r/Cisco 9h ago

Tenable vs Rapid7

4 Upvotes

I’m looking for a tool that supports multiple vendor hardware for tracking and reporting on cve’s that have been released. Rapid7 and Tenable came up on my radar. Would there be others to consider?


r/Cisco 9h ago

Discussion Anyone who interviewed for Cisco Software Automation Trainee on 9 July still waiting?

0 Upvotes

Hi everyone, I interviewed for the Software Automation Trainee (Graduate Apprentice) role on 9 July and haven’t received any update yet. Is anyone else from the same interview batch still waiting? If you interviewed on 9 July and received an offer, rejection, or any HR update, I’d appreciate it if you could share your status. Thanks!


r/Cisco 9h ago

How long does Cisco take to inform the result after the managerial round?

0 Upvotes

Hi everyone,

I recently interviewed for the Consulting Engineer – Wireless role. I completed my managerial round on July 8, but I haven't received any update from HR yet.

I understand that hiring timelines can vary, but I was wondering if anyone who has gone through this process could share their experience. How long did it take for you to receive feedback or the next update after the managerial round?

Any insights would be greatly appreciated. Thanks!


r/Cisco 17h ago

Question Still on MPLS across 14 sites and the renewal came in 30 percent higher, talk me through what you did.

44 Upvotes

In manufacturing with 14 sites across three countries. MPLS since before I was here. Renewal quote landed last week about 30 percent up on the last one with no change in what we get and the account manager said something about capacity costs that I did not find convincing. 

Meanwhile, the actual traffic pattern has completely changed but not the circuits. Everything is going to M365 and a couple of SaaS things now such that we are hauling cloud traffic across the private network to break out centrally, which is the least sensible possible route for it. The MPLS is doing a great job of carrying traffic to a datacentre that hosts progressively less every year. 

I know where this ends up: SD-WAN, broadband and LTE at the smaller sites, keep something private where the two plants that talk to each other need it. What I don't have a feel for is the security side. Right now security happens at the central breakout. If every site breaks out locally then either I put a box at every site or I do the inspection in the cloud, and I've not run either. 

For the people who have done this migration, what did you underestimate? Not looking for a vendor pitch, more interested in what went wrong.


r/Cisco 19h ago

Cisco Apprenticeship 2026

1 Upvotes

Interview - 17 July

Any update on PDC or LOI mail?


r/Cisco 1d ago

Configuring 802.1Q tunneling

12 Upvotes

I have a setup with Cisco switches (9300) which are interconnected with a good old LACP trunk allowing all VLAN. Other ports are either access ports or trunk ports with specified VLAN depending on what's behind. Now I'm asked to change the LACP connection to QinQ. I've checked this piece of documentation: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/lanswitch/configuration/xe-3se/3850/lnsw-ieee-8021q-tunneling.html and it "just a configuration" on the Po interface among other considerations. I haven't done this before so the question is if I'm going to break everything as soon as I change the port to dot1q-tunnel? I'm not exactly certain what's meant by "asymmetrical links" this is not explained in the article. Thanks for any insights.


r/Cisco 1d ago

issues with ftd and av posturing

1 Upvotes

I'm having a hell of a time getting this working...i dunno what im doing wrong.

Claude seems to think that its because the posture module on the client doesn't appear to be returning the AV version for AMP...but i cant figure out why.

ftd is 7.7.11, anyconnect and amp are latest....the hostscan(firewall posture module) is the matching version.

are there any caveats? or random FTD isms that im missing here?


r/Cisco 1d ago

Firmware Versions Cisco SG200

2 Upvotes

Hi everyone,

I'm trying to update my old Cisco SG200-08 switch. It is currently running on a very old firmware version (1.0.8.3).

To jump to the newer release trees, I need the intermediate step v1.2.7.76.
Unfortunately, Cisco removed the direct download links for these archived files and all i can find are newer Versions. The Switch ist running Hardware Revision V04 (if this matters)

Does anyone have this firmware version archived?
Or could point me in the right direction to download it.

Thanks in advance for any help!
saiken


r/Cisco 1d ago

IOS-XE object-group in ACE not working?

1 Upvotes

There is a confirmed bug since June 2026 but affected version is 16.6.x.

I have 26.01.01 and ACE with network object group (consist of two hosts) is not permitting traffic. Replacing it with respective IPs permits traffic as expected.

Since I am middle of migration from old platform to C9500 and using plenty of object groups to simplify things, this possible bug makes huge obstacle for me.

Anyone using object groups in latest IOS-XE versions without problems?


r/Cisco 1d ago

Germany got blacklisted?

