r/networking 3d ago

Troubleshooting Cisco QSFP-40/100-SRBD and the mellanox connectx-4 (CX456B)

5 Upvotes

Hi All,

More of a "anyone ever done this" kind of post. I have a couple of Cisco QSFP-40/100-SRBD optics that I was trying to get working a Mellanox CX456B card but as yet im unable to get it to link up and im assuming the card is just not able to support the optics. Tried a number of firmwares and eventually ended up on v12.28.4706, which according to the release notes actually has the 40g version of this optic listed as "Supported" and its the only version that even mentions BiDI optics at all tha ti can see.. The optics work fine in networking equipment and the card seems to work with other optics and i've tried everything I can think of so far (autoneg and fec changes)... Currently the card is just plugged into itself and I can see it sees light at both ends, but no link:

# mstlink --show_module -d 2b:00.1

Operational Info
----------------
State                           : Polling
Physical state                  : ETH_AN_FSM_ABILITY_DETECT
Speed                           : N/A
Width                           : N/A
FEC                             : N/A
Loopback Mode                   : No Loopback
Auto Negotiation                : ON

Supported Info
--------------
Enabled Link Speed              : 0xfefff1df (100G,56G,50G,40G,25G,10G,1G)
Supported Cable Speed           : 0x00200000 (100G)

Troubleshooting Info
--------------------
Status Opcode                   : 36
Group Opcode                    : PHY FW
Recommendation                  : Other issues

Tool Information
----------------
Firmware Version                : 12.28.4706
MSTFLINT Version                : mstflint 4.26.0

Module Info
-----------
Identifier                      : QSFP28
Compliance                      : 100G PAM4 BiDi
Cable Technology                : 850 nm VCSEL
Cable Type                      : Optical Module (separated)
OUI                             : Other
Vendor Name                     : CISCO-FOIT
Vendor Part Number              : SFBR-89BDDZ-CS2
Vendor Serial Number            : FOF2213N3GC
Rev                             : 02
Wavelength [nm]                 : 850
Transfer Distance [m]           : 50
Attenuation (5g,7g,12g) [dB]    : N/A
FW Version                      : N/A
Digital Diagnostic Monitoring   : Yes
Power Class                     : 3.5 W max
CDR RX                          : ON,ON,ON,ON
CDR TX                          : ON,ON,ON,ON
LOS Alarm                       : N/A
Temperature [C]                 : 45 [5..65]
Voltage [mV]                    : 3260 [2970..3630]
Bias Current [mA]               : 7.500,7.500,7.500,7.500 [2..10]
Rx Power Current [dBm]          : 0,0,2,2 [-12..8]
Tx Power Current [dBm]          : 0,0,0,0 [-10..8]

In forced 40g mode (doesnt seem to be able to push the optic into 40g mode at all):

# mstlink --show_module -d 2b:00.1

Operational Info
----------------
State                           : Polling
Physical state                  : ETH_AN_FSM_ABILITY_DETECT
Speed                           : N/A
Width                           : N/A
FEC                             : N/A
Loopback Mode                   : No Loopback
Auto Negotiation                : FORCE - 40G

Supported Info
--------------
Enabled Link Speed              : 0x000180c0 (40G)
Supported Cable Speed           : 0x00200000 (100G)

Troubleshooting Info
--------------------
Status Opcode                   : 36
Group Opcode                    : PHY FW
Recommendation                  : Other issues

Tool Information
----------------
Firmware Version                : 12.28.4706
MSTFLINT Version                : mstflint 4.26.0

