New to Forward or a seasoned professional? You found the right place!
Recently active
A few weeks ago I wrote about what building Skyforge taught me about network emulation and digital twins. If you haven’t read it, you can find it here: The response was much larger than I expected, but one conversation afterwards stuck with me.An colleague mentioned they were starting to hear a different question from customers. It wasn’t really about digital twins anymore. It was about AI.If tools like Claude can generate software this quickly, doesn’t that fundamentally change the build-versus-buy equation?It’s a fair question, and honestly, it’s one I’ve been asking myself as well.After all, I spent the last six months building Skyforge with Claude sitting beside me. I don’t mean that as a marketing statement about AI. I mean it literally. Large parts of the platform, from Go services and Kubernetes manifests to GitOps workflows, deployment automation, documentation, and countless little pieces of glue code started life as conversations instead of blank files.There is absolutely no
Some cyberattacks need a zero-day to make headlines. This one didn't. For years, Russian intelligence has simply walked through open doors: default SNMP community strings left unchanged, Cisco's Smart Install left switched on, routers nobody got around to patching. That activity was significant enough to bring eighteen agencies together on a single warning. NSA, CISA, FBI, and DC3 in the United States joined fourteen international partners, including the UK's NCSC, Australia's ACSC, and Canada's Cyber Centre, to co-sign a joint advisory: AA26-194A, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting." When that many agencies put their names on one document, it's worth reading closely. Russian FSB Center 16 actors (tracked in the industry as Berserk Bear, Energetic Bear, Dragonfly, and Static Tundra, among other names) have been opportunistically compromising routers and switches worldwide for over a decade, and they're still finding plenty of them, not through
On June 18, 2026, CISA issued an urgent advisory warning that malicious cyber actors — believed to be a Russian-speaking criminal group — have compromised nearly 74,000 Fortinet firewall and VPN devices across 194 countries in a campaign now dubbed FortiBleed. The list of affected organizations spans global enterprises and, most alarmingly, a Turkish NATO defense contractor from which classified documents were successfully exfiltrated. As of this writing, independent telemetry puts the number of compromised devices at over 86,000.CISA’s recommended actions are straightforward: terminate all SSL VPN and administrative sessions, reset credentials, enable phishing-resistant MFA, migrate password storage to PBKDF2 hashing, and restrict management interfaces from the public internet.Good advice. But reactive. The more important question is: could your team have known these conditions existed before attackers found them?The answer, for organizations running Forward Networks, is yes.The campa
A discussion at Cisco Live this year got me thinking about network emulation and digital twins. About six months ago, I started building Skyforge, an internal network emulation platform at Forward. The project started as an attempt to solve a practical problem: how do you quickly create realistic multi-vendor environments for demos, testing, and experimentation without maintaining racks of physical hardware? The name comes from The Elder Scrolls V: Skyrim, which is probably what happens when you spend too many hours playing video games and then find yourself naming infrastructure projects. Skyforge uses Kubernetes to orchestrate and manage emulated network environments, along with netlab to generate topologies, configurations, and deployment artifacts across multiple vendors. None of those technologies are particularly new, and individually they're all excellent at what they do. What surprised me wasn't getting the individual pieces working. What surprised me was how quickly the proble
CISA issued Binding Operational Directive 26-04 on June 10, 2026, fundamentally reshaping how federal agencies must prioritize and remediate vulnerabilities. Rather than treating all CVEs with equal urgency, BOD 26-04 establishes a risk-tiered patching framework built around four variables: whether the asset is publicly exposed, whether the vulnerability is in the Known Exploited Vulnerabilities (KEV) catalog, whether the exploit can be automated by an adversary, and the technical impact an attacker achieves after exploitation. The directive allows agencies to defer the lowest-risk vulnerabilities entirely to the next system upgrade, while demanding the fastest action—three days—on the highest-risk combinations. This post outlines what the directive requires and how Forward Enterprise helps organizations answer the questions that determine each risk tier. This directive supersedes both BOD 22-01 (Known Exploited Vulnerabilities) and BOD 19-02 (Vulnerability Remediation for Internet-Acc
Managing an on-premises network intelligence platform should be straightforward — and with Forward Enterprise Appliance 16.5 and the upcoming version 17, we're making it significantly easier and more secure.Here's what's changing and why it matters.A New Way to Administer Your ApplianceStarting with version 16.4, we introduced a Text User Interface (TUI) — a guided, menu-driven environment accessible via SSH or the console. Rather than navigating the underlying Linux OS directly, administrators now have a single, purpose-built interface for every common task.The TUI covers everything from initial node configuration and cluster deployment to Forward Enterprise upgrades, security settings, and built-in diagnostics — all in one place.Version 16.5: Refinements Based on Your FeedbackForward Enterprise Appliance 16.5 (available May 2026) is the last release in the 16.x line to include open shell access. It brings vulnerability fixes and TUI improvements based on early adopter feedback. If yo
When attempting to access the Vulnerabilities page I get the following errors.Jakarta.servlet.servletexception:request processing failed:java.util.concurrent.completionexception:java.util.nosuchelementexception:no value presentThis error has accord since the last time I updated my CVE using the Vulnerabilities page.