21 Upvotes

Cisco Software Download page says:
We are sorry, but analysis of your internet protocol (IP) address does not permit us to complete this transaction because it is originating from a territory that is not authorized to receive Cisco products without a government issued license.

Tested multiple accounts, multiple software products from multiple public ip addresses.

Anyone else run into this error at the moment?

Support only said this is an account issue and we are not eligible for export-controlled hard- and software as is. However, worked fine Friday...

Has chancellor Merz finally annoyed Trump too much?


r/Cisco 2d ago

Question Cisco Umbrella SWG Client Issue

3 Upvotes

I currently have the Cisco Umbrellas SIG Advantage subscription. I enabled SWG and configured everything as far as I know, but the client shows license invalid under the SWG section.


r/Cisco 2d ago

CML MCP Connectivity Issue

4 Upvotes

Has anyone successfully connected to their Cisco Modeling Labs with Claude via MCP?

My Claude Desktop shows the connector with all permissions available, but my Claude Desktop does not have access for some reason.

I have a feeling I’m missing something small here.


r/Cisco 2d ago

Cisco Software Engineer Trainee (Technical Graduate Apprentice) - Waiting after NATS submission

1 Upvotes

Hi everyone,

I interviewed for the Cisco Software Engineer Trainee (Technical Graduate Apprentice) role on 1 July.

I completed all three rounds:

Technical

Managerial

ETR

On 6 July, I received the official email asking me to submit my NATS ID and Provisional Degree Certificate, and I submitted everything on the same day.

It's now been about 2 weeks since document submission (almost 3 weeks since the interview), and I haven't received any update, acknowledgement, LOI, or offer letter.

Has anyone else gone through the same process?

How long did it take for you to receive the next email?

Did you eventually get the offer letter after waiting?

Is this waiting period normal for the Cisco apprenticeship?

Any recent experiences would really help. Thanks!


r/Cisco 3d ago

Aironet cap 4502I E K9

1 Upvotes

Hi I just bought an Aironet cap 3502I E K9 used on eBay and I was wondering how I could use it as an regular wifi access point at home


r/Cisco 3d ago

Grad network engineer interview

2 Upvotes

Hi all,

Upcoming technical round at Cisco for a grad net engineer. I do have my CCNA with some experience. So I’m not going in fully blind.

Just looking for some advice on what I should maybe look into before the interview? First time interviewing at Cisco so quite excited but also a little nervy.

I appreciate any comments!

Cheers 👋

EDIT: was easy enough, they cared more about my experience and troubleshooting methods. No deep dive into OSPF/BGP etc


r/Cisco 3d ago

Silly Question..

27 Upvotes

Is Meraki worth it?

We're a start-up looking for something inexpensive, simple to manage, and scalable to connect multiple sites across multiple locations. We're currently only a small team with a mix of NBN and 4G/5G connections.

Judging by the Meraki demo, and Cisco's reputation in general, it seems like a great solution, but is there something just as trustworthy while being simpler to deploy and use (and cheaper)?


r/Cisco 4d ago

Send Netflow over IPSec using same IP

0 Upvotes

Could anyone tell me if IOS-XE would complain if I configure Netflow to source it's feed from the same IP as my IPSec tunnel source (but different VRF).

What I mean is:

* Netflow coming from Lo10 in vf-netflow

* IPSec sourced from g0/0/0 in vf-internet

* Both have same IP address, different VRFs

I'm expecting Netflow to be a one-way outbound UDP flow anyway, but IPsec would of course involve packets in both directions.

inter g0/0/0

vrf forwarding vf-internet

ip address 100.0.0.1 255.255.255.252

inter Tun10

vrf forwarding vf-netflow

tunnel vrf vf-internet

ip address 10.0.0.0 255.255.255.254

tunnel source gi0/0/0

tunnel destination 200.0.0.1

tunnel mode ipsec ipv4

interface Lo10

vrf vf-netflow

ip address 100.0.0.1255.255.255.255

flow exporter NETFLOW

source Lo10

destination 200.0.0.10 vrf vf-netflow

ip route vf-netflow 200.0.0.10/32 Tu10 10.0.0.1 ! Imaginary next hop IP


r/Cisco 4d ago

Question Cisco AIR-AP2802I-E-K9 always enters BootROM init>> after every power cycle despite healthy firmware/images

0 Upvotes

Hi everyone,

I'm trying to recover a Cisco AIR-AP2802I-E-K9 (Mobility Express) that behaves very strangely.

