Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
Using NQE to do Configurations Compliance checks require having the proper structure for the searched text pattern.Ex: this will not match eventhough that line exists within the configurations, but it’s not in the root levelPATTERN=```set admintimeout 10```;So, to match this line we have to provide the proper structure, or recusively add an extra level until a match is foundSo, modifing that example to one of the below patterns should workPATTERN1=```config system global set admintimeout 10```;PATTERN2=```{(string)+} set admintimeout 10```;So, in this example it was only 1 level down, so it’s straight forward to fix.But having to work with different patterns with different nesting levels the below code can be used to automatically modify the provided pattern and recursively search all the different levels Beware that there are many limitations due to the actual version of the language.ex: splitting a string is not straight forward, so the pattern has to be provided as a list of strings
One of my colleagues told me that some of our devices had licence issues.output from show licence usage shows the issue easily, so custom command is the way to go SOMEDEVICE# show license usageFeature Ins Lic Status Expiry Date Comments Count--------------------------------------------------------------------------------….NXOS_ESSENTIALS_M4 No - Unused - -FC_PORT_ACTIVATION_PKG No 0 Unused -LAN_ENTERPRISE_SERVICES_PKG No - In use Honor Start 70D 15H-------------------------------------------------------------------------------- The key part is to extract the features for the device, and check that the No is present, with In Use also present.This is done via the following function, which determines valid input and detects violation.blockData =```{feature:string} {active:string} {licenceCount:string} {status:string}```;customCommand = "show license usage";getRe
I like to give my team little challenges to exercise their NQE skills. Why don’t you play along this weekend and let’s see all the different ways you can accomplish this goal. Tune in to see some creative ways to solve the FizzBuzz challenge with NQEFizzBuzzThe task is to write a program that prints the numbers from 1 to 100, but with a twist:For multiples of three, print "Fizz" instead of the number. For multiples of five, print "Buzz" instead of the number. For numbers which are multiples of both three and five, print "FizzBuzz" instead of the number.
One of the painful parts of trying to audit configurations, is accounting for the variations in the configuration that differ based on Vendor/Model/OS etc… Additionally, accounting for ‘old’ configurations/mis-configuration across these variations adds an extra (sometimes silent, sometimes not) “WTF” as one attempts to isolate the problems.With initial input from Arica , I wound up writing 2 scripts to find the ‘new’ configuration and one to find the old, then ‘xlookup-ed’ the differences in excel. Not to fun, but it was effective enough. Then I figured, how hard could it be to combine them? It was harder than I though, so I created the shell, and then asked for some help from a colleague (thanks Ahmed).@AricaFN@AhmedKhedr The result of the script produces an easily scanned results for the problems.Model ---- DeviceName ---- GoodConfig --- BadConfig/*** @intent Ensure SNMP Communities are correct* @description 2 columns, one column showing where the "GOOD Strings are, and another colu
For the networks I work on there are a lot of different servers, mainly due to environmental conditions such as NAT that are used for the basic management of the devices. This include authentication, snmp-traps, ntp, syslog and so on.The following code allows us to see at a glance all the unique servers ip addresses, along with a reference to each device being used.It’s very easy to list this as individual records, but sometimes it’s nice to consolidate this to show the number of servers, and how many devices are using them. One such use case, may be when moving device from old/demising servers to new servers.This script is a skeleton for Tacacs, it does not deal with the various different command syntax across the various vendors and is just shown as an example. In this case for Cisco.Firstly a function to get the information from each device, namely the authentication server and the device name.getTacacsDeviceEntry(device) = foreach match in patternMatches(device.files.config, `t
Hello,With the actual version of NQE not providing direct way to initialise an Empty list ex:let empty_list = []orempty_list = [] A workaround for this is to construct the creation of that list and providing a value with the same data type you need// an empty List<String>FALLBACK =foreach x in [""]where x != ""select x; // an empty list of NumbersFALLBACK_NUMBERS=foreach x in [0]where x != 0select x; Taking this logic further we can create a function that provides us an empty list of whatever generic type. by taking a default value of that type as an input, then comparing against that value The below block contains the full PoC code// an empty List<String>FALLBACK =foreach x in [""]where x != ""select x;// an empty list of NumbersFALLBACK_NUMBERS=foreach x in [0]where x != 0select x;// An empty list of a generic type TemptyListT(default_val)=foreach x in [default_val]where x != default_valselect x;foreach a in [""]let empty_list_of_strings = FALLBACKlet empty_list_of_number
Before we head off into the weekend I was hoping to ask the community what their stance is on schema based network configuration interfaces like NetConf and OpenConfig GNMI. Question 1: Do you currently or plan to use NetConf and/or GNMI to manage policy across your network? Do you leverage this in your automation pipeline? If so, do you find sufficient vendor support?Question 2: If you do leverage NetConf/GNMI for configuration data, do you still want to inspect the policies via CLI?Thanks for your insights.