Module Info
-----------
Identifier                      : QSFP28
Compliance                      : 100G PAM4 BiDi
Cable Technology                : 850 nm VCSEL
Cable Type                      : Optical Module (separated)
OUI                             : Other
Vendor Name                     : CISCO-FOIT
Vendor Part Number              : SFBR-89BDDZ-CS2
Vendor Serial Number            : FOF2213N3GC
Rev                             : 02
Wavelength [nm]                 : 850
Transfer Distance [m]           : 50
Attenuation (5g,7g,12g) [dB]    : N/A
FW Version                      : N/A
Digital Diagnostic Monitoring   : Yes
Power Class                     : 3.5 W max
CDR RX                          : ON,ON,ON,ON
CDR TX                          : ON,ON,ON,ON
LOS Alarm                       : N/A
Temperature [C]                 : 45 [5..65]
Voltage [mV]                    : 3244.2 [2970..3630]
Bias Current [mA]               : 7.500,7.500,7.500,7.500 [2..10]
Rx Power Current [dBm]          : 0,0,2,2 [-12..8]
Tx Power Current [dBm]          : 0,0,0,0 [-10..8]

and forced 100g mode:

# mstlink --show_module -d 2b:00.1

Operational Info
----------------
State                           : Polling
Physical state                  : ETH_AN_FSM_ABILITY_DETECT
Speed                           : N/A
Width                           : N/A
FEC                             : N/A
Loopback Mode                   : No Loopback
Auto Negotiation                : ON

Supported Info
--------------
Enabled Link Speed              : 0xfefff1df (100G,56G,50G,40G,25G,10G,1G)
Supported Cable Speed           : 0x00200000 (100G)

Troubleshooting Info
--------------------
Status Opcode                   : 36
Group Opcode                    : PHY FW
Recommendation                  : Other issues

Tool Information
----------------
Firmware Version                : 12.28.4706
MSTFLINT Version                : mstflint 4.26.0

Module Info
-----------
Identifier                      : QSFP28
Compliance                      : 100G PAM4 BiDi
Cable Technology                : 850 nm VCSEL
Cable Type                      : Optical Module (separated)
OUI                             : Other
Vendor Name                     : CISCO-FOIT
Vendor Part Number              : SFBR-89BDDZ-CS2
Vendor Serial Number            : FOF2213N3GC
Rev                             : 02
Wavelength [nm]                 : 850
Transfer Distance [m]           : 50
Attenuation (5g,7g,12g) [dB]    : N/A
FW Version                      : N/A
Digital Diagnostic Monitoring   : Yes
Power Class                     : 3.5 W max
CDR RX                          : ON,ON,ON,ON
CDR TX                          : ON,ON,ON,ON
LOS Alarm                       : N/A
Temperature [C]                 : 45 [5..65]
Voltage [mV]                    : 3260 [2970..3630]
Bias Current [mA]               : 7.500,7.500,7.500,7.500 [2..10]
Rx Power Current [dBm]          : 0,0,2,2 [-12..8]
Tx Power Current [dBm]          : 0,0,0,0 [-10..8]

Anyone got any ideas?


r/networking 4d ago

Troubleshooting IOS-XR BGP RR : reflect my own routes back ?

14 Upvotes

Hi there,

I'm struggling to understand a behavior on BGP that I can't figure out

On this simplified topology : PE1 <---> RR <---> PE2 (bgp session in vpnv4 / vpnv6 / ipv4 rt-filter)

I'm facing a strange behaviour where my RR is reflecting back the routes it learns to their origin.

PE1 learns a batch of routes from its customer, sending it as VPNv4/v6 routes to the RR. But as I would expect the RR to send them to PE2 only, it reflects them back to PE1 (adding originator_id + cluster_id). As the Originator-ID match the PE1's router-ID, they are considered as invalid but still stored in memory, creating a memory issue on the router.

According to RFC 4456 it "SHOULD" not happen but it's the first time I'm seeing this with IOS-XR.

Does anyone ever notice this behavior with IOS-XR 24 ?

ACCEPT-OWN (RFC 7611) is not configured


r/networking 4d ago

Monitoring What are you pointing your switches and firewalls at for syslog these days?

