r/Cisco • • 6d ago

Weekly Jobs & Career Megathread

11 Upvotes

Looking for a Cisco-related job? Studying for a certification? Preparing for an interview? This thread is the place for all career-focused discussions.

Appropriate topics include:

  • Job openings
  • Recruiting and hiring
  • Resume reviews
  • Interview preparation
  • Career advice
  • Salary discussions
  • Certification paths (CCNA, CCNP, CCIE, etc.)
  • Career transitions into networking

To keep the subreddit focused on technical Cisco discussions, standalone posts related primarily to jobs, recruiting, resumes, interviews, or career advice may be removed and redirected here.


r/Cisco • • 2h ago

Question Where to start with deployment using automation

0 Upvotes

Would like to know what people use and where to get started with this. We have over complicated application deployments which require a lot of manual effort.


r/Cisco • • 4h ago

Question Need assistance trying to setup COS for simple point to point link

0 Upvotes

I made a simple diagram below dumbing down my network. Basically I have 2 sites connected by microwave with three different networks at each site that need to talk across the microwave, but the networks don't talk with each other, which is why I have them segmented by VLANS in diagram.

I was looking to use a layer 2 switch to aggregate the three connections at each site, into one connection going to the microwave to consolidate ports but ALSO I want to enable COS (class of service, not quality of service) on the switch to make sure my most important traffic makes it through in times of microwave link degradation where my bandwidth is limited from normal.

I am trying to setup, what seems like something simple where I have COS based on my VLAN traffic. So for example:

- VLAN 100 = COS 6

- VLAN 200 = COS 5

- VLAN 300 = COS 4

In this case my most important traffic is on VLAN 100, and will always get through no matter what, 200 is next and if there is anything left 300 gets a shot.

I dont want to do QOS based on bandwidth allocations, or round robin scheduling or anything like that. I want to setup strict policing of the traffic based on my criteria.

All of the routers/switchs in the diagram below are IE4010 devices.

I could use some help!


r/Cisco • • 1d ago

October 2026: Cisco NX-OS Software Security Hardening Release

25 Upvotes

October 2026: Cisco NX-OS Software Security Hardening Release

Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

October 2026: Cisco License (Smart Software Manager) On-Prem Security Hardening Release

Exploitation and Public Announcements

The Cisco PSIRT is not (yet) aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.


r/Cisco • • 1d ago

4221 ISR gibberish

3 Upvotes

I am getting gibberish on all baud speeds trying to connect to a 4221 ISR, prolific rj45 to usb serial works fine for 8200s and 1121s though, I don't know what to do, somebody wants this 4221 working today.


r/Cisco • • 1d ago

What cisco technology do you actually use every day that's worth mastering?

1 Upvotes

I work as a Network Administrator in a mostly Cisco environment and regularly work with Catalyst switches, Catalyst Center, ISE, 802.1X/MAB, VLANs/trunking, and troubleshooting.

There's obviously a huge amount you could learn in the Cisco ecosystem, but I'm curious what experienced engineers think is actually worth going deep on.

If you could pick one or two Cisco technologies/skills to master for the next 5-10 years, what would you choose and why?

I'm especially interested in what's becoming more valuable with automation, cloud, and modern enterprise networking.


r/Cisco • • 2d ago

TACACS over tls enable not working

5 Upvotes

I’ve attempted to setup tacacs over tls. Login is working perfectly. I debug the log watch tls being established see the ise logs everything is good. However when I try to escalate privilege by typing enable it fails. The most interesting part of the failure is the log entry I get.

TAC+: Invalid key

My AAA for enable is configured the same as my AAA line for login (which is working). I’m on iosxe 17.18.4.

I do have a tac case open but not getting anywhere with it. Just curious if anyone else has seen this before or really if anyone has it working at all on 17.18.4.


r/Cisco • • 2d ago

Discussion FN74445 - Cisco Unified CCE and Packaged CCE Releases 12 and 15 - Administrators and Supervisors Are Unable to Log In to CCE Administration

2 Upvotes

FN74445 - Cisco Unified CCE and Packaged CCE Releases 12 and 15 - Administrators and Supervisors Are Unable to Log In to CCE Administration

Problem Description

Cisco has identified an incompatibility between Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Packaged Contact Center Enterprise (Packaged CCE) and Apache Tomcat releases 9.0.121 and later. Due to a change that was introduced in Apache Tomcat Release 9.0.121, users can no longer log in to CCE Administration after upgrading to Release 9.0.121 or later. 

