Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
Want to use NQE to gain insights into your network, but don’t know where to begin? Follow along as I cover the basics of NQE and shares example queries. Have questions? Ask them below!
How to earn badges and move up the ranks Recognition is given to community members for their contributions and engagement within the Community. Here are the activities that lead to the awarding of badges and rank promotion: Replies Participating in discussions and responding to questions will give you points for replies. Topics Creating new topics and asking new questions demonstrates your ability to share new ideas with other members. Answers Other members and moderators can mark your responses to questions as correct. Likes Given / Received Recognizing the contributions of others is important in every community. Ranks Ramping Up Welcome! Every new community member starts here. Ask a few questions and like a few contributions from others and you’ll be moving up the ranks. Driver You’ll receive the rank of Driver after replying to your first discussion and liking posts by others. Spotter The Spotter rank is given to community members that not only particip
We built this community to help you get the most out of Forward Networks — and to connect you with others who are redefining what’s possible in network infrastructure. Whether you’re here to learn, share, or troubleshoot, you’re part of a group that believes great networks are built together. 💬 Product Discussions Explore the full potential of Forward Enterprise.Talk with other users about setup, configuration, integrations, automation workflows, and real-world use cases. 🔍 NQE Discussions Resources Dive into Network Query Engine (NQE) — the language that powers insight across your digital twin.Join discussions with other NQE developers, find real-world examples, and access step-by-step guides to build your skills and share your own solutions. 📚 Knowledge Base Get quick answers and best practices from the Forward Knowledge Base.You’ll find curated articles, configuration tips, and product insights to help you solve challenges faster. If you have questions, drop us an email at comm
Our community is here for everyone. We want to make sure that the community offers a positive experience for all visitors. We have established the following guidelines so it is clear what is expected of all community members. If you have any questions, please contact us at community@forwardnetworks.com. Be friendlyLet’s treat each other with respect. Users will not post any racist, sexist, discriminatory, derogatory, threatening or otherwise insulting content. Please refrain from using profanity or other offensive language. Keep it legalUsers may not post any offensive material, share illegal or copyrighted content, attempt to distribute illegal substances, distribute viruses, or anything that is considered illegal by your country of residence.Stay on topicPlease do not change the subject of a discussion to something not intended by the original poster. Any off-topic posting on threads will result in content being removed and ultimately can lead to denied community access.Save the sell
For many organizations, the challenge of gaining full visibility into all devices connected to their network goes beyond traditional routers, switches, and firewalls. Non-network devices—such as power controllers, printers, terminal servers and security cameras—are often left out of inventory reports, even though they can pose operational and security risks if unmanaged.This became a critical need for one of our large financial services customers. They required a way to inventory every device on their network, including thousands of non-network endpoints still accessible via SNMP. Their goal? Replace an existing NetBrain solution and consolidate into Forward Networks as their single source of truth.The result is the Endpoints feature—engineered to discover and report on any device Forward can authenticate to via CLI, SNMP, or API. This guide walks you through setting up SNMP Endpoints using real-world configurations and examples. With this workflow, you can generate a comprehensive in
Attempt to manage EoL - In progress
Is it possible to run a NQE query similar to aclEntry.lifecycleData?.lastUsed which returns the list of applications that has been identified passing through a security policy?Something similar to Palo Alto’s “apps seen” or Fortinet’s Fortiview Application Usage?
Can we make the api to download nqe reports in csv/ xlsx format a public api? I find this a lot more convenient than using the offset / limit api for fetching query results especially for very large datasets (greater than 500K records).
