Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
Date: 10/14/2025Time: 6:00 PM – 6:30 PM Pacific (9:00 PM – 9:30 PM Eastern)Duration: Approximately 30 minutesForward Quest will undergo scheduled maintenance this evening to improve platform performance. During this time, the site may be temporarily unavailable.Please note: Avoid starting a new Quest challenge during the maintenance window. Any active sessions may be interrupted. Thanks for competing and leveling up in Forward Quest!
As part of my onboarding with Forward Networks, I’ve been exploring its native dashboarding capabilities. While the built-in dashboards offer useful insights, I’m not fully convinced they’ll meet the specific reporting needs of our leadership team.To address this, I’m evaluating two integration options:SharePoint: Using the Forward API to retrieve and transform data, then render dashboards tailored to our requirements directly within SharePoint. Grafana Cloud: If SharePoint proves limiting, I’ll explore leveraging our existing Grafana Cloud instance for more flexible visualization.Has anyone integrated Forward with either platform? I’d really appreciate any experiences, suggestions, or recommendations.Below is the format I think supports the SLT teams requirements.Thanks for any feedback.
The Framework Regional Variations Determining a Device’s Region Changing Variables Based on Region Knowing the Collection State Anatomy of a test Imports Pattern Matching Function Exceptions Report Putting Tests Together Making NQE Verifications Creating Scorecards Summary Ok, so you make all your configs using Ansible or Netbox Config Templates and are feeling good that you’ve got a consistent configuration everywhere - nice! Having a solid templating system to produce standardized configs is a great first step. But once the devices have been made live on the network, how can we run in-life tests to make sure their configurations have not drifted away from the ‘golden’ one they started out with? Two general approaches might be used for this: Regenerate configs periodically and compare them with the live config. Write specific tests for parts of the configuration (security hardening measures for example) and leave the remainder unchecked. Option 1 is a fairly simple approach
You may often want to find all pattern matches within the device configuration and filter the results based on a regular expression.The following NQE query uses a regex filter as part of a two step process in the getMatch(device) function.First, we find peer-group names in a Cisco BGP configuration and stores each match in a string called groupName by matching on the pattern defined at the top of the query.Second, we iterate through each each pattern match and filter the groupName based on the regex `^PUBLIC.*(?:-4|-X)$`The regex matches a string that starts with the word “PUBLIC” and end with either “-4” or “-X”.The main foreach loop at the bottom of the query applies the function getMatch to output a list of devices along with all the matching peer group names pattern = ```router bgp {number} neighbor {groupName: string} peer-group```;getMatch(device) =foreach match in blockMatches(device.files.config, pattern)let validRegex = re`^PUBLIC.*(?:-4|-X)$`let groupName = match.data.groupNa
Just posting up a simple Python script that allows you to make API calls from behind a proxy that also requires authentication.I have capitalised things that you need to customise. Of course it isn’t good practice to have usernames and passwords in your script so this is just for illustrative purposes.import requestsimport base64api_user = "YourApiUser"api_pass = "YourApiPassword"api_creds = api_user + ":" + api_passapi_bytes = api_creds.encode("ascii")api_encoded = base64.b64encode(api_bytes)print(api_encoded)api_string = api_encoded.decode("ascii")proxies = { "http": "http://YourProxyUser:YourProxyPassword@ProxyServerIp:ProxyPort", "https": http://YourProxyUser:YourProxyPassword@ProxyServerIp:ProxyPort",}try: response = requests.get("https://fwd.app/api/networks", proxies=proxies, headers={"Authorization" : "Basic " + api_string}) print(response.json())except requests.exceptions.ProxyError as e: print("Proxy error:", e)
CISA just issued Emergency Directive 25‑03 mandating actions to identify and mitigate a campaign exploiting zero‑day vulnerabilities in Cisco ASA / Firepower devices. While the directive is written for federal agencies, the threat is relevant to any organization using those platforms. Below is a summary, risk assessment, and recommended mitigations — along with what Forward Networks is doing to support customers. What’s Going OnCampaign targets Cisco ASA and Firepower / FTD appliances Exploits include unauthenticated RCE and privilege escalation Persistence observed via ROM manipulation Linked to 'ArcaneDoor' activity CVEs: CVE‑2025‑20333 (RCE) and CVE‑2025‑20362 (privilege escalation) Directive mandates inventory, forensic dumps, patching, and reporting Why This Matters to Forward CustomersIf you rely on Cisco ASA, ASAv, or Firepower/FTD appliances in your network perimeter or DMZ, your infrastructure may be at risk of compromise, persistent code injections, or deeper intrusion. Becau
