Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
foreach d in network.devicesforeach i in d.interfaceswhere length(i.links) != 0where i.adminStatus == AdminStatus.DOWNselect {deviceName:d.name, interface:i.name}
Launch Podcast Join Craig Johnson (@captainpacket) and William Collins as they discuss the power of community, and then dig into the growth and adoption of Digital Twins and where they fit in today’s tech stack. Topics covered include:The Concept of Digital Twins in Networking: Drawing parallels to other industries like manufacturing. Craig explains that a digital twin is a digital representation of a real-world network, allowing for easier troubleshooting, visualization, and understanding of network components and configurations. Evolution of Digital Twin with Cloud and Automation: Craig discusses the evolution of digital twin solutions, particularly in the context of cloud and automation. The conversation highlights the importance of extending digital twin capabilities to multi-cloud environments and standardizing network forwarding logic across vendors. Core Technical Components and Implementation: Craig outlines the technical components required for implementing a digital twin, fo
Well let me tell you something brother! You think you know everything about Zero Trust?? You don't know diddley about network security without a network digital twin. Watch @Mike hit viewers with the figurative folding chair of knowledge or be hit by one. Tune in to see which it is!
Good news, you can ask it all the questions you want with Forward Enterprise's new AI Assist feature. Watch @Mike use natural language to perform Network Query Engine searches-- no matter your role or skill level, you can conduct sophisticated network queries with a minimal learning curve.
How can federal agencies possibly comply with the HUNDREDS of complex specifications in the DISA STIG compliance checklists? @Mike has special guest @devecis in studio to learn how a network digital twin can streamline your federal network compliance and give you full confidence heading into an audit.
For those interested in security certifications, I wanted to pass along this hidden gem of certification training.Ben Malisow is an excellent technical editor and trainer, and is the guy behind the wannabea.. certification training programs. I would highly recommend his trainings for CISM, CISSP, CCSP, and SSCP for anyone interested in these certifications. - https://www.wannabeacism.com/
Sometimes a path search may not present the results you expect. When engaging with support regarding a path search issue, you may be asked to provide a snapshot with the relevant path search data. To capture a snapshot of a path search, first perform the path search in question. In this example, we are performing a simple path search from atl-ce01 to atl-core-pe01: Now, press and hold the Alt or Cmd key, and the icon on the far right of the query bar will change from ‘Copy Query’ to ‘Export Query’. Click on the ‘Export Query’ icon: The Export Snapshot wizard will now display all devices relevant to that path, and allow you to add any additional devices you wish to add to the snapshot (if necessary). Finally, obfuscate the IP and MAC addresses if necessary, and export the snapshot: This will allow you to download a zip file snapshot of the path search and all devices within the path of this search. This will provide the support team with all data necessary to investigate your path sear
An FW engineer was looking to get the results from the command, “show firewall vip”, from all Fortinet Firewalls in Forward Networks. Command: show firewall vipconfig firewall vip edit "x-7.6.254.158-dns" set uuid d60c0a52-2630-51eb-9d53-bc032ca5e1c0 set extip x.x.x.x set mappedip "y.y.y.y" set extintf "any" next edit "x.x.x.1/32" set uuid 796a2ac2-2251-51ec-5c82-26b2e049a7a7 set comment "Voice LAB" set extip x.x.x.1 set mappedip "y.y.y.1" set extintf "any" next edit "x.x.x.2-y.y.y.2" set uuid 9ea63058-47ac-51ec-2a7f-5b0d00a1d142 set comment "Cloud" set extip x.x.x.2 set mappedip "y.y.y.2" set extintf "any" next Finding the command in the data model /** Thank you Danny Ramirez with the Smarts on this * * @intent Grap VIP's on Fortinets command.output of "show firewall vip" * @description Define VIP format, and then iterate through to pull the VIP * Name and theMapped
As network engineers, we have few tools that can help us correlate the actual state of our network devices, and our intent. In many cases maybe our intent is not clearly defined: How many EIGRP neighbors is the set of core switches really supposed to have? How many neighbors should I be learning a specific prefix from? How many entries should I have for prefix x in my EIGRP Topology or my OSPF Database? Is my intent to have all the entries installed in the Route Table as ECMP paths or should I only ever have 1 next-hop that only changes if a path becomes unavailable? In the network engineering realm specifically, even with automation tools like Ansible - without structuring your playbook logic very specifically - there are assumptions being made about the current state of the network. Even if your Ansible repos & playbooks are structured in a declarative and idempotent fashion, they are not exactly a consumable way for a network engineer to learn about the network - and you are re
Morning folks! We recently got the opportunity to leverage Forward Networks NQE for a Cyber Security ask. They want to verify that EC2 Instances are not being assigned the default Security Group. This should be a simple enough task. AWS creates the security group with the name ‘default’ so all we need to do is create an NQE Query that checks our Cloud Objects with a type of ‘instance’ and verify that the list (I’m assuming it is a list type) of security groups does not contain ‘default’. However, after reviewing the NQE Data Model I’m not convinced the ‘Cloud Objects’ are exposed in such a way we can correlate instance to security group. Can someone confirm or deny this?I do see that the instance tags are exposed as part of the ComputeInstance data model, so a workaround would be for us to edit our Terraform code so that security groups assigned to the instance are also created as tags on the instance so we can expose that correlation for consumption in NQE.