If you manage Cisco ASA, Firepower, or Secure Firewall anywhere in your environment, this one demands your immediate attention.On April 23, 2026, CISA published Analysis Report AR26-113A, a malware analysis report on a backdoor known as FIRESTARTER. The report — issued jointly with the UK’s National Cyber Security Centre — confirms that at least one U.S. federal agency was compromised through a Cisco Firepower device, and that the attackers used FIRESTARTER to maintain persistent access even after the device was patched and rebooted. CISA has urged every organization running Cisco Secure Firewall ASA or Firepower Threat Defense (FTD) software to assess exposure now.This isn’t a brand-new vulnerability story — the underlying CVEs have been in CISA’s Known Exploited Vulnerabilities (KEV) catalog since September 25, 2025. What’s new is the depth of evidence about how the ArcaneDoor threat actor (tracked by Cisco Talos as UAT-4356) is operating after initial exploitation, and just how per
As of April 15, NIST is changing how it handles CVEs in the NVD. The new approach is risk-based: every submission still lands in the NVD, but only a subset will get the full analysis and enrichment treatment going forward:CVEs in CISA’s Known Exploited Vulnerabilities (KEV) catalog CVEs in software the federal government uses CVEs in “critical software” as defined by Executive Order 14028Everything else — including the existing backlog — gets marked “Not Scheduled.” NIST is also dropping its own severity scoring for most CVEs, to “reduce duplication of effort.” The full breakdown is on the NVD process page.The rationale is reasonable — CVE volume has exploded, and central triage at that scale was never going to hold forever. But in practice, the single source a lot of security and network teams have been leaning on for enrichment is about to get a whole lot thinner. That’s worth pausing on. The hot takeHere’s a line straight out of our own documentation FAQ:“We use the NIST National Vu
This is a companion post to CISA Adds CVE-2025-53521 to KEV: What It Means for F5 BIG-IP APM SystemsIf you manage Rockwell Automation/Allen-Bradley programmable logic controllers anywhere in your environment — or if you're responsible for any network that touches operational technology — this advisory is one of the most serious things to land in 2026.On April 7, 2026, six U.S. government agencies issued a joint advisory: the FBI, CISA, NSA, EPA, Department of Energy, and U.S. Cyber Command. When that many agencies co-sign a warning, it reflects both the severity of the activity and the breadth of the threat. The advisory (AA26-097A) confirms that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-facing Rockwell Automation/Allen-Bradley PLCs across multiple U.S. critical infrastructure sectors, resulting in operational disruptions and financial loss. What's HappeningSince at least March 2026, an Iranian-affiliated APT group has been targeting in
If you manage F5 BIG-IP Access Policy Manager (APM) anywhere in your environment, this one demands your immediate attention.On March 27, 2026, CISA added CVE-2025-53521 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation of a critical flaw in F5 BIG-IP APM. Federal Civilian Executive Branch (FCEB) agencies were given until March 30, 2026 — just 72 hours — to remediate. That kind of deadline reflects just how serious CISA considers this threat. What Happened — and Why the UrgencyThis vulnerability has a bit of a history that makes it particularly tricky. CVE-2025-53521 was originally disclosed by F5 back in October 2025 as part of their quarterly security advisory cycle. At the time, it was categorized as a denial-of-service (DoS) vulnerability with a CVSS v4 score of 8.7 — serious, but not immediately alarming for organizations that were still working through their patch queues.Fast forward to March 2026. F5 revised its advisory based on new
We're excited to share that, by popular demand, In-App Audit Logs are now available, giving org admins full visibility into activity across their Forward Networks platform - no support ticket required. Where to find itHead to Platform → System → Audit Logs to get started.Full visibility into platform activityAudit Logs capture every meaningful change in your environment, including create, update, and delete operations, as well as authentication events. Every log entry includes the timestamp, originating IP address, the user who performed the action, the HTTP method used, the target object affected, and the outcome, giving you a complete, reliable picture of what happened and when.Accountability built inImpersonation activity is fully visible too. If an action is taken on behalf of another user, the log clearly reflects that, so you always have an accurate record of changes in your environment.Powerful filtering and exportFinding the events you care about is quick and easy. Every column
I’ve brought this up a few times on calls with our account team. It would be really helpful if we could filter with a bit more flexibility in Sources & Inventories.Currently, if I’m searching for a Tag the logic is a “OR” so if I want a device in “APAC” && “Switch” && “Arista” I can’t get a reduced set of devices.It would be great to combine the filtering to isolate devices more quickly.
