This is the weekly Network freak roundup for 2026-W40. It collects the latest practical networking articles published this week, so the X feed can stay quiet while readers still get all links in one place.
Pages
Usefull links
Categories
- ACI adoption (1)
- AI (23)
- AI Agents (14)
- AI Demos (1)
- AI Infrastructure (18)
- AI-ready infrastructure (1)
- AI‑ready networks (1)
- Anthropic (14)
- App-ID (1)
- Artificial Intelligence (3)
- Automation (12)
- automation and orchestration (1)
- Backup (2)
- BFD (1)
- BGP (48)
- BGP Attributes (8)
- BGP Communities (1)
- BGP Lab (1)
- BGP Table Watch (11)
- Capacity Planning (2)
- CCDE (1)
- CCIE (3)
- CCIP (1)
- CCNP (2)
- Change Management (2)
- ChatGPT (1)
- Cisco (2)
- Cisco ACI (1)
- Claude Code (5)
- Claude Fable 5 (1)
- Claude Opus 5.5 (13)
- Coding Agents (2)
- Cybersecurity (2)
- Data Center (52)
- data center trends data center automation (1)
- DC Notes (1)
- Design Guide (1)
- DHCP (2)
- EIGRP (5)
- Enterprise AI (1)
- EVPN (8)
- EVPN/VXLAN (10)
- F5 BIG-IP (6)
- Firewall (7)
- Firewalls (5)
- FlexAlgo (1)
- GitHub (1)
- GlobalProtect (1)
- Google Gemini (1)
- GPT-6 Astra (17)
- GPU Cluster (1)
- GPU Clusters (1)
- Grok (1)
- High Availability (2)
- Home Network (1)
- HPE (1)
- ICMP (1)
- InfiniBand (3)
- Internet Routing (11)
- Interview Questions (25)
- IOS configuration (9)
- IPv6 (11)
- IS-IS (2)
- ISP (1)
- Juniper (3)
- JunOS (1)
- Knowledge Work (1)
- L3VPN (1)
- LACP (1)
- Leaf-Spine (1)
- Linux Networking (1)
- LLDP (1)
- Load Balancing (6)
- Monitoring (14)
- Monthly BGP Report (2)
- MPLS (13)
- MPLS. (1)
- MX960 (1)
- NAT (1)
- NCCL (2)
- NetDevOps (2)
- Network Automation (12)
- network automation surveynetwork automation (1)
- Network Calculator (1)
- Network Design (7)
- Network Monitoring (1)
- network orchestration (1)
- Network Security (9)
- Networking (66)
- news (1)
- Nokia (1)
- NVIDIA (3)
- Off topic (2)
- OpenAI (5)
- OSPF (15)
- Palo Alto Networks (10)
- Panorama (2)
- photos (2)
- Power and Cooling (1)
- Prisma SD-WAN (2)
- Productivity (1)
- Projects (4)
- QoS (4)
- Ransomware (1)
- Redistribution (1)
- RoCE (1)
- RoCEv2 (2)
- Routing (33)
- Security (16)
- Segment Routing (2)
- Segmentation (1)
- Service Provider (19)
- Slurm (1)
- Small Business (1)
- SMB Networking (1)
- SR (3)
- SSL Decryption (1)
- Storage (1)
- Storage Networking (1)
- STP (4)
- Switching (9)
- TLS (1)
- Troubleshooting (74)
- User-ID (1)
- Vibe Coding (14)
- virtualization (1)
- VLAN (2)
- vPC (1)
- VXLAN (8)
- Weekly Roundup (5)
- xAI (1)
Network freak Weekly Roundup: 2026-W40
10/04/2026 | Filed Under Data Center, Networking, Weekly Roundup | 0 Comments
IPsec Phase 1 vs Phase 2 Explained: SAs, Crypto Maps and IKEv2
Short answer: In IKEv1, Phase 1 authenticates the VPN peers and establishes the IKE/ISAKMP security association that protects their negotiation; Phase 2 uses that protected channel to negotiate IPsec security associations for data traffic.[1] An established Phase 1 is therefore not proof that your application traffic has a working IPsec SA.
This is the distinction behind the interview question, “What is the difference between IPsec Phase 1 and Phase 2?” The terminology belongs to IKEv1: IKEv2 uses IKE_SA_INIT, IKE_AUTH and CREATE_CHILD_SA exchanges rather than the same two-phase process.[2] IKEv1 is deprecated; learn its terminology for interviews and legacy troubleshooting, not as a recommendation for a new deployment.[3]
10/04/2026 | Filed Under Firewall, Interview Questions, Networking, Security | 0 Comments
F5 BIG-IP Client IP Missing: X-Forwarded-For Troubleshooting Checklist
An application behind F5 BIG-IP works, but every access-log entry shows the load balancer instead of the visitor. Before disabling SNAT, separate two requirements: preserving the packet source address and conveying a client address in an HTTP header. BIG-IP SNAT changes the source address of a connection; an HTTP profile can insert client-address information into a request without undoing that translation.[1][2]
This troubleshooting guide provides a reusable decision table, a narrowly scoped NGINX configuration example, and an acceptance matrix for detecting spoofed or incorrectly trusted X-Forwarded-For headers. The examples are hypothetical and unexecuted on BIG-IP or NGINX; the workflow is an original operational recommendation, not a vendor-certified deployment recipe.
