Docker Compose for Your Home Lab, Part 1: A Container Is Not a Tiny VM
Three months ago you ran a docker run command from a blog post and got Pi-hole working. Three weeks later it died on a reboot and never came back.
Three months ago you ran a docker run command from a blog post and got Pi-hole working. Three weeks later it died on a reboot and never came back.
Three months ago you ran a docker run command from a blog post and got Pi-hole working. Three weeks later it died on a reboot and never came back.
You finally caved and started using Claude. You opened a new chat and typed something like this. prompt My BGP session keeps dropping. How do I fix it? What came back was a CCNA-level checklist.
Somebody asks in standup: “why did we change the ACL on edge-fw-02 last quarter? Who did it, and what else did they touch?” You know the answer lives in the repo.
192.168.10.37/26. Network, mask, broadcast, first host, last host, usable count. No calculator, no cheat sheet. If you rattled all six off without breaking stride, you got your reps in somewhere.
I’ve been listening to “you should care about IPv6” talks for two decades. I’ve given a few myself… so when Nick Buraglio took the stage at CHI-NOG 13, I knew the script.
Doyle had just wrapped his automation-framework talk, and Tyler Conrad was up next. Principal engineer at Arista, Austin, fifteen years split between customer-side and vendor-side.
I went into NFD40 thinking the AI networking pitches were going to be the marketing layer dressed up in new vocabulary, and I came out convinced it’s a different design problem.
This month RFC 10005 quietly became a Proposed Standard.
You’ve had git in your daily workflow for a few weeks. You’ve got the basics down, until you do one of these… You committed vault_password.txt and pushed it before your second coffee.
Brad Gorman’s ARIN workshop laid out where routing security stands today, ROAs you can trust, ASPA shipping, BGPSec quietly retired.
Declared bias up front. Jeff Doyle is a friend, but that doesn’t influence what comes next.
I sat in Brad Gorman’s RPKI workshop at CHI-NOG 13 with the kind of attention you give a talk when somebody on stage just admitted the security model has known holes.
“We haven’t announced any products yet.
Last Tuesday you made changes to a playbook because the on-call engineer needed an ACL pushed in a hurry.
Most “AI-powered observability” pitches you sit through ask you to trust the model.
Somehow I’ve never made it to CHI-NOG, the Chicago Network Operators Group’s annual gathering. That changes this year.
Dr. Deepak Kakadia got about ninety seconds into his NFD40 talk before he said the thing nobody else on the AI Ops circuit is willing to say out loud. LLMs were invented to model human behavior.
Alex Saroyan had about ninety seconds onstage before he made the architectural claim that the rest of the AI-networking conversation has been ducking.
Thomas Scheibe walked on stage and said the quiet part out loud.
Field Day vendors pay real money to get in front of a room full of independent engineers. These engineers have zero obligation to write a post, produce content, or even discuss anything they see.
Halfway through Tom Emmons’ scale-out segment at NFD40, a fellow delegate looked at Arista’s load-balancing slide and said what most of us were thinking… this could have any vendor’s logo on it.
Your AirPods just connected to the wrong device. Again. iMessage is taking twenty minutes to sync a message between your laptop and your phone sitting six inches apart.
So… the merch store is back. Don’t act surprised.
Cisco showed up to NFD40 selling two different pitches in the same session, and nobody on stage reconciled them.
Anyone who has managed carrier circuits for a living knows the pain. Quoting takes forever. Installs drag on with zero visibility.
I’ve been building networks for nearly thirty years. I understand leaf-spine fabrics, BGP design, VRF isolation, ECMP, and congestion management.
Every network engineer has that moment. You’re troubleshooting something, you reach for the tool that should exist, and it either doesn’t or it was last updated when Obama was in office.
I’m Heading to Networking Field Day 40 I’m excited to announce that I’ve been selected as a delegate for Networking Field Day 40, taking place April 8–10, 2026 in Silicon Valley.
If you’re a contractor, consultant, or anyone who VPNs into multiple client networks, you’ve experienced the pain. You connect to a Client’s VPN, and suddenly you can’t print to your local printer.
Yet another day brings another meeting about another security product recommending SSL Decryption at our network edge.
Routerjockey has transitioned to Hugo, a fast and flexible static site generator. Hugo utilizes a straightforward, markdown-like syntax for content creation, and has a robust theming system.