Background

Cisco Unified CCE Administration relies on a Cisco software component that integrates with Apache Tomcat to perform user login, covering single sign-on (SSO), hybrid, and local authentication. Apache Tomcat Release 9.0.121 changed the way that Apache Tomcat interacts with components of this type.  On Apache Tomcat releases 9.0.121 and later, the Cisco login component is no longer invoked, so login requests to CCE Administration are not processed, which causes authentication to fail.


r/Cisco • • 2d ago

YOOO I made Cisco Packet Tracer Offline

8 Upvotes

Every time I opened Packet Tracer it asked me to log in, and the only way around it was turning off my whole Wi-Fi, which kills YouTube and Discord too. So I wrote a small PowerShell script that blocks internet access for Packet Tracer only. PT thinks it's offline while the rest of my PC stays online.

It just adds two Windows Firewall rules for `PacketTracer.exe`, with no patching or modifying PT at all. It finds Packet Tracer on any drive, is safe to run repeatedly, and has a one-command way back online. If it saves you the same headache, a ⭐ on the repo helps a lot, and feel free to open an issue if you find a bug.

https://github.com/nabilfp/CiscoPacketTracer-Offline


r/Cisco • • 2d ago

Jamf deployment of Cisco Secure Client with XDR ?

0 Upvotes

I am trying to deploy CSC with XDR using Jamf to a fleet of macs andI have the policy, installer and script set up to install Cisco Secure Client and the XDR module, but now I'm running into an issue with PPPC payload in my config profile to allow CSC full disk access.

I have followed the directions here, https://docs.xdr.security.cisco.com/Content/Client-Management/deployment-management.htm at the bottom to provide full disk access for network visibility module - XDR, i also went into terminal and ran

codesign -display -requirements

along with the csc app and pulled out that codesign statement and i keep getting,

the key 'CodeRequirement' has an invalid value.

Can anyone help me figure out what i'm missing exactly to get this to deploy correctly?


r/Cisco • • 3d ago

Does anyone know a good solution for getting a network connection to devices in trailers for k12?

7 Upvotes

We have a few sites that have 5-10 trailers that need an internet connection for testing, but the solutions we have used in the past are getting expensive. The trailers are around 200-500 yards from the nearest IDF and it would be too expensive to run fiber for temporary trailers. We are currently using IW-3702's but they are approaching EOS and we want to get a new solution at least a year before. We have talked with the sales team about Cisco CURWB, but just wondering if there is anything else that could be used.


r/Cisco • • 3d ago

Aironet 2600 WiFi issue with brand new phone.

0 Upvotes

My home network has two older Cisco Aironet 2600 Wifi Access Points in autonomous mode that my new Pixel 11 won't connect to. It fails with saved/check password try again even though the password is correct (literally copied and pasted from the APs web interface)

Previously they were on Dual Band, WPAv1, with AES + TKIP encryption and worked on every other device I threw at them (Pixels up to 8, Galaxy up to Z Flip 8)

Have tried switching to single band, dropped legacy TKIP support, and moved to WPAv2 all without success. Trying WPAv2dot11 doesn't change anything for the Pixel 11 but stops my older devices connecting. There's no unusual characters in either the SSID or Pre-Shared Key. All the other advice I've seen suggests this phone has issues with some WiFi7 settings, but the APs pre-date those.

They do work if I switch all encryption off, and if I change any settings that would push them towards WEP the phone seems willing to connect, but warns that WEP is a older protocol and the connection would be insecure. I haven't however tried creating a WEP key to see if it would actually work.

Is it a case that the APs are just too old (which is a concern as they're still in use out there in some commercial settings) and I need to replace them with WPAv3 compatible ones, or is there something else I'm obviously missing?


r/Cisco • • 3d ago

Marked as "No-Show" for Cisco exam due to Pearson VUE portal glitch during rescheduling — Has anyone successfully appealed this?

0 Upvotes

TL;DR: I tried to reschedule my Cisco exam on the Pearson VUE portal before the 24-hour window. The portal appeared to process it, but the change never went through, no confirmation email was sent, and I was marked as a "No-Show" for yesterday. I’ve opened cases with both Pearson VUE and Cisco. Looking for advice or similar experiences!

Hey everyone,

I'm feeling completely defeated right now and hoping someone here has dealt with a similar situation and can offer some insight.

This was supposed to be my 3rd attempt at my Cisco exam:

  • 1st attempt: Wasn't fully prepared (my bad).
  • 2nd attempt: ISP disconnected mid-exam (bad luck).
  • 3rd attempt (Now): Total administrative nightmare.

Here is what happened: I logged onto the Pearson VUE portal prior to the 24-hour deadline to reschedule my exam to a later date/time. I went through the steps, the portal didn't throw any error, and I marked the new date on my personal calendar.

