SlideShare a Scribd company logo
Best Current Operational Practices
FrOScon 13 Network Track
Falk Stern, Maximilian Wilhelm
1 / 16
Agenda
1. Who are we?
2. Do
3. Don't
2 / 16
Who's who Falk Stern
Full Stack Infrastructure Engineer
IPv6 fanboy
Runs his own Kubernetes cluster in his basement
Consultant @ Profi Engineering Systems AG
Contact
@wrf42
falk@fourecks.de
3 / 16
Who's who Maximilian Wilhelm
Networker
OpenSource Hacker
Fanboy of
(Debian) Linux
ifupdown2
Occupation:
By day: Senior Infrastructure Architect, Uni Paderborn
By night: Infrastructure Archmage, Freifunk Hochstift
In between: Freelance Solution Architect for hire
Contact
@BarbarossaTM
max@sdn.clinic
4 / 16
Document your stu
5 / 16
Document your stu
Netbox
Racktables
i-doit
Visio / Excel
6 / 16
Have Infrastructure
Logserver
Graylog
NTP service
Logging is useless if every device has a different time
Monitor
Icinga 2
LibreNMS (editor's choice!)
Configuration Management
oxidized
rancid
Have DNS (forward and reverse)
Maintain it!!1elf!
7 / 16
Ansible
Salt
Chef
Puppet
Automate, automate, automate
8 / 16
Use managed switches
They are worth the extra cost
Enable Spanning Tree
Known to save asses more than once
Use redundant paths
Always keep a spare device handy
Layer 2 pitfalls
9 / 16
Layer 2 pitfalls
Enable VTP transparent mode
Disable Dynamic Trunking Protocol
Always use LACP active mode
Always use LACP, not PagP or static Etherchannels
10 / 16
Segment your network
Build small Layer 3 islands
Route where you can, switch where you must
Routers gonna route, only Jeff bridges
familiarize with dynamic routing protocols
11 / 16
Get to know Linux
flexible, versatile OS for everything
Use it for infrastructure tasks
12 / 16
Don't rely on vendor features
13 / 16
Security
Disable proxy arp
Hosts should have only a single upstream interface
Review your firewall rules regularly
Have some
Use source code management for configurations
14 / 16
Security - Live at Network Track ¯(ツ)/¯
Sehr geehrte Damen und Herren,
Cisco Smart Install (SMI) ist eine Funktion zur automatischen Konfiguration von Netzwerk-Switches. Diese wurde zur
Verwendung in lokalen Netzwerken entwickelt und sollte nicht aus unsicheren Netzen wie dem Internet zugreifbar
sein.
[...] CERT-Bund hat von einer externen Quelle Informationen zu IP-Adressen in Deutschland erhalten, auf denen ein
Cisco-Gerät mit aktiver Smart-Install-Funktion offen aus dem Internet erreichbar ist.
Cisco empfiehlt, die Smart-Install-Funktion zu deaktivieren. [...]
Betroffene Systeme in Ihrem Netzbereich:
"asn","ip","timestamp"
"39225","194.107.207.35","2018-08-24 12:08:43"
"39225","194.107.207.37","2018-08-24 12:19:03"
Mit freundlichen Grüßen
das Team CERT-Bund
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Referat CK22 - CERT-Bund
Godesberger Allee 185-189, 53175 Bonn, Germany
15 / 16
Being part of the DFZ
Use BCP38 (Ingress filtering)
Use filters on your BGP sessions
Maximum Prefixes
IRR filters
RSPL filters
Filter Bogon Prefixes
Use communities
Customer / Peering / Transit / IXP ...
16 / 16

More Related Content

PDF
Overlays & IP-Fabrics - viele Wege führen nach Rom und warum Layer2 keine Lös...
PDF
Building your own CGN boxes with Linux
PDF
Anycast all the things
PDF
Fun with PRB, VRFs and NetNS on Linux - What is it, how does it work, what ca...
PDF
Dynamische Routingprotokolle Aufzucht und Pflege - OSPF
PDF
Contemporary network configuration for linux - ifupdown-ng
PDF
IPv6 im Jahre 2018
PDF
Dynamische Routingprotokolle Aufzucht und Pflege - BGP
Overlays & IP-Fabrics - viele Wege führen nach Rom und warum Layer2 keine Lös...
Building your own CGN boxes with Linux
Anycast all the things
Fun with PRB, VRFs and NetNS on Linux - What is it, how does it work, what ca...
Dynamische Routingprotokolle Aufzucht und Pflege - OSPF
Contemporary network configuration for linux - ifupdown-ng
IPv6 im Jahre 2018
Dynamische Routingprotokolle Aufzucht und Pflege - BGP

What's hot (20)