In 2012, we saw the launch of Viptela, a pioneer in SDWAN network solutions.
Gartner has been saying that “next big thing” in network security is the increased use of artificial intelligence (AI) and machine learning (ML) technologies for years now… Mainly because these …
As businesses continue to shift towards remote and distributed work environments, the need for secure and reliable network infrastructure has never been greater.
With the release of the new 9200 series switches many enterprise organizations are starting to look towards the future. Cisco has also been looking towards the future… of their profit margin.
But how does all of this relate to IT Infrastructure and Operations? AIOps is the combination of AI and IT Operations.
In the past I have personally given a lot of flack towards Gartner, but that was when I was in a different stage of my career.
I made a couple changes to the RouterJockey store this week and I wanted to make sure I got the word out. Previously the store worked in sprints that I tried to open up 2-3x a year.
Founded by Kunihiro Ishiguro and Yoshinari Yoshikawa the founders of GNU Zebra, came together to form IP Infusion back in 1999 as a commercial-grade, hardware-independent networking software company.
At times I have trouble focusing on writing articles for some of the presentations I am exposed to at Tech Field Day. Because of that, I really wanted to try something different.
Hey guys, I just wanted to drop a quick note to let you know that I’ve relaunched my teespring shirt campaigns with enough time that you should get your orders before Cisco Live US 2017.
During Networking Field Day 15 our friends from the Linux Foundation, including Lisa Caywood, briefed us on a recent “acquisition” from Cisco.
Yet again I find myself honored, and questioning their selection methods, by being selected for a Networking Field Day event. Networking Field Day 15 kicks off April 6 and 7th in San Jose California.
Whenever I start talking about network visibility and aggreagation taps I can’t help but think of The Matrix.
Forward Networks has stepped out of the shadows to announce their Network Assurance platform, and I was fortunate enough to be a delegate for Networking Field Day 13 to see their first public …
Looks like the culprit in the recent Cisco debacle is the Intel Atom “System on Chip” (SoC) that Cisco used in it’s gear.
A couple months ago many engineers started hearing rumors regarding an ISR 4331 recall, and problems surrounding the device.
This is going to be a busy week for the Tech Field Day family. They have delegates en-route to Tech Field Day 12 this morning, and Wednesday the crew for Networking Field Day 13 arrive.
Today’s IT landscape if full of software defined marketecture, and lore of a dystopian future full of network engineers that do nothing but write code.
In the past few months we have seen major outages from United Airlines, the NYSE, and the Wall Street Journal. With almost 5,000 flights grounded, and NYSE halting trading the cost of failure is high.
First, I want to apologize for not doing my job. Over the past couple years I’ve let this site become slightly stagnant.
Ok maybe that title is a bit grandiose… But due to the great response I received Friday morning from the launch of the original PCAP shirt, and the IPv6 follow-up, I decided to create a few new …
Some days I don’t know why I do things… But last night I was playing around with creating a PCAP meme when my friend Josh Kittle said he’d be interested in a t-shirt like that.
With ASA version 9.4 Cisco has added support for Elliptic curve cryptography (ECC), which is one of the most powerful types of encryption in use today.
Looking for the printable version? This list now lives as a cheatsheet at /tools/well-known-intervals/ — same data, scannable card layout, with a “Print / Save as PDF” button for taking it with you.
Today is a good day. By a 3-2 vote, the FCC has voted to adopt net neutrality rules to protect the open Internet.
Cisco just announced to the Cisco Champion community that the guest speaker for the keynote is going to be none other than …… Mike Rowe!!
BGP Communities has to be one of my favorite features added to the BGP protocol.
Yes, you heard me right. Aerosmith! One of the most looked forward to social events for Cisco Live has always been the Customer Appreciation Events (CAE).
Thank you Ed Koczan for sharing the video that led me to find this video. It’s a national treasure for those of us that appreciate binary.
After much waiting from all of us, Cisco has released, on “cyber Monday” no less, VIRL.
Some of you may have heard that Jeff Fry has published his Unofficial JNCIE-ENT Prep Guide, but how many of you have purchased it yet?
Before we get into the how, let’s talk about the why.