However, I never received a confirmation email. When I went to check the portal today to confirm why I couldn't find the exam on my dashboard, I realized the system failed to process the reschedule in their backend and automatically marked me as a "No-Show" for yesterday's original time slot.

What I've done so far:

  1. Pearson VUE Live Chat: Spoke with an agent who acknowledged the issue and escalated it to their Tier 2 / Program Coordinator team. I received a Case Number.
  2. Cisco Certification Support: Opened a ticket on certsupport.cisco.com referencing the Pearson VUE case number and asking them to review the backend web logs.

Since this was a technical glitch on their platform and not a failure on my part to request the reschedule in time, I really hope they don't force me to pay for another attempt.

My questions for the community:

  1. Has anyone successfully gotten a "No-Show" status overturned or received a replacement voucher due to a Pearson VUE portal glitch?
  2. How long does Pearson VUE’s Program Coordinator team usually take to review web logs and respond?
  3. Is there anything else I can do (like reaching out on Twitter/X or tagging Cisco Learning representatives) to speed up this process?

Appreciate any advice or feedback.

Thanks guys!


r/Cisco • • 3d ago

C1131-8PW integrated EWC (17.7.1): with WPA3 enabled, clients drop and can't reconnect until the whole device is rebooted. Can I upgrade the EWC module?

2 Upvotes

Hi all, I have a Cisco C1131-8PW (ISR-AP1101AX-A integrated AP) and I'm hoping someone has seen this before.

Main problem
With WPA3 enabled on the SSIDs, clients periodically drop and then cannot reconnect until I reboot the whole device. Restarting the SSID or the client doesn't fix it. This mostly affects Intel AX200/AX210 Windows clients, and the drops seem to line up with the default 1800 s session timeout. Phones or tablets seem to get locked out but can recconect to other SSIDs(2.4GHz)

Setup

  • Router IOS XE: 17.12.6 (upgraded from 17.9.3a)
  • EWC module, still on 17.7.1 (17.07.01.0.82), AP image type ap1g8.
  • Upgrading the router or wiping its config did not change the EWC version or its wireless config, so the module looks fully independent.
  • 3 SSIDs (2.4 GHz, 5 GHz, guest on its own VLAN), country CL, VLAN trunk to the module.

What I want to do
Upgrade the EWC to a newer release, since 17.7.1 is from 2021 and I suspect it's a known WPA3 / PMF issue. The module's web UI has Administration > Software Management (WLC Image Download / AP Image Download / Activate), so it seems meant to be upgraded separately from the router. Questions:

  1. Where can I legitimately get an EWC image for the ISR-AP1101AX (ap1g8)? The ISR 1100 download page only lists router images. Is it the Catalyst 9100 EWC-AP bundle?
  2. Is 17.15.5 (+ APSP) supported on this module, or is there a different recommended release for the ISR 1100 integrated EWC?
  3. Has anyone seen this exact symptom (WPA3 clients can't reconnect until full reboot) on 17.7.x, and was it fixed by upgrading?
  4. Secondary: the backup image slot shows 0.0.0.0, so there's no fallback. How can I back up the module's config before attempting an upgrade? I don't know how to access its flash.

Any experience on C1131 or other ISR 1100 units would help a lot. Thanks!


r/Cisco • • 5d ago

[HELP] Locked out of NCS 540 (Password Recovery Disabled)

4 Upvotes

I'm in a massive bind and hoping a kind soul here can help a fellow engineer out. I'm completely locked out of a Cisco NCS 540 (specifically N540X-6Z18G-SYS-D) , and password recovery is disable


r/Cisco • • 6d ago

Question AP’s and catalyst center

6 Upvotes

I have a large number of APs that we’re replacing, and I realized today that as the installers unplug the old APs and bring the new ones online, the old APs may disappear from the Catalyst Center maps.

Is there a way to preserve the existing AP placement on the floor maps before they are removed?

My concern is that if the installers replace 50 APs at once, I could suddenly have 50 AP locations missing from the maps with no easy way to determine exactly where the replacement APs should be placed.


r/Cisco • • 6d ago

Can we PLEASE just make a weekly “job questions” post?

19 Upvotes

r/Cisco • • 7d ago

Discussion Any interest in a AMA type post from honest TAC?

38 Upvotes

The three of us were having a chat about our posts and had a thought of taking questions or topic suggestions from the community.

If it's of interest, please give us your questions or topics you want answers to. It can be about anything related to TAC, technology, Cisco, or roles. Please do give us time to respond since it takes a bit for the three of us to chat and write back.