Forward Networks parse, processes and normalizes the snapshot details gathered. You have heard this term over and over again. Let’s use this method to see all of the subnets across all AWS, GCP and Azure deployments. This NQE query is based upon the example in the DataModel for network → cloudAccounts → vpcs → subnets → ifaces /** * @intent Enumerate the Routing Table for all Cloud Providers * @description Enumerate the Routing Table for all Cloud Providers. The notModeled column indicates the ipAddress is not modeled. */ipModeled(ipAddress) = foreach cloudAccount in network.cloudAccounts foreach vpc in cloudAccount.vpcs foreach subnet in vpc.subnets foreach iface in subnet.ifaces where ipAddress in iface.ipAddresses select iface.ipAddresses;foreach cloudAccount in network.cloudAccountsforeach vpc in cloudAccount.vpcsforeach routeTable in vpc.routeTablesforeach route in routeTable.routeswhere isPresent(route.nextHop)let nextHop = route.nextHoplet ipAddress = when nextHop is
Azure VNet peering and Global VNet peering routes the subnets in each VNet as defined by the VNet routing table. In some cases the Cloud Account configured in the Forward Networks platform does not have permission to enumerate all the necessary VNets. One needs to update the Microsoft Azure subscriptions service principals to include the missing VNets. But how does one find the VNets that are not modeled but referenced by other VNets? NQE, of course. The method of finding missing VNets is fairly straightforward. Similar to using the widely used “check for missing next hop route peers” NQE query, this NQE performs a similar task./** * @intent List VPCs / Microsoft Azure VNets that are not modeled. * @description Need the Microsoft subscriptions to be added to the service principal. See the VPC / VNet values in the destinationVPCId column. */idsOfCollectedVpcs = foreach cloudAccount in network.cloudAccounts foreach vpc in cloudAccount.vpcs select distinct vpc.id;foreach cloudAcc
Forward Networks NQE is very powerful. The information is there. The examples are clearly written for copying and pasting to create or combine new queries. This NQE lists the AWS Hosts / Instances with MAC address(es). Listing the instance type (ex: t2.micro) enables sorting by size. Or, finding whether the instance is up or down. Or simply listing all instances across all accounts. /** * @intent List all AWS Hosts and MAC Addresses * @description List all AWS Hosts and MAC Addresses */foreach cloudAccount in network.cloudAccountsforeach vpc in cloudAccount.vpcsforeach computeInstance in vpc.computeInstancesforeach iface in computeInstance.instanceIfacesforeach subnet in vpc.subnetswhere subnet.id == iface.subnetIdforeach subnetIface in subnet.ifaceswhere subnetIface.id == iface.ifaceIdselect { cloudAccountName: cloudAccount.name, vpcId: vpc.id, computeInstanceId: computeInstance.id, name: computeInstance.name, tags: computeInstance.tags, isUp: computeInstance.isUp, imag
The method of using the Forward Networks search bar to list all devices where a subnet is learned or advertised is very useful. This NQE lists the route, egress interface, interface description and a bit more. Displaying the next hop MAC address and associated OUI vendor is useful in determining whether the next hop is a router or firewall. /** * @intent List IP Prefixes / Route Table entries for all Routers * @description List the Route Table and egress interfaces detailes. Useful to determine where a particular route is, and what routes egress a device or interface. */getNextHopDesc(deviceName, interfaceName) = foreach interface in deviceName.interfaces where interface.name == interfaceName select interface.description;getNextHopMac(deviceName, interfaceName, ipNextHop) = foreach interface in deviceName.interfaces foreach subinterface in interface.subinterfaces let ipv4 = subinterface.ipv4 foreach neighbor in ipv4.neighbors where neighbor.ip == ipNextHop select neighbor.li
Keeping track of IP subnet allocation across multiple AWS accounts can be challenging. With NQE you can query all the VPCs at once.The following NQE query list the root level CIDR blocks for each VPC, and then shows how the IP space is allocated across each subnet.foreach cloudAccount in network.cloudAccountsforeach vpc in cloudAccount.vpcsforeach subnet in vpc.subnetsselect { cloudAccountName: cloudAccount.name, vpcId: vpc.id, ipv4CidrBlocks: vpc.ipv4CidrBlocks, subnetId: subnet.id, name: subnet.name, tags: subnet.tags, addresses: subnet.addresses, region: subnet.region, availabilityZone: subnet.availabilityZone} This NQE goes even further, showing the UNALLOCATED IP space in each CIDR block. That is, the IP prefixes within each VPC that have NOT been assigned to a subnet:/** * @intent Find all unallocated IPv4 VPC CIDR blocks * @description An unallocated CIDR block for a VPC is a CIDR block assigned to the VPC but not used by any subnet. * The restriction to IPv4 is because
