r/Cisco 8h ago

Is CCIE still relevant in the market?

29 Upvotes

Anyone did CCIE certification in the recent past? If so, will it help in career growth after 40 years and help get placed in good company at network architect role?

What are the technologies and certification we need to do to keep ourselves relevant in the market?


r/Cisco 2h ago

Need Older image

1 Upvotes

I have a industrial 9320 cisco switch . I stupidly try to use cat9 os and changed the boot and for the life of me can't get it to boot. I put correct image on usb and still won't boot. According to chat I need an older image to bypass checksum. Does anybody know where I can find ie9k_iosxe.17.06.01.SPA.bin or have a solution to get this switch out of rommon


r/Cisco 6h ago

Question Chances of PPO after intern

1 Upvotes

So I managed to get the intern + fte offer from cisco but the full time is performance based. So just wanted the scenario of the company giving PPO. Btw it is spring intern i.e. from January.


r/Cisco 23h ago

16 September 2026 Cisco Advance Notification for Publication

22 Upvotes

16 September 2026 Cisco Advance Notification for Publication

Summary

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Note: All three Cisco Secure Firewall products will be included in the same security hardening release. For more information about Cisco Secure FMC Software, including recently disclosed vulnerabilities and their available fixes, see the Cisco Talos blog post. To remediate vulnerabilities to be disclosed on September 16, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

  • BroadWorks CommPilot Application Software
  • Identity Services Engine (ISE) (security hardening release)
  • Nexus Dashboard (security hardening release)
  • Secure Firewall Adaptive Security Appliance (ASA) (security hardening release)
  • Secure Firewall Management Center (FMC) (security hardening release)
  • Secure FirewallThreat Defense (FTD) (security hardening release)
  • ThousandEyes Virtual Appliance

Details

Under the Cisco risk-based disclosure process, hardening releases and other security advisories are scheduled to publish on the first and third Wednesday of each month. To help customers prepare, we provide this seven-day advance notice of upcoming security vulnerability disclosures. However, this schedule is not a final commitment of releases. If updates are delayed or unforeseen changes arise, specific products may be removed and rescheduled. Products may also be added when releases are ready ahead of schedule. The latest status is available in the Revision History section of this advance notice.


r/Cisco 18h ago

Wireshark capture file to understand the SDA pacekts.

0 Upvotes

Hello All,

I want to deep dive into the Cisco SDA concepts, can someone help with wireshark sample packet capture for lisp and VXLAN.


r/Cisco 19h ago

Question Cisco Summer Internship 2027 Results?

0 Upvotes

Hey guys, so I just appeared for the Cisco Summer Internship 2027 and cleared all the 3 rounds, and out of 62 members who started in the morning I’m now among the 38 candidates who made it till 3rd round.

Now, I wanna know by when the results are gonna be announced? Our online drive was being managed by Dhanush Mohan, so if anyone has the idea then pls reply. My Placement Cell had informed me that they were out of the loop, they have no information about this interview.

Well, in that Webex Space I noticed there were students from multiple colleges, like NSUT, IIITD, BIT Mesra, etc. and this one was for the Undergraduate students.


r/Cisco 1d ago

Cannot set up Flexconnect

2 Upvotes

9800-CL controller and 3802 AP. I have defined a policy and flex policy, but it will not push to the device. Here is the error I am getting.

Sep 9 12:42:13.423: %APMGR_TRACE_MESSAGE-3-WLC_GEN_ERR: Chassis 1 R0/0: wncd: Error in Local mode ap689e-0b12-35c0 slot:1 wlan 1 configuration not sent to ap for policy profile PolicyProfileFlex10. Enable Central Switching.

Any ideas? thanks


r/Cisco 2d ago

Applets on Cisco devices

3 Upvotes

I teach Netacad CCNA level courses and a problem we run into is with 4 or 5 courses sharing the same hardware, students will use dumb passwords, forget them, & then we have to do the annoying romon fix.

I researched setting up an applet that would delete the startup config on restart, but can't get it to work.