Since the dawn of time people have skirted best practice and banged together networks, putting the proverbial square peg in the esoteric round hole.
This week at Interop NYC, Cisco launched it’s ISR 4000 Series. This is a new approach for them focused on delivering services to your branch offices.
I generally try to avoid oversharing when it comes to my thoughts about presentations, but I have to mention that after sitting down with Glue Networks and their “SDN” presentation, it was truly a …
As of ACS v5.4 Cisco has finally included VMware tools for their ADE OS.
Quite a while ago I had a need for some network duct tape… Policy Based Routing while useful should only IMHO be used as a temporary fix.
Over the years IT professionals have sat through countless presentations, conference calls, and keynotes.
As many of you know my background isn’t in enterprise, but I currently fill that role in my $job.
Mid December 2012 Apple shut down the Messages Beta for Lion, soon after many hackintosh users started noticing issues with signing into iMessage.
Recently I was faced with an issue outside my normal expertise… those of you that know me realize I am anything but a security engineer. But in reality, you must always expand your horizons.
Vi is arguably the best text editing software in the world. There, I said it… deal with it!
My feelings towards the Nexus 2000 Fabric Extender (FEX) are hardly a secret. The myriad of design choices and platform limitations present engineers with some rather difficult decisions.
INE published a great info-graphic on the earning potential of Cisco’s certifications and I felt the need to share it here.
In situations where service providers want to offer transparent LAN services that preserve a customers VLAN tags across your Layer-2 network, this amendment to the IEEE 802.
Since I’ve recently had some fun working with the Cisco 5585-X and the IPS blades, I wanted to document some of the information I learned while getting them online.
As a follow up to my blog post covering Vim on the PacketPushers blog, I wanted to share with you another time saving tip for getting our jobs done not only quickly, but helping to remove one of the …
Recently I’ve been lucky enough to be challenged with learning a bit about Fibre Channel Switching, but I’m even luckier in that I’m getting to know it on a set of MDS switches running NX-OS …
Our second visit on day 2 of Networking Field Day was Brocade, who incidentally supplied us with a great lunch!
The second day of Networking Field Day 2 started early at the Juniper EBC, luckily Abner Germanow was prepared with breakfast for the weary and slightly hung over delegates.
I could’ve just as easily called this article Gigamon… fixing problems you didn’t know about or Why Gigamon scares the crap out of me — but I wont, because they already did!
NEC is currently the only Vendor that is shipping an OpenFlow enabled product today. So naturally, their presentation led off with a message about what they’re bringing to the market.
During the coarse of NFD2 I found an iPhone app called Halftone, and later, one named ComicStrip that allow you to add some fun effects and speech bubbles to your photos… So, I started in on some of …
First of all, I want to say thank you to everyone from Cisco Systems for inviting us into the CCIC (Cisco Cloud Innovation Center), this was an amazing room to hold our discussions.
Well, here is the update that I promised you. I’ve spent the last few days with some of the top minds in Networking industry.
What is OpenFlow? OpenFlow is a proposed standard for exchanging flow data between controllers and networking devices.
As I feel this may be a regular section of the blog due to my lack of availability. Please suggest a better name for this “series”.
Have you heard the news?
Ever get locked out of a router or switch that is many hours or even days away? Recently, I had the pleasure, again.
My most recently collection of interesting bits of data found out on the blogsphere/internets. Due to my lack of time, I’ve decided to recycle what I find out on the ‘net and share it here.
Everyone has different views on hardening IOS, and while I do not claim to be an expert, these are the practices that I commonly use when bringing up a new device.
As many of you may know, I’m in the middle of a huge network redesign, last week our new firewalls finally arrived and it became time for us to start migrating services onto the edge network I’ve been …
I’ve never had the opportunity to really do much with F5 load balancers in the past, but recently one our system engineers needed some load balancing setup, and wanted to know if we could assign some …
Next generation data centers across the world are taking advantage of Cisco’s Virtual PortChannel.
Rather quietly, at least I never heard anything, on July 29th, Cisco released NX-OS Version 5.2(1) for the Nexus 7000 platform.
This morning several CCIE candidates received an email stating that on August 1, 2011, Cisco will be raising the cost for the CCIE lab from $1,400 to $1,500.
It’s been a tough week since I left Las Vegas.