Version 26.2 of the platform introduces new enhancements to topology, including line drawing and multi-select capabilities.You will now see the Line tool in the Annotations section, allowing you to add straight lines to your network diagrams alongside the classic shapes already available. Lines can include arrows, be displayed as solid or dashed, and support the same colour options as any other annotation element.Multi-select enables you to select multiple annotation elements at once and move them as a single object, a valuable capability as your diagrams grow in scale and complexity.I spent some time this morning trying out the new features on one of our lab networks:Multiselect and lines in actionEnhancements such as these form part of our ongoing, iterative approach to evolving Topology into a comprehensive, one-stop destination for accurate and easily understood network diagramming.What enhancements would you like to see in the Topology? Let me know in the comments.
CISA recently issued Emergency Directive 26-03, requiring federal agencies to take immediate action to mitigate vulnerabilities affecting Cisco SD-WAN systems. The directive was issued after security agencies observed active exploitation of vulnerabilities that could allow attackers to gain privileged access to SD-WAN management components.Federal agencies must quickly identify affected systems, apply vendor fixes, and verify that SD-WAN management infrastructure is not exposed or compromised. This post outlines what the directive requires and how Forward Enterprise helps organizations rapidly identify impacted infrastructure, validate exposure, and confirm remediation across complex networks. Who should read this postSecurity and Network Operations teams managing Cisco SD-WAN infrastructure Network engineers responsible for WAN edge, SD-WAN controllers, or branch connectivity Risk and compliance professionals working in public-sector or enterprise environments responding to CISA d
Keeping track of hardware lifecycle isn't just good practice anymore - in many cases, it's required. Regulations like Europe's Digital Operational Resilience Act (DORA) and the UK's Telecommunications Security Act (TSA) now require organisations to document legacy infrastructure.Forward Networks already provides End of Life (EoL) data for Cisco and F5 devices to help customers prepare for these audits. With our latest update, Check Point is now supported too. That means one less vendor to track manually.Using a simple NQE query, like the one I made below, you can quickly generate reports across your Cisco, F5, and Check Point environments for their EoL state. Add it as a verification check to get alerts when devices go EoL, or create a custom scorecard to monitor the current EoL status of your estate. foreach device in network.devicesforeach component in device.platform.componentslet componentViolation = if isPresent(component.support) && isPresent(co
Hi team, I am new to the forward networks enterprise solutions and recently facing some issues in the application. I have set of network devices with different vendors (Cisco, Fortinet, huwawei, F5, etc) in my workspace with application version 25.11 and have configured a daily snapshot collection schedule. Recently I observed the snapshots are not been collected fornthe last 2 days and tried to find the cause, I see there is a timeout error popping up for all my network devices under the workspace. I tried to check what are the devices added in last 2 days under Diffs section by comparing the last successful snapshots versus last failed snapshot to narrow down the issue thinking any dew device added might have caused the issue due to modelling errors but couldn't find any devices newly added. Since I have 800+ devices I am not able to narrow down the issue and reached out to support for assistance and awaiting reply. Meanwhile, I thought to post this issue/behavior here to see if a
CISA issued Binding Operational Directive 26-02 on February 5, 2026, requiring Federal Civilian Executive Branch (FCEB) agencies to eliminate unsupported edge devices from their networks. These end-of-support (EOS) devices no longer receive vendor security updates and are actively exploited by nation-state threat actors as entry points into federal networks. Federal agencies must now take immediate action to inventory, update, and ultimately replace these vulnerable devices across strict timelines. This post outlines what the directive requires and how network visibility platforms can address the operational challenges of meeting these requirements. Who should read this postSecurity and Network Operations teams managing edge infrastructure including routers, firewalls, load balancers, and VPN gateways Network engineers responsible for maintaining network perimeter devices across hybrid and multi-vendor environments Risk and compliance professionals working in public-sector or enterpris
In release 26.1 we brought out a feature that eases the onboarding of new devices quite a lot. If you have a good naming convention (or three, in the case of some of my customers) you can use this to good effect.Let’s see how it works. Here are some devices I just added (one of which isn’t collecting yet, I know). They are all located in a site called Farnham, but initially go into the Default unassigned location:Newly-added devices in the default location Imagine I had just added a few hundred devices using a CSV or something. Moving all these unassigned devices into locations would be a long job, right? Not any more…. Now we can use wildcard matching to put them into a location based on their name. The steps are shown in the GIF below:open up the Manage Locations menu (in Sources) edit the location of interest edit the device list at that location choose the Dynamic Match option enter a pattern to match on - e.g. pop1*Entering the dynamic match for a location Now we define th