PDF
Intent driven, fully automated deployment of anycasted load balancers with ha...
PDF
L2/L3 für Fortgeschrittene - Helle und dunkle Magie im Linux-Netzwerkstack
PDF
Netzwerkgrundlagen - Von Ethernet bis IP
PDF
Angewandte Netzwerkgrundlagen reloaded - von Layer 1 bis 3
PDF
Contemporary Linux Networking
PDF
Building your own sdn with debian linux salt stack and python
PPT
6.Routing
PPTX
Operationalizing VRF in the Data Center
PDF
AS201701 - Building an Internet backbone with pure 1he servers and Linux
PDF
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
PDF
LinuxCon 2015 Linux Kernel Networking Walkthrough
PDF
Xpress path vxlan_bgp_evpn_appricot2019-v2_
PDF
Cilium - API-aware Networking and Security for Containers based on BPF
PDF
Linux Kernel Status Report for IEEE 802.15.4 & 6LoWPAN
PDF
DevConf 2014 Kernel Networking Walkthrough
PDF
OpenNebulaConf2018 - Scalable L2 overlay networks with routed VXLAN / BGP EVP...
PDF
Networking Fundamentals: Local Networks
PDF
Cilium - Fast IPv6 Container Networking with BPF and XDP
PDF
The Spectre of Meltdowns
PDF
The Next Generation Firewall for Red Hat Enterprise Linux 7 RC
Intent driven, fully automated deployment of anycasted load balancers with ha...
L2/L3 für Fortgeschrittene - Helle und dunkle Magie im Linux-Netzwerkstack
Netzwerkgrundlagen - Von Ethernet bis IP
Angewandte Netzwerkgrundlagen reloaded - von Layer 1 bis 3
Contemporary Linux Networking
Building your own sdn with debian linux salt stack and python
6.Routing
Operationalizing VRF in the Data Center
AS201701 - Building an Internet backbone with pure 1he servers and Linux
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
LinuxCon 2015 Linux Kernel Networking Walkthrough
Xpress path vxlan_bgp_evpn_appricot2019-v2_
Cilium - API-aware Networking and Security for Containers based on BPF
Linux Kernel Status Report for IEEE 802.15.4 & 6LoWPAN
DevConf 2014 Kernel Networking Walkthrough
OpenNebulaConf2018 - Scalable L2 overlay networks with routed VXLAN / BGP EVP...
Networking Fundamentals: Local Networks
Cilium - Fast IPv6 Container Networking with BPF and XDP
The Spectre of Meltdowns
The Next Generation Firewall for Red Hat Enterprise Linux 7 RC
Ad

Similar to Best Current Operational Practices - Dos, Don’ts and lessons learned (20)

PPTX
Commissioning, Managing & Troubleshooting Industrial Networks
PDF
Path Solutions Network Monitor V4 Glossy
PPT
The 3 aspects of network performance management
PPT
network-management Web base.ppt
PPT
Monitor and manage everything Cisco using OpManager
PPTX
Monitoring network performance- Part 3_Free OpManager training
PDF
1 to 100 Master All Steps of Deployment, Seamless Integration, and Migration ...
PDF
Model-driven Network Automation
PDF
Presentation data center design overview
PDF
PLNOG 8: Merike Kaeo - Guide to Building Secure Infrastructures
PPTX
Security at the Speed of the Network
PPTX
OpManager Technical Overview
PPTX
Opmanagertechnicaloverview 160128123947
PPTX
Overview OpManager
PDF
Proactive monitoring tools or services - Open Source
PDF
Quick wins in the NetOps Journey by Vincent Boon, Opengear
PDF
NETFLOW ANALYZER 9600 - AN OVERVIEW
PPTX
New OpManager v12
PPT
Genesys System - 8dec2010
PPTX
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Commissioning, Managing & Troubleshooting Industrial Networks
Path Solutions Network Monitor V4 Glossy
The 3 aspects of network performance management
network-management Web base.ppt
Monitor and manage everything Cisco using OpManager
Monitoring network performance- Part 3_Free OpManager training
1 to 100 Master All Steps of Deployment, Seamless Integration, and Migration ...
Model-driven Network Automation
Presentation data center design overview
PLNOG 8: Merike Kaeo - Guide to Building Secure Infrastructures
Security at the Speed of the Network
OpManager Technical Overview
Opmanagertechnicaloverview 160128123947
Overview OpManager
Proactive monitoring tools or services - Open Source
Quick wins in the NetOps Journey by Vincent Boon, Opengear
NETFLOW ANALYZER 9600 - AN OVERVIEW
New OpManager v12
Genesys System - 8dec2010
Adopting SD-WAN With Confidence: How To Assure and Troubleshoot Internet-base...
Ad

Recently uploaded (20)