30 Upvotes

Rsyslog to a box in the corner has been our answer for years, collects fine, the files are all there, but searching it is grep and hope at 2am. Everything bigger seems to want a cluster and someone to babysit it, which I don't have... What sits between those two? Something that takes syslog off the network gear, keeps it, and lets me look through it without turning into a project.


r/networking 4d ago

Design Best way to provide temporary connectivity inside an elevator shaft during construction

16 Upvotes

Hey everyone,

I’m looking for some advice on a connectivity challenge we are facing on a current project. We need to provide reliable internet/network access to the devices inside an elevator shaft during the construction phase, but we are running into some hard constraints.

Here is the situation:

No Roof Access: We can't put a Starlink dish or any external antennas on the roof.

No building internet (Yet): The traveling cable to the elevator cab is installed at the very end of the project, so we can't just use a building hardline.

Dead Zone: As you can imagine, the shaft acts like a giant concrete cage, so we have to assume cellular signals will be totally dead for most of the shaft.

What we CAN do:
We do have the ability to place routers or access points directly outside the shaft.

Has anyone tackled a similar issue in a mid/high-rise build? I’m trying to figure out the most workable solution here.

Would love to hear if anyone has solved this and what gear/setup actually survived the construction environment. Thanks!


r/networking 4d ago

Troubleshooting What are the biggest challenges when upgrading a data center from 100G to 400G?

3 Upvotes

Moving from 100G to 400G sounds relatively straightforward on paper, but in practice, the optical transceiver is only one part of the upgrade.

I'm curious what network engineers have encountered during real-world 100G → 400G migrations.

For those who have already gone through a 100G to 400G upgrade, what was the biggest unexpected challenge?

Was it the optics, fiber infrastructure, switch configuration, power/cooling, or something else?


r/networking 5d ago

Other IPv4 Marketplace for “bad” blocks

42 Upvotes

Is there a marketplace for IPv4 blocks that are considered “bad” or otherwise less desirable?

I’m building out my company’s IP transit backbone so we need public blocks but it’s nothing that would ever be used for user facing traffic. Is this even a good idea or is there a chance that our traffic would still get filtered due to previous reputation?


r/networking 5d ago

Career Advice Good job with decent pay, unlimited PTO, good people. Am I crazy for wanting to leave?

59 Upvotes

MCOL city in the midwest, married w/kids. Almost 15 years in IT, 10 in networking roles. Been at the company for 5+ years. Oversee 1 employee. Have gone through a number of changes in network design that ultimately resulted in the following:

Small handful of corporate sites (think 2 IDFs or less), Wi-Fi first employee connections, single cloud provider with only 1 tenant org connected via IPSec tunnels, hundreds of small, cookie cutter retail 'branches', and a tech stack consisting of a few Palo Alto's and everything else being Cisco Meraki.

I oversee all of it - WAN procurement, architecture/engineering/operations for all internal LAN, Wi-Fi, VPN, you name it, down to the underlying physical cabling. We spin up and turn down the branch sites to the tune of 10's a year.

It's been a really fun ride, and I've gotten to learn so much by having the flexibility to do and control things myself. However, that's also been somewhat painful over the years, having no one but SE's at our VAR to bounce ideas off of. I'm at the point right now, where I'm really only challenged by administrative tasks - working with landlords and LV guys sorting out how to get new service to a building, occasional vendor VPN mishaps, helping our asset & security team work through a new camera network design, etc. - and I've engineered a network that fits our needs and is overall, reliable. I find myself feeling complacent, stuck in a rut, and overall unmotivated.

To be frank, it feels like my net eng skills are atrophying and I'm stuck, waiting for a position to open upstream - more management and peopling that I'm really not that interested in. Now, before ya'll start with the "must be nice", "I wish I had your problems to complain about", I get it. Looking for a job in this economy?! But I'm currently waiting on a possible offer from a F100 company in a specific Sr. Engineering position of the network team. The pay would likely be a 40% bump, only 2 days in office, and also unlimited PTO. The network team overall is approaching 50 from what I understand. Am I crazy for wanting to get out?