10/04/2026 | Filed Under F5 BIG-IP, Load Balancing, Security, Troubleshooting | 0 Comments
NAT vs PAT vs Static NAT vs DNAT Explained with Packet Flow
What is the difference between NAT, PAT, static NAT and DNAT? They describe different aspects of translation, not four mutually exclusive features: NAT is the umbrella, PAT includes transport-port mapping, static NAT fixes an address mapping, and DNAT changes a packet's destination.[1][2][3]
Short answer: Basic NAT translates IP addresses; PAT (called NAPT in RFC 3022) lets multiple internal endpoints share an external address using transport identifiers.[1] Static one-to-one NAT describes how the address mapping is assigned, while SNAT and DNAT describe whether the source or destination is rewritten.[2][3]
10/03/2026 | Filed Under Firewall, Interview Questions, Networking, Security | 0 Comments
Palo Alto User-ID Wrong User: IP Mapping Troubleshooting Matrix
An application is blocked for the right employee, but the Palo Alto firewall log shows a different username. Before changing the Security policy, answer a narrower question: which identity source associated this connection with that user, and was an IP address alone enough to identify them?
This guide provides a User-ID troubleshooting matrix, a read-only evidence workflow and a change-acceptance checklist. It focuses on incorrect or missing IP-to-user mappings, including the shared-IP case on terminal servers. All examples are hypothetical; commands are templates, not results from a production firewall.
10/03/2026 | Filed Under Palo Alto Networks, Security, Troubleshooting, User-ID | 0 Comments
Slurm Job Pending with Idle GPUs: A 256-GPU Sizing and Troubleshooting Checklist
A Slurm job can remain pending while a dashboard shows dozens of idle GPUs. Before buying more accelerators or changing the fabric, ask a narrower question: can the scheduler assemble the exact node, GPU, CPU, memory, policy and locality shape requested by this job? A cluster-wide free-GPU total is not enough to answer it.
This guide provides a 256-GPU capacity worksheet, a pending-job troubleshooting matrix, two original diagrams and a deployment checklist. The design and queue snapshots are hypothetical; the arithmetic was executed in Python. Configuration and diagnostic commands are unexecuted examples, not results from a production cluster. They require adaptation to your installed Slurm release and site policy.
10/02/2026 | Filed Under AI Infrastructure, Data Center, GPU Clusters, Slurm, Troubleshooting | 0 Comments
Monthly BGP Table Watch: Prefix and ASN Trends — September 2026
This monthly BGP Table Watch report summarizes how the public routing table changed over roughly the last 30 days, using the latest public Potaroo/CIDR Report samples available on 2026-10-01.
The goal is to provide a slower, more useful view than the daily snapshots: month-over-month prefix growth, IPv6 movement, visible ASN changes, and the route-churn areas worth watching.
10/01/2026 | Filed Under BGP, BGP Table Watch, Internet Routing, IPv6, Monthly BGP Report, Networking, Routing | 0 Comments
Administrative Distance vs Metric vs Longest Prefix Match Explained
Does a router choose the lowest administrative distance, the lowest metric, or the longest prefix? The answer depends on whether you mean building the routing table or forwarding a packet.[1]
Short answer: A routing protocol selects its candidates using its own path-selection rules; administrative distance (AD) selects between competing route sources for the same prefix and prefix length; longest prefix match selects the most specific installed route when forwarding a packet.[1] Do not treat these as three numbers compared together for every packet.[1]
10/01/2026 | Filed Under EIGRP, Interview Questions, Networking, OSPF, Routing | 0 Comments
Panorama Out of Sync: Commit and Push Troubleshooting Checklist
Panorama commit succeeded, but the firewall still shows an old setting—or the managed-device view says out of sync. Do not start by selecting Force Template Values. First identify which boundary failed: commit to Panorama, push selection, the firewall job, or the effective configuration on the target.
This guide provides a reusable troubleshooting matrix and push approval worksheet for that investigation. It is a proposed operational workflow, not a report of a production incident or an executed firewall test. Product behavior is grounded in the PAN-OS 11.2 Commit Operations reference and the vendor's Templates and Template Stacks page; check the matching documentation for your deployed release.[1][3]
10/01/2026 | Filed Under Firewalls, Palo Alto Networks, Panorama, Troubleshooting | 0 Comments
Route Redistribution Risks Between OSPF, EIGRP and BGP: Loops, Tags and Metrics
Route redistribution can make two routing domains reachable while quietly creating a path for routes to return to their origin. The interview question is: what can go wrong when redistributing OSPF, EIGRP and BGP, and how do you prevent it?
