOL app password and see if that resolves your issue.

  1. Sign in and go to the AOL Account security page. You can do this by signing on to AOL from a computer.
  2. Click Generate app password or Manage app passwords.
  3. Select your app from the drop down menu and click Generate.
  4. Follow the instructions below the password.Be sure to enter the password into your app without any spaces.Click Done.
  5. Use this app password and your email address to sign in to your email app.

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/01/aol-verizon-breaks-microsoft-outlook/feed/ 2
It’s never a DNS issue right? https://blog.michaelfmcnamara.com/2022/01/its-never-a-dns-issue-right/ https://blog.michaelfmcnamara.com/2022/01/its-never-a-dns-issue-right/#comments Sun, 23 Jan 2022 22:02:02 +0000 https://blog.michaelfmcnamara.com/?p=7317 I stumbled into an interesting issue today that gave me a smile when I determined it was a DNS issue.

I was doing some consulting work around WireGuard for a client, and noticed a number of odd issues and just general wonky behavior with everything being slow. This specific client uses Ubuntu Linux while I’m more of a RedHat/CentOS/Rocky guy so I thought it was an issue with the DNS caching that Ubuntu utilizes in systemd-resolve. A few quick tests using a Windows client proved that the issues weren’t limited to just the Ubuntu server, it was impacting every device. DNS queries were taking between 5 to 6 seconds and some were timing out entirely.

The client had mentioned some oddities and issues and I thought there might be a duplicate IP on the network – pretty standard affair in some networks. This wasn’t a duplicate IP issue so I went straight to the DNS servers themselves – Microsoft Windows Server 2019. I found that the root forwarders for each server were setup to use some very old Verizon DNS servers – and wouldn’t you know that some of them were no longer responding. I removed all the Verizon entries and added the two standard Google DNS servers – 8.8.8.8, 8.8.4.4. After applying that and restarting each DNS server the problem was gone and everything was running smoothly again.

What do you use for your DNS forwarders? Or do you rely on the root hints file maintained by Internic?

Cheers!

]]>
https://blog.michaelfmcnamara.com/2022/01/its-never-a-dns-issue-right/feed/ 4
HPE/Aruba Instant Access Points – mixing models on the same virtual controller https://blog.michaelfmcnamara.com/2021/11/hpe-aruba-instant-access-points-mixing-models-on-the-same-virtual-controller/ Tue, 02 Nov 2021 23:32:49 +0000 https://blog.michaelfmcnamara.com/?p=7300

In the past if you wanted to mix an Aruba IAP-100 series and an Aruba IAP-200 series in the same network and virtual controller you had to make sure that both APs were running the same software/firmware revision prior to trying to pair them together. If you didn’t you’d end up with one AP becoming the virtual controller and the other one would just continually reboot trying to join the virtual controller because it was unable to upgrade itself as the software image between classes/models is different.

I recently discovered that this is no longer an issue… APs that are not managed by Airwave (AMP) will reach out to the Internet (Aruba Central? or Aruba Activate?) and upgrade themselves without issue to whatever version the virtual controller is running. And APs that are managed by Airwave will also upgrade themselves so long as the upgrade image is downloaded and installed into AMP for the APs to retrieve.

This is a really nice feature, and helps simplify break-fix issues when older APs die and need to be replaced but you don’t have any IAP-135s available. Now you can use IAP-215s or any 200 series APs and whether or not you have Airwave your AP will be upgraded to the correct software to work properly.

You can mix and match APs based on software release…. IAP-135s and IAP-215s running 6.4.x software work well together, as will IAP-215s, IAP-315s and even IAP-515s running 8.6.x software.

Cheers!

Update: Friday November 11, 2021

The is a known issue with older software releases that will break the ability to upgrade from the cloud. The AP in question needs to be on a “newer” release in order to establish an SSL session to the cloud. Additional details can be found in Aruba Support Advisory ARUBA-SA-20191219-PLVL08 titled Aruba Instant Certificate Expiry Issue.

]]>
PA TAP 529 Investment Plan for College https://blog.michaelfmcnamara.com/2021/11/pa-tap-529-investment-plan-for-college/ Tue, 02 Nov 2021 02:25:08 +0000 https://blog.michaelfmcnamara.com/?p=6948

While this topic is very different from the usual content I write, I feel it will have value for those young adults with children that are sure to be following a similar track in life; “How do I pay for my child’s college education?” I’m not financially savvy by any means, but here’s your call to action if you haven’t yet done anything to start saving.

I’m a Gen Xer and I would consider myself as middle income. I’m not rich or poor by any means, but I don’t want for much either. I buy a car/SUV every 10 years or so, mow my own lawn, pay my monthly mortgage and yearly taxes. I hold a full-time job with a large retailer, I run my own consulting business and I try to volunteer regularly with a number of organizations. With three daughters I wasn’t exactly sure how I was going to save for their college education. After a lot of reading and research I decided that a Pennsylvania TAP 529 plan was the best tool and provided the most benefits for me and my family being a Pennsylvania resident. The biggest benefit is that all my TAP 529 contributions are tax deductible at the state level. In 2020 I believe the max contribution per beneficiary was $14,000. So I could contribute $14,000 to each of my TAP 529 plans and have those contributions deducted from my income on my state taxes. This will generally save me a few thousand dollars in taxes, which I can then re-invest back into the TAP 529 accounts. In addition, the funds I contribute to the TAP 529 are excluded from the FASFA application for student aid.