Following the current popular topic of “Whats in your toolbag?” ala Stretch and Fryguy. I’ve decided (after some persuading) to detail the contents of my own bag.
IP SLA is a function of Cisco’s IOS enabling you to analyze a Service Level Agreement (SLA) for an IP application or service.
I finished up most of my registration for Cisco Live 2011 / #cl11 yesterday and figured I would put up a copy of my schedule.
Ever since Cisco released IOS 12.0.1T we’ve had the ability to broaden the reach of the extended ACL to allow the influence of time.
I got asked a rather interested question the other day.
Can you imagine a video conference taking place on a primarily T1 based WAN? Multiple copies of the same video stream being unicast from the host to each participant.
We all know how stressful our jobs can be.
Switch Virtual Interfaces, or SVIs on Cisco IOS use a feature called autostate to determine the interface availability.
Yesterday, work presented an interesting issue I wanted to share with everyone.
Most enterprise networks use BGP to peer with their Internet Service Providers if they want to be multi-homed.
The Nexus 1000V is a software-based Cisco NX-OS switch that integrates into VMware vSphere 4 and operates inside the VMware ESX hypervisor.
Striving to reach that last 9? Looking for a way to increase your uptime while still being able to do maintenance on your network? Wish you could shutdown your OSPF neighbors like your BGP peers?
Less than a year after changing the rules with ASA version 8.3, Cisco has released a new OS version 8.4.
Tired of setting up SPAN sessions? Need to do some packet analysis? Since IOS 12.4(20)T Cisco has made Embedded Packet Capture (EPC) available.
The Nexus 7000 and 5000 series have taken port-channel functionality to the next level by enabling port-channels to exist between links that are connected to different devices.
Whether your networking lab has 3 devices or 30 an access server, also commonly called a terminal server, is the vital connection between you and those devices.
In the world of first hop redundancy, we have plenty of choices. In order to make the right decision for your network you should know the basics regarding all three.
Previous thoughts on load balancing BGP were that it is not a load balancing protocol and in order to achieve any sort of balanced traffic you would have to perform some sort of route balancing.
Greg Ferro of Etheralmind.com has started a petition asking Cisco to embrace those who pursue Cisco’s certifications a legal course of licensing without the cost of building a home made space shuttle.
Cisco IOS has plenty of gems contained within, but few are as fun, and as endlessly useful as the Embedded Event Manager, or EEM.
Learning the particulars of Cisco IOS is one of the most valuable things a network engineer can do. These skills will be the basis of everything you do on the lab and on your network.
The Cisco IOS archive command is not only very useful in keeping configuration archives, but it can also be used to log commands entered into the router, along with their user name.
The concepts behind Private VLANs are in fact rather simple, but it is quite easy to get discombobulated in the details.
Bidirectional Forwarding Detection (BFD) is a UDP-based protocol that provides fast (very fast!) routing protocol independent detection of layer-3 next hop failures.
A while back, I was playing on a 3750 switch in a customers lab and came across something I’ve never seen before. It seems that some Cisco switches have a built in Time-domain reflectometer, or TDR.
Unlike subnet masks, wildcard masks allow you to use discontiguous bits which enable you to match on a range of values.
As a followup to my previous post on Regular Expression Basics, I wanted to give a few examples on using them on Cisco IOS.
At times, the ‘rules of BGP’ don’t fit the needs of our productions networks. When we get into today’s production networks how often do book configurations apply? I’ll tell you one thing.
Recently, an update to all jailbroken phones could of caused major damage to anyone who uses Rock… There were several community updates in the last few days due to the iPad and new Jailbreak release.
This is the fourth and final part of my Cisco voip basics series. ( Parts 1, 2 & 3 ) Our goal in this series has been setting up a working voice gateway that you could use in your home office.
Have you ever needed to access a site that had an IP restriction, or one inside your remote network?
Netcat or nc, is a forgotten tool in too many arsenals these days. It lays dormant waiting at the command line to make connections across the globe for you.
Ever wanted direct network access to your Dynamips lab? Have you ever needed to lab something that used the SDM, but you run Dynamips under OSX?
Policy based routing is the process of altering a packets path based on criteria other than the destination address, commonly referred to as ‘policy routing’.
Anyone that has touched a computer these days has probably heard of ping. But very few know of its true origins these days. The following is based off the original developer, Mike Muuss’s website.
