New to Forward or a seasoned professional? You found the right place!
Recently active
We were finally able to configure and get SSO online and operational this past week in our Dev environment, and pushed it in to the production world yesterday. After running fine for about 10-12 hours, we came in this morning to the following error: SAML validation failed. Invalid assertion [insert a bunch of random letters and numbers] for SAML response [insert more random letters and numbers]: Assertion IssueInstant was invalid, expiredContact your Org Admin to resolve the issue. I check with the in group that manages SSO and they claim nothing has changed on their end, so now I must ask: How do we get past this so I can turn SSO back on? P.S. we are on base 11 app version 24.8 (rolling to 24.9 in a couple hours)
Scenario: Disabled all classic and all but one custom source in order to speed up and test an NQE with extractJson on an endpoint for a specific device. Observation: Unable to take a snapshot without at least one Classic source enabled.
The ability to include/exclude custom sources in bulk in the same way as classic sources would be useful if capability is possible. Secondary to an ability to bulk include/exclude custom sources would be the ability to bulk edit custom source profiles, basic authentication, SSL validation, and location. I also noticed when editing custom source that I had to update in phases. I imported csv of devices. I then attempted to update the profile and auth and location but it stated the source already existed and when I exited it only saved one of the settings. I then edited the src again and updated the location. If I recall it was unable to edit the tags at the same time as other config fields as well. No big deal for the few devices in my workspace and I have finished update but wanted to bring to your attention.
We are thrilled to announce the release of AI Assist for NQE! Whether you're new to the platform or a seasoned NQE expert, AI Assist allows you to skip complex syntax and describe what you need in plain English, making it easier than ever to create NQE queries. Generating an NQE query using AI AssistWhat is AI Assist?AI Assist enables you to write NQE queries using everyday language. Instead of manually writing complex queries, you can simply describe what you're looking for, and AI Assist will generate the appropriate NQE query for you. For example, to create a query that lists all CVEs currently impacting devices within a network, you can type, “List CVEs impacting each device,” and NQE AI Assist will instantly translate that into a valid query. How to Use AI AssistUsing AI Assist is easy. Just follow these steps:Log in to Forward Enterprise. Navigate to the NQE Library. Open the query editor by adding a new query. Click the AI Assist button. In the Generate tab, type your natural la
Is there a way to export all CVEs that the platform is scanning for. We know how to get the ones that are affecting devices, but we want a list of them all, regardless of impact.
Before we head off into the weekend I was hoping to ask the community what their stance is on schema based network configuration interfaces like NetConf and OpenConfig GNMI. Question 1: Do you currently or plan to use NetConf and/or GNMI to manage policy across your network? Do you leverage this in your automation pipeline? If so, do you find sufficient vendor support?Question 2: If you do leverage NetConf/GNMI for configuration data, do you still want to inspect the policies via CLI?Thanks for your insights.