You can use the NQE group function to collapse rows that have multiple matching columns.In the following example, we make a list of all devices in the network (and store in a list called data), and group all the devices in data together that have matching values for Vendor, Model, OS, and OS Version. The matching values are grouped by attributes.Note that list stored in data just has device names. We don’t actually list all the device names within the select statement. The device is the identifier for each unique element that is hidden when you use the group function. We access the list of devices in each group (within the list data) with a foreach loop in order to count the unique items and provide a total in the last column./** * @intent List devices grouped by matching Vendor, Model, OS, and Version and the total number of devices in each group. * @description List devices grouped by matching Vendor, Model, OS, and Version and the total number of devices in each group. */foreach dev
Flagging an important warning from the FBI / IC3, and sharing resources to help you assess and reduce risk. Alert Number: I-082025-PSA - Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure The High-LevelThe FBI is alerting that Russian FSB cyber actors (aka Center 16 / “Berserk Bear” / “Dragonfly”) are actively exploiting a known vulnerability in Cisco Smart Install (SMI) — CVE-2018-0171 — to target networking devices globally. These actors are using SNMP (especially older/insecure versions v1 and v2) and unpatched / end-of-life devices to:Collect configuration files. Modify configs to insert or enable unauthorized access. Do reconnaissance inside victim networks, with particular interest in protocols & applications used in critical infrastructure / industrial control systems.The vulnerability and use of legacy/unsecured protocols make aging equipment especially risky. Even if a device is not directly breached, weak practices may allow attackers in
This NQE extracts the config for each ACL, accounting for all syntaxes used in Cisco devices. The order is determined by the line number, which is used to compare the line of the deny statement with the last line of the ACL config and returns the failures by device and ACL name.standard(config) = foreach match in patternMatches(config, `access-list {aclName:string} {!"remark"}`) group match.line as config by match.data.aclName as name select { name, config };nested(config) = foreach match in patternMatches(config, `ip access-list {string} {name:string}`) let config = (foreach line in match.line.children where !hasMatch(line.text, re`.*remark.*`) select line) select { name: match.data.name, config };foreach device in network.devicesforeach acl in standard(device.files.config) + nested(device.files.config)let maxLine = max(foreach line in acl.config select line.lineNumber)foreach line in acl.configwhere hasMatch(line.text, re`.*deny\s*ip any any.*`) &&
Hello: Hopefully this isnt a repeat as i couldn’t find the answer on here so I wanted to post it. im trying to match against “tags” within the application, and everything I am tying, regarding the ‘where matches” command is used, isnt working. This is in the regular inventory so i have the statement “foreach device in network.devices” list as well above where i think the match line should go. I can it list the tags, just not match/filter on tags.
In this video, I demonstrate how Forward Enterprise replaces Infoblox NetMRI, which has now reached its Last Order Date (April 30, 2025) and will go end of support in April 2027. Many teams are looking for a solution that not only replaces NetMRI but also takes them far beyond its limitations — and that’s exactly what Forward provides. Here are a few highlights from the video:A true network digital twin: Forward mathematically models your entire environment — devices, topology, and paths — so you can validate intent, detect drift, and troubleshoot with precision. Continuous validation & automation: Changes can be verified before they’re deployed, and misconfigurations are flagged automatically. Multi-vendor and hybrid cloud support: Visibility and assurance across your whole network, whether it’s on-prem, cloud, or hybrid. Certified Infoblox IntegrationWe have a validated integration with Infoblox NIOS DDI. This is especially powerful for NetMRI users because:Network data (su
We’re excited to announce the launch of the newly reinvented Forward Quest — a monthly interactive challenge designed to put your Forward Networks skills to the test. Play Forward Quest What is Forward Quest?Forward Quest is an online game experience built around real-world network engineering scenarios. Each challenge is timed, and your results are added to a community leaderboard where you can see how you stack up against other Forward users. Why play?Forward Quest is more than just a game — it’s a fun way to: Sharpen your skills by solving challenges that mirror real engineering tasks. Learn by doing and discover new ways to use Forward Enterprise in real-world situations. Earn bragging rights (and prizes!) by climbing the leaderboard. Unlock badges that showcase your achievements in the community. How to play Head to Forward Quest Log in with your Forward Community account Start the first challenge and race the clock to see how fast you can solve it! The first monthly ch