Problem

Every time the AP loses power and boots again, it always stops at the BootROM board selection menu:

Please choose one of the following boards:
1. 3K
2. 2K (new)
3. 2K (proto)
4. Milos
5. 2KH
6. 3KVE (v-sku)
7. 3KH/3KA/4K
8. Duplo

init>>

It never boots automatically.

If I manually continue, it reaches U-Boot and then boots Mobility Express normally.

BootROM

BootROM - 1.78
Booting from SPI flash, Secure mode

RSA Public key verification PASSED
CSK block signature verification PASSED
Boot header signature verification PASSED
Box ID verification PASSED

Detected Device ID 6920
Board: Barbados-2K

U-Boot

U-Boot 2013.01
Board: Barbados-2K
CPU: Marvell Armada 88F6920
RAM: 1GB
SPI Flash: 4MB
NAND: 256MB

Environment:

bootcmd=nandboot
BOOT=part1
activepart=part1
boardid=0x21
FACTORY_RESET=0
MANUAL_BOOT=0

Firmware

The AP boots successfully into Mobility Express.

show boot

Primary Boot Image: 8.10.151.0
Backup Boot Image : 8.10.196.0

Both images appear healthy.

The AP can boot and run normally.

NAND

nand info

shows normal NAND.

The filesystem exists.

nand dump 0x200000 0x100

starts with

55 42 49 23

which is the UBI header.

So NAND does not appear empty or corrupted.

SPI

SPI is readable and writable.

saveenv

works successfully.

U-Boot supports:

sf read
sf write
sf erase
sf update

Strange behavior

dump_board_env reports:

Board ID: Unknown (default to 3K)
Flags=00000000

while U-Boot itself reports:

boardid=0x21

So U-Boot knows the board ID, but dump_board_env does not.

What I've already tried

  • Factory reset
  • Reboot
  • Power cycle
  • Booting both firmware images
  • Verified Secure Boot passes
  • Checked NAND
  • Checked UBI
  • Checked U-Boot environment
  • saveenv
  • clear_board_env
  • resetenv

None of these changed the behavior.

My question

Since both Mobility Express images are healthy, I don't think this is a normal firmware recovery case that requires TFTP.

Has anyone seen an AIR-AP2802I that always enters BootROM init>> after every power cycle?

Could this indicate corrupted manufacturing/board environment stored in SPI rather than a firmware problem?

Is there a known way to restore the board environment, or force BootROM to skip the board-selection menu?

Any ideas would be greatly appreciated.Hi everyone,


r/Cisco 5d ago

HA/firepower without fmc

7 Upvotes

Can you run firepowers in HA without FMC? I’d like to strip things down as simple as possible.


r/Cisco 5d ago

GoDaddy Certificates (R1) and Secure Client/Anyconnect

8 Upvotes

I ran into an issue yesterday with one of my clients after renewing the certificate that was being used for their Secure Client configuration. (Yes, I know, GoDaddy sucks - unfortunately my employer continues to use them so I'm stuck.)

Since GoDaddy decided to break the internet with their R1 CA being put into use before the big players like Apple and Microsoft have trusted the CA, for all certificates renewed now, we had to do some hoop jumping.

The setup I was working on was a FTDv being managed by FDM. I re-keyed the certificate like usual, pushed the update, checked in FireFox that the certificate showed the new one and was valid and went about my day. I don't have a login for this customer's VPN to test, so normally a cursory "does the new cert show up after changing the trustpoint?" test via webbrowser to their login page has been enough... well I'll be updating my own test procedures, but I digress.

Customer submits a ticket stating they cannot login to the VPN now, so I dig around and realize what happened. No big deal, just toss in the R1 to G2 intermediate certificate in the chain and call it a day like we've had to do with the Citrix, Exchange and webservers for other clients. Nope, not with Cisco. I opened a TAC case and spoke with an engineer about it, and got my answer immediately - there is no way to push the CA cert or the intermediate cross cert. "You can push it to your windows users with a GPO though!"

Push comes to shove I engaged our desktop support guy who was able to script the certs to be installed via PowerShell and the RMM solution we use. The certs we installed were the R1 CA certificate and the r1-cross-g2 certificate, directly available from https://certs.godaddy.com/repository

Hope this helps someone else, as I couldn't find much online


r/Cisco 5d ago

Avoid CE Credits use when expiring.

6 Upvotes

Hi, as you can see in the picture I have 81 CE points.

My Certification expires on Feb. 2028, I´m just worried that the 40 points expiring on Feb. 2027 will be used to recertify my CCNP.

I would prefer to earn more credits and let renew the certificationon 2028 instead 2027.... Is it possible?