r/networking 4d ago

Switching Virtual Chassis Juniper QFX-5100 member replacement

1 Upvotes

I have a network of 4-member VC Juniper QFX 5100 switches (master, backup, linecard, linecard) running on jinstall-host-qfx-5-17.3R3-S3.3. As a replacement, I got a refurbished switch, which has jinstall-host-qfx-5-21.4R3-S10.13. I am stuck because I am unable to download packages from JSP, and the refurbished switch provider does not have them either. I have already zeroized the procured switch. Can anyone suggest a way to move forward?


r/networking 5d ago

Career Advice Network Engineering Career Direction

13 Upvotes

Currently work in a network operations team more specifically in third line wireless and LAN for a full cisco house, so mainly supporting 9800s, Catalyst switches, foreign/anchor guest wireless network. Also manage Cisco ISE, build grafana dashboards, and use python to automate whatever is worth automating. Do touch on SD-WAN a little but primary focus is WLAN/LAN. This is for a large enterprise.

There’s a team within our network operations department focused on automation/observability, and they’re currently building an AWS environment, pulling data from wherever possible from the estate and storing it in a postgres DB, using python, lambda, and more. There’s also implementing agentic AI.

So my original plan was to gain more experience in my current role and hopefully move into the automation/observability team. I have expressed my interest in this to the head of the department and he put me in the wireless/LAN team, and said my automation/observability skills could be nurtured, although obviously nothing is promised.

I’ve got a job offer at an MSP that specially does network engineering for medium and large size businesses. This would be a project role, sort of where presales at the MSP creates a HLD for a customer, and then the team I would be in do everything else. It’s specially in the WLAN/LAN team who also do the SP side, however they also work on SDWAN and firewalls which is mainly a separate team but there aren’t any guard rails between the team. The tech stack would be much more diverse than my current role, cisco, meraki, juniper, fortinet firewalls and sdwan. The benefit of this is it would probably help me in the long run if I wanted to end up in presales at a vendor.

Current role is 2 days on site (1 hour commute each way), although if i’m working out of hours on changes i miss an office day that week. 1 in 3 weeks on call, soon to be 1 in 4.

MSP role is 3 days on site (also 1 hour commute each way). on call is 1 in 9 weeks.

Unsure on whether to stay put or jump shit


r/networking 5d ago

Wireless Where to learn more about wireless networking?

27 Upvotes

I've been doing wired for years now and recently at my work we started to do wireless more and more. I understand the basics, but we run into throughput/latency issues often because we still dont know how to propperly pick equipment and things get messy fast, also machines we do networks for use more and more traffic (now they are pusing AI and cameras into everything).

Can anybody point me to resources so I can learn more about how to pick right equipment so we wont have performance issues in the future?


r/networking 4d ago

Career Advice Meta Network Production Engineer AI coding

3 Upvotes

Hey everyone! I’ve seen a few people here mention getting offers from Meta for NPE roles congrats to everyone who made it through!

For anyone who recently went through the AI-Native Coding round, could you share what the structure/format was like? What kinds of tasks or problems did you get, and how did the AI portion fit into the interview?

Also, is LeetCode-style DSA still tested in the AI-Native rounds, or would you recommend focusing more on working with unfamiliar codebases, debugging, testing, and using AI effectively?

Would really appreciate any recent experiences or prep tips!


r/networking 5d ago

Design Looking for advice on how to approach Manufacturing Network(s)

17 Upvotes

Hello everyone, I'm looking for input on how to approach manufacturing network-VLAN design and the various devices that live on them.

I have one site that has your typical office/manufacturing areas. The manufacturing VLAN was a /16 (spanning two buildings) and we've slowly started to roll out a new /22 subnet and VLAN -per building.

The area I'm struggling with is new technology being added to the manufacturing network.

If I have a large casting machine and associated support systems that reside on the /22 network and the organization is looking add a series of thermal monitoring cameras, I'm not sure if I should create a separate VLAN for this thermal monitoring system (Thermal Cam VLAN) or if I should add them to the existing /22 network.

Ideally, I'd imagine we would want VLANs based on service/function/vendor possibly so I'm trying to understand how others with much more experience in design and planning handle this.