As part of doing configuration audits for our NX-OS devices, I needed a check to see if two conditions were met in a configuration to check compliance.If both conditions were present → GoodIf one condition was met and the other wasn’t → BADElse if → Both conditions were not present → Also good.This is relatively simple with a single condition, but adding another variable, kind of stumped me. Credit to Glen Turner @FN for solving the logic puzzle on this.The example below is for OSPF enabled and SNMP traps for OSPF is enabled. This logic can be used for many other two condition checks such as //VarsPatternNetFlow = ```feature netflow```;PatternNetFlow_Config = ```flow timeout active 60```;//FunctionsCheckPattern(config , pattern) = !hasBlockMatch(config, pattern);&& //VarsPatternBFD = ```feature bfd```;PatternBFD_Config = ```bfd interval 300 min_rx 300 multiplier 3```;//FunctionsCheckPattern(config , pattern) = !hasBlockMatch(config, pattern); /** * @intent Ensure DC NX-OS Devic
On May 21st we have shown the integration between Forward and NetBox in a joint webinar. UPDATE: The webinar recording is now available on YouTube:https://youtu.be/TSX14uke1NE.The description includes a link to the webinar slides and the GitHub repository. The integration is part of the NetBox’s Network Automation Architecture framework where Forward provides the Observability and Assurance piece, as shown in the picture below:NetBox Network Automation Architecture The first use case is about onboarding an empty NetBox instance with device data collected by Forward, such as Devices, Interfaces, Vendors, Location, and so forth.Onboarding an empty NetBox instanceThe integration is based on a Python script. It imports the data from Forward using NQE queries via REST APIs, transform the data from the Forward to the NetBox schema and then exports it to NetBoxThe process can be automated using a web-hook so that NetBox is updated every time Forward collects from the network.To run the integr
I have a problem where the two lines of this module output are not the same. How can I put in essentially null place holders so that they resultant patterns are the "same"?example outputNotice that module 2 does not have Fw or Sw.Mod MAC addresses Hw Fw Sw Status 1 a03d.6f81.0740 to a03d.6f81.074f 1.1 15.0(1r)SG12 03.07.03.E Ok 2 b0aa.777d.d010 to b0aa.777d.d017 1.0 Ok I was trying to use these two patterns and tried to put in placeholds of Fw and Sw at the end of "pattern03". But the NQE does not like this.pattern02 = ```Mod MAC addresses {modNum:number} {string} to {string} {hwVer:string} {fwVer:string} {swVer:string} {modStatus:string}```;pattern03 = ```Mod MAC addresses {modNum:number} {string} to {string} {hwVer:string} {modStatus:string} {fwVer: null:string} {swVer: null:string}```;getMacAddrList(parsedOutput) = foreach pattern in [pattern02, pattern03] foreach match in blockMatches
Problem StatementOur company had issues where some network leafs were not connected to all our spines within an ACI fabric.Traditional methods to validate this were time consuming so we developed a basic NQE query to assist.How it workswe leverage the LLDP information for the network leaves and match this to our spines. In our case, we rely on the device naming convention to match LLDP entries to spines. Our spines have SP within the name.NQE ScriptFunction to gather the links to spines for a given device/* * function: countSpineNeighbours * * parameters: device: Device * * purpose * ------- * * count the number of links that are between the spines and the leafs * * spines are matched based on the SP in the device name, at position 8 * * returns: dict * * { * deviceName: string * interfaceName: string * } */countSpineNeighbours(device) = foreach interface in device.interfaces where interface.interfaceType == IfaceType.IF_ETHERNET foreach n in interface.lldp.neighbors where
Happy Thursday All! I hope you’re having a great week. I know it’s been a busy one so I’ve highlighted this week’s most popular articles and discussions in the community. Did I miss one of your favorites? Add it in the comments below! Here’s the list... @AricaFN ‘s article on extracting data from custom commands is a great discussion for anyone that has to go beyond the data model to tailor the Forward platform to their organization’s specific needs. @Christopher is on fire (hehe) with this new NQE query that uses the Forward Enterprise aclEntry object to provide consistent output from any Firewall vendor. And if you’re interested in automation, @Christopher’s article on interfacing with Forward with API and Python is a great example to follow. @Mike ‘s complete NQE tutorial video series is the go to for anyone learning NQE or experts brushing up on the finer points. Building on @cariddir‘s scripts, @RobertWelch create this plug-and-play NQE to unify the Fortinet Version output for
Sean Deveci, Federal Systems EngineerAndreas Voellmy, Sr. Director of Engineering Join me, @devecis, and @Andreas as we show you how to upgrade your NQEs, making them easier to troubleshoot, more scalable, and more resilient. These techniques are not only great for NQE, but will also up improve your Python and Javascript. Work side-by-side with us as we show you how to:Improve the results of your scripts to maximize the end-user experience. Streamline your scripts so they're easier to read, manage and share. Make your scripts more resilient so they can keep up with your changing environment. Ask questions below and let us know what you'd like to see in future demos!
