Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
In cloud environments, the complexity of network architecture, especially with the prevalent use of NAT (Network Address Translation), often obscures visibility, making the detection of duplicate subnets a challenging task. This lack of transparency can lead to network inefficiencies, conflicts, and potential security risks. The NQE query I'm sharing specifically addresses this challenge, offering a streamlined approach to uncover hidden duplicate subnets, a crucial step in maintaining a robust and efficient cloud network. To tackle the issue of detecting overlapping IPv4 CIDR blocks across different VPCs in cloud environments, I've developed a precise NQE (Network Query Engine) query. This query methodically scans through all cloud accounts and their respective VPCs, identifying any instances where IPv4 CIDR blocks overlap. The query is designed to compare each VPC within a cloud account against others, ensuring comprehensive coverage and accurate detection of duplications. Below is t
At Forward Networks, ensuring a seamless and efficient support experience for our users is our top priority. Our revamped Support Portal is designed to make getting the help you need both straightforward and swift. Here’s how you can navigate our user-friendly platform:Creating a Support Account Submitting a Support Request Tracking Your Support RequestsCreating a Support AccountAccess the Portal: Visit our Support Portal at https://support.forwardnetworks.com.Log In or Register:Already a Community Member? Use your community credentials to sign in.New Users: Registration is a breeze! Just follow these simple steps: Click on ‘Sign Up’. Enter your email and choose a password. Verify your email by clicking the link sent to your inbox. Set up Two-Factor Authentication (2FA) with your preferred TOTP app for added security. Submitting a Support RequestOnce logged in, you’re all set to submit a support request. Here’s how to ensure your request is handled efficiently:Determine the Urgency: Se
Join me on an introduction to working with Lists in NQE. We cover some of the basic list comparisons and the list function length().Code examples used in videoReturn all Arista devices, and if the device is not running the approved OS, return a violation for that deviceapproved_os = ["4.15.0F"];foreach device in network.deviceswhere device.platform.os == OS.ARISTA_EOSselect { violation: device.platform.osVersion not in approved_os, name: device.name, version: device.platform.osVersion} There is another way to write this query. We can write it so that it will only return all devices that are violating versus returning every device and violating the devices that are not compliant. This query would look like:approved_os = ["4.15.0F"]foreach device in network.deviceswhere device.platform.os == OS.ARISTA_EOSwhere device.platform.osVersion not in approved_osselect {violation: truename: device.name, version: device.platform.osVersion} We are using where only to filter devices that are run
Hi! Looking for help with an NQE to scan/identify configuration for all Cisco switches within a workspace that contain one of two QOS policy maps within at least one of the device interfaces. For example interface gigabitethernet1/1 service-policy output 1P7Q3T orservice-policy output 1P7Q1T Thanks
In todays video, we are going to look at the basics of working with numbers and booleans in NQE. Code examples used in videoCheck to make sure that the distribution switches that run spanning-tree in a newly acquired DC are running the correct root bridge priority, if not show a violation rbPri = 5297;foreach device in network.devicesforeach stpRoot in device.stp.rapidPvst.vlanswhere matches(device.name, "sjc*dist*")select { violation: rbPri != stpRoot.bridgePriority, device: device.name, vlanID: stpRoot.vlanId }Any questions or comments, post them in the comments below 👇🏻
Forward’s own Matt Honea (@matthonea), Head of Security and Compliance, and Mike Lossmann (@Mike), Technical Product Marketing Manager recently presented at Security Field Day 10 (XFD10).Matt and Mike bring diverse experience in cybersecurity and networking infrastructure to these presentations from XFD10. Learn as Matt dissects today’s threats, how they’re delivered, and how to protect your organization from similar attacks. Mike provides a demonstration of the Forward Networks Enterprise application, specifically highlighting how it can safeguard your organization’s network and, in turn, your organization’s valuable intellectual property. Do you have questions or want to learn more? Ask below! The Game Changer - Network Digital Twin for Network Security with Forward Networks Matt and Mike discuss reasons why are so many network security breaches are hitting hitting the headlines lately Matt Honea guides you through the latest news-worthy exploitations of network vulnerabilities a
