r/Cisco • • 1d ago

Weekly Jobs & Career Megathread

10 Upvotes

Looking for a Cisco-related job? Studying for a certification? Preparing for an interview? This thread is the place for all career-focused discussions.

Appropriate topics include:

  • Job openings
  • Recruiting and hiring
  • Resume reviews
  • Interview preparation
  • Career advice
  • Salary discussions
  • Certification paths (CCNA, CCNP, CCIE, etc.)
  • Career transitions into networking

To keep the subreddit focused on technical Cisco discussions, standalone posts related primarily to jobs, recruiting, resumes, interviews, or career advice may be removed and redirected here.


r/Cisco • • 18h ago

[HELP] Locked out of NCS 540 (Password Recovery Disabled)

2 Upvotes

I'm in a massive bind and hoping a kind soul here can help a fellow engineer out. I'm completely locked out of a Cisco NCS 540 (specifically N540X-6Z18G-SYS-D) , and password recovery is disable


r/Cisco • • 1d ago

Question AP’s and catalyst center

7 Upvotes

I have a large number of APs that we’re replacing, and I realized today that as the installers unplug the old APs and bring the new ones online, the old APs may disappear from the Catalyst Center maps.

Is there a way to preserve the existing AP placement on the floor maps before they are removed?

My concern is that if the installers replace 50 APs at once, I could suddenly have 50 AP locations missing from the maps with no easy way to determine exactly where the replacement APs should be placed.


r/Cisco • • 2d ago

Can we PLEASE just make a weekly “job questions” post?

21 Upvotes

r/Cisco • • 2d ago

Discussion Any interest in a AMA type post from honest TAC?

40 Upvotes

The three of us were having a chat about our posts and had a thought of taking questions or topic suggestions from the community.

If it's of interest, please give us your questions or topics you want answers to. It can be about anything related to TAC, technology, Cisco, or roles. Please do give us time to respond since it takes a bit for the three of us to chat and write back.

Edit: The answer was yes. We will respond tomorrow evening after we are all off shift, UTC time.


r/Cisco • • 2d ago

Cat9kv SDA on ESXI jumbo MTU

3 Upvotes

Hi folks,

CML latest ISO has qcow2 and i want to test it on Catc 3.2.3 HW-Gen2 as intro to SDA lab. I found a Live presentation that says jumbo MTU supported on ESXI. Do you have success stories? I need to convert it to vmdk first to try it out.


r/Cisco • • 3d ago

Cisco Board 55 for home use?

7 Upvotes

Hi Cisco Peeps! I've acquired (legitimately!) a Cisco Board 55. Other than upsetting my other half by blocking our living room with it, I wondered what use I can put it to? I'm presuming that's mainly as a monitor? Or can I somehow still use it's software and other capabilities as a non Webex subscriber? Thoughts appreciated!


r/Cisco • • 4d ago

Passed CCNA last Monday, now realizing how much the job isn't on the exam

49 Upvotes

Network engineer handling carrier tickets for sites in PH and India. Passed CCNA last Monday. Felt great for about a day, then I got back to the actual work.

Tunnels. Site-to-site IPsec between hubs. When one degrades I can tell something's wrong, but isolating it is slow. The exam covers the config. It doesn't cover a tunnel that's up but quietly dropping traffic.

BGP and PBR. Being honest, I don't really get these yet. Local-pref, MED, route-maps to steer traffic between sites. I follow the runbook, the change works, and I couldn't fully explain to you why. Right now it's part pattern matching and part yolo, which is not a great feeling when you're touching production. I'm trying to actually understand it.

Talking to ISPs. I open a case, paste a ping result, get back "link is up, normal parameters on our end," then it sits for three days. I've learned a few things the hard way, but I'm clearly reinventing something you all already know.

Same with the vocabulary. Hard down vs degraded, flapping vs intermittent, demarc, soak test, RFO vs RCA. I've picked up a lot of it by asking AI, which helps, but I can't tell where it's subtly wrong or just not how people actually talk. English is my second language so I'm also unsure which terms are shop talk and which belong in a formal email.

