Connect with others to answer questions, gain new insights, and grow your networking knowledge.
Recently active
After spending the last 8 weeks as an intern, I’ve learned a lot about network digital twins and how they enhance visibility, maintenance, and security. You can read more about my experience in this post. Over the last few weeks, I’ve created powerful scripts to answer common security and compliance questions that years ago would have taken hours trying to answer in the CLI. The query I created below identifies Arista devices that have a security vulnerability in their configuration.Benefit of this NQEThis query solves similar issues to those I encountered at previous network admin jobs. This query drastically cut the time I would have otherwise spent investigating issues on individual devices. With a little effort in creating this query, I can now answer these questions in seconds with each new network snapshot.What this NQE doesThe script identifies all Arista devices on the network that are missing the enable password xxxXXX command. This could be a policy driven configuration that
In the early days of my Air Force career, the tech control facility was filled with the aroma of coffee and the buzz of technology. Each morning, my role was clear: brew the perfect cup for my boss and run countless validation checks through the CLI, ensuring each day started on the right note. Does this sound familiar? Maybe not the coffee but certainly hunched over the keyboard staring at a CRT screen using the CLI to search across hundreds of devices. These were monotonous tasks, logging in to each device one after the next, looking for significant events and up/down statuses, then documenting that information to provide an update to the division chief. It made me wonder if there was a way to automate this drudgery. It has been 20 years since then and I am now an intern with Forward. It has been a fantastic opportunity to advance my skills in Linux, Python, and deepen my understanding of the role of DevOps in technology organizations. Key takeaways I have observed at Forward: Coll
Hi all, I am new to NQE and trying to find out a way to list up all the devices with the EOL/S status.Here is the script which the first phase./*** @intent End-of-life data for operating systems** @description If EoL data is known for the OS of a device,* then that device shows the respected dates, if not EoS related columns shows null.** Data exists for devices running any of these OSes:* ARISTA_EOS, IOS, IOS_XE, IOS_XR, JUNOS, NXOS, and PAN_OS. */ foreach device in network.deviceslet platform = device.platformlet osSupport = platform.osSupport/* where isPresent(osSupport) */select { Device: device.name, Vendor: platform.vendor, Model: platform.model, OS: platform.os, "OS Version": platform.osVersion, "End of OS maintenance": osSupport?.lastMaintenanceDate, "End of OS vulnerability": osSupport?.lastVulnerabilityDate, "End of OS support": osSupport?.lastSupportDate, URL: osSupport?.announcementUrl, Location: device.locationName, Tags: device.tagNames, "Collection IP": devi
can Forward Network application (itself) integrate with Grafana, or Sysdig for monitoring the system health (i.e. cpu, memory, logfile, processes, filesystem) attributes. would like to send to dashboard tier team monitoring
Hello! We are trying to write a NQE referencing the State File OSPF PEERS, but we cant find anything related to code or the CommandType, or any data really, in the NQE data model. Can someone please point me in the right direction.
You can use NQE to examine the firewall rules in all firewalls in a network. However, you will need to use a different approach depending on what you want to audit in your security rules.Forward Enterprise collects and parses the ACLs and security rules from all devices: firewalls, routers, switches, and so on. The data is then parsed and normalized. This data is stored in a database in a custom format that allows the Forward application to perform path analysis.The following NQE query uses the Forward Enterprise aclEntry object to provide consistent output from any vendor Firewall. Note that the scope of device types in the output is limited by using the where statement and filtering to DeviceType.FIREWALL.This query will work for every ACL/security rule on any Firewall in the network. However, because the query is working on normalized data, each security rule in a firewall may be broken up into multiple aclEntry objects. The results of this query may therefore have multiple lines wi
If you’re interested in other ways to identify non-compliant devices, check out this article I wrote: The Hardware and Software Compliance Checker is a powerful script designed to ensure all network devices are authorized and operating on approved OS versions. By providing a detailed view of the network inventory, this query identifies devices that either lack approval to be on the network or are running outdated or incorrect software. With its comprehensive approach, this NQE empowers network administrators to maintain compliance, enhance security, and streamline operational workflows.Benefits of Using the Hardware and Software Compliance Checker:Enhanced Compliance: Ensures all devices on the network are authorized and running approved OS versions. Improved Efficiency: Automates the identification of non-compliant devices, saving time and reducing manual effort. Proactive Security: Helps prevent vulnerabilities by identifying and addressing outdated or unauthorized devices.How it Wor