Short answer: the main risks are route feedback, unexpected path selection, incompatible metrics and unwanted prefix propagation; Cisco documents filtering and route-tag policies as ways to control these risks.[2] My recommended starting point is a narrow prefix allowlist, explicit target-protocol metrics, origin tagging with return-path rejection, and failure testing at every redistribution boundary.
9/30/2026 | Filed Under BGP, EIGRP, Interview Questions, Networking, OSPF | 0 Comments
F5 BIG-IP Server SSL Handshake Failed: SNI and Certificate Troubleshooting Matrix
A browser reaches the F5 virtual server, the pool looks healthy, yet the application fails after a backend certificate renewal. Before changing ciphers or disabling certificate checks, identify which TLS conversation fails. This guide provides a Server SSL troubleshooting matrix, a profile-review worksheet and a controlled acceptance test plan.
Scope: conventional BIG-IP LTM reverse-proxy TLS termination with re-encryption to HTTPS pool members—not TLS passthrough, SSL Orchestrator or forward proxy. Recommendations below are an original operational workflow, not results from a production incident or a completed lab. F5's BIG-IP 17.5.1 SSL administration guide is the main configuration reference; the older v14 TMSH reference is used only for explicitly identified command and field semantics.[4][3]
9/30/2026 | Filed Under F5 BIG-IP, Load Balancing, TLS, Troubleshooting | 0 Comments
EIGRP Metric and K-Values Explained: Formula, Examples and Troubleshooting
EIGRP metric questions usually test three things: which inputs matter by default, how bandwidth and delay combine, and why mismatched K-values prevent neighbors from forming.
Short answer: with default K-values, EIGRP uses minimum path bandwidth and cumulative delay; for classic metrics, the calculation is 256 × (10^7 / minimum bandwidth in kbps + total delay in tens of microseconds).[1]
K1 and K3 default to 1; K2, K4 and K5 default to 0, so load and reliability do not contribute to the default calculation.[1]
9/29/2026 | Filed Under EIGRP, Interview Questions, Networking | 0 Comments
RoCE PFC Buffer Sizing Guide: 400G Headroom Worksheet and ECN Checklist
A GPU cluster can pass a quiet link test and still collapse under synchronized traffic. Before buying switches with a bigger advertised buffer, ask a more precise question: how much traffic can arrive after a congested port requests a pause, and where can that traffic be stored? This guide provides a headroom worksheet, an incast calculation and a deployment test matrix for that decision.
The worked design is hypothetical: 32 servers, eight GPUs per server, and a selected 400 Gb/s Ethernet fabric. Calculations are executed arithmetic, not benchmark measurements or validated switch settings. The configuration examples are explicitly pinned to NVIDIA Cumulus Linux 5.9 documentation; they are not claims about the newest release or every Spectrum generation. Use your actual ASIC, network operating system and NIC support matrix before making changes.
9/29/2026 | Filed Under AI Infrastructure, Data Center, QoS, RoCE, Troubleshooting | 0 Comments
EIGRP Stuck in Active Explained: SIA Troubleshooting and Prevention
EIGRP Stuck in Active (SIA) means that a route's distributed computation has not received a required Reply within the permitted time; Cisco implementations can reset the unresponsive neighbor and remove routes learned through it.[1] For an interview, distinguish normal Active route computation from Stuck in Active, then explain how you would trace the missing reply and reduce query scope.[1][2]
9/28/2026 | Filed Under EIGRP, Interview Questions, Networking | 0 Comments
Weekly BGP Table Watch: IPv4, IPv6 and ASN Changes — 2026-09-28
The global BGP table keeps moving every day. This weekly BGP Table Watch snapshot tracks IPv4 prefixes, IPv6 prefixes, visible ASNs and the largest routing-table changes reported during the last week.
The goal is not to alarm on every change. BGP is noisy by design. The goal is to build a simple operational habit: watch the size of the routing table, notice large origin-AS changes, and keep an eye on where new ASNs and route withdrawals appear.
9/28/2026 | Filed Under BGP, BGP Table Watch, Internet Routing, IPv6, Networking, Routing | 0 Comments
Popular Posts
-
BGP neighbor states are the first place to look when a peering session does not reach Established. This older lab note explains how BGP u...
-
BGP message types are the protocol building blocks used after two peers establish the TCP session on port 179. This note keeps the origin...
-
Recently I've been gathering in my work all cisco equipment which I can use to lab. I have found few routers (2911, 1921, 1...
-
Quick summary: Cisco SPAN port mirroring copies traffic from a source interface or VLAN to a destination interface where you can connect W...
-
JUNOS upgrade on MX960 platform. Recently I have been participating in project where we had to upgade few big boxes in the network. ...