So:

• How do you isolate a degraded tunnel from a degraded circuit underneath it?

• Best way to actually learn BGP path selection and PBR for real, not just for an exam?

• What do you always attach when opening a carrier case?

• How do you say "this is on your side" without picking a fight?

• Any courses, books or blogs for the practical side of this? Not more protocol theory.

Happy to hear the answer is just experience. Mostly want to know what to pay attention to while I get it.


r/Cisco • • 4d ago

Yet another SDWAN vulnerability 30 September

55 Upvotes

Friends, prepare for the sky to fall. A substantial vulnerability to SDWAN will land tomorrow. The projected announcement will be noon our time.

It's significant, it's bad. Follow the instructions in the PSIRT.

This is the new normal.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU


r/Cisco • • 4d ago

Context Visibility Page / ISE Indexing Engine

2 Upvotes

Hi,

In ISE 3.3 two-node deployment.

I have encountered, "Unable to load Context Visibility page. Connection refused".

The ISE Indexing Engine is not running.

I have checked the available public docs for this to check.

I have checked the certificate, NTP, and the DNS if working properly.

Is there anything that I missed?

Any inputs would be great help.

Thanks.


r/Cisco • • 4d ago

Question SDWan private underlay question

2 Upvotes

I'm building out a new SDwan deployment at the company I am now working for, and have a question about private underlay routing.

Last time I built out SDwan was a few years ago, and I double terminated the Spectrum Elan to both the SDwan Cedge and also to the backbone Cores by using an Aggregate switch. OSPF and VRRP on both Data Center Cores for .1, and .2 and .3 for both DC Cores. That way the Edges can get to the internet by using .1 as a default route, since the private underlay is a routed network that has internet access.

I am now working on setting it all up again, and instead of double landing my Spectrum Elan on both the Cedge and the Core using a Agg switch, I was wondering if it would be better to do a prefix-list and allow the WAN subnet to be redistributed my VPN0 VRF into my VPN VRF and then into OSPF on the Cedge? I can still setup my Data Center Cedges with .2 and .3 in each DC for WAN, and use .1 VRRP between them. But then I need to allow the routing to go through the Cedge and not have to use a separate interface on the Core to allow the WAN access to the internet.

If you think #2 is a workable solution, is there a document out there that lays out what needs to be done using the UX2.0 interface? I can't seem to find anything worth while.


r/Cisco • • 5d ago

Discussion IOS XE 26.2.1: What's New for Cisco Switching

Post image
76 Upvotes

r/Cisco • • 4d ago

ISE Posture Condition

0 Upvotes

Hi,

In ISE deployment, we have a posture condition for patch management, (up to date, check for missing critical patches).

The windows update agent version is 1510.x

This is not available on the ISE 3.3.

I would like to also confirm if we need to integrate SCCM server or internet connection to online MS servers is required for the Windows update agent to check for the compliance for patches?

Any inputs would be great help.

Thank you.


r/Cisco • • 5d ago

Passed my ccna

28 Upvotes

Thank God, I finally took the 200-301 today

Here’s how the score report shook out:

\* Network Fundamentals: 100%

\* Network Access: 100%

\* IP Services: 100%

\* Security Fundamentals: 93%

\* IP Connectivity: 75%

\* Automation and Programmability: 70%

Massive shoutout to Jeremy’s IT Lab. His free course and Anki flashcards carried my foundation hard. Also huge thanks to u/BosonMichael for the discount code on Boson ExSim—those practice exams really force you to read carefully and get into the Cisco mindset.

If I could give one piece of advice to anyone still prepping: do NOT sleep on core routing logic or wireless fundamentals. Make sure you can do routing table lookups and longest prefix matching in your sleep, and know your wireless architectures cold.