If you’re interested in other ways to identify non-compliant devices, check out this article I wrote:The End-of-Life (EOL) and End-of-Sale (EOS) Checker is a streamlined tool that identifies network devices nearing or past their vendor support lifecycle. By cross-referencing inventory data with a list of outdated devices sourced from vendor sites, such as Cisco’s EOL/EOS database, the query ensures administrators are aware of devices that may pose operational risks. This proactive approach enables organizations to plan replacements, reduce downtime, and ensure ongoing compliance with industry standards.Benefits of Using this NQE:Proactive Replacement Planning: Identifies aging devices before they become liabilities, reducing unplanned downtime. Streamlined Compliance: Ensures devices meet organizational and vendor standards, avoiding security and support gaps. Optimized Team Collaboration: Role-based access and automated alerts keep relevant stakeholders informed and responsive.How the
🌟 Revolutionize Your Multicast Network Management with Forward Enterprise 🌟Managing multicast networks can be a daunting task, but Forward Enterprise makes it seamless with its advanced visibility, analysis, and troubleshooting. This demo showcases how the platform simplifies complex operations, offering unparalleled control and insights into your multicast network infrastructure. Forward Enterprise - Multicast BenefitsSimplified Multicast Management: With an intuitive interface and dynamic topology maps, Forward Enterprise makes it easy for both novices and experts to manage and analyze complex multicast networks efficiently. Comprehensive and Actionable Insights: The platform provides a unified view of network configurations, paths, and device states, empowering administrators with the knowledge to optimize operations and prevent issues. Proactive Troubleshooting and Time-Saving Tools: Advanced search and validation features enable quick diagnosis and resolution of network proble
Recently, two critical vulnerabilities (CVE-2024-0012 and CVE-2024-9474) were discovered in Palo Alto Networks' PanOS operating system. CVE-2024-0012 lets an attacker gain admin access and exploit other vulnerabilities like 2024-9474. These vulnerabilities allow attackers to gain admin privileges and plant malicious code, potentially giving them deeper access to company networks. The highlights are available below. Watch the video for the full story.Here’s how you can address these threats: Understand the Threat: The vulnerabilities enable unauthorized access, risking the security of your firewalls and networks. CISA has issued directive BOD 23-02. This directive outlines how organizations can reduce their attack surface from misconfigured management interfaces. Leverage Forward for Validation: Identify devices exposed to these vulnerabilities. Filter and prioritize affected devices, especially those connected to the internet The Forward platform provides a nightly update of CVE d
I am trying to find the specific commandType for the information in the device ‘nat v4’ result. For Cisco devices, it looks like a result of ‘show ip nat statistics’ but I cannot find the specific commandType in the data model documentation. Is there somewhere that can be searched?
Keeping your network source of truth accurate is critical in cloud environments that evolve rapidly. Forward Networks’ cloud modeling capabilities make it easier to understand your network state, but manual snapshot collections for every change can be time-consuming. To solve this, I recently built an automated workflow using AWS EventBridge to trigger Forward Networks’ cloud snapshot collections for relevant AWS network changes. In this post, I’ll share how to set up this integration, including tips to limit the number of collections and keep costs within the AWS Free Tier. The Challenge AWS environments experience frequent changes, such as:• Creating or deleting VPCs.• Modifying route tables or DirectConnect links.• Updating Elastic Load Balancers. Manually capturing snapshots for every change isn’t practical, and triggering collections for every event might overwhelm your workspace. I wanted a solution that:1. Automates snapshot collection for specific, relevant changes.2. Limits un
Some output from commands has a comma immediately after the output number: nat-limit statistics: max entry: max allowed 0, used 0, missed 0 I can parse the result as a string, but want to grab the data as a number so I can do other operations (math/comparison/etc). I can remove the comma with a replacement function (thanks @GaryB )cleanComma(s) = replaceMatches(s, ",", ""); however the output, even while being a number (0) is still considered a string. Looking at toNumber, the documentation gives the warning it is for IPv4 addresses only. Is there a way to convert a string into a number variable type?
How can i add AVI LB on FWN , TO use port https ,443 .?
I am using the NQE query to retrieve Fortinet Firewall NTP details. However, I am also receiving details for VDOM (Virtual Context ) or virtual contexts, which I do not want. Could you please assist me in refining the NQE query to exclude these VDOM details?
Hi Team,I need to obtain a list of devices that have syslog enabled as well as those that do not. I have checked the Forward Library and the community but could not find any relevant queries for this purpose. Could you please assist me in generating the list of devices with syslog enabled and those without it? Thank you!
NQE Query for F5 NTP Server details from config, Please help us to collect this data.