I ended up selecting the PA 529 Investment Plan, and that’s where the money has been gowning for the past few years. There’s a lot of flexibility in how the funds can be allocated, if you are interested in taking an active part you can select from a myriad of options. Or you can set it and forget it and the plan will automatically re-allocate the funds to less riskier investments the closer your child gets to college age.

My Thoughts

It’s never too late to start saving or investing. Whether you are saving for your child’s college education or for your eventual retirement, there are plenty of ways to start saving and investing today. In 2018 I opened an account with Betterment, a robo advisor. That account has provide a rate of return around 9.7% annually, not a phenomenal number by any stretch but it’s definitely better than 0%.

What are you doing today to save for your child’s college education or your retirement?

Cheers!

]]>
Cisco Nexus 9300 SSD Firmware Issue https://blog.michaelfmcnamara.com/2021/10/cisco-nexus-9300-ssd-firmware-issue/ Sun, 31 Oct 2021 13:48:23 +0000 https://blog.michaelfmcnamara.com/?p=7282 I recently stumbled into yet another interesting issue that turned out to be a bug in the SSD firmware of some Cisco Nexus 9000 Series switches. We had performed an upgrade in two of our Data Centers just over 3 years ago using the Cisco Nexus 9000 Series product line providing a 10/40Gbps network. Within the past week we had several of those switches crash and reboot themselves. Upon further investigation I found some switches that didn’t crash or reboot themselves were running with a read-only file system. It turned out that this was a known bug that had been identified by Cisco earlier this year.

Field Notice: FN – 72150 – Nexus 9000/3000 Will Fail With SSD Read-Only Filesystem – Power Cycle Required – BIOS/Firmware Upgrade Recommended

The issue was further compounded by some sloppy management, with several switches having unsaved configurations or having crashed and rebooted with unsaved configurations and ultimately inconsistent VPC states. In the short term I ended up deploying the SSD firmware update to all the impacted Cisco Nexus 9000 series switches in my network. I’ll look at performing the recommended software upgrades early next year.

You can setup notifications on the Cisco website to help keep you informed of field notices, software releases and security bulletins.

Anyone else run into this problem?

Cheers!

]]>
Making the leap to Rocky Linux 8.4 https://blog.michaelfmcnamara.com/2021/10/making-the-leap-to-rocky-linux-8-0/ Sat, 30 Oct 2021 14:09:48 +0000 https://blog.michaelfmcnamara.com/?p=6967
Rocky Linux

You always need to be learning in the technology field, it’s a field that is constantly evolving and to that point you need to be constantly expanding your knowledge and testing out new products, methods, solutions, etc.

I’m not a big fan of Oracle Linux for a number of reasons, which I’m not interesting in diving it here, so today I’m moving this server from CentOS 7.9 to Rocky Linux 8.4.

I’m also also taking the opportunity to downsize my server since my daughters are no longer spending hours upon hours playing Minecraft – life is slowly returning to normal, if only slowly. This will give me an opportunity to test out Rocky Linux and decide which operating system I’ll be using going forward in my personal and professional endeavors.

CentOS Linux release 7.9.2009 (Core)
MariaDB 10.5.12
nginx/1.20.1
PHP 7.4.25

to

Rocky Linux release 8.4 (Green Obsidian)
10.3.28-MariaDB
nginx/1.14.1
PHP 8.0.12

I’m trying to only spend a few hours doing this so I’m going to stick with the standard MariaDB and nginx packages that are available in the repos, although I’m upgrading to PHP 8.0 using the Remi repo. Upgrading to PHP 8.0 is going to cause me some headaches because I’m using some older WordPress plugins that are likely to break and I’ll need to pull them off the site.

If you want to live migrate a server, there’s lots of documentation and tools available to help you.

Have you done any work with Rocky Linux? I’d but curious to hear your take.

Cheers!

]]>
How to troubleshoot Faceook, Instagram, WhatsApp outages? https://blog.michaelfmcnamara.com/2021/10/how-to-troubleshoot-faceook-instagram-whatsapp-outages/ Mon, 04 Oct 2021 20:52:27 +0000 https://blog.michaelfmcnamara.com/?p=6955

Things certainly went south for Facebook today in a spectacular way as Reddit and other forums lit up with posts about Facebook, Instagram and WhatsApp being down and unreachable. Someone asked me a simple question? How do you troubleshoot an outage like that? We’re obviously limited as “outsiders” but even as a regular netizen we can do a bit of investigative troubleshooting to get some idea of what’s going on at Facebook.

If you tried to visit Facebook earlier today you would have likely seen this message in your web browser.