Avoiding device management being exposed on interfaces to the internet is something that we all want to avoid, but if such an exposure was to occur wouldn’t you want to know?This query inspects all interfaces and specifically checks whether http, https, fgfm (FortiManager), snmp, and SSH are enabled via the set allowaccess command. To run this check you’ll need to configure a custom command.Custom Command Required.show system interfacesThe Query:/** * @intent Do not present fgfm, SSH, HTTPS on the internet ports * @description Check all interfaces that face the internet to ensure * "SSH","HTTPS" and "fgfm" are not present. Example Interface: edit "mgmt1" set vdom "root" set ip 169.254.255.2 255.255.255.255 set allowaccess ping https ssh snmp set status down set type physical set dedicated-to management set role lan set snmp-index 1 next */ifacePattern = ```config system interface edit {ifaceName:string} set ip
This is to discuss a common practice with the use of the interface Description field.It is really common to look at CDP or LLDP and find the neighbor device name, then put that remote device name into the interface Description of the interface that connects these two devices together. It is also common to add the remote device interface as well./** * @intent Verify if the interface description includes the device name of the linked device * @description Use the Link element of the data model to determine the device name and interface * of a networking device that is connected to this interface. * Verify that the remote device name and remote interface an included in the interface Description. */export getL3Interfaces(device: Device) = foreach iface in device.interfaces where length(iface.links) > 0 foreach ifaceIpInfo in getSvis(iface) + getSubIfaces(iface) select { name: ifaceIpInfo.name, adminStatus: ifaceIpInfo.adminStatus, operStatus: ifaceIpInfo.operStatus, ipv
If you’ve ever waded into the world of cybersecurity, you’ve probably run across the acronyms CWE, CVE, and KEV. They sound similar, and they’re all related to security flaws — but each serves a different purpose. Here’s a clear breakdown: CWE (Common Weakness Enumeration)Think of CWE as a blueprint of mistakes. Maintained by MITRE, CWE is a catalog of weakness types — ways that software or hardware can go wrong. A CWE is not tied to a single product; instead, it describes a class of design or coding errors. CWEs can be abstract (like “improper input validation”) or very specific (like “integer overflow in arithmetic operations”). Example: CWE-269 (Improper Privilege Management), which outlines the general problem of failing to correctly enforce privilege levels. CVE (Common Vulnerabilities and Exposures)CVE zooms in from the abstract to the concrete and specific. A CVE is an actual, identified vulnerability in a particular product or version. Every CVE entry includes metadata
Chinese state-sponsored threat actors are targeting network infrastructure worldwide, leveraging compromised routers and edge devices to establish long-term persistence and exfiltrate sensitive data. A recent joint cybersecurity advisory from NSA, CISA, FBI, and international partners highlights the scale of this threat and provides detailed mitigation guidance.At Forward Networks, we’ve created a purpose-built NQE query to help customers quickly identify two of the most common risks associated with this campaign:Known exploited vulnerabilities used by the threat actors to gain initial access Permissive ACLs that may allow traffic to flow to attacker-controlled IP addresses Why this threat mattersThe campaign—tracked in industry reporting under names such as Salt Typhoon and RedMike—isn’t limited to a single vendor or region. Attackers embed themselves in network devices, sometimes at ISPs or providers, then use those footholds to:Steal authentication information by redirecting TACA
OverviewWorking with IP addresses in NQE opens up all kinds of possibilities, but it’s not always clear what tools are available out of the box. I’ve worked with several customers who wanted to do everything from filtering IPv6 neighbors to calculating subnet utilization across thousands of devices—and the good news is, NQE makes a lot of this simpler than you might expect.In this post, I’m sharing five of my favorite IP address-related techniques that you might not know about, along with tips for using them in your own queries. 1. Use toNumber() to Compare IP AddressesWhen you want to compare IP addresses (e.g., sort them, find the lowest one, etc.), you can use toNumber() to convert each address into a numeric value.Note that this can only be applied to an IPv4 address.toNumber(10.1.2.3) // Converts to an integer based on its position in the full IPv4 rangeThis is useful for identifying router IDs or evaluating address ranges, especially when you don’t know in advance how the addres
In dynamic network environments, engineers often make quick changes directly to a device’s running configuration to resolve issues or apply updates. But if those changes aren’t saved to the startup configuration, they’ll be lost on the next device restart—potentially causing outages or security gaps.This oversight can lead to:Devices booting with outdated configurations Outages and service disruptions Security vulnerabilities if critical policy changes aren’t retained Manually verifying that all running configs are saved can be time-consuming and error-prone, especially in large environments. Forward Networks’ Network Query Engine (NQE) simplifies this process by automatically comparing the running and startup configurations across devices in your network.PrerequisitesAccess to Forward Enterprise with NQE enabled Cisco devices modeled in Forward Networks Network Admin role to create custom commands Add the following Custom Commands (requires Network Admin Role) show startup-