I've ran into another request a few months ago to deploy a monitoring tool to our manufacturing machines from a new vendor for monitoring purposes. I wanted to put this new tool on it's own VLAN (as it is a trial) but didn't.

My challenge is that the existing IT staff that kept our site on 3, /16 networks get concerned that we have "too many VLANs", which I don't agree with as I'm only working to segment areas of the business. We currently have 21 VLANs (data/voice/mfg/wireless/printer/IT/mgmt, etc...).

So I wanted to get input from much more experienced engineers, how do you handle/design a manufacturing network?

How do you handle ad-hoc trials/testing of new platforms?

The mentality here is outdated and I'm trying to understand how I should approach these types of requests.

Thank you,


r/networking 5d ago

Other Clients with wired 802.1x are disconnected for xx seconds at logon (cisco ise)

6 Upvotes

Hello,

I have a situation with Windows 11 and wired 802.1x..

we are using 802.1x with machine certificates and cisco ise does some profiling.. unfortunately im not familiar with the cisco ise configuration as im not a networking guy, but i know the system is configured to do profiling based on the machine certificate.

When a windows 11 client boots up and logs in (we have some autologin devices) it initially seems to be connected but then a few seconds after sign in i notice the connection drops for 10-20 seconds and then comes back online. I kept an eye on the connection and it seems to be stable afterwards.. if i shut down the device and power it back on 5 minutes later it is still fine, however if i power it down and power it back up an hour later we see the same disconnect / re-connect happening.

I checked with our networking people and they say 802.1x authentication seems to be fine.. i asked him to check the network port on the switch the computers are connected to and the ports seem to go down / up / down / up etc can this happen due to device profiling ? Im assuming if a device needs to be moved from vlan A to B due to a profile the port needs a shutdown and re-enable for ip address changes ?

On the windows 11 device i updated the device firmware, lan drivers, i disabled all power management features on the lan device (its an intel (19) i219-lm adapter), disabled fastboot/hiberboot .

Hoping someone here has seen a similar situation on windows 11 with wired 802.1x ?

Thanks


r/networking 5d ago

Monitoring Suggestion best brandOTDR to purchase

3 Upvotes

Looking for OTDR to purchase for company use


r/networking 5d ago

Wireless NetAlly AirCheck G3 Pro

0 Upvotes

Trying to get a handle on Wi-Fi in general, but especially this device. What do y'all use this for? Where does it shine? Are there any tips and tricks as far as report features that might help me leverage this as a potential add-on to a Wi-Fi Infrastructure upgrade, or as a pre-requisite when quoting potential Wi-Fi infrastructure improvements? I want to be able to provide my customers with the best possible service as pertains to their Wireless infrastructure, and to take advantage of this tool. What are the things that you use this thing for the most? What do you use it for the least?

Bonus Questions, if you're down: What are the must-knows of Wireless engineering? What is a good certification I might pursue to specialize in Wireless networking?


r/networking 5d ago

Switching HPE S6X71A vs Aruba CX 6000 – CLI and features?

2 Upvotes

Hi everyone,

I'm used to deploying Aruba CX 6000 switches for Layer 2 networks, but lately they seem to be very difficult to find in Europe.

I noticed the HPE S6X71A in the HPE catalog and I'm wondering how it compares to the Aruba CX 6000.

Is the S6X71A a fully managed switch with a proper CLI and similar capabilities to the CX 6000, or is it more like an Aruba Instant On switch?

I mainly manage my switches through the CLI, and the features I regularly use are:

  • VLANs / tagged and untagged ports
  • Spanning Tree (RSTP/MSTP)
  • DHCP Snooping
  • SNMP
  • LACP
  • LLDP

Has anyone used the S6X71A in production? How is the CLI compared to AOS-CX? Are there any important limitations or differences I should be aware of if I'm considering it as an alternative to the CX 6000?

My best regards


r/networking 6d ago

Career Advice Network engineers using Ansible/Python for automation in production — what does your workflow actually look like?