This site can’t be reached
www.facebook.com’s server IP address count not be found.

Let’s start with the basics…. DNS resolution.

[root@woodstock ~]# dig facebook.com +short
[root@woodstock ~]#

That’s not good… we can’t get an IP address for facebook.com, let’s try www.facebook.com as well.

[root@woodstock ~]# dig www.facebook.com +short
[root@woodstock ~]#

Ok, equally bad… let’s try to find the authoritative DNS servers for the domain facebook.com. We know from experience that a.gtld-servers.net. is a top level DNS server for the .com TLD, but let’s confirm it’s still in the list of servers. (I’ll edit the output below to help save space and focus our attention)

[root@woodstock ~]# dig ns com

;; ANSWER SECTION:
com. 170780 IN NS b.gtld-servers.net.
com. 170780 IN NS i.gtld-servers.net.
com. 170780 IN NS m.gtld-servers.net.
com. 170780 IN NS j.gtld-servers.net.
com. 170780 IN NS l.gtld-servers.net.
com. 170780 IN NS e.gtld-servers.net.
com. 170780 IN NS k.gtld-servers.net.
com. 170780 IN NS h.gtld-servers.net.
com. 170780 IN NS g.gtld-servers.net.
com. 170780 IN NS d.gtld-servers.net.
com. 170780 IN NS c.gtld-servers.net.
com. 170780 IN NS a.gtld-servers.net.
com. 170780 IN NS f.gtld-servers.net.

;; ADDITIONAL SECTION:
a.gtld-servers.net. 69518 IN A 192.5.6.30
b.gtld-servers.net. 82780 IN A 192.33.14.30
c.gtld-servers.net. 84678 IN A 192.26.92.30
d.gtld-servers.net. 84679 IN A 192.31.80.30
e.gtld-servers.net. 84678 IN A 192.12.94.30
f.gtld-servers.net. 84138 IN A 192.35.51.30
g.gtld-servers.net. 84679 IN A 192.42.93.30
h.gtld-servers.net. 84678 IN A 192.54.112.30
i.gtld-servers.net. 84679 IN A 192.43.172.30
j.gtld-servers.net. 82780 IN A 192.48.79.30
k.gtld-servers.net. 84679 IN A 192.52.178.30
l.gtld-servers.net. 84138 IN A 192.41.162.30
m.gtld-servers.net. 84679 IN A 192.55.83.30
a.gtld-servers.net. 81113 IN AAAA 2001:503:a83e::2:30

Ok, so a.gtld-servers.net is still in there… so let’s ask that DNS server who are the DNS servers for the domain facebook.com.

[root@woodstock ~]# dig @a.gtld-servers.net. ns facebook.com

;; QUESTION SECTION:
;facebook.com. IN NS

;; AUTHORITY SECTION:
facebook.com. 172800 IN NS a.ns.facebook.com.
facebook.com. 172800 IN NS b.ns.facebook.com.
facebook.com. 172800 IN NS c.ns.facebook.com.
facebook.com. 172800 IN NS d.ns.facebook.com.

;; ADDITIONAL SECTION:
a.ns.facebook.com. 172800 IN A 129.134.30.12
a.ns.facebook.com. 172800 IN AAAA 2a03:2880:f0fc:c:face:b00c:0:35
b.ns.facebook.com. 172800 IN A 129.134.31.12
b.ns.facebook.com. 172800 IN AAAA 2a03:2880:f0fd:c:face:b00c:0:35
c.ns.facebook.com. 172800 IN A 185.89.218.12
c.ns.facebook.com. 172800 IN AAAA 2a03:2880:f1fc:c:face:b00c:0:35
d.ns.facebook.com. 172800 IN A 185.89.219.12
d.ns.facebook.com. 172800 IN AAAA 2a03:2880:f1fd:c:face:b00c:0:35

There are the DNS servers for the domain facebook.com, so let’s see if we can communicate with any of them.

Let’s start by pinging the servers (for brevity I’m only going to go through the first server above… but they all were having issues today)

[root@woodstock ~]# ping a.ns.facebook.com -c 5 -q
PING a.ns.facebook.com (129.134.30.12) 56(84) bytes of data.

--- a.ns.facebook.com ping statistics ---
5 packets transmitted, 0 received, 100% packet loss, time 3999ms

That’s not completely unexpected as most networks today block ICMP traffic by default to prevent DoS attacks so let’s try a simple DNS query to that server.

[root@woodstock ~]# dig @a.ns.facebook.com ns facebook.com

; <<>> DiG 9.11.4-P2-RedHat-9.11.4-26.P2.el7_9.5 <<>> @a.ns.facebook.com ns facebook.com
; (1 server found)
;; global options: +cmd
;; connection timed out; no servers could be reached

That’s definitely not good, so we can assume at this point that we’re unable to communicate with the DNS servers for the facebook.com domain name, hence the error message we’re gettting in the web browser. But let’s dig a little deeper to see if the IP networks that are associated with those DNS servers are “online” and reachable. We can do that by looking at a BGP looking glass or full BGP routing table and see if that prefix is being advertised, we can also try to traceroute to the IP address in question and see if we can reach the Facebook network.