I’m not sure if most people check back on the built in configs in the Forward Library, but this one is pretty slick. Are these part of release notes or anything? I looked in the NQE documentation and didn’t find anything related, but I could be looking in the wrong spot.@queryquery(Operating_Systems: List<OS>, Device_Name_Patterns: List<String>, Config_Pattern: PatternBlocks<{}>) = foreach device in network.devices where isPresent(device.files.config) where length(Operating_Systems) == 0 || device.platform.os in Operating_Systems where length(Device_Name_Patterns) == 0 || max(foreach pattern in Device_Name_Patterns select matches(device.name, pattern)) foreach match in blockMatches(device.files.config, Config_Pattern) select { Device: device.name, OS: device.platform.os, "OS Version": device.platform.osVersion, Model: device.platform.model, Match: match.blocks, Tags: device.tagNames };Regardless, these queri
Hey Folks!I’m looking to find out if anyone has modeled their corporate VPN access - maybe using Synthetic Devices - in such a way that allows you to search for user workflows to determine if they are allowed, and have them properly modeled as coming in through the VPN Firewall instead of at the switch VLAN. We are looking to create intent checks for access through our VPN. Happy NQEing!
In this NQE Video, I am going cover and how to use let and group-by qualifiers.Join me for a look at the two NQE qualifiers, let and group-by.Code examples used in videoforeach device in network.deviceslet deviceName = device.namelet affected_interfaces = (foreach interface in device.interfaces group interface.name as interfaces_name by interface.operStatus as oper_status select { int: interfaces_name, oper: oper_status,})foreach entry in affected_interfacesselect { deviceName: deviceName, interfaceNames: entry.int, operStatus: entry.oper}LetUsing let to assign expressions that make the code more easily readable, in this case assigning the device OS version and operating system to variables and filtering on them foreach device in network.deviceslet version = device.platform.osVersionlet os = device.platform.oswhere os == OS.ARISTA_EOS && matches(version, "4.15*")select { deviceName: device.name, version: version, os: os}Grou
I am working on automated resolution of failed connections. Two questions: (1) On this page in the documentation: /docs/nqe/data-model/type_devicecollectionerror/ there is a list of errors but no descriptions. Can someone provide? (2) I am studying a failure report and the Connect Test Status notes each of these in PHASEs which seems to imply that each is determined in a sequence. Is there a list of PHASE order for these? AUTHENTICATION_FAILED-AUTHENTICATION PHASEAUTHORIZATION_FAILED-AUTHORIZATION PHASECONNECTION_FAILED-CONNECTION PHASEDEVICE_IS_CHILD_CONTEXT-SETUP PHASEDEVICE_TYPE_MISMATCH-TYPE_DISCOVERY PHASEDEVICE_TYPE_UNDETECTED-TYPE_DISCOVERY PHASEGUEST_MISSING_HOST_RESULTS-SETUP PHASEJUMP_SERVER_AUTHENTICATION_FAILED-CONNECTION PHASEJUMP_SERVER_CONNECTION_FAILED-CONNECTION PHASEOTHER-AUTHORIZATION PHASEPING_FAILED-CONNECTION PHASEPORT_REACHABILITY_FAILED-CONNECTION PHASEPRIV_PASSWORD_ERROR-SETUP PHASEPROMPT_DISCOVERY_FAILED-SETUP PHASESESSION_CLOSED-TYPE_DISCOVERY PHASETIMED
The MTU query that comes canned in Forward Networks was pretty cool. However, I just wanted the MTU info on links that contained an LLDP or CDP neighbor entry, b/c I just don’t care about the MTU of of access devices, just the infrastructure links.I tried to also modify to not pull MTU on Mgmt Interfaces (ma1, MA1, mgmt0) However, I’m still pulling some ‘ma1’ interfaces! Oh well .I just sort it out later, but if anyone sees the issue, chime in./** * @intent Return the MTU of interfaces that contain a CDP or LLDP neighbor * @description rcariddi 6/30/2023 Find All links of CDP/LLDP, make sure each side of the link matches. This allows us to ignore non infrastructure links * If we want all values, remove the line: where isPresent(interface1.cdp) || isPresent(interface1.lldp) **/foreach device1 in network.devicesforeach interface1 in device1.interfaceswhere isPresent(interface1.mtu)where isPresent(interface1.cdp) || isPresent(interface1.lldp)where toLowerCase(interface1.name) not in ["m