On July 28, 2026, CISA, the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners released "CI Fortify – Advice for Isolating Vital Systems." The guidance gives critical infrastructure (CI) operators a practical framework for disconnecting vital operational technology (OT) from corporate, internet-facing, and other less-trusted networks — and for continuing to deliver essential services while isolated. Nearly every step in that framework comes down to two questions: which devices matter, and what paths connect them to everything else. This post summarizes the guidance and outlines how Forward Enterprise helps answer both. Who should read this postNetwork engineers and architects responsible for segmentation between IT, OT, and vendor/cloud networks Incident response and business continuity planners building isolation and crisis-response plan Security teams validating that segmentation and isolation controls actually work as de
A few weeks ago I wrote about what building Skyforge taught me about network emulation and digital twins. If you haven’t read it, you can find it here: The response was much larger than I expected, but one conversation afterwards stuck with me.An colleague mentioned they were starting to hear a different question from customers. It wasn’t really about digital twins anymore. It was about AI.If tools like Claude can generate software this quickly, doesn’t that fundamentally change the build-versus-buy equation?It’s a fair question, and honestly, it’s one I’ve been asking myself as well.After all, I spent the last six months building Skyforge with Claude sitting beside me. I don’t mean that as a marketing statement about AI. I mean it literally. Large parts of the platform, from Go services and Kubernetes manifests to GitOps workflows, deployment automation, documentation, and countless little pieces of glue code started life as conversations instead of blank files.There is absolutely no
Sometimes you just want to get the results of custom commands quickly.Here is what the command group contains for collection:show ip bgp summaryshow environmentshow interface statusshow ip routeshow port-channel summaryshow lldp neighborsshow ip arp vrf allshow ip arpshow mac address-tableshow inventoryshow interfacesshow cdp neighborsshow ip ospf interfaceshow ip ospf neighborsHere’s a template NXOS/*** @intent NX-OS Multi-Command **/getCommandResponse(device, commandText) = max(foreach command in device.outputs.commands where command.commandText == commandText select command.response);main = foreach device in network.devices where device.platform.vendor == Vendor.CISCO where device.platform.os == OS.NXOS where device.name == device.system.physicalName let bgpSummary = getCommandResponse(device, "show ip bgp summary") let environment = getCommandResponse(device, "show environment") let interfaceStatus = getCommandResponse(device, "show interface status
Some cyberattacks need a zero-day to make headlines. This one didn't. For years, Russian intelligence has simply walked through open doors: default SNMP community strings left unchanged, Cisco's Smart Install left switched on, routers nobody got around to patching. That activity was significant enough to bring eighteen agencies together on a single warning. NSA, CISA, FBI, and DC3 in the United States joined fourteen international partners, including the UK's NCSC, Australia's ACSC, and Canada's Cyber Centre, to co-sign a joint advisory: AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting." When that many agencies put their names on one document, it's worth reading closely. Russian FSB Center 16 actors (tracked in the industry as Berserk Bear, Energetic Bear, Dragonfly, and Static Tundra, among other names) have been opportunistically compromising routers and switches worldwide for over a decade, and they're still finding plenty of them, not through
Environment:Forward Networks (self-hosted) ServiceNow CMDB integration via NQE query Target class: cmdb_ci_ip_firewallIssue:When mapping System Criticality (a ServiceNow choice field) from an NQE query to ServiceNow via Forward's native CMDB integration, the field consistently reports "data type mismatched" regardless of the value format used.Attempted formats — all result in data type mismatched:"System Criticality": "2" "System Criticality": 2 "System Criticality": "2 - High" "System Criticality": ["2"] "System Criticality": [2] "System Criticality": ["2 - High"] Top-level named list: systemCriticality = ["2"] referenced in selectQuestion:Is ServiceNow choice field type mapping supported in Forward's NQE→CMDB integration? If so, what is the correct NQE syntax or integration configuration to map to a choice field without a type mismatch?Current workaround being considered:ServiceNow business rule that sets system_criticality = "2" on insert/update when discovery_source == "Forward Net
Does anyone know if there is a log or export for the push to service now? We are having an issue with service now processing the model_id (ref). It looks like forward is mapping “model” to both snow’s model_number and model_id. However, it looks like it isn’t being processed on the cmdb side. I just want to see if there is a way to show evidence of the payload forward is sending. Thank you
