Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
When attempting to access the Vulnerabilities page I get the following errors.Jakarta.servlet.servletexception:request processing failed:java.util.concurrent.completionexception:java.util.nosuchelementexception:no value presentThis error has accord since the last time I updated my CVE using the Vulnerabilities page.
If you manage Cisco ASA, Firepower, or Secure Firewall anywhere in your environment, this one demands your immediate attention.On April 23, 2026, CISA published Analysis Report AR26-113A, a malware analysis report on a backdoor known as FIRESTARTER. The report — issued jointly with the UK’s National Cyber Security Centre — confirms that at least one U.S. federal agency was compromised through a Cisco Firepower device, and that the attackers used FIRESTARTER to maintain persistent access even after the device was patched and rebooted. CISA has urged every organization running Cisco Secure Firewall ASA or Firepower Threat Defense (FTD) software to assess exposure now.This isn’t a brand-new vulnerability story — the underlying CVEs have been in CISA’s Known Exploited Vulnerabilities (KEV) catalog since September 25, 2025. What’s new is the depth of evidence about how the ArcaneDoor threat actor (tracked by Cisco Talos as UAT-4356) is operating after initial exploitation, and just how per
As of April 15, NIST is changing how it handles CVEs in the NVD. The new approach is risk-based: every submission still lands in the NVD, but only a subset will get the full analysis and enrichment treatment going forward:CVEs in CISA’s Known Exploited Vulnerabilities (KEV) catalog CVEs in software the federal government uses CVEs in “critical software” as defined by Executive Order 14028Everything else — including the existing backlog — gets marked “Not Scheduled.” NIST is also dropping its own severity scoring for most CVEs, to “reduce duplication of effort.” The full breakdown is on the NVD process page.The rationale is reasonable — CVE volume has exploded, and central triage at that scale was never going to hold forever. But in practice, the single source a lot of security and network teams have been leaning on for enrichment is about to get a whole lot thinner. That’s worth pausing on. The hot takeHere’s a line straight out of our own documentation FAQ:“We use the NIST National Vu
This is a companion post to CISA Adds CVE-2025-53521 to KEV: What It Means for F5 BIG-IP APM SystemsIf you manage Rockwell Automation/Allen-Bradley programmable logic controllers anywhere in your environment — or if you're responsible for any network that touches operational technology — this advisory is one of the most serious things to land in 2026.On April 7, 2026, six U.S. government agencies issued a joint advisory: the FBI, CISA, NSA, EPA, Department of Energy, and U.S. Cyber Command. When that many agencies co-sign a warning, it reflects both the severity of the activity and the breadth of the threat. The advisory (AA26-097A) confirms that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-facing Rockwell Automation/Allen-Bradley PLCs across multiple U.S. critical infrastructure sectors, resulting in operational disruptions and financial loss. What's HappeningSince at least March 2026, an Iranian-affiliated APT group has been targeting in
A common network configuration is to have hosts(servers) connected to a leaf switch, which in turn is connected to spine switches, and finally to an upstream L3 switch / gateway.Host → Leaf Switch (ToR) → Spine Switch(s) → L3 Switch / Gateway(s)in this scenario, no hosts are directly connected to the spine switch.Suppose the Network Team wanted to upgrade a Spine switch. Ideally, a leaf switch would not be impacted by a single spine switch going offline. However, the Network Team must still notify application owners for servers on downstream switches with potential impact.The following NQE query can be used to list all access switches and their hosts that are downstream from a given switch:import "@fwd/Interfaces/Interface Utilities";@queryquery(deviceName: String) = foreach device in network.devices where device.name == deviceName foreach link in getLinkedInterfaces(device) let remoteDeviceName = link.remoteDeviceName foreach remoteDevice in network.devices where remoteDevice.na
If you manage F5 BIG-IP Access Policy Manager (APM) anywhere in your environment, this one demands your immediate attention.On March 27, 2026, CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation of a critical flaw in F5 BIG-IP APM. Federal Civilian Executive Branch (FCEB) agencies were given until March 30, 2026 — just 72 hours — to remediate. That kind of deadline reflects just how serious CISA considers this threat. What Happened — and Why the UrgencyThis vulnerability has a bit of a history that makes it particularly tricky. CVE-2025-53521 was originally disclosed by F5 back in October 2025 as part of their quarterly security advisory cycle. At the time, it was categorized as a denial-of-service (DoS) vulnerability with a CVSS v4 score of 8.7 — serious, but not immediately alarming for organizations that were still working through their patch queues.Fast forward to March 2026. F5 revised its advisory based on new
The Problem with “It Doesn’t Hurt Anything”Over time, stale configuration creates real friction:Configs become harder to read and reason about Engineers hesitate to make changes because “something might depend on it” Troubleshooting takes longer because it’s unclear what actually matters The network slowly accumulates configuration debtNone of this usually comes from bad configuration. It comes from old configuration that was never cleaned up.The Core ObjectiveThe primary objective of this approach is not to modify or remove configuration automatically, but to make potential problem areas visible.Identify configuration elements that are likely unused Extract them in a consistent, scalable way Present the results in a form that engineers can easily understandOnce those configs are visible, humans can make informed decisions instead of guessing.NQE for Cisco ASAThis NQE identifies objects that are not used by any ACL entries. This is just one example of how we can quickly identify “conf
Hi TeamI am looking for some help to create a workplace in FN.This workplace will contain only CISCO devices and NQEs (BGP status and Interface Status). I want to auto execute this workspace (snapshot) by every 30 mins so that I can fetch interface and BGP status of cisco devices. Any help on this really appreciated. Thank you.