I hope everyone had a relaxing holiday and New Year!Now that we are getting back into the swing of things, do you suspect there are rogue devices in your network, but you have no easy way to find them? I remembered what I had to do back in the day to find rogue devices, and needless to say, it was not easy to find them. Could Forward Networks help Mike find these rogue devices? I had the same question, and I enlisted the help of our resident NQE expert, Jack Shen, to see if we could identify and locate where these unwanted devices are easily. Code example used in the demoThe NQE query that was used in the video to find if there were any Huawei devices in their network is below. foreach device in network.devicesforeach host in device.hostswhere isPresent(host.macAddress)let assigneeName = ouiAssignee(host.macAddress)where isPresent(assigneeName)let vendor = toUpperCase(assigneeName)select { violation: matches(vendor, "HUAWEI*"), deviceName: device.name, deviceInterfaces: host.int
In todays NQE Video, I will show you the basics of using if expressions and how to use them when you want to create your own multi-vendor parser.Code examples used in videoThis particular parser is going to look at DNS servers and check to make sure that they are configured with the appropriate servers.dns_addresses = [ipAddress("1.1.1.1"), ipAddress("1.0.0.1")];ios_xe = ```ip name-server {dns:ipv4Address+}```;arista = ```ip name-server vrf {string} {dns:ipv4Address+}```;palo_alto = ```config devices localhost.localdomain deviceconfig system dns-setting servers primary {dns:ipv4Address+} ```;cisco_asa = ```dns server-group {string} name-server {dns:ipv4Address+}```;generic = ```dns {dns:ipv4Address+}```;foreach device in network.deviceslet os = device.platform.oslet dns_pattern = if os == OS.PAN_OS then palo_alto else if os == OS.IOS_XE then ios_xe else if os == OS.ARISTA_EOS then arista else if os == OS.ASA then cisco_as
In today's video I will introduce the NQE foreach and where statements. We explore the data model and how to start off your NQE queries as well as go into when and why you would want to use a where statement.Code examples used in videoReturn all IPsec tunnels and create a report of the peer IP address, interface status and operational statusforeach device in network.devicesforeach interface in device.interfaceswhere interface.interfaceType == IfaceType.IF_TUNNEL_IPSECselect { deviceName: device.name, tunnelName: interface.name, peerIP: interface.tunnel.dst, adminStatus: interface.adminStatus, operStatus: interface.operStatus}You could modify the above to violate if the administrative status is up but the operational status not up with the following NQE query:foreach device in network.devicesforeach interface in device.interfaceswhere interface.interfaceType == IfaceType.IF_TUNNEL_IPSECselect { deviceName: device.name, tunnelName: interface.name, peerIP: interface.tunnel.dst, v
Join Mike on a journey to introduce a feature of the Forward Enterprise platform called the Network Query Engine (A.K.A NQE) and why it will make your job as a network or security operator much easier. Let us know what you think about NQE; what do you see yourself using it for? If you have any questions ask them below 👇🏻 Code example used in videoReturn a violation if an interface on a Cisco IOS XE device is administratively up but operationally downforeach device in network.devicesforeach interface in device.interfaceswhere device.platform.os == OS.IOS_XEselect { deviceName: device.name, interfaceName: interface.name, adminStatus: interface.adminStatus, operStatus: interface.operStatus, violation: interface.adminStatus == AdminStatus.UP && interface.operStatus != OperStatus.UP}
Join me for a look at the comparisons you can use in NQE to filter out on what data you need to see in your query. Code examples used in videoUsing equals (==) to return any default routes in any VRF foreach device in network.devicesforeach networkInstance in device.networkInstanceslet afts = networkInstance.aftslet ipv4Unicast = afts.ipv4Unicastforeach ipEntry in ipv4Unicast.ipEntrieswhere ipEntry.prefix == ipSubnet("0.0.0.0/0")foreach nh in ipEntry.nextHopswhere isPresent(nh.ipAddress)select { deviceName: device.name, vrfName: networkInstance.name, RouteEntry: ipEntry.prefix, nextHop: nh.ipAddress}Using not equal to (!=), to exclude ASA’s a platform inventory reportforeach device in network.deviceswhere device.platform.model != "ASAv"select { deviceName: device.name, deviceModel: device.platform.model }Choose whether or not to report on interface MTU that is:Greater than 1500 ( > ) Greater than or equal to 1500 ( >= ) Less than 1500 ( < ) Less than or equal to 1500
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.