Tagged: cisco
61 posts · browse all tags
-
Five Minutes and an Empty Port Part 10: The Closing Checklist and a Vendor Comparison
Closing the series: a practical checklist pulling Parts 7 through 9 together, and a straight comparison of how Cisco, Fortinet, Juniper, and Arista actually implement each control.
-
Five Minutes and an Empty Port Part 7: Port Security and the Layer 2 Hygiene Most Networks Already Own
The defensive turn starts at the layer that would have stopped Part 6's persistent dropbox outright: port security, DHCP snooping, Dynamic ARP Inspection, and the rest of the Layer 2 hygiene most switches can already do without buying anything new.
-
One Crafted Request From a Reload: Inside CVE-2026-20349 on Cisco Secure Firewall ASA and FTD
An unauthenticated attacker who can reach the Remote Access SSL VPN service on an ASA or FTD device can crash it with one crafted HTTP request. No login, no workaround, just a reload. What CVE-2026-20349 actually is, and why VPN-facing edges keep being the softest part of the firewall.
-
Seven CWEs, One Advisory: Cisco's August 2026 IOS XE Hardening Release
Cisco's IOS XE team ran the same internal-review model it used on Catalyst SD-WAN in August, grouping fixes by CWE class instead of shipping one CVE per bug. Seven CVE IDs, seven vulnerability classes, no known exploitation, and the same AI-assisted discovery line in the source section.
-
One CSV Upload From Root: Inside CVE-2026-20245 on Cisco Catalyst SD-WAN Manager
A rogue peering connection, a password changed and quietly changed back, then one crafted CSV file that turned an admin session into root. Mandiant's writeup of CVE-2026-20245 is the missing middle chapter between this site's UAT-8616 post and August's hardening release.
-
SDWSCS Part 13: Monitoring with vManage & vAnalytics
The SDWSCS finale — module 13: operating everything the series deployed. vManage's security and Cloud OnRamp dashboards, the UTD and tunnel health signals worth alerting on, vAnalytics/Cisco SDWAN Analytics for trends and forecasting, and a day-2 runbook.
-
Declare Yourself Trusted: Inside UAT-8616's Three-Year Run Against Cisco Catalyst SD-WAN
Two maximum-severity Cisco Catalyst SD-WAN authentication bypasses, one threat actor, three years of quiet control-plane access. What CVE-2026-20182 and CVE-2026-20127 actually broke, how UAT-8616 used it, and what the fix demands beyond patching.
-
Marking Its Own Homework: Inside Cisco's August 2026 Catalyst SD-WAN Hardening Release
Three months after UAT-8616 forced Cisco's hand on SD-WAN, a different kind of disclosure: an internal security review, five CWE-grouped CVEs up to CVSS 9.9, and an admission that some of the bugs were found by AI models, not people.
-
SDWSCS Part 12: Cloud Interconnect & OnRamp for Colocation
Modules 11–12 of SDWSCS: software-defined cloud interconnect with Megaport and Equinix — virtual routers and private cross-connects provisioned from vManage — and Cloud OnRamp for Colocation: CSP clusters, NFVIS, and vManage-orchestrated VNF service chains.
-
SDWSCS Part 11: Cloud OnRamp Multicloud — AWS, Azure & GCP
Module 10 of SDWSCS: extending the fabric into public cloud with Cloud OnRamp for Multicloud — cloud gateways built from Catalyst 8000Vs, AWS Transit Gateway and Cloud WAN, Azure vWAN, GCP NCC, and the tag-based intent mapping that connects VPCs to service VPNs.
-
SDWSCS Part 10: Cloud OnRamp for SaaS
Module 9 of SDWSCS: Cloud OnRamp for SaaS in deployment detail — vQoE probing and scoring, DIA vs gateway vs client access exits, the Microsoft 365 telemetry integration, Webex/Office/custom app lists, and verifying the path decisions it makes.
-
SDWSCS Part 9: ThousandEyes — Monitoring Cloud Services
Module 8 of SDWSCS: deploying ThousandEyes enterprise agents in app hosting on Catalyst edges, test types and what each proves, the vManage integration, and building Microsoft 365 monitoring that turns 'Teams is slow' into an actionable path diagnosis.