We're excited to share that, by popular demand, In-App Audit Logs are now available, giving org admins full visibility into activity across their Forward Networks platform - no support ticket required. Where to find itHead to Platform → System → Audit Logs to get started.Full visibility into platform activityAudit Logs capture every meaningful change in your environment, including create, update, and delete operations, as well as authentication events. Every log entry includes the timestamp, originating IP address, the user who performed the action, the HTTP method used, the target object affected, and the outcome, giving you a complete, reliable picture of what happened and when.Accountability built inImpersonation activity is fully visible too. If an action is taken on behalf of another user, the log clearly reflects that, so you always have an accurate record of changes in your environment.Powerful filtering and exportFinding the events you care about is quick and easy. Every column
Hi team,Is there a way to see or get API logs to know which user has performed what kind of api calls & actions ( read / view / change) using thier account?
Sequential Thinking in NQE using State Pipeline One interesting challenge when writing logic in NQE is that the language does not support a traditional sequential programming style (loops, mutable variables, recursion, etc.).But we can emulate iteration by threading state through a series of transformations.This resembles techniques used in functional programming such as state threading or CPS-like transformations, where computation is expressed as a chain of pure transformations.Let’s look at a simple example: computing the integer log₂(i) using a sequential algorithm.Sequential C-like styleint log2(int i) {int e = 32, b = 0;while (e >= 1) { if (i >= 2 ** e) { i /= (2 ** e); b += e; } return b;}Conceptually, each loop iteration transforms the state:(i, e, b) → (i', e/2, b')Since NQE has no while statement, we first unroll the iterations:if (i >= 2^32) { i /= 2^32; b += 32; }if (i >= 2^16) { i /= 2^16; b += 16; }if (i >= 2^8) { i /= 2^8; b += 8; }if (i >= 2
I’ve brought this up a few times on calls with our account team. It would be really helpful if we could filter with a bit more flexibility in Sources & Inventories.Currently, if I’m searching for a Tag the logic is a “OR” so if I want a device in “APAC” && “Switch” && “Arista” I can’t get a reduced set of devices.It would be great to combine the filtering to isolate devices more quickly.
Depracated - please see:For updated version This is a script that @rob helped greatly with. It parses through SNMP configuration on IOS-XE devices. Then does a comparison of the templates in the file and provides:What’s missing, what is extra, and the captured configuration.I’ve added additional functionality to leverage tagging, which helps identify which config block belongs to what kind of devices. I have documented as best I can, hopefully this helps other as much as it’s helping me. /*** * @intent SNMP Validation (IOS) * @description Validates Cisco IOS-XE SNMP configs and extracts community/host details. * * LOGIC SUMMARY: * 1. Checks device against 3 regional patterns (AMRS, EMEA, APAC). * 2. Uses the 'Hybrid Approach': * - Uses 'device.files.config' (Bag) for the blockDiff engine (Accuracy). * - Uses 'configAsString' (String) for Regex extraction (Speed). * 3. Outputs a clean table with missing lines and current settings.***/// Tagging Function to look for tagged devices in or
Continuing scripts to pull more information from Cisco WLC’s. Find my original Cisco WAP post here: Pre-requisites:Add Custom Command to IOS-XE for collection “show ap image | inc None” Add Tag of “WLC” on your Wireless Controllers WLC’s are on c9800 running IOS-XE IOS-XE version is 17.x.x/*** @intent - pull Name & OS Versions from Cisco AP's via Cisco WLC's* @description Log into Cisco WLC's "C9800" and pull AP information from the controllers with "show ap image | inc None"**/// Pattern of output//AP_INFO = ```{APName:string} {PrimaryOS:string} {BackupOS:string}```;foreach device in network.deviceslet platform = device.platformforeach Tag in device.tagNameswhere Tag == "WLC"foreach Command in device.outputs.commandswhere Command.commandText == "show ap image | inc None"let parsed = parseConfigBlocks(OS.IOS_XE, Command.response) //parses text into lineslet matchData = blockMatches(parsed, AP_INFO) //applies pattern to linesforeach x in matchDataselect { name: device.name, Loca
updated Scripts: 1This NQE script audits NTP configuration compliance for IOS-XE Branch devices in the AMRS and EMEA regions. It compares each device's running configuration against locally-defined gold standards (approved NTP server IPs per region, with variants for LAN switches, SDWAN routers, and WLCs — both with and without VRF syntax). For each device it identifies missing NTP servers (present in the standard but absent from the device) using blockDiff, and extra NTP servers (configured on the device but not in the approved list) using set subtraction. The results are output as a compliance table with a violation flag, the missing/extra server details, and device metadata derived from tags (region, environment, function, manager). Edit the IP’s in the xxxx Standard to your own (and remove what you don’t need).Additionally, there is a Utility in here (export_get_list_match_from_tags) at the beginning. The code requires the devices to be tagged with a region (AMRS APAC EMEA LATM) Th