Thanks!


r/Cisco 5d ago

Cisco RMA delay issue

15 Upvotes

I have 3 RMA (2 N9K & 1 Catalyst) and Cisco failed to commit to 4 hours SLA support and RMA.

They said the replacement unit is not ready and I have to wait until mid of August.

Are you guys also having this issue?

Can someone please advise me how to escalate to their higher management?


r/Cisco 6d ago

Wifi Cisco

1 Upvotes

Alguém tem alguma dica de como contornar alta retransmissão e interferência nos access points?
Estou com seguinte cenário, fiz um site survey com ferramenta ekahau, criei um perfil de rádio frequência de acordo com o survey, é um ambiente de alta densidade, contendo 14 access point no térreo e 13 no primeiro andar, o perfil de RF em 5Ghz ficou com data rate mandatory 24 mega, potência ficou entre 8 a 12 dbm, mas olhando no catalyst center as antenas sempre se mantem em 8dbm, os canais são fixo, tentei não sobrepor os canais, deixando o mais longe possível, coloquei RX-SOP em Medium, o roaming esta bom, mas o problema é que durante o horário de trabalho no catalisty todas as atenas estão com interferencia entre 30 a 60%, e a taxa de retransmissão entre 30 a 70%, não estou conseguindo contornar e diminuir esses valores, fora do horário de trabalho as antenas não tem interferencias, alguem tem alguma dica? Obrigado a todos!


r/Cisco 6d ago

Question C1300 - Tagged VLAN traffic not forwarding on trunk to/from Firewall

3 Upvotes

Setup: Cisco C1300-12XT-2X, firmware 4,1,9,85 (latest). Interface te1/0/13 is an 802.1Q trunk to a WatchGuard Firebox M690 (WG physical interface 10, also configured as a tagged trunk).

Trunk config on te1/0/13:

interface TenGigabitEthernet1/0/13
switchport mode trunk
switchport trunk native vlan 101
switchport trunk allowed vlan 2-4094

VLANs in use: 101 (native/untagged), 201, 203, 204 (tagged).

Problem: VLAN 101 (untagged) works fine. VLANs 201, 203, 204 (tagged) do not — show mac address-table interface te1/0/13 only ever shows VLAN 101 entries, never anything for 201/203/204, even after generating traffic and bouncing the port.

Interesting data point: Devices on access ports assigned to VLAN 201 can talk to each other fine (so VLAN 201 itself is alive and working on the switch), but none of them can reach the WatchGuard's VLAN 201 gateway IP, which sits behind te1/0/13. So the problem seems isolated specifically to traffic crossing that one trunk port, not VLAN 201 as a whole.

What makes this stranger: te1/0/14 has the exact same trunk configuration, connected to a different downstream switch, and works perfectly across all four VLANs.

Already ruled out:

  • Frame Type = Admit All, Ingress Filtering = Enabled, PVID = 1
  • Spanning Tree = Forwarding on te
  • Port Security — not locked/enabled
  • Storm Control, ACLs, DHCP Snooping — none enabled switch-wide
  • Bounced the interface (shut/no shut) after the cleanup — no change

WatchGuard side: Already worked through this with WatchGuard support — they've confirmed the Firebox VLAN interfaces (201/203/204) on interface 10 are correctly configured with IPs/DHCP scopes and tagged on the right physical interface. They're pointing back at the switch.

Question: Config is clean and matches a known-working port line for line, and VLAN 201 is confirmed functional elsewhere on the switch, but tagged traffic just never seems to reach the WatchGuard across this one trunk port. Has anyone run into something like this on the C1300 series? Wondering if there's a known firmware bug, a hardware forwarding-table sync issue, or some non-obvious setting I'm missing. About to set up a port mirror on te1/0/13 to confirm whether tagged frames are even physically arriving, but wanted to check if this rings a bell for anyone first.

\* Post drafted with AI assistance to organize troubleshooting steps. all technical details/config are from my own testing*

Edit/Update: we removed the C1300 switch and put in place an old C2960. Same trunk config and getting the same result. PCAP picks up the tagged VLAN traffic across interfaces with devices on static VALN 201 IPs but still nothing on the WG end 😩


r/Cisco 6d ago

High DataPlane Usage

3 Upvotes

Hey everyone.
Curious to see if yall have run into a similar issue. We’ve got some FTD 1140s that have started running hotter after upgrading to 7.6.4.
Before upgrading we were regularly running at about 70-75% Data Plane usage, now we seem to be regularly at 85%. Depending on the time of day we’re getting into the low to mid-90’s %.
Nothing has changed in our network other than this upgrade. I’m curious if yall have experienced anything similar or this is related to some sort of bug related to 7.6.4.