Some customers have asked, “How do I run a custom command on just a few devices, to test if it gives me what I need for an NQE query?” You can do this with a workspace network!First, click the Network drop down and choose Add Workspace network Add a name for your Workspace and click Next. Add the device or devices you want to test the custom command(s) on and click Add X devices. Then Next. Check the custom command group you want to include in the Workspace and click Next and Done. You can also skip this step and add the custom command in the workspace later. Make sure you are in the new Workspace network in the Network selection drop-down. Go to Settings > Collection Settings > Custom commands and enable the Custom command group.(You can also add a new custom command from this page by editing the command group or adding a new one.) Return to the main page by clicking Search, and then choose Take Snapshot from the snapshot drop-down. This will collect the data using your cust
Forward Networks includes serial numbers in its model as part of the component object. So if you want to see the serial number for a device, you must iterate through the components of that device. The serial number for the device itself usually belongs to the chassis, but some vendors may have multiple controller cards. The serial numbers for line cards, power supplies, etc will also be listed as components with serial numbers.There is a build-in NQE query in the Forward Library called Device Hardware that is included in Inventory+ by default. If it has been deleted from Inventory+, you can add it back by clicking on Inventory+ > Add NQE Queries and then selecting the Device Hardware NQE and clicking add and then Add.Note the foreach component in platform.components loop and the component.serialNumber entry in the NQE query code below:/** * @intent Information about device hardware */foreach device in network.deviceslet platform = device.platformforeach component in platform.compone
I am trying to create a NQE query for all the F5 devices. The query searches for SSL profile on custom command. Custom Command is : show ltm virtual detail recursive | grep -E "Ltm::ClientSSL Profile:" -E "Virtual Server:"The NQE should return SSL Profiles and the VIPs associated with them.
This is a script to pull switch port stats from our access switches in our network. The data pulled in this script is used for ‘right sizing’ and network planning. We can then export the results, and pivot table them to see the % of switch ports in use/not-in use. I’ll add this attachment later./*** @intent Show int counters on Arista & IOS-XE Switches * @description * 1. Check to see what switch ports have had no traffic accross the wire for sizing and planning. * 2. Match on platform.os* 3. Use the information from the custom command 'show int counters'.* 4. Get counts of switch ports on that device so we can use to calculate % in use**/// Pattern of output// Arista & Cisco Same ColumnsTraffic = ```{Port:string} {InOctets:number} {InUcastPkts:number} {InMcastPkts:number} {InBcastPkts:number}```;// Arista FunctionEOS_Stats = foreach device in network.deviceswhere device.platform.os == OS.ARISTA_EOSforeach command in device.outputs.commandswhere command.commandText == "sh int
AWS - Public IPv4 charge changes Back on Jul 28, 2023, AWS announced forthcoming changes to their billing for IPv4 public IP usage, which take effect as of Feb 1, 2024. In summary, AWS says, "Effective February 1, 2024, there will be a charge of $0.005 per IP per hour for all public IPv4 addresses, whether attached to a service or not (there is already a charge for public IPv4 addresses you allocate in your account but don’t attach to an EC2 instance).". More information can be viewed here: https://aws.amazon.com/blogs/aws/new-aws-public-ipv4-address-charge-public-ip-insights/. Update Apr. 2, 2024: In light of this, Forward Networks can assist with keeping track of your Public IP usage via an improved NQE Query located in “NQE->Library->Forward Library->Cloud->AWS->Public IPv4 Cloud Cost” that will show you what's being used: /** * @intent Shows the number and cost of AWS public IPv4 IP addresses */import "L3/IpAddressUtils";// $0.005 per hour per IPcostPerIpPerDay = 24.
