He is with us.
6 mins read

He is with us.

I few years ago I was dealing with a big problem… my switching network had some serious limitations… I inherited some 48 port POE switches that just didn’t performed that well anymore.

Some of the problems I had were: very slow initialization at boot up, web UI (the primary way to configure this switch) was using dated cipher suites and browsers such as Chrome wouldn’t even connect to it anymore.

I also have a huge problem with uplinks.. I only had 4 1GB SFP ports on that switch, and the switching capacity was only just above 100 Gbps. The only thing this switch had going for it was that I had a full 740W POE budget and it could power our POE phones no problem. I also wanted to have a master switch that I would uplink to and this brand didn’t really have that.

We were also needing to run some Fiber and I wanted to have a Fiber backbone between our switches so what I inherited only had 1Gbps Ethernet as a trunk. Finally, I noticed that when the network utilization got too high, the switches would become unresponsive or reboot – I was hitting their maximum capability.

I had learned Cisco but we can’t afford Cisco and I wasn’t in love with the small business products. We needed something better, what I really was looking for was speed… wine on a beer budget so to speak.

The Unifi series of switches would have been a good choice but I didn’t know enough about their product at the time to implement. And I happened upon a killer series of switches… one of which is the Mikrotik CRS354-48P-4S+2Q+RM. I had some serious reservations about this switch, it isn’t the easiest thing in the world to learn, there are many ways which I could implement it. I know that some people had experienced serious problems with stability and groups of ports freezing on that model.

But I got a couple and did serious testing with it, and found that if I updated to the newer firmware, all my stability problems went away. I stuck with RouterOS instead of SwitchOS, and learned how to configure the hardware offloading for L2, and since I have a very, very powerful killer router with many interfaces – I let my router do all the network security and let my switches do what they do best – switch network frames.

I don’t want to give up too much information about what exactly we all run at our work – but I had a guy ask me if our router was like a home commodity router, like a entry level Belkin… lol. Uh no… our router is an enterprise grade router with HTTPS content inspection and a full suite of security services. Our router also is connected to a massive online dashboard that gives us complete visibility into logging, clients, reporting, VPN, DNS, attacks, and more than you could imagine – like Geo-location blocking, AI powered file inspection, and so on.

Our router (like a Unifi), has very strong polices between network zones and I only allow the traffic we need and nothing more. The main thing is that it is a very fast router so I can easily allow it to do all the security policies and routing without it even having to breath hard – so we can offload all OSI layers > layer2 to our firewall and let the switches switch.

The Mikrotik switch has 10 Gbps uplinks… it even has 2x 40G QSFP+ uplinks (but that would be severe overkill for us) – but instead of us using Ethernet trunks, we’ve moved to 10Gbps SFP uplinks. I also like the fact that Mikrotik also has a cli that lets you run commands. I turned off all webui to the Mikrotik.

You’re really going to have to have your act together if you are going to install a Mikrotik switch and really configure it properly, there are many, many settings and to secure it properly there a lot of configuration to do. But the backup and restore functionality is great – I have had virtually zero problems running Mikrotik switches as our core switches – they are a workhorse of a switch.

The truth is I really prayed about it a lot – I’m not telling you to put your faith in Mikrotik. I asked God to bless our network and make it stable. I realize that might sound incredibly foolish to some of you… an I.T. guy that says technology is just a small thing compared to putting your faith in God? What difference would that make on hardware and software in a box?

It’s important that we know our stuff, that we make wise decisions but we need to realize that is the extent of our power. Psalm 127:1 Unless the LORD builds the house, those who build it labor in vain. Unless the LORD watches over the city, the watchman stays awake in vain. The Lord has the last word and ultimate say in our lives. Even the best conceived network with the most shrewd configuration can fall if the Lord isn’t involved. I completely believe that. I do my best, but my best is nothing – I have to ask the Lord to bless my work and make it pleasing for him – then it can stand because I’m not holding it up – the Lord is.

Jason

Leave a Reply

Your email address will not be published. Required fields are marked *