Network died, hard, during company Christmas party, leaving lone techie to fix it
- Reference: 1689578893
- News link: https://www.theregister.co.uk/2023/07/17/who_me/
- Source link:
This week meet a reader we'll Regomize as "Roy" who was contracted to a very large corporation. The company in question was upgrading the core switches on its network from Cisco 4500s to "the shiny new Cisco Nexus 7000 series" – that should give some idea of when this was happening.
As our story begins, the shiny new 7000s were in place and operating in parallel with the existing 4500s. All that remained was to "move all the root bridges for the vlans from the 4500 to the 7000."
[1]
How hard can that be? Sounds like a doddle. Roy does mention that there were some 80 of these switches distributed about the building, so maybe a little bit tricky.
[2]
[3]
Also, the plan was to switch the Nexus switches to use VTP, or VLAN trunking protocol. That should, Roy believed, involve sending a single command to the main switch – again, not a big deal for a resourceful guy like Roy – and the change would ripple out across the network.
He timed the changeover for the night of the company Christmas party, which he did not plan to attend. The idea was that with everyone celebrating the season, network downtime (Roy predicted about half an hour) would not cause a loss of productivity.
[4]
All appeared to go well at first. In fact Roy was on his way out of the building when the security guard in the foyer stopped him.
There was a problem. All of the security camera feeds had gone blank.
Roy tried to log into the network to investigate, and found he was locked out. He used his console to access the switches directly, and found that authentication was down. In fact, the entire VLAN was gone.
[5]
This could only mean one thing.
[6]Turning a computer off, then on again, never goes wrong. Right?
[7]Hacking a Foosball table scored an own goal for naughty engineers
[8]Security? Working servers? Who needs those when you can have a shiny floor?
[9]Data cleanser did its job, but – oopsie! – also doubled customers' bills
No, not terrorists, nor even exceptional thieves. It meant Roy had to reconfigure each and every individual switch manually. All 80 of them. And it had to be done before work in the morning, or his bosses at Nakatomi – er, actually that very large corporation – would not be well pleased.
Welcome to the party, pal.
It transpired that for VTP to work, the command had to be sent to each of the switches – not just one of them. Roy had not done that.
So he made his way around the building (he does not specify using the air conditioning ducts, but we like to imagine), reversing the changes he'd made to the Nexus switches and manually reconfiguring each one with the appropriate VTP command to get the VLAN working again.
What had been scheduled for half an hour ended up taking until 7:30 the following morning.
Ultimately it was a happy ending – thankfully without any inferior sequels.
Have you ever encountered a technical snafu that could potentially be adapted into a popular seasonal action flick? Tell us all about it in [10]an email to Who, Me? and we'll share it with the world.
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/sysadminmonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLURR9jH2hWds0bXTWcXRQAAAYY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/sysadminmonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLURR9jH2hWds0bXTWcXRQAAAYY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/sysadminmonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLURR9jH2hWds0bXTWcXRQAAAYY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/sysadminmonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLURR9jH2hWds0bXTWcXRQAAAYY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/sysadminmonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLURR9jH2hWds0bXTWcXRQAAAYY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/07/10/who_me/
[7] https://www.theregister.com/2023/07/03/who_me/
[8] https://www.theregister.com/2023/06/26/who_me/
[9] https://www.theregister.com/2023/06/19/who_me/
[10] mailto:whome@theregister.com
[11] https://whitepapers.theregister.com/
The marvels of VLANs on Cisco switches. Still having nightmares about switches deleting their entire VLAN database and entering all ports in VLAN1.
"for VTP to work, the command had to be sent to each of the switches"
So he was operating on faulty assumptions. I don't want to be harsh, but it seems that an admin should always check that what he's doing is the right thing, otherwise mayhem might ensue.
He didn't make sure, and he paid the price (one lost XMas evening).
I'm not necessarily saying that an admin should consult the manual every time, but I would have thought that, just before sending a command that should reconfigure the entire network (not something you do every day, I guess), it might be a good thing to double-check and be sure.
Oh well, he's learned his lesson.
Re: "for VTP to work, the command had to be sent to each of the switches"
I'm not necessarily saying that an admin should consult the manual every time, but I would have thought that, just before sending a command that should reconfigure the entire network (not something you do every day, I guess), it might be a good thing to double-check and be sure.
sounds logical but the manual is normally thousands of pages long and often obscure language that means mistakes happen even though the manual has been consulted.
the only way to be sure is to lab it, not with all 80 switches but certainly at least 5 and see if the command does "behave" as expected.
VTP is something that sounds great but truly not.
Its like L2 domains with spanning tree everywhere, just do yourself and everyone a favour and migrate to routed links. spanning tree is the work of the devil and will kick you hard when it gets large
Re: "for VTP to work, the command had to be sent to each of the switches"
Failing to RTFM and causing downtime for a large environment (80 switches and the intention to move to Nexus 7Ks suggests it's likely north of 2000 end user ports) that you then have to fix was 1990s cowboy IT rather than late noughties/early twenty teens behaviour. Even StackOverflow/Serverfault would likely have had the 2-minute summary given the Nexus 7000 came out in 2008.
If you don't have time to learn then get in touch with a friendly reseller or contractor that knows what they are doing.
It will save your time for something considerably more valuable than donating it to the company as an early Christmas present.
VTP often considered a security risk
Most places i've been to its been disabled.
1 site we did a network replacement & it was a mess, story was a previous admin based on site went on a training course and implemented vtp when he returned, caused a huge outage and was disposed off shortly after.
the legend was no one wanted to clean up his mess so a switch replacement project later and his mess remained. Discussions of should we not just remove it now resulted in deep intakes of breath and mutterings of more than my jobs worth etc.
taking the hint i just replaced the hardware with equivalent config, the inference being it worked before i did anything & it still worked once i left so no controversy from me. The fact we knew a new outsourcer was incoming also reduced the desire to meddle.
Reason why VTP is considered a security risk is that a malicious person can impact all switch vlan config from 1 place, or add/delete/modify vlans etc. Also a lab switch with a later vland db version can amend the db's of an established environment detrimentally. It can be secured but most people didn't bother.
https://community.cisco.com/t5/switching/stay-away-from-vtp/m-p/2462239/highlight/true#M292198
Well done on spinning Nakatomi in.
"I now have root access. Ho Ho Ho".
ObXKCD
[1]Sysadmin
[1] https://xkcd.com/705/
Yippee ki-yay, motherboard.
I can just see...
An office chair with a note saying "now I have a network analyser" taped to it