Background on the Jump Server for FWD Enterprise Forward Enterprise obtains data for path analysis primarily using industry-standard command-line interface (CLI) access. This is typically done with secure shell (SSH) read-only credentials provided to the platform so that configuration and state can be retrieved. In certain customer instances, it is required to limit SSH access to a specific host or hosts, which will more effectively audit and maintain the security of network devices. This is commonly known as the bastion or jump server. A jump server, jump host, or jump box is a computer on a network used to access and manage devices in a separate security zone. The most common example is managing a host in a DMZ from trusted networks or computers. A jump server is a hardened and monitored device that spans two dissimilar security zones and provides a controlled means of access between them. User access should be tightly controlled and monitored OpenSSH is commonly used for configurati
In todays video, we are going to go into a deeper dive on the NQE files tab. We discuss the different states the NQE queries can be in and go over the permission structure in NQE. Any questions or comments, feel free to post them below
I am trying to get the BGP advertised and received prefixes for Arista EOS and Cisco NXOA devices. I tried the below two queries and they only work for IOS and IOS-XE. devicesBGP Received routes ----------------------------------------------------------foreach device in network.devices// where device.name == "jcdwans01"where isPresent(device.bgpRib)let bgpRib = device.bgpRibforeach afiSafi in bgpRib.afiSafisforeach neighbor in afiSafi.neighborswhere isPresent(neighbor.adjRibInPost)let adjRibInPost = neighbor.adjRibInPostselect { deviceName: device.name, platform: device.platform.os, afiSafiAfiSafiName: afiSafi.afiSafiName, neighborNeighborAddress: neighbor.neighborAddress, routesCount: length(adjRibInPost.routes)}BGP advertised routes -foreach device in network.deviceswhere isPresent(device.bgpRib)let bgpRib = device.bgpRibforeach afiSafi in bgpRib.afiSafisforeach neighbor in afiSafi.neighborswhere isPresent(neighbor.adjRibOutPost)let adjRibOutPost = neighbor.adjRibOutPostforeach
This is both incredibly amazing and absolutely frightening. The cat is extremely out of the bag now.Boston Dynamics put a generative AI into the robot dog Spot. And there are different personalities.
If you are in/near the Atlanta area on Nov 14, please join me at this Optm event where I will presenting with other executives from Optm, Infoblox, BigPanda, and LogicMonitor. I’d love to connect in person, and happy to have additional conversations. Event Registration
We had a fun costume contest for Forward employees and their fur babies. Here are the winners!Our co-founder, Peyman, won Best Costume!Our infra engineer, Manuel, won Most Original Costume!Our apps engineering manager, Gayathri, won Scariest Costume!Gayathri’s dog, Nash, won Best Pet Costume!What do you think of the costumes? Do you have any fun ones to share of your own? 🎃
You can now attach EC2 interfaces to multiple different VPCs in AWS: https://aws.amazon.com/about-aws/whats-new/2023/10/multi-vpc-eni-attachments/ The implications of this are pretty huge - previously to control access (with a firewall, etc) between VPCs you needed to use a Transit Gateway, generally associated with a centralized applicance via a Gateway load balancer. This solution is great and scales very well, but its probably overkill for smaller environments. What if you only have 2-4 VPCs? This solution would work great - simple attach your NVA interfaces to different VPCs and modify your route tables accordingly. This eliminates the cost and complexity of TGWs, keeping all the performance benefits. What use cases can you see for this new functionality? Off the top of my head, you could also provide remote access without using a VPN gateway too. I’m sure there are more. This also models correctly out of the box in Forward as well :)
WHO DARES TO INVESTIGATE THE DARK PRESENCE WITHIN THE NETWORK DURING AN AUDIT? Network modeling illuminates the dark corners of your network, so you don't have to be scared anymore. No boogeyman can derail your network audit because the 'digital twin' models all of your network devices, even the cloud, with mathematically-accurate precision. It’s the single-source of truth trusted by the world's largest networks. It’s not dark magic — it's Forward Enterprise.
Is it possible to use a SSH jump server to log into a Telnet server, and then from there log into each of the devices?