In the latest release, Forward Networks significantly optimized the CVE (vulnerability) experience—both in performance and in how engineers investigate exposure and risk across their network. The changes focus on faster load times, clearer filtering, and more actionable context when you’re analyzing which devices Clickable Risk Metrics with Live FilteringThe high-level CVE widgets (e.g., “devices receiving traffic from the Internet,” “known exploited,” “unconfirmed vulnerabilities”) are now fully interactive. Clicking any of these automatically applies the corresponding filters to the device and CVE tables, instantly narrowing the view to what actually matters.Those filters also persist when you drill down into CVE detail pages, so your investigative context is never lost. Unified CVE View Across Multiple VendorsInstead of duplicating the same CVE multiple times (once per vendor), a single CVE entry now shows all affected vendors and platforms together—for example, Juniper, Cisco,
Ready to put your network skills to the test? Compete in the Forward Quest Capture-the-Flag challenge at Cisco Live in Amsterdam! We’ll have multiple daily competitions and the overall winner each day will take home a pair of Airpods Pro 3 that feature Live Translation. Join us February 9–12, at RAI Amsterdam (Booth D01), and compete against other network professionals to solve real-world network scenarios with speed and accuracy. Register for a date and time to compete at https://forwardquest.live/ using your Forward Community username and password, then stop by the booth to jump into the challenge and climb the leaderboard. You can compete in one competition per day. Each day, the top performer will take home a pair of AirPods Pro 3! Where: Cisco Live EMEA, RAI Amsterdam (Booth D01)When: February 9-12, 2026Register for a time to complete: https://forwardquest.live/ See you in Amsterdam!
New in 26.1, Forward now supports Dark Mode across the entire application, providing a consistent, high-contrast experience in all major areas of the product, including dashboards, topology views, and the NQE/code editor. Users can choose between Light Mode, Dark Mode, or an Auto setting that follows their operating system theme. This preference is saved at the user level, so your experience stays consistent across sessions and devices. The latest release also improves text contrast to enhance readability in low-light environments. Dark Mode is useful in several common operating scenarios: Network Operations Centers (NOCs)Large wall displays running Forward dashboards for long periods benefit from Dark Mode by reducing glare and eye strain, making KPIs, alerts, and topology changes easier to monitor around the clock. Low-light or “dark office” environmentsFor teams working evening shifts, on-call rotations, or in dimly lit rooms, Dark Mode provides a more comfortable viewing experienc
If you’ve worked in networking long enough, you’ve probably taken down production at least once. I know I have. That’s why I believe in introducing a little controlled chaos—not to be reckless, but to build resilience and make sure we never walk out of a change window with a broken network. Most of my career has been on the data center side, with years of Cisco and CLI habits that never really go away. I’ve always relied on baselining, validation, and proving intent before and after every change. Now I’m applying that same mindset to AWS networking, where you can’t just SSH into a box and run your favorite show commands, but the need for confidence in how the network will behave is just as critical. 1. Get your bearings with a real network viewBefore I touch anything, I need situational awareness. In the data center, that meant topology diagrams, routing tables, and a mental model of how packets actually flow. In the cloud, if you don’t deliberately build that picture, you’re flying b
Curious about AWS but not sure where to start? In this step-by-step walkthrough, I’ll show how to set up your own AWS Free Tier account, configure billing safeguards, and follow best practices for security and user management. Whether you’re preparing for certifications or just experimenting with cloud services, this guide will help you get started with confidence. Cloud infrastructure has become essential in today’s IT landscape, and gaining hands-on experience with AWS (Amazon Web Services) is a valuable step for any engineer. The AWS Free Tier allows you to experiment with building, using, and tearing down AWS services at little to no cost—an excellent way to learn without breaking the budget.In this article, I’ll walk you through: Why you might want to create an AWS Free Tier account How to set one up safely Best practices for billing, security, and user management How to clean up or close your account when you’re done Why Use AWS Free Tier?Creating your own AWS Free Tier
The CISA advisory AA25‑239A details a sophisticated espionage campaign attributed to Chinese state-sponsored actors, collectively referred to as Salt Typhoon. Why Does Salt Typhoon Matter?These actors are targeting vulnerable network infrastructure — including routers and switches — to gain initial access, persist in the environment, move laterally, and exfiltrate sensitive data. In an earlier post we described how to counter initial access from Salt Typhoon actors. In this post we will look closer at one of key tactics in this campaign, which involves abuse of the GuestShell feature available on certain Cisco platforms. What is GuestShell?GuestShell is a containerized Linux environment embedded within certain Cisco devices (e.g., IOS XE). It allows administrators — or, in the wrong hands, attackers — to run Linux commands and applications directly on the device. Since the activity within a virtual container is monitored less closely than native operations on switches and routers, cu
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.