Let’s use WHOIS to see what network that IP address is a member of (again I’ve cut out some of the output below).

[root@woodstock ~]# whois 129.134.30.12
[Querying whois.arin.net]
[whois.arin.net]

NetRange: 129.134.0.0 - 129.134.255.255
CIDR: 129.134.0.0/16
NetName: THEFA-3
NetHandle: NET-129-134-0-0-1
Parent: NET129 (NET-129-0-0-0-0)
NetType: Direct Assignment
OriginAS:
Organization: Facebook, Inc. (THEFA-3)
RegDate: 2015-05-13
Updated: 2015-05-13
Ref: https://rdap.arin.net/registry/ip/129.134.0.0

Ok, so the original netblock assigned to Facebook from ARIN was 129.134.0.0/16 but Facebook could have subnetted that so we need to mindful that it could be smaller than the /16 we see allocated above.

There was a mention in some of the forums that all BGP peers to Facebook were down, so let’s check there. Let’s look at the Hurricane Electric’s Network Looking Glass using the IP address of 129.134.30.12. That shows us the following (as of 5:00PM EDT Monday October 4, 2021).

core1.mnz1.he.net> show ip bgp routes detail 129.134.30.12
Number of BGP Routes matching display condition : 2
S:SUPPRESSED F:FILTERED s:STALE x:BEST-EXTERNAL
1 Prefix: 129.134.0.0/17, Rx path-id:0x00000000, Tx path-id:0x00000001, rank:0x00000001, Status: BI, Age: 28d7h21m27s
NEXT_HOP: 65.49.109.182, Metric: 1486, Learned from Peer: 216.218.252.172 (6939)
LOCAL_PREF: 100, MED: 0, ORIGIN: igp, Weight: 0, GROUP_BEST: 1
AS_PATH: 3491 32934
COMMUNITIES: 6939:1111 6939:7039 6939:8392 6939:9003
2 Prefix: 129.134.0.0/17, Rx path-id:0x00000000, Tx path-id:0x00040001, rank:0x00000002, Status: Ex, Age: 86d22h8m40s
NEXT_HOP: 62.115.42.144, Metric: 0, Learned from Peer: 62.115.42.144 (1299)
LOCAL_PREF: 70, MED: 48, ORIGIN: igp, Weight: 0, GROUP_BEST: 1
AS_PATH: 1299 32934
COMMUNITIES: 6939:2000 6939:7297 6939:8840 6939:9001
Last update to IP routing table: 2d3h2m25s

Entry cached for another 60 seconds.

So it would appear that the routes are in the Internet BGP tables for that first server… I’m going to guess that Facebook is in recovery mode and slowly restoring their network – assuming it’s not a DoS attack or something similar.

Let’s try a traceroute using ICMP packets, again we need to be mindful that some organizations will block all ICMP traffic to protect themselves against the miscredants and to better conceal their network topology.

[root@woodstock~]# traceroute -I 129.134.30.12
traceroute to 129.134.30.12 (129.134.30.12), 30 hops max, 60 byte packets
1 107.170.19.254 (107.170.19.254) 4.061 ms 4.040 ms 4.037 ms
2 138.197.248.154 (138.197.248.154) 1.545 ms 1.558 ms 1.558 ms
3 157.240.71.232 (157.240.71.232) 41.384 ms 41.345 ms 41.380 ms
4 157.240.42.70 (157.240.42.70) 1.893 ms 1.911 ms 1.913 ms
5 157.240.40.230 (157.240.40.230) 3.552 ms 3.529 ms 3.538 ms
6 129.134.47.188 (129.134.47.188) 8.797 ms 7.276 ms 7.229 ms
7 * * *
8 * * *
9 * * *
10 * * *
11 * * *
12 * * *

Ok, so we’re definitely reaching parts of the Facebook network, as 129.134.47.188 is on the same advertised network as a.ns.facebook.com (129.134.30.12).

Unfortunately that’s about as far as we can take it from here, we’ll need to wait for the news from Facebook itself.

Cheers!

]]>
How does latency impact network throughput? https://blog.michaelfmcnamara.com/2021/09/how-does-latency-impact-network-throughput/ Tue, 28 Sep 2021 16:49:15 +0000 https://blog.michaelfmcnamara.com/?p=6246 I was recently having a conversation with a DevOps colleague (let’s not jeer too loudly) who was trying to understand why he wasn’t getting more than 350Mbps between two servers over a 1Gbps WAN connection. He thought there must be a problem with the network and suggested that I should open a ticket with the carrier to “fix” the issue. I attempted to explain to him that it was the latency and distance between the two servers (3,000 miles) that was limiting the TCP performance and he could potentially overcome that issue by using multiple TCP sockets with larger TCP window sizes, or potentially switch to UDP instead of TCP.