-
SDWSCS Part 8: CASB, DLP & Securing Microsoft 365
Module 7 of SDWSCS: the CASB layer riding on Umbrella SIG — shadow IT discovery, app controls, tenant restrictions for Microsoft 365, data loss prevention, and remote browser isolation. What each control needs from the SDWAN side to work.
-
SDWSCS Part 7: Umbrella SIG — Deployment & DNS Policies
Module 6 of SDWSCS: Umbrella SIG architecture and deployment — the automatic tunnel workflow from vManage, active/active vs active/backup designs, steering traffic into the SIG, and DNS security policies as the first (and cheapest) enforcement layer.
-
SDWSCS Part 6: SASE — Architecture & Use Cases
Module 5 of SDWSCS: what SASE actually is once the marketing is stripped away — the SSE service stack, how Cisco assembles it from Catalyst SDWAN, Umbrella, Duo and ThousandEyes, and the use cases where cloud-delivered enforcement beats on-box or chained designs.
-
SDWSCS Part 5: Secure DIA & Service Chaining
Module 4 of SDWSCS: assembling the embedded stack into a secure Direct Internet Access design, then service chaining — OMP service routes, control and data policy steering, and the dedicated-security patterns for traffic that must transit a real firewall.
-
SDWSCS Part 4: Content Filtering — URL Filtering & TLS/SSL Decryption
Module 3 of SDWSCS: URL filtering with categories and web reputation, block pages, and the TLS/SSL decryption proxy — CA design choices, the decrypt policy, undecryptable traffic handling, and why decryption is the feature that needs a change-management plan.
-
SDWSCS Part 3: On-Premises Threat Prevention — Firewall, IPS & AMP
Module 2 of SDWSCS: deploying the application-aware enterprise firewall, Snort-based IPS with its three signature sets, and AMP file reputation with Threat Grid sandboxing — plus fail-open vs fail-close and the verification commands for each.
-
SDWSCS Part 2: The SDWAN Security Model & Unified Security Policy
Module 1 of the SDWSCS syllabus: why DIA changed the threat model, the four security deployment patterns, what actually runs on a Catalyst edge (zone-based firewall vs the UTD container), and the unified security policy framework that ties it together.
-
SDWSCS Part 1: Course Overview & Study Roadmap
Kicking off a thirteen-part series on Cisco's SDWSCS syllabus — SDWAN security and cloud solutions. Part 1 explains what the course covers, how it extends ENSDWI, maps all thirteen modules and eleven labs to this series, and sets out a realistic study plan.
-
OSPF Deep Dive Part 10: A Vendor-Neutral Troubleshooting Methodology
A structured way to diagnose OSPF problems that works on any vendor, because it's built on the neighbor state machine from Part 1, not on any platform's specific commands: what state is it stuck at, and what does that state rule in or out.
-
OSPF Deep Dive Part 11: Show Commands and the LSDB, Side by Side
The same neighbor table, interface state, and LSDB, read through three different command sets: Cisco IOS/IOS-XE, FortiOS, and Junos, mapped side by side against the CORE-CSR/BRANCH-FGT/EDGE-MX lab from this series.
-
OSPF Deep Dive Part 12: A Multi-Vendor Outage, Start to Finish
A closing walkthrough on the CORE-CSR/BRANCH-FGT/EDGE-MX lab: a complaint with no down interfaces and no failed adjacencies anywhere, a red herring that turns out to be real but irrelevant, and a root cause that traces straight back to Part 3's reference-bandwidth warning.
-
OSPF Deep Dive Part 4: Virtual Links, Summarization, and Redistribution
Fixing the lab's missing backbone connection with a virtual link, then summarizing at the ABR and redistributing a static route at the NSSA's ASBR, with working syntax on Cisco, FortiOS, and Junos for each.