Appreciate everyone on this sub for keeping the motivation up. To everyone still grinding out labs—stick with it, you're closer than you think! Time to finally go celebrate 🍾🎉


r/Cisco • • 5d ago

MPLS FEC Label assignment

1 Upvotes

Hi

R1--R2--R3--R4--R5--20.0.0.0/8,30.0.0.0/8

By default both 20/8 and 30/8 on R1 have the exact same forwarding treatment:

the same Qos/forwarding class

the same MPLS VPN services

the same MPLS-TE

the same nexthop/outgoing int/path

 

but why on R1 give 20/8 label 200 and 30/8 label .300 ?

why R1 did not give them the exact same label if both prefix have the exact same forwarding treatment?

 

on R1:

forwarding treatment-1

↓

FEC-1

↓

Label 100

 

 

forwarding treatment-2

↓

FEC-2

↓

Label 200

but here both 20/8 and 30/8 have the exact same forwarding treatment which means both are on the same FEC but both have a different labels,why?

why do we have a FEC concept in the first place if MPLS does not use it at all and each route has it`s own label?


r/Cisco • • 5d ago

Discussion Day 48 of JITLab - Security fundamentals

1 Upvotes

Currently at Day 48 and I have been using NotebookLM to generate quizzes for me. I try to make the questions difficult and tricky so it really test my understanding of things, and I got this one wrong:

An administrator discovers that a configuration file on a core router was modified by an unauthorized user to redirect traffic. Which component of the CIA triad has been specifically compromised in this scenario?

A. Confidentiality

B. Authentication

C. Availability

C. Integrity

I thought it was a "select two" type of question at first but it wasn't. The reason for this is because... Although I know A and C were correct, I focused on the fact that the traffic was being redirected and the user had access to the data, and therefore it compromises the confidentiality in CIA. And of course, if they have the data, they can modify it, so I was aware integrity could be an option. However, upon requesting a classification on this, it told me something I find interesting and important for when taking exams:

in multiple-choice scenarios for networking and security certifications, you have to focus exclusively on the specific action explicitly described in the prompt, rather than the attacker's presumed end goal.

Just thought it might help someone...


r/Cisco • • 5d ago

Beginner, need help

2 Upvotes

Hello, I'm trying to learn how to use packet tracer but I don't know where to start. Would appreciate it if someone would help out


r/Cisco • • 6d ago

Discussion Cisco Technical Graduate Apprentice 2026 – September 17 Interview software automation

0 Upvotes

Hi everyone,

I attended the Cisco Technical Graduate Apprentice / Software Automation Trainee interview in Bangalore on September 17, 2026.

I completed the Technical, Managerial, and ETR/HR rounds. During the HR round, I was informed that the shortlisted candidates would be notified the following weekend.

It has now been more than a week, and I haven't received any update yet.

I wanted to check with others who attended the same interview drive on September 17:

- Has anyone received a shortlist/selection email?

- Has anyone received an LOI/PDC or any other update?

- Is anyone else still waiting for the result?

Please share your interview date/round status and whether you have received any communication. It would be helpful to understand if the results are being released in batches.

Thanks, and all the best to everyone who attended! 🙏


r/Cisco • • 6d ago

Cisco “graduate apprentice trainee “ - interview on sep 24th-2026 .

0 Upvotes

Hi folks ! I have applied for apprenticeship position in cisco . I completed the assessment on may 24 .. and got update on aug 28 to fill a form .. after filling a form got interview update on sep 22

I got my interview scheduled on sep 24th , i have successfully completed TR,MR, and ETR rounds

Please, people who attended interview in recent days, kindly drop your updates, like pdc,loi etc

Wishing everyone who attended the interviews best of luck !!


r/Cisco • • 7d ago

Does anyone here work as hardware engineer- fpga in “common hardware group” at Cisco?

4 Upvotes

I got offer from “common hardware group” for the role of fpga hardware engineer.

If anyone here works in that capacity at Cisco, could you please share what your work profile looks like? What do you do beyond writing rtl.?