In Part 1 we introduced several techniques for dealing with semi-structured data to parse a Juniper Inventory. In Part 2 we will leverage a few more techniques to parse a more complex output. 1. Let’s setup our test by grabbing the output from the “show chassis hardware” command. remember to use the multi-string block delimiter “””We have 5 columns Item, Version, Part number, Serial number and Description, but we are only interested in three: Item, Serial number and Description. output = """Hardware inventory:Item Version Part number Serial number DescriptionChassis JN2221837ABC MX960Midplane REV 03 710-013698 TR0123 MX960 BackplaneFPM Board REV 03 710-014974 JZ1111 Front Panel DisplayPDM Rev 03 740-013110 QCS1012345U Power Distribution ModulePEM 0 Rev 07 740-029344 QCS1012346U DC 4.1kW Power Entry ModulePEM 1 Rev 07 740-029344 Q
Sometimes you need to parse out information that is not in the NQE data model for various reasons. It maybe device specific information that is not generalizable across vendors, or not generally useful in dataplane analysis but maybe important for operations. Importing this data is beyond the scope of this post but you can read more about it here: Getting Custom CommandsFirst, I am going to demonstrate how you build up your parsing chops by leveraging a testing approach to NQE, then will demonstrate how this can be applied to your collection data. Setting up your testing. We need to represent the data that our custom command will import into the snapshot. We can represent this by setting a variable to a multiline string using the delimiter ”””output = """Item Version Part number Serial number FRU model numberMidplane REV 03 710-013698 TR0001 CHAS-BP-MX960-SFPM Board REV 03 710-014974 JZ2323 CRAFT-MX960-SPEM 0 Re
This is a check I wrote to check BFD Status on Arista and IOS-XE as a single combined query. Unfortunately, I can’t change the name of the title to include Arista && IOS-XEscreenShot /*** @intent BFD State Arista & IOS-XE* @description Add Command 'show bfd neighbors || peers' and report status - apply to EOS and IOX-XE Devices**/EOS_BFDPattern = ```{DstAddr:ipv4Address} {MyDisc:number} {YourDisc:string} {Interface:string} {Type:string} {LastUp:string} {LastDown:string} {LastDiag:string} {State1:string} {State2:string} {State3:string} {State4:string} ```;iosXE_BFDPattern = ```{ip:ipv4Address} {LD:string} {RD:string} {State:string} {Int1:string}```;// Define EOS FunctionArista_BFD = foreach Device in network.deviceslet Platform = Device.platformwhere Platform.os == OS.ARISTA_EOSlet Outputs = Device.outputsforeach Command in Outputs.commandswhere Command.commandText == "show bfd peers"let parsed = parseConfigBlocks(OS.ARISTA_EOS, Command.response)let matchData = blockMatche
Many customers often ask me about digging into data, especially when it involves sifting through device status or custom command outputs. Sometimes, it's a piece of cake to handle because the data is nicely structured, but other times, it's like solving a puzzle. Just last week, I was helping out a customer who needed to extract security policy data from their enforcement points to keep tabs on various compliance matters. The data they had to deal with was all over the place – lines of varying lengths, multiple strings scattered within the lines, and positional changes for the data we needed.This got me thinking, and I wanted to share some techniques for handling these tricky data chunks. I can't share the exact customer query with you, but I've thrown together a sample query to show one way of tackling this.Imagine you've got data like this:"Don't teach me how to extract stuff with IP address 10.1.1.1 and float 10 from string." "Please teach me how not to extract stuff with IP addres
Audit our DNS configuration on Arista Devices and Cisco Devices - Would like to be able to combine the script as a single check, and started it (Second Code Script), but it’s not working yet, I need a little tutoring. /** * @intent Audit DNS Configuration on Arista * @description Searches through the running configuration for a pattern match. */DNS_Standard = ["name-server 1.7.7.7 & 1.7.7.8", "dns domain net.xyz.com ", "ip domain lookup source-interface Loopback0"];AristaPatternDNS =```ip domain lookup source-interface Loopback0dns domain net.xyz.comip name-server vrf default {ipv4Address} ip name-server vrf default {ipv4Address} ```;/* Select a list of devices by vendor */foreach device in network.deviceswhere device.platform.vendor == Vendor.ARISTA || device.platform.os == OS.ARISTA_EOSlet outputs = device.outputsforeach command in outputs.commandswhere command.commandType == CommandType.CONFIGlet response = command.response/* parse out the pattern defined above from the respons
I’m taking the show on the road! Watch how the Blast Radius feature can localize a compromised host in seconds, even while on vacation, with Forward Enterprise. Live from Forward Networks HQ in sunny Santa Clara, California.
No one can hear you scream in outer space when the network is down! Join me to see where forward can help!
I’d like to use FN APIs to integrate with Splunk and SIEM / Security systems. Has anyone else done this?
Are there any character restrictions for tags? I would like to use ’ : ‘ in a tag as a namespace but want to be sure there won't be any caveats. I don't see anything in the docs.
Is there a reference to building new dashboards using NQE derived values as inputs?
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.