Version 26.2 of the platform introduces new enhancements to topology, including line drawing and multi-select capabilities.You will now see the Line tool in the Annotations section, allowing you to add straight lines to your network diagrams alongside the classic shapes already available. Lines can include arrows, be displayed as solid or dashed, and support the same colour options as any other annotation element.Multi-select enables you to select multiple annotation elements at once and move them as a single object, a valuable capability as your diagrams grow in scale and complexity.I spent some time this morning trying out the new features on one of our lab networks:Multiselect and lines in actionEnhancements such as these form part of our ongoing, iterative approach to evolving Topology into a comprehensive, one-stop destination for accurate and easily understood network diagramming.What enhancements would you like to see in the Topology? Let me know in the comments.
CISA recently issued Emergency Directive 26-03, requiring federal agencies to take immediate action to mitigate vulnerabilities affecting Cisco SD-WAN systems. The directive was issued after security agencies observed active exploitation of vulnerabilities that could allow attackers to gain privileged access to SD-WAN management components.Federal agencies must quickly identify affected systems, apply vendor fixes, and verify that SD-WAN management infrastructure is not exposed or compromised. This post outlines what the directive requires and how Forward Enterprise helps organizations rapidly identify impacted infrastructure, validate exposure, and confirm remediation across complex networks. Who should read this postSecurity and Network Operations teams managing Cisco SD-WAN infrastructure Network engineers responsible for WAN edge, SD-WAN controllers, or branch connectivity Risk and compliance professionals working in public-sector or enterprise environments responding to CISA d
Keeping track of hardware lifecycle isn't just good practice anymore - in many cases, it's required. Regulations like Europe's Digital Operational Resilience Act (DORA) and the UK's Telecommunications Security Act (TSA) now require organisations to document legacy infrastructure.Forward Networks already provides End of Life (EoL) data for Cisco and F5 devices to help customers prepare for these audits. With our latest update, Check Point is now supported too. That means one less vendor to track manually.Using a simple NQE query, like the one I made below, you can quickly generate reports across your Cisco, F5, and Check Point environments for their EoL state. Add it as a verification check to get alerts when devices go EoL, or create a custom scorecard to monitor the current EoL status of your estate. foreach device in network.devicesforeach component in device.platform.componentslet componentViolation = if isPresent(component.support) && isPresent(co
Hi team, I am new to the forward networks enterprise solutions and recently facing some issues in the application. I have set of network devices with different vendors (Cisco, Fortinet, huwawei, F5, etc) in my workspace with application version 25.11 and have configured a daily snapshot collection schedule. Recently I observed the snapshots are not been collected fornthe last 2 days and tried to find the cause, I see there is a timeout error popping up for all my network devices under the workspace. I tried to check what are the devices added in last 2 days under Diffs section by comparing the last successful snapshots versus last failed snapshot to narrow down the issue thinking any dew device added might have caused the issue due to modelling errors but couldn't find any devices newly added. Since I have 800+ devices I am not able to narrow down the issue and reached out to support for assistance and awaiting reply. Meanwhile, I thought to post this issue/behavior here to see if a
Hello NQE Enthusiasts,Here is another Koan challenge. A group of friends went for a hike. They were Biff, Betty, Fred, Archy, Ethel, Edgar and Xavier. While they were hiking, two of the friends had to turn back early and not finish the hike with their friends. Before the group ended their hike they found another of their friends on the trail. That person joined them for the rest of the hike.Here is the group of friends that finished the hike together. Biff, Betty, Jorge, Fred, Ethel and Edgar.You could eyeball this and tell me the answer, but try using NQE to answer these questions.Which two friends had to turn back early?Which friend joined them in the middle of the hike?Try not to look at the replies until you have tried the challenge yourself. Hints:There is a structure within NQE that is similar to a “group”.You are looking for the remainder of one “group”.Contributions: Tyson Henrie
