Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
I have an already pretty extensive NQE written to return a half dozen or so fields, but I cant figure out how to differentiate whether the CVE returned is a OS or Config match...or both. Can someone help with that code?
Has anyone put together a simple Query to grab the advertised routes to a BGP Peer?I haven’t had much time to try, but maybe someone has done this on side.In summary, I want to try and associate routes to a device/location in our branch environment.foreach device in network.deviceswhere "Branch" in device.tagNames && "WAN" in device.tagNames I thought there would be some simple query in the model to just pull ‘bgp advertised routes’ and I could limit it with the above, and associate that route to that location. But after looking for 10 min, I couldn’t find anything of use. Anyway, if anyone has done something, it would be great to see/try. I saw a very ‘wild’ one on the community @baher , amazing work BTW.But i’m basically looking for the result of the routes advertised to any BGP neighbor.
Hello: I am not sure if this should be a discussion or question so apologies on that. I have an NQE where I am pulling the raw Oid data and displaying the rawValue result as an output. I want to be able to name each of those outputs so that its know to the public what that raw data represents. One such example is a returned value of INV: 2.12 in the rawValue field. But I would like to have know as hardware revision.I did apply names to the Oids in the custom source profile, but its not pulling that. Can this be done?
Is there a way to export all CVEs that the platform is scanning for. We know how to get the ones that are affecting devices, but we want a list of them all, regardless of impact.
Hi Forward Networks team, I am looking at the API, specifically the call to get a device's data files.I can get the files for a single device at a time by just putting in the hostname in the parameters, however I was wondering if there is a parameter which will allow me to pull from multiple devices at once.For example lets say I want to pull from devices ABC, DEF, GHIorI want to pull from every device that starts with ABC*Is this something that can be done?Or would another possibility be to create a separate group of devices which includes all the devices I want to pull from and then just run the GET call on that device group. Kind regards,Sebastian
Hello,I have a question when using the Search Path API.Could we get an elaboration on the meaning of that “DELIVERED_TO_INCORRECT_LOCATION” forward outcome status, such as why it appears and if there’s anything we can do to address the “INCORRECT_LOCATION” part, if it’s necessary?I presume the status means that somewhere along the routing, it somehow ended up at a destination Forward Networks didn’t expect. But I just wanted to know if there was any more to it.Thanks!
Hi Team,We want to fetch the Cloud objects difference count that compare today and yesterday(For example) Snapshot and provide the missing Cloud objects details which are missing from Current snapshot through NQE Query. Please assist us if anyone can relate with this.
Identifying all the IP addresses on your network can be a complex and tedious task - and even impossible on some networks. This NQE makes it significantly easier to identify all the IP addresses in use on your network, including those that are stale or obsolete. OverviewThis NQE identifies IPv4 and IPv6 addresses that are in use within the network. Due to the scarcity and value of IPv4 addresses, companies often seek to maximize their utilization and identify any under utilized address space. This can help to either improve the utilization of owned addresses or free up unused address space for sale. Whether you’re consolidating for financial purposes or re-IPing due to mergers, acquisitions, or network reorganizations, this NQE is essential for identifying all the IP addresses within the network. ResultsImproved IP Utilization: By identifying stale or obsolete IP addresses, this NQE enables organizations to optimize their IP space, reducing the need to purchase additional address spa
This is a good example of how NQE can work well with IP subnet information.In this case the customer had found that the router's parser would not exclude misconfigurations. They found that some of the NHRP configuration commands had used the incorrect subnet. The correct IP configs were there as well, but now it means there are extra config lines and it would be nice to clean these up. There were under 100 devices that were violations out of the tens of thousands of devices that were collected.Config segment from Cisco router with a violation.!interface Tunnel0 ip address 10.16.1.16 255.255.255.0 ip nhrp map multicast 172.16.16.1 ip nhrp map 10.6.16.1 172.16.16.1 <<--This command does not match the tunnel subnet ip nhrp map multicast 192.168.16.1 ip nhrp map 10.16.1.1 192.168.16.1 ip nhrp network-id 16 ip nhrp nhs 10.16.1.1!/** * @intent Find ip nhrp commands that are not in the same subnet as the tunnel subnet * @description The 'ip nhrp map' and 'ip nhrp nhs' address should be