-
OSPF Deep Dive Part 5: OSPFv3 and Running OSPF Over IPv6
OSPFv3 isn't OSPFv2 with bigger addresses. It separates topology from addressing, drops built-in authentication in favor of IPsec, and runs over link-local addresses by default, plus the per-vendor syntax to bring it up on Cisco, FortiOS, and Junos.
-
OSPF Deep Dive Part 6: Authentication and Security Hardening
What an unauthenticated OSPF segment actually exposes, why plaintext and MD5 authentication are both weaker than they look, and how to configure HMAC-SHA key chains on Cisco, FortiOS, and Junos.
-
OSPF Deep Dive Part 7: Cisco IOS/IOS-XE Implementation and Gotchas
CORE-CSR's actual configuration: process ID scope, the network-statement vs interface-based config split, the passive-interface-default trap, and why raising reference-bandwidth only ever warns once, locally, at configuration time.
-
ENSDWI Part 12: Management, Operations, and Exam Day
Blueprint domain 6.0 — vManage AAA, monitoring and alarms, REST API monitoring, and software image management — then a revision strategy for the whole blueprint and what to expect on exam day. Series finale.
-
Juniper Session Smart SD-WAN Deep Dive Part 8: Failure Modes, Scale Limits, and a Five-Way Vendor Comparison
Series finale. What happens to the data plane when Conductor or Mist goes dark, where SSR's scale story sits, and Session Smart Routing lined up against Fortinet, Cisco/Viptela, Arista/VeloCloud, and Palo Alto/Prisma — five philosophies, one underlying question.
-
Palo Alto Prisma SDWAN Deep Dive Part 8: Failure Modes, Scale Limits, and a Vendor Comparison Checklist
Series finale. What actually happens when Strata Cloud Manager goes dark, where Prisma SDWAN's scale limits sit, and an honest, direct comparison against Fortinet's collapsed model and Cisco's fully decoupled one — the fourth philosophy, lined up against the three already covered on this site.
-
ENSDWI Part 11: QoS and Application Quality of Experience
Blueprint 5.4 and 5.5: the WAN Edge QoS pipeline — classification, marking, policing, shaping, scheduling, queuing — plus per-tunnel and adaptive QoS, then App-QoE: TCP optimization, DRE, packet duplication, FEC, and AppNav.
-
ENSDWI Part 10: Security — Service Insertion, Embedded, and Cloud-Delivered
Blueprint 5.1–5.3: service insertion with OMP service routes, the embedded security stack — app-aware firewall, Snort IPS, URL filtering, AMP, SSL/TLS proxy, TrustSec — and cloud security integration with Umbrella DNS and SIG tunnels.
-
ENSDWI Part 9: Data Policies, Segmentation, App-Aware Routing, and DIA
Blueprint 4.2–4.5: centralized data policy at the edge, VPN segmentation and per-VPN topologies, application-aware routing with SLA classes and BFD measurements, and direct Internet access with NAT fallback.
-
ENSDWI Part 8: Control Policies
Blueprint 4.1: the centralized policy framework, how control policy is evaluated at vSmart, match/action anatomy, and the canonical topologies — hub-and-spoke, regional mesh, and TLOC preference steering — built entirely by filtering routing information.
-
ENSDWI Part 7: OMP, TLOCs, Routing Protocols, Multicast, and Config Groups
Blueprint 3.3–3.7: configuring OMP and TLOCs, service-side OSPF/BGP/EIGRP and VRRP with their loop-prevention markers, multicast over the overlay, and the configuration-group/feature-profile model that v1.2 added to the exam.
-
ENSDWI Part 6: WAN Edge Deployment — ZTP, Bootstrap, and TLOC Extension
Blueprint 3.1 and 3.2: onboarding edges with ZTP, PnP, and bootstrap; data-centre and regional-hub designs; circuit termination and TLOC extension; dynamic tunnels; and how the underlay and overlay exchange routes.
-
Ansible Deep Dive Part 10 Lab: Automating a Cisco and FortiGate Fleet With Ansible
Part 10, the second lab: network-specific Ansible modules against a mixed Cisco IOS and FortiGate fleet — cisco.ios facts and config, fortinet.fortios firewall policy objects, connection: network_cli vs httpapi, and a config-drift check playbook.