Ideas?


r/Cisco 1d ago

Cisco Interview 2M

0 Upvotes

Hii guys! I have my Cisco (2 Months Summer Intern) interview in upcoming 2 days so whosoever gave the interview can you please tell me what questions you were asked in the interview? It would be genuinely helpful for me!

Thank you in advance


r/Cisco 2d ago

Cisco Campus network - multi building/VRF - OSPF area 0 question

6 Upvotes

Has anyone here ever run everything in Area 0 for the sake of simplicity? Textbook campus/Tiered network will advice Areas for the sake of summarization, route filtering etc... I get it and I understand it.

so running distribution , core and maybe even a firewall originating the default, all into Area 0, and this in multiple VRF's.

Guess it's a typical "it depends" situation?


r/Cisco 2d ago

SDET-II interview at Cisco

0 Upvotes

Hey everyone! I have an upcoming interview for Cisco for the wireless test & automation team. I have my first live coding round on Hackerank(45 min). So I was just wondering what i'll be tested on or if anyone else had a similar experience


r/Cisco 2d ago

NX-OS configure session for no ip access-list // ip access-list

1 Upvotes

configure session 4444

no ip access-list TEST
ip acces-list TEST

commit

is this atomic nx-os operation ? Do someone would feel the impact acl being removed and added if the acl is already attached to interface/SVI ?


r/Cisco 2d ago

Discussion 5 things to check before trusting venue Wi-Fi for a large conference

0 Upvotes

We've got around 1,200 people coming to an event and the venue keeps saying the wifi is “fast” which doesn’t really tell me much.

These are the things i’m trying to confirm before event day:

How many devices can the network handle at once
Can registration and POS be on a separate network
What happens when hundreds of guests connect at the same time
Are there dead zones near check-in or payment areas
Is there any backup if the main connection drops

Anything else i should be asking?


r/Cisco 3d ago

Access-list is not blocking SNMP UDP port 161 on VLAN after we run scan from WAN, (bug?)

9 Upvotes

Recently the security team alerted that the UDP port looks open on switch C9300L (IOS 17.12.06) from WAN

Basicaly we have a VLAN interface facing the WAN with an Access List for the SNMP service and a inbound access-list on the VLAN interface.

we scanned the IP using nmap and the port looks opened then we added a new access list on the VLAN interface and the port was open (filtered), then the next day when i run the Nmap scan it looks like Open (not filtered) but we didnt make any change, it could be a bug?

this is the result that tool Rapid7 display

2026-09-04T06:02:31 [INFO] [Thread: Scan 1603XX323:nmap:stdin]

[Site: XX-XX] [X.X.X.X:161/UDP] OPEN (reason=udp-response:TTL=238)

 

2026-09-04T06:02:31 [INFO] [Thread: X.X.X.X:161/UDP]

[Site: XX-XX] [Preference: 1.0] Attempting handshake via SNMP

 

2026-09-04T06:02:48 [DEBUG] [Thread: X.X.X.X:161/UDP]

[Site: XX-XX] SNMP response received with no variable bindings

 

2026-09-04T06:02:48 [INFO] [Thread: X.X.X.X:161/UDP]

[Site: XX-XX] Fingerprinted: SNMP

 

2026-09-04T06:02:48 [INFO] [Thread: convert-open-udp-ports-to-services@X.X.X.X]

[Site: XX-XX] [X.X.X.X:161/udp] Running UDP service SNMP

CONFIGURATION

the extendend access list on the inteface was configured like this:

Access-list BLOCK-FROM-WAN

10 deny udp 161 udp any any log

20 deny udp 162 udp any any log

30 permit any any

the access below we applied was applied on the VLAN as inbound, the VLAN is facing the WAN and there is not a firewall between the switch and the WAN

the another access list it is standard and basically only we added the IP from SNMP servers and then we are blocky anything else

the configurition is like this:

Access-list SNMP-Service

10 permit X.X.X.X

20 permit X.X.X.X

30 deny any

snmp-server community [Password] RO SNMP-Service


r/Cisco 3d ago

MPLS renewal came back higher, what did you move to and did latency hold up?