On June 18, 2026, CISA issued an urgent advisory warning that malicious cyber actors — believed to be a Russian-speaking criminal group — have compromised nearly 74,000 Fortinet firewall and VPN devices across 194 countries in a campaign now dubbed FortiBleed. The list of affected organizations spans global enterprises and, most alarmingly, a Turkish NATO defense contractor from which classified documents were successfully exfiltrated. As of this writing, independent telemetry puts the number of compromised devices at over 86,000.CISA’s recommended actions are straightforward: terminate all SSL VPN and administrative sessions, reset credentials, enable phishing-resistant MFA, migrate password storage to PBKDF2 hashing, and restrict management interfaces from the public internet.Good advice. But reactive. The more important question is: could your team have known these conditions existed before attackers found them?The answer, for organizations running Forward Networks, is yes.The campa
A discussion at Cisco Live this year got me thinking about network emulation and digital twins. About six months ago, I started building Skyforge, an internal network emulation platform at Forward. The project started as an attempt to solve a practical problem: how do you quickly create realistic multi-vendor environments for demos, testing, and experimentation without maintaining racks of physical hardware? The name comes from The Elder Scrolls V: Skyrim, which is probably what happens when you spend too many hours playing video games and then find yourself naming infrastructure projects. Skyforge uses Kubernetes to orchestrate and manage emulated network environments, along with netlab to generate topologies, configurations, and deployment artifacts across multiple vendors. None of those technologies are particularly new, and individually they're all excellent at what they do. What surprised me wasn't getting the individual pieces working. What surprised me was how quickly the proble
As part of a network initiative, I’m sharing all the scripts that I have worked on to create an audit program. These files feed are then fed into PowerBi for better visualization by engineers and mgmt.First step is create a utility called, “tag_var_util” to grab tags, of which, will be used as part of the logic to assign a template to different sets of attribtues.This utility will then be imported on all other NQE Audit Scripts. // Create a new NQE Function called: tag_var_util// Add the following utility to extract tags given to devices in Forward Networks Sources// TAGS to identify Environmentexport get_env_from_tags(tags: Bag)= get_list_match_from_tags(tags, ["DC", "CoLo", "Branch", "AWS"]);// TAGS to identify a sub category of locationexport get_SubDc_from_tags(tags: Bag)= get_list_match_from_tags(tags, ["Branch", "DC01", "DC02" ]);// TAGS to identify which managers owns the productexport get_mgr_from_tags(tags: Bag)= get_list_match_from_tags(tags, ["Moe", "Larry", "Curly"]);//
CISA issued Binding Operational Directive 26-04 on June 10, 2026, fundamentally reshaping how federal agencies must prioritize and remediate vulnerabilities. Rather than treating all CVEs with equal urgency, BOD 26-04 establishes a risk-tiered patching framework built around four variables: whether the asset is publicly exposed, whether the vulnerability is in the Known Exploited Vulnerabilities (KEV) catalog, whether the exploit can be automated by an adversary, and the technical impact an attacker achieves after exploitation. The directive allows agencies to defer the lowest-risk vulnerabilities entirely to the next system upgrade, while demanding the fastest action—three days—on the highest-risk combinations. This post outlines what the directive requires and how Forward Enterprise helps organizations answer the questions that determine each risk tier. This directive supersedes both BOD 22-01 (Known Exploited Vulnerabilities) and BOD 19-02 (Vulnerability Remediation for Internet-Acc
As part of a network initiative, I’m sharing all the scripts that I have worked on to create an audit program. These files feed are then fed into PowerBi for better visualization by engineers and mgmt.Power Bi Display of Forward NQE belowStarting with AAA.First step is create a utility called, “tag_var_util” to grab tags, of which, will be used as part of the logic to assign a template to different sets of attribtues.This utility will then be imported on all other NQE Audit Scripts.// Best practice is to tag all devices with the following:// Environment && Sub-Environment && Manager && Region && Function && VRF && Mgmt-Interface (source interface for mgmt. traffic)// Each Script will import the utilities: import "PROD/Standards_Network/NetworkVars/tag_var_util"; let region = get_region_from_tags(device.tagNames) let deviceFunc = get_function_from_tags(device.tagNames) let environment = get_env_from_tags(device.tagNames) let vrf
we are using below format to collect the data from Fortinet firewall for custom command. endconfig globalshow system dnsshow system ntp can anyone check and confirm ,these will not impact anything ,if i remove config gloabl , than command will not run.