I wrote a basic NQE script to obtain the uptime for devices and display them in years, days and hours. When i reviewed the results I saw some super robust devices out there that had not been rebooted for several years.This led to some discussion about whether uptime could be used in part to determine in device software upgrades were taking place regularly. As such we developed a really basic uptime check and threshold of around 6 months. Any devices that been up longer than 6 months would definitely have not been upgraded. (Our devices all reboot for software patches and upgrades).This script is below/*------------------------------------------------------------------------------------------------------------ * thresholdDays the number of days before uptime is not acceptable. ------------------------------------------------------------------------------------------------------------*/thresholdDays = 183;/*---------------------------------------------------------------------------------
Extracting public IP data from AWS can be painful and time consuming. This NQE makes it easy to identify public IPs across all accounts and regions and can be customized for other cloud providers. OverviewStarting in February 2024, AWS began charging for public IP addresses to incentivize the migration to IPv6 due to the depletion of IPv4 space. Managing these costs can be challenging, especially with AWS’s VPC IP Address Manager (IPAM) which only works across a single account and incurs additional charges. Our NQE provides a comprehensive view across accounts and regions without extra costs, simplifying IP management. This functionality also extends to other cloud platforms like Azure and GCP, offering a unified solution for IP management.ResultsThis NQE simplifies IP management by providing a centralized dashboard to view and manage IP addresses across multiple AWS accounts and regions. The Public IP NQE identifies underutilized IP addresses, helping customers avoid unnecessary charg
OverviewSecurity Technical Implementation Guides (STIGs) are critical for ensuring that organizational devices accessing the Department of Defense Information Networks (DODIN) meet stringent security requirements. The NQE STIG compliance check makes it easier to validate that device configurations are compliant with STIG standards and verify those configurations remain compliant with each snapshot. STIG compliance involves a comprehensive list of requirements ensuring proper configuration of authentication, logging, network time protocol (NTP), and management plane. These requirements can vary significantly depending on the device type and vendor, with different configurations needed for everything from backbone routers and campus layer switches, to VPN concentrators. Given the complexity and variety of these requirements, maintaining compliance can be a daunting task. This NQE solution provides comprehensive auditing capabilities for STIG compliance as well as extensibility to validat
Managing wide area networks (WANs) efficiently is paramount for businesses. This Network Query Engine (NQE) serves as a critical tool, offering visibility into WAN circuits by integrating external data sources from service providers.OverviewIn today's digital landscape, businesses rely on wide area networks (WANs) to connect different parts of their operations. A common challenge is the lack of visibility into all WAN circuits, leading to inefficiencies and unnecessary costs. That's where this Network Query Engine (NQE) steps in, providing a solution that allows customers to use external data sources, such as CSV files, to better manage their networks. For instance, a customer can take a CSV from a service provider like AT&T, and use it to match IP addresses to devices in their network. This helps identify routers and WAN interfaces that might not be immediately visible, ensuring that only necessary circuits remain active. ResultsCustomers have found this capability invaluable for
Is there any additional documentation as to what needs to be included in any NQE query that is used to dynamically create l3vpn synthetic devices ?
If you've ever wished Demo Tuesdays were longer OR if you've always wondered what @Mike looks like in sequins-- this is the stream you've been waiting for. Mike takes our Cisco Live Demo Theater audience through a full 30 minutes of Forward Enterprise product demonstration live in Las Vegas.
How can i collect below information from Forward Network via API for Network devices. ?• IP address,• MAC address• Interface details• Device Name• Subnet details1.Which API should be used to get the above information? In the documentation, I see an API to get networks/ Network collection/ devices ;2.Is there a single API call that can pull the above information, or are there multiple API calls?3.If it's one API call, what's the Max pagination limit?4.Can you please provide a Sample API or a Postman export to make an API call.
How can i collect NQE Query Data from Forward Network to Power BI Easily,
Hi All,Need to fetch interface alias details of Fortinet firewalls from NQE query. Please help me to build the logic.