I used iPerf3 to demonstrate the issue… with a single stream/thread we were able to achieve ~ 350Mbps. With a second stream/thread we were able to hit ~ 600Mbps. With a third stream/thread we were able to hit ~ 789Mbps.

It wasn’t magic…. it’s the well known fact that latency plays a huge role in TCP performance. In order to understand why it impacts TCP performance you need to understand how TCP works. TCP requires that transmitted data sets are acknowledged before the next set of data can be transmitted. The TCP window size determines the size of those data sets, larger TCP window size allows more data to be transmitted before an acknowledgement is required. The delay in getting the acknowledgement back is what limits the performance.

There is a well written blog article from Netbeez written by Stefano Gridelli titled, Impact of Packet Loss and Round-Trip Time on Throughput that covers this topic in great detail. You can even apply a mathematical formula to determine the max potential throughput given a known RTT latency.

Cheers!

]]>
Lenovo ThinkPad T14 with Realtek 8852AE Wireless Issues https://blog.michaelfmcnamara.com/2021/08/lenovo-thinkpad-t14-with-realtek-8852ae-wireless-issues/ Sun, 22 Aug 2021 14:16:16 +0000 https://blog.michaelfmcnamara.com/?p=6934 I’m still alive, just super busy these days… here’s a quick one for anyone using the Lenovo ThinkPad T14 (the issue also impacts a bunch of other models).

It turns out there are multiple models of the Lenovo ThinkPad T14, one with an Intel wireless NIC and one with a Realtek wireless NIC. We quickly discovered that the model with a Realtek RTL8852AE WiFi 6 802.11ax PCIe adapter was having a lot of issues staying connected to a number of different Cisco Wireless LAN Controllers in different physical locations. The symptom displayed to the user as an inability to pull a DHCP address, even though the device showed it was connected to the SSID. In the end it turns out that a driver released on August 10, 2021 (6001.0.10.334) that apparently fixes an issue when clients are using a Cisco wireless infrastructure. Unfortunately there’s no mention of what exactly the issue was in the release notes.

You can find the updated driver and release notes at the following link;

https://pcsupport.lenovo.com/us/en/products/laptops-and-netbooks/thinkpad-t-series-laptops/thinkpad-t14s-type-20uh-20uj/downloads/driver-list/component?name=Networking%3A%20Wireless%20LAN

I’ve been seeing a lot of issues as we move to WiFi 6 access points – currently rolling out Juniper MIST AP43s. And in the vast majority of these cases older drivers are the problem. A quick upgrade to the latest and greatest driver is solving the majority of issues. So if you are having issues with the WiFi 6 based access point or client, I would strongly suggest you update your driver before you fire up WireShark.

Cheers!

]]>
How to start blogging in 2021? https://blog.michaelfmcnamara.com/2021/03/how-to-start-blogging-in-2021/ Sun, 14 Mar 2021 15:50:44 +0000 https://blog.michaelfmcnamara.com/?p=6798 It’s interesting how many people still ask this basic question, wanting to know how much it costs and what it takes or more specifically “how to do it”. I get the question from college students, colleagues and more often neighbors who stumble upon my not so secret digital identify. While there’s a lot more social media around today than there was back when I started blogging in 2007 and I believe there’s still a space for blogging. You’d be surprised that many of the reasons people start blogs are commonly similar. Whether it’s for professional exposure or experience, personal interests or curiosity there are no shortage of tools or solutions available today to help a budding creator.

I started with Blogger back in 2007 and then in 2008 I migrated to a self-hosted installation of WordPress. While there are a number of great managed solutions available today I’m one of those guys that enjoys the challenges of learning by building it yourself and then managing it day to day. The self-hosted WordPress or WordPress.org as some refer to it, requires a server to run the software stack. In my case I’m using a Linux Virtual Private Server (VPS) rented/leased from a hosting provider in order to run WordPress. This was traditionally done with what is referred to as a LAMP stack, Linux, Apache, MySQL and PHP. These days I’m running a LEMP stack which includes Linux, Nginx, MariaDB and PHP. I’ve gone through a few hosting providers in my days, starting with RimuHosting, then Linode and today I’m using DigitalOcean. I’m also still using GoDaddy as my domain registrar. While I’ve heard a lot of horror stories from GoDaddy customers I haven’t experienced any issues myself. I have heard really good stores from customers of Gandi.net.

You can still find my original site on Blogger today at http://michaelfmcnamara.blogspot.com/.

If you are looking to test out blogging I would strongly suggest you start with Blogger or perhaps WordPress.com – not to be confused with WordPress.org. Whether you decide to try Blogger or WordPress.com both solutions make it incredibly easy to get up and running quickly and easily. If you later find that you enjoy blogging and you want to delve into all the features and options then you can migrate your content to any number of solutions, both commercial and other.