Happy Thursday All! I hope you’re having a great week. I know it’s been a busy one so I’ve highlighted this week’s most popular articles and discussions in the community. Did I miss one of your favorites? Add it in the comments below! Here’s the list... @AricaFN ‘s article on extracting data from custom commands is a great discussion for anyone that has to go beyond the data model to tailor the Forward platform to their organization’s specific needs. @Christopher is on fire (hehe) with this new NQE query that uses the Forward Enterprise aclEntry object to provide consistent output from any Firewall vendor. And if you’re interested in automation, @Christopher’s article on interfacing with Forward with API and Python is a great example to follow. @Mike ‘s complete NQE tutorial video series is the go to for anyone learning NQE or experts brushing up on the finer points. Building on @cariddir‘s scripts, @RobertWelch create this plug-and-play NQE to unify the Fortinet Version output for
We have started to do some testing with FN. In our AWS network, we are using Cisco Firepower Threat Defense (FTD) devices managed by Firepower Management Console (FMC). FN is able to connect to an FTD and retrieve device details but does not support retrieval from FMC.In our network, for complicated routing reasons, we can’t easily enable FN to connect to our FTD instances. I can, however, provide a URL that will retrieve all the information from FMC. I would like to configure an “HTTP(S) external source” to provide that info. What I cannot figure out, however, is the required format for the data to that is returned by the URL GET. The document just states that FN will “infer” the schema. In my case, there’s no inference needed. I am writing the code that will return the info. I can format the data however FN needs it.For those who care about the details, the implementation is an AWS Lambda function that connects to the FMC REST API and returns the info. An AWS API gateway provides the
Incident Management: A Proactive Approach to Minimize Disruption Experiencing an incident can be chaotic, with alarms sounding off and urgent communications flooding in, often at the least opportune moments. The key to effective incident management is not just to respond with urgency but to anticipate and mitigate issues before they escalate. The TL;DRTo effectively manage incidents, you must first establish visibility across and baselines of your network. Know what’s normal and what’s not. Ensure robust logs are being collected in a centralized manner, and contain all relevant details to facilitate troubleshooting. Develop your response team. Know their strengths and weaknesses, and ensure everyone on the team has skin in the game. publish playbooks, runbooks, and other procedural documents so everyone knows what is expected of them during an incident. Foster relationships with your peers and other teams long before an incident ever begins. And always strive to improve your incident m
Launch Podcast Join Craig Johnson (@captainpacket) and William Collins as they discuss the power of community, and then dig into the growth and adoption of Digital Twins and where they fit in today’s tech stack. Topics covered include:The Concept of Digital Twins in Networking: Drawing parallels to other industries like manufacturing. Craig explains that a digital twin is a digital representation of a real-world network, allowing for easier troubleshooting, visualization, and understanding of network components and configurations. Evolution of Digital Twin with Cloud and Automation: Craig discusses the evolution of digital twin solutions, particularly in the context of cloud and automation. The conversation highlights the importance of extending digital twin capabilities to multi-cloud environments and standardizing network forwarding logic across vendors. Core Technical Components and Implementation: Craig outlines the technical components required for implementing a digital twin, fo
For those interested in security certifications, I wanted to pass along this hidden gem of certification training.Ben Malisow is an excellent technical editor and trainer, and is the guy behind the wannabea.. certification training programs. I would highly recommend his trainings for CISM, CISSP, CCSP, and SSCP for anyone interested in these certifications. - https://www.wannabeacism.com/
Sometimes a path search may not present the results you expect. When engaging with support regarding a path search issue, you may be asked to provide a snapshot with the relevant path search data. To capture a snapshot of a path search, first perform the path search in question. In this example, we are performing a simple path search from atl-ce01 to atl-core-pe01: Now, press and hold the Alt or Cmd key, and the icon on the far right of the query bar will change from ‘Copy Query’ to ‘Export Query’. Click on the ‘Export Query’ icon: The Export Snapshot wizard will now display all devices relevant to that path, and allow you to add any additional devices you wish to add to the snapshot (if necessary). Finally, obfuscate the IP and MAC addresses if necessary, and export the snapshot: This will allow you to download a zip file snapshot of the path search and all devices within the path of this search. This will provide the support team with all data necessary to investigate your path sear
