Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
How do you create a custom SSL certificate for the fwd web interface?
Hello Team, we have an NQE thatsearches all L2 switches obtains each interface status obtains speed obtains sfp informationfor all ports in up state. So far, we have the following:foreach device in network.devicesforeach item in device.platform.componentswhere item.partType == DevicePartType.TRANSCEIVERlet interface = (foreach interface in device.interfaces where isPresent(findInterface(device, item.name)) where interface.name == findInterface(device, item.name).interface.name select interface)where length(interface) == 1let int = min(interface)select { deviceName: device.name, iface: int.name, speed: int.ethernet.negotiatedPortSpeed, partType: item.partType, partName: item.name,} Is there a way we could extract and add the below underlined in BLUE as additional columns as well? Thanks in advance for your time and help
Is there a way to connect external sources to a postgres database or consume a postgres DB backup? We cannot collect directly from type 1 encryptors but we can get a backup of the encryptor manager DB
I want to feed a list of ~5K IP addresses into forward and track the IP down to whatever info is available (device interface, standby address, device interface neighbor, host).I have two functions that build the lists of records that I need to join by ip address.FromCSV (~5K records) and allKnownIps (~200-300K records)What is the most efficient / elegant way to join essentially join these tables?I tried to build the smaller list first and then build the known IP list only if there is a match and then ran a nested loopcsvListIPs = (foreach ip in FromCSV select ip.ipAddr);// List of ~5K IPsallknownIpList = (foreach knownIp in allKnownIps where knownIp.ipAddr in csvListIPs select ip);//Filter for only known IPs in CSVlistforeach knownIp in allknownIpListforeach csvIP in FromCSVwhere knownIp.ipAddr == csvIP.ipaddrselect{};So I have two questions:Is there a more elegant way to do this? 5K IP's trying to match against the 250K Potential IP's (I have normalized everything so that it's ipv4
I finally managed to write a useful NQE query with no help. Yay! This query lists all of the loopback interfaces and their IP addresses. I tested it, and it works. But I am curious if there is a more efficient or elegant way to enumerate the IP addresses. Seems to me a little clumsy. getSubIfaceIpInfos(iface) = foreach subIface in iface.subinterfaces foreach subnet in subIface.ipv4.addresses select subnet;foreach device in network.devicesforeach interface in device.interfaceswhere interface.loopbackModelet ifaceSubnets = getSubIfaceIpInfos(interface)select { deviceName: device.name, interfaceName: interface.name, ipAddress: foreach subnet in ifaceSubnets select ipSubnet(subnet.ip, subnet.prefixLength)}
I am trying to use a where filter like so: where (a && b) || cPrettify keeps removing the parenthesis. Doesn’t this mess with the order of operations?
For Path Search Ranking, will devices that have a more specific subnet always rank higher than devices with a less specific subnet as the ingress device for a path?
We want to run two clusters in HA Active/Standby. We deployed one cluster yesterday and licensed it. We deployed the second cluster today. I am unclear on how we would license the second cluster. I assume we need a second deployment, but can I apply the same license to that new deployment, or would it require a new license as well?
I am trying to use the harvest the INVENTORY device state file but target the Description field, but I am unsure on on how to do that so that I can select it. I have the following:import "External/Juniper-EoS";foreach device in network.deviceswhere device.platform.vendor == Vendor.JUNIPERlet outputs=device.outputsforeach command in outputs.commandswhere command.commandType == CommandType.INVENTORYlet platform = device.platformwhere isPresent(platform.model)foreach part in platform.componentswhere isPresent(part.serialNumber)select { deviceName: device.name, model: platform.model, part: part.serialNumber, violation: if part.partId in juniper_eos then true else false}
Is there a way to add an "or" statement in a NQE? We are checking IOS versions against a model and Cisco says it can be this or that but the NQE we have looks like it's looking for both and throwing a false positive.
Is there a way to filter out duplicate MAC entries to get a unique MAC address count? Using the standard NQE library query under "L2 -> Mac Entries" returns every VLAN and device a MAC entry is seen on, skewing the results as shown in the example image.
We created the Forward Networks Community as a place to share NQE solutions and collaborate on innovative ways to better understand our networks. Network Query Engine (NQE) enables your network and security teams to search your network just like a database. NQE provides an open platform for accessing information about your network in easy to read reports and diagrams. This offers an interface for the uniform presentation of dozens of vendors, thousands of devices, billions of lines of configuration code, and multiple public cloud providers across your enterprise network. ❗Before you share any NQE script or screenshots from Forward Networks, ensure you remove sensitive information. This may include host names, IP addresses, company names, or other information you’d prefer to keep private. You can also choose an anonymous username if you wish to have an additional layer of privacy. What to include when you share an NQE: What it doesInclude a short description of what your NQE script do
Snapshots stopped working several days ago. Is there a way to check logs to determine the root cause?
Curious on how to work with strings in NQE? This video covers the basics of working with the String datatype in NQE. Let us know what have you done with strings that made your co-workers say “How did you do that!” Post your queries or questions below 👇🏻 Code examples used in videoReturn all devices where the first three characters of the device name is atlforeach device in network.deviceswhere prefix(device.name, 3) == "atl" select { deviceName: device.name}Return all devices where the beginning of the device name is atlforeach device in network.deviceswhere matches(device.name, "atl*")select { deviceName: device.name}Return all devices where the beginning of the device name is atl and contains the word spineforeach device in network.deviceswhere matches(device.name, "atl*spine*")select { deviceName: device.name}
Can you confirm where Forward would need access to upgrades so we can add those policies to our Firewall? (Ex AWS, S3, Gitlab etc). Also, if there’s any other reason Forward Networks would need to reach externally.Thanks
What happens when you are the sole subject matter expert on a part of the network, and something happens to it while you are in the middle of a root canal? Can Forward Enterprise help? Watch to find out!
Tuesday, Tuesday, Tuesday! It's a DEMO-lition derby of Attack Surface Management, Zero Trust, and Vulnerability Management-- all with the world's most extreme network digital twin, Forward Enterprise. I am, n the driver's seat, so buckle up and tune in!
In todays NQE video, join Mike on learning how to navigate the NQE library! Have any questions? Post them in the comments below 👇🏻
Watch the recordingJoin Nikhil to learn how SecOps teams are using Forward.Why is network data your most valuable asset to ensure compliance? Join Nikhil Handigol, Co-founder of Forward Networks, to explore our integrations with Tenable and Rapid7. The demo will highlight how our solutions deliver complete attack surface visibility that empowers SecOps teams to proactively identify impacted hosts with critical vulnerabilities accessible from the Internet or other critical exposure points in seconds.
Grab a fistful of tacos and watch me show you what Forward Enterprise can really do.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.