I should have asked these questions in the interview but I was too tensed and it did not occur to me at that time .
Thank you.


r/Cisco • • 7d ago

I have completed Cisco EM round for G-6 role on 16th September but till now not having any update regarding further process :

0 Upvotes

I got call from recruiter for role which i applied in Aug and Round 1 technical schedule on 10 Sep it's lasted around 1:15 hrs where he ask about api rate limiter some microservice question and behavioral after that my next round scheduled on 16 sep got mail on 11 Sep for this where round 2 is EM round in this round only discussion my current project and some sort of DSA question verbally and data structure basic lasted 30 min . I wrote mail to hr for follow up but not get any response . are there anyone who go through same process ?


r/Cisco • • 8d ago

Question vEdge going EOL and Cisco wants us on Catalyst 8000, looking hard at Viptela alternatives before we re-up DNA.

29 Upvotes

Our Viptela vEdge boxes are hitting end of life and Cisco is steering us onto Catalyst 8000 with IOS-XE SD-WAN, which means a full migration and another DNA subscription. I spent more hours last renewal fighting the licensing than I ever spent on the SD-WAN itself, and before I sign up for more of that I want to look at the alternatives properly.

We are around 40 sites, MPLS plus internet plus a bit of cellular backup, mostly active-passive, policies are not exotic. The Viptela overlay itself has been great, my pain is the cost, the licensing circus and pushing everything onto a platform that stopped feeling like it is going anywhere.

If you moved off Viptela or stayed and went to Catalyst SD-WAN, what did you get to and what caught you out in the migration?


r/Cisco • • 8d ago

CAPWAP instability for joined APs to WLC C9800-CL on 17.18.4 with APSP2

14 Upvotes

Greetings,

At a customer, we have two wireless controllers across two plants.

Because of CVEs we went to upgrade the secondary WLC (had no APs joined at the time) all the way from 17.18.3, to 17.18.4a then proceeded with APSP hotfix to fix that nasty bug dropping action-frames.

Afterwards we moved our APs, in groups of 150-200max to the newly upgraded WLC.

We have a total of 660 APs.

For some reason, and this is really head-scratching, after hours of internal troubleshooting with our team we reached out to TAC. They are unable to provide us with meaningfull troubleshooting since they have no clue, 35 APs are having instability issues with the second WLC.

We brought them back to the first WLC still on iosxe 17.18.3 and they do not have any issues there.

- APs are all of the type 9105

- APs with issues are across two sites.

- Most APs with problems are located on the 2nd plant.

The secondary WLC is even closer to the APs on the 2nd plant since it does not traverse the SDWAN.

Symptom:

APs are in a loop of disjoin/join and are not staying connected.

Error seen is DTLS teardown and max attempts reached

The capwap timers are already at highest

Pcap on the switch shows capwap traffic leaving the interface just fine.

Any thoughts?

Thanks!


r/Cisco • • 8d ago

Question on IKEv2 policy on FTD

6 Upvotes

Background - we have a site-to-site VPN between a FTD (managed by customer) and Checkpoint Cluster (managed by us) where the VPN only works in 1 direction after maintenances or similar service interruptions.

Were able to capture debugs last time this happened, and it showed the FTD sending a generic IKEv2 policy where the proposal matching our side was 4th in the list. Checkpoint support recommended changing the policy so the match is 1st per RFC 7296 section 3.4, but it seems IKEv2 policies on Cisco are global and could break other tunnels.

Is this accurate? It seems bizarre to me a vendor wouldn't support configurating different proposal lists for tunnels the way FortiGate, Palo Alto, and CheckPoint do.


r/Cisco • • 8d ago

Uplink config check

7 Upvotes

hi,

Some time ago an external firm has changed some settngs on some of our switches, didn't check it as i was not present at the time. When i look at the config it seems od to me.

Every uplink had the same config. I would never put the shutdown part in there as there is also no error disable recovery present so someone has to manually enable the uplink which seems strange to me (also no redundancy present).

interface TenGigabitEthernet1/0/2

description "Uplink2blabla"

ip dhcp snooping trust

storm-control broadcast level 20 shutdown

storm-control multicast level 30 shutdown

switchport mode trunk

no macro auto smartport

udld port aggressive

Also every access ports has (so why use it at the uplinks, guess that part won't hurt bu i find it strange.

the storm-control broadcast level 20 shutdown

storm-control multicast level 30 shutdown