New to Forward or a seasoned professional? You found the right place!
Recently active
We wanted to call your attention to an upcoming NQE API change that was announced in the 25.12 release notes. This post provides additional detail and guidance to help you proactively update affected API integrations ahead of the change. What’s Changing In release 26.3, the default value of the itemFormat parameter for NQE API responses will change:Current default: LEGACY Future default: JSONThis applies to the following API endpoints:POST /api/nqe POST /api/nqe-diffs/{before}/{after}If your automation depends on the current behavior, we strongly recommend opting into itemFormat: "JSON" now so you can validate and adjust ahead of the default switch. If you need to continue using the legacy behavior after 26.3, you must explicitly specify "itemFormat": "LEGACY" in each request. Who Is Affected Most NQE queries will not be impacted.This change only affects queries that return complex columns — specifically:Columns whose values are records / objects Or collections of objects embedded as
Understanding how your network evolves is crucial, especially for spotting configuration changes and potential vulnerabilities. Forward Enterprise makes this process intuitive—even if many snapshots aren’t fully processed. Let’s walk through how to reveal changes and vulnerabilities without processing every snapshot. Step 1: Go to a processed snapshot in your network inventory. Step 2: Find and select the device you’re interested in. Open its device card and view its configuration. This shows the current state, but you can also check its history to see all changes over time. Step 3: Review the configuration history to spot changes. Look for when lines were added or modified. For example, if the text “foo” was added recently, you’ll see exactly when that change happened. The history view highlights both recent and older changes, including when the entire configuration was first introduced. Step 4: To examine specific lines, highlight them in the config, right-click, and choose
Hi Team, Could you help me to understand how Forward Networks model the host ?
Where My Network Survey Lessons Really Began: High-Security Environments I’ve spent years surveying some of the most complex, layered, and mission-critical networks in high-security environments. One of the most impactful experiences came from supporting the Air Force’s Base Infrastructure Management (BIM) initiative—a massive effort to modernize, standardize, and truly understand the state of base-area network (BAN).These networks weren’t designed once; they were designed over time—by different teams, different contractors, and different mission owners. Every environment had its own personality, its own quirks, and its own technical ghosts. And when BIM kicked off, it quickly became clear that the Air Force needed a repeatable way to actually see what they had before they could improve it.Traditional approaches—flying in engineers to open comms closets and manually log into devices—took weeks and still left blind spots. We needed a better, faster, more reliable way to uncover the trut
One of the greatest strengths of using a digital twin is being able to separate the routing and firewall behavior of a particular traffic flow.For example, suppose we have a web application that is not functioning properly because traffic from the Internet cannot reach a public virtual-ip that is mapped to private IP on a top-of-rack switch on port 80.We enter this path search in the Forward Network Search bar.We can see immediately that the traffic is being blocked on an edge firewall (atl-edge-fw01). However, we don’t know what would happen to the traffic if it is permitted through this firewall and continues along its path.Are all the routing protocols properly configured to deliver the traffic to its destination? Is there another firewall in the path that would block the traffic?We can answer these questions by using permit-all mode.By enabling permit-mode, we pose the hypothetical question “what happens to the traffic if it is permitted through all the security rules in the path?”
CISA issued Emergency Directive 26-01 on October 15, 2025, following the discovery of a nation-state breach involving F5 BIG-IP source code and vulnerabilities. Federal agencies must take immediate action to inventory, patch, and secure affected devices before key October and December deadlines. This post outlines what the directive requires and how Forward Enterprise helps organizations meet those requirements through network visibility, automation, and compliance verification. Who should read this postSecurity and Network Operations teams managing F5 Networks BIG-IP hardware or virtual appliances Network engineers responsible for external-facing application delivery infrastructure Risk and compliance professionals working in public-sector or enterprise environments subject to federal advisoriesWhat is covered in this postSummary of CISA Emergency Directive 26-01 and its significance Key actions required by the directive (and associated deadlines) How Forward Networks helps ag
It always starts the same way. A team decides it’s time to get serious about network automation. They want to move fast, be resilient, eliminate toil, and reduce outages. Everyone’s on board. There’s talk of Python scripts, intent-based networking, even AI-powered predictions. But then someone finally asks the most basic question: “Do we actually know what IPs are in use?” Cue the awkward silence. Someone eventually mutters, “We’ve got a spreadsheet.”Honestly, I get it. I’ve been there. Most of us have. If you’ve got a few dozen devices and a small team, tracking IP allocations in Excel or Google Sheets might be enough. But once your environment scales—even modestly—that house of cards starts to wobble. Multiple admins start making updates. File shares go down. Local versions get out of sync. And suddenly, nobody knows what’s actually live in the network.Before you even think about automation, you need a reliable source of truth for your IPs. That’s where proper IP Address Management (
Date: 10/14/2025Time: 6:00 PM – 6:30 PM Pacific (9:00 PM – 9:30 PM Eastern)Duration: Approximately 30 minutesForward Quest will undergo scheduled maintenance this evening to improve platform performance. During this time, the site may be temporarily unavailable.Please note: Avoid starting a new Quest challenge during the maintenance window. Any active sessions may be interrupted. Thanks for competing and leveling up in Forward Quest!
