[AusNOG] Removing the four stale TAL from the APNIC RPKI validation set.

2018-02-26 Thread George Michaelson
Updating RPKI trust anchor configuration --- APNIC has completed the process of transitioning from its previous Resource Public Key Infrastructure (RPKI) trust anchor arrangement to a new single trust anchor configuration. Each RIR will publis

Re: [AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread Bill Walker
Hi Daniel, As it looks like I've already posted most of what you want, I'll share it with the list: http://www.wjw.co.nz/2016/09/cleanly-shutdown-esxi-60-and-synology.html http://www.wjw.co.nz/2016/09/installing-vmware-cli-tools-on-linux.html http://www.wjw.co.nz/2017/08/perl-script-to-shutd

Re: [AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread Bill
Sounds like small scale with a UPS that size At home I have a smart-UPS 1500. I pass serial comms from the APC UPS to a Linux VM that runs APCUPSD, there are scripts that are triggered by ups events that nicely shutdown my vm’s and NAS devices in the correct order to avoid data corruption. Wh

Re: [AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread Robert Hudson
Most UPSs can send a signal around their power state via serial or USB. ESXi has, if I recall correctly, the ability to recognise this. Some vendors have additional software to make it work better. The trick becomes being able to shut the VMs down (and then the host) before power is lost. I am no

Re: [AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread JORDI PALET MARTINEZ
I use APC PCNS (I’ve updated them to the latest version available December 2017) and updated my ESXI from 5.5 to 6.5 and everything is working fine. Regards, Jordi De: AusNOG en nombre de Christopher Hawker Fecha: martes, 27 de febrero de 2018, 9:39 Para: Daniel Watson , "ausnog@lists.au

Re: [AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread Christopher Hawker
Hello Daniel, I'd have a look at APC UPS Daemon - http://www.apcupsd.com/. "Apcupsd can be used for power mangement and controlling most of APC’s UPS models on Unix and Windows machines. Apcupsd works with most of APC’s Smart-UPS models as well as most simple signalling models such a Back-UPS

Re: [AusNOG] Mikrotik IKEv2 > Cisco IOS

2018-02-26 Thread Jason Leschnik
Hey Cameron, I haven't done this configuration personally but have you tried labbing this in GNS3? Use the Mikrotik appliance and if you do it all on Linux it's a fairly smooth process to setup. It might help to cutout the WAN as being an issue if this isn't something you're testing in a lab. Jus

Re: [AusNOG] Best practices on speeding up BGP convergence times

2018-02-26 Thread Rhys Hanrahan
Hi Guys, Thanks David for confirming BFD is the way to go here. Luckily, I have been able to enable BFD on all my transit links so far, so the time to detect peer failure has been quick. And thanks Geoff for your detailed reply. From some off-list discussions, I think that I first need to appl

Re: [AusNOG] Best practices on speeding up BGP convergence times

2018-02-26 Thread Alex Samad
Hi Add in my experience. I have multiple upstreams, I advertise to all upstreams at the same time, I am not sure why you wouldn't do that. Maybe to control the reverse path. I preference by stuffing AS - seems to work well for us. But I ran into issue with convergence. 1) time it would take fo

[AusNOG] UPS Compatibility with ESXI 6.5 Communication

2018-02-26 Thread Daniel Watson
Hi Members, Just seeking some input on/off list for recommendations for any entry level’ish UPS’s that would be compatible with communication through USB to shutdown an ESXI environment upon loss of power. I have taken a decent look around at some of the available models on the current market

[AusNOG] Mikrotik IKEv2 > Cisco IOS

2018-02-26 Thread Cameron Murray
Guys, Has anyone had any success with this configuration? We've spent a few hours today trying to get the connection to come up. Requested configuration: https://ibb.co/gBrmsc The cisco is reporting: *Failed to receive the AUTH msg* before the timer The Mikrotik is re transmitting Phase 1 unti

Re: [AusNOG] Best practices on speeding up BGP convergence times

2018-02-26 Thread David Hughes
On 26 Feb 2018, at 9:52 pm, Geoff Huston mailto:g...@apnic.net>> wrote: a) detecting link down quickly You can adjust your BGP session keepalive timers to smaller values and make the session more sensitive to outages as a result. I also thought that these days you can get the interface statu

Re: [AusNOG] Best practices on speeding up BGP convergence times

2018-02-26 Thread Geoff Huston
I’m not sure that we have a clear idea of what “convergence" means in this this context. lets try to walk through this. If you are referring to the amount of time it takes for a distance vector protocol like BGP to get to a point where there are no further updates to a routed prefix, then the co

Re: [AusNOG] Best practices on speeding up BGP convergence times

2018-02-26 Thread David Hughes
Hi It was at APRICOT but only dealt with how bad the default timers were in dealing with silent peer failure. If you’re running BFD then you aren’t waiting for timers to expire before tearing down the session so those details are largely irrelevant. For those that aren’t running BFD upstream