-
ENSDWI Part 5: Certificates, Device Lists, and Control-Plane Troubleshooting
Blueprint 2.3 and 2.4: the certificate trust model end to end — root CA options, controller CSRs, the WAN Edge authorized serial list — then the systematic control-connection troubleshooting flow behind most ENSDWI exhibit questions.
-
ENSDWI Part 4: Controller Deployment — Cloud, On-Prem, Scale, and Redundancy
Blueprint 2.1 and 2.2: Cisco-hosted vs on-premises controllers, hosting platform requirements, installing the vManage/vBond/vSmart trio, and the scalability and redundancy rules — clustering, affinity, and how many of each you actually need.
-
ENSDWI Part 3: Edge Platforms and Cloud OnRamp
Finishing blueprint domain 1.0: the cEdge and vEdge platform families and how to pick between them, then all four Cloud OnRamp variants — SaaS, IaaS, Colocation, and Multicloud/Interconnect — at the depth the exam actually tests.
-
ENSDWI Part 2: Architecture — Planes, Components, and Multi-Region Fabric
Blueprint domain 1.1: the four planes and their components, OMP's three route types, TLOCs, IPsec vs GRE encapsulation, BFD's dual role, and Multi-Region Fabric — the v1.2 addition that older study material misses entirely.
-
ENSDWI Part 1: Exam Syllabus & Study Roadmap
Kicking off a twelve-part study series for the Cisco 300-415 ENSDWI exam. Part 1 breaks down the v1.2 blueprint domain by domain, maps every topic to a part of this series, and covers exam logistics, lab options, and how to study for a 90-minute concentration exam.
-
Cisco Catalyst SDWAN Deep Dive Part 1: Components, Controllers, and the Four Planes
Starting a ten-part deep dive into Cisco Catalyst SDWAN. Part 1 covers the Viptela lineage, the four controller planes (vManage, vSmart, vBond, WAN Edge), the certificate trust model, and the control-connection bring-up sequence.
-
Cisco Catalyst SDWAN Deep Dive Part 10: Failure Modes, Scale Limits, and a Vendor Comparison
Part 10, the finale: what actually breaks (vBond, vSmart, vManage) and what doesn't when it does, vManage's documented scale ceiling, and a head-to-head of OMP/TLOC against Fortinet ADVPN, Arista DMPO, and VeloCloud.
-
Cisco Catalyst SDWAN Deep Dive Part 2: OMP, the Overlay Management Protocol
Part 2 of the Cisco Catalyst SDWAN series: what OMP actually carries between WAN Edge and vSmart — OMP routes, TLOC routes, and service routes — how best-path selection and multipath differ from BGP, and why the overlay/underlay split is the whole point.
-
Cisco Catalyst SDWAN Deep Dive Part 3: TLOCs, Color, and Centralized Policy
Part 3 of the Cisco Catalyst SDWAN series: what TLOC color actually constrains, how restrict/no-restrict shapes which tunnels can form, and how centralized control policy on vSmart turns that into enforced topology — full mesh, hub-and-spoke, or anything between.
-
Cisco Catalyst SDWAN Deep Dive Part 4: BFD, App-Route SLAs, and cEdge Forwarding
Part 4: how BFD over every data tunnel drives both fast failure detection and continuous SLA measurement, how app-route policy steers on that data, and where cEdge's IOS-XE forwarding pipeline diverges from legacy vEdge.
-
Cisco Catalyst SDWAN Deep Dive Part 5: Topology Walkthroughs — Dual Transport, DIA, and TLOC Extension
Part 5: VPN segmentation (transport vs. service VPNs), a worked dual-MPLS-plus-Internet branch design, direct internet access for local breakout, and TLOC extension for sites with no WAN circuit of their own.
-
Cisco Catalyst SDWAN Deep Dive Part 6: Cloud OnRamp for SaaS and IaaS
Part 6: how Cloud OnRamp for SaaS continuously measures per-app, per-transport path quality to pick the best local breakout, and how Cloud OnRamp for IaaS extends the fabric directly into AWS and Azure as cloud-resident sites.