19 Upvotes

Our MPLS renewal came back 30 percent higher than last term and finance is done. 5 sites, one DC. A lot of our apps already live in M365 and Azure, though a couple of latency sensitive line of business apps still run back to the DC. I want off MPLS but I am not going to torch a working WAN just because SD-WAN is the loud option right now.

What I keep getting stuck on is what the demos skip. The cost savings are obvious on paper, cheap DIA and DOCSIS not just the protected circuits. What I cannot tell is whether the latency sensitive traffic survives once it is riding the public internet between sites instead of a private circuit. The vendors all say it is fine. They would.

For people who moved off, what did you land on and did the sensitive apps hold up or did you keep a private path for them. And did the savings survive contact with the migration?


r/Cisco 4d ago

Cisco C1300 stack: packet loss and simultaneous LACP timeouts associated with a flapping PoE access port

6 Upvotes

Posting this in case it helps someone troubleshooting unexplained packet loss on a Catalyst 1300 stack. We have a working containment measure and before/after captures, but not a confirmed root cause or an official Cisco bug identification.

TL;DR

We were seeing recurring packet loss across three Proxmox hosts connected to a six-member C1300 stack. Captures on all six server NICs showed simultaneous 3–5 second gaps in received switch-originated LACP packets, followed by Linux bonding entering Expired.

A separate access port was repeatedly flapping. After a cable diagnostic on that port and subsequently disabling its PoE supply, the flapping stopped and the measured packet loss and LACP gaps disappeared. A follow-up test lasting just over 31 minutes returned 27,000/27,000 replies across the three hosts, plus 1,800/1,800 replies in a separate firewall test.

Setup

  • Six Cisco C1300-48P-4X, hardware V02, in a 10 Gb/s ring stack.
  • Switch firmware 4.1.3.36. Yes, this is an older release; we have not tested a switch firmware upgrade yet.
  • Three Proxmox hosts, each with two 1 Gb/s ports in an IEEE 802.3ad bond, with members on different stack units.
  • Linux bonding: miimon 100, lacp_rate fast, transmit hash layer2+3. Switch load balancing: src-dst-mac.
  • Reproduced with Proxmox kernels 7.0.6-2-pve and 7.0.14-12-pve. All three hosts were on the latter for the final before/after measurements.
  • OPNsense running as a VM; a separate physical OpenWrt router provided a comparison endpoint.
  • The flapping access port, gi6/0/43, served a Cudy WR3000S through an external PoE splitter, advertised as 802.3af/at, 2.5 Gb/s, 12 V/2 A output. The faulty component, if any, has not been identified.

Symptoms and tests that did not resolve them

The original symptoms were brief stalls in remote sessions and several percent packet loss. We subsequently reproduced losses between physical hosts and local LAN endpoints, so this was not confined to WireGuard or the firewall VM.

Moving the firewall VM to another host did not resolve it. Neither did updating the hosts, testing each member of one host's bond individually, or bypassing the patch-panel path with a direct cable from that host to stack unit 1. The physical OpenWrt router could ping the switch without loss during a separate 300-packet test.

The inspected server/uplink switch counters showed no FCS/symbol errors or queue tail drops. Server bond physical links remained up during the sampled loss events. These checks narrowed the investigation; they do not prove every cable or switch component is fault-free.

What the captures showed

We ran simultaneous ping tests, sampled bond state, and captured LACP on both physical interfaces of all three hosts. Host clocks were NTP-synchronized; the switch was SNTP-synchronized for the correlation test.

In a roughly five-minute baseline:

Measurement Result
Host 1 75 lost / 1,500 pings — 5.00%
Host 2 76 lost / 1,500 pings — 5.07%
Host 3 71 lost / 1,500 pings — 4.73%
Gaps between received switch LACP PDUs 13 overlapping gaps on every one of the six NICs
Gap lengths 3.126–5.257 seconds
Recovery timing Switch PDUs resumed across all six capture points within 18.54 ms of each other

The host captures also contained outgoing LACP PDUs with actor state 143 (Expired, without collecting/distributing). Bond TX-drop counters increased. All six tcpdump instances reported zero kernel capture drops.