Hi,I wrote an NQE query which is expected to return devices with CRITICAL severity only. The query returns almost a million results which is unlikely. Each device has so many rows with CRITICAL CVEs. foreach cveDatabase in [network.cveDatabase]foreach cve in cveDatabase.cvesforeach device in network.deviceslet platform = device.platformlet Severity = Severity.CRITICALselect { "Device Name": device.name, "CVE ID": cve.cveId, "Severity": Severity.CRITICAL, "Vendor": platform.vendor, "Model": platform.model}
We have started to do some testing with FN. In our AWS network, we are using Cisco Firepower Threat Defense (FTD) devices managed by Firepower Management Console (FMC). FN is able to connect to an FTD and retrieve device details but does not support retrieval from FMC.In our network, for complicated routing reasons, we can’t easily enable FN to connect to our FTD instances. I can, however, provide a URL that will retrieve all the information from FMC. I would like to configure an “HTTP(S) external source” to provide that info. What I cannot figure out, however, is the required format for the data to that is returned by the URL GET. The document just states that FN will “infer” the schema. In my case, there’s no inference needed. I am writing the code that will return the info. I can format the data however FN needs it.For those who care about the details, the implementation is an AWS Lambda function that connects to the FMC REST API and returns the info. An AWS API gateway provides the
Hi all, We are getting “No processed Snapshot found. Please take a Snapshot and try again.” when trying to hook Forward Network with SNOW CMDB, anyone has any idea why this happen ? ( We do have snapshots already taken and processed) Thank you
Incident Management: A Proactive Approach to Minimize Disruption Experiencing an incident can be chaotic, with alarms sounding off and urgent communications flooding in, often at the least opportune moments. The key to effective incident management is not just to respond with urgency but to anticipate and mitigate issues before they escalate. The TL;DRTo effectively manage incidents, you must first establish visibility across and baselines of your network. Know what’s normal and what’s not. Ensure robust logs are being collected in a centralized manner, and contain all relevant details to facilitate troubleshooting. Develop your response team. Know their strengths and weaknesses, and ensure everyone on the team has skin in the game. publish playbooks, runbooks, and other procedural documents so everyone knows what is expected of them during an incident. Foster relationships with your peers and other teams long before an incident ever begins. And always strive to improve your incident m
No time! Skip to the demo. @nikhilhandigol demonstrates how generative A.I. unlocks network insights and shows the Tech Field Day delegates how Forward Networks seamlessly incorporates generative A.I. into its network digital twin software. Inside the most popular product feature, Network Query Engine, every user can perform natural language queries to access crucial network data in seconds. You can watch the entire Tech Field Day here. Got questions? Ask below!
Every network engineer can associate with 7:58 In this introduction, @Mike explains Forward Network's digital twin software, Forward Enterprise, and how network digital twin benefits more than just networking people. Forward Enterprise analyzes every possible network behavior, traces where every packet could ever go, and gives every user a queryable vendor-independent data model so NetOps, SecOps, CloudOps and even Compliance teams can get a mathematically-accurate view of the network.Check out the entire Network Field Day series here
This is a simple NQE to run a custom command to report on the ABOOT Version and Platform of Arista Devices. From Arista:In a small set of cases systems may experience an unexpected reboot. The reload is due to an uncorrectable ECC error caused by a corner case timing conflict on the CPU sub-system tracked by bugID 419257. This bug affects the range of CPU models present in these products. The affected systems are not restricted by specific serial numbers or date code ranges and the reload is unpredictable. Systems running Aboot6 BIOS revision lower than 6.1.7 or 6.0.9 and Aboot4 BIOS revision lower than 4.1.1 or 4.0.7 are susceptible to this issue. There are currently 4 release trains of Aboot across these systems: 4.0.x and 4.1.x, 6.0.x, and 6.1.x. A single common patch file will introduce the update across all release trains and is not platform or version-specific----------------------------------------------------------------------------------------------------------The custom Comma
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.