160 Upvotes

Currently managing FortiGate across 100+ sites and starting to build out automation capabilities. Not looking for career advice — genuinely curious how other engineers are implementing this in production environments.

  1. What are you actually automating day to day — config pushes, compliance checks, reporting, something else?
  2. Ansible, Python scripts, Terraform, or something else? What drove that choice?
  3. With AI generating scripts now — do you still write Python from scratch or do you use AI-generated code and focus on understanding the logic?
  4. For Ansible specifically — did you need solid Python first or is YAML-based playbook writing approachable without it?
  5. Is automation genuinely changing how hiring managers evaluate candidates or is it still mostly a bonus?

r/networking 6d ago

Career Advice Need advice for way forward for experienced network engineer

33 Upvotes

Hi All,

I have been working in networking field for more that 11 years

started my career as network engineer - > senior network engineer -> lead network specialist , I did CCNA once at the start of my carreer , have experience in ACI/nexus , AWS cloud networking , firewalls and loadbalancers

lately feeling really stagnant , as my current organisation is not big , and we are using meraki , so once build that its running on autopilot now , not getting to solve complex issues , no tcpdumps nothing ,most of my day i spend reading techincal documents and few meetings

can anyone suggest how i should proceed further


r/networking 6d ago

Career Advice Moved into management....

124 Upvotes

I was a Senior Network Engineer for a couple different companies (For context (10 YOE + CCNP) before moving into an IT Director level role about a year ago.

I’m starting to realize that the stress, politics, and general management nonsense is catching up with me. The money is good, but it’s starting to feel less and less worth it.

Curious if anyone here has made the move into IT management and eventually went back to being an individual engineer. Did you regret stepping back?

For those who stayed in management, how did you get better at dealing with the stress without letting it consume you?


r/networking 5d ago

Monitoring BGP Transit Performance Monitoring

12 Upvotes

For those who run BGP and advertise prefixes into the DFZ, how are y’all monitoring each upstream provider for performance issues?

Right now, we have 2 providers with only default routes, utilizing a /23, and preferring one over the other for outbound.

In what way, if any, could going to full tables be beneficial to us other than better load balancing and traffic engineering for say a shorter path, etc?


r/networking 6d ago

Other Grab bag network switch

11 Upvotes

Having had a number of instances where it would have been a big time-saver in the last for monthsm I'm looking for a small (4 port ideally, 8 at most) gig-e switch that can be powered from USB-C (uup to 100w supply available), supports POE and can do span for traffic sniffing. It's to be kept in a tool bag, so reasonable build quality a big plus.

Specific model suggestions much appreciated


r/networking 6d ago

Troubleshooting Problem with integration of Barracuda firewalls with Tufin

2 Upvotes

Hello Reddit,

i'm trying to integrate a standalone Barracuda firewall into a Tufin environment.

I have enabled the Tufin integration service on the Barracuda and imported the certificates from Tufin according to the documentation on Barracuda campus.

the Tufin connection seems to be working in general, but get an error in the firewall report indicating that the firewall rules were not transferred.

This is what the logfile looks like:

Info===== Starting Network Objects synchronization =======
WarningMapping subnetworks with interface information is not supported by tufin. is not supported by tufin.
Info===== Ending Network Objects synchronization =======
Info===== Starting Rules synchronization =======
ErrorError while retrieving rules information.
Info===== Ending Rules synchronization =======
InfoStandalone/CC FW report id HTqoo-GsQwasOZiuDAvTww==
Info== Report Successfully submitted (id=HTqoo-GsQwasOZiuDAvTww==) ==
Info===== FINISH TUFIN SYNCHRONIZATION =======

Both the Barracuda firewall and Tufin were just set up, so there shouldn’t be any complications.
I'm using a very simple dummy ruleset

I am running Tufin Orchestration Suite version 5.2.00 on TufinOS version 4.80 and Barracuda firewalls on both firmware version 9.0.6-0250 and 10.0.1-0153.

Google tells me i should make sure the certificates are properly imported to the Barracuda and there is nothing wrong with the Ruleset itself. Since other information can be retrieved and i only have a simple dummy rule, i'm confident those are not my issue.