CISA just issued Emergency Directive 25‑03 mandating actions to identify and mitigate a campaign exploiting zero‑day vulnerabilities in Cisco ASA / Firepower devices. While the directive is written for federal agencies, the threat is relevant to any organization using those platforms. Below is a summary, risk assessment, and recommended mitigations — along with what Forward Networks is doing to support customers. What’s Going OnCampaign targets Cisco ASA and Firepower / FTD appliances Exploits include unauthenticated RCE and privilege escalation Persistence observed via ROM manipulation Linked to 'ArcaneDoor' activity CVEs: CVE‑2025‑20333 (RCE) and CVE‑2025‑20362 (privilege escalation) Directive mandates inventory, forensic dumps, patching, and reporting Why This Matters to Forward CustomersIf you rely on Cisco ASA, ASAv, or Firepower/FTD appliances in your network perimeter or DMZ, your infrastructure may be at risk of compromise, persistent code injections, or deeper intrusion. Becau
Flagging an important warning from the FBI / IC3, and sharing resources to help you assess and reduce risk. Alert Number: I-082025-PSA - Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure The High-LevelThe FBI is alerting that Russian FSB cyber actors (aka Center 16 / “Berserk Bear” / “Dragonfly”) are actively exploiting a known vulnerability in Cisco Smart Install (SMI) — CVE-2018-0171 — to target networking devices globally. These actors are using SNMP (especially older/insecure versions v1 and v2) and unpatched / end-of-life devices to:Collect configuration files. Modify configs to insert or enable unauthorized access. Do reconnaissance inside victim networks, with particular interest in protocols & applications used in critical infrastructure / industrial control systems.The vulnerability and use of legacy/unsecured protocols make aging equipment especially risky. Even if a device is not directly breached, weak practices may allow attackers in
We’re excited to announce the launch of the newly reinvented Forward Quest — a monthly interactive challenge designed to put your Forward Networks skills to the test. Play Forward Quest What is Forward Quest?Forward Quest is an online game experience built around real-world network engineering scenarios. Each challenge is timed, and your results are added to a community leaderboard where you can see how you stack up against other Forward users. Why play?Forward Quest is more than just a game — it’s a fun way to: Sharpen your skills by solving challenges that mirror real engineering tasks. Learn by doing and discover new ways to use Forward Enterprise in real-world situations. Earn bragging rights (and prizes!) by climbing the leaderboard. Unlock badges that showcase your achievements in the community. How to play Head to Forward Quest Log in with your Forward Community account Start the first challenge and race the clock to see how fast you can solve it! The first monthly ch
If you’ve ever waded into the world of cybersecurity, you’ve probably run across the acronyms CWE, CVE, and KEV. They sound similar, and they’re all related to security flaws — but each serves a different purpose. Here’s a clear breakdown: CWE (Common Weakness Enumeration)Think of CWE as a blueprint of mistakes. Maintained by MITRE, CWE is a catalog of weakness types — ways that software or hardware can go wrong. A CWE is not tied to a single product; instead, it describes a class of design or coding errors. CWEs can be abstract (like “improper input validation”) or very specific (like “integer overflow in arithmetic operations”). Example: CWE-269 (Improper Privilege Management), which outlines the general problem of failing to correctly enforce privilege levels. CVE (Common Vulnerabilities and Exposures)CVE zooms in from the abstract to the concrete and specific. A CVE is an actual, identified vulnerability in a particular product or version. Every CVE entry includes metadata
I have created the Forwords Network account .Why I can not login this vis this link.Forward Enterprise | Forward Networks Docs
Could you help simulate the staging of new BGP peers, route-maps, and new routes to understand how they might impact route path behavior? I am planning to stage a change that involves adding a new link and BGP peer, with the expectation that routes will prefer the new path after the change. Can this scenario be simulated in the forward network to validate the expected behavior? So far, I’ve attempted to simulate the changes, and I can see the new/modified interfaces and the transit IPs. However, I don’t see the BGP peer. Am I missing something in the simulation process? Any guidance would be appreciated. Are there any limitation with the simulation feature.