There is a specific section of the AFM config which refers to the default action of the firewall, the below query checks that the default action is Drop.F5 AFM Config to check for.}sys db tm.fw.defaultaction { value "drop"} /** * @intent Check that all F5's that are running AFM have the default action set to deny * @description THis will check sys db tm.fw.defaultaction for the value drop and error * if it is not drop. **/// Note {} have been removed as they can not be included in the pattern.defaultPattern = ```sys db tm.fw.defaultaction value "drop"```;foreach device in network.deviceswhere device.platform.os == OS.F5foreach command in device.outputs.commands//Check for only the F5's with AFM Configwhere command.commandType == CommandType.F5_AFM_CONFIG//Extract the command response.let AFMConfig = parseConfigBlocks(OS.F5,command.response)//Match the patternlet match = blockMatches(AFMConfig,defaultPattern)let violation = if length(match) == 0 then true else falselet DropActio
Here are a set of 3 scripts for:NXOSEOSIOS (and IOS-XE)The scripts look for configuration related to source interfaces. Over the years, engineers have used Loopback0, dedicated management interfaces, Loopback10, or other random interfaces to source traffic from. We have an an inititiative to clean these inconsistencies up.These scripts parse through the configs looking anything related to the ‘source-interface’ or ‘local-interface’ etc. Then it finds the associated configuration of those interfaces, such as IP Address, VRF, description.I have also tuned them to ignore parts of the configuration that are not important to the effort , ex:no ip redirectsno ip route-cacheno ip unreachablesno ip proxy-arpip mtu {number}load-interval {number}ip helper-address {string}negotiation autostandbye {string}etc...Cisco NXOS/*** * @intent Source-Interface Extraction (NXOS) * @description Extracts all source-interface configs and interface details from config text.***/// --- 1. Helper Functions ---g
Forward brings in Fortinet firewalls as the device its self and the VDOM’s this becomes challenging when you need to validate the tacacs configuration for the physical device this means quite often the vdoms or even the root vdom will fail even though tacacs is configured on the device.The simple solution is to add a permitted violation list, however this needs to be maintained manually there must be a better solution surely?userTacacs =```config user tacacs+ edit "TACACS" set server [server 1 IP Address] set secondary-server [server 2 IP Address] set key ENC {string} set secondary-key ENC {string} set authorization enable nextend```;systemAdmin = ```config system admin edit "tacacs" set remote-auth enable set accprofile "no_access" set vdom {vdoms:string} set wildcard enable set remote-group "TACACS_ACCESS" set accprofile-override enable```;foreach device in network.deviceswhere device.platform.v
Managing an on-premises network intelligence platform should be straightforward — and with Forward Enterprise Appliance 16.5 and the upcoming version 17, we're making it significantly easier and more secure.Here's what's changing and why it matters.A New Way to Administer Your ApplianceStarting with version 16.4, we introduced a Text User Interface (TUI) — a guided, menu-driven environment accessible via SSH or the console. Rather than navigating the underlying Linux OS directly, administrators now have a single, purpose-built interface for every common task.The TUI covers everything from initial node configuration and cluster deployment to Forward Enterprise upgrades, security settings, and built-in diagnostics — all in one place.Version 16.5: Refinements Based on Your FeedbackForward Enterprise Appliance 16.5 (available May 2026) is the last release in the 16.x line to include open shell access. It brings vulnerability fixes and TUI improvements based on early adopter feedback. If yo
Children LinesThis document aims to improve understanding of how NQE parses Cisco-like configuration. It also provides templates for common NQE checks related to configurations. Forward NQE takes Cisco-like configuration and parses it into a subset of “parent” and “child” lines. The “parent” and “child” relationship is based on the number of indents in front of each line. Each Cisco configuration always starts with a line with no indent in front of it. (e.g. “router bgp 65000”). Some configurations, referred to by Cisco as “global configurations” such as “feature bgp”, do not have additional parameters, and therefore they do not have “children” lines. Others, such as “router bgp 65000”, require additional parameters to configure that particular feature. In the below example, “router bgp 65000” is the main parent line consisting of “children” that are line 2-4, 7, and 10. Furthermore, the child lines 4, 7 and 10 each have additional “children” lines of their own; line 4 has lines 5-6;
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.