Welcome to my haven!

This is my little corner on the internet, were I write about my current projects, networking, security and everything else I encouner in my everyday work and studies. The projects are longer and more detailed, the normal blog post for my every day findings. Feel free to have a look around or reach out if you have questions or just want to say Hi!

RPVST - Behavior of RPVST and VLANs that are not allowed via trunk links

Today I encountered a scenario in which an HPE Aruba ProCurve switch (AOS-S), used as an access switch in a classic three-tier network topology, declares certain VLANs (in this case, VLAN 16) as root bridges. However, on the core switch, all VLANs are configured with a spanning tree priority of 4096 — see VLANs 12 and 53.

  VLAN  Root Mac        Root       Root       Root                 Hello
  ID    Address         Priority   Path-Cost  Port                 Time(sec)
  ----- --------------- ---------- ---------- -------------------- ---------
  1     f8f8f8-c3c3c3   32,768     0          This switch is root  2
  998   f8f8f8-c3c3c3   32,768     0          This switch is root  2
  999   f8f8f8-c3c3c3   32,768     0          This switch is root  2
  53    1bfdec-1bfdec   4096       2250       Trk1                 2
  12    1bfdec-1bfdec   4096       2250       Trk1                 2
  16    f8f8f8-c3c3c3   32,768     0          This switch is root  2

If you think about it, the reason is relatively clear. All VLANs that have been created on the switch participate in Rapid Per-VLAN Spanning Tree formation and also send different BPDUs per VLAN over a trunk link. If the VLAN is not permitted on the trunk, the BPDUs for that VLAN will never be sent over the trunk and therefore cannot negotiate with the neighboring switch to determine who will be the root bridge.

Cisco C8300 - Create dedicated Management Interface without OOB Port

The Cisco C8300 and C8200 routers doesn’t have an Out-of-Band-Management Port. Nevertheless you can create a dedicated management interface over an in-band port.

When using an in-band port for management access it is still going through the normal data plane. When you follow this post, creating an dedicated management port over an in-band port doesn’t make it magically an out-of-band port.

In order to accomplish this we would need to create a dedicated management VRF, assign it to the interface and limit the SSH access with an ACL. The management port can then be connected to the regular out-of-band management network over that port. In the following examples we are using the Gi0/0/0 port as a dedicated management interface.

IPSec (IKEv2) - Hub and Spoke Design

This blog demonstrate a possible IPsec hub and spoke design with IKEv2 and VTI. The focus here is on an IPsec configuration that is identical on all sides to ensure a consistent configuration. The basic design is shown in the figure below. image

Security considerations

In general, this example uses AES (CBC) with at least 256 bits. On newer Cisco routers, it is possible to use AES in GCM mode. GCM is the newer mode compared to CBC. However, there are potential security concerns with GCM if the initial vector is reused. One advantage of GCM is that it combines encryption and integrity, eliminating the need for an additional algorithm for integrity (as is the case with CBC).

Microsoft Windows offline activation in 2026

Microsoft deactivated the offline telephone activation back in december last year. But now in my current project we need to activate Windows Pro and the Office Suite in an offline enviroment. Microsoft established a new process which I think is working pretty good.

At first I read that the offline activation is not possible anymore for OEM licenses, but in the documentation page for the new activation process states that it is possible to activate Retail, OEM and Volume / CSP licenses in this portal.

Remove ConfigMgr client in task sequence during OSD deployment

I was busy the last few days creating a task sequence inside the Microsoft Configuration Manager (Config Mgr) or also known as SCCM in the past, where we remove the config mgr agent after the task sequence is finished. Sounds easy right? Well I thought so too, but it wasnt as easy as run ccmsetup.exe /uninstall as a command line argument.

What did not work

  1. I tried to run ccmsetup.exe /uninstall as a command line argument. In WinPE and full OS mode.
  2. All other forms of running the ccmsetup.exe /uninstall command inside powershell scripts.
  3. I found this script which kind of worked but it left a lot of remnant files in C:\Windows. Additionally the task sequence breaks directly after execution.

What did work

The cleanest way to remove the agent from the computer at the end of the task sequence is to use the build-in Prepare ConfigMgr Client for Capture method.

Cisco ignore startup configuration

The startup configuration can be bypassed by booting into ROMMON or during normal operation. In either case, a reboot is required.

This is particularly useful, for example, if you need to perform a password recovery because you have forgotten your password, or for troubleshooting purposes.

Configuration in IOS

Switch# configure terminal
! to activate
Switch(config)# system ignore startup-config

! to deactivate
Switch(config)# no system ignore startup-config

Configuration in ROMMON

In the background, the IOS command simply sets the ROMMON variable SWITCH_IGNORE_STARTUP_CONFIG to 1 or 0 which we can also do manually.

Fixing SCEP Certificate Enrollment over HTTPS on eLux Thin Clients

Currently we trying out eLux as an replacement of older thin clients with ThinOS or IgelOS. We tried to configure 802.1x authentication and the therefore needed certificate enrollment with our current SCEP/NDES server. We came across the issue that the scep client that eLux uses – sscep – an open source “Simple SCEP client for Unix” doesn’t support certificates requests over HTTPS.

When investigating the problem we found this GitHub issue which explains our problem. Our NDES server was only reachable over HTTPS – both on the administration page and most importantly also on the request web page (certsrv/mscep) where the client requests their certificates.