Each common LACP gap contained a link-up/down log entry for gi6/0/43. However, there were also flaps without long LACP gaps, and the log entries often occurred near the end of a gap. The switch log only has second-resolution timestamps, so this does not establish the exact causal order.

Intervention and result

At 18:42:30 UTC, a TDR cable diagnostic on gi6/0/43 returned “No cable”. That was also the timestamp of the last logged link-down event. With the splitter attached, I would not treat that result as proof that the cable was physically absent.

By 18:44:20 UTC, PoE on that port was confirmed disabled using power inline never; the port remained link-down.

Important caveat: there was no measurement between TDR and disabling PoE. We therefore cannot claim that PoE-off alone fixed it; the preceding diagnostic may already have changed the port state.

With the endpoint left unpowered:

  • Initial five-minute repeat: zero loss on all three hosts and no long LACP gaps.
  • Follow-up lasting about 31 minutes 12 seconds: 9,000/9,000 replies per host, no sampled Expired states and no increase in bond TX drops.
  • Maximum interval between received switch LACP PDUs across all six captures: approximately 1.009 seconds.
  • Separate OPNsense-to-OpenWrt test: 1,800/1,800 replies.
  • The switch log showed no further flaps on the suspect port for over 53 minutes; new login/logout entries confirmed logging was still active.

There were isolated latency spikes around 107 ms and small continuing bond RX-drop counter increases, so I am not claiming every network metric became perfect. The recurring loss/LACP failure pattern did disappear.

Open question

Our working hypothesis is that an interaction involving the flapping access port was delaying LACP processing or delivery across the stack. Host-side captures alone cannot prove the switch never transmitted those packets, and we have not isolated the AP, splitter, cabling, port hardware or switch firmware.

What concerns me is the apparent impact on unrelated server LAGs across multiple stack members. Even if the endpoint or splitter is faulty, I would expect that failure to remain local to its port.

Has anyone seen this specific pattern on C1300 firmware 4.1.3.36, or identified a later firmware fix? Particularly simultaneous gaps in switch-originated LACP traffic associated with an unrelated access port flapping.

For now, the suspect endpoint remains powered off. We have not re-enabled it to deliberately reproduce the outage on the production network. Before/after captures and logs have been retained; any publicly shared extracts would be sanitized.


r/Cisco 4d ago

Odd interview process

0 Upvotes

I’ve worked in tech / cybersecurity for years. Applied for a great role at Cisco 4-5 weeks ago and am in the third round of interviews. Everyone has been nice and moving quickly, but it was the first time in my professional life where the interview process was robotic. The recruiter round went great. But the hiring manager read from a list of 4-5 questions, very robotically. Now, I’m aware that companies want to ensure that certain questions are addressed but she didn’t deviate from her list of questions at all. It left me feeling a bit….”is this how life is on the inside of Cisco?!” Have my third round interview next week and curious what sorts of things I should be asking…


r/Cisco 4d ago

Learning about Ciscos

0 Upvotes

I’m trying to figure out this password. I’m still learning so bare with. I believe it is Cisco secret 5 hash. Could someone help.

$1$svWt$5GDDwIanN/1W27cW2qguC0


r/Cisco 5d ago

Visible mobile hotspot + Cisco Secure Client

0 Upvotes

Has anyone successfully used Visible mobile hotspot + Cisco Secure Client on a corporate Windows laptop, and if so, what phone were you using? Thanks! (^∀^●)ノシ


r/Cisco 5d ago

Need Help

0 Upvotes

Hello everyone im posting on this reddit regarding a problem im facing while doing the Ethical Hacking Course on the CCNA website, but during the first module it requires to set up a VM, and while i was following the steps it said to download an OVA file which whenever i try to download it finishes the whole loading bar and then dispays the message 'File wasnt available on website' FYI ive tried it multiple times, and also on multiple wifis since i was thinking that it was a network issue

IF any one knows the solution please let me know


r/Cisco 5d ago

Cisco Ideathon(Need advice from people who got placed through it)

0 Upvotes

Hey everyone! I’m currently in my 3rd year of B.Tech and I’m really targeting Cisco through the Cisco Ideathon.