I am working on automated resolution of failed connections. Two questions: (1) On this page in the documentation: /docs/nqe/data-model/type_devicecollectionerror/ there is a list of errors but no descriptions. Can someone provide? (2) I am studying a failure report and the Connect Test Status notes each of these in PHASEs which seems to imply that each is determined in a sequence. Is there a list of PHASE order for these? AUTHENTICATION_FAILED-AUTHENTICATION PHASEAUTHORIZATION_FAILED-AUTHORIZATION PHASECONNECTION_FAILED-CONNECTION PHASEDEVICE_IS_CHILD_CONTEXT-SETUP PHASEDEVICE_TYPE_MISMATCH-TYPE_DISCOVERY PHASEDEVICE_TYPE_UNDETECTED-TYPE_DISCOVERY PHASEGUEST_MISSING_HOST_RESULTS-SETUP PHASEJUMP_SERVER_AUTHENTICATION_FAILED-CONNECTION PHASEJUMP_SERVER_CONNECTION_FAILED-CONNECTION PHASEOTHER-AUTHORIZATION PHASEPING_FAILED-CONNECTION PHASEPORT_REACHABILITY_FAILED-CONNECTION PHASEPRIV_PASSWORD_ERROR-SETUP PHASEPROMPT_DISCOVERY_FAILED-SETUP PHASESESSION_CLOSED-TYPE_DISCOVERY PHASETIMED
Background on the Jump Server for FWD Enterprise Forward Enterprise obtains data for path analysis primarily using industry-standard command-line interface (CLI) access. This is typically done with secure shell (SSH) read-only credentials provided to the platform so that configuration and state can be retrieved. In certain customer instances, it is required to limit SSH access to a specific host or hosts, which will more effectively audit and maintain the security of network devices. This is commonly known as the bastion or jump server. A jump server, jump host, or jump box is a computer on a network used to access and manage devices in a separate security zone. The most common example is managing a host in a DMZ from trusted networks or computers. A jump server is a hardened and monitored device that spans two dissimilar security zones and provides a controlled means of access between them. User access should be tightly controlled and monitored OpenSSH is commonly used for configurati
This is both incredibly amazing and absolutely frightening. The cat is extremely out of the bag now.Boston Dynamics put a generative AI into the robot dog Spot. And there are different personalities.
If you are in/near the Atlanta area on Nov 14, please join me at this Optm event where I will presenting with other executives from Optm, Infoblox, BigPanda, and LogicMonitor. I’d love to connect in person, and happy to have additional conversations. Event Registration
We had a fun costume contest for Forward employees and their fur babies. Here are the winners!Our co-founder, Peyman, won Best Costume!Our infra engineer, Manuel, won Most Original Costume!Our apps engineering manager, Gayathri, won Scariest Costume!Gayathri’s dog, Nash, won Best Pet Costume!What do you think of the costumes? Do you have any fun ones to share of your own? 🎃
You can now attach EC2 interfaces to multiple different VPCs in AWS: https://aws.amazon.com/about-aws/whats-new/2023/10/multi-vpc-eni-attachments/ The implications of this are pretty huge - previously to control access (with a firewall, etc) between VPCs you needed to use a Transit Gateway, generally associated with a centralized applicance via a Gateway load balancer. This solution is great and scales very well, but its probably overkill for smaller environments. What if you only have 2-4 VPCs? This solution would work great - simple attach your NVA interfaces to different VPCs and modify your route tables accordingly. This eliminates the cost and complexity of TGWs, keeping all the performance benefits. What use cases can you see for this new functionality? Off the top of my head, you could also provide remote access without using a VPN gateway too. I’m sure there are more. This also models correctly out of the box in Forward as well :)
Is it possible to use a SSH jump server to log into a Telnet server, and then from there log into each of the devices?
I’d like to use FN APIs to integrate with Splunk and SIEM / Security systems. Has anyone else done this?
Are there any character restrictions for tags? I would like to use ’ : ‘ in a tag as a namespace but want to be sure there won't be any caveats. I don't see anything in the docs.
How do you create a custom SSL certificate for the fwd web interface?
Is there a way to connect external sources to a postgres database or consume a postgres DB backup? We cannot collect directly from type 1 encryptors but we can get a backup of the encryptor manager DB
For Path Search Ranking, will devices that have a more specific subnet always rank higher than devices with a less specific subnet as the ingress device for a path?
We want to run two clusters in HA Active/Standby. We deployed one cluster yesterday and licensed it. We deployed the second cluster today. I am unclear on how we would license the second cluster. I assume we need a second deployment, but can I apply the same license to that new deployment, or would it require a new license as well?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.