This is for On-Prem environments, to securely retrieve the CVE database file through automation. Create a secure env file (path of your choosing) for your Forward SAAS credentials This keeps secrets out of code and scriptsexport FWD_USERNAME='your_username' # <-- Replace with your Forward SAAS UNexport FWD_PASSWORD='your_password' # <-- Replace with your Forward SAAS PW Add the Python script (path of your choosing) to download the CVE index This is the meat and potatoes of retrieving the file for SAAS#!/usr/bin/env python3import requests, osfrom requests.auth import HTTPBasicAuthusername = os.environ.get("FWD_USERNAME")password = os.environ.get("FWD_PASSWORD")if not username or not password: raise ValueError("Missing credentials.")url = "https://fwd.app/api/cve-index"output_file = "/tmp/cve-index.bin.gz"r = requests.get(url, auth=HTTPBasicAuth(username, password), verify=False)r.raise_for_status()with open(output_file, "wb") as f: f.write(r.content)print(f"Saved to {output
we are using below NQE Query to get the NTP Server details , i need to remove some static value in server coloum, ciscontppattern=``` ntp server {server:string}```;getServers(device) = foreach match in blockMatches(device.files.config, ciscontppattern) select { serverIP: match.data.server}; foreach device in network.deviceslet platform = device.platformwhere device.platform.vendor == Vendor.CISCO select { device: device.name, vendor: device.platform.vendor, tags: device.tagNames, os: device.platform.os, OSVersion :platform.osVersion, servers: (foreach server in getServers(device) select server.serverIP)} Example : i dont want to show entry those have server value - “Inte”
Hi allHas anyone onboarded Arista WIFI yet, the models we have are managed centrally via CV-CUE the Wifi version of cloudvision, although you can extract some commands via SSH.Had a quick look around and couldn’t find anything, I will in the meantime dig around about custom devices 😀Thanks
In the early days of my Air Force career, the tech control facility was filled with the aroma of coffee and the buzz of technology. Each morning, my role was clear: brew the perfect cup for my boss and run countless validation checks through the CLI, ensuring each day started on the right note. Does this sound familiar? Maybe not the coffee but certainly hunched over the keyboard staring at a CRT screen using the CLI to search across hundreds of devices. These were monotonous tasks, logging in to each device one after the next, looking for significant events and up/down statuses, then documenting that information to provide an update to the division chief. It made me wonder if there was a way to automate this drudgery. It has been 20 years since then and I am now an intern with Forward. It has been a fantastic opportunity to advance my skills in Linux, Python, and deepen my understanding of the role of DevOps in technology organizations. Key takeaways I have observed at Forward: Coll
🌟 Revolutionize Your Multicast Network Management with Forward Enterprise 🌟Managing multicast networks can be a daunting task, but Forward Enterprise makes it seamless with its advanced visibility, analysis, and troubleshooting. This demo showcases how the platform simplifies complex operations, offering unparalleled control and insights into your multicast network infrastructure. Forward Enterprise - Multicast BenefitsSimplified Multicast Management: With an intuitive interface and dynamic topology maps, Forward Enterprise makes it easy for both novices and experts to manage and analyze complex multicast networks efficiently. Comprehensive and Actionable Insights: The platform provides a unified view of network configurations, paths, and device states, empowering administrators with the knowledge to optimize operations and prevent issues. Proactive Troubleshooting and Time-Saving Tools: Advanced search and validation features enable quick diagnosis and resolution of network proble
Recently, two critical vulnerabilities (CVE-2024-0012 and CVE-2024-9474) were discovered in Palo Alto Networks' PanOS operating system. CVE-2024-0012 lets an attacker gain admin access and exploit other vulnerabilities like 2024-9474. These vulnerabilities allow attackers to gain admin privileges and plant malicious code, potentially giving them deeper access to company networks. The highlights are available below. Watch the video for the full story.Here’s how you can address these threats: Understand the Threat: The vulnerabilities enable unauthorized access, risking the security of your firewalls and networks. CISA has issued directive BOD 23-02. This directive outlines how organizations can reduce their attack surface from misconfigured management interfaces. Leverage Forward for Validation: Identify devices exposed to these vulnerabilities. Filter and prioritize affected devices, especially those connected to the internet The Forward platform provides a nightly update of CVE d
How can i add AVI LB on FWN , TO use port https ,443 .?
is it possible to run NQEs immediately after a snapshot completes? If Forward can baseline what NQEs are always run after a snapshot completes (possibly this data baseline is based upon a period of time such as 30 days or some admin defined time period). Administrators can use this baseline data to flag those NQEs of priority to run immediately after the snapshot completes. in this way, results from priority NQEs are immediately available (from cached results) for applications to use with minimal delay.
Hey, Forward Community Members!We're thrilled to invite you to submit your ideas for network configurations you’d like to see analyzed within our Net3 lab network. Whether it's testing new scenarios, troubleshooting common issues, or exploring unique configurations, we want to know what network setups you’re interested in. Example lab scenarios include:Layer 2 Host-to-Host communication in VXLAN EVPN fabric based on Arista STP/RSTP Layer2 pods built with Cisco or Arista switches Layer 3 MPBGP with VXLAN EVPN forwarding (Arista vEOS) IPv6/IPv4 Dual stack forwarding using routers/switches by Cisco and Arista, as well as Palo Alto firewalls SD-WAN Viptela/Catalyst SD-WAN As well as other configurations including Network Services - Load-balancer single-arm (SNAT/DNAT): A10 And many others! What network configuration would you like to see? Our Net3 lab network is constantly expanding with a diverse set of devices, offering a robust environment for analysis and experimentation. H
What command can be ran from the CLI to find the postgres version?
I was helping some folks in getting familiar with Forward Networks, we were having trouble in adding in new devices (that already exist in the parent network) in to the already created workspace. The existing options to add devices in the workspace looks to only include ways to create new connections to those devices. But I did not see any way for me to pull in existing devices from the parent network, after the workspace was already created. Does anyone have any insight into this?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.