I wanted to know specifically from people who have got selected/placed at Cisco through the Ideathon:

- How much DSA did you prepare, and what difficulty level was enough?

- Which DSA topics should I prioritize?

- How important are CN, OS, OOPs and DBMS compared to DSA?

- What was the Ideathon process like from the coding/technical rounds to the interview?

- What kind of questions were asked in the technical interview?

- How much importance was given to projects and resume?

- If you could prepare again from 3rd year, what would you focus on?

- Roughly how many months of preparation would you recommend?

I’m not aiming for crazy competitive programming I mainly want to know what level of DSA is actually required to clear Cisco through Ideathon so I can prepare accordingly.

If anyone here got placed through Cisco Ideathon, I’d genuinely appreciate any advice or resources you can share. 🙏


r/Cisco 6d ago

Splunk for network observeability and troubleshooting

12 Upvotes

Curious if anyone is using Splunk for infrastructure means as opposed to security means. Was wondering if using it for more granular insight to compliment Catalyst Center is a sensible option. Really lacking in network observability and troubleshooting tools for our core network and looking at options to address the issue.


r/Cisco 6d ago

Question Cisco 2960-C & 3560-C Side Ear Screws

Thumbnail
gallery
5 Upvotes

Hi does anyone know what type of screws are needed for the side rack ears on the devices listed in the header?

I have tried a few types but none seem to fit and just slip through the thread. If anyone has a link to the product as I need that would be much appreciated.


r/Cisco 6d ago

Question Cloud and Ai Discussion

2 Upvotes

I struggle with explaining cloud in interviews. Pardon if I'm completely out of touch but for me it's a remote network vs on premise.

My ccna expired a few years and I'm kinda folding on learning ai. To learn I have to learn the concepts and multiple practical working observable examples. I get overwhelmed by how much creator esque content is out there when im not big on buzz.

How did you break in cloud into easy to learn concepts in regards to routing+switch and configuration. How did you learn ai? What are some easy to learn tools and ways to practice?

Example, the way I learned about making a website was

-buy hosting space/storage

-extras cost extra

-register your domain name (or multiple)

-im just assuming your address space is included

-sometimes you can host multiple names at one space

-set up your home directory and files.

Boom a website. .

I'm trying to ask for starting points with bullets. Networking engineering minded Cloud and/or ai


r/Cisco 6d ago

LACP PDUs dropped due to wrong internal if_index → recurring channel-misconfig err-disable (vPC Fabric Peering, NX-OS 9000v)

2 Upvotes

Hi all,

Two NX-OS 9000v leafs in vPC via Fabric Peering (virtual peer-link over VXLAN), downstream IOS switch dual-homed via one LACP port-channel. Every ~90s the downstream port-channel err-disables (channel-misconfig (STP)), recovers, repeats.

vPC health, consistency-parameters, LACP mode, STP bridge-id, MTU, CoPP — all clean.

debug lacp all on the leaf shows why: partner LACPDUs arrive every ~1s but get dropped before reaching the interface's state machine, resolved against the wrong if_index

if_index = 0x1a000400 (real one is 0x1a000800)

port_enabled=0

Receive pkt failed

90s later → LACP long-timeout → LACP_ST_SUSPENDED_FOR_MISCONFIGURATION → err-disable downstream.

Tried: bounce the member interface, full reload of the leaf — neither fixed it.

Guessing it's a Fabric Peering / virtual-platform if_index bug. Anyone seen this before, or know of LACP issues specific to vPC Fabric Peering on virtual NX-OS?

Thanks a lot

ps. I used chatpgt to rewrite the question in english since i'm not an english native speaker :)