Since I run a self-hosted WordPress site I needed to purchase the following components separately;

Domain Name (michaelfmcnamara.com)GoDaddy$56.32/2 years
Virtual Private Server (Linux CentOS 7.6 x64)DigitalOcean$240/2 years
SSL Certificate (Wildcard)RapidSSL$258.00/2 years
$554.32 Total (2 years)

As you can see the costs quickly add up, on average $23/monthly. I advise anyone just jumping into blogging to start out with a free solution until you are ready to commit your hard earned $$$. I use my server to host multiple websites (and more recently a Minecraft server) so the costs presented above are a little skewed so don’t go postal on me in the comments. There are definitely cheaper alternatives out there, this is just what I’m doing these days and it works for me. As another example if you used a WordPress.com Premium account that would run you $8/monthly or $192 over 2 years.

You can look to use advertising to help offset some of the costs above. For a number of years there I was earning about $130/monthly from Google Adsense and directly contracted banner ads which helped offset the costs. It takes quiet a bit of effort to get beyond anything more than “beer” money so keep that in mind if you think you’ll be able to launch a blog or even a YouTube channel and it will start paying for itself in six months.

In the end it’s not Blogger or WordPress that’s going to make your blog successful, it will be the content that you share!

If you have any questions drop them below and I’ll do my best to answer them.

Cheers!

]]>
LastPass – Internet Upheaval https://blog.michaelfmcnamara.com/2021/03/lastpass-internet-upheaval/ https://blog.michaelfmcnamara.com/2021/03/lastpass-internet-upheaval/#comments Mon, 08 Mar 2021 04:48:54 +0000 https://blog.michaelfmcnamara.com/?p=6903

It seems that everyone and anyone wants to talk about LastPass since their announcement on February 16th that they were going to limit their free tier product offering. The vast majority of videos and articles haven’t been kind to LastPass or their current owners, LogMeIn.

I haven’t really mentioned LastPass since I first talked about them in December of 2014. I’m a paying LastPass customer since 2013. At the time a LastPass premium account was $12/year. A small cost for any IT professional that values their time (and productivity) and security in trying to keep the passwords for every application they use or every system they manage in their head. I currently have 763 passwords in my vault.

It seems that anytime a vendor takes away something that was free the Internet masses take to their media of choice to rail against the injustice. A large number of tech savvy users already scowl at the mention of LogMeIn. The company eliminated it’s free account offering of the popular remote control application by the same name in 2014. In 2016 the company acquired GoToMyPC, the largest competitor to LogMeIn, and subsequently raised the pricing on that service.

I’m no fan of LogMeIn, but I support paying for products that provide a value and service in my day to day life. As an Information Technology professional a Password Manager should be an essential part of your kit. Thankfully there are plenty to choose from and they all have their own strengths and weaknesses.

I believe prior to the LogMeIn acquisition you needed a Premium LastPass account to use the mobile application on either Android or iOS. Someone feel free to correct me in the comments below. I’m not sure where or when that changed was made but somewhere along the line they started allowing non-Premium users to use the mobile app. The timing here is important because it does feel like a potential bait and switch play. Opening the mobile app for a few years and then squeezing that group in hopes of getting some percentage to switch to a Premium account.

If I had to choose a password manager today I wouldn’t necessarily jump at spending $36/year – the current pricing for new LastPass Premium customers. However, I might be convinced to purchase their new LastPass Family for 6 family members at $48/year. That said I’ve been pretty happy with LastPass to date.

What password manager are you using? Hopefully you are using a password manager!

Cheers!

]]>
https://blog.michaelfmcnamara.com/2021/03/lastpass-internet-upheaval/feed/ 1
VMware VeloCloud SD-WAN Orchestrator API and Python – Part 3 https://blog.michaelfmcnamara.com/2021/03/vmware-velocloud-sd-wan-orchestrator-api-and-python-part-3/ Tue, 02 Mar 2021 03:31:11 +0000 https://blog.michaelfmcnamara.com/?p=6886 It looks like this project is going to be moving forward again… time to dust off the Python code and finish out the last few pieces to the puzzle.

Interestingly enough I ran into a quick problem testing my original code. It looks like something had changed with the “Profile” that we’re using for each Edge. When I run my original Python script I’m getting a HTTP/400 returned along with the following response code, Interface “CELL1” present in Profile but not in Edge. Looking through some of the JSON data it would appear that something has changed with the Profile that I’m using in the configuration. The error I’m getting when calling rest/configuration/updateConfigurationModule likely means that I’m missing some required data in my Jinja templates that the VMware VeloCloud Orchestrator is now expecting.

There is a Chrome extension called VeloCloud Developer Assistant, that can help you break down the JSON data and make it a little easier to visually consume and troubleshoot. I personally prefer just going into the Chrome developer tools and copying out the entire JSON data block that’s being posted and then running that through some JSON formatting tool to help clean it up for human consumption. If you go through the steps in the web UI with the Chrome developer tools open, can you go back and extract all the JSON data that is being sent to the VeloCloud Orchestrator, and in short you can easily reverse engineering the calls and the JSON data.