Your Regex Toolkit is Here!Starting with Release 24.10, NQE supports regular expressions (or “regex”), one of the most requested features from our community. Regular expressions are an essential toolkit for working with textual data, and networking often requires us to handle plenty of it. Whether you’re parsing the output of commands like show interfaces brief or making sense of complex device naming conventions, regex in NQE can make these tasks faster and more efficient. Why Regular Expressions Matter in NetworkingRegular expressions provide a powerful way to:Identify patterns within strings, such as determining if a device name follows a specific naming convention or verifying whether a string is a valid IP address. Extract data from network outputs. For example, extracting IP addresses from a configuration file or pulling cell values from an ASCII table. Transform strings. For example, replace all IP addresses in a config file with a redacted indicator or reformat dates from mm/dd
Do patterns need to be standardized or will blockMatches match when lines are missing? pattern=```line one {main:string} sub-line1 may or may not be consistently present sub-line2 may or may not be consistently present sub-line3 {value1:string} is target and sub-line3 will always be there sub-line4 may or may not be consistently present sub-line5 may or may not be consistently present sub-line6 may or may not be consistently present sub-line7 may or may not be consistently present sub-line8 {value2:string} is target and sub-line8 will always be there sub-sub-line9 {value3:string} is target and sub-sub-line9 will always be there sub-line10 may or may not be consistently present sub-line11 may or may not be consistently present sub-line12 {value4:string} is target and may or may not be present sub-sub-line13 {value5:string} is target and sub-sub-line13 will be there if sub-line12 is present sub-line14 may or may not be consistently
I have created a synthetic node inside a workspace to run down the various connections for a complex multibranch setup with multiple MPLS vpns and Internet VPNs. Is there a way to move or download the synthetic nodes so I can recreate them inside the parent network now that I have confirmed the accuracy inside the workspace? Note that I am trying to move it from a workspace back to the parent network - otherwise I would just recreate the workspace from the parent and include the synthetic.
One of my customers came to me with a problem.Given a list of servers, how to determine if the keys applied are unique.Took some overnight thinking on this but using a simple approach with our group qualifier we can restructure the output in a way we can make the evaluation.The first thing we need to do is provide the input data.You should always have data that will represent a pass and a failure scenario. This way when posting here on the community, others can replicate the query and have a firm understanding of the outcome testpass = """set system ntp server 1.1.1.1 key 1set system ntp server 2.2.2.2 key 2set system ntp server 3.3.3.3 key 3""";testfail = """set system ntp server 1.1.1.1 key 2set system ntp server 2.2.2.2 key 2set system ntp server 3.3.3.3 key 3""";So we need to ensure that for the list of servers that each key is unique i.e. there are no servers that are using the same key. We also want to be able to identify the offenders so they can be remediatedThe expression be
I had to change a lot, but this keeps the intent. This is from a PANOS firewall. The problem is that I am trying to find the objects in this list. However, some objects have double quotes to show there are spaces in the name of the object and some do not. I’m not sure how to clean this since NQE natively does not use double quotes to designate a single object that happens to contain spaces. sampleInput = """policy { shared; panorama { address-group { THE-GRAPE-Subnets { static [ "Green Grapes Are Good" RedGrapes BlackGrapes "Wine Grapes" PurpleGrapes]; tag GRAPES; description "This is a list of Grapes"; }""";pattern01 = ```policy panorama address-group THE-GRAPE-Subnets static "[ {object: (string*)} ```;foreach x in [1]let config = parseConfigBlocks(OS.PAN_OS, sampleInput)foreach match in blockMatches(config, pattern01)select { objects: match.data, block: match.blocks}Then this is the result from the “objects” column.{object:["Green
How can i add Custom command for fortinet. command that i am looking. show system dns. show system ntp. show system central-management config system central-management.
vlan456 is configured with VRRP group 456, for the below query, length of vrrpFhrpGroupsCount is returned as 0configuration snippet:interface vlan456 no shutdown ip address 10.7.0.1/26 ip pim sparse-mode ip igmp version 3 ! vrrp-group 456 priority 110 virtual-address 10.7.0.7!for the below query,@queryget_vrrp_details(host_pattern: String) = foreach device in network.devices where matches(device.name, toUpperCase(host_pattern)) foreach interface in device.interfaces where isPresent(interface.routedVlan) let routedVlan = interface.routedVlan let ipv4 = routedVlan.ipv4 let fhrp = ipv4.fhrp let vrrp = fhrp.vrrp select { deviceName: device.name, interfaceName: interface.name, vlan: routedVlan.vlan, hsrpFhrpGroupsCount: length(fhrp.hsrp.fhrpGroups), vrrpFhrpGroupsCount: length(fhrp.vrrp.fhrpGroups) }; length of vrrpFhrpGroupsCount is r
I am trying to get data out of a Cisco DMVPN hub on the spokes via NHRP database. Specifically the ARIN addresses and if the spoke has a firewall or other NAT. I was modelling off of this NQE question and it works...except for the 2nd pattern is not detecting the child line.The above question had a parent line that was always present if the new child was present and NHRP has the new child only if there is a NAT in the path while the parent line is always present. The line in question is the “(Claimed NBMA address: <IP address>)” line at the bottom of the 2nd example - it is indented 1 space from the line above ‘NBMA address’ which is always present. I tried both the NHRP data in the data model as well as a custom command ‘show ip nhrp’ with identical results. //NHRP Database output//Command: show ip nhrp//10.100.12.5/32 via 10.100.12.5// Tunnel1 created 1d18h, expire 01:56:31// Type: dynamic, Flags: unique registered nhop// NBMA address: 12.12.31.74//10.100.12.6/32 via 1
Already have an account? Login
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.