I have created the Forwords Network account .Why I can not login this vis this link.Forward Enterprise | Forward Networks Docs
Forward NQE includes several under-the-hood optimizations that can improve query performance. This post focuses on the _lookup optimization, which can reduce execution time when filtering on a single key field using an exact equality comparison. Leveraging _lookup is considered a best practice whenever possible.In a recent query I wrote joining device CVE information with the EPSS database in a network containing 10,000 devices, re-writing the NQE to take advantage of _lookup reduced the execution time by over 50%. While this kind of optimization isn’t as dramatic as parallelization—where a multi-minute query might drop to seconds—it can still offer a significant and worthwhile improvement, particularly in queries with repeated key-based lookups over large lists. What _lookup DoesNormally, when you write a loop in NQE that scans a list for a match, the query engine will iterate over every item in that list and check the condition. This can be slow if the list or number of devices in th
When an NQE runs in parallel, it executes the same logic across all devices in the snapshot inventory simultaneously, rather than one device at a time in sequence. In practice, this can be the difference between a query that risks hitting the 20-minute timeout and one that completes in a fraction of the time. When Parallelization HappensA query will run in parallel if:It starts with an iteration over network.devices It does not access network.devices in any other way (only one iteration) It does not access network.endpoints It does not use the group … by qualifierHow to CheckFrom the NQE IDE:Windows: Alt + left-click Execute Mac: Option + left-click ExecuteIn the debug panel, look for:parallel_foreach device in network.devicesIf you only see foreach device in network.devices, it’s not parallelized.Example 1 — Pass the Device Object, Not Its Name Broken (serial)Passing device.name into a function and then re-looking up the device causes a second iteration over network.devices.getDeviceV
Hello NQE Enthusiasts,Here is another Koan challenge. Use pattern list to find the following using Arithmetic Operators from the NQE documentation. Target:Bonus = Tenure * 1000Annual Bonus = Bonus + 10000Stock Award = 25 * Tenure Union Donation = Bonus + Annual Bonus / 10Bonus Pool = 200000Bonus Allocation = Bonus Pool / Bonus + Annual Bonusfin = "finance";eng = "engineering";sales = "sales_team"; Input:persons = [{ Name: "Fred", Tenure: 1, Department: fin }, { Name: "Justine", Tenure: 2, Department: fin }, { Name: "Barney", Tenure: 3, Department: eng }, { Name: "Joey", Tenure: 4, Department: eng }, { Name: "Jack", totalsales: 20000, Tenure: 5, Department: sales }, { Name: "Mike", totalsales: 10000, Tenure: 6, Department: sales }, { Name: "Sam", totalsales: 30000, Tenure: 3, Department: sales }, { Name: "Harry", totalsales: 25000, Tenure: 2, Department: sales } ];Result:select distinct { Name: person.Name, Tenure: person.Tenure, Bonus: bonus, Annual_Bonus: annualbon
I am looking for for BGP protocol which will show below details: device nameNeighborAddressoutbound Interface descriptionpeerDeviceName peerVrfpeer outbound Interface descriptionsessionState: neighbor.sessionStatepeerType (Internal/External) The one I created, but its not loading:import "@fwd/L3/Interface Utilities"; //getL3Interfaces(device: Device)getPeerInfo(neighbor, sourceRouterId) = max(foreach device in network.devices where device.name == neighbor.peerDeviceName let l3IfaceList = getL3Interfaces(device) foreach networkInstance in device.networkInstances foreach protocol in networkInstance.protocols where isPresent(protocol.bgp) let bgp = protocol.bgp foreach neighbor in bgp.neighbors where neighbor.peerRouterId == sourceRouterId let outIface = max(foreach l3Iface in l3IfaceList foreach address in l3Iface.ipv4.addresses where neighbor.neighborAddress in ipS
The following NQE query lists all the IP addresses that are part of a NAT rule on any device in the network./** * @intent List all NAT entries * @description List all NAT entries, including post NAT IPs */foreach device in network.devicesforeach natEntry in device.natEntrieslet headerMatches = natEntry.headerMatcheslet ipv4SrcSubnets = natEntry.headerMatches.ipv4Srclet ipv4DstSubnets = natEntry.headerMatches.ipv4Dstlet ipv4NatSrcSubnets = (foreach rewrite in natEntry.rewrites select rewrite.ipv4Src)let ipv4NatDstSubnets = (foreach rewrite in natEntry.rewrites select rewrite.ipv4Dst)where isPresent(max(ipv4NatSrcSubnets)) || isPresent(max(ipv4NatDstSubnets))select { deviceName: device.name, "NAT type": natEntry.natType, "Source IP": ipv4SrcSubnets, "Destination IP": ipv4DstSubnets, "Source port start": (foreach tpSr in headerMatches.tpSrc select tpSr.start), "Source port end": (foreach tpSr in headerMatches.tpSrc
I see the filter function and count function shows as unknown functions in NQE query. Please help with appropriate functions for these two. I need to count the total number of interfaces in a devices and interfaces operational status DOWN in state.
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.