PDF
Introduction to the IoT system, how the IoT system works
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
presentation_pfe-universite-molay-seltan.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PPTX
Internet___Basics___Styled_ presentation
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PDF
The Internet -By the Numbers, Sri Lanka Edition
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PPTX
SAP Ariba Sourcing PPT for learning material
PPTX
Funds Management Learning Material for Beg
PDF
How to Ensure Data Integrity During Shopify Migration_ Best Practices for Sec...
PPTX
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPTX
522797556-Unit-2-Temperature-measurement-1-1.pptx
Introduction to the IoT system, how the IoT system works
The New Creative Director: How AI Tools for Social Media Content Creation Are...
presentation_pfe-universite-molay-seltan.pptx
international classification of diseases ICD-10 review PPT.pptx
Design_with_Watersergyerge45hrbgre4top (1).ppt
Decoding a Decade: 10 Years of Applied CTI Discipline
Internet___Basics___Styled_ presentation
Introuction about ICD -10 and ICD-11 PPT.pptx
The Internet -By the Numbers, Sri Lanka Edition
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Paper PDF World Game (s) Great Redesign.pdf
INTERNET------BASICS-------UPDATED PPT PRESENTATION
SAP Ariba Sourcing PPT for learning material
Funds Management Learning Material for Beg
How to Ensure Data Integrity During Shopify Migration_ Best Practices for Sec...
CHE NAA, , b,mn,mblblblbljb jb jlb ,j , ,C PPT.pptx
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
SASE Traffic Flow - ZTNA Connector-1.pdf
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
522797556-Unit-2-Temperature-measurement-1-1.pptx

Best Current Operational Practices - Dos, Don’ts and lessons learned

  • 1. Best Current Operational Practices FrOScon 13 Network Track Falk Stern, Maximilian Wilhelm 1 / 16
  • 2. Agenda 1. Who are we? 2. Do 3. Don't 2 / 16
  • 3. Who's who Falk Stern Full Stack Infrastructure Engineer IPv6 fanboy Runs his own Kubernetes cluster in his basement Consultant @ Profi Engineering Systems AG Contact @wrf42 falk@fourecks.de 3 / 16
  • 4. Who's who Maximilian Wilhelm Networker OpenSource Hacker Fanboy of (Debian) Linux ifupdown2 Occupation: By day: Senior Infrastructure Architect, Uni Paderborn By night: Infrastructure Archmage, Freifunk Hochstift In between: Freelance Solution Architect for hire Contact @BarbarossaTM max@sdn.clinic 4 / 16
  • 7. Have Infrastructure Logserver Graylog NTP service Logging is useless if every device has a different time Monitor Icinga 2 LibreNMS (editor's choice!) Configuration Management oxidized rancid Have DNS (forward and reverse) Maintain it!!1elf! 7 / 16
  • 9. Use managed switches They are worth the extra cost Enable Spanning Tree Known to save asses more than once Use redundant paths Always keep a spare device handy Layer 2 pitfalls 9 / 16
  • 10. Layer 2 pitfalls Enable VTP transparent mode Disable Dynamic Trunking Protocol Always use LACP active mode Always use LACP, not PagP or static Etherchannels 10 / 16
  • 11. Segment your network Build small Layer 3 islands Route where you can, switch where you must Routers gonna route, only Jeff bridges familiarize with dynamic routing protocols 11 / 16
  • 12. Get to know Linux flexible, versatile OS for everything Use it for infrastructure tasks 12 / 16
  • 13. Don't rely on vendor features 13 / 16
  • 14. Security Disable proxy arp Hosts should have only a single upstream interface Review your firewall rules regularly Have some Use source code management for configurations 14 / 16
  • 15. Security - Live at Network Track ¯(ツ)/¯ Sehr geehrte Damen und Herren, Cisco Smart Install (SMI) ist eine Funktion zur automatischen Konfiguration von Netzwerk-Switches. Diese wurde zur Verwendung in lokalen Netzwerken entwickelt und sollte nicht aus unsicheren Netzen wie dem Internet zugreifbar sein. [...] CERT-Bund hat von einer externen Quelle Informationen zu IP-Adressen in Deutschland erhalten, auf denen ein Cisco-Gerät mit aktiver Smart-Install-Funktion offen aus dem Internet erreichbar ist. Cisco empfiehlt, die Smart-Install-Funktion zu deaktivieren. [...] Betroffene Systeme in Ihrem Netzbereich: "asn","ip","timestamp" "39225","194.107.207.35","2018-08-24 12:08:43" "39225","194.107.207.37","2018-08-24 12:19:03" Mit freundlichen Grüßen das Team CERT-Bund Bundesamt für Sicherheit in der Informationstechnik (BSI) Referat CK22 - CERT-Bund Godesberger Allee 185-189, 53175 Bonn, Germany 15 / 16
  • 16. Being part of the DFZ Use BCP38 (Ingress filtering) Use filters on your BGP sessions Maximum Prefixes IRR filters RSPL filters Filter Bogon Prefixes Use communities Customer / Peering / Transit / IXP ... 16 / 16