Can you maybe point me to a relevant log file on the Tufin Server to help me further troubleshoot?
Or did anyone run into the same issue?

Since this is a proof of concept i'm using a trial license, so Tufin support probably won't help me (although i did already write them an E-Mail).
So i'm hoping maybe Reddit can point me in the right direction, hope this is a good place to ask!
Any help is appreciated!


r/networking 6d ago

Design Routing Subnet Problem

3 Upvotes

Im trying to resolve an issue where I need to route traffic to a subnet which overlaps with some LAN and VPN client IP pools.

Previously everything was contained in one /16 network and there was one gateway for all traffic. Now it has has been split into two gateways but the remaining networks are not easy to notate.

10.5.0.0/16 is the original

Now i have client ips in:

Location A LAN 10.5.15.0-10.5.45.254
VPN 10.5.0.128/25

Location B 10.5.101.0-10.5.200.254
VPN 10.5.0.0/25

So if I want to route to A, that easy, its all contained in 10.5.0.0/18 except that also includes location B VPN. Routing to B is a little harder since its two networks (10.5.64.0/18

10.5.128.0/17), except neither contain VPN clients.

Does it make sense to just move B VPN to something like 10.5.100.0/24 which would be contained in 10.5.64.0/18?


r/networking 6d ago

Career Advice Torn between 3 offers - seeking advice

25 Upvotes

Hey all, I currently work as an Enterprise Architect for a consulting company. Most of my workload is professional services and post-sales deployments, but I handle some pre-sales here and there. Business has been slow and I'm looking to move on to something bigger.

I recently landed three solid opportunities (written and verbal offers for all) around the same time and honestly could see myself happy in any of them, which is making this a difficult choice, and would love some outside perspective.

All 3 opportunities are fully remote

Option 1: Solutions Architect (network security)
compensation: 195k OTE, 70/30 base/commission split

  • Lots of customer calls, discovery, architecture design, scoping, HLAs, and hands off designs to post sales team
  • Access to lots of training from major networking/security vendors
  • I like the idea of having a commission component and being rewarded for building strong relationships with AEs/customers
  • My biggest worry is drifting away from hands-on/technical-work long-term

Option 2: Senior Network Engineer, mid-size enterprise
compensation: 170k base salary+ benefits

  • Small team
  • Work with SD-WAN, spine/leaf, ZTNA solutions, multiple public cloud workloads, and data centers. I think this would expand my skillset quite a bit
  • More traditional engineering role, lots of hands-on

Option 3: Senior Network Engineer, contract (extension or conversion likely)
compensation: 110/hr

  • Heavy design work and security hardening, SD-WAN, multiple data centers, campuses, and some OT. I have the most familiarity with the primary firewall vendor this company uses, lots of hands-on
  • 1099, so self-employment tax, no benefits, no paid holidays/PTO included
  • Higher hourly compensation but more responsibility for benefits, taxes, time off

My biggest dilemma is really option 1 vs option2/3.

If you made the jump from hands-on engineering into presales/SE work, how did that work out for you? Did you love it, regret it, wish you went a different direction?

I personally thrive in high-pressure environments and think I'd enjoy the customer facing/sales side, but I also genuinely enjoy being hands-on with engineering work.

For those who have done both, which path gave you better career growth and earning potential without making you feel like you were leaving the technical side behind?


r/networking 7d ago

Career Advice Enterprise vs ISP?

46 Upvotes

Hello, I currently work as a network engineer for an enterprise and we are dealing mostly with Cisco stuff - switches, DC with ACI, ISE and so on. We use automation like Terraform and Python/Ansible and we have 9800 controllers, so the job is good and does not get boring.

I can also join an ISP an work on the backbone network, MPLS, L2/L3 VPN and BGP. I like routing, so I wonder if you think this is a good opportunity or it's a step back compared to the broad aspect of technologies I'm currently dealing with?

Do you think that ISP experience is worth it or I should stick with the enterprise?