Hi Team,I want to add only admin status up interfaces condition, CDP LLDP neighbor info in below query, please help me on this.Extra question- 1. any method to shirk the results to only getting WAN interfaces any idea on this.2. want to add one more column to fetch circuit id details from Interface or Interface description.NQE Query- pattern_interfaces = ["*WAN *"];testPatterns(s, p) = max (foreach pattern in pselect matches(toLowerCase(s), toLowerCase(pattern)));foreach device in network.devicesforeach interface in device.interfaceslet platform = device.platformlet ethernet = interface.ethernetwhere isPresent(interface.description)where testPatterns(interface.description, pattern_interfaces)select { test: testPatterns(interface.description, pattern_interfaces), deviceName: device.name, Location: device.locationName, Tags: device.tagNames, Vendor: platform.vendor, Model: platform.model, interfaceName: interface.name, negotiatedSpeed: ethernet.negotiatedPortSpeed, negotiatedMod
I want to create a custom interface description nqe query in Forward Networks.Requirement is to getting only WAN, INT interfaces information through the query. I have used below logic through it i am not getting the results. Please help me out. foreach device in network.devicesforeach interface in device.interfaceslet platform = device.platformwhere interface.description=="WAN"select { deviceName: device.name, Location: device.locationName, Tags: device.tagNames, Vendor: platform.vendor, Model: platform.model, interfaceName: interface.name, description: interface.description,operStatus: interface.operStatus,adminStatus: interface.adminStatus,cdpNeighborsCount: length(interface.cdp.neighbors), lldpNeighborsCount: length(interface.lldp.neighbors) }
Sorry about the lack of punctuation in the title, I can’t edit after ;-)So I don’t know if this is possible, but maybe someone has an idea.The script below provides the following output:OutputThe goal of the script is to figure out how ‘over provisioned’ we are on a switch. i.e. how many ports have never passed a packet. This is in order to size environments better for future refreshes.So the output provides all the necessary info, but I’m not sure how to get a row to tell me “% Utililized”This would be the total count of the ports in use (last column) divided into the the number of ports that specific switch, that show “0” across the board, and I’ll just take 1 zero and assume the rest are zeros (sometimes they are not, but this is just an estimate anyway). Any ideas are greatly appreicated./*** @intent Branch Counters* @description Branch Counters Interface Status show int counters on Arista & IOS-XE Switches * 1. Check to see what switch ports have had no traffic accross the wir
Apologies - This isn’t a question, and I can’t change it to a conversation -With recent changes in our NAC servers, we needed to check that our ‘ip helper-addresses’ were consistent to our regional standards. This is something we usually did with Python, but here’s a simple script to grab the helpers on each of the interfaces. I got the script working, but had some formatting issues, and thankfully a colleague was able to use some logic to format (@danny,Ramirez) via this statement:let ips = (foreach ip in ServerIP where match.data.IntName == ip.data.IntName select distinct toString(ip.data.helper))Ideally, we would would define the NAC servers per region, and export them as a check, but I haven’t gotten there yet ;-)pattern = ```interface {IntName:string} ip helper-address {helper:ipv4Address}```;foreach device in network.devices// Feel free to trim the scope with a where// where "Branch" in device.tagNames && "Core" in device.tagNames && "C9500" in device.tagNames
Using the same logic in my previous post to grab ip helper addresses, I was thinking what else could I re-use this kind of script to grab, and it was for our OSPF configuration. If you are configuring OSPF type/timers/intervals/cost on interfaces, you can use this script to grab the values on each interface. This will make it easy to set up a violation check for anyone that wants. What would be ideal is if I could group the interfaces per devicehost-XYZ. intf1: Type: DeadInterval: HelloInterval: Load : Cost intf2: Type: DeadInterval: HelloInterval: Load : Cost intf3: Type: DeadInterval: HelloInterval: Load : Costhost-ABC. intf1: Type: DeadInterval: HelloInterval: Load : Cost intf2: Type: DeadInterval: HelloInterval: Load : Cost intf3: Type: DeadInterval: HelloInterval: Load : Cost // standard config// interface {ifaceName:string}// ip ospf network point-to-point// ip ospf dead-interval 20// ip ospf h
when going through devices with interface descriptions, for exampledescription “to site x interface gi0/0”;description “to site y interfaace gi0/1”:block pattern is description {desc:string}Since it is a description with multiple words and space delimited, is there a way to get the entire description no matter how many words there are? As the above would only get the first word.similar to the way I would use grep for example:grep '^description' ciscoconfig.txtor if I wanted specific columns or text within lines beginning with description, I would grep and use awk like belowgrep '^description' ciscoconfig.txt | awk '{print $2}'grep '^description' ciscoconfig.txt | awk '{print $2 $4}'grep '^description' ciscoconfig.txt | awk '{print $4 $2}'Etc.can anybody provide an NQE Example, Thanks
The API can be used to perform most functions available in the GUI. To perform complex queries of data in the API, it is necessary to insert an NQE query into the API call, or reference an existing NQE query in the Repository.In this example, we first create an NQE query in the Org Repository called list-interfaces. This NQE query will iterate through each device, interface, and sub-interface and list the IP addresses and MAC addresses for each interface.foreach device in network.devicesforeach interface in device.interfacesforeach subinterface in interface.subinterfaceslet ipv4 = subinterface.ipv4foreach address in ipv4.addressesselect { deviceName: device.name, interfaceName: interface.name, subinterfaceName: subinterface.name, ip: ipSubnet(address.ip, address.prefixLength), macAddress: interface.ethernet.macAddress}The output of the NQE in the GUI looks like this: In order to access this information via the API, you must first commit the query. Then get the Query ID and the Com
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.