CISA issued Binding Operational Directive 26-02 on February 5, 2026, requiring Federal Civilian Executive Branch (FCEB) agencies to eliminate unsupported edge devices from their networks. These end-of-support (EOS) devices no longer receive vendor security updates and are actively exploited by nation-state threat actors as entry points into federal networks. Federal agencies must now take immediate action to inventory, update, and ultimately replace these vulnerable devices across strict timelines. This post outlines what the directive requires and how network visibility platforms can address the operational challenges of meeting these requirements. Who should read this postSecurity and Network Operations teams managing edge infrastructure including routers, firewalls, load balancers, and VPN gateways Network engineers responsible for maintaining network perimeter devices across hybrid and multi-vendor environments Risk and compliance professionals working in public-sector or enterpris
In release 26.1 we brought out a feature that eases the onboarding of new devices quite a lot. If you have a good naming convention (or three, in the case of some of my customers) you can use this to good effect.Let’s see how it works. Here are some devices I just added (one of which isn’t collecting yet, I know). They are all located in a site called Farnham, but initially go into the Default unassigned location:Newly-added devices in the default location Imagine I had just added a few hundred devices using a CSV or something. Moving all these unassigned devices into locations would be a long job, right? Not any more…. Now we can use wildcard matching to put them into a location based on their name. The steps are shown in the GIF below:open up the Manage Locations menu (in Sources) edit the location of interest edit the device list at that location choose the Dynamic Match option enter a pattern to match on - e.g. pop1*Entering the dynamic match for a location Now we define th
Problem OverviewHow much could I save on my Cisco support renewal, if I could just tell what devices are ‘over-licensed’?That is a question that one of my customers was struggling with. Trying to answer this kind of question is very difficult if you have a large estate of switches that has been deployed over time. To complicate things, there are also various generations of Nexus switches and a number of licensing models and names. It is all very confusing.This script hopefully gives you the ability to answer this question, and in addition it calculates a 🚨 potential cost saving 🚨 based on licence prices you enter at the start.The result of this script is a report that looks like this: If that has got you interested, read on! Cisco NXOS LicensesIn terms of licensing, Nexus mainly breaks down into two license types - a switching-only license and a dynamic routing license. Depending on the model of Nexus, this will be ESSENTIALS (switching) / ADVANTAGE (routing/switching), or it m
In the latest release, Forward Networks significantly optimized the CVE (vulnerability) experience—both in performance and in how engineers investigate exposure and risk across their network. The changes focus on faster load times, clearer filtering, and more actionable context when you’re analyzing which devices Clickable Risk Metrics with Live FilteringThe high-level CVE widgets (e.g., “devices receiving traffic from the Internet,” “known exploited,” “unconfirmed vulnerabilities”) are now fully interactive. Clicking any of these automatically applies the corresponding filters to the device and CVE tables, instantly narrowing the view to what actually matters.Those filters also persist when you drill down into CVE detail pages, so your investigative context is never lost. Unified CVE View Across Multiple VendorsInstead of duplicating the same CVE multiple times (once per vendor), a single CVE entry now shows all affected vendors and platforms together—for example, Juniper, Cisco,
Ready to put your network skills to the test? Compete in the Forward Quest Capture-the-Flag challenge at Cisco Live in Amsterdam! We’ll have multiple daily competitions and the overall winner each day will take home a pair of Airpods Pro 3 that feature Live Translation. Join us February 9–12, at RAI Amsterdam (Booth D01), and compete against other network professionals to solve real-world network scenarios with speed and accuracy. Register for a date and time to compete at https://forwardquest.live/ using your Forward Community username and password, then stop by the booth to jump into the challenge and climb the leaderboard. You can compete in one competition per day. Each day, the top performer will take home a pair of AirPods Pro 3! Where: Cisco Live EMEA, RAI Amsterdam (Booth D01)When: February 9-12, 2026Register for a time to complete: https://forwardquest.live/ See you in Amsterdam!
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.