In the end I was able to find the missing CELL1 interface under the routedInterfaces element. I added the missing data elements to the Jinja template and everything started working again. I ended up writing a few other supporting scripts to help with the overall project goal. I wrote a Perl script to poll the existing hardware to gather up all the IP configuration details from each VLAN and interface which then can be fed into the Python script to build the configuration within the VeloCloud Orchestrator. There’s also a management IP required, so I used a snippet of Perl code that I wrote back in 2016 to call the Infoblox API to assign the next available IP address in the management subnet.

With the Jinja templates it’s relatively easy to put this code onto a web server and build a simple WebUI around some Python or PHP code to generate new configurations when needed.

Cheers!

]]>
Working from home upgrades https://blog.michaelfmcnamara.com/2021/02/working-from-home-upgrades/ Fri, 19 Feb 2021 01:00:00 +0000 https://blog.michaelfmcnamara.com/?p=6868 I made some purchases over the past few months to help improve my work from home environment and thought I’d share my thoughts on those items. I purchased all the items below from from my local BestBuy using the BestBuy Android mobile app with curbside pickup. As someone who works in retail I was really impressed with how well the checkout and curbside pickup process works at BestBuy and how effortless it was, a real technology win in my honest opinion. Kudos to their team on an incredibly frictionless process and to all their store associates. The pricing for each item was in line with pricing from online resellers so I wasn’t really sacrificing anything by purchasing from a traditional brick-n-mortar business and I was happy to support my local store.

LG – 34WL500-B 34″ IPS LED UltraWide FHD FreeSync Monitor with HDR (HDMI) – Black

When you upgrade to an UltraWide display you won’t ever want to go back. I desperately needed the additional desktop space on my work laptop to help improve my general productivity. I usually have 15-30 windows open at any time and having to switch back and forth, or worse yet go hunting for individual windows can be an incredible productivity drain. This display only has a max resolution of 2560 x 1080 but that’s fine for my aging eyes and provides me all the desktop real estate I need to work efficiently. The included stand isn’t overly large and brightness levels from the display are great. This monitor is currently on-sale at BestBuy for $300, a great price for a 34″ wide monitor. The 29″ version LG 29WL500-B is an even better deal at BestBuy for $200. I would recommend either of these for a work from home environment. I don’t play any games on this display so I can’t comment about game performance.

Logitech – G PRO X Wireless DTS Headphone:X 2.0 Gaming Headset for Windows with Blue VO!CE Mic Filter Tech and LIGHTSPEED Wireless – Black

I’ve traditionally used relatively cheap Plantronics headsets on my home desktop but I decided it was time to cut the cord and go with a premium wireless headset that would allow me to move around on long conference and video calls. Having the ability to move it around between my personal desktop and my corporate laptop was also extremely beneficial. I’m not yet sold on the Blue VOICE feature, I didn’t particularly like how I sounded with that feature enabled so I need to-do some additional testing and validation. I’m still up in the air about this headset, I’ll need a little more time before I decide if it was a good purchase.

Bose – Companion 2 Series III Multimedia Speaker System (2-Piece) – Black

I’ve often opt for the cheap Insignia speakers but this time I wanted a quality set of speakers to use when I wasn’t using my wireless headset and so I chose the Bose Companion 2 Series III speakers. I’m not a high-fidelity guy but these sound incredibly better than any other computer speakers I’ve ever owned and easily rival the sound put out from the Onkyo receiver and speakers in my basement surround sound system. These speakers get a solid buy rating from me. There are likely better options available for the audiophiles out there but I couldn’t justify spending $200 or $300 on desktop speakers.

Have you made any purchases lately? Anything fun?

Cheers!

]]>
The Swedes are coming! https://blog.michaelfmcnamara.com/2021/02/the-swedes-are-coming/ Thu, 18 Feb 2021 03:17:37 +0000 https://blog.michaelfmcnamara.com/?p=6860 No, I was hacked with some stolen user credentials.

I was surprised today when I noticed that someone had posted a new article to this site at 6:36AM this morning titled “3 Reasons to Start Using Dealspaces”. Interestingly enough the user account used to post the article was a test account under my wife’s name that I probably haven’t used in years.

I went looking at the nginx access.log files and found the relevant entires;

213.164.204.89 - - [17/Feb/2021:11:36:17 +0000] "POST //xmlrpc.php HTTP/1.1" 200 141 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
213.164.204.89 - - [17/Feb/2021:11:36:18 +0000] "POST //xmlrpc.php HTTP/1.1" 200 2253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"
213.164.204.89 - - [17/Feb/2021:11:36:19 +0000] "GET /2021/02/3-reasons-to-start-using-dealspaces/ HTTP/1.1" 200 9985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0"

The IP address belongs to a Swedish Internet Service Provider named Bahnhof, not particularly helpful as it could have also been a Tor endpoint or exit node. I can tell from the time stamps that the action was likely scripted as there was exactly one second between each request.

Needless to say I immediately deleted the post and the user account that was used to make the post and then changed my own password out of an abundance of caution. I then scoured the entire WordPress filesystem using the recent backup I had to try and make sure that nothing else was changed. I even dumped the database and ran a quick comparision against a recent backup, again looking for any changes or any obfuscated code.