-
Cisco Catalyst SDWAN Deep Dive Part 7: SIG, Secure Firewall, and Edge Security
Part 7: how DIA traffic gets inspected without a hub backhaul — Cisco Secure Internet Gateway integration, the on-box UTD container on cEdge, and how this converges with the broader SASE shift other vendors are making too.
-
Cisco Catalyst SDWAN Deep Dive Part 8: Automation — vManage API, Terraform, and Ansible
Part 8: why vManage's API-first design means automating Catalyst SDWAN looks nothing like CLI-scraping individual boxes, and where Terraform's declarative model and Ansible's procedural model each fit.
-
Cisco Catalyst SDWAN Deep Dive Part 9: The MPLS-to-SDWAN Cutover Playbook
Part 9: a phased, coexistence-based migration sequence from legacy MPLS to Catalyst SDWAN — pilot sites first, hubs last, explicit rollback triggers, and why ripping MPLS out in one weekend is the wrong instinct.
-
SDWAN Control Plane Showdown: Three Philosophies for Solving the Same Problem
Fortinet collapses control onto the data-plane device. Arista/VeloCloud collocates it on a multi-tenant Gateway. Cisco/Viptela decouples it fully into vSmart and OMP. Three architectures covered on this site, lined up side by side, right before the Cisco series picks up the third one.
-
A Brief History of SDWAN Controllers: Viptela, VeloCloud, CloudGenix, and Why Cisco Runs Two SDWAN Stacks
Three startups solved SDWAN's control-plane problem within a year of each other. Two got bought by exactly the company you'd expect; one brand didn't survive. The acquisition history of Viptela, VeloCloud, and CloudGenix — and why Cisco still runs two unrelated SDWAN stacks today.
-
From DSCP to Deep Packet Inspection: Why SDWAN Application-Aware Routing Killed Traditional QoS
A deep technical comparison of legacy QoS (DSCP/CoS, static priority queues, box-by-box CLI) against SDWAN Application-Aware Routing — plus a vendor-by-vendor breakdown of how Cisco Catalyst SDWAN, Fortinet, Juniper Mist (128T), and VeloCloud actually identify and steer application traffic.
-
The Packet Never Lies: Advanced tcpdump Recipes for the Enterprise Engineer
Bitwise BPF masking, enterprise recipes for asymmetric routing and retransmission hunting, a safe SSH-to-Wireshark live-streaming setup that won't loop your own session, and a cross-vendor capture map spanning Debian, Cisco IOS, FortiOS, Junos, and VeloCloud.
-
BGP Route Dampening Part 1: The Flapping Problem, Exponential Decay, and Cisco Configuration
A deep dive into how BGP route dampening works: the 1990s internet instability that created it, the exponential decay algorithm behind it, every Cisco parameter explained, and a full configuration and verification reference.
-
BGP Route Dampening Part 2: RFC 7454, BFD, and Where Dampening Still Belongs
Why the IETF now discourages global BGP route dampening, how Bidirectional Forwarding Detection interacts with it, what RFC 7454 actually says, and the specific modern scenarios where dampening remains the right answer.
-
Adding Vendor Route-Table Parsers to route-compare, and Why the Work Lives on a Branch
A follow-up on the route-compare tool: I taught it to read raw show ip route, get router info routing-table all, show route, and show routing route output directly — no Excel cleanup step. The work lives on a branch rather than on main, and this is why.
-
Netmiko in Practice: From a Show-Command Script to a Repeatable Audit Tool
A working network engineer's guide to Netmiko — starting from a small repo of mine that runs show commands across a JSON inventory, and extending it into something you can use as a real audit tool with structured output, concurrency, secure credentials, and a sane dry-run for config changes.
-
Route Leaking Between VRFs on Cisco IOS: From BGP First Principles to Advanced Manipulation
A practical end-to-end walkthrough of route leaking between VRFs on Cisco IOS — starting with the BGP and VRF fundamentals you need to actually understand what's happening, the static and MP-BGP options for the leak itself, and the route-map machinery that lets you control exactly what crosses.