Recently a “colleague”, I use that term very loosely here, was reviewing my recommendations for changes on his network.
This is a follow up to my previous Hackintosh post chronicling the build and setup of my ‘Hack Pro’.
Over the past couple months, the lack of desktop here at home has driven me up the wall.
This is one of those tricks you wish you learned about 10 years ago, but never did. You know how easy it is to mess up a nice looking access list.
A while back I asked everyone to vote on what topic they wanted to see next, and by no surprise almost every voted for MPLS VRFs.
As a follow up to my JunOS Olive tutorial, I made a demonstration video that shows Multicast functioning via OSPF to another Olive and an ImageStream VM.
Interested in trying out JunOS? Can’t afford to build a real Juniper lab? Sounds like you need some Olives.
As you may know, I am not big in the server world, even less into mail servers. They make me sick.
One of the most common questions I get concerns path selection within the router.
This is the third part of my Cisco voip basics series. ( Parts 1, 2 & 4 ) Our goal is to help you configure a Cisco voice gateway that you could use in your home office.
Snow Leopard was released on August 28th, and at 1:37pm I received my copy and proceeded to install it like a well trained puppy.
Got a Mac ? Got a Linux box that you use as a file server on your home network? Sick of problems with samba?
This is the second part of my Cisco voip basics series. ( Parts 1, 3 & 4 ) Our goal in this series is to setup a working voice gateway that you could use in your home office.
Ever thought you might be having some Layer 4 connectivity issues? Pings as you should know are ICMP transmissions and ICMP is a Layer 3 protocol (commonly used to send error messages).
This is the first part of my Cisco voip basics series. ( Parts 2, 3 & 4 ) VOIP is obviously becoming a large part of networks, even now part of your CCNP requirements are basic voip knowledge.
Recently, I was using one of my custom short cuts and fat fingered the F12 key on my laptop… What resulted was my screen shutting off.
This summer I learned about a fantastic offer from Juniper to ‘fast track’ you into a certification.
For some, BGP is a rather large obtrusive beast of a protocol that scares them half to death.
One of the most effective lab setups uses frame relay as its primary transport method. This is a configuration that many people use and praise for its ease of setup and maintenance.
Seriously… Why haven’t we seen this yet? This is the perfect application for the dashboard.
How many times a day do you issue a show command from configuration mode ? If you’re anything like me, its enough to get annoying.
This week I’ve started setting up a VOIP lab to explore the technology and when I’m done, I plan to integrate it into my home network.
Here are a few settings you can change using the OS X defaults command to access some system parameters. As always, proceed with caution, and don’t mess with things of which you have no clue.
Ever accidentally set your config register to a random value that isn’t in the Cisco documentation? No? Neither have I, but one day I encountered someone on #cisco that had.
This is one of the methods I’ve used in the past to secure a Linux host against brute force ssh attacks.
Before I even get started, I want to mention that not all regular expression metacharacters are supported in every application. Keep this in mind when building your matches.
So, I’m sure these have been posted almost on every networking blog under the sun, but who knows, right?
So, I purchased a couple extra routers, and a second layer3 switch from @usedciscoguy. He gave me a really good deal and I plan on purchasing a 6500 series switch from him as soon as I can afford it.
One of the things I used to deploy frequently at my previous position was transport for other ISPs and businesses.
Recently one of my clients asked me to help resolve an issue at an aggregation point on their network.
One of the questions I get asked several times a week by my clients is as such.
As I started building this lab, I realized that I had to find a refresher course on the IOS naming conventions.
Everyone does a fair amount of googling these days, but any network engineer can tell you that a quick ARIN whois search can be invalueable. I know I end up there quite often.
So, I had to reinstall Vista on my mac today — hadn’t touched it since I moved onto the Late 08 model… and once again, I started getting the common partition errors while Vista loads the bootloader.
PullTab is no longer maintained or supported. I’ve removed broken links within this article….
Ok — this is my first script that I’m posting here. Its a VERY simple ssh wrapper script that you can place in your path, preferably in ~/bin bash #!
I’ve been pondering it for quite some time, but yes now I have switched to Mac. I purchased a new 2.5ghz, 4gb of Ram, 15″ Macbook Pro.