My Thoughts?

Old user accounts are becoming a bigger and bigger problem as the longer they hang around in the wild they will eventually end up being compromised. This is why IT security professionals plead with users to use different passwords on every single website and to frequently change those passwords. Unfortunately in this case I’m going to guess that the password used for this account likely wasn’t very secure (Test123) and that’s likely how the hacker was able to login to WordPress and post the article. So shame on me for yet again falling into the roll of a user.

Are you curious if your user credentials have ever been leaked? Check out have i been pwned?

Cheers!

]]>
School Music Concerts, Copyrights, Live Streaming and Zoom https://blog.michaelfmcnamara.com/2021/02/school-music-concerts-copyrights-live-streaming-and-zoom/ Wed, 17 Feb 2021 03:10:20 +0000 https://blog.michaelfmcnamara.com/?p=6824 I attended a wonderfully orchestrated virtual performance this evening put together by my daughters’ high school music director. The event was streamed using Zoom and it was extremely well done, with the exception that I couldn’t hear the actual music performances.

I could hear other people on the call and I could hear the music director as he spoke but I couldn’t hear any of the audio he was “sharing” from his desktop or laptop. Thankfully it turned out I wasn’t alone as other people quickly reported the same issue in chat… but oddly enough it turned out there were other folks in the meeting that could hear the performance fine so I was stumped.

How is it that some attendees in the meeting could hear the audio but other attendees couldn’t hear the audio?

In the ensuing conversation I heard how one couple had an Apple iPad and they couldn’t hear anything. I learned that even my parents who were using their new Windows desktop that I built for them in January had no issues hearing the performances. I even connected to the meeting from a second Windows device and confirmed that it too had the same problem. I’m not sure if it’s relevant but I did discover that both of my Windows devices were running the same (latest) version of the Zoom client, Version: 5.5.2 (12494.0204). I can only guess that there is a Zoom bug out there that we stumbled into, perhaps it has something to-do with encryption as I noticed that the teacher’s audio stream was alerting as “not encrypted” during the meeting. I felt really bad for the teacher but there wasn’t anything he could do and it definitely wasn’t his fault. Technology had failed him, just like it has failed so many of us so many times. I likely suspect Zoom was the culprit in this specific instance – I actually submitted a support ticket to Zoom from my corporate account so we’ll see where that goes if anywhere. It was just another sign of the times in this new COVID-19 reality that we’re all living in.

Copyright

The teacher did make a comment that while LIVE streaming was allowed for educational use thanks to waivers from the music publishers, recording was still not permitted. I did some quick searching and found some relevant articles from the National Association for Music Education in an article titled, Music Publishers Agree to Allow Educational Use of Copyrighted Music. If you’ve ever tried to upload your child’s school performance to YouTube you’ll quickly run into issues if the recording has copyrighted music in it. I’ve been there done that, fun times getting a copyright strike against a middle school band performance.

My Thoughts?

I’m very disappointed to say that unfortunately technology failed again today, through no fault of the users. I’m usually pretty harsh on users (the word user is a dirty word in my house) but in this case it was the technology itself that failed. I like finding answers to these mysteries and hopefully Zoom will respond and we can fix it so the next concert can go on without any issues.

Cheers!

]]>
Discussion Forums – Closing https://blog.michaelfmcnamara.com/2021/02/discussion-forums-closing/ https://blog.michaelfmcnamara.com/2021/02/discussion-forums-closing/#comments Fri, 12 Feb 2021 02:38:35 +0000 https://blog.michaelfmcnamara.com/?p=6762

It’s hard to believe that the Network Infrastructure Forums have been running for over 11 years. In July of 2009 I installed Simple Machines Forum software on a virtual private server from RimuHosting with the purpose of setting up an open and free discussion forum for network engineers and system administrators. At the time I was extremely frustrated with a number of vendors and manufacturers supporting their users (outside of professional services). I felt that I could help fill the void… and in the case of Bay Networks, Nortel Networks, Avaya and Symbol, Motorola, Zebra I wasn’t far off. I went out and registered the domain networkinfrastructure.info and set out to create a place for IT professionals (including resellers) to share ideas, problems and solutions.

Like most everything in life though, it’s time has come and gone and it is time to more forward. The majority of the information on the forum is now extremely dated and with the rise of other solutions, user traffic has dropped off significantly in the past few years. At it’s peak the forum had a very robust community around Nortel switching and Symbol, Motorola, Zebra wireless equipment serving both end-users and resellers.

If you are interested in some statistics;

  • 49,023 registered members
    • 23,000 legitimate members when you remove all the bots
  • 20,891 posts
  • 4,383 topics
  • 62,621,940 page views

Special thanks to the moderators who helped curate the discussions, I couldn’t have done half as well without your contributions.

  • Dominik
  • Flintstone
  • Paul L
  • Telair

Thank you to everyone who participated in the discussions!

Cheers!

]]>
https://blog.michaelfmcnamara.com/2021/02/discussion-forums-closing/feed/ 4