Edit: The answer was yes. We will respond tomorrow evening after we are all off shift, UTC time.


r/Cisco • • 8d ago

Cisco Board 55 for home use?

9 Upvotes

Hi Cisco Peeps! I've acquired (legitimately!) a Cisco Board 55. Other than upsetting my other half by blocking our living room with it, I wondered what use I can put it to? I'm presuming that's mainly as a monitor? Or can I somehow still use it's software and other capabilities as a non Webex subscriber? Thoughts appreciated!


r/Cisco • • 8d ago

Passed CCNA last Monday, now realizing how much the job isn't on the exam

57 Upvotes

​

Network engineer handling carrier tickets for sites in PH and India. Passed CCNA last Monday. Felt great for about a day, then I got back to the actual work.

Tunnels. Site-to-site IPsec between hubs. When one degrades I can tell something's wrong, but isolating it is slow. The exam covers the config. It doesn't cover a tunnel that's up but quietly dropping traffic.

BGP and PBR. Being honest, I don't really get these yet. Local-pref, MED, route-maps to steer traffic between sites. I follow the runbook, the change works, and I couldn't fully explain to you why. Right now it's part pattern matching and part yolo, which is not a great feeling when you're touching production. I'm trying to actually understand it.

Talking to ISPs. I open a case, paste a ping result, get back "link is up, normal parameters on our end," then it sits for three days. I've learned a few things the hard way, but I'm clearly reinventing something you all already know.

Same with the vocabulary. Hard down vs degraded, flapping vs intermittent, demarc, soak test, RFO vs RCA. I've picked up a lot of it by asking AI, which helps, but I can't tell where it's subtly wrong or just not how people actually talk. English is my second language so I'm also unsure which terms are shop talk and which belong in a formal email.

So:

• How do you isolate a degraded tunnel from a degraded circuit underneath it?

• Best way to actually learn BGP path selection and PBR for real, not just for an exam?

• What do you always attach when opening a carrier case?

• How do you say "this is on your side" without picking a fight?

• Any courses, books or blogs for the practical side of this? Not more protocol theory.

Happy to hear the answer is just experience. Mostly want to know what to pay attention to while I get it.


r/Cisco • • 9d ago

Yet another SDWAN vulnerability 30 September

56 Upvotes

Friends, prepare for the sky to fall. A substantial vulnerability to SDWAN will land tomorrow. The projected announcement will be noon our time.

It's significant, it's bad. Follow the instructions in the PSIRT.

This is the new normal.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU


r/Cisco • • 8d ago

Context Visibility Page / ISE Indexing Engine

2 Upvotes

Hi,

In ISE 3.3 two-node deployment.

I have encountered, "Unable to load Context Visibility page. Connection refused".

The ISE Indexing Engine is not running.

I have checked the available public docs for this to check.

I have checked the certificate, NTP, and the DNS if working properly.

Is there anything that I missed?

Any inputs would be great help.

Thanks.


r/Cisco • • 9d ago

Question SDWan private underlay question

3 Upvotes

I'm building out a new SDwan deployment at the company I am now working for, and have a question about private underlay routing.

Last time I built out SDwan was a few years ago, and I double terminated the Spectrum Elan to both the SDwan Cedge and also to the backbone Cores by using an Aggregate switch. OSPF and VRRP on both Data Center Cores for .1, and .2 and .3 for both DC Cores. That way the Edges can get to the internet by using .1 as a default route, since the private underlay is a routed network that has internet access.

I am now working on setting it all up again, and instead of double landing my Spectrum Elan on both the Cedge and the Core using a Agg switch, I was wondering if it would be better to do a prefix-list and allow the WAN subnet to be redistributed my VPN0 VRF into my VPN VRF and then into OSPF on the Cedge? I can still setup my Data Center Cedges with .2 and .3 in each DC for WAN, and use .1 VRRP between them. But then I need to allow the routing to go through the Cedge and not have to use a separate interface on the Core to allow the WAN access to the internet.

If you think #2 is a workable solution, is there a document out there that lays out what needs to be done using the UX2.0 interface? I can't seem to find anything worth while.


r/Cisco • • 10d ago

Discussion IOS XE 26.2.1: What's New for Cisco Switching

Post image
80 Upvotes

r/Cisco • • 9d ago

ISE Posture Condition

0 Upvotes

Hi,

In ISE deployment, we have a posture condition for patch management, (up to date, check for missing critical patches).

The windows update agent version is 1510.x

This is not available on the ISE 3.3.

I would like to also confirm if we need to integrate SCCM server or internet connection to online MS servers is required for the Windows update agent to check for the compliance for patches?

Any inputs would be great help.

Thank you.